<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 02:05:33 +0000</lastBuildDate>
    <item>
      <title>bdu:2025-08071</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-08071</link>
      <description>bdu:2025-08071</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-08071</guid>
    </item>
    <item>
      <title>BELL-CVE-2024-36914</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2024-36914</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2024-36914</guid>
    </item>
    <item>
      <title>certfr-2024-avi-0667 — De multiples vulnérabilités ont été découvertes dans le noyau Linux d'Ubuntu. Certaines d'entre elles permettent à un a…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0667</link>
      <description>certfr-2024-avi-0667</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2024-avi-0667</guid>
    </item>
    <item>
      <title>EUVD-2026-345767</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-345767</link>
      <description>EUVD-2026-345767</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-345767</guid>
    </item>
    <item>
      <title>fkie_cve-2024-36914</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-36914</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;drm/amd/display: Skip on writeback when it&amp;#39;s not applicable&lt;/p&gt;
&lt;p&gt;[WHY]
dynamic memory safety error detector (KASAN) catches and generates error
messages &amp;#34;BUG: KASAN: slab-out-of-bounds&amp;#34; as writeback connector does not
support certain features which are not initialized.&lt;/p&gt;
&lt;p&gt;[HOW]
Skip them when connector type is DRM_MODE_CONNECTOR_WRITEBACK.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;drm/amd/display: Skip on writeback when it&amp;#39;s not applicable&lt;/p&gt;
&lt;p&gt;[WHY]
dynamic memory safety error detector (KASAN) catches and generates error
messages &amp;#34;BUG: KASAN: slab-out-of-bounds&amp;#34; as writeback connector does not
support certain features which are not initialized.&lt;/p&gt;
&lt;p&gt;[HOW]
Skip them when connector type is DRM_MODE_CONNECTOR_WRITEBACK.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-36914</guid>
    </item>
    <item>
      <title>msrc_CVE-2024-36914 — drm/amd/display: Skip on writeback when it's not applicable</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2024-36914</link>
      <description>msrc_CVE-2024-36914</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2024-36914</guid>
    </item>
    <item>
      <title>OESA-2024-2029 — kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2024-2029</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP3: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&#13;
&#13;
In the Linux kernel, the following vulnerability has been resolved:&#13;
&#13;
mlxsw: spectrum_acl_tcam: Fix stack corruption&#13;
&#13;
When tc filters are first added to a net device, the corresponding local
port gets bound to an ACL group in the device. The group contains a list
of ACLs. In turn, each ACL points to a different TCAM region where the
filters are stored. During forwarding, the ACLs are sequentially
evaluated until a match is found.&#13;
&#13;
One reason to place filters in different regions is when they are added
with decreasing priorities and in an alternating order so that two
consecutive filters can never fit in the same region because of their
key usage.&#13;
&#13;
In Spectrum-2 and newer ASICs the firmware started to report that the
maximum number of ACLs in a group is more than 16, but the layout of the
register that configures ACL groups (PAGT) was not updated to account
for that. It is therefore possible to hit stack corruption [1] in the
rare case where more than 16 ACLs in a group are required.&#13;
&#13;
Fix by limiting the maximum ACL group size to the minimum between what
the firmware reports and the maximum ACLs that fit in the PAGT register.&#13;
&#13;
Add a test case to make sure the machine does not crash when this
condition is hit.&#13;
&#13;
[1]
Kernel panic - not syncing: stack-protector: Kernel stack is corrupted in: mlxsw_sp_acl_tcam_group_update+0x116/0x120
[...]
 dump_stack_lvl+0x36/0x50
 panic+0x305/0x330
 __stack…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP3: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&#13;
&#13;
In the Linux kernel, the following vulnerability has been resolved:&#13;
&#13;
mlxsw: spectrum_acl_tcam: Fix stack corruption&#13;
&#13;
When tc filters are first added to a net device, the corresponding local
port gets bound to an ACL group in the device. The group contains a list
of ACLs. In turn, each ACL points to a different TCAM region where the
filters are stored. During forwarding, the ACLs are sequentially
evaluated until a match is found.&#13;
&#13;
One reason to place filters in different regions is when they are added
with decreasing priorities and in an alternating order so that two
consecutive filters can never fit in the same region because of their
key usage.&#13;
&#13;
In Spectrum-2 and newer ASICs the firmware started to report that the
maximum number of ACLs in a group is more than 16, but the layout of the
register that configures ACL groups (PAGT) was not updated to account
for that. It is therefore possible to hit stack corruption [1] in the
rare case where more than 16 ACLs in a group are required.&#13;
&#13;
Fix by limiting the maximum ACL group size to the minimum between what
the firmware reports and the maximum ACLs that fit in the PAGT register.&#13;
&#13;
Add a test case to make sure the machine does not crash when this
condition is hit.&#13;
&#13;
[1]
Kernel panic - not syncing: stack-protector: Kernel stack is corrupted in: mlxsw_sp_acl_tcam_group_update+0x116/0x120
[...]
 dump_stack_lvl+0x36/0x50
 panic+0x305/0x330
 __stack…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2024-2029</guid>
    </item>
    <item>
      <title>SUSE-SU-2024:2802-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2024:2802-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2024:2802-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2024-36914</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-36914</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux, Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe and 186 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Skip on writeback when it&amp;#39;s not applicable [WHY] dynamic memory safety error detector (KASAN) catches and generates error messages &amp;#34;BUG: KASAN: slab-out-of-bounds&amp;#34; as writeback connector does not support certain features which are not initialized. [HOW] Skip them when connector type is DRM_MODE_CONNECTOR_WRITEBACK.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux, Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe and 186 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Skip on writeback when it&amp;#39;s not applicable [WHY] dynamic memory safety error detector (KASAN) catches and generates error messages &amp;#34;BUG: KASAN: slab-out-of-bounds&amp;#34; as writeback connector does not support certain features which are not initialized. [HOW] Skip them when connector type is DRM_MODE_CONNECTOR_WRITEBACK.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-36914</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-1259 — Linux Kernel: Mehrere Schwachstellen ermöglichen Denial of Service und unspezifischen Angriff</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1259</link>
      <description>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen im Linux-Kernel ausnutzen, um einen Denial-of-Service-Zustand zu erzeugen oder einen unspezifischen Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen im Linux-Kernel ausnutzen, um einen Denial-of-Service-Zustand zu erzeugen oder einen unspezifischen Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1259</guid>
    </item>
  </channel>
</rss>
