<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 04:22:08 +0000</lastBuildDate>
    <item>
      <title>ALSA-2024:4928 — Moderate: kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2024:4928</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: bpftool, AlmaLinux:9: kernel, AlmaLinux:9: kernel-64k, AlmaLinux:9: kernel-64k-core, AlmaLinux:9: kernel-64k-debug, AlmaLinux:9: kernel-64k-debug-core, AlmaLinux:9: kernel-64k-debug-devel, AlmaLinux:9: kernel-64k-debug-devel-matched, AlmaLinux:9: kernel-64k-debug-modules, AlmaLinux:9: kernel-64k-debug-modules-core and 52 more&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: block: null pointer dereference in ioctl.c when length and logical block size are misaligned (CVE-2023-52458)
  * kernel: ext4: avoid allocating blocks from corrupted group in ext4_mb_try_best_found() (CVE-2024-26773)
  * kernel: bpf: Fix racing between bpf_timer_cancel_and_free and bpf_timer_cancel (CVE-2024-26737)
  * kernel: dm: call the resume method on internal suspend (CVE-2024-26880)
  * kernel: net/ipv6: avoid possible UAF in ip6_route_mpath_notify() (CVE-2024-26852)
  * kernel: Squashfs: check the inode number is not the invalid value of zero (CVE-2024-26982)
  * kernel: nfp: flower: handle acti_netdevs allocation failure (CVE-2024-27046)
  * kernel: octeontx2-af: Use separate handlers for interrupts (CVE-2024-27030)
  * kernel: icmp: prevent possible NULL dereferences from icmp_build_probe() (CVE-2024-35857)
  * kernel: mlxbf_gige: call request_irq() after NAPI initialized (CVE-2024-35907)
  * kernel: mlxbf_gige: stop interface during shutdown (CVE-2024-35885)
  * kernel: scsi: libfc: Fix potential NULL pointer dereference in fc_lport_ptp_setup() (CVE-2023-52809)
  * kernel: can: j1939: j1939_netdev_start(): fix UAF for rx_kref of j1939_priv (CVE-2021-47459)
  * kernel: scsi: lpfc: Release hbalock before calling lpfc_worker_wake_up() (CVE-2024-36924)
  * kernel: scsi: lpfc: Move NPIV&amp;#39;s transport unregistration to after resource clean up (CVE-202…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: bpftool, AlmaLinux:9: kernel, AlmaLinux:9: kernel-64k, AlmaLinux:9: kernel-64k-core, AlmaLinux:9: kernel-64k-debug, AlmaLinux:9: kernel-64k-debug-core, AlmaLinux:9: kernel-64k-debug-devel, AlmaLinux:9: kernel-64k-debug-devel-matched, AlmaLinux:9: kernel-64k-debug-modules, AlmaLinux:9: kernel-64k-debug-modules-core and 52 more&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: block: null pointer dereference in ioctl.c when length and logical block size are misaligned (CVE-2023-52458)
  * kernel: ext4: avoid allocating blocks from corrupted group in ext4_mb_try_best_found() (CVE-2024-26773)
  * kernel: bpf: Fix racing between bpf_timer_cancel_and_free and bpf_timer_cancel (CVE-2024-26737)
  * kernel: dm: call the resume method on internal suspend (CVE-2024-26880)
  * kernel: net/ipv6: avoid possible UAF in ip6_route_mpath_notify() (CVE-2024-26852)
  * kernel: Squashfs: check the inode number is not the invalid value of zero (CVE-2024-26982)
  * kernel: nfp: flower: handle acti_netdevs allocation failure (CVE-2024-27046)
  * kernel: octeontx2-af: Use separate handlers for interrupts (CVE-2024-27030)
  * kernel: icmp: prevent possible NULL dereferences from icmp_build_probe() (CVE-2024-35857)
  * kernel: mlxbf_gige: call request_irq() after NAPI initialized (CVE-2024-35907)
  * kernel: mlxbf_gige: stop interface during shutdown (CVE-2024-35885)
  * kernel: scsi: libfc: Fix potential NULL pointer dereference in fc_lport_ptp_setup() (CVE-2023-52809)
  * kernel: can: j1939: j1939_netdev_start(): fix UAF for rx_kref of j1939_priv (CVE-2021-47459)
  * kernel: scsi: lpfc: Release hbalock before calling lpfc_worker_wake_up() (CVE-2024-36924)
  * kernel: scsi: lpfc: Move NPIV&amp;#39;s transport unregistration to after resource clean up (CVE-202…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2024:4928</guid>
    </item>
    <item>
      <title>bdu:2024-09898</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2024-09898</link>
      <description>bdu:2024-09898</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2024-09898</guid>
    </item>
    <item>
      <title>BELL-CVE-2024-35907</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2024-35907</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2024-35907</guid>
    </item>
    <item>
      <title>certfr-2024-avi-0496 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de SUSE. Certaines d'entre elles permettent à un at…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0496</link>
      <description>certfr-2024-avi-0496</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2024-avi-0496</guid>
    </item>
    <item>
      <title>EUVD-2026-312774</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-312774</link>
      <description>EUVD-2026-312774</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-312774</guid>
    </item>
    <item>
      <title>fkie_cve-2024-35907</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-35907</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;mlxbf_gige: call request_irq() after NAPI initialized&lt;/p&gt;
&lt;p&gt;The mlxbf_gige driver encounters a NULL pointer exception in
mlxbf_gige_open() when kdump is enabled.  The sequence to reproduce
the exception is as follows:
a) enable kdump
b) trigger kdump via &amp;#34;echo c &amp;gt; /proc/sysrq-trigger&amp;#34;
c) kdump kernel executes
d) kdump kernel loads mlxbf_gige module
e) the mlxbf_gige module runs its open() as the
   the &amp;#34;oob_net0&amp;#34; interface is brought up
f) mlxbf_gige module will experience an exception
   during its open(), something like:&lt;/p&gt;
&lt;p&gt;Unable to handle kernel NULL pointer dereference at virtual address 0000000000000000
     Mem abort info:
       ESR = 0x0000000086000004
       EC = 0x21: IABT (current EL), IL = 32 bits
       SET = 0, FnV = 0
       EA = 0, S1PTW = 0
       FSC = 0x04: level 0 translation fault
     user pgtable: 4k pages, 48-bit VAs, pgdp=00000000e29a4000
     [0000000000000000] pgd=0000000000000000, p4d=0000000000000000
     Internal error: Oops: 0000000086000004 [#1] SMP
     CPU: 0 PID: 812 Comm: NetworkManager Tainted: G           OE     5.15.0-1035-bluefield #37-Ubuntu
     Hardware name: https://www.mellanox.com BlueField-3 SmartNIC Main Card/BlueField-3 SmartNIC Main Card, BIOS 4.6.0.13024 Jan 19 2024
     pstate: 80400009 (Nzcv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)
     pc : 0x0
     lr : __napi_poll+0x40/0x230
     sp : ffff800008003e00
     x29: ffff800008003e00 x28: 0000000000000000 x27…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;mlxbf_gige: call request_irq() after NAPI initialized&lt;/p&gt;
&lt;p&gt;The mlxbf_gige driver encounters a NULL pointer exception in
mlxbf_gige_open() when kdump is enabled.  The sequence to reproduce
the exception is as follows:
a) enable kdump
b) trigger kdump via &amp;#34;echo c &amp;gt; /proc/sysrq-trigger&amp;#34;
c) kdump kernel executes
d) kdump kernel loads mlxbf_gige module
e) the mlxbf_gige module runs its open() as the
   the &amp;#34;oob_net0&amp;#34; interface is brought up
f) mlxbf_gige module will experience an exception
   during its open(), something like:&lt;/p&gt;
&lt;p&gt;Unable to handle kernel NULL pointer dereference at virtual address 0000000000000000
     Mem abort info:
       ESR = 0x0000000086000004
       EC = 0x21: IABT (current EL), IL = 32 bits
       SET = 0, FnV = 0
       EA = 0, S1PTW = 0
       FSC = 0x04: level 0 translation fault
     user pgtable: 4k pages, 48-bit VAs, pgdp=00000000e29a4000
     [0000000000000000] pgd=0000000000000000, p4d=0000000000000000
     Internal error: Oops: 0000000086000004 [#1] SMP
     CPU: 0 PID: 812 Comm: NetworkManager Tainted: G           OE     5.15.0-1035-bluefield #37-Ubuntu
     Hardware name: https://www.mellanox.com BlueField-3 SmartNIC Main Card/BlueField-3 SmartNIC Main Card, BIOS 4.6.0.13024 Jan 19 2024
     pstate: 80400009 (Nzcv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)
     pc : 0x0
     lr : __napi_poll+0x40/0x230
     sp : ffff800008003e00
     x29: ffff800008003e00 x28: 0000000000000000 x27…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-35907</guid>
    </item>
    <item>
      <title>GHSA-x5xr-8rhw-qpr4</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-x5xr-8rhw-qpr4</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;mlxbf_gige: call request_irq() after NAPI initialized&lt;/p&gt;
&lt;p&gt;The mlxbf_gige driver encounters a NULL pointer exception in
mlxbf_gige_open() when kdump is enabled.  The sequence to reproduce
the exception is as follows:
a) enable kdump
b) trigger kdump via &amp;#34;echo c &amp;gt; /proc/sysrq-trigger&amp;#34;
c) kdump kernel executes
d) kdump kernel loads mlxbf_gige module
e) the mlxbf_gige module runs its open() as the
   the &amp;#34;oob_net0&amp;#34; interface is brought up
f) mlxbf_gige module will experience an exception
   during its open(), something like:&lt;/p&gt;
&lt;p&gt;Unable to handle kernel NULL pointer dereference at virtual address 0000000000000000
     Mem abort info:
       ESR = 0x0000000086000004
       EC = 0x21: IABT (current EL), IL = 32 bits
       SET = 0, FnV = 0
       EA = 0, S1PTW = 0
       FSC = 0x04: level 0 translation fault
     user pgtable: 4k pages, 48-bit VAs, pgdp=00000000e29a4000
     [0000000000000000] pgd=0000000000000000, p4d=0000000000000000
     Internal error: Oops: 0000000086000004 [#1] SMP
     CPU: 0 PID: 812 Comm: NetworkManager Tainted: G           OE     5.15.0-1035-bluefield #37-Ubuntu
     Hardware name: https://www.mellanox.com BlueField-3 SmartNIC Main Card/BlueField-3 SmartNIC Main Card, BIOS 4.6.0.13024 Jan 19 2024
     pstate: 80400009 (Nzcv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)
     pc : 0x0
     lr : __napi_poll+0x40/0x230
     sp : ffff800008003e00
     x29: ffff800008003e00 x28: 0000000000000000 x27…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;mlxbf_gige: call request_irq() after NAPI initialized&lt;/p&gt;
&lt;p&gt;The mlxbf_gige driver encounters a NULL pointer exception in
mlxbf_gige_open() when kdump is enabled.  The sequence to reproduce
the exception is as follows:
a) enable kdump
b) trigger kdump via &amp;#34;echo c &amp;gt; /proc/sysrq-trigger&amp;#34;
c) kdump kernel executes
d) kdump kernel loads mlxbf_gige module
e) the mlxbf_gige module runs its open() as the
   the &amp;#34;oob_net0&amp;#34; interface is brought up
f) mlxbf_gige module will experience an exception
   during its open(), something like:&lt;/p&gt;
&lt;p&gt;Unable to handle kernel NULL pointer dereference at virtual address 0000000000000000
     Mem abort info:
       ESR = 0x0000000086000004
       EC = 0x21: IABT (current EL), IL = 32 bits
       SET = 0, FnV = 0
       EA = 0, S1PTW = 0
       FSC = 0x04: level 0 translation fault
     user pgtable: 4k pages, 48-bit VAs, pgdp=00000000e29a4000
     [0000000000000000] pgd=0000000000000000, p4d=0000000000000000
     Internal error: Oops: 0000000086000004 [#1] SMP
     CPU: 0 PID: 812 Comm: NetworkManager Tainted: G           OE     5.15.0-1035-bluefield #37-Ubuntu
     Hardware name: https://www.mellanox.com BlueField-3 SmartNIC Main Card/BlueField-3 SmartNIC Main Card, BIOS 4.6.0.13024 Jan 19 2024
     pstate: 80400009 (Nzcv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)
     pc : 0x0
     lr : __napi_poll+0x40/0x230
     sp : ffff800008003e00
     x29: ffff800008003e00 x28: 0000000000000000 x27…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-x5xr-8rhw-qpr4</guid>
    </item>
    <item>
      <title>RHSA-2024:4928 — Red Hat Security Advisory: kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2024:4928</link>
      <description>&lt;p&gt;kernel: can: j1939: j1939_netdev_start(): fix UAF for rx_kref of j1939_priv kernel: net: amd-xgbe: Fix skb data length underflow kernel: block: null pointer dereference in ioctl.c when length and logical block size are misaligned kernel: scsi: libfc: Fix potential NULL pointer dereference in fc_lport_ptp_setup() kernel: bpf: Fix racing between bpf_timer_cancel_and_free and bpf_timer_cancel kernel: ext4: avoid allocating blocks from corrupted group in ext4_mb_try_best_found() kernel: net/ipv6: avoid possible UAF in ip6_route_mpath_notify() kernel: dm: call the resume method on internal suspend kernel: Squashfs: check the inode number is not the invalid value of zero kernel: octeontx2-af: race condition on interupts kernel: nfp: flower: handle acti_netdevs allocation failure kernel: icmp: prevent possible NULL dereferences from icmp_build_probe() kernel: mlxbf_gige: stop interface during shutdown kernel: mlxbf_gige: call request_irq() after NAPI initialized kernel: drm/ast: Fix soft lockup kernel: scsi: lpfc: Release hbalock before calling lpfc_worker_wake_up() kernel: scsi: lpfc: Move NPIV&amp;#39;s transport unregistration to after resource clean up kernel: epoll: be better about file lifetimes&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;kernel: can: j1939: j1939_netdev_start(): fix UAF for rx_kref of j1939_priv kernel: net: amd-xgbe: Fix skb data length underflow kernel: block: null pointer dereference in ioctl.c when length and logical block size are misaligned kernel: scsi: libfc: Fix potential NULL pointer dereference in fc_lport_ptp_setup() kernel: bpf: Fix racing between bpf_timer_cancel_and_free and bpf_timer_cancel kernel: ext4: avoid allocating blocks from corrupted group in ext4_mb_try_best_found() kernel: net/ipv6: avoid possible UAF in ip6_route_mpath_notify() kernel: dm: call the resume method on internal suspend kernel: Squashfs: check the inode number is not the invalid value of zero kernel: octeontx2-af: race condition on interupts kernel: nfp: flower: handle acti_netdevs allocation failure kernel: icmp: prevent possible NULL dereferences from icmp_build_probe() kernel: mlxbf_gige: stop interface during shutdown kernel: mlxbf_gige: call request_irq() after NAPI initialized kernel: drm/ast: Fix soft lockup kernel: scsi: lpfc: Release hbalock before calling lpfc_worker_wake_up() kernel: scsi: lpfc: Move NPIV&amp;#39;s transport unregistration to after resource clean up kernel: epoll: be better about file lifetimes&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2024:4928</guid>
    </item>
    <item>
      <title>RHSA-2024:5364 — Red Hat Security Advisory: kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2024:5364</link>
      <description>&lt;p&gt;kernel: tty: Fix out-of-bound vmalloc access in imageblit kernel: gfs2: Fix kernel NULL pointer dereference in gfs2_rgrp_dump kernel: wifi: ath10k: fix NULL pointer dereference in ath10k_wmi_tlv_op_pull_mgmt_tx_compl_ev() kernel: cxl/port: Fix delete_endpoint() vs parent unregistration race kernel: platform/x86: wmi: Fix opening of char device kernel: dmaengine/idxd: hardware erratum allows potential security problem with direct access by untrusted application kernel: net: ice: Fix potential NULL pointer dereference in ice_bridge_setlink() kernel: wifi: ath9k: delay all of ath9k_wmi_event_tasklet() until init is complete kernel: nfp: flower: handle acti_netdevs allocation failure kernel: wifi: rtl8xxxu: add cancel_work_sync() for c2hcmd_work kernel: wifi: mac80211: check/clear fast rx for non-4addr sta VLAN changes kernel: wifi: iwlwifi: dbg-tlv: ensure NUL termination kernel: mlxsw: spectrum_acl_tcam: Fix memory leak when canceling rehash work kernel: mlxbf_gige: call request_irq() after NAPI initialized kernel: wifi: cfg80211: check A-MSDU format more carefully kernel: wifi: iwlwifi: read txq-&amp;amp;gt;read_ptr under lock kernel: wifi: nl80211: don&amp;amp;#39;t free NULL coalescing rule kernel: net: kernel: UAF in network route management kernel: net: bridge: xmit: make sure we have at least eth header len bytes kernel: net/mlx5: Discard command completions in internal error kernel: net/mlx5: Add a timeout to acquire the command queue semaphore kernel: r8169: Fix possible ring buffer c…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;kernel: tty: Fix out-of-bound vmalloc access in imageblit kernel: gfs2: Fix kernel NULL pointer dereference in gfs2_rgrp_dump kernel: wifi: ath10k: fix NULL pointer dereference in ath10k_wmi_tlv_op_pull_mgmt_tx_compl_ev() kernel: cxl/port: Fix delete_endpoint() vs parent unregistration race kernel: platform/x86: wmi: Fix opening of char device kernel: dmaengine/idxd: hardware erratum allows potential security problem with direct access by untrusted application kernel: net: ice: Fix potential NULL pointer dereference in ice_bridge_setlink() kernel: wifi: ath9k: delay all of ath9k_wmi_event_tasklet() until init is complete kernel: nfp: flower: handle acti_netdevs allocation failure kernel: wifi: rtl8xxxu: add cancel_work_sync() for c2hcmd_work kernel: wifi: mac80211: check/clear fast rx for non-4addr sta VLAN changes kernel: wifi: iwlwifi: dbg-tlv: ensure NUL termination kernel: mlxsw: spectrum_acl_tcam: Fix memory leak when canceling rehash work kernel: mlxbf_gige: call request_irq() after NAPI initialized kernel: wifi: cfg80211: check A-MSDU format more carefully kernel: wifi: iwlwifi: read txq-&amp;amp;gt;read_ptr under lock kernel: wifi: nl80211: don&amp;amp;#39;t free NULL coalescing rule kernel: net: kernel: UAF in network route management kernel: net: bridge: xmit: make sure we have at least eth header len bytes kernel: net/mlx5: Discard command completions in internal error kernel: net/mlx5: Add a timeout to acquire the command queue semaphore kernel: r8169: Fix possible ring buffer c…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2024:5364</guid>
    </item>
    <item>
      <title>SUSE-SU-2024:2008-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2024:2008-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2024:2008-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2024-35907</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-35907</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 123 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: mlxbf_gige: call request_irq() after NAPI initialized The mlxbf_gige driver encounters a NULL pointer exception in mlxbf_gige_open() when kdump is enabled.  The sequence to reproduce the exception is as follows: a) enable kdump b) trigger kdump via &amp;#34;echo c &amp;gt; /proc/sysrq-trigger&amp;#34; c) kdump kernel executes d) kdump kernel loads mlxbf_gige module e) the mlxbf_gige module runs its open() as the    the &amp;#34;oob_net0&amp;#34; interface is brought up f) mlxbf_gige module will experience an exception    during its open(), something like:      Unable to handle kernel NULL pointer dereference at virtual address 0000000000000000      Mem abort info:        ESR = 0x0000000086000004        EC = 0x21: IABT (current EL), IL = 32 bits        SET = 0, FnV = 0        EA = 0, S1PTW = 0        FSC = 0x04: level 0 translation fault      user pgtable: 4k pages, 48-bit VAs, pgdp=00000000e29a4000      [0000000000000000] pgd=0000000000000000, p4d=0000000000000000      Internal error: Oops: 0000000086000004 [#1] SMP      CPU: 0 PID: 812 Comm: NetworkManager Tainted: G           OE 5.15.0-1035-bluefield #37-Ubuntu      Hardware name: https://www.mellanox.com BlueField-3 SmartNIC Main Card/BlueField-3 SmartNIC Main Card, BIOS 4.6.0.13024 Jan 19 2024      pstate: 80400009 (Nzcv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)      pc : 0x0      lr : __napi_poll+0x40/0x230      sp : ffff800008003e00      x29: ffff800008003e00 x28: 0000000000000000 x27: 00000…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 123 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: mlxbf_gige: call request_irq() after NAPI initialized The mlxbf_gige driver encounters a NULL pointer exception in mlxbf_gige_open() when kdump is enabled.  The sequence to reproduce the exception is as follows: a) enable kdump b) trigger kdump via &amp;#34;echo c &amp;gt; /proc/sysrq-trigger&amp;#34; c) kdump kernel executes d) kdump kernel loads mlxbf_gige module e) the mlxbf_gige module runs its open() as the    the &amp;#34;oob_net0&amp;#34; interface is brought up f) mlxbf_gige module will experience an exception    during its open(), something like:      Unable to handle kernel NULL pointer dereference at virtual address 0000000000000000      Mem abort info:        ESR = 0x0000000086000004        EC = 0x21: IABT (current EL), IL = 32 bits        SET = 0, FnV = 0        EA = 0, S1PTW = 0        FSC = 0x04: level 0 translation fault      user pgtable: 4k pages, 48-bit VAs, pgdp=00000000e29a4000      [0000000000000000] pgd=0000000000000000, p4d=0000000000000000      Internal error: Oops: 0000000086000004 [#1] SMP      CPU: 0 PID: 812 Comm: NetworkManager Tainted: G           OE 5.15.0-1035-bluefield #37-Ubuntu      Hardware name: https://www.mellanox.com BlueField-3 SmartNIC Main Card/BlueField-3 SmartNIC Main Card, BIOS 4.6.0.13024 Jan 19 2024      pstate: 80400009 (Nzcv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)      pc : 0x0      lr : __napi_poll+0x40/0x230      sp : ffff800008003e00      x29: ffff800008003e00 x28: 0000000000000000 x27: 00000…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-35907</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-1188 — Linux Kernel: Mehrere Schwachstellen ermöglichen Denial of Service</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1188</link>
      <description>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen in Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen in Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1188</guid>
    </item>
  </channel>
</rss>
