<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T15:27:50.011330+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-13895</id>
    <title>bdu:2025-13895</title>
    <updated>2026-10-02T15:27:50.115544+00:00</updated>
    <content>bdu:2025-13895</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-13895"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2025-39874</id>
    <title>BELL-CVE-2025-39874</title>
    <updated>2026-10-02T15:27:50.115579+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:stream: linux-lts</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2025-39874"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-314798</id>
    <title>EUVD-2026-314798</title>
    <updated>2026-10-02T15:27:50.115606+00:00</updated>
    <content>EUVD-2026-314798</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-314798"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-39874</id>
    <title>fkie_cve-2025-39874</title>
    <updated>2026-10-02T15:27:50.115619+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>macsec: sync features on RTM_NEWLINK</p>
<p>Syzkaller managed to lock the lower device via ETHTOOL_SFEATURES:</p>
<p>netdev_lock include/linux/netdevice.h:2761 [inline]
 netdev_lock_ops include/net/netdev_lock.h:42 [inline]
 netdev_sync_lower_features net/core/dev.c:10649 [inline]
 __netdev_update_features+0xcb1/0x1be0 net/core/dev.c:10819
 netdev_update_features+0x6d/0xe0 net/core/dev.c:10876
 macsec_notify+0x2f5/0x660 drivers/net/macsec.c:4533
 notifier_call_chain+0x1b3/0x3e0 kernel/notifier.c:85
 call_netdevice_notifiers_extack net/core/dev.c:2267 [inline]
 call_netdevice_notifiers net/core/dev.c:2281 [inline]
 netdev_features_change+0x85/0xc0 net/core/dev.c:1570
 __dev_ethtool net/ethtool/ioctl.c:3469 [inline]
 dev_ethtool+0x1536/0x19b0 net/ethtool/ioctl.c:3502
 dev_ioctl+0x392/0x1150 net/core/dev_ioctl.c:759</p>
<p>It happens because lower features are out of sync with the upper:</p>
<p>__dev_ethtool (real_dev)
    netdev_lock_ops(real_dev)
    ETHTOOL_SFEATURES
      __netdev_features_change
        netdev_sync_upper_features
          disable LRO on the lower
    if (old_features != dev-&gt;features)
      netdev_features_change
        fires NETDEV_FEAT_CHANGE
	macsec_notify
	  NETDEV_FEAT_CHANGE
	    netdev_update_features (for each macsec dev)
	      netdev_sync_lower_features
	        if (upper_features != lower_features)
	          netdev_lock_ops(lower) # lower == real_dev
		  stuck
		  ...</p>
<p>netdev_unlock_ops(real…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-39874"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-rmcq-9vcc-9423</id>
    <title>GHSA-rmcq-9vcc-9423</title>
    <updated>2026-10-02T15:27:50.115664+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>macsec: sync features on RTM_NEWLINK</p>
<p>Syzkaller managed to lock the lower device via ETHTOOL_SFEATURES:</p>
<p>netdev_lock include/linux/netdevice.h:2761 [inline]
 netdev_lock_ops include/net/netdev_lock.h:42 [inline]
 netdev_sync_lower_features net/core/dev.c:10649 [inline]
 __netdev_update_features+0xcb1/0x1be0 net/core/dev.c:10819
 netdev_update_features+0x6d/0xe0 net/core/dev.c:10876
 macsec_notify+0x2f5/0x660 drivers/net/macsec.c:4533
 notifier_call_chain+0x1b3/0x3e0 kernel/notifier.c:85
 call_netdevice_notifiers_extack net/core/dev.c:2267 [inline]
 call_netdevice_notifiers net/core/dev.c:2281 [inline]
 netdev_features_change+0x85/0xc0 net/core/dev.c:1570
 __dev_ethtool net/ethtool/ioctl.c:3469 [inline]
 dev_ethtool+0x1536/0x19b0 net/ethtool/ioctl.c:3502
 dev_ioctl+0x392/0x1150 net/core/dev_ioctl.c:759</p>
<p>It happens because lower features are out of sync with the upper:</p>
<p>__dev_ethtool (real_dev)
    netdev_lock_ops(real_dev)
    ETHTOOL_SFEATURES
      __netdev_features_change
        netdev_sync_upper_features
          disable LRO on the lower
    if (old_features != dev-&gt;features)
      netdev_features_change
        fires NETDEV_FEAT_CHANGE
	macsec_notify
	  NETDEV_FEAT_CHANGE
	    netdev_update_features (for each macsec dev)
	      netdev_sync_lower_features
	        if (upper_features != lower_features)
	          netdev_lock_ops(lower) # lower == real_dev
		  stuck
		  ...</p>
<p>netdev_unlock_ops(real…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-rmcq-9vcc-9423"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-39874</id>
    <title>UBUNTU-CVE-2025-39874</title>
    <updated>2026-10-02T15:27:50.115698+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 79 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: macsec: sync features on RTM_NEWLINK Syzkaller managed to lock the lower device via ETHTOOL_SFEATURES:  netdev_lock include/linux/netdevice.h:2761 [inline]  netdev_lock_ops include/net/netdev_lock.h:42 [inline]  netdev_sync_lower_features net/core/dev.c:10649 [inline]  __netdev_update_features+0xcb1/0x1be0 net/core/dev.c:10819  netdev_update_features+0x6d/0xe0 net/core/dev.c:10876  macsec_notify+0x2f5/0x660 drivers/net/macsec.c:4533  notifier_call_chain+0x1b3/0x3e0 kernel/notifier.c:85  call_netdevice_notifiers_extack net/core/dev.c:2267 [inline]  call_netdevice_notifiers net/core/dev.c:2281 [inline]  netdev_features_change+0x85/0xc0 net/core/dev.c:1570  __dev_ethtool net/ethtool/ioctl.c:3469 [inline]  dev_ethtool+0x1536/0x19b0 net/ethtool/ioctl.c:3502  dev_ioctl+0x392/0x1150 net/core/dev_ioctl.c:759 It happens because lower features are out of sync with the upper:   __dev_ethtool (real_dev)     netdev_lock_ops(real_dev)     ETHTOOL_SFEATURES       __netdev_features_change         netdev_sync_upper_features           disable LRO on the lower     if (old_features != dev-&gt;features)       netdev_features_change         fires NETDEV_FEAT_CHANGE 	macsec_notify 	  NETDEV_FEAT_CHANGE 	    netdev_update_features (for each macsec dev) 	      netdev_sync_lower_features 	        if (upper_features != lower_features) 	          netdev_lock_ops(lower) # lower == real_dev 		  stuck 		  ...     netdev_unlock_ops(real_dev)…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-39874"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2107</id>
    <title>WID-SEC-W-2025-2107 — Linux Kernel: Mehrere Schwachstellen</title>
    <updated>2026-10-02T15:27:50.115838+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen oder nicht näher beschriebene Auswirkungen zu erzielen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2107"/>
  </entry>
</feed>
