<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 09:39:16 +0000</lastBuildDate>
    <item>
      <title>ALSA-2021:1093 — Important: kernel security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2021:1093</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: kernel-abi-whitelists, AlmaLinux:8: kernel-tools-libs-devel&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: use after free in eventpoll.c may lead to escalation of privilege (CVE-2020-0466)&lt;/p&gt;
&lt;p&gt;* kernel: SCSI target (LIO) write to any block on ILO backstore (CVE-2020-28374)&lt;/p&gt;
&lt;p&gt;* kernel: Use after free via PI futex state (CVE-2021-3347)&lt;/p&gt;
&lt;p&gt;* kernel: race conditions caused by wrong locking in net/vmw_vsock/af_vsock.c (CVE-2021-26708)&lt;/p&gt;
&lt;p&gt;* kernel: out-of-bounds read in libiscsi module (CVE-2021-27364)&lt;/p&gt;
&lt;p&gt;* kernel: heap buffer overflow in the iSCSI subsystem (CVE-2021-27365)&lt;/p&gt;
&lt;p&gt;* Kernel: KVM: host stack overflow due to lazy update IOAPIC (CVE-2020-27152)&lt;/p&gt;
&lt;p&gt;* kernel: iscsi: unrestricted access to sessions and handles (CVE-2021-27363)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Bug Fix(es):&lt;/p&gt;
&lt;p&gt;* race condition when creating child sockets from syncookies (BZ#1915529)&lt;/p&gt;
&lt;p&gt;* On System Z, a hash needs state randomized for entropy extraction (BZ#1915816)&lt;/p&gt;
&lt;p&gt;* scsi: target: core_tmr_abort_task() reporting multiple aborts for the same se_cmd-&amp;gt;tag (BZ#1918354)&lt;/p&gt;
&lt;p&gt;* [mlx5] VF interface stats are not reflected in &amp;#34;ip -s link show&amp;#34; / &amp;#34;ifconfig &amp;lt;vf&amp;gt;&amp;#34; commands (BZ#1921060)&lt;/p&gt;
&lt;p&gt;* Win10 guest automatic reboot after migration in Win10 and WSL2 on Intel hosts (BZ#1923281)&lt;/p&gt;
&lt;p&gt;* [AlmaLinux 8.3] Repeated messages - Unable to burst-read optrom segment (BZ#1924222)&lt;/p&gt;
&lt;p&gt;* Backport…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: kernel-abi-whitelists, AlmaLinux:8: kernel-tools-libs-devel&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: use after free in eventpoll.c may lead to escalation of privilege (CVE-2020-0466)&lt;/p&gt;
&lt;p&gt;* kernel: SCSI target (LIO) write to any block on ILO backstore (CVE-2020-28374)&lt;/p&gt;
&lt;p&gt;* kernel: Use after free via PI futex state (CVE-2021-3347)&lt;/p&gt;
&lt;p&gt;* kernel: race conditions caused by wrong locking in net/vmw_vsock/af_vsock.c (CVE-2021-26708)&lt;/p&gt;
&lt;p&gt;* kernel: out-of-bounds read in libiscsi module (CVE-2021-27364)&lt;/p&gt;
&lt;p&gt;* kernel: heap buffer overflow in the iSCSI subsystem (CVE-2021-27365)&lt;/p&gt;
&lt;p&gt;* Kernel: KVM: host stack overflow due to lazy update IOAPIC (CVE-2020-27152)&lt;/p&gt;
&lt;p&gt;* kernel: iscsi: unrestricted access to sessions and handles (CVE-2021-27363)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Bug Fix(es):&lt;/p&gt;
&lt;p&gt;* race condition when creating child sockets from syncookies (BZ#1915529)&lt;/p&gt;
&lt;p&gt;* On System Z, a hash needs state randomized for entropy extraction (BZ#1915816)&lt;/p&gt;
&lt;p&gt;* scsi: target: core_tmr_abort_task() reporting multiple aborts for the same se_cmd-&amp;gt;tag (BZ#1918354)&lt;/p&gt;
&lt;p&gt;* [mlx5] VF interface stats are not reflected in &amp;#34;ip -s link show&amp;#34; / &amp;#34;ifconfig &amp;lt;vf&amp;gt;&amp;#34; commands (BZ#1921060)&lt;/p&gt;
&lt;p&gt;* Win10 guest automatic reboot after migration in Win10 and WSL2 on Intel hosts (BZ#1923281)&lt;/p&gt;
&lt;p&gt;* [AlmaLinux 8.3] Repeated messages - Unable to burst-read optrom segment (BZ#1924222)&lt;/p&gt;
&lt;p&gt;* Backport…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2021:1093</guid>
    </item>
    <item>
      <title>bdu:2021-01218</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2021-01218</link>
      <description>bdu:2021-01218</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2021-01218</guid>
    </item>
    <item>
      <title>certfr-2021-avi-191 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de
Debian LTS. Certaines d'entre elles permettent à…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2021-avi-191</link>
      <description>certfr-2021-avi-191</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2021-avi-191</guid>
    </item>
    <item>
      <title>cnvd-2021-19422</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2021-19422</link>
      <description>cnvd-2021-19422</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2021-19422</guid>
    </item>
    <item>
      <title>EUVD-2026-25502</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-25502</link>
      <description>EUVD-2026-25502</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-25502</guid>
    </item>
    <item>
      <title>fkie_cve-2021-27365</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2021-27365</link>
      <description>&lt;p&gt;An issue was discovered in the Linux kernel through 5.11.3. Certain iSCSI data structures do not have appropriate length constraints or checks, and can exceed the PAGE_SIZE value. An unprivileged user can send a Netlink message that is associated with iSCSI, and has a length up to the maximum length of a Netlink message.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An issue was discovered in the Linux kernel through 5.11.3. Certain iSCSI data structures do not have appropriate length constraints or checks, and can exceed the PAGE_SIZE value. An unprivileged user can send a Netlink message that is associated with iSCSI, and has a length up to the maximum length of a Netlink message.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2021-27365</guid>
    </item>
    <item>
      <title>GHSA-qwp9-8pwv-6hg4</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-qwp9-8pwv-6hg4</link>
      <description>&lt;p&gt;An issue was discovered in the Linux kernel through 5.11.3. Certain iSCSI data structures do not have appropriate length constraints or checks, and can exceed the PAGE_SIZE value. An unprivileged user can send a Netlink message that is associated with iSCSI, and has a length up to the maximum length of a Netlink message.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An issue was discovered in the Linux kernel through 5.11.3. Certain iSCSI data structures do not have appropriate length constraints or checks, and can exceed the PAGE_SIZE value. An unprivileged user can send a Netlink message that is associated with iSCSI, and has a length up to the maximum length of a Netlink message.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-qwp9-8pwv-6hg4</guid>
    </item>
    <item>
      <title>gsd-2021-27365</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2021-27365</link>
      <description>gsd-2021-27365</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2021-27365</guid>
    </item>
    <item>
      <title>msrc_CVE-2021-27365 — An issue was discovered in the Linux kernel through 5.11.3. Certain iSCSI data structures do not have appropriate lengt…</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2021-27365</link>
      <description>msrc_CVE-2021-27365</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2021-27365</guid>
    </item>
    <item>
      <title>OESA-2021-1111 — kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2021-1111</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS: kernel, openEuler:20.03-LTS-SP1: kernel&lt;/p&gt;
&lt;p&gt;The kernel package contains the Linux kernel (vmlinuz), the core of any Linux operating system. The kernel handles the basic functions of the operating system: memory allocation, process allocation, device input and output, etc.&#13;
&#13;
Security Fix(es):&#13;
&#13;
An issue was discovered in the Linux kernel 2.6.39 through 5.10.16, as used in Xen. Block, net, and SCSI backends consider certain errors a plain bug, deliberately causing a kernel crash. For errors potentially being at least under the influence of guests (such as out of memory conditions), it isn&amp;amp;apos;t correct to assume a plain bug. Memory allocations potentially causing such crashes occur only when Linux is running in PV mode, though. This affects drivers/block/xen-blkback/blkback.c and drivers/xen/xen-scsiback.c.(CVE-2021-26931)&#13;
&#13;
An issue was discovered in the Linux kernel 3.11 through 5.10.16, as used by Xen. To service requests to the PV backend, the driver maps grant references provided by the frontend. In this process, errors may be encountered. In one case, an error encountered earlier might be discarded by later processing, resulting in the caller assuming successful mapping, and hence subsequent operations trying to access space that wasn&amp;amp;apos;t mapped. In another case, internal state would be insufficiently updated, preventing safe recovery from the error. This affects drivers/block/xen-blkback/blkback.c.(CVE-2021-26930)&#13;
&#13;
An issue was discovered in the Linux kernel 3.2 through 5.10.16, as used by Xen. Grant map…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS: kernel, openEuler:20.03-LTS-SP1: kernel&lt;/p&gt;
&lt;p&gt;The kernel package contains the Linux kernel (vmlinuz), the core of any Linux operating system. The kernel handles the basic functions of the operating system: memory allocation, process allocation, device input and output, etc.&#13;
&#13;
Security Fix(es):&#13;
&#13;
An issue was discovered in the Linux kernel 2.6.39 through 5.10.16, as used in Xen. Block, net, and SCSI backends consider certain errors a plain bug, deliberately causing a kernel crash. For errors potentially being at least under the influence of guests (such as out of memory conditions), it isn&amp;amp;apos;t correct to assume a plain bug. Memory allocations potentially causing such crashes occur only when Linux is running in PV mode, though. This affects drivers/block/xen-blkback/blkback.c and drivers/xen/xen-scsiback.c.(CVE-2021-26931)&#13;
&#13;
An issue was discovered in the Linux kernel 3.11 through 5.10.16, as used by Xen. To service requests to the PV backend, the driver maps grant references provided by the frontend. In this process, errors may be encountered. In one case, an error encountered earlier might be discarded by later processing, resulting in the caller assuming successful mapping, and hence subsequent operations trying to access space that wasn&amp;amp;apos;t mapped. In another case, internal state would be insufficiently updated, preventing safe recovery from the error. This affects drivers/block/xen-blkback/blkback.c.(CVE-2021-26930)&#13;
&#13;
An issue was discovered in the Linux kernel 3.2 through 5.10.16, as used by Xen. Grant map…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2021-1111</guid>
    </item>
    <item>
      <title>openSUSE-SU-2021:0532-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2021:0532-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2021:0532-1</guid>
    </item>
    <item>
      <title>RHSA-2021:1069 — Red Hat Security Advisory: kpatch-patch security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2021:1069</link>
      <description>&lt;p&gt;kernel: out-of-bounds read in libiscsi module kernel: heap buffer overflow in the iSCSI subsystem&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;kernel: out-of-bounds read in libiscsi module kernel: heap buffer overflow in the iSCSI subsystem&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2021:1069</guid>
    </item>
    <item>
      <title>SUSE-SU-2021:1046-1 — Security update for the Linux Kernel (Live Patch 16 for SLE 12 SP5)</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2021:1046-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel (Live Patch 16 for SLE 12 SP5)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel (Live Patch 16 for SLE 12 SP5)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2021:1046-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2021-27365</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-27365</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux, Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:16.04:LTS: linux, Ubuntu:16.04:LTS: linux-aws, Ubuntu:16.04:LTS: linux-aws-hwe, Ubuntu:16.04:LTS: linux-azure, Ubuntu:16.04:LTS: linux-gcp, Ubuntu:16.04:LTS: linux-hwe and 70 more&lt;/p&gt;
&lt;p&gt;An issue was discovered in the Linux kernel through 5.11.3. Certain iSCSI data structures do not have appropriate length constraints or checks, and can exceed the PAGE_SIZE value. An unprivileged user can send a Netlink message that is associated with iSCSI, and has a length up to the maximum length of a Netlink message.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux, Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:16.04:LTS: linux, Ubuntu:16.04:LTS: linux-aws, Ubuntu:16.04:LTS: linux-aws-hwe, Ubuntu:16.04:LTS: linux-azure, Ubuntu:16.04:LTS: linux-gcp, Ubuntu:16.04:LTS: linux-hwe and 70 more&lt;/p&gt;
&lt;p&gt;An issue was discovered in the Linux kernel through 5.11.3. Certain iSCSI data structures do not have appropriate length constraints or checks, and can exceed the PAGE_SIZE value. An unprivileged user can send a Netlink message that is associated with iSCSI, and has a length up to the maximum length of a Netlink message.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-27365</guid>
    </item>
  </channel>
</rss>
