<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-09T05:43:40.961515+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-03275</id>
    <title>bdu:2026-03275</title>
    <updated>2026-10-09T05:43:40.973310+00:00</updated>
    <content>bdu:2026-03275</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-03275"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2025-39910</id>
    <title>BELL-CVE-2025-39910</title>
    <updated>2026-10-09T05:43:40.973349+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2025-39910"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-314822</id>
    <title>EUVD-2026-314822</title>
    <updated>2026-10-09T05:43:40.973378+00:00</updated>
    <content>EUVD-2026-314822</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-314822"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-39910</id>
    <title>fkie_cve-2025-39910</title>
    <updated>2026-10-09T05:43:40.973390+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>mm/vmalloc, mm/kasan: respect gfp mask in kasan_populate_vmalloc()</p>
<p>kasan_populate_vmalloc() and its helpers ignore the caller's gfp_mask and
always allocate memory using the hardcoded GFP_KERNEL flag.  This makes
them inconsistent with vmalloc(), which was recently extended to support
GFP_NOFS and GFP_NOIO allocations.</p>
<p>Page table allocations performed during shadow population also ignore the
external gfp_mask.  To preserve the intended semantics of GFP_NOFS and
GFP_NOIO, wrap the apply_to_page_range() calls into the appropriate
memalloc scope.</p>
<p>xfs calls vmalloc with GFP_NOFS, so this bug could lead to deadlock.</p>
<p>There was a report here
https://lkml.kernel.org/r/686ea951.050a0220.385921.0016.GAE@google.com</p>
<p>This patch:
 - Extends kasan_populate_vmalloc() and helpers to take gfp_mask;
 - Passes gfp_mask down to alloc_pages_bulk() and __get_free_page();
 - Enforces GFP_NOFS/NOIO semantics with memalloc_*_save()/restore()
   around apply_to_page_range();
 - Updates vmalloc.c and percpu allocator call sites accordingly.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-39910"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-xqc4-9x8w-pf49</id>
    <title>GHSA-xqc4-9x8w-pf49</title>
    <updated>2026-10-09T05:43:40.973423+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>mm/vmalloc, mm/kasan: respect gfp mask in kasan_populate_vmalloc()</p>
<p>kasan_populate_vmalloc() and its helpers ignore the caller's gfp_mask and
always allocate memory using the hardcoded GFP_KERNEL flag.  This makes
them inconsistent with vmalloc(), which was recently extended to support
GFP_NOFS and GFP_NOIO allocations.</p>
<p>Page table allocations performed during shadow population also ignore the
external gfp_mask.  To preserve the intended semantics of GFP_NOFS and
GFP_NOIO, wrap the apply_to_page_range() calls into the appropriate
memalloc scope.</p>
<p>xfs calls vmalloc with GFP_NOFS, so this bug could lead to deadlock.</p>
<p>There was a report here
https://lkml.kernel.org/r/686ea951.050a0220.385921.0016.GAE@google.com</p>
<p>This patch:
 - Extends kasan_populate_vmalloc() and helpers to take gfp_mask;
 - Passes gfp_mask down to alloc_pages_bulk() and __get_free_page();
 - Enforces GFP_NOFS/NOIO semantics with memalloc_*_save()/restore()
   around apply_to_page_range();
 - Updates vmalloc.c and percpu allocator call sites accordingly.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-xqc4-9x8w-pf49"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2025-39910</id>
    <title>msrc_CVE-2025-39910 — mm/vmalloc, mm/kasan: respect gfp mask in kasan_populate_vmalloc()</title>
    <updated>2026-10-09T05:43:40.973448+00:00</updated>
    <content>msrc_CVE-2025-39910</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2025-39910"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-1337</id>
    <title>OESA-2026-1337 — kernel security update</title>
    <updated>2026-10-09T05:43:40.973464+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS: kernel</p>
<p>The Linux Kernel, the operating system core itself.

Security Fix(es):</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>md/dm-raid: don&amp;apos;t call md_reap_sync_thread() directly</p>
<p>Currently md_reap_sync_thread() is called from raid_message() directly
without holding &amp;apos;reconfig_mutex&amp;apos;, this is definitely unsafe because
md_reap_sync_thread() can change many fields that is protected by
&amp;apos;reconfig_mutex&amp;apos;.</p>
<p>However, hold &amp;apos;reconfig_mutex&amp;apos; here is still problematic because this
will cause deadlock, for example, commit 130443d60b1b (&amp;quot;md: refactor
idle/frozen_sync_thread() to fix deadlock&amp;quot;).</p>
<p>Fix this problem by using stop_sync_thread() to unregister sync_thread,
like md/raid did.(CVE-2024-35808)</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>x86: fix user address masking non-canonical speculation issue</p>
<p>It turns out that AMD has a &amp;quot;Meltdown Lite(tm)&amp;quot; issue with non-canonical
accesses in kernel space.  And so using just the high bit to decide
whether an access is in user space or kernel space ends up with the good
old &amp;quot;leak speculative data&amp;quot; if you have the right gadget using the
result:</p>
<p>CVE-2020-12965 “Transient Execution of Non-Canonical Accesses“</p>
<p>Now, the kernel surrounds the access with a STAC/CLAC pair, and those
instructions end up serializing execution on older Zen architectures,
which closes the speculation window.</p>
<p>But that was true only up until Zen 5, which renames t…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-1337"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-39910</id>
    <title>UBUNTU-CVE-2025-39910</title>
    <updated>2026-10-09T05:43:40.973629+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 125 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: mm/vmalloc, mm/kasan: respect gfp mask in kasan_populate_vmalloc() kasan_populate_vmalloc() and its helpers ignore the caller's gfp_mask and always allocate memory using the hardcoded GFP_KERNEL flag.  This makes them inconsistent with vmalloc(), which was recently extended to support GFP_NOFS and GFP_NOIO allocations. Page table allocations performed during shadow population also ignore the external gfp_mask.  To preserve the intended semantics of GFP_NOFS and GFP_NOIO, wrap the apply_to_page_range() calls into the appropriate memalloc scope. xfs calls vmalloc with GFP_NOFS, so this bug could lead to deadlock. There was a report here https://lkml.kernel.org/r/686ea951.050a0220.385921.0016.GAE@google.com This patch:  - Extends kasan_populate_vmalloc() and helpers to take gfp_mask;  - Passes gfp_mask down to alloc_pages_bulk() and __get_free_page();  - Enforces GFP_NOFS/NOIO semantics with memalloc_*_save()/restore()    around apply_to_page_range();  - Updates vmalloc.c and percpu allocator call sites accordingly.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-39910"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2170</id>
    <title>WID-SEC-W-2025-2170 — Linux Kernel: Mehrere Schwachstellen</title>
    <updated>2026-10-09T05:43:40.973786+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen und andere nicht näher spezifizierte Angriffe durchzuführen, möglicherweise um beliebigen Code auszuführen oder eine Speicherbeschädigung zu verursachen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2170"/>
  </entry>
</feed>
