<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 15:33:37 +0000</lastBuildDate>
    <item>
      <title>ALSA-2024:7000 — Important: kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2024:7000</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: bpftool, AlmaLinux:8: kernel, AlmaLinux:8: kernel-abi-stablelists, AlmaLinux:8: kernel-core, AlmaLinux:8: kernel-cross-headers, AlmaLinux:8: kernel-debug, AlmaLinux:8: kernel-debug-core, AlmaLinux:8: kernel-debug-devel, AlmaLinux:8: kernel-debug-modules, AlmaLinux:8: kernel-debug-modules-extra and 15 more&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.  
Security Fix(es):&lt;/p&gt;
&lt;p&gt;CVE-2023-6040  CVE-2024-26595  CVE-2024-26600  CVE-2021-46984  CVE-2023-52478  CVE-2023-52476  CVE-2023-52522  CVE-2021-47101  CVE-2021-47097  CVE-2023-52605  CVE-2024-26638  CVE-2024-26645  CVE-2024-26665  CVE-2024-26720  CVE-2024-26717  CVE-2024-26769  CVE-2024-26846  CVE-2024-26894  CVE-2024-26880  CVE-2024-26855  CVE-2024-26923  CVE-2024-26939  CVE-2024-27013  CVE-2024-27042  CVE-2024-35809  CVE-2023-52683  CVE-2024-35884  CVE-2024-35877  CVE-2024-35944  CVE-2024-35989  CVE-2021-47412  CVE-2021-47393  CVE-2021-47386  CVE-2021-47385  CVE-2021-47384  CVE-2021-47383  CVE-2021-47432  CVE-2021-47352  CVE-2021-47338  CVE-2021-47321  CVE-2021-47289  CVE-2021-47287  CVE-2023-52798  CVE-2023-52809  CVE-2023-52817  CVE-2023-52840  CVE-2023-52800  CVE-2021-47441  CVE-2021-47466  CVE-2021-47455  CVE-2021-47497  CVE-2021-47560  CVE-2021-47527  CVE-2024-36883  CVE-2024-36922  CVE-2024-36920  CVE-2024-36902  CVE-2024-36953  CVE-2024-36939  CVE-2024-36919  CVE-2024-36901  CVE-2021-47582  CVE-2021-47609  CVE-2024-38619  CVE-2022-48754  CVE-2022-48760  CVE-2024-38581  CVE-2024-38579  CVE-2024-38570  CVE-2024-38559  CVE-2024-38558  CVE-2024-37356  CVE-2024-39471  CVE-2024-39499  CVE-2024-39501  CVE-2024-39506  CVE-2024-40904  CVE-2024-40911  CVE-2024-40912  CVE-2024-40929  CVE-2024-40931  CVE-2024-40941  CVE-2024-40954  CVE-2024-40958  CVE-2024-40959  CVE-2024-40960  CVE-2024-40972…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: bpftool, AlmaLinux:8: kernel, AlmaLinux:8: kernel-abi-stablelists, AlmaLinux:8: kernel-core, AlmaLinux:8: kernel-cross-headers, AlmaLinux:8: kernel-debug, AlmaLinux:8: kernel-debug-core, AlmaLinux:8: kernel-debug-devel, AlmaLinux:8: kernel-debug-modules, AlmaLinux:8: kernel-debug-modules-extra and 15 more&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.  
Security Fix(es):&lt;/p&gt;
&lt;p&gt;CVE-2023-6040  CVE-2024-26595  CVE-2024-26600  CVE-2021-46984  CVE-2023-52478  CVE-2023-52476  CVE-2023-52522  CVE-2021-47101  CVE-2021-47097  CVE-2023-52605  CVE-2024-26638  CVE-2024-26645  CVE-2024-26665  CVE-2024-26720  CVE-2024-26717  CVE-2024-26769  CVE-2024-26846  CVE-2024-26894  CVE-2024-26880  CVE-2024-26855  CVE-2024-26923  CVE-2024-26939  CVE-2024-27013  CVE-2024-27042  CVE-2024-35809  CVE-2023-52683  CVE-2024-35884  CVE-2024-35877  CVE-2024-35944  CVE-2024-35989  CVE-2021-47412  CVE-2021-47393  CVE-2021-47386  CVE-2021-47385  CVE-2021-47384  CVE-2021-47383  CVE-2021-47432  CVE-2021-47352  CVE-2021-47338  CVE-2021-47321  CVE-2021-47289  CVE-2021-47287  CVE-2023-52798  CVE-2023-52809  CVE-2023-52817  CVE-2023-52840  CVE-2023-52800  CVE-2021-47441  CVE-2021-47466  CVE-2021-47455  CVE-2021-47497  CVE-2021-47560  CVE-2021-47527  CVE-2024-36883  CVE-2024-36922  CVE-2024-36920  CVE-2024-36902  CVE-2024-36953  CVE-2024-36939  CVE-2024-36919  CVE-2024-36901  CVE-2021-47582  CVE-2021-47609  CVE-2024-38619  CVE-2022-48754  CVE-2022-48760  CVE-2024-38581  CVE-2024-38579  CVE-2024-38570  CVE-2024-38559  CVE-2024-38558  CVE-2024-37356  CVE-2024-39471  CVE-2024-39499  CVE-2024-39501  CVE-2024-39506  CVE-2024-40904  CVE-2024-40911  CVE-2024-40912  CVE-2024-40929  CVE-2024-40931  CVE-2024-40941  CVE-2024-40954  CVE-2024-40958  CVE-2024-40959  CVE-2024-40960  CVE-2024-40972…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2024:7000</guid>
    </item>
    <item>
      <title>bdu:2026-01446</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-01446</link>
      <description>bdu:2026-01446</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-01446</guid>
    </item>
    <item>
      <title>BELL-CVE-2024-40998</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2024-40998</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2024-40998</guid>
    </item>
    <item>
      <title>certfr-2024-avi-0669 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de SUSE. Certaines d'entre elles permettent à un at…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0669</link>
      <description>certfr-2024-avi-0669</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2024-avi-0669</guid>
    </item>
    <item>
      <title>EUVD-2026-312978</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-312978</link>
      <description>EUVD-2026-312978</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-312978</guid>
    </item>
    <item>
      <title>fkie_cve-2024-40998</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-40998</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;ext4: fix uninitialized ratelimit_state-&amp;gt;lock access in __ext4_fill_super()&lt;/p&gt;
&lt;p&gt;In the following concurrency we will access the uninitialized rs-&amp;gt;lock:&lt;/p&gt;
&lt;p&gt;ext4_fill_super
  ext4_register_sysfs
   // sysfs registered msg_ratelimit_interval_ms
                             // Other processes modify rs-&amp;gt;interval to
                             // non-zero via msg_ratelimit_interval_ms
  ext4_orphan_cleanup
    ext4_msg(sb, KERN_INFO, &amp;#34;Errors on filesystem, &amp;#34;
      __ext4_msg
        ___ratelimit(&amp;amp;(EXT4_SB(sb)-&amp;gt;s_msg_ratelimit_state)
          if (!rs-&amp;gt;interval)  // do nothing if interval is 0
            return 1;
          raw_spin_trylock_irqsave(&amp;amp;rs-&amp;gt;lock, flags)
            raw_spin_trylock(lock)
              _raw_spin_trylock
                __raw_spin_trylock
                  spin_acquire(&amp;amp;lock-&amp;gt;dep_map, 0, 1, _RET_IP_)
                    lock_acquire
                      __lock_acquire
                        register_lock_class
                          assign_lock_key
                            dump_stack();
  ratelimit_state_init(&amp;amp;sbi-&amp;gt;s_msg_ratelimit_state, 5 * HZ, 10);
    raw_spin_lock_init(&amp;amp;rs-&amp;gt;lock);
    // init rs-&amp;gt;lock here&lt;/p&gt;
&lt;p&gt;and get the following dump_stack:&lt;/p&gt;
&lt;p&gt;=========================================================
INFO: trying to register non-static key.
The code is fine but needs lockdep annotation, or maybe
you didn&amp;#39;t initialize this object before use?
turning off the locking correctness va…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;ext4: fix uninitialized ratelimit_state-&amp;gt;lock access in __ext4_fill_super()&lt;/p&gt;
&lt;p&gt;In the following concurrency we will access the uninitialized rs-&amp;gt;lock:&lt;/p&gt;
&lt;p&gt;ext4_fill_super
  ext4_register_sysfs
   // sysfs registered msg_ratelimit_interval_ms
                             // Other processes modify rs-&amp;gt;interval to
                             // non-zero via msg_ratelimit_interval_ms
  ext4_orphan_cleanup
    ext4_msg(sb, KERN_INFO, &amp;#34;Errors on filesystem, &amp;#34;
      __ext4_msg
        ___ratelimit(&amp;amp;(EXT4_SB(sb)-&amp;gt;s_msg_ratelimit_state)
          if (!rs-&amp;gt;interval)  // do nothing if interval is 0
            return 1;
          raw_spin_trylock_irqsave(&amp;amp;rs-&amp;gt;lock, flags)
            raw_spin_trylock(lock)
              _raw_spin_trylock
                __raw_spin_trylock
                  spin_acquire(&amp;amp;lock-&amp;gt;dep_map, 0, 1, _RET_IP_)
                    lock_acquire
                      __lock_acquire
                        register_lock_class
                          assign_lock_key
                            dump_stack();
  ratelimit_state_init(&amp;amp;sbi-&amp;gt;s_msg_ratelimit_state, 5 * HZ, 10);
    raw_spin_lock_init(&amp;amp;rs-&amp;gt;lock);
    // init rs-&amp;gt;lock here&lt;/p&gt;
&lt;p&gt;and get the following dump_stack:&lt;/p&gt;
&lt;p&gt;=========================================================
INFO: trying to register non-static key.
The code is fine but needs lockdep annotation, or maybe
you didn&amp;#39;t initialize this object before use?
turning off the locking correctness va…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-40998</guid>
    </item>
    <item>
      <title>GHSA-p23j-c29j-hjgv</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-p23j-c29j-hjgv</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;ext4: fix uninitialized ratelimit_state-&amp;gt;lock access in __ext4_fill_super()&lt;/p&gt;
&lt;p&gt;In the following concurrency we will access the uninitialized rs-&amp;gt;lock:&lt;/p&gt;
&lt;p&gt;ext4_fill_super
  ext4_register_sysfs
   // sysfs registered msg_ratelimit_interval_ms
                             // Other processes modify rs-&amp;gt;interval to
                             // non-zero via msg_ratelimit_interval_ms
  ext4_orphan_cleanup
    ext4_msg(sb, KERN_INFO, &amp;#34;Errors on filesystem, &amp;#34;
      __ext4_msg
        ___ratelimit(&amp;amp;(EXT4_SB(sb)-&amp;gt;s_msg_ratelimit_state)
          if (!rs-&amp;gt;interval)  // do nothing if interval is 0
            return 1;
          raw_spin_trylock_irqsave(&amp;amp;rs-&amp;gt;lock, flags)
            raw_spin_trylock(lock)
              _raw_spin_trylock
                __raw_spin_trylock
                  spin_acquire(&amp;amp;lock-&amp;gt;dep_map, 0, 1, _RET_IP_)
                    lock_acquire
                      __lock_acquire
                        register_lock_class
                          assign_lock_key
                            dump_stack();
  ratelimit_state_init(&amp;amp;sbi-&amp;gt;s_msg_ratelimit_state, 5 * HZ, 10);
    raw_spin_lock_init(&amp;amp;rs-&amp;gt;lock);
    // init rs-&amp;gt;lock here&lt;/p&gt;
&lt;p&gt;and get the following dump_stack:&lt;/p&gt;
&lt;p&gt;=========================================================
INFO: trying to register non-static key.
The code is fine but needs lockdep annotation, or maybe
you didn&amp;#39;t initialize this object before use?
turning off the locking correctness va…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;ext4: fix uninitialized ratelimit_state-&amp;gt;lock access in __ext4_fill_super()&lt;/p&gt;
&lt;p&gt;In the following concurrency we will access the uninitialized rs-&amp;gt;lock:&lt;/p&gt;
&lt;p&gt;ext4_fill_super
  ext4_register_sysfs
   // sysfs registered msg_ratelimit_interval_ms
                             // Other processes modify rs-&amp;gt;interval to
                             // non-zero via msg_ratelimit_interval_ms
  ext4_orphan_cleanup
    ext4_msg(sb, KERN_INFO, &amp;#34;Errors on filesystem, &amp;#34;
      __ext4_msg
        ___ratelimit(&amp;amp;(EXT4_SB(sb)-&amp;gt;s_msg_ratelimit_state)
          if (!rs-&amp;gt;interval)  // do nothing if interval is 0
            return 1;
          raw_spin_trylock_irqsave(&amp;amp;rs-&amp;gt;lock, flags)
            raw_spin_trylock(lock)
              _raw_spin_trylock
                __raw_spin_trylock
                  spin_acquire(&amp;amp;lock-&amp;gt;dep_map, 0, 1, _RET_IP_)
                    lock_acquire
                      __lock_acquire
                        register_lock_class
                          assign_lock_key
                            dump_stack();
  ratelimit_state_init(&amp;amp;sbi-&amp;gt;s_msg_ratelimit_state, 5 * HZ, 10);
    raw_spin_lock_init(&amp;amp;rs-&amp;gt;lock);
    // init rs-&amp;gt;lock here&lt;/p&gt;
&lt;p&gt;and get the following dump_stack:&lt;/p&gt;
&lt;p&gt;=========================================================
INFO: trying to register non-static key.
The code is fine but needs lockdep annotation, or maybe
you didn&amp;#39;t initialize this object before use?
turning off the locking correctness va…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-p23j-c29j-hjgv</guid>
    </item>
    <item>
      <title>msrc_CVE-2024-40998 — ext4: fix uninitialized ratelimit_state-&gt;lock access in __ext4_fill_super()</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2024-40998</link>
      <description>msrc_CVE-2024-40998</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2024-40998</guid>
    </item>
    <item>
      <title>OESA-2024-2255 — kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2024-2255</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP3: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&#13;
&#13;
In the Linux kernel, the following vulnerability has been resolved:&#13;
&#13;
drm/i915/gt: Cleanup partial engine discovery failures&#13;
&#13;
If we abort driver initialisation in the middle of gt/engine discovery,
some engines will be fully setup and some not. Those incompletely setup
engines only have &amp;amp;apos;engine-&amp;amp;gt;release == NULL&amp;amp;apos; and so will leak any of the
common objects allocated.&#13;
&#13;
v2:
 - Drop the destroy_pinned_context() helper for now.  It&amp;amp;apos;s not really
   worth it with just a single callsite at the moment.  (Janusz)(CVE-2022-48893)&#13;
&#13;
In the Linux kernel, the following vulnerability has been resolved:&#13;
&#13;
f2fs: fix to avoid dirent corruption&#13;
&#13;
As Al reported in link[1]:&#13;
&#13;
f2fs_rename()
...
	if (old_dir != new_dir &amp;amp;amp;&amp;amp;amp; !whiteout)
		f2fs_set_link(old_inode, old_dir_entry,
					old_dir_page, new_dir);
	else
		f2fs_put_page(old_dir_page, 0);&#13;
&#13;
You want correct inumber in the &amp;amp;quot;..&amp;amp;quot; link.  And cross-directory
rename does move the source to new parent, even if you&amp;amp;apos;d been asked
to leave a whiteout in the old place.&#13;
&#13;
[1] https://lore.kernel.org/all/20231017055040.GN800259@ZenIV/&#13;
&#13;
With below testcase, it may cause dirent corruption, due to it missed
to call f2fs_set_link() to update &amp;amp;quot;..&amp;amp;quot; link to new directory.
- mkdir -p dir/foo
- renameat2 -w dir/foo bar&#13;
&#13;
[ASSERT] (__chk_dots_dentries:1421)  --&amp;amp;gt; Bad inode number[0x4] for &amp;amp;apos;..&amp;amp;apos;, parent parent ino is [0…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP3: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&#13;
&#13;
In the Linux kernel, the following vulnerability has been resolved:&#13;
&#13;
drm/i915/gt: Cleanup partial engine discovery failures&#13;
&#13;
If we abort driver initialisation in the middle of gt/engine discovery,
some engines will be fully setup and some not. Those incompletely setup
engines only have &amp;amp;apos;engine-&amp;amp;gt;release == NULL&amp;amp;apos; and so will leak any of the
common objects allocated.&#13;
&#13;
v2:
 - Drop the destroy_pinned_context() helper for now.  It&amp;amp;apos;s not really
   worth it with just a single callsite at the moment.  (Janusz)(CVE-2022-48893)&#13;
&#13;
In the Linux kernel, the following vulnerability has been resolved:&#13;
&#13;
f2fs: fix to avoid dirent corruption&#13;
&#13;
As Al reported in link[1]:&#13;
&#13;
f2fs_rename()
...
	if (old_dir != new_dir &amp;amp;amp;&amp;amp;amp; !whiteout)
		f2fs_set_link(old_inode, old_dir_entry,
					old_dir_page, new_dir);
	else
		f2fs_put_page(old_dir_page, 0);&#13;
&#13;
You want correct inumber in the &amp;amp;quot;..&amp;amp;quot; link.  And cross-directory
rename does move the source to new parent, even if you&amp;amp;apos;d been asked
to leave a whiteout in the old place.&#13;
&#13;
[1] https://lore.kernel.org/all/20231017055040.GN800259@ZenIV/&#13;
&#13;
With below testcase, it may cause dirent corruption, due to it missed
to call f2fs_set_link() to update &amp;amp;quot;..&amp;amp;quot; link to new directory.
- mkdir -p dir/foo
- renameat2 -w dir/foo bar&#13;
&#13;
[ASSERT] (__chk_dots_dentries:1421)  --&amp;amp;gt; Bad inode number[0x4] for &amp;amp;apos;..&amp;amp;apos;, parent parent ino is [0…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2024-2255</guid>
    </item>
    <item>
      <title>RHSA-2024:7000 — Red Hat Security Advisory: kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2024:7000</link>
      <description>&lt;p&gt;kernel: kyber: fix out of bounds access when preempted kernel: Input: elantech - fix stack out of bound access in elantech_change_report_id() kernel: asix: fix uninit-value in asix_mdio_read() kernel: driver core: auxiliary bus: Fix memory leak when driver_register() fail kernel: ACPI: fix NULL pointer dereference kernel: watchdog: Fix possible use-after-free by calling del_timer_sync() kernel: fbmem: Do not delete the mode that is still in use kernel: virtio-net: Add validation for used length kernel: tty: Fix out-of-bound vmalloc access in imageblit kernel: hwmon: (w83793) Fix NULL pointer dereference by removing unnecessary structure field kernel: hwmon: (w83792d) Fix NULL pointer dereference by removing unnecessary structure field kernel: hwmon: (w83791d) Fix NULL pointer dereference by removing unnecessary structure field kernel: hwmon: (mlxreg-fan) Return non-zero value when fan current state is enforced from sysfs kernel: block: don&amp;#39;t call rq_qos_ops-&amp;gt;done_bio if the bio isn&amp;#39;t tracked kernel: lib/generic-radix-tree.c: Don&amp;#39;t overflow in peek() kernel: mlxsw: thermal: Fix out-of-bounds memory accesses kernel: ptp: Fix possible memory leak in ptp_clock_register() kernel: mm, slub: fix potential memoryleak in kmem_cache_open() kernel: nvmem: Fix shift-out-of-bound (UBSAN) with byte size cells kernel: serial: core: fix transmit-buffer reset and memleak kernel: mlxsw: spectrum: Protect driver from buggy firmware kernel: USB: core: Make do_proc_control() and do_proc_bulk() k…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;kernel: kyber: fix out of bounds access when preempted kernel: Input: elantech - fix stack out of bound access in elantech_change_report_id() kernel: asix: fix uninit-value in asix_mdio_read() kernel: driver core: auxiliary bus: Fix memory leak when driver_register() fail kernel: ACPI: fix NULL pointer dereference kernel: watchdog: Fix possible use-after-free by calling del_timer_sync() kernel: fbmem: Do not delete the mode that is still in use kernel: virtio-net: Add validation for used length kernel: tty: Fix out-of-bound vmalloc access in imageblit kernel: hwmon: (w83793) Fix NULL pointer dereference by removing unnecessary structure field kernel: hwmon: (w83792d) Fix NULL pointer dereference by removing unnecessary structure field kernel: hwmon: (w83791d) Fix NULL pointer dereference by removing unnecessary structure field kernel: hwmon: (mlxreg-fan) Return non-zero value when fan current state is enforced from sysfs kernel: block: don&amp;#39;t call rq_qos_ops-&amp;gt;done_bio if the bio isn&amp;#39;t tracked kernel: lib/generic-radix-tree.c: Don&amp;#39;t overflow in peek() kernel: mlxsw: thermal: Fix out-of-bounds memory accesses kernel: ptp: Fix possible memory leak in ptp_clock_register() kernel: mm, slub: fix potential memoryleak in kmem_cache_open() kernel: nvmem: Fix shift-out-of-bound (UBSAN) with byte size cells kernel: serial: core: fix transmit-buffer reset and memleak kernel: mlxsw: spectrum: Protect driver from buggy firmware kernel: USB: core: Make do_proc_control() and do_proc_bulk() k…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2024:7000</guid>
    </item>
    <item>
      <title>RHSA-2024:7001 — Red Hat Security Advisory: kernel-rt security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2024:7001</link>
      <description>&lt;p&gt;kernel: kyber: fix out of bounds access when preempted kernel: Input: elantech - fix stack out of bound access in elantech_change_report_id() kernel: asix: fix uninit-value in asix_mdio_read() kernel: driver core: auxiliary bus: Fix memory leak when driver_register() fail kernel: ACPI: fix NULL pointer dereference kernel: watchdog: Fix possible use-after-free by calling del_timer_sync() kernel: fbmem: Do not delete the mode that is still in use kernel: virtio-net: Add validation for used length kernel: tty: Fix out-of-bound vmalloc access in imageblit kernel: hwmon: (w83793) Fix NULL pointer dereference by removing unnecessary structure field kernel: hwmon: (w83792d) Fix NULL pointer dereference by removing unnecessary structure field kernel: hwmon: (w83791d) Fix NULL pointer dereference by removing unnecessary structure field kernel: hwmon: (mlxreg-fan) Return non-zero value when fan current state is enforced from sysfs kernel: block: don&amp;#39;t call rq_qos_ops-&amp;gt;done_bio if the bio isn&amp;#39;t tracked kernel: lib/generic-radix-tree.c: Don&amp;#39;t overflow in peek() kernel: mlxsw: thermal: Fix out-of-bounds memory accesses kernel: ptp: Fix possible memory leak in ptp_clock_register() kernel: mm, slub: fix potential memoryleak in kmem_cache_open() kernel: nvmem: Fix shift-out-of-bound (UBSAN) with byte size cells kernel: serial: core: fix transmit-buffer reset and memleak kernel: mlxsw: spectrum: Protect driver from buggy firmware kernel: USB: core: Make do_proc_control() and do_proc_bulk() k…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;kernel: kyber: fix out of bounds access when preempted kernel: Input: elantech - fix stack out of bound access in elantech_change_report_id() kernel: asix: fix uninit-value in asix_mdio_read() kernel: driver core: auxiliary bus: Fix memory leak when driver_register() fail kernel: ACPI: fix NULL pointer dereference kernel: watchdog: Fix possible use-after-free by calling del_timer_sync() kernel: fbmem: Do not delete the mode that is still in use kernel: virtio-net: Add validation for used length kernel: tty: Fix out-of-bound vmalloc access in imageblit kernel: hwmon: (w83793) Fix NULL pointer dereference by removing unnecessary structure field kernel: hwmon: (w83792d) Fix NULL pointer dereference by removing unnecessary structure field kernel: hwmon: (w83791d) Fix NULL pointer dereference by removing unnecessary structure field kernel: hwmon: (mlxreg-fan) Return non-zero value when fan current state is enforced from sysfs kernel: block: don&amp;#39;t call rq_qos_ops-&amp;gt;done_bio if the bio isn&amp;#39;t tracked kernel: lib/generic-radix-tree.c: Don&amp;#39;t overflow in peek() kernel: mlxsw: thermal: Fix out-of-bounds memory accesses kernel: ptp: Fix possible memory leak in ptp_clock_register() kernel: mm, slub: fix potential memoryleak in kmem_cache_open() kernel: nvmem: Fix shift-out-of-bound (UBSAN) with byte size cells kernel: serial: core: fix transmit-buffer reset and memleak kernel: mlxsw: spectrum: Protect driver from buggy firmware kernel: USB: core: Make do_proc_control() and do_proc_bulk() k…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2024:7001</guid>
    </item>
    <item>
      <title>SUSE-SU-2024:2802-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2024:2802-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2024:2802-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2024-40998</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-40998</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux, Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe and 186 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: ext4: fix uninitialized ratelimit_state-&amp;gt;lock access in __ext4_fill_super() In the following concurrency we will access the uninitialized rs-&amp;gt;lock: ext4_fill_super   ext4_register_sysfs    // sysfs registered msg_ratelimit_interval_ms                              // Other processes modify rs-&amp;gt;interval to                              // non-zero via msg_ratelimit_interval_ms   ext4_orphan_cleanup     ext4_msg(sb, KERN_INFO, &amp;#34;Errors on filesystem, &amp;#34;       __ext4_msg         ___ratelimit(&amp;amp;(EXT4_SB(sb)-&amp;gt;s_msg_ratelimit_state)           if (!rs-&amp;gt;interval)  // do nothing if interval is 0             return 1;           raw_spin_trylock_irqsave(&amp;amp;rs-&amp;gt;lock, flags)             raw_spin_trylock(lock)               _raw_spin_trylock                 __raw_spin_trylock                   spin_acquire(&amp;amp;lock-&amp;gt;dep_map, 0, 1, _RET_IP_)                     lock_acquire                       __lock_acquire                         register_lock_class                           assign_lock_key                             dump_stack();   ratelimit_state_init(&amp;amp;sbi-&amp;gt;s_msg_ratelimit_state, 5 * HZ, 10);     raw_spin_lock_init(&amp;amp;rs-&amp;gt;lock);     // init rs-&amp;gt;lock here and get the following dump_stack: ========================================================= INFO: trying to register non-static key. The code is fine but needs lockdep annotation, or maybe you didn&amp;#39;t initialize this object before use? turning off the locking correctness validat…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux, Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe and 186 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: ext4: fix uninitialized ratelimit_state-&amp;gt;lock access in __ext4_fill_super() In the following concurrency we will access the uninitialized rs-&amp;gt;lock: ext4_fill_super   ext4_register_sysfs    // sysfs registered msg_ratelimit_interval_ms                              // Other processes modify rs-&amp;gt;interval to                              // non-zero via msg_ratelimit_interval_ms   ext4_orphan_cleanup     ext4_msg(sb, KERN_INFO, &amp;#34;Errors on filesystem, &amp;#34;       __ext4_msg         ___ratelimit(&amp;amp;(EXT4_SB(sb)-&amp;gt;s_msg_ratelimit_state)           if (!rs-&amp;gt;interval)  // do nothing if interval is 0             return 1;           raw_spin_trylock_irqsave(&amp;amp;rs-&amp;gt;lock, flags)             raw_spin_trylock(lock)               _raw_spin_trylock                 __raw_spin_trylock                   spin_acquire(&amp;amp;lock-&amp;gt;dep_map, 0, 1, _RET_IP_)                     lock_acquire                       __lock_acquire                         register_lock_class                           assign_lock_key                             dump_stack();   ratelimit_state_init(&amp;amp;sbi-&amp;gt;s_msg_ratelimit_state, 5 * HZ, 10);     raw_spin_lock_init(&amp;amp;rs-&amp;gt;lock);     // init rs-&amp;gt;lock here and get the following dump_stack: ========================================================= INFO: trying to register non-static key. The code is fine but needs lockdep annotation, or maybe you didn&amp;#39;t initialize this object before use? turning off the locking correctness validat…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-40998</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-1607 — Linux Kernel: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1607</link>
      <description>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen im Linux-Kernel ausnutzen, um seine Privilegien zu erweitern, einen Denial-of-Service-Zustand zu erzeugen, vertrauliche Informationen offenzulegen oder einen unspezifischen Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen im Linux-Kernel ausnutzen, um seine Privilegien zu erweitern, einen Denial-of-Service-Zustand zu erzeugen, vertrauliche Informationen offenzulegen oder einen unspezifischen Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1607</guid>
    </item>
  </channel>
</rss>
