<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T16:11:26.268803+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-12246</id>
    <title>bdu:2025-12246</title>
    <updated>2026-10-04T16:11:26.434039+00:00</updated>
    <content>bdu:2025-12246</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-12246"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2025-37851</id>
    <title>BELL-CVE-2025-37851</title>
    <updated>2026-10-04T16:11:26.434110+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2025-37851"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0463</id>
    <title>certfr-2025-avi-0463 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de Debian LTS. Elles permettent à un attaquant de p…</title>
    <updated>2026-10-04T16:11:26.434146+00:00</updated>
    <content>certfr-2025-avi-0463</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-0463"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-314280</id>
    <title>EUVD-2026-314280</title>
    <updated>2026-10-04T16:11:26.434165+00:00</updated>
    <content>EUVD-2026-314280</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-314280"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-37851</id>
    <title>fkie_cve-2025-37851</title>
    <updated>2026-10-04T16:11:26.434176+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>fbdev: omapfb: Add 'plane' value check</p>
<p>Function dispc_ovl_setup is not intended to work with the value OMAP_DSS_WB
of the enum parameter plane.</p>
<p>The value of this parameter is initialized in dss_init_overlays and in the
current state of the code it cannot take this value so it's not a real
problem.</p>
<p>For the purposes of defensive coding it wouldn't be superfluous to check
the parameter value, because some functions down the call stack process
this value correctly and some not.</p>
<p>For example, in dispc_ovl_setup_global_alpha it may lead to buffer
overflow.</p>
<p>Add check for this value.</p>
<p>Found by Linux Verification Center (linuxtesting.org) with SVACE static
analysis tool.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-37851"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-775j-mphj-44x5</id>
    <title>GHSA-775j-mphj-44x5</title>
    <updated>2026-10-04T16:11:26.434211+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>fbdev: omapfb: Add 'plane' value check</p>
<p>Function dispc_ovl_setup is not intended to work with the value OMAP_DSS_WB
of the enum parameter plane.</p>
<p>The value of this parameter is initialized in dss_init_overlays and in the
current state of the code it cannot take this value so it's not a real
problem.</p>
<p>For the purposes of defensive coding it wouldn't be superfluous to check
the parameter value, because some functions down the call stack process
this value correctly and some not.</p>
<p>For example, in dispc_ovl_setup_global_alpha it may lead to buffer
overflow.</p>
<p>Add check for this value.</p>
<p>Found by Linux Verification Center (linuxtesting.org) with SVACE static
analysis tool.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-775j-mphj-44x5"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2025-37851</id>
    <title>msrc_CVE-2025-37851 — fbdev: omapfb: Add 'plane' value check</title>
    <updated>2026-10-04T16:11:26.434234+00:00</updated>
    <content>msrc_CVE-2025-37851</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2025-37851"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2025-1572</id>
    <title>OESA-2025-1572 — kernel security update</title>
    <updated>2026-10-04T16:11:26.434252+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS: kernel</p>
<p>The Linux Kernel, the operating system core itself.

Security Fix(es):</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>wifi: ath11k: add srng-&amp;gt;lock for ath11k_hal_srng_* in monitor mode</p>
<p>ath11k_hal_srng_* should be used with srng-&amp;gt;lock to protect srng data.</p>
<p>For ath11k_dp_rx_mon_dest_process() and ath11k_dp_full_mon_process_rx(),
they use ath11k_hal_srng_* for many times but never call srng-&amp;gt;lock.</p>
<p>So when running (full) monitor mode, warning will occur:
RIP: 0010:ath11k_hal_srng_dst_peek+0x18/0x30 [ath11k]
Call Trace:
 ? ath11k_hal_srng_dst_peek+0x18/0x30 [ath11k]
 ath11k_dp_rx_process_mon_status+0xc45/0x1190 [ath11k]
 ? idr_alloc_u32+0x97/0xd0
 ath11k_dp_rx_process_mon_rings+0x32a/0x550 [ath11k]
 ath11k_dp_service_srng+0x289/0x5a0 [ath11k]
 ath11k_pcic_ext_grp_napi_poll+0x30/0xd0 [ath11k]
 __napi_poll+0x30/0x1f0
 net_rx_action+0x198/0x320
 __do_softirq+0xdd/0x319</p>
<p>So add srng-&amp;gt;lock for them to avoid such warnings.</p>
<p>Inorder to fetch the srng-&amp;gt;lock, should change srng&amp;apos;s definition from
&amp;apos;void&amp;apos; to &amp;apos;struct hal_srng&amp;apos;. And initialize them elsewhere to prevent
one line of code from being too long. This is consistent with other ring
process functions, such as ath11k_dp_process_rx().</p>
<p>Tested-on: WCN6855 hw2.0 PCI WLAN.HSP.1.1-03125-QCAHSPSWPL_V1_V2_SILICONZ_LITE-3.6510.30
Tested-on: QCN9074 hw1.0 PCI WLAN.HK.2.7.0.1-01744-QCAHKSWPL_SILICONZ-1(CVE-2024-58096)</p>
<p>In the Linux kernel, the following vulnerability has been res…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2025-1572"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2025:01964-1</id>
    <title>SUSE-SU-2025:01964-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-04T16:11:26.434387+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2025:01964-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-37851</id>
    <title>UBUNTU-CVE-2025-37851</title>
    <updated>2026-10-04T16:11:26.434607+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: linux, Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe and 206 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: fbdev: omapfb: Add 'plane' value check Function dispc_ovl_setup is not intended to work with the value OMAP_DSS_WB of the enum parameter plane. The value of this parameter is initialized in dss_init_overlays and in the current state of the code it cannot take this value so it's not a real problem. For the purposes of defensive coding it wouldn't be superfluous to check the parameter value, because some functions down the call stack process this value correctly and some not. For example, in dispc_ovl_setup_global_alpha it may lead to buffer overflow. Add check for this value. Found by Linux Verification Center (linuxtesting.org) with SVACE static analysis tool.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-37851"/>
  </entry>
</feed>
