<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-10T16:50:40.118261+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2024-41014</id>
    <title>CVE-2024-41014 — xfs: add bounds checking to xlog_recover_process_data</title>
    <updated>2026-10-10T16:50:40.628261+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Linux</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>xfs: add bounds checking to xlog_recover_process_data</p>
<p>There is a lack of verification of the space occupied by fixed members
of xlog_op_header in the xlog_recover_process_data.</p>
<p>We can create a crafted image to trigger an out of bounds read by
following these steps:
    1) Mount an image of xfs, and do some file operations to leave records
    2) Before umounting, copy the image for subsequent steps to simulate
       abnormal exit. Because umount will ensure that tail_blk and
       head_blk are the same, which will result in the inability to enter
       xlog_recover_process_data
    3) Write a tool to parse and modify the copied image in step 2
    4) Make the end of the xlog_op_header entries only 1 byte away from
       xlog_rec_header-&gt;h_size
    5) xlog_rec_header-&gt;h_num_logops++
    6) Modify xlog_rec_header-&gt;h_crc</p>
<p>Fix:
Add a check to make sure there is sufficient space to access fixed members
of xlog_op_header.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2024-41014"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/usn-7449-1</id>
    <title>USN-7449-1 — linux, linux-aws, linux-azure, linux-azure-6.8, linux-ibm, linux-lowlatency, linux-lowlatency-hwe-6.8, linux-nvidia, li…</title>
    <updated>2026-10-10T16:50:40.628359+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:22.04:LTS: linux-azure-6.8, Ubuntu:22.04:LTS: linux-lowlatency-hwe-6.8, Ubuntu:22.04:LTS: linux-nvidia-6.8, Ubuntu:22.04:LTS: linux-oracle-6.8, Ubuntu:24.04:LTS: linux, Ubuntu:24.04:LTS: linux-aws, Ubuntu:24.04:LTS: linux-azure, Ubuntu:24.04:LTS: linux-ibm, Ubuntu:24.04:LTS: linux-lowlatency, Ubuntu:24.04:LTS: linux-nvidia and 3 more</p>
<p>Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
  - ARM64 architecture;
  - MIPS architecture;
  - PowerPC architecture;
  - RISC-V architecture;
  - S390 architecture;
  - SuperH RISC architecture;
  - User-Mode Linux (UML);
  - x86 architecture;
  - Block layer subsystem;
  - Cryptographic API;
  - Compute Acceleration Framework;
  - ACPI drivers;
  - Drivers core;
  - RAM backed block device driver;
  - Compressed RAM block device driver;
  - TPM device driver;
  - Clock framework and drivers;
  - Data acquisition framework and drivers;
  - CPU frequency scaling framework;
  - Hardware crypto device drivers;
  - CXL (Compute Express Link) drivers;
  - EDAC drivers;
  - ARM SCMI message protocol;
  - ARM SCPI message protocol;
  - EFI core;
  - GPIO subsystem;
  - GPU drivers;
  - HID subsystem;
  - I3C subsystem;
  - IIO ADC drivers;
  - IIO subsystem;
  - InfiniBand drivers;
  - IOMMU subsystem;
  - LED subsystem;
  - Multiple devices driver;
  - Media drivers;
  - Multifunction device drivers;
  - MMC subsystem;
  - MTD block device drivers;
  - Network drivers;
  - Mellanox network drivers;
  - STMicroelectronics network drivers;
  - NVME drivers;
  - PCI subsystem;
  - PHY drivers;
  - Pin controllers subsystem;
  - x86 platform drivers;
  - i.MX PM domains;
  - Voltage and Current Regulator drivers;
  - StarFive reset controller drivers;…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/usn-7449-1"/>
  </entry>
</feed>
