<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T12:08:44.060602+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:4012</id>
    <title>ALSA-2026:4012 — Moderate: kernel security update</title>
    <updated>2026-10-03T12:08:44.136854+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:10: kernel-abi-stablelists, AlmaLinux:10: kernel-doc</p>
<p>The kernel packages contain the Linux kernel, the core of any Linux operating system.</p>
<p>Security Fix(es):</p>
<p>* kernel: Linux kernel: Use-after-free in device mapper due to race condition in zone reporting (CVE-2025-38141)
  * kernel: Linux kernel io_uring: Local privilege escalation, information disclosure, or denial of service via use-after-free (CVE-2025-38106)
  * kernel: drm/xe: Make dma-fences compliant with the safe access rules (CVE-2025-38703)
  * kernel: Linux kernel: Denial of Service via out-of-bounds read in USB configuration parsing (CVE-2025-39760)
  * kernel: HID: intel-thc-hid: intel-thc: Fix incorrect pointer arithmetic in I2C regs save (CVE-2025-39818)
  * kernel: Kernel: Use-after-free in GPIO character device allows privilege escalation or denial of service (CVE-2025-40249)
  * kernel: ipv6: BUG() in pskb_expand_head() as part of calipso_skbuff_setattr() (CVE-2025-71085)
  * kernel: macvlan: fix possible UAF in macvlan_forward_source() (CVE-2026-23001)
  * kernel: Linux kernel: Denial of Service due to a deadlock in hugetlb folio migration (CVE-2026-23097)
  * kernel: Linux kernel: Information disclosure in efivarfs via incorrect error propagation (CVE-2026-23156)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:4012"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-03306</id>
    <title>bdu:2026-03306</title>
    <updated>2026-10-03T12:08:44.136929+00:00</updated>
    <content>bdu:2026-03306</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-03306"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2025-39818</id>
    <title>BELL-CVE-2025-39818</title>
    <updated>2026-10-03T12:08:44.136948+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:stream: linux-lts</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2025-39818"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-1050</id>
    <title>certfr-2025-avi-1050 — De multiples vulnérabilités ont été découvertes dans le noyau Linux d'Ubuntu. Certaines d'entre elles permettent à un a…</title>
    <updated>2026-10-03T12:08:44.136967+00:00</updated>
    <content>certfr-2025-avi-1050</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-1050"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-347218</id>
    <title>EUVD-2026-347218</title>
    <updated>2026-10-03T12:08:44.136983+00:00</updated>
    <content>EUVD-2026-347218</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-347218"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-39818</id>
    <title>fkie_cve-2025-39818</title>
    <updated>2026-10-03T12:08:44.136995+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>HID: intel-thc-hid: intel-thc: Fix incorrect pointer arithmetic in I2C regs save</p>
<p>Improper use of secondary pointer (&amp;dev-&gt;i2c_subip_regs) caused
kernel crash and out-of-bounds error:</p>
<p>BUG: KASAN: slab-out-of-bounds in _regmap_bulk_read+0x449/0x510
 Write of size 4 at addr ffff888136005dc0 by task kworker/u33:5/5107</p>
<p>CPU: 3 UID: 0 PID: 5107 Comm: kworker/u33:5 Not tainted 6.16.0+ #3 PREEMPT(voluntary)
 Workqueue: async async_run_entry_fn
 Call Trace:
  &lt;TASK&gt;
  dump_stack_lvl+0x76/0xa0
  print_report+0xd1/0x660
  ? __pfx__raw_spin_lock_irqsave+0x10/0x10
  ? kasan_complete_mode_report_info+0x26/0x200
  kasan_report+0xe1/0x120
  ? _regmap_bulk_read+0x449/0x510
  ? _regmap_bulk_read+0x449/0x510
  __asan_report_store4_noabort+0x17/0x30
  _regmap_bulk_read+0x449/0x510
  ? __pfx__regmap_bulk_read+0x10/0x10
  regmap_bulk_read+0x270/0x3d0
  pio_complete+0x1ee/0x2c0 [intel_thc]
  ? __pfx_pio_complete+0x10/0x10 [intel_thc]
  ? __pfx_pio_wait+0x10/0x10 [intel_thc]
  ? regmap_update_bits_base+0x13b/0x1f0
  thc_i2c_subip_pio_read+0x117/0x270 [intel_thc]
  thc_i2c_subip_regs_save+0xc2/0x140 [intel_thc]
  ? __pfx_thc_i2c_subip_regs_save+0x10/0x10 [intel_thc]
[...]
 The buggy address belongs to the object at ffff888136005d00
  which belongs to the cache kmalloc-rnd-12-192 of size 192
 The buggy address is located 0 bytes to the right of
  allocated 192-byte region [ffff888136005d00, ffff888136005dc0)</p>
<p>Replaced with direc…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-39818"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-2xm6-gr28-3f78</id>
    <title>GHSA-2xm6-gr28-3f78</title>
    <updated>2026-10-03T12:08:44.137037+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>HID: intel-thc-hid: intel-thc: Fix incorrect pointer arithmetic in I2C regs save</p>
<p>Improper use of secondary pointer (&amp;dev-&gt;i2c_subip_regs) caused
kernel crash and out-of-bounds error:</p>
<p>BUG: KASAN: slab-out-of-bounds in _regmap_bulk_read+0x449/0x510
 Write of size 4 at addr ffff888136005dc0 by task kworker/u33:5/5107</p>
<p>CPU: 3 UID: 0 PID: 5107 Comm: kworker/u33:5 Not tainted 6.16.0+ #3 PREEMPT(voluntary)
 Workqueue: async async_run_entry_fn
 Call Trace:
  &lt;TASK&gt;
  dump_stack_lvl+0x76/0xa0
  print_report+0xd1/0x660
  ? __pfx__raw_spin_lock_irqsave+0x10/0x10
  ? kasan_complete_mode_report_info+0x26/0x200
  kasan_report+0xe1/0x120
  ? _regmap_bulk_read+0x449/0x510
  ? _regmap_bulk_read+0x449/0x510
  __asan_report_store4_noabort+0x17/0x30
  _regmap_bulk_read+0x449/0x510
  ? __pfx__regmap_bulk_read+0x10/0x10
  regmap_bulk_read+0x270/0x3d0
  pio_complete+0x1ee/0x2c0 [intel_thc]
  ? __pfx_pio_complete+0x10/0x10 [intel_thc]
  ? __pfx_pio_wait+0x10/0x10 [intel_thc]
  ? regmap_update_bits_base+0x13b/0x1f0
  thc_i2c_subip_pio_read+0x117/0x270 [intel_thc]
  thc_i2c_subip_regs_save+0xc2/0x140 [intel_thc]
  ? __pfx_thc_i2c_subip_regs_save+0x10/0x10 [intel_thc]
[...]
 The buggy address belongs to the object at ffff888136005d00
  which belongs to the cache kmalloc-rnd-12-192 of size 192
 The buggy address is located 0 bytes to the right of
  allocated 192-byte region [ffff888136005d00, ffff888136005dc0)</p>
<p>Replaced with direc…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-2xm6-gr28-3f78"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:4012</id>
    <title>RHSA-2026:4012 — Red Hat Security Advisory: kernel security update</title>
    <updated>2026-10-03T12:08:44.137070+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>kernel: Linux kernel io_uring: Local privilege escalation, information disclosure, or denial of service via use-after-free kernel: Linux kernel: Use-after-free in device mapper due to race condition in zone reporting kernel: drm/xe: Make dma-fences compliant with the safe access rules kernel: Linux kernel: Denial of Service via out-of-bounds read in USB configuration parsing kernel: HID: intel-thc-hid: intel-thc: Fix incorrect pointer arithmetic in I2C regs save kernel: Kernel: Use-after-free in GPIO character device allows privilege escalation or denial of service kernel: ipv6: BUG() in pskb_expand_head() as part of calipso_skbuff_setattr() kernel: macvlan: fix possible UAF in macvlan_forward_source() kernel: Linux kernel: Denial of Service due to a deadlock in hugetlb folio migration kernel: Linux kernel: Information disclosure in efivarfs via incorrect error propagation</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:4012"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-39818</id>
    <title>UBUNTU-CVE-2025-39818</title>
    <updated>2026-10-03T12:08:44.137105+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 88 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: HID: intel-thc-hid: intel-thc: Fix incorrect pointer arithmetic in I2C regs save Improper use of secondary pointer (&amp;dev-&gt;i2c_subip_regs) caused kernel crash and out-of-bounds error:  BUG: KASAN: slab-out-of-bounds in _regmap_bulk_read+0x449/0x510  Write of size 4 at addr ffff888136005dc0 by task kworker/u33:5/5107  CPU: 3 UID: 0 PID: 5107 Comm: kworker/u33:5 Not tainted 6.16.0+ #3 PREEMPT(voluntary)  Workqueue: async async_run_entry_fn  Call Trace:   &lt;TASK&gt;   dump_stack_lvl+0x76/0xa0   print_report+0xd1/0x660   ? __pfx__raw_spin_lock_irqsave+0x10/0x10   ? kasan_complete_mode_report_info+0x26/0x200   kasan_report+0xe1/0x120   ? _regmap_bulk_read+0x449/0x510   ? _regmap_bulk_read+0x449/0x510   __asan_report_store4_noabort+0x17/0x30   _regmap_bulk_read+0x449/0x510   ? __pfx__regmap_bulk_read+0x10/0x10   regmap_bulk_read+0x270/0x3d0   pio_complete+0x1ee/0x2c0 [intel_thc]   ? __pfx_pio_complete+0x10/0x10 [intel_thc]   ? __pfx_pio_wait+0x10/0x10 [intel_thc]   ? regmap_update_bits_base+0x13b/0x1f0   thc_i2c_subip_pio_read+0x117/0x270 [intel_thc]   thc_i2c_subip_regs_save+0xc2/0x140 [intel_thc]   ? __pfx_thc_i2c_subip_regs_save+0x10/0x10 [intel_thc] [...]  The buggy address belongs to the object at ffff888136005d00   which belongs to the cache kmalloc-rnd-12-192 of size 192  The buggy address is located 0 bytes to the right of   allocated 192-byte region [ffff888136005d00, ffff888136005dc0) Replaced with direct arr…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-39818"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2077</id>
    <title>WID-SEC-W-2025-2077 — Linux Kernel: Mehrere Schwachstellen</title>
    <updated>2026-10-03T12:08:44.137260+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen oder nicht näher beschriebene Auswirkungen zu erzielen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2077"/>
  </entry>
</feed>
