<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T04:11:06.408503+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-15172</id>
    <title>bdu:2025-15172</title>
    <updated>2026-10-03T04:11:07.197938+00:00</updated>
    <content>bdu:2025-15172</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-15172"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2025-38574</id>
    <title>BELL-CVE-2025-38574</title>
    <updated>2026-10-03T04:11:07.198005+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2025-38574"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0894</id>
    <title>certfr-2025-avi-0894 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de Debian LTS. Certaines d'entre elles permettent à…</title>
    <updated>2026-10-03T04:11:07.198041+00:00</updated>
    <content>certfr-2025-avi-0894</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-0894"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-347105</id>
    <title>EUVD-2026-347105</title>
    <updated>2026-10-03T04:11:07.198059+00:00</updated>
    <content>EUVD-2026-347105</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-347105"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-38574</id>
    <title>fkie_cve-2025-38574</title>
    <updated>2026-10-03T04:11:07.198071+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>pptp: ensure minimal skb length in pptp_xmit()</p>
<p>Commit aabc6596ffb3 ("net: ppp: Add bound checking for skb data
on ppp_sync_txmung") fixed ppp_sync_txmunge()</p>
<p>We need a similar fix in pptp_xmit(), otherwise we might
read uninit data as reported by syzbot.</p>
<p>BUG: KMSAN: uninit-value in pptp_xmit+0xc34/0x2720 drivers/net/ppp/pptp.c:193
  pptp_xmit+0xc34/0x2720 drivers/net/ppp/pptp.c:193
  ppp_channel_bridge_input drivers/net/ppp/ppp_generic.c:2290 [inline]
  ppp_input+0x1d6/0xe60 drivers/net/ppp/ppp_generic.c:2314
  pppoe_rcv_core+0x1e8/0x760 drivers/net/ppp/pppoe.c:379
  sk_backlog_rcv+0x142/0x420 include/net/sock.h:1148
  __release_sock+0x1d3/0x330 net/core/sock.c:3213
  release_sock+0x6b/0x270 net/core/sock.c:3767
  pppoe_sendmsg+0x15d/0xcb0 drivers/net/ppp/pppoe.c:904
  sock_sendmsg_nosec net/socket.c:712 [inline]
  __sock_sendmsg+0x330/0x3d0 net/socket.c:727
  ____sys_sendmsg+0x893/0xd80 net/socket.c:2566
  ___sys_sendmsg+0x271/0x3b0 net/socket.c:2620
  __sys_sendmmsg+0x2d9/0x7c0 net/socket.c:2709</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-38574"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-39q5-4vqc-9p73</id>
    <title>GHSA-39q5-4vqc-9p73</title>
    <updated>2026-10-03T04:11:07.198107+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>pptp: ensure minimal skb length in pptp_xmit()</p>
<p>Commit aabc6596ffb3 ("net: ppp: Add bound checking for skb data
on ppp_sync_txmung") fixed ppp_sync_txmunge()</p>
<p>We need a similar fix in pptp_xmit(), otherwise we might
read uninit data as reported by syzbot.</p>
<p>BUG: KMSAN: uninit-value in pptp_xmit+0xc34/0x2720 drivers/net/ppp/pptp.c:193
  pptp_xmit+0xc34/0x2720 drivers/net/ppp/pptp.c:193
  ppp_channel_bridge_input drivers/net/ppp/ppp_generic.c:2290 [inline]
  ppp_input+0x1d6/0xe60 drivers/net/ppp/ppp_generic.c:2314
  pppoe_rcv_core+0x1e8/0x760 drivers/net/ppp/pppoe.c:379
  sk_backlog_rcv+0x142/0x420 include/net/sock.h:1148
  __release_sock+0x1d3/0x330 net/core/sock.c:3213
  release_sock+0x6b/0x270 net/core/sock.c:3767
  pppoe_sendmsg+0x15d/0xcb0 drivers/net/ppp/pppoe.c:904
  sock_sendmsg_nosec net/socket.c:712 [inline]
  __sock_sendmsg+0x330/0x3d0 net/socket.c:727
  ____sys_sendmsg+0x893/0xd80 net/socket.c:2566
  ___sys_sendmsg+0x271/0x3b0 net/socket.c:2620
  __sys_sendmmsg+0x2d9/0x7c0 net/socket.c:2709</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-39q5-4vqc-9p73"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2025-38574</id>
    <title>msrc_CVE-2025-38574 — pptp: ensure minimal skb length in pptp_xmit()</title>
    <updated>2026-10-03T04:11:07.198131+00:00</updated>
    <content>msrc_CVE-2025-38574</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2025-38574"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2025-2268</id>
    <title>OESA-2025-2268 — kernel security update</title>
    <updated>2026-10-03T04:11:07.198149+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS: kernel</p>
<p>The Linux Kernel, the operating system core itself.

Security Fix(es):</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>rapidio: fix an API misues when rio_add_net() fails</p>
<p>rio_add_net() calls device_register() and fails when device_register()
fails.  Thus, put_device() should be used rather than kfree().  Add
&amp;quot;mport-&amp;gt;net = NULL;&amp;quot; to avoid a use after free issue.(CVE-2025-21934)</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>cifs: Fix integer overflow while processing closetimeo mount option</p>
<p>User-provided mount parameter closetimeo of type u32 is intended to have
an upper limit, but before it is validated, the value is converted from
seconds to jiffies which can lead to an integer overflow.</p>
<p>Found by Linux Verification Center (linuxtesting.org) with SVACE.(CVE-2025-21962)</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>ksmbd: fix use-after-free in ksmbd_free_work_struct</p>
<p>-&amp;gt;interim_entry of ksmbd_work could be deleted after oplock is freed.
We don&amp;apos;t need to manage it with linked list. The interim request could be
immediately sent whenever a oplock break wait is needed.(CVE-2025-21967)</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>ksmbd: fix use-after-free in kerberos authentication</p>
<p>Setting sess-&amp;gt;user = NULL was introduced to fix the dangling pointer
created by ksmbd_free_user. However, it is possible another thread could
be operating on the session and make us…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2025-2268"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2025:20081-1</id>
    <title>openSUSE-SU-2025:20081-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-03T04:11:07.198256+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2025:20081-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2025:03600-1</id>
    <title>SUSE-SU-2025:03600-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-03T04:11:07.198598+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2025:03600-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-38574</id>
    <title>UBUNTU-CVE-2025-38574</title>
    <updated>2026-10-03T04:11:07.198828+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: linux, Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe and 214 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: pptp: ensure minimal skb length in pptp_xmit() Commit aabc6596ffb3 ("net: ppp: Add bound checking for skb data on ppp_sync_txmung") fixed ppp_sync_txmunge() We need a similar fix in pptp_xmit(), otherwise we might read uninit data as reported by syzbot. BUG: KMSAN: uninit-value in pptp_xmit+0xc34/0x2720 drivers/net/ppp/pptp.c:193   pptp_xmit+0xc34/0x2720 drivers/net/ppp/pptp.c:193   ppp_channel_bridge_input drivers/net/ppp/ppp_generic.c:2290 [inline]   ppp_input+0x1d6/0xe60 drivers/net/ppp/ppp_generic.c:2314   pppoe_rcv_core+0x1e8/0x760 drivers/net/ppp/pppoe.c:379   sk_backlog_rcv+0x142/0x420 include/net/sock.h:1148   __release_sock+0x1d3/0x330 net/core/sock.c:3213   release_sock+0x6b/0x270 net/core/sock.c:3767   pppoe_sendmsg+0x15d/0xcb0 drivers/net/ppp/pppoe.c:904   sock_sendmsg_nosec net/socket.c:712 [inline]   __sock_sendmsg+0x330/0x3d0 net/socket.c:727   ____sys_sendmsg+0x893/0xd80 net/socket.c:2566   ___sys_sendmsg+0x271/0x3b0 net/socket.c:2620   __sys_sendmmsg+0x2d9/0x7c0 net/socket.c:2709</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-38574"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1869</id>
    <title>WID-SEC-W-2025-1869 — Linux Kernel: Mehrere Schwachstellen</title>
    <updated>2026-10-03T04:11:07.199083+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen im Linux-Kernel ausnutzen, um einen Denial-of-Service-Zustand zu erzeugen oder andere nicht spezifizierte Angriffe durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1869"/>
  </entry>
</feed>
