<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 01:49:50 +0000</lastBuildDate>
    <item>
      <title>ALSA-2024:6567 — Moderate: kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2024:6567</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: bpftool, AlmaLinux:9: kernel, AlmaLinux:9: kernel-64k, AlmaLinux:9: kernel-64k-core, AlmaLinux:9: kernel-64k-debug, AlmaLinux:9: kernel-64k-debug-core, AlmaLinux:9: kernel-64k-debug-devel, AlmaLinux:9: kernel-64k-debug-devel-matched, AlmaLinux:9: kernel-64k-debug-modules, AlmaLinux:9: kernel-64k-debug-modules-core and 52 more&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: efivarfs: force RO when remounting if SetVariable is not supported (CVE-2023-52463)
  * kernel: nfsd: fix RELEASE_LOCKOWNER (CVE-2024-26629)
  * kernel: mm: cachestat: fix folio read-after-free in cache walk (CVE-2024-26630)
  * kernel: mm/writeback: fix possible divide-by-zero in wb_dirty_limits(), again (CVE-2024-26720)
  * kernel: Bluetooth: af_bluetooth: Fix deadlock (CVE-2024-26886)
  * kernel: kprobes/x86: Use copy_from_kernel_nofault() to read from unsafe address (CVE-2024-26946)
  * kernel: KVM: SVM: Flush pages under kvm-&amp;amp;gt;lock to fix UAF in svm_register_enc_region() (CVE-2024-35791)
  * kernel: mm: cachestat: fix two shmem bugs (CVE-2024-35797)
  * kernel: x86/coco: Require seeding RNG with RDRAND on CoCo systems (CVE-2024-35875)
  * kernel: mm/hugetlb: fix missing hugetlb_lock for resv uncharge (CVE-2024-36000)
  * kernel: iommufd: Fix missing update of domains_itree after splitting iopt_area (CVE-2023-52801)
  * kernel: net: fix out-of-bounds access in ops_init (CVE-2024-36883)
  * kernel: regmap: maple: Fix cache corruption in regcache_maple_drop() (CVE-2024-36019)
  * kernel: usb-storage: alauda: Check whether the media is initialized (CVE-2024-38619)
  * kernel: net: bridge: mst: fix vlan use-after-free (CVE-2024-36979)
  * kernel: scsi: qedf: Ensure the copied buf is NUL terminated (CVE-2024-38559)
  * kernel: xhci: Handle TD clearing fo…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: bpftool, AlmaLinux:9: kernel, AlmaLinux:9: kernel-64k, AlmaLinux:9: kernel-64k-core, AlmaLinux:9: kernel-64k-debug, AlmaLinux:9: kernel-64k-debug-core, AlmaLinux:9: kernel-64k-debug-devel, AlmaLinux:9: kernel-64k-debug-devel-matched, AlmaLinux:9: kernel-64k-debug-modules, AlmaLinux:9: kernel-64k-debug-modules-core and 52 more&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: efivarfs: force RO when remounting if SetVariable is not supported (CVE-2023-52463)
  * kernel: nfsd: fix RELEASE_LOCKOWNER (CVE-2024-26629)
  * kernel: mm: cachestat: fix folio read-after-free in cache walk (CVE-2024-26630)
  * kernel: mm/writeback: fix possible divide-by-zero in wb_dirty_limits(), again (CVE-2024-26720)
  * kernel: Bluetooth: af_bluetooth: Fix deadlock (CVE-2024-26886)
  * kernel: kprobes/x86: Use copy_from_kernel_nofault() to read from unsafe address (CVE-2024-26946)
  * kernel: KVM: SVM: Flush pages under kvm-&amp;amp;gt;lock to fix UAF in svm_register_enc_region() (CVE-2024-35791)
  * kernel: mm: cachestat: fix two shmem bugs (CVE-2024-35797)
  * kernel: x86/coco: Require seeding RNG with RDRAND on CoCo systems (CVE-2024-35875)
  * kernel: mm/hugetlb: fix missing hugetlb_lock for resv uncharge (CVE-2024-36000)
  * kernel: iommufd: Fix missing update of domains_itree after splitting iopt_area (CVE-2023-52801)
  * kernel: net: fix out-of-bounds access in ops_init (CVE-2024-36883)
  * kernel: regmap: maple: Fix cache corruption in regcache_maple_drop() (CVE-2024-36019)
  * kernel: usb-storage: alauda: Check whether the media is initialized (CVE-2024-38619)
  * kernel: net: bridge: mst: fix vlan use-after-free (CVE-2024-36979)
  * kernel: scsi: qedf: Ensure the copied buf is NUL terminated (CVE-2024-38559)
  * kernel: xhci: Handle TD clearing fo…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2024:6567</guid>
    </item>
    <item>
      <title>bdu:2025-13354</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-13354</link>
      <description>bdu:2025-13354</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-13354</guid>
    </item>
    <item>
      <title>BELL-CVE-2024-35875</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2024-35875</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2024-35875</guid>
    </item>
    <item>
      <title>certfr-2024-avi-0496 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de SUSE. Certaines d'entre elles permettent à un at…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0496</link>
      <description>certfr-2024-avi-0496</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2024-avi-0496</guid>
    </item>
    <item>
      <title>EUVD-2026-345689</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-345689</link>
      <description>EUVD-2026-345689</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-345689</guid>
    </item>
    <item>
      <title>fkie_cve-2024-35875</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-35875</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;x86/coco: Require seeding RNG with RDRAND on CoCo systems&lt;/p&gt;
&lt;p&gt;There are few uses of CoCo that don&amp;#39;t rely on working cryptography and
hence a working RNG. Unfortunately, the CoCo threat model means that the
VM host cannot be trusted and may actively work against guests to
extract secrets or manipulate computation. Since a malicious host can
modify or observe nearly all inputs to guests, the only remaining source
of entropy for CoCo guests is RDRAND.&lt;/p&gt;
&lt;p&gt;If RDRAND is broken -- due to CPU hardware fault -- the RNG as a whole
is meant to gracefully continue on gathering entropy from other sources,
but since there aren&amp;#39;t other sources on CoCo, this is catastrophic.
This is mostly a concern at boot time when initially seeding the RNG, as
after that the consequences of a broken RDRAND are much more
theoretical.&lt;/p&gt;
&lt;p&gt;So, try at boot to seed the RNG using 256 bits of RDRAND output. If this
fails, panic(). This will also trigger if the system is booted without
RDRAND, as RDRAND is essential for a safe CoCo boot.&lt;/p&gt;
&lt;p&gt;Add this deliberately to be &amp;#34;just a CoCo x86 driver feature&amp;#34; and not
part of the RNG itself. Many device drivers and platforms have some
desire to contribute something to the RNG, and add_device_randomness()
is specifically meant for this purpose.&lt;/p&gt;
&lt;p&gt;Any driver can call it with seed data of any quality, or even garbage
quality, and it can only possibly make the quality of the RNG better or
have no effect, but can never…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;x86/coco: Require seeding RNG with RDRAND on CoCo systems&lt;/p&gt;
&lt;p&gt;There are few uses of CoCo that don&amp;#39;t rely on working cryptography and
hence a working RNG. Unfortunately, the CoCo threat model means that the
VM host cannot be trusted and may actively work against guests to
extract secrets or manipulate computation. Since a malicious host can
modify or observe nearly all inputs to guests, the only remaining source
of entropy for CoCo guests is RDRAND.&lt;/p&gt;
&lt;p&gt;If RDRAND is broken -- due to CPU hardware fault -- the RNG as a whole
is meant to gracefully continue on gathering entropy from other sources,
but since there aren&amp;#39;t other sources on CoCo, this is catastrophic.
This is mostly a concern at boot time when initially seeding the RNG, as
after that the consequences of a broken RDRAND are much more
theoretical.&lt;/p&gt;
&lt;p&gt;So, try at boot to seed the RNG using 256 bits of RDRAND output. If this
fails, panic(). This will also trigger if the system is booted without
RDRAND, as RDRAND is essential for a safe CoCo boot.&lt;/p&gt;
&lt;p&gt;Add this deliberately to be &amp;#34;just a CoCo x86 driver feature&amp;#34; and not
part of the RNG itself. Many device drivers and platforms have some
desire to contribute something to the RNG, and add_device_randomness()
is specifically meant for this purpose.&lt;/p&gt;
&lt;p&gt;Any driver can call it with seed data of any quality, or even garbage
quality, and it can only possibly make the quality of the RNG better or
have no effect, but can never…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-35875</guid>
    </item>
    <item>
      <title>GHSA-43j5-9vgx-7g7j</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-43j5-9vgx-7g7j</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;x86/coco: Require seeding RNG with RDRAND on CoCo systems&lt;/p&gt;
&lt;p&gt;There are few uses of CoCo that don&amp;#39;t rely on working cryptography and
hence a working RNG. Unfortunately, the CoCo threat model means that the
VM host cannot be trusted and may actively work against guests to
extract secrets or manipulate computation. Since a malicious host can
modify or observe nearly all inputs to guests, the only remaining source
of entropy for CoCo guests is RDRAND.&lt;/p&gt;
&lt;p&gt;If RDRAND is broken -- due to CPU hardware fault -- the RNG as a whole
is meant to gracefully continue on gathering entropy from other sources,
but since there aren&amp;#39;t other sources on CoCo, this is catastrophic.
This is mostly a concern at boot time when initially seeding the RNG, as
after that the consequences of a broken RDRAND are much more
theoretical.&lt;/p&gt;
&lt;p&gt;So, try at boot to seed the RNG using 256 bits of RDRAND output. If this
fails, panic(). This will also trigger if the system is booted without
RDRAND, as RDRAND is essential for a safe CoCo boot.&lt;/p&gt;
&lt;p&gt;Add this deliberately to be &amp;#34;just a CoCo x86 driver feature&amp;#34; and not
part of the RNG itself. Many device drivers and platforms have some
desire to contribute something to the RNG, and add_device_randomness()
is specifically meant for this purpose.&lt;/p&gt;
&lt;p&gt;Any driver can call it with seed data of any quality, or even garbage
quality, and it can only possibly make the quality of the RNG better or
have no effect, but can never…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;x86/coco: Require seeding RNG with RDRAND on CoCo systems&lt;/p&gt;
&lt;p&gt;There are few uses of CoCo that don&amp;#39;t rely on working cryptography and
hence a working RNG. Unfortunately, the CoCo threat model means that the
VM host cannot be trusted and may actively work against guests to
extract secrets or manipulate computation. Since a malicious host can
modify or observe nearly all inputs to guests, the only remaining source
of entropy for CoCo guests is RDRAND.&lt;/p&gt;
&lt;p&gt;If RDRAND is broken -- due to CPU hardware fault -- the RNG as a whole
is meant to gracefully continue on gathering entropy from other sources,
but since there aren&amp;#39;t other sources on CoCo, this is catastrophic.
This is mostly a concern at boot time when initially seeding the RNG, as
after that the consequences of a broken RDRAND are much more
theoretical.&lt;/p&gt;
&lt;p&gt;So, try at boot to seed the RNG using 256 bits of RDRAND output. If this
fails, panic(). This will also trigger if the system is booted without
RDRAND, as RDRAND is essential for a safe CoCo boot.&lt;/p&gt;
&lt;p&gt;Add this deliberately to be &amp;#34;just a CoCo x86 driver feature&amp;#34; and not
part of the RNG itself. Many device drivers and platforms have some
desire to contribute something to the RNG, and add_device_randomness()
is specifically meant for this purpose.&lt;/p&gt;
&lt;p&gt;Any driver can call it with seed data of any quality, or even garbage
quality, and it can only possibly make the quality of the RNG better or
have no effect, but can never…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-43j5-9vgx-7g7j</guid>
    </item>
    <item>
      <title>msrc_CVE-2024-35875 — x86/coco: Require seeding RNG with RDRAND on CoCo systems</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2024-35875</link>
      <description>msrc_CVE-2024-35875</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2024-35875</guid>
    </item>
    <item>
      <title>RHSA-2024:6267 — Red Hat Security Advisory: kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2024:6267</link>
      <description>&lt;p&gt;kernel: kprobes/x86: Use copy_from_kernel_nofault() to read from unsafe address kernel: netfilter: bridge: replace physindev with physinif in nf_bridge_info kernel: x86/coco: Require seeding RNG with RDRAND on CoCo systems kernel: bpf, sockmap: Prevent lock inversion deadlock in map delete elem kernel: bnxt_re: avoid shift undefined behavior in bnxt_qplib_alloc_init_hwq kernel: gfs2: Fix potential glock use-after-free on unmount kernel: ionic: fix use after netif_napi_del() kernel: mm/huge_memory: don&amp;amp;#39;t unpoison huge_zero_folio kernel: dmaengine: idxd: Fix possible Use-After-Free in irq_process_work_list kernel: scsi: qedi: Fix crash while reading debugfs attribute kernel: tipc: force a dst refcount before doing decryption kernel: ppp: reject claimed-as-LCP but actually malformed packets kernel: Revert &amp;amp;#34;mm/writeback: fix possible divide-by-zero in wb_dirty_limits(), again&amp;amp;#34; kernel: mm: avoid overflows in dirty throttling logic&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;kernel: kprobes/x86: Use copy_from_kernel_nofault() to read from unsafe address kernel: netfilter: bridge: replace physindev with physinif in nf_bridge_info kernel: x86/coco: Require seeding RNG with RDRAND on CoCo systems kernel: bpf, sockmap: Prevent lock inversion deadlock in map delete elem kernel: bnxt_re: avoid shift undefined behavior in bnxt_qplib_alloc_init_hwq kernel: gfs2: Fix potential glock use-after-free on unmount kernel: ionic: fix use after netif_napi_del() kernel: mm/huge_memory: don&amp;amp;#39;t unpoison huge_zero_folio kernel: dmaengine: idxd: Fix possible Use-After-Free in irq_process_work_list kernel: scsi: qedi: Fix crash while reading debugfs attribute kernel: tipc: force a dst refcount before doing decryption kernel: ppp: reject claimed-as-LCP but actually malformed packets kernel: Revert &amp;amp;#34;mm/writeback: fix possible divide-by-zero in wb_dirty_limits(), again&amp;amp;#34; kernel: mm: avoid overflows in dirty throttling logic&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2024:6267</guid>
    </item>
    <item>
      <title>RHSA-2024:6567 — Red Hat Security Advisory: kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2024:6567</link>
      <description>&lt;p&gt;kernel: efivarfs: force RO when remounting if SetVariable is not supported kernel: iommufd: Fix missing update of domains_itree after splitting iopt_area kernel: nfsd: fix RELEASE_LOCKOWNER kernel: mm: cachestat: fix folio read-after-free in cache walk kernel: mm/writeback: fix possible divide-by-zero in wb_dirty_limits(), again kernel: Bluetooth: af_bluetooth: Fix deadlock kernel: kprobes/x86: Use copy_from_kernel_nofault() to read from unsafe address kernel: KVM: SVM: Flush pages under kvm-&amp;amp;gt;lock to fix UAF in svm_register_enc_region() kernel: mm: cachestat: fix two shmem bugs kernel: x86/coco: Require seeding RNG with RDRAND on CoCo systems kernel: mm/hugetlb: fix missing hugetlb_lock for resv uncharge kernel: regmap: maple: Fix cache corruption in regcache_maple_drop() kernel: net: fix out-of-bounds access in ops_init kernel: net: bridge: mst: fix vlan use-after-free kernel: scsi: qedf: Ensure the copied buf is NUL terminated kernel: usb-storage: alauda: Check whether the media is initialized kernel: xhci: Handle TD clearing for multiple streams case kernel: cxl/region: Fix memregion leaks in devm_cxl_add_region() kernel: net/sched: Fix UAF when resolving a clash kernel: ppp: reject claimed-as-LCP but actually malformed packets kernel: mm: prevent derefencing NULL ptr in pfn_section_valid() kernel: nvme: avoid double free special payload kernel: PCI/MSI: Fix UAF in msi_capability_init kernel: xdp: Remove WARN() from __xdp_reg_mem_model() kernel: x86: stop playing stack…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;kernel: efivarfs: force RO when remounting if SetVariable is not supported kernel: iommufd: Fix missing update of domains_itree after splitting iopt_area kernel: nfsd: fix RELEASE_LOCKOWNER kernel: mm: cachestat: fix folio read-after-free in cache walk kernel: mm/writeback: fix possible divide-by-zero in wb_dirty_limits(), again kernel: Bluetooth: af_bluetooth: Fix deadlock kernel: kprobes/x86: Use copy_from_kernel_nofault() to read from unsafe address kernel: KVM: SVM: Flush pages under kvm-&amp;amp;gt;lock to fix UAF in svm_register_enc_region() kernel: mm: cachestat: fix two shmem bugs kernel: x86/coco: Require seeding RNG with RDRAND on CoCo systems kernel: mm/hugetlb: fix missing hugetlb_lock for resv uncharge kernel: regmap: maple: Fix cache corruption in regcache_maple_drop() kernel: net: fix out-of-bounds access in ops_init kernel: net: bridge: mst: fix vlan use-after-free kernel: scsi: qedf: Ensure the copied buf is NUL terminated kernel: usb-storage: alauda: Check whether the media is initialized kernel: xhci: Handle TD clearing for multiple streams case kernel: cxl/region: Fix memregion leaks in devm_cxl_add_region() kernel: net/sched: Fix UAF when resolving a clash kernel: ppp: reject claimed-as-LCP but actually malformed packets kernel: mm: prevent derefencing NULL ptr in pfn_section_valid() kernel: nvme: avoid double free special payload kernel: PCI/MSI: Fix UAF in msi_capability_init kernel: xdp: Remove WARN() from __xdp_reg_mem_model() kernel: x86: stop playing stack…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2024:6567</guid>
    </item>
    <item>
      <title>SUSE-SU-2024:2008-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2024:2008-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2024:2008-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2024-35875</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-35875</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe, Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:Pro:16.04:LTS: linux-oracle, Ubuntu:Pro:18.04:LTS: linux, Ubuntu:Pro:18.04:LTS: linux-aws, Ubuntu:18.04:LTS: linux-aws-5.0 and 172 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: x86/coco: Require seeding RNG with RDRAND on CoCo systems There are few uses of CoCo that don&amp;#39;t rely on working cryptography and hence a working RNG. Unfortunately, the CoCo threat model means that the VM host cannot be trusted and may actively work against guests to extract secrets or manipulate computation. Since a malicious host can modify or observe nearly all inputs to guests, the only remaining source of entropy for CoCo guests is RDRAND. If RDRAND is broken -- due to CPU hardware fault -- the RNG as a whole is meant to gracefully continue on gathering entropy from other sources, but since there aren&amp;#39;t other sources on CoCo, this is catastrophic. This is mostly a concern at boot time when initially seeding the RNG, as after that the consequences of a broken RDRAND are much more theoretical. So, try at boot to seed the RNG using 256 bits of RDRAND output. If this fails, panic(). This will also trigger if the system is booted without RDRAND, as RDRAND is essential for a safe CoCo boot. Add this deliberately to be &amp;#34;just a CoCo x86 driver feature&amp;#34; and not part of the RNG itself. Many device drivers and platforms have some desire to contribute something to the RNG, and add_device_randomness() is specifically meant for this purpose. Any driver can call it with seed data of any quality, or even garbage quality, and it can only possibly make the quality of the RNG better or have no effect, but can never make i…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe, Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:Pro:16.04:LTS: linux-oracle, Ubuntu:Pro:18.04:LTS: linux, Ubuntu:Pro:18.04:LTS: linux-aws, Ubuntu:18.04:LTS: linux-aws-5.0 and 172 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: x86/coco: Require seeding RNG with RDRAND on CoCo systems There are few uses of CoCo that don&amp;#39;t rely on working cryptography and hence a working RNG. Unfortunately, the CoCo threat model means that the VM host cannot be trusted and may actively work against guests to extract secrets or manipulate computation. Since a malicious host can modify or observe nearly all inputs to guests, the only remaining source of entropy for CoCo guests is RDRAND. If RDRAND is broken -- due to CPU hardware fault -- the RNG as a whole is meant to gracefully continue on gathering entropy from other sources, but since there aren&amp;#39;t other sources on CoCo, this is catastrophic. This is mostly a concern at boot time when initially seeding the RNG, as after that the consequences of a broken RDRAND are much more theoretical. So, try at boot to seed the RNG using 256 bits of RDRAND output. If this fails, panic(). This will also trigger if the system is booted without RDRAND, as RDRAND is essential for a safe CoCo boot. Add this deliberately to be &amp;#34;just a CoCo x86 driver feature&amp;#34; and not part of the RNG itself. Many device drivers and platforms have some desire to contribute something to the RNG, and add_device_randomness() is specifically meant for this purpose. Any driver can call it with seed data of any quality, or even garbage quality, and it can only possibly make the quality of the RNG better or have no effect, but can never make i…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-35875</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-1188 — Linux Kernel: Mehrere Schwachstellen ermöglichen Denial of Service</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1188</link>
      <description>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen in Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen in Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1188</guid>
    </item>
  </channel>
</rss>
