<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T15:49:22.982115+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:1661</id>
    <title>ALSA-2026:1661 — Moderate: kernel-rt security update</title>
    <updated>2026-10-02T15:49:23.325292+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: kernel-rt, AlmaLinux:8: kernel-rt-core, AlmaLinux:8: kernel-rt-debug, AlmaLinux:8: kernel-rt-debug-core, AlmaLinux:8: kernel-rt-debug-devel, AlmaLinux:8: kernel-rt-debug-modules, AlmaLinux:8: kernel-rt-debug-modules-extra, AlmaLinux:8: kernel-rt-devel, AlmaLinux:8: kernel-rt-modules, AlmaLinux:8: kernel-rt-modules-extra</p>
<p>The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements.</p>
<p>Security Fix(es):</p>
<p>* kernel: IB/hfi1: Fix sdma.h tx-&gt;num_descs off-by-one error (CVE-2024-26766)
  * kernel: RDMA/core: Fix "KASAN: slab-use-after-free Read in ib_register_device" problem (CVE-2025-38022)
  * kernel: Linux kernel: RDMA/rxe use-after-free vulnerability leading to potential arbitrary code execution (CVE-2025-38024)
  * kernel: Linux kernel: Memory corruption in Squashfs due to incorrect block size calculation (CVE-2025-38415)
  * kernel: Linux kernel: Denial of Service in ATM CLIP module via infinite recursion (CVE-2025-38459)
  * kernel: Linux kernel: Denial of Service via out-of-bounds read in USB configuration parsing (CVE-2025-39760)
  * kernel: mptcp: fix race condition in mptcp_schedule_work() (CVE-2025-40258)
  * kernel: Linux kernel: Use-after-free in proc_readdir_de() can lead to privilege escalation or denial of service. (CVE-2025-40271)
  * kernel: Linux kernel: Information disclosure and denial of service via out-of-bounds read in font glyph handling (CVE-2025-40322)
  * kernel: tcp: fix a signed-integer-overflow bug in tcp_add_backlog() (CVE-2022-50865)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:1661"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-05110</id>
    <title>bdu:2026-05110</title>
    <updated>2026-10-02T15:49:23.325408+00:00</updated>
    <content>bdu:2026-05110</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-05110"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2025-40271</id>
    <title>BELL-CVE-2025-40271</title>
    <updated>2026-10-02T15:49:23.325429+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2025-40271"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-1136</id>
    <title>certfr-2025-avi-1136 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de Debian LTS. Certaines d'entre elles permettent à…</title>
    <updated>2026-10-02T15:49:23.325453+00:00</updated>
    <content>certfr-2025-avi-1136</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-1136"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-347401</id>
    <title>EUVD-2026-347401</title>
    <updated>2026-10-02T15:49:23.325469+00:00</updated>
    <content>EUVD-2026-347401</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-347401"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-40271</id>
    <title>fkie_cve-2025-40271</title>
    <updated>2026-10-02T15:49:23.325481+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>fs/proc: fix uaf in proc_readdir_de()</p>
<p>Pde is erased from subdir rbtree through rb_erase(), but not set the node
to EMPTY, which may result in uaf access.  We should use RB_CLEAR_NODE()
set the erased node to EMPTY, then pde_subdir_next() will return NULL to
avoid uaf access.</p>
<p>We found an uaf issue while using stress-ng testing, need to run testcase
getdent and tun in the same time.  The steps of the issue is as follows:</p>
<p>1) use getdent to traverse dir /proc/pid/net/dev_snmp6/, and current
   pde is tun3;</p>
<p>2) in the [time windows] unregister netdevice tun3 and tun2, and erase
   them from rbtree.  erase tun3 first, and then erase tun2.  the
   pde(tun2) will be released to slab;</p>
<p>3) continue to getdent process, then pde_subdir_next() will return
   pde(tun2) which is released, it will case uaf access.</p>
<p>CPU 0                                      |    CPU 1
-------------------------------------------------------------------------
traverse dir /proc/pid/net/dev_snmp6/      |   unregister_netdevice(tun-&gt;dev)   //tun3 tun2
sys_getdents64()                           |
  iterate_dir()                            |
    proc_readdir()                         |
      proc_readdir_de()                    |     snmp6_unregister_dev()
        pde_get(de);                       |       proc_remove()
        read_unlock(&amp;proc_subdir_lock);    |         remove_proc_subtree()
                                           |…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-40271"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-r37x-wmxh-7hvh</id>
    <title>GHSA-r37x-wmxh-7hvh</title>
    <updated>2026-10-02T15:49:23.325525+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>fs/proc: fix uaf in proc_readdir_de()</p>
<p>Pde is erased from subdir rbtree through rb_erase(), but not set the node
to EMPTY, which may result in uaf access.  We should use RB_CLEAR_NODE()
set the erased node to EMPTY, then pde_subdir_next() will return NULL to
avoid uaf access.</p>
<p>We found an uaf issue while using stress-ng testing, need to run testcase
getdent and tun in the same time.  The steps of the issue is as follows:</p>
<p>1) use getdent to traverse dir /proc/pid/net/dev_snmp6/, and current
   pde is tun3;</p>
<p>2) in the [time windows] unregister netdevice tun3 and tun2, and erase
   them from rbtree.  erase tun3 first, and then erase tun2.  the
   pde(tun2) will be released to slab;</p>
<p>3) continue to getdent process, then pde_subdir_next() will return
   pde(tun2) which is released, it will case uaf access.</p>
<p>CPU 0                                      |    CPU 1
-------------------------------------------------------------------------
traverse dir /proc/pid/net/dev_snmp6/      |   unregister_netdevice(tun-&gt;dev)   //tun3 tun2
sys_getdents64()                           |
  iterate_dir()                            |
    proc_readdir()                         |
      proc_readdir_de()                    |     snmp6_unregister_dev()
        pde_get(de);                       |       proc_remove()
        read_unlock(&amp;proc_subdir_lock);    |         remove_proc_subtree()
                                           |…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-r37x-wmxh-7hvh"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-26-188-05</id>
    <title>ICSA-26-188-05 — Siemens SINEC OS</title>
    <updated>2026-10-02T15:49:23.325560+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A vulnerability has been found in GNU elfutils 0.192 and classified as critical. This vulnerability affects the function __libdw_thread_tail in the library libdw_alloc.c of the component eu-readelf. The manipulation of the argument w leads to memory corruption. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The name of the patch is 2636426a091bd6c6f7f02e49ab20d4cdc6bfc753. It is recommended to apply a patch to fix this issue. A vulnerability classified as problematic was found in GNU elfutils 0.192. This vulnerability affects the function elf_strptr in the library /libelf/elf_strptr.c of the component eu-strip. The manipulation leads to denial of service. It is possible to launch the attack on the local host. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The name of the patch is b16f441cca0a4841050e3215a9f120a6d8aea918. It is recommended to apply a patch to fix this issue. A flaw was found in how GLib’s GString manages memory when adding data to strings. If a string is already very large, combining it with more input can cause a hidden overflow in the size calculation. This makes the system think it has enough memory when it doesn’t. As a result, data may be written past the end of the allocated memory, leading to crashes or memory corrup…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-26-188-05"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-1306</id>
    <title>OESA-2026-1306 — kernel security update</title>
    <updated>2026-10-02T15:49:23.326007+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP4: kernel</p>
<p>The Linux Kernel, the operating system core itself.

Security Fix(es):</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>cacheinfo: Fix shared_cpu_map to handle shared caches at different levels</p>
<p>The cacheinfo sets up the shared_cpu_map by checking whether the caches
with the same index are shared between CPUs. However, this will trigger
slab-out-of-bounds access if the CPUs do not have the same cache hierarchy.
Another problem is the mismatched shared_cpu_map when the shared cache does
not have the same index between CPUs.</p>
<p>CPU0	I	D	L3
index	0	1	2	x
	^	^	^	^
index	0	1	2	3
CPU1	I	D	L2	L3</p>
<p>This patch checks each cache is shared with all caches on other CPUs.(CVE-2023-53254)</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>drm/radeon: Fix integer overflow in radeon_cs_parser_init</p>
<p>The type of size is unsigned, if size is 0x40000000, there will be an
integer overflow, size will be zero after size *= sizeof(uint32_t),
will cause uninitialized memory to be referenced later(CVE-2023-53309)</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>media: v4l2-mem2mem: add lock to protect parameter num_rdy</p>
<p>Getting below error when using KCSAN to check the driver. Adding lock to
protect parameter num_rdy when getting the value with function:
v4l2_m2m_num_src_bufs_ready/v4l2_m2m_num_dst_bufs_ready.</p>
<p>kworker/u16:3: [name:report&amp;amp;]BUG: KCSAN: data-race in v4l2_m2m_buf_queue
kworker/u16:3: [name:report&amp;amp;]</p>
<p>kworker/u16:3: [name…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-1306"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:20145-1</id>
    <title>openSUSE-SU-2026:20145-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-02T15:49:23.326092+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:20145-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:1661</id>
    <title>RHSA-2026:1661 — Red Hat Security Advisory: kernel-rt security update</title>
    <updated>2026-10-02T15:49:23.326231+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>kernel: tcp: fix a signed-integer-overflow bug in tcp_add_backlog() kernel: IB/hfi1: Fix sdma.h tx-&gt;num_descs off-by-one error kernel: RDMA/core: Fix "KASAN: slab-use-after-free Read in ib_register_device" problem kernel: Linux kernel: RDMA/rxe use-after-free vulnerability leading to potential arbitrary code execution kernel: Linux kernel: Memory corruption in Squashfs due to incorrect block size calculation kernel: Linux kernel: Denial of Service in ATM CLIP module via infinite recursion kernel: Linux kernel: Denial of Service via out-of-bounds read in USB configuration parsing kernel: mptcp: fix race condition in mptcp_schedule_work() kernel: Linux kernel: Use-after-free in proc_readdir_de() can lead to privilege escalation or denial of service. kernel: Linux kernel: Information disclosure and denial of service via out-of-bounds read in font glyph handling</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:1661"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ssa-253495</id>
    <title>SSA-253495 — SSA-253495: Multiple Vulnerabilities in SINEC OS before V4.0</title>
    <updated>2026-10-02T15:49:23.326274+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A vulnerability has been found in GNU elfutils 0.192 and classified as critical. This vulnerability affects the function __libdw_thread_tail in the library libdw_alloc.c of the component eu-readelf. The manipulation of the argument w leads to memory corruption. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The name of the patch is 2636426a091bd6c6f7f02e49ab20d4cdc6bfc753. It is recommended to apply a patch to fix this issue. A vulnerability classified as problematic was found in GNU elfutils 0.192. This vulnerability affects the function elf_strptr in the library /libelf/elf_strptr.c of the component eu-strip. The manipulation leads to denial of service. It is possible to launch the attack on the local host. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The name of the patch is b16f441cca0a4841050e3215a9f120a6d8aea918. It is recommended to apply a patch to fix this issue. A flaw was found in how GLib’s GString manages memory when adding data to strings. If a string is already very large, combining it with more input can cause a hidden overflow in the size calculation. This makes the system think it has enough memory when it doesn’t. As a result, data may be written past the end of the allocated memory, leading to crashes or memory corrup…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ssa-253495"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:0278-1</id>
    <title>SUSE-SU-2026:0278-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-02T15:49:23.326710+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:0278-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-40271</id>
    <title>UBUNTU-CVE-2025-40271</title>
    <updated>2026-10-02T15:49:23.326935+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe, Ubuntu:16.04:LTS: linux-hwe-edge and 227 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: fs/proc: fix uaf in proc_readdir_de() Pde is erased from subdir rbtree through rb_erase(), but not set the node to EMPTY, which may result in uaf access.  We should use RB_CLEAR_NODE() set the erased node to EMPTY, then pde_subdir_next() will return NULL to avoid uaf access. We found an uaf issue while using stress-ng testing, need to run testcase getdent and tun in the same time.  The steps of the issue is as follows: 1) use getdent to traverse dir /proc/pid/net/dev_snmp6/, and current    pde is tun3; 2) in the [time windows] unregister netdevice tun3 and tun2, and erase    them from rbtree.  erase tun3 first, and then erase tun2.  the    pde(tun2) will be released to slab; 3) continue to getdent process, then pde_subdir_next() will return    pde(tun2) which is released, it will case uaf access. CPU 0                                      |    CPU 1 ------------------------------------------------------------------------- traverse dir /proc/pid/net/dev_snmp6/      | unregister_netdevice(tun-&gt;dev)   //tun3 tun2 sys_getdents64()                           |   iterate_dir()                            |     proc_readdir()                         |       proc_readdir_de()                    |     snmp6_unregister_dev()         pde_get(de);                       |       proc_remove()         read_unlock(&amp;proc_subdir_lock);    |         remove_proc_subtree()                                            | write_lock(&amp;p…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-40271"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2756</id>
    <title>WID-SEC-W-2025-2756 — Linux Kernel: Mehrere Schwachstellen ermöglichen Denial of Service</title>
    <updated>2026-10-02T15:49:23.327206+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen Denial-of-Service-Zustand zu erzeugen oder weitere, nicht spezifizierte Auswirkungen zu erlangen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2756"/>
  </entry>
</feed>
