<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T22:12:26.728300+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-11416</id>
    <title>bdu:2026-11416</title>
    <updated>2026-10-03T22:12:27.598238+00:00</updated>
    <content>bdu:2026-11416</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-11416"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2025-68204</id>
    <title>BELL-CVE-2025-68204</title>
    <updated>2026-10-03T22:12:27.598294+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2025-68204"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0057</id>
    <title>certfr-2026-avi-0057 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de Debian LTS. Elles permettent à un attaquant de p…</title>
    <updated>2026-10-03T22:12:27.598332+00:00</updated>
    <content>certfr-2026-avi-0057</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0057"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-315053</id>
    <title>EUVD-2026-315053</title>
    <updated>2026-10-03T22:12:27.598350+00:00</updated>
    <content>EUVD-2026-315053</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-315053"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-68204</id>
    <title>fkie_cve-2025-68204</title>
    <updated>2026-10-03T22:12:27.598362+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>pmdomain: arm: scmi: Fix genpd leak on provider registration failure</p>
<p>If of_genpd_add_provider_onecell() fails during probe, the previously
created generic power domains are not removed, leading to a memory leak
and potential kernel crash later in genpd_debug_add().</p>
<p>Add proper error handling to unwind the initialized domains before
returning from probe to ensure all resources are correctly released on
failure.</p>
<p>Example crash trace observed without this fix:</p>
<p>| Unable to handle kernel paging request at virtual address fffffffffffffc70
  | CPU: 1 UID: 0 PID: 1 Comm: swapper/0 Not tainted 6.18.0-rc1 #405 PREEMPT
  | Hardware name: ARM LTD ARM Juno Development Platform/ARM Juno Development Platform
  | pstate: 00000005 (nzcv daif -PAN -UAO -TCO -DIT -SSBS BTYPE=--)
  | pc : genpd_debug_add+0x2c/0x160
  | lr : genpd_debug_init+0x74/0x98
  | Call trace:
  |  genpd_debug_add+0x2c/0x160 (P)
  |  genpd_debug_init+0x74/0x98
  |  do_one_initcall+0xd0/0x2d8
  |  do_initcall_level+0xa0/0x140
  |  do_initcalls+0x60/0xa8
  |  do_basic_setup+0x28/0x40
  |  kernel_init_freeable+0xe8/0x170
  |  kernel_init+0x2c/0x140
  |  ret_from_fork+0x10/0x20</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-68204"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-c8h7-f9cr-785x</id>
    <title>GHSA-c8h7-f9cr-785x</title>
    <updated>2026-10-03T22:12:27.598400+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>pmdomain: arm: scmi: Fix genpd leak on provider registration failure</p>
<p>If of_genpd_add_provider_onecell() fails during probe, the previously
created generic power domains are not removed, leading to a memory leak
and potential kernel crash later in genpd_debug_add().</p>
<p>Add proper error handling to unwind the initialized domains before
returning from probe to ensure all resources are correctly released on
failure.</p>
<p>Example crash trace observed without this fix:</p>
<p>| Unable to handle kernel paging request at virtual address fffffffffffffc70
  | CPU: 1 UID: 0 PID: 1 Comm: swapper/0 Not tainted 6.18.0-rc1 #405 PREEMPT
  | Hardware name: ARM LTD ARM Juno Development Platform/ARM Juno Development Platform
  | pstate: 00000005 (nzcv daif -PAN -UAO -TCO -DIT -SSBS BTYPE=--)
  | pc : genpd_debug_add+0x2c/0x160
  | lr : genpd_debug_init+0x74/0x98
  | Call trace:
  |  genpd_debug_add+0x2c/0x160 (P)
  |  genpd_debug_init+0x74/0x98
  |  do_one_initcall+0xd0/0x2d8
  |  do_initcall_level+0xa0/0x140
  |  do_initcalls+0x60/0xa8
  |  do_basic_setup+0x28/0x40
  |  kernel_init_freeable+0xe8/0x170
  |  kernel_init+0x2c/0x140
  |  ret_from_fork+0x10/0x20</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-c8h7-f9cr-785x"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2025-68204</id>
    <title>msrc_CVE-2025-68204 — pmdomain: arm: scmi: Fix genpd leak on provider registration failure</title>
    <updated>2026-10-03T22:12:27.598426+00:00</updated>
    <content>msrc_CVE-2025-68204</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2025-68204"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-1566</id>
    <title>OESA-2026-1566 — kernel security update</title>
    <updated>2026-10-03T22:12:27.598443+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS-SP1: kernel</p>
<p>The Linux Kernel, the operating system core itself.

Security Fix(es):</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>udp: Deal with race between UDP socket address change and rehash</p>
<p>If a UDP socket changes its local address while it&amp;apos;s receiving
datagrams, as a result of connect(), there is a period during which
a lookup operation might fail to find it, after the address is changed
but before the secondary hash (port and address) and the four-tuple
hash (local and remote ports and addresses) are updated.</p>
<p>Secondary hash chains were introduced by commit 30fff9231fad (&amp;quot;udp:
bind() optimisation&amp;quot;) and, as a result, a rehash operation became
needed to make a bound socket reachable again after a connect().</p>
<p>This operation was introduced by commit 719f835853a9 (&amp;quot;udp: add
rehash on connect()&amp;quot;) which isn&amp;apos;t however a complete fix: the
socket will be found once the rehashing completes, but not while
it&amp;apos;s pending.</p>
<p>This is noticeable with a socat(1) server in UDP4-LISTEN mode, and a
client sending datagrams to it. After the server receives the first
datagram (cf. _xioopen_ipdgram_listen()), it issues a connect() to
the address of the sender, in order to set up a directed flow.</p>
<p>Now, if the client, running on a different CPU thread, happens to
send a (subsequent) datagram while the server&amp;apos;s socket changes its
address, but is not rehashed yet, this will result in a failed
lookup and a port unreachable error delivered to the…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-1566"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:21555-1</id>
    <title>openSUSE-SU-2026:21555-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-03T22:12:27.598814+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:21555-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:0278-1</id>
    <title>SUSE-SU-2026:0278-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-03T22:12:27.599333+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:0278-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-68204</id>
    <title>UBUNTU-CVE-2025-68204</title>
    <updated>2026-10-03T22:12:27.599554+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:Pro:18.04:LTS: linux-aws-5.4, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:Pro:18.04:LTS: linux-azure-5.4, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3 and 201 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: pmdomain: arm: scmi: Fix genpd leak on provider registration failure If of_genpd_add_provider_onecell() fails during probe, the previously created generic power domains are not removed, leading to a memory leak and potential kernel crash later in genpd_debug_add(). Add proper error handling to unwind the initialized domains before returning from probe to ensure all resources are correctly released on failure. Example crash trace observed without this fix:   | Unable to handle kernel paging request at virtual address fffffffffffffc70   | CPU: 1 UID: 0 PID: 1 Comm: swapper/0 Not tainted 6.18.0-rc1 #405 PREEMPT   | Hardware name: ARM LTD ARM Juno Development Platform/ARM Juno Development Platform   | pstate: 00000005 (nzcv daif -PAN -UAO -TCO -DIT -SSBS BTYPE=--)   | pc : genpd_debug_add+0x2c/0x160   | lr : genpd_debug_init+0x74/0x98   | Call trace:   |  genpd_debug_add+0x2c/0x160 (P)   |  genpd_debug_init+0x74/0x98   |  do_one_initcall+0xd0/0x2d8   |  do_initcall_level+0xa0/0x140   |  do_initcalls+0x60/0xa8   |  do_basic_setup+0x28/0x40   |  kernel_init_freeable+0xe8/0x170   |  kernel_init+0x2c/0x140   |  ret_from_fork+0x10/0x20</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-68204"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2868</id>
    <title>WID-SEC-W-2025-2868 — Linux Kernel: Mehrere Schwachstellen</title>
    <updated>2026-10-03T22:12:27.599781+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um nicht näher spezifizierte Angriffe durchzuführen, die möglicherweise zu einer Denial-of-Service- Bedingung führen oder eine Speicherbeschädigung verursachen können.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2868"/>
  </entry>
</feed>
