<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 10:15:14 +0000</lastBuildDate>
    <item>
      <title>bdu:2024-07403</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2024-07403</link>
      <description>bdu:2024-07403</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2024-07403</guid>
    </item>
    <item>
      <title>BELL-CVE-2024-38620</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2024-38620</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2024-38620</guid>
    </item>
    <item>
      <title>certfr-2024-avi-0667 — De multiples vulnérabilités ont été découvertes dans le noyau Linux d'Ubuntu. Certaines d'entre elles permettent à un a…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0667</link>
      <description>certfr-2024-avi-0667</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2024-avi-0667</guid>
    </item>
    <item>
      <title>EUVD-2026-357806</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-357806</link>
      <description>EUVD-2026-357806</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-357806</guid>
    </item>
    <item>
      <title>fkie_cve-2024-38620</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-38620</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;Bluetooth: HCI: Remove HCI_AMP support&lt;/p&gt;
&lt;p&gt;Since BT_HS has been remove HCI_AMP controllers no longer has any use so
remove it along with the capability of creating AMP controllers.&lt;/p&gt;
&lt;p&gt;Since we no longer need to differentiate between AMP and Primary
controllers, as only HCI_PRIMARY is left, this also remove
hdev-&amp;gt;dev_type altogether.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;Bluetooth: HCI: Remove HCI_AMP support&lt;/p&gt;
&lt;p&gt;Since BT_HS has been remove HCI_AMP controllers no longer has any use so
remove it along with the capability of creating AMP controllers.&lt;/p&gt;
&lt;p&gt;Since we no longer need to differentiate between AMP and Primary
controllers, as only HCI_PRIMARY is left, this also remove
hdev-&amp;gt;dev_type altogether.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-38620</guid>
    </item>
    <item>
      <title>GHSA-xhv2-gw9c-73rm</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-xhv2-gw9c-73rm</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;Bluetooth: HCI: Remove HCI_AMP support&lt;/p&gt;
&lt;p&gt;Since BT_HS has been remove HCI_AMP controllers no longer has any use so
remove it along with the capability of creating AMP controllers.&lt;/p&gt;
&lt;p&gt;Since we no longer need to differentiate between AMP and Primary
controllers, as only HCI_PRIMARY is left, this also remove
hdev-&amp;gt;dev_type altogether.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;Bluetooth: HCI: Remove HCI_AMP support&lt;/p&gt;
&lt;p&gt;Since BT_HS has been remove HCI_AMP controllers no longer has any use so
remove it along with the capability of creating AMP controllers.&lt;/p&gt;
&lt;p&gt;Since we no longer need to differentiate between AMP and Primary
controllers, as only HCI_PRIMARY is left, this also remove
hdev-&amp;gt;dev_type altogether.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-xhv2-gw9c-73rm</guid>
    </item>
    <item>
      <title>msrc_CVE-2024-38620 — Bluetooth: HCI: Remove HCI_AMP support</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2024-38620</link>
      <description>msrc_CVE-2024-38620</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2024-38620</guid>
    </item>
    <item>
      <title>OESA-2024-1863 — kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2024-1863</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&#13;
&#13;
In the Linux kernel, the following vulnerability has been resolved:&#13;
&#13;
rtnetlink: Correct nested IFLA_VF_VLAN_LIST attribute validation&#13;
&#13;
Each attribute inside a nested IFLA_VF_VLAN_LIST is assumed to be a
struct ifla_vf_vlan_info so the size of such attribute needs to be at least
of sizeof(struct ifla_vf_vlan_info) which is 14 bytes.
The current size validation in do_setvfinfo is against NLA_HDRLEN (4 bytes)
which is less than sizeof(struct ifla_vf_vlan_info) so this validation
is not enough and a too small attribute might be cast to a
struct ifla_vf_vlan_info, this might result in an out of bands
read access when accessing the saved (casted) entry in ivvl.(CVE-2024-36017)&#13;
&#13;
In the Linux kernel, the following vulnerability has been resolved:&#13;
&#13;
null_blk: fix null-ptr-dereference while configuring &amp;amp;apos;power&amp;amp;apos; and &amp;amp;apos;submit_queues&amp;amp;apos;&#13;
&#13;
Writing &amp;amp;apos;power&amp;amp;apos; and &amp;amp;apos;submit_queues&amp;amp;apos; concurrently will trigger kernel
panic:&#13;
&#13;
Test script:&#13;
&#13;
modprobe null_blk nr_devices=0
mkdir -p /sys/kernel/config/nullb/nullb0
while true; do echo 1 &amp;amp;gt; submit_queues; echo 4 &amp;amp;gt; submit_queues; done &amp;amp;amp;
while true; do echo 1 &amp;amp;gt; power; echo 0 &amp;amp;gt; power; done&#13;
&#13;
Test result:&#13;
&#13;
BUG: kernel NULL pointer dereference, address: 0000000000000148
Oops: 0000 [#1] PREEMPT SMP
RIP: 0010:__lock_acquire+0x41d/0x28f0
Call Trace:
 &amp;amp;lt;TASK&amp;amp;gt;
 lock_acquire+0x121/0x450
 down_write+0x5f/0x1d0
 simple_recu…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&#13;
&#13;
In the Linux kernel, the following vulnerability has been resolved:&#13;
&#13;
rtnetlink: Correct nested IFLA_VF_VLAN_LIST attribute validation&#13;
&#13;
Each attribute inside a nested IFLA_VF_VLAN_LIST is assumed to be a
struct ifla_vf_vlan_info so the size of such attribute needs to be at least
of sizeof(struct ifla_vf_vlan_info) which is 14 bytes.
The current size validation in do_setvfinfo is against NLA_HDRLEN (4 bytes)
which is less than sizeof(struct ifla_vf_vlan_info) so this validation
is not enough and a too small attribute might be cast to a
struct ifla_vf_vlan_info, this might result in an out of bands
read access when accessing the saved (casted) entry in ivvl.(CVE-2024-36017)&#13;
&#13;
In the Linux kernel, the following vulnerability has been resolved:&#13;
&#13;
null_blk: fix null-ptr-dereference while configuring &amp;amp;apos;power&amp;amp;apos; and &amp;amp;apos;submit_queues&amp;amp;apos;&#13;
&#13;
Writing &amp;amp;apos;power&amp;amp;apos; and &amp;amp;apos;submit_queues&amp;amp;apos; concurrently will trigger kernel
panic:&#13;
&#13;
Test script:&#13;
&#13;
modprobe null_blk nr_devices=0
mkdir -p /sys/kernel/config/nullb/nullb0
while true; do echo 1 &amp;amp;gt; submit_queues; echo 4 &amp;amp;gt; submit_queues; done &amp;amp;amp;
while true; do echo 1 &amp;amp;gt; power; echo 0 &amp;amp;gt; power; done&#13;
&#13;
Test result:&#13;
&#13;
BUG: kernel NULL pointer dereference, address: 0000000000000148
Oops: 0000 [#1] PREEMPT SMP
RIP: 0010:__lock_acquire+0x41d/0x28f0
Call Trace:
 &amp;amp;lt;TASK&amp;amp;gt;
 lock_acquire+0x121/0x450
 down_write+0x5f/0x1d0
 simple_recu…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2024-1863</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2024-38620</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-38620</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 78 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: Bluetooth: HCI: Remove HCI_AMP support Since BT_HS has been remove HCI_AMP controllers no longer has any use so remove it along with the capability of creating AMP controllers. Since we no longer need to differentiate between AMP and Primary controllers, as only HCI_PRIMARY is left, this also remove hdev-&amp;gt;dev_type altogether.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 78 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: Bluetooth: HCI: Remove HCI_AMP support Since BT_HS has been remove HCI_AMP controllers no longer has any use so remove it along with the capability of creating AMP controllers. Since we no longer need to differentiate between AMP and Primary controllers, as only HCI_PRIMARY is left, this also remove hdev-&amp;gt;dev_type altogether.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-38620</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-1418 — Linux Kernel: Mehrere Schwachstellen ermöglichen nicht spezifizierten Angriff</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1418</link>
      <description>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1418</guid>
    </item>
  </channel>
</rss>
