<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 13:48:49 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-02669</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-02669</link>
      <description>bdu:2026-02669</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-02669</guid>
    </item>
    <item>
      <title>BELL-CVE-2025-21656</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2025-21656</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2025-21656</guid>
    </item>
    <item>
      <title>certfr-2025-avi-0088 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de SUSE. Certaines d'entre elles permettent à un at…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0088</link>
      <description>certfr-2025-avi-0088</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0088</guid>
    </item>
    <item>
      <title>EUVD-2026-313992</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-313992</link>
      <description>EUVD-2026-313992</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-313992</guid>
    </item>
    <item>
      <title>fkie_cve-2025-21656</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-21656</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;hwmon: (drivetemp) Fix driver producing garbage data when SCSI errors occur&lt;/p&gt;
&lt;p&gt;scsi_execute_cmd() function can return both negative (linux codes) and
positive (scsi_cmnd result field) error codes.&lt;/p&gt;
&lt;p&gt;Currently the driver just passes error codes of scsi_execute_cmd() to
hwmon core, which is incorrect because hwmon only checks for negative
error codes. This leads to hwmon reporting uninitialized data to
userspace in case of SCSI errors (for example if the disk drive was
disconnected).&lt;/p&gt;
&lt;p&gt;This patch checks scsi_execute_cmd() output and returns -EIO if it&amp;#39;s
error code is positive.&lt;/p&gt;
&lt;p&gt;[groeck: Avoid inline variable declaration for portability]&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;hwmon: (drivetemp) Fix driver producing garbage data when SCSI errors occur&lt;/p&gt;
&lt;p&gt;scsi_execute_cmd() function can return both negative (linux codes) and
positive (scsi_cmnd result field) error codes.&lt;/p&gt;
&lt;p&gt;Currently the driver just passes error codes of scsi_execute_cmd() to
hwmon core, which is incorrect because hwmon only checks for negative
error codes. This leads to hwmon reporting uninitialized data to
userspace in case of SCSI errors (for example if the disk drive was
disconnected).&lt;/p&gt;
&lt;p&gt;This patch checks scsi_execute_cmd() output and returns -EIO if it&amp;#39;s
error code is positive.&lt;/p&gt;
&lt;p&gt;[groeck: Avoid inline variable declaration for portability]&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-21656</guid>
    </item>
    <item>
      <title>GHSA-2g47-jxc2-73xh</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-2g47-jxc2-73xh</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;hwmon: (drivetemp) Fix driver producing garbage data when SCSI errors occur&lt;/p&gt;
&lt;p&gt;scsi_execute_cmd() function can return both negative (linux codes) and
positive (scsi_cmnd result field) error codes.&lt;/p&gt;
&lt;p&gt;Currently the driver just passes error codes of scsi_execute_cmd() to
hwmon core, which is incorrect because hwmon only checks for negative
error codes. This leads to hwmon reporting uninitialized data to
userspace in case of SCSI errors (for example if the disk drive was
disconnected).&lt;/p&gt;
&lt;p&gt;This patch checks scsi_execute_cmd() output and returns -EIO if it&amp;#39;s
error code is positive.&lt;/p&gt;
&lt;p&gt;[groeck: Avoid inline variable declaration for portability]&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;hwmon: (drivetemp) Fix driver producing garbage data when SCSI errors occur&lt;/p&gt;
&lt;p&gt;scsi_execute_cmd() function can return both negative (linux codes) and
positive (scsi_cmnd result field) error codes.&lt;/p&gt;
&lt;p&gt;Currently the driver just passes error codes of scsi_execute_cmd() to
hwmon core, which is incorrect because hwmon only checks for negative
error codes. This leads to hwmon reporting uninitialized data to
userspace in case of SCSI errors (for example if the disk drive was
disconnected).&lt;/p&gt;
&lt;p&gt;This patch checks scsi_execute_cmd() output and returns -EIO if it&amp;#39;s
error code is positive.&lt;/p&gt;
&lt;p&gt;[groeck: Avoid inline variable declaration for portability]&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-2g47-jxc2-73xh</guid>
    </item>
    <item>
      <title>msrc_CVE-2025-21656 — hwmon: (drivetemp) Fix driver producing garbage data when SCSI errors occur</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2025-21656</link>
      <description>msrc_CVE-2025-21656</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2025-21656</guid>
    </item>
    <item>
      <title>OESA-2025-1204 — kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2025-1204</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;bpf: Prevent tailcall infinite loop caused by freplace&lt;/p&gt;
&lt;p&gt;There is a potential infinite loop issue that can occur when using a
combination of tail calls and freplace.&lt;/p&gt;
&lt;p&gt;In an upcoming selftest, the attach target for entry_freplace of
tailcall_freplace.c is subprog_tc of tc_bpf2bpf.c, while the tail call in
entry_freplace leads to entry_tc. This results in an infinite loop:&lt;/p&gt;
&lt;p&gt;entry_tc -&amp;amp;gt; subprog_tc -&amp;amp;gt; entry_freplace --tailcall-&amp;amp;gt; entry_tc.&lt;/p&gt;
&lt;p&gt;The problem arises because the tail_call_cnt in entry_freplace resets to
zero each time entry_freplace is executed, causing the tail call mechanism
to never terminate, eventually leading to a kernel panic.&lt;/p&gt;
&lt;p&gt;To fix this issue, the solution is twofold:&lt;/p&gt;
&lt;p&gt;1. Prevent updating a program extended by an freplace program to a
   prog_array map.
2. Prevent extending a program that is already part of a prog_array map
   with an freplace program.&lt;/p&gt;
&lt;p&gt;This ensures that:&lt;/p&gt;
&lt;p&gt;* If a program or its subprogram has been extended by an freplace program,
  it can no longer be updated to a prog_array map.
* If a program has been added to a prog_array map, neither it nor its
  subprograms can be extended by an freplace program.&lt;/p&gt;
&lt;p&gt;Moreover, an extension program should not be tailcalled. As such, return
-EINVAL if the program has a type of BPF_PROG_TYPE_EXT when adding it to a
prog_array map.&lt;/p&gt;
&lt;p&gt;Additionally, fix a minor code s…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;bpf: Prevent tailcall infinite loop caused by freplace&lt;/p&gt;
&lt;p&gt;There is a potential infinite loop issue that can occur when using a
combination of tail calls and freplace.&lt;/p&gt;
&lt;p&gt;In an upcoming selftest, the attach target for entry_freplace of
tailcall_freplace.c is subprog_tc of tc_bpf2bpf.c, while the tail call in
entry_freplace leads to entry_tc. This results in an infinite loop:&lt;/p&gt;
&lt;p&gt;entry_tc -&amp;amp;gt; subprog_tc -&amp;amp;gt; entry_freplace --tailcall-&amp;amp;gt; entry_tc.&lt;/p&gt;
&lt;p&gt;The problem arises because the tail_call_cnt in entry_freplace resets to
zero each time entry_freplace is executed, causing the tail call mechanism
to never terminate, eventually leading to a kernel panic.&lt;/p&gt;
&lt;p&gt;To fix this issue, the solution is twofold:&lt;/p&gt;
&lt;p&gt;1. Prevent updating a program extended by an freplace program to a
   prog_array map.
2. Prevent extending a program that is already part of a prog_array map
   with an freplace program.&lt;/p&gt;
&lt;p&gt;This ensures that:&lt;/p&gt;
&lt;p&gt;* If a program or its subprogram has been extended by an freplace program,
  it can no longer be updated to a prog_array map.
* If a program has been added to a prog_array map, neither it nor its
  subprograms can be extended by an freplace program.&lt;/p&gt;
&lt;p&gt;Moreover, an extension program should not be tailcalled. As such, return
-EINVAL if the program has a type of BPF_PROG_TYPE_EXT when adding it to a
prog_array map.&lt;/p&gt;
&lt;p&gt;Additionally, fix a minor code s…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2025-1204</guid>
    </item>
    <item>
      <title>SUSE-SU-2025:0289-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2025:0289-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2025:0289-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-21656</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-21656</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 144 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: hwmon: (drivetemp) Fix driver producing garbage data when SCSI errors occur scsi_execute_cmd() function can return both negative (linux codes) and positive (scsi_cmnd result field) error codes. Currently the driver just passes error codes of scsi_execute_cmd() to hwmon core, which is incorrect because hwmon only checks for negative error codes. This leads to hwmon reporting uninitialized data to userspace in case of SCSI errors (for example if the disk drive was disconnected). This patch checks scsi_execute_cmd() output and returns -EIO if it&amp;#39;s error code is positive. [groeck: Avoid inline variable declaration for portability]&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 144 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: hwmon: (drivetemp) Fix driver producing garbage data when SCSI errors occur scsi_execute_cmd() function can return both negative (linux codes) and positive (scsi_cmnd result field) error codes. Currently the driver just passes error codes of scsi_execute_cmd() to hwmon core, which is incorrect because hwmon only checks for negative error codes. This leads to hwmon reporting uninitialized data to userspace in case of SCSI errors (for example if the disk drive was disconnected). This patch checks scsi_execute_cmd() output and returns -EIO if it&amp;#39;s error code is positive. [groeck: Avoid inline variable declaration for portability]&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-21656</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-0155 — Linux Kernel: Mehrere Schwachstellen ermöglichen Denial of Service</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0155</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen und um nicht näher beschriebene Auswirkungen zu erzielen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen und um nicht näher beschriebene Auswirkungen zu erzielen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0155</guid>
    </item>
  </channel>
</rss>
