<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T00:55:13.482581+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-14968</id>
    <title>bdu:2025-14968</title>
    <updated>2026-10-04T00:55:13.706001+00:00</updated>
    <content>bdu:2025-14968</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-14968"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2025-38520</id>
    <title>BELL-CVE-2025-38520</title>
    <updated>2026-10-04T00:55:13.706078+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2025-38520"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0787</id>
    <title>certfr-2025-avi-0787 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de SUSE. Certaines d'entre elles permettent à un at…</title>
    <updated>2026-10-04T00:55:13.706120+00:00</updated>
    <content>certfr-2025-avi-0787</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-0787"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-320855</id>
    <title>EUVD-2026-320855</title>
    <updated>2026-10-04T00:55:13.706139+00:00</updated>
    <content>EUVD-2026-320855</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-320855"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-38520</id>
    <title>fkie_cve-2025-38520</title>
    <updated>2026-10-04T00:55:13.706151+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>drm/amdkfd: Don't call mmput from MMU notifier callback</p>
<p>If the process is exiting, the mmput inside mmu notifier callback from
compactd or fork or numa balancing could release the last reference
of mm struct to call exit_mmap and free_pgtable, this triggers deadlock
with below backtrace.</p>
<p>The deadlock will leak kfd process as mmu notifier release is not called
and cause VRAM leaking.</p>
<p>The fix is to take mm reference mmget_non_zero when adding prange to the
deferred list to pair with mmput in deferred list work.</p>
<p>If prange split and add into pchild list, the pchild work_item.mm is not
used, so remove the mm parameter from svm_range_unmap_split and
svm_range_add_child.</p>
<p>The backtrace of hung task:</p>
<p>INFO: task python:348105 blocked for more than 64512 seconds.
 Call Trace:
  __schedule+0x1c3/0x550
  schedule+0x46/0xb0
  rwsem_down_write_slowpath+0x24b/0x4c0
  unlink_anon_vmas+0xb1/0x1c0
  free_pgtables+0xa9/0x130
  exit_mmap+0xbc/0x1a0
  mmput+0x5a/0x140
  svm_range_cpu_invalidate_pagetables+0x2b/0x40 [amdgpu]
  mn_itree_invalidate+0x72/0xc0
  __mmu_notifier_invalidate_range_start+0x48/0x60
  try_to_unmap_one+0x10fa/0x1400
  rmap_walk_anon+0x196/0x460
  try_to_unmap+0xbb/0x210
  migrate_page_unmap+0x54d/0x7e0
  migrate_pages_batch+0x1c3/0xae0
  migrate_pages_sync+0x98/0x240
  migrate_pages+0x25c/0x520
  compact_zone+0x29d/0x590
  compact_zone_order+0xb6/0xf0
  try_to_compact_pages+0xbe/0x220
  __alloc_pages_…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-38520"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-8w9j-8c65-frh3</id>
    <title>GHSA-8w9j-8c65-frh3</title>
    <updated>2026-10-04T00:55:13.706199+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>drm/amdkfd: Don't call mmput from MMU notifier callback</p>
<p>If the process is exiting, the mmput inside mmu notifier callback from
compactd or fork or numa balancing could release the last reference
of mm struct to call exit_mmap and free_pgtable, this triggers deadlock
with below backtrace.</p>
<p>The deadlock will leak kfd process as mmu notifier release is not called
and cause VRAM leaking.</p>
<p>The fix is to take mm reference mmget_non_zero when adding prange to the
deferred list to pair with mmput in deferred list work.</p>
<p>If prange split and add into pchild list, the pchild work_item.mm is not
used, so remove the mm parameter from svm_range_unmap_split and
svm_range_add_child.</p>
<p>The backtrace of hung task:</p>
<p>INFO: task python:348105 blocked for more than 64512 seconds.
 Call Trace:
  __schedule+0x1c3/0x550
  schedule+0x46/0xb0
  rwsem_down_write_slowpath+0x24b/0x4c0
  unlink_anon_vmas+0xb1/0x1c0
  free_pgtables+0xa9/0x130
  exit_mmap+0xbc/0x1a0
  mmput+0x5a/0x140
  svm_range_cpu_invalidate_pagetables+0x2b/0x40 [amdgpu]
  mn_itree_invalidate+0x72/0xc0
  __mmu_notifier_invalidate_range_start+0x48/0x60
  try_to_unmap_one+0x10fa/0x1400
  rmap_walk_anon+0x196/0x460
  try_to_unmap+0xbb/0x210
  migrate_page_unmap+0x54d/0x7e0
  migrate_pages_batch+0x1c3/0xae0
  migrate_pages_sync+0x98/0x240
  migrate_pages+0x25c/0x520
  compact_zone+0x29d/0x590
  compact_zone_order+0xb6/0xf0
  try_to_compact_pages+0xbe/0x220
  __alloc_pages_…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-8w9j-8c65-frh3"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2025-38520</id>
    <title>msrc_CVE-2025-38520 — drm/amdkfd: Don't call mmput from MMU notifier callback</title>
    <updated>2026-10-04T00:55:13.706233+00:00</updated>
    <content>msrc_CVE-2025-38520</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2025-38520"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:20287-1</id>
    <title>openSUSE-SU-2026:20287-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-04T00:55:13.706252+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:20287-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2025:03272-1</id>
    <title>SUSE-SU-2025:03272-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-04T00:55:13.706386+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2025:03272-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-38520</id>
    <title>UBUNTU-CVE-2025-38520</title>
    <updated>2026-10-04T00:55:13.706458+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 162 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Don't call mmput from MMU notifier callback If the process is exiting, the mmput inside mmu notifier callback from compactd or fork or numa balancing could release the last reference of mm struct to call exit_mmap and free_pgtable, this triggers deadlock with below backtrace. The deadlock will leak kfd process as mmu notifier release is not called and cause VRAM leaking. The fix is to take mm reference mmget_non_zero when adding prange to the deferred list to pair with mmput in deferred list work. If prange split and add into pchild list, the pchild work_item.mm is not used, so remove the mm parameter from svm_range_unmap_split and svm_range_add_child. The backtrace of hung task:  INFO: task python:348105 blocked for more than 64512 seconds.  Call Trace:   __schedule+0x1c3/0x550   schedule+0x46/0xb0   rwsem_down_write_slowpath+0x24b/0x4c0   unlink_anon_vmas+0xb1/0x1c0   free_pgtables+0xa9/0x130   exit_mmap+0xbc/0x1a0   mmput+0x5a/0x140   svm_range_cpu_invalidate_pagetables+0x2b/0x40 [amdgpu]   mn_itree_invalidate+0x72/0xc0   __mmu_notifier_invalidate_range_start+0x48/0x60   try_to_unmap_one+0x10fa/0x1400   rmap_walk_anon+0x196/0x460   try_to_unmap+0xbb/0x210   migrate_page_unmap+0x54d/0x7e0   migrate_pages_batch+0x1c3/0xae0   migrate_pages_sync+0x98/0x240   migrate_pages+0x25c/0x520   compact_zone+0x29d/0x590   compact_zone_order+0xb6/0xf0   try_to_compact_pages+0xbe/0x220   __alloc_pages_direct_…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-38520"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1858</id>
    <title>WID-SEC-W-2025-1858 — Linux Kernel: Mehrere Schwachstellen</title>
    <updated>2026-10-04T00:55:13.706708+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen oder andere nicht spezifizierte Angriffe durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1858"/>
  </entry>
</feed>
