<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 06:06:25 +0000</lastBuildDate>
    <item>
      <title>ALSA-2024:5928 — Important: kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2024:5928</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: bpftool, AlmaLinux:9: kernel, AlmaLinux:9: kernel-64k, AlmaLinux:9: kernel-64k-core, AlmaLinux:9: kernel-64k-debug, AlmaLinux:9: kernel-64k-debug-core, AlmaLinux:9: kernel-64k-debug-devel, AlmaLinux:9: kernel-64k-debug-devel-matched, AlmaLinux:9: kernel-64k-debug-modules, AlmaLinux:9: kernel-64k-debug-modules-core and 52 more&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: nftables: nft_set_rbtree skip end interval element from gc (CVE-2024-26581)
  * kernel: netfilter: nft_limit: reject configurations that cause integer overflow (CVE-2024-26668)
  * kernel: vfio/pci: Lock external INTx masking ops (CVE-2024-26810)
  * kernel: net: ice: Fix potential NULL pointer dereference in ice_bridge_setlink() (CVE-2024-26855)
  * kernel: x86/xen: Add some null pointer checking to smp.c (CVE-2024-26908)
  * kernel: netfilter: nf_tables: release mutex after nft_gc_seq_end from abort path (CVE-2024-26925)
  * kernel: netfilter: nf_tables: Fix potential data-race in __nft_expr_type_get() (CVE-2024-27020)
  * kernel: netfilter: nf_tables: Fix potential data-race in __nft_obj_type_get() (CVE-2024-27019)
  * kernel: netfilter: flowtable: validate pppoe header (CVE-2024-27016)
  * kernel: netfilter: bridge: confirm multicast packets before passing them up the stack (CVE-2024-27415)
  * kernel: netfilter: bridge: replace physindev with physinif in nf_bridge_info (CVE-2024-35839)
  * kernel: netfilter: nf_tables: Fix potential data-race in __nft_flowtable_type_get() (CVE-2024-35898)
  * kernel: netfilter: nf_tables: discard table flag update with pending basechain deletion (CVE-2024-35897)
  * kernel: netfilter: validate user input for expected length (CVE-2024-35896)
  * kernel: netfilter: complete validation of user input (CVE-2024-35962)
  *…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: bpftool, AlmaLinux:9: kernel, AlmaLinux:9: kernel-64k, AlmaLinux:9: kernel-64k-core, AlmaLinux:9: kernel-64k-debug, AlmaLinux:9: kernel-64k-debug-core, AlmaLinux:9: kernel-64k-debug-devel, AlmaLinux:9: kernel-64k-debug-devel-matched, AlmaLinux:9: kernel-64k-debug-modules, AlmaLinux:9: kernel-64k-debug-modules-core and 52 more&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: nftables: nft_set_rbtree skip end interval element from gc (CVE-2024-26581)
  * kernel: netfilter: nft_limit: reject configurations that cause integer overflow (CVE-2024-26668)
  * kernel: vfio/pci: Lock external INTx masking ops (CVE-2024-26810)
  * kernel: net: ice: Fix potential NULL pointer dereference in ice_bridge_setlink() (CVE-2024-26855)
  * kernel: x86/xen: Add some null pointer checking to smp.c (CVE-2024-26908)
  * kernel: netfilter: nf_tables: release mutex after nft_gc_seq_end from abort path (CVE-2024-26925)
  * kernel: netfilter: nf_tables: Fix potential data-race in __nft_expr_type_get() (CVE-2024-27020)
  * kernel: netfilter: nf_tables: Fix potential data-race in __nft_obj_type_get() (CVE-2024-27019)
  * kernel: netfilter: flowtable: validate pppoe header (CVE-2024-27016)
  * kernel: netfilter: bridge: confirm multicast packets before passing them up the stack (CVE-2024-27415)
  * kernel: netfilter: bridge: replace physindev with physinif in nf_bridge_info (CVE-2024-35839)
  * kernel: netfilter: nf_tables: Fix potential data-race in __nft_flowtable_type_get() (CVE-2024-35898)
  * kernel: netfilter: nf_tables: discard table flag update with pending basechain deletion (CVE-2024-35897)
  * kernel: netfilter: validate user input for expected length (CVE-2024-35896)
  * kernel: netfilter: complete validation of user input (CVE-2024-35962)
  *…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2024:5928</guid>
    </item>
    <item>
      <title>bdu:2025-08063</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-08063</link>
      <description>bdu:2025-08063</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-08063</guid>
    </item>
    <item>
      <title>BELL-CVE-2024-38540</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2024-38540</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2024-38540</guid>
    </item>
    <item>
      <title>certfr-2024-avi-0578 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de SUSE. Certaines d'entre elles permettent à un at…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0578</link>
      <description>certfr-2024-avi-0578</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2024-avi-0578</guid>
    </item>
    <item>
      <title>EUVD-2026-312864</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-312864</link>
      <description>EUVD-2026-312864</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-312864</guid>
    </item>
    <item>
      <title>fkie_cve-2024-38540</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-38540</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;bnxt_re: avoid shift undefined behavior in bnxt_qplib_alloc_init_hwq&lt;/p&gt;
&lt;p&gt;Undefined behavior is triggered when bnxt_qplib_alloc_init_hwq is called
with hwq_attr-&amp;gt;aux_depth != 0 and hwq_attr-&amp;gt;aux_stride == 0.
In that case, &amp;#34;roundup_pow_of_two(hwq_attr-&amp;gt;aux_stride)&amp;#34; gets called.
roundup_pow_of_two is documented as undefined for 0.&lt;/p&gt;
&lt;p&gt;Fix it in the one caller that had this combination.&lt;/p&gt;
&lt;p&gt;The undefined behavior was detected by UBSAN:
  UBSAN: shift-out-of-bounds in ./include/linux/log2.h:57:13
  shift exponent 64 is too large for 64-bit type &amp;#39;long unsigned int&amp;#39;
  CPU: 24 PID: 1075 Comm: (udev-worker) Not tainted 6.9.0-rc6+ #4
  Hardware name: Abacus electric, s.r.o. - servis@abacus.cz Super Server/H12SSW-iN, BIOS 2.7 10/25/2023
  Call Trace:
   &amp;lt;TASK&amp;gt;
   dump_stack_lvl+0x5d/0x80
   ubsan_epilogue+0x5/0x30
   __ubsan_handle_shift_out_of_bounds.cold+0x61/0xec
   __roundup_pow_of_two+0x25/0x35 [bnxt_re]
   bnxt_qplib_alloc_init_hwq+0xa1/0x470 [bnxt_re]
   bnxt_qplib_create_qp+0x19e/0x840 [bnxt_re]
   bnxt_re_create_qp+0x9b1/0xcd0 [bnxt_re]
   ? srso_alias_return_thunk+0x5/0xfbef5
   ? srso_alias_return_thunk+0x5/0xfbef5
   ? __kmalloc+0x1b6/0x4f0
   ? create_qp.part.0+0x128/0x1c0 [ib_core]
   ? __pfx_bnxt_re_create_qp+0x10/0x10 [bnxt_re]
   create_qp.part.0+0x128/0x1c0 [ib_core]
   ib_create_qp_kernel+0x50/0xd0 [ib_core]
   create_mad_qp+0x8e/0xe0 [ib_core]
   ? __pfx_qp_event_handler+0x10/0x10 [ib_core]
   ib_mad_init_d…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;bnxt_re: avoid shift undefined behavior in bnxt_qplib_alloc_init_hwq&lt;/p&gt;
&lt;p&gt;Undefined behavior is triggered when bnxt_qplib_alloc_init_hwq is called
with hwq_attr-&amp;gt;aux_depth != 0 and hwq_attr-&amp;gt;aux_stride == 0.
In that case, &amp;#34;roundup_pow_of_two(hwq_attr-&amp;gt;aux_stride)&amp;#34; gets called.
roundup_pow_of_two is documented as undefined for 0.&lt;/p&gt;
&lt;p&gt;Fix it in the one caller that had this combination.&lt;/p&gt;
&lt;p&gt;The undefined behavior was detected by UBSAN:
  UBSAN: shift-out-of-bounds in ./include/linux/log2.h:57:13
  shift exponent 64 is too large for 64-bit type &amp;#39;long unsigned int&amp;#39;
  CPU: 24 PID: 1075 Comm: (udev-worker) Not tainted 6.9.0-rc6+ #4
  Hardware name: Abacus electric, s.r.o. - servis@abacus.cz Super Server/H12SSW-iN, BIOS 2.7 10/25/2023
  Call Trace:
   &amp;lt;TASK&amp;gt;
   dump_stack_lvl+0x5d/0x80
   ubsan_epilogue+0x5/0x30
   __ubsan_handle_shift_out_of_bounds.cold+0x61/0xec
   __roundup_pow_of_two+0x25/0x35 [bnxt_re]
   bnxt_qplib_alloc_init_hwq+0xa1/0x470 [bnxt_re]
   bnxt_qplib_create_qp+0x19e/0x840 [bnxt_re]
   bnxt_re_create_qp+0x9b1/0xcd0 [bnxt_re]
   ? srso_alias_return_thunk+0x5/0xfbef5
   ? srso_alias_return_thunk+0x5/0xfbef5
   ? __kmalloc+0x1b6/0x4f0
   ? create_qp.part.0+0x128/0x1c0 [ib_core]
   ? __pfx_bnxt_re_create_qp+0x10/0x10 [bnxt_re]
   create_qp.part.0+0x128/0x1c0 [ib_core]
   ib_create_qp_kernel+0x50/0xd0 [ib_core]
   create_mad_qp+0x8e/0xe0 [ib_core]
   ? __pfx_qp_event_handler+0x10/0x10 [ib_core]
   ib_mad_init_d…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-38540</guid>
    </item>
    <item>
      <title>GHSA-h5r4-f5wx-726x</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-h5r4-f5wx-726x</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;bnxt_re: avoid shift undefined behavior in bnxt_qplib_alloc_init_hwq&lt;/p&gt;
&lt;p&gt;Undefined behavior is triggered when bnxt_qplib_alloc_init_hwq is called
with hwq_attr-&amp;gt;aux_depth != 0 and hwq_attr-&amp;gt;aux_stride == 0.
In that case, &amp;#34;roundup_pow_of_two(hwq_attr-&amp;gt;aux_stride)&amp;#34; gets called.
roundup_pow_of_two is documented as undefined for 0.&lt;/p&gt;
&lt;p&gt;Fix it in the one caller that had this combination.&lt;/p&gt;
&lt;p&gt;The undefined behavior was detected by UBSAN:
  UBSAN: shift-out-of-bounds in ./include/linux/log2.h:57:13
  shift exponent 64 is too large for 64-bit type &amp;#39;long unsigned int&amp;#39;
  CPU: 24 PID: 1075 Comm: (udev-worker) Not tainted 6.9.0-rc6+ #4
  Hardware name: Abacus electric, s.r.o. - servis@abacus.cz Super Server/H12SSW-iN, BIOS 2.7 10/25/2023
  Call Trace:
   &amp;lt;TASK&amp;gt;
   dump_stack_lvl+0x5d/0x80
   ubsan_epilogue+0x5/0x30
   __ubsan_handle_shift_out_of_bounds.cold+0x61/0xec
   __roundup_pow_of_two+0x25/0x35 [bnxt_re]
   bnxt_qplib_alloc_init_hwq+0xa1/0x470 [bnxt_re]
   bnxt_qplib_create_qp+0x19e/0x840 [bnxt_re]
   bnxt_re_create_qp+0x9b1/0xcd0 [bnxt_re]
   ? srso_alias_return_thunk+0x5/0xfbef5
   ? srso_alias_return_thunk+0x5/0xfbef5
   ? __kmalloc+0x1b6/0x4f0
   ? create_qp.part.0+0x128/0x1c0 [ib_core]
   ? __pfx_bnxt_re_create_qp+0x10/0x10 [bnxt_re]
   create_qp.part.0+0x128/0x1c0 [ib_core]
   ib_create_qp_kernel+0x50/0xd0 [ib_core]
   create_mad_qp+0x8e/0xe0 [ib_core]
   ? __pfx_qp_event_handler+0x10/0x10 [ib_core]
   ib_mad_init_d…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;bnxt_re: avoid shift undefined behavior in bnxt_qplib_alloc_init_hwq&lt;/p&gt;
&lt;p&gt;Undefined behavior is triggered when bnxt_qplib_alloc_init_hwq is called
with hwq_attr-&amp;gt;aux_depth != 0 and hwq_attr-&amp;gt;aux_stride == 0.
In that case, &amp;#34;roundup_pow_of_two(hwq_attr-&amp;gt;aux_stride)&amp;#34; gets called.
roundup_pow_of_two is documented as undefined for 0.&lt;/p&gt;
&lt;p&gt;Fix it in the one caller that had this combination.&lt;/p&gt;
&lt;p&gt;The undefined behavior was detected by UBSAN:
  UBSAN: shift-out-of-bounds in ./include/linux/log2.h:57:13
  shift exponent 64 is too large for 64-bit type &amp;#39;long unsigned int&amp;#39;
  CPU: 24 PID: 1075 Comm: (udev-worker) Not tainted 6.9.0-rc6+ #4
  Hardware name: Abacus electric, s.r.o. - servis@abacus.cz Super Server/H12SSW-iN, BIOS 2.7 10/25/2023
  Call Trace:
   &amp;lt;TASK&amp;gt;
   dump_stack_lvl+0x5d/0x80
   ubsan_epilogue+0x5/0x30
   __ubsan_handle_shift_out_of_bounds.cold+0x61/0xec
   __roundup_pow_of_two+0x25/0x35 [bnxt_re]
   bnxt_qplib_alloc_init_hwq+0xa1/0x470 [bnxt_re]
   bnxt_qplib_create_qp+0x19e/0x840 [bnxt_re]
   bnxt_re_create_qp+0x9b1/0xcd0 [bnxt_re]
   ? srso_alias_return_thunk+0x5/0xfbef5
   ? srso_alias_return_thunk+0x5/0xfbef5
   ? __kmalloc+0x1b6/0x4f0
   ? create_qp.part.0+0x128/0x1c0 [ib_core]
   ? __pfx_bnxt_re_create_qp+0x10/0x10 [bnxt_re]
   create_qp.part.0+0x128/0x1c0 [ib_core]
   ib_create_qp_kernel+0x50/0xd0 [ib_core]
   create_mad_qp+0x8e/0xe0 [ib_core]
   ? __pfx_qp_event_handler+0x10/0x10 [ib_core]
   ib_mad_init_d…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-h5r4-f5wx-726x</guid>
    </item>
    <item>
      <title>msrc_CVE-2024-38540 — bnxt_re: avoid shift undefined behavior in bnxt_qplib_alloc_init_hwq</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2024-38540</link>
      <description>msrc_CVE-2024-38540</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2024-38540</guid>
    </item>
    <item>
      <title>OESA-2024-1860 — kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2024-1860</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP1: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&#13;
&#13;
In the Linux kernel, the following vulnerability has been resolved:&#13;
&#13;
RDMA/cma: Ensure rdma_addr_cancel() happens before issuing more requests&#13;
&#13;
The FSM can run in a circle allowing rdma_resolve_ip() to be called twice
on the same id_priv. While this cannot happen without going through the
work, it violates the invariant that the same address resolution
background request cannot be active twice.&#13;
&#13;
       CPU 1                                  CPU 2&#13;
&#13;
rdma_resolve_addr():
  RDMA_CM_IDLE -&amp;amp;gt; RDMA_CM_ADDR_QUERY
  rdma_resolve_ip(addr_handler)  #1&#13;
&#13;
			 process_one_req(): for #1
                          addr_handler():
                            RDMA_CM_ADDR_QUERY -&amp;amp;gt; RDMA_CM_ADDR_BOUND
                            mutex_unlock(&amp;amp;amp;id_priv-&amp;amp;gt;handler_mutex);
                            [.. handler still running ..]&#13;
&#13;
rdma_resolve_addr():
  RDMA_CM_ADDR_BOUND -&amp;amp;gt; RDMA_CM_ADDR_QUERY
  rdma_resolve_ip(addr_handler)
    !! two requests are now on the req_list&#13;
&#13;
rdma_destroy_id():
 destroy_id_handler_unlock():
  _destroy_id():
   cma_cancel_operation():
    rdma_addr_cancel()&#13;
&#13;
                          // process_one_req() self removes it
		          spin_lock_bh(&amp;amp;amp;lock);
                           cancel_delayed_work(&amp;amp;amp;req-&amp;amp;gt;work);
	                   if (!list_empty(&amp;amp;amp;req-&amp;amp;gt;list)) == true&#13;
&#13;
      ! rdma_addr_cancel() returns after process_on_req #1 is done&#13;
&#13;
   kfree(id_priv…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP1: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&#13;
&#13;
In the Linux kernel, the following vulnerability has been resolved:&#13;
&#13;
RDMA/cma: Ensure rdma_addr_cancel() happens before issuing more requests&#13;
&#13;
The FSM can run in a circle allowing rdma_resolve_ip() to be called twice
on the same id_priv. While this cannot happen without going through the
work, it violates the invariant that the same address resolution
background request cannot be active twice.&#13;
&#13;
       CPU 1                                  CPU 2&#13;
&#13;
rdma_resolve_addr():
  RDMA_CM_IDLE -&amp;amp;gt; RDMA_CM_ADDR_QUERY
  rdma_resolve_ip(addr_handler)  #1&#13;
&#13;
			 process_one_req(): for #1
                          addr_handler():
                            RDMA_CM_ADDR_QUERY -&amp;amp;gt; RDMA_CM_ADDR_BOUND
                            mutex_unlock(&amp;amp;amp;id_priv-&amp;amp;gt;handler_mutex);
                            [.. handler still running ..]&#13;
&#13;
rdma_resolve_addr():
  RDMA_CM_ADDR_BOUND -&amp;amp;gt; RDMA_CM_ADDR_QUERY
  rdma_resolve_ip(addr_handler)
    !! two requests are now on the req_list&#13;
&#13;
rdma_destroy_id():
 destroy_id_handler_unlock():
  _destroy_id():
   cma_cancel_operation():
    rdma_addr_cancel()&#13;
&#13;
                          // process_one_req() self removes it
		          spin_lock_bh(&amp;amp;amp;lock);
                           cancel_delayed_work(&amp;amp;amp;req-&amp;amp;gt;work);
	                   if (!list_empty(&amp;amp;amp;req-&amp;amp;gt;list)) == true&#13;
&#13;
      ! rdma_addr_cancel() returns after process_on_req #1 is done&#13;
&#13;
   kfree(id_priv…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2024-1860</guid>
    </item>
    <item>
      <title>RHSA-2024:5928 — Red Hat Security Advisory: kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2024:5928</link>
      <description>&lt;p&gt;kernel: x86/xen: Fix memory leak in xen_smp_intr_init{_pv}() kernel: cxl/port: Fix delete_endpoint() vs parent unregistration race kernel: tty: n_gsm: require CAP_NET_ADMIN to attach N_GSM0710 ldisc kernel: nftables: nft_set_rbtree skip end interval element from gc kernel: netfilter: nft_limit: reject configurations that cause integer overflow kernel: vfio/pci: Lock external INTx masking ops kernel: net: ice: Fix potential NULL pointer dereference in ice_bridge_setlink() kernel: x86/xen: Add some null pointer checking to smp.c kernel: netfilter: nf_tables: release mutex after nft_gc_seq_end from abort path kernel: netfilter: flowtable: validate pppoe header kernel: netfilter: nf_tables: Fix potential data-race in __nft_obj_type_get() kernel: netfilter: nf_tables: Fix potential data-race in __nft_expr_type_get() kernel: netfilter: bridge: confirm multicast packets before passing them up the stack kernel: netfilter: bridge: replace physindev with physinif in nf_bridge_info kernel: netfilter: validate user input for expected length kernel: netfilter: nf_tables: discard table flag update with pending basechain deletion kernel: netfilter: nf_tables: Fix potential data-race in __nft_flowtable_type_get() kernel: netfilter: complete validation of user input kernel: ice: fix LAG and VF lock dependency in ice_reset_vf() kernel: scsi: qla2xxx: Fix off by one in qla_edif_app_getstats() kernel: net: bridge: xmit: make sure we have at least eth header len bytes kernel: bnxt_re: avoid shif…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;kernel: x86/xen: Fix memory leak in xen_smp_intr_init{_pv}() kernel: cxl/port: Fix delete_endpoint() vs parent unregistration race kernel: tty: n_gsm: require CAP_NET_ADMIN to attach N_GSM0710 ldisc kernel: nftables: nft_set_rbtree skip end interval element from gc kernel: netfilter: nft_limit: reject configurations that cause integer overflow kernel: vfio/pci: Lock external INTx masking ops kernel: net: ice: Fix potential NULL pointer dereference in ice_bridge_setlink() kernel: x86/xen: Add some null pointer checking to smp.c kernel: netfilter: nf_tables: release mutex after nft_gc_seq_end from abort path kernel: netfilter: flowtable: validate pppoe header kernel: netfilter: nf_tables: Fix potential data-race in __nft_obj_type_get() kernel: netfilter: nf_tables: Fix potential data-race in __nft_expr_type_get() kernel: netfilter: bridge: confirm multicast packets before passing them up the stack kernel: netfilter: bridge: replace physindev with physinif in nf_bridge_info kernel: netfilter: validate user input for expected length kernel: netfilter: nf_tables: discard table flag update with pending basechain deletion kernel: netfilter: nf_tables: Fix potential data-race in __nft_flowtable_type_get() kernel: netfilter: complete validation of user input kernel: ice: fix LAG and VF lock dependency in ice_reset_vf() kernel: scsi: qla2xxx: Fix off by one in qla_edif_app_getstats() kernel: net: bridge: xmit: make sure we have at least eth header len bytes kernel: bnxt_re: avoid shif…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2024:5928</guid>
    </item>
    <item>
      <title>RHSA-2024:6206 — Red Hat Security Advisory: kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2024:6206</link>
      <description>&lt;p&gt;kernel: ipc/mqueue, msg, sem: avoid relying on a stack reference past its expiry kernel: hwmon: (w83792d) Fix NULL pointer dereference by removing unnecessary structure field kernel: net: amd-xgbe: Fix skb data length underflow kernel: phylib: fix potential use-after-free kernel: net: fix information leakage in /proc/net/ptype kernel: drm: Don&amp;#39;t unref the same fb many times by mistake due to deadlock handling kernel: pstore/ram: Fix crash when setting number of cpus to an odd number kernel: TCP-spoofed ghost ACKs and leak leak initial sequence number kernel: drm/amdgpu: Fix possible null pointer dereference kernel: dmaengine/idxd: hardware erratum allows potential security problem with direct access by untrusted application kernel: mm/writeback: fix possible divide-by-zero in wb_dirty_limits(), again kernel: vfio/pci: Lock external INTx masking ops kernel: net/ipv6: avoid possible UAF in ip6_route_mpath_notify() kernel: igc: avoid returning frame twice in XDP_REDIRECT kernel: crypto: qat - resolve race condition during AER recovery kernel: fs: sysfs: Fix reference leak in sysfs_break_active_protection() kernel: ipvlan: Dont Use skb-&amp;amp;gt;sk in ipvlan_process_v{4,6}_outbound kernel: wifi: mac80211: check/clear fast rx for non-4addr sta VLAN changes kernel: wifi: iwlwifi: dbg-tlv: ensure NUL termination kernel: rtnetlink: Correct nested IFLA_VF_VLAN_LIST attribute validation kernel: tls: fix missing memory barrier in tls_init kernel: net: fix out-of-bounds access in ops_init ker…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;kernel: ipc/mqueue, msg, sem: avoid relying on a stack reference past its expiry kernel: hwmon: (w83792d) Fix NULL pointer dereference by removing unnecessary structure field kernel: net: amd-xgbe: Fix skb data length underflow kernel: phylib: fix potential use-after-free kernel: net: fix information leakage in /proc/net/ptype kernel: drm: Don&amp;#39;t unref the same fb many times by mistake due to deadlock handling kernel: pstore/ram: Fix crash when setting number of cpus to an odd number kernel: TCP-spoofed ghost ACKs and leak leak initial sequence number kernel: drm/amdgpu: Fix possible null pointer dereference kernel: dmaengine/idxd: hardware erratum allows potential security problem with direct access by untrusted application kernel: mm/writeback: fix possible divide-by-zero in wb_dirty_limits(), again kernel: vfio/pci: Lock external INTx masking ops kernel: net/ipv6: avoid possible UAF in ip6_route_mpath_notify() kernel: igc: avoid returning frame twice in XDP_REDIRECT kernel: crypto: qat - resolve race condition during AER recovery kernel: fs: sysfs: Fix reference leak in sysfs_break_active_protection() kernel: ipvlan: Dont Use skb-&amp;amp;gt;sk in ipvlan_process_v{4,6}_outbound kernel: wifi: mac80211: check/clear fast rx for non-4addr sta VLAN changes kernel: wifi: iwlwifi: dbg-tlv: ensure NUL termination kernel: rtnetlink: Correct nested IFLA_VF_VLAN_LIST attribute validation kernel: tls: fix missing memory barrier in tls_init kernel: net: fix out-of-bounds access in ops_init ker…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2024:6206</guid>
    </item>
    <item>
      <title>SUSE-SU-2024:2372-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2024:2372-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2024:2372-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2024-38540</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-38540</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 130 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: bnxt_re: avoid shift undefined behavior in bnxt_qplib_alloc_init_hwq Undefined behavior is triggered when bnxt_qplib_alloc_init_hwq is called with hwq_attr-&amp;gt;aux_depth != 0 and hwq_attr-&amp;gt;aux_stride == 0. In that case, &amp;#34;roundup_pow_of_two(hwq_attr-&amp;gt;aux_stride)&amp;#34; gets called. roundup_pow_of_two is documented as undefined for 0. Fix it in the one caller that had this combination. The undefined behavior was detected by UBSAN:   UBSAN: shift-out-of-bounds in ./include/linux/log2.h:57:13   shift exponent 64 is too large for 64-bit type &amp;#39;long unsigned int&amp;#39;   CPU: 24 PID: 1075 Comm: (udev-worker) Not tainted 6.9.0-rc6+ #4   Hardware name: Abacus electric, s.r.o. - servis@abacus.cz Super Server/H12SSW-iN, BIOS 2.7 10/25/2023   Call Trace:    &amp;lt;TASK&amp;gt;    dump_stack_lvl+0x5d/0x80    ubsan_epilogue+0x5/0x30    __ubsan_handle_shift_out_of_bounds.cold+0x61/0xec    __roundup_pow_of_two+0x25/0x35 [bnxt_re]    bnxt_qplib_alloc_init_hwq+0xa1/0x470 [bnxt_re]    bnxt_qplib_create_qp+0x19e/0x840 [bnxt_re]    bnxt_re_create_qp+0x9b1/0xcd0 [bnxt_re]    ? srso_alias_return_thunk+0x5/0xfbef5    ? srso_alias_return_thunk+0x5/0xfbef5    ? __kmalloc+0x1b6/0x4f0    ? create_qp.part.0+0x128/0x1c0 [ib_core]    ? __pfx_bnxt_re_create_qp+0x10/0x10 [bnxt_re]    create_qp.part.0+0x128/0x1c0 [ib_core]    ib_create_qp_kernel+0x50/0xd0 [ib_core]    create_mad_qp+0x8e/0xe0 [ib_core]    ? __pfx_qp_event_handler+0x10/0x10 [ib_core]    ib_mad_init_devic…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 130 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: bnxt_re: avoid shift undefined behavior in bnxt_qplib_alloc_init_hwq Undefined behavior is triggered when bnxt_qplib_alloc_init_hwq is called with hwq_attr-&amp;gt;aux_depth != 0 and hwq_attr-&amp;gt;aux_stride == 0. In that case, &amp;#34;roundup_pow_of_two(hwq_attr-&amp;gt;aux_stride)&amp;#34; gets called. roundup_pow_of_two is documented as undefined for 0. Fix it in the one caller that had this combination. The undefined behavior was detected by UBSAN:   UBSAN: shift-out-of-bounds in ./include/linux/log2.h:57:13   shift exponent 64 is too large for 64-bit type &amp;#39;long unsigned int&amp;#39;   CPU: 24 PID: 1075 Comm: (udev-worker) Not tainted 6.9.0-rc6+ #4   Hardware name: Abacus electric, s.r.o. - servis@abacus.cz Super Server/H12SSW-iN, BIOS 2.7 10/25/2023   Call Trace:    &amp;lt;TASK&amp;gt;    dump_stack_lvl+0x5d/0x80    ubsan_epilogue+0x5/0x30    __ubsan_handle_shift_out_of_bounds.cold+0x61/0xec    __roundup_pow_of_two+0x25/0x35 [bnxt_re]    bnxt_qplib_alloc_init_hwq+0xa1/0x470 [bnxt_re]    bnxt_qplib_create_qp+0x19e/0x840 [bnxt_re]    bnxt_re_create_qp+0x9b1/0xcd0 [bnxt_re]    ? srso_alias_return_thunk+0x5/0xfbef5    ? srso_alias_return_thunk+0x5/0xfbef5    ? __kmalloc+0x1b6/0x4f0    ? create_qp.part.0+0x128/0x1c0 [ib_core]    ? __pfx_bnxt_re_create_qp+0x10/0x10 [bnxt_re]    create_qp.part.0+0x128/0x1c0 [ib_core]    ib_create_qp_kernel+0x50/0xd0 [ib_core]    create_mad_qp+0x8e/0xe0 [ib_core]    ? __pfx_qp_event_handler+0x10/0x10 [ib_core]    ib_mad_init_devic…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-38540</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-1418 — Linux Kernel: Mehrere Schwachstellen ermöglichen nicht spezifizierten Angriff</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1418</link>
      <description>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1418</guid>
    </item>
  </channel>
</rss>
