<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 18:40:34 +0000</lastBuildDate>
    <item>
      <title>bdu:2025-01906</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-01906</link>
      <description>bdu:2025-01906</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-01906</guid>
    </item>
    <item>
      <title>BELL-CVE-2024-44982</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2024-44982</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2024-44982</guid>
    </item>
    <item>
      <title>certfr-2024-avi-0837 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de Debian. Elles permettent à un attaquant de provo…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0837</link>
      <description>certfr-2024-avi-0837</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2024-avi-0837</guid>
    </item>
    <item>
      <title>EUVD-2026-313195</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-313195</link>
      <description>EUVD-2026-313195</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-313195</guid>
    </item>
    <item>
      <title>fkie_cve-2024-44982</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-44982</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;drm/msm/dpu: cleanup FB if dpu_format_populate_layout fails&lt;/p&gt;
&lt;p&gt;If the dpu_format_populate_layout() fails, then FB is prepared, but not
cleaned up. This ends up leaking the pin_count on the GEM object and
causes a splat during DRM file closure:&lt;/p&gt;
&lt;p&gt;msm_obj-&amp;gt;pin_count
WARNING: CPU: 2 PID: 569 at drivers/gpu/drm/msm/msm_gem.c:121 update_lru_locked+0xc4/0xcc
[...]
Call trace:
 update_lru_locked+0xc4/0xcc
 put_pages+0xac/0x100
 msm_gem_free_object+0x138/0x180
 drm_gem_object_free+0x1c/0x30
 drm_gem_object_handle_put_unlocked+0x108/0x10c
 drm_gem_object_release_handle+0x58/0x70
 idr_for_each+0x68/0xec
 drm_gem_release+0x28/0x40
 drm_file_free+0x174/0x234
 drm_release+0xb0/0x160
 __fput+0xc0/0x2c8
 __fput_sync+0x50/0x5c
 __arm64_sys_close+0x38/0x7c
 invoke_syscall+0x48/0x118
 el0_svc_common.constprop.0+0x40/0xe0
 do_el0_svc+0x1c/0x28
 el0_svc+0x4c/0x120
 el0t_64_sync_handler+0x100/0x12c
 el0t_64_sync+0x190/0x194
irq event stamp: 129818
hardirqs last  enabled at (129817): [&amp;lt;ffffa5f6d953fcc0&amp;gt;] console_unlock+0x118/0x124
hardirqs last disabled at (129818): [&amp;lt;ffffa5f6da7dcf04&amp;gt;] el1_dbg+0x24/0x8c
softirqs last  enabled at (129808): [&amp;lt;ffffa5f6d94afc18&amp;gt;] handle_softirqs+0x4c8/0x4e8
softirqs last disabled at (129785): [&amp;lt;ffffa5f6d94105e4&amp;gt;] __do_softirq+0x14/0x20&lt;/p&gt;
&lt;p&gt;Patchwork: https://patchwork.freedesktop.org/patch/600714/&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;drm/msm/dpu: cleanup FB if dpu_format_populate_layout fails&lt;/p&gt;
&lt;p&gt;If the dpu_format_populate_layout() fails, then FB is prepared, but not
cleaned up. This ends up leaking the pin_count on the GEM object and
causes a splat during DRM file closure:&lt;/p&gt;
&lt;p&gt;msm_obj-&amp;gt;pin_count
WARNING: CPU: 2 PID: 569 at drivers/gpu/drm/msm/msm_gem.c:121 update_lru_locked+0xc4/0xcc
[...]
Call trace:
 update_lru_locked+0xc4/0xcc
 put_pages+0xac/0x100
 msm_gem_free_object+0x138/0x180
 drm_gem_object_free+0x1c/0x30
 drm_gem_object_handle_put_unlocked+0x108/0x10c
 drm_gem_object_release_handle+0x58/0x70
 idr_for_each+0x68/0xec
 drm_gem_release+0x28/0x40
 drm_file_free+0x174/0x234
 drm_release+0xb0/0x160
 __fput+0xc0/0x2c8
 __fput_sync+0x50/0x5c
 __arm64_sys_close+0x38/0x7c
 invoke_syscall+0x48/0x118
 el0_svc_common.constprop.0+0x40/0xe0
 do_el0_svc+0x1c/0x28
 el0_svc+0x4c/0x120
 el0t_64_sync_handler+0x100/0x12c
 el0t_64_sync+0x190/0x194
irq event stamp: 129818
hardirqs last  enabled at (129817): [&amp;lt;ffffa5f6d953fcc0&amp;gt;] console_unlock+0x118/0x124
hardirqs last disabled at (129818): [&amp;lt;ffffa5f6da7dcf04&amp;gt;] el1_dbg+0x24/0x8c
softirqs last  enabled at (129808): [&amp;lt;ffffa5f6d94afc18&amp;gt;] handle_softirqs+0x4c8/0x4e8
softirqs last disabled at (129785): [&amp;lt;ffffa5f6d94105e4&amp;gt;] __do_softirq+0x14/0x20&lt;/p&gt;
&lt;p&gt;Patchwork: https://patchwork.freedesktop.org/patch/600714/&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-44982</guid>
    </item>
    <item>
      <title>GHSA-59fp-j85q-63j4</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-59fp-j85q-63j4</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;drm/msm/dpu: cleanup FB if dpu_format_populate_layout fails&lt;/p&gt;
&lt;p&gt;If the dpu_format_populate_layout() fails, then FB is prepared, but not
cleaned up. This ends up leaking the pin_count on the GEM object and
causes a splat during DRM file closure:&lt;/p&gt;
&lt;p&gt;msm_obj-&amp;gt;pin_count
WARNING: CPU: 2 PID: 569 at drivers/gpu/drm/msm/msm_gem.c:121 update_lru_locked+0xc4/0xcc
[...]
Call trace:
 update_lru_locked+0xc4/0xcc
 put_pages+0xac/0x100
 msm_gem_free_object+0x138/0x180
 drm_gem_object_free+0x1c/0x30
 drm_gem_object_handle_put_unlocked+0x108/0x10c
 drm_gem_object_release_handle+0x58/0x70
 idr_for_each+0x68/0xec
 drm_gem_release+0x28/0x40
 drm_file_free+0x174/0x234
 drm_release+0xb0/0x160
 __fput+0xc0/0x2c8
 __fput_sync+0x50/0x5c
 __arm64_sys_close+0x38/0x7c
 invoke_syscall+0x48/0x118
 el0_svc_common.constprop.0+0x40/0xe0
 do_el0_svc+0x1c/0x28
 el0_svc+0x4c/0x120
 el0t_64_sync_handler+0x100/0x12c
 el0t_64_sync+0x190/0x194
irq event stamp: 129818
hardirqs last  enabled at (129817): [&amp;lt;ffffa5f6d953fcc0&amp;gt;] console_unlock+0x118/0x124
hardirqs last disabled at (129818): [&amp;lt;ffffa5f6da7dcf04&amp;gt;] el1_dbg+0x24/0x8c
softirqs last  enabled at (129808): [&amp;lt;ffffa5f6d94afc18&amp;gt;] handle_softirqs+0x4c8/0x4e8
softirqs last disabled at (129785): [&amp;lt;ffffa5f6d94105e4&amp;gt;] __do_softirq+0x14/0x20&lt;/p&gt;
&lt;p&gt;Patchwork: https://patchwork.freedesktop.org/patch/600714/&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;drm/msm/dpu: cleanup FB if dpu_format_populate_layout fails&lt;/p&gt;
&lt;p&gt;If the dpu_format_populate_layout() fails, then FB is prepared, but not
cleaned up. This ends up leaking the pin_count on the GEM object and
causes a splat during DRM file closure:&lt;/p&gt;
&lt;p&gt;msm_obj-&amp;gt;pin_count
WARNING: CPU: 2 PID: 569 at drivers/gpu/drm/msm/msm_gem.c:121 update_lru_locked+0xc4/0xcc
[...]
Call trace:
 update_lru_locked+0xc4/0xcc
 put_pages+0xac/0x100
 msm_gem_free_object+0x138/0x180
 drm_gem_object_free+0x1c/0x30
 drm_gem_object_handle_put_unlocked+0x108/0x10c
 drm_gem_object_release_handle+0x58/0x70
 idr_for_each+0x68/0xec
 drm_gem_release+0x28/0x40
 drm_file_free+0x174/0x234
 drm_release+0xb0/0x160
 __fput+0xc0/0x2c8
 __fput_sync+0x50/0x5c
 __arm64_sys_close+0x38/0x7c
 invoke_syscall+0x48/0x118
 el0_svc_common.constprop.0+0x40/0xe0
 do_el0_svc+0x1c/0x28
 el0_svc+0x4c/0x120
 el0t_64_sync_handler+0x100/0x12c
 el0t_64_sync+0x190/0x194
irq event stamp: 129818
hardirqs last  enabled at (129817): [&amp;lt;ffffa5f6d953fcc0&amp;gt;] console_unlock+0x118/0x124
hardirqs last disabled at (129818): [&amp;lt;ffffa5f6da7dcf04&amp;gt;] el1_dbg+0x24/0x8c
softirqs last  enabled at (129808): [&amp;lt;ffffa5f6d94afc18&amp;gt;] handle_softirqs+0x4c8/0x4e8
softirqs last disabled at (129785): [&amp;lt;ffffa5f6d94105e4&amp;gt;] __do_softirq+0x14/0x20&lt;/p&gt;
&lt;p&gt;Patchwork: https://patchwork.freedesktop.org/patch/600714/&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-59fp-j85q-63j4</guid>
    </item>
    <item>
      <title>msrc_CVE-2024-44982 — drm/msm/dpu: cleanup FB if dpu_format_populate_layout fails</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2024-44982</link>
      <description>msrc_CVE-2024-44982</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2024-44982</guid>
    </item>
    <item>
      <title>OESA-2024-2216 — kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2024-2216</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP3: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&#13;
&#13;
In the Linux kernel, the following vulnerability has been resolved:&#13;
&#13;
ALSA: usb-audio: Stop parsing channels bits when all channels are found.&#13;
&#13;
If a usb audio device sets more bits than the amount of channels
it could write outside of the map array.(CVE-2024-27436)&#13;
&#13;
In the Linux kernel, the following vulnerability has been resolved:&#13;
&#13;
usb: gadget: f_fs: Fix race between aio_cancel() and AIO request complete&#13;
&#13;
FFS based applications can utilize the aio_cancel() callback to dequeue
pending USB requests submitted to the UDC.  There is a scenario where the
FFS application issues an AIO cancel call, while the UDC is handling a
soft disconnect.  For a DWC3 based implementation, the callstack looks
like the following:&#13;
&#13;
    DWC3 Gadget                               FFS Application
dwc3_gadget_soft_disconnect()              ...
  --&amp;amp;gt; dwc3_stop_active_transfers()
    --&amp;amp;gt; dwc3_gadget_giveback(-ESHUTDOWN)
      --&amp;amp;gt; ffs_epfile_async_io_complete()   ffs_aio_cancel()
        --&amp;amp;gt; usb_ep_free_request()            --&amp;amp;gt; usb_ep_dequeue()&#13;
&#13;
There is currently no locking implemented between the AIO completion
handler and AIO cancel, so the issue occurs if the completion routine is
running in parallel to an AIO cancel call coming from the FFS application.
As the completion call frees the USB request (io_data-&amp;amp;gt;req) the FFS
application is also referencing it for the usb_ep_dequeue() call.  This can…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP3: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&#13;
&#13;
In the Linux kernel, the following vulnerability has been resolved:&#13;
&#13;
ALSA: usb-audio: Stop parsing channels bits when all channels are found.&#13;
&#13;
If a usb audio device sets more bits than the amount of channels
it could write outside of the map array.(CVE-2024-27436)&#13;
&#13;
In the Linux kernel, the following vulnerability has been resolved:&#13;
&#13;
usb: gadget: f_fs: Fix race between aio_cancel() and AIO request complete&#13;
&#13;
FFS based applications can utilize the aio_cancel() callback to dequeue
pending USB requests submitted to the UDC.  There is a scenario where the
FFS application issues an AIO cancel call, while the UDC is handling a
soft disconnect.  For a DWC3 based implementation, the callstack looks
like the following:&#13;
&#13;
    DWC3 Gadget                               FFS Application
dwc3_gadget_soft_disconnect()              ...
  --&amp;amp;gt; dwc3_stop_active_transfers()
    --&amp;amp;gt; dwc3_gadget_giveback(-ESHUTDOWN)
      --&amp;amp;gt; ffs_epfile_async_io_complete()   ffs_aio_cancel()
        --&amp;amp;gt; usb_ep_free_request()            --&amp;amp;gt; usb_ep_dequeue()&#13;
&#13;
There is currently no locking implemented between the AIO completion
handler and AIO cancel, so the issue occurs if the completion routine is
running in parallel to an AIO cancel call coming from the FFS application.
As the completion call frees the USB request (io_data-&amp;amp;gt;req) the FFS
application is also referencing it for the usb_ep_dequeue() call.  This can…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2024-2216</guid>
    </item>
    <item>
      <title>SUSE-SU-2024:3551-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2024:3551-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2024:3551-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2024-44982</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-44982</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:Pro:18.04:LTS: linux-aws-5.4, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:Pro:18.04:LTS: linux-azure-5.4, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3 and 159 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: drm/msm/dpu: cleanup FB if dpu_format_populate_layout fails If the dpu_format_populate_layout() fails, then FB is prepared, but not cleaned up. This ends up leaking the pin_count on the GEM object and causes a splat during DRM file closure: msm_obj-&amp;gt;pin_count WARNING: CPU: 2 PID: 569 at drivers/gpu/drm/msm/msm_gem.c:121 update_lru_locked+0xc4/0xcc [...] Call trace:  update_lru_locked+0xc4/0xcc  put_pages+0xac/0x100  msm_gem_free_object+0x138/0x180  drm_gem_object_free+0x1c/0x30  drm_gem_object_handle_put_unlocked+0x108/0x10c  drm_gem_object_release_handle+0x58/0x70  idr_for_each+0x68/0xec  drm_gem_release+0x28/0x40  drm_file_free+0x174/0x234  drm_release+0xb0/0x160  __fput+0xc0/0x2c8  __fput_sync+0x50/0x5c  __arm64_sys_close+0x38/0x7c  invoke_syscall+0x48/0x118  el0_svc_common.constprop.0+0x40/0xe0  do_el0_svc+0x1c/0x28  el0_svc+0x4c/0x120  el0t_64_sync_handler+0x100/0x12c  el0t_64_sync+0x190/0x194 irq event stamp: 129818 hardirqs last  enabled at (129817): [&amp;lt;ffffa5f6d953fcc0&amp;gt;] console_unlock+0x118/0x124 hardirqs last disabled at (129818): [&amp;lt;ffffa5f6da7dcf04&amp;gt;] el1_dbg+0x24/0x8c softirqs last  enabled at (129808): [&amp;lt;ffffa5f6d94afc18&amp;gt;] handle_softirqs+0x4c8/0x4e8 softirqs last disabled at (129785): [&amp;lt;ffffa5f6d94105e4&amp;gt;] __do_softirq+0x14/0x20 Patchwork: https://patchwork.freedesktop.org/patch/600714/&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:Pro:18.04:LTS: linux-aws-5.4, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:Pro:18.04:LTS: linux-azure-5.4, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3 and 159 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: drm/msm/dpu: cleanup FB if dpu_format_populate_layout fails If the dpu_format_populate_layout() fails, then FB is prepared, but not cleaned up. This ends up leaking the pin_count on the GEM object and causes a splat during DRM file closure: msm_obj-&amp;gt;pin_count WARNING: CPU: 2 PID: 569 at drivers/gpu/drm/msm/msm_gem.c:121 update_lru_locked+0xc4/0xcc [...] Call trace:  update_lru_locked+0xc4/0xcc  put_pages+0xac/0x100  msm_gem_free_object+0x138/0x180  drm_gem_object_free+0x1c/0x30  drm_gem_object_handle_put_unlocked+0x108/0x10c  drm_gem_object_release_handle+0x58/0x70  idr_for_each+0x68/0xec  drm_gem_release+0x28/0x40  drm_file_free+0x174/0x234  drm_release+0xb0/0x160  __fput+0xc0/0x2c8  __fput_sync+0x50/0x5c  __arm64_sys_close+0x38/0x7c  invoke_syscall+0x48/0x118  el0_svc_common.constprop.0+0x40/0xe0  do_el0_svc+0x1c/0x28  el0_svc+0x4c/0x120  el0t_64_sync_handler+0x100/0x12c  el0t_64_sync+0x190/0x194 irq event stamp: 129818 hardirqs last  enabled at (129817): [&amp;lt;ffffa5f6d953fcc0&amp;gt;] console_unlock+0x118/0x124 hardirqs last disabled at (129818): [&amp;lt;ffffa5f6da7dcf04&amp;gt;] el1_dbg+0x24/0x8c softirqs last  enabled at (129808): [&amp;lt;ffffa5f6d94afc18&amp;gt;] handle_softirqs+0x4c8/0x4e8 softirqs last disabled at (129785): [&amp;lt;ffffa5f6d94105e4&amp;gt;] __do_softirq+0x14/0x20 Patchwork: https://patchwork.freedesktop.org/patch/600714/&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-44982</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-2057 — Linux Kernel: Mehrere Schwachstellen ermöglichen Denial of Service oder unspezifischer Angriff</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-2057</link>
      <description>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen in Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen oder weitere unspezifische Angriffe durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen in Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen oder weitere unspezifische Angriffe durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-2057</guid>
    </item>
  </channel>
</rss>
