<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 15:10:10 +0000</lastBuildDate>
    <item>
      <title>ALSA-2021:4056 — Important: kernel security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2021:4056</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: kernel-tools-libs-devel&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: use-after-free in drivers/infiniband/core/ucma.c ctx use-after-free (CVE-2020-36385)&lt;/p&gt;
&lt;p&gt;* kernel: out-of-bounds write due to a heap buffer overflow in __hidinput_change_resolution_multipliers() of hid-input.c (CVE-2021-0512)&lt;/p&gt;
&lt;p&gt;* kernel: SVM nested virtualization issue in KVM (VMLOAD/VMSAVE) (CVE-2021-3656)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Bug Fix(es):&lt;/p&gt;
&lt;p&gt;* [HPE 8.3 bug] No EDAC MC0 message with one-DIMM two-processor configuration under AlmaLinux8.3 (BZ#1982182)&lt;/p&gt;
&lt;p&gt;* mlx: devlink port function shows all zero hw_addr (BZ#1986837)&lt;/p&gt;
&lt;p&gt;* net/sched: act_mirred: allow saving the last chain processed on xmit path (BZ#1992230)&lt;/p&gt;
&lt;p&gt;* AlmaLinux8.3 - System hang and / or r/o fs during SVC/v5k/v7k maintenance with ibmvfc (BZ#1993892)&lt;/p&gt;
&lt;p&gt;* AlmaLinux8.1 Snapshot3 - PVT:940:virt:4TB:LPM operation failed by returning HSCLA2CF, HSCL365C SRC&amp;#39;s - Linux partition suspend timeout (-&amp;gt; documentation/Linux Alert through LTC bug 182549) (BZ#1993952)&lt;/p&gt;
&lt;p&gt;* AlmaLinux8.4 - benchTableRepDMLAsyncBarrier regresses by 34% on AlmaLinux8.4 on POWER9 compared to AlmaLinux8.2 (performance) (BZ#1997431)&lt;/p&gt;
&lt;p&gt;* [panic] call trace: ice_probe+0x238/0x10f0 [ice] (BZ#1997539)&lt;/p&gt;
&lt;p&gt;* [ice, PTP] ice: fix GPIO 1PPS signal  (BZ#1997572)&lt;/p&gt;
&lt;p&gt;* Fix locality handling in the tpm_tis…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: kernel-tools-libs-devel&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: use-after-free in drivers/infiniband/core/ucma.c ctx use-after-free (CVE-2020-36385)&lt;/p&gt;
&lt;p&gt;* kernel: out-of-bounds write due to a heap buffer overflow in __hidinput_change_resolution_multipliers() of hid-input.c (CVE-2021-0512)&lt;/p&gt;
&lt;p&gt;* kernel: SVM nested virtualization issue in KVM (VMLOAD/VMSAVE) (CVE-2021-3656)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Bug Fix(es):&lt;/p&gt;
&lt;p&gt;* [HPE 8.3 bug] No EDAC MC0 message with one-DIMM two-processor configuration under AlmaLinux8.3 (BZ#1982182)&lt;/p&gt;
&lt;p&gt;* mlx: devlink port function shows all zero hw_addr (BZ#1986837)&lt;/p&gt;
&lt;p&gt;* net/sched: act_mirred: allow saving the last chain processed on xmit path (BZ#1992230)&lt;/p&gt;
&lt;p&gt;* AlmaLinux8.3 - System hang and / or r/o fs during SVC/v5k/v7k maintenance with ibmvfc (BZ#1993892)&lt;/p&gt;
&lt;p&gt;* AlmaLinux8.1 Snapshot3 - PVT:940:virt:4TB:LPM operation failed by returning HSCLA2CF, HSCL365C SRC&amp;#39;s - Linux partition suspend timeout (-&amp;gt; documentation/Linux Alert through LTC bug 182549) (BZ#1993952)&lt;/p&gt;
&lt;p&gt;* AlmaLinux8.4 - benchTableRepDMLAsyncBarrier regresses by 34% on AlmaLinux8.4 on POWER9 compared to AlmaLinux8.2 (performance) (BZ#1997431)&lt;/p&gt;
&lt;p&gt;* [panic] call trace: ice_probe+0x238/0x10f0 [ice] (BZ#1997539)&lt;/p&gt;
&lt;p&gt;* [ice, PTP] ice: fix GPIO 1PPS signal  (BZ#1997572)&lt;/p&gt;
&lt;p&gt;* Fix locality handling in the tpm_tis…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2021:4056</guid>
    </item>
    <item>
      <title>bdu:2021-03320</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2021-03320</link>
      <description>bdu:2021-03320</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2021-03320</guid>
    </item>
    <item>
      <title>certfr-2021-avi-441 — De multiples vulnérabilités ont été découvertes dans Google Android.
Certaines d'entre elles permettent à un attaquant…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2021-avi-441</link>
      <description>certfr-2021-avi-441</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2021-avi-441</guid>
    </item>
    <item>
      <title>cnvd-2021-44319</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2021-44319</link>
      <description>cnvd-2021-44319</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2021-44319</guid>
    </item>
    <item>
      <title>EUVD-2026-19974</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-19974</link>
      <description>EUVD-2026-19974</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-19974</guid>
    </item>
    <item>
      <title>fkie_cve-2021-0512</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2021-0512</link>
      <description>&lt;p&gt;In __hidinput_change_resolution_multipliers of hid-input.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-173843328References: Upstream kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In __hidinput_change_resolution_multipliers of hid-input.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-173843328References: Upstream kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2021-0512</guid>
    </item>
    <item>
      <title>GHSA-x4h3-hq3r-rqx8</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-x4h3-hq3r-rqx8</link>
      <description>&lt;p&gt;In __hidinput_change_resolution_multipliers of hid-input.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-173843328References: Upstream kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In __hidinput_change_resolution_multipliers of hid-input.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-173843328References: Upstream kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-x4h3-hq3r-rqx8</guid>
    </item>
    <item>
      <title>gsd-2021-0512</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2021-0512</link>
      <description>gsd-2021-0512</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2021-0512</guid>
    </item>
    <item>
      <title>ICSA-24-074-07 — Siemens SIMATIC</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-24-074-07</link>
      <description>&lt;p&gt;An attacker could cause a crash or potentially execute arbitrary code by sending specially crafted DNS responses to the DNSmasq process. In order to exploit this vulnerability, an attacker must be able to trigger DNS requests from the device, and must be in a privileged position to inject malicious DNS responses. An issue was discovered in net/ipv6/ip6mr.c in the Linux kernel before 4.11. By setting a specific socket option, an attacker can control a pointer in kernel land and cause an inet_csk_listen_stop general protection fault, or potentially execute arbitrary code under certain circumstances. The issue can be triggered as root (e.g., inside a default LXC container or with the CAP_NET_ADMIN capability) or after namespace unsharing. This occurs because sk_type and protocol are not checked in the appropriate part of the ip6_mroute_* functions. NOTE: this affects Linux distributions that use 4.9.x longterm kernels before 4.9.187. In checkKeyIntent of AccountManagerService.java, there is a possible permission bypass. This could lead to local information disclosure with User execution privileges needed. User interaction is needed for exploitation. Product: Android Versions: Android-10, Android-9 Android ID: A-123700107 In setNiNotification of GpsNetInitiatedHandler.java, there is a possible permissions bypass due to an empty mutable PendingIntent. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploit…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An attacker could cause a crash or potentially execute arbitrary code by sending specially crafted DNS responses to the DNSmasq process. In order to exploit this vulnerability, an attacker must be able to trigger DNS requests from the device, and must be in a privileged position to inject malicious DNS responses. An issue was discovered in net/ipv6/ip6mr.c in the Linux kernel before 4.11. By setting a specific socket option, an attacker can control a pointer in kernel land and cause an inet_csk_listen_stop general protection fault, or potentially execute arbitrary code under certain circumstances. The issue can be triggered as root (e.g., inside a default LXC container or with the CAP_NET_ADMIN capability) or after namespace unsharing. This occurs because sk_type and protocol are not checked in the appropriate part of the ip6_mroute_* functions. NOTE: this affects Linux distributions that use 4.9.x longterm kernels before 4.9.187. In checkKeyIntent of AccountManagerService.java, there is a possible permission bypass. This could lead to local information disclosure with User execution privileges needed. User interaction is needed for exploitation. Product: Android Versions: Android-10, Android-9 Android ID: A-123700107 In setNiNotification of GpsNetInitiatedHandler.java, there is a possible permissions bypass due to an empty mutable PendingIntent. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploit…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-24-074-07</guid>
    </item>
    <item>
      <title>openSUSE-SU-2021:2305-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2021:2305-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2021:2305-1</guid>
    </item>
    <item>
      <title>RHSA-2021:3443 — Red Hat Security Advisory: kpatch-patch security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2021:3443</link>
      <description>&lt;p&gt;kernel: out-of-bounds write due to a heap buffer overflow in __hidinput_change_resolution_multipliers() of hid-input.c kernel: use-after-free in route4_change() in net/sched/cls_route.c kernel: powerpc: KVM guest OS users can cause host OS memory corruption&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;kernel: out-of-bounds write due to a heap buffer overflow in __hidinput_change_resolution_multipliers() of hid-input.c kernel: use-after-free in route4_change() in net/sched/cls_route.c kernel: powerpc: KVM guest OS users can cause host OS memory corruption&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2021:3443</guid>
    </item>
    <item>
      <title>SUSE-SU-2021:14764-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2021:14764-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2021:14764-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2021-0512</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-0512</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:14.04:LTS: linux, Ubuntu:16.04:LTS: linux, Ubuntu:16.04:LTS: linux-aws, Ubuntu:16.04:LTS: linux-kvm, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp and 66 more&lt;/p&gt;
&lt;p&gt;In __hidinput_change_resolution_multipliers of hid-input.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-173843328References: Upstream kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:14.04:LTS: linux, Ubuntu:16.04:LTS: linux, Ubuntu:16.04:LTS: linux-aws, Ubuntu:16.04:LTS: linux-kvm, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp and 66 more&lt;/p&gt;
&lt;p&gt;In __hidinput_change_resolution_multipliers of hid-input.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-173843328References: Upstream kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-0512</guid>
    </item>
  </channel>
</rss>
