<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 07:48:35 +0000</lastBuildDate>
    <item>
      <title>ALSA-2024:10939 — Moderate: kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2024:10939</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: bpftool, AlmaLinux:9: kernel, AlmaLinux:9: kernel-64k, AlmaLinux:9: kernel-64k-core, AlmaLinux:9: kernel-64k-debug, AlmaLinux:9: kernel-64k-debug-core, AlmaLinux:9: kernel-64k-debug-devel, AlmaLinux:9: kernel-64k-debug-devel-matched, AlmaLinux:9: kernel-64k-debug-modules, AlmaLinux:9: kernel-64k-debug-modules-core and 53 more&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: net/smc: fix illegal rmb_desc access in SMC-D connection dump (CVE-2024-26615)
  * kernel: block: initialize integrity buffer to zero before writing it to media (CVE-2024-43854)
  * kernel: iommu: Restore lost return in iommu_report_device_fault() (CVE-2024-44994)
  * kernel: netfilter: flowtable: initialise extack before use (CVE-2024-45018)
  * kernel: selinux,smack: don&amp;#39;t bypass permissions check in inode_setsecctx hook (CVE-2024-46695)
  * kernel: net: avoid potential underflow in qdisc_pkt_len_init() with UFO (CVE-2024-49949)
  * kernel: netfilter: nft_payload: sanitize offset and length before calling skb_checksum() (CVE-2024-50251)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: bpftool, AlmaLinux:9: kernel, AlmaLinux:9: kernel-64k, AlmaLinux:9: kernel-64k-core, AlmaLinux:9: kernel-64k-debug, AlmaLinux:9: kernel-64k-debug-core, AlmaLinux:9: kernel-64k-debug-devel, AlmaLinux:9: kernel-64k-debug-devel-matched, AlmaLinux:9: kernel-64k-debug-modules, AlmaLinux:9: kernel-64k-debug-modules-core and 53 more&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: net/smc: fix illegal rmb_desc access in SMC-D connection dump (CVE-2024-26615)
  * kernel: block: initialize integrity buffer to zero before writing it to media (CVE-2024-43854)
  * kernel: iommu: Restore lost return in iommu_report_device_fault() (CVE-2024-44994)
  * kernel: netfilter: flowtable: initialise extack before use (CVE-2024-45018)
  * kernel: selinux,smack: don&amp;#39;t bypass permissions check in inode_setsecctx hook (CVE-2024-46695)
  * kernel: net: avoid potential underflow in qdisc_pkt_len_init() with UFO (CVE-2024-49949)
  * kernel: netfilter: nft_payload: sanitize offset and length before calling skb_checksum() (CVE-2024-50251)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2024:10939</guid>
    </item>
    <item>
      <title>bdu:2025-03752</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-03752</link>
      <description>bdu:2025-03752</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-03752</guid>
    </item>
    <item>
      <title>BELL-CVE-2024-44994</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2024-44994</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2024-44994</guid>
    </item>
    <item>
      <title>certfr-2024-avi-1078 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de Red Hat. Certaines d'entre elles permettent à un…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2024-avi-1078</link>
      <description>certfr-2024-avi-1078</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2024-avi-1078</guid>
    </item>
    <item>
      <title>EUVD-2026-346066</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-346066</link>
      <description>EUVD-2026-346066</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-346066</guid>
    </item>
    <item>
      <title>fkie_cve-2024-44994</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-44994</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;iommu: Restore lost return in iommu_report_device_fault()&lt;/p&gt;
&lt;p&gt;When iommu_report_device_fault gets called with a partial fault it is
supposed to collect the fault into the group and then return.&lt;/p&gt;
&lt;p&gt;Instead the return was accidently deleted which results in trying to
process the fault and an eventual crash.&lt;/p&gt;
&lt;p&gt;Deleting the return was a typo, put it back.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;iommu: Restore lost return in iommu_report_device_fault()&lt;/p&gt;
&lt;p&gt;When iommu_report_device_fault gets called with a partial fault it is
supposed to collect the fault into the group and then return.&lt;/p&gt;
&lt;p&gt;Instead the return was accidently deleted which results in trying to
process the fault and an eventual crash.&lt;/p&gt;
&lt;p&gt;Deleting the return was a typo, put it back.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-44994</guid>
    </item>
    <item>
      <title>GHSA-7hqv-cx6x-h3c9</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-7hqv-cx6x-h3c9</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;iommu: Restore lost return in iommu_report_device_fault()&lt;/p&gt;
&lt;p&gt;When iommu_report_device_fault gets called with a partial fault it is
supposed to collect the fault into the group and then return.&lt;/p&gt;
&lt;p&gt;Instead the return was accidently deleted which results in trying to
process the fault and an eventual crash.&lt;/p&gt;
&lt;p&gt;Deleting the return was a typo, put it back.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;iommu: Restore lost return in iommu_report_device_fault()&lt;/p&gt;
&lt;p&gt;When iommu_report_device_fault gets called with a partial fault it is
supposed to collect the fault into the group and then return.&lt;/p&gt;
&lt;p&gt;Instead the return was accidently deleted which results in trying to
process the fault and an eventual crash.&lt;/p&gt;
&lt;p&gt;Deleting the return was a typo, put it back.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-7hqv-cx6x-h3c9</guid>
    </item>
    <item>
      <title>OESA-2024-2181 — kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2024-2181</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&#13;
&#13;
In the Linux kernel, the following vulnerability has been resolved:&#13;
&#13;
tcp: Use refcount_inc_not_zero() in tcp_twsk_unique().&#13;
&#13;
Anderson Nascimento reported a use-after-free splat in tcp_twsk_unique()
with nice analysis.&#13;
&#13;
Since commit ec94c2696f0b (&amp;amp;quot;tcp/dccp: avoid one atomic operation for
timewait hashdance&amp;amp;quot;), inet_twsk_hashdance() sets TIME-WAIT socket&amp;amp;apos;s
sk_refcnt after putting it into ehash and releasing the bucket lock.&#13;
&#13;
Thus, there is a small race window where other threads could try to
reuse the port during connect() and call sock_hold() in tcp_twsk_unique()
for the TIME-WAIT socket with zero refcnt.&#13;
&#13;
If that happens, the refcnt taken by tcp_twsk_unique() is overwritten
and sock_put() will cause underflow, triggering a real use-after-free
somewhere else.&#13;
&#13;
To avoid the use-after-free, we need to use refcount_inc_not_zero() in
tcp_twsk_unique() and give up on reusing the port if it returns false.&#13;
&#13;
[0]:
refcount_t: addition on 0; use-after-free.
WARNING: CPU: 0 PID: 1039313 at lib/refcount.c:25 refcount_warn_saturate+0xe5/0x110
CPU: 0 PID: 1039313 Comm: trigger Not tainted 6.8.6-200.fc39.x86_64 #1
Hardware name: VMware, Inc. VMware20,1/440BX Desktop Reference Platform, BIOS VMW201.00V.21805430.B64.2305221830 05/22/2023
RIP: 0010:refcount_warn_saturate+0xe5/0x110
Code: 42 8e ff 0f 0b c3 cc cc cc cc 80 3d aa 13 ea 01 00 0f 85 5e ff ff ff 48 c7 c7 f8 8e b7 82 c6 05 96 13 ea…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&#13;
&#13;
In the Linux kernel, the following vulnerability has been resolved:&#13;
&#13;
tcp: Use refcount_inc_not_zero() in tcp_twsk_unique().&#13;
&#13;
Anderson Nascimento reported a use-after-free splat in tcp_twsk_unique()
with nice analysis.&#13;
&#13;
Since commit ec94c2696f0b (&amp;amp;quot;tcp/dccp: avoid one atomic operation for
timewait hashdance&amp;amp;quot;), inet_twsk_hashdance() sets TIME-WAIT socket&amp;amp;apos;s
sk_refcnt after putting it into ehash and releasing the bucket lock.&#13;
&#13;
Thus, there is a small race window where other threads could try to
reuse the port during connect() and call sock_hold() in tcp_twsk_unique()
for the TIME-WAIT socket with zero refcnt.&#13;
&#13;
If that happens, the refcnt taken by tcp_twsk_unique() is overwritten
and sock_put() will cause underflow, triggering a real use-after-free
somewhere else.&#13;
&#13;
To avoid the use-after-free, we need to use refcount_inc_not_zero() in
tcp_twsk_unique() and give up on reusing the port if it returns false.&#13;
&#13;
[0]:
refcount_t: addition on 0; use-after-free.
WARNING: CPU: 0 PID: 1039313 at lib/refcount.c:25 refcount_warn_saturate+0xe5/0x110
CPU: 0 PID: 1039313 Comm: trigger Not tainted 6.8.6-200.fc39.x86_64 #1
Hardware name: VMware, Inc. VMware20,1/440BX Desktop Reference Platform, BIOS VMW201.00V.21805430.B64.2305221830 05/22/2023
RIP: 0010:refcount_warn_saturate+0xe5/0x110
Code: 42 8e ff 0f 0b c3 cc cc cc cc 80 3d aa 13 ea 01 00 0f 85 5e ff ff ff 48 c7 c7 f8 8e b7 82 c6 05 96 13 ea…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2024-2181</guid>
    </item>
    <item>
      <title>RHSA-2024:10939 — Red Hat Security Advisory: kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2024:10939</link>
      <description>&lt;p&gt;kernel: net/smc: fix illegal rmb_desc access in SMC-D connection dump kernel: block: initialize integrity buffer to zero before writing it to media kernel: iommu: Restore lost return in iommu_report_device_fault() kernel: netfilter: flowtable: initialise extack before use kernel: selinux,smack: don&amp;#39;t bypass permissions check in inode_setsecctx hook kernel: net: avoid potential underflow in qdisc_pkt_len_init() with UFO kernel: netfilter: nft_payload: sanitize offset and length before calling skb_checksum()&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;kernel: net/smc: fix illegal rmb_desc access in SMC-D connection dump kernel: block: initialize integrity buffer to zero before writing it to media kernel: iommu: Restore lost return in iommu_report_device_fault() kernel: netfilter: flowtable: initialise extack before use kernel: selinux,smack: don&amp;#39;t bypass permissions check in inode_setsecctx hook kernel: net: avoid potential underflow in qdisc_pkt_len_init() with UFO kernel: netfilter: nft_payload: sanitize offset and length before calling skb_checksum()&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2024:10939</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2024-44994</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-44994</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 66 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: iommu: Restore lost return in iommu_report_device_fault() When iommu_report_device_fault gets called with a partial fault it is supposed to collect the fault into the group and then return. Instead the return was accidently deleted which results in trying to process the fault and an eventual crash. Deleting the return was a typo, put it back.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 66 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: iommu: Restore lost return in iommu_report_device_fault() When iommu_report_device_fault gets called with a partial fault it is supposed to collect the fault into the group and then return. Instead the return was accidently deleted which results in trying to process the fault and an eventual crash. Deleting the return was a typo, put it back.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-44994</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-2057 — Linux Kernel: Mehrere Schwachstellen ermöglichen Denial of Service oder unspezifischer Angriff</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-2057</link>
      <description>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen in Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen oder weitere unspezifische Angriffe durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen in Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen oder weitere unspezifische Angriffe durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-2057</guid>
    </item>
  </channel>
</rss>
