<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 07:17:15 +0000</lastBuildDate>
    <item>
      <title>bdu:2025-04397</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-04397</link>
      <description>bdu:2025-04397</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-04397</guid>
    </item>
    <item>
      <title>BELL-CVE-2024-26732</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2024-26732</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2024-26732</guid>
    </item>
    <item>
      <title>EUVD-2026-312576</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-312576</link>
      <description>EUVD-2026-312576</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-312576</guid>
    </item>
    <item>
      <title>fkie_cve-2024-26732</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-26732</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;net: implement lockless setsockopt(SO_PEEK_OFF)&lt;/p&gt;
&lt;p&gt;syzbot reported a lockdep violation [1] involving af_unix
support of SO_PEEK_OFF.&lt;/p&gt;
&lt;p&gt;Since SO_PEEK_OFF is inherently not thread safe (it uses a per-socket
sk_peek_off field), there is really no point to enforce a pointless
thread safety in the kernel.&lt;/p&gt;
&lt;p&gt;After this patch :&lt;/p&gt;
&lt;p&gt;- setsockopt(SO_PEEK_OFF) no longer acquires the socket lock.&lt;/p&gt;
&lt;p&gt;- skb_consume_udp() no longer has to acquire the socket lock.&lt;/p&gt;
&lt;p&gt;- af_unix no longer needs a special version of sk_set_peek_off(),
  because it does not lock u-&amp;gt;iolock anymore.&lt;/p&gt;
&lt;p&gt;As a followup, we could replace prot-&amp;gt;set_peek_off to be a boolean
and avoid an indirect call, since we always use sk_set_peek_off().&lt;/p&gt;
&lt;p&gt;[1]&lt;/p&gt;
&lt;p&gt;WARNING: possible circular locking dependency detected
6.8.0-rc4-syzkaller-00267-g0f1dd5e91e2b #0 Not tainted&lt;/p&gt;
&lt;p&gt;syz-executor.2/30025 is trying to acquire lock:
 ffff8880765e7d80 (&amp;amp;u-&amp;gt;iolock){+.+.}-{3:3}, at: unix_set_peek_off+0x26/0xa0 net/unix/af_unix.c:789&lt;/p&gt;
&lt;p&gt;but task is already holding lock:
 ffff8880765e7930 (sk_lock-AF_UNIX){+.+.}-{0:0}, at: lock_sock include/net/sock.h:1691 [inline]
 ffff8880765e7930 (sk_lock-AF_UNIX){+.+.}-{0:0}, at: sockopt_lock_sock net/core/sock.c:1060 [inline]
 ffff8880765e7930 (sk_lock-AF_UNIX){+.+.}-{0:0}, at: sk_setsockopt+0xe52/0x3360 net/core/sock.c:1193&lt;/p&gt;
&lt;p&gt;which lock already depends on the new lock.&lt;/p&gt;
&lt;p&gt;the existing dependency chain (in reverse order) is:&lt;/p&gt;
&lt;p&gt;-&amp;gt; #1 (sk_lock-AF_UNIX){+.+.}-{0:0}:…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;net: implement lockless setsockopt(SO_PEEK_OFF)&lt;/p&gt;
&lt;p&gt;syzbot reported a lockdep violation [1] involving af_unix
support of SO_PEEK_OFF.&lt;/p&gt;
&lt;p&gt;Since SO_PEEK_OFF is inherently not thread safe (it uses a per-socket
sk_peek_off field), there is really no point to enforce a pointless
thread safety in the kernel.&lt;/p&gt;
&lt;p&gt;After this patch :&lt;/p&gt;
&lt;p&gt;- setsockopt(SO_PEEK_OFF) no longer acquires the socket lock.&lt;/p&gt;
&lt;p&gt;- skb_consume_udp() no longer has to acquire the socket lock.&lt;/p&gt;
&lt;p&gt;- af_unix no longer needs a special version of sk_set_peek_off(),
  because it does not lock u-&amp;gt;iolock anymore.&lt;/p&gt;
&lt;p&gt;As a followup, we could replace prot-&amp;gt;set_peek_off to be a boolean
and avoid an indirect call, since we always use sk_set_peek_off().&lt;/p&gt;
&lt;p&gt;[1]&lt;/p&gt;
&lt;p&gt;WARNING: possible circular locking dependency detected
6.8.0-rc4-syzkaller-00267-g0f1dd5e91e2b #0 Not tainted&lt;/p&gt;
&lt;p&gt;syz-executor.2/30025 is trying to acquire lock:
 ffff8880765e7d80 (&amp;amp;u-&amp;gt;iolock){+.+.}-{3:3}, at: unix_set_peek_off+0x26/0xa0 net/unix/af_unix.c:789&lt;/p&gt;
&lt;p&gt;but task is already holding lock:
 ffff8880765e7930 (sk_lock-AF_UNIX){+.+.}-{0:0}, at: lock_sock include/net/sock.h:1691 [inline]
 ffff8880765e7930 (sk_lock-AF_UNIX){+.+.}-{0:0}, at: sockopt_lock_sock net/core/sock.c:1060 [inline]
 ffff8880765e7930 (sk_lock-AF_UNIX){+.+.}-{0:0}, at: sk_setsockopt+0xe52/0x3360 net/core/sock.c:1193&lt;/p&gt;
&lt;p&gt;which lock already depends on the new lock.&lt;/p&gt;
&lt;p&gt;the existing dependency chain (in reverse order) is:&lt;/p&gt;
&lt;p&gt;-&amp;gt; #1 (sk_lock-AF_UNIX){+.+.}-{0:0}:…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-26732</guid>
    </item>
    <item>
      <title>GHSA-q4jh-g383-rjcg</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-q4jh-g383-rjcg</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;net: implement lockless setsockopt(SO_PEEK_OFF)&lt;/p&gt;
&lt;p&gt;syzbot reported a lockdep violation [1] involving af_unix
support of SO_PEEK_OFF.&lt;/p&gt;
&lt;p&gt;Since SO_PEEK_OFF is inherently not thread safe (it uses a per-socket
sk_peek_off field), there is really no point to enforce a pointless
thread safety in the kernel.&lt;/p&gt;
&lt;p&gt;After this patch :&lt;/p&gt;
&lt;p&gt;- setsockopt(SO_PEEK_OFF) no longer acquires the socket lock.&lt;/p&gt;
&lt;p&gt;- skb_consume_udp() no longer has to acquire the socket lock.&lt;/p&gt;
&lt;p&gt;- af_unix no longer needs a special version of sk_set_peek_off(),
  because it does not lock u-&amp;gt;iolock anymore.&lt;/p&gt;
&lt;p&gt;As a followup, we could replace prot-&amp;gt;set_peek_off to be a boolean
and avoid an indirect call, since we always use sk_set_peek_off().&lt;/p&gt;
&lt;p&gt;[1]&lt;/p&gt;
&lt;p&gt;WARNING: possible circular locking dependency detected
6.8.0-rc4-syzkaller-00267-g0f1dd5e91e2b #0 Not tainted&lt;/p&gt;
&lt;p&gt;syz-executor.2/30025 is trying to acquire lock:
 ffff8880765e7d80 (&amp;amp;u-&amp;gt;iolock){+.+.}-{3:3}, at: unix_set_peek_off+0x26/0xa0 net/unix/af_unix.c:789&lt;/p&gt;
&lt;p&gt;but task is already holding lock:
 ffff8880765e7930 (sk_lock-AF_UNIX){+.+.}-{0:0}, at: lock_sock include/net/sock.h:1691 [inline]
 ffff8880765e7930 (sk_lock-AF_UNIX){+.+.}-{0:0}, at: sockopt_lock_sock net/core/sock.c:1060 [inline]
 ffff8880765e7930 (sk_lock-AF_UNIX){+.+.}-{0:0}, at: sk_setsockopt+0xe52/0x3360 net/core/sock.c:1193&lt;/p&gt;
&lt;p&gt;which lock already depends on the new lock.&lt;/p&gt;
&lt;p&gt;the existing dependency chain (in reverse order) is:&lt;/p&gt;
&lt;p&gt;-&amp;gt; #1 (sk_lock-AF_UNIX){+.+.}-{0:0}:…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;net: implement lockless setsockopt(SO_PEEK_OFF)&lt;/p&gt;
&lt;p&gt;syzbot reported a lockdep violation [1] involving af_unix
support of SO_PEEK_OFF.&lt;/p&gt;
&lt;p&gt;Since SO_PEEK_OFF is inherently not thread safe (it uses a per-socket
sk_peek_off field), there is really no point to enforce a pointless
thread safety in the kernel.&lt;/p&gt;
&lt;p&gt;After this patch :&lt;/p&gt;
&lt;p&gt;- setsockopt(SO_PEEK_OFF) no longer acquires the socket lock.&lt;/p&gt;
&lt;p&gt;- skb_consume_udp() no longer has to acquire the socket lock.&lt;/p&gt;
&lt;p&gt;- af_unix no longer needs a special version of sk_set_peek_off(),
  because it does not lock u-&amp;gt;iolock anymore.&lt;/p&gt;
&lt;p&gt;As a followup, we could replace prot-&amp;gt;set_peek_off to be a boolean
and avoid an indirect call, since we always use sk_set_peek_off().&lt;/p&gt;
&lt;p&gt;[1]&lt;/p&gt;
&lt;p&gt;WARNING: possible circular locking dependency detected
6.8.0-rc4-syzkaller-00267-g0f1dd5e91e2b #0 Not tainted&lt;/p&gt;
&lt;p&gt;syz-executor.2/30025 is trying to acquire lock:
 ffff8880765e7d80 (&amp;amp;u-&amp;gt;iolock){+.+.}-{3:3}, at: unix_set_peek_off+0x26/0xa0 net/unix/af_unix.c:789&lt;/p&gt;
&lt;p&gt;but task is already holding lock:
 ffff8880765e7930 (sk_lock-AF_UNIX){+.+.}-{0:0}, at: lock_sock include/net/sock.h:1691 [inline]
 ffff8880765e7930 (sk_lock-AF_UNIX){+.+.}-{0:0}, at: sockopt_lock_sock net/core/sock.c:1060 [inline]
 ffff8880765e7930 (sk_lock-AF_UNIX){+.+.}-{0:0}, at: sk_setsockopt+0xe52/0x3360 net/core/sock.c:1193&lt;/p&gt;
&lt;p&gt;which lock already depends on the new lock.&lt;/p&gt;
&lt;p&gt;the existing dependency chain (in reverse order) is:&lt;/p&gt;
&lt;p&gt;-&amp;gt; #1 (sk_lock-AF_UNIX){+.+.}-{0:0}:…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-q4jh-g383-rjcg</guid>
    </item>
    <item>
      <title>gsd-2024-26732</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2024-26732</link>
      <description>gsd-2024-26732</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2024-26732</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2024-26732</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-26732</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 56 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: net: implement lockless setsockopt(SO_PEEK_OFF) syzbot reported a lockdep violation [1] involving af_unix support of SO_PEEK_OFF. Since SO_PEEK_OFF is inherently not thread safe (it uses a per-socket sk_peek_off field), there is really no point to enforce a pointless thread safety in the kernel. After this patch : - setsockopt(SO_PEEK_OFF) no longer acquires the socket lock. - skb_consume_udp() no longer has to acquire the socket lock. - af_unix no longer needs a special version of sk_set_peek_off(),   because it does not lock u-&amp;gt;iolock anymore. As a followup, we could replace prot-&amp;gt;set_peek_off to be a boolean and avoid an indirect call, since we always use sk_set_peek_off(). [1] WARNING: possible circular locking dependency detected 6.8.0-rc4-syzkaller-00267-g0f1dd5e91e2b #0 Not tainted syz-executor.2/30025 is trying to acquire lock:  ffff8880765e7d80 (&amp;amp;u-&amp;gt;iolock){+.+.}-{3:3}, at: unix_set_peek_off+0x26/0xa0 net/unix/af_unix.c:789 but task is already holding lock:  ffff8880765e7930 (sk_lock-AF_UNIX){+.+.}-{0:0}, at: lock_sock include/net/sock.h:1691 [inline]  ffff8880765e7930 (sk_lock-AF_UNIX){+.+.}-{0:0}, at: sockopt_lock_sock net/core/sock.c:1060 [inline]  ffff8880765e7930 (sk_lock-AF_UNIX){+.+.}-{0:0}, at: sk_setsockopt+0xe52/0x3360 net/core/sock.c:1193 which lock already depends on the new lock. the existing dependency chain (in reverse order) is: -&amp;gt; #1 (sk_lock-AF_UNIX){+.+.}-{0:0}:         lock_acqui…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 56 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: net: implement lockless setsockopt(SO_PEEK_OFF) syzbot reported a lockdep violation [1] involving af_unix support of SO_PEEK_OFF. Since SO_PEEK_OFF is inherently not thread safe (it uses a per-socket sk_peek_off field), there is really no point to enforce a pointless thread safety in the kernel. After this patch : - setsockopt(SO_PEEK_OFF) no longer acquires the socket lock. - skb_consume_udp() no longer has to acquire the socket lock. - af_unix no longer needs a special version of sk_set_peek_off(),   because it does not lock u-&amp;gt;iolock anymore. As a followup, we could replace prot-&amp;gt;set_peek_off to be a boolean and avoid an indirect call, since we always use sk_set_peek_off(). [1] WARNING: possible circular locking dependency detected 6.8.0-rc4-syzkaller-00267-g0f1dd5e91e2b #0 Not tainted syz-executor.2/30025 is trying to acquire lock:  ffff8880765e7d80 (&amp;amp;u-&amp;gt;iolock){+.+.}-{3:3}, at: unix_set_peek_off+0x26/0xa0 net/unix/af_unix.c:789 but task is already holding lock:  ffff8880765e7930 (sk_lock-AF_UNIX){+.+.}-{0:0}, at: lock_sock include/net/sock.h:1691 [inline]  ffff8880765e7930 (sk_lock-AF_UNIX){+.+.}-{0:0}, at: sockopt_lock_sock net/core/sock.c:1060 [inline]  ffff8880765e7930 (sk_lock-AF_UNIX){+.+.}-{0:0}, at: sk_setsockopt+0xe52/0x3360 net/core/sock.c:1193 which lock already depends on the new lock. the existing dependency chain (in reverse order) is: -&amp;gt; #1 (sk_lock-AF_UNIX){+.+.}-{0:0}:         lock_acqui…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-26732</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-0773 — Linux Kernel: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0773</link>
      <description>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen, seine Privilegien eskalieren oder einen nicht näher spezifizierten Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen, seine Privilegien eskalieren oder einen nicht näher spezifizierten Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0773</guid>
    </item>
  </channel>
</rss>
