<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 02:40:22 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-02367</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-02367</link>
      <description>bdu:2026-02367</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-02367</guid>
    </item>
    <item>
      <title>EUVD-2026-311155</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-311155</link>
      <description>EUVD-2026-311155</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-311155</guid>
    </item>
    <item>
      <title>fkie_cve-2022-50314</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-50314</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;nbd: Fix hung when signal interrupts nbd_start_device_ioctl()&lt;/p&gt;
&lt;p&gt;syzbot reported hung task [1].  The following program is a simplified
version of the reproducer:&lt;/p&gt;
&lt;p&gt;int main(void)
{
	int sv[2], fd;&lt;/p&gt;
&lt;p&gt;if (socketpair(AF_UNIX, SOCK_STREAM, 0, sv) &amp;lt; 0)
		return 1;
	if ((fd = open(&amp;#34;/dev/nbd0&amp;#34;, 0)) &amp;lt; 0)
		return 1;
	if (ioctl(fd, NBD_SET_SIZE_BLOCKS, 0x81) &amp;lt; 0)
		return 1;
	if (ioctl(fd, NBD_SET_SOCK, sv[0]) &amp;lt; 0)
		return 1;
	if (ioctl(fd, NBD_DO_IT) &amp;lt; 0)
		return 1;
	return 0;
}&lt;/p&gt;
&lt;p&gt;When signal interrupt nbd_start_device_ioctl() waiting the condition
atomic_read(&amp;amp;config-&amp;gt;recv_threads) == 0, the task can hung because it
waits the completion of the inflight IOs.&lt;/p&gt;
&lt;p&gt;This patch fixes the issue by clearing queue, not just shutdown, when
signal interrupt nbd_start_device_ioctl().&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;nbd: Fix hung when signal interrupts nbd_start_device_ioctl()&lt;/p&gt;
&lt;p&gt;syzbot reported hung task [1].  The following program is a simplified
version of the reproducer:&lt;/p&gt;
&lt;p&gt;int main(void)
{
	int sv[2], fd;&lt;/p&gt;
&lt;p&gt;if (socketpair(AF_UNIX, SOCK_STREAM, 0, sv) &amp;lt; 0)
		return 1;
	if ((fd = open(&amp;#34;/dev/nbd0&amp;#34;, 0)) &amp;lt; 0)
		return 1;
	if (ioctl(fd, NBD_SET_SIZE_BLOCKS, 0x81) &amp;lt; 0)
		return 1;
	if (ioctl(fd, NBD_SET_SOCK, sv[0]) &amp;lt; 0)
		return 1;
	if (ioctl(fd, NBD_DO_IT) &amp;lt; 0)
		return 1;
	return 0;
}&lt;/p&gt;
&lt;p&gt;When signal interrupt nbd_start_device_ioctl() waiting the condition
atomic_read(&amp;amp;config-&amp;gt;recv_threads) == 0, the task can hung because it
waits the completion of the inflight IOs.&lt;/p&gt;
&lt;p&gt;This patch fixes the issue by clearing queue, not just shutdown, when
signal interrupt nbd_start_device_ioctl().&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-50314</guid>
    </item>
    <item>
      <title>GHSA-x3q5-jcq9-7rv7</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-x3q5-jcq9-7rv7</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;nbd: Fix hung when signal interrupts nbd_start_device_ioctl()&lt;/p&gt;
&lt;p&gt;syzbot reported hung task [1].  The following program is a simplified
version of the reproducer:&lt;/p&gt;
&lt;p&gt;int main(void)
{
	int sv[2], fd;&lt;/p&gt;
&lt;p&gt;if (socketpair(AF_UNIX, SOCK_STREAM, 0, sv) &amp;lt; 0)
		return 1;
	if ((fd = open(&amp;#34;/dev/nbd0&amp;#34;, 0)) &amp;lt; 0)
		return 1;
	if (ioctl(fd, NBD_SET_SIZE_BLOCKS, 0x81) &amp;lt; 0)
		return 1;
	if (ioctl(fd, NBD_SET_SOCK, sv[0]) &amp;lt; 0)
		return 1;
	if (ioctl(fd, NBD_DO_IT) &amp;lt; 0)
		return 1;
	return 0;
}&lt;/p&gt;
&lt;p&gt;When signal interrupt nbd_start_device_ioctl() waiting the condition
atomic_read(&amp;amp;config-&amp;gt;recv_threads) == 0, the task can hung because it
waits the completion of the inflight IOs.&lt;/p&gt;
&lt;p&gt;This patch fixes the issue by clearing queue, not just shutdown, when
signal interrupt nbd_start_device_ioctl().&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;nbd: Fix hung when signal interrupts nbd_start_device_ioctl()&lt;/p&gt;
&lt;p&gt;syzbot reported hung task [1].  The following program is a simplified
version of the reproducer:&lt;/p&gt;
&lt;p&gt;int main(void)
{
	int sv[2], fd;&lt;/p&gt;
&lt;p&gt;if (socketpair(AF_UNIX, SOCK_STREAM, 0, sv) &amp;lt; 0)
		return 1;
	if ((fd = open(&amp;#34;/dev/nbd0&amp;#34;, 0)) &amp;lt; 0)
		return 1;
	if (ioctl(fd, NBD_SET_SIZE_BLOCKS, 0x81) &amp;lt; 0)
		return 1;
	if (ioctl(fd, NBD_SET_SOCK, sv[0]) &amp;lt; 0)
		return 1;
	if (ioctl(fd, NBD_DO_IT) &amp;lt; 0)
		return 1;
	return 0;
}&lt;/p&gt;
&lt;p&gt;When signal interrupt nbd_start_device_ioctl() waiting the condition
atomic_read(&amp;amp;config-&amp;gt;recv_threads) == 0, the task can hung because it
waits the completion of the inflight IOs.&lt;/p&gt;
&lt;p&gt;This patch fixes the issue by clearing queue, not just shutdown, when
signal interrupt nbd_start_device_ioctl().&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-x3q5-jcq9-7rv7</guid>
    </item>
    <item>
      <title>OESA-2025-2533 — kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2025-2533</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP4: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;md: Replace snprintf with scnprintf&lt;/p&gt;
&lt;p&gt;Current code produces a warning as shown below when total characters
in the constituent block device names plus the slashes exceeds 200.
snprintf() returns the number of characters generated from the given
input, which could cause the expression “200 – len” to wrap around
to a large positive number. Fix this by using scnprintf() instead,
which returns the actual number of characters written into the buffer.&lt;/p&gt;
&lt;p&gt;[ 1513.267938] ------------[ cut here ]------------
[ 1513.267943] WARNING: CPU: 15 PID: 37247 at &amp;amp;lt;snip&amp;amp;gt;/lib/vsprintf.c:2509 vsnprintf+0x2c8/0x510
[ 1513.267944] Modules linked in:  &amp;amp;lt;snip&amp;amp;gt;
[ 1513.267969] CPU: 15 PID: 37247 Comm: mdadm Not tainted 5.4.0-1085-azure #90~18.04.1-Ubuntu
[ 1513.267969] Hardware name: Microsoft Corporation Virtual Machine/Virtual Machine, BIOS Hyper-V UEFI Release v4.1 05/09/2022
[ 1513.267971] RIP: 0010:vsnprintf+0x2c8/0x510
&amp;amp;lt;-snip-&amp;amp;gt;
[ 1513.267982] Call Trace:
[ 1513.267986]  snprintf+0x45/0x70
[ 1513.267990]  ? disk_name+0x71/0xa0
[ 1513.267993]  dump_zones+0x114/0x240 [raid0]
[ 1513.267996]  ? _cond_resched+0x19/0x40
[ 1513.267998]  raid0_run+0x19e/0x270 [raid0]
[ 1513.268000]  md_run+0x5e0/0xc50
[ 1513.268003]  ? security_capable+0x3f/0x60
[ 1513.268005]  do_md_run+0x19/0x110
[ 1513.268006]  md_ioctl+0x195e/0x1f90
[ 1513.268007]  blkdev_ioctl+0x9…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP4: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;md: Replace snprintf with scnprintf&lt;/p&gt;
&lt;p&gt;Current code produces a warning as shown below when total characters
in the constituent block device names plus the slashes exceeds 200.
snprintf() returns the number of characters generated from the given
input, which could cause the expression “200 – len” to wrap around
to a large positive number. Fix this by using scnprintf() instead,
which returns the actual number of characters written into the buffer.&lt;/p&gt;
&lt;p&gt;[ 1513.267938] ------------[ cut here ]------------
[ 1513.267943] WARNING: CPU: 15 PID: 37247 at &amp;amp;lt;snip&amp;amp;gt;/lib/vsprintf.c:2509 vsnprintf+0x2c8/0x510
[ 1513.267944] Modules linked in:  &amp;amp;lt;snip&amp;amp;gt;
[ 1513.267969] CPU: 15 PID: 37247 Comm: mdadm Not tainted 5.4.0-1085-azure #90~18.04.1-Ubuntu
[ 1513.267969] Hardware name: Microsoft Corporation Virtual Machine/Virtual Machine, BIOS Hyper-V UEFI Release v4.1 05/09/2022
[ 1513.267971] RIP: 0010:vsnprintf+0x2c8/0x510
&amp;amp;lt;-snip-&amp;amp;gt;
[ 1513.267982] Call Trace:
[ 1513.267986]  snprintf+0x45/0x70
[ 1513.267990]  ? disk_name+0x71/0xa0
[ 1513.267993]  dump_zones+0x114/0x240 [raid0]
[ 1513.267996]  ? _cond_resched+0x19/0x40
[ 1513.267998]  raid0_run+0x19e/0x270 [raid0]
[ 1513.268000]  md_run+0x5e0/0xc50
[ 1513.268003]  ? security_capable+0x3f/0x60
[ 1513.268005]  do_md_run+0x19/0x110
[ 1513.268006]  md_ioctl+0x195e/0x1f90
[ 1513.268007]  blkdev_ioctl+0x9…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2025-2533</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2022-50314</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-50314</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux, Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe, Ubuntu:Pro:16.04:LTS: linux-oracle, Ubuntu:Pro:16.04:LTS: linux and 155 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: nbd: Fix hung when signal interrupts nbd_start_device_ioctl() syzbot reported hung task [1].  The following program is a simplified version of the reproducer: int main(void) { 	int sv[2], fd; 	if (socketpair(AF_UNIX, SOCK_STREAM, 0, sv) &amp;lt; 0) 		return 1; 	if ((fd = open(&amp;#34;/dev/nbd0&amp;#34;, 0)) &amp;lt; 0) 		return 1; 	if (ioctl(fd, NBD_SET_SIZE_BLOCKS, 0x81) &amp;lt; 0) 		return 1; 	if (ioctl(fd, NBD_SET_SOCK, sv[0]) &amp;lt; 0) 		return 1; 	if (ioctl(fd, NBD_DO_IT) &amp;lt; 0) 		return 1; 	return 0; } When signal interrupt nbd_start_device_ioctl() waiting the condition atomic_read(&amp;amp;config-&amp;gt;recv_threads) == 0, the task can hung because it waits the completion of the inflight IOs. This patch fixes the issue by clearing queue, not just shutdown, when signal interrupt nbd_start_device_ioctl().&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux, Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe, Ubuntu:Pro:16.04:LTS: linux-oracle, Ubuntu:Pro:16.04:LTS: linux and 155 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: nbd: Fix hung when signal interrupts nbd_start_device_ioctl() syzbot reported hung task [1].  The following program is a simplified version of the reproducer: int main(void) { 	int sv[2], fd; 	if (socketpair(AF_UNIX, SOCK_STREAM, 0, sv) &amp;lt; 0) 		return 1; 	if ((fd = open(&amp;#34;/dev/nbd0&amp;#34;, 0)) &amp;lt; 0) 		return 1; 	if (ioctl(fd, NBD_SET_SIZE_BLOCKS, 0x81) &amp;lt; 0) 		return 1; 	if (ioctl(fd, NBD_SET_SOCK, sv[0]) &amp;lt; 0) 		return 1; 	if (ioctl(fd, NBD_DO_IT) &amp;lt; 0) 		return 1; 	return 0; } When signal interrupt nbd_start_device_ioctl() waiting the condition atomic_read(&amp;amp;config-&amp;gt;recv_threads) == 0, the task can hung because it waits the completion of the inflight IOs. This patch fixes the issue by clearing queue, not just shutdown, when signal interrupt nbd_start_device_ioctl().&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-50314</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-2053 — Linux Kernel: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2053</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen oder nicht näher beschriebene Auswirkungen zu erzielen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen oder nicht näher beschriebene Auswirkungen zu erzielen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2053</guid>
    </item>
  </channel>
</rss>
