<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 13:00:24 +0000</lastBuildDate>
    <item>
      <title>bdu:2024-11002</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2024-11002</link>
      <description>bdu:2024-11002</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2024-11002</guid>
    </item>
    <item>
      <title>BELL-CVE-2024-40900</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2024-40900</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2024-40900</guid>
    </item>
    <item>
      <title>certfr-2024-avi-0613 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de Debian. Elles permettent à un attaquant de provo…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0613</link>
      <description>certfr-2024-avi-0613</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2024-avi-0613</guid>
    </item>
    <item>
      <title>EUVD-2026-345863</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-345863</link>
      <description>EUVD-2026-345863</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-345863</guid>
    </item>
    <item>
      <title>fkie_cve-2024-40900</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-40900</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;cachefiles: remove requests from xarray during flushing requests&lt;/p&gt;
&lt;p&gt;Even with CACHEFILES_DEAD set, we can still read the requests, so in the
following concurrency the request may be used after it has been freed:&lt;/p&gt;
&lt;p&gt;mount  |   daemon_thread1    |    daemon_thread2
------------------------------------------------------------
 cachefiles_ondemand_init_object
  cachefiles_ondemand_send_req
   REQ_A = kzalloc(sizeof(*req) + data_len)
   wait_for_completion(&amp;amp;REQ_A-&amp;gt;done)
            cachefiles_daemon_read
             cachefiles_ondemand_daemon_read
                                  // close dev fd
                                  cachefiles_flush_reqs
                                   complete(&amp;amp;REQ_A-&amp;gt;done)
   kfree(REQ_A)
              xa_lock(&amp;amp;cache-&amp;gt;reqs);
              cachefiles_ondemand_select_req
                req-&amp;gt;msg.opcode != CACHEFILES_OP_READ
                // req use-after-free !!!
              xa_unlock(&amp;amp;cache-&amp;gt;reqs);
                                   xa_destroy(&amp;amp;cache-&amp;gt;reqs)&lt;/p&gt;
&lt;p&gt;Hence remove requests from cache-&amp;gt;reqs when flushing them to avoid
accessing freed requests.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;cachefiles: remove requests from xarray during flushing requests&lt;/p&gt;
&lt;p&gt;Even with CACHEFILES_DEAD set, we can still read the requests, so in the
following concurrency the request may be used after it has been freed:&lt;/p&gt;
&lt;p&gt;mount  |   daemon_thread1    |    daemon_thread2
------------------------------------------------------------
 cachefiles_ondemand_init_object
  cachefiles_ondemand_send_req
   REQ_A = kzalloc(sizeof(*req) + data_len)
   wait_for_completion(&amp;amp;REQ_A-&amp;gt;done)
            cachefiles_daemon_read
             cachefiles_ondemand_daemon_read
                                  // close dev fd
                                  cachefiles_flush_reqs
                                   complete(&amp;amp;REQ_A-&amp;gt;done)
   kfree(REQ_A)
              xa_lock(&amp;amp;cache-&amp;gt;reqs);
              cachefiles_ondemand_select_req
                req-&amp;gt;msg.opcode != CACHEFILES_OP_READ
                // req use-after-free !!!
              xa_unlock(&amp;amp;cache-&amp;gt;reqs);
                                   xa_destroy(&amp;amp;cache-&amp;gt;reqs)&lt;/p&gt;
&lt;p&gt;Hence remove requests from cache-&amp;gt;reqs when flushing them to avoid
accessing freed requests.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-40900</guid>
    </item>
    <item>
      <title>GHSA-c93g-8734-9cr8</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-c93g-8734-9cr8</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;cachefiles: remove requests from xarray during flushing requests&lt;/p&gt;
&lt;p&gt;Even with CACHEFILES_DEAD set, we can still read the requests, so in the
following concurrency the request may be used after it has been freed:&lt;/p&gt;
&lt;p&gt;mount  |   daemon_thread1    |    daemon_thread2
------------------------------------------------------------
 cachefiles_ondemand_init_object
  cachefiles_ondemand_send_req
   REQ_A = kzalloc(sizeof(*req) + data_len)
   wait_for_completion(&amp;amp;REQ_A-&amp;gt;done)
            cachefiles_daemon_read
             cachefiles_ondemand_daemon_read
                                  // close dev fd
                                  cachefiles_flush_reqs
                                   complete(&amp;amp;REQ_A-&amp;gt;done)
   kfree(REQ_A)
              xa_lock(&amp;amp;cache-&amp;gt;reqs);
              cachefiles_ondemand_select_req
                req-&amp;gt;msg.opcode != CACHEFILES_OP_READ
                // req use-after-free !!!
              xa_unlock(&amp;amp;cache-&amp;gt;reqs);
                                   xa_destroy(&amp;amp;cache-&amp;gt;reqs)&lt;/p&gt;
&lt;p&gt;Hence remove requests from cache-&amp;gt;reqs when flushing them to avoid
accessing freed requests.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;cachefiles: remove requests from xarray during flushing requests&lt;/p&gt;
&lt;p&gt;Even with CACHEFILES_DEAD set, we can still read the requests, so in the
following concurrency the request may be used after it has been freed:&lt;/p&gt;
&lt;p&gt;mount  |   daemon_thread1    |    daemon_thread2
------------------------------------------------------------
 cachefiles_ondemand_init_object
  cachefiles_ondemand_send_req
   REQ_A = kzalloc(sizeof(*req) + data_len)
   wait_for_completion(&amp;amp;REQ_A-&amp;gt;done)
            cachefiles_daemon_read
             cachefiles_ondemand_daemon_read
                                  // close dev fd
                                  cachefiles_flush_reqs
                                   complete(&amp;amp;REQ_A-&amp;gt;done)
   kfree(REQ_A)
              xa_lock(&amp;amp;cache-&amp;gt;reqs);
              cachefiles_ondemand_select_req
                req-&amp;gt;msg.opcode != CACHEFILES_OP_READ
                // req use-after-free !!!
              xa_unlock(&amp;amp;cache-&amp;gt;reqs);
                                   xa_destroy(&amp;amp;cache-&amp;gt;reqs)&lt;/p&gt;
&lt;p&gt;Hence remove requests from cache-&amp;gt;reqs when flushing them to avoid
accessing freed requests.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-c93g-8734-9cr8</guid>
    </item>
    <item>
      <title>OESA-2024-1960 — kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2024-1960</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&#13;
&#13;
In the Linux kernel, the following vulnerability has been resolved:&#13;
&#13;
efi: libstub: only free priv.runtime_map when allocated&#13;
&#13;
priv.runtime_map is only allocated when efi_novamap is not set.
Otherwise, it is an uninitialized value.  In the error path, it is freed
unconditionally.  Avoid passing an uninitialized value to free_pool.
Free priv.runtime_map only when it was allocated.&#13;
&#13;
This bug was discovered and resolved using Coverity Static Analysis
Security Testing (SAST) by Synopsys, Inc.(CVE-2024-33619)&#13;
&#13;
In the Linux kernel, the following vulnerability has been resolved:&#13;
&#13;
fpga: region: add owner module and take its refcount&#13;
&#13;
The current implementation of the fpga region assumes that the low-level
module registers a driver for the parent device and uses its owner pointer
to take the module&amp;amp;apos;s refcount. This approach is problematic since it can
lead to a null pointer dereference while attempting to get the region
during programming if the parent device does not have a driver.&#13;
&#13;
To address this problem, add a module owner pointer to the fpga_region
struct and use it to take the module&amp;amp;apos;s refcount. Modify the functions for
registering a region to take an additional owner module parameter and
rename them to avoid conflicts. Use the old function names for helper
macros that automatically set the module that registers the region as the
owner. This ensures compatibility with existing low…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&#13;
&#13;
In the Linux kernel, the following vulnerability has been resolved:&#13;
&#13;
efi: libstub: only free priv.runtime_map when allocated&#13;
&#13;
priv.runtime_map is only allocated when efi_novamap is not set.
Otherwise, it is an uninitialized value.  In the error path, it is freed
unconditionally.  Avoid passing an uninitialized value to free_pool.
Free priv.runtime_map only when it was allocated.&#13;
&#13;
This bug was discovered and resolved using Coverity Static Analysis
Security Testing (SAST) by Synopsys, Inc.(CVE-2024-33619)&#13;
&#13;
In the Linux kernel, the following vulnerability has been resolved:&#13;
&#13;
fpga: region: add owner module and take its refcount&#13;
&#13;
The current implementation of the fpga region assumes that the low-level
module registers a driver for the parent device and uses its owner pointer
to take the module&amp;amp;apos;s refcount. This approach is problematic since it can
lead to a null pointer dereference while attempting to get the region
during programming if the parent device does not have a driver.&#13;
&#13;
To address this problem, add a module owner pointer to the fpga_region
struct and use it to take the module&amp;amp;apos;s refcount. Modify the functions for
registering a region to take an additional owner module parameter and
rename them to avoid conflicts. Use the old function names for helper
macros that automatically set the module that registers the region as the
owner. This ensures compatibility with existing low…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2024-1960</guid>
    </item>
    <item>
      <title>SUSE-SU-2024:2894-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2024:2894-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2024:2894-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2024-40900</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-40900</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux, Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe and 186 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: cachefiles: remove requests from xarray during flushing requests Even with CACHEFILES_DEAD set, we can still read the requests, so in the following concurrency the request may be used after it has been freed:      mount  |   daemon_thread1    |    daemon_thread2 ------------------------------------------------------------  cachefiles_ondemand_init_object   cachefiles_ondemand_send_req    REQ_A = kzalloc(sizeof(*req) + data_len)    wait_for_completion(&amp;amp;REQ_A-&amp;gt;done)             cachefiles_daemon_read              cachefiles_ondemand_daemon_read                                   // close dev fd                                   cachefiles_flush_reqs                                    complete(&amp;amp;REQ_A-&amp;gt;done)    kfree(REQ_A)               xa_lock(&amp;amp;cache-&amp;gt;reqs);               cachefiles_ondemand_select_req                 req-&amp;gt;msg.opcode != CACHEFILES_OP_READ                 // req use-after-free !!!               xa_unlock(&amp;amp;cache-&amp;gt;reqs);                                    xa_destroy(&amp;amp;cache-&amp;gt;reqs) Hence remove requests from cache-&amp;gt;reqs when flushing them to avoid accessing freed requests.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux, Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe and 186 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: cachefiles: remove requests from xarray during flushing requests Even with CACHEFILES_DEAD set, we can still read the requests, so in the following concurrency the request may be used after it has been freed:      mount  |   daemon_thread1    |    daemon_thread2 ------------------------------------------------------------  cachefiles_ondemand_init_object   cachefiles_ondemand_send_req    REQ_A = kzalloc(sizeof(*req) + data_len)    wait_for_completion(&amp;amp;REQ_A-&amp;gt;done)             cachefiles_daemon_read              cachefiles_ondemand_daemon_read                                   // close dev fd                                   cachefiles_flush_reqs                                    complete(&amp;amp;REQ_A-&amp;gt;done)    kfree(REQ_A)               xa_lock(&amp;amp;cache-&amp;gt;reqs);               cachefiles_ondemand_select_req                 req-&amp;gt;msg.opcode != CACHEFILES_OP_READ                 // req use-after-free !!!               xa_unlock(&amp;amp;cache-&amp;gt;reqs);                                    xa_destroy(&amp;amp;cache-&amp;gt;reqs) Hence remove requests from cache-&amp;gt;reqs when flushing them to avoid accessing freed requests.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-40900</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-1607 — Linux Kernel: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1607</link>
      <description>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen im Linux-Kernel ausnutzen, um seine Privilegien zu erweitern, einen Denial-of-Service-Zustand zu erzeugen, vertrauliche Informationen offenzulegen oder einen unspezifischen Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen im Linux-Kernel ausnutzen, um seine Privilegien zu erweitern, einen Denial-of-Service-Zustand zu erzeugen, vertrauliche Informationen offenzulegen oder einen unspezifischen Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1607</guid>
    </item>
  </channel>
</rss>
