<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 21:15:55 +0000</lastBuildDate>
    <item>
      <title>bdu:2025-05879</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-05879</link>
      <description>bdu:2025-05879</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-05879</guid>
    </item>
    <item>
      <title>BELL-CVE-2024-46848</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2024-46848</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2024-46848</guid>
    </item>
    <item>
      <title>certfr-2024-avi-0837 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de Debian. Elles permettent à un attaquant de provo…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0837</link>
      <description>certfr-2024-avi-0837</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2024-avi-0837</guid>
    </item>
    <item>
      <title>EUVD-2026-313313</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-313313</link>
      <description>EUVD-2026-313313</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-313313</guid>
    </item>
    <item>
      <title>fkie_cve-2024-46848</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-46848</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;perf/x86/intel: Limit the period on Haswell&lt;/p&gt;
&lt;p&gt;Running the ltp test cve-2015-3290 concurrently reports the following
warnings.&lt;/p&gt;
&lt;p&gt;perfevents: irq loop stuck!
  WARNING: CPU: 31 PID: 32438 at arch/x86/events/intel/core.c:3174
  intel_pmu_handle_irq+0x285/0x370
  Call Trace:
   &amp;lt;NMI&amp;gt;
   ? __warn+0xa4/0x220
   ? intel_pmu_handle_irq+0x285/0x370
   ? __report_bug+0x123/0x130
   ? intel_pmu_handle_irq+0x285/0x370
   ? __report_bug+0x123/0x130
   ? intel_pmu_handle_irq+0x285/0x370
   ? report_bug+0x3e/0xa0
   ? handle_bug+0x3c/0x70
   ? exc_invalid_op+0x18/0x50
   ? asm_exc_invalid_op+0x1a/0x20
   ? irq_work_claim+0x1e/0x40
   ? intel_pmu_handle_irq+0x285/0x370
   perf_event_nmi_handler+0x3d/0x60
   nmi_handle+0x104/0x330&lt;/p&gt;
&lt;p&gt;Thanks to Thomas Gleixner&amp;#39;s analysis, the issue is caused by the low
initial period (1) of the frequency estimation algorithm, which triggers
the defects of the HW, specifically erratum HSW11 and HSW143. (For the
details, please refer https://lore.kernel.org/lkml/87plq9l5d2.ffs@tglx/)&lt;/p&gt;
&lt;p&gt;The HSW11 requires a period larger than 100 for the INST_RETIRED.ALL
event, but the initial period in the freq mode is 1. The erratum is the
same as the BDM11, which has been supported in the kernel. A minimum
period of 128 is enforced as well on HSW.&lt;/p&gt;
&lt;p&gt;HSW143 is regarding that the fixed counter 1 may overcount 32 with the
Hyper-Threading is enabled. However, based on the test, the hardware
has more issues than it tel…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;perf/x86/intel: Limit the period on Haswell&lt;/p&gt;
&lt;p&gt;Running the ltp test cve-2015-3290 concurrently reports the following
warnings.&lt;/p&gt;
&lt;p&gt;perfevents: irq loop stuck!
  WARNING: CPU: 31 PID: 32438 at arch/x86/events/intel/core.c:3174
  intel_pmu_handle_irq+0x285/0x370
  Call Trace:
   &amp;lt;NMI&amp;gt;
   ? __warn+0xa4/0x220
   ? intel_pmu_handle_irq+0x285/0x370
   ? __report_bug+0x123/0x130
   ? intel_pmu_handle_irq+0x285/0x370
   ? __report_bug+0x123/0x130
   ? intel_pmu_handle_irq+0x285/0x370
   ? report_bug+0x3e/0xa0
   ? handle_bug+0x3c/0x70
   ? exc_invalid_op+0x18/0x50
   ? asm_exc_invalid_op+0x1a/0x20
   ? irq_work_claim+0x1e/0x40
   ? intel_pmu_handle_irq+0x285/0x370
   perf_event_nmi_handler+0x3d/0x60
   nmi_handle+0x104/0x330&lt;/p&gt;
&lt;p&gt;Thanks to Thomas Gleixner&amp;#39;s analysis, the issue is caused by the low
initial period (1) of the frequency estimation algorithm, which triggers
the defects of the HW, specifically erratum HSW11 and HSW143. (For the
details, please refer https://lore.kernel.org/lkml/87plq9l5d2.ffs@tglx/)&lt;/p&gt;
&lt;p&gt;The HSW11 requires a period larger than 100 for the INST_RETIRED.ALL
event, but the initial period in the freq mode is 1. The erratum is the
same as the BDM11, which has been supported in the kernel. A minimum
period of 128 is enforced as well on HSW.&lt;/p&gt;
&lt;p&gt;HSW143 is regarding that the fixed counter 1 may overcount 32 with the
Hyper-Threading is enabled. However, based on the test, the hardware
has more issues than it tel…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-46848</guid>
    </item>
    <item>
      <title>GHSA-f8x4-897j-jj7g</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-f8x4-897j-jj7g</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;perf/x86/intel: Limit the period on Haswell&lt;/p&gt;
&lt;p&gt;Running the ltp test cve-2015-3290 concurrently reports the following
warnings.&lt;/p&gt;
&lt;p&gt;perfevents: irq loop stuck!
  WARNING: CPU: 31 PID: 32438 at arch/x86/events/intel/core.c:3174
  intel_pmu_handle_irq+0x285/0x370
  Call Trace:
   &amp;lt;NMI&amp;gt;
   ? __warn+0xa4/0x220
   ? intel_pmu_handle_irq+0x285/0x370
   ? __report_bug+0x123/0x130
   ? intel_pmu_handle_irq+0x285/0x370
   ? __report_bug+0x123/0x130
   ? intel_pmu_handle_irq+0x285/0x370
   ? report_bug+0x3e/0xa0
   ? handle_bug+0x3c/0x70
   ? exc_invalid_op+0x18/0x50
   ? asm_exc_invalid_op+0x1a/0x20
   ? irq_work_claim+0x1e/0x40
   ? intel_pmu_handle_irq+0x285/0x370
   perf_event_nmi_handler+0x3d/0x60
   nmi_handle+0x104/0x330&lt;/p&gt;
&lt;p&gt;Thanks to Thomas Gleixner&amp;#39;s analysis, the issue is caused by the low
initial period (1) of the frequency estimation algorithm, which triggers
the defects of the HW, specifically erratum HSW11 and HSW143. (For the
details, please refer https://lore.kernel.org/lkml/87plq9l5d2.ffs@tglx/)&lt;/p&gt;
&lt;p&gt;The HSW11 requires a period larger than 100 for the INST_RETIRED.ALL
event, but the initial period in the freq mode is 1. The erratum is the
same as the BDM11, which has been supported in the kernel. A minimum
period of 128 is enforced as well on HSW.&lt;/p&gt;
&lt;p&gt;HSW143 is regarding that the fixed counter 1 may overcount 32 with the
Hyper-Threading is enabled. However, based on the test, the hardware
has more issues than it tel…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;perf/x86/intel: Limit the period on Haswell&lt;/p&gt;
&lt;p&gt;Running the ltp test cve-2015-3290 concurrently reports the following
warnings.&lt;/p&gt;
&lt;p&gt;perfevents: irq loop stuck!
  WARNING: CPU: 31 PID: 32438 at arch/x86/events/intel/core.c:3174
  intel_pmu_handle_irq+0x285/0x370
  Call Trace:
   &amp;lt;NMI&amp;gt;
   ? __warn+0xa4/0x220
   ? intel_pmu_handle_irq+0x285/0x370
   ? __report_bug+0x123/0x130
   ? intel_pmu_handle_irq+0x285/0x370
   ? __report_bug+0x123/0x130
   ? intel_pmu_handle_irq+0x285/0x370
   ? report_bug+0x3e/0xa0
   ? handle_bug+0x3c/0x70
   ? exc_invalid_op+0x18/0x50
   ? asm_exc_invalid_op+0x1a/0x20
   ? irq_work_claim+0x1e/0x40
   ? intel_pmu_handle_irq+0x285/0x370
   perf_event_nmi_handler+0x3d/0x60
   nmi_handle+0x104/0x330&lt;/p&gt;
&lt;p&gt;Thanks to Thomas Gleixner&amp;#39;s analysis, the issue is caused by the low
initial period (1) of the frequency estimation algorithm, which triggers
the defects of the HW, specifically erratum HSW11 and HSW143. (For the
details, please refer https://lore.kernel.org/lkml/87plq9l5d2.ffs@tglx/)&lt;/p&gt;
&lt;p&gt;The HSW11 requires a period larger than 100 for the INST_RETIRED.ALL
event, but the initial period in the freq mode is 1. The erratum is the
same as the BDM11, which has been supported in the kernel. A minimum
period of 128 is enforced as well on HSW.&lt;/p&gt;
&lt;p&gt;HSW143 is regarding that the fixed counter 1 may overcount 32 with the
Hyper-Threading is enabled. However, based on the test, the hardware
has more issues than it tel…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-f8x4-897j-jj7g</guid>
    </item>
    <item>
      <title>msrc_CVE-2024-46848 — perf/x86/intel: Limit the period on Haswell</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2024-46848</link>
      <description>msrc_CVE-2024-46848</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2024-46848</guid>
    </item>
    <item>
      <title>OESA-2024-2255 — kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2024-2255</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP3: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&#13;
&#13;
In the Linux kernel, the following vulnerability has been resolved:&#13;
&#13;
drm/i915/gt: Cleanup partial engine discovery failures&#13;
&#13;
If we abort driver initialisation in the middle of gt/engine discovery,
some engines will be fully setup and some not. Those incompletely setup
engines only have &amp;amp;apos;engine-&amp;amp;gt;release == NULL&amp;amp;apos; and so will leak any of the
common objects allocated.&#13;
&#13;
v2:
 - Drop the destroy_pinned_context() helper for now.  It&amp;amp;apos;s not really
   worth it with just a single callsite at the moment.  (Janusz)(CVE-2022-48893)&#13;
&#13;
In the Linux kernel, the following vulnerability has been resolved:&#13;
&#13;
f2fs: fix to avoid dirent corruption&#13;
&#13;
As Al reported in link[1]:&#13;
&#13;
f2fs_rename()
...
	if (old_dir != new_dir &amp;amp;amp;&amp;amp;amp; !whiteout)
		f2fs_set_link(old_inode, old_dir_entry,
					old_dir_page, new_dir);
	else
		f2fs_put_page(old_dir_page, 0);&#13;
&#13;
You want correct inumber in the &amp;amp;quot;..&amp;amp;quot; link.  And cross-directory
rename does move the source to new parent, even if you&amp;amp;apos;d been asked
to leave a whiteout in the old place.&#13;
&#13;
[1] https://lore.kernel.org/all/20231017055040.GN800259@ZenIV/&#13;
&#13;
With below testcase, it may cause dirent corruption, due to it missed
to call f2fs_set_link() to update &amp;amp;quot;..&amp;amp;quot; link to new directory.
- mkdir -p dir/foo
- renameat2 -w dir/foo bar&#13;
&#13;
[ASSERT] (__chk_dots_dentries:1421)  --&amp;amp;gt; Bad inode number[0x4] for &amp;amp;apos;..&amp;amp;apos;, parent parent ino is [0…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP3: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&#13;
&#13;
In the Linux kernel, the following vulnerability has been resolved:&#13;
&#13;
drm/i915/gt: Cleanup partial engine discovery failures&#13;
&#13;
If we abort driver initialisation in the middle of gt/engine discovery,
some engines will be fully setup and some not. Those incompletely setup
engines only have &amp;amp;apos;engine-&amp;amp;gt;release == NULL&amp;amp;apos; and so will leak any of the
common objects allocated.&#13;
&#13;
v2:
 - Drop the destroy_pinned_context() helper for now.  It&amp;amp;apos;s not really
   worth it with just a single callsite at the moment.  (Janusz)(CVE-2022-48893)&#13;
&#13;
In the Linux kernel, the following vulnerability has been resolved:&#13;
&#13;
f2fs: fix to avoid dirent corruption&#13;
&#13;
As Al reported in link[1]:&#13;
&#13;
f2fs_rename()
...
	if (old_dir != new_dir &amp;amp;amp;&amp;amp;amp; !whiteout)
		f2fs_set_link(old_inode, old_dir_entry,
					old_dir_page, new_dir);
	else
		f2fs_put_page(old_dir_page, 0);&#13;
&#13;
You want correct inumber in the &amp;amp;quot;..&amp;amp;quot; link.  And cross-directory
rename does move the source to new parent, even if you&amp;amp;apos;d been asked
to leave a whiteout in the old place.&#13;
&#13;
[1] https://lore.kernel.org/all/20231017055040.GN800259@ZenIV/&#13;
&#13;
With below testcase, it may cause dirent corruption, due to it missed
to call f2fs_set_link() to update &amp;amp;quot;..&amp;amp;quot; link to new directory.
- mkdir -p dir/foo
- renameat2 -w dir/foo bar&#13;
&#13;
[ASSERT] (__chk_dots_dentries:1421)  --&amp;amp;gt; Bad inode number[0x4] for &amp;amp;apos;..&amp;amp;apos;, parent parent ino is [0…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2024-2255</guid>
    </item>
    <item>
      <title>SUSE-SU-2024:3983-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2024:3983-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2024:3983-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2024-46848</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-46848</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux, Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe and 188 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: perf/x86/intel: Limit the period on Haswell Running the ltp test cve-2015-3290 concurrently reports the following warnings. perfevents: irq loop stuck!   WARNING: CPU: 31 PID: 32438 at arch/x86/events/intel/core.c:3174   intel_pmu_handle_irq+0x285/0x370   Call Trace:    &amp;lt;NMI&amp;gt;    ? __warn+0xa4/0x220    ? intel_pmu_handle_irq+0x285/0x370    ? __report_bug+0x123/0x130    ? intel_pmu_handle_irq+0x285/0x370    ? __report_bug+0x123/0x130    ? intel_pmu_handle_irq+0x285/0x370    ? report_bug+0x3e/0xa0    ? handle_bug+0x3c/0x70    ? exc_invalid_op+0x18/0x50    ? asm_exc_invalid_op+0x1a/0x20    ? irq_work_claim+0x1e/0x40    ? intel_pmu_handle_irq+0x285/0x370    perf_event_nmi_handler+0x3d/0x60    nmi_handle+0x104/0x330 Thanks to Thomas Gleixner&amp;#39;s analysis, the issue is caused by the low initial period (1) of the frequency estimation algorithm, which triggers the defects of the HW, specifically erratum HSW11 and HSW143. (For the details, please refer https://lore.kernel.org/lkml/87plq9l5d2.ffs@tglx/) The HSW11 requires a period larger than 100 for the INST_RETIRED.ALL event, but the initial period in the freq mode is 1. The erratum is the same as the BDM11, which has been supported in the kernel. A minimum period of 128 is enforced as well on HSW. HSW143 is regarding that the fixed counter 1 may overcount 32 with the Hyper-Threading is enabled. However, based on the test, the hardware has more issues than it tells. Be…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux, Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe and 188 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: perf/x86/intel: Limit the period on Haswell Running the ltp test cve-2015-3290 concurrently reports the following warnings. perfevents: irq loop stuck!   WARNING: CPU: 31 PID: 32438 at arch/x86/events/intel/core.c:3174   intel_pmu_handle_irq+0x285/0x370   Call Trace:    &amp;lt;NMI&amp;gt;    ? __warn+0xa4/0x220    ? intel_pmu_handle_irq+0x285/0x370    ? __report_bug+0x123/0x130    ? intel_pmu_handle_irq+0x285/0x370    ? __report_bug+0x123/0x130    ? intel_pmu_handle_irq+0x285/0x370    ? report_bug+0x3e/0xa0    ? handle_bug+0x3c/0x70    ? exc_invalid_op+0x18/0x50    ? asm_exc_invalid_op+0x1a/0x20    ? irq_work_claim+0x1e/0x40    ? intel_pmu_handle_irq+0x285/0x370    perf_event_nmi_handler+0x3d/0x60    nmi_handle+0x104/0x330 Thanks to Thomas Gleixner&amp;#39;s analysis, the issue is caused by the low initial period (1) of the frequency estimation algorithm, which triggers the defects of the HW, specifically erratum HSW11 and HSW143. (For the details, please refer https://lore.kernel.org/lkml/87plq9l5d2.ffs@tglx/) The HSW11 requires a period larger than 100 for the INST_RETIRED.ALL event, but the initial period in the freq mode is 1. The erratum is the same as the BDM11, which has been supported in the kernel. A minimum period of 128 is enforced as well on HSW. HSW143 is regarding that the fixed counter 1 may overcount 32 with the Hyper-Threading is enabled. However, based on the test, the hardware has more issues than it tells. Be…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-46848</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-3050 — Linux Kernel: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-3050</link>
      <description>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen in Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen und andere nicht spezifizierte Auswirkungen zu verursachen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen in Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen und andere nicht spezifizierte Auswirkungen zu verursachen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-3050</guid>
    </item>
  </channel>
</rss>
