<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 20:06:03 +0000</lastBuildDate>
    <item>
      <title>bdu:2023-03725</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2023-03725</link>
      <description>bdu:2023-03725</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2023-03725</guid>
    </item>
    <item>
      <title>Withdrawn: BELL-CVE-2023-3338 — CVE-2023-3338 does not affect BellSoft software</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2023-3338</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2023-3338</guid>
    </item>
    <item>
      <title>certfr-2023-avi-0601 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de
Debian. Certaines d'entre elles permettent à un…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2023-avi-0601</link>
      <description>certfr-2023-avi-0601</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2023-avi-0601</guid>
    </item>
    <item>
      <title>cnvd-2024-08095</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2024-08095</link>
      <description>cnvd-2024-08095</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2024-08095</guid>
    </item>
    <item>
      <title>EUVD-2026-220656</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-220656</link>
      <description>EUVD-2026-220656</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-220656</guid>
    </item>
    <item>
      <title>fkie_cve-2023-3338</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2023-3338</link>
      <description>&lt;p&gt;A null pointer dereference flaw was found in the Linux kernel&amp;#39;s DECnet networking protocol. This issue could allow a remote user to crash the system.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A null pointer dereference flaw was found in the Linux kernel&amp;#39;s DECnet networking protocol. This issue could allow a remote user to crash the system.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2023-3338</guid>
    </item>
    <item>
      <title>GHSA-qj9w-7hh5-mf2q</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-qj9w-7hh5-mf2q</link>
      <description>&lt;p&gt;A flaw null pointer dereference in the Linux kernel DECnet networking protocol was found. A remote user could use this flaw to crash the system.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw null pointer dereference in the Linux kernel DECnet networking protocol was found. A remote user could use this flaw to crash the system.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-qj9w-7hh5-mf2q</guid>
    </item>
    <item>
      <title>gsd-2023-3338</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2023-3338</link>
      <description>gsd-2023-3338</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2023-3338</guid>
    </item>
    <item>
      <title>ICSA-23-166-11 — Siemens SIMATIC S7-1500 TM MFP Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-23-166-11</link>
      <description>&lt;p&gt;json-c through 0.14 has an integer overflow and out-of-bounds write via a large JSON file, as demonstrated by printbuf_memappend. A memory overflow vulnerability was found in the Linux kernel’s ipc functionality of the memcg subsystem, in the way a user calls the semget function multiple times, creating semaphores. This flaw allows a local user to starve the resources, causing a denial of service. The highest threat from this vulnerability is to system availability. A vulnerability was found in the fs/inode.c:inode_init_owner() function logic of the LInux kernel that allows local users to create files for the XFS file-system with an unintended group ownership and with group execution and SGID permission bits set, in a scenario where a directory is SGID and belongs to a certain group and is writable by a user who is not a member of this group. This can lead to excessive permissions granted in case when they should not. This vulnerability is similar to the previous CVE-2018-13405 and adds the missed fix for the XFS. When sending malicous data to kernel by ioctl cmd FBIOPUT_VSCREENINFO,kernel will write memory out of bounds. In gc_data_segment in fs/f2fs/gc.c in the Linux kernel before 5.16.3, special files are not considered, leading to a move_data_page NULL pointer dereference. A flaw was found in the Linux kernel. The existing KVM SEV API has a vulnerability that allows a non-root (host) user-level application to crash the host kernel by creating a confidential guest VM inst…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;json-c through 0.14 has an integer overflow and out-of-bounds write via a large JSON file, as demonstrated by printbuf_memappend. A memory overflow vulnerability was found in the Linux kernel’s ipc functionality of the memcg subsystem, in the way a user calls the semget function multiple times, creating semaphores. This flaw allows a local user to starve the resources, causing a denial of service. The highest threat from this vulnerability is to system availability. A vulnerability was found in the fs/inode.c:inode_init_owner() function logic of the LInux kernel that allows local users to create files for the XFS file-system with an unintended group ownership and with group execution and SGID permission bits set, in a scenario where a directory is SGID and belongs to a certain group and is writable by a user who is not a member of this group. This can lead to excessive permissions granted in case when they should not. This vulnerability is similar to the previous CVE-2018-13405 and adds the missed fix for the XFS. When sending malicous data to kernel by ioctl cmd FBIOPUT_VSCREENINFO,kernel will write memory out of bounds. In gc_data_segment in fs/f2fs/gc.c in the Linux kernel before 5.16.3, special files are not considered, leading to a move_data_page NULL pointer dereference. A flaw was found in the Linux kernel. The existing KVM SEV API has a vulnerability that allows a non-root (host) user-level application to crash the host kernel by creating a confidential guest VM inst…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-23-166-11</guid>
    </item>
    <item>
      <title>msrc_CVE-2023-3338 — Crash due to a null pointer dereference in the dn_nsp_send function</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2023-3338</link>
      <description>msrc_CVE-2023-3338</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2023-3338</guid>
    </item>
    <item>
      <title>OESA-2023-1435 — kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2023-1435</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;A time-of-check to time-of-use issue exists in io_uring subsystem&amp;amp;apos;s IORING_OP_CLOSE operation in the Linux kernel&amp;amp;apos;s versions 5.6 - 5.11 (inclusive), which allows a local user to elevate their privileges to root. Introduced in b5dba59e0cf7e2cc4d3b3b1ac5fe81ddf21959eb, patched in 9eac1904d3364254d622bf2c771c4f85cd435fc2, backported to stable in 788d0824269bef539fe31a785b1517882eafed93.(CVE-2023-1295)&lt;/p&gt;
&lt;p&gt;A heap out-of-bounds write vulnerability in the Linux Kernel ipvlan network driver can be exploited to achieve local privilege escalation.&lt;/p&gt;
&lt;p&gt;The out-of-bounds write is caused by missing skb-&amp;amp;gt;cb  initialization in the ipvlan network driver. The vulnerability is reachable if CONFIG_IPVLAN is enabled.&lt;/p&gt;
&lt;p&gt;We recommend upgrading past commit 90cbed5247439a966b645b34eb0a2e037836ea8e.&lt;/p&gt;
&lt;p&gt;(CVE-2023-3090)&lt;/p&gt;
&lt;p&gt;A use-after-free flaw was found in the Netfilter subsystem of the Linux kernel when processing named and anonymous sets in batch requests, which can lead to performing arbitrary reads and writes in kernel memory. This flaw allows a local user with CAP_NET_ADMIN capability to crash or potentially escalate their privileges on the system.(CVE-2023-3117)&lt;/p&gt;
&lt;p&gt;Linux Kernel nftables Use-After-Free Local Privilege Escalation Vulnerability; `nft_chain_lookup_byid()` failed to check whether a chain was active and CAP_NET_ADMIN is in any user or network namespace(CVE-2023-31248)&lt;/p&gt;
&lt;p&gt;An issue was discovered in the Linux kerne…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;A time-of-check to time-of-use issue exists in io_uring subsystem&amp;amp;apos;s IORING_OP_CLOSE operation in the Linux kernel&amp;amp;apos;s versions 5.6 - 5.11 (inclusive), which allows a local user to elevate their privileges to root. Introduced in b5dba59e0cf7e2cc4d3b3b1ac5fe81ddf21959eb, patched in 9eac1904d3364254d622bf2c771c4f85cd435fc2, backported to stable in 788d0824269bef539fe31a785b1517882eafed93.(CVE-2023-1295)&lt;/p&gt;
&lt;p&gt;A heap out-of-bounds write vulnerability in the Linux Kernel ipvlan network driver can be exploited to achieve local privilege escalation.&lt;/p&gt;
&lt;p&gt;The out-of-bounds write is caused by missing skb-&amp;amp;gt;cb  initialization in the ipvlan network driver. The vulnerability is reachable if CONFIG_IPVLAN is enabled.&lt;/p&gt;
&lt;p&gt;We recommend upgrading past commit 90cbed5247439a966b645b34eb0a2e037836ea8e.&lt;/p&gt;
&lt;p&gt;(CVE-2023-3090)&lt;/p&gt;
&lt;p&gt;A use-after-free flaw was found in the Netfilter subsystem of the Linux kernel when processing named and anonymous sets in batch requests, which can lead to performing arbitrary reads and writes in kernel memory. This flaw allows a local user with CAP_NET_ADMIN capability to crash or potentially escalate their privileges on the system.(CVE-2023-3117)&lt;/p&gt;
&lt;p&gt;Linux Kernel nftables Use-After-Free Local Privilege Escalation Vulnerability; `nft_chain_lookup_byid()` failed to check whether a chain was active and CAP_NET_ADMIN is in any user or network namespace(CVE-2023-31248)&lt;/p&gt;
&lt;p&gt;An issue was discovered in the Linux kerne…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2023-1435</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2023-3338</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-3338</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux, Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe and 134 more&lt;/p&gt;
&lt;p&gt;A null pointer dereference flaw was found in the Linux kernel&amp;#39;s DECnet networking protocol. This issue could allow a remote user to crash the system.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux, Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe and 134 more&lt;/p&gt;
&lt;p&gt;A null pointer dereference flaw was found in the Linux kernel&amp;#39;s DECnet networking protocol. This issue could allow a remote user to crash the system.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-3338</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-1564 — Linux Kernel: Schwachstelle ermöglicht Denial of Service</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1564</link>
      <description>&lt;p&gt;Ein lokaler Angreifer kann eine Schwachstelle im Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein lokaler Angreifer kann eine Schwachstelle im Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1564</guid>
    </item>
  </channel>
</rss>
