<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T09:52:06.534199+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-03258</id>
    <title>bdu:2026-03258</title>
    <updated>2026-10-04T09:52:06.861023+00:00</updated>
    <content>bdu:2026-03258</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-03258"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2025-37920</id>
    <title>BELL-CVE-2025-37920</title>
    <updated>2026-10-04T09:52:06.861096+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2025-37920"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0625</id>
    <title>certfr-2025-avi-0625 — De multiples vulnérabilités ont été découvertes dans Ubuntu Ubuntu. Certaines d'entre elles permettent à un attaquant d…</title>
    <updated>2026-10-04T09:52:06.861132+00:00</updated>
    <content>certfr-2025-avi-0625</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-0625"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-346858</id>
    <title>EUVD-2026-346858</title>
    <updated>2026-10-04T09:52:06.861151+00:00</updated>
    <content>EUVD-2026-346858</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-346858"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-37920</id>
    <title>fkie_cve-2025-37920</title>
    <updated>2026-10-04T09:52:06.861164+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>xsk: Fix race condition in AF_XDP generic RX path</p>
<p>Move rx_lock from xsk_socket to xsk_buff_pool.
Fix synchronization for shared umem mode in
generic RX path where multiple sockets share
single xsk_buff_pool.</p>
<p>RX queue is exclusive to xsk_socket, while FILL
queue can be shared between multiple sockets.
This could result in race condition where two
CPU cores access RX path of two different sockets
sharing the same umem.</p>
<p>Protect both queues by acquiring spinlock in shared
xsk_buff_pool.</p>
<p>Lock contention may be minimized in the future by some
per-thread FQ buffering.</p>
<p>It's safe and necessary to move spin_lock_bh(rx_lock)
after xsk_rcv_check():
* xs-&gt;pool and spinlock_init is synchronized by
  xsk_bind() -&gt; xsk_is_bound() memory barriers.
* xsk_rcv_check() may return true at the moment
  of xsk_release() or xsk_unbind_dev(),
  however this will not cause any data races or
  race conditions. xsk_unbind_dev() removes xdp
  socket from all maps and waits for completion
  of all outstanding rx operations. Packets in
  RX path will either complete safely or drop.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-37920"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-4qc6-52f6-6vgr</id>
    <title>GHSA-4qc6-52f6-6vgr</title>
    <updated>2026-10-04T09:52:06.861201+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>xsk: Fix race condition in AF_XDP generic RX path</p>
<p>Move rx_lock from xsk_socket to xsk_buff_pool.
Fix synchronization for shared umem mode in
generic RX path where multiple sockets share
single xsk_buff_pool.</p>
<p>RX queue is exclusive to xsk_socket, while FILL
queue can be shared between multiple sockets.
This could result in race condition where two
CPU cores access RX path of two different sockets
sharing the same umem.</p>
<p>Protect both queues by acquiring spinlock in shared
xsk_buff_pool.</p>
<p>Lock contention may be minimized in the future by some
per-thread FQ buffering.</p>
<p>It's safe and necessary to move spin_lock_bh(rx_lock)
after xsk_rcv_check():
* xs-&gt;pool and spinlock_init is synchronized by
  xsk_bind() -&gt; xsk_is_bound() memory barriers.
* xsk_rcv_check() may return true at the moment
  of xsk_release() or xsk_unbind_dev(),
  however this will not cause any data races or
  race conditions. xsk_unbind_dev() removes xdp
  socket from all maps and waits for completion
  of all outstanding rx operations. Packets in
  RX path will either complete safely or drop.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-4qc6-52f6-6vgr"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2025-37920</id>
    <title>msrc_CVE-2025-37920 — xsk: Fix race condition in AF_XDP generic RX path</title>
    <updated>2026-10-04T09:52:06.861227+00:00</updated>
    <content>msrc_CVE-2025-37920</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2025-37920"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2025-2077</id>
    <title>OESA-2025-2077 — kernel security update</title>
    <updated>2026-10-04T09:52:06.861244+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS: kernel</p>
<p>The Linux Kernel, the operating system core itself.

Security Fix(es):</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>mac802154: check local interfaces before deleting sdata list</p>
<p>syzkaller reported a corrupted list in ieee802154_if_remove. [1]</p>
<p>Remove an IEEE 802.15.4 network interface after unregister an IEEE 802.15.4
hardware device from the system.</p>
<p>CPU0					CPU1
====					====
genl_family_rcv_msg_doit		ieee802154_unregister_hw
ieee802154_del_iface			ieee802154_remove_interfaces
rdev_del_virtual_intf_deprecated	list_del(&amp;amp;sdata-&amp;gt;list)
ieee802154_if_remove
list_del_rcu</p>
<p>The net device has been unregistered, since the rcu grace period,
unregistration must be run before ieee802154_if_remove.</p>
<p>To avoid this issue, add a check for local-&amp;gt;interfaces before deleting
sdata list.</p>
<p>[1]
kernel BUG at lib/list_debug.c:58!
Oops: invalid opcode: 0000 [#1] PREEMPT SMP KASAN PTI
CPU: 0 UID: 0 PID: 6277 Comm: syz-executor157 Not tainted 6.12.0-rc6-syzkaller-00005-g557329bcecc2 #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 09/13/2024
RIP: 0010:__list_del_entry_valid_or_report+0xf4/0x140 lib/list_debug.c:56
Code: e8 a1 7e 00 07 90 0f 0b 48 c7 c7 e0 37 60 8c 4c 89 fe e8 8f 7e 00 07 90 0f 0b 48 c7 c7 40 38 60 8c 4c 89 fe e8 7d 7e 00 07 90 &amp;lt;0f&amp;gt; 0b 48 c7 c7 a0 38 60 8c 4c 89 fe e8 6b 7e 00 07 90 0f 0b 48 c7
RSP: 0018:ffffc9000490f3d0 EFLAGS: 00010246
RAX: 000000000000004e RBX: dead000000000122 RCX: d211eee56bb28d00
RDX:…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2025-2077"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2025:02846-1</id>
    <title>SUSE-SU-2025:02846-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-04T09:52:06.861493+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2025:02846-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-37920</id>
    <title>UBUNTU-CVE-2025-37920</title>
    <updated>2026-10-04T09:52:06.861579+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:Pro:18.04:LTS: linux-aws-5.4, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:Pro:18.04:LTS: linux-azure-5.4, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3 and 185 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: xsk: Fix race condition in AF_XDP generic RX path Move rx_lock from xsk_socket to xsk_buff_pool. Fix synchronization for shared umem mode in generic RX path where multiple sockets share single xsk_buff_pool. RX queue is exclusive to xsk_socket, while FILL queue can be shared between multiple sockets. This could result in race condition where two CPU cores access RX path of two different sockets sharing the same umem. Protect both queues by acquiring spinlock in shared xsk_buff_pool. Lock contention may be minimized in the future by some per-thread FQ buffering. It's safe and necessary to move spin_lock_bh(rx_lock) after xsk_rcv_check(): * xs-&gt;pool and spinlock_init is synchronized by   xsk_bind() -&gt; xsk_is_bound() memory barriers. * xsk_rcv_check() may return true at the moment   of xsk_release() or xsk_unbind_dev(),   however this will not cause any data races or   race conditions. xsk_unbind_dev() removes xdp   socket from all maps and waits for completion   of all outstanding rx operations. Packets in   RX path will either complete safely or drop.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-37920"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1114</id>
    <title>WID-SEC-W-2025-1114 — Linux Kernel: Mehrere Schwachstellen</title>
    <updated>2026-10-04T09:52:06.861903+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Linux Kernel ausnutzen, um einen Denial of Service Angriff und weitere nicht spezifizierte Angriffe durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1114"/>
  </entry>
</feed>
