<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 19:39:53 +0000</lastBuildDate>
    <item>
      <title>ALSA-2025:20518 — Moderate: kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2025:20518</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: kernel, AlmaLinux:9: kernel-64k, AlmaLinux:9: kernel-64k-core, AlmaLinux:9: kernel-64k-debug, AlmaLinux:9: kernel-64k-debug-core, AlmaLinux:9: kernel-64k-debug-devel, AlmaLinux:9: kernel-64k-debug-devel-matched, AlmaLinux:9: kernel-64k-debug-modules, AlmaLinux:9: kernel-64k-debug-modules-core, AlmaLinux:9: kernel-64k-debug-modules-extra and 64 more&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: can: isotp: fix potential CAN frame reception race in isotp_rcv() (CVE-2022-48830)
  * kernel: soc: qcom: cmd-db: Map shared memory as WC, not WB (CVE-2024-46689)
  * kernel: Squashfs: sanity check symbolic link size (CVE-2024-46744)
  * kernel: vfs: fix race between evice_inodes() and find_inode()&amp;amp;#38;iput() (CVE-2024-47679)
  * kernel: x86/tdx: Fix &amp;#34;in-kernel MMIO&amp;#34; check (CVE-2024-47727)
  * kernel: rxrpc: Fix a race between socket set up and I/O thread creation (CVE-2024-49864)
  * kernel: io_uring: check if we need to reschedule during overflow flush (CVE-2024-50060)
  * kernel: can: m_can: pci: add missing m_can_class_free_dev() in probe/remove methods (CVE-2022-49024)
  * kernel: posix-clock: Fix missing timespec64 check in pc_clock_settime() (CVE-2024-50195)
  * kernel: rxrpc: Fix missing locking causing hanging calls (CVE-2024-50294)
  * kernel: io_uring/rw: fix missing NOWAIT check for O_DIRECT start write (CVE-2024-53052)
  * kernel: afs: Fix lock recursion (CVE-2024-53090)
  * kernel: virtio/vsock: Fix accept_queue memory leak (CVE-2024-53119)
  * kernel: KVM: VMX: Bury Intel PT virtualization (guest/host mode) behind CONFIG_BROKEN (CVE-2024-53135)
  * kernel: xen: Xen hypercall page unsafe against speculative attacks (Xen Security Advisory 466) (CVE-2024-53241)
  * kernel: RDMA/rxe: Fix the qp flush warnings in req (CVE-2024-53229)
  * kernel:…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: kernel, AlmaLinux:9: kernel-64k, AlmaLinux:9: kernel-64k-core, AlmaLinux:9: kernel-64k-debug, AlmaLinux:9: kernel-64k-debug-core, AlmaLinux:9: kernel-64k-debug-devel, AlmaLinux:9: kernel-64k-debug-devel-matched, AlmaLinux:9: kernel-64k-debug-modules, AlmaLinux:9: kernel-64k-debug-modules-core, AlmaLinux:9: kernel-64k-debug-modules-extra and 64 more&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: can: isotp: fix potential CAN frame reception race in isotp_rcv() (CVE-2022-48830)
  * kernel: soc: qcom: cmd-db: Map shared memory as WC, not WB (CVE-2024-46689)
  * kernel: Squashfs: sanity check symbolic link size (CVE-2024-46744)
  * kernel: vfs: fix race between evice_inodes() and find_inode()&amp;amp;#38;iput() (CVE-2024-47679)
  * kernel: x86/tdx: Fix &amp;#34;in-kernel MMIO&amp;#34; check (CVE-2024-47727)
  * kernel: rxrpc: Fix a race between socket set up and I/O thread creation (CVE-2024-49864)
  * kernel: io_uring: check if we need to reschedule during overflow flush (CVE-2024-50060)
  * kernel: can: m_can: pci: add missing m_can_class_free_dev() in probe/remove methods (CVE-2022-49024)
  * kernel: posix-clock: Fix missing timespec64 check in pc_clock_settime() (CVE-2024-50195)
  * kernel: rxrpc: Fix missing locking causing hanging calls (CVE-2024-50294)
  * kernel: io_uring/rw: fix missing NOWAIT check for O_DIRECT start write (CVE-2024-53052)
  * kernel: afs: Fix lock recursion (CVE-2024-53090)
  * kernel: virtio/vsock: Fix accept_queue memory leak (CVE-2024-53119)
  * kernel: KVM: VMX: Bury Intel PT virtualization (guest/host mode) behind CONFIG_BROKEN (CVE-2024-53135)
  * kernel: xen: Xen hypercall page unsafe against speculative attacks (Xen Security Advisory 466) (CVE-2024-53241)
  * kernel: RDMA/rxe: Fix the qp flush warnings in req (CVE-2024-53229)
  * kernel:…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2025:20518</guid>
    </item>
    <item>
      <title>bdu:2026-04479</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-04479</link>
      <description>bdu:2026-04479</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-04479</guid>
    </item>
    <item>
      <title>certfr-2025-avi-0307 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de SUSE. Certaines d'entre elles permettent à un at…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0307</link>
      <description>certfr-2025-avi-0307</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0307</guid>
    </item>
    <item>
      <title>EUVD-2026-310503</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-310503</link>
      <description>EUVD-2026-310503</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-310503</guid>
    </item>
    <item>
      <title>fkie_cve-2022-49353</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-49353</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;powerpc/papr_scm: don&amp;#39;t requests stats with &amp;#39;0&amp;#39; sized stats buffer&lt;/p&gt;
&lt;p&gt;Sachin reported [1] that on a POWER-10 lpar he is seeing a kernel panic being
reported with vPMEM when papr_scm probe is being called. The panic is of the
form below and is observed only with following option disabled(profile) for the
said LPAR &amp;#39;Enable Performance Information Collection&amp;#39; in the HMC:&lt;/p&gt;
&lt;p&gt;Kernel attempted to write user page (1c) - exploit attempt? (uid: 0)
 BUG: Kernel NULL pointer dereference on write at 0x0000001c
 Faulting instruction address: 0xc008000001b90844
 Oops: Kernel access of bad area, sig: 11 [#1]
&amp;lt;snip&amp;gt;
 NIP [c008000001b90844] drc_pmem_query_stats+0x5c/0x270 [papr_scm]
 LR [c008000001b92794] papr_scm_probe+0x2ac/0x6ec [papr_scm]
 Call Trace:
       0xc00000000941bca0 (unreliable)
       papr_scm_probe+0x2ac/0x6ec [papr_scm]
       platform_probe+0x98/0x150
       really_probe+0xfc/0x510
       __driver_probe_device+0x17c/0x230
&amp;lt;snip&amp;gt;
 ---[ end trace 0000000000000000 ]---
 Kernel panic - not syncing: Fatal exception&lt;/p&gt;
&lt;p&gt;On investigation looks like this panic was caused due to a &amp;#39;stat_buffer&amp;#39; of
size==0 being provided to drc_pmem_query_stats() to fetch all performance
stats-ids of an NVDIMM. However drc_pmem_query_stats() shouldn&amp;#39;t have been called
since the vPMEM NVDIMM doesn&amp;#39;t support and performance stat-id&amp;#39;s. This was caused
due to missing check for &amp;#39;p-&amp;gt;stat_buffer_len&amp;#39; at the beginning of
papr_scm_pmu_check_event…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;powerpc/papr_scm: don&amp;#39;t requests stats with &amp;#39;0&amp;#39; sized stats buffer&lt;/p&gt;
&lt;p&gt;Sachin reported [1] that on a POWER-10 lpar he is seeing a kernel panic being
reported with vPMEM when papr_scm probe is being called. The panic is of the
form below and is observed only with following option disabled(profile) for the
said LPAR &amp;#39;Enable Performance Information Collection&amp;#39; in the HMC:&lt;/p&gt;
&lt;p&gt;Kernel attempted to write user page (1c) - exploit attempt? (uid: 0)
 BUG: Kernel NULL pointer dereference on write at 0x0000001c
 Faulting instruction address: 0xc008000001b90844
 Oops: Kernel access of bad area, sig: 11 [#1]
&amp;lt;snip&amp;gt;
 NIP [c008000001b90844] drc_pmem_query_stats+0x5c/0x270 [papr_scm]
 LR [c008000001b92794] papr_scm_probe+0x2ac/0x6ec [papr_scm]
 Call Trace:
       0xc00000000941bca0 (unreliable)
       papr_scm_probe+0x2ac/0x6ec [papr_scm]
       platform_probe+0x98/0x150
       really_probe+0xfc/0x510
       __driver_probe_device+0x17c/0x230
&amp;lt;snip&amp;gt;
 ---[ end trace 0000000000000000 ]---
 Kernel panic - not syncing: Fatal exception&lt;/p&gt;
&lt;p&gt;On investigation looks like this panic was caused due to a &amp;#39;stat_buffer&amp;#39; of
size==0 being provided to drc_pmem_query_stats() to fetch all performance
stats-ids of an NVDIMM. However drc_pmem_query_stats() shouldn&amp;#39;t have been called
since the vPMEM NVDIMM doesn&amp;#39;t support and performance stat-id&amp;#39;s. This was caused
due to missing check for &amp;#39;p-&amp;gt;stat_buffer_len&amp;#39; at the beginning of
papr_scm_pmu_check_event…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-49353</guid>
    </item>
    <item>
      <title>GHSA-6gv8-fgf9-gqgc</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-6gv8-fgf9-gqgc</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;powerpc/papr_scm: don&amp;#39;t requests stats with &amp;#39;0&amp;#39; sized stats buffer&lt;/p&gt;
&lt;p&gt;Sachin reported [1] that on a POWER-10 lpar he is seeing a kernel panic being
reported with vPMEM when papr_scm probe is being called. The panic is of the
form below and is observed only with following option disabled(profile) for the
said LPAR &amp;#39;Enable Performance Information Collection&amp;#39; in the HMC:&lt;/p&gt;
&lt;p&gt;Kernel attempted to write user page (1c) - exploit attempt? (uid: 0)
 BUG: Kernel NULL pointer dereference on write at 0x0000001c
 Faulting instruction address: 0xc008000001b90844
 Oops: Kernel access of bad area, sig: 11 [#1]
&amp;lt;snip&amp;gt;
 NIP [c008000001b90844] drc_pmem_query_stats+0x5c/0x270 [papr_scm]
 LR [c008000001b92794] papr_scm_probe+0x2ac/0x6ec [papr_scm]
 Call Trace:
       0xc00000000941bca0 (unreliable)
       papr_scm_probe+0x2ac/0x6ec [papr_scm]
       platform_probe+0x98/0x150
       really_probe+0xfc/0x510
       __driver_probe_device+0x17c/0x230
&amp;lt;snip&amp;gt;
 ---[ end trace 0000000000000000 ]---
 Kernel panic - not syncing: Fatal exception&lt;/p&gt;
&lt;p&gt;On investigation looks like this panic was caused due to a &amp;#39;stat_buffer&amp;#39; of
size==0 being provided to drc_pmem_query_stats() to fetch all performance
stats-ids of an NVDIMM. However drc_pmem_query_stats() shouldn&amp;#39;t have been called
since the vPMEM NVDIMM doesn&amp;#39;t support and performance stat-id&amp;#39;s. This was caused
due to missing check for &amp;#39;p-&amp;gt;stat_buffer_len&amp;#39; at the beginning of
papr_scm_pmu_check_event…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;powerpc/papr_scm: don&amp;#39;t requests stats with &amp;#39;0&amp;#39; sized stats buffer&lt;/p&gt;
&lt;p&gt;Sachin reported [1] that on a POWER-10 lpar he is seeing a kernel panic being
reported with vPMEM when papr_scm probe is being called. The panic is of the
form below and is observed only with following option disabled(profile) for the
said LPAR &amp;#39;Enable Performance Information Collection&amp;#39; in the HMC:&lt;/p&gt;
&lt;p&gt;Kernel attempted to write user page (1c) - exploit attempt? (uid: 0)
 BUG: Kernel NULL pointer dereference on write at 0x0000001c
 Faulting instruction address: 0xc008000001b90844
 Oops: Kernel access of bad area, sig: 11 [#1]
&amp;lt;snip&amp;gt;
 NIP [c008000001b90844] drc_pmem_query_stats+0x5c/0x270 [papr_scm]
 LR [c008000001b92794] papr_scm_probe+0x2ac/0x6ec [papr_scm]
 Call Trace:
       0xc00000000941bca0 (unreliable)
       papr_scm_probe+0x2ac/0x6ec [papr_scm]
       platform_probe+0x98/0x150
       really_probe+0xfc/0x510
       __driver_probe_device+0x17c/0x230
&amp;lt;snip&amp;gt;
 ---[ end trace 0000000000000000 ]---
 Kernel panic - not syncing: Fatal exception&lt;/p&gt;
&lt;p&gt;On investigation looks like this panic was caused due to a &amp;#39;stat_buffer&amp;#39; of
size==0 being provided to drc_pmem_query_stats() to fetch all performance
stats-ids of an NVDIMM. However drc_pmem_query_stats() shouldn&amp;#39;t have been called
since the vPMEM NVDIMM doesn&amp;#39;t support and performance stat-id&amp;#39;s. This was caused
due to missing check for &amp;#39;p-&amp;gt;stat_buffer_len&amp;#39; at the beginning of
papr_scm_pmu_check_event…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-6gv8-fgf9-gqgc</guid>
    </item>
    <item>
      <title>RHSA-2025:20518 — Red Hat Security Advisory: kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2025:20518</link>
      <description>&lt;p&gt;kernel: can: isotp: fix potential CAN frame reception race in isotp_rcv() kernel: can: m_can: pci: add missing m_can_class_free_dev() in probe/remove methods kernel: can: isotp: sanitize CAN ID checks in isotp_bind() kernel: powerpc/papr_scm: don&amp;#39;t requests stats with &amp;#39;0&amp;#39; sized stats buffer kernel: efi: Do not import certificates from UEFI Secure Boot for T2 Macs kernel: powerpc/xics: fix refcount leak in icp_opal_init() kernel: powerpc/xive: Fix refcount leak in xive_spapr_init kernel: list: fix a data-race around ep-&amp;gt;rdllist kernel: powerpc/xive/spapr: correct bitmap allocation size kernel: ima: Fix potential memory leak in ima_init_crypto() kernel: ima: Fix a potential integer overflow in ima_appraise_measurement kernel: tracing/histograms: Fix memory leak problem kernel: usbnet: fix memory leak in error case kernel: linux/dim: Fix divide by 0 in RDMA DIM kernel: net: tun: unlink NAPI from device on destruction kernel: can: j1939: j1939_send_one(): fix missing CAN header initialization kernel: intel_th: Fix a resource leak in an error handling path kernel: powerpc/rtas: avoid scheduling in rtas_os_term() kernel: can: isotp: split tx timer into transmission and timeout kernel: Linux kernel: Denial of Service in xsk_diag due to use-after-free during socket cleanup kernel: smc: Fix use-after-free in tcp_write_timer_handler() kernel: inotify: Avoid reporting event with invalid wd kernel: Linux kernel (CAN J1939): Denial of Service via deadlock kernel: net/smc: fix potential p…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;kernel: can: isotp: fix potential CAN frame reception race in isotp_rcv() kernel: can: m_can: pci: add missing m_can_class_free_dev() in probe/remove methods kernel: can: isotp: sanitize CAN ID checks in isotp_bind() kernel: powerpc/papr_scm: don&amp;#39;t requests stats with &amp;#39;0&amp;#39; sized stats buffer kernel: efi: Do not import certificates from UEFI Secure Boot for T2 Macs kernel: powerpc/xics: fix refcount leak in icp_opal_init() kernel: powerpc/xive: Fix refcount leak in xive_spapr_init kernel: list: fix a data-race around ep-&amp;gt;rdllist kernel: powerpc/xive/spapr: correct bitmap allocation size kernel: ima: Fix potential memory leak in ima_init_crypto() kernel: ima: Fix a potential integer overflow in ima_appraise_measurement kernel: tracing/histograms: Fix memory leak problem kernel: usbnet: fix memory leak in error case kernel: linux/dim: Fix divide by 0 in RDMA DIM kernel: net: tun: unlink NAPI from device on destruction kernel: can: j1939: j1939_send_one(): fix missing CAN header initialization kernel: intel_th: Fix a resource leak in an error handling path kernel: powerpc/rtas: avoid scheduling in rtas_os_term() kernel: can: isotp: split tx timer into transmission and timeout kernel: Linux kernel: Denial of Service in xsk_diag due to use-after-free during socket cleanup kernel: smc: Fix use-after-free in tcp_write_timer_handler() kernel: inotify: Avoid reporting event with invalid wd kernel: Linux kernel (CAN J1939): Denial of Service via deadlock kernel: net/smc: fix potential p…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2025:20518</guid>
    </item>
    <item>
      <title>SUSE-SU-2025:1176-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2025:1176-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2025:1176-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2022-49353</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-49353</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 69 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: powerpc/papr_scm: don&amp;#39;t requests stats with &amp;#39;0&amp;#39; sized stats buffer Sachin reported [1] that on a POWER-10 lpar he is seeing a kernel panic being reported with vPMEM when papr_scm probe is being called. The panic is of the form below and is observed only with following option disabled(profile) for the said LPAR &amp;#39;Enable Performance Information Collection&amp;#39; in the HMC:  Kernel attempted to write user page (1c) - exploit attempt? (uid: 0)  BUG: Kernel NULL pointer dereference on write at 0x0000001c  Faulting instruction address: 0xc008000001b90844  Oops: Kernel access of bad area, sig: 11 [#1] &amp;lt;snip&amp;gt;  NIP [c008000001b90844] drc_pmem_query_stats+0x5c/0x270 [papr_scm]  LR [c008000001b92794] papr_scm_probe+0x2ac/0x6ec [papr_scm]  Call Trace:        0xc00000000941bca0 (unreliable)        papr_scm_probe+0x2ac/0x6ec [papr_scm]        platform_probe+0x98/0x150        really_probe+0xfc/0x510        __driver_probe_device+0x17c/0x230 &amp;lt;snip&amp;gt;  ---[ end trace 0000000000000000 ]---  Kernel panic - not syncing: Fatal exception On investigation looks like this panic was caused due to a &amp;#39;stat_buffer&amp;#39; of size==0 being provided to drc_pmem_query_stats() to fetch all performance stats-ids of an NVDIMM. However drc_pmem_query_stats() shouldn&amp;#39;t have been called since the vPMEM NVDIMM doesn&amp;#39;t support and performance stat-id&amp;#39;s. This was caused due to missing check for &amp;#39;p-&amp;gt;stat_buffer_len&amp;#39; at the beginning of papr_scm_pmu_check_events()…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 69 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: powerpc/papr_scm: don&amp;#39;t requests stats with &amp;#39;0&amp;#39; sized stats buffer Sachin reported [1] that on a POWER-10 lpar he is seeing a kernel panic being reported with vPMEM when papr_scm probe is being called. The panic is of the form below and is observed only with following option disabled(profile) for the said LPAR &amp;#39;Enable Performance Information Collection&amp;#39; in the HMC:  Kernel attempted to write user page (1c) - exploit attempt? (uid: 0)  BUG: Kernel NULL pointer dereference on write at 0x0000001c  Faulting instruction address: 0xc008000001b90844  Oops: Kernel access of bad area, sig: 11 [#1] &amp;lt;snip&amp;gt;  NIP [c008000001b90844] drc_pmem_query_stats+0x5c/0x270 [papr_scm]  LR [c008000001b92794] papr_scm_probe+0x2ac/0x6ec [papr_scm]  Call Trace:        0xc00000000941bca0 (unreliable)        papr_scm_probe+0x2ac/0x6ec [papr_scm]        platform_probe+0x98/0x150        really_probe+0xfc/0x510        __driver_probe_device+0x17c/0x230 &amp;lt;snip&amp;gt;  ---[ end trace 0000000000000000 ]---  Kernel panic - not syncing: Fatal exception On investigation looks like this panic was caused due to a &amp;#39;stat_buffer&amp;#39; of size==0 being provided to drc_pmem_query_stats() to fetch all performance stats-ids of an NVDIMM. However drc_pmem_query_stats() shouldn&amp;#39;t have been called since the vPMEM NVDIMM doesn&amp;#39;t support and performance stat-id&amp;#39;s. This was caused due to missing check for &amp;#39;p-&amp;gt;stat_buffer_len&amp;#39; at the beginning of papr_scm_pmu_check_events()…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-49353</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2253 — IBM Security Verify Access: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2253</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in IBM Security Verify Access ausnutzen, um erweiterte Berechtigungen zu erlangen, beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, sensible Informationen offenzulegen und andere, nicht näher bezeichnete Angriffe durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in IBM Security Verify Access ausnutzen, um erweiterte Berechtigungen zu erlangen, beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, sensible Informationen offenzulegen und andere, nicht näher bezeichnete Angriffe durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2253</guid>
    </item>
  </channel>
</rss>
