<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 04:56:38 +0000</lastBuildDate>
    <item>
      <title>bdu:2025-01696</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-01696</link>
      <description>bdu:2025-01696</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-01696</guid>
    </item>
    <item>
      <title>certfr-2024-avi-0999 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de SUSE. Certaines d'entre elles permettent à un at…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0999</link>
      <description>certfr-2024-avi-0999</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2024-avi-0999</guid>
    </item>
    <item>
      <title>EUVD-2026-344632</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-344632</link>
      <description>EUVD-2026-344632</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-344632</guid>
    </item>
    <item>
      <title>fkie_cve-2022-48967</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-48967</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;NFC: nci: Bounds check struct nfc_target arrays&lt;/p&gt;
&lt;p&gt;While running under CONFIG_FORTIFY_SOURCE=y, syzkaller reported:&lt;/p&gt;
&lt;p&gt;memcpy: detected field-spanning write (size 129) of single field &amp;#34;target-&amp;gt;sensf_res&amp;#34; at net/nfc/nci/ntf.c:260 (size 18)&lt;/p&gt;
&lt;p&gt;This appears to be a legitimate lack of bounds checking in
nci_add_new_protocol(). Add the missing checks.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;NFC: nci: Bounds check struct nfc_target arrays&lt;/p&gt;
&lt;p&gt;While running under CONFIG_FORTIFY_SOURCE=y, syzkaller reported:&lt;/p&gt;
&lt;p&gt;memcpy: detected field-spanning write (size 129) of single field &amp;#34;target-&amp;gt;sensf_res&amp;#34; at net/nfc/nci/ntf.c:260 (size 18)&lt;/p&gt;
&lt;p&gt;This appears to be a legitimate lack of bounds checking in
nci_add_new_protocol(). Add the missing checks.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-48967</guid>
    </item>
    <item>
      <title>GHSA-2645-7hqp-7qr7</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-2645-7hqp-7qr7</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;NFC: nci: Bounds check struct nfc_target arrays&lt;/p&gt;
&lt;p&gt;While running under CONFIG_FORTIFY_SOURCE=y, syzkaller reported:&lt;/p&gt;
&lt;p&gt;memcpy: detected field-spanning write (size 129) of single field &amp;#34;target-&amp;gt;sensf_res&amp;#34; at net/nfc/nci/ntf.c:260 (size 18)&lt;/p&gt;
&lt;p&gt;This appears to be a legitimate lack of bounds checking in
nci_add_new_protocol(). Add the missing checks.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;NFC: nci: Bounds check struct nfc_target arrays&lt;/p&gt;
&lt;p&gt;While running under CONFIG_FORTIFY_SOURCE=y, syzkaller reported:&lt;/p&gt;
&lt;p&gt;memcpy: detected field-spanning write (size 129) of single field &amp;#34;target-&amp;gt;sensf_res&amp;#34; at net/nfc/nci/ntf.c:260 (size 18)&lt;/p&gt;
&lt;p&gt;This appears to be a legitimate lack of bounds checking in
nci_add_new_protocol(). Add the missing checks.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-2645-7hqp-7qr7</guid>
    </item>
    <item>
      <title>OESA-2024-2323 — kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2024-2323</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP4: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&#13;
&#13;
In the Linux kernel, the following vulnerability has been resolved:  udf: Fix preallocation discarding at indirect extent boundary  When preallocation extent is the first one in the extent block, the code would corrupt extent tree header instead. Fix the problem and use udf_delete_aext() for deleting extent to avoid some code duplication.(CVE-2022-48946)&#13;
&#13;
In the Linux kernel, the following vulnerability has been resolved:  NFC: nci: Bounds check struct nfc_target arrays  While running under CONFIG_FORTIFY_SOURCE=y, syzkaller reported:    memcpy: detected field-spanning write (size 129) of single field &amp;amp;quot;target-&amp;amp;gt;sensf_res&amp;amp;quot; at net/nfc/nci/ntf.c:260 (size 18)  This appears to be a legitimate lack of bounds checking in nci_add_new_protocol(). Add the missing checks.(CVE-2022-48967)&#13;
&#13;
In the Linux kernel, the following vulnerability has been resolved:  gpio: amd8111: Fix PCI device reference count leak  for_each_pci_dev() is implemented by pci_get_device(). The comment of pci_get_device() says that it will increase the reference count for the returned pci_dev and also decrease the reference count for the input pci_dev @from if it is not NULL.  If we break for_each_pci_dev() loop with pdev not NULL, we need to call pci_dev_put() to decrease the reference count. Add the missing pci_dev_put() after the &amp;amp;apos;out&amp;amp;apos; label. Since pci_dev_put() can handle NULL input parameter, there is no prob…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP4: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&#13;
&#13;
In the Linux kernel, the following vulnerability has been resolved:  udf: Fix preallocation discarding at indirect extent boundary  When preallocation extent is the first one in the extent block, the code would corrupt extent tree header instead. Fix the problem and use udf_delete_aext() for deleting extent to avoid some code duplication.(CVE-2022-48946)&#13;
&#13;
In the Linux kernel, the following vulnerability has been resolved:  NFC: nci: Bounds check struct nfc_target arrays  While running under CONFIG_FORTIFY_SOURCE=y, syzkaller reported:    memcpy: detected field-spanning write (size 129) of single field &amp;amp;quot;target-&amp;amp;gt;sensf_res&amp;amp;quot; at net/nfc/nci/ntf.c:260 (size 18)  This appears to be a legitimate lack of bounds checking in nci_add_new_protocol(). Add the missing checks.(CVE-2022-48967)&#13;
&#13;
In the Linux kernel, the following vulnerability has been resolved:  gpio: amd8111: Fix PCI device reference count leak  for_each_pci_dev() is implemented by pci_get_device(). The comment of pci_get_device() says that it will increase the reference count for the returned pci_dev and also decrease the reference count for the input pci_dev @from if it is not NULL.  If we break for_each_pci_dev() loop with pdev not NULL, we need to call pci_dev_put() to decrease the reference count. Add the missing pci_dev_put() after the &amp;amp;apos;out&amp;amp;apos; label. Since pci_dev_put() can handle NULL input parameter, there is no prob…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2024-2323</guid>
    </item>
    <item>
      <title>SSA-202008 — SSA-202008: Multiple Vulnerabilities in Ruggedcom Rox Before V2.17.0</title>
      <link>https://cve.radiocsirt.org/vuln/ssa-202008</link>
      <description>&lt;p&gt;An issue was discovered in shadow 4.5. newgidmap (in shadow-utils) is setuid and allows an unprivileged user to be placed in a user namespace where setgroups(2) is permitted. This allows an attacker to remove themselves from a supplementary group, which may allow access to certain filesystem paths if the administrator has used &amp;#34;group blacklisting&amp;#34; (e.g., chmod g-rwx) to restrict access to paths. This flaw effectively reverts a security feature in the kernel (in particular, the /proc/self/setgroups knob) to prevent this sort of privilege escalation. GnuPG 2.2.4 and 2.2.5 does not enforce a configuration in which key certification requires an offline master Certify key, which results in apparently valid certifications that occurred only with access to a signing subkey. remember_Ktype in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.30, allows attackers to trigger excessive memory consumption (aka OOM). This can occur during execution of cxxfilt. binutils version 2.32 and earlier contains a Integer Overflow vulnerability in objdump, bfd_get_dynamic_reloc_upper_bound,bfd_canonicalize_dynamic_reloc that can result in Integer overflow trigger heap overflow. Successful exploitation allows execution of arbitrary code.. This attack appear to be exploitable via Local. This vulnerability appears to have been fixed in after commit 3a551c7a1b80fca579461774860574eabfd7f18f. libseccomp before 2.4.0 did not correctly generate 64-bit syscall argument comparisons using the ar…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An issue was discovered in shadow 4.5. newgidmap (in shadow-utils) is setuid and allows an unprivileged user to be placed in a user namespace where setgroups(2) is permitted. This allows an attacker to remove themselves from a supplementary group, which may allow access to certain filesystem paths if the administrator has used &amp;#34;group blacklisting&amp;#34; (e.g., chmod g-rwx) to restrict access to paths. This flaw effectively reverts a security feature in the kernel (in particular, the /proc/self/setgroups knob) to prevent this sort of privilege escalation. GnuPG 2.2.4 and 2.2.5 does not enforce a configuration in which key certification requires an offline master Certify key, which results in apparently valid certifications that occurred only with access to a signing subkey. remember_Ktype in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.30, allows attackers to trigger excessive memory consumption (aka OOM). This can occur during execution of cxxfilt. binutils version 2.32 and earlier contains a Integer Overflow vulnerability in objdump, bfd_get_dynamic_reloc_upper_bound,bfd_canonicalize_dynamic_reloc that can result in Integer overflow trigger heap overflow. Successful exploitation allows execution of arbitrary code.. This attack appear to be exploitable via Local. This vulnerability appears to have been fixed in after commit 3a551c7a1b80fca579461774860574eabfd7f18f. libseccomp before 2.4.0 did not correctly generate 64-bit syscall argument comparisons using the ar…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ssa-202008</guid>
    </item>
    <item>
      <title>SUSE-SU-2024:3983-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2024:3983-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2024:3983-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2022-48967</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-48967</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux, Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe, Ubuntu:Pro:16.04:LTS: linux-oracle, Ubuntu:Pro:16.04:LTS: linux and 147 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: NFC: nci: Bounds check struct nfc_target arrays While running under CONFIG_FORTIFY_SOURCE=y, syzkaller reported:   memcpy: detected field-spanning write (size 129) of single field &amp;#34;target-&amp;gt;sensf_res&amp;#34; at net/nfc/nci/ntf.c:260 (size 18) This appears to be a legitimate lack of bounds checking in nci_add_new_protocol(). Add the missing checks.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux, Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe, Ubuntu:Pro:16.04:LTS: linux-oracle, Ubuntu:Pro:16.04:LTS: linux and 147 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: NFC: nci: Bounds check struct nfc_target arrays While running under CONFIG_FORTIFY_SOURCE=y, syzkaller reported:   memcpy: detected field-spanning write (size 129) of single field &amp;#34;target-&amp;gt;sensf_res&amp;#34; at net/nfc/nci/ntf.c:260 (size 18) This appears to be a legitimate lack of bounds checking in nci_add_new_protocol(). Add the missing checks.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-48967</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-3251 — Linux Kernel: Mehrere Schwachstellen ermöglichen Denial of Service</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-3251</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen oder andere, nicht näher bekannte Auswirkungen zu erzielen..&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen oder andere, nicht näher bekannte Auswirkungen zu erzielen..&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-3251</guid>
    </item>
  </channel>
</rss>
