<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 16:11:15 +0000</lastBuildDate>
    <item>
      <title>bdu:2024-11577</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2024-11577</link>
      <description>bdu:2024-11577</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2024-11577</guid>
    </item>
    <item>
      <title>BELL-CVE-2024-38614</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2024-38614</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2024-38614</guid>
    </item>
    <item>
      <title>certfr-2024-avi-0667 — De multiples vulnérabilités ont été découvertes dans le noyau Linux d'Ubuntu. Certaines d'entre elles permettent à un a…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0667</link>
      <description>certfr-2024-avi-0667</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2024-avi-0667</guid>
    </item>
    <item>
      <title>EUVD-2026-345831</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-345831</link>
      <description>EUVD-2026-345831</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-345831</guid>
    </item>
    <item>
      <title>fkie_cve-2024-38614</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-38614</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;openrisc: traps: Don&amp;#39;t send signals to kernel mode threads&lt;/p&gt;
&lt;p&gt;OpenRISC exception handling sends signals to user processes on floating
point exceptions and trap instructions (for debugging) among others.
There is a bug where the trap handling logic may send signals to kernel
threads, we should not send these signals to kernel threads, if that
happens we treat it as an error.&lt;/p&gt;
&lt;p&gt;This patch adds conditions to die if the kernel receives these
exceptions in kernel mode code.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;openrisc: traps: Don&amp;#39;t send signals to kernel mode threads&lt;/p&gt;
&lt;p&gt;OpenRISC exception handling sends signals to user processes on floating
point exceptions and trap instructions (for debugging) among others.
There is a bug where the trap handling logic may send signals to kernel
threads, we should not send these signals to kernel threads, if that
happens we treat it as an error.&lt;/p&gt;
&lt;p&gt;This patch adds conditions to die if the kernel receives these
exceptions in kernel mode code.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-38614</guid>
    </item>
    <item>
      <title>GHSA-q47h-3hgq-6c3p</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-q47h-3hgq-6c3p</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;openrisc: traps: Don&amp;#39;t send signals to kernel mode threads&lt;/p&gt;
&lt;p&gt;OpenRISC exception handling sends signals to user processes on floating
point exceptions and trap instructions (for debugging) among others.
There is a bug where the trap handling logic may send signals to kernel
threads, we should not send these signals to kernel threads, if that
happens we treat it as an error.&lt;/p&gt;
&lt;p&gt;This patch adds conditions to die if the kernel receives these
exceptions in kernel mode code.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;openrisc: traps: Don&amp;#39;t send signals to kernel mode threads&lt;/p&gt;
&lt;p&gt;OpenRISC exception handling sends signals to user processes on floating
point exceptions and trap instructions (for debugging) among others.
There is a bug where the trap handling logic may send signals to kernel
threads, we should not send these signals to kernel threads, if that
happens we treat it as an error.&lt;/p&gt;
&lt;p&gt;This patch adds conditions to die if the kernel receives these
exceptions in kernel mode code.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-q47h-3hgq-6c3p</guid>
    </item>
    <item>
      <title>OESA-2024-1863 — kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2024-1863</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&#13;
&#13;
In the Linux kernel, the following vulnerability has been resolved:&#13;
&#13;
rtnetlink: Correct nested IFLA_VF_VLAN_LIST attribute validation&#13;
&#13;
Each attribute inside a nested IFLA_VF_VLAN_LIST is assumed to be a
struct ifla_vf_vlan_info so the size of such attribute needs to be at least
of sizeof(struct ifla_vf_vlan_info) which is 14 bytes.
The current size validation in do_setvfinfo is against NLA_HDRLEN (4 bytes)
which is less than sizeof(struct ifla_vf_vlan_info) so this validation
is not enough and a too small attribute might be cast to a
struct ifla_vf_vlan_info, this might result in an out of bands
read access when accessing the saved (casted) entry in ivvl.(CVE-2024-36017)&#13;
&#13;
In the Linux kernel, the following vulnerability has been resolved:&#13;
&#13;
null_blk: fix null-ptr-dereference while configuring &amp;amp;apos;power&amp;amp;apos; and &amp;amp;apos;submit_queues&amp;amp;apos;&#13;
&#13;
Writing &amp;amp;apos;power&amp;amp;apos; and &amp;amp;apos;submit_queues&amp;amp;apos; concurrently will trigger kernel
panic:&#13;
&#13;
Test script:&#13;
&#13;
modprobe null_blk nr_devices=0
mkdir -p /sys/kernel/config/nullb/nullb0
while true; do echo 1 &amp;amp;gt; submit_queues; echo 4 &amp;amp;gt; submit_queues; done &amp;amp;amp;
while true; do echo 1 &amp;amp;gt; power; echo 0 &amp;amp;gt; power; done&#13;
&#13;
Test result:&#13;
&#13;
BUG: kernel NULL pointer dereference, address: 0000000000000148
Oops: 0000 [#1] PREEMPT SMP
RIP: 0010:__lock_acquire+0x41d/0x28f0
Call Trace:
 &amp;amp;lt;TASK&amp;amp;gt;
 lock_acquire+0x121/0x450
 down_write+0x5f/0x1d0
 simple_recu…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&#13;
&#13;
In the Linux kernel, the following vulnerability has been resolved:&#13;
&#13;
rtnetlink: Correct nested IFLA_VF_VLAN_LIST attribute validation&#13;
&#13;
Each attribute inside a nested IFLA_VF_VLAN_LIST is assumed to be a
struct ifla_vf_vlan_info so the size of such attribute needs to be at least
of sizeof(struct ifla_vf_vlan_info) which is 14 bytes.
The current size validation in do_setvfinfo is against NLA_HDRLEN (4 bytes)
which is less than sizeof(struct ifla_vf_vlan_info) so this validation
is not enough and a too small attribute might be cast to a
struct ifla_vf_vlan_info, this might result in an out of bands
read access when accessing the saved (casted) entry in ivvl.(CVE-2024-36017)&#13;
&#13;
In the Linux kernel, the following vulnerability has been resolved:&#13;
&#13;
null_blk: fix null-ptr-dereference while configuring &amp;amp;apos;power&amp;amp;apos; and &amp;amp;apos;submit_queues&amp;amp;apos;&#13;
&#13;
Writing &amp;amp;apos;power&amp;amp;apos; and &amp;amp;apos;submit_queues&amp;amp;apos; concurrently will trigger kernel
panic:&#13;
&#13;
Test script:&#13;
&#13;
modprobe null_blk nr_devices=0
mkdir -p /sys/kernel/config/nullb/nullb0
while true; do echo 1 &amp;amp;gt; submit_queues; echo 4 &amp;amp;gt; submit_queues; done &amp;amp;amp;
while true; do echo 1 &amp;amp;gt; power; echo 0 &amp;amp;gt; power; done&#13;
&#13;
Test result:&#13;
&#13;
BUG: kernel NULL pointer dereference, address: 0000000000000148
Oops: 0000 [#1] PREEMPT SMP
RIP: 0010:__lock_acquire+0x41d/0x28f0
Call Trace:
 &amp;amp;lt;TASK&amp;amp;gt;
 lock_acquire+0x121/0x450
 down_write+0x5f/0x1d0
 simple_recu…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2024-1863</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2024-38614</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-38614</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 88 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: openrisc: traps: Don&amp;#39;t send signals to kernel mode threads OpenRISC exception handling sends signals to user processes on floating point exceptions and trap instructions (for debugging) among others. There is a bug where the trap handling logic may send signals to kernel threads, we should not send these signals to kernel threads, if that happens we treat it as an error. This patch adds conditions to die if the kernel receives these exceptions in kernel mode code.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 88 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: openrisc: traps: Don&amp;#39;t send signals to kernel mode threads OpenRISC exception handling sends signals to user processes on floating point exceptions and trap instructions (for debugging) among others. There is a bug where the trap handling logic may send signals to kernel threads, we should not send these signals to kernel threads, if that happens we treat it as an error. This patch adds conditions to die if the kernel receives these exceptions in kernel mode code.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-38614</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-1418 — Linux Kernel: Mehrere Schwachstellen ermöglichen nicht spezifizierten Angriff</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1418</link>
      <description>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1418</guid>
    </item>
  </channel>
</rss>
