<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T10:21:07.687976+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-11763</id>
    <title>bdu:2025-11763</title>
    <updated>2026-10-04T10:21:07.731739+00:00</updated>
    <content>bdu:2025-11763</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-11763"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2025-37814</id>
    <title>BELL-CVE-2025-37814</title>
    <updated>2026-10-04T10:21:07.731781+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2025-37814"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0559</id>
    <title>certfr-2025-avi-0559 — De multiples vulnérabilités ont été découvertes dans le noyau Linux d'Ubuntu. Certaines d'entre elles permettent à un a…</title>
    <updated>2026-10-04T10:21:07.731811+00:00</updated>
    <content>certfr-2025-avi-0559</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-0559"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-346825</id>
    <title>EUVD-2026-346825</title>
    <updated>2026-10-04T10:21:07.731829+00:00</updated>
    <content>EUVD-2026-346825</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-346825"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-37814</id>
    <title>fkie_cve-2025-37814</title>
    <updated>2026-10-04T10:21:07.731841+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>tty: Require CAP_SYS_ADMIN for all usages of TIOCL_SELMOUSEREPORT</p>
<p>This requirement was overeagerly loosened in commit 2f83e38a095f
("tty: Permit some TIOCL_SETSEL modes without CAP_SYS_ADMIN"), but as
it turns out,</p>
<p>(1) the logic I implemented there was inconsistent (apologies!),</p>
<p>(2) TIOCL_SELMOUSEREPORT might actually be a small security risk
      after all, and</p>
<p>(3) TIOCL_SELMOUSEREPORT is only meant to be used by the mouse
      daemon (GPM or Consolation), which runs as CAP_SYS_ADMIN
      already.</p>
<p>In more detail:</p>
<p>1. The previous patch has inconsistent logic:</p>
<p>In commit 2f83e38a095f ("tty: Permit some TIOCL_SETSEL modes
   without CAP_SYS_ADMIN"), we checked for sel_mode ==
   TIOCL_SELMOUSEREPORT, but overlooked that the lower four bits of
   this "mode" parameter were actually used as an additional way to
   pass an argument.  So the patch did actually still require
   CAP_SYS_ADMIN, if any of the mouse button bits are set, but did not
   require it if none of the mouse buttons bits are set.</p>
<p>This logic is inconsistent and was not intentional.  We should have
   the same policies for using TIOCL_SELMOUSEREPORT independent of the
   value of the "hidden" mouse button argument.</p>
<p>I sent a separate documentation patch to the man page list with
   more details on TIOCL_SELMOUSEREPORT:
   https://lore.kernel.org/all/20250223091342.35523-2-gnoack3000@gmail.com/</p>
<p>2. TIOCL_SELMOUSEREPORT is…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-37814"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-vjw7-4w34-rrq4</id>
    <title>GHSA-vjw7-4w34-rrq4</title>
    <updated>2026-10-04T10:21:07.731896+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>tty: Require CAP_SYS_ADMIN for all usages of TIOCL_SELMOUSEREPORT</p>
<p>This requirement was overeagerly loosened in commit 2f83e38a095f
("tty: Permit some TIOCL_SETSEL modes without CAP_SYS_ADMIN"), but as
it turns out,</p>
<p>(1) the logic I implemented there was inconsistent (apologies!),</p>
<p>(2) TIOCL_SELMOUSEREPORT might actually be a small security risk
      after all, and</p>
<p>(3) TIOCL_SELMOUSEREPORT is only meant to be used by the mouse
      daemon (GPM or Consolation), which runs as CAP_SYS_ADMIN
      already.</p>
<p>In more detail:</p>
<p>1. The previous patch has inconsistent logic:</p>
<p>In commit 2f83e38a095f ("tty: Permit some TIOCL_SETSEL modes
   without CAP_SYS_ADMIN"), we checked for sel_mode ==
   TIOCL_SELMOUSEREPORT, but overlooked that the lower four bits of
   this "mode" parameter were actually used as an additional way to
   pass an argument.  So the patch did actually still require
   CAP_SYS_ADMIN, if any of the mouse button bits are set, but did not
   require it if none of the mouse buttons bits are set.</p>
<p>This logic is inconsistent and was not intentional.  We should have
   the same policies for using TIOCL_SELMOUSEREPORT independent of the
   value of the "hidden" mouse button argument.</p>
<p>I sent a separate documentation patch to the man page list with
   more details on TIOCL_SELMOUSEREPORT:
   https://lore.kernel.org/all/20250223091342.35523-2-gnoack3000@gmail.com/</p>
<p>2. TIOCL_SELMOUSEREPORT is…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-vjw7-4w34-rrq4"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2025:02333-1</id>
    <title>SUSE-SU-2025:02333-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-04T10:21:07.731940+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2025:02333-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-37814</id>
    <title>UBUNTU-CVE-2025-37814</title>
    <updated>2026-10-04T10:21:07.732053+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 79 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: tty: Require CAP_SYS_ADMIN for all usages of TIOCL_SELMOUSEREPORT This requirement was overeagerly loosened in commit 2f83e38a095f ("tty: Permit some TIOCL_SETSEL modes without CAP_SYS_ADMIN"), but as it turns out,   (1) the logic I implemented there was inconsistent (apologies!),   (2) TIOCL_SELMOUSEREPORT might actually be a small security risk       after all, and   (3) TIOCL_SELMOUSEREPORT is only meant to be used by the mouse       daemon (GPM or Consolation), which runs as CAP_SYS_ADMIN       already. In more detail: 1. The previous patch has inconsistent logic:    In commit 2f83e38a095f ("tty: Permit some TIOCL_SETSEL modes    without CAP_SYS_ADMIN"), we checked for sel_mode ==    TIOCL_SELMOUSEREPORT, but overlooked that the lower four bits of    this "mode" parameter were actually used as an additional way to    pass an argument.  So the patch did actually still require    CAP_SYS_ADMIN, if any of the mouse button bits are set, but did not    require it if none of the mouse buttons bits are set.    This logic is inconsistent and was not intentional.  We should have    the same policies for using TIOCL_SELMOUSEREPORT independent of the    value of the "hidden" mouse button argument.    I sent a separate documentation patch to the man page list with    more details on TIOCL_SELMOUSEREPORT:    https://lore.kernel.org/all/20250223091342.35523-2-gnoack3000@gmail.com/ 2. TIOCL_SELMOUSEREPORT is indeed a p…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-37814"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0975</id>
    <title>WID-SEC-W-2025-0975 — Linux Kernel: Mehrere Schwachstellen ermöglichen Denial of Service</title>
    <updated>2026-10-04T10:21:07.732181+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Linux Kernel ausnutzen, um einen Denial of Service Angriff oder einen unspezifischen Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0975"/>
  </entry>
</feed>
