<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T12:38:09.824678+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-03081</id>
    <title>bdu:2026-03081</title>
    <updated>2026-10-04T12:38:10.602728+00:00</updated>
    <content>bdu:2026-03081</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-03081"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2025-38584</id>
    <title>BELL-CVE-2025-38584</title>
    <updated>2026-10-04T12:38:10.602793+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2025-38584"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0895</id>
    <title>certfr-2025-avi-0895 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de SUSE. Certaines d'entre elles permettent à un at…</title>
    <updated>2026-10-04T12:38:10.602826+00:00</updated>
    <content>certfr-2025-avi-0895</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-0895"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-347111</id>
    <title>EUVD-2026-347111</title>
    <updated>2026-10-04T12:38:10.602845+00:00</updated>
    <content>EUVD-2026-347111</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-347111"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-38584</id>
    <title>fkie_cve-2025-38584</title>
    <updated>2026-10-04T12:38:10.602857+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>padata: Fix pd UAF once and for all</p>
<p>There is a race condition/UAF in padata_reorder that goes back
to the initial commit.  A reference count is taken at the start
of the process in padata_do_parallel, and released at the end in
padata_serial_worker.</p>
<p>This reference count is (and only is) required for padata_replace
to function correctly.  If padata_replace is never called then
there is no issue.</p>
<p>In the function padata_reorder which serves as the core of padata,
as soon as padata is added to queue-&gt;serial.list, and the associated
spin lock released, that padata may be processed and the reference
count on pd would go away.</p>
<p>Fix this by getting the next padata before the squeue-&gt;serial lock
is released.</p>
<p>In order to make this possible, simplify padata_reorder by only
calling it once the next padata arrives.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-38584"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-7848-x3wq-cg7m</id>
    <title>GHSA-7848-x3wq-cg7m</title>
    <updated>2026-10-04T12:38:10.602893+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>padata: Fix pd UAF once and for all</p>
<p>There is a race condition/UAF in padata_reorder that goes back
to the initial commit.  A reference count is taken at the start
of the process in padata_do_parallel, and released at the end in
padata_serial_worker.</p>
<p>This reference count is (and only is) required for padata_replace
to function correctly.  If padata_replace is never called then
there is no issue.</p>
<p>In the function padata_reorder which serves as the core of padata,
as soon as padata is added to queue-&gt;serial.list, and the associated
spin lock released, that padata may be processed and the reference
count on pd would go away.</p>
<p>Fix this by getting the next padata before the squeue-&gt;serial lock
is released.</p>
<p>In order to make this possible, simplify padata_reorder by only
calling it once the next padata arrives.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-7848-x3wq-cg7m"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2025-38584</id>
    <title>msrc_CVE-2025-38584 — padata: Fix pd UAF once and for all</title>
    <updated>2026-10-04T12:38:10.602916+00:00</updated>
    <content>msrc_CVE-2025-38584</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2025-38584"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2025-2268</id>
    <title>OESA-2025-2268 — kernel security update</title>
    <updated>2026-10-04T12:38:10.602934+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS: kernel</p>
<p>The Linux Kernel, the operating system core itself.

Security Fix(es):</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>rapidio: fix an API misues when rio_add_net() fails</p>
<p>rio_add_net() calls device_register() and fails when device_register()
fails.  Thus, put_device() should be used rather than kfree().  Add
&amp;quot;mport-&amp;gt;net = NULL;&amp;quot; to avoid a use after free issue.(CVE-2025-21934)</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>cifs: Fix integer overflow while processing closetimeo mount option</p>
<p>User-provided mount parameter closetimeo of type u32 is intended to have
an upper limit, but before it is validated, the value is converted from
seconds to jiffies which can lead to an integer overflow.</p>
<p>Found by Linux Verification Center (linuxtesting.org) with SVACE.(CVE-2025-21962)</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>ksmbd: fix use-after-free in ksmbd_free_work_struct</p>
<p>-&amp;gt;interim_entry of ksmbd_work could be deleted after oplock is freed.
We don&amp;apos;t need to manage it with linked list. The interim request could be
immediately sent whenever a oplock break wait is needed.(CVE-2025-21967)</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>ksmbd: fix use-after-free in kerberos authentication</p>
<p>Setting sess-&amp;gt;user = NULL was introduced to fix the dangling pointer
created by ksmbd_free_user. However, it is possible another thread could
be operating on the session and make us…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2025-2268"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2025:20081-1</id>
    <title>openSUSE-SU-2025:20081-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-04T12:38:10.603041+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2025:20081-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2025:03600-1</id>
    <title>SUSE-SU-2025:03600-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-04T12:38:10.603443+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2025:03600-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-38584</id>
    <title>UBUNTU-CVE-2025-38584</title>
    <updated>2026-10-04T12:38:10.603701+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: linux, Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe and 214 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: padata: Fix pd UAF once and for all There is a race condition/UAF in padata_reorder that goes back to the initial commit.  A reference count is taken at the start of the process in padata_do_parallel, and released at the end in padata_serial_worker. This reference count is (and only is) required for padata_replace to function correctly.  If padata_replace is never called then there is no issue. In the function padata_reorder which serves as the core of padata, as soon as padata is added to queue-&gt;serial.list, and the associated spin lock released, that padata may be processed and the reference count on pd would go away. Fix this by getting the next padata before the squeue-&gt;serial lock is released. In order to make this possible, simplify padata_reorder by only calling it once the next padata arrives.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-38584"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1869</id>
    <title>WID-SEC-W-2025-1869 — Linux Kernel: Mehrere Schwachstellen</title>
    <updated>2026-10-04T12:38:10.604270+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen im Linux-Kernel ausnutzen, um einen Denial-of-Service-Zustand zu erzeugen oder andere nicht spezifizierte Angriffe durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1869"/>
  </entry>
</feed>
