<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-05T09:33:36.738623+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2025-39955</id>
    <title>CVE-2025-39955 — tcp: Clear tcp_sk(sk)-&gt;fastopen_rsk in tcp_disconnect().</title>
    <updated>2026-10-05T09:33:36.981411+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Linux, Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, Siemens SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP, Siemens SIPLUS S7-1500 CPU 1518-4 PN/DP MFP</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>tcp: Clear tcp_sk(sk)-&gt;fastopen_rsk in tcp_disconnect().</p>
<p>syzbot reported the splat below where a socket had tcp_sk(sk)-&gt;fastopen_rsk
in the TCP_ESTABLISHED state. [0]</p>
<p>syzbot reused the server-side TCP Fast Open socket as a new client before
the TFO socket completes 3WHS:</p>
<p>1. accept()
  2. connect(AF_UNSPEC)
  3. connect() to another destination</p>
<p>As of accept(), sk-&gt;sk_state is TCP_SYN_RECV, and tcp_disconnect() changes
it to TCP_CLOSE and makes connect() possible, which restarts timers.</p>
<p>Since tcp_disconnect() forgot to clear tcp_sk(sk)-&gt;fastopen_rsk, the
retransmit timer triggered the warning and the intended packet was not
retransmitted.</p>
<p>Let's call reqsk_fastopen_remove() in tcp_disconnect().</p>
<p>[0]:
WARNING: CPU: 2 PID: 0 at net/ipv4/tcp_timer.c:542 tcp_retransmit_timer (net/ipv4/tcp_timer.c:542 (discriminator 7))
Modules linked in:
CPU: 2 UID: 0 PID: 0 Comm: swapper/2 Not tainted 6.17.0-rc5-g201825fb4278 #62 PREEMPT(voluntary)
Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
RIP: 0010:tcp_retransmit_timer (net/ipv4/tcp_timer.c:542 (discriminator 7))
Code: 41 55 41 54 55 53 48 8b af b8 08 00 00 48 89 fb 48 85 ed 0f 84 55 01 00 00 0f b6 47 12 3c 03 74 0c 0f b6 47 12 3c 04 74 04 90 &lt;0f&gt; 0b 90 48 8b 85 c0 00 00 00 48 89 ef 48 8b 40 30 e8 6a 4f 06 3e
RSP: 0018:ffffc900002f8d40 EFLAGS: 00010293
RAX: 0000000000000002 RBX: ffff888106911400 RCX: 0000000000000017
RD…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2025-39955"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2025:21931</id>
    <title>RHSA-2025:21931 — Red Hat Security Advisory: kernel security update</title>
    <updated>2026-10-05T09:33:36.981519+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>kernel: NFS: Fix filehandle bounds checking in nfs_fh_to_dentry() kernel: tcp: Clear tcp_sk(sk)-&gt;fastopen_rsk in tcp_disconnect()</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2025:21931"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2025:22388</id>
    <title>RHSA-2025:22388 — Red Hat Security Advisory: kernel security update</title>
    <updated>2026-10-05T09:33:36.981546+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>kernel: nbd: fix incomplete validation of ioctl arg kernel: nfsd: handle get_client_locked() failure in nfsd4_setclientid_confirm() kernel: smb: client: fix race with concurrent opens in rename(2) kernel: mm/memory-failure: fix VM_BUG_ON_PAGE(PagePoisoned(page)) when unpoison memory kernel: e1000e: fix heap overflow in e1000_set_eeprom kernel: tcp: Clear tcp_sk(sk)-&gt;fastopen_rsk in tcp_disconnect() kernel: Linux kernel: Privilege escalation or Denial of Service via TCP Fast Open vulnerability</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2025:22388"/>
  </entry>
</feed>
