<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 09:13:34 +0000</lastBuildDate>
    <item>
      <title>bdu:2024-10097</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2024-10097</link>
      <description>bdu:2024-10097</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2024-10097</guid>
    </item>
    <item>
      <title>BELL-CVE-2024-50217</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2024-50217</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2024-50217</guid>
    </item>
    <item>
      <title>certfr-2025-avi-0152 — De multiples vulnérabilités ont été découvertes dans le noyau Linux d'Ubuntu. Certaines d'entre elles permettent à un a…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0152</link>
      <description>certfr-2025-avi-0152</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0152</guid>
    </item>
    <item>
      <title>EUVD-2026-346335</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-346335</link>
      <description>EUVD-2026-346335</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-346335</guid>
    </item>
    <item>
      <title>fkie_cve-2024-50217</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-50217</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;btrfs: fix use-after-free of block device file in __btrfs_free_extra_devids()&lt;/p&gt;
&lt;p&gt;Mounting btrfs from two images (which have the same one fsid and two
different dev_uuids) in certain executing order may trigger an UAF for
variable &amp;#39;device-&amp;gt;bdev_file&amp;#39; in __btrfs_free_extra_devids(). And
following are the details:&lt;/p&gt;
&lt;p&gt;1. Attach image_1 to loop0, attach image_2 to loop1, and scan btrfs
   devices by ioctl(BTRFS_IOC_SCAN_DEV):&lt;/p&gt;
&lt;p&gt;/  btrfs_device_1 → loop0
   fs_device
             \  btrfs_device_2 → loop1
2. mount /dev/loop0 /mnt
   btrfs_open_devices
    btrfs_device_1-&amp;gt;bdev_file = btrfs_get_bdev_and_sb(loop0)
    btrfs_device_2-&amp;gt;bdev_file = btrfs_get_bdev_and_sb(loop1)
   btrfs_fill_super
    open_ctree
     fail: btrfs_close_devices // -ENOMEM
	    btrfs_close_bdev(btrfs_device_1)
             fput(btrfs_device_1-&amp;gt;bdev_file)
	      // btrfs_device_1-&amp;gt;bdev_file is freed
	    btrfs_close_bdev(btrfs_device_2)
             fput(btrfs_device_2-&amp;gt;bdev_file)&lt;/p&gt;
&lt;p&gt;3. mount /dev/loop1 /mnt
   btrfs_open_devices
    btrfs_get_bdev_and_sb(&amp;amp;bdev_file)
     // EIO, btrfs_device_1-&amp;gt;bdev_file is not assigned,
     // which points to a freed memory area
    btrfs_device_2-&amp;gt;bdev_file = btrfs_get_bdev_and_sb(loop1)
   btrfs_fill_super
    open_ctree
     btrfs_free_extra_devids
      if (btrfs_device_1-&amp;gt;bdev_file)
       fput(btrfs_device_1-&amp;gt;bdev_file) // UAF !&lt;/p&gt;
&lt;p&gt;Fix it by setting &amp;#39;device-&amp;gt;bdev_file&amp;#39; as &amp;#39;NULL&amp;#39; after closing t…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;btrfs: fix use-after-free of block device file in __btrfs_free_extra_devids()&lt;/p&gt;
&lt;p&gt;Mounting btrfs from two images (which have the same one fsid and two
different dev_uuids) in certain executing order may trigger an UAF for
variable &amp;#39;device-&amp;gt;bdev_file&amp;#39; in __btrfs_free_extra_devids(). And
following are the details:&lt;/p&gt;
&lt;p&gt;1. Attach image_1 to loop0, attach image_2 to loop1, and scan btrfs
   devices by ioctl(BTRFS_IOC_SCAN_DEV):&lt;/p&gt;
&lt;p&gt;/  btrfs_device_1 → loop0
   fs_device
             \  btrfs_device_2 → loop1
2. mount /dev/loop0 /mnt
   btrfs_open_devices
    btrfs_device_1-&amp;gt;bdev_file = btrfs_get_bdev_and_sb(loop0)
    btrfs_device_2-&amp;gt;bdev_file = btrfs_get_bdev_and_sb(loop1)
   btrfs_fill_super
    open_ctree
     fail: btrfs_close_devices // -ENOMEM
	    btrfs_close_bdev(btrfs_device_1)
             fput(btrfs_device_1-&amp;gt;bdev_file)
	      // btrfs_device_1-&amp;gt;bdev_file is freed
	    btrfs_close_bdev(btrfs_device_2)
             fput(btrfs_device_2-&amp;gt;bdev_file)&lt;/p&gt;
&lt;p&gt;3. mount /dev/loop1 /mnt
   btrfs_open_devices
    btrfs_get_bdev_and_sb(&amp;amp;bdev_file)
     // EIO, btrfs_device_1-&amp;gt;bdev_file is not assigned,
     // which points to a freed memory area
    btrfs_device_2-&amp;gt;bdev_file = btrfs_get_bdev_and_sb(loop1)
   btrfs_fill_super
    open_ctree
     btrfs_free_extra_devids
      if (btrfs_device_1-&amp;gt;bdev_file)
       fput(btrfs_device_1-&amp;gt;bdev_file) // UAF !&lt;/p&gt;
&lt;p&gt;Fix it by setting &amp;#39;device-&amp;gt;bdev_file&amp;#39; as &amp;#39;NULL&amp;#39; after closing t…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-50217</guid>
    </item>
    <item>
      <title>GHSA-5684-4xfg-mxj4</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-5684-4xfg-mxj4</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;btrfs: fix use-after-free of block device file in __btrfs_free_extra_devids()&lt;/p&gt;
&lt;p&gt;Mounting btrfs from two images (which have the same one fsid and two
different dev_uuids) in certain executing order may trigger an UAF for
variable &amp;#39;device-&amp;gt;bdev_file&amp;#39; in __btrfs_free_extra_devids(). And
following are the details:&lt;/p&gt;
&lt;p&gt;1. Attach image_1 to loop0, attach image_2 to loop1, and scan btrfs
   devices by ioctl(BTRFS_IOC_SCAN_DEV):&lt;/p&gt;
&lt;p&gt;/  btrfs_device_1 → loop0
   fs_device
             \  btrfs_device_2 → loop1
2. mount /dev/loop0 /mnt
   btrfs_open_devices
    btrfs_device_1-&amp;gt;bdev_file = btrfs_get_bdev_and_sb(loop0)
    btrfs_device_2-&amp;gt;bdev_file = btrfs_get_bdev_and_sb(loop1)
   btrfs_fill_super
    open_ctree
     fail: btrfs_close_devices // -ENOMEM
	    btrfs_close_bdev(btrfs_device_1)
             fput(btrfs_device_1-&amp;gt;bdev_file)
	      // btrfs_device_1-&amp;gt;bdev_file is freed
	    btrfs_close_bdev(btrfs_device_2)
             fput(btrfs_device_2-&amp;gt;bdev_file)&lt;/p&gt;
&lt;p&gt;3. mount /dev/loop1 /mnt
   btrfs_open_devices
    btrfs_get_bdev_and_sb(&amp;amp;bdev_file)
     // EIO, btrfs_device_1-&amp;gt;bdev_file is not assigned,
     // which points to a freed memory area
    btrfs_device_2-&amp;gt;bdev_file = btrfs_get_bdev_and_sb(loop1)
   btrfs_fill_super
    open_ctree
     btrfs_free_extra_devids
      if (btrfs_device_1-&amp;gt;bdev_file)
       fput(btrfs_device_1-&amp;gt;bdev_file) // UAF !&lt;/p&gt;
&lt;p&gt;Fix it by setting &amp;#39;device-&amp;gt;bdev_file&amp;#39; as &amp;#39;NULL&amp;#39; after closing t…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;btrfs: fix use-after-free of block device file in __btrfs_free_extra_devids()&lt;/p&gt;
&lt;p&gt;Mounting btrfs from two images (which have the same one fsid and two
different dev_uuids) in certain executing order may trigger an UAF for
variable &amp;#39;device-&amp;gt;bdev_file&amp;#39; in __btrfs_free_extra_devids(). And
following are the details:&lt;/p&gt;
&lt;p&gt;1. Attach image_1 to loop0, attach image_2 to loop1, and scan btrfs
   devices by ioctl(BTRFS_IOC_SCAN_DEV):&lt;/p&gt;
&lt;p&gt;/  btrfs_device_1 → loop0
   fs_device
             \  btrfs_device_2 → loop1
2. mount /dev/loop0 /mnt
   btrfs_open_devices
    btrfs_device_1-&amp;gt;bdev_file = btrfs_get_bdev_and_sb(loop0)
    btrfs_device_2-&amp;gt;bdev_file = btrfs_get_bdev_and_sb(loop1)
   btrfs_fill_super
    open_ctree
     fail: btrfs_close_devices // -ENOMEM
	    btrfs_close_bdev(btrfs_device_1)
             fput(btrfs_device_1-&amp;gt;bdev_file)
	      // btrfs_device_1-&amp;gt;bdev_file is freed
	    btrfs_close_bdev(btrfs_device_2)
             fput(btrfs_device_2-&amp;gt;bdev_file)&lt;/p&gt;
&lt;p&gt;3. mount /dev/loop1 /mnt
   btrfs_open_devices
    btrfs_get_bdev_and_sb(&amp;amp;bdev_file)
     // EIO, btrfs_device_1-&amp;gt;bdev_file is not assigned,
     // which points to a freed memory area
    btrfs_device_2-&amp;gt;bdev_file = btrfs_get_bdev_and_sb(loop1)
   btrfs_fill_super
    open_ctree
     btrfs_free_extra_devids
      if (btrfs_device_1-&amp;gt;bdev_file)
       fput(btrfs_device_1-&amp;gt;bdev_file) // UAF !&lt;/p&gt;
&lt;p&gt;Fix it by setting &amp;#39;device-&amp;gt;bdev_file&amp;#39; as &amp;#39;NULL&amp;#39; after closing t…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-5684-4xfg-mxj4</guid>
    </item>
    <item>
      <title>msrc_CVE-2024-50217 — btrfs: fix use-after-free of block device file in __btrfs_free_extra_devids()</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2024-50217</link>
      <description>msrc_CVE-2024-50217</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2024-50217</guid>
    </item>
    <item>
      <title>OESA-2024-2492 — kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2024-2492</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&#13;
&#13;
In the Linux kernel, the following vulnerability has been resolved:  bpf: support non-r10 register spill/fill to/from stack in precision tracking  Use instruction (jump) history to record instructions that performed register spill/fill to/from stack, regardless if this was done through read-only r10 register, or any other register after copying r10 into it *and* potentially adjusting offset.  To make this work reliably, we push extra per-instruction flags into instruction history, encoding stack slot index (spi) and stack frame number in extra 10 bit flags we take away from prev_idx in instruction history. We don&amp;amp;apos;t touch idx field for maximum performance, as it&amp;amp;apos;s checked most frequently during backtracking.  This change removes basically the last remaining practical limitation of precision backtracking logic in BPF verifier. It fixes known deficiencies, but also opens up new opportunities to reduce number of verified states, explored in the subsequent patches.  There are only three differences in selftests&amp;amp;apos; BPF object files according to veristat, all in the positive direction (less states).  File                                    Program        Insns (A)  Insns (B)  Insns  (DIFF)  States (A)  States (B)  States (DIFF) --------------------------------------  -------------  ---------  ---------  -------------  ----------  ----------  ------------- test_cls_redirect_dynptr.bpf.linked3.o…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&#13;
&#13;
In the Linux kernel, the following vulnerability has been resolved:  bpf: support non-r10 register spill/fill to/from stack in precision tracking  Use instruction (jump) history to record instructions that performed register spill/fill to/from stack, regardless if this was done through read-only r10 register, or any other register after copying r10 into it *and* potentially adjusting offset.  To make this work reliably, we push extra per-instruction flags into instruction history, encoding stack slot index (spi) and stack frame number in extra 10 bit flags we take away from prev_idx in instruction history. We don&amp;amp;apos;t touch idx field for maximum performance, as it&amp;amp;apos;s checked most frequently during backtracking.  This change removes basically the last remaining practical limitation of precision backtracking logic in BPF verifier. It fixes known deficiencies, but also opens up new opportunities to reduce number of verified states, explored in the subsequent patches.  There are only three differences in selftests&amp;amp;apos; BPF object files according to veristat, all in the positive direction (less states).  File                                    Program        Insns (A)  Insns (B)  Insns  (DIFF)  States (A)  States (B)  States (DIFF) --------------------------------------  -------------  ---------  ---------  -------------  ----------  ----------  ------------- test_cls_redirect_dynptr.bpf.linked3.o…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2024-2492</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:14500-1 — kernel-devel-6.11.8-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:14500-1</link>
      <description>&lt;p&gt;kernel-devel-6.11.8-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;kernel-devel-6.11.8-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:14500-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2024-50217</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-50217</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe, Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:Pro:16.04:LTS: linux-oracle, Ubuntu:Pro:18.04:LTS: linux, Ubuntu:Pro:18.04:LTS: linux-aws, Ubuntu:18.04:LTS: linux-aws-5.0 and 196 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: btrfs: fix use-after-free of block device file in __btrfs_free_extra_devids() Mounting btrfs from two images (which have the same one fsid and two different dev_uuids) in certain executing order may trigger an UAF for variable &amp;#39;device-&amp;gt;bdev_file&amp;#39; in __btrfs_free_extra_devids(). And following are the details: 1. Attach image_1 to loop0, attach image_2 to loop1, and scan btrfs    devices by ioctl(BTRFS_IOC_SCAN_DEV):              /  btrfs_device_1 → loop0    fs_device              \  btrfs_device_2 → loop1 2. mount /dev/loop0 /mnt    btrfs_open_devices     btrfs_device_1-&amp;gt;bdev_file = btrfs_get_bdev_and_sb(loop0)     btrfs_device_2-&amp;gt;bdev_file = btrfs_get_bdev_and_sb(loop1)    btrfs_fill_super     open_ctree      fail: btrfs_close_devices // -ENOMEM 	    btrfs_close_bdev(btrfs_device_1)              fput(btrfs_device_1-&amp;gt;bdev_file) 	      // btrfs_device_1-&amp;gt;bdev_file is freed 	    btrfs_close_bdev(btrfs_device_2)              fput(btrfs_device_2-&amp;gt;bdev_file) 3. mount /dev/loop1 /mnt    btrfs_open_devices     btrfs_get_bdev_and_sb(&amp;amp;bdev_file)      // EIO, btrfs_device_1-&amp;gt;bdev_file is not assigned,      // which points to a freed memory area     btrfs_device_2-&amp;gt;bdev_file = btrfs_get_bdev_and_sb(loop1)    btrfs_fill_super     open_ctree      btrfs_free_extra_devids       if (btrfs_device_1-&amp;gt;bdev_file)        fput(btrfs_device_1-&amp;gt;bdev_file) // UAF ! Fix it by setting &amp;#39;device-&amp;gt;bdev_file&amp;#39; as &amp;#39;NULL&amp;#39; after closing the btr…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe, Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:Pro:16.04:LTS: linux-oracle, Ubuntu:Pro:18.04:LTS: linux, Ubuntu:Pro:18.04:LTS: linux-aws, Ubuntu:18.04:LTS: linux-aws-5.0 and 196 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: btrfs: fix use-after-free of block device file in __btrfs_free_extra_devids() Mounting btrfs from two images (which have the same one fsid and two different dev_uuids) in certain executing order may trigger an UAF for variable &amp;#39;device-&amp;gt;bdev_file&amp;#39; in __btrfs_free_extra_devids(). And following are the details: 1. Attach image_1 to loop0, attach image_2 to loop1, and scan btrfs    devices by ioctl(BTRFS_IOC_SCAN_DEV):              /  btrfs_device_1 → loop0    fs_device              \  btrfs_device_2 → loop1 2. mount /dev/loop0 /mnt    btrfs_open_devices     btrfs_device_1-&amp;gt;bdev_file = btrfs_get_bdev_and_sb(loop0)     btrfs_device_2-&amp;gt;bdev_file = btrfs_get_bdev_and_sb(loop1)    btrfs_fill_super     open_ctree      fail: btrfs_close_devices // -ENOMEM 	    btrfs_close_bdev(btrfs_device_1)              fput(btrfs_device_1-&amp;gt;bdev_file) 	      // btrfs_device_1-&amp;gt;bdev_file is freed 	    btrfs_close_bdev(btrfs_device_2)              fput(btrfs_device_2-&amp;gt;bdev_file) 3. mount /dev/loop1 /mnt    btrfs_open_devices     btrfs_get_bdev_and_sb(&amp;amp;bdev_file)      // EIO, btrfs_device_1-&amp;gt;bdev_file is not assigned,      // which points to a freed memory area     btrfs_device_2-&amp;gt;bdev_file = btrfs_get_bdev_and_sb(loop1)    btrfs_fill_super     open_ctree      btrfs_free_extra_devids       if (btrfs_device_1-&amp;gt;bdev_file)        fput(btrfs_device_1-&amp;gt;bdev_file) // UAF ! Fix it by setting &amp;#39;device-&amp;gt;bdev_file&amp;#39; as &amp;#39;NULL&amp;#39; after closing the btr…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-50217</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-3397 — Linux Kernel: Mehrere Schwachstellen ermöglichen nicht spezifizierten Angriff</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-3397</link>
      <description>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-3397</guid>
    </item>
  </channel>
</rss>
