<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 21:13:46 +0000</lastBuildDate>
    <item>
      <title>9AKK108470A8948 — ELSB/Home Solutions Outdated SW Components in ABB Welcome IP-Gateway.</title>
      <link>https://cve.radiocsirt.org/vuln/9akk108470a8948</link>
      <description>&lt;p&gt;ABB became aware of vulnerabilities in IPGW product versions listed as affected in the advisory. An attacker who successfully exploits these vulnerabilities could potentially gain unauthorized access and potentially compromise the system&amp;#39;s - and log-file - confidentiality, integrity and availability. 
ABB requires that the IP-address of an IPGW should not be accessible from the Internet  or any other network considered insecure. The communication between IPGW and the associated Internet Service shall be outbound-initiated, bi-directional. Any unsolicited inbound connection shall be discarded. A common way to ensure this best practice is to operate IPGW behind a firewall.  
Researchers have reported 2518 CVEs to ABB which were identified using an automated scanning tool in a local network. ABB has analyzed these CVEs carefully and came to the following result:&lt;/p&gt;
&lt;p&gt;2074 - CVE&amp;#39;s not impacting IPGW because it belongs to SW components inside the IPGW-Firmware-Image, that are not supported by the IPGW as a product, e.g. IPGW does not support: Display, USB-port, Keyboard, etc.&lt;/p&gt;
&lt;p&gt;7 - High Severity CVEs that belong to SW components integrated in IPGW-firmware-image.  These CVE’s are considered to have a high severity because there are proof of concept (PoC) descriptions available. 
For cases that are not fixed, ABB was not able to find an appropriate solution.&lt;/p&gt;
&lt;p&gt;34 - Medium CVEs that belong to SW components integrated in IPGW-firmware-image.  ABB defines a medium severity for CVE’s where…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;ABB became aware of vulnerabilities in IPGW product versions listed as affected in the advisory. An attacker who successfully exploits these vulnerabilities could potentially gain unauthorized access and potentially compromise the system&amp;#39;s - and log-file - confidentiality, integrity and availability. 
ABB requires that the IP-address of an IPGW should not be accessible from the Internet  or any other network considered insecure. The communication between IPGW and the associated Internet Service shall be outbound-initiated, bi-directional. Any unsolicited inbound connection shall be discarded. A common way to ensure this best practice is to operate IPGW behind a firewall.  
Researchers have reported 2518 CVEs to ABB which were identified using an automated scanning tool in a local network. ABB has analyzed these CVEs carefully and came to the following result:&lt;/p&gt;
&lt;p&gt;2074 - CVE&amp;#39;s not impacting IPGW because it belongs to SW components inside the IPGW-Firmware-Image, that are not supported by the IPGW as a product, e.g. IPGW does not support: Display, USB-port, Keyboard, etc.&lt;/p&gt;
&lt;p&gt;7 - High Severity CVEs that belong to SW components integrated in IPGW-firmware-image.  These CVE’s are considered to have a high severity because there are proof of concept (PoC) descriptions available. 
For cases that are not fixed, ABB was not able to find an appropriate solution.&lt;/p&gt;
&lt;p&gt;34 - Medium CVEs that belong to SW components integrated in IPGW-firmware-image.  ABB defines a medium severity for CVE’s where…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/9akk108470a8948</guid>
    </item>
    <item>
      <title>ALSA-2024:2394 — Important: kernel security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2024:2394</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: bpftool, AlmaLinux:9: kernel, AlmaLinux:9: kernel-64k, AlmaLinux:9: kernel-64k-core, AlmaLinux:9: kernel-64k-debug, AlmaLinux:9: kernel-64k-debug-core, AlmaLinux:9: kernel-64k-debug-devel, AlmaLinux:9: kernel-64k-debug-devel-matched, AlmaLinux:9: kernel-64k-debug-modules, AlmaLinux:9: kernel-64k-debug-modules-core and 52 more&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: GSM multiplexing race condition leads to privilege escalation (CVE-2023-6546)
  * kernel: multiple use-after-free vulnerabilities (CVE-2024-1086, CVE-2023-3567, CVE-2023-4133, CVE-2023-6932, CVE-2023-39198, CVE-2023-51043, CVE-2023-51779, CVE-2023-51780, CVE-2024-1085, CVE-2024-26582)
  * kernel: Bluetooth BR/EDR PIN Pairing procedure is vulnerable to an impersonation attack (CVE-2020-26555)
  * kernel: memcg does not limit the number of POSIX file locks allowing memory exhaustion (CVE-2022-0480)
  * kernel: multiple NULL pointer dereference vulnerabilities (CVE-2022-38096, CVE-2023-6622, CVE-2023-6915, CVE-2023-42754, CVE-2023-46862, CVE-2023-52574, CVE-2024-0841, CVE-2023-52448)
  * kernel: integer overflow in l2cap_config_req() in net/bluetooth/l2cap_core.c (CVE-2022-45934)
  * kernel: netfilter: nf_tables: out-of-bounds access in nf_tables_newtable() (CVE-2023-6040)
  * kernel: GC&amp;#39;s deletion of an SKB races with unix_stream_read_generic() leading to UAF (CVE-2023-6531)
  * kernel: Out of boundary write in perf_read_group() as result of overflow a perf_event&amp;#39;s read_size (CVE-2023-6931)
  * kernel: Bluetooth Forward and Future Secrecy Attacks and Defenses (CVE-2023-24023)
  * kernel: irdma: Improper access control (CVE-2023-25775)
  * Kernel: double free in hci_conn_cleanup of the bluetooth subsystem (CVE-2023-28464)
  * kernel: Bluetooth: HCI: global o…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: bpftool, AlmaLinux:9: kernel, AlmaLinux:9: kernel-64k, AlmaLinux:9: kernel-64k-core, AlmaLinux:9: kernel-64k-debug, AlmaLinux:9: kernel-64k-debug-core, AlmaLinux:9: kernel-64k-debug-devel, AlmaLinux:9: kernel-64k-debug-devel-matched, AlmaLinux:9: kernel-64k-debug-modules, AlmaLinux:9: kernel-64k-debug-modules-core and 52 more&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: GSM multiplexing race condition leads to privilege escalation (CVE-2023-6546)
  * kernel: multiple use-after-free vulnerabilities (CVE-2024-1086, CVE-2023-3567, CVE-2023-4133, CVE-2023-6932, CVE-2023-39198, CVE-2023-51043, CVE-2023-51779, CVE-2023-51780, CVE-2024-1085, CVE-2024-26582)
  * kernel: Bluetooth BR/EDR PIN Pairing procedure is vulnerable to an impersonation attack (CVE-2020-26555)
  * kernel: memcg does not limit the number of POSIX file locks allowing memory exhaustion (CVE-2022-0480)
  * kernel: multiple NULL pointer dereference vulnerabilities (CVE-2022-38096, CVE-2023-6622, CVE-2023-6915, CVE-2023-42754, CVE-2023-46862, CVE-2023-52574, CVE-2024-0841, CVE-2023-52448)
  * kernel: integer overflow in l2cap_config_req() in net/bluetooth/l2cap_core.c (CVE-2022-45934)
  * kernel: netfilter: nf_tables: out-of-bounds access in nf_tables_newtable() (CVE-2023-6040)
  * kernel: GC&amp;#39;s deletion of an SKB races with unix_stream_read_generic() leading to UAF (CVE-2023-6531)
  * kernel: Out of boundary write in perf_read_group() as result of overflow a perf_event&amp;#39;s read_size (CVE-2023-6931)
  * kernel: Bluetooth Forward and Future Secrecy Attacks and Defenses (CVE-2023-24023)
  * kernel: irdma: Improper access control (CVE-2023-25775)
  * Kernel: double free in hci_conn_cleanup of the bluetooth subsystem (CVE-2023-28464)
  * kernel: Bluetooth: HCI: global o…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2024:2394</guid>
    </item>
    <item>
      <title>bdu:2023-09022</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2023-09022</link>
      <description>bdu:2023-09022</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2023-09022</guid>
    </item>
    <item>
      <title>BELL-CVE-2023-6932</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2023-6932</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2023-6932</guid>
    </item>
    <item>
      <title>certfr-2024-avi-0055 — De multiples vulnérabilités ont été découvertes dans &lt;span
class="textit"&gt;le noyau Linux de SUSE&lt;/span&gt;. Certaines d'en…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0055</link>
      <description>certfr-2024-avi-0055</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2024-avi-0055</guid>
    </item>
    <item>
      <title>cnvd-2023-101108</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2023-101108</link>
      <description>cnvd-2023-101108</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2023-101108</guid>
    </item>
    <item>
      <title>EUVD-2026-316901</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-316901</link>
      <description>EUVD-2026-316901</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-316901</guid>
    </item>
    <item>
      <title>fkie_cve-2023-6932</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2023-6932</link>
      <description>&lt;p&gt;A use-after-free vulnerability in the Linux kernel&amp;#39;s ipv4: igmp component can be exploited to achieve local privilege escalation.&lt;/p&gt;
&lt;p&gt;A race condition can be exploited to cause a timer be mistakenly registered on a RCU read locked object which is freed by another thread.&lt;/p&gt;
&lt;p&gt;We recommend upgrading past commit e2b706c691905fe78468c361aaabc719d0a496f1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A use-after-free vulnerability in the Linux kernel&amp;#39;s ipv4: igmp component can be exploited to achieve local privilege escalation.&lt;/p&gt;
&lt;p&gt;A race condition can be exploited to cause a timer be mistakenly registered on a RCU read locked object which is freed by another thread.&lt;/p&gt;
&lt;p&gt;We recommend upgrading past commit e2b706c691905fe78468c361aaabc719d0a496f1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2023-6932</guid>
    </item>
    <item>
      <title>GHSA-m2ff-6895-cr34</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-m2ff-6895-cr34</link>
      <description>&lt;p&gt;A use-after-free vulnerability in the Linux kernel&amp;#39;s ipv4: igmp component can be exploited to achieve local privilege escalation.&lt;/p&gt;
&lt;p&gt;A race condition can be exploited to cause a timer be mistakenly registered on a RCU read locked object which is freed by another thread.&lt;/p&gt;
&lt;p&gt;We recommend upgrading past commit e2b706c691905fe78468c361aaabc719d0a496f1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A use-after-free vulnerability in the Linux kernel&amp;#39;s ipv4: igmp component can be exploited to achieve local privilege escalation.&lt;/p&gt;
&lt;p&gt;A race condition can be exploited to cause a timer be mistakenly registered on a RCU read locked object which is freed by another thread.&lt;/p&gt;
&lt;p&gt;We recommend upgrading past commit e2b706c691905fe78468c361aaabc719d0a496f1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-m2ff-6895-cr34</guid>
    </item>
    <item>
      <title>gsd-2023-6932</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2023-6932</link>
      <description>gsd-2023-6932</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2023-6932</guid>
    </item>
    <item>
      <title>ICSA-23-166-11 — Siemens SIMATIC S7-1500 TM MFP Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-23-166-11</link>
      <description>&lt;p&gt;json-c through 0.14 has an integer overflow and out-of-bounds write via a large JSON file, as demonstrated by printbuf_memappend. A memory overflow vulnerability was found in the Linux kernel’s ipc functionality of the memcg subsystem, in the way a user calls the semget function multiple times, creating semaphores. This flaw allows a local user to starve the resources, causing a denial of service. The highest threat from this vulnerability is to system availability. A vulnerability was found in the fs/inode.c:inode_init_owner() function logic of the LInux kernel that allows local users to create files for the XFS file-system with an unintended group ownership and with group execution and SGID permission bits set, in a scenario where a directory is SGID and belongs to a certain group and is writable by a user who is not a member of this group. This can lead to excessive permissions granted in case when they should not. This vulnerability is similar to the previous CVE-2018-13405 and adds the missed fix for the XFS. When sending malicous data to kernel by ioctl cmd FBIOPUT_VSCREENINFO,kernel will write memory out of bounds. In gc_data_segment in fs/f2fs/gc.c in the Linux kernel before 5.16.3, special files are not considered, leading to a move_data_page NULL pointer dereference. A flaw was found in the Linux kernel. The existing KVM SEV API has a vulnerability that allows a non-root (host) user-level application to crash the host kernel by creating a confidential guest VM inst…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;json-c through 0.14 has an integer overflow and out-of-bounds write via a large JSON file, as demonstrated by printbuf_memappend. A memory overflow vulnerability was found in the Linux kernel’s ipc functionality of the memcg subsystem, in the way a user calls the semget function multiple times, creating semaphores. This flaw allows a local user to starve the resources, causing a denial of service. The highest threat from this vulnerability is to system availability. A vulnerability was found in the fs/inode.c:inode_init_owner() function logic of the LInux kernel that allows local users to create files for the XFS file-system with an unintended group ownership and with group execution and SGID permission bits set, in a scenario where a directory is SGID and belongs to a certain group and is writable by a user who is not a member of this group. This can lead to excessive permissions granted in case when they should not. This vulnerability is similar to the previous CVE-2018-13405 and adds the missed fix for the XFS. When sending malicous data to kernel by ioctl cmd FBIOPUT_VSCREENINFO,kernel will write memory out of bounds. In gc_data_segment in fs/f2fs/gc.c in the Linux kernel before 5.16.3, special files are not considered, leading to a move_data_page NULL pointer dereference. A flaw was found in the Linux kernel. The existing KVM SEV API has a vulnerability that allows a non-root (host) user-level application to crash the host kernel by creating a confidential guest VM inst…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-23-166-11</guid>
    </item>
    <item>
      <title>msrc_CVE-2023-6932 — Use-after-free in Linux kernel's ipv4: igmp component</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2023-6932</link>
      <description>msrc_CVE-2023-6932</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2023-6932</guid>
    </item>
    <item>
      <title>OESA-2024-1030 — kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2024-1030</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&#13;
&#13;
openeuler-linux-kernel-4.19.0-cbs_destroy-NULL-ptr-deref-391216(CVE-2021-33630)&#13;
&#13;
openeuler-linux-kernel-5.10.149-ext4_write_inline_data-kernel_bug-365020(CVE-2021-33631)&#13;
&#13;
An out-of-bounds read vulnerability was found in the NVMe-oF/TCP subsystem in the Linux kernel. This issue may allow a remote attacker to send a crafted TCP packet, triggering a heap-based buffer overflow that results in kmalloc data being printed and potentially leaked to the kernel ring buffer (dmesg).(CVE-2023-6121)&#13;
&#13;
A heap out-of-bounds write vulnerability in the Linux kernel&amp;amp;apos;s Performance Events system component can be exploited to achieve local privilege escalation.&#13;
&#13;
A perf_event&amp;amp;apos;s read_size can overflow, leading to an heap out-of-bounds increment or write in perf_read_group().&#13;
&#13;
We recommend upgrading past commit 382c27f4ed28f803b1f1473ac2d8db0afc795a1b.&#13;
&#13;
(CVE-2023-6931)&#13;
&#13;
A use-after-free vulnerability in the Linux kernel&amp;amp;apos;s ipv4: igmp component can be exploited to achieve local privilege escalation.&#13;
&#13;
A race condition can be exploited to cause a timer be mistakenly registered on a RCU read locked object which is freed by another thread.&#13;
&#13;
We recommend upgrading past commit e2b706c691905fe78468c361aaabc719d0a496f1.&#13;
&#13;
(CVE-2023-6932)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&#13;
&#13;
openeuler-linux-kernel-4.19.0-cbs_destroy-NULL-ptr-deref-391216(CVE-2021-33630)&#13;
&#13;
openeuler-linux-kernel-5.10.149-ext4_write_inline_data-kernel_bug-365020(CVE-2021-33631)&#13;
&#13;
An out-of-bounds read vulnerability was found in the NVMe-oF/TCP subsystem in the Linux kernel. This issue may allow a remote attacker to send a crafted TCP packet, triggering a heap-based buffer overflow that results in kmalloc data being printed and potentially leaked to the kernel ring buffer (dmesg).(CVE-2023-6121)&#13;
&#13;
A heap out-of-bounds write vulnerability in the Linux kernel&amp;amp;apos;s Performance Events system component can be exploited to achieve local privilege escalation.&#13;
&#13;
A perf_event&amp;amp;apos;s read_size can overflow, leading to an heap out-of-bounds increment or write in perf_read_group().&#13;
&#13;
We recommend upgrading past commit 382c27f4ed28f803b1f1473ac2d8db0afc795a1b.&#13;
&#13;
(CVE-2023-6931)&#13;
&#13;
A use-after-free vulnerability in the Linux kernel&amp;amp;apos;s ipv4: igmp component can be exploited to achieve local privilege escalation.&#13;
&#13;
A race condition can be exploited to cause a timer be mistakenly registered on a RCU read locked object which is freed by another thread.&#13;
&#13;
We recommend upgrading past commit e2b706c691905fe78468c361aaabc719d0a496f1.&#13;
&#13;
(CVE-2023-6932)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2024-1030</guid>
    </item>
    <item>
      <title>RHSA-2024:0723 — Red Hat Security Advisory: kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2024:0723</link>
      <description>&lt;p&gt;kernel: sctp: fail if no bound addresses can be used for a given scope kernel: NULL pointer dereference in nvmet_tcp_build_iovec kernel: NULL pointer dereference in nvmet_tcp_execute_request kernel: NULL pointer dereference in __nvmet_req_complete kernel: Out-Of-Bounds Read vulnerability in smbCalcSize kernel: OOB Access in smb2_dump_detail kernel: use-after-free in IPv4 IGMP kernel: refcount leak in ctnetlink_create_conntrack() kernel: drivers/usb/storage/ene_ub6250.c kernel: ktls overwrites readonly memory pages when using function splice with a ktls socket as destination&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;kernel: sctp: fail if no bound addresses can be used for a given scope kernel: NULL pointer dereference in nvmet_tcp_build_iovec kernel: NULL pointer dereference in nvmet_tcp_execute_request kernel: NULL pointer dereference in __nvmet_req_complete kernel: Out-Of-Bounds Read vulnerability in smbCalcSize kernel: OOB Access in smb2_dump_detail kernel: use-after-free in IPv4 IGMP kernel: refcount leak in ctnetlink_create_conntrack() kernel: drivers/usb/storage/ene_ub6250.c kernel: ktls overwrites readonly memory pages when using function splice with a ktls socket as destination&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2024:0723</guid>
    </item>
    <item>
      <title>RHSA-2024:2394 — Red Hat Security Advisory: kernel security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2024:2394</link>
      <description>&lt;p&gt;kernel: Bluetooth BR/EDR PIN Pairing procedure is vulnerable to an impersonation attack kernel: ovl: fix warning in ovl_create_real() kernel: memcg does not limit the number of POSIX file locks allowing memory exhaustion kernel: vmwgfx: NULL pointer dereference in vmw_cmd_dx_define_query kernel: integer overflow in l2cap_config_req() in net/bluetooth/l2cap_core.c kernel: i2c: mlxbf: prevent stack overflow in mlxbf_i2c_smbus_start_transaction() kernel: Bluetooth: L2CAP: Fix u8 overflow kernel: hwmon: (coretemp) fix pci device refcount leak in nv1a_ram_new() kernel: tracing: Fix sleeping function called from invalid context on RT kernel kernel: net: mdio: unexport __init-annotated mdio_bus_init() kernel: arm64: ftrace: consistently handle PLTs. kernel: mm/uffd: fix pte marker when fork() without fork event kernel: Bluetooth: Fix a buffer overflow in mgmt_mesh_add() kernel: tty: n_gsm: add sanity check for gsm-&amp;gt;receive in gsm_receive_buf() kernel: ftrace: Fix NULL pointer dereference in is_ftrace_trampoline when ftrace is dead kernel: tee: add overflow check in register_shm_helper() kernel: tty: n_gsm: fix deadlock and link starvation in outgoing data path kernel: PM: hibernate: defer device probing when resuming from hibernation kernel: ext4: don&amp;#39;t allow journal inode to have encrypt flag kernel: ext4: fix delayed allocation bug in ext4_clu_mapped for bigalloc + inline kernel: erofs: fix order &amp;gt;= MAX_ORDER warning due to crafted negative i_size kernel: perf/x86/intel/uncore: F…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;kernel: Bluetooth BR/EDR PIN Pairing procedure is vulnerable to an impersonation attack kernel: ovl: fix warning in ovl_create_real() kernel: memcg does not limit the number of POSIX file locks allowing memory exhaustion kernel: vmwgfx: NULL pointer dereference in vmw_cmd_dx_define_query kernel: integer overflow in l2cap_config_req() in net/bluetooth/l2cap_core.c kernel: i2c: mlxbf: prevent stack overflow in mlxbf_i2c_smbus_start_transaction() kernel: Bluetooth: L2CAP: Fix u8 overflow kernel: hwmon: (coretemp) fix pci device refcount leak in nv1a_ram_new() kernel: tracing: Fix sleeping function called from invalid context on RT kernel kernel: net: mdio: unexport __init-annotated mdio_bus_init() kernel: arm64: ftrace: consistently handle PLTs. kernel: mm/uffd: fix pte marker when fork() without fork event kernel: Bluetooth: Fix a buffer overflow in mgmt_mesh_add() kernel: tty: n_gsm: add sanity check for gsm-&amp;gt;receive in gsm_receive_buf() kernel: ftrace: Fix NULL pointer dereference in is_ftrace_trampoline when ftrace is dead kernel: tee: add overflow check in register_shm_helper() kernel: tty: n_gsm: fix deadlock and link starvation in outgoing data path kernel: PM: hibernate: defer device probing when resuming from hibernation kernel: ext4: don&amp;#39;t allow journal inode to have encrypt flag kernel: ext4: fix delayed allocation bug in ext4_clu_mapped for bigalloc + inline kernel: erofs: fix order &amp;gt;= MAX_ORDER warning due to crafted negative i_size kernel: perf/x86/intel/uncore: F…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2024:2394</guid>
    </item>
    <item>
      <title>RXSA-2024:3138 — Moderate: kernel security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rxsa-2024:3138</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:8: kernel&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Additional Changes:&lt;/p&gt;
&lt;p&gt;For detailed information on changes in this release, see the Rocky Linux SIG Cloud 8.10 Release Notes linked from the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:8: kernel&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Additional Changes:&lt;/p&gt;
&lt;p&gt;For detailed information on changes in this release, see the Rocky Linux SIG Cloud 8.10 Release Notes linked from the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rxsa-2024:3138</guid>
    </item>
    <item>
      <title>SSA-265688 — SSA-265688: Vulnerabilities in the additional GNU/Linux subsystem of the SIMATIC S7-1500 TM MFP V1.1</title>
      <link>https://cve.radiocsirt.org/vuln/ssa-265688</link>
      <description>&lt;p&gt;An out-of-bounds (OOB) memory write flaw was found in the NFSD in the Linux kernel. Missing sanity may lead to a write beyond bmval[bmlen-1] in nfsd4_decode_bitmap4 in fs/nfsd/nfs4xdr.c. In this flaw, a local attacker with user privilege may gain access to out-of-bounds memory, leading to a system integrity and confidentiality threat. fs/nfsd/trace.h in the Linux kernel before 5.13.4 might allow remote attackers to cause a denial of service (out-of-bounds read in strlen) by sending NFS traffic when the trace event framework is being used for nfsd. SUNRPC: null pointer dereference in svc_rqst_free(). When alloc_pages_node() returns null in svc_rqst_alloc(), the null rq_scratch_page pointer will be dereferenced when calling put_page() in svc_rqst_free(). NFSD: READDIR buffer overflow. If a client sends a READDIR count argument that is too small (say, zero), then the buffer size calculation in the new init_dirlist helper functions results in an underflow, allowing the XDR stream functions to write beyond the actual buffer. This calculation has always been suspect. NFSD has never sanity- checked the READDIR count argument, but the old entry encoders managed the problem correctly. With the commits below, entry encoding changed, exposing the underflow to the pointer arithmetic in xdr_reserve_space(). Modern NFS clients attempt to retrieve as much data as possible for each READDIR request. nfsd: NULL dereference in nfs3svc_encode_getaclres. A NULL pointer dereference vulnerability…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An out-of-bounds (OOB) memory write flaw was found in the NFSD in the Linux kernel. Missing sanity may lead to a write beyond bmval[bmlen-1] in nfsd4_decode_bitmap4 in fs/nfsd/nfs4xdr.c. In this flaw, a local attacker with user privilege may gain access to out-of-bounds memory, leading to a system integrity and confidentiality threat. fs/nfsd/trace.h in the Linux kernel before 5.13.4 might allow remote attackers to cause a denial of service (out-of-bounds read in strlen) by sending NFS traffic when the trace event framework is being used for nfsd. SUNRPC: null pointer dereference in svc_rqst_free(). When alloc_pages_node() returns null in svc_rqst_alloc(), the null rq_scratch_page pointer will be dereferenced when calling put_page() in svc_rqst_free(). NFSD: READDIR buffer overflow. If a client sends a READDIR count argument that is too small (say, zero), then the buffer size calculation in the new init_dirlist helper functions results in an underflow, allowing the XDR stream functions to write beyond the actual buffer. This calculation has always been suspect. NFSD has never sanity- checked the READDIR count argument, but the old entry encoders managed the problem correctly. With the commits below, entry encoding changed, exposing the underflow to the pointer arithmetic in xdr_reserve_space(). Modern NFS clients attempt to retrieve as much data as possible for each READDIR request. nfsd: NULL dereference in nfs3svc_encode_getaclres. A NULL pointer dereference vulnerability…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ssa-265688</guid>
    </item>
    <item>
      <title>SUSE-SU-2024:0110-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2024:0110-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2024:0110-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2023-6932</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-6932</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux, Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe and 155 more&lt;/p&gt;
&lt;p&gt;A use-after-free vulnerability in the Linux kernel&amp;#39;s ipv4: igmp component can be exploited to achieve local privilege escalation. A race condition can be exploited to cause a timer be mistakenly registered on a RCU read locked object which is freed by another thread. We recommend upgrading past commit e2b706c691905fe78468c361aaabc719d0a496f1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux, Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe and 155 more&lt;/p&gt;
&lt;p&gt;A use-after-free vulnerability in the Linux kernel&amp;#39;s ipv4: igmp component can be exploited to achieve local privilege escalation. A race condition can be exploited to cause a timer be mistakenly registered on a RCU read locked object which is freed by another thread. We recommend upgrading past commit e2b706c691905fe78468c361aaabc719d0a496f1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-6932</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-3181 — Linux Kernel: Mehrere Schwachstellen ermöglichen Privilegieneskalation</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-3181</link>
      <description>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen in Linux Kernel ausnutzen, um einen Denial of Service zu verursachen, Code auszuführen oder um seine Privilegien zu erhöhen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen in Linux Kernel ausnutzen, um einen Denial of Service zu verursachen, Code auszuführen oder um seine Privilegien zu erhöhen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-3181</guid>
    </item>
  </channel>
</rss>
