<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 18:20:31 +0000</lastBuildDate>
    <item>
      <title>bdu:2025-04674</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-04674</link>
      <description>bdu:2025-04674</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-04674</guid>
    </item>
    <item>
      <title>BELL-CVE-2024-56664</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2024-56664</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2024-56664</guid>
    </item>
    <item>
      <title>certfr-2025-avi-0088 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de SUSE. Certaines d'entre elles permettent à un at…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0088</link>
      <description>certfr-2025-avi-0088</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0088</guid>
    </item>
    <item>
      <title>EUVD-2026-346512</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-346512</link>
      <description>EUVD-2026-346512</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-346512</guid>
    </item>
    <item>
      <title>fkie_cve-2024-56664</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-56664</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;bpf, sockmap: Fix race between element replace and close()&lt;/p&gt;
&lt;p&gt;Element replace (with a socket different from the one stored) may race
with socket&amp;#39;s close() link popping &amp;amp; unlinking. __sock_map_delete()
unconditionally unrefs the (wrong) element:&lt;/p&gt;
&lt;p&gt;// set map[0] = s0
map_update_elem(map, 0, s0)&lt;/p&gt;
&lt;p&gt;// drop fd of s0
close(s0)
  sock_map_close()
    lock_sock(sk)               (s0!)
    sock_map_remove_links(sk)
      link = sk_psock_link_pop()
      sock_map_unlink(sk, link)
        sock_map_delete_from_link
                                        // replace map[0] with s1
                                        map_update_elem(map, 0, s1)
                                          sock_map_update_elem
                                (s1!)       lock_sock(sk)
                                            sock_map_update_common
                                              psock = sk_psock(sk)
                                              spin_lock(&amp;amp;stab-&amp;gt;lock)
                                              osk = stab-&amp;gt;sks[idx]
                                              sock_map_add_link(..., &amp;amp;stab-&amp;gt;sks[idx])
                                              sock_map_unref(osk, &amp;amp;stab-&amp;gt;sks[idx])
                                                psock = sk_psock(osk)
                                                sk_psock_put(sk, psock)
                                                  if (refcount_dec_and_test(&amp;amp;psock))…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;bpf, sockmap: Fix race between element replace and close()&lt;/p&gt;
&lt;p&gt;Element replace (with a socket different from the one stored) may race
with socket&amp;#39;s close() link popping &amp;amp; unlinking. __sock_map_delete()
unconditionally unrefs the (wrong) element:&lt;/p&gt;
&lt;p&gt;// set map[0] = s0
map_update_elem(map, 0, s0)&lt;/p&gt;
&lt;p&gt;// drop fd of s0
close(s0)
  sock_map_close()
    lock_sock(sk)               (s0!)
    sock_map_remove_links(sk)
      link = sk_psock_link_pop()
      sock_map_unlink(sk, link)
        sock_map_delete_from_link
                                        // replace map[0] with s1
                                        map_update_elem(map, 0, s1)
                                          sock_map_update_elem
                                (s1!)       lock_sock(sk)
                                            sock_map_update_common
                                              psock = sk_psock(sk)
                                              spin_lock(&amp;amp;stab-&amp;gt;lock)
                                              osk = stab-&amp;gt;sks[idx]
                                              sock_map_add_link(..., &amp;amp;stab-&amp;gt;sks[idx])
                                              sock_map_unref(osk, &amp;amp;stab-&amp;gt;sks[idx])
                                                psock = sk_psock(osk)
                                                sk_psock_put(sk, psock)
                                                  if (refcount_dec_and_test(&amp;amp;psock))…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-56664</guid>
    </item>
    <item>
      <title>GHSA-22x4-j6vj-fmm5</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-22x4-j6vj-fmm5</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;bpf, sockmap: Fix race between element replace and close()&lt;/p&gt;
&lt;p&gt;Element replace (with a socket different from the one stored) may race
with socket&amp;#39;s close() link popping &amp;amp; unlinking. __sock_map_delete()
unconditionally unrefs the (wrong) element:&lt;/p&gt;
&lt;p&gt;// set map[0] = s0
map_update_elem(map, 0, s0)&lt;/p&gt;
&lt;p&gt;// drop fd of s0
close(s0)
  sock_map_close()
    lock_sock(sk)               (s0!)
    sock_map_remove_links(sk)
      link = sk_psock_link_pop()
      sock_map_unlink(sk, link)
        sock_map_delete_from_link
                                        // replace map[0] with s1
                                        map_update_elem(map, 0, s1)
                                          sock_map_update_elem
                                (s1!)       lock_sock(sk)
                                            sock_map_update_common
                                              psock = sk_psock(sk)
                                              spin_lock(&amp;amp;stab-&amp;gt;lock)
                                              osk = stab-&amp;gt;sks[idx]
                                              sock_map_add_link(..., &amp;amp;stab-&amp;gt;sks[idx])
                                              sock_map_unref(osk, &amp;amp;stab-&amp;gt;sks[idx])
                                                psock = sk_psock(osk)
                                                sk_psock_put(sk, psock)
                                                  if (refcount_dec_and_test(&amp;amp;psock))…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;bpf, sockmap: Fix race between element replace and close()&lt;/p&gt;
&lt;p&gt;Element replace (with a socket different from the one stored) may race
with socket&amp;#39;s close() link popping &amp;amp; unlinking. __sock_map_delete()
unconditionally unrefs the (wrong) element:&lt;/p&gt;
&lt;p&gt;// set map[0] = s0
map_update_elem(map, 0, s0)&lt;/p&gt;
&lt;p&gt;// drop fd of s0
close(s0)
  sock_map_close()
    lock_sock(sk)               (s0!)
    sock_map_remove_links(sk)
      link = sk_psock_link_pop()
      sock_map_unlink(sk, link)
        sock_map_delete_from_link
                                        // replace map[0] with s1
                                        map_update_elem(map, 0, s1)
                                          sock_map_update_elem
                                (s1!)       lock_sock(sk)
                                            sock_map_update_common
                                              psock = sk_psock(sk)
                                              spin_lock(&amp;amp;stab-&amp;gt;lock)
                                              osk = stab-&amp;gt;sks[idx]
                                              sock_map_add_link(..., &amp;amp;stab-&amp;gt;sks[idx])
                                              sock_map_unref(osk, &amp;amp;stab-&amp;gt;sks[idx])
                                                psock = sk_psock(osk)
                                                sk_psock_put(sk, psock)
                                                  if (refcount_dec_and_test(&amp;amp;psock))…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-22x4-j6vj-fmm5</guid>
    </item>
    <item>
      <title>msrc_CVE-2024-56664 — bpf, sockmap: Fix race between element replace and close()</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2024-56664</link>
      <description>msrc_CVE-2024-56664</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2024-56664</guid>
    </item>
    <item>
      <title>OESA-2025-1409 — kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2025-1409</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP3: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;fs/ntfs3: Fix some memory leaks in an error handling path of &amp;amp;apos;log_replay()&amp;amp;apos;&lt;/p&gt;
&lt;p&gt;All error handling paths lead to &amp;amp;apos;out&amp;amp;apos; where many resources are freed.&lt;/p&gt;
&lt;p&gt;Do it as well here instead of a direct return, otherwise &amp;amp;apos;log&amp;amp;apos;, &amp;amp;apos;ra&amp;amp;apos; and
&amp;amp;apos;log-&amp;amp;gt;one_page_buf&amp;amp;apos; (at least) will leak.(CVE-2021-47660)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;list: fix a data-race around ep-&amp;amp;gt;rdllist&lt;/p&gt;
&lt;p&gt;ep_poll() first calls ep_events_available() with no lock held and checks
if ep-&amp;amp;gt;rdllist is empty by list_empty_careful(), which reads
rdllist-&amp;amp;gt;prev.  Thus all accesses to it need some protection to avoid
store/load-tearing.&lt;/p&gt;
&lt;p&gt;Note INIT_LIST_HEAD_RCU() already has the annotation for both prev
and next.&lt;/p&gt;
&lt;p&gt;Commit bf3b9f6372c4 (&amp;amp;quot;epoll: Add busy poll support to epoll with socket
fds.&amp;amp;quot;) added the first lockless ep_events_available(), and commit
c5a282e9635e (&amp;amp;quot;fs/epoll: reduce the scope of wq lock in epoll_wait()&amp;amp;quot;)
made some ep_events_available() calls lockless and added single call under
a lock, finally commit e59d3c64cba6 (&amp;amp;quot;epoll: eliminate unnecessary lock
for zero timeout&amp;amp;quot;) made the last ep_events_available() lockless.&lt;/p&gt;
&lt;p&gt;BUG: KCSAN: data-race in do_epoll_wait / do_epoll_wait&lt;/p&gt;
&lt;p&gt;write to 0xffff88810480c7d8 of 8 bytes by task 1802 on cpu 0:
 INIT_LIST_HEAD include/linux…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP3: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;fs/ntfs3: Fix some memory leaks in an error handling path of &amp;amp;apos;log_replay()&amp;amp;apos;&lt;/p&gt;
&lt;p&gt;All error handling paths lead to &amp;amp;apos;out&amp;amp;apos; where many resources are freed.&lt;/p&gt;
&lt;p&gt;Do it as well here instead of a direct return, otherwise &amp;amp;apos;log&amp;amp;apos;, &amp;amp;apos;ra&amp;amp;apos; and
&amp;amp;apos;log-&amp;amp;gt;one_page_buf&amp;amp;apos; (at least) will leak.(CVE-2021-47660)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;list: fix a data-race around ep-&amp;amp;gt;rdllist&lt;/p&gt;
&lt;p&gt;ep_poll() first calls ep_events_available() with no lock held and checks
if ep-&amp;amp;gt;rdllist is empty by list_empty_careful(), which reads
rdllist-&amp;amp;gt;prev.  Thus all accesses to it need some protection to avoid
store/load-tearing.&lt;/p&gt;
&lt;p&gt;Note INIT_LIST_HEAD_RCU() already has the annotation for both prev
and next.&lt;/p&gt;
&lt;p&gt;Commit bf3b9f6372c4 (&amp;amp;quot;epoll: Add busy poll support to epoll with socket
fds.&amp;amp;quot;) added the first lockless ep_events_available(), and commit
c5a282e9635e (&amp;amp;quot;fs/epoll: reduce the scope of wq lock in epoll_wait()&amp;amp;quot;)
made some ep_events_available() calls lockless and added single call under
a lock, finally commit e59d3c64cba6 (&amp;amp;quot;epoll: eliminate unnecessary lock
for zero timeout&amp;amp;quot;) made the last ep_events_available() lockless.&lt;/p&gt;
&lt;p&gt;BUG: KCSAN: data-race in do_epoll_wait / do_epoll_wait&lt;/p&gt;
&lt;p&gt;write to 0xffff88810480c7d8 of 8 bytes by task 1802 on cpu 0:
 INIT_LIST_HEAD include/linux…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2025-1409</guid>
    </item>
    <item>
      <title>RHSA-2025:6966 — Red Hat Security Advisory: kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2025:6966</link>
      <description>&lt;p&gt;kernel: xen-netfront: Fix NULL sring after live migration kernel: fscache: Fix oops due to race with cookie_lru and use_cookie kernel: tracing: Free buffers when a used dynamic event is removed kernel: net: tun: Fix use-after-free in tun_detach() kernel: hwmon: (ibmpex) Fix possible UAF when ibmpex_register_bmc() fails kernel: erofs/zmap.c: Fix incorrect offset calculation kernel: arm64/mm: fix incorrect file_map_count for non-leaf pmd/pud kernel: s390: avoid using global register for current_stack_pointer kernel: erofs: fix missing xas_retry() in fscache mode kernel: rpmsg: qcom_smd: Fix refcount leak in qcom_smd_parse_edge kernel: remoteproc: k3-r5: Fix refcount leak in k3_r5_cluster_of_init kernel: of: check previous kernel&amp;#39;s ima-kexec-buffer against memory bounds kernel: coresight: Clear the connection field properly kernel: Linux kernel: Denial of Service in coresight: trbe kernel: rpmsg: char: Avoid double destroy of default endpoint kernel: coresight: cti: Fix hang in cti_disable_hw() kernel: lib/fonts: fix undefined behavior in bit shift for get_default_font kernel: Kernel: Denial of Service in pci_endpoint_test due to zero-length DMA mapping kernel: Linux kernel: Denial of Service in erofs due to memory leak kernel: erofs: fix missing unmap if z_erofs_get_extent_compressedlen() fails kernel: pipe: wakeup wr_wait after setting max_usage kernel: ntb: intel: Fix the NULL vs IS_ERR() bug for debugfs_create_dir() kernel: qed/qed_sriov: guard against NULL derefs from qed_…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;kernel: xen-netfront: Fix NULL sring after live migration kernel: fscache: Fix oops due to race with cookie_lru and use_cookie kernel: tracing: Free buffers when a used dynamic event is removed kernel: net: tun: Fix use-after-free in tun_detach() kernel: hwmon: (ibmpex) Fix possible UAF when ibmpex_register_bmc() fails kernel: erofs/zmap.c: Fix incorrect offset calculation kernel: arm64/mm: fix incorrect file_map_count for non-leaf pmd/pud kernel: s390: avoid using global register for current_stack_pointer kernel: erofs: fix missing xas_retry() in fscache mode kernel: rpmsg: qcom_smd: Fix refcount leak in qcom_smd_parse_edge kernel: remoteproc: k3-r5: Fix refcount leak in k3_r5_cluster_of_init kernel: of: check previous kernel&amp;#39;s ima-kexec-buffer against memory bounds kernel: coresight: Clear the connection field properly kernel: Linux kernel: Denial of Service in coresight: trbe kernel: rpmsg: char: Avoid double destroy of default endpoint kernel: coresight: cti: Fix hang in cti_disable_hw() kernel: lib/fonts: fix undefined behavior in bit shift for get_default_font kernel: Kernel: Denial of Service in pci_endpoint_test due to zero-length DMA mapping kernel: Linux kernel: Denial of Service in erofs due to memory leak kernel: erofs: fix missing unmap if z_erofs_get_extent_compressedlen() fails kernel: pipe: wakeup wr_wait after setting max_usage kernel: ntb: intel: Fix the NULL vs IS_ERR() bug for debugfs_create_dir() kernel: qed/qed_sriov: guard against NULL derefs from qed_…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2025:6966</guid>
    </item>
    <item>
      <title>SUSE-SU-2025:0236-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2025:0236-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2025:0236-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2024-56664</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-56664</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:Pro:18.04:LTS: linux-aws-5.4, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:Pro:18.04:LTS: linux-azure-5.4, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3 and 169 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: bpf, sockmap: Fix race between element replace and close() Element replace (with a socket different from the one stored) may race with socket&amp;#39;s close() link popping &amp;amp; unlinking. __sock_map_delete() unconditionally unrefs the (wrong) element: // set map[0] = s0 map_update_elem(map, 0, s0) // drop fd of s0 close(s0)   sock_map_close()     lock_sock(sk)               (s0!)     sock_map_remove_links(sk)       link = sk_psock_link_pop()       sock_map_unlink(sk, link)         sock_map_delete_from_link                                         // replace map[0] with s1                                         map_update_elem(map, 0, s1)                                           sock_map_update_elem                                 (s1!)       lock_sock(sk)                                             sock_map_update_common                                               psock = sk_psock(sk)                                               spin_lock(&amp;amp;stab-&amp;gt;lock)                                               osk = stab-&amp;gt;sks[idx]                                               sock_map_add_link(..., &amp;amp;stab-&amp;gt;sks[idx])                                               sock_map_unref(osk, &amp;amp;stab-&amp;gt;sks[idx])                                                 psock = sk_psock(osk)                                                 sk_psock_put(sk, psock)                                                   if (refcount_dec_and_test(&amp;amp;psock))…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:Pro:18.04:LTS: linux-aws-5.4, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:Pro:18.04:LTS: linux-azure-5.4, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3 and 169 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: bpf, sockmap: Fix race between element replace and close() Element replace (with a socket different from the one stored) may race with socket&amp;#39;s close() link popping &amp;amp; unlinking. __sock_map_delete() unconditionally unrefs the (wrong) element: // set map[0] = s0 map_update_elem(map, 0, s0) // drop fd of s0 close(s0)   sock_map_close()     lock_sock(sk)               (s0!)     sock_map_remove_links(sk)       link = sk_psock_link_pop()       sock_map_unlink(sk, link)         sock_map_delete_from_link                                         // replace map[0] with s1                                         map_update_elem(map, 0, s1)                                           sock_map_update_elem                                 (s1!)       lock_sock(sk)                                             sock_map_update_common                                               psock = sk_psock(sk)                                               spin_lock(&amp;amp;stab-&amp;gt;lock)                                               osk = stab-&amp;gt;sks[idx]                                               sock_map_add_link(..., &amp;amp;stab-&amp;gt;sks[idx])                                               sock_map_unref(osk, &amp;amp;stab-&amp;gt;sks[idx])                                                 psock = sk_psock(osk)                                                 sk_psock_put(sk, psock)                                                   if (refcount_dec_and_test(&amp;amp;psock))…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-56664</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-3762 — Linux Kernel: Mehrere Schwachstellen ermöglichen Denial of Service</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-3762</link>
      <description>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen in Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen und um nicht näher beschriebene Effekte zu erzielen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen in Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen und um nicht näher beschriebene Effekte zu erzielen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-3762</guid>
    </item>
  </channel>
</rss>
