<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 17:13:44 +0000</lastBuildDate>
    <item>
      <title>ALSA-2024:2394 — Important: kernel security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2024:2394</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: bpftool, AlmaLinux:9: kernel, AlmaLinux:9: kernel-64k, AlmaLinux:9: kernel-64k-core, AlmaLinux:9: kernel-64k-debug, AlmaLinux:9: kernel-64k-debug-core, AlmaLinux:9: kernel-64k-debug-devel, AlmaLinux:9: kernel-64k-debug-devel-matched, AlmaLinux:9: kernel-64k-debug-modules, AlmaLinux:9: kernel-64k-debug-modules-core and 52 more&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: GSM multiplexing race condition leads to privilege escalation (CVE-2023-6546)
  * kernel: multiple use-after-free vulnerabilities (CVE-2024-1086, CVE-2023-3567, CVE-2023-4133, CVE-2023-6932, CVE-2023-39198, CVE-2023-51043, CVE-2023-51779, CVE-2023-51780, CVE-2024-1085, CVE-2024-26582)
  * kernel: Bluetooth BR/EDR PIN Pairing procedure is vulnerable to an impersonation attack (CVE-2020-26555)
  * kernel: memcg does not limit the number of POSIX file locks allowing memory exhaustion (CVE-2022-0480)
  * kernel: multiple NULL pointer dereference vulnerabilities (CVE-2022-38096, CVE-2023-6622, CVE-2023-6915, CVE-2023-42754, CVE-2023-46862, CVE-2023-52574, CVE-2024-0841, CVE-2023-52448)
  * kernel: integer overflow in l2cap_config_req() in net/bluetooth/l2cap_core.c (CVE-2022-45934)
  * kernel: netfilter: nf_tables: out-of-bounds access in nf_tables_newtable() (CVE-2023-6040)
  * kernel: GC&amp;#39;s deletion of an SKB races with unix_stream_read_generic() leading to UAF (CVE-2023-6531)
  * kernel: Out of boundary write in perf_read_group() as result of overflow a perf_event&amp;#39;s read_size (CVE-2023-6931)
  * kernel: Bluetooth Forward and Future Secrecy Attacks and Defenses (CVE-2023-24023)
  * kernel: irdma: Improper access control (CVE-2023-25775)
  * Kernel: double free in hci_conn_cleanup of the bluetooth subsystem (CVE-2023-28464)
  * kernel: Bluetooth: HCI: global o…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: bpftool, AlmaLinux:9: kernel, AlmaLinux:9: kernel-64k, AlmaLinux:9: kernel-64k-core, AlmaLinux:9: kernel-64k-debug, AlmaLinux:9: kernel-64k-debug-core, AlmaLinux:9: kernel-64k-debug-devel, AlmaLinux:9: kernel-64k-debug-devel-matched, AlmaLinux:9: kernel-64k-debug-modules, AlmaLinux:9: kernel-64k-debug-modules-core and 52 more&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: GSM multiplexing race condition leads to privilege escalation (CVE-2023-6546)
  * kernel: multiple use-after-free vulnerabilities (CVE-2024-1086, CVE-2023-3567, CVE-2023-4133, CVE-2023-6932, CVE-2023-39198, CVE-2023-51043, CVE-2023-51779, CVE-2023-51780, CVE-2024-1085, CVE-2024-26582)
  * kernel: Bluetooth BR/EDR PIN Pairing procedure is vulnerable to an impersonation attack (CVE-2020-26555)
  * kernel: memcg does not limit the number of POSIX file locks allowing memory exhaustion (CVE-2022-0480)
  * kernel: multiple NULL pointer dereference vulnerabilities (CVE-2022-38096, CVE-2023-6622, CVE-2023-6915, CVE-2023-42754, CVE-2023-46862, CVE-2023-52574, CVE-2024-0841, CVE-2023-52448)
  * kernel: integer overflow in l2cap_config_req() in net/bluetooth/l2cap_core.c (CVE-2022-45934)
  * kernel: netfilter: nf_tables: out-of-bounds access in nf_tables_newtable() (CVE-2023-6040)
  * kernel: GC&amp;#39;s deletion of an SKB races with unix_stream_read_generic() leading to UAF (CVE-2023-6531)
  * kernel: Out of boundary write in perf_read_group() as result of overflow a perf_event&amp;#39;s read_size (CVE-2023-6931)
  * kernel: Bluetooth Forward and Future Secrecy Attacks and Defenses (CVE-2023-24023)
  * kernel: irdma: Improper access control (CVE-2023-25775)
  * Kernel: double free in hci_conn_cleanup of the bluetooth subsystem (CVE-2023-28464)
  * kernel: Bluetooth: HCI: global o…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2024:2394</guid>
    </item>
    <item>
      <title>bdu:2024-07822</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2024-07822</link>
      <description>bdu:2024-07822</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2024-07822</guid>
    </item>
    <item>
      <title>BELL-CVE-2023-52476</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2023-52476</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2023-52476</guid>
    </item>
    <item>
      <title>certfr-2024-avi-0329 — De multiples vulnérabilités ont été découvertes dans &lt;span
class="textit"&gt;le noyau Linux de SUSE&lt;/span&gt;. Certaines d'en…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0329</link>
      <description>certfr-2024-avi-0329</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2024-avi-0329</guid>
    </item>
    <item>
      <title>EUVD-2026-311528</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-311528</link>
      <description>EUVD-2026-311528</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-311528</guid>
    </item>
    <item>
      <title>fkie_cve-2023-52476</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2023-52476</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;perf/x86/lbr: Filter vsyscall addresses&lt;/p&gt;
&lt;p&gt;We found that a panic can occur when a vsyscall is made while LBR sampling
is active. If the vsyscall is interrupted (NMI) for perf sampling, this
call sequence can occur (most recent at top):&lt;/p&gt;
&lt;p&gt;__insn_get_emulate_prefix()
    insn_get_emulate_prefix()
    insn_get_prefixes()
    insn_get_opcode()
    decode_branch_type()
    get_branch_type()
    intel_pmu_lbr_filter()
    intel_pmu_handle_irq()
    perf_event_nmi_handler()&lt;/p&gt;
&lt;p&gt;Within __insn_get_emulate_prefix() at frame 0, a macro is called:&lt;/p&gt;
&lt;p&gt;peek_nbyte_next(insn_byte_t, insn, i)&lt;/p&gt;
&lt;p&gt;Within this macro, this dereference occurs:&lt;/p&gt;
&lt;p&gt;(insn)-&amp;gt;next_byte&lt;/p&gt;
&lt;p&gt;Inspecting registers at this point, the value of the next_byte field is the
address of the vsyscall made, for example the location of the vsyscall
version of gettimeofday() at 0xffffffffff600000. The access to an address
in the vsyscall region will trigger an oops due to an unhandled page fault.&lt;/p&gt;
&lt;p&gt;To fix the bug, filtering for vsyscalls can be done when
determining the branch type. This patch will return
a &amp;#34;none&amp;#34; branch if a kernel address if found to lie in the
vsyscall region.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;perf/x86/lbr: Filter vsyscall addresses&lt;/p&gt;
&lt;p&gt;We found that a panic can occur when a vsyscall is made while LBR sampling
is active. If the vsyscall is interrupted (NMI) for perf sampling, this
call sequence can occur (most recent at top):&lt;/p&gt;
&lt;p&gt;__insn_get_emulate_prefix()
    insn_get_emulate_prefix()
    insn_get_prefixes()
    insn_get_opcode()
    decode_branch_type()
    get_branch_type()
    intel_pmu_lbr_filter()
    intel_pmu_handle_irq()
    perf_event_nmi_handler()&lt;/p&gt;
&lt;p&gt;Within __insn_get_emulate_prefix() at frame 0, a macro is called:&lt;/p&gt;
&lt;p&gt;peek_nbyte_next(insn_byte_t, insn, i)&lt;/p&gt;
&lt;p&gt;Within this macro, this dereference occurs:&lt;/p&gt;
&lt;p&gt;(insn)-&amp;gt;next_byte&lt;/p&gt;
&lt;p&gt;Inspecting registers at this point, the value of the next_byte field is the
address of the vsyscall made, for example the location of the vsyscall
version of gettimeofday() at 0xffffffffff600000. The access to an address
in the vsyscall region will trigger an oops due to an unhandled page fault.&lt;/p&gt;
&lt;p&gt;To fix the bug, filtering for vsyscalls can be done when
determining the branch type. This patch will return
a &amp;#34;none&amp;#34; branch if a kernel address if found to lie in the
vsyscall region.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2023-52476</guid>
    </item>
    <item>
      <title>GHSA-p6q6-7q65-mgx6</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-p6q6-7q65-mgx6</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;perf/x86/lbr: Filter vsyscall addresses&lt;/p&gt;
&lt;p&gt;We found that a panic can occur when a vsyscall is made while LBR sampling
is active. If the vsyscall is interrupted (NMI) for perf sampling, this
call sequence can occur (most recent at top):&lt;/p&gt;
&lt;p&gt;__insn_get_emulate_prefix()
    insn_get_emulate_prefix()
    insn_get_prefixes()
    insn_get_opcode()
    decode_branch_type()
    get_branch_type()
    intel_pmu_lbr_filter()
    intel_pmu_handle_irq()
    perf_event_nmi_handler()&lt;/p&gt;
&lt;p&gt;Within __insn_get_emulate_prefix() at frame 0, a macro is called:&lt;/p&gt;
&lt;p&gt;peek_nbyte_next(insn_byte_t, insn, i)&lt;/p&gt;
&lt;p&gt;Within this macro, this dereference occurs:&lt;/p&gt;
&lt;p&gt;(insn)-&amp;gt;next_byte&lt;/p&gt;
&lt;p&gt;Inspecting registers at this point, the value of the next_byte field is the
address of the vsyscall made, for example the location of the vsyscall
version of gettimeofday() at 0xffffffffff600000. The access to an address
in the vsyscall region will trigger an oops due to an unhandled page fault.&lt;/p&gt;
&lt;p&gt;To fix the bug, filtering for vsyscalls can be done when
determining the branch type. This patch will return
a &amp;#34;none&amp;#34; branch if a kernel address if found to lie in the
vsyscall region.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;perf/x86/lbr: Filter vsyscall addresses&lt;/p&gt;
&lt;p&gt;We found that a panic can occur when a vsyscall is made while LBR sampling
is active. If the vsyscall is interrupted (NMI) for perf sampling, this
call sequence can occur (most recent at top):&lt;/p&gt;
&lt;p&gt;__insn_get_emulate_prefix()
    insn_get_emulate_prefix()
    insn_get_prefixes()
    insn_get_opcode()
    decode_branch_type()
    get_branch_type()
    intel_pmu_lbr_filter()
    intel_pmu_handle_irq()
    perf_event_nmi_handler()&lt;/p&gt;
&lt;p&gt;Within __insn_get_emulate_prefix() at frame 0, a macro is called:&lt;/p&gt;
&lt;p&gt;peek_nbyte_next(insn_byte_t, insn, i)&lt;/p&gt;
&lt;p&gt;Within this macro, this dereference occurs:&lt;/p&gt;
&lt;p&gt;(insn)-&amp;gt;next_byte&lt;/p&gt;
&lt;p&gt;Inspecting registers at this point, the value of the next_byte field is the
address of the vsyscall made, for example the location of the vsyscall
version of gettimeofday() at 0xffffffffff600000. The access to an address
in the vsyscall region will trigger an oops due to an unhandled page fault.&lt;/p&gt;
&lt;p&gt;To fix the bug, filtering for vsyscalls can be done when
determining the branch type. This patch will return
a &amp;#34;none&amp;#34; branch if a kernel address if found to lie in the
vsyscall region.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-p6q6-7q65-mgx6</guid>
    </item>
    <item>
      <title>gsd-2023-52476</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2023-52476</link>
      <description>gsd-2023-52476</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2023-52476</guid>
    </item>
    <item>
      <title>OESA-2024-1392 — kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2024-1392</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&#13;
&#13;
In the Linux kernel, the following vulnerability has been resolved:&#13;
&#13;
media: dvbdev: Fix memory leak in dvb_media_device_free()&#13;
&#13;
dvb_media_device_free() is leaking memory. Free `dvbdev-&amp;amp;gt;adapter-&amp;amp;gt;conn`
before setting it to NULL, as documented in include/media/media-device.h:
&amp;amp;quot;The media_entity instance itself must be freed explicitly by the driver
if required.&amp;amp;quot;(CVE-2020-36777)&#13;
&#13;
In the Linux kernel, the following vulnerability has been resolved:&#13;
&#13;
i2c: sprd: fix reference leak when pm_runtime_get_sync fails&#13;
&#13;
The PM reference count is not expected to be incremented on
return in sprd_i2c_master_xfer() and sprd_i2c_remove().&#13;
&#13;
However, pm_runtime_get_sync will increment the PM reference
count even failed. Forgetting to putting operation will result
in a reference leak here.&#13;
&#13;
Replace it with pm_runtime_resume_and_get to keep usage
counter balanced.(CVE-2020-36780)&#13;
&#13;
In the Linux kernel, the following vulnerability has been resolved:&#13;
&#13;
i2c: cadence: fix reference leak when pm_runtime_get_sync fails&#13;
&#13;
The PM reference count is not expected to be incremented on
return in functions cdns_i2c_master_xfer and cdns_reg_slave.&#13;
&#13;
However, pm_runtime_get_sync will increment pm usage counter
even failed. Forgetting to putting operation will result in a
reference leak here.&#13;
&#13;
Replace it with pm_runtime_resume_and_get to keep usage
counter balanced.(CVE-2020-36784)&#13;
&#13;
In the Linux kernel,…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&#13;
&#13;
In the Linux kernel, the following vulnerability has been resolved:&#13;
&#13;
media: dvbdev: Fix memory leak in dvb_media_device_free()&#13;
&#13;
dvb_media_device_free() is leaking memory. Free `dvbdev-&amp;amp;gt;adapter-&amp;amp;gt;conn`
before setting it to NULL, as documented in include/media/media-device.h:
&amp;amp;quot;The media_entity instance itself must be freed explicitly by the driver
if required.&amp;amp;quot;(CVE-2020-36777)&#13;
&#13;
In the Linux kernel, the following vulnerability has been resolved:&#13;
&#13;
i2c: sprd: fix reference leak when pm_runtime_get_sync fails&#13;
&#13;
The PM reference count is not expected to be incremented on
return in sprd_i2c_master_xfer() and sprd_i2c_remove().&#13;
&#13;
However, pm_runtime_get_sync will increment the PM reference
count even failed. Forgetting to putting operation will result
in a reference leak here.&#13;
&#13;
Replace it with pm_runtime_resume_and_get to keep usage
counter balanced.(CVE-2020-36780)&#13;
&#13;
In the Linux kernel, the following vulnerability has been resolved:&#13;
&#13;
i2c: cadence: fix reference leak when pm_runtime_get_sync fails&#13;
&#13;
The PM reference count is not expected to be incremented on
return in functions cdns_i2c_master_xfer and cdns_reg_slave.&#13;
&#13;
However, pm_runtime_get_sync will increment pm usage counter
even failed. Forgetting to putting operation will result in a
reference leak here.&#13;
&#13;
Replace it with pm_runtime_resume_and_get to keep usage
counter balanced.(CVE-2020-36784)&#13;
&#13;
In the Linux kernel,…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2024-1392</guid>
    </item>
    <item>
      <title>RHSA-2024:2394 — Red Hat Security Advisory: kernel security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2024:2394</link>
      <description>&lt;p&gt;kernel: Bluetooth BR/EDR PIN Pairing procedure is vulnerable to an impersonation attack kernel: ovl: fix warning in ovl_create_real() kernel: memcg does not limit the number of POSIX file locks allowing memory exhaustion kernel: vmwgfx: NULL pointer dereference in vmw_cmd_dx_define_query kernel: integer overflow in l2cap_config_req() in net/bluetooth/l2cap_core.c kernel: i2c: mlxbf: prevent stack overflow in mlxbf_i2c_smbus_start_transaction() kernel: Bluetooth: L2CAP: Fix u8 overflow kernel: hwmon: (coretemp) fix pci device refcount leak in nv1a_ram_new() kernel: tracing: Fix sleeping function called from invalid context on RT kernel kernel: net: mdio: unexport __init-annotated mdio_bus_init() kernel: arm64: ftrace: consistently handle PLTs. kernel: mm/uffd: fix pte marker when fork() without fork event kernel: Bluetooth: Fix a buffer overflow in mgmt_mesh_add() kernel: tty: n_gsm: add sanity check for gsm-&amp;gt;receive in gsm_receive_buf() kernel: ftrace: Fix NULL pointer dereference in is_ftrace_trampoline when ftrace is dead kernel: tee: add overflow check in register_shm_helper() kernel: tty: n_gsm: fix deadlock and link starvation in outgoing data path kernel: PM: hibernate: defer device probing when resuming from hibernation kernel: ext4: don&amp;#39;t allow journal inode to have encrypt flag kernel: ext4: fix delayed allocation bug in ext4_clu_mapped for bigalloc + inline kernel: erofs: fix order &amp;gt;= MAX_ORDER warning due to crafted negative i_size kernel: perf/x86/intel/uncore: F…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;kernel: Bluetooth BR/EDR PIN Pairing procedure is vulnerable to an impersonation attack kernel: ovl: fix warning in ovl_create_real() kernel: memcg does not limit the number of POSIX file locks allowing memory exhaustion kernel: vmwgfx: NULL pointer dereference in vmw_cmd_dx_define_query kernel: integer overflow in l2cap_config_req() in net/bluetooth/l2cap_core.c kernel: i2c: mlxbf: prevent stack overflow in mlxbf_i2c_smbus_start_transaction() kernel: Bluetooth: L2CAP: Fix u8 overflow kernel: hwmon: (coretemp) fix pci device refcount leak in nv1a_ram_new() kernel: tracing: Fix sleeping function called from invalid context on RT kernel kernel: net: mdio: unexport __init-annotated mdio_bus_init() kernel: arm64: ftrace: consistently handle PLTs. kernel: mm/uffd: fix pte marker when fork() without fork event kernel: Bluetooth: Fix a buffer overflow in mgmt_mesh_add() kernel: tty: n_gsm: add sanity check for gsm-&amp;gt;receive in gsm_receive_buf() kernel: ftrace: Fix NULL pointer dereference in is_ftrace_trampoline when ftrace is dead kernel: tee: add overflow check in register_shm_helper() kernel: tty: n_gsm: fix deadlock and link starvation in outgoing data path kernel: PM: hibernate: defer device probing when resuming from hibernation kernel: ext4: don&amp;#39;t allow journal inode to have encrypt flag kernel: ext4: fix delayed allocation bug in ext4_clu_mapped for bigalloc + inline kernel: erofs: fix order &amp;gt;= MAX_ORDER warning due to crafted negative i_size kernel: perf/x86/intel/uncore: F…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2024:2394</guid>
    </item>
    <item>
      <title>RHSA-2024:7001 — Red Hat Security Advisory: kernel-rt security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2024:7001</link>
      <description>&lt;p&gt;kernel: kyber: fix out of bounds access when preempted kernel: Input: elantech - fix stack out of bound access in elantech_change_report_id() kernel: asix: fix uninit-value in asix_mdio_read() kernel: driver core: auxiliary bus: Fix memory leak when driver_register() fail kernel: ACPI: fix NULL pointer dereference kernel: watchdog: Fix possible use-after-free by calling del_timer_sync() kernel: fbmem: Do not delete the mode that is still in use kernel: virtio-net: Add validation for used length kernel: tty: Fix out-of-bound vmalloc access in imageblit kernel: hwmon: (w83793) Fix NULL pointer dereference by removing unnecessary structure field kernel: hwmon: (w83792d) Fix NULL pointer dereference by removing unnecessary structure field kernel: hwmon: (w83791d) Fix NULL pointer dereference by removing unnecessary structure field kernel: hwmon: (mlxreg-fan) Return non-zero value when fan current state is enforced from sysfs kernel: block: don&amp;#39;t call rq_qos_ops-&amp;gt;done_bio if the bio isn&amp;#39;t tracked kernel: lib/generic-radix-tree.c: Don&amp;#39;t overflow in peek() kernel: mlxsw: thermal: Fix out-of-bounds memory accesses kernel: ptp: Fix possible memory leak in ptp_clock_register() kernel: mm, slub: fix potential memoryleak in kmem_cache_open() kernel: nvmem: Fix shift-out-of-bound (UBSAN) with byte size cells kernel: serial: core: fix transmit-buffer reset and memleak kernel: mlxsw: spectrum: Protect driver from buggy firmware kernel: USB: core: Make do_proc_control() and do_proc_bulk() k…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;kernel: kyber: fix out of bounds access when preempted kernel: Input: elantech - fix stack out of bound access in elantech_change_report_id() kernel: asix: fix uninit-value in asix_mdio_read() kernel: driver core: auxiliary bus: Fix memory leak when driver_register() fail kernel: ACPI: fix NULL pointer dereference kernel: watchdog: Fix possible use-after-free by calling del_timer_sync() kernel: fbmem: Do not delete the mode that is still in use kernel: virtio-net: Add validation for used length kernel: tty: Fix out-of-bound vmalloc access in imageblit kernel: hwmon: (w83793) Fix NULL pointer dereference by removing unnecessary structure field kernel: hwmon: (w83792d) Fix NULL pointer dereference by removing unnecessary structure field kernel: hwmon: (w83791d) Fix NULL pointer dereference by removing unnecessary structure field kernel: hwmon: (mlxreg-fan) Return non-zero value when fan current state is enforced from sysfs kernel: block: don&amp;#39;t call rq_qos_ops-&amp;gt;done_bio if the bio isn&amp;#39;t tracked kernel: lib/generic-radix-tree.c: Don&amp;#39;t overflow in peek() kernel: mlxsw: thermal: Fix out-of-bounds memory accesses kernel: ptp: Fix possible memory leak in ptp_clock_register() kernel: mm, slub: fix potential memoryleak in kmem_cache_open() kernel: nvmem: Fix shift-out-of-bound (UBSAN) with byte size cells kernel: serial: core: fix transmit-buffer reset and memleak kernel: mlxsw: spectrum: Protect driver from buggy firmware kernel: USB: core: Make do_proc_control() and do_proc_bulk() k…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2024:7001</guid>
    </item>
    <item>
      <title>SUSE-SU-2024:1454-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2024:1454-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2024:1454-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2023-52476</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-52476</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux, Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe and 157 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: perf/x86/lbr: Filter vsyscall addresses We found that a panic can occur when a vsyscall is made while LBR sampling is active. If the vsyscall is interrupted (NMI) for perf sampling, this call sequence can occur (most recent at top):     __insn_get_emulate_prefix()     insn_get_emulate_prefix()     insn_get_prefixes()     insn_get_opcode()     decode_branch_type()     get_branch_type()     intel_pmu_lbr_filter()     intel_pmu_handle_irq()     perf_event_nmi_handler() Within __insn_get_emulate_prefix() at frame 0, a macro is called:     peek_nbyte_next(insn_byte_t, insn, i) Within this macro, this dereference occurs:     (insn)-&amp;gt;next_byte Inspecting registers at this point, the value of the next_byte field is the address of the vsyscall made, for example the location of the vsyscall version of gettimeofday() at 0xffffffffff600000. The access to an address in the vsyscall region will trigger an oops due to an unhandled page fault. To fix the bug, filtering for vsyscalls can be done when determining the branch type. This patch will return a &amp;#34;none&amp;#34; branch if a kernel address if found to lie in the vsyscall region.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux, Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe and 157 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: perf/x86/lbr: Filter vsyscall addresses We found that a panic can occur when a vsyscall is made while LBR sampling is active. If the vsyscall is interrupted (NMI) for perf sampling, this call sequence can occur (most recent at top):     __insn_get_emulate_prefix()     insn_get_emulate_prefix()     insn_get_prefixes()     insn_get_opcode()     decode_branch_type()     get_branch_type()     intel_pmu_lbr_filter()     intel_pmu_handle_irq()     perf_event_nmi_handler() Within __insn_get_emulate_prefix() at frame 0, a macro is called:     peek_nbyte_next(insn_byte_t, insn, i) Within this macro, this dereference occurs:     (insn)-&amp;gt;next_byte Inspecting registers at this point, the value of the next_byte field is the address of the vsyscall made, for example the location of the vsyscall version of gettimeofday() at 0xffffffffff600000. The access to an address in the vsyscall region will trigger an oops due to an unhandled page fault. To fix the bug, filtering for vsyscalls can be done when determining the branch type. This patch will return a &amp;#34;none&amp;#34; branch if a kernel address if found to lie in the vsyscall region.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-52476</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-0511 — Linux Kernel: Mehrere Schwachstellen ermöglichen Denial of Service und unspezifische Angriffe</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0511</link>
      <description>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen im Linux-Kernel ausnutzen, um einen Denial-of-Service-Zustand herbeizuführen oder einen nicht spezifizierten Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen im Linux-Kernel ausnutzen, um einen Denial-of-Service-Zustand herbeizuführen oder einen nicht spezifizierten Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0511</guid>
    </item>
  </channel>
</rss>
