<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T03:26:49.506827+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-02685</id>
    <title>bdu:2026-02685</title>
    <updated>2026-10-04T03:26:49.646036+00:00</updated>
    <content>bdu:2026-02685</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-02685"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2025-39950</id>
    <title>BELL-CVE-2025-39950</title>
    <updated>2026-10-04T03:26:49.646079+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2025-39950"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-1073</id>
    <title>certfr-2025-avi-1073 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de SUSE. Certaines d'entre elles permettent à un at…</title>
    <updated>2026-10-04T03:26:49.646110+00:00</updated>
    <content>certfr-2025-avi-1073</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-1073"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-314837</id>
    <title>EUVD-2026-314837</title>
    <updated>2026-10-04T03:26:49.646128+00:00</updated>
    <content>EUVD-2026-314837</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-314837"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-39950</id>
    <title>fkie_cve-2025-39950</title>
    <updated>2026-10-04T03:26:49.646140+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>net/tcp: Fix a NULL pointer dereference when using TCP-AO with TCP_REPAIR</p>
<p>A NULL pointer dereference can occur in tcp_ao_finish_connect() during a
connect() system call on a socket with a TCP-AO key added and TCP_REPAIR
enabled.</p>
<p>The function is called with skb being NULL and attempts to dereference it
on tcp_hdr(skb)-&gt;seq without a prior skb validation.</p>
<p>Fix this by checking if skb is NULL before dereferencing it.</p>
<p>The commentary is taken from bpf_skops_established(), which is also called
in the same flow. Unlike the function being patched,
bpf_skops_established() validates the skb before dereferencing it.</p>
<p>int main(void){
	struct sockaddr_in sockaddr;
	struct tcp_ao_add tcp_ao;
	int sk;
	int one = 1;</p>
<p>memset(&amp;sockaddr,'\0',sizeof(sockaddr));
	memset(&amp;tcp_ao,'\0',sizeof(tcp_ao));</p>
<p>sk = socket(AF_INET, SOCK_STREAM, IPPROTO_TCP);</p>
<p>sockaddr.sin_family = AF_INET;</p>
<p>memcpy(tcp_ao.alg_name,"cmac(aes128)",12);
	memcpy(tcp_ao.key,"ABCDEFGHABCDEFGH",16);
	tcp_ao.keylen = 16;</p>
<p>memcpy(&amp;tcp_ao.addr,&amp;sockaddr,sizeof(sockaddr));</p>
<p>setsockopt(sk, IPPROTO_TCP, TCP_AO_ADD_KEY, &amp;tcp_ao,
	sizeof(tcp_ao));
	setsockopt(sk, IPPROTO_TCP, TCP_REPAIR, &amp;one, sizeof(one));</p>
<p>sockaddr.sin_family = AF_INET;
	sockaddr.sin_port = htobe16(123);</p>
<p>inet_aton("127.0.0.1", &amp;sockaddr.sin_addr);</p>
<p>connect(sk,(struct sockaddr *)&amp;sockaddr,sizeof(sockaddr));</p>
<p>return 0;
}</p>
<p>$ gcc tcp-ao-nullptr.c -o tcp-ao-nullptr -Wall
$ unshare -Urn</p>
<p>BUG: ke…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-39950"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-f4h6-hf7g-852r</id>
    <title>GHSA-f4h6-hf7g-852r</title>
    <updated>2026-10-04T03:26:49.646194+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>net/tcp: Fix a NULL pointer dereference when using TCP-AO with TCP_REPAIR</p>
<p>A NULL pointer dereference can occur in tcp_ao_finish_connect() during a
connect() system call on a socket with a TCP-AO key added and TCP_REPAIR
enabled.</p>
<p>The function is called with skb being NULL and attempts to dereference it
on tcp_hdr(skb)-&gt;seq without a prior skb validation.</p>
<p>Fix this by checking if skb is NULL before dereferencing it.</p>
<p>The commentary is taken from bpf_skops_established(), which is also called
in the same flow. Unlike the function being patched,
bpf_skops_established() validates the skb before dereferencing it.</p>
<p>int main(void){
	struct sockaddr_in sockaddr;
	struct tcp_ao_add tcp_ao;
	int sk;
	int one = 1;</p>
<p>memset(&amp;sockaddr,'\0',sizeof(sockaddr));
	memset(&amp;tcp_ao,'\0',sizeof(tcp_ao));</p>
<p>sk = socket(AF_INET, SOCK_STREAM, IPPROTO_TCP);</p>
<p>sockaddr.sin_family = AF_INET;</p>
<p>memcpy(tcp_ao.alg_name,"cmac(aes128)",12);
	memcpy(tcp_ao.key,"ABCDEFGHABCDEFGH",16);
	tcp_ao.keylen = 16;</p>
<p>memcpy(&amp;tcp_ao.addr,&amp;sockaddr,sizeof(sockaddr));</p>
<p>setsockopt(sk, IPPROTO_TCP, TCP_AO_ADD_KEY, &amp;tcp_ao,
	sizeof(tcp_ao));
	setsockopt(sk, IPPROTO_TCP, TCP_REPAIR, &amp;one, sizeof(one));</p>
<p>sockaddr.sin_family = AF_INET;
	sockaddr.sin_port = htobe16(123);</p>
<p>inet_aton("127.0.0.1", &amp;sockaddr.sin_addr);</p>
<p>connect(sk,(struct sockaddr *)&amp;sockaddr,sizeof(sockaddr));</p>
<p>return 0;
}</p>
<p>$ gcc tcp-ao-nullptr.c -o tcp-ao-nullptr -Wall
$ unshare -Urn</p>
<p>BUG: ke…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-f4h6-hf7g-852r"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2025:20091-1</id>
    <title>openSUSE-SU-2025:20091-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-04T03:26:49.646235+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2025:20091-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2025:21080-1</id>
    <title>SUSE-SU-2025:21080-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-04T03:26:49.646349+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2025:21080-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-39950</id>
    <title>UBUNTU-CVE-2025-39950</title>
    <updated>2026-10-04T03:26:49.646411+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 124 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: net/tcp: Fix a NULL pointer dereference when using TCP-AO with TCP_REPAIR A NULL pointer dereference can occur in tcp_ao_finish_connect() during a connect() system call on a socket with a TCP-AO key added and TCP_REPAIR enabled. The function is called with skb being NULL and attempts to dereference it on tcp_hdr(skb)-&gt;seq without a prior skb validation. Fix this by checking if skb is NULL before dereferencing it. The commentary is taken from bpf_skops_established(), which is also called in the same flow. Unlike the function being patched, bpf_skops_established() validates the skb before dereferencing it. int main(void){ 	struct sockaddr_in sockaddr; 	struct tcp_ao_add tcp_ao; 	int sk; 	int one = 1; 	memset(&amp;sockaddr,'\0',sizeof(sockaddr)); 	memset(&amp;tcp_ao,'\0',sizeof(tcp_ao)); 	sk = socket(AF_INET, SOCK_STREAM, IPPROTO_TCP); 	sockaddr.sin_family = AF_INET; 	memcpy(tcp_ao.alg_name,"cmac(aes128)",12); 	memcpy(tcp_ao.key,"ABCDEFGHABCDEFGH",16); 	tcp_ao.keylen = 16; 	memcpy(&amp;tcp_ao.addr,&amp;sockaddr,sizeof(sockaddr)); 	setsockopt(sk, IPPROTO_TCP, TCP_AO_ADD_KEY, &amp;tcp_ao, 	sizeof(tcp_ao)); 	setsockopt(sk, IPPROTO_TCP, TCP_REPAIR, &amp;one, sizeof(one)); 	sockaddr.sin_family = AF_INET; 	sockaddr.sin_port = htobe16(123); 	inet_aton("127.0.0.1", &amp;sockaddr.sin_addr); 	connect(sk,(struct sockaddr *)&amp;sockaddr,sizeof(sockaddr)); return 0; } $ gcc tcp-ao-nullptr.c -o tcp-ao-nullptr -Wall $ unshare -Urn BUG: kernel NULL pointer…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-39950"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2194</id>
    <title>WID-SEC-W-2025-2194 — Linux Kernel: Mehrere Schwachstellen</title>
    <updated>2026-10-04T03:26:49.646588+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein lokaler Angreifer kann mehrere Schwachstellen in Linux Kernel ausnutzen, um nicht näher spezifizierte Angriffe durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2194"/>
  </entry>
</feed>
