<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 21:47:39 +0000</lastBuildDate>
    <item>
      <title>ALSA-2020:4431 — Moderate: kernel security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2020:4431</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: kernel-tools-libs-devel&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: use after free in the video driver leads to local privilege escalation (CVE-2019-9458)&lt;/p&gt;
&lt;p&gt;* kernel: use-after-free in drivers/bluetooth/hci_ldisc.c (CVE-2019-15917)&lt;/p&gt;
&lt;p&gt;* kernel: out-of-bounds access in function hclge_tm_schd_mode_vnet_base_cfg (CVE-2019-15925)&lt;/p&gt;
&lt;p&gt;* kernel: memory leak in ccp_run_sha_cmd() (CVE-2019-18808)&lt;/p&gt;
&lt;p&gt;* kernel: Denial Of Service in the __ipmi_bmc_register() (CVE-2019-19046)&lt;/p&gt;
&lt;p&gt;* kernel: out-of-bounds write in ext4_xattr_set_entry (CVE-2019-19319)&lt;/p&gt;
&lt;p&gt;* Kernel: kvm: OOB memory write via kvm_dev_ioctl_get_cpuid (CVE-2019-19332)&lt;/p&gt;
&lt;p&gt;* kernel: use-after-free in ext4_put_super (CVE-2019-19447)&lt;/p&gt;
&lt;p&gt;* kernel: a malicious USB device in the drivers/input/ff-memless.c leads to use-after-free (CVE-2019-19524)&lt;/p&gt;
&lt;p&gt;* kernel: race condition caused by a malicious USB device in the USB character device driver layer (CVE-2019-19537)&lt;/p&gt;
&lt;p&gt;* kernel: use-after-free in serial_ir_init_module() (CVE-2019-19543)&lt;/p&gt;
&lt;p&gt;* kernel: use-after-free in __ext4_expand_extra_isize and ext4_xattr_set_entry (CVE-2019-19767)&lt;/p&gt;
&lt;p&gt;* kernel: use-after-free in debugfs_remove (CVE-2019-19770)&lt;/p&gt;
&lt;p&gt;* kernel: out-of-bounds write via crafted keycode table (CVE-2019-20636)&lt;/p&gt;
&lt;p&gt;* kernel: possible use-after-free due to a race condition in cdev_get  (CVE-2020-0305)&lt;/p&gt;
&lt;p&gt;* kernel: out-of-bounds read in in vc_do_resize function (CVE-2020-8647)&lt;/p&gt;
&lt;p&gt;* kernel: use-after-free in n_tty_receive_buf_common function (CVE-2020-8648)&lt;/p&gt;
&lt;p&gt;* kernel:…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: kernel-tools-libs-devel&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: use after free in the video driver leads to local privilege escalation (CVE-2019-9458)&lt;/p&gt;
&lt;p&gt;* kernel: use-after-free in drivers/bluetooth/hci_ldisc.c (CVE-2019-15917)&lt;/p&gt;
&lt;p&gt;* kernel: out-of-bounds access in function hclge_tm_schd_mode_vnet_base_cfg (CVE-2019-15925)&lt;/p&gt;
&lt;p&gt;* kernel: memory leak in ccp_run_sha_cmd() (CVE-2019-18808)&lt;/p&gt;
&lt;p&gt;* kernel: Denial Of Service in the __ipmi_bmc_register() (CVE-2019-19046)&lt;/p&gt;
&lt;p&gt;* kernel: out-of-bounds write in ext4_xattr_set_entry (CVE-2019-19319)&lt;/p&gt;
&lt;p&gt;* Kernel: kvm: OOB memory write via kvm_dev_ioctl_get_cpuid (CVE-2019-19332)&lt;/p&gt;
&lt;p&gt;* kernel: use-after-free in ext4_put_super (CVE-2019-19447)&lt;/p&gt;
&lt;p&gt;* kernel: a malicious USB device in the drivers/input/ff-memless.c leads to use-after-free (CVE-2019-19524)&lt;/p&gt;
&lt;p&gt;* kernel: race condition caused by a malicious USB device in the USB character device driver layer (CVE-2019-19537)&lt;/p&gt;
&lt;p&gt;* kernel: use-after-free in serial_ir_init_module() (CVE-2019-19543)&lt;/p&gt;
&lt;p&gt;* kernel: use-after-free in __ext4_expand_extra_isize and ext4_xattr_set_entry (CVE-2019-19767)&lt;/p&gt;
&lt;p&gt;* kernel: use-after-free in debugfs_remove (CVE-2019-19770)&lt;/p&gt;
&lt;p&gt;* kernel: out-of-bounds write via crafted keycode table (CVE-2019-20636)&lt;/p&gt;
&lt;p&gt;* kernel: possible use-after-free due to a race condition in cdev_get  (CVE-2020-0305)&lt;/p&gt;
&lt;p&gt;* kernel: out-of-bounds read in in vc_do_resize function (CVE-2020-8647)&lt;/p&gt;
&lt;p&gt;* kernel: use-after-free in n_tty_receive_buf_common function (CVE-2020-8648)&lt;/p&gt;
&lt;p&gt;* kernel:…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2020:4431</guid>
    </item>
    <item>
      <title>bdu:2020-05792</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2020-05792</link>
      <description>bdu:2020-05792</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2020-05792</guid>
    </item>
    <item>
      <title>certfr-2020-avi-642 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de
SUSE. Elles permettent à un attaquant de provoqu…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2020-avi-642</link>
      <description>certfr-2020-avi-642</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2020-avi-642</guid>
    </item>
    <item>
      <title>EUVD-2026-270615</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-270615</link>
      <description>EUVD-2026-270615</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-270615</guid>
    </item>
    <item>
      <title>fkie_cve-2020-14381</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2020-14381</link>
      <description>&lt;p&gt;A flaw was found in the Linux kernel’s futex implementation. This flaw allows a local attacker to corrupt system memory or escalate their privileges when creating a futex on a filesystem that is about to be unmounted. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in the Linux kernel’s futex implementation. This flaw allows a local attacker to corrupt system memory or escalate their privileges when creating a futex on a filesystem that is about to be unmounted. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2020-14381</guid>
    </item>
    <item>
      <title>GHSA-69w4-9w32-v3qh</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-69w4-9w32-v3qh</link>
      <description>&lt;p&gt;A flaw was found in the Linux kernel’s futex implementation. This flaw allows a local attacker to corrupt system memory or escalate their privileges when creating a futex on a filesystem that is about to be unmounted. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in the Linux kernel’s futex implementation. This flaw allows a local attacker to corrupt system memory or escalate their privileges when creating a futex on a filesystem that is about to be unmounted. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-69w4-9w32-v3qh</guid>
    </item>
    <item>
      <title>gsd-2020-14381</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2020-14381</link>
      <description>gsd-2020-14381</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2020-14381</guid>
    </item>
    <item>
      <title>ICSA-24-074-07 — Siemens SIMATIC</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-24-074-07</link>
      <description>&lt;p&gt;An attacker could cause a crash or potentially execute arbitrary code by sending specially crafted DNS responses to the DNSmasq process. In order to exploit this vulnerability, an attacker must be able to trigger DNS requests from the device, and must be in a privileged position to inject malicious DNS responses. An issue was discovered in net/ipv6/ip6mr.c in the Linux kernel before 4.11. By setting a specific socket option, an attacker can control a pointer in kernel land and cause an inet_csk_listen_stop general protection fault, or potentially execute arbitrary code under certain circumstances. The issue can be triggered as root (e.g., inside a default LXC container or with the CAP_NET_ADMIN capability) or after namespace unsharing. This occurs because sk_type and protocol are not checked in the appropriate part of the ip6_mroute_* functions. NOTE: this affects Linux distributions that use 4.9.x longterm kernels before 4.9.187. In checkKeyIntent of AccountManagerService.java, there is a possible permission bypass. This could lead to local information disclosure with User execution privileges needed. User interaction is needed for exploitation. Product: Android Versions: Android-10, Android-9 Android ID: A-123700107 In setNiNotification of GpsNetInitiatedHandler.java, there is a possible permissions bypass due to an empty mutable PendingIntent. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploit…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An attacker could cause a crash or potentially execute arbitrary code by sending specially crafted DNS responses to the DNSmasq process. In order to exploit this vulnerability, an attacker must be able to trigger DNS requests from the device, and must be in a privileged position to inject malicious DNS responses. An issue was discovered in net/ipv6/ip6mr.c in the Linux kernel before 4.11. By setting a specific socket option, an attacker can control a pointer in kernel land and cause an inet_csk_listen_stop general protection fault, or potentially execute arbitrary code under certain circumstances. The issue can be triggered as root (e.g., inside a default LXC container or with the CAP_NET_ADMIN capability) or after namespace unsharing. This occurs because sk_type and protocol are not checked in the appropriate part of the ip6_mroute_* functions. NOTE: this affects Linux distributions that use 4.9.x longterm kernels before 4.9.187. In checkKeyIntent of AccountManagerService.java, there is a possible permission bypass. This could lead to local information disclosure with User execution privileges needed. User interaction is needed for exploitation. Product: Android Versions: Android-10, Android-9 Android ID: A-123700107 In setNiNotification of GpsNetInitiatedHandler.java, there is a possible permissions bypass due to an empty mutable PendingIntent. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploit…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-24-074-07</guid>
    </item>
    <item>
      <title>msrc_CVE-2020-14381 — A flaw was found in the Linux kernel’s futex implementation. This flaw allows a local attacker to corrupt system memory…</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2020-14381</link>
      <description>msrc_CVE-2020-14381</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2020-14381</guid>
    </item>
    <item>
      <title>OESA-2021-1086 — kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2021-1086</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&#13;
&#13;
In drivers/target/target_core_xcopy.c in the Linux kernel before 5.10.7, insufficient identifier checking in the LIO SCSI target code can be used by remote attackers to read or write files via directory traversal in an XCOPY request, aka CID-2896c93811e3. For example, an attack can occur over a network if the attacker has access to one iSCSI LUN. The attacker gains control over file access because I/O operations are proxied via an attacker-selected backstore.(CVE-2020-28374)&#13;
&#13;
An issue was discovered in Xen through 4.14.x. Some OSes (such as Linux, FreeBSD, and NetBSD) are processing watch events using a single thread. If the events are received faster than the thread is able to handle, they will get queued. As the queue is unbounded, a guest may be able to trigger an OOM in the backend. All systems with a FreeBSD, Linux, or NetBSD (any version) dom0 are vulnerable.(CVE-2020-29568)&#13;
&#13;
In the nl80211_policy policy of nl80211.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not required for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-119770583(CVE-2020-27068)&#13;
&#13;
A flaw was found in the Linux kernels implementation of MIDI, where an attacker with a local account and the permissions to issue an ioctl commands to midi devices, could trigger a use-afte…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&#13;
&#13;
In drivers/target/target_core_xcopy.c in the Linux kernel before 5.10.7, insufficient identifier checking in the LIO SCSI target code can be used by remote attackers to read or write files via directory traversal in an XCOPY request, aka CID-2896c93811e3. For example, an attack can occur over a network if the attacker has access to one iSCSI LUN. The attacker gains control over file access because I/O operations are proxied via an attacker-selected backstore.(CVE-2020-28374)&#13;
&#13;
An issue was discovered in Xen through 4.14.x. Some OSes (such as Linux, FreeBSD, and NetBSD) are processing watch events using a single thread. If the events are received faster than the thread is able to handle, they will get queued. As the queue is unbounded, a guest may be able to trigger an OOM in the backend. All systems with a FreeBSD, Linux, or NetBSD (any version) dom0 are vulnerable.(CVE-2020-29568)&#13;
&#13;
In the nl80211_policy policy of nl80211.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not required for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-119770583(CVE-2020-27068)&#13;
&#13;
A flaw was found in the Linux kernels implementation of MIDI, where an attacker with a local account and the permissions to issue an ioctl commands to midi devices, could trigger a use-afte…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2021-1086</guid>
    </item>
    <item>
      <title>openSUSE-SU-2020:1655-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2020:1655-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2020:1655-1</guid>
    </item>
    <item>
      <title>RHSA-2020:4609 — Red Hat Security Advisory: kernel-rt security and bug fix update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2020:4609</link>
      <description>&lt;p&gt;kernel: kernel pointer leak due to WARN_ON statement in video driver leads to local information disclosure kernel: use after free due to race condition in the video driver leads to local privilege escalation kernel: use-after-free in drivers/bluetooth/hci_ldisc.c kernel: out-of-bounds access in function hclge_tm_schd_mode_vnet_base_cfg kernel: null-pointer dereference in drivers/net/fjes/fjes_main.c kernel: null pointer dereference in drivers/scsi/qla2xxx/qla_os.c kernel: memory leak in ccp_run_sha_cmd() function in drivers/crypto/ccp/ccp-ops.c kernel: memory leak in  af9005_identify_state() function in drivers/media/usb/dvb-usb/af9005.c kernel: Denial Of Service in the __ipmi_bmc_register() function in drivers/char/ipmi/ipmi_msghandler.c kernel: A memory leak in the mwifiex_pcie_alloc_cmdrsp_buf() function in drivers/net/wireless/marvell/mwifiex/pcie.c allows to cause DoS kernel: memory leak in the crypto_report() function in crypto/crypto_user_base.c allows for DoS kernel: Two memory leaks in the rtl_usb_probe() function in drivers/net/wireless/realtek/rtlwifi/usb.c allow for a DoS kernel: A memory leak in the rtl8xxxu_submit_int_urb() function in drivers/net/wireless/realtek/rtl8xxxu/rtl8xxxu_core.c allows for a DoS kernel: A memory leak in the predicate_parse() function in kernel/trace/trace_events_filter.c allows for a DoS kernel: out-of-bounds write in ext4_xattr_set_entry in fs/ext4/xattr.c Kernel: kvm: OOB memory write via kvm_dev_ioctl_get_cpuid kernel: mounting a c…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;kernel: kernel pointer leak due to WARN_ON statement in video driver leads to local information disclosure kernel: use after free due to race condition in the video driver leads to local privilege escalation kernel: use-after-free in drivers/bluetooth/hci_ldisc.c kernel: out-of-bounds access in function hclge_tm_schd_mode_vnet_base_cfg kernel: null-pointer dereference in drivers/net/fjes/fjes_main.c kernel: null pointer dereference in drivers/scsi/qla2xxx/qla_os.c kernel: memory leak in ccp_run_sha_cmd() function in drivers/crypto/ccp/ccp-ops.c kernel: memory leak in  af9005_identify_state() function in drivers/media/usb/dvb-usb/af9005.c kernel: Denial Of Service in the __ipmi_bmc_register() function in drivers/char/ipmi/ipmi_msghandler.c kernel: A memory leak in the mwifiex_pcie_alloc_cmdrsp_buf() function in drivers/net/wireless/marvell/mwifiex/pcie.c allows to cause DoS kernel: memory leak in the crypto_report() function in crypto/crypto_user_base.c allows for DoS kernel: Two memory leaks in the rtl_usb_probe() function in drivers/net/wireless/realtek/rtlwifi/usb.c allow for a DoS kernel: A memory leak in the rtl8xxxu_submit_int_urb() function in drivers/net/wireless/realtek/rtl8xxxu/rtl8xxxu_core.c allows for a DoS kernel: A memory leak in the predicate_parse() function in kernel/trace/trace_events_filter.c allows for a DoS kernel: out-of-bounds write in ext4_xattr_set_entry in fs/ext4/xattr.c Kernel: kvm: OOB memory write via kvm_dev_ioctl_get_cpuid kernel: mounting a c…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2020:4609</guid>
    </item>
    <item>
      <title>SUSE-SU-2020:2904-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2020:2904-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2020:2904-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2020-14381</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-14381</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:14.04:LTS: linux, Ubuntu:16.04:LTS: linux, Ubuntu:16.04:LTS: linux-aws, Ubuntu:16.04:LTS: linux-aws-hwe, Ubuntu:16.04:LTS: linux-azure, Ubuntu:16.04:LTS: linux-gcp, Ubuntu:16.04:LTS: linux-hwe and 44 more&lt;/p&gt;
&lt;p&gt;A flaw was found in the Linux kernel’s futex implementation. This flaw allows a local attacker to corrupt system memory or escalate their privileges when creating a futex on a filesystem that is about to be unmounted. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:14.04:LTS: linux, Ubuntu:16.04:LTS: linux, Ubuntu:16.04:LTS: linux-aws, Ubuntu:16.04:LTS: linux-aws-hwe, Ubuntu:16.04:LTS: linux-azure, Ubuntu:16.04:LTS: linux-gcp, Ubuntu:16.04:LTS: linux-hwe and 44 more&lt;/p&gt;
&lt;p&gt;A flaw was found in the Linux kernel’s futex implementation. This flaw allows a local attacker to corrupt system memory or escalate their privileges when creating a futex on a filesystem that is about to be unmounted. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-14381</guid>
    </item>
  </channel>
</rss>
