<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T21:58:20.638519+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2025:18318</id>
    <title>ALSA-2025:18318 — Moderate: kernel security update</title>
    <updated>2026-10-04T21:58:22.635187+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:10: kernel-abi-stablelists, AlmaLinux:10: kernel-doc</p>
<p>The kernel packages contain the Linux kernel, the core of any Linux operating system.</p>
<p>Security Fix(es):</p>
<p>* kernel: KVM: x86/hyper-v: Skip non-canonical addresses during PV TLB flush (CVE-2025-38351)
  * kernel: sunrpc: fix client side handling of tls alerts (CVE-2025-38571)
  * kernel: eventpoll: Fix semi-unbounded recursion (CVE-2025-38614)
  * kernel: ipv6: reject malicious packets in ipv6_gso_segment() (CVE-2025-38572)
  * kernel: efivarfs: Fix slab-out-of-bounds in efivarfs_d_compare (CVE-2025-39817)
  * kernel: scsi: lpfc: Fix buffer free/clear order in deferred receive path (CVE-2025-39841)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2025:18318"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-15171</id>
    <title>bdu:2025-15171</title>
    <updated>2026-10-04T21:58:22.635311+00:00</updated>
    <content>bdu:2025-15171</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-15171"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2025-38572</id>
    <title>BELL-CVE-2025-38572</title>
    <updated>2026-10-04T21:58:22.635331+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2025-38572"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0787</id>
    <title>certfr-2025-avi-0787 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de SUSE. Certaines d'entre elles permettent à un at…</title>
    <updated>2026-10-04T21:58:22.635353+00:00</updated>
    <content>certfr-2025-avi-0787</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-0787"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-347103</id>
    <title>EUVD-2026-347103</title>
    <updated>2026-10-04T21:58:22.635371+00:00</updated>
    <content>EUVD-2026-347103</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-347103"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-38572</id>
    <title>fkie_cve-2025-38572</title>
    <updated>2026-10-04T21:58:22.635383+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>ipv6: reject malicious packets in ipv6_gso_segment()</p>
<p>syzbot was able to craft a packet with very long IPv6 extension headers
leading to an overflow of skb-&gt;transport_header.</p>
<p>This 16bit field has a limited range.</p>
<p>Add skb_reset_transport_header_careful() helper and use it
from ipv6_gso_segment()</p>
<p>WARNING: CPU: 0 PID: 5871 at ./include/linux/skbuff.h:3032 skb_reset_transport_header include/linux/skbuff.h:3032 [inline]
WARNING: CPU: 0 PID: 5871 at ./include/linux/skbuff.h:3032 ipv6_gso_segment+0x15e2/0x21e0 net/ipv6/ip6_offload.c:151
Modules linked in:
CPU: 0 UID: 0 PID: 5871 Comm: syz-executor211 Not tainted 6.16.0-rc6-syzkaller-g7abc678e3084 #0 PREEMPT(full)
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 07/12/2025
 RIP: 0010:skb_reset_transport_header include/linux/skbuff.h:3032 [inline]
 RIP: 0010:ipv6_gso_segment+0x15e2/0x21e0 net/ipv6/ip6_offload.c:151
Call Trace:
 &lt;TASK&gt;
  skb_mac_gso_segment+0x31c/0x640 net/core/gso.c:53
  nsh_gso_segment+0x54a/0xe10 net/nsh/nsh.c:110
  skb_mac_gso_segment+0x31c/0x640 net/core/gso.c:53
  __skb_gso_segment+0x342/0x510 net/core/gso.c:124
  skb_gso_segment include/net/gso.h:83 [inline]
  validate_xmit_skb+0x857/0x11b0 net/core/dev.c:3950
  validate_xmit_skb_list+0x84/0x120 net/core/dev.c:4000
  sch_direct_xmit+0xd3/0x4b0 net/sched/sch_generic.c:329
  __dev_xmit_skb net/core/dev.c:4102 [inline]
  __dev_queue_xmit+0x17b6/0x3a70 net/core/dev…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-38572"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-j327-57v5-q43v</id>
    <title>GHSA-j327-57v5-q43v</title>
    <updated>2026-10-04T21:58:22.635426+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>ipv6: reject malicious packets in ipv6_gso_segment()</p>
<p>syzbot was able to craft a packet with very long IPv6 extension headers
leading to an overflow of skb-&gt;transport_header.</p>
<p>This 16bit field has a limited range.</p>
<p>Add skb_reset_transport_header_careful() helper and use it
from ipv6_gso_segment()</p>
<p>WARNING: CPU: 0 PID: 5871 at ./include/linux/skbuff.h:3032 skb_reset_transport_header include/linux/skbuff.h:3032 [inline]
WARNING: CPU: 0 PID: 5871 at ./include/linux/skbuff.h:3032 ipv6_gso_segment+0x15e2/0x21e0 net/ipv6/ip6_offload.c:151
Modules linked in:
CPU: 0 UID: 0 PID: 5871 Comm: syz-executor211 Not tainted 6.16.0-rc6-syzkaller-g7abc678e3084 #0 PREEMPT(full)
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 07/12/2025
 RIP: 0010:skb_reset_transport_header include/linux/skbuff.h:3032 [inline]
 RIP: 0010:ipv6_gso_segment+0x15e2/0x21e0 net/ipv6/ip6_offload.c:151
Call Trace:
 &lt;TASK&gt;
  skb_mac_gso_segment+0x31c/0x640 net/core/gso.c:53
  nsh_gso_segment+0x54a/0xe10 net/nsh/nsh.c:110
  skb_mac_gso_segment+0x31c/0x640 net/core/gso.c:53
  __skb_gso_segment+0x342/0x510 net/core/gso.c:124
  skb_gso_segment include/net/gso.h:83 [inline]
  validate_xmit_skb+0x857/0x11b0 net/core/dev.c:3950
  validate_xmit_skb_list+0x84/0x120 net/core/dev.c:4000
  sch_direct_xmit+0xd3/0x4b0 net/sched/sch_generic.c:329
  __dev_xmit_skb net/core/dev.c:4102 [inline]
  __dev_queue_xmit+0x17b6/0x3a70 net/core/dev…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-j327-57v5-q43v"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2025-38572</id>
    <title>msrc_CVE-2025-38572 — ipv6: reject malicious packets in ipv6_gso_segment()</title>
    <updated>2026-10-04T21:58:22.635458+00:00</updated>
    <content>msrc_CVE-2025-38572</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2025-38572"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-1306</id>
    <title>OESA-2026-1306 — kernel security update</title>
    <updated>2026-10-04T21:58:22.635475+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP4: kernel</p>
<p>The Linux Kernel, the operating system core itself.

Security Fix(es):</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>cacheinfo: Fix shared_cpu_map to handle shared caches at different levels</p>
<p>The cacheinfo sets up the shared_cpu_map by checking whether the caches
with the same index are shared between CPUs. However, this will trigger
slab-out-of-bounds access if the CPUs do not have the same cache hierarchy.
Another problem is the mismatched shared_cpu_map when the shared cache does
not have the same index between CPUs.</p>
<p>CPU0	I	D	L3
index	0	1	2	x
	^	^	^	^
index	0	1	2	3
CPU1	I	D	L2	L3</p>
<p>This patch checks each cache is shared with all caches on other CPUs.(CVE-2023-53254)</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>drm/radeon: Fix integer overflow in radeon_cs_parser_init</p>
<p>The type of size is unsigned, if size is 0x40000000, there will be an
integer overflow, size will be zero after size *= sizeof(uint32_t),
will cause uninitialized memory to be referenced later(CVE-2023-53309)</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>media: v4l2-mem2mem: add lock to protect parameter num_rdy</p>
<p>Getting below error when using KCSAN to check the driver. Adding lock to
protect parameter num_rdy when getting the value with function:
v4l2_m2m_num_src_bufs_ready/v4l2_m2m_num_dst_bufs_ready.</p>
<p>kworker/u16:3: [name:report&amp;amp;]BUG: KCSAN: data-race in v4l2_m2m_buf_queue
kworker/u16:3: [name:report&amp;amp;]</p>
<p>kworker/u16:3: [name…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-1306"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2025:20081-1</id>
    <title>openSUSE-SU-2025:20081-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-04T21:58:22.635562+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2025:20081-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2025:18318</id>
    <title>RHSA-2025:18318 — Red Hat Security Advisory: kernel security update</title>
    <updated>2026-10-04T21:58:22.635906+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>kernel: KVM: x86/hyper-v: Skip non-canonical addresses during PV TLB flush kernel: sunrpc: fix client side handling of tls alerts kernel: ipv6: reject malicious packets in ipv6_gso_segment() kernel: eventpoll: Fix semi-unbounded recursion kernel: efivarfs: Fix slab-out-of-bounds in efivarfs_d_compare kernel: scsi: lpfc: Fix buffer free/clear order in deferred receive path</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2025:18318"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2025:03272-1</id>
    <title>SUSE-SU-2025:03272-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-04T21:58:22.635933+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2025:03272-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-38572</id>
    <title>UBUNTU-CVE-2025-38572</title>
    <updated>2026-10-04T21:58:22.636001+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: linux, Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe and 214 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: ipv6: reject malicious packets in ipv6_gso_segment() syzbot was able to craft a packet with very long IPv6 extension headers leading to an overflow of skb-&gt;transport_header. This 16bit field has a limited range. Add skb_reset_transport_header_careful() helper and use it from ipv6_gso_segment() WARNING: CPU: 0 PID: 5871 at ./include/linux/skbuff.h:3032 skb_reset_transport_header include/linux/skbuff.h:3032 [inline] WARNING: CPU: 0 PID: 5871 at ./include/linux/skbuff.h:3032 ipv6_gso_segment+0x15e2/0x21e0 net/ipv6/ip6_offload.c:151 Modules linked in: CPU: 0 UID: 0 PID: 5871 Comm: syz-executor211 Not tainted 6.16.0-rc6-syzkaller-g7abc678e3084 #0 PREEMPT(full) Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 07/12/2025  RIP: 0010:skb_reset_transport_header include/linux/skbuff.h:3032 [inline]  RIP: 0010:ipv6_gso_segment+0x15e2/0x21e0 net/ipv6/ip6_offload.c:151 Call Trace:  &lt;TASK&gt;   skb_mac_gso_segment+0x31c/0x640 net/core/gso.c:53   nsh_gso_segment+0x54a/0xe10 net/nsh/nsh.c:110   skb_mac_gso_segment+0x31c/0x640 net/core/gso.c:53   __skb_gso_segment+0x342/0x510 net/core/gso.c:124   skb_gso_segment include/net/gso.h:83 [inline]   validate_xmit_skb+0x857/0x11b0 net/core/dev.c:3950   validate_xmit_skb_list+0x84/0x120 net/core/dev.c:4000   sch_direct_xmit+0xd3/0x4b0 net/sched/sch_generic.c:329   __dev_xmit_skb net/core/dev.c:4102 [inline]   __dev_queue_xmit+0x17b6/0x3a70 net/core/dev.c:46…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-38572"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1869</id>
    <title>WID-SEC-W-2025-1869 — Linux Kernel: Mehrere Schwachstellen</title>
    <updated>2026-10-04T21:58:22.636257+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen im Linux-Kernel ausnutzen, um einen Denial-of-Service-Zustand zu erzeugen oder andere nicht spezifizierte Angriffe durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1869"/>
  </entry>
</feed>
