<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T08:32:41.349592+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-12366</id>
    <title>bdu:2026-12366</title>
    <updated>2026-10-04T08:32:41.416886+00:00</updated>
    <content>bdu:2026-12366</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-12366"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2025-71221</id>
    <title>BELL-CVE-2025-71221</title>
    <updated>2026-10-04T08:32:41.416936+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2025-71221"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0316</id>
    <title>certfr-2026-avi-0316 — De multiples vulnérabilités ont été découvertes dans les produits VMware. Elles permettent à un attaquant de provoquer…</title>
    <updated>2026-10-04T08:32:41.416973+00:00</updated>
    <content>certfr-2026-avi-0316</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0316"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-364635</id>
    <title>EUVD-2026-364635</title>
    <updated>2026-10-04T08:32:41.416992+00:00</updated>
    <content>EUVD-2026-364635</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-364635"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-71221</id>
    <title>fkie_cve-2025-71221</title>
    <updated>2026-10-04T08:32:41.417003+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>dmaengine: mmp_pdma: Fix race condition in mmp_pdma_residue()</p>
<p>Add proper locking in mmp_pdma_residue() to prevent use-after-free when
accessing descriptor list and descriptor contents.</p>
<p>The race occurs when multiple threads call tx_status() while the tasklet
on another CPU is freeing completed descriptors:</p>
<p>CPU 0                              CPU 1
-----                              -----
mmp_pdma_tx_status()
mmp_pdma_residue()
  -&gt; NO LOCK held
     list_for_each_entry(sw, ..)
                                   DMA interrupt
                                   dma_do_tasklet()
                                     -&gt; spin_lock(&amp;desc_lock)
                                        list_move(sw-&gt;node, ...)
                                        spin_unlock(&amp;desc_lock)
  |                                     dma_pool_free(sw) &lt;- FREED!
  -&gt; access sw-&gt;desc &lt;- UAF!</p>
<p>This issue can be reproduced when running dmatest on the same channel with
multiple threads (threads_per_chan &gt; 1).</p>
<p>Fix by protecting the chain_running list iteration and descriptor access
with the chan-&gt;desc_lock spinlock.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-71221"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-959m-9w2w-7jxc</id>
    <title>GHSA-959m-9w2w-7jxc</title>
    <updated>2026-10-04T08:32:41.417041+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>dmaengine: mmp_pdma: Fix race condition in mmp_pdma_residue()</p>
<p>Add proper locking in mmp_pdma_residue() to prevent use-after-free when
accessing descriptor list and descriptor contents.</p>
<p>The race occurs when multiple threads call tx_status() while the tasklet
on another CPU is freeing completed descriptors:</p>
<p>CPU 0                              CPU 1
-----                              -----
mmp_pdma_tx_status()
mmp_pdma_residue()
  -&gt; NO LOCK held
     list_for_each_entry(sw, ..)
                                   DMA interrupt
                                   dma_do_tasklet()
                                     -&gt; spin_lock(&amp;desc_lock)
                                        list_move(sw-&gt;node, ...)
                                        spin_unlock(&amp;desc_lock)
  |                                     dma_pool_free(sw) &lt;- FREED!
  -&gt; access sw-&gt;desc &lt;- UAF!</p>
<p>This issue can be reproduced when running dmatest on the same channel with
multiple threads (threads_per_chan &gt; 1).</p>
<p>Fix by protecting the chain_running list iteration and descriptor access
with the chan-&gt;desc_lock spinlock.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-959m-9w2w-7jxc"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-26-209-04</id>
    <title>ICSA-26-209-04 — Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</title>
    <updated>2026-10-04T08:32:41.417068+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.6 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant).</p>
<p>Siemens is preparing fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-26-209-04"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2025-71221</id>
    <title>msrc_CVE-2025-71221 — dmaengine: mmp_pdma: Fix race condition in mmp_pdma_residue()</title>
    <updated>2026-10-04T08:32:41.417284+00:00</updated>
    <content>msrc_CVE-2025-71221</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2025-71221"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-1505</id>
    <title>OESA-2026-1505 — kernel security update</title>
    <updated>2026-10-04T08:32:41.417300+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:22.03-LTS-SP4: kernel</p>
<p>The Linux Kernel, the operating system core itself.

Security Fix(es):</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>bpf, cpumap: Make sure kthread is running before map update returns</p>
<p>The following warning was reported when running stress-mode enabled
xdp_redirect_cpu with some RT threads:</p>
<p>------------[ cut here ]------------
  WARNING: CPU: 4 PID: 65 at kernel/bpf/cpumap.c:135
  CPU: 4 PID: 65 Comm: kworker/4:1 Not tainted 6.5.0-rc2+ #1
  Hardware name: QEMU Standard PC (i440FX + PIIX, 1996)
  Workqueue: events cpu_map_kthread_stop
  RIP: 0010:put_cpu_map_entry+0xda/0x220
  ......
  Call Trace:
   &amp;lt;TASK&amp;gt;
   ? show_regs+0x65/0x70
   ? __warn+0xa5/0x240
   ......
   ? put_cpu_map_entry+0xda/0x220
   cpu_map_kthread_stop+0x41/0x60
   process_one_work+0x6b0/0xb80
   worker_thread+0x96/0x720
   kthread+0x1a5/0x1f0
   ret_from_fork+0x3a/0x70
   ret_from_fork_asm+0x1b/0x30
   &amp;lt;/TASK&amp;gt;</p>
<p>The root cause is the same as commit 436901649731 (&amp;quot;bpf: cpumap: Fix memory
leak in cpu_map_update_elem&amp;quot;). The kthread is stopped prematurely by
kthread_stop() in cpu_map_kthread_stop(), and kthread() doesn&amp;apos;t call
cpu_map_kthread_run() at all but XDP program has already queued some
frames or skbs into ptr_ring. So when __cpu_map_ring_cleanup() checks
the ptr_ring, it will find it was not emptied and report a warning.</p>
<p>An alternative fix is to use __cpu_map_ring_cleanup() to drop these
pending frames or skbs when kthread_stop() returns -EINTR,…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-1505"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ssa-019113</id>
    <title>SSA-019113 — SSA-019113: Vulnerabilities in the additional GNU/Linux subsystem of the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1.6</title>
    <updated>2026-10-04T08:32:41.417366+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.6 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant).</p>
<p>Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ssa-019113"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-71221</id>
    <title>UBUNTU-CVE-2025-71221</title>
    <updated>2026-10-04T08:32:41.417594+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe, Ubuntu:16.04:LTS: linux-hwe-edge and 231 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: dmaengine: mmp_pdma: Fix race condition in mmp_pdma_residue() Add proper locking in mmp_pdma_residue() to prevent use-after-free when accessing descriptor list and descriptor contents. The race occurs when multiple threads call tx_status() while the tasklet on another CPU is freeing completed descriptors: CPU 0                              CPU 1 -----                              ----- mmp_pdma_tx_status() mmp_pdma_residue()   -&gt; NO LOCK held      list_for_each_entry(sw, ..)                                    DMA interrupt                                    dma_do_tasklet()                                      -&gt; spin_lock(&amp;desc_lock)                                         list_move(sw-&gt;node, ...)                                         spin_unlock(&amp;desc_lock)   |                                     dma_pool_free(sw) &lt;- FREED!   -&gt; access sw-&gt;desc &lt;- UAF! This issue can be reproduced when running dmatest on the same channel with multiple threads (threads_per_chan &gt; 1). Fix by protecting the chain_running list iteration and descriptor access with the chan-&gt;desc_lock spinlock.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-71221"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0421</id>
    <title>WID-SEC-W-2026-0421 — Linux Kernel: Mehrere Schwachstellen</title>
    <updated>2026-10-04T08:32:41.417872+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen im Linux-Kernel ausnutzen, um nicht näher spezifizierte Angriffe durchzuführen, die möglicherweise zu einer Denial-of-Service- Bedingung führen oder eine Speicherbeschädigung verursachen können.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0421"/>
  </entry>
</feed>
