<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 23:09:57 +0000</lastBuildDate>
    <item>
      <title>bdu:2025-15382</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-15382</link>
      <description>bdu:2025-15382</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-15382</guid>
    </item>
    <item>
      <title>BELL-CVE-2023-4458</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2023-4458</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2023-4458</guid>
    </item>
    <item>
      <title>cnvd-2024-45869</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2024-45869</link>
      <description>cnvd-2024-45869</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2024-45869</guid>
    </item>
    <item>
      <title>EUVD-2026-201625</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-201625</link>
      <description>EUVD-2026-201625</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-201625</guid>
    </item>
    <item>
      <title>fkie_cve-2023-4458</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2023-4458</link>
      <description>&lt;p&gt;A flaw was found within the parsing of extended attributes in the kernel ksmbd module. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this to disclose sensitive information on affected installations of Linux. Only systems with ksmbd enabled are vulnerable to this CVE.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found within the parsing of extended attributes in the kernel ksmbd module. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this to disclose sensitive information on affected installations of Linux. Only systems with ksmbd enabled are vulnerable to this CVE.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2023-4458</guid>
    </item>
    <item>
      <title>GHSA-gqjr-4mgj-g55g</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-gqjr-4mgj-g55g</link>
      <description>&lt;p&gt;A flaw was found within the parsing of extended attributes in the kernel ksmbd module. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this to disclose sensitive information on affected installations of Linux. Only systems with ksmbd enabled are vulnerable to this CVE.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found within the parsing of extended attributes in the kernel ksmbd module. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this to disclose sensitive information on affected installations of Linux. Only systems with ksmbd enabled are vulnerable to this CVE.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-gqjr-4mgj-g55g</guid>
    </item>
    <item>
      <title>gsd-2023-4458</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2023-4458</link>
      <description>gsd-2023-4458</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2023-4458</guid>
    </item>
    <item>
      <title>msrc_CVE-2023-4458 — Kernel: ksmbd: smb2_open out-of-bounds read information disclosure vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2023-4458</link>
      <description>msrc_CVE-2023-4458</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2023-4458</guid>
    </item>
    <item>
      <title>OESA-2025-1963 — kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2025-1963</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP3: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;net/sched: act_ct: fix ref leak when switching zones&lt;/p&gt;
&lt;p&gt;When switching zones or network namespaces without doing a ct clear in
between, it is now leaking a reference to the old ct entry. That&amp;amp;apos;s
because tcf_ct_skb_nfct_cached() returns false and
tcf_ct_flow_table_lookup() may simply overwrite it.&lt;/p&gt;
&lt;p&gt;The fix is to, as the ct entry is not reusable, free it already at
tcf_ct_skb_nfct_cached().(CVE-2022-49183)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;net: annotate races around sk-&amp;amp;gt;sk_bound_dev_if&lt;/p&gt;
&lt;p&gt;UDP sendmsg() is lockless, and reads sk-&amp;amp;gt;sk_bound_dev_if while
this field can be changed by another thread.&lt;/p&gt;
&lt;p&gt;Adds minimal annotations to avoid KCSAN splats for UDP.
Following patches will add more annotations to potential lockless readers.&lt;/p&gt;
&lt;p&gt;BUG: KCSAN: data-race in __ip6_datagram_connect / udpv6_sendmsg&lt;/p&gt;
&lt;p&gt;write to 0xffff888136d47a94 of 4 bytes by task 7681 on cpu 0:
 __ip6_datagram_connect+0x6e2/0x930 net/ipv6/datagram.c:221
 ip6_datagram_connect+0x2a/0x40 net/ipv6/datagram.c:272
 inet_dgram_connect+0x107/0x190 net/ipv4/af_inet.c:576
 __sys_connect_file net/socket.c:1900 [inline]
 __sys_connect+0x197/0x1b0 net/socket.c:1917
 __do_sys_connect net/socket.c:1927 [inline]
 __se_sys_connect net/socket.c:1924 [inline]
 __x64_sys_connect+0x3d/0x50 net/socket.c:1924
 do_syscall_x64 arch/x86/entry/common.c:50 [inline]
 d…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP3: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;net/sched: act_ct: fix ref leak when switching zones&lt;/p&gt;
&lt;p&gt;When switching zones or network namespaces without doing a ct clear in
between, it is now leaking a reference to the old ct entry. That&amp;amp;apos;s
because tcf_ct_skb_nfct_cached() returns false and
tcf_ct_flow_table_lookup() may simply overwrite it.&lt;/p&gt;
&lt;p&gt;The fix is to, as the ct entry is not reusable, free it already at
tcf_ct_skb_nfct_cached().(CVE-2022-49183)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;net: annotate races around sk-&amp;amp;gt;sk_bound_dev_if&lt;/p&gt;
&lt;p&gt;UDP sendmsg() is lockless, and reads sk-&amp;amp;gt;sk_bound_dev_if while
this field can be changed by another thread.&lt;/p&gt;
&lt;p&gt;Adds minimal annotations to avoid KCSAN splats for UDP.
Following patches will add more annotations to potential lockless readers.&lt;/p&gt;
&lt;p&gt;BUG: KCSAN: data-race in __ip6_datagram_connect / udpv6_sendmsg&lt;/p&gt;
&lt;p&gt;write to 0xffff888136d47a94 of 4 bytes by task 7681 on cpu 0:
 __ip6_datagram_connect+0x6e2/0x930 net/ipv6/datagram.c:221
 ip6_datagram_connect+0x2a/0x40 net/ipv6/datagram.c:272
 inet_dgram_connect+0x107/0x190 net/ipv4/af_inet.c:576
 __sys_connect_file net/socket.c:1900 [inline]
 __sys_connect+0x197/0x1b0 net/socket.c:1917
 __do_sys_connect net/socket.c:1927 [inline]
 __se_sys_connect net/socket.c:1924 [inline]
 __x64_sys_connect+0x3d/0x50 net/socket.c:1924
 do_syscall_x64 arch/x86/entry/common.c:50 [inline]
 d…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2025-1963</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2023-4458</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-4458</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 99 more&lt;/p&gt;
&lt;p&gt;A flaw was found within the parsing of extended attributes in the kernel ksmbd module. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this to disclose sensitive information on affected installations of Linux. Only systems with ksmbd enabled are vulnerable to this CVE.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 99 more&lt;/p&gt;
&lt;p&gt;A flaw was found within the parsing of extended attributes in the kernel ksmbd module. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this to disclose sensitive information on affected installations of Linux. Only systems with ksmbd enabled are vulnerable to this CVE.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-4458</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-3462 — Linux Kernel: Schwachstelle ermöglicht Offenlegung von Informationen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-3462</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle im Linux Kernel ausnutzen, um Informationen offenzulegen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle im Linux Kernel ausnutzen, um Informationen offenzulegen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-3462</guid>
    </item>
  </channel>
</rss>
