<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T15:11:57.105637+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2022:5249</id>
    <title>ALSA-2022:5249 — Important: kernel security and bug fix update</title>
    <updated>2026-10-02T15:11:57.568469+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:9: bpftool, AlmaLinux:9: kernel, AlmaLinux:9: kernel-abi-stablelists, AlmaLinux:9: kernel-core, AlmaLinux:9: kernel-cross-headers, AlmaLinux:9: kernel-debug, AlmaLinux:9: kernel-debug-core, AlmaLinux:9: kernel-debug-devel, AlmaLinux:9: kernel-debug-devel-matched, AlmaLinux:9: kernel-debug-modules and 18 more</p>
<p>The kernel packages contain the Linux kernel, the core of any Linux operating system.
Security Fix(es):
* kernel: Small table perturb size in the TCP source port generation algorithm can lead to information leak (CVE-2022-1012)
* kernel: race condition in perf_event_open leads to privilege escalation (CVE-2022-1729)
* kernel: a use-after-free write in the netfilter subsystem can lead to privilege escalation to root (CVE-2022-1966)
* kernel: buffer overflow in IPsec ESP transformation code (CVE-2022-27666)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Bug Fix(es):
* make SHA512_arch algos and CRYPTO_USER built-ins (BZ#2072643)
* SR-IOV performance &gt; 50% degradation (BZ#2074830)
* fix data corruption caused by dm-integrity (BZ#2082187)
* SCTP client-side peeloff issues [almalinux-9] (BZ#2084044)
* TCP connection fails in a asymmetric routing situation (BZ#2085480)
* Fails to boot Multiple RT VMs each with multiple vCPUs (BZ#2086963)
* spec: Fix separate tools build (BZ#2090852)
* call traces related to eeh_pseries observed and vmcore is not captured, when kdump is triggered (BZ#2092255)
* Mark ThunderX NIC driver as unmaintained (BZ#2092638)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2022:5249"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2022-02919</id>
    <title>bdu:2022-02919</title>
    <updated>2026-10-02T15:11:57.568587+00:00</updated>
    <content>bdu:2022-02919</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2022-02919"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2022-1012</id>
    <title>Withdrawn: BELL-CVE-2022-1012 — CVE-2022-1012 does not affect BellSoft software</title>
    <updated>2026-10-02T15:11:57.568606+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>
          <strong>Withdrawn by the publisher.</strong>
        </p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2022-1012"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2022-avi-527</id>
    <title>certfr-2022-avi-527 — De multiples vulnérabilités ont été découvertes dans le noyau Linux
d'Ubuntu. Certaines d'entre elles permettent à un a…</title>
    <updated>2026-10-02T15:11:57.568622+00:00</updated>
    <content>certfr-2022-avi-527</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2022-avi-527"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-11377</id>
    <title>EUVD-2026-11377</title>
    <updated>2026-10-02T15:11:57.568638+00:00</updated>
    <content>EUVD-2026-11377</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-11377"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2022-1012</id>
    <title>fkie_cve-2022-1012</title>
    <updated>2026-10-02T15:11:57.568650+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A memory leak problem was found in the TCP source port generation algorithm in net/ipv4/tcp.c due to the small table perturb size. This flaw may allow an attacker to information leak and may cause a denial of service problem.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2022-1012"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2022-1012</id>
    <title>gsd-2022-1012</title>
    <updated>2026-10-02T15:11:57.568672+00:00</updated>
    <content>gsd-2022-1012</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2022-1012"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-23-166-11</id>
    <title>ICSA-23-166-11 — Siemens SIMATIC S7-1500 TM MFP Linux Kernel</title>
    <updated>2026-10-02T15:11:57.568683+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>json-c through 0.14 has an integer overflow and out-of-bounds write via a large JSON file, as demonstrated by printbuf_memappend. A memory overflow vulnerability was found in the Linux kernel’s ipc functionality of the memcg subsystem, in the way a user calls the semget function multiple times, creating semaphores. This flaw allows a local user to starve the resources, causing a denial of service. The highest threat from this vulnerability is to system availability. A vulnerability was found in the fs/inode.c:inode_init_owner() function logic of the LInux kernel that allows local users to create files for the XFS file-system with an unintended group ownership and with group execution and SGID permission bits set, in a scenario where a directory is SGID and belongs to a certain group and is writable by a user who is not a member of this group. This can lead to excessive permissions granted in case when they should not. This vulnerability is similar to the previous CVE-2018-13405 and adds the missed fix for the XFS. When sending malicous data to kernel by ioctl cmd FBIOPUT_VSCREENINFO,kernel will write memory out of bounds. In gc_data_segment in fs/f2fs/gc.c in the Linux kernel before 5.16.3, special files are not considered, leading to a move_data_page NULL pointer dereference. A flaw was found in the Linux kernel. The existing KVM SEV API has a vulnerability that allows a non-root (host) user-level application to crash the host kernel by creating a confidential guest VM inst…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-23-166-11"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2022-1012</id>
    <title>msrc_CVE-2022-1012 — A memory leak problem was found in the TCP source port generation algorithm in net/ipv4/tcp.c due to the small table pe…</title>
    <updated>2026-10-02T15:11:57.569107+00:00</updated>
    <content>msrc_CVE-2022-1012</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2022-1012"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2022-1691</id>
    <title>OESA-2022-1691 — kernel security update</title>
    <updated>2026-10-02T15:11:57.569127+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP1: kernel, openEuler:20.03-LTS-SP3: kernel, openEuler:22.03-LTS: kernel</p>
<p>The Linux Kernel, the operating system core itself.



Security Fix(es):

Non-transparent sharing of branch predictor within a context in some Intel(R) Processors may allow an authorized user to potentially enable information disclosure via local access.(CVE-2022-0002)

In the Linux kernel before 5.17.3, fs/io_uring.c has a use-after-free due to a race condition in io_uring timeouts. This can be triggered by a local user who has no access to any user namespace; however, the race condition perhaps can only be exploited infrequently.(CVE-2022-29582)

A use-after-free vulnerability was found in the Linux kernel in drivers/net/hamradio. This flaw allows a local attacker with a user privilege to cause a denial of service (DOS) when the mkiss or sixpack device is detached and reclaim resources early.(CVE-2022-1195)

In mmc_blk_read_single of block.c, there is a possible way to read kernel heap memory due to uninitialized data. This could lead to local information disclosure if reading from an SD card that triggers errors, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-216481035References: Upstream kernel(CVE-2022-20008)

Due to the small table perturb size, a memory leak flaw was found in the Linux kernel’s TCP source port generation algorithm in the net/ipv4/tcp.c function. This flaw allows an attacker to leak information and may cause a denial of service.(CVE-2022…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2022-1691"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2022:2549-1</id>
    <title>openSUSE-SU-2022:2549-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-02T15:11:57.569168+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2022:2549-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2022:5214</id>
    <title>RHSA-2022:5214 — Red Hat Security Advisory: kpatch-patch security update</title>
    <updated>2026-10-02T15:11:57.569192+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>kernel: Small table perturb size in the TCP source port generation algorithm can lead to information leak kernel: netfilter: nf_tables: incorrect NFT_STATEFUL_EXPR check leads to a use-after-free (write) kernel: buffer overflow in IPsec ESP transformation code kernel: a use-after-free write in the netfilter subsystem can lead to privilege escalation to root</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2022:5214"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2022:2172-1</id>
    <title>SUSE-SU-2022:2172-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-02T15:11:57.569214+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2022:2172-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-1012</id>
    <title>UBUNTU-CVE-2022-1012</title>
    <updated>2026-10-02T15:11:57.569232+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux, Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe, Ubuntu:Pro:16.04:LTS: linux-oracle, Ubuntu:Pro:16.04:LTS: linux and 117 more</p>
<p>A memory leak problem was found in the TCP source port generation algorithm in net/ipv4/tcp.c due to the small table perturb size. This flaw may allow an attacker to information leak and may cause a denial of service problem.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-1012"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0501</id>
    <title>WID-SEC-W-2022-0501 — Linux Kernel: Schwachstelle ermöglicht Denial of Service</title>
    <updated>2026-10-02T15:11:57.569415+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann eine Schwachstelle im Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen oder Informationen offenzulegen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0501"/>
  </entry>
</feed>
