<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-07T12:50:23.417147+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2022-49636</id>
    <title>CVE-2022-49636 — vlan: fix memory leak in vlan_newlink()</title>
    <updated>2026-10-07T12:50:23.635770+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Linux</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>vlan: fix memory leak in vlan_newlink()</p>
<p>Blamed commit added back a bug I fixed in commit 9bbd917e0bec
("vlan: fix memory leak in vlan_dev_set_egress_priority")</p>
<p>If a memory allocation fails in vlan_changelink() after other allocations
succeeded, we need to call vlan_dev_free_egress_priority()
to free all allocated memory because after a failed -&gt;newlink()
we do not call any methods like ndo_uninit() or dev-&gt;priv_destructor().</p>
<p>In following example, if the allocation for last element 2000:2001 fails,
we need to free eight prior allocations:</p>
<p>ip link add link dummy0 dummy0.100 type vlan id 100 \
	egress-qos-map 1:2 2:3 3:4 4:5 5:6 6:7 7:8 8:9 2000:2001</p>
<p>syzbot report was:</p>
<p>BUG: memory leak
unreferenced object 0xffff888117bd1060 (size 32):
comm "syz-executor408", pid 3759, jiffies 4294956555 (age 34.090s)
hex dump (first 32 bytes):
09 00 00 00 00 a0 00 00 00 00 00 00 00 00 00 00 ................
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
backtrace:
[&lt;ffffffff83fc60ad&gt;] kmalloc include/linux/slab.h:600 [inline]
[&lt;ffffffff83fc60ad&gt;] vlan_dev_set_egress_priority+0xed/0x170 net/8021q/vlan_dev.c:193
[&lt;ffffffff83fc6628&gt;] vlan_changelink+0x178/0x1d0 net/8021q/vlan_netlink.c:128
[&lt;ffffffff83fc67c8&gt;] vlan_newlink+0x148/0x260 net/8021q/vlan_netlink.c:185
[&lt;ffffffff838b1278&gt;] rtnl_newlink_create net/core/rtnetlink.c:3363 [inline]
[&lt;ffffffff838b1278&gt;] __rtnl_newlink+0xa58/0xdc0 net/core/rtnetlink.c:…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2022-49636"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/usn-7585-1</id>
    <title>USN-7585-1 — linux, linux-aws, linux-aws-5.4, linux-azure, linux-gcp, linux-gcp-5.4, linux-ibm, linux-ibm-5.4, linux-kvm, linux-orac…</title>
    <updated>2026-10-07T12:50:23.635866+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:18.04:LTS: linux-aws-5.4, Ubuntu:Pro:18.04:LTS: linux-gcp-5.4, Ubuntu:Pro:18.04:LTS: linux-ibm-5.4, Ubuntu:Pro:18.04:LTS: linux-oracle-5.4, Ubuntu:Pro:20.04:LTS: linux, Ubuntu:Pro:20.04:LTS: linux-aws, Ubuntu:Pro:20.04:LTS: linux-azure, Ubuntu:Pro:20.04:LTS: linux-gcp, Ubuntu:Pro:20.04:LTS: linux-ibm, Ubuntu:Pro:20.04:LTS: linux-kvm and 2 more</p>
<p>It was discovered that the CIFS network file system implementation in the
Linux kernel did not properly verify the target namespace when handling
upcalls. An attacker could use this to expose sensitive information.
(CVE-2025-2312)</p>
<p>Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
  - PowerPC architecture;
  - x86 architecture;
  - iSCSI Boot Firmware Table Attributes driver;
  - GPU drivers;
  - HID subsystem;
  - InfiniBand drivers;
  - Media drivers;
  - MemoryStick subsystem;
  - Network drivers;
  - NTB driver;
  - PCI subsystem;
  - SCSI subsystem;
  - Thermal drivers;
  - JFS file system;
  - File systems infrastructure;
  - Tracing infrastructure;
  - 802.1Q VLAN protocol;
  - Asynchronous Transfer Mode (ATM) subsystem;
  - Bluetooth subsystem;
  - IPv6 networking;
  - Netfilter;
  - Network traffic control;
  - Sun RPC protocol;
  - USB sound devices;
(CVE-2025-22007, CVE-2025-21959, CVE-2025-22021, CVE-2025-22063,
CVE-2025-22045, CVE-2024-58093, CVE-2022-49636, CVE-2025-22020,
CVE-2024-53168, CVE-2025-22071, CVE-2025-39735, CVE-2025-21991,
CVE-2025-21992, CVE-2025-21996, CVE-2025-22035, CVE-2023-53034,
CVE-2025-22054, CVE-2025-23136, CVE-2025-22073, CVE-2024-56551,
CVE-2025-22005, CVE-2025-37937, CVE-2021-47211, CVE-2025-22086,
CVE-2025-21956, CVE-2025-38637, CVE-2025-22004, CVE-2025-22018,
CVE-2025-22079, CVE-2025-21957, CVE-2025-21993)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/usn-7585-1"/>
  </entry>
</feed>
