<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 18:07:45 +0000</lastBuildDate>
    <item>
      <title>bdu:2024-08403</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2024-08403</link>
      <description>bdu:2024-08403</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2024-08403</guid>
    </item>
    <item>
      <title>BELL-CVE-2023-52493</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2023-52493</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2023-52493</guid>
    </item>
    <item>
      <title>certfr-2024-avi-0329 — De multiples vulnérabilités ont été découvertes dans &lt;span
class="textit"&gt;le noyau Linux de SUSE&lt;/span&gt;. Certaines d'en…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0329</link>
      <description>certfr-2024-avi-0329</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2024-avi-0329</guid>
    </item>
    <item>
      <title>EUVD-2026-311537</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-311537</link>
      <description>EUVD-2026-311537</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-311537</guid>
    </item>
    <item>
      <title>fkie_cve-2023-52493</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2023-52493</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;bus: mhi: host: Drop chan lock before queuing buffers&lt;/p&gt;
&lt;p&gt;Ensure read and write locks for the channel are not taken in succession by
dropping the read lock from parse_xfer_event() such that a callback given
to client can potentially queue buffers and acquire the write lock in that
process. Any queueing of buffers should be done without channel read lock
acquired as it can result in multiple locks and a soft lockup.&lt;/p&gt;
&lt;p&gt;[mani: added fixes tag and cc&amp;#39;ed stable]&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;bus: mhi: host: Drop chan lock before queuing buffers&lt;/p&gt;
&lt;p&gt;Ensure read and write locks for the channel are not taken in succession by
dropping the read lock from parse_xfer_event() such that a callback given
to client can potentially queue buffers and acquire the write lock in that
process. Any queueing of buffers should be done without channel read lock
acquired as it can result in multiple locks and a soft lockup.&lt;/p&gt;
&lt;p&gt;[mani: added fixes tag and cc&amp;#39;ed stable]&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2023-52493</guid>
    </item>
    <item>
      <title>GHSA-7vjh-prmq-cfm3</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-7vjh-prmq-cfm3</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;bus: mhi: host: Drop chan lock before queuing buffers&lt;/p&gt;
&lt;p&gt;Ensure read and write locks for the channel are not taken in succession by
dropping the read lock from parse_xfer_event() such that a callback given
to client can potentially queue buffers and acquire the write lock in that
process. Any queueing of buffers should be done without channel read lock
acquired as it can result in multiple locks and a soft lockup.&lt;/p&gt;
&lt;p&gt;[mani: added fixes tag and cc&amp;#39;ed stable]&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;bus: mhi: host: Drop chan lock before queuing buffers&lt;/p&gt;
&lt;p&gt;Ensure read and write locks for the channel are not taken in succession by
dropping the read lock from parse_xfer_event() such that a callback given
to client can potentially queue buffers and acquire the write lock in that
process. Any queueing of buffers should be done without channel read lock
acquired as it can result in multiple locks and a soft lockup.&lt;/p&gt;
&lt;p&gt;[mani: added fixes tag and cc&amp;#39;ed stable]&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-7vjh-prmq-cfm3</guid>
    </item>
    <item>
      <title>gsd-2023-52493</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2023-52493</link>
      <description>gsd-2023-52493</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2023-52493</guid>
    </item>
    <item>
      <title>OESA-2024-1498 — kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2024-1498</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&#13;
&#13;
In the Linux kernel, the following vulnerability has been resolved:&#13;
&#13;
crypto: qcom-rng - ensure buffer for generate is completely filled&#13;
&#13;
The generate function in struct rng_alg expects that the destination
buffer is completely filled if the function returns 0. qcom_rng_read()
can run into a situation where the buffer is partially filled with
randomness and the remaining part of the buffer is zeroed since
qcom_rng_generate() doesn&amp;amp;apos;t check the return value. This issue can
be reproduced by running the following from libkcapi:&#13;
&#13;
    kcapi-rng -b 9000000 &amp;amp;gt; OUTFILE&#13;
&#13;
The generated OUTFILE will have three huge sections that contain all
zeros, and this is caused by the code where the test
&amp;amp;apos;val &amp;amp;amp; PRNG_STATUS_DATA_AVAIL&amp;amp;apos; fails.&#13;
&#13;
Let&amp;amp;apos;s fix this issue by ensuring that qcom_rng_read() always returns
with a full buffer if the function returns success. Let&amp;amp;apos;s also have
qcom_rng_generate() return the correct value.&#13;
&#13;
Here&amp;amp;apos;s some statistics from the ent project
(https://www.fourmilab.ch/random/) that shows information about the
quality of the generated numbers:&#13;
&#13;
    $ ent -c qcom-random-before
    Value Char Occurrences Fraction
      0           606748   0.067416
      1            33104   0.003678
      2            33001   0.003667
    ...
    253   �        32883   0.003654
    254   �        33035   0.003671
    255   �        33239   0.003693&#13;
&#13;
    Total:       90…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&#13;
&#13;
In the Linux kernel, the following vulnerability has been resolved:&#13;
&#13;
crypto: qcom-rng - ensure buffer for generate is completely filled&#13;
&#13;
The generate function in struct rng_alg expects that the destination
buffer is completely filled if the function returns 0. qcom_rng_read()
can run into a situation where the buffer is partially filled with
randomness and the remaining part of the buffer is zeroed since
qcom_rng_generate() doesn&amp;amp;apos;t check the return value. This issue can
be reproduced by running the following from libkcapi:&#13;
&#13;
    kcapi-rng -b 9000000 &amp;amp;gt; OUTFILE&#13;
&#13;
The generated OUTFILE will have three huge sections that contain all
zeros, and this is caused by the code where the test
&amp;amp;apos;val &amp;amp;amp; PRNG_STATUS_DATA_AVAIL&amp;amp;apos; fails.&#13;
&#13;
Let&amp;amp;apos;s fix this issue by ensuring that qcom_rng_read() always returns
with a full buffer if the function returns success. Let&amp;amp;apos;s also have
qcom_rng_generate() return the correct value.&#13;
&#13;
Here&amp;amp;apos;s some statistics from the ent project
(https://www.fourmilab.ch/random/) that shows information about the
quality of the generated numbers:&#13;
&#13;
    $ ent -c qcom-random-before
    Value Char Occurrences Fraction
      0           606748   0.067416
      1            33104   0.003678
      2            33001   0.003667
    ...
    253   �        32883   0.003654
    254   �        33035   0.003671
    255   �        33239   0.003693&#13;
&#13;
    Total:       90…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2024-1498</guid>
    </item>
    <item>
      <title>SUSE-SU-2024:1466-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2024:1466-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2024:1466-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2023-52493</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-52493</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 104 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: bus: mhi: host: Drop chan lock before queuing buffers Ensure read and write locks for the channel are not taken in succession by dropping the read lock from parse_xfer_event() such that a callback given to client can potentially queue buffers and acquire the write lock in that process. Any queueing of buffers should be done without channel read lock acquired as it can result in multiple locks and a soft lockup. [mani: added fixes tag and cc&amp;#39;ed stable]&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 104 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: bus: mhi: host: Drop chan lock before queuing buffers Ensure read and write locks for the channel are not taken in succession by dropping the read lock from parse_xfer_event() such that a callback given to client can potentially queue buffers and acquire the write lock in that process. Any queueing of buffers should be done without channel read lock acquired as it can result in multiple locks and a soft lockup. [mani: added fixes tag and cc&amp;#39;ed stable]&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-52493</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-0527 — Linux Kernel: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0527</link>
      <description>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen Denial of Service Zustand zu verursachen und einen nicht näher spezifizierten Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen Denial of Service Zustand zu verursachen und einen nicht näher spezifizierten Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0527</guid>
    </item>
  </channel>
</rss>
