<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 17:47:01 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-05777</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-05777</link>
      <description>bdu:2026-05777</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-05777</guid>
    </item>
    <item>
      <title>certfr-2025-avi-0509 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de SUSE. Certaines d'entre elles permettent à un at…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0509</link>
      <description>certfr-2025-avi-0509</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0509</guid>
    </item>
    <item>
      <title>EUVD-2026-310875</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-310875</link>
      <description>EUVD-2026-310875</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-310875</guid>
    </item>
    <item>
      <title>fkie_cve-2022-49871</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-49871</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;net: tun: Fix memory leaks of napi_get_frags&lt;/p&gt;
&lt;p&gt;kmemleak reports after running test_progs:&lt;/p&gt;
&lt;p&gt;unreferenced object 0xffff8881b1672dc0 (size 232):
  comm &amp;#34;test_progs&amp;#34;, pid 394388, jiffies 4354712116 (age 841.975s)
  hex dump (first 32 bytes):
    e0 84 d7 a8 81 88 ff ff 80 2c 67 b1 81 88 ff ff  .........,g.....
    00 40 c5 9b 81 88 ff ff 00 00 00 00 00 00 00 00  .@..............
  backtrace:
    [&amp;lt;00000000c8f01748&amp;gt;] napi_skb_cache_get+0xd4/0x150
    [&amp;lt;0000000041c7fc09&amp;gt;] __napi_build_skb+0x15/0x50
    [&amp;lt;00000000431c7079&amp;gt;] __napi_alloc_skb+0x26e/0x540
    [&amp;lt;000000003ecfa30e&amp;gt;] napi_get_frags+0x59/0x140
    [&amp;lt;0000000099b2199e&amp;gt;] tun_get_user+0x183d/0x3bb0 [tun]
    [&amp;lt;000000008a5adef0&amp;gt;] tun_chr_write_iter+0xc0/0x1b1 [tun]
    [&amp;lt;0000000049993ff4&amp;gt;] do_iter_readv_writev+0x19f/0x320
    [&amp;lt;000000008f338ea2&amp;gt;] do_iter_write+0x135/0x630
    [&amp;lt;000000008a3377a4&amp;gt;] vfs_writev+0x12e/0x440
    [&amp;lt;00000000a6b5639a&amp;gt;] do_writev+0x104/0x280
    [&amp;lt;00000000ccf065d8&amp;gt;] do_syscall_64+0x3b/0x90
    [&amp;lt;00000000d776e329&amp;gt;] entry_SYSCALL_64_after_hwframe+0x63/0xcd&lt;/p&gt;
&lt;p&gt;The issue occurs in the following scenarios:
tun_get_user()
  napi_gro_frags()
    napi_frags_finish()
      case GRO_NORMAL:
        gro_normal_one()
          list_add_tail(&amp;amp;skb-&amp;gt;list, &amp;amp;napi-&amp;gt;rx_list);
          &amp;lt;-- While napi-&amp;gt;rx_count &amp;lt; READ_ONCE(gro_normal_batch),
          &amp;lt;-- gro_normal_list() is not called, napi-&amp;gt;rx_list is not empty
  &amp;lt;-- not ask to complete the gro work, will…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;net: tun: Fix memory leaks of napi_get_frags&lt;/p&gt;
&lt;p&gt;kmemleak reports after running test_progs:&lt;/p&gt;
&lt;p&gt;unreferenced object 0xffff8881b1672dc0 (size 232):
  comm &amp;#34;test_progs&amp;#34;, pid 394388, jiffies 4354712116 (age 841.975s)
  hex dump (first 32 bytes):
    e0 84 d7 a8 81 88 ff ff 80 2c 67 b1 81 88 ff ff  .........,g.....
    00 40 c5 9b 81 88 ff ff 00 00 00 00 00 00 00 00  .@..............
  backtrace:
    [&amp;lt;00000000c8f01748&amp;gt;] napi_skb_cache_get+0xd4/0x150
    [&amp;lt;0000000041c7fc09&amp;gt;] __napi_build_skb+0x15/0x50
    [&amp;lt;00000000431c7079&amp;gt;] __napi_alloc_skb+0x26e/0x540
    [&amp;lt;000000003ecfa30e&amp;gt;] napi_get_frags+0x59/0x140
    [&amp;lt;0000000099b2199e&amp;gt;] tun_get_user+0x183d/0x3bb0 [tun]
    [&amp;lt;000000008a5adef0&amp;gt;] tun_chr_write_iter+0xc0/0x1b1 [tun]
    [&amp;lt;0000000049993ff4&amp;gt;] do_iter_readv_writev+0x19f/0x320
    [&amp;lt;000000008f338ea2&amp;gt;] do_iter_write+0x135/0x630
    [&amp;lt;000000008a3377a4&amp;gt;] vfs_writev+0x12e/0x440
    [&amp;lt;00000000a6b5639a&amp;gt;] do_writev+0x104/0x280
    [&amp;lt;00000000ccf065d8&amp;gt;] do_syscall_64+0x3b/0x90
    [&amp;lt;00000000d776e329&amp;gt;] entry_SYSCALL_64_after_hwframe+0x63/0xcd&lt;/p&gt;
&lt;p&gt;The issue occurs in the following scenarios:
tun_get_user()
  napi_gro_frags()
    napi_frags_finish()
      case GRO_NORMAL:
        gro_normal_one()
          list_add_tail(&amp;amp;skb-&amp;gt;list, &amp;amp;napi-&amp;gt;rx_list);
          &amp;lt;-- While napi-&amp;gt;rx_count &amp;lt; READ_ONCE(gro_normal_batch),
          &amp;lt;-- gro_normal_list() is not called, napi-&amp;gt;rx_list is not empty
  &amp;lt;-- not ask to complete the gro work, will…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-49871</guid>
    </item>
    <item>
      <title>GHSA-jfw6-w783-5hhm</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-jfw6-w783-5hhm</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;net: tun: Fix memory leaks of napi_get_frags&lt;/p&gt;
&lt;p&gt;kmemleak reports after running test_progs:&lt;/p&gt;
&lt;p&gt;unreferenced object 0xffff8881b1672dc0 (size 232):
  comm &amp;#34;test_progs&amp;#34;, pid 394388, jiffies 4354712116 (age 841.975s)
  hex dump (first 32 bytes):
    e0 84 d7 a8 81 88 ff ff 80 2c 67 b1 81 88 ff ff  .........,g.....
    00 40 c5 9b 81 88 ff ff 00 00 00 00 00 00 00 00  .@..............
  backtrace:
    [&amp;lt;00000000c8f01748&amp;gt;] napi_skb_cache_get+0xd4/0x150
    [&amp;lt;0000000041c7fc09&amp;gt;] __napi_build_skb+0x15/0x50
    [&amp;lt;00000000431c7079&amp;gt;] __napi_alloc_skb+0x26e/0x540
    [&amp;lt;000000003ecfa30e&amp;gt;] napi_get_frags+0x59/0x140
    [&amp;lt;0000000099b2199e&amp;gt;] tun_get_user+0x183d/0x3bb0 [tun]
    [&amp;lt;000000008a5adef0&amp;gt;] tun_chr_write_iter+0xc0/0x1b1 [tun]
    [&amp;lt;0000000049993ff4&amp;gt;] do_iter_readv_writev+0x19f/0x320
    [&amp;lt;000000008f338ea2&amp;gt;] do_iter_write+0x135/0x630
    [&amp;lt;000000008a3377a4&amp;gt;] vfs_writev+0x12e/0x440
    [&amp;lt;00000000a6b5639a&amp;gt;] do_writev+0x104/0x280
    [&amp;lt;00000000ccf065d8&amp;gt;] do_syscall_64+0x3b/0x90
    [&amp;lt;00000000d776e329&amp;gt;] entry_SYSCALL_64_after_hwframe+0x63/0xcd&lt;/p&gt;
&lt;p&gt;The issue occurs in the following scenarios:
tun_get_user()
  napi_gro_frags()
    napi_frags_finish()
      case GRO_NORMAL:
        gro_normal_one()
          list_add_tail(&amp;amp;skb-&amp;gt;list, &amp;amp;napi-&amp;gt;rx_list);
          &amp;lt;-- While napi-&amp;gt;rx_count &amp;lt; READ_ONCE(gro_normal_batch),
          &amp;lt;-- gro_normal_list() is not called, napi-&amp;gt;rx_list is not empty
  &amp;lt;-- not ask to complete the gro work, will…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;net: tun: Fix memory leaks of napi_get_frags&lt;/p&gt;
&lt;p&gt;kmemleak reports after running test_progs:&lt;/p&gt;
&lt;p&gt;unreferenced object 0xffff8881b1672dc0 (size 232):
  comm &amp;#34;test_progs&amp;#34;, pid 394388, jiffies 4354712116 (age 841.975s)
  hex dump (first 32 bytes):
    e0 84 d7 a8 81 88 ff ff 80 2c 67 b1 81 88 ff ff  .........,g.....
    00 40 c5 9b 81 88 ff ff 00 00 00 00 00 00 00 00  .@..............
  backtrace:
    [&amp;lt;00000000c8f01748&amp;gt;] napi_skb_cache_get+0xd4/0x150
    [&amp;lt;0000000041c7fc09&amp;gt;] __napi_build_skb+0x15/0x50
    [&amp;lt;00000000431c7079&amp;gt;] __napi_alloc_skb+0x26e/0x540
    [&amp;lt;000000003ecfa30e&amp;gt;] napi_get_frags+0x59/0x140
    [&amp;lt;0000000099b2199e&amp;gt;] tun_get_user+0x183d/0x3bb0 [tun]
    [&amp;lt;000000008a5adef0&amp;gt;] tun_chr_write_iter+0xc0/0x1b1 [tun]
    [&amp;lt;0000000049993ff4&amp;gt;] do_iter_readv_writev+0x19f/0x320
    [&amp;lt;000000008f338ea2&amp;gt;] do_iter_write+0x135/0x630
    [&amp;lt;000000008a3377a4&amp;gt;] vfs_writev+0x12e/0x440
    [&amp;lt;00000000a6b5639a&amp;gt;] do_writev+0x104/0x280
    [&amp;lt;00000000ccf065d8&amp;gt;] do_syscall_64+0x3b/0x90
    [&amp;lt;00000000d776e329&amp;gt;] entry_SYSCALL_64_after_hwframe+0x63/0xcd&lt;/p&gt;
&lt;p&gt;The issue occurs in the following scenarios:
tun_get_user()
  napi_gro_frags()
    napi_frags_finish()
      case GRO_NORMAL:
        gro_normal_one()
          list_add_tail(&amp;amp;skb-&amp;gt;list, &amp;amp;napi-&amp;gt;rx_list);
          &amp;lt;-- While napi-&amp;gt;rx_count &amp;lt; READ_ONCE(gro_normal_batch),
          &amp;lt;-- gro_normal_list() is not called, napi-&amp;gt;rx_list is not empty
  &amp;lt;-- not ask to complete the gro work, will…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-jfw6-w783-5hhm</guid>
    </item>
    <item>
      <title>OESA-2025-1820 — kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2025-1820</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP4: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;tipc: fix the msg-&amp;amp;gt;req tlv len check in tipc_nl_compat_name_table_dump_header&lt;/p&gt;
&lt;p&gt;This is a follow-up for commit 974cb0e3e7c9 (&amp;amp;quot;tipc: fix uninit-value
in tipc_nl_compat_name_table_dump&amp;amp;quot;) where it should have type casted
sizeof(..) to int to work when TLV_GET_DATA_LEN() returns a negative
value.&lt;/p&gt;
&lt;p&gt;syzbot reported a call trace because of it:&lt;/p&gt;
&lt;p&gt;BUG: KMSAN: uninit-value in ...
   tipc_nl_compat_name_table_dump+0x841/0xea0 net/tipc/netlink_compat.c:934
   __tipc_nl_compat_dumpit+0xab2/0x1320 net/tipc/netlink_compat.c:238
   tipc_nl_compat_dumpit+0x991/0xb50 net/tipc/netlink_compat.c:321
   tipc_nl_compat_recv+0xb6e/0x1640 net/tipc/netlink_compat.c:1324
   genl_family_rcv_msg_doit net/netlink/genetlink.c:731 [inline]
   genl_family_rcv_msg net/netlink/genetlink.c:775 [inline]
   genl_rcv_msg+0x103f/0x1260 net/netlink/genetlink.c:792
   netlink_rcv_skb+0x3a5/0x6c0 net/netlink/af_netlink.c:2501
   genl_rcv+0x3c/0x50 net/netlink/genetlink.c:803
   netlink_unicast_kernel net/netlink/af_netlink.c:1319 [inline]
   netlink_unicast+0xf3b/0x1270 net/netlink/af_netlink.c:1345
   netlink_sendmsg+0x1288/0x1440 net/netlink/af_netlink.c:1921
   sock_sendmsg_nosec net/socket.c:714 [inline]
   sock_sendmsg net/socket.c:734 [inline](CVE-2022-49862)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;net: tun: Fix memory leaks of…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP4: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;tipc: fix the msg-&amp;amp;gt;req tlv len check in tipc_nl_compat_name_table_dump_header&lt;/p&gt;
&lt;p&gt;This is a follow-up for commit 974cb0e3e7c9 (&amp;amp;quot;tipc: fix uninit-value
in tipc_nl_compat_name_table_dump&amp;amp;quot;) where it should have type casted
sizeof(..) to int to work when TLV_GET_DATA_LEN() returns a negative
value.&lt;/p&gt;
&lt;p&gt;syzbot reported a call trace because of it:&lt;/p&gt;
&lt;p&gt;BUG: KMSAN: uninit-value in ...
   tipc_nl_compat_name_table_dump+0x841/0xea0 net/tipc/netlink_compat.c:934
   __tipc_nl_compat_dumpit+0xab2/0x1320 net/tipc/netlink_compat.c:238
   tipc_nl_compat_dumpit+0x991/0xb50 net/tipc/netlink_compat.c:321
   tipc_nl_compat_recv+0xb6e/0x1640 net/tipc/netlink_compat.c:1324
   genl_family_rcv_msg_doit net/netlink/genetlink.c:731 [inline]
   genl_family_rcv_msg net/netlink/genetlink.c:775 [inline]
   genl_rcv_msg+0x103f/0x1260 net/netlink/genetlink.c:792
   netlink_rcv_skb+0x3a5/0x6c0 net/netlink/af_netlink.c:2501
   genl_rcv+0x3c/0x50 net/netlink/genetlink.c:803
   netlink_unicast_kernel net/netlink/af_netlink.c:1319 [inline]
   netlink_unicast+0xf3b/0x1270 net/netlink/af_netlink.c:1345
   netlink_sendmsg+0x1288/0x1440 net/netlink/af_netlink.c:1921
   sock_sendmsg_nosec net/socket.c:714 [inline]
   sock_sendmsg net/socket.c:734 [inline](CVE-2022-49862)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;net: tun: Fix memory leaks of…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2025-1820</guid>
    </item>
    <item>
      <title>SUSE-SU-2025:01918-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2025:01918-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2025:01918-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2022-49871</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-49871</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe, Ubuntu:Pro:16.04:LTS: linux-oracle, Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux, Ubuntu:18.04:LTS: linux-aws, Ubuntu:18.04:LTS: linux-aws-5.4 and 141 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: net: tun: Fix memory leaks of napi_get_frags kmemleak reports after running test_progs: unreferenced object 0xffff8881b1672dc0 (size 232):   comm &amp;#34;test_progs&amp;#34;, pid 394388, jiffies 4354712116 (age 841.975s)   hex dump (first 32 bytes):     e0 84 d7 a8 81 88 ff ff 80 2c 67 b1 81 88 ff ff  .........,g.....     00 40 c5 9b 81 88 ff ff 00 00 00 00 00 00 00 00  .@..............   backtrace:     [&amp;lt;00000000c8f01748&amp;gt;] napi_skb_cache_get+0xd4/0x150     [&amp;lt;0000000041c7fc09&amp;gt;] __napi_build_skb+0x15/0x50     [&amp;lt;00000000431c7079&amp;gt;] __napi_alloc_skb+0x26e/0x540     [&amp;lt;000000003ecfa30e&amp;gt;] napi_get_frags+0x59/0x140     [&amp;lt;0000000099b2199e&amp;gt;] tun_get_user+0x183d/0x3bb0 [tun]     [&amp;lt;000000008a5adef0&amp;gt;] tun_chr_write_iter+0xc0/0x1b1 [tun]     [&amp;lt;0000000049993ff4&amp;gt;] do_iter_readv_writev+0x19f/0x320     [&amp;lt;000000008f338ea2&amp;gt;] do_iter_write+0x135/0x630     [&amp;lt;000000008a3377a4&amp;gt;] vfs_writev+0x12e/0x440     [&amp;lt;00000000a6b5639a&amp;gt;] do_writev+0x104/0x280     [&amp;lt;00000000ccf065d8&amp;gt;] do_syscall_64+0x3b/0x90     [&amp;lt;00000000d776e329&amp;gt;] entry_SYSCALL_64_after_hwframe+0x63/0xcd The issue occurs in the following scenarios: tun_get_user()   napi_gro_frags()     napi_frags_finish()       case GRO_NORMAL:         gro_normal_one()           list_add_tail(&amp;amp;skb-&amp;gt;list, &amp;amp;napi-&amp;gt;rx_list);           &amp;lt;-- While napi-&amp;gt;rx_count &amp;lt; READ_ONCE(gro_normal_batch),           &amp;lt;-- gro_normal_list() is not called, napi-&amp;gt;rx_list is not empty   &amp;lt;-- not ask to complete the gro work, will caus…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe, Ubuntu:Pro:16.04:LTS: linux-oracle, Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux, Ubuntu:18.04:LTS: linux-aws, Ubuntu:18.04:LTS: linux-aws-5.4 and 141 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: net: tun: Fix memory leaks of napi_get_frags kmemleak reports after running test_progs: unreferenced object 0xffff8881b1672dc0 (size 232):   comm &amp;#34;test_progs&amp;#34;, pid 394388, jiffies 4354712116 (age 841.975s)   hex dump (first 32 bytes):     e0 84 d7 a8 81 88 ff ff 80 2c 67 b1 81 88 ff ff  .........,g.....     00 40 c5 9b 81 88 ff ff 00 00 00 00 00 00 00 00  .@..............   backtrace:     [&amp;lt;00000000c8f01748&amp;gt;] napi_skb_cache_get+0xd4/0x150     [&amp;lt;0000000041c7fc09&amp;gt;] __napi_build_skb+0x15/0x50     [&amp;lt;00000000431c7079&amp;gt;] __napi_alloc_skb+0x26e/0x540     [&amp;lt;000000003ecfa30e&amp;gt;] napi_get_frags+0x59/0x140     [&amp;lt;0000000099b2199e&amp;gt;] tun_get_user+0x183d/0x3bb0 [tun]     [&amp;lt;000000008a5adef0&amp;gt;] tun_chr_write_iter+0xc0/0x1b1 [tun]     [&amp;lt;0000000049993ff4&amp;gt;] do_iter_readv_writev+0x19f/0x320     [&amp;lt;000000008f338ea2&amp;gt;] do_iter_write+0x135/0x630     [&amp;lt;000000008a3377a4&amp;gt;] vfs_writev+0x12e/0x440     [&amp;lt;00000000a6b5639a&amp;gt;] do_writev+0x104/0x280     [&amp;lt;00000000ccf065d8&amp;gt;] do_syscall_64+0x3b/0x90     [&amp;lt;00000000d776e329&amp;gt;] entry_SYSCALL_64_after_hwframe+0x63/0xcd The issue occurs in the following scenarios: tun_get_user()   napi_gro_frags()     napi_frags_finish()       case GRO_NORMAL:         gro_normal_one()           list_add_tail(&amp;amp;skb-&amp;gt;list, &amp;amp;napi-&amp;gt;rx_list);           &amp;lt;-- While napi-&amp;gt;rx_count &amp;lt; READ_ONCE(gro_normal_batch),           &amp;lt;-- gro_normal_list() is not called, napi-&amp;gt;rx_list is not empty   &amp;lt;-- not ask to complete the gro work, will caus…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-49871</guid>
    </item>
  </channel>
</rss>
