<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 22:12:48 +0000</lastBuildDate>
    <item>
      <title>bdu:2023-02745</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2023-02745</link>
      <description>bdu:2023-02745</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2023-02745</guid>
    </item>
    <item>
      <title>Withdrawn: BELL-CVE-2023-32251 — CVE-2023-32251 does not affect BellSoft software</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2023-32251</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2023-32251</guid>
    </item>
    <item>
      <title>EUVD-2026-331291</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-331291</link>
      <description>EUVD-2026-331291</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-331291</guid>
    </item>
    <item>
      <title>fkie_cve-2023-32251</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2023-32251</link>
      <description>&lt;p&gt;A vulnerability has been identified in the Linux kernel&amp;#39;s ksmbd component (kernel SMB/CIFS server). A security control designed to prevent dictionary attacks, which introduces a 5-second delay during session setup, can be bypassed through the use of asynchronous requests. This bypass negates the intended anti-brute-force protection, potentially allowing attackers to conduct dictionary attacks more efficiently against user credentials or other authentication mechanisms.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability has been identified in the Linux kernel&amp;#39;s ksmbd component (kernel SMB/CIFS server). A security control designed to prevent dictionary attacks, which introduces a 5-second delay during session setup, can be bypassed through the use of asynchronous requests. This bypass negates the intended anti-brute-force protection, potentially allowing attackers to conduct dictionary attacks more efficiently against user credentials or other authentication mechanisms.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2023-32251</guid>
    </item>
    <item>
      <title>GHSA-7rf9-h4hc-6359</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-7rf9-h4hc-6359</link>
      <description>&lt;p&gt;A vulnerability has been identified in the Linux kernel&amp;#39;s ksmbd component (kernel SMB/CIFS server). A security control designed to prevent dictionary attacks, which introduces a 5-second delay during session setup, can be bypassed through the use of asynchronous requests. This bypass negates the intended anti-brute-force protection, potentially allowing attackers to conduct dictionary attacks more efficiently against user credentials or other authentication mechanisms.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability has been identified in the Linux kernel&amp;#39;s ksmbd component (kernel SMB/CIFS server). A security control designed to prevent dictionary attacks, which introduces a 5-second delay during session setup, can be bypassed through the use of asynchronous requests. This bypass negates the intended anti-brute-force protection, potentially allowing attackers to conduct dictionary attacks more efficiently against user credentials or other authentication mechanisms.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-7rf9-h4hc-6359</guid>
    </item>
    <item>
      <title>gsd-2023-32251</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2023-32251</link>
      <description>gsd-2023-32251</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2023-32251</guid>
    </item>
    <item>
      <title>OESA-2023-1668 — kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2023-1668</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&#13;
&#13;
An issue was discovered in the Linux kernel through 6.0.9. drivers/media/usb/ttusb-dec/ttusb_dec.c has a memory leak because of the lack of a dvb_frontend_detach call.(CVE-2022-45887)&lt;/p&gt;
&lt;p&gt;A division-by-zero error on some AMD processors can potentially return speculative data resulting in loss of confidentiality. &#13;
&#13;
&#13;
&#13;
&#13;
&#13;
&#13;
&#13;
(CVE-2023-20588)&#13;
&#13;
In multiple functions  of io_uring.c, there is a possible kernel memory corruption due to improper locking. This could lead to local escalation of privilege in the kernel with System execution privileges needed. User interaction is not needed for exploitation.&#13;
&#13;
(CVE-2023-21400)&#13;
&#13;
VUL-0: CVE-2023-32249: kernel: Linux Kernel ksmbd Multichannel Improper Authentication Session Hijack Vulnerability(CVE-2023-32249)&#13;
&#13;
VUL-0: CVE-2023-32251: kernel: Linux Kernel ksmbd Improper Restriction of Excessive Authentication Attempts Protection Bypass Vulnerability(CVE-2023-32251)&#13;
&#13;
VUL-0: CVE-2023-32253: kernel: Linux Kernel ksmbd Session Deadlock Denial-of-Service Vulnerability(CVE-2023-32253)&#13;
&#13;
** REJECT ** CVE-2023-4881 was wrongly assigned to a bug that was deemed to be a non-security issue by the Linux kernel security team.(CVE-2023-4881)&#13;
&#13;
A use-after-free vulnerability in the Linux kernel&amp;amp;apos;s net/sched: sch_qfq component can be exploited to achieve local privilege escalation.&#13;
&#13;
When the plug qdisc is used as a class of the qfq qdisc, sending network packe…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&#13;
&#13;
An issue was discovered in the Linux kernel through 6.0.9. drivers/media/usb/ttusb-dec/ttusb_dec.c has a memory leak because of the lack of a dvb_frontend_detach call.(CVE-2022-45887)&lt;/p&gt;
&lt;p&gt;A division-by-zero error on some AMD processors can potentially return speculative data resulting in loss of confidentiality. &#13;
&#13;
&#13;
&#13;
&#13;
&#13;
&#13;
&#13;
(CVE-2023-20588)&#13;
&#13;
In multiple functions  of io_uring.c, there is a possible kernel memory corruption due to improper locking. This could lead to local escalation of privilege in the kernel with System execution privileges needed. User interaction is not needed for exploitation.&#13;
&#13;
(CVE-2023-21400)&#13;
&#13;
VUL-0: CVE-2023-32249: kernel: Linux Kernel ksmbd Multichannel Improper Authentication Session Hijack Vulnerability(CVE-2023-32249)&#13;
&#13;
VUL-0: CVE-2023-32251: kernel: Linux Kernel ksmbd Improper Restriction of Excessive Authentication Attempts Protection Bypass Vulnerability(CVE-2023-32251)&#13;
&#13;
VUL-0: CVE-2023-32253: kernel: Linux Kernel ksmbd Session Deadlock Denial-of-Service Vulnerability(CVE-2023-32253)&#13;
&#13;
** REJECT ** CVE-2023-4881 was wrongly assigned to a bug that was deemed to be a non-security issue by the Linux kernel security team.(CVE-2023-4881)&#13;
&#13;
A use-after-free vulnerability in the Linux kernel&amp;amp;apos;s net/sched: sch_qfq component can be exploited to achieve local privilege escalation.&#13;
&#13;
When the plug qdisc is used as a class of the qfq qdisc, sending network packe…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2023-1668</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2023-32251</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-32251</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux, Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe and 168 more&lt;/p&gt;
&lt;p&gt;A vulnerability has been identified in the Linux kernel&amp;#39;s ksmbd component (kernel SMB/CIFS server). A security control designed to prevent dictionary attacks, which introduces a 5-second delay during session setup, can be bypassed through the use of asynchronous requests. This bypass negates the intended anti-brute-force protection, potentially allowing attackers to conduct dictionary attacks more efficiently against user credentials or other authentication mechanisms.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux, Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe and 168 more&lt;/p&gt;
&lt;p&gt;A vulnerability has been identified in the Linux kernel&amp;#39;s ksmbd component (kernel SMB/CIFS server). A security control designed to prevent dictionary attacks, which introduces a 5-second delay during session setup, can be bypassed through the use of asynchronous requests. This bypass negates the intended anti-brute-force protection, potentially allowing attackers to conduct dictionary attacks more efficiently against user credentials or other authentication mechanisms.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-32251</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-1255 — Linux Kernel (ksmbd): Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1255</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen Denial of Service-Zustand herbeizuführen, Informationen offenzulegen, Sicherheitsvorkehrungen zu umgehen, Privilegien zu erweitern und beliebigen Code auszuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen Denial of Service-Zustand herbeizuführen, Informationen offenzulegen, Sicherheitsvorkehrungen zu umgehen, Privilegien zu erweitern und beliebigen Code auszuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1255</guid>
    </item>
  </channel>
</rss>
