<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T02:22:14.535415+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-14654</id>
    <title>bdu:2025-14654</title>
    <updated>2026-10-04T02:22:14.634220+00:00</updated>
    <content>bdu:2025-14654</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-14654"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2025-40205</id>
    <title>BELL-CVE-2025-40205</title>
    <updated>2026-10-04T02:22:14.634269+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2025-40205"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-1048</id>
    <title>certfr-2025-avi-1048 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de Debian LTS. Certaines d'entre elles permettent à…</title>
    <updated>2026-10-04T02:22:14.634301+00:00</updated>
    <content>certfr-2025-avi-1048</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-1048"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-347375</id>
    <title>EUVD-2026-347375</title>
    <updated>2026-10-04T02:22:14.634319+00:00</updated>
    <content>EUVD-2026-347375</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-347375"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-40205</id>
    <title>fkie_cve-2025-40205</title>
    <updated>2026-10-04T02:22:14.634330+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>btrfs: avoid potential out-of-bounds in btrfs_encode_fh()</p>
<p>The function btrfs_encode_fh() does not properly account for the three
cases it handles.</p>
<p>Before writing to the file handle (fh), the function only returns to the
user BTRFS_FID_SIZE_NON_CONNECTABLE (5 dwords, 20 bytes) or
BTRFS_FID_SIZE_CONNECTABLE (8 dwords, 32 bytes).</p>
<p>However, when a parent exists and the root ID of the parent and the
inode are different, the function writes BTRFS_FID_SIZE_CONNECTABLE_ROOT
(10 dwords, 40 bytes).</p>
<p>If *max_len is not large enough, this write goes out of bounds because
BTRFS_FID_SIZE_CONNECTABLE_ROOT is greater than
BTRFS_FID_SIZE_CONNECTABLE originally returned.</p>
<p>This results in an 8-byte out-of-bounds write at
fid-&gt;parent_root_objectid = parent_root_id.</p>
<p>A previous attempt to fix this issue was made but was lost.</p>
<p>https://lore.kernel.org/all/4CADAEEC020000780001B32C@vpn.id2.novell.com/</p>
<p>Although this issue does not seem to be easily triggerable, it is a
potential memory corruption bug that should be fixed. This patch
resolves the issue by ensuring the function returns the appropriate size
for all three cases and validates that *max_len is large enough before
writing any data.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-40205"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-7v4m-qg52-mxg3</id>
    <title>GHSA-7v4m-qg52-mxg3</title>
    <updated>2026-10-04T02:22:14.634374+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>btrfs: avoid potential out-of-bounds in btrfs_encode_fh()</p>
<p>The function btrfs_encode_fh() does not properly account for the three
cases it handles.</p>
<p>Before writing to the file handle (fh), the function only returns to the
user BTRFS_FID_SIZE_NON_CONNECTABLE (5 dwords, 20 bytes) or
BTRFS_FID_SIZE_CONNECTABLE (8 dwords, 32 bytes).</p>
<p>However, when a parent exists and the root ID of the parent and the
inode are different, the function writes BTRFS_FID_SIZE_CONNECTABLE_ROOT
(10 dwords, 40 bytes).</p>
<p>If *max_len is not large enough, this write goes out of bounds because
BTRFS_FID_SIZE_CONNECTABLE_ROOT is greater than
BTRFS_FID_SIZE_CONNECTABLE originally returned.</p>
<p>This results in an 8-byte out-of-bounds write at
fid-&gt;parent_root_objectid = parent_root_id.</p>
<p>A previous attempt to fix this issue was made but was lost.</p>
<p>https://lore.kernel.org/all/4CADAEEC020000780001B32C@vpn.id2.novell.com/</p>
<p>Although this issue does not seem to be easily triggerable, it is a
potential memory corruption bug that should be fixed. This patch
resolves the issue by ensuring the function returns the appropriate size
for all three cases and validates that *max_len is large enough before
writing any data.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-7v4m-qg52-mxg3"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2025-40205</id>
    <title>msrc_CVE-2025-40205 — btrfs: avoid potential out-of-bounds in btrfs_encode_fh()</title>
    <updated>2026-10-04T02:22:14.634401+00:00</updated>
    <content>msrc_CVE-2025-40205</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2025-40205"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-1950</id>
    <title>OESA-2026-1950 — kernel security update</title>
    <updated>2026-10-04T02:22:14.634418+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:22.03-LTS-SP4: kernel</p>
<p>The Linux Kernel, the operating system core itself.

Security Fix(es):</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>btrfs: fix extent map use-after-free when handling missing device in read_one_chunk</p>
<p>Store the error code before freeing the extent_map. Though it&amp;apos;s
reference counted structure, in that function it&amp;apos;s the first and last
allocation so this would lead to a potential use-after-free.</p>
<p>The error can happen eg. when chunk is stored on a missing device and
the degraded mount option is missing.</p>
<p>Bugzilla: https://bugzilla.kernel.org/show_bug.cgi?id=216721(CVE-2022-50300)</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>parisc: Fix locking in pdc_iodc_print() firmware call</p>
<p>Utilize pdc_lock spinlock to protect parallel modifications of the
iodc_dbuf[] buffer, check length to prevent buffer overflow of
iodc_dbuf[], drop the iodc_retbuf[] buffer and fix some wrong
indentings.(CVE-2022-50518)</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>fs/ntfs3: Add length check in indx_get_root</p>
<p>This adds a length check to guarantee the retrieved index root is legit.</p>
<p>[  162.459513] BUG: KASAN: use-after-free in hdr_find_e.isra.0+0x10c/0x320
[  162.460176] Read of size 2 at addr ffff8880037bca99 by task mount/243
[  162.460851]
[  162.461252] CPU: 0 PID: 243 Comm: mount Not tainted 6.0.0-rc7 #42
[  162.461744] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.14.0-0-g155821a1990b-prebuilt.qe…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-1950"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2025:20172-1</id>
    <title>openSUSE-SU-2025:20172-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-04T02:22:14.634528+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2025:20172-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2025:4422-1</id>
    <title>SUSE-SU-2025:4422-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-04T02:22:14.634607+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2025:4422-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-40205</id>
    <title>UBUNTU-CVE-2025-40205</title>
    <updated>2026-10-04T02:22:14.634663+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: linux, Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe and 228 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: btrfs: avoid potential out-of-bounds in btrfs_encode_fh() The function btrfs_encode_fh() does not properly account for the three cases it handles. Before writing to the file handle (fh), the function only returns to the user BTRFS_FID_SIZE_NON_CONNECTABLE (5 dwords, 20 bytes) or BTRFS_FID_SIZE_CONNECTABLE (8 dwords, 32 bytes). However, when a parent exists and the root ID of the parent and the inode are different, the function writes BTRFS_FID_SIZE_CONNECTABLE_ROOT (10 dwords, 40 bytes). If *max_len is not large enough, this write goes out of bounds because BTRFS_FID_SIZE_CONNECTABLE_ROOT is greater than BTRFS_FID_SIZE_CONNECTABLE originally returned. This results in an 8-byte out-of-bounds write at fid-&gt;parent_root_objectid = parent_root_id. A previous attempt to fix this issue was made but was lost. https://lore.kernel.org/all/4CADAEEC020000780001B32C@vpn.id2.novell.com/ Although this issue does not seem to be easily triggerable, it is a potential memory corruption bug that should be fixed. This patch resolves the issue by ensuring the function returns the appropriate size for all three cases and validates that *max_len is large enough before writing any data.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-40205"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2595</id>
    <title>WID-SEC-W-2025-2595 — Linux Kernel: Mehrere Schwachstellen</title>
    <updated>2026-10-04T02:22:14.634978+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen im Linux-Kernel ausnutzen, um nicht näher spezifizierte Angriffe durchzuführen, die möglicherweise zu einer Denial-of-Service- Bedingung führen oder eine Speicherbeschädigung verursachen können.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2595"/>
  </entry>
</feed>
