<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 03:17:52 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-03989</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-03989</link>
      <description>bdu:2026-03989</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-03989</guid>
    </item>
    <item>
      <title>BELL-CVE-2025-21831</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2025-21831</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2025-21831</guid>
    </item>
    <item>
      <title>certfr-2025-avi-0307 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de SUSE. Certaines d'entre elles permettent à un at…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0307</link>
      <description>certfr-2025-avi-0307</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0307</guid>
    </item>
    <item>
      <title>EUVD-2026-314057</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-314057</link>
      <description>EUVD-2026-314057</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-314057</guid>
    </item>
    <item>
      <title>fkie_cve-2025-21831</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-21831</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;PCI: Avoid putting some root ports into D3 on TUXEDO Sirius Gen1&lt;/p&gt;
&lt;p&gt;commit 9d26d3a8f1b0 (&amp;#34;PCI: Put PCIe ports into D3 during suspend&amp;#34;) sets the
policy that all PCIe ports are allowed to use D3.  When the system is
suspended if the port is not power manageable by the platform and won&amp;#39;t be
used for wakeup via a PME this sets up the policy for these ports to go
into D3hot.&lt;/p&gt;
&lt;p&gt;This policy generally makes sense from an OSPM perspective but it leads to
problems with wakeup from suspend on the TUXEDO Sirius 16 Gen 1 with a
specific old BIOS. This manifests as a system hang.&lt;/p&gt;
&lt;p&gt;On the affected Device + BIOS combination, add a quirk for the root port of
the problematic controller to ensure that these root ports are not put into
D3hot at suspend.&lt;/p&gt;
&lt;p&gt;This patch is based on&lt;/p&gt;
&lt;p&gt;https://lore.kernel.org/linux-pci/20230708214457.1229-2-mario.limonciello@amd.com&lt;/p&gt;
&lt;p&gt;but with the added condition both in the documentation and in the code to
apply only to the TUXEDO Sirius 16 Gen 1 with a specific old BIOS and only
the affected root ports.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;PCI: Avoid putting some root ports into D3 on TUXEDO Sirius Gen1&lt;/p&gt;
&lt;p&gt;commit 9d26d3a8f1b0 (&amp;#34;PCI: Put PCIe ports into D3 during suspend&amp;#34;) sets the
policy that all PCIe ports are allowed to use D3.  When the system is
suspended if the port is not power manageable by the platform and won&amp;#39;t be
used for wakeup via a PME this sets up the policy for these ports to go
into D3hot.&lt;/p&gt;
&lt;p&gt;This policy generally makes sense from an OSPM perspective but it leads to
problems with wakeup from suspend on the TUXEDO Sirius 16 Gen 1 with a
specific old BIOS. This manifests as a system hang.&lt;/p&gt;
&lt;p&gt;On the affected Device + BIOS combination, add a quirk for the root port of
the problematic controller to ensure that these root ports are not put into
D3hot at suspend.&lt;/p&gt;
&lt;p&gt;This patch is based on&lt;/p&gt;
&lt;p&gt;https://lore.kernel.org/linux-pci/20230708214457.1229-2-mario.limonciello@amd.com&lt;/p&gt;
&lt;p&gt;but with the added condition both in the documentation and in the code to
apply only to the TUXEDO Sirius 16 Gen 1 with a specific old BIOS and only
the affected root ports.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-21831</guid>
    </item>
    <item>
      <title>GHSA-m4j5-fq6h-r8gv</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-m4j5-fq6h-r8gv</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;PCI: Avoid putting some root ports into D3 on TUXEDO Sirius Gen1&lt;/p&gt;
&lt;p&gt;commit 9d26d3a8f1b0 (&amp;#34;PCI: Put PCIe ports into D3 during suspend&amp;#34;) sets the
policy that all PCIe ports are allowed to use D3.  When the system is
suspended if the port is not power manageable by the platform and won&amp;#39;t be
used for wakeup via a PME this sets up the policy for these ports to go
into D3hot.&lt;/p&gt;
&lt;p&gt;This policy generally makes sense from an OSPM perspective but it leads to
problems with wakeup from suspend on the TUXEDO Sirius 16 Gen 1 with a
specific old BIOS. This manifests as a system hang.&lt;/p&gt;
&lt;p&gt;On the affected Device + BIOS combination, add a quirk for the root port of
the problematic controller to ensure that these root ports are not put into
D3hot at suspend.&lt;/p&gt;
&lt;p&gt;This patch is based on&lt;/p&gt;
&lt;p&gt;https://lore.kernel.org/linux-pci/20230708214457.1229-2-mario.limonciello@amd.com&lt;/p&gt;
&lt;p&gt;but with the added condition both in the documentation and in the code to
apply only to the TUXEDO Sirius 16 Gen 1 with a specific old BIOS and only
the affected root ports.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;PCI: Avoid putting some root ports into D3 on TUXEDO Sirius Gen1&lt;/p&gt;
&lt;p&gt;commit 9d26d3a8f1b0 (&amp;#34;PCI: Put PCIe ports into D3 during suspend&amp;#34;) sets the
policy that all PCIe ports are allowed to use D3.  When the system is
suspended if the port is not power manageable by the platform and won&amp;#39;t be
used for wakeup via a PME this sets up the policy for these ports to go
into D3hot.&lt;/p&gt;
&lt;p&gt;This policy generally makes sense from an OSPM perspective but it leads to
problems with wakeup from suspend on the TUXEDO Sirius 16 Gen 1 with a
specific old BIOS. This manifests as a system hang.&lt;/p&gt;
&lt;p&gt;On the affected Device + BIOS combination, add a quirk for the root port of
the problematic controller to ensure that these root ports are not put into
D3hot at suspend.&lt;/p&gt;
&lt;p&gt;This patch is based on&lt;/p&gt;
&lt;p&gt;https://lore.kernel.org/linux-pci/20230708214457.1229-2-mario.limonciello@amd.com&lt;/p&gt;
&lt;p&gt;but with the added condition both in the documentation and in the code to
apply only to the TUXEDO Sirius 16 Gen 1 with a specific old BIOS and only
the affected root ports.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-m4j5-fq6h-r8gv</guid>
    </item>
    <item>
      <title>msrc_CVE-2025-21831 — PCI: Avoid putting some root ports into D3 on TUXEDO Sirius Gen1</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2025-21831</link>
      <description>msrc_CVE-2025-21831</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2025-21831</guid>
    </item>
    <item>
      <title>OESA-2025-1446 — kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2025-1446</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP1: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;ntb_hw_switchtec: Fix shift-out-of-bounds in switchtec_ntb_mw_set_trans&lt;/p&gt;
&lt;p&gt;There is a kernel API ntb_mw_clear_trans() would pass 0 to both addr and
size. This would make xlate_pos negative.&lt;/p&gt;
&lt;p&gt;[   23.734156] switchtec switchtec0: MW 0: part 0 addr 0x0000000000000000 size 0x0000000000000000
[   23.734158] ================================================================================
[   23.734172] UBSAN: shift-out-of-bounds in drivers/ntb/hw/mscc/ntb_hw_switchtec.c:293:7
[   23.734418] shift exponent -1 is negative&lt;/p&gt;
&lt;p&gt;Ensuring xlate_pos is a positive or zero before BIT.(CVE-2023-53034)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;drm/msm/gem: prevent integer overflow in msm_ioctl_gem_submit()&lt;/p&gt;
&lt;p&gt;The &amp;amp;quot;submit-&amp;amp;gt;cmd[i].size&amp;amp;quot; and &amp;amp;quot;submit-&amp;amp;gt;cmd[i].offset&amp;amp;quot; variables are u32
values that come from the user via the submit_lookup_cmds() function.
This addition could lead to an integer wrapping bug so use size_add()
to prevent that.&lt;/p&gt;
&lt;p&gt;Patchwork: https://patchwork.freedesktop.org/patch/624696/(CVE-2024-52559)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;fs/ntfs3: Mark inode as bad as soon as error detected in mi_enum_attr()&lt;/p&gt;
&lt;p&gt;Extended the `mi_enum_attr()` function interface with an additional
parameter, `struct ntfs_inode *ni`, to allow marking the inode
as bad as soon as an error i…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP1: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;ntb_hw_switchtec: Fix shift-out-of-bounds in switchtec_ntb_mw_set_trans&lt;/p&gt;
&lt;p&gt;There is a kernel API ntb_mw_clear_trans() would pass 0 to both addr and
size. This would make xlate_pos negative.&lt;/p&gt;
&lt;p&gt;[   23.734156] switchtec switchtec0: MW 0: part 0 addr 0x0000000000000000 size 0x0000000000000000
[   23.734158] ================================================================================
[   23.734172] UBSAN: shift-out-of-bounds in drivers/ntb/hw/mscc/ntb_hw_switchtec.c:293:7
[   23.734418] shift exponent -1 is negative&lt;/p&gt;
&lt;p&gt;Ensuring xlate_pos is a positive or zero before BIT.(CVE-2023-53034)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;drm/msm/gem: prevent integer overflow in msm_ioctl_gem_submit()&lt;/p&gt;
&lt;p&gt;The &amp;amp;quot;submit-&amp;amp;gt;cmd[i].size&amp;amp;quot; and &amp;amp;quot;submit-&amp;amp;gt;cmd[i].offset&amp;amp;quot; variables are u32
values that come from the user via the submit_lookup_cmds() function.
This addition could lead to an integer wrapping bug so use size_add()
to prevent that.&lt;/p&gt;
&lt;p&gt;Patchwork: https://patchwork.freedesktop.org/patch/624696/(CVE-2024-52559)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;fs/ntfs3: Mark inode as bad as soon as error detected in mi_enum_attr()&lt;/p&gt;
&lt;p&gt;Extended the `mi_enum_attr()` function interface with an additional
parameter, `struct ntfs_inode *ni`, to allow marking the inode
as bad as soon as an error i…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2025-1446</guid>
    </item>
    <item>
      <title>SUSE-SU-2025:01919-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2025:01919-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2025:01919-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-21831</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-21831</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe, Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:Pro:16.04:LTS: linux-oracle, Ubuntu:Pro:18.04:LTS: linux, Ubuntu:Pro:18.04:LTS: linux-aws, Ubuntu:18.04:LTS: linux-aws-5.0 and 191 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: PCI: Avoid putting some root ports into D3 on TUXEDO Sirius Gen1 commit 9d26d3a8f1b0 (&amp;#34;PCI: Put PCIe ports into D3 during suspend&amp;#34;) sets the policy that all PCIe ports are allowed to use D3.  When the system is suspended if the port is not power manageable by the platform and won&amp;#39;t be used for wakeup via a PME this sets up the policy for these ports to go into D3hot. This policy generally makes sense from an OSPM perspective but it leads to problems with wakeup from suspend on the TUXEDO Sirius 16 Gen 1 with a specific old BIOS. This manifests as a system hang. On the affected Device + BIOS combination, add a quirk for the root port of the problematic controller to ensure that these root ports are not put into D3hot at suspend. This patch is based on https://lore.kernel.org/linux-pci/20230708214457.1229-2-mario.limonciello@amd.com but with the added condition both in the documentation and in the code to apply only to the TUXEDO Sirius 16 Gen 1 with a specific old BIOS and only the affected root ports.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe, Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:Pro:16.04:LTS: linux-oracle, Ubuntu:Pro:18.04:LTS: linux, Ubuntu:Pro:18.04:LTS: linux-aws, Ubuntu:18.04:LTS: linux-aws-5.0 and 191 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: PCI: Avoid putting some root ports into D3 on TUXEDO Sirius Gen1 commit 9d26d3a8f1b0 (&amp;#34;PCI: Put PCIe ports into D3 during suspend&amp;#34;) sets the policy that all PCIe ports are allowed to use D3.  When the system is suspended if the port is not power manageable by the platform and won&amp;#39;t be used for wakeup via a PME this sets up the policy for these ports to go into D3hot. This policy generally makes sense from an OSPM perspective but it leads to problems with wakeup from suspend on the TUXEDO Sirius 16 Gen 1 with a specific old BIOS. This manifests as a system hang. On the affected Device + BIOS combination, add a quirk for the root port of the problematic controller to ensure that these root ports are not put into D3hot at suspend. This patch is based on https://lore.kernel.org/linux-pci/20230708214457.1229-2-mario.limonciello@amd.com but with the added condition both in the documentation and in the code to apply only to the TUXEDO Sirius 16 Gen 1 with a specific old BIOS and only the affected root ports.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-21831</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-0499 — Linux Kernel: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0499</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um nicht spezifizierte Auswirkungen zu erzeugen oder einen Denial-of-Service-Zustand zu verursachen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um nicht spezifizierte Auswirkungen zu erzeugen oder einen Denial-of-Service-Zustand zu verursachen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0499</guid>
    </item>
  </channel>
</rss>
