<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T11:03:17.470307+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:18134</id>
    <title>ALSA-2026:18134 — Moderate: kernel security update</title>
    <updated>2026-10-03T11:03:17.656782+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:10: kernel, AlmaLinux:10: kernel-64k, AlmaLinux:10: kernel-64k-core, AlmaLinux:10: kernel-64k-debug, AlmaLinux:10: kernel-64k-debug-core, AlmaLinux:10: kernel-64k-debug-devel, AlmaLinux:10: kernel-64k-debug-devel-matched, AlmaLinux:10: kernel-64k-debug-modules, AlmaLinux:10: kernel-64k-debug-modules-core, AlmaLinux:10: kernel-64k-debug-modules-extra and 65 more</p>
<p>The kernel packages contain the Linux kernel, the core of any Linux operating system.</p>
<p>Security Fix(es):</p>
<p>* kernel: tcp_bpf: Fix the sk_mem_uncharge logic in tcp_bpf_sendmsg (CVE-2024-56633)
  * kernel: KVM: x86: Load DR6 with guest value only before entering .vcpu_run() loop (CVE-2025-21839)
  * kernel: block: fix resource leak in blk_register_queue() error path (CVE-2025-37980)
  * kernel: dmaengine: idxd: fix memory leak in error handling path of idxd_alloc (CVE-2025-38015)
  * kernel: espintcp: remove encap socket caching to avoid reference leak (CVE-2025-38097)
  * kernel: bpf: fix ktls panic with sockmap (CVE-2025-38166)
  * kernel: bpf: Check rcu_read_lock_trace_held() in bpf_map_lookup_percpu_elem() (CVE-2025-38202)
  * kernel: bpf: Do not include stack ptr register in precision backtracking bookkeeping (CVE-2025-38279)
  * kernel: ring-buffer: Do not trigger WARN_ON() due to a commit_overrun (CVE-2025-38267)
  * kernel: phy: qcom-qmp-usb: Fix an NULL vs IS_ERR() bug (CVE-2025-38275)
  * kernel: ftrace: Fix UAF when lookup kallsym after ftrace disabled (CVE-2025-38346)
  * kernel: ACPICA: fix acpi operand cache leak in dswstate.c (CVE-2025-38345)
  * kernel: nvmet: fix memory leak of bio integrity (CVE-2025-38405)
  * kernel: netfilter: flowtable: account for Ethernet header in nf_flow_pppoe_proto() (CVE-2025-38441)
  * kernel: net: vlan: fix VLAN 0 refcount imbalance of toggling filtering during runtime (CVE-2025-38470)
  * kernel: fs: writeback: fix use-after…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:18134"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-03986</id>
    <title>bdu:2026-03986</title>
    <updated>2026-10-03T11:03:17.656938+00:00</updated>
    <content>bdu:2026-03986</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-03986"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2025-40034</id>
    <title>BELL-CVE-2025-40034</title>
    <updated>2026-10-03T11:03:17.656958+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:stream: linux-lts</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2025-40034"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0169</id>
    <title>certfr-2026-avi-0169 — De multiples vulnérabilités ont été découvertes dans le noyau Linux d'Ubuntu. Certaines d'entre elles permettent à un a…</title>
    <updated>2026-10-03T11:03:17.656978+00:00</updated>
    <content>certfr-2026-avi-0169</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0169"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-314872</id>
    <title>EUVD-2026-314872</title>
    <updated>2026-10-03T11:03:17.656993+00:00</updated>
    <content>EUVD-2026-314872</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-314872"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-40034</id>
    <title>fkie_cve-2025-40034</title>
    <updated>2026-10-03T11:03:17.657004+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>PCI/AER: Avoid NULL pointer dereference in aer_ratelimit()</p>
<p>When platform firmware supplies error information to the OS, e.g., via the
ACPI APEI GHES mechanism, it may identify an error source device that
doesn't advertise an AER Capability and therefore dev-&gt;aer_info, which
contains AER stats and ratelimiting data, is NULL.</p>
<p>pci_dev_aer_stats_incr() already checks dev-&gt;aer_info for NULL, but
aer_ratelimit() did not, leading to NULL pointer dereferences like this one
from the URL below:</p>
<p>{1}[Hardware Error]: Hardware error from APEI Generic Hardware Error Source: 0
  {1}[Hardware Error]: event severity: corrected
  {1}[Hardware Error]:   device_id: 0000:00:00.0
  {1}[Hardware Error]:   vendor_id: 0x8086, device_id: 0x2020
  {1}[Hardware Error]:   aer_cor_status: 0x00001000, aer_cor_mask: 0x00002000
  BUG: kernel NULL pointer dereference, address: 0000000000000264
  RIP: 0010:___ratelimit+0xc/0x1b0
  pci_print_aer+0x141/0x360
  aer_recover_work_func+0xb5/0x130</p>
<p>[8086:2020] is an Intel "Sky Lake-E DMI3 Registers" device that claims to
be a Root Port but does not advertise an AER Capability.</p>
<p>Add a NULL check in aer_ratelimit() to avoid the NULL pointer dereference.
Note that this also prevents ratelimiting these events from GHES.</p>
<p>[bhelgaas: add crash details to commit log]</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-40034"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-4wjr-gmwc-pw8f</id>
    <title>GHSA-4wjr-gmwc-pw8f</title>
    <updated>2026-10-03T11:03:17.657041+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>PCI/AER: Avoid NULL pointer dereference in aer_ratelimit()</p>
<p>When platform firmware supplies error information to the OS, e.g., via the
ACPI APEI GHES mechanism, it may identify an error source device that
doesn't advertise an AER Capability and therefore dev-&gt;aer_info, which
contains AER stats and ratelimiting data, is NULL.</p>
<p>pci_dev_aer_stats_incr() already checks dev-&gt;aer_info for NULL, but
aer_ratelimit() did not, leading to NULL pointer dereferences like this one
from the URL below:</p>
<p>{1}[Hardware Error]: Hardware error from APEI Generic Hardware Error Source: 0
  {1}[Hardware Error]: event severity: corrected
  {1}[Hardware Error]:   device_id: 0000:00:00.0
  {1}[Hardware Error]:   vendor_id: 0x8086, device_id: 0x2020
  {1}[Hardware Error]:   aer_cor_status: 0x00001000, aer_cor_mask: 0x00002000
  BUG: kernel NULL pointer dereference, address: 0000000000000264
  RIP: 0010:___ratelimit+0xc/0x1b0
  pci_print_aer+0x141/0x360
  aer_recover_work_func+0xb5/0x130</p>
<p>[8086:2020] is an Intel "Sky Lake-E DMI3 Registers" device that claims to
be a Root Port but does not advertise an AER Capability.</p>
<p>Add a NULL check in aer_ratelimit() to avoid the NULL pointer dereference.
Note that this also prevents ratelimiting these events from GHES.</p>
<p>[bhelgaas: add crash details to commit log]</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-4wjr-gmwc-pw8f"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15702-1</id>
    <title>openSUSE-SU-2025:15702-1 — kernel-devel-6.17.7-1.1 on GA media</title>
    <updated>2026-10-03T11:03:17.657069+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>kernel-devel-6.17.7-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2025:15702-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:18134</id>
    <title>RHSA-2026:18134 — Red Hat Security Advisory: kernel security update</title>
    <updated>2026-10-03T11:03:17.657139+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>kernel: tcp_bpf: Fix the sk_mem_uncharge logic in tcp_bpf_sendmsg kernel: KVM: x86: Load DR6 with guest value only before entering .vcpu_run() loop kernel: ceph: kernel: Ceph: exploit of hardcoded IVECs, in a misuse of AES, resulting in authentication bypass kernel: block: fix resource leak in blk_register_queue() error path kernel: dmaengine: idxd: fix memory leak in error handling path of idxd_alloc kernel: espintcp: remove encap socket caching to avoid reference leak kernel: bpf: fix ktls panic with sockmap kernel: bpf: Check rcu_read_lock_trace_held() in bpf_map_lookup_percpu_elem() kernel: ring-buffer: Do not trigger WARN_ON() due to a commit_overrun kernel: phy: qcom-qmp-usb: Fix an NULL vs IS_ERR() bug kernel: bpf: Do not include stack ptr register in precision backtracking bookkeeping kernel: ACPICA: fix acpi operand cache leak in dswstate.c kernel: ftrace: Fix UAF when lookup kallsym after ftrace disabled kernel: nvmet: fix memory leak of bio integrity kernel: netfilter: flowtable: account for Ethernet header in nf_flow_pppoe_proto() kernel: net: vlan: fix VLAN 0 refcount imbalance of toggling filtering during runtime kernel: xfrm: Duplicate SPI Handling kernel: fs: writeback: fix use-after-free in __mark_inode_dirty() kernel: PCI/AER: Avoid NULL pointer dereference in aer_ratelimit() kernel: dm: fix NULL pointer dereference in __dm_suspend() kernel: Revert "NFSD: Remove the cap on number of operations per NFSv4 COMPOUND" kernel: Linux kernel MPTCP: Privilege escala…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:18134"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-40034</id>
    <title>UBUNTU-CVE-2025-40034</title>
    <updated>2026-10-03T11:03:17.657209+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 92 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: PCI/AER: Avoid NULL pointer dereference in aer_ratelimit() When platform firmware supplies error information to the OS, e.g., via the ACPI APEI GHES mechanism, it may identify an error source device that doesn't advertise an AER Capability and therefore dev-&gt;aer_info, which contains AER stats and ratelimiting data, is NULL. pci_dev_aer_stats_incr() already checks dev-&gt;aer_info for NULL, but aer_ratelimit() did not, leading to NULL pointer dereferences like this one from the URL below:   {1}[Hardware Error]: Hardware error from APEI Generic Hardware Error Source: 0   {1}[Hardware Error]: event severity: corrected   {1}[Hardware Error]:   device_id: 0000:00:00.0   {1}[Hardware Error]:   vendor_id: 0x8086, device_id: 0x2020   {1}[Hardware Error]:   aer_cor_status: 0x00001000, aer_cor_mask: 0x00002000   BUG: kernel NULL pointer dereference, address: 0000000000000264   RIP: 0010:___ratelimit+0xc/0x1b0   pci_print_aer+0x141/0x360   aer_recover_work_func+0xb5/0x130 [8086:2020] is an Intel "Sky Lake-E DMI3 Registers" device that claims to be a Root Port but does not advertise an AER Capability. Add a NULL check in aer_ratelimit() to avoid the NULL pointer dereference. Note that this also prevents ratelimiting these events from GHES. [bhelgaas: add crash details to commit log]</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-40034"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2431</id>
    <title>WID-SEC-W-2025-2431 — Linux Kernel: Mehrere Schwachstellen</title>
    <updated>2026-10-03T11:03:17.657356+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein lokaler Angreifer kann mehrere Schwachstellen im Linux-Kernel ausnutzen, um beliebigen Code auszuführen, privilegierten Zugriff zu erlangen, sensible Informationen zu stehlen oder betroffene Systeme funktionsunfähig zu machen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2431"/>
  </entry>
</feed>
