<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T03:18:28.262276+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-12066</id>
    <title>bdu:2025-12066</title>
    <updated>2026-10-04T03:18:29.831596+00:00</updated>
    <content>bdu:2025-12066</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-12066"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2025-38000</id>
    <title>BELL-CVE-2025-38000</title>
    <updated>2026-10-04T03:18:29.831684+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2025-38000"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0559</id>
    <title>certfr-2025-avi-0559 — De multiples vulnérabilités ont été découvertes dans le noyau Linux d'Ubuntu. Certaines d'entre elles permettent à un a…</title>
    <updated>2026-10-04T03:18:29.831718+00:00</updated>
    <content>certfr-2025-avi-0559</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-0559"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-346883</id>
    <title>EUVD-2026-346883</title>
    <updated>2026-10-04T03:18:29.831736+00:00</updated>
    <content>EUVD-2026-346883</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-346883"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-38000</id>
    <title>fkie_cve-2025-38000</title>
    <updated>2026-10-04T03:18:29.831747+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>sch_hfsc: Fix qlen accounting bug when using peek in hfsc_enqueue()</p>
<p>When enqueuing the first packet to an HFSC class, hfsc_enqueue() calls the
child qdisc's peek() operation before incrementing sch-&gt;q.qlen and
sch-&gt;qstats.backlog. If the child qdisc uses qdisc_peek_dequeued(), this may
trigger an immediate dequeue and potential packet drop. In such cases,
qdisc_tree_reduce_backlog() is called, but the HFSC qdisc's qlen and backlog
have not yet been updated, leading to inconsistent queue accounting. This
can leave an empty HFSC class in the active list, causing further
consequences like use-after-free.</p>
<p>This patch fixes the bug by moving the increment of sch-&gt;q.qlen and
sch-&gt;qstats.backlog before the call to the child qdisc's peek() operation.
This ensures that queue length and backlog are always accurate when packet
drops or dequeues are triggered during the peek.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-38000"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-5fqh-wrrw-3qc9</id>
    <title>GHSA-5fqh-wrrw-3qc9</title>
    <updated>2026-10-04T03:18:29.831782+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>sch_hfsc: Fix qlen accounting bug when using peek in hfsc_enqueue()</p>
<p>When enqueuing the first packet to an HFSC class, hfsc_enqueue() calls the
child qdisc's peek() operation before incrementing sch-&gt;q.qlen and
sch-&gt;qstats.backlog. If the child qdisc uses qdisc_peek_dequeued(), this may
trigger an immediate dequeue and potential packet drop. In such cases,
qdisc_tree_reduce_backlog() is called, but the HFSC qdisc's qlen and backlog
have not yet been updated, leading to inconsistent queue accounting. This
can leave an empty HFSC class in the active list, causing further
consequences like use-after-free.</p>
<p>This patch fixes the bug by moving the increment of sch-&gt;q.qlen and
sch-&gt;qstats.backlog before the call to the child qdisc's peek() operation.
This ensures that queue length and backlog are always accurate when packet
drops or dequeues are triggered during the peek.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-5fqh-wrrw-3qc9"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2025-38000</id>
    <title>msrc_CVE-2025-38000 — sch_hfsc: Fix qlen accounting bug when using peek in hfsc_enqueue()</title>
    <updated>2026-10-04T03:18:29.831806+00:00</updated>
    <content>msrc_CVE-2025-38000</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2025-38000"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2025-1871</id>
    <title>OESA-2025-1871 — kernel security update</title>
    <updated>2026-10-04T03:18:29.831824+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP4: kernel</p>
<p>The Linux Kernel, the operating system core itself.

Security Fix(es):</p>
<p>Linux kernel is the kernel used by Linux, the open source operating system of the Linux Foundation in the United States.
 There is a security vulnerability in Linux kernel, which originates from a qlen count error in sch_hfsc, which may cause inconsistent queue statistics.(CVE-2025-38000)</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>media: cxusb: no longer judge rbuf when the write fails</p>
<p>syzbot reported a uninit-value in cxusb_i2c_xfer. [1]</p>
<p>Only when the write operation of usb_bulk_msg() in dvb_usb_generic_rw()
succeeds and rlen is greater than 0, the read operation of usb_bulk_msg()
will be executed to read rlen bytes of data from the dvb device into the
rbuf.</p>
<p>In this case, although rlen is 1, the write operation failed which resulted
in the dvb read operation not being executed, and ultimately variable i was
not initialized.</p>
<p>[1]
BUG: KMSAN: uninit-value in cxusb_gpio_tuner drivers/media/usb/dvb-usb/cxusb.c:124 [inline]
BUG: KMSAN: uninit-value in cxusb_i2c_xfer+0x153a/0x1a60 drivers/media/usb/dvb-usb/cxusb.c:196
 cxusb_gpio_tuner drivers/media/usb/dvb-usb/cxusb.c:124 [inline]
 cxusb_i2c_xfer+0x153a/0x1a60 drivers/media/usb/dvb-usb/cxusb.c:196
 __i2c_transfer+0xe25/0x3150 drivers/i2c/i2c-core-base.c:-1
 i2c_transfer+0x317/0x4a0 drivers/i2c/i2c-core-base.c:2315
 i2c_transfer_buffer_flags+0x125/0x1e0 drivers/i2c/i2c-core-base.c:2343
 i2c_master_send include/linux/i2c.h:109 […</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2025-1871"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2025:12209</id>
    <title>RHSA-2025:12209 — Red Hat Security Advisory: kernel security update</title>
    <updated>2026-10-04T03:18:29.831876+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>kernel: media: uvcvideo: Fix double free in error path kernel: ipv6: mcast: extend RCU protection in igmp6_send() kernel: wifi: iwlwifi: limit printed string from FW file kernel: ext4: avoid journaling sb update on error if journal is destroying kernel: net_sched: hfsc: Fix a UAF vulnerability in class with netem as child qdisc kernel: mm/huge_memory: fix dereferencing invalid pmd migration entry kernel: sch_hfsc: Fix qlen accounting bug when using peek in hfsc_enqueue() kernel: net_sched: hfsc: Address reentrant enqueue adding class to eltree twice kernel: net/tipc: fix slab-use-after-free Read in tipc_aead_encrypt_done</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2025:12209"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2025:14748</id>
    <title>RHSA-2025:14748 — Red Hat Security Advisory: kernel security update</title>
    <updated>2026-10-04T03:18:29.831910+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>kernel: misc/vmw_vmci: fix an infoleak in vmci_host_do_receive_datagram() kernel: ext4: avoid resizing to a partial cluster size kernel: drivers:md:fix a potential use-after-free bug kernel: media: uvcvideo: Fix double free in error path kernel: HID: intel-ish-hid: Fix use-after-free issue in ishtp_hid_remove() kernel: ext4: fix off-by-one error in do_split kernel: sch_hfsc: Fix qlen accounting bug when using peek in hfsc_enqueue() kernel: sch_hfsc: make hfsc_qlen_notify() idempotent kernel: net/sched: Always pass notifications when child class becomes empty</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2025:14748"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2025:02249-1</id>
    <title>SUSE-SU-2025:02249-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-04T03:18:29.831939+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2025:02249-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-38000</id>
    <title>UBUNTU-CVE-2025-38000</title>
    <updated>2026-10-04T03:18:29.832010+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe, Ubuntu:Pro:16.04:LTS: linux-oracle, Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:Pro:18.04:LTS: linux, Ubuntu:Pro:18.04:LTS: linux-aws, Ubuntu:18.04:LTS: linux-aws-5.0 and 197 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: sch_hfsc: Fix qlen accounting bug when using peek in hfsc_enqueue() When enqueuing the first packet to an HFSC class, hfsc_enqueue() calls the child qdisc's peek() operation before incrementing sch-&gt;q.qlen and sch-&gt;qstats.backlog. If the child qdisc uses qdisc_peek_dequeued(), this may trigger an immediate dequeue and potential packet drop. In such cases, qdisc_tree_reduce_backlog() is called, but the HFSC qdisc's qlen and backlog have not yet been updated, leading to inconsistent queue accounting. This can leave an empty HFSC class in the active list, causing further consequences like use-after-free. This patch fixes the bug by moving the increment of sch-&gt;q.qlen and sch-&gt;qstats.backlog before the call to the child qdisc's peek() operation. This ensures that queue length and backlog are always accurate when packet drops or dequeues are triggered during the peek.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-38000"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1270</id>
    <title>WID-SEC-W-2025-1270 — Linux Kernel: Mehrere Schwachstellen ermöglichen Denial of Service</title>
    <updated>2026-10-04T03:18:29.832250+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein lokaler Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1270"/>
  </entry>
</feed>
