<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 20:07:50 +0000</lastBuildDate>
    <item>
      <title>ALSA-2025:20095 — Moderate: kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2025:20095</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: kernel, AlmaLinux:10: kernel-64k, AlmaLinux:10: kernel-64k-core, AlmaLinux:10: kernel-64k-debug, AlmaLinux:10: kernel-64k-debug-core, AlmaLinux:10: kernel-64k-debug-devel, AlmaLinux:10: kernel-64k-debug-devel-matched, AlmaLinux:10: kernel-64k-debug-modules, AlmaLinux:10: kernel-64k-debug-modules-core, AlmaLinux:10: kernel-64k-debug-modules-extra and 65 more&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: xen: Xen hypercall page unsafe against speculative attacks (Xen Security Advisory 466) (CVE-2024-53241)
  * kernel: exfat: fix out-of-bounds access of directory entries (CVE-2024-53147)
  * kernel: zram: fix NULL pointer in comp_algorithm_show() (CVE-2024-53222)
  * kernel: nfsd: release svc_expkey/svc_export with rcu_work (CVE-2024-53216)
  * kernel: acpi: nfit: vmalloc-out-of-bounds Read in acpi_nfit_ctl (CVE-2024-56662)
  * kernel: bpf: Fix UAF via mismatching bpf_prog/attachment RCU flavors (CVE-2024-56675)
  * kernel: crypto: pcrypt - Call crypto layer directly when padata_do_parallel() return -EBUSY (CVE-2024-56690)
  * kernel: igb: Fix potential invalid memory access in igb_init_module() (CVE-2024-52332)
  * kernel: af_packet: fix vlan_get_protocol_dgram() vs MSG_PEEK (CVE-2024-57901)
  * kernel: af_packet: fix vlan_get_tci() vs MSG_PEEK (CVE-2024-57902)
  * kernel: io_uring/sqpoll: zero sqd-&amp;gt;thread on tctx errors (CVE-2025-21633)
  * kernel: ipvlan: Fix use-after-free in ipvlan_get_iflink(). (CVE-2025-21652)
  * kernel: sched: sch_cake: add bounds checks to host bulk flow fairness counts (CVE-2025-21647)
  * kernel: io_uring/eventfd: ensure io_eventfd_signal() defers another RCU period (CVE-2025-21655)
  * kernel: netfs: Fix the (non-)cancellation of copy when cache is temporarily disabled (CVE-2024-57941)
  * kernel: netfs: Fix ceph copy to cache…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: kernel, AlmaLinux:10: kernel-64k, AlmaLinux:10: kernel-64k-core, AlmaLinux:10: kernel-64k-debug, AlmaLinux:10: kernel-64k-debug-core, AlmaLinux:10: kernel-64k-debug-devel, AlmaLinux:10: kernel-64k-debug-devel-matched, AlmaLinux:10: kernel-64k-debug-modules, AlmaLinux:10: kernel-64k-debug-modules-core, AlmaLinux:10: kernel-64k-debug-modules-extra and 65 more&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: xen: Xen hypercall page unsafe against speculative attacks (Xen Security Advisory 466) (CVE-2024-53241)
  * kernel: exfat: fix out-of-bounds access of directory entries (CVE-2024-53147)
  * kernel: zram: fix NULL pointer in comp_algorithm_show() (CVE-2024-53222)
  * kernel: nfsd: release svc_expkey/svc_export with rcu_work (CVE-2024-53216)
  * kernel: acpi: nfit: vmalloc-out-of-bounds Read in acpi_nfit_ctl (CVE-2024-56662)
  * kernel: bpf: Fix UAF via mismatching bpf_prog/attachment RCU flavors (CVE-2024-56675)
  * kernel: crypto: pcrypt - Call crypto layer directly when padata_do_parallel() return -EBUSY (CVE-2024-56690)
  * kernel: igb: Fix potential invalid memory access in igb_init_module() (CVE-2024-52332)
  * kernel: af_packet: fix vlan_get_protocol_dgram() vs MSG_PEEK (CVE-2024-57901)
  * kernel: af_packet: fix vlan_get_tci() vs MSG_PEEK (CVE-2024-57902)
  * kernel: io_uring/sqpoll: zero sqd-&amp;gt;thread on tctx errors (CVE-2025-21633)
  * kernel: ipvlan: Fix use-after-free in ipvlan_get_iflink(). (CVE-2025-21652)
  * kernel: sched: sch_cake: add bounds checks to host bulk flow fairness counts (CVE-2025-21647)
  * kernel: io_uring/eventfd: ensure io_eventfd_signal() defers another RCU period (CVE-2025-21655)
  * kernel: netfs: Fix the (non-)cancellation of copy when cache is temporarily disabled (CVE-2024-57941)
  * kernel: netfs: Fix ceph copy to cache…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2025:20095</guid>
    </item>
    <item>
      <title>bdu:2025-02803</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-02803</link>
      <description>bdu:2025-02803</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-02803</guid>
    </item>
    <item>
      <title>BELL-CVE-2025-21652</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2025-21652</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2025-21652</guid>
    </item>
    <item>
      <title>certfr-2025-avi-0133 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de SUSE. Elles permettent à un attaquant de provoqu…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0133</link>
      <description>certfr-2025-avi-0133</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0133</guid>
    </item>
    <item>
      <title>EUVD-2026-346618</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-346618</link>
      <description>EUVD-2026-346618</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-346618</guid>
    </item>
    <item>
      <title>fkie_cve-2025-21652</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-21652</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;ipvlan: Fix use-after-free in ipvlan_get_iflink().&lt;/p&gt;
&lt;p&gt;syzbot presented an use-after-free report [0] regarding ipvlan and
linkwatch.&lt;/p&gt;
&lt;p&gt;ipvlan does not hold a refcnt of the lower device unlike vlan and
macvlan.&lt;/p&gt;
&lt;p&gt;If the linkwatch work is triggered for the ipvlan dev, the lower dev
might have already been freed, resulting in UAF of ipvlan-&amp;gt;phy_dev in
ipvlan_get_iflink().&lt;/p&gt;
&lt;p&gt;We can delay the lower dev unregistration like vlan and macvlan by
holding the lower dev&amp;#39;s refcnt in dev-&amp;gt;netdev_ops-&amp;gt;ndo_init() and
releasing it in dev-&amp;gt;priv_destructor().&lt;/p&gt;
&lt;p&gt;Jakub pointed out calling .ndo_XXX after unregister_netdevice() has
returned is error prone and suggested [1] addressing this UAF in the
core by taking commit 750e51603395 (&amp;#34;net: avoid potential UAF in
default_operstate()&amp;#34;) further.&lt;/p&gt;
&lt;p&gt;Let&amp;#39;s assume unregistering devices DOWN and use RCU protection in
default_operstate() not to race with the device unregistration.&lt;/p&gt;
&lt;p&gt;[0]:
BUG: KASAN: slab-use-after-free in ipvlan_get_iflink+0x84/0x88 drivers/net/ipvlan/ipvlan_main.c:353
Read of size 4 at addr ffff0000d768c0e0 by task kworker/u8:35/6944&lt;/p&gt;
&lt;p&gt;CPU: 0 UID: 0 PID: 6944 Comm: kworker/u8:35 Not tainted 6.13.0-rc2-g9bc5c9515b48 #12 4c3cb9e8b4565456f6a355f312ff91f4f29b3c47
Hardware name: linux,dummy-virt (DT)
Workqueue: events_unbound linkwatch_event
Call trace:
 show_stack+0x38/0x50 arch/arm64/kernel/stacktrace.c:484 (C)
 __dump_stack lib/dump_stack.c:94 [inline]
 dump_stack_lvl+0xbc/0x108 li…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;ipvlan: Fix use-after-free in ipvlan_get_iflink().&lt;/p&gt;
&lt;p&gt;syzbot presented an use-after-free report [0] regarding ipvlan and
linkwatch.&lt;/p&gt;
&lt;p&gt;ipvlan does not hold a refcnt of the lower device unlike vlan and
macvlan.&lt;/p&gt;
&lt;p&gt;If the linkwatch work is triggered for the ipvlan dev, the lower dev
might have already been freed, resulting in UAF of ipvlan-&amp;gt;phy_dev in
ipvlan_get_iflink().&lt;/p&gt;
&lt;p&gt;We can delay the lower dev unregistration like vlan and macvlan by
holding the lower dev&amp;#39;s refcnt in dev-&amp;gt;netdev_ops-&amp;gt;ndo_init() and
releasing it in dev-&amp;gt;priv_destructor().&lt;/p&gt;
&lt;p&gt;Jakub pointed out calling .ndo_XXX after unregister_netdevice() has
returned is error prone and suggested [1] addressing this UAF in the
core by taking commit 750e51603395 (&amp;#34;net: avoid potential UAF in
default_operstate()&amp;#34;) further.&lt;/p&gt;
&lt;p&gt;Let&amp;#39;s assume unregistering devices DOWN and use RCU protection in
default_operstate() not to race with the device unregistration.&lt;/p&gt;
&lt;p&gt;[0]:
BUG: KASAN: slab-use-after-free in ipvlan_get_iflink+0x84/0x88 drivers/net/ipvlan/ipvlan_main.c:353
Read of size 4 at addr ffff0000d768c0e0 by task kworker/u8:35/6944&lt;/p&gt;
&lt;p&gt;CPU: 0 UID: 0 PID: 6944 Comm: kworker/u8:35 Not tainted 6.13.0-rc2-g9bc5c9515b48 #12 4c3cb9e8b4565456f6a355f312ff91f4f29b3c47
Hardware name: linux,dummy-virt (DT)
Workqueue: events_unbound linkwatch_event
Call trace:
 show_stack+0x38/0x50 arch/arm64/kernel/stacktrace.c:484 (C)
 __dump_stack lib/dump_stack.c:94 [inline]
 dump_stack_lvl+0xbc/0x108 li…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-21652</guid>
    </item>
    <item>
      <title>GHSA-p277-wqpc-75vw</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-p277-wqpc-75vw</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;ipvlan: Fix use-after-free in ipvlan_get_iflink().&lt;/p&gt;
&lt;p&gt;syzbot presented an use-after-free report [0] regarding ipvlan and
linkwatch.&lt;/p&gt;
&lt;p&gt;ipvlan does not hold a refcnt of the lower device unlike vlan and
macvlan.&lt;/p&gt;
&lt;p&gt;If the linkwatch work is triggered for the ipvlan dev, the lower dev
might have already been freed, resulting in UAF of ipvlan-&amp;gt;phy_dev in
ipvlan_get_iflink().&lt;/p&gt;
&lt;p&gt;We can delay the lower dev unregistration like vlan and macvlan by
holding the lower dev&amp;#39;s refcnt in dev-&amp;gt;netdev_ops-&amp;gt;ndo_init() and
releasing it in dev-&amp;gt;priv_destructor().&lt;/p&gt;
&lt;p&gt;Jakub pointed out calling .ndo_XXX after unregister_netdevice() has
returned is error prone and suggested [1] addressing this UAF in the
core by taking commit 750e51603395 (&amp;#34;net: avoid potential UAF in
default_operstate()&amp;#34;) further.&lt;/p&gt;
&lt;p&gt;Let&amp;#39;s assume unregistering devices DOWN and use RCU protection in
default_operstate() not to race with the device unregistration.&lt;/p&gt;
&lt;p&gt;[0]:
BUG: KASAN: slab-use-after-free in ipvlan_get_iflink+0x84/0x88 drivers/net/ipvlan/ipvlan_main.c:353
Read of size 4 at addr ffff0000d768c0e0 by task kworker/u8:35/6944&lt;/p&gt;
&lt;p&gt;CPU: 0 UID: 0 PID: 6944 Comm: kworker/u8:35 Not tainted 6.13.0-rc2-g9bc5c9515b48 #12 4c3cb9e8b4565456f6a355f312ff91f4f29b3c47
Hardware name: linux,dummy-virt (DT)
Workqueue: events_unbound linkwatch_event
Call trace:
 show_stack+0x38/0x50 arch/arm64/kernel/stacktrace.c:484 (C)
 __dump_stack lib/dump_stack.c:94 [inline]
 dump_stack_lvl+0xbc/0x108 li…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;ipvlan: Fix use-after-free in ipvlan_get_iflink().&lt;/p&gt;
&lt;p&gt;syzbot presented an use-after-free report [0] regarding ipvlan and
linkwatch.&lt;/p&gt;
&lt;p&gt;ipvlan does not hold a refcnt of the lower device unlike vlan and
macvlan.&lt;/p&gt;
&lt;p&gt;If the linkwatch work is triggered for the ipvlan dev, the lower dev
might have already been freed, resulting in UAF of ipvlan-&amp;gt;phy_dev in
ipvlan_get_iflink().&lt;/p&gt;
&lt;p&gt;We can delay the lower dev unregistration like vlan and macvlan by
holding the lower dev&amp;#39;s refcnt in dev-&amp;gt;netdev_ops-&amp;gt;ndo_init() and
releasing it in dev-&amp;gt;priv_destructor().&lt;/p&gt;
&lt;p&gt;Jakub pointed out calling .ndo_XXX after unregister_netdevice() has
returned is error prone and suggested [1] addressing this UAF in the
core by taking commit 750e51603395 (&amp;#34;net: avoid potential UAF in
default_operstate()&amp;#34;) further.&lt;/p&gt;
&lt;p&gt;Let&amp;#39;s assume unregistering devices DOWN and use RCU protection in
default_operstate() not to race with the device unregistration.&lt;/p&gt;
&lt;p&gt;[0]:
BUG: KASAN: slab-use-after-free in ipvlan_get_iflink+0x84/0x88 drivers/net/ipvlan/ipvlan_main.c:353
Read of size 4 at addr ffff0000d768c0e0 by task kworker/u8:35/6944&lt;/p&gt;
&lt;p&gt;CPU: 0 UID: 0 PID: 6944 Comm: kworker/u8:35 Not tainted 6.13.0-rc2-g9bc5c9515b48 #12 4c3cb9e8b4565456f6a355f312ff91f4f29b3c47
Hardware name: linux,dummy-virt (DT)
Workqueue: events_unbound linkwatch_event
Call trace:
 show_stack+0x38/0x50 arch/arm64/kernel/stacktrace.c:484 (C)
 __dump_stack lib/dump_stack.c:94 [inline]
 dump_stack_lvl+0xbc/0x108 li…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-p277-wqpc-75vw</guid>
    </item>
    <item>
      <title>msrc_CVE-2025-21652 — ipvlan: Fix use-after-free in ipvlan_get_iflink().</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2025-21652</link>
      <description>msrc_CVE-2025-21652</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2025-21652</guid>
    </item>
    <item>
      <title>OESA-2026-1228 — kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-1228</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;net: fec: remove .ndo_poll_controller to avoid deadlocks&lt;/p&gt;
&lt;p&gt;There is a deadlock issue found in sungem driver, please refer to the
commit ac0a230f719b (&amp;amp;quot;eth: sungem: remove .ndo_poll_controller to avoid
deadlocks&amp;amp;quot;). The root cause of the issue is that netpoll is in atomic
context and disable_irq() is called by .ndo_poll_controller interface
of sungem driver, however, disable_irq() might sleep. After analyzing
the implementation of fec_poll_controller(), the fec driver should have
the same issue. Due to the fec driver uses NAPI for TX completions, the
.ndo_poll_controller is unnecessary to be implemented in the fec driver,
so fec_poll_controller() can be safely removed.(CVE-2024-38553)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;ceph: give up on paths longer than PATH_MAX&lt;/p&gt;
&lt;p&gt;If the full path to be built by ceph_mdsc_build_path() happens to be
longer than PATH_MAX, then this function will enter an endless (retry)
loop, effectively blocking the whole task.  Most of the machine
becomes unusable, making this a very simple and effective DoS
vulnerability.&lt;/p&gt;
&lt;p&gt;I cannot imagine why this retry was ever implemented, but it seems
rather useless and harmful to me.  Let&amp;amp;apos;s remove it and fail with
ENAMETOOLONG instead.(CVE-2024-53685)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;Bluetooth: hc…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;net: fec: remove .ndo_poll_controller to avoid deadlocks&lt;/p&gt;
&lt;p&gt;There is a deadlock issue found in sungem driver, please refer to the
commit ac0a230f719b (&amp;amp;quot;eth: sungem: remove .ndo_poll_controller to avoid
deadlocks&amp;amp;quot;). The root cause of the issue is that netpoll is in atomic
context and disable_irq() is called by .ndo_poll_controller interface
of sungem driver, however, disable_irq() might sleep. After analyzing
the implementation of fec_poll_controller(), the fec driver should have
the same issue. Due to the fec driver uses NAPI for TX completions, the
.ndo_poll_controller is unnecessary to be implemented in the fec driver,
so fec_poll_controller() can be safely removed.(CVE-2024-38553)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;ceph: give up on paths longer than PATH_MAX&lt;/p&gt;
&lt;p&gt;If the full path to be built by ceph_mdsc_build_path() happens to be
longer than PATH_MAX, then this function will enter an endless (retry)
loop, effectively blocking the whole task.  Most of the machine
becomes unusable, making this a very simple and effective DoS
vulnerability.&lt;/p&gt;
&lt;p&gt;I cannot imagine why this retry was ever implemented, but it seems
rather useless and harmful to me.  Let&amp;amp;apos;s remove it and fail with
ENAMETOOLONG instead.(CVE-2024-53685)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;Bluetooth: hc…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-1228</guid>
    </item>
    <item>
      <title>RHSA-2025:20095 — Red Hat Security Advisory: kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2025:20095</link>
      <description>&lt;p&gt;microcode_ctl: From CVEorg collector kernel: information leak via transient execution vulnerability in some AMD processors kernel: transient execution vulnerability in some AMD processors kernel: drm/xe/tracing: Fix a potential TP_printk UAF kernel: igb: Fix potential invalid memory access in igb_init_module() kernel: exfat: fix out-of-bounds access of directory entries kernel: nfsd: release svc_expkey/svc_export with rcu_work kernel: zram: fix NULL pointer in comp_algorithm_show() kernel: xen: Xen hypercall page unsafe against speculative attacks (Xen Security Advisory 466) kernel: NFS: Fix potential buffer overflowin nfs_sysfs_link_rpc_client() kernel: acpi: nfit: vmalloc-out-of-bounds Read in acpi_nfit_ctl kernel: bpf: Fix UAF via mismatching bpf_prog/attachment RCU flavors kernel: crypto: pcrypt - Call crypto layer directly when padata_do_parallel() return -EBUSY kernel: af_packet: fix vlan_get_protocol_dgram() vs MSG_PEEK kernel: af_packet: fix vlan_get_tci() vs MSG_PEEK kernel: netfs: Fix the (non-)cancellation of copy when cache is temporarily disabled kernel: netfs: Fix ceph copy to cache on write-begin kernel: memcg: fix soft lockup in the OOM process kernel: usb: xhci: Fix NULL pointer dereference on certain command aborts kernel: xfrm: state: fix out-of-bounds read during lookup kernel: i3c: dw: Fix use-after-free in dw_i3c_master driver due to race condition kernel: HID: core: Fix assumption that Resolution Multipliers must be in Logical Collections kernel: Bluet…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;microcode_ctl: From CVEorg collector kernel: information leak via transient execution vulnerability in some AMD processors kernel: transient execution vulnerability in some AMD processors kernel: drm/xe/tracing: Fix a potential TP_printk UAF kernel: igb: Fix potential invalid memory access in igb_init_module() kernel: exfat: fix out-of-bounds access of directory entries kernel: nfsd: release svc_expkey/svc_export with rcu_work kernel: zram: fix NULL pointer in comp_algorithm_show() kernel: xen: Xen hypercall page unsafe against speculative attacks (Xen Security Advisory 466) kernel: NFS: Fix potential buffer overflowin nfs_sysfs_link_rpc_client() kernel: acpi: nfit: vmalloc-out-of-bounds Read in acpi_nfit_ctl kernel: bpf: Fix UAF via mismatching bpf_prog/attachment RCU flavors kernel: crypto: pcrypt - Call crypto layer directly when padata_do_parallel() return -EBUSY kernel: af_packet: fix vlan_get_protocol_dgram() vs MSG_PEEK kernel: af_packet: fix vlan_get_tci() vs MSG_PEEK kernel: netfs: Fix the (non-)cancellation of copy when cache is temporarily disabled kernel: netfs: Fix ceph copy to cache on write-begin kernel: memcg: fix soft lockup in the OOM process kernel: usb: xhci: Fix NULL pointer dereference on certain command aborts kernel: xfrm: state: fix out-of-bounds read during lookup kernel: i3c: dw: Fix use-after-free in dw_i3c_master driver due to race condition kernel: HID: core: Fix assumption that Resolution Multipliers must be in Logical Collections kernel: Bluet…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2025:20095</guid>
    </item>
    <item>
      <title>SUSE-SU-2025:0428-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2025:0428-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2025:0428-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-21652</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-21652</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 105 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: ipvlan: Fix use-after-free in ipvlan_get_iflink(). syzbot presented an use-after-free report [0] regarding ipvlan and linkwatch. ipvlan does not hold a refcnt of the lower device unlike vlan and macvlan. If the linkwatch work is triggered for the ipvlan dev, the lower dev might have already been freed, resulting in UAF of ipvlan-&amp;gt;phy_dev in ipvlan_get_iflink(). We can delay the lower dev unregistration like vlan and macvlan by holding the lower dev&amp;#39;s refcnt in dev-&amp;gt;netdev_ops-&amp;gt;ndo_init() and releasing it in dev-&amp;gt;priv_destructor(). Jakub pointed out calling .ndo_XXX after unregister_netdevice() has returned is error prone and suggested [1] addressing this UAF in the core by taking commit 750e51603395 (&amp;#34;net: avoid potential UAF in default_operstate()&amp;#34;) further. Let&amp;#39;s assume unregistering devices DOWN and use RCU protection in default_operstate() not to race with the device unregistration. [0]: BUG: KASAN: slab-use-after-free in ipvlan_get_iflink+0x84/0x88 drivers/net/ipvlan/ipvlan_main.c:353 Read of size 4 at addr ffff0000d768c0e0 by task kworker/u8:35/6944 CPU: 0 UID: 0 PID: 6944 Comm: kworker/u8:35 Not tainted 6.13.0-rc2-g9bc5c9515b48 #12 4c3cb9e8b4565456f6a355f312ff91f4f29b3c47 Hardware name: linux,dummy-virt (DT) Workqueue: events_unbound linkwatch_event Call trace:  show_stack+0x38/0x50 arch/arm64/kernel/stacktrace.c:484 (C)  __dump_stack lib/dump_stack.c:94 [inline]  dump_stack_lvl+0xbc/0x108 lib/dump_st…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 105 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: ipvlan: Fix use-after-free in ipvlan_get_iflink(). syzbot presented an use-after-free report [0] regarding ipvlan and linkwatch. ipvlan does not hold a refcnt of the lower device unlike vlan and macvlan. If the linkwatch work is triggered for the ipvlan dev, the lower dev might have already been freed, resulting in UAF of ipvlan-&amp;gt;phy_dev in ipvlan_get_iflink(). We can delay the lower dev unregistration like vlan and macvlan by holding the lower dev&amp;#39;s refcnt in dev-&amp;gt;netdev_ops-&amp;gt;ndo_init() and releasing it in dev-&amp;gt;priv_destructor(). Jakub pointed out calling .ndo_XXX after unregister_netdevice() has returned is error prone and suggested [1] addressing this UAF in the core by taking commit 750e51603395 (&amp;#34;net: avoid potential UAF in default_operstate()&amp;#34;) further. Let&amp;#39;s assume unregistering devices DOWN and use RCU protection in default_operstate() not to race with the device unregistration. [0]: BUG: KASAN: slab-use-after-free in ipvlan_get_iflink+0x84/0x88 drivers/net/ipvlan/ipvlan_main.c:353 Read of size 4 at addr ffff0000d768c0e0 by task kworker/u8:35/6944 CPU: 0 UID: 0 PID: 6944 Comm: kworker/u8:35 Not tainted 6.13.0-rc2-g9bc5c9515b48 #12 4c3cb9e8b4565456f6a355f312ff91f4f29b3c47 Hardware name: linux,dummy-virt (DT) Workqueue: events_unbound linkwatch_event Call trace:  show_stack+0x38/0x50 arch/arm64/kernel/stacktrace.c:484 (C)  __dump_stack lib/dump_stack.c:94 [inline]  dump_stack_lvl+0xbc/0x108 lib/dump_st…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-21652</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-0119 — Linux Kernel: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0119</link>
      <description>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen oder andere nicht spezifizierte Auswirkungen zu verursachen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen oder andere nicht spezifizierte Auswirkungen zu verursachen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0119</guid>
    </item>
  </channel>
</rss>
