<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 05:48:58 +0000</lastBuildDate>
    <item>
      <title>bdu:2025-10584</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-10584</link>
      <description>bdu:2025-10584</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-10584</guid>
    </item>
    <item>
      <title>certfr-2025-avi-0307 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de SUSE. Certaines d'entre elles permettent à un at…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0307</link>
      <description>certfr-2025-avi-0307</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0307</guid>
    </item>
    <item>
      <title>EUVD-2026-344696</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-344696</link>
      <description>EUVD-2026-344696</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-344696</guid>
    </item>
    <item>
      <title>fkie_cve-2022-49238</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-49238</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;ath11k: free peer for station when disconnect from AP for QCA6390/WCN6855&lt;/p&gt;
&lt;p&gt;Commit b4a0f54156ac (&amp;#34;ath11k: move peer delete after vdev stop of station
for QCA6390 and WCN6855&amp;#34;) is to fix firmware crash by changing the WMI
command sequence, but actually skip all the peer delete operation, then
it lead commit 58595c9874c6 (&amp;#34;ath11k: Fixing dangling pointer issue upon
peer delete failure&amp;#34;) not take effect, and then happened a use-after-free
warning from KASAN. because the peer-&amp;gt;sta is not set to NULL and then used
later.&lt;/p&gt;
&lt;p&gt;Change to only skip the WMI_PEER_DELETE_CMDID for QCA6390/WCN6855.&lt;/p&gt;
&lt;p&gt;log of user-after-free:&lt;/p&gt;
&lt;p&gt;[  534.888665] BUG: KASAN: use-after-free in ath11k_dp_rx_update_peer_stats+0x912/0xc10 [ath11k]
[  534.888696] Read of size 8 at addr ffff8881396bb1b8 by task rtcwake/2860&lt;/p&gt;
&lt;p&gt;[  534.888705] CPU: 4 PID: 2860 Comm: rtcwake Kdump: loaded Tainted: G        W         5.15.0-wt-ath+ #523
[  534.888712] Hardware name: Intel(R) Client Systems NUC8i7HVK/NUC8i7HVB, BIOS HNKBLi70.86A.0067.2021.0528.1339 05/28/2021
[  534.888716] Call Trace:
[  534.888720]  &amp;lt;IRQ&amp;gt;
[  534.888726]  dump_stack_lvl+0x57/0x7d
[  534.888736]  print_address_description.constprop.0+0x1f/0x170
[  534.888745]  ? ath11k_dp_rx_update_peer_stats+0x912/0xc10 [ath11k]
[  534.888771]  kasan_report.cold+0x83/0xdf
[  534.888783]  ? ath11k_dp_rx_update_peer_stats+0x912/0xc10 [ath11k]
[  534.888810]  ath11k_dp_rx_update_peer_stats+0x912/0xc10 [ath11k]
[…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;ath11k: free peer for station when disconnect from AP for QCA6390/WCN6855&lt;/p&gt;
&lt;p&gt;Commit b4a0f54156ac (&amp;#34;ath11k: move peer delete after vdev stop of station
for QCA6390 and WCN6855&amp;#34;) is to fix firmware crash by changing the WMI
command sequence, but actually skip all the peer delete operation, then
it lead commit 58595c9874c6 (&amp;#34;ath11k: Fixing dangling pointer issue upon
peer delete failure&amp;#34;) not take effect, and then happened a use-after-free
warning from KASAN. because the peer-&amp;gt;sta is not set to NULL and then used
later.&lt;/p&gt;
&lt;p&gt;Change to only skip the WMI_PEER_DELETE_CMDID for QCA6390/WCN6855.&lt;/p&gt;
&lt;p&gt;log of user-after-free:&lt;/p&gt;
&lt;p&gt;[  534.888665] BUG: KASAN: use-after-free in ath11k_dp_rx_update_peer_stats+0x912/0xc10 [ath11k]
[  534.888696] Read of size 8 at addr ffff8881396bb1b8 by task rtcwake/2860&lt;/p&gt;
&lt;p&gt;[  534.888705] CPU: 4 PID: 2860 Comm: rtcwake Kdump: loaded Tainted: G        W         5.15.0-wt-ath+ #523
[  534.888712] Hardware name: Intel(R) Client Systems NUC8i7HVK/NUC8i7HVB, BIOS HNKBLi70.86A.0067.2021.0528.1339 05/28/2021
[  534.888716] Call Trace:
[  534.888720]  &amp;lt;IRQ&amp;gt;
[  534.888726]  dump_stack_lvl+0x57/0x7d
[  534.888736]  print_address_description.constprop.0+0x1f/0x170
[  534.888745]  ? ath11k_dp_rx_update_peer_stats+0x912/0xc10 [ath11k]
[  534.888771]  kasan_report.cold+0x83/0xdf
[  534.888783]  ? ath11k_dp_rx_update_peer_stats+0x912/0xc10 [ath11k]
[  534.888810]  ath11k_dp_rx_update_peer_stats+0x912/0xc10 [ath11k]
[…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-49238</guid>
    </item>
    <item>
      <title>GHSA-xqq8-xc8f-f7c4</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-xqq8-xc8f-f7c4</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;ath11k: free peer for station when disconnect from AP for QCA6390/WCN6855&lt;/p&gt;
&lt;p&gt;Commit b4a0f54156ac (&amp;#34;ath11k: move peer delete after vdev stop of station
for QCA6390 and WCN6855&amp;#34;) is to fix firmware crash by changing the WMI
command sequence, but actually skip all the peer delete operation, then
it lead commit 58595c9874c6 (&amp;#34;ath11k: Fixing dangling pointer issue upon
peer delete failure&amp;#34;) not take effect, and then happened a use-after-free
warning from KASAN. because the peer-&amp;gt;sta is not set to NULL and then used
later.&lt;/p&gt;
&lt;p&gt;Change to only skip the WMI_PEER_DELETE_CMDID for QCA6390/WCN6855.&lt;/p&gt;
&lt;p&gt;log of user-after-free:&lt;/p&gt;
&lt;p&gt;[  534.888665] BUG: KASAN: use-after-free in ath11k_dp_rx_update_peer_stats+0x912/0xc10 [ath11k]
[  534.888696] Read of size 8 at addr ffff8881396bb1b8 by task rtcwake/2860&lt;/p&gt;
&lt;p&gt;[  534.888705] CPU: 4 PID: 2860 Comm: rtcwake Kdump: loaded Tainted: G        W         5.15.0-wt-ath+ #523
[  534.888712] Hardware name: Intel(R) Client Systems NUC8i7HVK/NUC8i7HVB, BIOS HNKBLi70.86A.0067.2021.0528.1339 05/28/2021
[  534.888716] Call Trace:
[  534.888720]  &amp;lt;IRQ&amp;gt;
[  534.888726]  dump_stack_lvl+0x57/0x7d
[  534.888736]  print_address_description.constprop.0+0x1f/0x170
[  534.888745]  ? ath11k_dp_rx_update_peer_stats+0x912/0xc10 [ath11k]
[  534.888771]  kasan_report.cold+0x83/0xdf
[  534.888783]  ? ath11k_dp_rx_update_peer_stats+0x912/0xc10 [ath11k]
[  534.888810]  ath11k_dp_rx_update_peer_stats+0x912/0xc10 [ath11k]
[…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;ath11k: free peer for station when disconnect from AP for QCA6390/WCN6855&lt;/p&gt;
&lt;p&gt;Commit b4a0f54156ac (&amp;#34;ath11k: move peer delete after vdev stop of station
for QCA6390 and WCN6855&amp;#34;) is to fix firmware crash by changing the WMI
command sequence, but actually skip all the peer delete operation, then
it lead commit 58595c9874c6 (&amp;#34;ath11k: Fixing dangling pointer issue upon
peer delete failure&amp;#34;) not take effect, and then happened a use-after-free
warning from KASAN. because the peer-&amp;gt;sta is not set to NULL and then used
later.&lt;/p&gt;
&lt;p&gt;Change to only skip the WMI_PEER_DELETE_CMDID for QCA6390/WCN6855.&lt;/p&gt;
&lt;p&gt;log of user-after-free:&lt;/p&gt;
&lt;p&gt;[  534.888665] BUG: KASAN: use-after-free in ath11k_dp_rx_update_peer_stats+0x912/0xc10 [ath11k]
[  534.888696] Read of size 8 at addr ffff8881396bb1b8 by task rtcwake/2860&lt;/p&gt;
&lt;p&gt;[  534.888705] CPU: 4 PID: 2860 Comm: rtcwake Kdump: loaded Tainted: G        W         5.15.0-wt-ath+ #523
[  534.888712] Hardware name: Intel(R) Client Systems NUC8i7HVK/NUC8i7HVB, BIOS HNKBLi70.86A.0067.2021.0528.1339 05/28/2021
[  534.888716] Call Trace:
[  534.888720]  &amp;lt;IRQ&amp;gt;
[  534.888726]  dump_stack_lvl+0x57/0x7d
[  534.888736]  print_address_description.constprop.0+0x1f/0x170
[  534.888745]  ? ath11k_dp_rx_update_peer_stats+0x912/0xc10 [ath11k]
[  534.888771]  kasan_report.cold+0x83/0xdf
[  534.888783]  ? ath11k_dp_rx_update_peer_stats+0x912/0xc10 [ath11k]
[  534.888810]  ath11k_dp_rx_update_peer_stats+0x912/0xc10 [ath11k]
[…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-xqq8-xc8f-f7c4</guid>
    </item>
    <item>
      <title>RHSA-2022:7683 — Red Hat Security Advisory: kernel security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2022:7683</link>
      <description>&lt;p&gt;kernel: off-path attacker may inject data or terminate victim&amp;#39;s TCP session kernel: race condition in VT_RESIZEX ioctl when vc_cons[i].d is already NULL leading to NULL pointer dereference kernel: use-after-free vulnerability in function sco_sock_sendmsg() kernel: memory leak for large arguments in video_usercopy function in drivers/media/v4l2-core/v4l2-ioctl.c kernel: veth: ensure skb entering GRO are not cloned. kernel: inet: fully convert sk-&amp;gt;sk_rx_dst to RCU rules kernel: NFSD: Fix READDIR buffer overflow kernel: cpufreq: CPPC: Fix potential memleak in cppc_cpufreq_cpu_init kernel: nvme-rdma: destroy cm id before destroy qp to avoid use after free kernel: regmap: Fix possible double-free in regcache_rbtree_exit() kernel: ethtool: do not perform operations on net devices being unregistered kernel: scsi: scsi_debug: Fix type in min_t to avoid stack OOB kernel: KVM: x86/mmu: Zap _all_ roots when unmapping gfn range in TDP MMU kernel: udmabuf: validate ubuf-&amp;gt;pagecount kernel: drm/virtio: Ensure that objs is not NULL in virtio_gpu_array_put_free() kernel: smb2_ioctl_query_info NULL pointer dereference kernel: NULL pointer dereference in udf_expand_file_adinicbdue() during writeback kernel: swiotlb information leak with DMA_FROM_DEVICE kernel: uninitialized registers on stack in nft_do_chain can cause kernel pointer leakage to UM kernel: race condition in snd_pcm_hw_free leading to use-after-free kernel: use-after-free in tc_new_tfilter() in net/sched/cls_api.c kernel: KVM: cm…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;kernel: off-path attacker may inject data or terminate victim&amp;#39;s TCP session kernel: race condition in VT_RESIZEX ioctl when vc_cons[i].d is already NULL leading to NULL pointer dereference kernel: use-after-free vulnerability in function sco_sock_sendmsg() kernel: memory leak for large arguments in video_usercopy function in drivers/media/v4l2-core/v4l2-ioctl.c kernel: veth: ensure skb entering GRO are not cloned. kernel: inet: fully convert sk-&amp;gt;sk_rx_dst to RCU rules kernel: NFSD: Fix READDIR buffer overflow kernel: cpufreq: CPPC: Fix potential memleak in cppc_cpufreq_cpu_init kernel: nvme-rdma: destroy cm id before destroy qp to avoid use after free kernel: regmap: Fix possible double-free in regcache_rbtree_exit() kernel: ethtool: do not perform operations on net devices being unregistered kernel: scsi: scsi_debug: Fix type in min_t to avoid stack OOB kernel: KVM: x86/mmu: Zap _all_ roots when unmapping gfn range in TDP MMU kernel: udmabuf: validate ubuf-&amp;gt;pagecount kernel: drm/virtio: Ensure that objs is not NULL in virtio_gpu_array_put_free() kernel: smb2_ioctl_query_info NULL pointer dereference kernel: NULL pointer dereference in udf_expand_file_adinicbdue() during writeback kernel: swiotlb information leak with DMA_FROM_DEVICE kernel: uninitialized registers on stack in nft_do_chain can cause kernel pointer leakage to UM kernel: race condition in snd_pcm_hw_free leading to use-after-free kernel: use-after-free in tc_new_tfilter() in net/sched/cls_api.c kernel: KVM: cm…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2022:7683</guid>
    </item>
    <item>
      <title>SUSE-SU-2025:1176-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2025:1176-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2025:1176-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2022-49238</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-49238</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 69 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: ath11k: free peer for station when disconnect from AP for QCA6390/WCN6855 Commit b4a0f54156ac (&amp;#34;ath11k: move peer delete after vdev stop of station for QCA6390 and WCN6855&amp;#34;) is to fix firmware crash by changing the WMI command sequence, but actually skip all the peer delete operation, then it lead commit 58595c9874c6 (&amp;#34;ath11k: Fixing dangling pointer issue upon peer delete failure&amp;#34;) not take effect, and then happened a use-after-free warning from KASAN. because the peer-&amp;gt;sta is not set to NULL and then used later. Change to only skip the WMI_PEER_DELETE_CMDID for QCA6390/WCN6855. log of user-after-free: [  534.888665] BUG: KASAN: use-after-free in ath11k_dp_rx_update_peer_stats+0x912/0xc10 [ath11k] [  534.888696] Read of size 8 at addr ffff8881396bb1b8 by task rtcwake/2860 [  534.888705] CPU: 4 PID: 2860 Comm: rtcwake Kdump: loaded Tainted: G   W         5.15.0-wt-ath+ #523 [  534.888712] Hardware name: Intel(R) Client Systems NUC8i7HVK/NUC8i7HVB, BIOS HNKBLi70.86A.0067.2021.0528.1339 05/28/2021 [  534.888716] Call Trace: [  534.888720]  &amp;lt;IRQ&amp;gt; [  534.888726]  dump_stack_lvl+0x57/0x7d [  534.888736]  print_address_description.constprop.0+0x1f/0x170 [  534.888745]  ? ath11k_dp_rx_update_peer_stats+0x912/0xc10 [ath11k] [  534.888771]  kasan_report.cold+0x83/0xdf [  534.888783]  ? ath11k_dp_rx_update_peer_stats+0x912/0xc10 [ath11k] [  534.888810]  ath11k_dp_rx_update_peer_stats+0x912/0xc10 [ath11k] [  534.888840…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 69 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: ath11k: free peer for station when disconnect from AP for QCA6390/WCN6855 Commit b4a0f54156ac (&amp;#34;ath11k: move peer delete after vdev stop of station for QCA6390 and WCN6855&amp;#34;) is to fix firmware crash by changing the WMI command sequence, but actually skip all the peer delete operation, then it lead commit 58595c9874c6 (&amp;#34;ath11k: Fixing dangling pointer issue upon peer delete failure&amp;#34;) not take effect, and then happened a use-after-free warning from KASAN. because the peer-&amp;gt;sta is not set to NULL and then used later. Change to only skip the WMI_PEER_DELETE_CMDID for QCA6390/WCN6855. log of user-after-free: [  534.888665] BUG: KASAN: use-after-free in ath11k_dp_rx_update_peer_stats+0x912/0xc10 [ath11k] [  534.888696] Read of size 8 at addr ffff8881396bb1b8 by task rtcwake/2860 [  534.888705] CPU: 4 PID: 2860 Comm: rtcwake Kdump: loaded Tainted: G   W         5.15.0-wt-ath+ #523 [  534.888712] Hardware name: Intel(R) Client Systems NUC8i7HVK/NUC8i7HVB, BIOS HNKBLi70.86A.0067.2021.0528.1339 05/28/2021 [  534.888716] Call Trace: [  534.888720]  &amp;lt;IRQ&amp;gt; [  534.888726]  dump_stack_lvl+0x57/0x7d [  534.888736]  print_address_description.constprop.0+0x1f/0x170 [  534.888745]  ? ath11k_dp_rx_update_peer_stats+0x912/0xc10 [ath11k] [  534.888771]  kasan_report.cold+0x83/0xdf [  534.888783]  ? ath11k_dp_rx_update_peer_stats+0x912/0xc10 [ath11k] [  534.888810]  ath11k_dp_rx_update_peer_stats+0x912/0xc10 [ath11k] [  534.888840…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-49238</guid>
    </item>
  </channel>
</rss>
