<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 04:17:19 +0000</lastBuildDate>
    <item>
      <title>bdu:2020-03245</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2020-03245</link>
      <description>bdu:2020-03245</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2020-03245</guid>
    </item>
    <item>
      <title>Withdrawn: BELL-CVE-2020-10768 — CVE-2020-10768 does not affect BellSoft software</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2020-10768</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2020-10768</guid>
    </item>
    <item>
      <title>certfr-2020-avi-383 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de
SUSE. Elles permettent à un attaquant de provoqu…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2020-avi-383</link>
      <description>certfr-2020-avi-383</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2020-avi-383</guid>
    </item>
    <item>
      <title>cnvd-2020-52624</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2020-52624</link>
      <description>cnvd-2020-52624</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2020-52624</guid>
    </item>
    <item>
      <title>EUVD-2026-40053</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-40053</link>
      <description>EUVD-2026-40053</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-40053</guid>
    </item>
    <item>
      <title>fkie_cve-2020-10768</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2020-10768</link>
      <description>&lt;p&gt;A flaw was found in the Linux Kernel before 5.8-rc1 in the prctl() function, where it can be used to enable indirect branch speculation after it has been disabled. This call incorrectly reports it as being &amp;#39;force disabled&amp;#39; when it is not and opens the system to Spectre v2 attacks. The highest threat from this vulnerability is to confidentiality.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in the Linux Kernel before 5.8-rc1 in the prctl() function, where it can be used to enable indirect branch speculation after it has been disabled. This call incorrectly reports it as being &amp;#39;force disabled&amp;#39; when it is not and opens the system to Spectre v2 attacks. The highest threat from this vulnerability is to confidentiality.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2020-10768</guid>
    </item>
    <item>
      <title>GHSA-5hg9-992p-865c</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-5hg9-992p-865c</link>
      <description>&lt;p&gt;A flaw was found in the Linux Kernel before 5.8-rc1 in the prctl() function, where it can be used to enable indirect branch speculation after it has been disabled. This call incorrectly reports it as being &amp;#39;force disabled&amp;#39; when it is not and opens the system to Spectre v2 attacks. The highest threat from this vulnerability is to confidentiality.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in the Linux Kernel before 5.8-rc1 in the prctl() function, where it can be used to enable indirect branch speculation after it has been disabled. This call incorrectly reports it as being &amp;#39;force disabled&amp;#39; when it is not and opens the system to Spectre v2 attacks. The highest threat from this vulnerability is to confidentiality.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-5hg9-992p-865c</guid>
    </item>
    <item>
      <title>gsd-2020-10768</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2020-10768</link>
      <description>gsd-2020-10768</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2020-10768</guid>
    </item>
    <item>
      <title>ICSA-24-074-07 — Siemens SIMATIC</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-24-074-07</link>
      <description>&lt;p&gt;An attacker could cause a crash or potentially execute arbitrary code by sending specially crafted DNS responses to the DNSmasq process. In order to exploit this vulnerability, an attacker must be able to trigger DNS requests from the device, and must be in a privileged position to inject malicious DNS responses. An issue was discovered in net/ipv6/ip6mr.c in the Linux kernel before 4.11. By setting a specific socket option, an attacker can control a pointer in kernel land and cause an inet_csk_listen_stop general protection fault, or potentially execute arbitrary code under certain circumstances. The issue can be triggered as root (e.g., inside a default LXC container or with the CAP_NET_ADMIN capability) or after namespace unsharing. This occurs because sk_type and protocol are not checked in the appropriate part of the ip6_mroute_* functions. NOTE: this affects Linux distributions that use 4.9.x longterm kernels before 4.9.187. In checkKeyIntent of AccountManagerService.java, there is a possible permission bypass. This could lead to local information disclosure with User execution privileges needed. User interaction is needed for exploitation. Product: Android Versions: Android-10, Android-9 Android ID: A-123700107 In setNiNotification of GpsNetInitiatedHandler.java, there is a possible permissions bypass due to an empty mutable PendingIntent. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploit…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An attacker could cause a crash or potentially execute arbitrary code by sending specially crafted DNS responses to the DNSmasq process. In order to exploit this vulnerability, an attacker must be able to trigger DNS requests from the device, and must be in a privileged position to inject malicious DNS responses. An issue was discovered in net/ipv6/ip6mr.c in the Linux kernel before 4.11. By setting a specific socket option, an attacker can control a pointer in kernel land and cause an inet_csk_listen_stop general protection fault, or potentially execute arbitrary code under certain circumstances. The issue can be triggered as root (e.g., inside a default LXC container or with the CAP_NET_ADMIN capability) or after namespace unsharing. This occurs because sk_type and protocol are not checked in the appropriate part of the ip6_mroute_* functions. NOTE: this affects Linux distributions that use 4.9.x longterm kernels before 4.9.187. In checkKeyIntent of AccountManagerService.java, there is a possible permission bypass. This could lead to local information disclosure with User execution privileges needed. User interaction is needed for exploitation. Product: Android Versions: Android-10, Android-9 Android ID: A-123700107 In setNiNotification of GpsNetInitiatedHandler.java, there is a possible permissions bypass due to an empty mutable PendingIntent. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploit…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-24-074-07</guid>
    </item>
    <item>
      <title>msrc_CVE-2020-10768 — A flaw was found in the Linux Kernel before 5.8-rc1 in the prctl() function where it can be used to enable indirect bra…</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2020-10768</link>
      <description>msrc_CVE-2020-10768</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2020-10768</guid>
    </item>
    <item>
      <title>openSUSE-SU-2020:0935-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2020:0935-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2020:0935-1</guid>
    </item>
    <item>
      <title>RHSA-2020:3016 — Red Hat Security Advisory: kernel-rt security and bug fix update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2020:3016</link>
      <description>&lt;p&gt;kernel: kvm: Information leak within a KVM guest kernel: use-after-free in sound/core/timer.c kernel: kernel: DAX hugepages not considered during mremap kernel: Rogue cross-process SSBD shutdown. Linux scheduler logical bug allows an attacker to turn off the SSBD protection. kernel: Indirect Branch Prediction Barrier is force-disabled when STIBP is unavailable or enhanced IBRS is available. kernel: Indirect branch speculation can be enabled after it was force-disabled by the PR_SPEC_FORCE_DISABLE prctl command. kernel: buffer overflow in mwifiex_cmd_append_vsie_tlv function in drivers/net/wireless/marvell/mwifiex/scan.c kernel: heap-based buffer overflow in mwifiex_ret_wmm_get_status function in drivers/net/wireless/marvell/mwifiex/wmm.c Kernel: vfio: access to disabled MMIO space of some devices may lead to DoS scenario&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;kernel: kvm: Information leak within a KVM guest kernel: use-after-free in sound/core/timer.c kernel: kernel: DAX hugepages not considered during mremap kernel: Rogue cross-process SSBD shutdown. Linux scheduler logical bug allows an attacker to turn off the SSBD protection. kernel: Indirect Branch Prediction Barrier is force-disabled when STIBP is unavailable or enhanced IBRS is available. kernel: Indirect branch speculation can be enabled after it was force-disabled by the PR_SPEC_FORCE_DISABLE prctl command. kernel: buffer overflow in mwifiex_cmd_append_vsie_tlv function in drivers/net/wireless/marvell/mwifiex/scan.c kernel: heap-based buffer overflow in mwifiex_ret_wmm_get_status function in drivers/net/wireless/marvell/mwifiex/wmm.c Kernel: vfio: access to disabled MMIO space of some devices may lead to DoS scenario&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2020:3016</guid>
    </item>
    <item>
      <title>SUSE-SU-2020:1693-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2020:1693-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2020:1693-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2020-10768</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-10768</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:16.04:LTS: linux, Ubuntu:16.04:LTS: linux-aws, Ubuntu:16.04:LTS: linux-aws-hwe, Ubuntu:16.04:LTS: linux-azure, Ubuntu:16.04:LTS: linux-gcp, Ubuntu:16.04:LTS: linux-hwe, Ubuntu:16.04:LTS: linux-kvm and 65 more&lt;/p&gt;
&lt;p&gt;A flaw was found in the Linux Kernel before 5.8-rc1 in the prctl() function, where it can be used to enable indirect branch speculation after it has been disabled. This call incorrectly reports it as being &amp;#39;force disabled&amp;#39; when it is not and opens the system to Spectre v2 attacks. The highest threat from this vulnerability is to confidentiality.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:16.04:LTS: linux, Ubuntu:16.04:LTS: linux-aws, Ubuntu:16.04:LTS: linux-aws-hwe, Ubuntu:16.04:LTS: linux-azure, Ubuntu:16.04:LTS: linux-gcp, Ubuntu:16.04:LTS: linux-hwe, Ubuntu:16.04:LTS: linux-kvm and 65 more&lt;/p&gt;
&lt;p&gt;A flaw was found in the Linux Kernel before 5.8-rc1 in the prctl() function, where it can be used to enable indirect branch speculation after it has been disabled. This call incorrectly reports it as being &amp;#39;force disabled&amp;#39; when it is not and opens the system to Spectre v2 attacks. The highest threat from this vulnerability is to confidentiality.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-10768</guid>
    </item>
  </channel>
</rss>
