<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 01:56:49 +0000</lastBuildDate>
    <item>
      <title>bdu:2024-08637</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2024-08637</link>
      <description>bdu:2024-08637</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2024-08637</guid>
    </item>
    <item>
      <title>BELL-CVE-2024-26741</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2024-26741</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2024-26741</guid>
    </item>
    <item>
      <title>certfr-2024-avi-0334 — De multiples vulnérabilités ont été découvertes dans &lt;span
class="textit"&gt;le noyau Linux de Debian&lt;/span&gt;. Elles permet…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0334</link>
      <description>certfr-2024-avi-0334</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2024-avi-0334</guid>
    </item>
    <item>
      <title>EUVD-2026-312581</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-312581</link>
      <description>EUVD-2026-312581</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-312581</guid>
    </item>
    <item>
      <title>fkie_cve-2024-26741</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-26741</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;dccp/tcp: Unhash sk from ehash for tb2 alloc failure after check_estalblished().&lt;/p&gt;
&lt;p&gt;syzkaller reported a warning [0] in inet_csk_destroy_sock() with no
repro.&lt;/p&gt;
&lt;p&gt;WARN_ON(inet_sk(sk)-&amp;gt;inet_num &amp;amp;&amp;amp; !inet_csk(sk)-&amp;gt;icsk_bind_hash);&lt;/p&gt;
&lt;p&gt;However, the syzkaller&amp;#39;s log hinted that connect() failed just before
the warning due to FAULT_INJECTION.  [1]&lt;/p&gt;
&lt;p&gt;When connect() is called for an unbound socket, we search for an
available ephemeral port.  If a bhash bucket exists for the port, we
call __inet_check_established() or __inet6_check_established() to check
if the bucket is reusable.&lt;/p&gt;
&lt;p&gt;If reusable, we add the socket into ehash and set inet_sk(sk)-&amp;gt;inet_num.&lt;/p&gt;
&lt;p&gt;Later, we look up the corresponding bhash2 bucket and try to allocate
it if it does not exist.&lt;/p&gt;
&lt;p&gt;Although it rarely occurs in real use, if the allocation fails, we must
revert the changes by check_established().  Otherwise, an unconnected
socket could illegally occupy an ehash entry.&lt;/p&gt;
&lt;p&gt;Note that we do not put tw back into ehash because sk might have
already responded to a packet for tw and it would be better to free
tw earlier under such memory presure.&lt;/p&gt;
&lt;p&gt;[0]:
WARNING: CPU: 0 PID: 350830 at net/ipv4/inet_connection_sock.c:1193 inet_csk_destroy_sock (net/ipv4/inet_connection_sock.c:1193)
Modules linked in:
Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.0-0-gd239552ce722-prebuilt.qemu.org 04/01/2014
RIP: 0010:inet_csk_destroy_sock (net/ipv4/inet_connection_…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;dccp/tcp: Unhash sk from ehash for tb2 alloc failure after check_estalblished().&lt;/p&gt;
&lt;p&gt;syzkaller reported a warning [0] in inet_csk_destroy_sock() with no
repro.&lt;/p&gt;
&lt;p&gt;WARN_ON(inet_sk(sk)-&amp;gt;inet_num &amp;amp;&amp;amp; !inet_csk(sk)-&amp;gt;icsk_bind_hash);&lt;/p&gt;
&lt;p&gt;However, the syzkaller&amp;#39;s log hinted that connect() failed just before
the warning due to FAULT_INJECTION.  [1]&lt;/p&gt;
&lt;p&gt;When connect() is called for an unbound socket, we search for an
available ephemeral port.  If a bhash bucket exists for the port, we
call __inet_check_established() or __inet6_check_established() to check
if the bucket is reusable.&lt;/p&gt;
&lt;p&gt;If reusable, we add the socket into ehash and set inet_sk(sk)-&amp;gt;inet_num.&lt;/p&gt;
&lt;p&gt;Later, we look up the corresponding bhash2 bucket and try to allocate
it if it does not exist.&lt;/p&gt;
&lt;p&gt;Although it rarely occurs in real use, if the allocation fails, we must
revert the changes by check_established().  Otherwise, an unconnected
socket could illegally occupy an ehash entry.&lt;/p&gt;
&lt;p&gt;Note that we do not put tw back into ehash because sk might have
already responded to a packet for tw and it would be better to free
tw earlier under such memory presure.&lt;/p&gt;
&lt;p&gt;[0]:
WARNING: CPU: 0 PID: 350830 at net/ipv4/inet_connection_sock.c:1193 inet_csk_destroy_sock (net/ipv4/inet_connection_sock.c:1193)
Modules linked in:
Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.0-0-gd239552ce722-prebuilt.qemu.org 04/01/2014
RIP: 0010:inet_csk_destroy_sock (net/ipv4/inet_connection_…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-26741</guid>
    </item>
    <item>
      <title>GHSA-x4x7-9mj3-h6gw</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-x4x7-9mj3-h6gw</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;dccp/tcp: Unhash sk from ehash for tb2 alloc failure after check_estalblished().&lt;/p&gt;
&lt;p&gt;syzkaller reported a warning [0] in inet_csk_destroy_sock() with no
repro.&lt;/p&gt;
&lt;p&gt;WARN_ON(inet_sk(sk)-&amp;gt;inet_num &amp;amp;&amp;amp; !inet_csk(sk)-&amp;gt;icsk_bind_hash);&lt;/p&gt;
&lt;p&gt;However, the syzkaller&amp;#39;s log hinted that connect() failed just before
the warning due to FAULT_INJECTION.  [1]&lt;/p&gt;
&lt;p&gt;When connect() is called for an unbound socket, we search for an
available ephemeral port.  If a bhash bucket exists for the port, we
call __inet_check_established() or __inet6_check_established() to check
if the bucket is reusable.&lt;/p&gt;
&lt;p&gt;If reusable, we add the socket into ehash and set inet_sk(sk)-&amp;gt;inet_num.&lt;/p&gt;
&lt;p&gt;Later, we look up the corresponding bhash2 bucket and try to allocate
it if it does not exist.&lt;/p&gt;
&lt;p&gt;Although it rarely occurs in real use, if the allocation fails, we must
revert the changes by check_established().  Otherwise, an unconnected
socket could illegally occupy an ehash entry.&lt;/p&gt;
&lt;p&gt;Note that we do not put tw back into ehash because sk might have
already responded to a packet for tw and it would be better to free
tw earlier under such memory presure.&lt;/p&gt;
&lt;p&gt;[0]:
WARNING: CPU: 0 PID: 350830 at net/ipv4/inet_connection_sock.c:1193 inet_csk_destroy_sock (net/ipv4/inet_connection_sock.c:1193)
Modules linked in:
Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.0-0-gd239552ce722-prebuilt.qemu.org 04/01/2014
RIP: 0010:inet_csk_destroy_sock (net/ipv4/inet_connection_…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;dccp/tcp: Unhash sk from ehash for tb2 alloc failure after check_estalblished().&lt;/p&gt;
&lt;p&gt;syzkaller reported a warning [0] in inet_csk_destroy_sock() with no
repro.&lt;/p&gt;
&lt;p&gt;WARN_ON(inet_sk(sk)-&amp;gt;inet_num &amp;amp;&amp;amp; !inet_csk(sk)-&amp;gt;icsk_bind_hash);&lt;/p&gt;
&lt;p&gt;However, the syzkaller&amp;#39;s log hinted that connect() failed just before
the warning due to FAULT_INJECTION.  [1]&lt;/p&gt;
&lt;p&gt;When connect() is called for an unbound socket, we search for an
available ephemeral port.  If a bhash bucket exists for the port, we
call __inet_check_established() or __inet6_check_established() to check
if the bucket is reusable.&lt;/p&gt;
&lt;p&gt;If reusable, we add the socket into ehash and set inet_sk(sk)-&amp;gt;inet_num.&lt;/p&gt;
&lt;p&gt;Later, we look up the corresponding bhash2 bucket and try to allocate
it if it does not exist.&lt;/p&gt;
&lt;p&gt;Although it rarely occurs in real use, if the allocation fails, we must
revert the changes by check_established().  Otherwise, an unconnected
socket could illegally occupy an ehash entry.&lt;/p&gt;
&lt;p&gt;Note that we do not put tw back into ehash because sk might have
already responded to a packet for tw and it would be better to free
tw earlier under such memory presure.&lt;/p&gt;
&lt;p&gt;[0]:
WARNING: CPU: 0 PID: 350830 at net/ipv4/inet_connection_sock.c:1193 inet_csk_destroy_sock (net/ipv4/inet_connection_sock.c:1193)
Modules linked in:
Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.0-0-gd239552ce722-prebuilt.qemu.org 04/01/2014
RIP: 0010:inet_csk_destroy_sock (net/ipv4/inet_connection_…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-x4x7-9mj3-h6gw</guid>
    </item>
    <item>
      <title>gsd-2024-26741</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2024-26741</link>
      <description>gsd-2024-26741</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2024-26741</guid>
    </item>
    <item>
      <title>SUSE-SU-2024:4314-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2024:4314-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2024:4314-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2024-26741</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-26741</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 66 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: dccp/tcp: Unhash sk from ehash for tb2 alloc failure after check_estalblished(). syzkaller reported a warning [0] in inet_csk_destroy_sock() with no repro.   WARN_ON(inet_sk(sk)-&amp;gt;inet_num &amp;amp;&amp;amp; !inet_csk(sk)-&amp;gt;icsk_bind_hash); However, the syzkaller&amp;#39;s log hinted that connect() failed just before the warning due to FAULT_INJECTION.  [1] When connect() is called for an unbound socket, we search for an available ephemeral port.  If a bhash bucket exists for the port, we call __inet_check_established() or __inet6_check_established() to check if the bucket is reusable. If reusable, we add the socket into ehash and set inet_sk(sk)-&amp;gt;inet_num. Later, we look up the corresponding bhash2 bucket and try to allocate it if it does not exist. Although it rarely occurs in real use, if the allocation fails, we must revert the changes by check_established().  Otherwise, an unconnected socket could illegally occupy an ehash entry. Note that we do not put tw back into ehash because sk might have already responded to a packet for tw and it would be better to free tw earlier under such memory presure. [0]: WARNING: CPU: 0 PID: 350830 at net/ipv4/inet_connection_sock.c:1193 inet_csk_destroy_sock (net/ipv4/inet_connection_sock.c:1193) Modules linked in: Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.0-0-gd239552ce722-prebuilt.qemu.org 04/01/2014 RIP: 0010:inet_csk_destroy_sock (net/ipv4/inet_connection_sock.c:119…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 66 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: dccp/tcp: Unhash sk from ehash for tb2 alloc failure after check_estalblished(). syzkaller reported a warning [0] in inet_csk_destroy_sock() with no repro.   WARN_ON(inet_sk(sk)-&amp;gt;inet_num &amp;amp;&amp;amp; !inet_csk(sk)-&amp;gt;icsk_bind_hash); However, the syzkaller&amp;#39;s log hinted that connect() failed just before the warning due to FAULT_INJECTION.  [1] When connect() is called for an unbound socket, we search for an available ephemeral port.  If a bhash bucket exists for the port, we call __inet_check_established() or __inet6_check_established() to check if the bucket is reusable. If reusable, we add the socket into ehash and set inet_sk(sk)-&amp;gt;inet_num. Later, we look up the corresponding bhash2 bucket and try to allocate it if it does not exist. Although it rarely occurs in real use, if the allocation fails, we must revert the changes by check_established().  Otherwise, an unconnected socket could illegally occupy an ehash entry. Note that we do not put tw back into ehash because sk might have already responded to a packet for tw and it would be better to free tw earlier under such memory presure. [0]: WARNING: CPU: 0 PID: 350830 at net/ipv4/inet_connection_sock.c:1193 inet_csk_destroy_sock (net/ipv4/inet_connection_sock.c:1193) Modules linked in: Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.0-0-gd239552ce722-prebuilt.qemu.org 04/01/2014 RIP: 0010:inet_csk_destroy_sock (net/ipv4/inet_connection_sock.c:119…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-26741</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-0773 — Linux Kernel: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0773</link>
      <description>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen, seine Privilegien eskalieren oder einen nicht näher spezifizierten Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen, seine Privilegien eskalieren oder einen nicht näher spezifizierten Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0773</guid>
    </item>
  </channel>
</rss>
