<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 20:13:23 +0000</lastBuildDate>
    <item>
      <title>bdu:2024-08072</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2024-08072</link>
      <description>bdu:2024-08072</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2024-08072</guid>
    </item>
    <item>
      <title>BELL-CVE-2024-46794</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2024-46794</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2024-46794</guid>
    </item>
    <item>
      <title>certfr-2024-avi-0837 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de Debian. Elles permettent à un attaquant de provo…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0837</link>
      <description>certfr-2024-avi-0837</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2024-avi-0837</guid>
    </item>
    <item>
      <title>EUVD-2026-313283</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-313283</link>
      <description>EUVD-2026-313283</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-313283</guid>
    </item>
    <item>
      <title>fkie_cve-2024-46794</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-46794</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;x86/tdx: Fix data leak in mmio_read()&lt;/p&gt;
&lt;p&gt;The mmio_read() function makes a TDVMCALL to retrieve MMIO data for an
address from the VMM.&lt;/p&gt;
&lt;p&gt;Sean noticed that mmio_read() unintentionally exposes the value of an
initialized variable (val) on the stack to the VMM.&lt;/p&gt;
&lt;p&gt;This variable is only needed as an output value. It did not need to be
passed to the VMM in the first place.&lt;/p&gt;
&lt;p&gt;Do not send the original value of *val to the VMM.&lt;/p&gt;
&lt;p&gt;[ dhansen: clarify what &amp;#39;val&amp;#39; is used for. ]&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;x86/tdx: Fix data leak in mmio_read()&lt;/p&gt;
&lt;p&gt;The mmio_read() function makes a TDVMCALL to retrieve MMIO data for an
address from the VMM.&lt;/p&gt;
&lt;p&gt;Sean noticed that mmio_read() unintentionally exposes the value of an
initialized variable (val) on the stack to the VMM.&lt;/p&gt;
&lt;p&gt;This variable is only needed as an output value. It did not need to be
passed to the VMM in the first place.&lt;/p&gt;
&lt;p&gt;Do not send the original value of *val to the VMM.&lt;/p&gt;
&lt;p&gt;[ dhansen: clarify what &amp;#39;val&amp;#39; is used for. ]&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-46794</guid>
    </item>
    <item>
      <title>GHSA-cx75-fvjc-vvr8</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-cx75-fvjc-vvr8</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;x86/tdx: Fix data leak in mmio_read()&lt;/p&gt;
&lt;p&gt;The mmio_read() function makes a TDVMCALL to retrieve MMIO data for an
address from the VMM.&lt;/p&gt;
&lt;p&gt;Sean noticed that mmio_read() unintentionally exposes the value of an
initialized variable (val) on the stack to the VMM.&lt;/p&gt;
&lt;p&gt;This variable is only needed as an output value. It did not need to be
passed to the VMM in the first place.&lt;/p&gt;
&lt;p&gt;Do not send the original value of *val to the VMM.&lt;/p&gt;
&lt;p&gt;[ dhansen: clarify what &amp;#39;val&amp;#39; is used for. ]&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;x86/tdx: Fix data leak in mmio_read()&lt;/p&gt;
&lt;p&gt;The mmio_read() function makes a TDVMCALL to retrieve MMIO data for an
address from the VMM.&lt;/p&gt;
&lt;p&gt;Sean noticed that mmio_read() unintentionally exposes the value of an
initialized variable (val) on the stack to the VMM.&lt;/p&gt;
&lt;p&gt;This variable is only needed as an output value. It did not need to be
passed to the VMM in the first place.&lt;/p&gt;
&lt;p&gt;Do not send the original value of *val to the VMM.&lt;/p&gt;
&lt;p&gt;[ dhansen: clarify what &amp;#39;val&amp;#39; is used for. ]&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-cx75-fvjc-vvr8</guid>
    </item>
    <item>
      <title>msrc_CVE-2024-46794 — x86/tdx: Fix data leak in mmio_read()</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2024-46794</link>
      <description>msrc_CVE-2024-46794</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2024-46794</guid>
    </item>
    <item>
      <title>OESA-2024-2423 — kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2024-2423</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&#13;
&#13;
In the Linux kernel, the following vulnerability has been resolved:&#13;
&#13;
usb: typec: ucsi: Fix null pointer dereference in trace&#13;
&#13;
ucsi_register_altmode checks IS_ERR for the alt pointer and treats
NULL as valid. When CONFIG_TYPEC_DP_ALTMODE is not enabled,
ucsi_register_displayport returns NULL which causes a NULL pointer
dereference in trace. Rather than return NULL, call
typec_port_register_altmode to register DisplayPort alternate mode
as a non-controllable mode when CONFIG_TYPEC_DP_ALTMODE is not enabled.(CVE-2024-46719)&#13;
&#13;
In the Linux kernel, the following vulnerability has been resolved:&#13;
&#13;
x86/tdx: Fix data leak in mmio_read()&#13;
&#13;
The mmio_read() function makes a TDVMCALL to retrieve MMIO data for an
address from the VMM.&#13;
&#13;
Sean noticed that mmio_read() unintentionally exposes the value of an
initialized variable (val) on the stack to the VMM.&#13;
&#13;
This variable is only needed as an output value. It did not need to be
passed to the VMM in the first place.&#13;
&#13;
Do not send the original value of *val to the VMM.&#13;
&#13;
[ dhansen: clarify what &amp;amp;apos;val&amp;amp;apos; is used for. ](CVE-2024-46794)&#13;
&#13;
In the Linux kernel, the following vulnerability has been resolved:&#13;
&#13;
drm/amdkfd: Check debug trap enable before write dbg_ev_file&#13;
&#13;
In interrupt context, write dbg_ev_file will be run by work queue. It
will cause write dbg_ev_file execution after debug_trap_disable, which
will cause NULL pointer access.
v2: canc…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&#13;
&#13;
In the Linux kernel, the following vulnerability has been resolved:&#13;
&#13;
usb: typec: ucsi: Fix null pointer dereference in trace&#13;
&#13;
ucsi_register_altmode checks IS_ERR for the alt pointer and treats
NULL as valid. When CONFIG_TYPEC_DP_ALTMODE is not enabled,
ucsi_register_displayport returns NULL which causes a NULL pointer
dereference in trace. Rather than return NULL, call
typec_port_register_altmode to register DisplayPort alternate mode
as a non-controllable mode when CONFIG_TYPEC_DP_ALTMODE is not enabled.(CVE-2024-46719)&#13;
&#13;
In the Linux kernel, the following vulnerability has been resolved:&#13;
&#13;
x86/tdx: Fix data leak in mmio_read()&#13;
&#13;
The mmio_read() function makes a TDVMCALL to retrieve MMIO data for an
address from the VMM.&#13;
&#13;
Sean noticed that mmio_read() unintentionally exposes the value of an
initialized variable (val) on the stack to the VMM.&#13;
&#13;
This variable is only needed as an output value. It did not need to be
passed to the VMM in the first place.&#13;
&#13;
Do not send the original value of *val to the VMM.&#13;
&#13;
[ dhansen: clarify what &amp;amp;apos;val&amp;amp;apos; is used for. ](CVE-2024-46794)&#13;
&#13;
In the Linux kernel, the following vulnerability has been resolved:&#13;
&#13;
drm/amdkfd: Check debug trap enable before write dbg_ev_file&#13;
&#13;
In interrupt context, write dbg_ev_file will be run by work queue. It
will cause write dbg_ev_file execution after debug_trap_disable, which
will cause NULL pointer access.
v2: canc…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2024-2423</guid>
    </item>
    <item>
      <title>SUSE-SU-2024:3551-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2024:3551-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2024:3551-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2024-46794</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-46794</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 89 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: x86/tdx: Fix data leak in mmio_read() The mmio_read() function makes a TDVMCALL to retrieve MMIO data for an address from the VMM. Sean noticed that mmio_read() unintentionally exposes the value of an initialized variable (val) on the stack to the VMM. This variable is only needed as an output value. It did not need to be passed to the VMM in the first place. Do not send the original value of *val to the VMM. [ dhansen: clarify what &amp;#39;val&amp;#39; is used for. ]&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 89 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: x86/tdx: Fix data leak in mmio_read() The mmio_read() function makes a TDVMCALL to retrieve MMIO data for an address from the VMM. Sean noticed that mmio_read() unintentionally exposes the value of an initialized variable (val) on the stack to the VMM. This variable is only needed as an output value. It did not need to be passed to the VMM in the first place. Do not send the original value of *val to the VMM. [ dhansen: clarify what &amp;#39;val&amp;#39; is used for. ]&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-46794</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-2173 — Linux Kernel: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-2173</link>
      <description>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen oder einen unspezifischen Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen oder einen unspezifischen Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-2173</guid>
    </item>
  </channel>
</rss>
