<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 13:34:56 +0000</lastBuildDate>
    <item>
      <title>ALSA-2024:5928 — Important: kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2024:5928</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: bpftool, AlmaLinux:9: kernel, AlmaLinux:9: kernel-64k, AlmaLinux:9: kernel-64k-core, AlmaLinux:9: kernel-64k-debug, AlmaLinux:9: kernel-64k-debug-core, AlmaLinux:9: kernel-64k-debug-devel, AlmaLinux:9: kernel-64k-debug-devel-matched, AlmaLinux:9: kernel-64k-debug-modules, AlmaLinux:9: kernel-64k-debug-modules-core and 52 more&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: nftables: nft_set_rbtree skip end interval element from gc (CVE-2024-26581)
  * kernel: netfilter: nft_limit: reject configurations that cause integer overflow (CVE-2024-26668)
  * kernel: vfio/pci: Lock external INTx masking ops (CVE-2024-26810)
  * kernel: net: ice: Fix potential NULL pointer dereference in ice_bridge_setlink() (CVE-2024-26855)
  * kernel: x86/xen: Add some null pointer checking to smp.c (CVE-2024-26908)
  * kernel: netfilter: nf_tables: release mutex after nft_gc_seq_end from abort path (CVE-2024-26925)
  * kernel: netfilter: nf_tables: Fix potential data-race in __nft_expr_type_get() (CVE-2024-27020)
  * kernel: netfilter: nf_tables: Fix potential data-race in __nft_obj_type_get() (CVE-2024-27019)
  * kernel: netfilter: flowtable: validate pppoe header (CVE-2024-27016)
  * kernel: netfilter: bridge: confirm multicast packets before passing them up the stack (CVE-2024-27415)
  * kernel: netfilter: bridge: replace physindev with physinif in nf_bridge_info (CVE-2024-35839)
  * kernel: netfilter: nf_tables: Fix potential data-race in __nft_flowtable_type_get() (CVE-2024-35898)
  * kernel: netfilter: nf_tables: discard table flag update with pending basechain deletion (CVE-2024-35897)
  * kernel: netfilter: validate user input for expected length (CVE-2024-35896)
  * kernel: netfilter: complete validation of user input (CVE-2024-35962)
  *…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: bpftool, AlmaLinux:9: kernel, AlmaLinux:9: kernel-64k, AlmaLinux:9: kernel-64k-core, AlmaLinux:9: kernel-64k-debug, AlmaLinux:9: kernel-64k-debug-core, AlmaLinux:9: kernel-64k-debug-devel, AlmaLinux:9: kernel-64k-debug-devel-matched, AlmaLinux:9: kernel-64k-debug-modules, AlmaLinux:9: kernel-64k-debug-modules-core and 52 more&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: nftables: nft_set_rbtree skip end interval element from gc (CVE-2024-26581)
  * kernel: netfilter: nft_limit: reject configurations that cause integer overflow (CVE-2024-26668)
  * kernel: vfio/pci: Lock external INTx masking ops (CVE-2024-26810)
  * kernel: net: ice: Fix potential NULL pointer dereference in ice_bridge_setlink() (CVE-2024-26855)
  * kernel: x86/xen: Add some null pointer checking to smp.c (CVE-2024-26908)
  * kernel: netfilter: nf_tables: release mutex after nft_gc_seq_end from abort path (CVE-2024-26925)
  * kernel: netfilter: nf_tables: Fix potential data-race in __nft_expr_type_get() (CVE-2024-27020)
  * kernel: netfilter: nf_tables: Fix potential data-race in __nft_obj_type_get() (CVE-2024-27019)
  * kernel: netfilter: flowtable: validate pppoe header (CVE-2024-27016)
  * kernel: netfilter: bridge: confirm multicast packets before passing them up the stack (CVE-2024-27415)
  * kernel: netfilter: bridge: replace physindev with physinif in nf_bridge_info (CVE-2024-35839)
  * kernel: netfilter: nf_tables: Fix potential data-race in __nft_flowtable_type_get() (CVE-2024-35898)
  * kernel: netfilter: nf_tables: discard table flag update with pending basechain deletion (CVE-2024-35897)
  * kernel: netfilter: validate user input for expected length (CVE-2024-35896)
  * kernel: netfilter: complete validation of user input (CVE-2024-35962)
  *…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2024:5928</guid>
    </item>
    <item>
      <title>bdu:2024-09994</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2024-09994</link>
      <description>bdu:2024-09994</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2024-09994</guid>
    </item>
    <item>
      <title>BELL-CVE-2024-27415</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2024-27415</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2024-27415</guid>
    </item>
    <item>
      <title>certfr-2024-avi-0546 — De multiples vulnérabilités ont été découvertes dans le noyau Linux d'Ubuntu. Certaines d'entre elles permettent à un a…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0546</link>
      <description>certfr-2024-avi-0546</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2024-avi-0546</guid>
    </item>
    <item>
      <title>EUVD-2026-345641</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-345641</link>
      <description>EUVD-2026-345641</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-345641</guid>
    </item>
    <item>
      <title>fkie_cve-2024-27415</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-27415</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;netfilter: bridge: confirm multicast packets before passing them up the stack&lt;/p&gt;
&lt;p&gt;conntrack nf_confirm logic cannot handle cloned skbs referencing
the same nf_conn entry, which will happen for multicast (broadcast)
frames on bridges.&lt;/p&gt;
&lt;p&gt;Example:
    macvlan0
       |
      br0
     /  \
  ethX    ethY&lt;/p&gt;
&lt;p&gt;ethX (or Y) receives a L2 multicast or broadcast packet containing
 an IP packet, flow is not yet in conntrack table.&lt;/p&gt;
&lt;p&gt;1. skb passes through bridge and fake-ip (br_netfilter)Prerouting.
    -&amp;gt; skb-&amp;gt;_nfct now references a unconfirmed entry
 2. skb is broad/mcast packet. bridge now passes clones out on each bridge
    interface.
 3. skb gets passed up the stack.
 4. In macvlan case, macvlan driver retains clone(s) of the mcast skb
    and schedules a work queue to send them out on the lower devices.&lt;/p&gt;
&lt;p&gt;The clone skb-&amp;gt;_nfct is not a copy, it is the same entry as the
    original skb.  The macvlan rx handler then returns RX_HANDLER_PASS.
 5. Normal conntrack hooks (in NF_INET_LOCAL_IN) confirm the orig skb.&lt;/p&gt;
&lt;p&gt;The Macvlan broadcast worker and normal confirm path will race.&lt;/p&gt;
&lt;p&gt;This race will not happen if step 2 already confirmed a clone. In that
case later steps perform skb_clone() with skb-&amp;gt;_nfct already confirmed (in
hash table).  This works fine.&lt;/p&gt;
&lt;p&gt;But such confirmation won&amp;#39;t happen when eb/ip/nftables rules dropped the
packets before they reached the nf_confirm step in postrouting.&lt;/p&gt;
&lt;p&gt;Pablo points out that nf_conntr…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;netfilter: bridge: confirm multicast packets before passing them up the stack&lt;/p&gt;
&lt;p&gt;conntrack nf_confirm logic cannot handle cloned skbs referencing
the same nf_conn entry, which will happen for multicast (broadcast)
frames on bridges.&lt;/p&gt;
&lt;p&gt;Example:
    macvlan0
       |
      br0
     /  \
  ethX    ethY&lt;/p&gt;
&lt;p&gt;ethX (or Y) receives a L2 multicast or broadcast packet containing
 an IP packet, flow is not yet in conntrack table.&lt;/p&gt;
&lt;p&gt;1. skb passes through bridge and fake-ip (br_netfilter)Prerouting.
    -&amp;gt; skb-&amp;gt;_nfct now references a unconfirmed entry
 2. skb is broad/mcast packet. bridge now passes clones out on each bridge
    interface.
 3. skb gets passed up the stack.
 4. In macvlan case, macvlan driver retains clone(s) of the mcast skb
    and schedules a work queue to send them out on the lower devices.&lt;/p&gt;
&lt;p&gt;The clone skb-&amp;gt;_nfct is not a copy, it is the same entry as the
    original skb.  The macvlan rx handler then returns RX_HANDLER_PASS.
 5. Normal conntrack hooks (in NF_INET_LOCAL_IN) confirm the orig skb.&lt;/p&gt;
&lt;p&gt;The Macvlan broadcast worker and normal confirm path will race.&lt;/p&gt;
&lt;p&gt;This race will not happen if step 2 already confirmed a clone. In that
case later steps perform skb_clone() with skb-&amp;gt;_nfct already confirmed (in
hash table).  This works fine.&lt;/p&gt;
&lt;p&gt;But such confirmation won&amp;#39;t happen when eb/ip/nftables rules dropped the
packets before they reached the nf_confirm step in postrouting.&lt;/p&gt;
&lt;p&gt;Pablo points out that nf_conntr…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-27415</guid>
    </item>
    <item>
      <title>GHSA-934r-h8mp-qw4r</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-934r-h8mp-qw4r</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;netfilter: bridge: confirm multicast packets before passing them up the stack&lt;/p&gt;
&lt;p&gt;conntrack nf_confirm logic cannot handle cloned skbs referencing
the same nf_conn entry, which will happen for multicast (broadcast)
frames on bridges.&lt;/p&gt;
&lt;p&gt;Example:
    macvlan0
       |
      br0
     /  \
  ethX    ethY&lt;/p&gt;
&lt;p&gt;ethX (or Y) receives a L2 multicast or broadcast packet containing
 an IP packet, flow is not yet in conntrack table.&lt;/p&gt;
&lt;p&gt;1. skb passes through bridge and fake-ip (br_netfilter)Prerouting.
    -&amp;gt; skb-&amp;gt;_nfct now references a unconfirmed entry
 2. skb is broad/mcast packet. bridge now passes clones out on each bridge
    interface.
 3. skb gets passed up the stack.
 4. In macvlan case, macvlan driver retains clone(s) of the mcast skb
    and schedules a work queue to send them out on the lower devices.&lt;/p&gt;
&lt;p&gt;The clone skb-&amp;gt;_nfct is not a copy, it is the same entry as the
    original skb.  The macvlan rx handler then returns RX_HANDLER_PASS.
 5. Normal conntrack hooks (in NF_INET_LOCAL_IN) confirm the orig skb.&lt;/p&gt;
&lt;p&gt;The Macvlan broadcast worker and normal confirm path will race.&lt;/p&gt;
&lt;p&gt;This race will not happen if step 2 already confirmed a clone. In that
case later steps perform skb_clone() with skb-&amp;gt;_nfct already confirmed (in
hash table).  This works fine.&lt;/p&gt;
&lt;p&gt;But such confirmation won&amp;#39;t happen when eb/ip/nftables rules dropped the
packets before they reached the nf_confirm step in postrouting.&lt;/p&gt;
&lt;p&gt;Pablo points out that nf_conntr…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;netfilter: bridge: confirm multicast packets before passing them up the stack&lt;/p&gt;
&lt;p&gt;conntrack nf_confirm logic cannot handle cloned skbs referencing
the same nf_conn entry, which will happen for multicast (broadcast)
frames on bridges.&lt;/p&gt;
&lt;p&gt;Example:
    macvlan0
       |
      br0
     /  \
  ethX    ethY&lt;/p&gt;
&lt;p&gt;ethX (or Y) receives a L2 multicast or broadcast packet containing
 an IP packet, flow is not yet in conntrack table.&lt;/p&gt;
&lt;p&gt;1. skb passes through bridge and fake-ip (br_netfilter)Prerouting.
    -&amp;gt; skb-&amp;gt;_nfct now references a unconfirmed entry
 2. skb is broad/mcast packet. bridge now passes clones out on each bridge
    interface.
 3. skb gets passed up the stack.
 4. In macvlan case, macvlan driver retains clone(s) of the mcast skb
    and schedules a work queue to send them out on the lower devices.&lt;/p&gt;
&lt;p&gt;The clone skb-&amp;gt;_nfct is not a copy, it is the same entry as the
    original skb.  The macvlan rx handler then returns RX_HANDLER_PASS.
 5. Normal conntrack hooks (in NF_INET_LOCAL_IN) confirm the orig skb.&lt;/p&gt;
&lt;p&gt;The Macvlan broadcast worker and normal confirm path will race.&lt;/p&gt;
&lt;p&gt;This race will not happen if step 2 already confirmed a clone. In that
case later steps perform skb_clone() with skb-&amp;gt;_nfct already confirmed (in
hash table).  This works fine.&lt;/p&gt;
&lt;p&gt;But such confirmation won&amp;#39;t happen when eb/ip/nftables rules dropped the
packets before they reached the nf_confirm step in postrouting.&lt;/p&gt;
&lt;p&gt;Pablo points out that nf_conntr…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-934r-h8mp-qw4r</guid>
    </item>
    <item>
      <title>gsd-2024-27415</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2024-27415</link>
      <description>gsd-2024-27415</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2024-27415</guid>
    </item>
    <item>
      <title>OESA-2024-1694 — kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2024-1694</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP3: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&#13;
&#13;
In the Linux kernel, the following vulnerability has been resolved:&#13;
&#13;
RDMA: Verify port when creating flow rule&#13;
&#13;
Validate port value provided by the user and with that remove no longer
needed validation by the driver.  The missing check in the mlx5_ib driver
could cause to the below oops.&#13;
&#13;
Call trace:
  _create_flow_rule+0x2d4/0xf28 [mlx5_ib]
  mlx5_ib_create_flow+0x2d0/0x5b0 [mlx5_ib]
  ib_uverbs_ex_create_flow+0x4cc/0x624 [ib_uverbs]
  ib_uverbs_handler_UVERBS_METHOD_INVOKE_WRITE+0xd4/0x150 [ib_uverbs]
  ib_uverbs_cmd_verbs.isra.7+0xb28/0xc50 [ib_uverbs]
  ib_uverbs_ioctl+0x158/0x1d0 [ib_uverbs]
  do_vfs_ioctl+0xd0/0xaf0
  ksys_ioctl+0x84/0xb4
  __arm64_sys_ioctl+0x28/0xc4
  el0_svc_common.constprop.3+0xa4/0x254
  el0_svc_handler+0x84/0xa0
  el0_svc+0x10/0x26c
 Code: b9401260 f9615681 51000400 8b001c20 (f9403c1a)(CVE-2021-47265)&#13;
&#13;
In the Linux kernel, the following vulnerability has been resolved:&#13;
&#13;
mISDN: fix possible use-after-free in HFC_cleanup()&#13;
&#13;
This module&amp;amp;apos;s remove path calls del_timer(). However, that function
does not wait until the timer handler finishes. This means that the
timer handler may still be running after the driver&amp;amp;apos;s remove function
has finished, which would result in a use-after-free.&#13;
&#13;
Fix by calling del_timer_sync(), which makes sure the timer handler
has finished, and unable to re-schedule itself.(CVE-2021-47356)&#13;
&#13;
In the Linux kernel, the following vul…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP3: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&#13;
&#13;
In the Linux kernel, the following vulnerability has been resolved:&#13;
&#13;
RDMA: Verify port when creating flow rule&#13;
&#13;
Validate port value provided by the user and with that remove no longer
needed validation by the driver.  The missing check in the mlx5_ib driver
could cause to the below oops.&#13;
&#13;
Call trace:
  _create_flow_rule+0x2d4/0xf28 [mlx5_ib]
  mlx5_ib_create_flow+0x2d0/0x5b0 [mlx5_ib]
  ib_uverbs_ex_create_flow+0x4cc/0x624 [ib_uverbs]
  ib_uverbs_handler_UVERBS_METHOD_INVOKE_WRITE+0xd4/0x150 [ib_uverbs]
  ib_uverbs_cmd_verbs.isra.7+0xb28/0xc50 [ib_uverbs]
  ib_uverbs_ioctl+0x158/0x1d0 [ib_uverbs]
  do_vfs_ioctl+0xd0/0xaf0
  ksys_ioctl+0x84/0xb4
  __arm64_sys_ioctl+0x28/0xc4
  el0_svc_common.constprop.3+0xa4/0x254
  el0_svc_handler+0x84/0xa0
  el0_svc+0x10/0x26c
 Code: b9401260 f9615681 51000400 8b001c20 (f9403c1a)(CVE-2021-47265)&#13;
&#13;
In the Linux kernel, the following vulnerability has been resolved:&#13;
&#13;
mISDN: fix possible use-after-free in HFC_cleanup()&#13;
&#13;
This module&amp;amp;apos;s remove path calls del_timer(). However, that function
does not wait until the timer handler finishes. This means that the
timer handler may still be running after the driver&amp;amp;apos;s remove function
has finished, which would result in a use-after-free.&#13;
&#13;
Fix by calling del_timer_sync(), which makes sure the timer handler
has finished, and unable to re-schedule itself.(CVE-2021-47356)&#13;
&#13;
In the Linux kernel, the following vul…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2024-1694</guid>
    </item>
    <item>
      <title>RHSA-2024:5928 — Red Hat Security Advisory: kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2024:5928</link>
      <description>&lt;p&gt;kernel: x86/xen: Fix memory leak in xen_smp_intr_init{_pv}() kernel: cxl/port: Fix delete_endpoint() vs parent unregistration race kernel: tty: n_gsm: require CAP_NET_ADMIN to attach N_GSM0710 ldisc kernel: nftables: nft_set_rbtree skip end interval element from gc kernel: netfilter: nft_limit: reject configurations that cause integer overflow kernel: vfio/pci: Lock external INTx masking ops kernel: net: ice: Fix potential NULL pointer dereference in ice_bridge_setlink() kernel: x86/xen: Add some null pointer checking to smp.c kernel: netfilter: nf_tables: release mutex after nft_gc_seq_end from abort path kernel: netfilter: flowtable: validate pppoe header kernel: netfilter: nf_tables: Fix potential data-race in __nft_obj_type_get() kernel: netfilter: nf_tables: Fix potential data-race in __nft_expr_type_get() kernel: netfilter: bridge: confirm multicast packets before passing them up the stack kernel: netfilter: bridge: replace physindev with physinif in nf_bridge_info kernel: netfilter: validate user input for expected length kernel: netfilter: nf_tables: discard table flag update with pending basechain deletion kernel: netfilter: nf_tables: Fix potential data-race in __nft_flowtable_type_get() kernel: netfilter: complete validation of user input kernel: ice: fix LAG and VF lock dependency in ice_reset_vf() kernel: scsi: qla2xxx: Fix off by one in qla_edif_app_getstats() kernel: net: bridge: xmit: make sure we have at least eth header len bytes kernel: bnxt_re: avoid shif…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;kernel: x86/xen: Fix memory leak in xen_smp_intr_init{_pv}() kernel: cxl/port: Fix delete_endpoint() vs parent unregistration race kernel: tty: n_gsm: require CAP_NET_ADMIN to attach N_GSM0710 ldisc kernel: nftables: nft_set_rbtree skip end interval element from gc kernel: netfilter: nft_limit: reject configurations that cause integer overflow kernel: vfio/pci: Lock external INTx masking ops kernel: net: ice: Fix potential NULL pointer dereference in ice_bridge_setlink() kernel: x86/xen: Add some null pointer checking to smp.c kernel: netfilter: nf_tables: release mutex after nft_gc_seq_end from abort path kernel: netfilter: flowtable: validate pppoe header kernel: netfilter: nf_tables: Fix potential data-race in __nft_obj_type_get() kernel: netfilter: nf_tables: Fix potential data-race in __nft_expr_type_get() kernel: netfilter: bridge: confirm multicast packets before passing them up the stack kernel: netfilter: bridge: replace physindev with physinif in nf_bridge_info kernel: netfilter: validate user input for expected length kernel: netfilter: nf_tables: discard table flag update with pending basechain deletion kernel: netfilter: nf_tables: Fix potential data-race in __nft_flowtable_type_get() kernel: netfilter: complete validation of user input kernel: ice: fix LAG and VF lock dependency in ice_reset_vf() kernel: scsi: qla2xxx: Fix off by one in qla_edif_app_getstats() kernel: net: bridge: xmit: make sure we have at least eth header len bytes kernel: bnxt_re: avoid shif…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2024:5928</guid>
    </item>
    <item>
      <title>RHSA-2024:7489 — Red Hat Security Advisory: kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2024:7489</link>
      <description>&lt;p&gt;kernel: netfilter: bridge: confirm multicast packets before passing them up the stack kernel: netfilter: tproxy: bail out if IP has been disabled on the device kernel: net: bridge: mst: fix vlan use-after-free kernel: net: openvswitch: fix overwriting ct original tuple for ICMPv6&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;kernel: netfilter: bridge: confirm multicast packets before passing them up the stack kernel: netfilter: tproxy: bail out if IP has been disabled on the device kernel: net: bridge: mst: fix vlan use-after-free kernel: net: openvswitch: fix overwriting ct original tuple for ICMPv6&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2024:7489</guid>
    </item>
    <item>
      <title>SUSE-SU-2025:01614-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2025:01614-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2025:01614-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2024-27415</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-27415</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux, Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe and 159 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: netfilter: bridge: confirm multicast packets before passing them up the stack conntrack nf_confirm logic cannot handle cloned skbs referencing the same nf_conn entry, which will happen for multicast (broadcast) frames on bridges.  Example:     macvlan0        |       br0      /  \   ethX    ethY  ethX (or Y) receives a L2 multicast or broadcast packet containing  an IP packet, flow is not yet in conntrack table.  1. skb passes through bridge and fake-ip (br_netfilter)Prerouting.     -&amp;gt; skb-&amp;gt;_nfct now references a unconfirmed entry  2. skb is broad/mcast packet. bridge now passes clones out on each bridge     interface.  3. skb gets passed up the stack.  4. In macvlan case, macvlan driver retains clone(s) of the mcast skb     and schedules a work queue to send them out on the lower devices.     The clone skb-&amp;gt;_nfct is not a copy, it is the same entry as the     original skb.  The macvlan rx handler then returns RX_HANDLER_PASS.  5. Normal conntrack hooks (in NF_INET_LOCAL_IN) confirm the orig skb. The Macvlan broadcast worker and normal confirm path will race. This race will not happen if step 2 already confirmed a clone. In that case later steps perform skb_clone() with skb-&amp;gt;_nfct already confirmed (in hash table).  This works fine. But such confirmation won&amp;#39;t happen when eb/ip/nftables rules dropped the packets before they reached the nf_confirm step in postrouting. Pablo points out that nf_conntrack_bridge…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux, Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe and 159 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: netfilter: bridge: confirm multicast packets before passing them up the stack conntrack nf_confirm logic cannot handle cloned skbs referencing the same nf_conn entry, which will happen for multicast (broadcast) frames on bridges.  Example:     macvlan0        |       br0      /  \   ethX    ethY  ethX (or Y) receives a L2 multicast or broadcast packet containing  an IP packet, flow is not yet in conntrack table.  1. skb passes through bridge and fake-ip (br_netfilter)Prerouting.     -&amp;gt; skb-&amp;gt;_nfct now references a unconfirmed entry  2. skb is broad/mcast packet. bridge now passes clones out on each bridge     interface.  3. skb gets passed up the stack.  4. In macvlan case, macvlan driver retains clone(s) of the mcast skb     and schedules a work queue to send them out on the lower devices.     The clone skb-&amp;gt;_nfct is not a copy, it is the same entry as the     original skb.  The macvlan rx handler then returns RX_HANDLER_PASS.  5. Normal conntrack hooks (in NF_INET_LOCAL_IN) confirm the orig skb. The Macvlan broadcast worker and normal confirm path will race. This race will not happen if step 2 already confirmed a clone. In that case later steps perform skb_clone() with skb-&amp;gt;_nfct already confirmed (in hash table).  This works fine. But such confirmation won&amp;#39;t happen when eb/ip/nftables rules dropped the packets before they reached the nf_confirm step in postrouting. Pablo points out that nf_conntrack_bridge…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-27415</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-1188 — Linux Kernel: Mehrere Schwachstellen ermöglichen Denial of Service</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1188</link>
      <description>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen in Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen in Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1188</guid>
    </item>
  </channel>
</rss>
