<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 19:39:19 +0000</lastBuildDate>
    <item>
      <title>bdu:2024-04215</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2024-04215</link>
      <description>bdu:2024-04215</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2024-04215</guid>
    </item>
    <item>
      <title>BELL-CVE-2024-35979</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2024-35979</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2024-35979</guid>
    </item>
    <item>
      <title>certfr-2024-avi-0578 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de SUSE. Certaines d'entre elles permettent à un at…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0578</link>
      <description>certfr-2024-avi-0578</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2024-avi-0578</guid>
    </item>
    <item>
      <title>EUVD-2026-345730</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-345730</link>
      <description>EUVD-2026-345730</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-345730</guid>
    </item>
    <item>
      <title>fkie_cve-2024-35979</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-35979</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;raid1: fix use-after-free for original bio in raid1_write_request()&lt;/p&gt;
&lt;p&gt;r1_bio-&amp;gt;bios[] is used to record new bios that will be issued to
underlying disks, however, in raid1_write_request(), r1_bio-&amp;gt;bios[]
will set to the original bio temporarily. Meanwhile, if blocked rdev
is set, free_r1bio() will be called causing that all r1_bio-&amp;gt;bios[]
to be freed:&lt;/p&gt;
&lt;p&gt;raid1_write_request()
 r1_bio = alloc_r1bio(mddev, bio); -&amp;gt; r1_bio-&amp;gt;bios[] is NULL
 for (i = 0;  i &amp;lt; disks; i++) -&amp;gt; for each rdev in conf
  // first rdev is normal
  r1_bio-&amp;gt;bios[0] = bio; -&amp;gt; set to original bio
  // second rdev is blocked
  if (test_bit(Blocked, &amp;amp;rdev-&amp;gt;flags))
   break&lt;/p&gt;
&lt;p&gt;if (blocked_rdev)
  free_r1bio()
   put_all_bios()
    bio_put(r1_bio-&amp;gt;bios[0]) -&amp;gt; original bio is freed&lt;/p&gt;
&lt;p&gt;Test scripts:&lt;/p&gt;
&lt;p&gt;mdadm -CR /dev/md0 -l1 -n4 /dev/sd[abcd] --assume-clean
fio -filename=/dev/md0 -ioengine=libaio -rw=write -bs=4k -numjobs=1 \
    -iodepth=128 -name=test -direct=1
echo blocked &amp;gt; /sys/block/md0/md/rd2/state&lt;/p&gt;
&lt;p&gt;Test result:&lt;/p&gt;
&lt;p&gt;BUG bio-264 (Not tainted): Object already free
-----------------------------------------------------------------------------&lt;/p&gt;
&lt;p&gt;Allocated in mempool_alloc_slab+0x24/0x50 age=1 cpu=1 pid=869
 kmem_cache_alloc+0x324/0x480
 mempool_alloc_slab+0x24/0x50
 mempool_alloc+0x6e/0x220
 bio_alloc_bioset+0x1af/0x4d0
 blkdev_direct_IO+0x164/0x8a0
 blkdev_write_iter+0x309/0x440
 aio_write+0x139/0x2f0
 io_submit_one+0x5ca/0xb70
 __do_sys_io_submit+0x86/0x27…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;raid1: fix use-after-free for original bio in raid1_write_request()&lt;/p&gt;
&lt;p&gt;r1_bio-&amp;gt;bios[] is used to record new bios that will be issued to
underlying disks, however, in raid1_write_request(), r1_bio-&amp;gt;bios[]
will set to the original bio temporarily. Meanwhile, if blocked rdev
is set, free_r1bio() will be called causing that all r1_bio-&amp;gt;bios[]
to be freed:&lt;/p&gt;
&lt;p&gt;raid1_write_request()
 r1_bio = alloc_r1bio(mddev, bio); -&amp;gt; r1_bio-&amp;gt;bios[] is NULL
 for (i = 0;  i &amp;lt; disks; i++) -&amp;gt; for each rdev in conf
  // first rdev is normal
  r1_bio-&amp;gt;bios[0] = bio; -&amp;gt; set to original bio
  // second rdev is blocked
  if (test_bit(Blocked, &amp;amp;rdev-&amp;gt;flags))
   break&lt;/p&gt;
&lt;p&gt;if (blocked_rdev)
  free_r1bio()
   put_all_bios()
    bio_put(r1_bio-&amp;gt;bios[0]) -&amp;gt; original bio is freed&lt;/p&gt;
&lt;p&gt;Test scripts:&lt;/p&gt;
&lt;p&gt;mdadm -CR /dev/md0 -l1 -n4 /dev/sd[abcd] --assume-clean
fio -filename=/dev/md0 -ioengine=libaio -rw=write -bs=4k -numjobs=1 \
    -iodepth=128 -name=test -direct=1
echo blocked &amp;gt; /sys/block/md0/md/rd2/state&lt;/p&gt;
&lt;p&gt;Test result:&lt;/p&gt;
&lt;p&gt;BUG bio-264 (Not tainted): Object already free
-----------------------------------------------------------------------------&lt;/p&gt;
&lt;p&gt;Allocated in mempool_alloc_slab+0x24/0x50 age=1 cpu=1 pid=869
 kmem_cache_alloc+0x324/0x480
 mempool_alloc_slab+0x24/0x50
 mempool_alloc+0x6e/0x220
 bio_alloc_bioset+0x1af/0x4d0
 blkdev_direct_IO+0x164/0x8a0
 blkdev_write_iter+0x309/0x440
 aio_write+0x139/0x2f0
 io_submit_one+0x5ca/0xb70
 __do_sys_io_submit+0x86/0x27…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-35979</guid>
    </item>
    <item>
      <title>GHSA-q2cp-mh84-p47v</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-q2cp-mh84-p47v</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;raid1: fix use-after-free for original bio in raid1_write_request()&lt;/p&gt;
&lt;p&gt;r1_bio-&amp;gt;bios[] is used to record new bios that will be issued to
underlying disks, however, in raid1_write_request(), r1_bio-&amp;gt;bios[]
will set to the original bio temporarily. Meanwhile, if blocked rdev
is set, free_r1bio() will be called causing that all r1_bio-&amp;gt;bios[]
to be freed:&lt;/p&gt;
&lt;p&gt;raid1_write_request()
 r1_bio = alloc_r1bio(mddev, bio); -&amp;gt; r1_bio-&amp;gt;bios[] is NULL
 for (i = 0;  i &amp;lt; disks; i++) -&amp;gt; for each rdev in conf
  // first rdev is normal
  r1_bio-&amp;gt;bios[0] = bio; -&amp;gt; set to original bio
  // second rdev is blocked
  if (test_bit(Blocked, &amp;amp;rdev-&amp;gt;flags))
   break&lt;/p&gt;
&lt;p&gt;if (blocked_rdev)
  free_r1bio()
   put_all_bios()
    bio_put(r1_bio-&amp;gt;bios[0]) -&amp;gt; original bio is freed&lt;/p&gt;
&lt;p&gt;Test scripts:&lt;/p&gt;
&lt;p&gt;mdadm -CR /dev/md0 -l1 -n4 /dev/sd[abcd] --assume-clean
fio -filename=/dev/md0 -ioengine=libaio -rw=write -bs=4k -numjobs=1 \
    -iodepth=128 -name=test -direct=1
echo blocked &amp;gt; /sys/block/md0/md/rd2/state&lt;/p&gt;
&lt;p&gt;Test result:&lt;/p&gt;
&lt;p&gt;BUG bio-264 (Not tainted): Object already free
-----------------------------------------------------------------------------&lt;/p&gt;
&lt;p&gt;Allocated in mempool_alloc_slab+0x24/0x50 age=1 cpu=1 pid=869
 kmem_cache_alloc+0x324/0x480
 mempool_alloc_slab+0x24/0x50
 mempool_alloc+0x6e/0x220
 bio_alloc_bioset+0x1af/0x4d0
 blkdev_direct_IO+0x164/0x8a0
 blkdev_write_iter+0x309/0x440
 aio_write+0x139/0x2f0
 io_submit_one+0x5ca/0xb70
 __do_sys_io_submit+0x86/0x27…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;raid1: fix use-after-free for original bio in raid1_write_request()&lt;/p&gt;
&lt;p&gt;r1_bio-&amp;gt;bios[] is used to record new bios that will be issued to
underlying disks, however, in raid1_write_request(), r1_bio-&amp;gt;bios[]
will set to the original bio temporarily. Meanwhile, if blocked rdev
is set, free_r1bio() will be called causing that all r1_bio-&amp;gt;bios[]
to be freed:&lt;/p&gt;
&lt;p&gt;raid1_write_request()
 r1_bio = alloc_r1bio(mddev, bio); -&amp;gt; r1_bio-&amp;gt;bios[] is NULL
 for (i = 0;  i &amp;lt; disks; i++) -&amp;gt; for each rdev in conf
  // first rdev is normal
  r1_bio-&amp;gt;bios[0] = bio; -&amp;gt; set to original bio
  // second rdev is blocked
  if (test_bit(Blocked, &amp;amp;rdev-&amp;gt;flags))
   break&lt;/p&gt;
&lt;p&gt;if (blocked_rdev)
  free_r1bio()
   put_all_bios()
    bio_put(r1_bio-&amp;gt;bios[0]) -&amp;gt; original bio is freed&lt;/p&gt;
&lt;p&gt;Test scripts:&lt;/p&gt;
&lt;p&gt;mdadm -CR /dev/md0 -l1 -n4 /dev/sd[abcd] --assume-clean
fio -filename=/dev/md0 -ioengine=libaio -rw=write -bs=4k -numjobs=1 \
    -iodepth=128 -name=test -direct=1
echo blocked &amp;gt; /sys/block/md0/md/rd2/state&lt;/p&gt;
&lt;p&gt;Test result:&lt;/p&gt;
&lt;p&gt;BUG bio-264 (Not tainted): Object already free
-----------------------------------------------------------------------------&lt;/p&gt;
&lt;p&gt;Allocated in mempool_alloc_slab+0x24/0x50 age=1 cpu=1 pid=869
 kmem_cache_alloc+0x324/0x480
 mempool_alloc_slab+0x24/0x50
 mempool_alloc+0x6e/0x220
 bio_alloc_bioset+0x1af/0x4d0
 blkdev_direct_IO+0x164/0x8a0
 blkdev_write_iter+0x309/0x440
 aio_write+0x139/0x2f0
 io_submit_one+0x5ca/0xb70
 __do_sys_io_submit+0x86/0x27…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-q2cp-mh84-p47v</guid>
    </item>
    <item>
      <title>RHSA-2024:9315 — Red Hat Security Advisory: kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2024:9315</link>
      <description>&lt;p&gt;kernel: use after free in i2c kernel: bluetooth: BR/EDR Bluetooth Impersonation Attacks (BIAS) kernel: hwmon: (lm90) Prevent integer overflow/underflow in hysteresis calculations kernel: asix: fix uninit-value in asix_mdio_read() kernel: tty: tty_buffer: Fix the softlockup issue in flush_to_ldisc kernel: hwmon: (w83793) Fix NULL pointer dereference by removing unnecessary structure field kernel: hwmon: (w83791d) Fix NULL pointer dereference by removing unnecessary structure field kernel: powerpc/64s: fix program check interrupt emergency stack path kernel: powerpc/64s: Fix unrecoverable MCE calling async handler from NMI kernel: lib/generic-radix-tree.c: Don&amp;#39;t overflow in peek() kernel: powerpc/smp: do not decrement idle task preempt count in CPU offline kernel: can: isotp: isotp_sendmsg(): add result check for wait_event_interruptible() kernel: usbnet: sanity check for maxpacket kernel: nvmem: Fix shift-out-of-bound (UBSAN) with byte size cells kernel: aio: fix use-after-free due to missing POLLFREE handling kernel: powerpc/pseries: Fix potential memleak in papr_get_attr() kernel: of: fdt: fix off-by-one error in unflatten_dt_nodes() kernel: thermal/int340x_thermal: handle data_vault when the value is ZERO_SIZE_PTR kernel: vt_ioctl: fix array_index_nospec in vt_setactivate kernel: bpf: Fix crash due to out of bounds access into reg2btf_ids. kernel: lz4: fix LZ4_decompress_safe_partial read out of bound kernel: x86/mce: Work around an erratum on fast string copy instructions…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;kernel: use after free in i2c kernel: bluetooth: BR/EDR Bluetooth Impersonation Attacks (BIAS) kernel: hwmon: (lm90) Prevent integer overflow/underflow in hysteresis calculations kernel: asix: fix uninit-value in asix_mdio_read() kernel: tty: tty_buffer: Fix the softlockup issue in flush_to_ldisc kernel: hwmon: (w83793) Fix NULL pointer dereference by removing unnecessary structure field kernel: hwmon: (w83791d) Fix NULL pointer dereference by removing unnecessary structure field kernel: powerpc/64s: fix program check interrupt emergency stack path kernel: powerpc/64s: Fix unrecoverable MCE calling async handler from NMI kernel: lib/generic-radix-tree.c: Don&amp;#39;t overflow in peek() kernel: powerpc/smp: do not decrement idle task preempt count in CPU offline kernel: can: isotp: isotp_sendmsg(): add result check for wait_event_interruptible() kernel: usbnet: sanity check for maxpacket kernel: nvmem: Fix shift-out-of-bound (UBSAN) with byte size cells kernel: aio: fix use-after-free due to missing POLLFREE handling kernel: powerpc/pseries: Fix potential memleak in papr_get_attr() kernel: of: fdt: fix off-by-one error in unflatten_dt_nodes() kernel: thermal/int340x_thermal: handle data_vault when the value is ZERO_SIZE_PTR kernel: vt_ioctl: fix array_index_nospec in vt_setactivate kernel: bpf: Fix crash due to out of bounds access into reg2btf_ids. kernel: lz4: fix LZ4_decompress_safe_partial read out of bound kernel: x86/mce: Work around an erratum on fast string copy instructions…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2024:9315</guid>
    </item>
    <item>
      <title>SUSE-SU-2024:2360-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2024:2360-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2024:2360-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2024-35979</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-35979</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 87 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: raid1: fix use-after-free for original bio in raid1_write_request() r1_bio-&amp;gt;bios[] is used to record new bios that will be issued to underlying disks, however, in raid1_write_request(), r1_bio-&amp;gt;bios[] will set to the original bio temporarily. Meanwhile, if blocked rdev is set, free_r1bio() will be called causing that all r1_bio-&amp;gt;bios[] to be freed: raid1_write_request()  r1_bio = alloc_r1bio(mddev, bio); -&amp;gt; r1_bio-&amp;gt;bios[] is NULL  for (i = 0;  i &amp;lt; disks; i++) -&amp;gt; for each rdev in conf   // first rdev is normal   r1_bio-&amp;gt;bios[0] = bio; -&amp;gt; set to original bio   // second rdev is blocked   if (test_bit(Blocked, &amp;amp;rdev-&amp;gt;flags))    break  if (blocked_rdev)   free_r1bio()    put_all_bios()     bio_put(r1_bio-&amp;gt;bios[0]) -&amp;gt; original bio is freed Test scripts: mdadm -CR /dev/md0 -l1 -n4 /dev/sd[abcd] --assume-clean fio -filename=/dev/md0 -ioengine=libaio -rw=write -bs=4k -numjobs=1 \     -iodepth=128 -name=test -direct=1 echo blocked &amp;gt; /sys/block/md0/md/rd2/state Test result: BUG bio-264 (Not tainted): Object already free ----------------------------------------------------------------------------- Allocated in mempool_alloc_slab+0x24/0x50 age=1 cpu=1 pid=869  kmem_cache_alloc+0x324/0x480  mempool_alloc_slab+0x24/0x50  mempool_alloc+0x6e/0x220  bio_alloc_bioset+0x1af/0x4d0  blkdev_direct_IO+0x164/0x8a0  blkdev_write_iter+0x309/0x440  aio_write+0x139/0x2f0  io_submit_one+0x5ca/0xb70  __do_sys_io_submit+0x86/0x270  __x64_…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 87 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: raid1: fix use-after-free for original bio in raid1_write_request() r1_bio-&amp;gt;bios[] is used to record new bios that will be issued to underlying disks, however, in raid1_write_request(), r1_bio-&amp;gt;bios[] will set to the original bio temporarily. Meanwhile, if blocked rdev is set, free_r1bio() will be called causing that all r1_bio-&amp;gt;bios[] to be freed: raid1_write_request()  r1_bio = alloc_r1bio(mddev, bio); -&amp;gt; r1_bio-&amp;gt;bios[] is NULL  for (i = 0;  i &amp;lt; disks; i++) -&amp;gt; for each rdev in conf   // first rdev is normal   r1_bio-&amp;gt;bios[0] = bio; -&amp;gt; set to original bio   // second rdev is blocked   if (test_bit(Blocked, &amp;amp;rdev-&amp;gt;flags))    break  if (blocked_rdev)   free_r1bio()    put_all_bios()     bio_put(r1_bio-&amp;gt;bios[0]) -&amp;gt; original bio is freed Test scripts: mdadm -CR /dev/md0 -l1 -n4 /dev/sd[abcd] --assume-clean fio -filename=/dev/md0 -ioengine=libaio -rw=write -bs=4k -numjobs=1 \     -iodepth=128 -name=test -direct=1 echo blocked &amp;gt; /sys/block/md0/md/rd2/state Test result: BUG bio-264 (Not tainted): Object already free ----------------------------------------------------------------------------- Allocated in mempool_alloc_slab+0x24/0x50 age=1 cpu=1 pid=869  kmem_cache_alloc+0x324/0x480  mempool_alloc_slab+0x24/0x50  mempool_alloc+0x6e/0x220  bio_alloc_bioset+0x1af/0x4d0  blkdev_direct_IO+0x164/0x8a0  blkdev_write_iter+0x309/0x440  aio_write+0x139/0x2f0  io_submit_one+0x5ca/0xb70  __do_sys_io_submit+0x86/0x270  __x64_…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-35979</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-1188 — Linux Kernel: Mehrere Schwachstellen ermöglichen Denial of Service</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1188</link>
      <description>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen in Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen in Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1188</guid>
    </item>
  </channel>
</rss>
