<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T12:31:48.907773+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:67471</id>
    <title>ALSA-2026:67471 — Important: kernel security, bug fix, and enhancement update</title>
    <updated>2026-10-03T12:31:49.403546+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:10: kernel, AlmaLinux:10: kernel-64k, AlmaLinux:10: kernel-64k-core, AlmaLinux:10: kernel-64k-debug, AlmaLinux:10: kernel-64k-debug-core, AlmaLinux:10: kernel-64k-debug-devel, AlmaLinux:10: kernel-64k-debug-devel-matched, AlmaLinux:10: kernel-64k-debug-modules, AlmaLinux:10: kernel-64k-debug-modules-core, AlmaLinux:10: kernel-64k-debug-modules-extra and 65 more</p>
<p>The kernel packages contain the Linux kernel, the core of any Linux operating system.</p>
<p>Security Fix(es):</p>
<p>* kernel: tls: Use __sk_dst_get() and dst_dev_rcu() in get_netdev_for_sock() (CVE-2025-40149)
  * kernel: Linux kernel: Denial of Service in qla2xxx SCSI driver due to improper command handling after chip reset (CVE-2025-68745)
  * kernel: drm/xe: Open-code GGTT MMIO access protection (CVE-2026-23466)
  * kernel: drm/xe: always keep track of remap prev/next (CVE-2026-31479)
  * kernel: drm/amdgpu: Fix fence put before wait in amdgpu_amdkfd_submit_ib (CVE-2026-31566)
  * kernel: xfrm: hold dev ref until after transport_finish NF_HOOK (CVE-2026-31663)
  * kernel: drm/i915/gt: fix refcount underflow in intel_engine_park_heartbeat (CVE-2026-31656)
  * kernel: smb: smbdirect: introduce smbdirect_socket.recv_io.credits.available (CVE-2026-31539)
  * kernel: vhost: move vdpa group bound check to vhost_vdpa (CVE-2026-43248)
  * kernel: drm/i915: Fix potential overflow of shmem scatterlist length (CVE-2026-43368)
  * kernel: drm/amdgpu: Fix use-after-free race in VM acquire (CVE-2026-43370)
  * kernel: scsi: target: configfs: Bound snprintf() return in tg_pt_gp_members_show() (CVE-2026-46149)
  * kernel: sctp: purge outqueue on stale COOKIE-ECHO handling (CVE-2026-52924)
  * kernel: netfilter: require Ethernet MAC header before using eth_hdr() (CVE-2026-53131)
  * kernel: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing (CVE-2026-53246)
  * kernel: xfr…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:67471"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-14952</id>
    <title>bdu:2025-14952</title>
    <updated>2026-10-03T12:31:49.403773+00:00</updated>
    <content>bdu:2025-14952</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-14952"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2025-40149</id>
    <title>BELL-CVE-2025-40149</title>
    <updated>2026-10-03T12:31:49.403795+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2025-40149"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-1133</id>
    <title>certfr-2025-avi-1133 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de SUSE. Certaines d'entre elles permettent à un at…</title>
    <updated>2026-10-03T12:31:49.403818+00:00</updated>
    <content>certfr-2025-avi-1133</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-1133"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-364577</id>
    <title>EUVD-2026-364577</title>
    <updated>2026-10-03T12:31:49.403834+00:00</updated>
    <content>EUVD-2026-364577</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-364577"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-40149</id>
    <title>fkie_cve-2025-40149</title>
    <updated>2026-10-03T12:31:49.403846+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>tls: Use __sk_dst_get() and dst_dev_rcu() in get_netdev_for_sock().</p>
<p>get_netdev_for_sock() is called during setsockopt(),
so not under RCU.</p>
<p>Using sk_dst_get(sk)-&gt;dev could trigger UAF.</p>
<p>Let's use __sk_dst_get() and dst_dev_rcu().</p>
<p>Note that the only -&gt;ndo_sk_get_lower_dev() user is
bond_sk_get_lower_dev(), which uses RCU.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-40149"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-f2w5-mmwp-c76h</id>
    <title>GHSA-f2w5-mmwp-c76h</title>
    <updated>2026-10-03T12:31:49.403873+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>tls: Use __sk_dst_get() and dst_dev_rcu() in get_netdev_for_sock().</p>
<p>get_netdev_for_sock() is called during setsockopt(),
so not under RCU.</p>
<p>Using sk_dst_get(sk)-&gt;dev could trigger UAF.</p>
<p>Let's use __sk_dst_get() and dst_dev_rcu().</p>
<p>Note that the only -&gt;ndo_sk_get_lower_dev() user is
bond_sk_get_lower_dev(), which uses RCU.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-f2w5-mmwp-c76h"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-26-209-04</id>
    <title>ICSA-26-209-04 — Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</title>
    <updated>2026-10-03T12:31:49.403893+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.6 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant).</p>
<p>Siemens is preparing fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-26-209-04"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2025-40149</id>
    <title>msrc_CVE-2025-40149 — tls: Use __sk_dst_get() and dst_dev_rcu() in get_netdev_for_sock().</title>
    <updated>2026-10-03T12:31:49.404126+00:00</updated>
    <content>msrc_CVE-2025-40149</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2025-40149"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2025-2772</id>
    <title>OESA-2025-2772 — kernel security update</title>
    <updated>2026-10-03T12:31:49.404143+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:22.03-LTS-SP3: kernel</p>
<p>The Linux Kernel, the operating system core itself.

Security Fix(es):</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>media: davinci: vpif: fix use-after-free on driver unbind</p>
<p>The driver allocates and registers two platform device structures during
probe, but the devices were never deregistered on driver unbind.</p>
<p>This results in a use-after-free on driver unbind as the device
structures were allocated using devres and would be freed by driver
core when remove() returns.</p>
<p>Fix this by adding the missing deregistration calls to the remove()
callback and failing probe on registration errors.</p>
<p>Note that the platform device structures must be freed using a proper
release callback to avoid leaking associated resources like device
names.(CVE-2021-47653)</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>mmc: core: use sysfs_emit() instead of sprintf()</p>
<p>sprintf() (still used in the MMC core for the sysfs output) is vulnerable
to the buffer overflow.  Use the new-fangled sysfs_emit() instead.</p>
<p>Found by Linux Verification Center (linuxtesting.org) with the SVACE static
analysis tool.(CVE-2022-49267)</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>Bluetooth: btmtksdio: fix use-after-free at btmtksdio_recv_event</p>
<p>We should not access skb buffer data anymore after hci_recv_frame was
called.</p>
<p>[   39.634809] BUG: KASAN: use-after-free in btmtksdio_recv_event+0x1b0
[   39.634855] Read of size 1 at addr ffffff80cf28a60d by tas…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2025-2772"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2025:20172-1</id>
    <title>openSUSE-SU-2025:20172-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-03T12:31:49.404251+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2025:20172-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:64767</id>
    <title>RHSA-2026:64767 — Red Hat Security Advisory: kernel security, bug fix, and enhancement update</title>
    <updated>2026-10-03T12:31:49.404326+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>kernel: tls: Use __sk_dst_get() and dst_dev_rcu() in get_netdev_for_sock() kernel: netfilter: nft_set_pipapo_avx2: don't return non-matching entry on expiry kernel: Bluetooth: hci_event: fix potential UAF in SSP passkey handlers kernel: net: ipv6: fix NOREF dst use in seg6 and rpl lwtunnels kernel: RDMA/mana: Validate rx_hash_key_len kernel: smb/client: fix out-of-bounds read in smb2_compound_op() kernel: ipv6: fix possible UAF in icmpv6_rcv() kernel: crypto: ccp - copy IV using skcipher ivsize kernel: scsi: target: iscsi: Validate CHAP_R length before base64 decode kernel: crypto: qat - validate RSA CRT component lengths</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:64767"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:67471</id>
    <title>RLSA-2026:67471 — Important: kernel security, bug fix, and enhancement update</title>
    <updated>2026-10-03T12:31:49.404363+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:10: kernel</p>
<p>The kernel packages contain the Linux kernel, the core of any Linux operating system.</p>
<p>Security Fix(es):</p>
<p>* kernel: tls: Use __sk_dst_get() and dst_dev_rcu() in get_netdev_for_sock() (CVE-2025-40149)</p>
<p>* kernel: Linux kernel: Denial of Service in qla2xxx SCSI driver due to improper command handling after chip reset (CVE-2025-68745)</p>
<p>* kernel: drm/xe: Open-code GGTT MMIO access protection (CVE-2026-23466)</p>
<p>* kernel: drm/xe: always keep track of remap prev/next (CVE-2026-31479)</p>
<p>* kernel: drm/amdgpu: Fix fence put before wait in amdgpu_amdkfd_submit_ib (CVE-2026-31566)</p>
<p>* kernel: xfrm: hold dev ref until after transport_finish NF_HOOK (CVE-2026-31663)</p>
<p>* kernel: drm/i915/gt: fix refcount underflow in intel_engine_park_heartbeat (CVE-2026-31656)</p>
<p>* kernel: smb: smbdirect: introduce smbdirect_socket.recv_io.credits.available (CVE-2026-31539)</p>
<p>* kernel: vhost: move vdpa group bound check to vhost_vdpa (CVE-2026-43248)</p>
<p>* kernel: drm/i915: Fix potential overflow of shmem scatterlist length (CVE-2026-43368)</p>
<p>* kernel: drm/amdgpu: Fix use-after-free race in VM acquire (CVE-2026-43370)</p>
<p>* kernel: scsi: target: configfs: Bound snprintf() return in tg_pt_gp_members_show() (CVE-2026-46149)</p>
<p>* kernel: sctp: purge outqueue on stale COOKIE-ECHO handling (CVE-2026-52924)</p>
<p>* kernel: netfilter: require Ethernet MAC header before using eth_hdr() (CVE-2026-53131)</p>
<p>* kernel: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing (CVE-2026-53246)</p>
<p>* kernel: xfrm: policy: fix use-af…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:67471"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ssa-019113</id>
    <title>SSA-019113 — SSA-019113: Vulnerabilities in the additional GNU/Linux subsystem of the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1.6</title>
    <updated>2026-10-03T12:31:49.404410+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.6 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant).</p>
<p>Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ssa-019113"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2025:4422-1</id>
    <title>SUSE-SU-2025:4422-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-03T12:31:49.404652+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2025:4422-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-40149</id>
    <title>UBUNTU-CVE-2025-40149</title>
    <updated>2026-10-03T12:31:49.404716+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:Pro:18.04:LTS: linux-aws-5.4, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:Pro:18.04:LTS: linux-azure-5.4, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3 and 201 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: tls: Use __sk_dst_get() and dst_dev_rcu() in get_netdev_for_sock(). get_netdev_for_sock() is called during setsockopt(), so not under RCU. Using sk_dst_get(sk)-&gt;dev could trigger UAF. Let's use __sk_dst_get() and dst_dev_rcu(). Note that the only -&gt;ndo_sk_get_lower_dev() user is bond_sk_get_lower_dev(), which uses RCU.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-40149"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2579</id>
    <title>WID-SEC-W-2025-2579 — Linux Kernel: Mehrere Schwachstellen</title>
    <updated>2026-10-03T12:31:49.404952+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen im Linux-Kernel ausnutzen, um nicht näher spezifizierte Angriffe durchzuführen, die möglicherweise zu einer Denial-of-Service- Bedingung führen oder eine Speicherbeschädigung verursachen können.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2579"/>
  </entry>
</feed>
