<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 01:24:38 +0000</lastBuildDate>
    <item>
      <title>ALSA-2022:0825 — Important: kernel security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2022:0825</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: kernel-tools-libs-devel&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;The following packages have been upgraded to a later upstream version: kernel (4.18.0). (BZ#2036888)&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: improper initialization of the &amp;#34;flags&amp;#34; member of the new pipe_buffer (CVE-2022-0847)&lt;/p&gt;
&lt;p&gt;* kernel: Use After Free in unix_gc() which could result in a local privilege escalation (CVE-2021-0920)&lt;/p&gt;
&lt;p&gt;* kernel: local privilege escalation by exploiting the fsconfig syscall parameter leads to container breakout (CVE-2021-4154)&lt;/p&gt;
&lt;p&gt;* kernel: possible privileges escalation due to missing TLB flush (CVE-2022-0330)&lt;/p&gt;
&lt;p&gt;* kernel: remote stack overflow via kernel panic on systems using TIPC may lead to DoS (CVE-2022-0435)&lt;/p&gt;
&lt;p&gt;* kernel: cgroups v1 release_agent feature may allow privilege escalation (CVE-2022-0492)&lt;/p&gt;
&lt;p&gt;* kernel: missing check in ioctl allows kernel memory read/write (CVE-2022-0516)&lt;/p&gt;
&lt;p&gt;* kernel: failing usercopy allows for use-after-free exploitation (CVE-2022-22942)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Bug Fix(es):&lt;/p&gt;
&lt;p&gt;* Intel QAT Kernel power up fix (BZ#2016437)&lt;/p&gt;
&lt;p&gt;* AlmaLinux8.4 seeing scsi_dma_map failed with mpt3sas driver and affecting performance (BZ#2018928)&lt;/p&gt;
&lt;p&gt;* [Lenovo 8.4 bug] audio_HDMI certification failed on AlmaLinux 8.4GA (No hdmi out) (BZ#2027335)&lt;/p&gt;
&lt;p&gt;* [AlmaLinux-8.5][4.18.0-323.el8.ppc64le][POWER8/9/10] security_flav…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: kernel-tools-libs-devel&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;The following packages have been upgraded to a later upstream version: kernel (4.18.0). (BZ#2036888)&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: improper initialization of the &amp;#34;flags&amp;#34; member of the new pipe_buffer (CVE-2022-0847)&lt;/p&gt;
&lt;p&gt;* kernel: Use After Free in unix_gc() which could result in a local privilege escalation (CVE-2021-0920)&lt;/p&gt;
&lt;p&gt;* kernel: local privilege escalation by exploiting the fsconfig syscall parameter leads to container breakout (CVE-2021-4154)&lt;/p&gt;
&lt;p&gt;* kernel: possible privileges escalation due to missing TLB flush (CVE-2022-0330)&lt;/p&gt;
&lt;p&gt;* kernel: remote stack overflow via kernel panic on systems using TIPC may lead to DoS (CVE-2022-0435)&lt;/p&gt;
&lt;p&gt;* kernel: cgroups v1 release_agent feature may allow privilege escalation (CVE-2022-0492)&lt;/p&gt;
&lt;p&gt;* kernel: missing check in ioctl allows kernel memory read/write (CVE-2022-0516)&lt;/p&gt;
&lt;p&gt;* kernel: failing usercopy allows for use-after-free exploitation (CVE-2022-22942)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Bug Fix(es):&lt;/p&gt;
&lt;p&gt;* Intel QAT Kernel power up fix (BZ#2016437)&lt;/p&gt;
&lt;p&gt;* AlmaLinux8.4 seeing scsi_dma_map failed with mpt3sas driver and affecting performance (BZ#2018928)&lt;/p&gt;
&lt;p&gt;* [Lenovo 8.4 bug] audio_HDMI certification failed on AlmaLinux 8.4GA (No hdmi out) (BZ#2027335)&lt;/p&gt;
&lt;p&gt;* [AlmaLinux-8.5][4.18.0-323.el8.ppc64le][POWER8/9/10] security_flav…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2022:0825</guid>
    </item>
    <item>
      <title>bdu:2022-00836</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2022-00836</link>
      <description>bdu:2022-00836</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2022-00836</guid>
    </item>
    <item>
      <title>certfr-2021-avi-837 — De multiples vulnérabilités ont été découvertes dans Google Android.
Certaines d'entre elles permettent à un attaquant…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2021-avi-837</link>
      <description>certfr-2021-avi-837</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2021-avi-837</guid>
    </item>
    <item>
      <title>cnvd-2021-101428</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2021-101428</link>
      <description>cnvd-2021-101428</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2021-101428</guid>
    </item>
    <item>
      <title>EUVD-2026-255897</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-255897</link>
      <description>EUVD-2026-255897</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-255897</guid>
    </item>
    <item>
      <title>fkie_cve-2021-0920</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2021-0920</link>
      <description>&lt;p&gt;In unix_scm_to_skb of af_unix.c, there is a possible use after free bug due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-196926917References: Upstream kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In unix_scm_to_skb of af_unix.c, there is a possible use after free bug due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-196926917References: Upstream kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2021-0920</guid>
    </item>
    <item>
      <title>GHSA-r93f-j2vf-vmc4</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-r93f-j2vf-vmc4</link>
      <description>&lt;p&gt;In unix_scm_to_skb of af_unix.c, there is a possible use after free bug due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-196926917References: Upstream kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In unix_scm_to_skb of af_unix.c, there is a possible use after free bug due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-196926917References: Upstream kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-r93f-j2vf-vmc4</guid>
    </item>
    <item>
      <title>gsd-2021-0920</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2021-0920</link>
      <description>gsd-2021-0920</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2021-0920</guid>
    </item>
    <item>
      <title>ICSA-24-074-07 — Siemens SIMATIC</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-24-074-07</link>
      <description>&lt;p&gt;An attacker could cause a crash or potentially execute arbitrary code by sending specially crafted DNS responses to the DNSmasq process. In order to exploit this vulnerability, an attacker must be able to trigger DNS requests from the device, and must be in a privileged position to inject malicious DNS responses. An issue was discovered in net/ipv6/ip6mr.c in the Linux kernel before 4.11. By setting a specific socket option, an attacker can control a pointer in kernel land and cause an inet_csk_listen_stop general protection fault, or potentially execute arbitrary code under certain circumstances. The issue can be triggered as root (e.g., inside a default LXC container or with the CAP_NET_ADMIN capability) or after namespace unsharing. This occurs because sk_type and protocol are not checked in the appropriate part of the ip6_mroute_* functions. NOTE: this affects Linux distributions that use 4.9.x longterm kernels before 4.9.187. In checkKeyIntent of AccountManagerService.java, there is a possible permission bypass. This could lead to local information disclosure with User execution privileges needed. User interaction is needed for exploitation. Product: Android Versions: Android-10, Android-9 Android ID: A-123700107 In setNiNotification of GpsNetInitiatedHandler.java, there is a possible permissions bypass due to an empty mutable PendingIntent. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploit…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An attacker could cause a crash or potentially execute arbitrary code by sending specially crafted DNS responses to the DNSmasq process. In order to exploit this vulnerability, an attacker must be able to trigger DNS requests from the device, and must be in a privileged position to inject malicious DNS responses. An issue was discovered in net/ipv6/ip6mr.c in the Linux kernel before 4.11. By setting a specific socket option, an attacker can control a pointer in kernel land and cause an inet_csk_listen_stop general protection fault, or potentially execute arbitrary code under certain circumstances. The issue can be triggered as root (e.g., inside a default LXC container or with the CAP_NET_ADMIN capability) or after namespace unsharing. This occurs because sk_type and protocol are not checked in the appropriate part of the ip6_mroute_* functions. NOTE: this affects Linux distributions that use 4.9.x longterm kernels before 4.9.187. In checkKeyIntent of AccountManagerService.java, there is a possible permission bypass. This could lead to local information disclosure with User execution privileges needed. User interaction is needed for exploitation. Product: Android Versions: Android-10, Android-9 Android ID: A-123700107 In setNiNotification of GpsNetInitiatedHandler.java, there is a possible permissions bypass due to an empty mutable PendingIntent. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploit…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-24-074-07</guid>
    </item>
    <item>
      <title>OESA-2021-1475 — kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2021-1475</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: kernel, openEuler:20.03-LTS-SP2: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&#13;
&#13;
A memory leak flaw in the Linux kernel&amp;amp;apos;s hugetlbfs memory usage was found in the way the user maps some regions of memory twice using shmget() which are aligned to PUD alignment with the fault of some of the memory pages. A local user could use this flaw to get unauthorized access to some data.(CVE-2021-4002)&#13;
&#13;
In unix_scm_to_skb of af_unix.c, there is a possible use after free bug due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-196926917References: Upstream kernel(CVE-2021-0920)&#13;
&#13;
A vulnerability was found in the fs/inode.c:inode_init_owner() function logic of the LInux kernel that allows local users to create files for the XFS file-system with an unintended group ownership and with group execution and SGID permission bits set, in a scenario where a directory is SGID and belongs to a certain group and is writable by a user who is not a member of this group. This can lead to excessive permissions granted in case when they should not. This vulnerability is similar to the previous CVE-2018-13405 and adds the missed fix for the XFS.(CVE-2021-4037)&#13;
&#13;
A race condition accessing file object in the Linux kernel OverlayFS subsystem was found in the way users do rename in specific way with OverlayFS. A local user could use this flaw to…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: kernel, openEuler:20.03-LTS-SP2: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&#13;
&#13;
A memory leak flaw in the Linux kernel&amp;amp;apos;s hugetlbfs memory usage was found in the way the user maps some regions of memory twice using shmget() which are aligned to PUD alignment with the fault of some of the memory pages. A local user could use this flaw to get unauthorized access to some data.(CVE-2021-4002)&#13;
&#13;
In unix_scm_to_skb of af_unix.c, there is a possible use after free bug due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-196926917References: Upstream kernel(CVE-2021-0920)&#13;
&#13;
A vulnerability was found in the fs/inode.c:inode_init_owner() function logic of the LInux kernel that allows local users to create files for the XFS file-system with an unintended group ownership and with group execution and SGID permission bits set, in a scenario where a directory is SGID and belongs to a certain group and is writable by a user who is not a member of this group. This can lead to excessive permissions granted in case when they should not. This vulnerability is similar to the previous CVE-2018-13405 and adds the missed fix for the XFS.(CVE-2021-4037)&#13;
&#13;
A race condition accessing file object in the Linux kernel OverlayFS subsystem was found in the way users do rename in specific way with OverlayFS. A local user could use this flaw to…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2021-1475</guid>
    </item>
    <item>
      <title>openSUSE-SU-2022:0366-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2022:0366-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2022:0366-1</guid>
    </item>
    <item>
      <title>RHSA-2022:0590 — Red Hat Security Advisory: kpatch-patch security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2022:0590</link>
      <description>&lt;p&gt;kernel: Use After Free in unix_gc() which could result in a local privilege escalation kernel: use-after-free in RDMA listen() kernel: xfs: raw block device data leak in XFS_IOC_ALLOCSP IOCTL&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;kernel: Use After Free in unix_gc() which could result in a local privilege escalation kernel: use-after-free in RDMA listen() kernel: xfs: raw block device data leak in XFS_IOC_ALLOCSP IOCTL&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2022:0590</guid>
    </item>
    <item>
      <title>SUSE-SU-2022:0068-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2022:0068-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2022:0068-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2021-0920</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-0920</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:14.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe and 83 more&lt;/p&gt;
&lt;p&gt;In unix_scm_to_skb of af_unix.c, there is a possible use after free bug due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-196926917References: Upstream kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:14.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe and 83 more&lt;/p&gt;
&lt;p&gt;In unix_scm_to_skb of af_unix.c, there is a possible use after free bug due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-196926917References: Upstream kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-0920</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-0049 — Linux Kernel: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0049</link>
      <description>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um seine Privilegien zu erhöhen, um Sicherheitsmechanismen zu umgehen und um Informationen offenzulegen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um seine Privilegien zu erhöhen, um Sicherheitsmechanismen zu umgehen und um Informationen offenzulegen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0049</guid>
    </item>
  </channel>
</rss>
