<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 13:36:24 +0000</lastBuildDate>
    <item>
      <title>2NGA002579 — ABB Arctic communication solution ARM600 Vulnerabilities</title>
      <link>https://cve.radiocsirt.org/vuln/2nga002579</link>
      <description>&lt;p&gt;ABB is aware of public reports of a vulnerabilities in product versions listed as affected in this advisory. An attacker who successfully exploited these vulnerabilities could cause the product to stop, make the product inacces-sible, take remote control of the product or insert and run arbitrary code.
As part of ABB product lifecycle policy, once a product transitions to end-of-life, we discontinue maintenance, security patches, and technical support to focus on current and future technologies. While the product will continue to function, we strongly recommend implementing mitigations defined in this document, such as using a private APN cellular network between Arctic wireless gateways and ARM600 for establishing VPN tunnels, to mitigate security risks and avoid potential vulnerabilities.
As part of ABB product lifecycle policy, once a product transitions to Limited state, we discontinue maintenance, security patches, and technical support to focus on current and future technologies. While the product will continue to function, we strongly recommend implementing mitigations defined in this document to mitigate security risks.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;ABB is aware of public reports of a vulnerabilities in product versions listed as affected in this advisory. An attacker who successfully exploited these vulnerabilities could cause the product to stop, make the product inacces-sible, take remote control of the product or insert and run arbitrary code.
As part of ABB product lifecycle policy, once a product transitions to end-of-life, we discontinue maintenance, security patches, and technical support to focus on current and future technologies. While the product will continue to function, we strongly recommend implementing mitigations defined in this document, such as using a private APN cellular network between Arctic wireless gateways and ARM600 for establishing VPN tunnels, to mitigate security risks and avoid potential vulnerabilities.
As part of ABB product lifecycle policy, once a product transitions to Limited state, we discontinue maintenance, security patches, and technical support to focus on current and future technologies. While the product will continue to function, we strongly recommend implementing mitigations defined in this document to mitigate security risks.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/2nga002579</guid>
    </item>
    <item>
      <title>ALSA-2023:0951 — Important: kernel security and bug fix update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2023:0951</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: bpftool, AlmaLinux:9: kernel, AlmaLinux:9: kernel-abi-stablelists, AlmaLinux:9: kernel-core, AlmaLinux:9: kernel-cross-headers, AlmaLinux:9: kernel-debug, AlmaLinux:9: kernel-debug-core, AlmaLinux:9: kernel-debug-devel, AlmaLinux:9: kernel-debug-devel-matched, AlmaLinux:9: kernel-debug-modules and 17 more&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: use-after-free caused by l2cap_reassemble_sdu() in net/bluetooth/l2cap_core.c (CVE-2022-3564)
* kernel: stack overflow in do_proc_dointvec and proc_skip_spaces (CVE-2022-4378)
* kernel: use-after-free in __nfs42_ssc_open() in fs/nfs/nfs4file.c leading to remote Denial of Service attack (CVE-2022-4379)
* kernel: Netfilter integer overflow vulnerability in nft_payload_copy_vlan (CVE-2023-0179)
* kernel: an out-of-bounds vulnerability in i2c-ismt driver (CVE-2022-2873)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Bug Fix(es):&lt;/p&gt;
&lt;p&gt;* AlmaLinux 9.0: LTP Test failure and crash at fork14 on Sapphire Rapids Platinum 8280+ (BZ#2133083)
* AlmaLinux 9.1 Extending NMI watchdog&amp;#39;s timer during LPM (BZ#2140085)
* AMDSERVER 9.1: amdpstate driver incorrectly designed to load as default for Genoa (BZ#2151274)
* qla2xxx NVMe-FC:  WARNING: CPU: 0 PID: 124072 at drivers/scsi/qla2xxx/qla_init.c:70 qla2xxx_rel_done_warning+0x25/0x30 [qla2xxx] (BZ#2152178)
* Regression: Kernel panic on Lenovo T480 with AH40 USB-C docking station (BZ#2153277)
* Scheduler Update (almalinux9.2) (BZ#2153792)
* AlmaLinux9.1, Nx_Gzip: nr_total_credits is not decremented when processing units are reduced by dlpar in shared mode. (FW1030 / DLPAR) (BZ#2154305)
* MSFT, MA…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: bpftool, AlmaLinux:9: kernel, AlmaLinux:9: kernel-abi-stablelists, AlmaLinux:9: kernel-core, AlmaLinux:9: kernel-cross-headers, AlmaLinux:9: kernel-debug, AlmaLinux:9: kernel-debug-core, AlmaLinux:9: kernel-debug-devel, AlmaLinux:9: kernel-debug-devel-matched, AlmaLinux:9: kernel-debug-modules and 17 more&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: use-after-free caused by l2cap_reassemble_sdu() in net/bluetooth/l2cap_core.c (CVE-2022-3564)
* kernel: stack overflow in do_proc_dointvec and proc_skip_spaces (CVE-2022-4378)
* kernel: use-after-free in __nfs42_ssc_open() in fs/nfs/nfs4file.c leading to remote Denial of Service attack (CVE-2022-4379)
* kernel: Netfilter integer overflow vulnerability in nft_payload_copy_vlan (CVE-2023-0179)
* kernel: an out-of-bounds vulnerability in i2c-ismt driver (CVE-2022-2873)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Bug Fix(es):&lt;/p&gt;
&lt;p&gt;* AlmaLinux 9.0: LTP Test failure and crash at fork14 on Sapphire Rapids Platinum 8280+ (BZ#2133083)
* AlmaLinux 9.1 Extending NMI watchdog&amp;#39;s timer during LPM (BZ#2140085)
* AMDSERVER 9.1: amdpstate driver incorrectly designed to load as default for Genoa (BZ#2151274)
* qla2xxx NVMe-FC:  WARNING: CPU: 0 PID: 124072 at drivers/scsi/qla2xxx/qla_init.c:70 qla2xxx_rel_done_warning+0x25/0x30 [qla2xxx] (BZ#2152178)
* Regression: Kernel panic on Lenovo T480 with AH40 USB-C docking station (BZ#2153277)
* Scheduler Update (almalinux9.2) (BZ#2153792)
* AlmaLinux9.1, Nx_Gzip: nr_total_credits is not decremented when processing units are reduced by dlpar in shared mode. (FW1030 / DLPAR) (BZ#2154305)
* MSFT, MA…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2023:0951</guid>
    </item>
    <item>
      <title>bdu:2022-07336</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2022-07336</link>
      <description>bdu:2022-07336</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2022-07336</guid>
    </item>
    <item>
      <title>Withdrawn: BELL-CVE-2022-4378 — CVE-2022-4378 does not affect BellSoft software</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2022-4378</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2022-4378</guid>
    </item>
    <item>
      <title>certfr-2022-avi-1115 — De multiples vulnérabilités ont été corrigées dans &lt;span
class="textit"&gt;le noyau Linux de SUSE&lt;/span&gt;. Elles permettent…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2022-avi-1115</link>
      <description>certfr-2022-avi-1115</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2022-avi-1115</guid>
    </item>
    <item>
      <title>EUVD-2026-228256</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-228256</link>
      <description>EUVD-2026-228256</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-228256</guid>
    </item>
    <item>
      <title>fkie_cve-2022-4378</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-4378</link>
      <description>&lt;p&gt;A stack overflow flaw was found in the Linux kernel&amp;#39;s SYSCTL subsystem in how a user changes certain kernel parameters and variables. This flaw allows a local user to crash or potentially escalate their privileges on the system.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A stack overflow flaw was found in the Linux kernel&amp;#39;s SYSCTL subsystem in how a user changes certain kernel parameters and variables. This flaw allows a local user to crash or potentially escalate their privileges on the system.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-4378</guid>
    </item>
    <item>
      <title>GHSA-v2c8-m646-2q5c</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-v2c8-m646-2q5c</link>
      <description>&lt;p&gt;A stack overflow flaw was found in the Linux kernel&amp;#39;s SYSCTL subsystem in how a user changes certain kernel parameters and variables. This flaw allows a local user to crash or potentially escalate their privileges on the system.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A stack overflow flaw was found in the Linux kernel&amp;#39;s SYSCTL subsystem in how a user changes certain kernel parameters and variables. This flaw allows a local user to crash or potentially escalate their privileges on the system.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-v2c8-m646-2q5c</guid>
    </item>
    <item>
      <title>gsd-2022-4378</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2022-4378</link>
      <description>gsd-2022-4378</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2022-4378</guid>
    </item>
    <item>
      <title>ICSA-23-166-10 — Siemens SIMATIC S7-1500 TM MFP BIOS</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-23-166-10</link>
      <description>&lt;p&gt;The iconv program in the GNU C Library (aka glibc or libc6) 2.31 and earlier, when invoked with multiple suffixes in the destination encoding (TRANSLATE or IGNORE) along with the -c option, enters an infinite loop when processing invalid multi-byte input sequences, leading to a denial of service. The iconv feature in the GNU C Library (aka glibc or libc6) through 2.32, when processing invalid multi-byte input sequences in the EUC-KR encoding, may have a buffer over-read. A use-after-free vulnerability introduced in glibc upstream version 2.14 was found in the way the tilde expansion was carried out. Directory paths containing an initial tilde followed by a valid username were affected by this issue. A local attacker could exploit this flaw by creating a specially crafted path that, when processed by the glob function, would potentially lead to arbitrary code execution. This was fixed in version 2.32. The GNU C Library (aka glibc or libc6) before 2.32 could overflow an on-stack buffer during range reduction if an input to an 80-bit long double function contains a non-canonical bit pattern, a seen when passing a 0x5d414141414141410000 value to sinl on x86 targets. This is related to sysdeps/ieee754/ldbl-96/e_rem_pio2l.c. The iconv function in the GNU C Library (aka glibc or libc6) 2.32 and earlier, when processing invalid multi-byte input sequences in IBM1364, IBM1371, IBM1388, IBM1390, and IBM1399 encodings, fails to advance the input state, which could lead to an infinite lo…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The iconv program in the GNU C Library (aka glibc or libc6) 2.31 and earlier, when invoked with multiple suffixes in the destination encoding (TRANSLATE or IGNORE) along with the -c option, enters an infinite loop when processing invalid multi-byte input sequences, leading to a denial of service. The iconv feature in the GNU C Library (aka glibc or libc6) through 2.32, when processing invalid multi-byte input sequences in the EUC-KR encoding, may have a buffer over-read. A use-after-free vulnerability introduced in glibc upstream version 2.14 was found in the way the tilde expansion was carried out. Directory paths containing an initial tilde followed by a valid username were affected by this issue. A local attacker could exploit this flaw by creating a specially crafted path that, when processed by the glob function, would potentially lead to arbitrary code execution. This was fixed in version 2.32. The GNU C Library (aka glibc or libc6) before 2.32 could overflow an on-stack buffer during range reduction if an input to an 80-bit long double function contains a non-canonical bit pattern, a seen when passing a 0x5d414141414141410000 value to sinl on x86 targets. This is related to sysdeps/ieee754/ldbl-96/e_rem_pio2l.c. The iconv function in the GNU C Library (aka glibc or libc6) 2.32 and earlier, when processing invalid multi-byte input sequences in IBM1364, IBM1371, IBM1388, IBM1390, and IBM1399 encodings, fails to advance the input state, which could lead to an infinite lo…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-23-166-10</guid>
    </item>
    <item>
      <title>msrc_CVE-2022-4378 — A stack overflow flaw was found in the Linux kernel's SYSCTL subsystem in how a user changes certain kernel parameters…</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2022-4378</link>
      <description>msrc_CVE-2022-4378</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2022-4378</guid>
    </item>
    <item>
      <title>OESA-2022-2162 — kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2022-2162</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS: kernel&lt;/p&gt;
&lt;p&gt;Security Fix(es):&#13;
&#13;
A use-after-free flaw was found in Linux kernel before 5.19.2. This issue occurs in cmd_hdl_filter in drivers/staging/rtl8712/rtl8712_cmd.c, allowing an attacker to launch a local denial of service attack and gain escalation of privileges.(CVE-2022-4095)&#13;
&#13;
There are null-ptr-deref vulnerabilities in drivers/net/slip of linux that allow attacker to
crash linux kernel by simulating slip network card from user-space of linux.&#13;
&#13;
------------------------------------------&#13;
&#13;
[Root cause]&#13;
&#13;
When a slip driver is detaching, the slip_close() will act to
cleanup necessary resources and sl-&amp;amp;gt;tty is set to NULL in
slip_close(). Meanwhile, the packet we transmit is blocked,
sl_tx_timeout() will be called. Although slip_close() and
sl_tx_timeout() use sl-&amp;amp;gt;lock to synchronize, we don`t judge
whether sl-&amp;amp;gt;tty equals to NULL in sl_tx_timeout() and the
null pointer dereference bug will happen.&#13;
&#13;
(Thread 1) | (Thread 2)
| slip_close()
| spin_lock_bh(&amp;amp;amp;sl-&amp;amp;gt;lock)
| ...
... | sl-&amp;amp;gt;tty = NULL //(1)
sl_tx_timeout() | spin_unlock_bh(&amp;amp;amp;sl-&amp;amp;gt;lock)
spin_lock(&amp;amp;amp;sl-&amp;amp;gt;lock); |
... | ...
tty_chars_in_buffer(sl-&amp;amp;gt;tty)|
if (tty-&amp;amp;gt;ops-&amp;amp;gt;..) //(2) |
... | synchronize_rcu()&#13;
&#13;
We set NULL to sl-&amp;amp;gt;tty in position (1) and dereference sl-&amp;amp;gt;tty
in position (2).&#13;
&#13;
------------------------------------------(CVE-2022-41858)&#13;
&#13;
A flaw was found in the Linux kernel&amp;amp;apos;s Layer 2 Tunneling Protocol (L2TP). A missing lock when clearing sk_user_data can lead to…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS: kernel&lt;/p&gt;
&lt;p&gt;Security Fix(es):&#13;
&#13;
A use-after-free flaw was found in Linux kernel before 5.19.2. This issue occurs in cmd_hdl_filter in drivers/staging/rtl8712/rtl8712_cmd.c, allowing an attacker to launch a local denial of service attack and gain escalation of privileges.(CVE-2022-4095)&#13;
&#13;
There are null-ptr-deref vulnerabilities in drivers/net/slip of linux that allow attacker to
crash linux kernel by simulating slip network card from user-space of linux.&#13;
&#13;
------------------------------------------&#13;
&#13;
[Root cause]&#13;
&#13;
When a slip driver is detaching, the slip_close() will act to
cleanup necessary resources and sl-&amp;amp;gt;tty is set to NULL in
slip_close(). Meanwhile, the packet we transmit is blocked,
sl_tx_timeout() will be called. Although slip_close() and
sl_tx_timeout() use sl-&amp;amp;gt;lock to synchronize, we don`t judge
whether sl-&amp;amp;gt;tty equals to NULL in sl_tx_timeout() and the
null pointer dereference bug will happen.&#13;
&#13;
(Thread 1) | (Thread 2)
| slip_close()
| spin_lock_bh(&amp;amp;amp;sl-&amp;amp;gt;lock)
| ...
... | sl-&amp;amp;gt;tty = NULL //(1)
sl_tx_timeout() | spin_unlock_bh(&amp;amp;amp;sl-&amp;amp;gt;lock)
spin_lock(&amp;amp;amp;sl-&amp;amp;gt;lock); |
... | ...
tty_chars_in_buffer(sl-&amp;amp;gt;tty)|
if (tty-&amp;amp;gt;ops-&amp;amp;gt;..) //(2) |
... | synchronize_rcu()&#13;
&#13;
We set NULL to sl-&amp;amp;gt;tty in position (1) and dereference sl-&amp;amp;gt;tty
in position (2).&#13;
&#13;
------------------------------------------(CVE-2022-41858)&#13;
&#13;
A flaw was found in the Linux kernel&amp;amp;apos;s Layer 2 Tunneling Protocol (L2TP). A missing lock when clearing sk_user_data can lead to…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2022-2162</guid>
    </item>
    <item>
      <title>RHSA-2023:0856 — Red Hat Security Advisory: kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2023:0856</link>
      <description>&lt;p&gt;kernel: memory corruption in AX88179_178A based USB ethernet device. kernel: use-after-free caused by l2cap_reassemble_sdu() in net/bluetooth/l2cap_core.c kernel: stack overflow in do_proc_dointvec and proc_skip_spaces&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;kernel: memory corruption in AX88179_178A based USB ethernet device. kernel: use-after-free caused by l2cap_reassemble_sdu() in net/bluetooth/l2cap_core.c kernel: stack overflow in do_proc_dointvec and proc_skip_spaces&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2023:0856</guid>
    </item>
    <item>
      <title>RHSA-2023:0951 — Red Hat Security Advisory: kernel security and bug fix update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2023:0951</link>
      <description>&lt;p&gt;kernel: an out-of-bounds vulnerability in i2c-ismt driver kernel: use-after-free caused by l2cap_reassemble_sdu() in net/bluetooth/l2cap_core.c kernel: stack overflow in do_proc_dointvec and proc_skip_spaces kernel: use-after-free in __nfs42_ssc_open() in fs/nfs/nfs4file.c leading to remote Denial of Service attack kernel: Bluetooth: L2CAP: Fix use-after-free caused by l2cap_reassemble_sdu kernel: Revert &amp;#34;usb: typec: ucsi: add a common function ucsi_unregister_connectors()&amp;#34; kernel: Netfilter integer overflow vulnerability in nft_payload_copy_vlan&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;kernel: an out-of-bounds vulnerability in i2c-ismt driver kernel: use-after-free caused by l2cap_reassemble_sdu() in net/bluetooth/l2cap_core.c kernel: stack overflow in do_proc_dointvec and proc_skip_spaces kernel: use-after-free in __nfs42_ssc_open() in fs/nfs/nfs4file.c leading to remote Denial of Service attack kernel: Bluetooth: L2CAP: Fix use-after-free caused by l2cap_reassemble_sdu kernel: Revert &amp;#34;usb: typec: ucsi: add a common function ucsi_unregister_connectors()&amp;#34; kernel: Netfilter integer overflow vulnerability in nft_payload_copy_vlan&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2023:0951</guid>
    </item>
    <item>
      <title>SUSE-SU-2022:4503-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2022:4503-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2022:4503-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2022-4378</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-4378</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 68 more&lt;/p&gt;
&lt;p&gt;A stack overflow flaw was found in the Linux kernel&amp;#39;s SYSCTL subsystem in how a user changes certain kernel parameters and variables. This flaw allows a local user to crash or potentially escalate their privileges on the system.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 68 more&lt;/p&gt;
&lt;p&gt;A stack overflow flaw was found in the Linux kernel&amp;#39;s SYSCTL subsystem in how a user changes certain kernel parameters and variables. This flaw allows a local user to crash or potentially escalate their privileges on the system.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-4378</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-2288 — Linux Kernel: Schwachstelle ermöglicht Denial of Service</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-2288</link>
      <description>&lt;p&gt;Ein lokaler Angreifer kann eine Schwachstelle im Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein lokaler Angreifer kann eine Schwachstelle im Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-2288</guid>
    </item>
  </channel>
</rss>
