<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 20:51:53 +0000</lastBuildDate>
    <item>
      <title>ALSA-2021:1093 — Important: kernel security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2021:1093</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: kernel-abi-whitelists, AlmaLinux:8: kernel-tools-libs-devel&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: use after free in eventpoll.c may lead to escalation of privilege (CVE-2020-0466)&lt;/p&gt;
&lt;p&gt;* kernel: SCSI target (LIO) write to any block on ILO backstore (CVE-2020-28374)&lt;/p&gt;
&lt;p&gt;* kernel: Use after free via PI futex state (CVE-2021-3347)&lt;/p&gt;
&lt;p&gt;* kernel: race conditions caused by wrong locking in net/vmw_vsock/af_vsock.c (CVE-2021-26708)&lt;/p&gt;
&lt;p&gt;* kernel: out-of-bounds read in libiscsi module (CVE-2021-27364)&lt;/p&gt;
&lt;p&gt;* kernel: heap buffer overflow in the iSCSI subsystem (CVE-2021-27365)&lt;/p&gt;
&lt;p&gt;* Kernel: KVM: host stack overflow due to lazy update IOAPIC (CVE-2020-27152)&lt;/p&gt;
&lt;p&gt;* kernel: iscsi: unrestricted access to sessions and handles (CVE-2021-27363)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Bug Fix(es):&lt;/p&gt;
&lt;p&gt;* race condition when creating child sockets from syncookies (BZ#1915529)&lt;/p&gt;
&lt;p&gt;* On System Z, a hash needs state randomized for entropy extraction (BZ#1915816)&lt;/p&gt;
&lt;p&gt;* scsi: target: core_tmr_abort_task() reporting multiple aborts for the same se_cmd-&amp;gt;tag (BZ#1918354)&lt;/p&gt;
&lt;p&gt;* [mlx5] VF interface stats are not reflected in &amp;#34;ip -s link show&amp;#34; / &amp;#34;ifconfig &amp;lt;vf&amp;gt;&amp;#34; commands (BZ#1921060)&lt;/p&gt;
&lt;p&gt;* Win10 guest automatic reboot after migration in Win10 and WSL2 on Intel hosts (BZ#1923281)&lt;/p&gt;
&lt;p&gt;* [AlmaLinux 8.3] Repeated messages - Unable to burst-read optrom segment (BZ#1924222)&lt;/p&gt;
&lt;p&gt;* Backport…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: kernel-abi-whitelists, AlmaLinux:8: kernel-tools-libs-devel&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: use after free in eventpoll.c may lead to escalation of privilege (CVE-2020-0466)&lt;/p&gt;
&lt;p&gt;* kernel: SCSI target (LIO) write to any block on ILO backstore (CVE-2020-28374)&lt;/p&gt;
&lt;p&gt;* kernel: Use after free via PI futex state (CVE-2021-3347)&lt;/p&gt;
&lt;p&gt;* kernel: race conditions caused by wrong locking in net/vmw_vsock/af_vsock.c (CVE-2021-26708)&lt;/p&gt;
&lt;p&gt;* kernel: out-of-bounds read in libiscsi module (CVE-2021-27364)&lt;/p&gt;
&lt;p&gt;* kernel: heap buffer overflow in the iSCSI subsystem (CVE-2021-27365)&lt;/p&gt;
&lt;p&gt;* Kernel: KVM: host stack overflow due to lazy update IOAPIC (CVE-2020-27152)&lt;/p&gt;
&lt;p&gt;* kernel: iscsi: unrestricted access to sessions and handles (CVE-2021-27363)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Bug Fix(es):&lt;/p&gt;
&lt;p&gt;* race condition when creating child sockets from syncookies (BZ#1915529)&lt;/p&gt;
&lt;p&gt;* On System Z, a hash needs state randomized for entropy extraction (BZ#1915816)&lt;/p&gt;
&lt;p&gt;* scsi: target: core_tmr_abort_task() reporting multiple aborts for the same se_cmd-&amp;gt;tag (BZ#1918354)&lt;/p&gt;
&lt;p&gt;* [mlx5] VF interface stats are not reflected in &amp;#34;ip -s link show&amp;#34; / &amp;#34;ifconfig &amp;lt;vf&amp;gt;&amp;#34; commands (BZ#1921060)&lt;/p&gt;
&lt;p&gt;* Win10 guest automatic reboot after migration in Win10 and WSL2 on Intel hosts (BZ#1923281)&lt;/p&gt;
&lt;p&gt;* [AlmaLinux 8.3] Repeated messages - Unable to burst-read optrom segment (BZ#1924222)&lt;/p&gt;
&lt;p&gt;* Backport…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2021:1093</guid>
    </item>
    <item>
      <title>bdu:2021-02593</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2021-02593</link>
      <description>bdu:2021-02593</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2021-02593</guid>
    </item>
    <item>
      <title>Withdrawn: BELL-CVE-2021-3347 — CVE-2021-3347 does not affect BellSoft software</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2021-3347</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2021-3347</guid>
    </item>
    <item>
      <title>certfr-2021-avi-077 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de
Debian. Certaines d'entre elles permettent à un…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2021-avi-077</link>
      <description>certfr-2021-avi-077</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2021-avi-077</guid>
    </item>
    <item>
      <title>cnvd-2021-14804</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2021-14804</link>
      <description>cnvd-2021-14804</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2021-14804</guid>
    </item>
    <item>
      <title>EUVD-2026-270644</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-270644</link>
      <description>EUVD-2026-270644</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-270644</guid>
    </item>
    <item>
      <title>fkie_cve-2021-3347</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2021-3347</link>
      <description>&lt;p&gt;An issue was discovered in the Linux kernel through 5.10.11. PI futexes have a kernel stack use-after-free during fault handling, allowing local users to execute code in the kernel, aka CID-34b1a1ce1458.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An issue was discovered in the Linux kernel through 5.10.11. PI futexes have a kernel stack use-after-free during fault handling, allowing local users to execute code in the kernel, aka CID-34b1a1ce1458.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2021-3347</guid>
    </item>
    <item>
      <title>GHSA-8r42-h5pm-2vw2</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-8r42-h5pm-2vw2</link>
      <description>&lt;p&gt;An issue was discovered in the Linux kernel through 5.10.11. PI futexes have a kernel stack use-after-free during fault handling, allowing local users to execute code in the kernel, aka CID-34b1a1ce1458.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An issue was discovered in the Linux kernel through 5.10.11. PI futexes have a kernel stack use-after-free during fault handling, allowing local users to execute code in the kernel, aka CID-34b1a1ce1458.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-8r42-h5pm-2vw2</guid>
    </item>
    <item>
      <title>gsd-2021-3347</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2021-3347</link>
      <description>gsd-2021-3347</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2021-3347</guid>
    </item>
    <item>
      <title>msrc_CVE-2021-3347 — An issue was discovered in the Linux kernel through 5.10.11. PI futexes have a kernel stack use-after-free during fault…</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2021-3347</link>
      <description>msrc_CVE-2021-3347</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2021-3347</guid>
    </item>
    <item>
      <title>OESA-2021-1086 — kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2021-1086</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&#13;
&#13;
In drivers/target/target_core_xcopy.c in the Linux kernel before 5.10.7, insufficient identifier checking in the LIO SCSI target code can be used by remote attackers to read or write files via directory traversal in an XCOPY request, aka CID-2896c93811e3. For example, an attack can occur over a network if the attacker has access to one iSCSI LUN. The attacker gains control over file access because I/O operations are proxied via an attacker-selected backstore.(CVE-2020-28374)&#13;
&#13;
An issue was discovered in Xen through 4.14.x. Some OSes (such as Linux, FreeBSD, and NetBSD) are processing watch events using a single thread. If the events are received faster than the thread is able to handle, they will get queued. As the queue is unbounded, a guest may be able to trigger an OOM in the backend. All systems with a FreeBSD, Linux, or NetBSD (any version) dom0 are vulnerable.(CVE-2020-29568)&#13;
&#13;
In the nl80211_policy policy of nl80211.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not required for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-119770583(CVE-2020-27068)&#13;
&#13;
A flaw was found in the Linux kernels implementation of MIDI, where an attacker with a local account and the permissions to issue an ioctl commands to midi devices, could trigger a use-afte…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&#13;
&#13;
In drivers/target/target_core_xcopy.c in the Linux kernel before 5.10.7, insufficient identifier checking in the LIO SCSI target code can be used by remote attackers to read or write files via directory traversal in an XCOPY request, aka CID-2896c93811e3. For example, an attack can occur over a network if the attacker has access to one iSCSI LUN. The attacker gains control over file access because I/O operations are proxied via an attacker-selected backstore.(CVE-2020-28374)&#13;
&#13;
An issue was discovered in Xen through 4.14.x. Some OSes (such as Linux, FreeBSD, and NetBSD) are processing watch events using a single thread. If the events are received faster than the thread is able to handle, they will get queued. As the queue is unbounded, a guest may be able to trigger an OOM in the backend. All systems with a FreeBSD, Linux, or NetBSD (any version) dom0 are vulnerable.(CVE-2020-29568)&#13;
&#13;
In the nl80211_policy policy of nl80211.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not required for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-119770583(CVE-2020-27068)&#13;
&#13;
A flaw was found in the Linux kernels implementation of MIDI, where an attacker with a local account and the permissions to issue an ioctl commands to midi devices, could trigger a use-afte…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2021-1086</guid>
    </item>
    <item>
      <title>openSUSE-SU-2021:0241-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2021:0241-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2021:0241-1</guid>
    </item>
    <item>
      <title>RHSA-2021:1081 — Red Hat Security Advisory: kernel-rt security and bug fix update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2021:1081</link>
      <description>&lt;p&gt;kernel: use after free in eventpoll.c may lead to escalation of privilege Kernel: KVM: host stack overflow due to lazy update IOAPIC kernel: SCSI target (LIO) write to any block on ILO backstore kernel: Use after free via PI futex state kernel: race conditions caused by wrong locking in net/vmw_vsock/af_vsock.c kernel: iscsi: unrestricted access to sessions and handles kernel: out-of-bounds read in libiscsi module kernel: heap buffer overflow in the iSCSI subsystem&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;kernel: use after free in eventpoll.c may lead to escalation of privilege Kernel: KVM: host stack overflow due to lazy update IOAPIC kernel: SCSI target (LIO) write to any block on ILO backstore kernel: Use after free via PI futex state kernel: race conditions caused by wrong locking in net/vmw_vsock/af_vsock.c kernel: iscsi: unrestricted access to sessions and handles kernel: out-of-bounds read in libiscsi module kernel: heap buffer overflow in the iSCSI subsystem&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2021:1081</guid>
    </item>
    <item>
      <title>SUSE-SU-2021:0347-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2021:0347-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2021:0347-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2021-3347</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-3347</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:14.04:LTS: linux, Ubuntu:16.04:LTS: linux, Ubuntu:16.04:LTS: linux-aws, Ubuntu:16.04:LTS: linux-aws-hwe, Ubuntu:16.04:LTS: linux-azure, Ubuntu:16.04:LTS: linux-gcp, Ubuntu:16.04:LTS: linux-hwe and 67 more&lt;/p&gt;
&lt;p&gt;An issue was discovered in the Linux kernel through 5.10.11. PI futexes have a kernel stack use-after-free during fault handling, allowing local users to execute code in the kernel, aka CID-34b1a1ce1458.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:14.04:LTS: linux, Ubuntu:16.04:LTS: linux, Ubuntu:16.04:LTS: linux-aws, Ubuntu:16.04:LTS: linux-aws-hwe, Ubuntu:16.04:LTS: linux-azure, Ubuntu:16.04:LTS: linux-gcp, Ubuntu:16.04:LTS: linux-hwe and 67 more&lt;/p&gt;
&lt;p&gt;An issue was discovered in the Linux kernel through 5.10.11. PI futexes have a kernel stack use-after-free during fault handling, allowing local users to execute code in the kernel, aka CID-34b1a1ce1458.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-3347</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-0063 — Juniper Junos Space: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0063</link>
      <description>&lt;p&gt;Ein Angreifer aus dem angrenzenden Netzwerk oder ein entfernter anonymer, authentisierter oder lokaler Angreifer kann mehrere Schwachstellen in Juniper Junos Space ausnutzen, um Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand auszulösen, beliebigen Code auszuführen und seine Privilegien zu erweitern.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer aus dem angrenzenden Netzwerk oder ein entfernter anonymer, authentisierter oder lokaler Angreifer kann mehrere Schwachstellen in Juniper Junos Space ausnutzen, um Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand auszulösen, beliebigen Code auszuführen und seine Privilegien zu erweitern.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0063</guid>
    </item>
  </channel>
</rss>
