<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 14:58:14 +0000</lastBuildDate>
    <item>
      <title>bdu:2025-14278</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-14278</link>
      <description>bdu:2025-14278</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-14278</guid>
    </item>
    <item>
      <title>certfr-2024-avi-0999 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de SUSE. Certaines d'entre elles permettent à un at…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0999</link>
      <description>certfr-2024-avi-0999</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2024-avi-0999</guid>
    </item>
    <item>
      <title>EUVD-2026-310301</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-310301</link>
      <description>EUVD-2026-310301</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-310301</guid>
    </item>
    <item>
      <title>fkie_cve-2022-49021</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-49021</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;net: phy: fix null-ptr-deref while probe() failed&lt;/p&gt;
&lt;p&gt;I got a null-ptr-deref report as following when doing fault injection test:&lt;/p&gt;
&lt;p&gt;BUG: kernel NULL pointer dereference, address: 0000000000000058
Oops: 0000 [#1] PREEMPT SMP KASAN PTI
CPU: 1 PID: 253 Comm: 507-spi-dm9051 Tainted: G    B            N 6.1.0-rc3+
Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.13.0-1ubuntu1.1 04/01/2014
RIP: 0010:klist_put+0x2d/0xd0
Call Trace:
 &amp;lt;TASK&amp;gt;
 klist_remove+0xf1/0x1c0
 device_release_driver_internal+0x23e/0x2d0
 bus_remove_device+0x1bd/0x240
 device_del+0x357/0x770
 phy_device_remove+0x11/0x30
 mdiobus_unregister+0xa5/0x140
 release_nodes+0x6a/0xa0
 devres_release_all+0xf8/0x150
 device_unbind_cleanup+0x19/0xd0&lt;/p&gt;
&lt;p&gt;//probe path:
phy_device_register()
  device_add()&lt;/p&gt;
&lt;p&gt;phy_connect
  phy_attach_direct() //set device driver
    probe() //it&amp;#39;s failed, driver is not bound
    device_bind_driver() // probe failed, it&amp;#39;s not called&lt;/p&gt;
&lt;p&gt;//remove path:
phy_device_remove()
  device_del()
    device_release_driver_internal()
      __device_release_driver() //dev-&amp;gt;drv is not NULL
        klist_remove() &amp;lt;- knode_driver is not added yet, cause null-ptr-deref&lt;/p&gt;
&lt;p&gt;In phy_attach_direct(), after setting the &amp;#39;dev-&amp;gt;driver&amp;#39;, probe() fails,
device_bind_driver() is not called, so the knode_driver-&amp;gt;n_klist is not
set, then it causes null-ptr-deref in __device_release_driver() while
deleting device. Fix this by setting dev-&amp;gt;driver to NULL in the…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;net: phy: fix null-ptr-deref while probe() failed&lt;/p&gt;
&lt;p&gt;I got a null-ptr-deref report as following when doing fault injection test:&lt;/p&gt;
&lt;p&gt;BUG: kernel NULL pointer dereference, address: 0000000000000058
Oops: 0000 [#1] PREEMPT SMP KASAN PTI
CPU: 1 PID: 253 Comm: 507-spi-dm9051 Tainted: G    B            N 6.1.0-rc3+
Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.13.0-1ubuntu1.1 04/01/2014
RIP: 0010:klist_put+0x2d/0xd0
Call Trace:
 &amp;lt;TASK&amp;gt;
 klist_remove+0xf1/0x1c0
 device_release_driver_internal+0x23e/0x2d0
 bus_remove_device+0x1bd/0x240
 device_del+0x357/0x770
 phy_device_remove+0x11/0x30
 mdiobus_unregister+0xa5/0x140
 release_nodes+0x6a/0xa0
 devres_release_all+0xf8/0x150
 device_unbind_cleanup+0x19/0xd0&lt;/p&gt;
&lt;p&gt;//probe path:
phy_device_register()
  device_add()&lt;/p&gt;
&lt;p&gt;phy_connect
  phy_attach_direct() //set device driver
    probe() //it&amp;#39;s failed, driver is not bound
    device_bind_driver() // probe failed, it&amp;#39;s not called&lt;/p&gt;
&lt;p&gt;//remove path:
phy_device_remove()
  device_del()
    device_release_driver_internal()
      __device_release_driver() //dev-&amp;gt;drv is not NULL
        klist_remove() &amp;lt;- knode_driver is not added yet, cause null-ptr-deref&lt;/p&gt;
&lt;p&gt;In phy_attach_direct(), after setting the &amp;#39;dev-&amp;gt;driver&amp;#39;, probe() fails,
device_bind_driver() is not called, so the knode_driver-&amp;gt;n_klist is not
set, then it causes null-ptr-deref in __device_release_driver() while
deleting device. Fix this by setting dev-&amp;gt;driver to NULL in the…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-49021</guid>
    </item>
    <item>
      <title>GHSA-44h7-hpp5-qghj</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-44h7-hpp5-qghj</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;net: phy: fix null-ptr-deref while probe() failed&lt;/p&gt;
&lt;p&gt;I got a null-ptr-deref report as following when doing fault injection test:&lt;/p&gt;
&lt;p&gt;BUG: kernel NULL pointer dereference, address: 0000000000000058
Oops: 0000 [#1] PREEMPT SMP KASAN PTI
CPU: 1 PID: 253 Comm: 507-spi-dm9051 Tainted: G    B            N 6.1.0-rc3+
Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.13.0-1ubuntu1.1 04/01/2014
RIP: 0010:klist_put+0x2d/0xd0
Call Trace:
 &amp;lt;TASK&amp;gt;
 klist_remove+0xf1/0x1c0
 device_release_driver_internal+0x23e/0x2d0
 bus_remove_device+0x1bd/0x240
 device_del+0x357/0x770
 phy_device_remove+0x11/0x30
 mdiobus_unregister+0xa5/0x140
 release_nodes+0x6a/0xa0
 devres_release_all+0xf8/0x150
 device_unbind_cleanup+0x19/0xd0&lt;/p&gt;
&lt;p&gt;//probe path:
phy_device_register()
  device_add()&lt;/p&gt;
&lt;p&gt;phy_connect
  phy_attach_direct() //set device driver
    probe() //it&amp;#39;s failed, driver is not bound
    device_bind_driver() // probe failed, it&amp;#39;s not called&lt;/p&gt;
&lt;p&gt;//remove path:
phy_device_remove()
  device_del()
    device_release_driver_internal()
      __device_release_driver() //dev-&amp;gt;drv is not NULL
        klist_remove() &amp;lt;- knode_driver is not added yet, cause null-ptr-deref&lt;/p&gt;
&lt;p&gt;In phy_attach_direct(), after setting the &amp;#39;dev-&amp;gt;driver&amp;#39;, probe() fails,
device_bind_driver() is not called, so the knode_driver-&amp;gt;n_klist is not
set, then it causes null-ptr-deref in __device_release_driver() while
deleting device. Fix this by setting dev-&amp;gt;driver to NULL in the…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;net: phy: fix null-ptr-deref while probe() failed&lt;/p&gt;
&lt;p&gt;I got a null-ptr-deref report as following when doing fault injection test:&lt;/p&gt;
&lt;p&gt;BUG: kernel NULL pointer dereference, address: 0000000000000058
Oops: 0000 [#1] PREEMPT SMP KASAN PTI
CPU: 1 PID: 253 Comm: 507-spi-dm9051 Tainted: G    B            N 6.1.0-rc3+
Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.13.0-1ubuntu1.1 04/01/2014
RIP: 0010:klist_put+0x2d/0xd0
Call Trace:
 &amp;lt;TASK&amp;gt;
 klist_remove+0xf1/0x1c0
 device_release_driver_internal+0x23e/0x2d0
 bus_remove_device+0x1bd/0x240
 device_del+0x357/0x770
 phy_device_remove+0x11/0x30
 mdiobus_unregister+0xa5/0x140
 release_nodes+0x6a/0xa0
 devres_release_all+0xf8/0x150
 device_unbind_cleanup+0x19/0xd0&lt;/p&gt;
&lt;p&gt;//probe path:
phy_device_register()
  device_add()&lt;/p&gt;
&lt;p&gt;phy_connect
  phy_attach_direct() //set device driver
    probe() //it&amp;#39;s failed, driver is not bound
    device_bind_driver() // probe failed, it&amp;#39;s not called&lt;/p&gt;
&lt;p&gt;//remove path:
phy_device_remove()
  device_del()
    device_release_driver_internal()
      __device_release_driver() //dev-&amp;gt;drv is not NULL
        klist_remove() &amp;lt;- knode_driver is not added yet, cause null-ptr-deref&lt;/p&gt;
&lt;p&gt;In phy_attach_direct(), after setting the &amp;#39;dev-&amp;gt;driver&amp;#39;, probe() fails,
device_bind_driver() is not called, so the knode_driver-&amp;gt;n_klist is not
set, then it causes null-ptr-deref in __device_release_driver() while
deleting device. Fix this by setting dev-&amp;gt;driver to NULL in the…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-44h7-hpp5-qghj</guid>
    </item>
    <item>
      <title>OESA-2024-2370 — kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2024-2370</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP4: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&#13;
&#13;
In the Linux kernel, the following vulnerability has been resolved:  usb: gadget: uvc: Prevent buffer overflow in setup handler  Setup function uvc_function_setup permits control transfer requests with up to 64 bytes of payload (UVC_MAX_REQUEST_SIZE), data stage handler for OUT transfer uses memcpy to copy req-&amp;amp;gt;actual bytes to uvc_event-&amp;amp;gt;data.data array of size 60. This may result in an overflow of 4 bytes.(CVE-2022-48948)&#13;
&#13;
In the Linux kernel, the following vulnerability has been resolved:  igb: Initialize mailbox message for VF reset  When a MAC address is not assigned to the VF, that portion of the message sent to the VF is not set. The memory, however, is allocated from the stack meaning that information may be leaked to the VM. Initialize the message buffer to 0 so that no information is passed to the VM in this case.(CVE-2022-48949)&#13;
&#13;
In the Linux kernel, the following vulnerability has been resolved:  net: hisilicon: Fix potential use-after-free in hix5hd2_rx()  The skb is delivered to napi_gro_receive() which may free it, after calling this, dereferencing skb may trigger use-after-free.(CVE-2022-48960)&#13;
&#13;
In the Linux kernel, the following vulnerability has been resolved:  net: hisilicon: Fix potential use-after-free in hisi_femac_rx()  The skb is delivered to napi_gro_receive() which may free it, after calling this, dereferencing skb may trigger use-after-free.(CVE-2022-48962)&#13;
&#13;
In…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP4: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&#13;
&#13;
In the Linux kernel, the following vulnerability has been resolved:  usb: gadget: uvc: Prevent buffer overflow in setup handler  Setup function uvc_function_setup permits control transfer requests with up to 64 bytes of payload (UVC_MAX_REQUEST_SIZE), data stage handler for OUT transfer uses memcpy to copy req-&amp;amp;gt;actual bytes to uvc_event-&amp;amp;gt;data.data array of size 60. This may result in an overflow of 4 bytes.(CVE-2022-48948)&#13;
&#13;
In the Linux kernel, the following vulnerability has been resolved:  igb: Initialize mailbox message for VF reset  When a MAC address is not assigned to the VF, that portion of the message sent to the VF is not set. The memory, however, is allocated from the stack meaning that information may be leaked to the VM. Initialize the message buffer to 0 so that no information is passed to the VM in this case.(CVE-2022-48949)&#13;
&#13;
In the Linux kernel, the following vulnerability has been resolved:  net: hisilicon: Fix potential use-after-free in hix5hd2_rx()  The skb is delivered to napi_gro_receive() which may free it, after calling this, dereferencing skb may trigger use-after-free.(CVE-2022-48960)&#13;
&#13;
In the Linux kernel, the following vulnerability has been resolved:  net: hisilicon: Fix potential use-after-free in hisi_femac_rx()  The skb is delivered to napi_gro_receive() which may free it, after calling this, dereferencing skb may trigger use-after-free.(CVE-2022-48962)&#13;
&#13;
In…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2024-2370</guid>
    </item>
    <item>
      <title>SUSE-SU-2024:3983-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2024:3983-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2024:3983-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2022-49021</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-49021</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux, Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe, Ubuntu:Pro:16.04:LTS: linux-oracle, Ubuntu:Pro:16.04:LTS: linux and 147 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: net: phy: fix null-ptr-deref while probe() failed I got a null-ptr-deref report as following when doing fault injection test: BUG: kernel NULL pointer dereference, address: 0000000000000058 Oops: 0000 [#1] PREEMPT SMP KASAN PTI CPU: 1 PID: 253 Comm: 507-spi-dm9051 Tainted: G    B            N 6.1.0-rc3+ Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.13.0-1ubuntu1.1 04/01/2014 RIP: 0010:klist_put+0x2d/0xd0 Call Trace:  &amp;lt;TASK&amp;gt;  klist_remove+0xf1/0x1c0  device_release_driver_internal+0x23e/0x2d0  bus_remove_device+0x1bd/0x240  device_del+0x357/0x770  phy_device_remove+0x11/0x30  mdiobus_unregister+0xa5/0x140  release_nodes+0x6a/0xa0  devres_release_all+0xf8/0x150  device_unbind_cleanup+0x19/0xd0 //probe path: phy_device_register()   device_add() phy_connect   phy_attach_direct() //set device driver     probe() //it&amp;#39;s failed, driver is not bound     device_bind_driver() // probe failed, it&amp;#39;s not called //remove path: phy_device_remove()   device_del()     device_release_driver_internal()       __device_release_driver() //dev-&amp;gt;drv is not NULL         klist_remove() &amp;lt;- knode_driver is not added yet, cause null-ptr-deref In phy_attach_direct(), after setting the &amp;#39;dev-&amp;gt;driver&amp;#39;, probe() fails, device_bind_driver() is not called, so the knode_driver-&amp;gt;n_klist is not set, then it causes null-ptr-deref in __device_release_driver() while deleting device. Fix this by setting dev-&amp;gt;driver to NULL in the error…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux, Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe, Ubuntu:Pro:16.04:LTS: linux-oracle, Ubuntu:Pro:16.04:LTS: linux and 147 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: net: phy: fix null-ptr-deref while probe() failed I got a null-ptr-deref report as following when doing fault injection test: BUG: kernel NULL pointer dereference, address: 0000000000000058 Oops: 0000 [#1] PREEMPT SMP KASAN PTI CPU: 1 PID: 253 Comm: 507-spi-dm9051 Tainted: G    B            N 6.1.0-rc3+ Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.13.0-1ubuntu1.1 04/01/2014 RIP: 0010:klist_put+0x2d/0xd0 Call Trace:  &amp;lt;TASK&amp;gt;  klist_remove+0xf1/0x1c0  device_release_driver_internal+0x23e/0x2d0  bus_remove_device+0x1bd/0x240  device_del+0x357/0x770  phy_device_remove+0x11/0x30  mdiobus_unregister+0xa5/0x140  release_nodes+0x6a/0xa0  devres_release_all+0xf8/0x150  device_unbind_cleanup+0x19/0xd0 //probe path: phy_device_register()   device_add() phy_connect   phy_attach_direct() //set device driver     probe() //it&amp;#39;s failed, driver is not bound     device_bind_driver() // probe failed, it&amp;#39;s not called //remove path: phy_device_remove()   device_del()     device_release_driver_internal()       __device_release_driver() //dev-&amp;gt;drv is not NULL         klist_remove() &amp;lt;- knode_driver is not added yet, cause null-ptr-deref In phy_attach_direct(), after setting the &amp;#39;dev-&amp;gt;driver&amp;#39;, probe() fails, device_bind_driver() is not called, so the knode_driver-&amp;gt;n_klist is not set, then it causes null-ptr-deref in __device_release_driver() while deleting device. Fix this by setting dev-&amp;gt;driver to NULL in the error…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-49021</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-3251 — Linux Kernel: Mehrere Schwachstellen ermöglichen Denial of Service</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-3251</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen oder andere, nicht näher bekannte Auswirkungen zu erzielen..&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen oder andere, nicht näher bekannte Auswirkungen zu erzielen..&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-3251</guid>
    </item>
  </channel>
</rss>
