<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T16:55:55.140767+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-09657</id>
    <title>bdu:2025-09657</title>
    <updated>2026-10-02T16:55:55.698924+00:00</updated>
    <content>bdu:2025-09657</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-09657"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2025-38348</id>
    <title>BELL-CVE-2025-38348</title>
    <updated>2026-10-02T16:55:55.699003+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2025-38348"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0698</id>
    <title>certfr-2025-avi-0698 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de Debian. Certaines d'entre elles permettent à un…</title>
    <updated>2026-10-02T16:55:55.699042+00:00</updated>
    <content>certfr-2025-avi-0698</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-0698"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-314555</id>
    <title>EUVD-2026-314555</title>
    <updated>2026-10-02T16:55:55.699062+00:00</updated>
    <content>EUVD-2026-314555</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-314555"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-38348</id>
    <title>fkie_cve-2025-38348</title>
    <updated>2026-10-02T16:55:55.699075+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>wifi: p54: prevent buffer-overflow in p54_rx_eeprom_readback()</p>
<p>Robert Morris reported:</p>
<p>|If a malicious USB device pretends to be an Intersil p54 wifi
|interface and generates an eeprom_readback message with a large
|eeprom-&gt;v1.len, p54_rx_eeprom_readback() will copy data from the
|message beyond the end of priv-&gt;eeprom.
|
|static void p54_rx_eeprom_readback(struct p54_common *priv,
|                                   struct sk_buff *skb)
|{
|        struct p54_hdr *hdr = (struct p54_hdr *) skb-&gt;data;
|        struct p54_eeprom_lm86 *eeprom = (struct p54_eeprom_lm86 *) hdr-&gt;data;
|
|        if (priv-&gt;fw_var &gt;= 0x509) {
|                memcpy(priv-&gt;eeprom, eeprom-&gt;v2.data,
|                       le16_to_cpu(eeprom-&gt;v2.len));
|        } else {
|                memcpy(priv-&gt;eeprom, eeprom-&gt;v1.data,
|                       le16_to_cpu(eeprom-&gt;v1.len));
|        }
| [...]</p>
<p>The eeprom-&gt;v{1,2}.len is set by the driver in p54_download_eeprom().
The device is supposed to provide the same length back to the driver.
But yes, it's possible (like shown in the report) to alter the value
to something that causes a crash/panic due to overrun.</p>
<p>This patch addresses the issue by adding the size to the common device
context, so p54_rx_eeprom_readback no longer relies on possibly tampered
values... That said, it also checks if the "firmware" altered the value
and no longer copies them.</p>
<p>The one, small saving grace is: Befor…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-38348"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-7vp7-2c88-3j3x</id>
    <title>GHSA-7vp7-2c88-3j3x</title>
    <updated>2026-10-02T16:55:55.699124+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>wifi: p54: prevent buffer-overflow in p54_rx_eeprom_readback()</p>
<p>Robert Morris reported:</p>
<p>|If a malicious USB device pretends to be an Intersil p54 wifi
|interface and generates an eeprom_readback message with a large
|eeprom-&gt;v1.len, p54_rx_eeprom_readback() will copy data from the
|message beyond the end of priv-&gt;eeprom.
|
|static void p54_rx_eeprom_readback(struct p54_common *priv,
|                                   struct sk_buff *skb)
|{
|        struct p54_hdr *hdr = (struct p54_hdr *) skb-&gt;data;
|        struct p54_eeprom_lm86 *eeprom = (struct p54_eeprom_lm86 *) hdr-&gt;data;
|
|        if (priv-&gt;fw_var &gt;= 0x509) {
|                memcpy(priv-&gt;eeprom, eeprom-&gt;v2.data,
|                       le16_to_cpu(eeprom-&gt;v2.len));
|        } else {
|                memcpy(priv-&gt;eeprom, eeprom-&gt;v1.data,
|                       le16_to_cpu(eeprom-&gt;v1.len));
|        }
| [...]</p>
<p>The eeprom-&gt;v{1,2}.len is set by the driver in p54_download_eeprom().
The device is supposed to provide the same length back to the driver.
But yes, it's possible (like shown in the report) to alter the value
to something that causes a crash/panic due to overrun.</p>
<p>This patch addresses the issue by adding the size to the common device
context, so p54_rx_eeprom_readback no longer relies on possibly tampered
values... That said, it also checks if the "firmware" altered the value
and no longer copies them.</p>
<p>The one, small saving grace is: Befor…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-7vp7-2c88-3j3x"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2025-38348</id>
    <title>msrc_CVE-2025-38348 — wifi: p54: prevent buffer-overflow in p54_rx_eeprom_readback()</title>
    <updated>2026-10-02T16:55:55.699158+00:00</updated>
    <content>msrc_CVE-2025-38348</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2025-38348"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2025-2695</id>
    <title>OESA-2025-2695 — kernel security update</title>
    <updated>2026-10-02T16:55:55.699177+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS-SP1: kernel</p>
<p>The Linux Kernel, the operating system core itself.

Security Fix(es):</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>misc: pci_endpoint_test: Avoid issue of interrupts remaining after request_irq error</p>
<p>After devm_request_irq() fails with error in pci_endpoint_test_request_irq(),
the pci_endpoint_test_free_irq_vectors() is called assuming that all IRQs
have been released.</p>
<p>However, some requested IRQs remain unreleased, so there are still
/proc/irq/* entries remaining, and this results in WARN() with the
following message:</p>
<p>remove_proc_entry: removing non-empty directory &amp;apos;irq/30&amp;apos;, leaking at least &amp;apos;pci-endpoint-test.0&amp;apos;
  WARNING: CPU: 0 PID: 202 at fs/proc/generic.c:719 remove_proc_entry +0x190/0x19c</p>
<p>To solve this issue, set the number of remaining IRQs to test-&amp;gt;num_irqs,
and release IRQs in advance by calling pci_endpoint_test_release_irq().</p>
<p>[kwilczynski: commit log](CVE-2025-23140)</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>drm/amdgpu: csa unmap use uninterruptible lock</p>
<p>After process exit to unmap csa and free GPU vm, if signal is accepted
and then waiting to take vm lock is interrupted and return, it causes
memory leaking and below warning backtrace.</p>
<p>Change to use uninterruptible wait lock fix the issue.</p>
<p>WARNING: CPU: 69 PID: 167800 at amd/amdgpu/amdgpu_kms.c:1525
 amdgpu_driver_postclose_kms+0x294/0x2a0 [amdgpu]
 Call Trace:
  &amp;lt;TASK&amp;gt;
  drm_file_free.part.0+0x1da/0x230 [drm]
  drm_clo…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2025-2695"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2025:20081-1</id>
    <title>openSUSE-SU-2025:20081-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-02T16:55:55.699465+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2025:20081-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2025:02853-1</id>
    <title>SUSE-SU-2025:02853-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-02T16:55:55.699808+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2025:02853-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-38348</id>
    <title>UBUNTU-CVE-2025-38348</title>
    <updated>2026-10-02T16:55:55.699985+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: linux, Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe and 213 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: wifi: p54: prevent buffer-overflow in p54_rx_eeprom_readback() Robert Morris reported: |If a malicious USB device pretends to be an Intersil p54 wifi |interface and generates an eeprom_readback message with a large |eeprom-&gt;v1.len, p54_rx_eeprom_readback() will copy data from the |message beyond the end of priv-&gt;eeprom. | |static void p54_rx_eeprom_readback(struct p54_common *priv, |                                   struct sk_buff *skb) |{ |        struct p54_hdr *hdr = (struct p54_hdr *) skb-&gt;data; |        struct p54_eeprom_lm86 *eeprom = (struct p54_eeprom_lm86 *) hdr-&gt;data; | |        if (priv-&gt;fw_var &gt;= 0x509) { |                memcpy(priv-&gt;eeprom, eeprom-&gt;v2.data, |                       le16_to_cpu(eeprom-&gt;v2.len)); |        } else { |                memcpy(priv-&gt;eeprom, eeprom-&gt;v1.data, |                       le16_to_cpu(eeprom-&gt;v1.len)); |        } | [...] The eeprom-&gt;v{1,2}.len is set by the driver in p54_download_eeprom(). The device is supposed to provide the same length back to the driver. But yes, it's possible (like shown in the report) to alter the value to something that causes a crash/panic due to overrun. This patch addresses the issue by adding the size to the common device context, so p54_rx_eeprom_readback no longer relies on possibly tampered values... That said, it also checks if the "firmware" altered the value and no longer copies them. The one, small saving grace is: Before the…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-38348"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1522</id>
    <title>WID-SEC-W-2025-1522 — Linux Kernel: Mehrere Schwachstellen ermöglichen Denial of Service</title>
    <updated>2026-10-02T16:55:55.700255+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen oder nicht spezifizierte Auswirkungen zu verursachen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1522"/>
  </entry>
</feed>
