<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-09T06:29:53.047585+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-04329</id>
    <title>bdu:2026-04329</title>
    <updated>2026-10-09T06:29:53.053743+00:00</updated>
    <content>bdu:2026-04329</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-04329"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2025-39904</id>
    <title>BELL-CVE-2025-39904</title>
    <updated>2026-10-09T06:29:53.053795+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:stream: linux-lts</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2025-39904"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-314817</id>
    <title>EUVD-2026-314817</title>
    <updated>2026-10-09T06:29:53.053821+00:00</updated>
    <content>EUVD-2026-314817</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-314817"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-39904</id>
    <title>fkie_cve-2025-39904</title>
    <updated>2026-10-09T06:29:53.053834+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>arm64: kexec: initialize kexec_buf struct in load_other_segments()</p>
<p>Patch series "kexec: Fix invalid field access".</p>
<p>The kexec_buf structure was previously declared without initialization. 
commit bf454ec31add ("kexec_file: allow to place kexec_buf randomly")
added a field that is always read but not consistently populated by all
architectures.  This un-initialized field will contain garbage.</p>
<p>This is also triggering a UBSAN warning when the uninitialized data was
accessed:</p>
<p>------------[ cut here ]------------
	UBSAN: invalid-load in ./include/linux/kexec.h:210:10
	load of value 252 is not a valid value for type '_Bool'</p>
<p>Zero-initializing kexec_buf at declaration ensures all fields are cleanly
set, preventing future instances of uninitialized memory being used.</p>
<p>An initial fix was already landed for arm64[0], and this patchset fixes
the problem on the remaining arm64 code and on riscv, as raised by Mark.</p>
<p>Discussions about this problem could be found at[1][2].</p>
<p>This patch (of 3):</p>
<p>The kexec_buf structure was previously declared without initialization.
commit bf454ec31add ("kexec_file: allow to place kexec_buf randomly")
added a field that is always read but not consistently populated by all
architectures. This un-initialized field will contain garbage.</p>
<p>This is also triggering a UBSAN warning when the uninitialized data was
accessed:</p>
<p>------------[ cut here ]------------
	UBSAN: invalid-load in ./includ…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-39904"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-9j3f-w66p-jqvg</id>
    <title>GHSA-9j3f-w66p-jqvg</title>
    <updated>2026-10-09T06:29:53.053886+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>arm64: kexec: initialize kexec_buf struct in load_other_segments()</p>
<p>Patch series "kexec: Fix invalid field access".</p>
<p>The kexec_buf structure was previously declared without initialization. 
commit bf454ec31add ("kexec_file: allow to place kexec_buf randomly")
added a field that is always read but not consistently populated by all
architectures.  This un-initialized field will contain garbage.</p>
<p>This is also triggering a UBSAN warning when the uninitialized data was
accessed:</p>
<p>------------[ cut here ]------------
	UBSAN: invalid-load in ./include/linux/kexec.h:210:10
	load of value 252 is not a valid value for type '_Bool'</p>
<p>Zero-initializing kexec_buf at declaration ensures all fields are cleanly
set, preventing future instances of uninitialized memory being used.</p>
<p>An initial fix was already landed for arm64[0], and this patchset fixes
the problem on the remaining arm64 code and on riscv, as raised by Mark.</p>
<p>Discussions about this problem could be found at[1][2].</p>
<p>This patch (of 3):</p>
<p>The kexec_buf structure was previously declared without initialization.
commit bf454ec31add ("kexec_file: allow to place kexec_buf randomly")
added a field that is always read but not consistently populated by all
architectures. This un-initialized field will contain garbage.</p>
<p>This is also triggering a UBSAN warning when the uninitialized data was
accessed:</p>
<p>------------[ cut here ]------------
	UBSAN: invalid-load in ./includ…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-9j3f-w66p-jqvg"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-39904</id>
    <title>UBUNTU-CVE-2025-39904</title>
    <updated>2026-10-09T06:29:53.053923+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 79 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: arm64: kexec: initialize kexec_buf struct in load_other_segments() Patch series "kexec: Fix invalid field access". The kexec_buf structure was previously declared without initialization. commit bf454ec31add ("kexec_file: allow to place kexec_buf randomly") added a field that is always read but not consistently populated by all architectures.  This un-initialized field will contain garbage. This is also triggering a UBSAN warning when the uninitialized data was accessed: 	------------[ cut here ]------------ 	UBSAN: invalid-load in ./include/linux/kexec.h:210:10 	load of value 252 is not a valid value for type '_Bool' Zero-initializing kexec_buf at declaration ensures all fields are cleanly set, preventing future instances of uninitialized memory being used. An initial fix was already landed for arm64[0], and this patchset fixes the problem on the remaining arm64 code and on riscv, as raised by Mark. Discussions about this problem could be found at[1][2]. This patch (of 3): The kexec_buf structure was previously declared without initialization. commit bf454ec31add ("kexec_file: allow to place kexec_buf randomly") added a field that is always read but not consistently populated by all architectures. This un-initialized field will contain garbage. This is also triggering a UBSAN warning when the uninitialized data was accessed: 	------------[ cut here ]------------ 	UBSAN: invalid-load in ./include/linux/kexec.…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-39904"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2170</id>
    <title>WID-SEC-W-2025-2170 — Linux Kernel: Mehrere Schwachstellen</title>
    <updated>2026-10-09T06:29:53.054045+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen und andere nicht näher spezifizierte Angriffe durchzuführen, möglicherweise um beliebigen Code auszuführen oder eine Speicherbeschädigung zu verursachen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2170"/>
  </entry>
</feed>
