<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 13:04:08 +0000</lastBuildDate>
    <item>
      <title>ALSA-2025:11298 — Moderate: kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2025:11298</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: bpftool, AlmaLinux:8: kernel, AlmaLinux:8: kernel-abi-stablelists, AlmaLinux:8: kernel-core, AlmaLinux:8: kernel-cross-headers, AlmaLinux:8: kernel-debug, AlmaLinux:8: kernel-debug-core, AlmaLinux:8: kernel-debug-devel, AlmaLinux:8: kernel-debug-modules, AlmaLinux:8: kernel-debug-modules-extra and 15 more&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: cifs: potential buffer overflow in handling symlinks (CVE-2022-49058)
  * kernel: media: uvcvideo: Remove dangling pointers (CVE-2024-58002)
  * kernel: media: uvcvideo: Fix double free in error path (CVE-2024-57980)
  * kernel: x86/microcode/AMD: Fix out-of-bounds on systems with CPU-less NUMA nodes (CVE-2025-21991)
  * kernel: net: atm: fix use after free in lec_send() (CVE-2025-22004)
  * kernel: ext4: fix off-by-one error in do_split (CVE-2025-23150)
  * kernel: ext4: ignore xattrs past end (CVE-2025-37738)
  * kernel: misc/vmw_vmci: fix an infoleak in vmci_host_do_receive_datagram() (CVE-2022-49788)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: bpftool, AlmaLinux:8: kernel, AlmaLinux:8: kernel-abi-stablelists, AlmaLinux:8: kernel-core, AlmaLinux:8: kernel-cross-headers, AlmaLinux:8: kernel-debug, AlmaLinux:8: kernel-debug-core, AlmaLinux:8: kernel-debug-devel, AlmaLinux:8: kernel-debug-modules, AlmaLinux:8: kernel-debug-modules-extra and 15 more&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: cifs: potential buffer overflow in handling symlinks (CVE-2022-49058)
  * kernel: media: uvcvideo: Remove dangling pointers (CVE-2024-58002)
  * kernel: media: uvcvideo: Fix double free in error path (CVE-2024-57980)
  * kernel: x86/microcode/AMD: Fix out-of-bounds on systems with CPU-less NUMA nodes (CVE-2025-21991)
  * kernel: net: atm: fix use after free in lec_send() (CVE-2025-22004)
  * kernel: ext4: fix off-by-one error in do_split (CVE-2025-23150)
  * kernel: ext4: ignore xattrs past end (CVE-2025-37738)
  * kernel: misc/vmw_vmci: fix an infoleak in vmci_host_do_receive_datagram() (CVE-2022-49788)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2025:11298</guid>
    </item>
    <item>
      <title>bdu:2026-03966</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-03966</link>
      <description>bdu:2026-03966</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-03966</guid>
    </item>
    <item>
      <title>certfr-2025-avi-0509 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de SUSE. Certaines d'entre elles permettent à un at…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0509</link>
      <description>certfr-2025-avi-0509</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0509</guid>
    </item>
    <item>
      <title>EUVD-2026-310809</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-310809</link>
      <description>EUVD-2026-310809</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-310809</guid>
    </item>
    <item>
      <title>fkie_cve-2022-49788</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-49788</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;misc/vmw_vmci: fix an infoleak in vmci_host_do_receive_datagram()&lt;/p&gt;
&lt;p&gt;`struct vmci_event_qp` allocated by qp_notify_peer() contains padding,
which may carry uninitialized data to the userspace, as observed by
KMSAN:&lt;/p&gt;
&lt;p&gt;BUG: KMSAN: kernel-infoleak in instrument_copy_to_user ./include/linux/instrumented.h:121
   instrument_copy_to_user ./include/linux/instrumented.h:121
   _copy_to_user+0x5f/0xb0 lib/usercopy.c:33
   copy_to_user ./include/linux/uaccess.h:169
   vmci_host_do_receive_datagram drivers/misc/vmw_vmci/vmci_host.c:431
   vmci_host_unlocked_ioctl+0x33d/0x43d0 drivers/misc/vmw_vmci/vmci_host.c:925
   vfs_ioctl fs/ioctl.c:51
  ...&lt;/p&gt;
&lt;p&gt;Uninit was stored to memory at:
   kmemdup+0x74/0xb0 mm/util.c:131
   dg_dispatch_as_host drivers/misc/vmw_vmci/vmci_datagram.c:271
   vmci_datagram_dispatch+0x4f8/0xfc0 drivers/misc/vmw_vmci/vmci_datagram.c:339
   qp_notify_peer+0x19a/0x290 drivers/misc/vmw_vmci/vmci_queue_pair.c:1479
   qp_broker_attach drivers/misc/vmw_vmci/vmci_queue_pair.c:1662
   qp_broker_alloc+0x2977/0x2f30 drivers/misc/vmw_vmci/vmci_queue_pair.c:1750
   vmci_qp_broker_alloc+0x96/0xd0 drivers/misc/vmw_vmci/vmci_queue_pair.c:1940
   vmci_host_do_alloc_queuepair drivers/misc/vmw_vmci/vmci_host.c:488
   vmci_host_unlocked_ioctl+0x24fd/0x43d0 drivers/misc/vmw_vmci/vmci_host.c:927
  ...&lt;/p&gt;
&lt;p&gt;Local variable ev created at:
   qp_notify_peer+0x54/0x290 drivers/misc/vmw_vmci/vmci_queue_pair.c:1456
   qp_broker_…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;misc/vmw_vmci: fix an infoleak in vmci_host_do_receive_datagram()&lt;/p&gt;
&lt;p&gt;`struct vmci_event_qp` allocated by qp_notify_peer() contains padding,
which may carry uninitialized data to the userspace, as observed by
KMSAN:&lt;/p&gt;
&lt;p&gt;BUG: KMSAN: kernel-infoleak in instrument_copy_to_user ./include/linux/instrumented.h:121
   instrument_copy_to_user ./include/linux/instrumented.h:121
   _copy_to_user+0x5f/0xb0 lib/usercopy.c:33
   copy_to_user ./include/linux/uaccess.h:169
   vmci_host_do_receive_datagram drivers/misc/vmw_vmci/vmci_host.c:431
   vmci_host_unlocked_ioctl+0x33d/0x43d0 drivers/misc/vmw_vmci/vmci_host.c:925
   vfs_ioctl fs/ioctl.c:51
  ...&lt;/p&gt;
&lt;p&gt;Uninit was stored to memory at:
   kmemdup+0x74/0xb0 mm/util.c:131
   dg_dispatch_as_host drivers/misc/vmw_vmci/vmci_datagram.c:271
   vmci_datagram_dispatch+0x4f8/0xfc0 drivers/misc/vmw_vmci/vmci_datagram.c:339
   qp_notify_peer+0x19a/0x290 drivers/misc/vmw_vmci/vmci_queue_pair.c:1479
   qp_broker_attach drivers/misc/vmw_vmci/vmci_queue_pair.c:1662
   qp_broker_alloc+0x2977/0x2f30 drivers/misc/vmw_vmci/vmci_queue_pair.c:1750
   vmci_qp_broker_alloc+0x96/0xd0 drivers/misc/vmw_vmci/vmci_queue_pair.c:1940
   vmci_host_do_alloc_queuepair drivers/misc/vmw_vmci/vmci_host.c:488
   vmci_host_unlocked_ioctl+0x24fd/0x43d0 drivers/misc/vmw_vmci/vmci_host.c:927
  ...&lt;/p&gt;
&lt;p&gt;Local variable ev created at:
   qp_notify_peer+0x54/0x290 drivers/misc/vmw_vmci/vmci_queue_pair.c:1456
   qp_broker_…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-49788</guid>
    </item>
    <item>
      <title>GHSA-65f7-9jmg-75c7</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-65f7-9jmg-75c7</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;misc/vmw_vmci: fix an infoleak in vmci_host_do_receive_datagram()&lt;/p&gt;
&lt;p&gt;`struct vmci_event_qp` allocated by qp_notify_peer() contains padding,
which may carry uninitialized data to the userspace, as observed by
KMSAN:&lt;/p&gt;
&lt;p&gt;BUG: KMSAN: kernel-infoleak in instrument_copy_to_user ./include/linux/instrumented.h:121
   instrument_copy_to_user ./include/linux/instrumented.h:121
   _copy_to_user+0x5f/0xb0 lib/usercopy.c:33
   copy_to_user ./include/linux/uaccess.h:169
   vmci_host_do_receive_datagram drivers/misc/vmw_vmci/vmci_host.c:431
   vmci_host_unlocked_ioctl+0x33d/0x43d0 drivers/misc/vmw_vmci/vmci_host.c:925
   vfs_ioctl fs/ioctl.c:51
  ...&lt;/p&gt;
&lt;p&gt;Uninit was stored to memory at:
   kmemdup+0x74/0xb0 mm/util.c:131
   dg_dispatch_as_host drivers/misc/vmw_vmci/vmci_datagram.c:271
   vmci_datagram_dispatch+0x4f8/0xfc0 drivers/misc/vmw_vmci/vmci_datagram.c:339
   qp_notify_peer+0x19a/0x290 drivers/misc/vmw_vmci/vmci_queue_pair.c:1479
   qp_broker_attach drivers/misc/vmw_vmci/vmci_queue_pair.c:1662
   qp_broker_alloc+0x2977/0x2f30 drivers/misc/vmw_vmci/vmci_queue_pair.c:1750
   vmci_qp_broker_alloc+0x96/0xd0 drivers/misc/vmw_vmci/vmci_queue_pair.c:1940
   vmci_host_do_alloc_queuepair drivers/misc/vmw_vmci/vmci_host.c:488
   vmci_host_unlocked_ioctl+0x24fd/0x43d0 drivers/misc/vmw_vmci/vmci_host.c:927
  ...&lt;/p&gt;
&lt;p&gt;Local variable ev created at:
   qp_notify_peer+0x54/0x290 drivers/misc/vmw_vmci/vmci_queue_pair.c:1456
   qp_broker_…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;misc/vmw_vmci: fix an infoleak in vmci_host_do_receive_datagram()&lt;/p&gt;
&lt;p&gt;`struct vmci_event_qp` allocated by qp_notify_peer() contains padding,
which may carry uninitialized data to the userspace, as observed by
KMSAN:&lt;/p&gt;
&lt;p&gt;BUG: KMSAN: kernel-infoleak in instrument_copy_to_user ./include/linux/instrumented.h:121
   instrument_copy_to_user ./include/linux/instrumented.h:121
   _copy_to_user+0x5f/0xb0 lib/usercopy.c:33
   copy_to_user ./include/linux/uaccess.h:169
   vmci_host_do_receive_datagram drivers/misc/vmw_vmci/vmci_host.c:431
   vmci_host_unlocked_ioctl+0x33d/0x43d0 drivers/misc/vmw_vmci/vmci_host.c:925
   vfs_ioctl fs/ioctl.c:51
  ...&lt;/p&gt;
&lt;p&gt;Uninit was stored to memory at:
   kmemdup+0x74/0xb0 mm/util.c:131
   dg_dispatch_as_host drivers/misc/vmw_vmci/vmci_datagram.c:271
   vmci_datagram_dispatch+0x4f8/0xfc0 drivers/misc/vmw_vmci/vmci_datagram.c:339
   qp_notify_peer+0x19a/0x290 drivers/misc/vmw_vmci/vmci_queue_pair.c:1479
   qp_broker_attach drivers/misc/vmw_vmci/vmci_queue_pair.c:1662
   qp_broker_alloc+0x2977/0x2f30 drivers/misc/vmw_vmci/vmci_queue_pair.c:1750
   vmci_qp_broker_alloc+0x96/0xd0 drivers/misc/vmw_vmci/vmci_queue_pair.c:1940
   vmci_host_do_alloc_queuepair drivers/misc/vmw_vmci/vmci_host.c:488
   vmci_host_unlocked_ioctl+0x24fd/0x43d0 drivers/misc/vmw_vmci/vmci_host.c:927
  ...&lt;/p&gt;
&lt;p&gt;Local variable ev created at:
   qp_notify_peer+0x54/0x290 drivers/misc/vmw_vmci/vmci_queue_pair.c:1456
   qp_broker_…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-65f7-9jmg-75c7</guid>
    </item>
    <item>
      <title>OESA-2025-1569 — kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2025-1569</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP4: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;gfs2: Check sb_bsize_shift after reading superblock&lt;/p&gt;
&lt;p&gt;Fuzzers like to scribble over sb_bsize_shift but in reality it&amp;amp;apos;s very
unlikely that this field would be corrupted on its own. Nevertheless it
should be checked to avoid the possibility of messy mount errors due to
bad calculations. It&amp;amp;apos;s always a fixed value based on the block size so
we can just check that it&amp;amp;apos;s the expected value.&lt;/p&gt;
&lt;p&gt;Tested with:&lt;/p&gt;
&lt;p&gt;mkfs.gfs2 -O -p lock_nolock /dev/vdb
    for i in 0 -1 64 65 32 33; do
        gfs2_edit -p sb field sb_bsize_shift $i /dev/vdb
        mount /dev/vdb /mnt/test &amp;amp;amp;&amp;amp;amp; umount /mnt/test
    done&lt;/p&gt;
&lt;p&gt;Before this patch we get a withdraw after&lt;/p&gt;
&lt;p&gt;[   76.413681] gfs2: fsid=loop0.0: fatal: invalid metadata block
[   76.413681]   bh = 19 (type: exp=5, found=4)
[   76.413681]   function = gfs2_meta_buffer, file = fs/gfs2/meta_io.c, line = 492&lt;/p&gt;
&lt;p&gt;and with UBSAN configured we also get complaints like&lt;/p&gt;
&lt;p&gt;[   76.373395] UBSAN: shift-out-of-bounds in fs/gfs2/ops_fstype.c:295:19
[   76.373815] shift exponent 4294967287 is too large for 64-bit type &amp;amp;apos;long unsigned int&amp;amp;apos;&lt;/p&gt;
&lt;p&gt;After the patch, these complaints don&amp;amp;apos;t appear, mount fails immediately
and we get an explanation in dmesg.(CVE-2022-49769)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;misc/vmw_vmci: fix an infoleak in vmci_host_do_receive_datagram()&lt;/p&gt;
&lt;p&gt;`s…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP4: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;gfs2: Check sb_bsize_shift after reading superblock&lt;/p&gt;
&lt;p&gt;Fuzzers like to scribble over sb_bsize_shift but in reality it&amp;amp;apos;s very
unlikely that this field would be corrupted on its own. Nevertheless it
should be checked to avoid the possibility of messy mount errors due to
bad calculations. It&amp;amp;apos;s always a fixed value based on the block size so
we can just check that it&amp;amp;apos;s the expected value.&lt;/p&gt;
&lt;p&gt;Tested with:&lt;/p&gt;
&lt;p&gt;mkfs.gfs2 -O -p lock_nolock /dev/vdb
    for i in 0 -1 64 65 32 33; do
        gfs2_edit -p sb field sb_bsize_shift $i /dev/vdb
        mount /dev/vdb /mnt/test &amp;amp;amp;&amp;amp;amp; umount /mnt/test
    done&lt;/p&gt;
&lt;p&gt;Before this patch we get a withdraw after&lt;/p&gt;
&lt;p&gt;[   76.413681] gfs2: fsid=loop0.0: fatal: invalid metadata block
[   76.413681]   bh = 19 (type: exp=5, found=4)
[   76.413681]   function = gfs2_meta_buffer, file = fs/gfs2/meta_io.c, line = 492&lt;/p&gt;
&lt;p&gt;and with UBSAN configured we also get complaints like&lt;/p&gt;
&lt;p&gt;[   76.373395] UBSAN: shift-out-of-bounds in fs/gfs2/ops_fstype.c:295:19
[   76.373815] shift exponent 4294967287 is too large for 64-bit type &amp;amp;apos;long unsigned int&amp;amp;apos;&lt;/p&gt;
&lt;p&gt;After the patch, these complaints don&amp;amp;apos;t appear, mount fails immediately
and we get an explanation in dmesg.(CVE-2022-49769)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;misc/vmw_vmci: fix an infoleak in vmci_host_do_receive_datagram()&lt;/p&gt;
&lt;p&gt;`s…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2025-1569</guid>
    </item>
    <item>
      <title>RHSA-2025:11298 — Red Hat Security Advisory: kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2025:11298</link>
      <description>&lt;p&gt;kernel: cifs: potential buffer overflow in handling symlinks kernel: misc/vmw_vmci: fix an infoleak in vmci_host_do_receive_datagram() kernel: media: uvcvideo: Fix double free in error path kernel: media: uvcvideo: Remove dangling pointers kernel: x86/microcode/AMD: Fix out-of-bounds on systems with CPU-less NUMA nodes kernel: net: atm: fix use after free in lec_send() kernel: ext4: fix off-by-one error in do_split kernel: ext4: ignore xattrs past end&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;kernel: cifs: potential buffer overflow in handling symlinks kernel: misc/vmw_vmci: fix an infoleak in vmci_host_do_receive_datagram() kernel: media: uvcvideo: Fix double free in error path kernel: media: uvcvideo: Remove dangling pointers kernel: x86/microcode/AMD: Fix out-of-bounds on systems with CPU-less NUMA nodes kernel: net: atm: fix use after free in lec_send() kernel: ext4: fix off-by-one error in do_split kernel: ext4: ignore xattrs past end&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2025:11298</guid>
    </item>
    <item>
      <title>RHSA-2025:11299 — Red Hat Security Advisory: kernel-rt security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2025:11299</link>
      <description>&lt;p&gt;kernel: cifs: potential buffer overflow in handling symlinks kernel: misc/vmw_vmci: fix an infoleak in vmci_host_do_receive_datagram() kernel: media: uvcvideo: Fix double free in error path kernel: media: uvcvideo: Remove dangling pointers kernel: x86/microcode/AMD: Fix out-of-bounds on systems with CPU-less NUMA nodes kernel: net: atm: fix use after free in lec_send() kernel: ext4: fix off-by-one error in do_split kernel: ext4: ignore xattrs past end&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;kernel: cifs: potential buffer overflow in handling symlinks kernel: misc/vmw_vmci: fix an infoleak in vmci_host_do_receive_datagram() kernel: media: uvcvideo: Fix double free in error path kernel: media: uvcvideo: Remove dangling pointers kernel: x86/microcode/AMD: Fix out-of-bounds on systems with CPU-less NUMA nodes kernel: net: atm: fix use after free in lec_send() kernel: ext4: fix off-by-one error in do_split kernel: ext4: ignore xattrs past end&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2025:11299</guid>
    </item>
    <item>
      <title>SUSE-SU-2025:01918-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2025:01918-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2025:01918-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2022-49788</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-49788</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux, Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe, Ubuntu:Pro:16.04:LTS: linux-oracle, Ubuntu:Pro:16.04:LTS: linux and 148 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: misc/vmw_vmci: fix an infoleak in vmci_host_do_receive_datagram() `struct vmci_event_qp` allocated by qp_notify_peer() contains padding, which may carry uninitialized data to the userspace, as observed by KMSAN:   BUG: KMSAN: kernel-infoleak in instrument_copy_to_user ./include/linux/instrumented.h:121    instrument_copy_to_user ./include/linux/instrumented.h:121    _copy_to_user+0x5f/0xb0 lib/usercopy.c:33    copy_to_user ./include/linux/uaccess.h:169    vmci_host_do_receive_datagram drivers/misc/vmw_vmci/vmci_host.c:431    vmci_host_unlocked_ioctl+0x33d/0x43d0 drivers/misc/vmw_vmci/vmci_host.c:925    vfs_ioctl fs/ioctl.c:51   ...   Uninit was stored to memory at:    kmemdup+0x74/0xb0 mm/util.c:131    dg_dispatch_as_host drivers/misc/vmw_vmci/vmci_datagram.c:271    vmci_datagram_dispatch+0x4f8/0xfc0 drivers/misc/vmw_vmci/vmci_datagram.c:339    qp_notify_peer+0x19a/0x290 drivers/misc/vmw_vmci/vmci_queue_pair.c:1479    qp_broker_attach drivers/misc/vmw_vmci/vmci_queue_pair.c:1662    qp_broker_alloc+0x2977/0x2f30 drivers/misc/vmw_vmci/vmci_queue_pair.c:1750    vmci_qp_broker_alloc+0x96/0xd0 drivers/misc/vmw_vmci/vmci_queue_pair.c:1940    vmci_host_do_alloc_queuepair drivers/misc/vmw_vmci/vmci_host.c:488    vmci_host_unlocked_ioctl+0x24fd/0x43d0 drivers/misc/vmw_vmci/vmci_host.c:927   ...   Local variable ev created at:    qp_notify_peer+0x54/0x290 drivers/misc/vmw_vmci/vmci_queue_pair.c:1456    qp_broker_attac…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux, Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe, Ubuntu:Pro:16.04:LTS: linux-oracle, Ubuntu:Pro:16.04:LTS: linux and 148 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: misc/vmw_vmci: fix an infoleak in vmci_host_do_receive_datagram() `struct vmci_event_qp` allocated by qp_notify_peer() contains padding, which may carry uninitialized data to the userspace, as observed by KMSAN:   BUG: KMSAN: kernel-infoleak in instrument_copy_to_user ./include/linux/instrumented.h:121    instrument_copy_to_user ./include/linux/instrumented.h:121    _copy_to_user+0x5f/0xb0 lib/usercopy.c:33    copy_to_user ./include/linux/uaccess.h:169    vmci_host_do_receive_datagram drivers/misc/vmw_vmci/vmci_host.c:431    vmci_host_unlocked_ioctl+0x33d/0x43d0 drivers/misc/vmw_vmci/vmci_host.c:925    vfs_ioctl fs/ioctl.c:51   ...   Uninit was stored to memory at:    kmemdup+0x74/0xb0 mm/util.c:131    dg_dispatch_as_host drivers/misc/vmw_vmci/vmci_datagram.c:271    vmci_datagram_dispatch+0x4f8/0xfc0 drivers/misc/vmw_vmci/vmci_datagram.c:339    qp_notify_peer+0x19a/0x290 drivers/misc/vmw_vmci/vmci_queue_pair.c:1479    qp_broker_attach drivers/misc/vmw_vmci/vmci_queue_pair.c:1662    qp_broker_alloc+0x2977/0x2f30 drivers/misc/vmw_vmci/vmci_queue_pair.c:1750    vmci_qp_broker_alloc+0x96/0xd0 drivers/misc/vmw_vmci/vmci_queue_pair.c:1940    vmci_host_do_alloc_queuepair drivers/misc/vmw_vmci/vmci_host.c:488    vmci_host_unlocked_ioctl+0x24fd/0x43d0 drivers/misc/vmw_vmci/vmci_host.c:927   ...   Local variable ev created at:    qp_notify_peer+0x54/0x290 drivers/misc/vmw_vmci/vmci_queue_pair.c:1456    qp_broker_attac…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-49788</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-1905 — IBM QRadar SIEM Komponente: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1905</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in IBM QRadar SIEM Komponenten ausnutzen, um Daten zu manipulieren, um einen Denial of Service Angriff durchzuführen, um beliebigen Programmcode auszuführen, um Sicherheitsvorkehrungen zu umgehen, und um Informationen offenzulegen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in IBM QRadar SIEM Komponenten ausnutzen, um Daten zu manipulieren, um einen Denial of Service Angriff durchzuführen, um beliebigen Programmcode auszuführen, um Sicherheitsvorkehrungen zu umgehen, und um Informationen offenzulegen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1905</guid>
    </item>
  </channel>
</rss>
