<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 20:18:28 +0000</lastBuildDate>
    <item>
      <title>ALSA-2024:4211 — Important: kernel security and bug fix update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2024:4211</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: bpftool, AlmaLinux:8: kernel, AlmaLinux:8: kernel-abi-stablelists, AlmaLinux:8: kernel-core, AlmaLinux:8: kernel-cross-headers, AlmaLinux:8: kernel-debug, AlmaLinux:8: kernel-debug-core, AlmaLinux:8: kernel-debug-devel, AlmaLinux:8: kernel-debug-modules, AlmaLinux:8: kernel-debug-modules-extra and 15 more&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: Bluetooth BR/EDR PIN Pairing procedure is vulnerable to an impersonation attack (CVE-2020-26555)
* kernel:TCP-spoofed ghost ACKs and leak leak initial sequence number (CVE-2023-52881,RHV-2024-1001)
* kernel: ovl: fix leaked dentry (CVE-2021-46972)
* kernel: platform/x86: dell-smbios-wmi: Fix oops on rmmod dell_smbios (CVE-2021-47073)
* kernel: mm/damon/vaddr-test: memory leak in damon_do_test_apply_three_regions() (CVE-2023-52560)
* kernel: ppp_async: limit MRU to 64K (CVE-2024-26675)
* kernel: mm/swap: fix race when skipping swapcache (CVE-2024-26759)
* kernel: net: ip_tunnel: prevent perpetual headroom growth (CVE-2024-26804)
* kernel: RDMA/mlx5: Fix fortify source warning while accessing Eth segment (CVE-2024-26907)
* kernel: x86/mm: Disallow vsyscall page read for copy_from_kernel_nofault() (CVE-2024-26906)
* kernel: powerpc/powernv: Add a null pointer check in opal_event_init() (CVE-2023-52686)
* kernel: powerpc/imc-pmu: Add a null pointer check in update_events_in_group() (CVE-2023-52675)
* kernel: KVM: SVM: improper check in svm_set_x2apic_msr_interception allows direct access to host x2apic msrs (CVE-2023-5090)
* kernel: EDAC/thunderx: Incorrect buffer size in drivers/edac/thunderx_edac.c (CVE-2023-52464)
* kernel: ipv6: sr: fix possible use-after-free and null-ptr-deref (CVE-2024-26735)
* kernel: mptcp: fix data re-injection from stale subflow (CVE-202…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: bpftool, AlmaLinux:8: kernel, AlmaLinux:8: kernel-abi-stablelists, AlmaLinux:8: kernel-core, AlmaLinux:8: kernel-cross-headers, AlmaLinux:8: kernel-debug, AlmaLinux:8: kernel-debug-core, AlmaLinux:8: kernel-debug-devel, AlmaLinux:8: kernel-debug-modules, AlmaLinux:8: kernel-debug-modules-extra and 15 more&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: Bluetooth BR/EDR PIN Pairing procedure is vulnerable to an impersonation attack (CVE-2020-26555)
* kernel:TCP-spoofed ghost ACKs and leak leak initial sequence number (CVE-2023-52881,RHV-2024-1001)
* kernel: ovl: fix leaked dentry (CVE-2021-46972)
* kernel: platform/x86: dell-smbios-wmi: Fix oops on rmmod dell_smbios (CVE-2021-47073)
* kernel: mm/damon/vaddr-test: memory leak in damon_do_test_apply_three_regions() (CVE-2023-52560)
* kernel: ppp_async: limit MRU to 64K (CVE-2024-26675)
* kernel: mm/swap: fix race when skipping swapcache (CVE-2024-26759)
* kernel: net: ip_tunnel: prevent perpetual headroom growth (CVE-2024-26804)
* kernel: RDMA/mlx5: Fix fortify source warning while accessing Eth segment (CVE-2024-26907)
* kernel: x86/mm: Disallow vsyscall page read for copy_from_kernel_nofault() (CVE-2024-26906)
* kernel: powerpc/powernv: Add a null pointer check in opal_event_init() (CVE-2023-52686)
* kernel: powerpc/imc-pmu: Add a null pointer check in update_events_in_group() (CVE-2023-52675)
* kernel: KVM: SVM: improper check in svm_set_x2apic_msr_interception allows direct access to host x2apic msrs (CVE-2023-5090)
* kernel: EDAC/thunderx: Incorrect buffer size in drivers/edac/thunderx_edac.c (CVE-2023-52464)
* kernel: ipv6: sr: fix possible use-after-free and null-ptr-deref (CVE-2024-26735)
* kernel: mptcp: fix data re-injection from stale subflow (CVE-202…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2024:4211</guid>
    </item>
    <item>
      <title>bdu:2025-13311</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-13311</link>
      <description>bdu:2025-13311</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-13311</guid>
    </item>
    <item>
      <title>BELL-CVE-2024-26759</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2024-26759</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2024-26759</guid>
    </item>
    <item>
      <title>certfr-2024-avi-0334 — De multiples vulnérabilités ont été découvertes dans &lt;span
class="textit"&gt;le noyau Linux de Debian&lt;/span&gt;. Elles permet…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0334</link>
      <description>certfr-2024-avi-0334</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2024-avi-0334</guid>
    </item>
    <item>
      <title>EUVD-2026-345502</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-345502</link>
      <description>EUVD-2026-345502</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-345502</guid>
    </item>
    <item>
      <title>fkie_cve-2024-26759</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-26759</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;mm/swap: fix race when skipping swapcache&lt;/p&gt;
&lt;p&gt;When skipping swapcache for SWP_SYNCHRONOUS_IO, if two or more threads
swapin the same entry at the same time, they get different pages (A, B). 
Before one thread (T0) finishes the swapin and installs page (A) to the
PTE, another thread (T1) could finish swapin of page (B), swap_free the
entry, then swap out the possibly modified page reusing the same entry. 
It breaks the pte_same check in (T0) because PTE value is unchanged,
causing ABA problem.  Thread (T0) will install a stalled page (A) into the
PTE and cause data corruption.&lt;/p&gt;
&lt;p&gt;One possible callstack is like this:&lt;/p&gt;
&lt;p&gt;CPU0                                 CPU1
----                                 ----
do_swap_page()                       do_swap_page() with same entry
&amp;lt;direct swapin path&amp;gt;                 &amp;lt;direct swapin path&amp;gt;
&amp;lt;alloc page A&amp;gt;                       &amp;lt;alloc page B&amp;gt;
swap_read_folio() &amp;lt;- read to page A  swap_read_folio() &amp;lt;- read to page B
&amp;lt;slow on later locks or interrupt&amp;gt;   &amp;lt;finished swapin first&amp;gt;
...                                  set_pte_at()
                                     swap_free() &amp;lt;- entry is free
                                     &amp;lt;write to page B, now page A stalled&amp;gt;
                                     &amp;lt;swap out page B to same swap entry&amp;gt;
pte_same() &amp;lt;- Check pass, PTE seems
              unchanged, but page A
              is stalled!
swap_free() &amp;lt;- page B content lost!
set_pte_at() &amp;lt;-…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;mm/swap: fix race when skipping swapcache&lt;/p&gt;
&lt;p&gt;When skipping swapcache for SWP_SYNCHRONOUS_IO, if two or more threads
swapin the same entry at the same time, they get different pages (A, B). 
Before one thread (T0) finishes the swapin and installs page (A) to the
PTE, another thread (T1) could finish swapin of page (B), swap_free the
entry, then swap out the possibly modified page reusing the same entry. 
It breaks the pte_same check in (T0) because PTE value is unchanged,
causing ABA problem.  Thread (T0) will install a stalled page (A) into the
PTE and cause data corruption.&lt;/p&gt;
&lt;p&gt;One possible callstack is like this:&lt;/p&gt;
&lt;p&gt;CPU0                                 CPU1
----                                 ----
do_swap_page()                       do_swap_page() with same entry
&amp;lt;direct swapin path&amp;gt;                 &amp;lt;direct swapin path&amp;gt;
&amp;lt;alloc page A&amp;gt;                       &amp;lt;alloc page B&amp;gt;
swap_read_folio() &amp;lt;- read to page A  swap_read_folio() &amp;lt;- read to page B
&amp;lt;slow on later locks or interrupt&amp;gt;   &amp;lt;finished swapin first&amp;gt;
...                                  set_pte_at()
                                     swap_free() &amp;lt;- entry is free
                                     &amp;lt;write to page B, now page A stalled&amp;gt;
                                     &amp;lt;swap out page B to same swap entry&amp;gt;
pte_same() &amp;lt;- Check pass, PTE seems
              unchanged, but page A
              is stalled!
swap_free() &amp;lt;- page B content lost!
set_pte_at() &amp;lt;-…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-26759</guid>
    </item>
    <item>
      <title>GHSA-p22p-8399-qrmf</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-p22p-8399-qrmf</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;mm/swap: fix race when skipping swapcache&lt;/p&gt;
&lt;p&gt;When skipping swapcache for SWP_SYNCHRONOUS_IO, if two or more threads
swapin the same entry at the same time, they get different pages (A, B). 
Before one thread (T0) finishes the swapin and installs page (A) to the
PTE, another thread (T1) could finish swapin of page (B), swap_free the
entry, then swap out the possibly modified page reusing the same entry. 
It breaks the pte_same check in (T0) because PTE value is unchanged,
causing ABA problem.  Thread (T0) will install a stalled page (A) into the
PTE and cause data corruption.&lt;/p&gt;
&lt;p&gt;One possible callstack is like this:&lt;/p&gt;
&lt;p&gt;CPU0                                 CPU1
----                                 ----
do_swap_page()                       do_swap_page() with same entry
&amp;lt;direct swapin path&amp;gt;                 &amp;lt;direct swapin path&amp;gt;
&amp;lt;alloc page A&amp;gt;                       &amp;lt;alloc page B&amp;gt;
swap_read_folio() &amp;lt;- read to page A  swap_read_folio() &amp;lt;- read to page B
&amp;lt;slow on later locks or interrupt&amp;gt;   &amp;lt;finished swapin first&amp;gt;
...                                  set_pte_at()
                                     swap_free() &amp;lt;- entry is free
                                     &amp;lt;write to page B, now page A stalled&amp;gt;
                                     &amp;lt;swap out page B to same swap entry&amp;gt;
pte_same() &amp;lt;- Check pass, PTE seems
              unchanged, but page A
              is stalled!
swap_free() &amp;lt;- page B content lost!
set_pte_at() &amp;lt;-…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;mm/swap: fix race when skipping swapcache&lt;/p&gt;
&lt;p&gt;When skipping swapcache for SWP_SYNCHRONOUS_IO, if two or more threads
swapin the same entry at the same time, they get different pages (A, B). 
Before one thread (T0) finishes the swapin and installs page (A) to the
PTE, another thread (T1) could finish swapin of page (B), swap_free the
entry, then swap out the possibly modified page reusing the same entry. 
It breaks the pte_same check in (T0) because PTE value is unchanged,
causing ABA problem.  Thread (T0) will install a stalled page (A) into the
PTE and cause data corruption.&lt;/p&gt;
&lt;p&gt;One possible callstack is like this:&lt;/p&gt;
&lt;p&gt;CPU0                                 CPU1
----                                 ----
do_swap_page()                       do_swap_page() with same entry
&amp;lt;direct swapin path&amp;gt;                 &amp;lt;direct swapin path&amp;gt;
&amp;lt;alloc page A&amp;gt;                       &amp;lt;alloc page B&amp;gt;
swap_read_folio() &amp;lt;- read to page A  swap_read_folio() &amp;lt;- read to page B
&amp;lt;slow on later locks or interrupt&amp;gt;   &amp;lt;finished swapin first&amp;gt;
...                                  set_pte_at()
                                     swap_free() &amp;lt;- entry is free
                                     &amp;lt;write to page B, now page A stalled&amp;gt;
                                     &amp;lt;swap out page B to same swap entry&amp;gt;
pte_same() &amp;lt;- Check pass, PTE seems
              unchanged, but page A
              is stalled!
swap_free() &amp;lt;- page B content lost!
set_pte_at() &amp;lt;-…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-p22p-8399-qrmf</guid>
    </item>
    <item>
      <title>gsd-2024-26759</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2024-26759</link>
      <description>gsd-2024-26759</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2024-26759</guid>
    </item>
    <item>
      <title>msrc_CVE-2024-26759 — mm/swap: fix race when skipping swapcache</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2024-26759</link>
      <description>msrc_CVE-2024-26759</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2024-26759</guid>
    </item>
    <item>
      <title>RHSA-2024:4211 — Red Hat Security Advisory: kernel security and bug fix update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2024:4211</link>
      <description>&lt;p&gt;kernel: Bluetooth BR/EDR PIN Pairing procedure is vulnerable to an impersonation attack kernel: PCI interrupt mapping cause oops kernel: ovl: fix leaked dentry kernel: ipc/mqueue, msg, sem: avoid relying on a stack reference past its expiry kernel: platform/x86: dell-smbios-wmi: Fix oops on rmmod dell_smbios kernel: net: cdc_eem: fix tx fixup skb leak kernel: net: ti: fix UAF in tlan_remove_one kernel: net: qcom/emac: fix UAF in emac_remove kernel: udf: Fix NULL pointer dereference in udf_symlink function kernel: mISDN: fix possible use-after-free in HFC_cleanup() kernel: can: peak_pci: peak_pci_remove(): fix UAF kernel: usbnet: sanity check for maxpacket kernel: block: null_blk: end timed out poll request kernel: KVM: SVM: improper check in svm_set_x2apic_msr_interception allows direct access to host x2apic msrs kernel: EDAC/thunderx: Incorrect buffer size in drivers/edac/thunderx_edac.c kernel: mm/damon/vaddr-test: memory leak in damon_do_test_apply_three_regions() kernel: hwrng: core - Fix page fault dead lock on mmap-ed hwrng kernel: net/mlx5e: Fix operation precedence bug in port timestamping napi_poll context kernel: net/mlx5e: fix a potential double-free in fs_any_create_groups kernel: crypto: s390/aes - Fix buffer overread in CTR mode kernel: powerpc/imc-pmu: Add a null pointer check in update_events_in_group() kernel: powerpc/powernv: Add a null pointer check in opal_event_init() kernel: tipc: fix kernel warning when sending SYN message kernel: net/usb: kalmia: Don&amp;amp;…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;kernel: Bluetooth BR/EDR PIN Pairing procedure is vulnerable to an impersonation attack kernel: PCI interrupt mapping cause oops kernel: ovl: fix leaked dentry kernel: ipc/mqueue, msg, sem: avoid relying on a stack reference past its expiry kernel: platform/x86: dell-smbios-wmi: Fix oops on rmmod dell_smbios kernel: net: cdc_eem: fix tx fixup skb leak kernel: net: ti: fix UAF in tlan_remove_one kernel: net: qcom/emac: fix UAF in emac_remove kernel: udf: Fix NULL pointer dereference in udf_symlink function kernel: mISDN: fix possible use-after-free in HFC_cleanup() kernel: can: peak_pci: peak_pci_remove(): fix UAF kernel: usbnet: sanity check for maxpacket kernel: block: null_blk: end timed out poll request kernel: KVM: SVM: improper check in svm_set_x2apic_msr_interception allows direct access to host x2apic msrs kernel: EDAC/thunderx: Incorrect buffer size in drivers/edac/thunderx_edac.c kernel: mm/damon/vaddr-test: memory leak in damon_do_test_apply_three_regions() kernel: hwrng: core - Fix page fault dead lock on mmap-ed hwrng kernel: net/mlx5e: Fix operation precedence bug in port timestamping napi_poll context kernel: net/mlx5e: fix a potential double-free in fs_any_create_groups kernel: crypto: s390/aes - Fix buffer overread in CTR mode kernel: powerpc/imc-pmu: Add a null pointer check in update_events_in_group() kernel: powerpc/powernv: Add a null pointer check in opal_event_init() kernel: tipc: fix kernel warning when sending SYN message kernel: net/usb: kalmia: Don&amp;amp;…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2024:4211</guid>
    </item>
    <item>
      <title>RHSA-2024:4352 — Red Hat Security Advisory: kernel-rt security and bug fix update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2024:4352</link>
      <description>&lt;p&gt;kernel: Bluetooth BR/EDR PIN Pairing procedure is vulnerable to an impersonation attack kernel: PCI interrupt mapping cause oops kernel: ovl: fix leaked dentry kernel: ipc/mqueue, msg, sem: avoid relying on a stack reference past its expiry kernel: platform/x86: dell-smbios-wmi: Fix oops on rmmod dell_smbios kernel: net: cdc_eem: fix tx fixup skb leak kernel: net: ti: fix UAF in tlan_remove_one kernel: net: qcom/emac: fix UAF in emac_remove kernel: udf: Fix NULL pointer dereference in udf_symlink function kernel: mISDN: fix possible use-after-free in HFC_cleanup() kernel: can: peak_pci: peak_pci_remove(): fix UAF kernel: usbnet: sanity check for maxpacket kernel: KVM: SVM: improper check in svm_set_x2apic_msr_interception allows direct access to host x2apic msrs kernel: EDAC/thunderx: Incorrect buffer size in drivers/edac/thunderx_edac.c kernel: mm/damon/vaddr-test: memory leak in damon_do_test_apply_three_regions() kernel: hwrng: core - Fix page fault dead lock on mmap-ed hwrng kernel: net/mlx5e: Fix operation precedence bug in port timestamping napi_poll context kernel: net/mlx5e: fix a potential double-free in fs_any_create_groups kernel: tipc: fix kernel warning when sending SYN message kernel: net/usb: kalmia: Don&amp;amp;#39;t pass act_len in usb_bulk_msg error path kernel: usb: config: fix iteration issue in &amp;amp;#39;usb_get_bos_descriptor()&amp;amp;#39; kernel: crypto: pcrypt - Fix hungtask for PADATA_RESET kernel: perf/core: Bail out early if the request AUX area is out of bound kernel…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;kernel: Bluetooth BR/EDR PIN Pairing procedure is vulnerable to an impersonation attack kernel: PCI interrupt mapping cause oops kernel: ovl: fix leaked dentry kernel: ipc/mqueue, msg, sem: avoid relying on a stack reference past its expiry kernel: platform/x86: dell-smbios-wmi: Fix oops on rmmod dell_smbios kernel: net: cdc_eem: fix tx fixup skb leak kernel: net: ti: fix UAF in tlan_remove_one kernel: net: qcom/emac: fix UAF in emac_remove kernel: udf: Fix NULL pointer dereference in udf_symlink function kernel: mISDN: fix possible use-after-free in HFC_cleanup() kernel: can: peak_pci: peak_pci_remove(): fix UAF kernel: usbnet: sanity check for maxpacket kernel: KVM: SVM: improper check in svm_set_x2apic_msr_interception allows direct access to host x2apic msrs kernel: EDAC/thunderx: Incorrect buffer size in drivers/edac/thunderx_edac.c kernel: mm/damon/vaddr-test: memory leak in damon_do_test_apply_three_regions() kernel: hwrng: core - Fix page fault dead lock on mmap-ed hwrng kernel: net/mlx5e: Fix operation precedence bug in port timestamping napi_poll context kernel: net/mlx5e: fix a potential double-free in fs_any_create_groups kernel: tipc: fix kernel warning when sending SYN message kernel: net/usb: kalmia: Don&amp;amp;#39;t pass act_len in usb_bulk_msg error path kernel: usb: config: fix iteration issue in &amp;amp;#39;usb_get_bos_descriptor()&amp;amp;#39; kernel: crypto: pcrypt - Fix hungtask for PADATA_RESET kernel: perf/core: Bail out early if the request AUX area is out of bound kernel…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2024:4352</guid>
    </item>
    <item>
      <title>SUSE-SU-2024:3551-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2024:3551-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2024:3551-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2024-26759</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-26759</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe, Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:Pro:16.04:LTS: linux-oracle, Ubuntu:Pro:18.04:LTS: linux, Ubuntu:Pro:18.04:LTS: linux-aws, Ubuntu:18.04:LTS: linux-aws-5.0 and 154 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: mm/swap: fix race when skipping swapcache When skipping swapcache for SWP_SYNCHRONOUS_IO, if two or more threads swapin the same entry at the same time, they get different pages (A, B). Before one thread (T0) finishes the swapin and installs page (A) to the PTE, another thread (T1) could finish swapin of page (B), swap_free the entry, then swap out the possibly modified page reusing the same entry. It breaks the pte_same check in (T0) because PTE value is unchanged, causing ABA problem.  Thread (T0) will install a stalled page (A) into the PTE and cause data corruption. One possible callstack is like this: CPU0                                 CPU1 ----                                 ---- do_swap_page()                       do_swap_page() with same entry &amp;lt;direct swapin path&amp;gt;                 &amp;lt;direct swapin path&amp;gt; &amp;lt;alloc page A&amp;gt;                       &amp;lt;alloc page B&amp;gt; swap_read_folio() &amp;lt;- read to page A  swap_read_folio() &amp;lt;- read to page B &amp;lt;slow on later locks or interrupt&amp;gt;   &amp;lt;finished swapin first&amp;gt; ...                                  set_pte_at()                                      swap_free() &amp;lt;- entry is free                                      &amp;lt;write to page B, now page A stalled&amp;gt;                                      &amp;lt;swap out page B to same swap entry&amp;gt; pte_same() &amp;lt;- Check pass, PTE seems               unchanged, but page A               is stalled! swap_free() &amp;lt;- page B content lost! set_pte_at() &amp;lt;- staled…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe, Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:Pro:16.04:LTS: linux-oracle, Ubuntu:Pro:18.04:LTS: linux, Ubuntu:Pro:18.04:LTS: linux-aws, Ubuntu:18.04:LTS: linux-aws-5.0 and 154 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: mm/swap: fix race when skipping swapcache When skipping swapcache for SWP_SYNCHRONOUS_IO, if two or more threads swapin the same entry at the same time, they get different pages (A, B). Before one thread (T0) finishes the swapin and installs page (A) to the PTE, another thread (T1) could finish swapin of page (B), swap_free the entry, then swap out the possibly modified page reusing the same entry. It breaks the pte_same check in (T0) because PTE value is unchanged, causing ABA problem.  Thread (T0) will install a stalled page (A) into the PTE and cause data corruption. One possible callstack is like this: CPU0                                 CPU1 ----                                 ---- do_swap_page()                       do_swap_page() with same entry &amp;lt;direct swapin path&amp;gt;                 &amp;lt;direct swapin path&amp;gt; &amp;lt;alloc page A&amp;gt;                       &amp;lt;alloc page B&amp;gt; swap_read_folio() &amp;lt;- read to page A  swap_read_folio() &amp;lt;- read to page B &amp;lt;slow on later locks or interrupt&amp;gt;   &amp;lt;finished swapin first&amp;gt; ...                                  set_pte_at()                                      swap_free() &amp;lt;- entry is free                                      &amp;lt;write to page B, now page A stalled&amp;gt;                                      &amp;lt;swap out page B to same swap entry&amp;gt; pte_same() &amp;lt;- Check pass, PTE seems               unchanged, but page A               is stalled! swap_free() &amp;lt;- page B content lost! set_pte_at() &amp;lt;- staled…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-26759</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-0773 — Linux Kernel: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0773</link>
      <description>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen, seine Privilegien eskalieren oder einen nicht näher spezifizierten Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen, seine Privilegien eskalieren oder einen nicht näher spezifizierten Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0773</guid>
    </item>
  </channel>
</rss>
