<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 08:33:33 +0000</lastBuildDate>
    <item>
      <title>ALSA-2024:6567 — Moderate: kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2024:6567</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: bpftool, AlmaLinux:9: kernel, AlmaLinux:9: kernel-64k, AlmaLinux:9: kernel-64k-core, AlmaLinux:9: kernel-64k-debug, AlmaLinux:9: kernel-64k-debug-core, AlmaLinux:9: kernel-64k-debug-devel, AlmaLinux:9: kernel-64k-debug-devel-matched, AlmaLinux:9: kernel-64k-debug-modules, AlmaLinux:9: kernel-64k-debug-modules-core and 52 more&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: efivarfs: force RO when remounting if SetVariable is not supported (CVE-2023-52463)
  * kernel: nfsd: fix RELEASE_LOCKOWNER (CVE-2024-26629)
  * kernel: mm: cachestat: fix folio read-after-free in cache walk (CVE-2024-26630)
  * kernel: mm/writeback: fix possible divide-by-zero in wb_dirty_limits(), again (CVE-2024-26720)
  * kernel: Bluetooth: af_bluetooth: Fix deadlock (CVE-2024-26886)
  * kernel: kprobes/x86: Use copy_from_kernel_nofault() to read from unsafe address (CVE-2024-26946)
  * kernel: KVM: SVM: Flush pages under kvm-&amp;amp;gt;lock to fix UAF in svm_register_enc_region() (CVE-2024-35791)
  * kernel: mm: cachestat: fix two shmem bugs (CVE-2024-35797)
  * kernel: x86/coco: Require seeding RNG with RDRAND on CoCo systems (CVE-2024-35875)
  * kernel: mm/hugetlb: fix missing hugetlb_lock for resv uncharge (CVE-2024-36000)
  * kernel: iommufd: Fix missing update of domains_itree after splitting iopt_area (CVE-2023-52801)
  * kernel: net: fix out-of-bounds access in ops_init (CVE-2024-36883)
  * kernel: regmap: maple: Fix cache corruption in regcache_maple_drop() (CVE-2024-36019)
  * kernel: usb-storage: alauda: Check whether the media is initialized (CVE-2024-38619)
  * kernel: net: bridge: mst: fix vlan use-after-free (CVE-2024-36979)
  * kernel: scsi: qedf: Ensure the copied buf is NUL terminated (CVE-2024-38559)
  * kernel: xhci: Handle TD clearing fo…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: bpftool, AlmaLinux:9: kernel, AlmaLinux:9: kernel-64k, AlmaLinux:9: kernel-64k-core, AlmaLinux:9: kernel-64k-debug, AlmaLinux:9: kernel-64k-debug-core, AlmaLinux:9: kernel-64k-debug-devel, AlmaLinux:9: kernel-64k-debug-devel-matched, AlmaLinux:9: kernel-64k-debug-modules, AlmaLinux:9: kernel-64k-debug-modules-core and 52 more&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: efivarfs: force RO when remounting if SetVariable is not supported (CVE-2023-52463)
  * kernel: nfsd: fix RELEASE_LOCKOWNER (CVE-2024-26629)
  * kernel: mm: cachestat: fix folio read-after-free in cache walk (CVE-2024-26630)
  * kernel: mm/writeback: fix possible divide-by-zero in wb_dirty_limits(), again (CVE-2024-26720)
  * kernel: Bluetooth: af_bluetooth: Fix deadlock (CVE-2024-26886)
  * kernel: kprobes/x86: Use copy_from_kernel_nofault() to read from unsafe address (CVE-2024-26946)
  * kernel: KVM: SVM: Flush pages under kvm-&amp;amp;gt;lock to fix UAF in svm_register_enc_region() (CVE-2024-35791)
  * kernel: mm: cachestat: fix two shmem bugs (CVE-2024-35797)
  * kernel: x86/coco: Require seeding RNG with RDRAND on CoCo systems (CVE-2024-35875)
  * kernel: mm/hugetlb: fix missing hugetlb_lock for resv uncharge (CVE-2024-36000)
  * kernel: iommufd: Fix missing update of domains_itree after splitting iopt_area (CVE-2023-52801)
  * kernel: net: fix out-of-bounds access in ops_init (CVE-2024-36883)
  * kernel: regmap: maple: Fix cache corruption in regcache_maple_drop() (CVE-2024-36019)
  * kernel: usb-storage: alauda: Check whether the media is initialized (CVE-2024-38619)
  * kernel: net: bridge: mst: fix vlan use-after-free (CVE-2024-36979)
  * kernel: scsi: qedf: Ensure the copied buf is NUL terminated (CVE-2024-38559)
  * kernel: xhci: Handle TD clearing fo…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2024:6567</guid>
    </item>
    <item>
      <title>bdu:2024-07692</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2024-07692</link>
      <description>bdu:2024-07692</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2024-07692</guid>
    </item>
    <item>
      <title>BELL-CVE-2024-41040</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2024-41040</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2024-41040</guid>
    </item>
    <item>
      <title>certfr-2024-avi-0693 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de SUSE. Certaines d'entre elles permettent à un at…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0693</link>
      <description>certfr-2024-avi-0693</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2024-avi-0693</guid>
    </item>
    <item>
      <title>EUVD-2026-345921</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-345921</link>
      <description>EUVD-2026-345921</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-345921</guid>
    </item>
    <item>
      <title>fkie_cve-2024-41040</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-41040</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;net/sched: Fix UAF when resolving a clash&lt;/p&gt;
&lt;p&gt;KASAN reports the following UAF:&lt;/p&gt;
&lt;p&gt;BUG: KASAN: slab-use-after-free in tcf_ct_flow_table_process_conn+0x12b/0x380 [act_ct]
 Read of size 1 at addr ffff888c07603600 by task handler130/6469&lt;/p&gt;
&lt;p&gt;Call Trace:
  &amp;lt;IRQ&amp;gt;
  dump_stack_lvl+0x48/0x70
  print_address_description.constprop.0+0x33/0x3d0
  print_report+0xc0/0x2b0
  kasan_report+0xd0/0x120
  __asan_load1+0x6c/0x80
  tcf_ct_flow_table_process_conn+0x12b/0x380 [act_ct]
  tcf_ct_act+0x886/0x1350 [act_ct]
  tcf_action_exec+0xf8/0x1f0
  fl_classify+0x355/0x360 [cls_flower]
  __tcf_classify+0x1fd/0x330
  tcf_classify+0x21c/0x3c0
  sch_handle_ingress.constprop.0+0x2c5/0x500
  __netif_receive_skb_core.constprop.0+0xb25/0x1510
  __netif_receive_skb_list_core+0x220/0x4c0
  netif_receive_skb_list_internal+0x446/0x620
  napi_complete_done+0x157/0x3d0
  gro_cell_poll+0xcf/0x100
  __napi_poll+0x65/0x310
  net_rx_action+0x30c/0x5c0
  __do_softirq+0x14f/0x491
  __irq_exit_rcu+0x82/0xc0
  irq_exit_rcu+0xe/0x20
  common_interrupt+0xa1/0xb0
  &amp;lt;/IRQ&amp;gt;
  &amp;lt;TASK&amp;gt;
  asm_common_interrupt+0x27/0x40&lt;/p&gt;
&lt;p&gt;Allocated by task 6469:
  kasan_save_stack+0x38/0x70
  kasan_set_track+0x25/0x40
  kasan_save_alloc_info+0x1e/0x40
  __kasan_krealloc+0x133/0x190
  krealloc+0xaa/0x130
  nf_ct_ext_add+0xed/0x230 [nf_conntrack]
  tcf_ct_act+0x1095/0x1350 [act_ct]
  tcf_action_exec+0xf8/0x1f0
  fl_classify+0x355/0x360 [cls_flower]
  __tcf_classify+0x1fd/0x330
  tcf_c…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;net/sched: Fix UAF when resolving a clash&lt;/p&gt;
&lt;p&gt;KASAN reports the following UAF:&lt;/p&gt;
&lt;p&gt;BUG: KASAN: slab-use-after-free in tcf_ct_flow_table_process_conn+0x12b/0x380 [act_ct]
 Read of size 1 at addr ffff888c07603600 by task handler130/6469&lt;/p&gt;
&lt;p&gt;Call Trace:
  &amp;lt;IRQ&amp;gt;
  dump_stack_lvl+0x48/0x70
  print_address_description.constprop.0+0x33/0x3d0
  print_report+0xc0/0x2b0
  kasan_report+0xd0/0x120
  __asan_load1+0x6c/0x80
  tcf_ct_flow_table_process_conn+0x12b/0x380 [act_ct]
  tcf_ct_act+0x886/0x1350 [act_ct]
  tcf_action_exec+0xf8/0x1f0
  fl_classify+0x355/0x360 [cls_flower]
  __tcf_classify+0x1fd/0x330
  tcf_classify+0x21c/0x3c0
  sch_handle_ingress.constprop.0+0x2c5/0x500
  __netif_receive_skb_core.constprop.0+0xb25/0x1510
  __netif_receive_skb_list_core+0x220/0x4c0
  netif_receive_skb_list_internal+0x446/0x620
  napi_complete_done+0x157/0x3d0
  gro_cell_poll+0xcf/0x100
  __napi_poll+0x65/0x310
  net_rx_action+0x30c/0x5c0
  __do_softirq+0x14f/0x491
  __irq_exit_rcu+0x82/0xc0
  irq_exit_rcu+0xe/0x20
  common_interrupt+0xa1/0xb0
  &amp;lt;/IRQ&amp;gt;
  &amp;lt;TASK&amp;gt;
  asm_common_interrupt+0x27/0x40&lt;/p&gt;
&lt;p&gt;Allocated by task 6469:
  kasan_save_stack+0x38/0x70
  kasan_set_track+0x25/0x40
  kasan_save_alloc_info+0x1e/0x40
  __kasan_krealloc+0x133/0x190
  krealloc+0xaa/0x130
  nf_ct_ext_add+0xed/0x230 [nf_conntrack]
  tcf_ct_act+0x1095/0x1350 [act_ct]
  tcf_action_exec+0xf8/0x1f0
  fl_classify+0x355/0x360 [cls_flower]
  __tcf_classify+0x1fd/0x330
  tcf_c…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-41040</guid>
    </item>
    <item>
      <title>GHSA-g37m-wg3j-xw8v</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-g37m-wg3j-xw8v</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;net/sched: Fix UAF when resolving a clash&lt;/p&gt;
&lt;p&gt;KASAN reports the following UAF:&lt;/p&gt;
&lt;p&gt;BUG: KASAN: slab-use-after-free in tcf_ct_flow_table_process_conn+0x12b/0x380 [act_ct]
 Read of size 1 at addr ffff888c07603600 by task handler130/6469&lt;/p&gt;
&lt;p&gt;Call Trace:
  &amp;lt;IRQ&amp;gt;
  dump_stack_lvl+0x48/0x70
  print_address_description.constprop.0+0x33/0x3d0
  print_report+0xc0/0x2b0
  kasan_report+0xd0/0x120
  __asan_load1+0x6c/0x80
  tcf_ct_flow_table_process_conn+0x12b/0x380 [act_ct]
  tcf_ct_act+0x886/0x1350 [act_ct]
  tcf_action_exec+0xf8/0x1f0
  fl_classify+0x355/0x360 [cls_flower]
  __tcf_classify+0x1fd/0x330
  tcf_classify+0x21c/0x3c0
  sch_handle_ingress.constprop.0+0x2c5/0x500
  __netif_receive_skb_core.constprop.0+0xb25/0x1510
  __netif_receive_skb_list_core+0x220/0x4c0
  netif_receive_skb_list_internal+0x446/0x620
  napi_complete_done+0x157/0x3d0
  gro_cell_poll+0xcf/0x100
  __napi_poll+0x65/0x310
  net_rx_action+0x30c/0x5c0
  __do_softirq+0x14f/0x491
  __irq_exit_rcu+0x82/0xc0
  irq_exit_rcu+0xe/0x20
  common_interrupt+0xa1/0xb0
  &amp;lt;/IRQ&amp;gt;
  &amp;lt;TASK&amp;gt;
  asm_common_interrupt+0x27/0x40&lt;/p&gt;
&lt;p&gt;Allocated by task 6469:
  kasan_save_stack+0x38/0x70
  kasan_set_track+0x25/0x40
  kasan_save_alloc_info+0x1e/0x40
  __kasan_krealloc+0x133/0x190
  krealloc+0xaa/0x130
  nf_ct_ext_add+0xed/0x230 [nf_conntrack]
  tcf_ct_act+0x1095/0x1350 [act_ct]
  tcf_action_exec+0xf8/0x1f0
  fl_classify+0x355/0x360 [cls_flower]
  __tcf_classify+0x1fd/0x330
  tcf_c…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;net/sched: Fix UAF when resolving a clash&lt;/p&gt;
&lt;p&gt;KASAN reports the following UAF:&lt;/p&gt;
&lt;p&gt;BUG: KASAN: slab-use-after-free in tcf_ct_flow_table_process_conn+0x12b/0x380 [act_ct]
 Read of size 1 at addr ffff888c07603600 by task handler130/6469&lt;/p&gt;
&lt;p&gt;Call Trace:
  &amp;lt;IRQ&amp;gt;
  dump_stack_lvl+0x48/0x70
  print_address_description.constprop.0+0x33/0x3d0
  print_report+0xc0/0x2b0
  kasan_report+0xd0/0x120
  __asan_load1+0x6c/0x80
  tcf_ct_flow_table_process_conn+0x12b/0x380 [act_ct]
  tcf_ct_act+0x886/0x1350 [act_ct]
  tcf_action_exec+0xf8/0x1f0
  fl_classify+0x355/0x360 [cls_flower]
  __tcf_classify+0x1fd/0x330
  tcf_classify+0x21c/0x3c0
  sch_handle_ingress.constprop.0+0x2c5/0x500
  __netif_receive_skb_core.constprop.0+0xb25/0x1510
  __netif_receive_skb_list_core+0x220/0x4c0
  netif_receive_skb_list_internal+0x446/0x620
  napi_complete_done+0x157/0x3d0
  gro_cell_poll+0xcf/0x100
  __napi_poll+0x65/0x310
  net_rx_action+0x30c/0x5c0
  __do_softirq+0x14f/0x491
  __irq_exit_rcu+0x82/0xc0
  irq_exit_rcu+0xe/0x20
  common_interrupt+0xa1/0xb0
  &amp;lt;/IRQ&amp;gt;
  &amp;lt;TASK&amp;gt;
  asm_common_interrupt+0x27/0x40&lt;/p&gt;
&lt;p&gt;Allocated by task 6469:
  kasan_save_stack+0x38/0x70
  kasan_set_track+0x25/0x40
  kasan_save_alloc_info+0x1e/0x40
  __kasan_krealloc+0x133/0x190
  krealloc+0xaa/0x130
  nf_ct_ext_add+0xed/0x230 [nf_conntrack]
  tcf_ct_act+0x1095/0x1350 [act_ct]
  tcf_action_exec+0xf8/0x1f0
  fl_classify+0x355/0x360 [cls_flower]
  __tcf_classify+0x1fd/0x330
  tcf_c…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-g37m-wg3j-xw8v</guid>
    </item>
    <item>
      <title>ICSA-25-226-07 — Siemens Third-Party Components in SINEC OS</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-25-226-07</link>
      <description>&lt;p&gt;nfsd: NULL dereference in nfs3svc_encode_getaclres. scsi: core: use-after-free vulnerability. NFSD: vulnerability caused by loff_t overflow on the server when a client reads near the maximum offset, causing the server to return an EINVAL error, which the client retries indefinitely, instead of handling out-of-range READ requests by returning a short result with an EOF flag. NFSD: Vulnerability caused by an underflow in ia_size due to a mismatch between signed and unsigned 64-bit file size values, which can cause issues when handling large file sizes from NFS clients. NFSD: Vulnerability handling large file sizes for NFSv3 improperly capping client size values larger than s64_max, leading to unexpected behavior and potential data corruption. sh: cpuinfo: warning for CONFIG_CPUMASK_OFFSTACK. When CONFIG_CPUMASK_OFFSTACK and CONFIG_DEBUG_PER_CPU_MAPS are selected, cpu_max_bits_warn() generates a runtime warning when showing /proc/cpuinfo. A failure in the -fstack-protector feature in GCC-based toolchains 
that target AArch64 allows an attacker to exploit an existing buffer 
overflow in dynamically-sized local variables in your application 
without this being detected. This stack-protector failure only applies 
to C99-style dynamically-sized local variables or those created using 
alloca(). The stack-protector operates as intended for statically-sized 
local variables.&lt;/p&gt;
&lt;p&gt;The default behavior when the stack-protector 
detects an overflow is to terminate your application, resulting…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;nfsd: NULL dereference in nfs3svc_encode_getaclres. scsi: core: use-after-free vulnerability. NFSD: vulnerability caused by loff_t overflow on the server when a client reads near the maximum offset, causing the server to return an EINVAL error, which the client retries indefinitely, instead of handling out-of-range READ requests by returning a short result with an EOF flag. NFSD: Vulnerability caused by an underflow in ia_size due to a mismatch between signed and unsigned 64-bit file size values, which can cause issues when handling large file sizes from NFS clients. NFSD: Vulnerability handling large file sizes for NFSv3 improperly capping client size values larger than s64_max, leading to unexpected behavior and potential data corruption. sh: cpuinfo: warning for CONFIG_CPUMASK_OFFSTACK. When CONFIG_CPUMASK_OFFSTACK and CONFIG_DEBUG_PER_CPU_MAPS are selected, cpu_max_bits_warn() generates a runtime warning when showing /proc/cpuinfo. A failure in the -fstack-protector feature in GCC-based toolchains 
that target AArch64 allows an attacker to exploit an existing buffer 
overflow in dynamically-sized local variables in your application 
without this being detected. This stack-protector failure only applies 
to C99-style dynamically-sized local variables or those created using 
alloca(). The stack-protector operates as intended for statically-sized 
local variables.&lt;/p&gt;
&lt;p&gt;The default behavior when the stack-protector 
detects an overflow is to terminate your application, resulting…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-25-226-07</guid>
    </item>
    <item>
      <title>OESA-2024-1960 — kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2024-1960</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&#13;
&#13;
In the Linux kernel, the following vulnerability has been resolved:&#13;
&#13;
efi: libstub: only free priv.runtime_map when allocated&#13;
&#13;
priv.runtime_map is only allocated when efi_novamap is not set.
Otherwise, it is an uninitialized value.  In the error path, it is freed
unconditionally.  Avoid passing an uninitialized value to free_pool.
Free priv.runtime_map only when it was allocated.&#13;
&#13;
This bug was discovered and resolved using Coverity Static Analysis
Security Testing (SAST) by Synopsys, Inc.(CVE-2024-33619)&#13;
&#13;
In the Linux kernel, the following vulnerability has been resolved:&#13;
&#13;
fpga: region: add owner module and take its refcount&#13;
&#13;
The current implementation of the fpga region assumes that the low-level
module registers a driver for the parent device and uses its owner pointer
to take the module&amp;amp;apos;s refcount. This approach is problematic since it can
lead to a null pointer dereference while attempting to get the region
during programming if the parent device does not have a driver.&#13;
&#13;
To address this problem, add a module owner pointer to the fpga_region
struct and use it to take the module&amp;amp;apos;s refcount. Modify the functions for
registering a region to take an additional owner module parameter and
rename them to avoid conflicts. Use the old function names for helper
macros that automatically set the module that registers the region as the
owner. This ensures compatibility with existing low…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&#13;
&#13;
In the Linux kernel, the following vulnerability has been resolved:&#13;
&#13;
efi: libstub: only free priv.runtime_map when allocated&#13;
&#13;
priv.runtime_map is only allocated when efi_novamap is not set.
Otherwise, it is an uninitialized value.  In the error path, it is freed
unconditionally.  Avoid passing an uninitialized value to free_pool.
Free priv.runtime_map only when it was allocated.&#13;
&#13;
This bug was discovered and resolved using Coverity Static Analysis
Security Testing (SAST) by Synopsys, Inc.(CVE-2024-33619)&#13;
&#13;
In the Linux kernel, the following vulnerability has been resolved:&#13;
&#13;
fpga: region: add owner module and take its refcount&#13;
&#13;
The current implementation of the fpga region assumes that the low-level
module registers a driver for the parent device and uses its owner pointer
to take the module&amp;amp;apos;s refcount. This approach is problematic since it can
lead to a null pointer dereference while attempting to get the region
during programming if the parent device does not have a driver.&#13;
&#13;
To address this problem, add a module owner pointer to the fpga_region
struct and use it to take the module&amp;amp;apos;s refcount. Modify the functions for
registering a region to take an additional owner module parameter and
rename them to avoid conflicts. Use the old function names for helper
macros that automatically set the module that registers the region as the
owner. This ensures compatibility with existing low…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2024-1960</guid>
    </item>
    <item>
      <title>RHSA-2024:6567 — Red Hat Security Advisory: kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2024:6567</link>
      <description>&lt;p&gt;kernel: efivarfs: force RO when remounting if SetVariable is not supported kernel: iommufd: Fix missing update of domains_itree after splitting iopt_area kernel: nfsd: fix RELEASE_LOCKOWNER kernel: mm: cachestat: fix folio read-after-free in cache walk kernel: mm/writeback: fix possible divide-by-zero in wb_dirty_limits(), again kernel: Bluetooth: af_bluetooth: Fix deadlock kernel: kprobes/x86: Use copy_from_kernel_nofault() to read from unsafe address kernel: KVM: SVM: Flush pages under kvm-&amp;amp;gt;lock to fix UAF in svm_register_enc_region() kernel: mm: cachestat: fix two shmem bugs kernel: x86/coco: Require seeding RNG with RDRAND on CoCo systems kernel: mm/hugetlb: fix missing hugetlb_lock for resv uncharge kernel: regmap: maple: Fix cache corruption in regcache_maple_drop() kernel: net: fix out-of-bounds access in ops_init kernel: net: bridge: mst: fix vlan use-after-free kernel: scsi: qedf: Ensure the copied buf is NUL terminated kernel: usb-storage: alauda: Check whether the media is initialized kernel: xhci: Handle TD clearing for multiple streams case kernel: cxl/region: Fix memregion leaks in devm_cxl_add_region() kernel: net/sched: Fix UAF when resolving a clash kernel: ppp: reject claimed-as-LCP but actually malformed packets kernel: mm: prevent derefencing NULL ptr in pfn_section_valid() kernel: nvme: avoid double free special payload kernel: PCI/MSI: Fix UAF in msi_capability_init kernel: xdp: Remove WARN() from __xdp_reg_mem_model() kernel: x86: stop playing stack…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;kernel: efivarfs: force RO when remounting if SetVariable is not supported kernel: iommufd: Fix missing update of domains_itree after splitting iopt_area kernel: nfsd: fix RELEASE_LOCKOWNER kernel: mm: cachestat: fix folio read-after-free in cache walk kernel: mm/writeback: fix possible divide-by-zero in wb_dirty_limits(), again kernel: Bluetooth: af_bluetooth: Fix deadlock kernel: kprobes/x86: Use copy_from_kernel_nofault() to read from unsafe address kernel: KVM: SVM: Flush pages under kvm-&amp;amp;gt;lock to fix UAF in svm_register_enc_region() kernel: mm: cachestat: fix two shmem bugs kernel: x86/coco: Require seeding RNG with RDRAND on CoCo systems kernel: mm/hugetlb: fix missing hugetlb_lock for resv uncharge kernel: regmap: maple: Fix cache corruption in regcache_maple_drop() kernel: net: fix out-of-bounds access in ops_init kernel: net: bridge: mst: fix vlan use-after-free kernel: scsi: qedf: Ensure the copied buf is NUL terminated kernel: usb-storage: alauda: Check whether the media is initialized kernel: xhci: Handle TD clearing for multiple streams case kernel: cxl/region: Fix memregion leaks in devm_cxl_add_region() kernel: net/sched: Fix UAF when resolving a clash kernel: ppp: reject claimed-as-LCP but actually malformed packets kernel: mm: prevent derefencing NULL ptr in pfn_section_valid() kernel: nvme: avoid double free special payload kernel: PCI/MSI: Fix UAF in msi_capability_init kernel: xdp: Remove WARN() from __xdp_reg_mem_model() kernel: x86: stop playing stack…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2024:6567</guid>
    </item>
    <item>
      <title>RHSA-2024:7001 — Red Hat Security Advisory: kernel-rt security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2024:7001</link>
      <description>&lt;p&gt;kernel: kyber: fix out of bounds access when preempted kernel: Input: elantech - fix stack out of bound access in elantech_change_report_id() kernel: asix: fix uninit-value in asix_mdio_read() kernel: driver core: auxiliary bus: Fix memory leak when driver_register() fail kernel: ACPI: fix NULL pointer dereference kernel: watchdog: Fix possible use-after-free by calling del_timer_sync() kernel: fbmem: Do not delete the mode that is still in use kernel: virtio-net: Add validation for used length kernel: tty: Fix out-of-bound vmalloc access in imageblit kernel: hwmon: (w83793) Fix NULL pointer dereference by removing unnecessary structure field kernel: hwmon: (w83792d) Fix NULL pointer dereference by removing unnecessary structure field kernel: hwmon: (w83791d) Fix NULL pointer dereference by removing unnecessary structure field kernel: hwmon: (mlxreg-fan) Return non-zero value when fan current state is enforced from sysfs kernel: block: don&amp;#39;t call rq_qos_ops-&amp;gt;done_bio if the bio isn&amp;#39;t tracked kernel: lib/generic-radix-tree.c: Don&amp;#39;t overflow in peek() kernel: mlxsw: thermal: Fix out-of-bounds memory accesses kernel: ptp: Fix possible memory leak in ptp_clock_register() kernel: mm, slub: fix potential memoryleak in kmem_cache_open() kernel: nvmem: Fix shift-out-of-bound (UBSAN) with byte size cells kernel: serial: core: fix transmit-buffer reset and memleak kernel: mlxsw: spectrum: Protect driver from buggy firmware kernel: USB: core: Make do_proc_control() and do_proc_bulk() k…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;kernel: kyber: fix out of bounds access when preempted kernel: Input: elantech - fix stack out of bound access in elantech_change_report_id() kernel: asix: fix uninit-value in asix_mdio_read() kernel: driver core: auxiliary bus: Fix memory leak when driver_register() fail kernel: ACPI: fix NULL pointer dereference kernel: watchdog: Fix possible use-after-free by calling del_timer_sync() kernel: fbmem: Do not delete the mode that is still in use kernel: virtio-net: Add validation for used length kernel: tty: Fix out-of-bound vmalloc access in imageblit kernel: hwmon: (w83793) Fix NULL pointer dereference by removing unnecessary structure field kernel: hwmon: (w83792d) Fix NULL pointer dereference by removing unnecessary structure field kernel: hwmon: (w83791d) Fix NULL pointer dereference by removing unnecessary structure field kernel: hwmon: (mlxreg-fan) Return non-zero value when fan current state is enforced from sysfs kernel: block: don&amp;#39;t call rq_qos_ops-&amp;gt;done_bio if the bio isn&amp;#39;t tracked kernel: lib/generic-radix-tree.c: Don&amp;#39;t overflow in peek() kernel: mlxsw: thermal: Fix out-of-bounds memory accesses kernel: ptp: Fix possible memory leak in ptp_clock_register() kernel: mm, slub: fix potential memoryleak in kmem_cache_open() kernel: nvmem: Fix shift-out-of-bound (UBSAN) with byte size cells kernel: serial: core: fix transmit-buffer reset and memleak kernel: mlxsw: spectrum: Protect driver from buggy firmware kernel: USB: core: Make do_proc_control() and do_proc_bulk() k…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2024:7001</guid>
    </item>
    <item>
      <title>SSA-355557 — SSA-355557: Multiple Vulnerabilities in Third-Party Components in SINEC OS before V3.2</title>
      <link>https://cve.radiocsirt.org/vuln/ssa-355557</link>
      <description>&lt;p&gt;nfsd: NULL dereference in nfs3svc_encode_getaclres. scsi: core: use-after-free vulnerability. NFSD: vulnerability caused by loff_t overflow on the server when a client reads near the maximum offset, causing the server to return an EINVAL error, which the client retries indefinitely, instead of handling out-of-range READ requests by returning a short result with an EOF flag. NFSD: Vulnerability caused by an underflow in ia_size due to a mismatch between signed and unsigned 64-bit file size values, which can cause issues when handling large file sizes from NFS clients. NFSD: Vulnerability handling large file sizes for NFSv3 improperly capping client size values larger than s64_max, leading to unexpected behavior and potential data corruption. sh: cpuinfo: warning for CONFIG_CPUMASK_OFFSTACK. When CONFIG_CPUMASK_OFFSTACK and CONFIG_DEBUG_PER_CPU_MAPS are selected, cpu_max_bits_warn() generates a runtime warning when showing /proc/cpuinfo. A failure in the -fstack-protector feature in GCC-based toolchains 
that target AArch64 allows an attacker to exploit an existing buffer 
overflow in dynamically-sized local variables in your application 
without this being detected. This stack-protector failure only applies 
to C99-style dynamically-sized local variables or those created using 
alloca(). The stack-protector operates as intended for statically-sized 
local variables.&lt;/p&gt;
&lt;p&gt;The default behavior when the stack-protector 
detects an overflow is to terminate your application, resulting…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;nfsd: NULL dereference in nfs3svc_encode_getaclres. scsi: core: use-after-free vulnerability. NFSD: vulnerability caused by loff_t overflow on the server when a client reads near the maximum offset, causing the server to return an EINVAL error, which the client retries indefinitely, instead of handling out-of-range READ requests by returning a short result with an EOF flag. NFSD: Vulnerability caused by an underflow in ia_size due to a mismatch between signed and unsigned 64-bit file size values, which can cause issues when handling large file sizes from NFS clients. NFSD: Vulnerability handling large file sizes for NFSv3 improperly capping client size values larger than s64_max, leading to unexpected behavior and potential data corruption. sh: cpuinfo: warning for CONFIG_CPUMASK_OFFSTACK. When CONFIG_CPUMASK_OFFSTACK and CONFIG_DEBUG_PER_CPU_MAPS are selected, cpu_max_bits_warn() generates a runtime warning when showing /proc/cpuinfo. A failure in the -fstack-protector feature in GCC-based toolchains 
that target AArch64 allows an attacker to exploit an existing buffer 
overflow in dynamically-sized local variables in your application 
without this being detected. This stack-protector failure only applies 
to C99-style dynamically-sized local variables or those created using 
alloca(). The stack-protector operates as intended for statically-sized 
local variables.&lt;/p&gt;
&lt;p&gt;The default behavior when the stack-protector 
detects an overflow is to terminate your application, resulting…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ssa-355557</guid>
    </item>
    <item>
      <title>SUSE-SU-2024:2894-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2024:2894-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2024:2894-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2024-41040</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-41040</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 129 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: net/sched: Fix UAF when resolving a clash KASAN reports the following UAF:  BUG: KASAN: slab-use-after-free in tcf_ct_flow_table_process_conn+0x12b/0x380 [act_ct]  Read of size 1 at addr ffff888c07603600 by task handler130/6469  Call Trace:   &amp;lt;IRQ&amp;gt;   dump_stack_lvl+0x48/0x70   print_address_description.constprop.0+0x33/0x3d0   print_report+0xc0/0x2b0   kasan_report+0xd0/0x120   __asan_load1+0x6c/0x80   tcf_ct_flow_table_process_conn+0x12b/0x380 [act_ct]   tcf_ct_act+0x886/0x1350 [act_ct]   tcf_action_exec+0xf8/0x1f0   fl_classify+0x355/0x360 [cls_flower]   __tcf_classify+0x1fd/0x330   tcf_classify+0x21c/0x3c0   sch_handle_ingress.constprop.0+0x2c5/0x500   __netif_receive_skb_core.constprop.0+0xb25/0x1510   __netif_receive_skb_list_core+0x220/0x4c0   netif_receive_skb_list_internal+0x446/0x620   napi_complete_done+0x157/0x3d0   gro_cell_poll+0xcf/0x100   __napi_poll+0x65/0x310   net_rx_action+0x30c/0x5c0   __do_softirq+0x14f/0x491   __irq_exit_rcu+0x82/0xc0   irq_exit_rcu+0xe/0x20   common_interrupt+0xa1/0xb0   &amp;lt;/IRQ&amp;gt;   &amp;lt;TASK&amp;gt;   asm_common_interrupt+0x27/0x40  Allocated by task 6469:   kasan_save_stack+0x38/0x70   kasan_set_track+0x25/0x40   kasan_save_alloc_info+0x1e/0x40   __kasan_krealloc+0x133/0x190   krealloc+0xaa/0x130   nf_ct_ext_add+0xed/0x230 [nf_conntrack]   tcf_ct_act+0x1095/0x1350 [act_ct]   tcf_action_exec+0xf8/0x1f0   fl_classify+0x355/0x360 [cls_flower]   __tcf_classify+0x1fd/0x330   tcf_classi…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 129 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: net/sched: Fix UAF when resolving a clash KASAN reports the following UAF:  BUG: KASAN: slab-use-after-free in tcf_ct_flow_table_process_conn+0x12b/0x380 [act_ct]  Read of size 1 at addr ffff888c07603600 by task handler130/6469  Call Trace:   &amp;lt;IRQ&amp;gt;   dump_stack_lvl+0x48/0x70   print_address_description.constprop.0+0x33/0x3d0   print_report+0xc0/0x2b0   kasan_report+0xd0/0x120   __asan_load1+0x6c/0x80   tcf_ct_flow_table_process_conn+0x12b/0x380 [act_ct]   tcf_ct_act+0x886/0x1350 [act_ct]   tcf_action_exec+0xf8/0x1f0   fl_classify+0x355/0x360 [cls_flower]   __tcf_classify+0x1fd/0x330   tcf_classify+0x21c/0x3c0   sch_handle_ingress.constprop.0+0x2c5/0x500   __netif_receive_skb_core.constprop.0+0xb25/0x1510   __netif_receive_skb_list_core+0x220/0x4c0   netif_receive_skb_list_internal+0x446/0x620   napi_complete_done+0x157/0x3d0   gro_cell_poll+0xcf/0x100   __napi_poll+0x65/0x310   net_rx_action+0x30c/0x5c0   __do_softirq+0x14f/0x491   __irq_exit_rcu+0x82/0xc0   irq_exit_rcu+0xe/0x20   common_interrupt+0xa1/0xb0   &amp;lt;/IRQ&amp;gt;   &amp;lt;TASK&amp;gt;   asm_common_interrupt+0x27/0x40  Allocated by task 6469:   kasan_save_stack+0x38/0x70   kasan_set_track+0x25/0x40   kasan_save_alloc_info+0x1e/0x40   __kasan_krealloc+0x133/0x190   krealloc+0xaa/0x130   nf_ct_ext_add+0xed/0x230 [nf_conntrack]   tcf_ct_act+0x1095/0x1350 [act_ct]   tcf_action_exec+0xf8/0x1f0   fl_classify+0x355/0x360 [cls_flower]   __tcf_classify+0x1fd/0x330   tcf_classi…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-41040</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-1722 — Linux Kernel: Mehrere Schwachstellen ermöglichen nicht spezifizierten Angriff</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1722</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1722</guid>
    </item>
  </channel>
</rss>
