<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 05:48:56 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-03918</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-03918</link>
      <description>bdu:2026-03918</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-03918</guid>
    </item>
    <item>
      <title>BELL-CVE-2025-21717</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2025-21717</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2025-21717</guid>
    </item>
    <item>
      <title>certfr-2025-avi-0529 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de SUSE. Certaines d'entre elles permettent à un at…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0529</link>
      <description>certfr-2025-avi-0529</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0529</guid>
    </item>
    <item>
      <title>EUVD-2026-346640</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-346640</link>
      <description>EUVD-2026-346640</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-346640</guid>
    </item>
    <item>
      <title>fkie_cve-2025-21717</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-21717</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;net/mlx5e: add missing cpu_to_node to kvzalloc_node in mlx5e_open_xdpredirect_sq&lt;/p&gt;
&lt;p&gt;kvzalloc_node is not doing a runtime check on the node argument
(__alloc_pages_node_noprof does have a VM_BUG_ON, but it expands to
nothing on !CONFIG_DEBUG_VM builds), so doing any ethtool/netlink
operation that calls mlx5e_open on a CPU that&amp;#39;s larger that MAX_NUMNODES
triggers OOB access and panic (see the trace below).&lt;/p&gt;
&lt;p&gt;Add missing cpu_to_node call to convert cpu id to node id.&lt;/p&gt;
&lt;p&gt;[  165.427394] mlx5_core 0000:5c:00.0 beth1: Link up
[  166.479327] BUG: unable to handle page fault for address: 0000000800000010
[  166.494592] #PF: supervisor read access in kernel mode
[  166.505995] #PF: error_code(0x0000) - not-present page
...
[  166.816958] Call Trace:
[  166.822380]  &amp;lt;TASK&amp;gt;
[  166.827034]  ? __die_body+0x64/0xb0
[  166.834774]  ? page_fault_oops+0x2cd/0x3f0
[  166.843862]  ? exc_page_fault+0x63/0x130
[  166.852564]  ? asm_exc_page_fault+0x22/0x30
[  166.861843]  ? __kvmalloc_node_noprof+0x43/0xd0
[  166.871897]  ? get_partial_node+0x1c/0x320
[  166.880983]  ? deactivate_slab+0x269/0x2b0
[  166.890069]  ___slab_alloc+0x521/0xa90
[  166.898389]  ? __kvmalloc_node_noprof+0x43/0xd0
[  166.908442]  __kmalloc_node_noprof+0x216/0x3f0
[  166.918302]  ? __kvmalloc_node_noprof+0x43/0xd0
[  166.928354]  __kvmalloc_node_noprof+0x43/0xd0
[  166.938021]  mlx5e_open_channels+0x5e2/0xc00
[  166.947496]  mlx5e_open_locked+0x3e/0xf0
[  166.9…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;net/mlx5e: add missing cpu_to_node to kvzalloc_node in mlx5e_open_xdpredirect_sq&lt;/p&gt;
&lt;p&gt;kvzalloc_node is not doing a runtime check on the node argument
(__alloc_pages_node_noprof does have a VM_BUG_ON, but it expands to
nothing on !CONFIG_DEBUG_VM builds), so doing any ethtool/netlink
operation that calls mlx5e_open on a CPU that&amp;#39;s larger that MAX_NUMNODES
triggers OOB access and panic (see the trace below).&lt;/p&gt;
&lt;p&gt;Add missing cpu_to_node call to convert cpu id to node id.&lt;/p&gt;
&lt;p&gt;[  165.427394] mlx5_core 0000:5c:00.0 beth1: Link up
[  166.479327] BUG: unable to handle page fault for address: 0000000800000010
[  166.494592] #PF: supervisor read access in kernel mode
[  166.505995] #PF: error_code(0x0000) - not-present page
...
[  166.816958] Call Trace:
[  166.822380]  &amp;lt;TASK&amp;gt;
[  166.827034]  ? __die_body+0x64/0xb0
[  166.834774]  ? page_fault_oops+0x2cd/0x3f0
[  166.843862]  ? exc_page_fault+0x63/0x130
[  166.852564]  ? asm_exc_page_fault+0x22/0x30
[  166.861843]  ? __kvmalloc_node_noprof+0x43/0xd0
[  166.871897]  ? get_partial_node+0x1c/0x320
[  166.880983]  ? deactivate_slab+0x269/0x2b0
[  166.890069]  ___slab_alloc+0x521/0xa90
[  166.898389]  ? __kvmalloc_node_noprof+0x43/0xd0
[  166.908442]  __kmalloc_node_noprof+0x216/0x3f0
[  166.918302]  ? __kvmalloc_node_noprof+0x43/0xd0
[  166.928354]  __kvmalloc_node_noprof+0x43/0xd0
[  166.938021]  mlx5e_open_channels+0x5e2/0xc00
[  166.947496]  mlx5e_open_locked+0x3e/0xf0
[  166.9…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-21717</guid>
    </item>
    <item>
      <title>GHSA-6v7v-ggwx-mwx7</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-6v7v-ggwx-mwx7</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;net/mlx5e: add missing cpu_to_node to kvzalloc_node in mlx5e_open_xdpredirect_sq&lt;/p&gt;
&lt;p&gt;kvzalloc_node is not doing a runtime check on the node argument
(__alloc_pages_node_noprof does have a VM_BUG_ON, but it expands to
nothing on !CONFIG_DEBUG_VM builds), so doing any ethtool/netlink
operation that calls mlx5e_open on a CPU that&amp;#39;s larger that MAX_NUMNODES
triggers OOB access and panic (see the trace below).&lt;/p&gt;
&lt;p&gt;Add missing cpu_to_node call to convert cpu id to node id.&lt;/p&gt;
&lt;p&gt;[  165.427394] mlx5_core 0000:5c:00.0 beth1: Link up
[  166.479327] BUG: unable to handle page fault for address: 0000000800000010
[  166.494592] #PF: supervisor read access in kernel mode
[  166.505995] #PF: error_code(0x0000) - not-present page
...
[  166.816958] Call Trace:
[  166.822380]  &amp;lt;TASK&amp;gt;
[  166.827034]  ? __die_body+0x64/0xb0
[  166.834774]  ? page_fault_oops+0x2cd/0x3f0
[  166.843862]  ? exc_page_fault+0x63/0x130
[  166.852564]  ? asm_exc_page_fault+0x22/0x30
[  166.861843]  ? __kvmalloc_node_noprof+0x43/0xd0
[  166.871897]  ? get_partial_node+0x1c/0x320
[  166.880983]  ? deactivate_slab+0x269/0x2b0
[  166.890069]  ___slab_alloc+0x521/0xa90
[  166.898389]  ? __kvmalloc_node_noprof+0x43/0xd0
[  166.908442]  __kmalloc_node_noprof+0x216/0x3f0
[  166.918302]  ? __kvmalloc_node_noprof+0x43/0xd0
[  166.928354]  __kvmalloc_node_noprof+0x43/0xd0
[  166.938021]  mlx5e_open_channels+0x5e2/0xc00
[  166.947496]  mlx5e_open_locked+0x3e/0xf0
[  166.9…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;net/mlx5e: add missing cpu_to_node to kvzalloc_node in mlx5e_open_xdpredirect_sq&lt;/p&gt;
&lt;p&gt;kvzalloc_node is not doing a runtime check on the node argument
(__alloc_pages_node_noprof does have a VM_BUG_ON, but it expands to
nothing on !CONFIG_DEBUG_VM builds), so doing any ethtool/netlink
operation that calls mlx5e_open on a CPU that&amp;#39;s larger that MAX_NUMNODES
triggers OOB access and panic (see the trace below).&lt;/p&gt;
&lt;p&gt;Add missing cpu_to_node call to convert cpu id to node id.&lt;/p&gt;
&lt;p&gt;[  165.427394] mlx5_core 0000:5c:00.0 beth1: Link up
[  166.479327] BUG: unable to handle page fault for address: 0000000800000010
[  166.494592] #PF: supervisor read access in kernel mode
[  166.505995] #PF: error_code(0x0000) - not-present page
...
[  166.816958] Call Trace:
[  166.822380]  &amp;lt;TASK&amp;gt;
[  166.827034]  ? __die_body+0x64/0xb0
[  166.834774]  ? page_fault_oops+0x2cd/0x3f0
[  166.843862]  ? exc_page_fault+0x63/0x130
[  166.852564]  ? asm_exc_page_fault+0x22/0x30
[  166.861843]  ? __kvmalloc_node_noprof+0x43/0xd0
[  166.871897]  ? get_partial_node+0x1c/0x320
[  166.880983]  ? deactivate_slab+0x269/0x2b0
[  166.890069]  ___slab_alloc+0x521/0xa90
[  166.898389]  ? __kvmalloc_node_noprof+0x43/0xd0
[  166.908442]  __kmalloc_node_noprof+0x216/0x3f0
[  166.918302]  ? __kvmalloc_node_noprof+0x43/0xd0
[  166.928354]  __kvmalloc_node_noprof+0x43/0xd0
[  166.938021]  mlx5e_open_channels+0x5e2/0xc00
[  166.947496]  mlx5e_open_locked+0x3e/0xf0
[  166.9…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-6v7v-ggwx-mwx7</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-21717</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-21717</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 69 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: add missing cpu_to_node to kvzalloc_node in mlx5e_open_xdpredirect_sq kvzalloc_node is not doing a runtime check on the node argument (__alloc_pages_node_noprof does have a VM_BUG_ON, but it expands to nothing on !CONFIG_DEBUG_VM builds), so doing any ethtool/netlink operation that calls mlx5e_open on a CPU that&amp;#39;s larger that MAX_NUMNODES triggers OOB access and panic (see the trace below). Add missing cpu_to_node call to convert cpu id to node id. [  165.427394] mlx5_core 0000:5c:00.0 beth1: Link up [  166.479327] BUG: unable to handle page fault for address: 0000000800000010 [  166.494592] #PF: supervisor read access in kernel mode [  166.505995] #PF: error_code(0x0000) - not-present page ... [  166.816958] Call Trace: [  166.822380]  &amp;lt;TASK&amp;gt; [  166.827034]  ? __die_body+0x64/0xb0 [  166.834774]  ? page_fault_oops+0x2cd/0x3f0 [  166.843862]  ? exc_page_fault+0x63/0x130 [  166.852564]  ? asm_exc_page_fault+0x22/0x30 [  166.861843]  ? __kvmalloc_node_noprof+0x43/0xd0 [  166.871897]  ? get_partial_node+0x1c/0x320 [  166.880983]  ? deactivate_slab+0x269/0x2b0 [  166.890069]  ___slab_alloc+0x521/0xa90 [  166.898389]  ? __kvmalloc_node_noprof+0x43/0xd0 [  166.908442]  __kmalloc_node_noprof+0x216/0x3f0 [  166.918302]  ? __kvmalloc_node_noprof+0x43/0xd0 [  166.928354]  __kvmalloc_node_noprof+0x43/0xd0 [  166.938021]  mlx5e_open_channels+0x5e2/0xc00 [  166.947496]  mlx5e_open_locked+0x3e/0xf0 [  166.95620…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 69 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: add missing cpu_to_node to kvzalloc_node in mlx5e_open_xdpredirect_sq kvzalloc_node is not doing a runtime check on the node argument (__alloc_pages_node_noprof does have a VM_BUG_ON, but it expands to nothing on !CONFIG_DEBUG_VM builds), so doing any ethtool/netlink operation that calls mlx5e_open on a CPU that&amp;#39;s larger that MAX_NUMNODES triggers OOB access and panic (see the trace below). Add missing cpu_to_node call to convert cpu id to node id. [  165.427394] mlx5_core 0000:5c:00.0 beth1: Link up [  166.479327] BUG: unable to handle page fault for address: 0000000800000010 [  166.494592] #PF: supervisor read access in kernel mode [  166.505995] #PF: error_code(0x0000) - not-present page ... [  166.816958] Call Trace: [  166.822380]  &amp;lt;TASK&amp;gt; [  166.827034]  ? __die_body+0x64/0xb0 [  166.834774]  ? page_fault_oops+0x2cd/0x3f0 [  166.843862]  ? exc_page_fault+0x63/0x130 [  166.852564]  ? asm_exc_page_fault+0x22/0x30 [  166.861843]  ? __kvmalloc_node_noprof+0x43/0xd0 [  166.871897]  ? get_partial_node+0x1c/0x320 [  166.880983]  ? deactivate_slab+0x269/0x2b0 [  166.890069]  ___slab_alloc+0x521/0xa90 [  166.898389]  ? __kvmalloc_node_noprof+0x43/0xd0 [  166.908442]  __kmalloc_node_noprof+0x216/0x3f0 [  166.918302]  ? __kvmalloc_node_noprof+0x43/0xd0 [  166.928354]  __kvmalloc_node_noprof+0x43/0xd0 [  166.938021]  mlx5e_open_channels+0x5e2/0xc00 [  166.947496]  mlx5e_open_locked+0x3e/0xf0 [  166.95620…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-21717</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-0453 — Linux Kernel: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0453</link>
      <description>&lt;p&gt;Ein entfernter Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0453</guid>
    </item>
  </channel>
</rss>
