<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 11:22:37 +0000</lastBuildDate>
    <item>
      <title>bdu:2025-02204</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-02204</link>
      <description>bdu:2025-02204</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-02204</guid>
    </item>
    <item>
      <title>BELL-CVE-2025-21703</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2025-21703</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2025-21703</guid>
    </item>
    <item>
      <title>certfr-2025-avi-0277 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de Debian LTS. Elles permettent à un attaquant de p…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0277</link>
      <description>certfr-2025-avi-0277</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0277</guid>
    </item>
    <item>
      <title>EUVD-2026-346635</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-346635</link>
      <description>EUVD-2026-346635</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-346635</guid>
    </item>
    <item>
      <title>fkie_cve-2025-21703</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-21703</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;netem: Update sch-&amp;gt;q.qlen before qdisc_tree_reduce_backlog()&lt;/p&gt;
&lt;p&gt;qdisc_tree_reduce_backlog() notifies parent qdisc only if child
qdisc becomes empty, therefore we need to reduce the backlog of the
child qdisc before calling it. Otherwise it would miss the opportunity
to call cops-&amp;gt;qlen_notify(), in the case of DRR, it resulted in UAF
since DRR uses -&amp;gt;qlen_notify() to maintain its active list.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;netem: Update sch-&amp;gt;q.qlen before qdisc_tree_reduce_backlog()&lt;/p&gt;
&lt;p&gt;qdisc_tree_reduce_backlog() notifies parent qdisc only if child
qdisc becomes empty, therefore we need to reduce the backlog of the
child qdisc before calling it. Otherwise it would miss the opportunity
to call cops-&amp;gt;qlen_notify(), in the case of DRR, it resulted in UAF
since DRR uses -&amp;gt;qlen_notify() to maintain its active list.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-21703</guid>
    </item>
    <item>
      <title>GHSA-cg86-m5xc-jqrm</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-cg86-m5xc-jqrm</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;netem: Update sch-&amp;gt;q.qlen before qdisc_tree_reduce_backlog()&lt;/p&gt;
&lt;p&gt;qdisc_tree_reduce_backlog() notifies parent qdisc only if child
qdisc becomes empty, therefore we need to reduce the backlog of the
child qdisc before calling it. Otherwise it would miss the opportunity
to call cops-&amp;gt;qlen_notify(), in the case of DRR, it resulted in UAF
since DRR uses -&amp;gt;qlen_notify() to maintain its active list.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;netem: Update sch-&amp;gt;q.qlen before qdisc_tree_reduce_backlog()&lt;/p&gt;
&lt;p&gt;qdisc_tree_reduce_backlog() notifies parent qdisc only if child
qdisc becomes empty, therefore we need to reduce the backlog of the
child qdisc before calling it. Otherwise it would miss the opportunity
to call cops-&amp;gt;qlen_notify(), in the case of DRR, it resulted in UAF
since DRR uses -&amp;gt;qlen_notify() to maintain its active list.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-cg86-m5xc-jqrm</guid>
    </item>
    <item>
      <title>ICSA-25-072-03 — Siemens SIMATIC S7-1500 TM MFP</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-25-072-03</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&#13;
Squashfs: check the inode number is not the invalid value of zero In the Linux kernel, the following vulnerability has been resolved: net: ethernet: lantiq_etop: fix double free in detach The number of the currently released descriptor is never incremented which results in the same skb being released multiple times. In the Linux kernel, the following vulnerability has been resolved: filelock: fix potential use-after-free in posix_lock_inode Light Hsieh reported a KASAN UAF warning in trace_posix_lock_inode(). The request pointer had been changed earlier to point to a lock entry that was added to the inode&amp;#39;s list. However, before the tracepoint could fire, another task raced in and freed that lock. Fix this by moving the tracepoint inside the spinlock, which should ensure that this doesn&amp;#39;t happen. In the Linux kernel, the following vulnerability has been resolved: mm: prevent derefencing NULL ptr in pfn_section_valid() Commit 5ec8e8ea8b77 (&amp;#34;mm/sparsemem: fix race in accessing memory_section-&amp;gt;usage&amp;#34;) changed pfn_section_valid() to add a READ_ONCE() call around &amp;#34;ms-&amp;gt;usage&amp;#34; to fix a race with section_deactivate() where ms-&amp;gt;usage can be cleared. The READ_ONCE() call, by itself, is not enough to prevent NULL pointer dereference. We need to check its value before dereferencing it. In the Linux kernel, the following vulnerability has been resolved: tcp_metrics: validate source addr length I don&amp;#39;t see anything check…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&#13;
Squashfs: check the inode number is not the invalid value of zero In the Linux kernel, the following vulnerability has been resolved: net: ethernet: lantiq_etop: fix double free in detach The number of the currently released descriptor is never incremented which results in the same skb being released multiple times. In the Linux kernel, the following vulnerability has been resolved: filelock: fix potential use-after-free in posix_lock_inode Light Hsieh reported a KASAN UAF warning in trace_posix_lock_inode(). The request pointer had been changed earlier to point to a lock entry that was added to the inode&amp;#39;s list. However, before the tracepoint could fire, another task raced in and freed that lock. Fix this by moving the tracepoint inside the spinlock, which should ensure that this doesn&amp;#39;t happen. In the Linux kernel, the following vulnerability has been resolved: mm: prevent derefencing NULL ptr in pfn_section_valid() Commit 5ec8e8ea8b77 (&amp;#34;mm/sparsemem: fix race in accessing memory_section-&amp;gt;usage&amp;#34;) changed pfn_section_valid() to add a READ_ONCE() call around &amp;#34;ms-&amp;gt;usage&amp;#34; to fix a race with section_deactivate() where ms-&amp;gt;usage can be cleared. The READ_ONCE() call, by itself, is not enough to prevent NULL pointer dereference. We need to check its value before dereferencing it. In the Linux kernel, the following vulnerability has been resolved: tcp_metrics: validate source addr length I don&amp;#39;t see anything check…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-25-072-03</guid>
    </item>
    <item>
      <title>msrc_CVE-2025-21703 — netem: Update sch-&gt;q.qlen before qdisc_tree_reduce_backlog()</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2025-21703</link>
      <description>msrc_CVE-2025-21703</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2025-21703</guid>
    </item>
    <item>
      <title>OESA-2025-1874 — kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2025-1874</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;pfifo_tail_enqueue: Drop new packet when sch-&amp;amp;gt;limit == 0&lt;/p&gt;
&lt;p&gt;Expected behaviour:
In case we reach scheduler&amp;amp;apos;s limit, pfifo_tail_enqueue() will drop a
packet in scheduler&amp;amp;apos;s queue and decrease scheduler&amp;amp;apos;s qlen by one.
Then, pfifo_tail_enqueue() enqueue new packet and increase
scheduler&amp;amp;apos;s qlen by one. Finally, pfifo_tail_enqueue() return
`NET_XMIT_CN` status code.&lt;/p&gt;
&lt;p&gt;Weird behaviour:
In case we set `sch-&amp;amp;gt;limit == 0` and trigger pfifo_tail_enqueue() on a
scheduler that has no packet, the &amp;amp;apos;drop a packet&amp;amp;apos; step will do nothing.
This means the scheduler&amp;amp;apos;s qlen still has value equal 0.
Then, we continue to enqueue new packet and increase scheduler&amp;amp;apos;s qlen by
one. In summary, we can leverage pfifo_tail_enqueue() to increase qlen by
one and return `NET_XMIT_CN` status code.&lt;/p&gt;
&lt;p&gt;The problem is:
Let&amp;amp;apos;s say we have two qdiscs: Qdisc_A and Qdisc_B.
 - Qdisc_A&amp;amp;apos;s type must have &amp;amp;apos;-&amp;amp;gt;graft()&amp;amp;apos; function to create parent/child relationship.
   Let&amp;amp;apos;s say Qdisc_A&amp;amp;apos;s type is `hfsc`. Enqueue packet to this qdisc will trigger `hfsc_enqueue`.
 - Qdisc_B&amp;amp;apos;s type is pfifo_head_drop. Enqueue packet to this qdisc will trigger `pfifo_tail_enqueue`.
 - Qdisc_B is configured to have `sch-&amp;amp;gt;limit == 0`.
 - Qdisc_A is configured to route the enqueued&amp;amp;apos;s packet to Qdisc_B.&lt;/p&gt;
&lt;p&gt;Enqueue packet through…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;pfifo_tail_enqueue: Drop new packet when sch-&amp;amp;gt;limit == 0&lt;/p&gt;
&lt;p&gt;Expected behaviour:
In case we reach scheduler&amp;amp;apos;s limit, pfifo_tail_enqueue() will drop a
packet in scheduler&amp;amp;apos;s queue and decrease scheduler&amp;amp;apos;s qlen by one.
Then, pfifo_tail_enqueue() enqueue new packet and increase
scheduler&amp;amp;apos;s qlen by one. Finally, pfifo_tail_enqueue() return
`NET_XMIT_CN` status code.&lt;/p&gt;
&lt;p&gt;Weird behaviour:
In case we set `sch-&amp;amp;gt;limit == 0` and trigger pfifo_tail_enqueue() on a
scheduler that has no packet, the &amp;amp;apos;drop a packet&amp;amp;apos; step will do nothing.
This means the scheduler&amp;amp;apos;s qlen still has value equal 0.
Then, we continue to enqueue new packet and increase scheduler&amp;amp;apos;s qlen by
one. In summary, we can leverage pfifo_tail_enqueue() to increase qlen by
one and return `NET_XMIT_CN` status code.&lt;/p&gt;
&lt;p&gt;The problem is:
Let&amp;amp;apos;s say we have two qdiscs: Qdisc_A and Qdisc_B.
 - Qdisc_A&amp;amp;apos;s type must have &amp;amp;apos;-&amp;amp;gt;graft()&amp;amp;apos; function to create parent/child relationship.
   Let&amp;amp;apos;s say Qdisc_A&amp;amp;apos;s type is `hfsc`. Enqueue packet to this qdisc will trigger `hfsc_enqueue`.
 - Qdisc_B&amp;amp;apos;s type is pfifo_head_drop. Enqueue packet to this qdisc will trigger `pfifo_tail_enqueue`.
 - Qdisc_B is configured to have `sch-&amp;amp;gt;limit == 0`.
 - Qdisc_A is configured to route the enqueued&amp;amp;apos;s packet to Qdisc_B.&lt;/p&gt;
&lt;p&gt;Enqueue packet through…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2025-1874</guid>
    </item>
    <item>
      <title>SUSE-SU-2025:01919-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2025:01919-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2025:01919-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-21703</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-21703</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:Pro:18.04:LTS: linux-aws-5.4, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:Pro:18.04:LTS: linux-azure-5.4, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3 and 123 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: netem: Update sch-&amp;gt;q.qlen before qdisc_tree_reduce_backlog() qdisc_tree_reduce_backlog() notifies parent qdisc only if child qdisc becomes empty, therefore we need to reduce the backlog of the child qdisc before calling it. Otherwise it would miss the opportunity to call cops-&amp;gt;qlen_notify(), in the case of DRR, it resulted in UAF since DRR uses -&amp;gt;qlen_notify() to maintain its active list.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:Pro:18.04:LTS: linux-aws-5.4, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:Pro:18.04:LTS: linux-azure-5.4, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3 and 123 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: netem: Update sch-&amp;gt;q.qlen before qdisc_tree_reduce_backlog() qdisc_tree_reduce_backlog() notifies parent qdisc only if child qdisc becomes empty, therefore we need to reduce the backlog of the child qdisc before calling it. Otherwise it would miss the opportunity to call cops-&amp;gt;qlen_notify(), in the case of DRR, it resulted in UAF since DRR uses -&amp;gt;qlen_notify() to maintain its active list.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-21703</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-0411 — Linux Kernel: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0411</link>
      <description>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen in Linux Kernel ausnutzen, um Dateien zu manipulieren oder seine Rechte zu erweitern.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen in Linux Kernel ausnutzen, um Dateien zu manipulieren oder seine Rechte zu erweitern.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0411</guid>
    </item>
  </channel>
</rss>
