<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 22:33:52 +0000</lastBuildDate>
    <item>
      <title>ALSA-2025:20518 — Moderate: kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2025:20518</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: kernel, AlmaLinux:9: kernel-64k, AlmaLinux:9: kernel-64k-core, AlmaLinux:9: kernel-64k-debug, AlmaLinux:9: kernel-64k-debug-core, AlmaLinux:9: kernel-64k-debug-devel, AlmaLinux:9: kernel-64k-debug-devel-matched, AlmaLinux:9: kernel-64k-debug-modules, AlmaLinux:9: kernel-64k-debug-modules-core, AlmaLinux:9: kernel-64k-debug-modules-extra and 64 more&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: can: isotp: fix potential CAN frame reception race in isotp_rcv() (CVE-2022-48830)
  * kernel: soc: qcom: cmd-db: Map shared memory as WC, not WB (CVE-2024-46689)
  * kernel: Squashfs: sanity check symbolic link size (CVE-2024-46744)
  * kernel: vfs: fix race between evice_inodes() and find_inode()&amp;amp;#38;iput() (CVE-2024-47679)
  * kernel: x86/tdx: Fix &amp;#34;in-kernel MMIO&amp;#34; check (CVE-2024-47727)
  * kernel: rxrpc: Fix a race between socket set up and I/O thread creation (CVE-2024-49864)
  * kernel: io_uring: check if we need to reschedule during overflow flush (CVE-2024-50060)
  * kernel: can: m_can: pci: add missing m_can_class_free_dev() in probe/remove methods (CVE-2022-49024)
  * kernel: posix-clock: Fix missing timespec64 check in pc_clock_settime() (CVE-2024-50195)
  * kernel: rxrpc: Fix missing locking causing hanging calls (CVE-2024-50294)
  * kernel: io_uring/rw: fix missing NOWAIT check for O_DIRECT start write (CVE-2024-53052)
  * kernel: afs: Fix lock recursion (CVE-2024-53090)
  * kernel: virtio/vsock: Fix accept_queue memory leak (CVE-2024-53119)
  * kernel: KVM: VMX: Bury Intel PT virtualization (guest/host mode) behind CONFIG_BROKEN (CVE-2024-53135)
  * kernel: xen: Xen hypercall page unsafe against speculative attacks (Xen Security Advisory 466) (CVE-2024-53241)
  * kernel: RDMA/rxe: Fix the qp flush warnings in req (CVE-2024-53229)
  * kernel:…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: kernel, AlmaLinux:9: kernel-64k, AlmaLinux:9: kernel-64k-core, AlmaLinux:9: kernel-64k-debug, AlmaLinux:9: kernel-64k-debug-core, AlmaLinux:9: kernel-64k-debug-devel, AlmaLinux:9: kernel-64k-debug-devel-matched, AlmaLinux:9: kernel-64k-debug-modules, AlmaLinux:9: kernel-64k-debug-modules-core, AlmaLinux:9: kernel-64k-debug-modules-extra and 64 more&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: can: isotp: fix potential CAN frame reception race in isotp_rcv() (CVE-2022-48830)
  * kernel: soc: qcom: cmd-db: Map shared memory as WC, not WB (CVE-2024-46689)
  * kernel: Squashfs: sanity check symbolic link size (CVE-2024-46744)
  * kernel: vfs: fix race between evice_inodes() and find_inode()&amp;amp;#38;iput() (CVE-2024-47679)
  * kernel: x86/tdx: Fix &amp;#34;in-kernel MMIO&amp;#34; check (CVE-2024-47727)
  * kernel: rxrpc: Fix a race between socket set up and I/O thread creation (CVE-2024-49864)
  * kernel: io_uring: check if we need to reschedule during overflow flush (CVE-2024-50060)
  * kernel: can: m_can: pci: add missing m_can_class_free_dev() in probe/remove methods (CVE-2022-49024)
  * kernel: posix-clock: Fix missing timespec64 check in pc_clock_settime() (CVE-2024-50195)
  * kernel: rxrpc: Fix missing locking causing hanging calls (CVE-2024-50294)
  * kernel: io_uring/rw: fix missing NOWAIT check for O_DIRECT start write (CVE-2024-53052)
  * kernel: afs: Fix lock recursion (CVE-2024-53090)
  * kernel: virtio/vsock: Fix accept_queue memory leak (CVE-2024-53119)
  * kernel: KVM: VMX: Bury Intel PT virtualization (guest/host mode) behind CONFIG_BROKEN (CVE-2024-53135)
  * kernel: xen: Xen hypercall page unsafe against speculative attacks (Xen Security Advisory 466) (CVE-2024-53241)
  * kernel: RDMA/rxe: Fix the qp flush warnings in req (CVE-2024-53229)
  * kernel:…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2025:20518</guid>
    </item>
    <item>
      <title>bdu:2024-08231</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2024-08231</link>
      <description>bdu:2024-08231</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2024-08231</guid>
    </item>
    <item>
      <title>BELL-CVE-2024-46744</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2024-46744</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2024-46744</guid>
    </item>
    <item>
      <title>certfr-2024-avi-0837 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de Debian. Elles permettent à un attaquant de provo…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0837</link>
      <description>certfr-2024-avi-0837</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2024-avi-0837</guid>
    </item>
    <item>
      <title>EUVD-2026-317052</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-317052</link>
      <description>EUVD-2026-317052</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-317052</guid>
    </item>
    <item>
      <title>fkie_cve-2024-46744</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-46744</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;Squashfs: sanity check symbolic link size&lt;/p&gt;
&lt;p&gt;Syzkiller reports a &amp;#34;KMSAN: uninit-value in pick_link&amp;#34; bug.&lt;/p&gt;
&lt;p&gt;This is caused by an uninitialised page, which is ultimately caused
by a corrupted symbolic link size read from disk.&lt;/p&gt;
&lt;p&gt;The reason why the corrupted symlink size causes an uninitialised
page is due to the following sequence of events:&lt;/p&gt;
&lt;p&gt;1. squashfs_read_inode() is called to read the symbolic
   link from disk.  This assigns the corrupted value
   3875536935 to inode-&amp;gt;i_size.&lt;/p&gt;
&lt;p&gt;2. Later squashfs_symlink_read_folio() is called, which assigns
   this corrupted value to the length variable, which being a
   signed int, overflows producing a negative number.&lt;/p&gt;
&lt;p&gt;3. The following loop that fills in the page contents checks that
   the copied bytes is less than length, which being negative means
   the loop is skipped, producing an uninitialised page.&lt;/p&gt;
&lt;p&gt;This patch adds a sanity check which checks that the symbolic
link size is not larger than expected.&lt;/p&gt;
&lt;p&gt;--&lt;/p&gt;
&lt;p&gt;V2: fix spelling mistake.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;Squashfs: sanity check symbolic link size&lt;/p&gt;
&lt;p&gt;Syzkiller reports a &amp;#34;KMSAN: uninit-value in pick_link&amp;#34; bug.&lt;/p&gt;
&lt;p&gt;This is caused by an uninitialised page, which is ultimately caused
by a corrupted symbolic link size read from disk.&lt;/p&gt;
&lt;p&gt;The reason why the corrupted symlink size causes an uninitialised
page is due to the following sequence of events:&lt;/p&gt;
&lt;p&gt;1. squashfs_read_inode() is called to read the symbolic
   link from disk.  This assigns the corrupted value
   3875536935 to inode-&amp;gt;i_size.&lt;/p&gt;
&lt;p&gt;2. Later squashfs_symlink_read_folio() is called, which assigns
   this corrupted value to the length variable, which being a
   signed int, overflows producing a negative number.&lt;/p&gt;
&lt;p&gt;3. The following loop that fills in the page contents checks that
   the copied bytes is less than length, which being negative means
   the loop is skipped, producing an uninitialised page.&lt;/p&gt;
&lt;p&gt;This patch adds a sanity check which checks that the symbolic
link size is not larger than expected.&lt;/p&gt;
&lt;p&gt;--&lt;/p&gt;
&lt;p&gt;V2: fix spelling mistake.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-46744</guid>
    </item>
    <item>
      <title>GHSA-fxvq-h88x-3jfr</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-fxvq-h88x-3jfr</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;Squashfs: sanity check symbolic link size&lt;/p&gt;
&lt;p&gt;Syzkiller reports a &amp;#34;KMSAN: uninit-value in pick_link&amp;#34; bug.&lt;/p&gt;
&lt;p&gt;This is caused by an uninitialised page, which is ultimately caused
by a corrupted symbolic link size read from disk.&lt;/p&gt;
&lt;p&gt;The reason why the corrupted symlink size causes an uninitialised
page is due to the following sequence of events:&lt;/p&gt;
&lt;p&gt;1. squashfs_read_inode() is called to read the symbolic
   link from disk.  This assigns the corrupted value
   3875536935 to inode-&amp;gt;i_size.&lt;/p&gt;
&lt;p&gt;2. Later squashfs_symlink_read_folio() is called, which assigns
   this corrupted value to the length variable, which being a
   signed int, overflows producing a negative number.&lt;/p&gt;
&lt;p&gt;3. The following loop that fills in the page contents checks that
   the copied bytes is less than length, which being negative means
   the loop is skipped, producing an uninitialised page.&lt;/p&gt;
&lt;p&gt;This patch adds a sanity check which checks that the symbolic
link size is not larger than expected.&lt;/p&gt;
&lt;p&gt;--&lt;/p&gt;
&lt;p&gt;V2: fix spelling mistake.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;Squashfs: sanity check symbolic link size&lt;/p&gt;
&lt;p&gt;Syzkiller reports a &amp;#34;KMSAN: uninit-value in pick_link&amp;#34; bug.&lt;/p&gt;
&lt;p&gt;This is caused by an uninitialised page, which is ultimately caused
by a corrupted symbolic link size read from disk.&lt;/p&gt;
&lt;p&gt;The reason why the corrupted symlink size causes an uninitialised
page is due to the following sequence of events:&lt;/p&gt;
&lt;p&gt;1. squashfs_read_inode() is called to read the symbolic
   link from disk.  This assigns the corrupted value
   3875536935 to inode-&amp;gt;i_size.&lt;/p&gt;
&lt;p&gt;2. Later squashfs_symlink_read_folio() is called, which assigns
   this corrupted value to the length variable, which being a
   signed int, overflows producing a negative number.&lt;/p&gt;
&lt;p&gt;3. The following loop that fills in the page contents checks that
   the copied bytes is less than length, which being negative means
   the loop is skipped, producing an uninitialised page.&lt;/p&gt;
&lt;p&gt;This patch adds a sanity check which checks that the symbolic
link size is not larger than expected.&lt;/p&gt;
&lt;p&gt;--&lt;/p&gt;
&lt;p&gt;V2: fix spelling mistake.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-fxvq-h88x-3jfr</guid>
    </item>
    <item>
      <title>ICSA-24-102-01 — Siemens SIMATIC S7-1500 TM MFP</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-24-102-01</link>
      <description>&lt;p&gt;An out-of-bounds (OOB) memory write flaw was found in the NFSD in the Linux kernel. Missing sanity may lead to a write beyond bmval[bmlen-1] in nfsd4_decode_bitmap4 in fs/nfsd/nfs4xdr.c. In this flaw, a local attacker with user privilege may gain access to out-of-bounds memory, leading to a system integrity and confidentiality threat. fs/nfsd/trace.h in the Linux kernel before 5.13.4 might allow remote attackers to cause a denial of service (out-of-bounds read in strlen) by sending NFS traffic when the trace event framework is being used for nfsd. SUNRPC: null pointer dereference in svc_rqst_free(). When alloc_pages_node() returns null in svc_rqst_alloc(), the null rq_scratch_page pointer will be dereferenced when calling put_page() in svc_rqst_free(). NFSD: READDIR buffer overflow. If a client sends a READDIR count argument that is too small (say, zero), then the buffer size calculation in the new init_dirlist helper functions results in an underflow, allowing the XDR stream functions to write beyond the actual buffer. This calculation has always been suspect. NFSD has never sanity- checked the READDIR count argument, but the old entry encoders managed the problem correctly. With the commits below, entry encoding changed, exposing the underflow to the pointer arithmetic in xdr_reserve_space(). Modern NFS clients attempt to retrieve as much data as possible for each READDIR request. nfsd: NULL dereference in nfs3svc_encode_getaclres. A NULL pointer dereference vulnerability…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An out-of-bounds (OOB) memory write flaw was found in the NFSD in the Linux kernel. Missing sanity may lead to a write beyond bmval[bmlen-1] in nfsd4_decode_bitmap4 in fs/nfsd/nfs4xdr.c. In this flaw, a local attacker with user privilege may gain access to out-of-bounds memory, leading to a system integrity and confidentiality threat. fs/nfsd/trace.h in the Linux kernel before 5.13.4 might allow remote attackers to cause a denial of service (out-of-bounds read in strlen) by sending NFS traffic when the trace event framework is being used for nfsd. SUNRPC: null pointer dereference in svc_rqst_free(). When alloc_pages_node() returns null in svc_rqst_alloc(), the null rq_scratch_page pointer will be dereferenced when calling put_page() in svc_rqst_free(). NFSD: READDIR buffer overflow. If a client sends a READDIR count argument that is too small (say, zero), then the buffer size calculation in the new init_dirlist helper functions results in an underflow, allowing the XDR stream functions to write beyond the actual buffer. This calculation has always been suspect. NFSD has never sanity- checked the READDIR count argument, but the old entry encoders managed the problem correctly. With the commits below, entry encoding changed, exposing the underflow to the pointer arithmetic in xdr_reserve_space(). Modern NFS clients attempt to retrieve as much data as possible for each READDIR request. nfsd: NULL dereference in nfs3svc_encode_getaclres. A NULL pointer dereference vulnerability…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-24-102-01</guid>
    </item>
    <item>
      <title>msrc_CVE-2024-46744 — Squashfs: sanity check symbolic link size</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2024-46744</link>
      <description>msrc_CVE-2024-46744</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2024-46744</guid>
    </item>
    <item>
      <title>OESA-2024-2181 — kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2024-2181</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&#13;
&#13;
In the Linux kernel, the following vulnerability has been resolved:&#13;
&#13;
tcp: Use refcount_inc_not_zero() in tcp_twsk_unique().&#13;
&#13;
Anderson Nascimento reported a use-after-free splat in tcp_twsk_unique()
with nice analysis.&#13;
&#13;
Since commit ec94c2696f0b (&amp;amp;quot;tcp/dccp: avoid one atomic operation for
timewait hashdance&amp;amp;quot;), inet_twsk_hashdance() sets TIME-WAIT socket&amp;amp;apos;s
sk_refcnt after putting it into ehash and releasing the bucket lock.&#13;
&#13;
Thus, there is a small race window where other threads could try to
reuse the port during connect() and call sock_hold() in tcp_twsk_unique()
for the TIME-WAIT socket with zero refcnt.&#13;
&#13;
If that happens, the refcnt taken by tcp_twsk_unique() is overwritten
and sock_put() will cause underflow, triggering a real use-after-free
somewhere else.&#13;
&#13;
To avoid the use-after-free, we need to use refcount_inc_not_zero() in
tcp_twsk_unique() and give up on reusing the port if it returns false.&#13;
&#13;
[0]:
refcount_t: addition on 0; use-after-free.
WARNING: CPU: 0 PID: 1039313 at lib/refcount.c:25 refcount_warn_saturate+0xe5/0x110
CPU: 0 PID: 1039313 Comm: trigger Not tainted 6.8.6-200.fc39.x86_64 #1
Hardware name: VMware, Inc. VMware20,1/440BX Desktop Reference Platform, BIOS VMW201.00V.21805430.B64.2305221830 05/22/2023
RIP: 0010:refcount_warn_saturate+0xe5/0x110
Code: 42 8e ff 0f 0b c3 cc cc cc cc 80 3d aa 13 ea 01 00 0f 85 5e ff ff ff 48 c7 c7 f8 8e b7 82 c6 05 96 13 ea…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&#13;
&#13;
In the Linux kernel, the following vulnerability has been resolved:&#13;
&#13;
tcp: Use refcount_inc_not_zero() in tcp_twsk_unique().&#13;
&#13;
Anderson Nascimento reported a use-after-free splat in tcp_twsk_unique()
with nice analysis.&#13;
&#13;
Since commit ec94c2696f0b (&amp;amp;quot;tcp/dccp: avoid one atomic operation for
timewait hashdance&amp;amp;quot;), inet_twsk_hashdance() sets TIME-WAIT socket&amp;amp;apos;s
sk_refcnt after putting it into ehash and releasing the bucket lock.&#13;
&#13;
Thus, there is a small race window where other threads could try to
reuse the port during connect() and call sock_hold() in tcp_twsk_unique()
for the TIME-WAIT socket with zero refcnt.&#13;
&#13;
If that happens, the refcnt taken by tcp_twsk_unique() is overwritten
and sock_put() will cause underflow, triggering a real use-after-free
somewhere else.&#13;
&#13;
To avoid the use-after-free, we need to use refcount_inc_not_zero() in
tcp_twsk_unique() and give up on reusing the port if it returns false.&#13;
&#13;
[0]:
refcount_t: addition on 0; use-after-free.
WARNING: CPU: 0 PID: 1039313 at lib/refcount.c:25 refcount_warn_saturate+0xe5/0x110
CPU: 0 PID: 1039313 Comm: trigger Not tainted 6.8.6-200.fc39.x86_64 #1
Hardware name: VMware, Inc. VMware20,1/440BX Desktop Reference Platform, BIOS VMW201.00V.21805430.B64.2305221830 05/22/2023
RIP: 0010:refcount_warn_saturate+0xe5/0x110
Code: 42 8e ff 0f 0b c3 cc cc cc cc 80 3d aa 13 ea 01 00 0f 85 5e ff ff ff 48 c7 c7 f8 8e b7 82 c6 05 96 13 ea…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2024-2181</guid>
    </item>
    <item>
      <title>RHSA-2025:20518 — Red Hat Security Advisory: kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2025:20518</link>
      <description>&lt;p&gt;kernel: can: isotp: fix potential CAN frame reception race in isotp_rcv() kernel: can: m_can: pci: add missing m_can_class_free_dev() in probe/remove methods kernel: can: isotp: sanitize CAN ID checks in isotp_bind() kernel: powerpc/papr_scm: don&amp;#39;t requests stats with &amp;#39;0&amp;#39; sized stats buffer kernel: efi: Do not import certificates from UEFI Secure Boot for T2 Macs kernel: powerpc/xics: fix refcount leak in icp_opal_init() kernel: powerpc/xive: Fix refcount leak in xive_spapr_init kernel: list: fix a data-race around ep-&amp;gt;rdllist kernel: powerpc/xive/spapr: correct bitmap allocation size kernel: ima: Fix potential memory leak in ima_init_crypto() kernel: ima: Fix a potential integer overflow in ima_appraise_measurement kernel: tracing/histograms: Fix memory leak problem kernel: usbnet: fix memory leak in error case kernel: linux/dim: Fix divide by 0 in RDMA DIM kernel: net: tun: unlink NAPI from device on destruction kernel: can: j1939: j1939_send_one(): fix missing CAN header initialization kernel: intel_th: Fix a resource leak in an error handling path kernel: powerpc/rtas: avoid scheduling in rtas_os_term() kernel: can: isotp: split tx timer into transmission and timeout kernel: Linux kernel: Denial of Service in xsk_diag due to use-after-free during socket cleanup kernel: smc: Fix use-after-free in tcp_write_timer_handler() kernel: inotify: Avoid reporting event with invalid wd kernel: Linux kernel (CAN J1939): Denial of Service via deadlock kernel: net/smc: fix potential p…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;kernel: can: isotp: fix potential CAN frame reception race in isotp_rcv() kernel: can: m_can: pci: add missing m_can_class_free_dev() in probe/remove methods kernel: can: isotp: sanitize CAN ID checks in isotp_bind() kernel: powerpc/papr_scm: don&amp;#39;t requests stats with &amp;#39;0&amp;#39; sized stats buffer kernel: efi: Do not import certificates from UEFI Secure Boot for T2 Macs kernel: powerpc/xics: fix refcount leak in icp_opal_init() kernel: powerpc/xive: Fix refcount leak in xive_spapr_init kernel: list: fix a data-race around ep-&amp;gt;rdllist kernel: powerpc/xive/spapr: correct bitmap allocation size kernel: ima: Fix potential memory leak in ima_init_crypto() kernel: ima: Fix a potential integer overflow in ima_appraise_measurement kernel: tracing/histograms: Fix memory leak problem kernel: usbnet: fix memory leak in error case kernel: linux/dim: Fix divide by 0 in RDMA DIM kernel: net: tun: unlink NAPI from device on destruction kernel: can: j1939: j1939_send_one(): fix missing CAN header initialization kernel: intel_th: Fix a resource leak in an error handling path kernel: powerpc/rtas: avoid scheduling in rtas_os_term() kernel: can: isotp: split tx timer into transmission and timeout kernel: Linux kernel: Denial of Service in xsk_diag due to use-after-free during socket cleanup kernel: smc: Fix use-after-free in tcp_write_timer_handler() kernel: inotify: Avoid reporting event with invalid wd kernel: Linux kernel (CAN J1939): Denial of Service via deadlock kernel: net/smc: fix potential p…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2025:20518</guid>
    </item>
    <item>
      <title>RHSA-2026:62568 — Red Hat Security Advisory: kernel security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:62568</link>
      <description>&lt;p&gt;kernel: Squashfs: sanity check symbolic link size kernel: ksm: use range-walk function to jump over holes in scan_get_next_rmap_item kernel: Bluetooth: SCO: fix race conditions in sco_sock_connect() kernel: netfilter: nft_set_pipapo_avx2: don&amp;#39;t return non-matching entry on expiry kernel: Bluetooth: hci_event: fix potential UAF in SSP passkey handlers kernel: net: ipv6: fix NOREF dst use in seg6 and rpl lwtunnels kernel: RDMA/mana: Validate rx_hash_key_len kernel: ipv6: fix possible UAF in icmpv6_rcv() kernel: ipv4: free net-&amp;gt;ipv4.sysctl_local_reserved_ports after unregister_net_sysctl_table() kernel: crypto: qat - validate RSA CRT component lengths kernel: net: bridge: stop fast-leave after deleting a port group kernel: vhost: reset the vring metadata cache on vring reconfiguration&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;kernel: Squashfs: sanity check symbolic link size kernel: ksm: use range-walk function to jump over holes in scan_get_next_rmap_item kernel: Bluetooth: SCO: fix race conditions in sco_sock_connect() kernel: netfilter: nft_set_pipapo_avx2: don&amp;#39;t return non-matching entry on expiry kernel: Bluetooth: hci_event: fix potential UAF in SSP passkey handlers kernel: net: ipv6: fix NOREF dst use in seg6 and rpl lwtunnels kernel: RDMA/mana: Validate rx_hash_key_len kernel: ipv6: fix possible UAF in icmpv6_rcv() kernel: ipv4: free net-&amp;gt;ipv4.sysctl_local_reserved_ports after unregister_net_sysctl_table() kernel: crypto: qat - validate RSA CRT component lengths kernel: net: bridge: stop fast-leave after deleting a port group kernel: vhost: reset the vring metadata cache on vring reconfiguration&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:62568</guid>
    </item>
    <item>
      <title>SSA-265688 — SSA-265688: Vulnerabilities in the additional GNU/Linux subsystem of the SIMATIC S7-1500 TM MFP V1.1</title>
      <link>https://cve.radiocsirt.org/vuln/ssa-265688</link>
      <description>&lt;p&gt;An out-of-bounds (OOB) memory write flaw was found in the NFSD in the Linux kernel. Missing sanity may lead to a write beyond bmval[bmlen-1] in nfsd4_decode_bitmap4 in fs/nfsd/nfs4xdr.c. In this flaw, a local attacker with user privilege may gain access to out-of-bounds memory, leading to a system integrity and confidentiality threat. fs/nfsd/trace.h in the Linux kernel before 5.13.4 might allow remote attackers to cause a denial of service (out-of-bounds read in strlen) by sending NFS traffic when the trace event framework is being used for nfsd. SUNRPC: null pointer dereference in svc_rqst_free(). When alloc_pages_node() returns null in svc_rqst_alloc(), the null rq_scratch_page pointer will be dereferenced when calling put_page() in svc_rqst_free(). NFSD: READDIR buffer overflow. If a client sends a READDIR count argument that is too small (say, zero), then the buffer size calculation in the new init_dirlist helper functions results in an underflow, allowing the XDR stream functions to write beyond the actual buffer. This calculation has always been suspect. NFSD has never sanity- checked the READDIR count argument, but the old entry encoders managed the problem correctly. With the commits below, entry encoding changed, exposing the underflow to the pointer arithmetic in xdr_reserve_space(). Modern NFS clients attempt to retrieve as much data as possible for each READDIR request. nfsd: NULL dereference in nfs3svc_encode_getaclres. A NULL pointer dereference vulnerability…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An out-of-bounds (OOB) memory write flaw was found in the NFSD in the Linux kernel. Missing sanity may lead to a write beyond bmval[bmlen-1] in nfsd4_decode_bitmap4 in fs/nfsd/nfs4xdr.c. In this flaw, a local attacker with user privilege may gain access to out-of-bounds memory, leading to a system integrity and confidentiality threat. fs/nfsd/trace.h in the Linux kernel before 5.13.4 might allow remote attackers to cause a denial of service (out-of-bounds read in strlen) by sending NFS traffic when the trace event framework is being used for nfsd. SUNRPC: null pointer dereference in svc_rqst_free(). When alloc_pages_node() returns null in svc_rqst_alloc(), the null rq_scratch_page pointer will be dereferenced when calling put_page() in svc_rqst_free(). NFSD: READDIR buffer overflow. If a client sends a READDIR count argument that is too small (say, zero), then the buffer size calculation in the new init_dirlist helper functions results in an underflow, allowing the XDR stream functions to write beyond the actual buffer. This calculation has always been suspect. NFSD has never sanity- checked the READDIR count argument, but the old entry encoders managed the problem correctly. With the commits below, entry encoding changed, exposing the underflow to the pointer arithmetic in xdr_reserve_space(). Modern NFS clients attempt to retrieve as much data as possible for each READDIR request. nfsd: NULL dereference in nfs3svc_encode_getaclres. A NULL pointer dereference vulnerability…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ssa-265688</guid>
    </item>
    <item>
      <title>SUSE-SU-2024:3551-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2024:3551-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2024:3551-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2024-46744</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-46744</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux, Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe and 186 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: Squashfs: sanity check symbolic link size Syzkiller reports a &amp;#34;KMSAN: uninit-value in pick_link&amp;#34; bug. This is caused by an uninitialised page, which is ultimately caused by a corrupted symbolic link size read from disk. The reason why the corrupted symlink size causes an uninitialised page is due to the following sequence of events: 1. squashfs_read_inode() is called to read the symbolic    link from disk.  This assigns the corrupted value    3875536935 to inode-&amp;gt;i_size. 2. Later squashfs_symlink_read_folio() is called, which assigns    this corrupted value to the length variable, which being a    signed int, overflows producing a negative number. 3. The following loop that fills in the page contents checks that    the copied bytes is less than length, which being negative means    the loop is skipped, producing an uninitialised page. This patch adds a sanity check which checks that the symbolic link size is not larger than expected. -- V2: fix spelling mistake.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux, Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe and 186 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: Squashfs: sanity check symbolic link size Syzkiller reports a &amp;#34;KMSAN: uninit-value in pick_link&amp;#34; bug. This is caused by an uninitialised page, which is ultimately caused by a corrupted symbolic link size read from disk. The reason why the corrupted symlink size causes an uninitialised page is due to the following sequence of events: 1. squashfs_read_inode() is called to read the symbolic    link from disk.  This assigns the corrupted value    3875536935 to inode-&amp;gt;i_size. 2. Later squashfs_symlink_read_folio() is called, which assigns    this corrupted value to the length variable, which being a    signed int, overflows producing a negative number. 3. The following loop that fills in the page contents checks that    the copied bytes is less than length, which being negative means    the loop is skipped, producing an uninitialised page. This patch adds a sanity check which checks that the symbolic link size is not larger than expected. -- V2: fix spelling mistake.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-46744</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-2173 — Linux Kernel: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-2173</link>
      <description>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen oder einen unspezifischen Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen oder einen unspezifischen Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-2173</guid>
    </item>
  </channel>
</rss>
