<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 19:30:42 +0000</lastBuildDate>
    <item>
      <title>ALSA-2025:9580 — Moderate: kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2025:9580</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: bpftool, AlmaLinux:8: kernel, AlmaLinux:8: kernel-abi-stablelists, AlmaLinux:8: kernel-core, AlmaLinux:8: kernel-cross-headers, AlmaLinux:8: kernel-debug, AlmaLinux:8: kernel-debug-core, AlmaLinux:8: kernel-debug-devel, AlmaLinux:8: kernel-debug-modules, AlmaLinux:8: kernel-debug-modules-extra and 15 more&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: cifs: fix double free race when mount fails in cifs_get_root() (CVE-2022-48919)
  * kernel: security/keys: fix slab-out-of-bounds in key_task_permission (CVE-2024-50301)
  * kernel: idpf: fix idpf_vc_core_init error path (CVE-2024-53064)
  * kernel: ndisc: use RCU protection in ndisc_alloc_skb() (CVE-2025-21764)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: bpftool, AlmaLinux:8: kernel, AlmaLinux:8: kernel-abi-stablelists, AlmaLinux:8: kernel-core, AlmaLinux:8: kernel-cross-headers, AlmaLinux:8: kernel-debug, AlmaLinux:8: kernel-debug-core, AlmaLinux:8: kernel-debug-devel, AlmaLinux:8: kernel-debug-modules, AlmaLinux:8: kernel-debug-modules-extra and 15 more&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: cifs: fix double free race when mount fails in cifs_get_root() (CVE-2022-48919)
  * kernel: security/keys: fix slab-out-of-bounds in key_task_permission (CVE-2024-50301)
  * kernel: idpf: fix idpf_vc_core_init error path (CVE-2024-53064)
  * kernel: ndisc: use RCU protection in ndisc_alloc_skb() (CVE-2025-21764)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2025:9580</guid>
    </item>
    <item>
      <title>bdu:2025-15032</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-15032</link>
      <description>bdu:2025-15032</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-15032</guid>
    </item>
    <item>
      <title>BELL-CVE-2024-53064</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2024-53064</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2024-53064</guid>
    </item>
    <item>
      <title>certfr-2025-avi-0047 — De multiples vulnérabilités ont été découvertes dans les produits SUSE. Certaines d'entre elles permettent à un attaqua…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0047</link>
      <description>certfr-2025-avi-0047</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0047</guid>
    </item>
    <item>
      <title>cnvd-2024-46391</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2024-46391</link>
      <description>cnvd-2024-46391</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2024-46391</guid>
    </item>
    <item>
      <title>EUVD-2026-313592</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-313592</link>
      <description>EUVD-2026-313592</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-313592</guid>
    </item>
    <item>
      <title>fkie_cve-2024-53064</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-53064</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;idpf: fix idpf_vc_core_init error path&lt;/p&gt;
&lt;p&gt;In an event where the platform running the device control plane
is rebooted, reset is detected on the driver. It releases
all the resources and waits for the reset to complete. Once the
reset is done, it tries to build the resources back. At this
time if the device control plane is not yet started, then
the driver timeouts on the virtchnl message and retries to
establish the mailbox again.&lt;/p&gt;
&lt;p&gt;In the retry flow, mailbox is deinitialized but the mailbox
workqueue is still alive and polling for the mailbox message.
This results in accessing the released control queue leading to
null-ptr-deref. Fix it by unrolling the work queue cancellation
and mailbox deinitialization in the reverse order which they got
initialized.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;idpf: fix idpf_vc_core_init error path&lt;/p&gt;
&lt;p&gt;In an event where the platform running the device control plane
is rebooted, reset is detected on the driver. It releases
all the resources and waits for the reset to complete. Once the
reset is done, it tries to build the resources back. At this
time if the device control plane is not yet started, then
the driver timeouts on the virtchnl message and retries to
establish the mailbox again.&lt;/p&gt;
&lt;p&gt;In the retry flow, mailbox is deinitialized but the mailbox
workqueue is still alive and polling for the mailbox message.
This results in accessing the released control queue leading to
null-ptr-deref. Fix it by unrolling the work queue cancellation
and mailbox deinitialization in the reverse order which they got
initialized.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-53064</guid>
    </item>
    <item>
      <title>GHSA-87vp-wcxm-f9g2</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-87vp-wcxm-f9g2</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;idpf: fix idpf_vc_core_init error path&lt;/p&gt;
&lt;p&gt;In an event where the platform running the device control plane
is rebooted, reset is detected on the driver. It releases
all the resources and waits for the reset to complete. Once the
reset is done, it tries to build the resources back. At this
time if the device control plane is not yet started, then
the driver timeouts on the virtchnl message and retries to
establish the mailbox again.&lt;/p&gt;
&lt;p&gt;In the retry flow, mailbox is deinitialized but the mailbox
workqueue is still alive and polling for the mailbox message.
This results in accessing the released control queue leading to
null-ptr-deref. Fix it by unrolling the work queue cancellation
and mailbox deinitialization in the reverse order which they got
initialized.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;idpf: fix idpf_vc_core_init error path&lt;/p&gt;
&lt;p&gt;In an event where the platform running the device control plane
is rebooted, reset is detected on the driver. It releases
all the resources and waits for the reset to complete. Once the
reset is done, it tries to build the resources back. At this
time if the device control plane is not yet started, then
the driver timeouts on the virtchnl message and retries to
establish the mailbox again.&lt;/p&gt;
&lt;p&gt;In the retry flow, mailbox is deinitialized but the mailbox
workqueue is still alive and polling for the mailbox message.
This results in accessing the released control queue leading to
null-ptr-deref. Fix it by unrolling the work queue cancellation
and mailbox deinitialization in the reverse order which they got
initialized.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-87vp-wcxm-f9g2</guid>
    </item>
    <item>
      <title>RHSA-2025:9580 — Red Hat Security Advisory: kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2025:9580</link>
      <description>&lt;p&gt;kernel: cifs: fix double free race when mount fails in cifs_get_root() kernel: Kernel: Denial of Service via memory leak in SMB client kernel: security/keys: fix slab-out-of-bounds in key_task_permission kernel: idpf: fix idpf_vc_core_init error path kernel: ndisc: use RCU protection in ndisc_alloc_skb() kernel: idpf: check error for register_netdev() on init kernel: idpf: fix null-ptr-deref in idpf_features_check&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;kernel: cifs: fix double free race when mount fails in cifs_get_root() kernel: Kernel: Denial of Service via memory leak in SMB client kernel: security/keys: fix slab-out-of-bounds in key_task_permission kernel: idpf: fix idpf_vc_core_init error path kernel: ndisc: use RCU protection in ndisc_alloc_skb() kernel: idpf: check error for register_netdev() on init kernel: idpf: fix null-ptr-deref in idpf_features_check&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2025:9580</guid>
    </item>
    <item>
      <title>RHSA-2025:9581 — Red Hat Security Advisory: kernel-rt security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2025:9581</link>
      <description>&lt;p&gt;kernel: cifs: fix double free race when mount fails in cifs_get_root() kernel: Kernel: Denial of Service via memory leak in SMB client kernel: security/keys: fix slab-out-of-bounds in key_task_permission kernel: idpf: fix idpf_vc_core_init error path kernel: ndisc: use RCU protection in ndisc_alloc_skb() kernel: idpf: fix null-ptr-deref in idpf_features_check&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;kernel: cifs: fix double free race when mount fails in cifs_get_root() kernel: Kernel: Denial of Service via memory leak in SMB client kernel: security/keys: fix slab-out-of-bounds in key_task_permission kernel: idpf: fix idpf_vc_core_init error path kernel: ndisc: use RCU protection in ndisc_alloc_skb() kernel: idpf: fix null-ptr-deref in idpf_features_check&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2025:9581</guid>
    </item>
    <item>
      <title>SUSE-SU-2025:0117-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2025:0117-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2025:0117-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2024-53064</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-53064</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 113 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: idpf: fix idpf_vc_core_init error path In an event where the platform running the device control plane is rebooted, reset is detected on the driver. It releases all the resources and waits for the reset to complete. Once the reset is done, it tries to build the resources back. At this time if the device control plane is not yet started, then the driver timeouts on the virtchnl message and retries to establish the mailbox again. In the retry flow, mailbox is deinitialized but the mailbox workqueue is still alive and polling for the mailbox message. This results in accessing the released control queue leading to null-ptr-deref. Fix it by unrolling the work queue cancellation and mailbox deinitialization in the reverse order which they got initialized.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 113 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: idpf: fix idpf_vc_core_init error path In an event where the platform running the device control plane is rebooted, reset is detected on the driver. It releases all the resources and waits for the reset to complete. Once the reset is done, it tries to build the resources back. At this time if the device control plane is not yet started, then the driver timeouts on the virtchnl message and retries to establish the mailbox again. In the retry flow, mailbox is deinitialized but the mailbox workqueue is still alive and polling for the mailbox message. This results in accessing the released control queue leading to null-ptr-deref. Fix it by unrolling the work queue cancellation and mailbox deinitialization in the reverse order which they got initialized.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-53064</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-3509 — Linux Kernel: Mehrere Schwachstellen ermöglichen nicht spezifizierten Angriff</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-3509</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Linux Kernel ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Linux Kernel ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-3509</guid>
    </item>
  </channel>
</rss>
