<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-07T03:37:01.660181+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2024:5928</id>
    <title>ALSA-2024:5928 — Important: kernel security update</title>
    <updated>2026-10-07T03:37:01.683872+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:9: bpftool, AlmaLinux:9: kernel, AlmaLinux:9: kernel-64k, AlmaLinux:9: kernel-64k-core, AlmaLinux:9: kernel-64k-debug, AlmaLinux:9: kernel-64k-debug-core, AlmaLinux:9: kernel-64k-debug-devel, AlmaLinux:9: kernel-64k-debug-devel-matched, AlmaLinux:9: kernel-64k-debug-modules, AlmaLinux:9: kernel-64k-debug-modules-core and 52 more</p>
<p>The kernel packages contain the Linux kernel, the core of any Linux operating system.</p>
<p>Security Fix(es):</p>
<p>* kernel: nftables: nft_set_rbtree skip end interval element from gc (CVE-2024-26581)
  * kernel: netfilter: nft_limit: reject configurations that cause integer overflow (CVE-2024-26668)
  * kernel: vfio/pci: Lock external INTx masking ops (CVE-2024-26810)
  * kernel: net: ice: Fix potential NULL pointer dereference in ice_bridge_setlink() (CVE-2024-26855)
  * kernel: x86/xen: Add some null pointer checking to smp.c (CVE-2024-26908)
  * kernel: netfilter: nf_tables: release mutex after nft_gc_seq_end from abort path (CVE-2024-26925)
  * kernel: netfilter: nf_tables: Fix potential data-race in __nft_expr_type_get() (CVE-2024-27020)
  * kernel: netfilter: nf_tables: Fix potential data-race in __nft_obj_type_get() (CVE-2024-27019)
  * kernel: netfilter: flowtable: validate pppoe header (CVE-2024-27016)
  * kernel: netfilter: bridge: confirm multicast packets before passing them up the stack (CVE-2024-27415)
  * kernel: netfilter: bridge: replace physindev with physinif in nf_bridge_info (CVE-2024-35839)
  * kernel: netfilter: nf_tables: Fix potential data-race in __nft_flowtable_type_get() (CVE-2024-35898)
  * kernel: netfilter: nf_tables: discard table flag update with pending basechain deletion (CVE-2024-35897)
  * kernel: netfilter: validate user input for expected length (CVE-2024-35896)
  * kernel: netfilter: complete validation of user input (CVE-2024-35962)
  *…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2024:5928"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2024-41041</id>
    <title>CVE-2024-41041 — udp: Set SOCK_RCU_FREE earlier in udp_lib_get_port().</title>
    <updated>2026-10-07T03:37:01.684129+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Linux</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>udp: Set SOCK_RCU_FREE earlier in udp_lib_get_port().</p>
<p>syzkaller triggered the warning [0] in udp_v4_early_demux().</p>
<p>In udp_v[46]_early_demux() and sk_lookup(), we do not touch the refcount
of the looked-up sk and use sock_pfree() as skb-&gt;destructor, so we check
SOCK_RCU_FREE to ensure that the sk is safe to access during the RCU grace
period.</p>
<p>Currently, SOCK_RCU_FREE is flagged for a bound socket after being put
into the hash table.  Moreover, the SOCK_RCU_FREE check is done too early
in udp_v[46]_early_demux() and sk_lookup(), so there could be a small race
window:</p>
<p>CPU1                                 CPU2
  ----                                 ----
  udp_v4_early_demux()                 udp_lib_get_port()
  |                                    |- hlist_add_head_rcu()
  |- sk = __udp4_lib_demux_lookup()    |
  |- DEBUG_NET_WARN_ON_ONCE(sk_is_refcounted(sk));
                                       `- sock_set_flag(sk, SOCK_RCU_FREE)</p>
<p>We had the same bug in TCP and fixed it in commit 871019b22d1b ("net:
set SOCK_RCU_FREE before inserting socket into hashtable").</p>
<p>Let's apply the same fix for UDP.</p>
<p>[0]:
WARNING: CPU: 0 PID: 11198 at net/ipv4/udp.c:2599 udp_v4_early_demux+0x481/0xb70 net/ipv4/udp.c:2599
Modules linked in:
CPU: 0 PID: 11198 Comm: syz-executor.1 Not tainted 6.9.0-g93bda33046e7 #13
Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.0-0-gd239552ce722-prebuilt.qemu.org 04/01/…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2024-41041"/>
  </entry>
</feed>
