<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T05:32:25.669429+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-10763</id>
    <title>bdu:2025-10763</title>
    <updated>2026-10-03T05:32:26.248320+00:00</updated>
    <content>bdu:2025-10763</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-10763"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2025-38197</id>
    <title>BELL-CVE-2025-38197</title>
    <updated>2026-10-03T05:32:26.248396+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2025-38197"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0698</id>
    <title>certfr-2025-avi-0698 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de Debian. Certaines d'entre elles permettent à un…</title>
    <updated>2026-10-03T05:32:26.248433+00:00</updated>
    <content>certfr-2025-avi-0698</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-0698"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-346961</id>
    <title>EUVD-2026-346961</title>
    <updated>2026-10-03T05:32:26.248453+00:00</updated>
    <content>EUVD-2026-346961</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-346961"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-38197</id>
    <title>fkie_cve-2025-38197</title>
    <updated>2026-10-03T05:32:26.248465+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>platform/x86: dell_rbu: Fix list usage</p>
<p>Pass the correct list head to list_for_each_entry*() when looping through
the packet list.</p>
<p>Without this patch, reading the packet data via sysfs will show the data
incorrectly (because it starts at the wrong packet), and clearing the
packet list will result in a NULL pointer dereference.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-38197"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-2v3f-mxwm-3xrj</id>
    <title>GHSA-2v3f-mxwm-3xrj</title>
    <updated>2026-10-03T05:32:26.248496+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>platform/x86: dell_rbu: Fix list usage</p>
<p>Pass the correct list head to list_for_each_entry*() when looping through
the packet list.</p>
<p>Without this patch, reading the packet data via sysfs will show the data
incorrectly (because it starts at the wrong packet), and clearing the
packet list will result in a NULL pointer dereference.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-2v3f-mxwm-3xrj"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2025-38197</id>
    <title>msrc_CVE-2025-38197 — platform/x86: dell_rbu: Fix list usage</title>
    <updated>2026-10-03T05:32:26.248514+00:00</updated>
    <content>msrc_CVE-2025-38197</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2025-38197"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2025-1869</id>
    <title>OESA-2025-1869 — kernel security update</title>
    <updated>2026-10-03T05:32:26.248531+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS-SP1: kernel</p>
<p>The Linux Kernel, the operating system core itself.

Security Fix(es):</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>pfifo_tail_enqueue: Drop new packet when sch-&amp;gt;limit == 0</p>
<p>Expected behaviour:
In case we reach scheduler&amp;apos;s limit, pfifo_tail_enqueue() will drop a
packet in scheduler&amp;apos;s queue and decrease scheduler&amp;apos;s qlen by one.
Then, pfifo_tail_enqueue() enqueue new packet and increase
scheduler&amp;apos;s qlen by one. Finally, pfifo_tail_enqueue() return
`NET_XMIT_CN` status code.</p>
<p>Weird behaviour:
In case we set `sch-&amp;gt;limit == 0` and trigger pfifo_tail_enqueue() on a
scheduler that has no packet, the &amp;apos;drop a packet&amp;apos; step will do nothing.
This means the scheduler&amp;apos;s qlen still has value equal 0.
Then, we continue to enqueue new packet and increase scheduler&amp;apos;s qlen by
one. In summary, we can leverage pfifo_tail_enqueue() to increase qlen by
one and return `NET_XMIT_CN` status code.</p>
<p>The problem is:
Let&amp;apos;s say we have two qdiscs: Qdisc_A and Qdisc_B.
 - Qdisc_A&amp;apos;s type must have &amp;apos;-&amp;gt;graft()&amp;apos; function to create parent/child relationship.
   Let&amp;apos;s say Qdisc_A&amp;apos;s type is `hfsc`. Enqueue packet to this qdisc will trigger `hfsc_enqueue`.
 - Qdisc_B&amp;apos;s type is pfifo_head_drop. Enqueue packet to this qdisc will trigger `pfifo_tail_enqueue`.
 - Qdisc_B is configured to have `sch-&amp;gt;limit == 0`.
 - Qdisc_A is configured to route the enqueued&amp;apos;s packet to Qdisc_B.</p>
<p>Enqueue packet through…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2025-1869"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2025:20081-1</id>
    <title>openSUSE-SU-2025:20081-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-03T05:32:26.248626+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2025:20081-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2025:02853-1</id>
    <title>SUSE-SU-2025:02853-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-03T05:32:26.248958+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2025:02853-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-38197</id>
    <title>UBUNTU-CVE-2025-38197</title>
    <updated>2026-10-03T05:32:26.249105+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 160 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: platform/x86: dell_rbu: Fix list usage Pass the correct list head to list_for_each_entry*() when looping through the packet list. Without this patch, reading the packet data via sysfs will show the data incorrectly (because it starts at the wrong packet), and clearing the packet list will result in a NULL pointer dereference.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-38197"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1465</id>
    <title>WID-SEC-W-2025-1465 — Linux Kernel: Mehrere Schwachstellen ermöglichen Denial of Service</title>
    <updated>2026-10-03T05:32:26.249304+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen oder nicht näher spezifizierte Auswirkungen zu erzielen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1465"/>
  </entry>
</feed>
