<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T01:54:20.224906+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2025-40090</id>
    <title>BELL-CVE-2025-40090</title>
    <updated>2026-10-04T01:54:20.335520+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:25: linux-lts</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2025-40090"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-347333</id>
    <title>EUVD-2026-347333</title>
    <updated>2026-10-04T01:54:20.335573+00:00</updated>
    <content>EUVD-2026-347333</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-347333"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-40090</id>
    <title>fkie_cve-2025-40090</title>
    <updated>2026-10-04T01:54:20.335588+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>ksmbd: fix recursive locking in RPC handle list access</p>
<p>Since commit 305853cce3794 ("ksmbd: Fix race condition in RPC handle list
access"), ksmbd_session_rpc_method() attempts to lock sess-&gt;rpc_lock.</p>
<p>This causes hung connections / tasks when a client attempts to open
a named pipe. Using Samba's rpcclient tool:</p>
<p>$ rpcclient //192.168.1.254 -U user%password
 $ rpcclient $&gt; srvinfo
 &lt;connection hung here&gt;</p>
<p>Kernel side:
  "echo 0 &gt; /proc/sys/kernel/hung_task_timeout_secs" disables this message.
  task:kworker/0:0 state:D stack:0 pid:5021 tgid:5021 ppid:2 flags:0x00200000
  Workqueue: ksmbd-io handle_ksmbd_work
  Call trace:
  __schedule from schedule+0x3c/0x58
  schedule from schedule_preempt_disabled+0xc/0x10
  schedule_preempt_disabled from rwsem_down_read_slowpath+0x1b0/0x1d8
  rwsem_down_read_slowpath from down_read+0x28/0x30
  down_read from ksmbd_session_rpc_method+0x18/0x3c
  ksmbd_session_rpc_method from ksmbd_rpc_open+0x34/0x68
  ksmbd_rpc_open from ksmbd_session_rpc_open+0x194/0x228
  ksmbd_session_rpc_open from create_smb2_pipe+0x8c/0x2c8
  create_smb2_pipe from smb2_open+0x10c/0x27ac
  smb2_open from handle_ksmbd_work+0x238/0x3dc
  handle_ksmbd_work from process_scheduled_works+0x160/0x25c
  process_scheduled_works from worker_thread+0x16c/0x1e8
  worker_thread from kthread+0xa8/0xb8
  kthread from ret_from_fork+0x14/0x38
  Exception stack(0x8529ffb0 to 0x8529fff8)</p>
<p>The task deadlocks because the…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-40090"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-m33j-r627-qphr</id>
    <title>GHSA-m33j-r627-qphr</title>
    <updated>2026-10-04T01:54:20.335635+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>ksmbd: fix recursive locking in RPC handle list access</p>
<p>Since commit 305853cce3794 ("ksmbd: Fix race condition in RPC handle list
access"), ksmbd_session_rpc_method() attempts to lock sess-&gt;rpc_lock.</p>
<p>This causes hung connections / tasks when a client attempts to open
a named pipe. Using Samba's rpcclient tool:</p>
<p>$ rpcclient //192.168.1.254 -U user%password
 $ rpcclient $&gt; srvinfo
 &lt;connection hung here&gt;</p>
<p>Kernel side:
  "echo 0 &gt; /proc/sys/kernel/hung_task_timeout_secs" disables this message.
  task:kworker/0:0 state:D stack:0 pid:5021 tgid:5021 ppid:2 flags:0x00200000
  Workqueue: ksmbd-io handle_ksmbd_work
  Call trace:
  __schedule from schedule+0x3c/0x58
  schedule from schedule_preempt_disabled+0xc/0x10
  schedule_preempt_disabled from rwsem_down_read_slowpath+0x1b0/0x1d8
  rwsem_down_read_slowpath from down_read+0x28/0x30
  down_read from ksmbd_session_rpc_method+0x18/0x3c
  ksmbd_session_rpc_method from ksmbd_rpc_open+0x34/0x68
  ksmbd_rpc_open from ksmbd_session_rpc_open+0x194/0x228
  ksmbd_session_rpc_open from create_smb2_pipe+0x8c/0x2c8
  create_smb2_pipe from smb2_open+0x10c/0x27ac
  smb2_open from handle_ksmbd_work+0x238/0x3dc
  handle_ksmbd_work from process_scheduled_works+0x160/0x25c
  process_scheduled_works from worker_thread+0x16c/0x1e8
  worker_thread from kthread+0xa8/0xb8
  kthread from ret_from_fork+0x14/0x38
  Exception stack(0x8529ffb0 to 0x8529fff8)</p>
<p>The task deadlocks because the…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-m33j-r627-qphr"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2025-40090</id>
    <title>msrc_CVE-2025-40090 — ksmbd: fix recursive locking in RPC handle list access</title>
    <updated>2026-10-04T01:54:20.335671+00:00</updated>
    <content>msrc_CVE-2025-40090</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2025-40090"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15702-1</id>
    <title>openSUSE-SU-2025:15702-1 — kernel-devel-6.17.7-1.1 on GA media</title>
    <updated>2026-10-04T01:54:20.335689+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>kernel-devel-6.17.7-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2025:15702-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-40090</id>
    <title>UBUNTU-CVE-2025-40090</title>
    <updated>2026-10-04T01:54:20.335749+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 77 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix recursive locking in RPC handle list access Since commit 305853cce3794 ("ksmbd: Fix race condition in RPC handle list access"), ksmbd_session_rpc_method() attempts to lock sess-&gt;rpc_lock. This causes hung connections / tasks when a client attempts to open a named pipe. Using Samba's rpcclient tool:  $ rpcclient //192.168.1.254 -U user%password  $ rpcclient $&gt; srvinfo  &lt;connection hung here&gt; Kernel side:   "echo 0 &gt; /proc/sys/kernel/hung_task_timeout_secs" disables this message.   task:kworker/0:0 state:D stack:0 pid:5021 tgid:5021 ppid:2 flags:0x00200000   Workqueue: ksmbd-io handle_ksmbd_work   Call trace:   __schedule from schedule+0x3c/0x58   schedule from schedule_preempt_disabled+0xc/0x10   schedule_preempt_disabled from rwsem_down_read_slowpath+0x1b0/0x1d8   rwsem_down_read_slowpath from down_read+0x28/0x30   down_read from ksmbd_session_rpc_method+0x18/0x3c   ksmbd_session_rpc_method from ksmbd_rpc_open+0x34/0x68   ksmbd_rpc_open from ksmbd_session_rpc_open+0x194/0x228   ksmbd_session_rpc_open from create_smb2_pipe+0x8c/0x2c8   create_smb2_pipe from smb2_open+0x10c/0x27ac   smb2_open from handle_ksmbd_work+0x238/0x3dc   handle_ksmbd_work from process_scheduled_works+0x160/0x25c   process_scheduled_works from worker_thread+0x16c/0x1e8   worker_thread from kthread+0xa8/0xb8   kthread from ret_from_fork+0x14/0x38   Exception stack(0x8529ffb0 to 0x8529fff8) The task deadlocks because the lock i…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-40090"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2450</id>
    <title>WID-SEC-W-2025-2450 — Linux Kernel: Mehrere Schwachstellen</title>
    <updated>2026-10-04T01:54:20.335888+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um nicht näher spezifizierte Angriffe durchzuführen, die möglicherweise zu einer Denial-of-Service-Situation führen oder eine Speicherbeschädigung verursachen können.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2450"/>
  </entry>
</feed>
