<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 15:29:09 +0000</lastBuildDate>
    <item>
      <title>ALSA-2025:11298 — Moderate: kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2025:11298</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: bpftool, AlmaLinux:8: kernel, AlmaLinux:8: kernel-abi-stablelists, AlmaLinux:8: kernel-core, AlmaLinux:8: kernel-cross-headers, AlmaLinux:8: kernel-debug, AlmaLinux:8: kernel-debug-core, AlmaLinux:8: kernel-debug-devel, AlmaLinux:8: kernel-debug-modules, AlmaLinux:8: kernel-debug-modules-extra and 15 more&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: cifs: potential buffer overflow in handling symlinks (CVE-2022-49058)
  * kernel: media: uvcvideo: Remove dangling pointers (CVE-2024-58002)
  * kernel: media: uvcvideo: Fix double free in error path (CVE-2024-57980)
  * kernel: x86/microcode/AMD: Fix out-of-bounds on systems with CPU-less NUMA nodes (CVE-2025-21991)
  * kernel: net: atm: fix use after free in lec_send() (CVE-2025-22004)
  * kernel: ext4: fix off-by-one error in do_split (CVE-2025-23150)
  * kernel: ext4: ignore xattrs past end (CVE-2025-37738)
  * kernel: misc/vmw_vmci: fix an infoleak in vmci_host_do_receive_datagram() (CVE-2022-49788)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: bpftool, AlmaLinux:8: kernel, AlmaLinux:8: kernel-abi-stablelists, AlmaLinux:8: kernel-core, AlmaLinux:8: kernel-cross-headers, AlmaLinux:8: kernel-debug, AlmaLinux:8: kernel-debug-core, AlmaLinux:8: kernel-debug-devel, AlmaLinux:8: kernel-debug-modules, AlmaLinux:8: kernel-debug-modules-extra and 15 more&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: cifs: potential buffer overflow in handling symlinks (CVE-2022-49058)
  * kernel: media: uvcvideo: Remove dangling pointers (CVE-2024-58002)
  * kernel: media: uvcvideo: Fix double free in error path (CVE-2024-57980)
  * kernel: x86/microcode/AMD: Fix out-of-bounds on systems with CPU-less NUMA nodes (CVE-2025-21991)
  * kernel: net: atm: fix use after free in lec_send() (CVE-2025-22004)
  * kernel: ext4: fix off-by-one error in do_split (CVE-2025-23150)
  * kernel: ext4: ignore xattrs past end (CVE-2025-37738)
  * kernel: misc/vmw_vmci: fix an infoleak in vmci_host_do_receive_datagram() (CVE-2022-49788)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2025:11298</guid>
    </item>
    <item>
      <title>bdu:2025-06036</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-06036</link>
      <description>bdu:2025-06036</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-06036</guid>
    </item>
    <item>
      <title>certfr-2025-avi-0252 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de SUSE. Certaines d'entre elles permettent à un at…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0252</link>
      <description>certfr-2025-avi-0252</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0252</guid>
    </item>
    <item>
      <title>EUVD-2026-344657</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-344657</link>
      <description>EUVD-2026-344657</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-344657</guid>
    </item>
    <item>
      <title>fkie_cve-2022-49058</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-49058</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;cifs: potential buffer overflow in handling symlinks&lt;/p&gt;
&lt;p&gt;Smatch printed a warning:
	arch/x86/crypto/poly1305_glue.c:198 poly1305_update_arch() error:
	__memcpy() &amp;#39;dctx-&amp;gt;buf&amp;#39; too small (16 vs u32max)&lt;/p&gt;
&lt;p&gt;It&amp;#39;s caused because Smatch marks &amp;#39;link_len&amp;#39; as untrusted since it comes
from sscanf(). Add a check to ensure that &amp;#39;link_len&amp;#39; is not larger than
the size of the &amp;#39;link_str&amp;#39; buffer.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;cifs: potential buffer overflow in handling symlinks&lt;/p&gt;
&lt;p&gt;Smatch printed a warning:
	arch/x86/crypto/poly1305_glue.c:198 poly1305_update_arch() error:
	__memcpy() &amp;#39;dctx-&amp;gt;buf&amp;#39; too small (16 vs u32max)&lt;/p&gt;
&lt;p&gt;It&amp;#39;s caused because Smatch marks &amp;#39;link_len&amp;#39; as untrusted since it comes
from sscanf(). Add a check to ensure that &amp;#39;link_len&amp;#39; is not larger than
the size of the &amp;#39;link_str&amp;#39; buffer.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-49058</guid>
    </item>
    <item>
      <title>GHSA-8x6x-mcww-82p3</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-8x6x-mcww-82p3</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;cifs: potential buffer overflow in handling symlinks&lt;/p&gt;
&lt;p&gt;Smatch printed a warning:
	arch/x86/crypto/poly1305_glue.c:198 poly1305_update_arch() error:
	__memcpy() &amp;#39;dctx-&amp;gt;buf&amp;#39; too small (16 vs u32max)&lt;/p&gt;
&lt;p&gt;It&amp;#39;s caused because Smatch marks &amp;#39;link_len&amp;#39; as untrusted since it comes
from sscanf(). Add a check to ensure that &amp;#39;link_len&amp;#39; is not larger than
the size of the &amp;#39;link_str&amp;#39; buffer.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;cifs: potential buffer overflow in handling symlinks&lt;/p&gt;
&lt;p&gt;Smatch printed a warning:
	arch/x86/crypto/poly1305_glue.c:198 poly1305_update_arch() error:
	__memcpy() &amp;#39;dctx-&amp;gt;buf&amp;#39; too small (16 vs u32max)&lt;/p&gt;
&lt;p&gt;It&amp;#39;s caused because Smatch marks &amp;#39;link_len&amp;#39; as untrusted since it comes
from sscanf(). Add a check to ensure that &amp;#39;link_len&amp;#39; is not larger than
the size of the &amp;#39;link_str&amp;#39; buffer.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-8x6x-mcww-82p3</guid>
    </item>
    <item>
      <title>RHSA-2023:2458 — Red Hat Security Advisory: kernel security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2023:2458</link>
      <description>&lt;p&gt;hw: cpu: AMD CPUs may transiently execute beyond unconditional direct branch kernel: ext4: kernel bug in ext4_write_inline_data_end() kernel: malicious data for FBIOPUT_VSCREENINFO ioctl may cause OOB write memory kernel: hwmon: (mlxreg-fan) Return non-zero value when fan current state is enforced from sysfs kernel: mlxsw: thermal: Fix out-of-bounds memory accesses kernel: mlxsw: spectrum: Protect driver from buggy firmware kernel: net: stmmac: fix tc flower deletion for VLAN priority Rx steering kernel: can: etas_es58x: es58x_rx_err_msg(): fix memory leak in error path kernel: possible race condition in drivers/tty/tty_buffers.c kernel: KVM: NULL pointer dereference in kvm_mmu_invpcid_gva kernel: use-after-free in free_pipe_info() could lead to privilege escalation kernel: KVM: nVMX: missing IBPB when exiting from nested guest can lead to Spectre v2 attacks kernel: netfilter: nf_conntrack_irc message handling issue kernel: race condition in xfrm_probe_algs can lead to OOB read/write kernel: out-of-bounds read in fib_nh_match of the file net/ipv4/fib_semantics.c kernel: race condition in hugetlb_no_page() in mm/hugetlb.c kernel: memory leak in ipv6_renew_options() kernel: data races around icsk-&amp;gt;icsk_af_ops in do_ipv6_setsockopt kernel: data races around sk-&amp;gt;sk_prot kernel: memory leak in l2cap_recv_acldata of the file net/bluetooth/l2cap_core.c kernel: denial of service in follow_page_pte in mm/gup.c due to poisoned pte entry kernel: use-after-free after failed devlink relo…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;hw: cpu: AMD CPUs may transiently execute beyond unconditional direct branch kernel: ext4: kernel bug in ext4_write_inline_data_end() kernel: malicious data for FBIOPUT_VSCREENINFO ioctl may cause OOB write memory kernel: hwmon: (mlxreg-fan) Return non-zero value when fan current state is enforced from sysfs kernel: mlxsw: thermal: Fix out-of-bounds memory accesses kernel: mlxsw: spectrum: Protect driver from buggy firmware kernel: net: stmmac: fix tc flower deletion for VLAN priority Rx steering kernel: can: etas_es58x: es58x_rx_err_msg(): fix memory leak in error path kernel: possible race condition in drivers/tty/tty_buffers.c kernel: KVM: NULL pointer dereference in kvm_mmu_invpcid_gva kernel: use-after-free in free_pipe_info() could lead to privilege escalation kernel: KVM: nVMX: missing IBPB when exiting from nested guest can lead to Spectre v2 attacks kernel: netfilter: nf_conntrack_irc message handling issue kernel: race condition in xfrm_probe_algs can lead to OOB read/write kernel: out-of-bounds read in fib_nh_match of the file net/ipv4/fib_semantics.c kernel: race condition in hugetlb_no_page() in mm/hugetlb.c kernel: memory leak in ipv6_renew_options() kernel: data races around icsk-&amp;gt;icsk_af_ops in do_ipv6_setsockopt kernel: data races around sk-&amp;gt;sk_prot kernel: memory leak in l2cap_recv_acldata of the file net/bluetooth/l2cap_core.c kernel: denial of service in follow_page_pte in mm/gup.c due to poisoned pte entry kernel: use-after-free after failed devlink relo…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2023:2458</guid>
    </item>
    <item>
      <title>RHSA-2025:11299 — Red Hat Security Advisory: kernel-rt security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2025:11299</link>
      <description>&lt;p&gt;kernel: cifs: potential buffer overflow in handling symlinks kernel: misc/vmw_vmci: fix an infoleak in vmci_host_do_receive_datagram() kernel: media: uvcvideo: Fix double free in error path kernel: media: uvcvideo: Remove dangling pointers kernel: x86/microcode/AMD: Fix out-of-bounds on systems with CPU-less NUMA nodes kernel: net: atm: fix use after free in lec_send() kernel: ext4: fix off-by-one error in do_split kernel: ext4: ignore xattrs past end&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;kernel: cifs: potential buffer overflow in handling symlinks kernel: misc/vmw_vmci: fix an infoleak in vmci_host_do_receive_datagram() kernel: media: uvcvideo: Fix double free in error path kernel: media: uvcvideo: Remove dangling pointers kernel: x86/microcode/AMD: Fix out-of-bounds on systems with CPU-less NUMA nodes kernel: net: atm: fix use after free in lec_send() kernel: ext4: fix off-by-one error in do_split kernel: ext4: ignore xattrs past end&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2025:11299</guid>
    </item>
    <item>
      <title>SSA-202008 — SSA-202008: Multiple Vulnerabilities in Ruggedcom Rox Before V2.17.0</title>
      <link>https://cve.radiocsirt.org/vuln/ssa-202008</link>
      <description>&lt;p&gt;An issue was discovered in shadow 4.5. newgidmap (in shadow-utils) is setuid and allows an unprivileged user to be placed in a user namespace where setgroups(2) is permitted. This allows an attacker to remove themselves from a supplementary group, which may allow access to certain filesystem paths if the administrator has used &amp;#34;group blacklisting&amp;#34; (e.g., chmod g-rwx) to restrict access to paths. This flaw effectively reverts a security feature in the kernel (in particular, the /proc/self/setgroups knob) to prevent this sort of privilege escalation. GnuPG 2.2.4 and 2.2.5 does not enforce a configuration in which key certification requires an offline master Certify key, which results in apparently valid certifications that occurred only with access to a signing subkey. remember_Ktype in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.30, allows attackers to trigger excessive memory consumption (aka OOM). This can occur during execution of cxxfilt. binutils version 2.32 and earlier contains a Integer Overflow vulnerability in objdump, bfd_get_dynamic_reloc_upper_bound,bfd_canonicalize_dynamic_reloc that can result in Integer overflow trigger heap overflow. Successful exploitation allows execution of arbitrary code.. This attack appear to be exploitable via Local. This vulnerability appears to have been fixed in after commit 3a551c7a1b80fca579461774860574eabfd7f18f. libseccomp before 2.4.0 did not correctly generate 64-bit syscall argument comparisons using the ar…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An issue was discovered in shadow 4.5. newgidmap (in shadow-utils) is setuid and allows an unprivileged user to be placed in a user namespace where setgroups(2) is permitted. This allows an attacker to remove themselves from a supplementary group, which may allow access to certain filesystem paths if the administrator has used &amp;#34;group blacklisting&amp;#34; (e.g., chmod g-rwx) to restrict access to paths. This flaw effectively reverts a security feature in the kernel (in particular, the /proc/self/setgroups knob) to prevent this sort of privilege escalation. GnuPG 2.2.4 and 2.2.5 does not enforce a configuration in which key certification requires an offline master Certify key, which results in apparently valid certifications that occurred only with access to a signing subkey. remember_Ktype in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.30, allows attackers to trigger excessive memory consumption (aka OOM). This can occur during execution of cxxfilt. binutils version 2.32 and earlier contains a Integer Overflow vulnerability in objdump, bfd_get_dynamic_reloc_upper_bound,bfd_canonicalize_dynamic_reloc that can result in Integer overflow trigger heap overflow. Successful exploitation allows execution of arbitrary code.. This attack appear to be exploitable via Local. This vulnerability appears to have been fixed in after commit 3a551c7a1b80fca579461774860574eabfd7f18f. libseccomp before 2.4.0 did not correctly generate 64-bit syscall argument comparisons using the ar…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ssa-202008</guid>
    </item>
    <item>
      <title>SUSE-SU-2025:1176-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2025:1176-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2025:1176-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2022-49058</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-49058</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux, Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe, Ubuntu:Pro:16.04:LTS: linux-oracle, Ubuntu:Pro:16.04:LTS: linux and 137 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: cifs: potential buffer overflow in handling symlinks Smatch printed a warning: 	arch/x86/crypto/poly1305_glue.c:198 poly1305_update_arch() error: 	__memcpy() &amp;#39;dctx-&amp;gt;buf&amp;#39; too small (16 vs u32max) It&amp;#39;s caused because Smatch marks &amp;#39;link_len&amp;#39; as untrusted since it comes from sscanf(). Add a check to ensure that &amp;#39;link_len&amp;#39; is not larger than the size of the &amp;#39;link_str&amp;#39; buffer.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux, Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe, Ubuntu:Pro:16.04:LTS: linux-oracle, Ubuntu:Pro:16.04:LTS: linux and 137 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: cifs: potential buffer overflow in handling symlinks Smatch printed a warning: 	arch/x86/crypto/poly1305_glue.c:198 poly1305_update_arch() error: 	__memcpy() &amp;#39;dctx-&amp;gt;buf&amp;#39; too small (16 vs u32max) It&amp;#39;s caused because Smatch marks &amp;#39;link_len&amp;#39; as untrusted since it comes from sscanf(). Add a check to ensure that &amp;#39;link_len&amp;#39; is not larger than the size of the &amp;#39;link_str&amp;#39; buffer.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-49058</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-1905 — IBM QRadar SIEM Komponente: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1905</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in IBM QRadar SIEM Komponenten ausnutzen, um Daten zu manipulieren, um einen Denial of Service Angriff durchzuführen, um beliebigen Programmcode auszuführen, um Sicherheitsvorkehrungen zu umgehen, und um Informationen offenzulegen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in IBM QRadar SIEM Komponenten ausnutzen, um Daten zu manipulieren, um einen Denial of Service Angriff durchzuführen, um beliebigen Programmcode auszuführen, um Sicherheitsvorkehrungen zu umgehen, und um Informationen offenzulegen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1905</guid>
    </item>
  </channel>
</rss>
