<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T16:55:49.362541+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-09176</id>
    <title>bdu:2025-09176</title>
    <updated>2026-10-02T16:55:50.081624+00:00</updated>
    <content>bdu:2025-09176</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-09176"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2025-38474</id>
    <title>BELL-CVE-2025-38474</title>
    <updated>2026-10-02T16:55:50.081693+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2025-38474"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0698</id>
    <title>certfr-2025-avi-0698 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de Debian. Certaines d'entre elles permettent à un…</title>
    <updated>2026-10-02T16:55:50.081730+00:00</updated>
    <content>certfr-2025-avi-0698</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-0698"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-314619</id>
    <title>EUVD-2026-314619</title>
    <updated>2026-10-02T16:55:50.081749+00:00</updated>
    <content>EUVD-2026-314619</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-314619"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-38474</id>
    <title>fkie_cve-2025-38474</title>
    <updated>2026-10-02T16:55:50.081760+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>usb: net: sierra: check for no status endpoint</p>
<p>The driver checks for having three endpoints and
having bulk in and out endpoints, but not that
the third endpoint is interrupt input.
Rectify the omission.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-38474"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-6787-fm33-h95m</id>
    <title>GHSA-6787-fm33-h95m</title>
    <updated>2026-10-02T16:55:50.081787+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>usb: net: sierra: check for no status endpoint</p>
<p>The driver checks for having three endpoints and
having bulk in and out endpoints, but not that
the third endpoint is interrupt input.
Rectify the omission.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-6787-fm33-h95m"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2025-38474</id>
    <title>msrc_CVE-2025-38474 — usb: net: sierra: check for no status endpoint</title>
    <updated>2026-10-02T16:55:50.081803+00:00</updated>
    <content>msrc_CVE-2025-38474</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2025-38474"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2025-1959</id>
    <title>OESA-2025-1959 — kernel security update</title>
    <updated>2026-10-02T16:55:50.081819+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS: kernel</p>
<p>The Linux Kernel, the operating system core itself.

Security Fix(es):</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>xfrm: state: fix out-of-bounds read during lookup</p>
<p>lookup and resize can run in parallel.</p>
<p>The xfrm_state_hash_generation seqlock ensures a retry, but the hash
functions can observe a hmask value that is too large for the new hlist
array.</p>
<p>rehash does:
  rcu_assign_pointer(net-&amp;gt;xfrm.state_bydst, ndst) [..]
  net-&amp;gt;xfrm.state_hmask = nhashmask;</p>
<p>While state lookup does:
  h = xfrm_dst_hash(net, daddr, saddr, tmpl-&amp;gt;reqid, encap_family);
  hlist_for_each_entry_rcu(x, net-&amp;gt;xfrm.state_bydst + h, bydst) {</p>
<p>This is only safe in case the update to state_bydst is larger than
net-&amp;gt;xfrm.xfrm_state_hmask (or if the lookup function gets
serialized via state spinlock again).</p>
<p>Fix this by prefetching state_hmask and the associated pointers.
The xfrm_state_hash_generation seqlock retry will ensure that the pointer
and the hmask will be consistent.</p>
<p>The existing helpers, like xfrm_dst_hash(), are now unsafe for RCU side,
add lockdep assertions to document that they are only safe for insert
side.</p>
<p>xfrm_state_lookup_byaddr() uses the spinlock rather than RCU.
AFAICS this is an oversight from back when state lookup was converted to
RCU, this lock should be replaced with RCU in a future patch.(CVE-2024-57982)</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>eth: bnxt: always recalculate features after XDP clearing, fix n…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2025-1959"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2025:20081-1</id>
    <title>openSUSE-SU-2025:20081-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-02T16:55:50.082080+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2025:20081-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2025:02853-1</id>
    <title>SUSE-SU-2025:02853-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-02T16:55:50.082480+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2025:02853-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-38474</id>
    <title>UBUNTU-CVE-2025-38474</title>
    <updated>2026-10-02T16:55:50.082633+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: linux, Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe and 214 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: usb: net: sierra: check for no status endpoint The driver checks for having three endpoints and having bulk in and out endpoints, but not that the third endpoint is interrupt input. Rectify the omission.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-38474"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1665</id>
    <title>WID-SEC-W-2025-1665 — Linux Kernel: Mehrere Schwachstellen</title>
    <updated>2026-10-02T16:55:50.082913+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen oder andere nicht spezifizierte Angriffe durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1665"/>
  </entry>
</feed>
