<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T19:41:02.892721+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-74645</id>
    <title>Withdrawn: BELL-CVE-2026-74645 — CVE-2026-74645 does not affect BellSoft software</title>
    <updated>2026-10-03T19:41:02.986003+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>
          <strong>Withdrawn by the publisher.</strong>
        </p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-74645"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-357777</id>
    <title>EUVD-2026-357777</title>
    <updated>2026-10-03T19:41:02.986050+00:00</updated>
    <content>EUVD-2026-357777</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-357777"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-74645</id>
    <title>fkie_cve-2026-74645</title>
    <updated>2026-10-03T19:41:02.986074+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>mm/damon/lru_sort: error out for &gt;10000 active_mem_bp</p>
<p>damos_quota_score() can trigger division by zero if the target value is
zero.  DAMON_LRU_SORT lets users set the target value for the hot memory
scheme via active_mem_bp parameter.  It avoids setting it as the target
value if the parameter value is zero.  However, it also sets the cold
memory scheme with a target value that is calculated as '10000 -
active_mem_bp + 2'.  Hence, if a user sets active_mem_bp 10002, the cold
memory scheme's quota goal target value can be zero.  As a result,
division by zero can be triggered.  Fix by returning an error when the
user tries to start DAMON with &gt;10000 active_mem_bp parameter value.</p>
<p>It makes no sense to set active_mem_bp with 10002.  It also requires
module parameters write permission to reproduce the issue.  That said, the
consequence is quite bad.</p>
<p>One reliable way to reproduce the issue is like below:</p>
<p># cd /sys/module/damon_lru_sort/parameters
    # echo 1000 &gt; wmarks_high
    # echo 995 &gt; wmarks_mid
    # echo 0 &gt; wmarks_low
    # echo 10002 &gt; active_mem_bp
    # echo Y &gt; enabled
    # dmesg -w
    [...]
    [  597.421247] Oops: divide error: 0000 [#1] SMP NOPTI
    [  597.428848] RIP: 0010:damos_quota_score+0x6f/0x480</p>
<p>This issue was discovered [1] by Sashiko.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-74645"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-pq4x-2prc-39cr</id>
    <title>GHSA-pq4x-2prc-39cr</title>
    <updated>2026-10-03T19:41:02.986140+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>mm/damon/lru_sort: error out for &gt;10000 active_mem_bp</p>
<p>damos_quota_score() can trigger division by zero if the target value is
zero.  DAMON_LRU_SORT lets users set the target value for the hot memory
scheme via active_mem_bp parameter.  It avoids setting it as the target
value if the parameter value is zero.  However, it also sets the cold
memory scheme with a target value that is calculated as '10000 -
active_mem_bp + 2'.  Hence, if a user sets active_mem_bp 10002, the cold
memory scheme's quota goal target value can be zero.  As a result,
division by zero can be triggered.  Fix by returning an error when the
user tries to start DAMON with &gt;10000 active_mem_bp parameter value.</p>
<p>It makes no sense to set active_mem_bp with 10002.  It also requires
module parameters write permission to reproduce the issue.  That said, the
consequence is quite bad.</p>
<p>One reliable way to reproduce the issue is like below:</p>
<p># cd /sys/module/damon_lru_sort/parameters
    # echo 1000 &gt; wmarks_high
    # echo 995 &gt; wmarks_mid
    # echo 0 &gt; wmarks_low
    # echo 10002 &gt; active_mem_bp
    # echo Y &gt; enabled
    # dmesg -w
    [...]
    [  597.421247] Oops: divide error: 0000 [#1] SMP NOPTI
    [  597.428848] RIP: 0010:damos_quota_score+0x6f/0x480</p>
<p>This issue was discovered [1] by Sashiko.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-pq4x-2prc-39cr"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-74645</id>
    <title>UBUNTU-CVE-2026-74645</title>
    <updated>2026-10-03T19:41:02.986195+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 117 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: mm/damon/lru_sort: error out for &gt;10000 active_mem_bp damos_quota_score() can trigger division by zero if the target value is zero.  DAMON_LRU_SORT lets users set the target value for the hot memory scheme via active_mem_bp parameter.  It avoids setting it as the target value if the parameter value is zero.  However, it also sets the cold memory scheme with a target value that is calculated as '10000 - active_mem_bp + 2'.  Hence, if a user sets active_mem_bp 10002, the cold memory scheme's quota goal target value can be zero.  As a result, division by zero can be triggered.  Fix by returning an error when the user tries to start DAMON with &gt;10000 active_mem_bp parameter value. It makes no sense to set active_mem_bp with 10002.  It also requires module parameters write permission to reproduce the issue.  That said, the consequence is quite bad. One reliable way to reproduce the issue is like below:     # cd /sys/module/damon_lru_sort/parameters     # echo 1000 &gt; wmarks_high     # echo 995 &gt; wmarks_mid     # echo 0 &gt; wmarks_low     # echo 10002 &gt; active_mem_bp     # echo Y &gt; enabled     # dmesg -w     [...]     [  597.421247] Oops: divide error: 0000 [#1] SMP NOPTI     [  597.428848] RIP: 0010:damos_quota_score+0x6f/0x480 This issue was discovered [1] by Sashiko.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-74645"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2970</id>
    <title>WID-SEC-W-2026-2970 — Linux Kernel: Mehrere Schwachstellen ermöglichen nicht spezifizierten Angriff</title>
    <updated>2026-10-03T19:41:02.986478+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen, möglicherweise Sicherheitsmaßnahmen zu umgehen, einen Denial-of-Service-Zustand herbeizuführen oder vertrauliche Informationen offenzulegen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2970"/>
  </entry>
</feed>
