<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 13:21:30 +0000</lastBuildDate>
    <item>
      <title>bdu:2025-04678</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-04678</link>
      <description>bdu:2025-04678</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-04678</guid>
    </item>
    <item>
      <title>BELL-CVE-2023-52757</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2023-52757</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2023-52757</guid>
    </item>
    <item>
      <title>certfr-2024-avi-0496 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de SUSE. Certaines d'entre elles permettent à un at…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0496</link>
      <description>certfr-2024-avi-0496</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2024-avi-0496</guid>
    </item>
    <item>
      <title>EUVD-2026-320422</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-320422</link>
      <description>EUVD-2026-320422</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-320422</guid>
    </item>
    <item>
      <title>fkie_cve-2023-52757</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2023-52757</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;smb: client: fix potential deadlock when releasing mids&lt;/p&gt;
&lt;p&gt;All release_mid() callers seem to hold a reference of @mid so there is
no need to call kref_put(&amp;amp;mid-&amp;gt;refcount, __release_mid) under
@server-&amp;gt;mid_lock spinlock.  If they don&amp;#39;t, then an use-after-free bug
would have occurred anyways.&lt;/p&gt;
&lt;p&gt;By getting rid of such spinlock also fixes a potential deadlock as
shown below&lt;/p&gt;
&lt;p&gt;CPU 0                                CPU 1
------------------------------------------------------------------
cifs_demultiplex_thread()            cifs_debug_data_proc_show()
 release_mid()
  spin_lock(&amp;amp;server-&amp;gt;mid_lock);
                                     spin_lock(&amp;amp;cifs_tcp_ses_lock)
				      spin_lock(&amp;amp;server-&amp;gt;mid_lock)
  __release_mid()
   smb2_find_smb_tcon()
    spin_lock(&amp;amp;cifs_tcp_ses_lock) *deadlock*&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;smb: client: fix potential deadlock when releasing mids&lt;/p&gt;
&lt;p&gt;All release_mid() callers seem to hold a reference of @mid so there is
no need to call kref_put(&amp;amp;mid-&amp;gt;refcount, __release_mid) under
@server-&amp;gt;mid_lock spinlock.  If they don&amp;#39;t, then an use-after-free bug
would have occurred anyways.&lt;/p&gt;
&lt;p&gt;By getting rid of such spinlock also fixes a potential deadlock as
shown below&lt;/p&gt;
&lt;p&gt;CPU 0                                CPU 1
------------------------------------------------------------------
cifs_demultiplex_thread()            cifs_debug_data_proc_show()
 release_mid()
  spin_lock(&amp;amp;server-&amp;gt;mid_lock);
                                     spin_lock(&amp;amp;cifs_tcp_ses_lock)
				      spin_lock(&amp;amp;server-&amp;gt;mid_lock)
  __release_mid()
   smb2_find_smb_tcon()
    spin_lock(&amp;amp;cifs_tcp_ses_lock) *deadlock*&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2023-52757</guid>
    </item>
    <item>
      <title>GHSA-jp9q-c7f4-2fxf</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-jp9q-c7f4-2fxf</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;smb: client: fix potential deadlock when releasing mids&lt;/p&gt;
&lt;p&gt;All release_mid() callers seem to hold a reference of @mid so there is
no need to call kref_put(&amp;amp;mid-&amp;gt;refcount, __release_mid) under
@server-&amp;gt;mid_lock spinlock.  If they don&amp;#39;t, then an use-after-free bug
would have occurred anyways.&lt;/p&gt;
&lt;p&gt;By getting rid of such spinlock also fixes a potential deadlock as
shown below&lt;/p&gt;
&lt;p&gt;CPU 0                                CPU 1
------------------------------------------------------------------
cifs_demultiplex_thread()            cifs_debug_data_proc_show()
 release_mid()
  spin_lock(&amp;amp;server-&amp;gt;mid_lock);
                                     spin_lock(&amp;amp;cifs_tcp_ses_lock)
				      spin_lock(&amp;amp;server-&amp;gt;mid_lock)
  __release_mid()
   smb2_find_smb_tcon()
    spin_lock(&amp;amp;cifs_tcp_ses_lock) *deadlock*&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;smb: client: fix potential deadlock when releasing mids&lt;/p&gt;
&lt;p&gt;All release_mid() callers seem to hold a reference of @mid so there is
no need to call kref_put(&amp;amp;mid-&amp;gt;refcount, __release_mid) under
@server-&amp;gt;mid_lock spinlock.  If they don&amp;#39;t, then an use-after-free bug
would have occurred anyways.&lt;/p&gt;
&lt;p&gt;By getting rid of such spinlock also fixes a potential deadlock as
shown below&lt;/p&gt;
&lt;p&gt;CPU 0                                CPU 1
------------------------------------------------------------------
cifs_demultiplex_thread()            cifs_debug_data_proc_show()
 release_mid()
  spin_lock(&amp;amp;server-&amp;gt;mid_lock);
                                     spin_lock(&amp;amp;cifs_tcp_ses_lock)
				      spin_lock(&amp;amp;server-&amp;gt;mid_lock)
  __release_mid()
   smb2_find_smb_tcon()
    spin_lock(&amp;amp;cifs_tcp_ses_lock) *deadlock*&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-jp9q-c7f4-2fxf</guid>
    </item>
    <item>
      <title>msrc_CVE-2023-52757 — smb: client: fix potential deadlock when releasing mids</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2023-52757</link>
      <description>msrc_CVE-2023-52757</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2023-52757</guid>
    </item>
    <item>
      <title>OESA-2024-1894 — kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2024-1894</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP3: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&#13;
&#13;
In the Linux kernel, the following vulnerability has been resolved:&#13;
&#13;
lib/generic-radix-tree.c: Don&amp;amp;apos;t overflow in peek()&#13;
&#13;
When we started spreading new inode numbers throughout most of the 64
bit inode space, that triggered some corner case bugs, in particular
some integer overflows related to the radix tree code. Oops.(CVE-2021-47432)&#13;
&#13;
In the Linux kernel, the following vulnerability has been resolved:&#13;
&#13;
scsi: ufs: Fix a deadlock in the error handler&#13;
&#13;
The following deadlock has been observed on a test setup:&#13;
&#13;
 - All tags allocated&#13;
&#13;
 - The SCSI error handler calls ufshcd_eh_host_reset_handler()&#13;
&#13;
 - ufshcd_eh_host_reset_handler() queues work that calls
   ufshcd_err_handler()&#13;
&#13;
 - ufshcd_err_handler() locks up as follows:&#13;
&#13;
Workqueue: ufs_eh_wq_0 ufshcd_err_handler.cfi_jt
Call trace:
 __switch_to+0x298/0x5d8
 __schedule+0x6cc/0xa94
 schedule+0x12c/0x298
 blk_mq_get_tag+0x210/0x480
 __blk_mq_alloc_request+0x1c8/0x284
 blk_get_request+0x74/0x134
 ufshcd_exec_dev_cmd+0x68/0x640
 ufshcd_verify_dev_init+0x68/0x35c
 ufshcd_probe_hba+0x12c/0x1cb8
 ufshcd_host_reset_and_restore+0x88/0x254
 ufshcd_reset_and_restore+0xd0/0x354
 ufshcd_err_handler+0x408/0xc58
 process_one_work+0x24c/0x66c
 worker_thread+0x3e8/0xa4c
 kthread+0x150/0x1b4
 ret_from_fork+0x10/0x30&#13;
&#13;
Fix this lockup by making ufshcd_exec_dev_cmd() allocate a reserved
request.(CVE-2021-47622)&#13;
&#13;
In the Linux kernel, the following…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP3: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&#13;
&#13;
In the Linux kernel, the following vulnerability has been resolved:&#13;
&#13;
lib/generic-radix-tree.c: Don&amp;amp;apos;t overflow in peek()&#13;
&#13;
When we started spreading new inode numbers throughout most of the 64
bit inode space, that triggered some corner case bugs, in particular
some integer overflows related to the radix tree code. Oops.(CVE-2021-47432)&#13;
&#13;
In the Linux kernel, the following vulnerability has been resolved:&#13;
&#13;
scsi: ufs: Fix a deadlock in the error handler&#13;
&#13;
The following deadlock has been observed on a test setup:&#13;
&#13;
 - All tags allocated&#13;
&#13;
 - The SCSI error handler calls ufshcd_eh_host_reset_handler()&#13;
&#13;
 - ufshcd_eh_host_reset_handler() queues work that calls
   ufshcd_err_handler()&#13;
&#13;
 - ufshcd_err_handler() locks up as follows:&#13;
&#13;
Workqueue: ufs_eh_wq_0 ufshcd_err_handler.cfi_jt
Call trace:
 __switch_to+0x298/0x5d8
 __schedule+0x6cc/0xa94
 schedule+0x12c/0x298
 blk_mq_get_tag+0x210/0x480
 __blk_mq_alloc_request+0x1c8/0x284
 blk_get_request+0x74/0x134
 ufshcd_exec_dev_cmd+0x68/0x640
 ufshcd_verify_dev_init+0x68/0x35c
 ufshcd_probe_hba+0x12c/0x1cb8
 ufshcd_host_reset_and_restore+0x88/0x254
 ufshcd_reset_and_restore+0xd0/0x354
 ufshcd_err_handler+0x408/0xc58
 process_one_work+0x24c/0x66c
 worker_thread+0x3e8/0xa4c
 kthread+0x150/0x1b4
 ret_from_fork+0x10/0x30&#13;
&#13;
Fix this lockup by making ufshcd_exec_dev_cmd() allocate a reserved
request.(CVE-2021-47622)&#13;
&#13;
In the Linux kernel, the following…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2024-1894</guid>
    </item>
    <item>
      <title>RHSA-2024:9315 — Red Hat Security Advisory: kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2024:9315</link>
      <description>&lt;p&gt;kernel: use after free in i2c kernel: bluetooth: BR/EDR Bluetooth Impersonation Attacks (BIAS) kernel: hwmon: (lm90) Prevent integer overflow/underflow in hysteresis calculations kernel: asix: fix uninit-value in asix_mdio_read() kernel: tty: tty_buffer: Fix the softlockup issue in flush_to_ldisc kernel: hwmon: (w83793) Fix NULL pointer dereference by removing unnecessary structure field kernel: hwmon: (w83791d) Fix NULL pointer dereference by removing unnecessary structure field kernel: powerpc/64s: fix program check interrupt emergency stack path kernel: powerpc/64s: Fix unrecoverable MCE calling async handler from NMI kernel: lib/generic-radix-tree.c: Don&amp;#39;t overflow in peek() kernel: powerpc/smp: do not decrement idle task preempt count in CPU offline kernel: can: isotp: isotp_sendmsg(): add result check for wait_event_interruptible() kernel: usbnet: sanity check for maxpacket kernel: nvmem: Fix shift-out-of-bound (UBSAN) with byte size cells kernel: aio: fix use-after-free due to missing POLLFREE handling kernel: powerpc/pseries: Fix potential memleak in papr_get_attr() kernel: of: fdt: fix off-by-one error in unflatten_dt_nodes() kernel: thermal/int340x_thermal: handle data_vault when the value is ZERO_SIZE_PTR kernel: vt_ioctl: fix array_index_nospec in vt_setactivate kernel: bpf: Fix crash due to out of bounds access into reg2btf_ids. kernel: lz4: fix LZ4_decompress_safe_partial read out of bound kernel: x86/mce: Work around an erratum on fast string copy instructions…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;kernel: use after free in i2c kernel: bluetooth: BR/EDR Bluetooth Impersonation Attacks (BIAS) kernel: hwmon: (lm90) Prevent integer overflow/underflow in hysteresis calculations kernel: asix: fix uninit-value in asix_mdio_read() kernel: tty: tty_buffer: Fix the softlockup issue in flush_to_ldisc kernel: hwmon: (w83793) Fix NULL pointer dereference by removing unnecessary structure field kernel: hwmon: (w83791d) Fix NULL pointer dereference by removing unnecessary structure field kernel: powerpc/64s: fix program check interrupt emergency stack path kernel: powerpc/64s: Fix unrecoverable MCE calling async handler from NMI kernel: lib/generic-radix-tree.c: Don&amp;#39;t overflow in peek() kernel: powerpc/smp: do not decrement idle task preempt count in CPU offline kernel: can: isotp: isotp_sendmsg(): add result check for wait_event_interruptible() kernel: usbnet: sanity check for maxpacket kernel: nvmem: Fix shift-out-of-bound (UBSAN) with byte size cells kernel: aio: fix use-after-free due to missing POLLFREE handling kernel: powerpc/pseries: Fix potential memleak in papr_get_attr() kernel: of: fdt: fix off-by-one error in unflatten_dt_nodes() kernel: thermal/int340x_thermal: handle data_vault when the value is ZERO_SIZE_PTR kernel: vt_ioctl: fix array_index_nospec in vt_setactivate kernel: bpf: Fix crash due to out of bounds access into reg2btf_ids. kernel: lz4: fix LZ4_decompress_safe_partial read out of bound kernel: x86/mce: Work around an erratum on fast string copy instructions…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2024:9315</guid>
    </item>
    <item>
      <title>SUSE-SU-2024:2008-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2024:2008-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2024:2008-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2023-52757</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-52757</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe, Ubuntu:Pro:16.04:LTS: linux-oracle, Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:Pro:18.04:LTS: linux, Ubuntu:Pro:18.04:LTS: linux-aws, Ubuntu:18.04:LTS: linux-aws-5.0 and 153 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: smb: client: fix potential deadlock when releasing mids All release_mid() callers seem to hold a reference of @mid so there is no need to call kref_put(&amp;amp;mid-&amp;gt;refcount, __release_mid) under @server-&amp;gt;mid_lock spinlock.  If they don&amp;#39;t, then an use-after-free bug would have occurred anyways. By getting rid of such spinlock also fixes a potential deadlock as shown below CPU 0                                CPU 1 ------------------------------------------------------------------ cifs_demultiplex_thread()            cifs_debug_data_proc_show()  release_mid()   spin_lock(&amp;amp;server-&amp;gt;mid_lock);                                      spin_lock(&amp;amp;cifs_tcp_ses_lock) 				      spin_lock(&amp;amp;server-&amp;gt;mid_lock)   __release_mid()    smb2_find_smb_tcon()     spin_lock(&amp;amp;cifs_tcp_ses_lock) *deadlock*&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe, Ubuntu:Pro:16.04:LTS: linux-oracle, Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:Pro:18.04:LTS: linux, Ubuntu:Pro:18.04:LTS: linux-aws, Ubuntu:18.04:LTS: linux-aws-5.0 and 153 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: smb: client: fix potential deadlock when releasing mids All release_mid() callers seem to hold a reference of @mid so there is no need to call kref_put(&amp;amp;mid-&amp;gt;refcount, __release_mid) under @server-&amp;gt;mid_lock spinlock.  If they don&amp;#39;t, then an use-after-free bug would have occurred anyways. By getting rid of such spinlock also fixes a potential deadlock as shown below CPU 0                                CPU 1 ------------------------------------------------------------------ cifs_demultiplex_thread()            cifs_debug_data_proc_show()  release_mid()   spin_lock(&amp;amp;server-&amp;gt;mid_lock);                                      spin_lock(&amp;amp;cifs_tcp_ses_lock) 				      spin_lock(&amp;amp;server-&amp;gt;mid_lock)   __release_mid()    smb2_find_smb_tcon()     spin_lock(&amp;amp;cifs_tcp_ses_lock) *deadlock*&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-52757</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-1197 — Linux Kernel: Mehrere Schwachstellen ermöglichen Denial of Service und unspezifische Angriffe</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1197</link>
      <description>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen im Linux-Kernel ausnutzen, um einen Denial-of-Service-Zustand zu erzeugen oder unspezifische Angriffe durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen im Linux-Kernel ausnutzen, um einen Denial-of-Service-Zustand zu erzeugen oder unspezifische Angriffe durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1197</guid>
    </item>
  </channel>
</rss>
