<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 21:39:41 +0000</lastBuildDate>
    <item>
      <title>bdu:2025-03125</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-03125</link>
      <description>bdu:2025-03125</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-03125</guid>
    </item>
    <item>
      <title>BELL-CVE-2024-49878</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2024-49878</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2024-49878</guid>
    </item>
    <item>
      <title>certfr-2024-avi-0999 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de SUSE. Certaines d'entre elles permettent à un at…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0999</link>
      <description>certfr-2024-avi-0999</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2024-avi-0999</guid>
    </item>
    <item>
      <title>EUVD-2026-313382</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-313382</link>
      <description>EUVD-2026-313382</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-313382</guid>
    </item>
    <item>
      <title>fkie_cve-2024-49878</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-49878</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;resource: fix region_intersects() vs add_memory_driver_managed()&lt;/p&gt;
&lt;p&gt;On a system with CXL memory, the resource tree (/proc/iomem) related to
CXL memory may look like something as follows.&lt;/p&gt;
&lt;p&gt;490000000-50fffffff : CXL Window 0
  490000000-50fffffff : region0
    490000000-50fffffff : dax0.0
      490000000-50fffffff : System RAM (kmem)&lt;/p&gt;
&lt;p&gt;Because drivers/dax/kmem.c calls add_memory_driver_managed() during
onlining CXL memory, which makes &amp;#34;System RAM (kmem)&amp;#34; a descendant of &amp;#34;CXL
Window X&amp;#34;.  This confuses region_intersects(), which expects all &amp;#34;System
RAM&amp;#34; resources to be at the top level of iomem_resource.  This can lead to
bugs.&lt;/p&gt;
&lt;p&gt;For example, when the following command line is executed to write some
memory in CXL memory range via /dev/mem,&lt;/p&gt;
&lt;p&gt;$ dd if=data of=/dev/mem bs=$((1 &amp;lt;&amp;lt; 10)) seek=$((0x490000000 &amp;gt;&amp;gt; 10)) count=1
 dd: error writing &amp;#39;/dev/mem&amp;#39;: Bad address
 1+0 records in
 0+0 records out
 0 bytes copied, 0.0283507 s, 0.0 kB/s&lt;/p&gt;
&lt;p&gt;the command fails as expected.  However, the error code is wrong.  It
should be &amp;#34;Operation not permitted&amp;#34; instead of &amp;#34;Bad address&amp;#34;.  More
seriously, the /dev/mem permission checking in devmem_is_allowed() passes
incorrectly.  Although the accessing is prevented later because ioremap()
isn&amp;#39;t allowed to map system RAM, it is a potential security issue.  During
command executing, the following warning is reported in the kernel log for
calling ioremap() on system RAM.&lt;/p&gt;
&lt;p&gt;ioremap on RAM at 0x00…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;resource: fix region_intersects() vs add_memory_driver_managed()&lt;/p&gt;
&lt;p&gt;On a system with CXL memory, the resource tree (/proc/iomem) related to
CXL memory may look like something as follows.&lt;/p&gt;
&lt;p&gt;490000000-50fffffff : CXL Window 0
  490000000-50fffffff : region0
    490000000-50fffffff : dax0.0
      490000000-50fffffff : System RAM (kmem)&lt;/p&gt;
&lt;p&gt;Because drivers/dax/kmem.c calls add_memory_driver_managed() during
onlining CXL memory, which makes &amp;#34;System RAM (kmem)&amp;#34; a descendant of &amp;#34;CXL
Window X&amp;#34;.  This confuses region_intersects(), which expects all &amp;#34;System
RAM&amp;#34; resources to be at the top level of iomem_resource.  This can lead to
bugs.&lt;/p&gt;
&lt;p&gt;For example, when the following command line is executed to write some
memory in CXL memory range via /dev/mem,&lt;/p&gt;
&lt;p&gt;$ dd if=data of=/dev/mem bs=$((1 &amp;lt;&amp;lt; 10)) seek=$((0x490000000 &amp;gt;&amp;gt; 10)) count=1
 dd: error writing &amp;#39;/dev/mem&amp;#39;: Bad address
 1+0 records in
 0+0 records out
 0 bytes copied, 0.0283507 s, 0.0 kB/s&lt;/p&gt;
&lt;p&gt;the command fails as expected.  However, the error code is wrong.  It
should be &amp;#34;Operation not permitted&amp;#34; instead of &amp;#34;Bad address&amp;#34;.  More
seriously, the /dev/mem permission checking in devmem_is_allowed() passes
incorrectly.  Although the accessing is prevented later because ioremap()
isn&amp;#39;t allowed to map system RAM, it is a potential security issue.  During
command executing, the following warning is reported in the kernel log for
calling ioremap() on system RAM.&lt;/p&gt;
&lt;p&gt;ioremap on RAM at 0x00…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-49878</guid>
    </item>
    <item>
      <title>GHSA-f3xx-63r9-v2cp</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-f3xx-63r9-v2cp</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;resource: fix region_intersects() vs add_memory_driver_managed()&lt;/p&gt;
&lt;p&gt;On a system with CXL memory, the resource tree (/proc/iomem) related to
CXL memory may look like something as follows.&lt;/p&gt;
&lt;p&gt;490000000-50fffffff : CXL Window 0
  490000000-50fffffff : region0
    490000000-50fffffff : dax0.0
      490000000-50fffffff : System RAM (kmem)&lt;/p&gt;
&lt;p&gt;Because drivers/dax/kmem.c calls add_memory_driver_managed() during
onlining CXL memory, which makes &amp;#34;System RAM (kmem)&amp;#34; a descendant of &amp;#34;CXL
Window X&amp;#34;.  This confuses region_intersects(), which expects all &amp;#34;System
RAM&amp;#34; resources to be at the top level of iomem_resource.  This can lead to
bugs.&lt;/p&gt;
&lt;p&gt;For example, when the following command line is executed to write some
memory in CXL memory range via /dev/mem,&lt;/p&gt;
&lt;p&gt;$ dd if=data of=/dev/mem bs=$((1 &amp;lt;&amp;lt; 10)) seek=$((0x490000000 &amp;gt;&amp;gt; 10)) count=1
 dd: error writing &amp;#39;/dev/mem&amp;#39;: Bad address
 1+0 records in
 0+0 records out
 0 bytes copied, 0.0283507 s, 0.0 kB/s&lt;/p&gt;
&lt;p&gt;the command fails as expected.  However, the error code is wrong.  It
should be &amp;#34;Operation not permitted&amp;#34; instead of &amp;#34;Bad address&amp;#34;.  More
seriously, the /dev/mem permission checking in devmem_is_allowed() passes
incorrectly.  Although the accessing is prevented later because ioremap()
isn&amp;#39;t allowed to map system RAM, it is a potential security issue.  During
command executing, the following warning is reported in the kernel log for
calling ioremap() on system RAM.&lt;/p&gt;
&lt;p&gt;ioremap on RAM at 0x00…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;resource: fix region_intersects() vs add_memory_driver_managed()&lt;/p&gt;
&lt;p&gt;On a system with CXL memory, the resource tree (/proc/iomem) related to
CXL memory may look like something as follows.&lt;/p&gt;
&lt;p&gt;490000000-50fffffff : CXL Window 0
  490000000-50fffffff : region0
    490000000-50fffffff : dax0.0
      490000000-50fffffff : System RAM (kmem)&lt;/p&gt;
&lt;p&gt;Because drivers/dax/kmem.c calls add_memory_driver_managed() during
onlining CXL memory, which makes &amp;#34;System RAM (kmem)&amp;#34; a descendant of &amp;#34;CXL
Window X&amp;#34;.  This confuses region_intersects(), which expects all &amp;#34;System
RAM&amp;#34; resources to be at the top level of iomem_resource.  This can lead to
bugs.&lt;/p&gt;
&lt;p&gt;For example, when the following command line is executed to write some
memory in CXL memory range via /dev/mem,&lt;/p&gt;
&lt;p&gt;$ dd if=data of=/dev/mem bs=$((1 &amp;lt;&amp;lt; 10)) seek=$((0x490000000 &amp;gt;&amp;gt; 10)) count=1
 dd: error writing &amp;#39;/dev/mem&amp;#39;: Bad address
 1+0 records in
 0+0 records out
 0 bytes copied, 0.0283507 s, 0.0 kB/s&lt;/p&gt;
&lt;p&gt;the command fails as expected.  However, the error code is wrong.  It
should be &amp;#34;Operation not permitted&amp;#34; instead of &amp;#34;Bad address&amp;#34;.  More
seriously, the /dev/mem permission checking in devmem_is_allowed() passes
incorrectly.  Although the accessing is prevented later because ioremap()
isn&amp;#39;t allowed to map system RAM, it is a potential security issue.  During
command executing, the following warning is reported in the kernel log for
calling ioremap() on system RAM.&lt;/p&gt;
&lt;p&gt;ioremap on RAM at 0x00…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-f3xx-63r9-v2cp</guid>
    </item>
    <item>
      <title>ICSA-25-226-07 — Siemens Third-Party Components in SINEC OS</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-25-226-07</link>
      <description>&lt;p&gt;nfsd: NULL dereference in nfs3svc_encode_getaclres. scsi: core: use-after-free vulnerability. NFSD: vulnerability caused by loff_t overflow on the server when a client reads near the maximum offset, causing the server to return an EINVAL error, which the client retries indefinitely, instead of handling out-of-range READ requests by returning a short result with an EOF flag. NFSD: Vulnerability caused by an underflow in ia_size due to a mismatch between signed and unsigned 64-bit file size values, which can cause issues when handling large file sizes from NFS clients. NFSD: Vulnerability handling large file sizes for NFSv3 improperly capping client size values larger than s64_max, leading to unexpected behavior and potential data corruption. sh: cpuinfo: warning for CONFIG_CPUMASK_OFFSTACK. When CONFIG_CPUMASK_OFFSTACK and CONFIG_DEBUG_PER_CPU_MAPS are selected, cpu_max_bits_warn() generates a runtime warning when showing /proc/cpuinfo. A failure in the -fstack-protector feature in GCC-based toolchains 
that target AArch64 allows an attacker to exploit an existing buffer 
overflow in dynamically-sized local variables in your application 
without this being detected. This stack-protector failure only applies 
to C99-style dynamically-sized local variables or those created using 
alloca(). The stack-protector operates as intended for statically-sized 
local variables.&lt;/p&gt;
&lt;p&gt;The default behavior when the stack-protector 
detects an overflow is to terminate your application, resulting…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;nfsd: NULL dereference in nfs3svc_encode_getaclres. scsi: core: use-after-free vulnerability. NFSD: vulnerability caused by loff_t overflow on the server when a client reads near the maximum offset, causing the server to return an EINVAL error, which the client retries indefinitely, instead of handling out-of-range READ requests by returning a short result with an EOF flag. NFSD: Vulnerability caused by an underflow in ia_size due to a mismatch between signed and unsigned 64-bit file size values, which can cause issues when handling large file sizes from NFS clients. NFSD: Vulnerability handling large file sizes for NFSv3 improperly capping client size values larger than s64_max, leading to unexpected behavior and potential data corruption. sh: cpuinfo: warning for CONFIG_CPUMASK_OFFSTACK. When CONFIG_CPUMASK_OFFSTACK and CONFIG_DEBUG_PER_CPU_MAPS are selected, cpu_max_bits_warn() generates a runtime warning when showing /proc/cpuinfo. A failure in the -fstack-protector feature in GCC-based toolchains 
that target AArch64 allows an attacker to exploit an existing buffer 
overflow in dynamically-sized local variables in your application 
without this being detected. This stack-protector failure only applies 
to C99-style dynamically-sized local variables or those created using 
alloca(). The stack-protector operates as intended for statically-sized 
local variables.&lt;/p&gt;
&lt;p&gt;The default behavior when the stack-protector 
detects an overflow is to terminate your application, resulting…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-25-226-07</guid>
    </item>
    <item>
      <title>msrc_CVE-2024-49878 — resource: fix region_intersects() vs add_memory_driver_managed()</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2024-49878</link>
      <description>msrc_CVE-2024-49878</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2024-49878</guid>
    </item>
    <item>
      <title>OESA-2024-2370 — kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2024-2370</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP4: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&#13;
&#13;
In the Linux kernel, the following vulnerability has been resolved:  usb: gadget: uvc: Prevent buffer overflow in setup handler  Setup function uvc_function_setup permits control transfer requests with up to 64 bytes of payload (UVC_MAX_REQUEST_SIZE), data stage handler for OUT transfer uses memcpy to copy req-&amp;amp;gt;actual bytes to uvc_event-&amp;amp;gt;data.data array of size 60. This may result in an overflow of 4 bytes.(CVE-2022-48948)&#13;
&#13;
In the Linux kernel, the following vulnerability has been resolved:  igb: Initialize mailbox message for VF reset  When a MAC address is not assigned to the VF, that portion of the message sent to the VF is not set. The memory, however, is allocated from the stack meaning that information may be leaked to the VM. Initialize the message buffer to 0 so that no information is passed to the VM in this case.(CVE-2022-48949)&#13;
&#13;
In the Linux kernel, the following vulnerability has been resolved:  net: hisilicon: Fix potential use-after-free in hix5hd2_rx()  The skb is delivered to napi_gro_receive() which may free it, after calling this, dereferencing skb may trigger use-after-free.(CVE-2022-48960)&#13;
&#13;
In the Linux kernel, the following vulnerability has been resolved:  net: hisilicon: Fix potential use-after-free in hisi_femac_rx()  The skb is delivered to napi_gro_receive() which may free it, after calling this, dereferencing skb may trigger use-after-free.(CVE-2022-48962)&#13;
&#13;
In…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP4: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&#13;
&#13;
In the Linux kernel, the following vulnerability has been resolved:  usb: gadget: uvc: Prevent buffer overflow in setup handler  Setup function uvc_function_setup permits control transfer requests with up to 64 bytes of payload (UVC_MAX_REQUEST_SIZE), data stage handler for OUT transfer uses memcpy to copy req-&amp;amp;gt;actual bytes to uvc_event-&amp;amp;gt;data.data array of size 60. This may result in an overflow of 4 bytes.(CVE-2022-48948)&#13;
&#13;
In the Linux kernel, the following vulnerability has been resolved:  igb: Initialize mailbox message for VF reset  When a MAC address is not assigned to the VF, that portion of the message sent to the VF is not set. The memory, however, is allocated from the stack meaning that information may be leaked to the VM. Initialize the message buffer to 0 so that no information is passed to the VM in this case.(CVE-2022-48949)&#13;
&#13;
In the Linux kernel, the following vulnerability has been resolved:  net: hisilicon: Fix potential use-after-free in hix5hd2_rx()  The skb is delivered to napi_gro_receive() which may free it, after calling this, dereferencing skb may trigger use-after-free.(CVE-2022-48960)&#13;
&#13;
In the Linux kernel, the following vulnerability has been resolved:  net: hisilicon: Fix potential use-after-free in hisi_femac_rx()  The skb is delivered to napi_gro_receive() which may free it, after calling this, dereferencing skb may trigger use-after-free.(CVE-2022-48962)&#13;
&#13;
In…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2024-2370</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:14500-1 — kernel-devel-6.11.8-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:14500-1</link>
      <description>&lt;p&gt;kernel-devel-6.11.8-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;kernel-devel-6.11.8-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:14500-1</guid>
    </item>
    <item>
      <title>SSA-355557 — SSA-355557: Multiple Vulnerabilities in Third-Party Components in SINEC OS before V3.2</title>
      <link>https://cve.radiocsirt.org/vuln/ssa-355557</link>
      <description>&lt;p&gt;nfsd: NULL dereference in nfs3svc_encode_getaclres. scsi: core: use-after-free vulnerability. NFSD: vulnerability caused by loff_t overflow on the server when a client reads near the maximum offset, causing the server to return an EINVAL error, which the client retries indefinitely, instead of handling out-of-range READ requests by returning a short result with an EOF flag. NFSD: Vulnerability caused by an underflow in ia_size due to a mismatch between signed and unsigned 64-bit file size values, which can cause issues when handling large file sizes from NFS clients. NFSD: Vulnerability handling large file sizes for NFSv3 improperly capping client size values larger than s64_max, leading to unexpected behavior and potential data corruption. sh: cpuinfo: warning for CONFIG_CPUMASK_OFFSTACK. When CONFIG_CPUMASK_OFFSTACK and CONFIG_DEBUG_PER_CPU_MAPS are selected, cpu_max_bits_warn() generates a runtime warning when showing /proc/cpuinfo. A failure in the -fstack-protector feature in GCC-based toolchains 
that target AArch64 allows an attacker to exploit an existing buffer 
overflow in dynamically-sized local variables in your application 
without this being detected. This stack-protector failure only applies 
to C99-style dynamically-sized local variables or those created using 
alloca(). The stack-protector operates as intended for statically-sized 
local variables.&lt;/p&gt;
&lt;p&gt;The default behavior when the stack-protector 
detects an overflow is to terminate your application, resulting…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;nfsd: NULL dereference in nfs3svc_encode_getaclres. scsi: core: use-after-free vulnerability. NFSD: vulnerability caused by loff_t overflow on the server when a client reads near the maximum offset, causing the server to return an EINVAL error, which the client retries indefinitely, instead of handling out-of-range READ requests by returning a short result with an EOF flag. NFSD: Vulnerability caused by an underflow in ia_size due to a mismatch between signed and unsigned 64-bit file size values, which can cause issues when handling large file sizes from NFS clients. NFSD: Vulnerability handling large file sizes for NFSv3 improperly capping client size values larger than s64_max, leading to unexpected behavior and potential data corruption. sh: cpuinfo: warning for CONFIG_CPUMASK_OFFSTACK. When CONFIG_CPUMASK_OFFSTACK and CONFIG_DEBUG_PER_CPU_MAPS are selected, cpu_max_bits_warn() generates a runtime warning when showing /proc/cpuinfo. A failure in the -fstack-protector feature in GCC-based toolchains 
that target AArch64 allows an attacker to exploit an existing buffer 
overflow in dynamically-sized local variables in your application 
without this being detected. This stack-protector failure only applies 
to C99-style dynamically-sized local variables or those created using 
alloca(). The stack-protector operates as intended for statically-sized 
local variables.&lt;/p&gt;
&lt;p&gt;The default behavior when the stack-protector 
detects an overflow is to terminate your application, resulting…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ssa-355557</guid>
    </item>
    <item>
      <title>SUSE-SU-2024:3984-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2024:3984-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2024:3984-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2024-49878</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-49878</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:Pro:18.04:LTS: linux-aws-5.4, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:Pro:18.04:LTS: linux-azure-5.4, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3 and 165 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: resource: fix region_intersects() vs add_memory_driver_managed() On a system with CXL memory, the resource tree (/proc/iomem) related to CXL memory may look like something as follows. 490000000-50fffffff : CXL Window 0   490000000-50fffffff : region0     490000000-50fffffff : dax0.0       490000000-50fffffff : System RAM (kmem) Because drivers/dax/kmem.c calls add_memory_driver_managed() during onlining CXL memory, which makes &amp;#34;System RAM (kmem)&amp;#34; a descendant of &amp;#34;CXL Window X&amp;#34;.  This confuses region_intersects(), which expects all &amp;#34;System RAM&amp;#34; resources to be at the top level of iomem_resource.  This can lead to bugs. For example, when the following command line is executed to write some memory in CXL memory range via /dev/mem,  $ dd if=data of=/dev/mem bs=$((1 &amp;lt;&amp;lt; 10)) seek=$((0x490000000 &amp;gt;&amp;gt; 10)) count=1  dd: error writing &amp;#39;/dev/mem&amp;#39;: Bad address  1+0 records in  0+0 records out  0 bytes copied, 0.0283507 s, 0.0 kB/s the command fails as expected.  However, the error code is wrong.  It should be &amp;#34;Operation not permitted&amp;#34; instead of &amp;#34;Bad address&amp;#34;.  More seriously, the /dev/mem permission checking in devmem_is_allowed() passes incorrectly.  Although the accessing is prevented later because ioremap() isn&amp;#39;t allowed to map system RAM, it is a potential security issue.  During command executing, the following warning is reported in the kernel log for calling ioremap() on system RAM.  ioremap on RAM at 0x0000000490…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:Pro:18.04:LTS: linux-aws-5.4, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:Pro:18.04:LTS: linux-azure-5.4, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3 and 165 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: resource: fix region_intersects() vs add_memory_driver_managed() On a system with CXL memory, the resource tree (/proc/iomem) related to CXL memory may look like something as follows. 490000000-50fffffff : CXL Window 0   490000000-50fffffff : region0     490000000-50fffffff : dax0.0       490000000-50fffffff : System RAM (kmem) Because drivers/dax/kmem.c calls add_memory_driver_managed() during onlining CXL memory, which makes &amp;#34;System RAM (kmem)&amp;#34; a descendant of &amp;#34;CXL Window X&amp;#34;.  This confuses region_intersects(), which expects all &amp;#34;System RAM&amp;#34; resources to be at the top level of iomem_resource.  This can lead to bugs. For example, when the following command line is executed to write some memory in CXL memory range via /dev/mem,  $ dd if=data of=/dev/mem bs=$((1 &amp;lt;&amp;lt; 10)) seek=$((0x490000000 &amp;gt;&amp;gt; 10)) count=1  dd: error writing &amp;#39;/dev/mem&amp;#39;: Bad address  1+0 records in  0+0 records out  0 bytes copied, 0.0283507 s, 0.0 kB/s the command fails as expected.  However, the error code is wrong.  It should be &amp;#34;Operation not permitted&amp;#34; instead of &amp;#34;Bad address&amp;#34;.  More seriously, the /dev/mem permission checking in devmem_is_allowed() passes incorrectly.  Although the accessing is prevented later because ioremap() isn&amp;#39;t allowed to map system RAM, it is a potential security issue.  During command executing, the following warning is reported in the kernel log for calling ioremap() on system RAM.  ioremap on RAM at 0x0000000490…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-49878</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-3251 — Linux Kernel: Mehrere Schwachstellen ermöglichen Denial of Service</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-3251</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen oder andere, nicht näher bekannte Auswirkungen zu erzielen..&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen oder andere, nicht näher bekannte Auswirkungen zu erzielen..&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-3251</guid>
    </item>
  </channel>
</rss>
