<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 08:27:27 +0000</lastBuildDate>
    <item>
      <title>bdu:2025-07898</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-07898</link>
      <description>bdu:2025-07898</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-07898</guid>
    </item>
    <item>
      <title>BELL-CVE-2024-50240</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2024-50240</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2024-50240</guid>
    </item>
    <item>
      <title>certfr-2024-avi-1102 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de SUSE. Certaines d'entre elles permettent à un at…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2024-avi-1102</link>
      <description>certfr-2024-avi-1102</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2024-avi-1102</guid>
    </item>
    <item>
      <title>EUVD-2026-313552</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-313552</link>
      <description>EUVD-2026-313552</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-313552</guid>
    </item>
    <item>
      <title>fkie_cve-2024-50240</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-50240</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;phy: qcom: qmp-usb: fix NULL-deref on runtime suspend&lt;/p&gt;
&lt;p&gt;Commit 413db06c05e7 (&amp;#34;phy: qcom-qmp-usb: clean up probe initialisation&amp;#34;)
removed most users of the platform device driver data, but mistakenly
also removed the initialisation despite the data still being used in the
runtime PM callbacks.&lt;/p&gt;
&lt;p&gt;Restore the driver data initialisation at probe to avoid a NULL-pointer
dereference on runtime suspend.&lt;/p&gt;
&lt;p&gt;Apparently no one uses runtime PM, which currently needs to be enabled
manually through sysfs, with this driver.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;phy: qcom: qmp-usb: fix NULL-deref on runtime suspend&lt;/p&gt;
&lt;p&gt;Commit 413db06c05e7 (&amp;#34;phy: qcom-qmp-usb: clean up probe initialisation&amp;#34;)
removed most users of the platform device driver data, but mistakenly
also removed the initialisation despite the data still being used in the
runtime PM callbacks.&lt;/p&gt;
&lt;p&gt;Restore the driver data initialisation at probe to avoid a NULL-pointer
dereference on runtime suspend.&lt;/p&gt;
&lt;p&gt;Apparently no one uses runtime PM, which currently needs to be enabled
manually through sysfs, with this driver.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-50240</guid>
    </item>
    <item>
      <title>GHSA-2fwq-2wwr-qrww</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-2fwq-2wwr-qrww</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;phy: qcom: qmp-usb: fix NULL-deref on runtime suspend&lt;/p&gt;
&lt;p&gt;Commit 413db06c05e7 (&amp;#34;phy: qcom-qmp-usb: clean up probe initialisation&amp;#34;)
removed most users of the platform device driver data, but mistakenly
also removed the initialisation despite the data still being used in the
runtime PM callbacks.&lt;/p&gt;
&lt;p&gt;Restore the driver data initialisation at probe to avoid a NULL-pointer
dereference on runtime suspend.&lt;/p&gt;
&lt;p&gt;Apparently no one uses runtime PM, which currently needs to be enabled
manually through sysfs, with this driver.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;phy: qcom: qmp-usb: fix NULL-deref on runtime suspend&lt;/p&gt;
&lt;p&gt;Commit 413db06c05e7 (&amp;#34;phy: qcom-qmp-usb: clean up probe initialisation&amp;#34;)
removed most users of the platform device driver data, but mistakenly
also removed the initialisation despite the data still being used in the
runtime PM callbacks.&lt;/p&gt;
&lt;p&gt;Restore the driver data initialisation at probe to avoid a NULL-pointer
dereference on runtime suspend.&lt;/p&gt;
&lt;p&gt;Apparently no one uses runtime PM, which currently needs to be enabled
manually through sysfs, with this driver.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-2fwq-2wwr-qrww</guid>
    </item>
    <item>
      <title>msrc_CVE-2024-50240 — phy: qcom: qmp-usb: fix NULL-deref on runtime suspend</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2024-50240</link>
      <description>msrc_CVE-2024-50240</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2024-50240</guid>
    </item>
    <item>
      <title>OESA-2025-1097 — kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2025-1097</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;ksmbd: fix potencial out-of-bounds when buffer offset is invalid&lt;/p&gt;
&lt;p&gt;I found potencial out-of-bounds when buffer offset fields of a few requests
is invalid. This patch set the minimum value of buffer offset field to
-&amp;amp;gt;Buffer offset to validate buffer length.(CVE-2024-26952)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;ksmbd: fix slab-out-of-bounds in smb_strndup_from_utf16()&lt;/p&gt;
&lt;p&gt;If -&amp;amp;gt;NameOffset of smb2_create_req is smaller than Buffer offset of
smb2_create_req, slab-out-of-bounds read can happen from smb2_open.
This patch set the minimum value of the name offset to the buffer offset
to validate name length of smb2_create_req().(CVE-2024-26954)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;fpga: bridge: add owner module and take its refcount&lt;/p&gt;
&lt;p&gt;The current implementation of the fpga bridge assumes that the low-level
module registers a driver for the parent device and uses its owner pointer
to take the module&amp;amp;apos;s refcount. This approach is problematic since it can
lead to a null pointer dereference while attempting to get the bridge if
the parent device does not have a driver.&lt;/p&gt;
&lt;p&gt;To address this problem, add a module owner pointer to the fpga_bridge
struct and use it to take the module&amp;amp;apos;s refcount. Modify the function for
registering a bridge to take an additional owner module paramet…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;ksmbd: fix potencial out-of-bounds when buffer offset is invalid&lt;/p&gt;
&lt;p&gt;I found potencial out-of-bounds when buffer offset fields of a few requests
is invalid. This patch set the minimum value of buffer offset field to
-&amp;amp;gt;Buffer offset to validate buffer length.(CVE-2024-26952)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;ksmbd: fix slab-out-of-bounds in smb_strndup_from_utf16()&lt;/p&gt;
&lt;p&gt;If -&amp;amp;gt;NameOffset of smb2_create_req is smaller than Buffer offset of
smb2_create_req, slab-out-of-bounds read can happen from smb2_open.
This patch set the minimum value of the name offset to the buffer offset
to validate name length of smb2_create_req().(CVE-2024-26954)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;fpga: bridge: add owner module and take its refcount&lt;/p&gt;
&lt;p&gt;The current implementation of the fpga bridge assumes that the low-level
module registers a driver for the parent device and uses its owner pointer
to take the module&amp;amp;apos;s refcount. This approach is problematic since it can
lead to a null pointer dereference while attempting to get the bridge if
the parent device does not have a driver.&lt;/p&gt;
&lt;p&gt;To address this problem, add a module owner pointer to the fpga_bridge
struct and use it to take the module&amp;amp;apos;s refcount. Modify the function for
registering a bridge to take an additional owner module paramet…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2025-1097</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:14500-1 — kernel-devel-6.11.8-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:14500-1</link>
      <description>&lt;p&gt;kernel-devel-6.11.8-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;kernel-devel-6.11.8-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:14500-1</guid>
    </item>
    <item>
      <title>SUSE-SU-2024:4314-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2024:4314-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2024:4314-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2024-50240</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-50240</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 101 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: phy: qcom: qmp-usb: fix NULL-deref on runtime suspend Commit 413db06c05e7 (&amp;#34;phy: qcom-qmp-usb: clean up probe initialisation&amp;#34;) removed most users of the platform device driver data, but mistakenly also removed the initialisation despite the data still being used in the runtime PM callbacks. Restore the driver data initialisation at probe to avoid a NULL-pointer dereference on runtime suspend. Apparently no one uses runtime PM, which currently needs to be enabled manually through sysfs, with this driver.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 101 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: phy: qcom: qmp-usb: fix NULL-deref on runtime suspend Commit 413db06c05e7 (&amp;#34;phy: qcom-qmp-usb: clean up probe initialisation&amp;#34;) removed most users of the platform device driver data, but mistakenly also removed the initialisation despite the data still being used in the runtime PM callbacks. Restore the driver data initialisation at probe to avoid a NULL-pointer dereference on runtime suspend. Apparently no one uses runtime PM, which currently needs to be enabled manually through sysfs, with this driver.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-50240</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-3397 — Linux Kernel: Mehrere Schwachstellen ermöglichen nicht spezifizierten Angriff</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-3397</link>
      <description>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-3397</guid>
    </item>
  </channel>
</rss>
