<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T19:39:26.990140+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2025:12980</id>
    <title>ALSA-2025:12980 — Moderate: glibc security update</title>
    <updated>2026-10-02T19:39:27.462938+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: compat-libpthread-nonshared, AlmaLinux:8: glibc, AlmaLinux:8: glibc-all-langpacks, AlmaLinux:8: glibc-benchtests, AlmaLinux:8: glibc-common, AlmaLinux:8: glibc-devel, AlmaLinux:8: glibc-doc, AlmaLinux:8: glibc-gconv-extra, AlmaLinux:8: glibc-headers, AlmaLinux:8: glibc-langpack-aa and 204 more</p>
<p>The glibc packages provide the standard C libraries (libc), POSIX thread libraries (libpthread), standard math libraries (libm), and the name service cache daemon (nscd) used by multiple programs on the system. Without these libraries, the Linux system cannot function correctly.</p>
<p>Security Fix(es):</p>
<p>* glibc: Double free in glibc (CVE-2025-8058)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2025:12980"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-16181</id>
    <title>bdu:2025-16181</title>
    <updated>2026-10-02T19:39:27.463210+00:00</updated>
    <content>bdu:2025-16181</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-16181"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2025-8058</id>
    <title>BELL-CVE-2025-8058</title>
    <updated>2026-10-02T19:39:27.463250+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: glibc, Alpaquita:stream: glibc, BellSoft Hardened Containers:23: glibc, BellSoft Hardened Containers:stream: glibc</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2025-8058"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-glibc-cve-2025-8058</id>
    <title>BREW-glibc-CVE-2025-8058</title>
    <updated>2026-10-02T19:39:27.463274+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: glibc</p>
<p>The regcomp function in the GNU C library version from 2.4 to 2.41 is 
subject to a double free if some previous allocation fails. It can be 
accomplished either by a malloc failure or by using an interposed malloc
 that injects random malloc failures. The double free can allow buffer 
manipulation depending of how the regex is constructed. This issue 
affects all architectures and ABIs supported by the GNU C library.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-glibc-cve-2025-8058"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0756</id>
    <title>certfr-2025-avi-0756 — De multiples vulnérabilités ont été découvertes dans les produits VMware. Elles permettent à un attaquant de provoquer…</title>
    <updated>2026-10-02T19:39:27.463296+00:00</updated>
    <content>certfr-2025-avi-0756</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-0756"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-260098</id>
    <title>EUVD-2026-260098</title>
    <updated>2026-10-02T19:39:27.463313+00:00</updated>
    <content>EUVD-2026-260098</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-260098"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-8058</id>
    <title>fkie_cve-2025-8058</title>
    <updated>2026-10-02T19:39:27.463324+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The regcomp function in the GNU C library version from 2.4 to 2.41 is 
subject to a double free if some previous allocation fails. It can be 
accomplished either by a malloc failure or by using an interposed malloc
 that injects random malloc failures. The double free can allow buffer 
manipulation depending of how the regex is constructed. This issue 
affects all architectures and ABIs supported by the GNU C library.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-8058"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-8xjp-c72j-67q8</id>
    <title>GHSA-8xjp-c72j-67q8</title>
    <updated>2026-10-02T19:39:27.463346+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The regcomp function in the GNU C library version from 2.4 to 2.41 is 
subject to a double free if some previous allocation fails. It can be 
accomplished either by a malloc failure or by using an interposed malloc
 that injects random malloc failures. The double free can allow buffer 
manipulation depending of how the regex is constructed. This issue 
affects all architectures and ABIs supported by the GNU C library.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-8xjp-c72j-67q8"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-25-072-03</id>
    <title>ICSA-25-072-03 — Siemens SIMATIC S7-1500 TM MFP</title>
    <updated>2026-10-02T19:39:27.463361+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>In the Linux kernel, the following vulnerability has been resolved:
Squashfs: check the inode number is not the invalid value of zero In the Linux kernel, the following vulnerability has been resolved: net: ethernet: lantiq_etop: fix double free in detach The number of the currently released descriptor is never incremented which results in the same skb being released multiple times. In the Linux kernel, the following vulnerability has been resolved: filelock: fix potential use-after-free in posix_lock_inode Light Hsieh reported a KASAN UAF warning in trace_posix_lock_inode(). The request pointer had been changed earlier to point to a lock entry that was added to the inode's list. However, before the tracepoint could fire, another task raced in and freed that lock. Fix this by moving the tracepoint inside the spinlock, which should ensure that this doesn't happen. In the Linux kernel, the following vulnerability has been resolved: mm: prevent derefencing NULL ptr in pfn_section_valid() Commit 5ec8e8ea8b77 ("mm/sparsemem: fix race in accessing memory_section-&gt;usage") changed pfn_section_valid() to add a READ_ONCE() call around "ms-&gt;usage" to fix a race with section_deactivate() where ms-&gt;usage can be cleared. The READ_ONCE() call, by itself, is not enough to prevent NULL pointer dereference. We need to check its value before dereferencing it. In the Linux kernel, the following vulnerability has been resolved: tcp_metrics: validate source addr length I don't see anything check…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-25-072-03"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2025-8058</id>
    <title>msrc_CVE-2025-8058 — The regcomp function in the GNU C library version from 2.4 to 2.41 is 
subject to a double free if some previous alloca…</title>
    <updated>2026-10-02T19:39:27.463418+00:00</updated>
    <content>msrc_CVE-2025-8058</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2025-8058"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2025-2043</id>
    <title>OESA-2025-2043 — glibc security update</title>
    <updated>2026-10-02T19:39:27.463436+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:22.03-LTS-SP4: glibc</p>
<p>The GNU C Library project provides the core libraries for the GNU system and
GNU/Linux systems, as well as many other systems that use Linux as the kernel.
These libraries provide critical APIs including ISO C11, POSIX.1-2008, BSD,
OS-specific APIs and more. These APIs include such foundational facilities as
open, read, write, malloc, printf, getaddrinfo, dlopen, pthread_create, crypt,
 login, exit and more.

Security Fix(es):</p>
<p>The regcomp function in the GNU C library version from 2.4 to 2.41 is 
subject to a double free if some previous allocation fails. It can be 
accomplished either by a malloc failure or by using an interposed malloc
 that injects random malloc failures. The double free can allow buffer 
manipulation depending of how the regex is constructed. This issue 
affects all architectures and ABIs supported by the GNU C library.(CVE-2025-8058)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2025-2043"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15459-1</id>
    <title>openSUSE-SU-2025:15459-1 — glibc-2.42-1.1 on GA media</title>
    <updated>2026-10-02T19:39:27.463461+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>glibc-2.42-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2025:15459-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2025:13240</id>
    <title>RHSA-2025:13240 — Red Hat Security Advisory: glibc security update</title>
    <updated>2026-10-02T19:39:27.463478+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>glibc: Double free in glibc</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2025:13240"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:0680-1</id>
    <title>SUSE-SU-2026:0680-1 — Security update for glibc</title>
    <updated>2026-10-02T19:39:27.463493+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for glibc</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:0680-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-8058</id>
    <title>UBUNTU-CVE-2025-8058</title>
    <updated>2026-10-02T19:39:27.463508+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: eglibc, Ubuntu:Pro:16.04:LTS: glibc, Ubuntu:Pro:18.04:LTS: glibc, Ubuntu:Pro:20.04:LTS: glibc, Ubuntu:22.04:LTS: glibc, Ubuntu:24.04:LTS: glibc</p>
<p>The regcomp function in the GNU C library version from 2.4 to 2.41 is subject to a double free if some previous allocation fails. It can be accomplished either by a malloc failure or by using an interposed malloc  that injects random malloc failures. The double free can allow buffer manipulation depending of how the regex is constructed. This issue affects all architectures and ABIs supported by the GNU C library.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-8058"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1637</id>
    <title>WID-SEC-W-2025-1637 — GNU libc: Schwachstelle ermöglicht unspezifischen Angriff</title>
    <updated>2026-10-02T19:39:27.463542+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein lokaler Angreifer kann eine Schwachstelle in GNU libc ausnutzen, um nicht näher spezifizierte Auswirkungen zu erzielen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1637"/>
  </entry>
</feed>
