<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T23:39:23.253755+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:64808</id>
    <title>ALSA-2026:64808 — Important: kernel security update</title>
    <updated>2026-10-03T23:39:23.693659+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:9: kernel, AlmaLinux:9: kernel-64k, AlmaLinux:9: kernel-64k-core, AlmaLinux:9: kernel-64k-debug, AlmaLinux:9: kernel-64k-debug-core, AlmaLinux:9: kernel-64k-debug-devel, AlmaLinux:9: kernel-64k-debug-devel-matched, AlmaLinux:9: kernel-64k-debug-modules, AlmaLinux:9: kernel-64k-debug-modules-core, AlmaLinux:9: kernel-64k-debug-modules-extra and 64 more</p>
<p>The kernel packages contain the Linux kernel, the core of any Linux operating system.</p>
<p>Security Fix(es):</p>
<p>* kernel: can: bcm: add locking for bcm_op runtime updates (CVE-2025-38004)
  * kernel: io_uring/poll: fix signed comparison in io_poll_get_ownership() (CVE-2026-52933)
  * kernel: netfilter: nat: use kfree_rcu to release ops (CVE-2026-53000)
  * kernel: smb: client: protect tc_count increment in smb2_find_smb_sess_tcon_unlocked() (CVE-2026-64136)
  * kernel: nvmet: fix pre-auth out-of-bounds heap read in Discovery Get Log Page (CVE-2026-64320)
  * kernel: nvmet-auth: validate reply message payload bounds against transfer length (CVE-2026-64319)
  * kernel: KVM: arm64: Bound used_lrs when flushing the pKVM hyp vCPU (CVE-2026-64287)
  * kernel: smb: client: fix change notify replay double-free (CVE-2026-64384)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:64808"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-11862</id>
    <title>bdu:2025-11862</title>
    <updated>2026-10-03T23:39:23.693849+00:00</updated>
    <content>bdu:2025-11862</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-11862"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2025-38004</id>
    <title>BELL-CVE-2025-38004</title>
    <updated>2026-10-03T23:39:23.693869+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2025-38004"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0587</id>
    <title>certfr-2025-avi-0587 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de SUSE. Certaines d'entre elles permettent à un at…</title>
    <updated>2026-10-03T23:39:23.693892+00:00</updated>
    <content>certfr-2025-avi-0587</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-0587"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-346887</id>
    <title>EUVD-2026-346887</title>
    <updated>2026-10-03T23:39:23.693910+00:00</updated>
    <content>EUVD-2026-346887</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-346887"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-38004</id>
    <title>fkie_cve-2025-38004</title>
    <updated>2026-10-03T23:39:23.693922+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>can: bcm: add locking for bcm_op runtime updates</p>
<p>The CAN broadcast manager (CAN BCM) can send a sequence of CAN frames via
hrtimer. The content and also the length of the sequence can be changed
resp reduced at runtime where the 'currframe' counter is then set to zero.</p>
<p>Although this appeared to be a safe operation the updates of 'currframe'
can be triggered from user space and hrtimer context in bcm_can_tx().
Anderson Nascimento created a proof of concept that triggered a KASAN
slab-out-of-bounds read access which can be prevented with a spin_lock_bh.</p>
<p>At the rework of bcm_can_tx() the 'count' variable has been moved into
the protected section as this variable can be modified from both contexts
too.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-38004"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-29qg-42xm-553c</id>
    <title>GHSA-29qg-42xm-553c</title>
    <updated>2026-10-03T23:39:23.693955+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>can: bcm: add locking for bcm_op runtime updates</p>
<p>The CAN broadcast manager (CAN BCM) can send a sequence of CAN frames via
hrtimer. The content and also the length of the sequence can be changed
resp reduced at runtime where the 'currframe' counter is then set to zero.</p>
<p>Although this appeared to be a safe operation the updates of 'currframe'
can be triggered from user space and hrtimer context in bcm_can_tx().
Anderson Nascimento created a proof of concept that triggered a KASAN
slab-out-of-bounds read access which can be prevented with a spin_lock_bh.</p>
<p>At the rework of bcm_can_tx() the 'count' variable has been moved into
the protected section as this variable can be modified from both contexts
too.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-29qg-42xm-553c"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2025-38004</id>
    <title>msrc_CVE-2025-38004 — can: bcm: add locking for bcm_op runtime updates</title>
    <updated>2026-10-03T23:39:23.693978+00:00</updated>
    <content>msrc_CVE-2025-38004</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2025-38004"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2025-2120</id>
    <title>OESA-2025-2120 — kernel security update</title>
    <updated>2026-10-03T23:39:23.693996+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS: kernel</p>
<p>The Linux Kernel, the operating system core itself.

Security Fix(es):</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>gtp: Destroy device along with udp socket&amp;apos;s netns dismantle.</p>
<p>gtp_newlink() links the device to a list in dev_net(dev) instead of
src_net, where a udp tunnel socket is created.</p>
<p>Even when src_net is removed, the device stays alive on dev_net(dev).
Then, removing src_net triggers the splat below. [0]</p>
<p>In this example, gtp0 is created in ns2, and the udp socket is created
in ns1.</p>
<p>ip netns add ns1
  ip netns add ns2
  ip -n ns1 link add netns ns2 name gtp0 type gtp role sgsn
  ip netns del ns1</p>
<p>Let&amp;apos;s link the device to the socket&amp;apos;s netns instead.</p>
<p>Now, gtp_net_exit_batch_rtnl() needs another netdev iteration to remove
all gtp devices in the netns.</p>
<p>[0]:
ref_tracker: net notrefcnt@000000003d6e7d05 has 1/2 users at
     sk_alloc (./include/net/net_namespace.h:345 net/core/sock.c:2236)
     inet_create (net/ipv4/af_inet.c:326 net/ipv4/af_inet.c:252)
     __sock_create (net/socket.c:1558)
     udp_sock_create4 (net/ipv4/udp_tunnel_core.c:18)
     gtp_create_sock (./include/net/udp_tunnel.h:59 drivers/net/gtp.c:1423)
     gtp_create_sockets (drivers/net/gtp.c:1447)
     gtp_newlink (drivers/net/gtp.c:1507)
     rtnl_newlink (net/core/rtnetlink.c:3786 net/core/rtnetlink.c:3897 net/core/rtnetlink.c:4012)
     rtnetlink_rcv_msg (net/core/rtnetlink.c:6922)
     netlink_rcv_skb (net/netlink/af_netlink.c:2542)
     netlink_unicast…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2025-2120"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:64775</id>
    <title>RHSA-2026:64775 — Red Hat Security Advisory: kernel security, bug fix, and enhancement update</title>
    <updated>2026-10-03T23:39:23.694473+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>kernel: can: bcm: add locking for bcm_op runtime updates kernel: ipv6: add NULL checks for idev in SRv6 paths kernel: udp: Fix wildcard bind conflict check when using hash2 kernel: ipv6: prevent possible UaF in addrconf_permanent_addr() kernel: tcp: call sk_data_ready() after listener migration kernel: inet: RAW sockets using IPPROTO_RAW MUST drop incoming ICMP kernel: flow_dissector: do not dissect PPPoE PFC frames kernel: io_uring/poll: fix signed comparison in io_poll_get_ownership() kernel: ppp: require CAP_NET_ADMIN in target netns for unattached ioctls kernel: net: guard timestamp cmsgs to real error queue skbs kernel: ipv6: sit: reload inner IPv6 header after GSO offloads kernel: net: add pskb_may_pull() to skb_gro_receive_list() kernel: ipv6: anycast: insert aca into global hash under idev-&gt;lock kernel: ipv6: mcast: Fix use-after-free when processing MLD queries kernel: KVM: arm64: Take the SRCU lock for page table walks in fault injection and AT emulation kernel: vxlan: do not reuse cached ip_hdr() value after skb_tunnel_check_pmtu() kernel: ipv4: free net-&gt;ipv4.sysctl_local_reserved_ports after unregister_net_sysctl_table() kernel: fuse: clear intr_entry in fuse_resend and fuse_remove_pending_req kernel: KVM: arm64: Bound used_lrs when flushing the pKVM hyp vCPU kernel: nvmet-auth: validate reply message payload bounds against transfer length kernel: rhashtable: clear stale iter-&gt;p on table restart kernel: smb: client: fix double-free in SMB2_close() replay</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:64775"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:64775</id>
    <title>RLSA-2026:64775 — Important: kernel security, bug fix, and enhancement update</title>
    <updated>2026-10-03T23:39:23.694531+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:10: kernel</p>
<p>The kernel packages contain the Linux kernel, the core of any Linux operating system.</p>
<p>Security Fix(es):</p>
<p>* kernel: can: bcm: add locking for bcm_op runtime updates (CVE-2025-38004)</p>
<p>* kernel: ipv6: add NULL checks for idev in SRv6 paths (CVE-2026-23442)</p>
<p>* kernel: udp: Fix wildcard bind conflict check when using hash2 (CVE-2026-31503)</p>
<p>* kernel: ipv6: prevent possible UaF in addrconf_permanent_addr() (CVE-2026-43339)</p>
<p>* kernel: tcp: call sk_data_ready() after listener migration (CVE-2026-46015)</p>
<p>* kernel: inet: RAW sockets using IPPROTO_RAW MUST drop incoming ICMP (CVE-2026-46266)</p>
<p>* kernel: flow_dissector: do not dissect PPPoE PFC frames (CVE-2026-46306)</p>
<p>* kernel: io_uring/poll: fix signed comparison in io_poll_get_ownership() (CVE-2026-52933)</p>
<p>* kernel: ppp: require CAP_NET_ADMIN in target netns for unattached ioctls (CVE-2026-53075)</p>
<p>* kernel: KVM: arm64: Take the SRCU lock for page table walks in fault injection and AT emulation (CVE-2026-53277)</p>
<p>* kernel: ipv6: sit: reload inner IPv6 header after GSO offloads (CVE-2026-53228)</p>
<p>* kernel: net: add pskb_may_pull() to skb_gro_receive_list() (CVE-2026-53235)</p>
<p>* kernel: net: guard timestamp cmsgs to real error queue skbs (CVE-2026-53223)</p>
<p>* kernel: ipv6: mcast: Fix use-after-free when processing MLD queries (CVE-2026-53275)</p>
<p>* kernel: ipv6: anycast: insert aca into global hash under idev-&gt;lock (CVE-2026-53259)</p>
<p>* kernel: ipv4: free net-&gt;ipv4.sysctl_local_reserved_ports after unregister_net_sysctl_table() (CVE-2026-64002)</p>
<p>*…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:64775"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2025:02249-1</id>
    <title>SUSE-SU-2025:02249-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-03T23:39:23.694578+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2025:02249-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-38004</id>
    <title>UBUNTU-CVE-2025-38004</title>
    <updated>2026-10-03T23:39:23.694671+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: linux, Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe and 212 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: can: bcm: add locking for bcm_op runtime updates The CAN broadcast manager (CAN BCM) can send a sequence of CAN frames via hrtimer. The content and also the length of the sequence can be changed resp reduced at runtime where the 'currframe' counter is then set to zero. Although this appeared to be a safe operation the updates of 'currframe' can be triggered from user space and hrtimer context in bcm_can_tx(). Anderson Nascimento created a proof of concept that triggered a KASAN slab-out-of-bounds read access which can be prevented with a spin_lock_bh. At the rework of bcm_can_tx() the 'count' variable has been moved into the protected section as this variable can be modified from both contexts too.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-38004"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1270</id>
    <title>WID-SEC-W-2025-1270 — Linux Kernel: Mehrere Schwachstellen ermöglichen Denial of Service</title>
    <updated>2026-10-03T23:39:23.694964+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein lokaler Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1270"/>
  </entry>
</feed>
