<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 11:22:40 +0000</lastBuildDate>
    <item>
      <title>ALSA-2025:22387 — Moderate: kernel-rt security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2025:22387</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: kernel-rt, AlmaLinux:8: kernel-rt-core, AlmaLinux:8: kernel-rt-debug, AlmaLinux:8: kernel-rt-debug-core, AlmaLinux:8: kernel-rt-debug-devel, AlmaLinux:8: kernel-rt-debug-modules, AlmaLinux:8: kernel-rt-debug-modules-extra, AlmaLinux:8: kernel-rt-devel, AlmaLinux:8: kernel-rt-modules, AlmaLinux:8: kernel-rt-modules-extra&lt;/p&gt;
&lt;p&gt;The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: nfsd: handle get_client_locked() failure in nfsd4_setclientid_confirm() (CVE-2025-38724)
  * kernel: smb: client: fix race with concurrent opens in rename(2) (CVE-2025-39825)
  * kernel: mm/memory-failure: fix VM_BUG_ON_PAGE(PagePoisoned(page)) when unpoison memory (CVE-2025-39883)
  * kernel: e1000e: fix heap overflow in e1000_set_eeprom (CVE-2025-39898)
  * kernel: nbd: fix incomplete validation of ioctl arg (CVE-2023-53513)
  * kernel: tcp: Clear tcp_sk(sk)-&amp;gt;fastopen_rsk in tcp_disconnect() (CVE-2025-39955)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: kernel-rt, AlmaLinux:8: kernel-rt-core, AlmaLinux:8: kernel-rt-debug, AlmaLinux:8: kernel-rt-debug-core, AlmaLinux:8: kernel-rt-debug-devel, AlmaLinux:8: kernel-rt-debug-modules, AlmaLinux:8: kernel-rt-debug-modules-extra, AlmaLinux:8: kernel-rt-devel, AlmaLinux:8: kernel-rt-modules, AlmaLinux:8: kernel-rt-modules-extra&lt;/p&gt;
&lt;p&gt;The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: nfsd: handle get_client_locked() failure in nfsd4_setclientid_confirm() (CVE-2025-38724)
  * kernel: smb: client: fix race with concurrent opens in rename(2) (CVE-2025-39825)
  * kernel: mm/memory-failure: fix VM_BUG_ON_PAGE(PagePoisoned(page)) when unpoison memory (CVE-2025-39883)
  * kernel: e1000e: fix heap overflow in e1000_set_eeprom (CVE-2025-39898)
  * kernel: nbd: fix incomplete validation of ioctl arg (CVE-2023-53513)
  * kernel: tcp: Clear tcp_sk(sk)-&amp;gt;fastopen_rsk in tcp_disconnect() (CVE-2025-39955)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2025:22387</guid>
    </item>
    <item>
      <title>bdu:2025-12902</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-12902</link>
      <description>bdu:2025-12902</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-12902</guid>
    </item>
    <item>
      <title>BELL-CVE-2023-53513</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2023-53513</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2023-53513</guid>
    </item>
    <item>
      <title>certfr-2025-avi-0921 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de SUSE. Certaines d'entre elles permettent à un at…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0921</link>
      <description>certfr-2025-avi-0921</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0921</guid>
    </item>
    <item>
      <title>EUVD-2026-326748</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-326748</link>
      <description>EUVD-2026-326748</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-326748</guid>
    </item>
    <item>
      <title>fkie_cve-2023-53513</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2023-53513</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;nbd: fix incomplete validation of ioctl arg&lt;/p&gt;
&lt;p&gt;We tested and found an alarm caused by nbd_ioctl arg without verification.
The UBSAN warning calltrace like below:&lt;/p&gt;
&lt;p&gt;UBSAN: Undefined behaviour in fs/buffer.c:1709:35
signed integer overflow:
-9223372036854775808 - 1 cannot be represented in type &amp;#39;long long int&amp;#39;
CPU: 3 PID: 2523 Comm: syz-executor.0 Not tainted 4.19.90 #1
Hardware name: linux,dummy-virt (DT)
Call trace:
 dump_backtrace+0x0/0x3f0 arch/arm64/kernel/time.c:78
 show_stack+0x28/0x38 arch/arm64/kernel/traps.c:158
 __dump_stack lib/dump_stack.c:77 [inline]
 dump_stack+0x170/0x1dc lib/dump_stack.c:118
 ubsan_epilogue+0x18/0xb4 lib/ubsan.c:161
 handle_overflow+0x188/0x1dc lib/ubsan.c:192
 __ubsan_handle_sub_overflow+0x34/0x44 lib/ubsan.c:206
 __block_write_full_page+0x94c/0xa20 fs/buffer.c:1709
 block_write_full_page+0x1f0/0x280 fs/buffer.c:2934
 blkdev_writepage+0x34/0x40 fs/block_dev.c:607
 __writepage+0x68/0xe8 mm/page-writeback.c:2305
 write_cache_pages+0x44c/0xc70 mm/page-writeback.c:2240
 generic_writepages+0xdc/0x148 mm/page-writeback.c:2329
 blkdev_writepages+0x2c/0x38 fs/block_dev.c:2114
 do_writepages+0xd4/0x250 mm/page-writeback.c:2344&lt;/p&gt;
&lt;p&gt;The reason for triggering this warning is __block_write_full_page()
-&amp;gt; i_size_read(inode) - 1 overflow.
inode-&amp;gt;i_size is assigned in __nbd_ioctl() -&amp;gt; nbd_set_size() -&amp;gt; bytesize.
We think it is necessary to limit the size of arg to prevent errors.&lt;/p&gt;
&lt;p&gt;Moreover, __nbd…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;nbd: fix incomplete validation of ioctl arg&lt;/p&gt;
&lt;p&gt;We tested and found an alarm caused by nbd_ioctl arg without verification.
The UBSAN warning calltrace like below:&lt;/p&gt;
&lt;p&gt;UBSAN: Undefined behaviour in fs/buffer.c:1709:35
signed integer overflow:
-9223372036854775808 - 1 cannot be represented in type &amp;#39;long long int&amp;#39;
CPU: 3 PID: 2523 Comm: syz-executor.0 Not tainted 4.19.90 #1
Hardware name: linux,dummy-virt (DT)
Call trace:
 dump_backtrace+0x0/0x3f0 arch/arm64/kernel/time.c:78
 show_stack+0x28/0x38 arch/arm64/kernel/traps.c:158
 __dump_stack lib/dump_stack.c:77 [inline]
 dump_stack+0x170/0x1dc lib/dump_stack.c:118
 ubsan_epilogue+0x18/0xb4 lib/ubsan.c:161
 handle_overflow+0x188/0x1dc lib/ubsan.c:192
 __ubsan_handle_sub_overflow+0x34/0x44 lib/ubsan.c:206
 __block_write_full_page+0x94c/0xa20 fs/buffer.c:1709
 block_write_full_page+0x1f0/0x280 fs/buffer.c:2934
 blkdev_writepage+0x34/0x40 fs/block_dev.c:607
 __writepage+0x68/0xe8 mm/page-writeback.c:2305
 write_cache_pages+0x44c/0xc70 mm/page-writeback.c:2240
 generic_writepages+0xdc/0x148 mm/page-writeback.c:2329
 blkdev_writepages+0x2c/0x38 fs/block_dev.c:2114
 do_writepages+0xd4/0x250 mm/page-writeback.c:2344&lt;/p&gt;
&lt;p&gt;The reason for triggering this warning is __block_write_full_page()
-&amp;gt; i_size_read(inode) - 1 overflow.
inode-&amp;gt;i_size is assigned in __nbd_ioctl() -&amp;gt; nbd_set_size() -&amp;gt; bytesize.
We think it is necessary to limit the size of arg to prevent errors.&lt;/p&gt;
&lt;p&gt;Moreover, __nbd…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2023-53513</guid>
    </item>
    <item>
      <title>GHSA-jvcg-848p-wjgf</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-jvcg-848p-wjgf</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;nbd: fix incomplete validation of ioctl arg&lt;/p&gt;
&lt;p&gt;We tested and found an alarm caused by nbd_ioctl arg without verification.
The UBSAN warning calltrace like below:&lt;/p&gt;
&lt;p&gt;UBSAN: Undefined behaviour in fs/buffer.c:1709:35
signed integer overflow:
-9223372036854775808 - 1 cannot be represented in type &amp;#39;long long int&amp;#39;
CPU: 3 PID: 2523 Comm: syz-executor.0 Not tainted 4.19.90 #1
Hardware name: linux,dummy-virt (DT)
Call trace:
 dump_backtrace+0x0/0x3f0 arch/arm64/kernel/time.c:78
 show_stack+0x28/0x38 arch/arm64/kernel/traps.c:158
 __dump_stack lib/dump_stack.c:77 [inline]
 dump_stack+0x170/0x1dc lib/dump_stack.c:118
 ubsan_epilogue+0x18/0xb4 lib/ubsan.c:161
 handle_overflow+0x188/0x1dc lib/ubsan.c:192
 __ubsan_handle_sub_overflow+0x34/0x44 lib/ubsan.c:206
 __block_write_full_page+0x94c/0xa20 fs/buffer.c:1709
 block_write_full_page+0x1f0/0x280 fs/buffer.c:2934
 blkdev_writepage+0x34/0x40 fs/block_dev.c:607
 __writepage+0x68/0xe8 mm/page-writeback.c:2305
 write_cache_pages+0x44c/0xc70 mm/page-writeback.c:2240
 generic_writepages+0xdc/0x148 mm/page-writeback.c:2329
 blkdev_writepages+0x2c/0x38 fs/block_dev.c:2114
 do_writepages+0xd4/0x250 mm/page-writeback.c:2344&lt;/p&gt;
&lt;p&gt;The reason for triggering this warning is __block_write_full_page()
-&amp;gt; i_size_read(inode) - 1 overflow.
inode-&amp;gt;i_size is assigned in __nbd_ioctl() -&amp;gt; nbd_set_size() -&amp;gt; bytesize.
We think it is necessary to limit the size of arg to prevent errors.&lt;/p&gt;
&lt;p&gt;Moreover, __nbd…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;nbd: fix incomplete validation of ioctl arg&lt;/p&gt;
&lt;p&gt;We tested and found an alarm caused by nbd_ioctl arg without verification.
The UBSAN warning calltrace like below:&lt;/p&gt;
&lt;p&gt;UBSAN: Undefined behaviour in fs/buffer.c:1709:35
signed integer overflow:
-9223372036854775808 - 1 cannot be represented in type &amp;#39;long long int&amp;#39;
CPU: 3 PID: 2523 Comm: syz-executor.0 Not tainted 4.19.90 #1
Hardware name: linux,dummy-virt (DT)
Call trace:
 dump_backtrace+0x0/0x3f0 arch/arm64/kernel/time.c:78
 show_stack+0x28/0x38 arch/arm64/kernel/traps.c:158
 __dump_stack lib/dump_stack.c:77 [inline]
 dump_stack+0x170/0x1dc lib/dump_stack.c:118
 ubsan_epilogue+0x18/0xb4 lib/ubsan.c:161
 handle_overflow+0x188/0x1dc lib/ubsan.c:192
 __ubsan_handle_sub_overflow+0x34/0x44 lib/ubsan.c:206
 __block_write_full_page+0x94c/0xa20 fs/buffer.c:1709
 block_write_full_page+0x1f0/0x280 fs/buffer.c:2934
 blkdev_writepage+0x34/0x40 fs/block_dev.c:607
 __writepage+0x68/0xe8 mm/page-writeback.c:2305
 write_cache_pages+0x44c/0xc70 mm/page-writeback.c:2240
 generic_writepages+0xdc/0x148 mm/page-writeback.c:2329
 blkdev_writepages+0x2c/0x38 fs/block_dev.c:2114
 do_writepages+0xd4/0x250 mm/page-writeback.c:2344&lt;/p&gt;
&lt;p&gt;The reason for triggering this warning is __block_write_full_page()
-&amp;gt; i_size_read(inode) - 1 overflow.
inode-&amp;gt;i_size is assigned in __nbd_ioctl() -&amp;gt; nbd_set_size() -&amp;gt; bytesize.
We think it is necessary to limit the size of arg to prevent errors.&lt;/p&gt;
&lt;p&gt;Moreover, __nbd…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-jvcg-848p-wjgf</guid>
    </item>
    <item>
      <title>RHSA-2024:2394 — Red Hat Security Advisory: kernel security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2024:2394</link>
      <description>&lt;p&gt;kernel: Bluetooth BR/EDR PIN Pairing procedure is vulnerable to an impersonation attack kernel: ovl: fix warning in ovl_create_real() kernel: memcg does not limit the number of POSIX file locks allowing memory exhaustion kernel: vmwgfx: NULL pointer dereference in vmw_cmd_dx_define_query kernel: integer overflow in l2cap_config_req() in net/bluetooth/l2cap_core.c kernel: i2c: mlxbf: prevent stack overflow in mlxbf_i2c_smbus_start_transaction() kernel: Bluetooth: L2CAP: Fix u8 overflow kernel: hwmon: (coretemp) fix pci device refcount leak in nv1a_ram_new() kernel: tracing: Fix sleeping function called from invalid context on RT kernel kernel: net: mdio: unexport __init-annotated mdio_bus_init() kernel: arm64: ftrace: consistently handle PLTs. kernel: mm/uffd: fix pte marker when fork() without fork event kernel: Bluetooth: Fix a buffer overflow in mgmt_mesh_add() kernel: tty: n_gsm: add sanity check for gsm-&amp;gt;receive in gsm_receive_buf() kernel: ftrace: Fix NULL pointer dereference in is_ftrace_trampoline when ftrace is dead kernel: tee: add overflow check in register_shm_helper() kernel: tty: n_gsm: fix deadlock and link starvation in outgoing data path kernel: PM: hibernate: defer device probing when resuming from hibernation kernel: ext4: don&amp;#39;t allow journal inode to have encrypt flag kernel: ext4: fix delayed allocation bug in ext4_clu_mapped for bigalloc + inline kernel: erofs: fix order &amp;gt;= MAX_ORDER warning due to crafted negative i_size kernel: perf/x86/intel/uncore: F…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;kernel: Bluetooth BR/EDR PIN Pairing procedure is vulnerable to an impersonation attack kernel: ovl: fix warning in ovl_create_real() kernel: memcg does not limit the number of POSIX file locks allowing memory exhaustion kernel: vmwgfx: NULL pointer dereference in vmw_cmd_dx_define_query kernel: integer overflow in l2cap_config_req() in net/bluetooth/l2cap_core.c kernel: i2c: mlxbf: prevent stack overflow in mlxbf_i2c_smbus_start_transaction() kernel: Bluetooth: L2CAP: Fix u8 overflow kernel: hwmon: (coretemp) fix pci device refcount leak in nv1a_ram_new() kernel: tracing: Fix sleeping function called from invalid context on RT kernel kernel: net: mdio: unexport __init-annotated mdio_bus_init() kernel: arm64: ftrace: consistently handle PLTs. kernel: mm/uffd: fix pte marker when fork() without fork event kernel: Bluetooth: Fix a buffer overflow in mgmt_mesh_add() kernel: tty: n_gsm: add sanity check for gsm-&amp;gt;receive in gsm_receive_buf() kernel: ftrace: Fix NULL pointer dereference in is_ftrace_trampoline when ftrace is dead kernel: tee: add overflow check in register_shm_helper() kernel: tty: n_gsm: fix deadlock and link starvation in outgoing data path kernel: PM: hibernate: defer device probing when resuming from hibernation kernel: ext4: don&amp;#39;t allow journal inode to have encrypt flag kernel: ext4: fix delayed allocation bug in ext4_clu_mapped for bigalloc + inline kernel: erofs: fix order &amp;gt;= MAX_ORDER warning due to crafted negative i_size kernel: perf/x86/intel/uncore: F…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2024:2394</guid>
    </item>
    <item>
      <title>RHSA-2025:22095 — Red Hat Security Advisory: kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2025:22095</link>
      <description>&lt;p&gt;kernel: Bluetooth: L2CAP: Fix user-after-free kernel: net/sched: act_ct: fix skb leak and crash on ooo frags kernel: wifi: mac80211: check S1G action frame size kernel: Bluetooth: L2CAP: fix &amp;#34;bad unlock balance&amp;#34; in l2cap_disconnect_rsp kernel: ip6mr: Fix skb_under_panic in ip6mr_cache_report() kernel: nbd: fix incomplete validation of ioctl arg kernel: smb: client: fix potential UAF in cifs_stats_proc_write() kernel: ethtool: check device is present when getting link settings kernel: ALSA: usb-audio: Validate UAC3 power domain descriptors, too kernel: ipv6: sr: Fix MAC comparison to be constant-time kernel: NFS: Fix filehandle bounds checking in nfs_fh_to_dentry() kernel: ALSA: usb-audio: Validate UAC3 cluster segment descriptors kernel: efivarfs: Fix slab-out-of-bounds in efivarfs_d_compare kernel: x86/vmscape: Add conditional IBPB mitigation&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;kernel: Bluetooth: L2CAP: Fix user-after-free kernel: net/sched: act_ct: fix skb leak and crash on ooo frags kernel: wifi: mac80211: check S1G action frame size kernel: Bluetooth: L2CAP: fix &amp;#34;bad unlock balance&amp;#34; in l2cap_disconnect_rsp kernel: ip6mr: Fix skb_under_panic in ip6mr_cache_report() kernel: nbd: fix incomplete validation of ioctl arg kernel: smb: client: fix potential UAF in cifs_stats_proc_write() kernel: ethtool: check device is present when getting link settings kernel: ALSA: usb-audio: Validate UAC3 power domain descriptors, too kernel: ipv6: sr: Fix MAC comparison to be constant-time kernel: NFS: Fix filehandle bounds checking in nfs_fh_to_dentry() kernel: ALSA: usb-audio: Validate UAC3 cluster segment descriptors kernel: efivarfs: Fix slab-out-of-bounds in efivarfs_d_compare kernel: x86/vmscape: Add conditional IBPB mitigation&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2025:22095</guid>
    </item>
    <item>
      <title>SUSE-SU-2025:3716-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2025:3716-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2025:3716-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2023-53513</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-53513</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux, Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe and 163 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: nbd: fix incomplete validation of ioctl arg We tested and found an alarm caused by nbd_ioctl arg without verification. The UBSAN warning calltrace like below: UBSAN: Undefined behaviour in fs/buffer.c:1709:35 signed integer overflow: -9223372036854775808 - 1 cannot be represented in type &amp;#39;long long int&amp;#39; CPU: 3 PID: 2523 Comm: syz-executor.0 Not tainted 4.19.90 #1 Hardware name: linux,dummy-virt (DT) Call trace:  dump_backtrace+0x0/0x3f0 arch/arm64/kernel/time.c:78  show_stack+0x28/0x38 arch/arm64/kernel/traps.c:158  __dump_stack lib/dump_stack.c:77 [inline]  dump_stack+0x170/0x1dc lib/dump_stack.c:118  ubsan_epilogue+0x18/0xb4 lib/ubsan.c:161  handle_overflow+0x188/0x1dc lib/ubsan.c:192  __ubsan_handle_sub_overflow+0x34/0x44 lib/ubsan.c:206  __block_write_full_page+0x94c/0xa20 fs/buffer.c:1709  block_write_full_page+0x1f0/0x280 fs/buffer.c:2934  blkdev_writepage+0x34/0x40 fs/block_dev.c:607  __writepage+0x68/0xe8 mm/page-writeback.c:2305  write_cache_pages+0x44c/0xc70 mm/page-writeback.c:2240  generic_writepages+0xdc/0x148 mm/page-writeback.c:2329  blkdev_writepages+0x2c/0x38 fs/block_dev.c:2114  do_writepages+0xd4/0x250 mm/page-writeback.c:2344 The reason for triggering this warning is __block_write_full_page() -&amp;gt; i_size_read(inode) - 1 overflow. inode-&amp;gt;i_size is assigned in __nbd_ioctl() -&amp;gt; nbd_set_size() -&amp;gt; bytesize. We think it is necessary to limit the size of arg to prevent errors. Moreover, __nbd_ioct…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux, Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe and 163 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: nbd: fix incomplete validation of ioctl arg We tested and found an alarm caused by nbd_ioctl arg without verification. The UBSAN warning calltrace like below: UBSAN: Undefined behaviour in fs/buffer.c:1709:35 signed integer overflow: -9223372036854775808 - 1 cannot be represented in type &amp;#39;long long int&amp;#39; CPU: 3 PID: 2523 Comm: syz-executor.0 Not tainted 4.19.90 #1 Hardware name: linux,dummy-virt (DT) Call trace:  dump_backtrace+0x0/0x3f0 arch/arm64/kernel/time.c:78  show_stack+0x28/0x38 arch/arm64/kernel/traps.c:158  __dump_stack lib/dump_stack.c:77 [inline]  dump_stack+0x170/0x1dc lib/dump_stack.c:118  ubsan_epilogue+0x18/0xb4 lib/ubsan.c:161  handle_overflow+0x188/0x1dc lib/ubsan.c:192  __ubsan_handle_sub_overflow+0x34/0x44 lib/ubsan.c:206  __block_write_full_page+0x94c/0xa20 fs/buffer.c:1709  block_write_full_page+0x1f0/0x280 fs/buffer.c:2934  blkdev_writepage+0x34/0x40 fs/block_dev.c:607  __writepage+0x68/0xe8 mm/page-writeback.c:2305  write_cache_pages+0x44c/0xc70 mm/page-writeback.c:2240  generic_writepages+0xdc/0x148 mm/page-writeback.c:2329  blkdev_writepages+0x2c/0x38 fs/block_dev.c:2114  do_writepages+0xd4/0x250 mm/page-writeback.c:2344 The reason for triggering this warning is __block_write_full_page() -&amp;gt; i_size_read(inode) - 1 overflow. inode-&amp;gt;i_size is assigned in __nbd_ioctl() -&amp;gt; nbd_set_size() -&amp;gt; bytesize. We think it is necessary to limit the size of arg to prevent errors. Moreover, __nbd_ioct…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-53513</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-2187 — Linux Kernel: Mehrere Schwachstellen ermöglichen Denial of Service</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2187</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen und um nicht nähere beschriebene Effekte zu verursachen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen und um nicht nähere beschriebene Effekte zu verursachen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2187</guid>
    </item>
  </channel>
</rss>
