<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 10:56:26 +0000</lastBuildDate>
    <item>
      <title>bdu:2024-11548</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2024-11548</link>
      <description>bdu:2024-11548</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2024-11548</guid>
    </item>
    <item>
      <title>BELL-CVE-2024-38600</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2024-38600</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2024-38600</guid>
    </item>
    <item>
      <title>certfr-2024-avi-0578 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de SUSE. Certaines d'entre elles permettent à un at…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0578</link>
      <description>certfr-2024-avi-0578</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2024-avi-0578</guid>
    </item>
    <item>
      <title>EUVD-2026-312885</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-312885</link>
      <description>EUVD-2026-312885</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-312885</guid>
    </item>
    <item>
      <title>fkie_cve-2024-38600</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-38600</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;ALSA: Fix deadlocks with kctl removals at disconnection&lt;/p&gt;
&lt;p&gt;In snd_card_disconnect(), we set card-&amp;gt;shutdown flag at the beginning,
call callbacks and do sync for card-&amp;gt;power_ref_sleep waiters at the
end.  The callback may delete a kctl element, and this can lead to a
deadlock when the device was in the suspended state.  Namely:&lt;/p&gt;
&lt;p&gt;* A process waits for the power up at snd_power_ref_and_wait() in
  snd_ctl_info() or read/write() inside card-&amp;gt;controls_rwsem.&lt;/p&gt;
&lt;p&gt;* The system gets disconnected meanwhile, and the driver tries to
  delete a kctl via snd_ctl_remove*(); it tries to take
  card-&amp;gt;controls_rwsem again, but this is already locked by the
  above.  Since the sleeper isn&amp;#39;t woken up, this deadlocks.&lt;/p&gt;
&lt;p&gt;An easy fix is to wake up sleepers before processing the driver
disconnect callbacks but right after setting the card-&amp;gt;shutdown flag.
Then all sleepers will abort immediately, and the code flows again.&lt;/p&gt;
&lt;p&gt;So, basically this patch moves the wait_event() call at the right
timing.  While we&amp;#39;re at it, just to be sure, call wait_event_all()
instead of wait_event(), although we don&amp;#39;t use exclusive events on
this queue for now.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;ALSA: Fix deadlocks with kctl removals at disconnection&lt;/p&gt;
&lt;p&gt;In snd_card_disconnect(), we set card-&amp;gt;shutdown flag at the beginning,
call callbacks and do sync for card-&amp;gt;power_ref_sleep waiters at the
end.  The callback may delete a kctl element, and this can lead to a
deadlock when the device was in the suspended state.  Namely:&lt;/p&gt;
&lt;p&gt;* A process waits for the power up at snd_power_ref_and_wait() in
  snd_ctl_info() or read/write() inside card-&amp;gt;controls_rwsem.&lt;/p&gt;
&lt;p&gt;* The system gets disconnected meanwhile, and the driver tries to
  delete a kctl via snd_ctl_remove*(); it tries to take
  card-&amp;gt;controls_rwsem again, but this is already locked by the
  above.  Since the sleeper isn&amp;#39;t woken up, this deadlocks.&lt;/p&gt;
&lt;p&gt;An easy fix is to wake up sleepers before processing the driver
disconnect callbacks but right after setting the card-&amp;gt;shutdown flag.
Then all sleepers will abort immediately, and the code flows again.&lt;/p&gt;
&lt;p&gt;So, basically this patch moves the wait_event() call at the right
timing.  While we&amp;#39;re at it, just to be sure, call wait_event_all()
instead of wait_event(), although we don&amp;#39;t use exclusive events on
this queue for now.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-38600</guid>
    </item>
    <item>
      <title>GHSA-3h59-8483-h44f</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-3h59-8483-h44f</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;ALSA: Fix deadlocks with kctl removals at disconnection&lt;/p&gt;
&lt;p&gt;In snd_card_disconnect(), we set card-&amp;gt;shutdown flag at the beginning,
call callbacks and do sync for card-&amp;gt;power_ref_sleep waiters at the
end.  The callback may delete a kctl element, and this can lead to a
deadlock when the device was in the suspended state.  Namely:&lt;/p&gt;
&lt;p&gt;* A process waits for the power up at snd_power_ref_and_wait() in
  snd_ctl_info() or read/write() inside card-&amp;gt;controls_rwsem.&lt;/p&gt;
&lt;p&gt;* The system gets disconnected meanwhile, and the driver tries to
  delete a kctl via snd_ctl_remove*(); it tries to take
  card-&amp;gt;controls_rwsem again, but this is already locked by the
  above.  Since the sleeper isn&amp;#39;t woken up, this deadlocks.&lt;/p&gt;
&lt;p&gt;An easy fix is to wake up sleepers before processing the driver
disconnect callbacks but right after setting the card-&amp;gt;shutdown flag.
Then all sleepers will abort immediately, and the code flows again.&lt;/p&gt;
&lt;p&gt;So, basically this patch moves the wait_event() call at the right
timing.  While we&amp;#39;re at it, just to be sure, call wait_event_all()
instead of wait_event(), although we don&amp;#39;t use exclusive events on
this queue for now.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;ALSA: Fix deadlocks with kctl removals at disconnection&lt;/p&gt;
&lt;p&gt;In snd_card_disconnect(), we set card-&amp;gt;shutdown flag at the beginning,
call callbacks and do sync for card-&amp;gt;power_ref_sleep waiters at the
end.  The callback may delete a kctl element, and this can lead to a
deadlock when the device was in the suspended state.  Namely:&lt;/p&gt;
&lt;p&gt;* A process waits for the power up at snd_power_ref_and_wait() in
  snd_ctl_info() or read/write() inside card-&amp;gt;controls_rwsem.&lt;/p&gt;
&lt;p&gt;* The system gets disconnected meanwhile, and the driver tries to
  delete a kctl via snd_ctl_remove*(); it tries to take
  card-&amp;gt;controls_rwsem again, but this is already locked by the
  above.  Since the sleeper isn&amp;#39;t woken up, this deadlocks.&lt;/p&gt;
&lt;p&gt;An easy fix is to wake up sleepers before processing the driver
disconnect callbacks but right after setting the card-&amp;gt;shutdown flag.
Then all sleepers will abort immediately, and the code flows again.&lt;/p&gt;
&lt;p&gt;So, basically this patch moves the wait_event() call at the right
timing.  While we&amp;#39;re at it, just to be sure, call wait_event_all()
instead of wait_event(), although we don&amp;#39;t use exclusive events on
this queue for now.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-3h59-8483-h44f</guid>
    </item>
    <item>
      <title>OESA-2024-1960 — kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2024-1960</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&#13;
&#13;
In the Linux kernel, the following vulnerability has been resolved:&#13;
&#13;
efi: libstub: only free priv.runtime_map when allocated&#13;
&#13;
priv.runtime_map is only allocated when efi_novamap is not set.
Otherwise, it is an uninitialized value.  In the error path, it is freed
unconditionally.  Avoid passing an uninitialized value to free_pool.
Free priv.runtime_map only when it was allocated.&#13;
&#13;
This bug was discovered and resolved using Coverity Static Analysis
Security Testing (SAST) by Synopsys, Inc.(CVE-2024-33619)&#13;
&#13;
In the Linux kernel, the following vulnerability has been resolved:&#13;
&#13;
fpga: region: add owner module and take its refcount&#13;
&#13;
The current implementation of the fpga region assumes that the low-level
module registers a driver for the parent device and uses its owner pointer
to take the module&amp;amp;apos;s refcount. This approach is problematic since it can
lead to a null pointer dereference while attempting to get the region
during programming if the parent device does not have a driver.&#13;
&#13;
To address this problem, add a module owner pointer to the fpga_region
struct and use it to take the module&amp;amp;apos;s refcount. Modify the functions for
registering a region to take an additional owner module parameter and
rename them to avoid conflicts. Use the old function names for helper
macros that automatically set the module that registers the region as the
owner. This ensures compatibility with existing low…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&#13;
&#13;
In the Linux kernel, the following vulnerability has been resolved:&#13;
&#13;
efi: libstub: only free priv.runtime_map when allocated&#13;
&#13;
priv.runtime_map is only allocated when efi_novamap is not set.
Otherwise, it is an uninitialized value.  In the error path, it is freed
unconditionally.  Avoid passing an uninitialized value to free_pool.
Free priv.runtime_map only when it was allocated.&#13;
&#13;
This bug was discovered and resolved using Coverity Static Analysis
Security Testing (SAST) by Synopsys, Inc.(CVE-2024-33619)&#13;
&#13;
In the Linux kernel, the following vulnerability has been resolved:&#13;
&#13;
fpga: region: add owner module and take its refcount&#13;
&#13;
The current implementation of the fpga region assumes that the low-level
module registers a driver for the parent device and uses its owner pointer
to take the module&amp;amp;apos;s refcount. This approach is problematic since it can
lead to a null pointer dereference while attempting to get the region
during programming if the parent device does not have a driver.&#13;
&#13;
To address this problem, add a module owner pointer to the fpga_region
struct and use it to take the module&amp;amp;apos;s refcount. Modify the functions for
registering a region to take an additional owner module parameter and
rename them to avoid conflicts. Use the old function names for helper
macros that automatically set the module that registers the region as the
owner. This ensures compatibility with existing low…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2024-1960</guid>
    </item>
    <item>
      <title>RHSA-2024:9315 — Red Hat Security Advisory: kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2024:9315</link>
      <description>&lt;p&gt;kernel: use after free in i2c kernel: bluetooth: BR/EDR Bluetooth Impersonation Attacks (BIAS) kernel: hwmon: (lm90) Prevent integer overflow/underflow in hysteresis calculations kernel: asix: fix uninit-value in asix_mdio_read() kernel: tty: tty_buffer: Fix the softlockup issue in flush_to_ldisc kernel: hwmon: (w83793) Fix NULL pointer dereference by removing unnecessary structure field kernel: hwmon: (w83791d) Fix NULL pointer dereference by removing unnecessary structure field kernel: powerpc/64s: fix program check interrupt emergency stack path kernel: powerpc/64s: Fix unrecoverable MCE calling async handler from NMI kernel: lib/generic-radix-tree.c: Don&amp;#39;t overflow in peek() kernel: powerpc/smp: do not decrement idle task preempt count in CPU offline kernel: can: isotp: isotp_sendmsg(): add result check for wait_event_interruptible() kernel: usbnet: sanity check for maxpacket kernel: nvmem: Fix shift-out-of-bound (UBSAN) with byte size cells kernel: aio: fix use-after-free due to missing POLLFREE handling kernel: powerpc/pseries: Fix potential memleak in papr_get_attr() kernel: of: fdt: fix off-by-one error in unflatten_dt_nodes() kernel: thermal/int340x_thermal: handle data_vault when the value is ZERO_SIZE_PTR kernel: vt_ioctl: fix array_index_nospec in vt_setactivate kernel: bpf: Fix crash due to out of bounds access into reg2btf_ids. kernel: lz4: fix LZ4_decompress_safe_partial read out of bound kernel: x86/mce: Work around an erratum on fast string copy instructions…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;kernel: use after free in i2c kernel: bluetooth: BR/EDR Bluetooth Impersonation Attacks (BIAS) kernel: hwmon: (lm90) Prevent integer overflow/underflow in hysteresis calculations kernel: asix: fix uninit-value in asix_mdio_read() kernel: tty: tty_buffer: Fix the softlockup issue in flush_to_ldisc kernel: hwmon: (w83793) Fix NULL pointer dereference by removing unnecessary structure field kernel: hwmon: (w83791d) Fix NULL pointer dereference by removing unnecessary structure field kernel: powerpc/64s: fix program check interrupt emergency stack path kernel: powerpc/64s: Fix unrecoverable MCE calling async handler from NMI kernel: lib/generic-radix-tree.c: Don&amp;#39;t overflow in peek() kernel: powerpc/smp: do not decrement idle task preempt count in CPU offline kernel: can: isotp: isotp_sendmsg(): add result check for wait_event_interruptible() kernel: usbnet: sanity check for maxpacket kernel: nvmem: Fix shift-out-of-bound (UBSAN) with byte size cells kernel: aio: fix use-after-free due to missing POLLFREE handling kernel: powerpc/pseries: Fix potential memleak in papr_get_attr() kernel: of: fdt: fix off-by-one error in unflatten_dt_nodes() kernel: thermal/int340x_thermal: handle data_vault when the value is ZERO_SIZE_PTR kernel: vt_ioctl: fix array_index_nospec in vt_setactivate kernel: bpf: Fix crash due to out of bounds access into reg2btf_ids. kernel: lz4: fix LZ4_decompress_safe_partial read out of bound kernel: x86/mce: Work around an erratum on fast string copy instructions…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2024:9315</guid>
    </item>
    <item>
      <title>SUSE-SU-2024:2372-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2024:2372-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2024:2372-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2024-38600</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-38600</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux, Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe and 185 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: ALSA: Fix deadlocks with kctl removals at disconnection In snd_card_disconnect(), we set card-&amp;gt;shutdown flag at the beginning, call callbacks and do sync for card-&amp;gt;power_ref_sleep waiters at the end.  The callback may delete a kctl element, and this can lead to a deadlock when the device was in the suspended state.  Namely: * A process waits for the power up at snd_power_ref_and_wait() in   snd_ctl_info() or read/write() inside card-&amp;gt;controls_rwsem. * The system gets disconnected meanwhile, and the driver tries to   delete a kctl via snd_ctl_remove*(); it tries to take   card-&amp;gt;controls_rwsem again, but this is already locked by the   above.  Since the sleeper isn&amp;#39;t woken up, this deadlocks. An easy fix is to wake up sleepers before processing the driver disconnect callbacks but right after setting the card-&amp;gt;shutdown flag. Then all sleepers will abort immediately, and the code flows again. So, basically this patch moves the wait_event() call at the right timing.  While we&amp;#39;re at it, just to be sure, call wait_event_all() instead of wait_event(), although we don&amp;#39;t use exclusive events on this queue for now.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux, Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe and 185 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: ALSA: Fix deadlocks with kctl removals at disconnection In snd_card_disconnect(), we set card-&amp;gt;shutdown flag at the beginning, call callbacks and do sync for card-&amp;gt;power_ref_sleep waiters at the end.  The callback may delete a kctl element, and this can lead to a deadlock when the device was in the suspended state.  Namely: * A process waits for the power up at snd_power_ref_and_wait() in   snd_ctl_info() or read/write() inside card-&amp;gt;controls_rwsem. * The system gets disconnected meanwhile, and the driver tries to   delete a kctl via snd_ctl_remove*(); it tries to take   card-&amp;gt;controls_rwsem again, but this is already locked by the   above.  Since the sleeper isn&amp;#39;t woken up, this deadlocks. An easy fix is to wake up sleepers before processing the driver disconnect callbacks but right after setting the card-&amp;gt;shutdown flag. Then all sleepers will abort immediately, and the code flows again. So, basically this patch moves the wait_event() call at the right timing.  While we&amp;#39;re at it, just to be sure, call wait_event_all() instead of wait_event(), although we don&amp;#39;t use exclusive events on this queue for now.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-38600</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-1418 — Linux Kernel: Mehrere Schwachstellen ermöglichen nicht spezifizierten Angriff</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1418</link>
      <description>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1418</guid>
    </item>
  </channel>
</rss>
