<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T13:07:27.312707+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-13639</id>
    <title>bdu:2025-13639</title>
    <updated>2026-10-03T13:07:27.913962+00:00</updated>
    <content>bdu:2025-13639</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-13639"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2025-40049</id>
    <title>BELL-CVE-2025-40049</title>
    <updated>2026-10-03T13:07:27.914067+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2025-40049"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0941</id>
    <title>certfr-2025-avi-0941 — De multiples vulnérabilités ont été découvertes dans les produits Microsoft. Elles permettent à un attaquant de provoqu…</title>
    <updated>2026-10-03T13:07:27.914105+00:00</updated>
    <content>certfr-2025-avi-0941</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-0941"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-314878</id>
    <title>EUVD-2026-314878</title>
    <updated>2026-10-03T13:07:27.914123+00:00</updated>
    <content>EUVD-2026-314878</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-314878"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-40049</id>
    <title>fkie_cve-2025-40049</title>
    <updated>2026-10-03T13:07:27.914134+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>Squashfs: fix uninit-value in squashfs_get_parent</p>
<p>Syzkaller reports a "KMSAN: uninit-value in squashfs_get_parent" bug.</p>
<p>This is caused by open_by_handle_at() being called with a file handle
containing an invalid parent inode number.  In particular the inode number
is that of a symbolic link, rather than a directory.</p>
<p>Squashfs_get_parent() gets called with that symbolic link inode, and
accesses the parent member field.</p>
<p>unsigned int parent_ino = squashfs_i(inode)-&gt;parent;</p>
<p>Because non-directory inodes in Squashfs do not have a parent value, this
is uninitialised, and this causes an uninitialised value access.</p>
<p>The fix is to initialise parent with the invalid inode 0, which will cause
an EINVAL error to be returned.</p>
<p>Regular inodes used to share the parent field with the block_list_start
field.  This is removed in this commit to enable the parent field to
contain the invalid inode number 0.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-40049"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-pq9p-38r9-fjq5</id>
    <title>GHSA-pq9p-38r9-fjq5</title>
    <updated>2026-10-03T13:07:27.914174+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>Squashfs: fix uninit-value in squashfs_get_parent</p>
<p>Syzkaller reports a "KMSAN: uninit-value in squashfs_get_parent" bug.</p>
<p>This is caused by open_by_handle_at() being called with a file handle
containing an invalid parent inode number.  In particular the inode number
is that of a symbolic link, rather than a directory.</p>
<p>Squashfs_get_parent() gets called with that symbolic link inode, and
accesses the parent member field.</p>
<p>unsigned int parent_ino = squashfs_i(inode)-&gt;parent;</p>
<p>Because non-directory inodes in Squashfs do not have a parent value, this
is uninitialised, and this causes an uninitialised value access.</p>
<p>The fix is to initialise parent with the invalid inode 0, which will cause
an EINVAL error to be returned.</p>
<p>Regular inodes used to share the parent field with the block_list_start
field.  This is removed in this commit to enable the parent field to
contain the invalid inode number 0.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-pq9p-38r9-fjq5"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2025-40049</id>
    <title>msrc_CVE-2025-40049 — Squashfs: fix uninit-value in squashfs_get_parent</title>
    <updated>2026-10-03T13:07:27.914200+00:00</updated>
    <content>msrc_CVE-2025-40049</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2025-40049"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2025-2772</id>
    <title>OESA-2025-2772 — kernel security update</title>
    <updated>2026-10-03T13:07:27.914218+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:22.03-LTS-SP3: kernel</p>
<p>The Linux Kernel, the operating system core itself.

Security Fix(es):</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>media: davinci: vpif: fix use-after-free on driver unbind</p>
<p>The driver allocates and registers two platform device structures during
probe, but the devices were never deregistered on driver unbind.</p>
<p>This results in a use-after-free on driver unbind as the device
structures were allocated using devres and would be freed by driver
core when remove() returns.</p>
<p>Fix this by adding the missing deregistration calls to the remove()
callback and failing probe on registration errors.</p>
<p>Note that the platform device structures must be freed using a proper
release callback to avoid leaking associated resources like device
names.(CVE-2021-47653)</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>mmc: core: use sysfs_emit() instead of sprintf()</p>
<p>sprintf() (still used in the MMC core for the sysfs output) is vulnerable
to the buffer overflow.  Use the new-fangled sysfs_emit() instead.</p>
<p>Found by Linux Verification Center (linuxtesting.org) with the SVACE static
analysis tool.(CVE-2022-49267)</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>Bluetooth: btmtksdio: fix use-after-free at btmtksdio_recv_event</p>
<p>We should not access skb buffer data anymore after hci_recv_frame was
called.</p>
<p>[   39.634809] BUG: KASAN: use-after-free in btmtksdio_recv_event+0x1b0
[   39.634855] Read of size 1 at addr ffffff80cf28a60d by tas…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2025-2772"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15702-1</id>
    <title>openSUSE-SU-2025:15702-1 — kernel-devel-6.17.7-1.1 on GA media</title>
    <updated>2026-10-03T13:07:27.914328+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>kernel-devel-6.17.7-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2025:15702-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2025:21040-1</id>
    <title>SUSE-SU-2025:21040-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-03T13:07:27.914396+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2025:21040-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-40049</id>
    <title>UBUNTU-CVE-2025-40049</title>
    <updated>2026-10-03T13:07:27.914524+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: linux, Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe and 228 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: Squashfs: fix uninit-value in squashfs_get_parent Syzkaller reports a "KMSAN: uninit-value in squashfs_get_parent" bug. This is caused by open_by_handle_at() being called with a file handle containing an invalid parent inode number.  In particular the inode number is that of a symbolic link, rather than a directory. Squashfs_get_parent() gets called with that symbolic link inode, and accesses the parent member field. 	unsigned int parent_ino = squashfs_i(inode)-&gt;parent; Because non-directory inodes in Squashfs do not have a parent value, this is uninitialised, and this causes an uninitialised value access. The fix is to initialise parent with the invalid inode 0, which will cause an EINVAL error to be returned. Regular inodes used to share the parent field with the block_list_start field.  This is removed in this commit to enable the parent field to contain the invalid inode number 0.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-40049"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2431</id>
    <title>WID-SEC-W-2025-2431 — Linux Kernel: Mehrere Schwachstellen</title>
    <updated>2026-10-03T13:07:27.915066+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein lokaler Angreifer kann mehrere Schwachstellen im Linux-Kernel ausnutzen, um beliebigen Code auszuführen, privilegierten Zugriff zu erlangen, sensible Informationen zu stehlen oder betroffene Systeme funktionsunfähig zu machen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2431"/>
  </entry>
</feed>
