<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 08:47:59 +0000</lastBuildDate>
    <item>
      <title>ALSA-2025:10379 — Important: kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2025:10379</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: kernel, AlmaLinux:9: kernel-64k, AlmaLinux:9: kernel-64k-core, AlmaLinux:9: kernel-64k-debug, AlmaLinux:9: kernel-64k-debug-core, AlmaLinux:9: kernel-64k-debug-devel, AlmaLinux:9: kernel-64k-debug-devel-matched, AlmaLinux:9: kernel-64k-debug-modules, AlmaLinux:9: kernel-64k-debug-modules-core, AlmaLinux:9: kernel-64k-debug-modules-extra and 66 more&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: ipv6: mcast: extend RCU protection in igmp6_send() (CVE-2025-21759)
  * kernel: ovl: fix UAF in ovl_dentry_update_reval by moving dput() in ovl_link_up (CVE-2025-21887)
  * kernel: net: atm: fix use after free in lec_send() (CVE-2025-22004)
  * kernel: udf: Fix a slab-out-of-bounds write bug in udf_find_entry() (CVE-2022-49846)
  * kernel: vmxnet3: Fix malformed packet sizing in vmxnet3_process_xdp (CVE-2025-37799)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: kernel, AlmaLinux:9: kernel-64k, AlmaLinux:9: kernel-64k-core, AlmaLinux:9: kernel-64k-debug, AlmaLinux:9: kernel-64k-debug-core, AlmaLinux:9: kernel-64k-debug-devel, AlmaLinux:9: kernel-64k-debug-devel-matched, AlmaLinux:9: kernel-64k-debug-modules, AlmaLinux:9: kernel-64k-debug-modules-core, AlmaLinux:9: kernel-64k-debug-modules-extra and 66 more&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: ipv6: mcast: extend RCU protection in igmp6_send() (CVE-2025-21759)
  * kernel: ovl: fix UAF in ovl_dentry_update_reval by moving dput() in ovl_link_up (CVE-2025-21887)
  * kernel: net: atm: fix use after free in lec_send() (CVE-2025-22004)
  * kernel: udf: Fix a slab-out-of-bounds write bug in udf_find_entry() (CVE-2022-49846)
  * kernel: vmxnet3: Fix malformed packet sizing in vmxnet3_process_xdp (CVE-2025-37799)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2025:10379</guid>
    </item>
    <item>
      <title>bdu:2025-03684</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-03684</link>
      <description>bdu:2025-03684</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-03684</guid>
    </item>
    <item>
      <title>BELL-CVE-2025-21887</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2025-21887</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2025-21887</guid>
    </item>
    <item>
      <title>certfr-2025-avi-0333 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de Debian. Elles permettent à un attaquant de provo…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0333</link>
      <description>certfr-2025-avi-0333</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0333</guid>
    </item>
    <item>
      <title>EUVD-2026-364507</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-364507</link>
      <description>EUVD-2026-364507</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-364507</guid>
    </item>
    <item>
      <title>fkie_cve-2025-21887</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-21887</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;ovl: fix UAF in ovl_dentry_update_reval by moving dput() in ovl_link_up&lt;/p&gt;
&lt;p&gt;The issue was caused by dput(upper) being called before
ovl_dentry_update_reval(), while upper-&amp;gt;d_flags was still
accessed in ovl_dentry_remote().&lt;/p&gt;
&lt;p&gt;Move dput(upper) after its last use to prevent use-after-free.&lt;/p&gt;
&lt;p&gt;BUG: KASAN: slab-use-after-free in ovl_dentry_remote fs/overlayfs/util.c:162 [inline]
BUG: KASAN: slab-use-after-free in ovl_dentry_update_reval+0xd2/0xf0 fs/overlayfs/util.c:167&lt;/p&gt;
&lt;p&gt;Call Trace:
 &amp;lt;TASK&amp;gt;
 __dump_stack lib/dump_stack.c:88 [inline]
 dump_stack_lvl+0x116/0x1f0 lib/dump_stack.c:114
 print_address_description mm/kasan/report.c:377 [inline]
 print_report+0xc3/0x620 mm/kasan/report.c:488
 kasan_report+0xd9/0x110 mm/kasan/report.c:601
 ovl_dentry_remote fs/overlayfs/util.c:162 [inline]
 ovl_dentry_update_reval+0xd2/0xf0 fs/overlayfs/util.c:167
 ovl_link_up fs/overlayfs/copy_up.c:610 [inline]
 ovl_copy_up_one+0x2105/0x3490 fs/overlayfs/copy_up.c:1170
 ovl_copy_up_flags+0x18d/0x200 fs/overlayfs/copy_up.c:1223
 ovl_rename+0x39e/0x18c0 fs/overlayfs/dir.c:1136
 vfs_rename+0xf84/0x20a0 fs/namei.c:4893
...
 &amp;lt;/TASK&amp;gt;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;ovl: fix UAF in ovl_dentry_update_reval by moving dput() in ovl_link_up&lt;/p&gt;
&lt;p&gt;The issue was caused by dput(upper) being called before
ovl_dentry_update_reval(), while upper-&amp;gt;d_flags was still
accessed in ovl_dentry_remote().&lt;/p&gt;
&lt;p&gt;Move dput(upper) after its last use to prevent use-after-free.&lt;/p&gt;
&lt;p&gt;BUG: KASAN: slab-use-after-free in ovl_dentry_remote fs/overlayfs/util.c:162 [inline]
BUG: KASAN: slab-use-after-free in ovl_dentry_update_reval+0xd2/0xf0 fs/overlayfs/util.c:167&lt;/p&gt;
&lt;p&gt;Call Trace:
 &amp;lt;TASK&amp;gt;
 __dump_stack lib/dump_stack.c:88 [inline]
 dump_stack_lvl+0x116/0x1f0 lib/dump_stack.c:114
 print_address_description mm/kasan/report.c:377 [inline]
 print_report+0xc3/0x620 mm/kasan/report.c:488
 kasan_report+0xd9/0x110 mm/kasan/report.c:601
 ovl_dentry_remote fs/overlayfs/util.c:162 [inline]
 ovl_dentry_update_reval+0xd2/0xf0 fs/overlayfs/util.c:167
 ovl_link_up fs/overlayfs/copy_up.c:610 [inline]
 ovl_copy_up_one+0x2105/0x3490 fs/overlayfs/copy_up.c:1170
 ovl_copy_up_flags+0x18d/0x200 fs/overlayfs/copy_up.c:1223
 ovl_rename+0x39e/0x18c0 fs/overlayfs/dir.c:1136
 vfs_rename+0xf84/0x20a0 fs/namei.c:4893
...
 &amp;lt;/TASK&amp;gt;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-21887</guid>
    </item>
    <item>
      <title>GHSA-vjwm-w9rc-f4cc</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-vjwm-w9rc-f4cc</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;ovl: fix UAF in ovl_dentry_update_reval by moving dput() in ovl_link_up&lt;/p&gt;
&lt;p&gt;The issue was caused by dput(upper) being called before
ovl_dentry_update_reval(), while upper-&amp;gt;d_flags was still
accessed in ovl_dentry_remote().&lt;/p&gt;
&lt;p&gt;Move dput(upper) after its last use to prevent use-after-free.&lt;/p&gt;
&lt;p&gt;BUG: KASAN: slab-use-after-free in ovl_dentry_remote fs/overlayfs/util.c:162 [inline]
BUG: KASAN: slab-use-after-free in ovl_dentry_update_reval+0xd2/0xf0 fs/overlayfs/util.c:167&lt;/p&gt;
&lt;p&gt;Call Trace:
 &amp;lt;TASK&amp;gt;
 __dump_stack lib/dump_stack.c:88 [inline]
 dump_stack_lvl+0x116/0x1f0 lib/dump_stack.c:114
 print_address_description mm/kasan/report.c:377 [inline]
 print_report+0xc3/0x620 mm/kasan/report.c:488
 kasan_report+0xd9/0x110 mm/kasan/report.c:601
 ovl_dentry_remote fs/overlayfs/util.c:162 [inline]
 ovl_dentry_update_reval+0xd2/0xf0 fs/overlayfs/util.c:167
 ovl_link_up fs/overlayfs/copy_up.c:610 [inline]
 ovl_copy_up_one+0x2105/0x3490 fs/overlayfs/copy_up.c:1170
 ovl_copy_up_flags+0x18d/0x200 fs/overlayfs/copy_up.c:1223
 ovl_rename+0x39e/0x18c0 fs/overlayfs/dir.c:1136
 vfs_rename+0xf84/0x20a0 fs/namei.c:4893
...
 &amp;lt;/TASK&amp;gt;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;ovl: fix UAF in ovl_dentry_update_reval by moving dput() in ovl_link_up&lt;/p&gt;
&lt;p&gt;The issue was caused by dput(upper) being called before
ovl_dentry_update_reval(), while upper-&amp;gt;d_flags was still
accessed in ovl_dentry_remote().&lt;/p&gt;
&lt;p&gt;Move dput(upper) after its last use to prevent use-after-free.&lt;/p&gt;
&lt;p&gt;BUG: KASAN: slab-use-after-free in ovl_dentry_remote fs/overlayfs/util.c:162 [inline]
BUG: KASAN: slab-use-after-free in ovl_dentry_update_reval+0xd2/0xf0 fs/overlayfs/util.c:167&lt;/p&gt;
&lt;p&gt;Call Trace:
 &amp;lt;TASK&amp;gt;
 __dump_stack lib/dump_stack.c:88 [inline]
 dump_stack_lvl+0x116/0x1f0 lib/dump_stack.c:114
 print_address_description mm/kasan/report.c:377 [inline]
 print_report+0xc3/0x620 mm/kasan/report.c:488
 kasan_report+0xd9/0x110 mm/kasan/report.c:601
 ovl_dentry_remote fs/overlayfs/util.c:162 [inline]
 ovl_dentry_update_reval+0xd2/0xf0 fs/overlayfs/util.c:167
 ovl_link_up fs/overlayfs/copy_up.c:610 [inline]
 ovl_copy_up_one+0x2105/0x3490 fs/overlayfs/copy_up.c:1170
 ovl_copy_up_flags+0x18d/0x200 fs/overlayfs/copy_up.c:1223
 ovl_rename+0x39e/0x18c0 fs/overlayfs/dir.c:1136
 vfs_rename+0xf84/0x20a0 fs/namei.c:4893
...
 &amp;lt;/TASK&amp;gt;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-vjwm-w9rc-f4cc</guid>
    </item>
    <item>
      <title>ICSA-26-209-04 — Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-26-209-04</link>
      <description>&lt;p&gt;Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.6 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant).&lt;/p&gt;
&lt;p&gt;Siemens is preparing fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.6 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant).&lt;/p&gt;
&lt;p&gt;Siemens is preparing fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-26-209-04</guid>
    </item>
    <item>
      <title>msrc_CVE-2025-21887 — ovl: fix UAF in ovl_dentry_update_reval by moving dput() in ovl_link_up</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2025-21887</link>
      <description>msrc_CVE-2025-21887</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2025-21887</guid>
    </item>
    <item>
      <title>OESA-2025-1371 — kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2025-1371</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;fs: relax assertions on failure to encode file handles&lt;/p&gt;
&lt;p&gt;Encoding file handles is usually performed by a filesystem &amp;amp;gt;encode_fh()
method that may fail for various reasons.&lt;/p&gt;
&lt;p&gt;The legacy users of exportfs_encode_fh(), namely, nfsd and
name_to_handle_at(2) syscall are ready to cope with the possibility
of failure to encode a file handle.&lt;/p&gt;
&lt;p&gt;There are a few other users of exportfs_encode_{fh,fid}() that
currently have a WARN_ON() assertion when -&amp;amp;gt;encode_fh() fails.
Relax those assertions because they are wrong.&lt;/p&gt;
&lt;p&gt;The second linked bug report states commit 16aac5ad1fa9 (&amp;amp;quot;ovl: support
encoding non-decodable file handles&amp;amp;quot;) in v6.6 as the regressing commit,
but this is not accurate.&lt;/p&gt;
&lt;p&gt;The aforementioned commit only increases the chances of the assertion
and allows triggering the assertion with the reproducer using overlayfs,
inotify and drop_caches.&lt;/p&gt;
&lt;p&gt;Triggering this assertion was always possible with other filesystems and
other reasons of -&amp;amp;gt;encode_fh() failures and more particularly, it was
also possible with the exact same reproducer using overlayfs that is
mounted with options index=on,nfs_export=on also on kernels &amp;amp;lt; v6.6.
Therefore, I am not listing the aforementioned commit as a Fixes commit.&lt;/p&gt;
&lt;p&gt;Backport hint: this patch will have a trivial conflict applying to
v6.6.y, and other trivial conflicts applying to stable kernels &amp;amp;l…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;fs: relax assertions on failure to encode file handles&lt;/p&gt;
&lt;p&gt;Encoding file handles is usually performed by a filesystem &amp;amp;gt;encode_fh()
method that may fail for various reasons.&lt;/p&gt;
&lt;p&gt;The legacy users of exportfs_encode_fh(), namely, nfsd and
name_to_handle_at(2) syscall are ready to cope with the possibility
of failure to encode a file handle.&lt;/p&gt;
&lt;p&gt;There are a few other users of exportfs_encode_{fh,fid}() that
currently have a WARN_ON() assertion when -&amp;amp;gt;encode_fh() fails.
Relax those assertions because they are wrong.&lt;/p&gt;
&lt;p&gt;The second linked bug report states commit 16aac5ad1fa9 (&amp;amp;quot;ovl: support
encoding non-decodable file handles&amp;amp;quot;) in v6.6 as the regressing commit,
but this is not accurate.&lt;/p&gt;
&lt;p&gt;The aforementioned commit only increases the chances of the assertion
and allows triggering the assertion with the reproducer using overlayfs,
inotify and drop_caches.&lt;/p&gt;
&lt;p&gt;Triggering this assertion was always possible with other filesystems and
other reasons of -&amp;amp;gt;encode_fh() failures and more particularly, it was
also possible with the exact same reproducer using overlayfs that is
mounted with options index=on,nfs_export=on also on kernels &amp;amp;lt; v6.6.
Therefore, I am not listing the aforementioned commit as a Fixes commit.&lt;/p&gt;
&lt;p&gt;Backport hint: this patch will have a trivial conflict applying to
v6.6.y, and other trivial conflicts applying to stable kernels &amp;amp;l…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2025-1371</guid>
    </item>
    <item>
      <title>RHSA-2025:10379 — Red Hat Security Advisory: kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2025:10379</link>
      <description>&lt;p&gt;kernel: udf: Fix a slab-out-of-bounds write bug in udf_find_entry() kernel: ipv6: mcast: extend RCU protection in igmp6_send() kernel: ovl: fix UAF in ovl_dentry_update_reval by moving dput() in ovl_link_up kernel: net: atm: fix use after free in lec_send() kernel: vmxnet3: Fix malformed packet sizing in vmxnet3_process_xdp&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;kernel: udf: Fix a slab-out-of-bounds write bug in udf_find_entry() kernel: ipv6: mcast: extend RCU protection in igmp6_send() kernel: ovl: fix UAF in ovl_dentry_update_reval by moving dput() in ovl_link_up kernel: net: atm: fix use after free in lec_send() kernel: vmxnet3: Fix malformed packet sizing in vmxnet3_process_xdp&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2025:10379</guid>
    </item>
    <item>
      <title>RHSA-2025:11810 — Red Hat Security Advisory: kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2025:11810</link>
      <description>&lt;p&gt;kernel: tty: tty_buffer: Fix the softlockup issue in flush_to_ldisc kernel: perf/core: Bail out early if the request AUX area is out of bound kernel: rcu-tasks: Avoid pr_info() with spin lock in cblist_init_generic() kernel: drm/amd/display: Implement bounds check for stream encoder creation in DCN301 kernel: nbd: null check for nla_nest_start kernel: firmware: cs_dsp: Fix overflow checking of wmfw header kernel: powerpc/pseries: Whitelist dtl slub object for copying to userspace kernel: usb: xhci: prevent potential failure in handle_tx_event() for Transfer events without TRB kernel: parport: Proper fix for array out-of-bounds access kernel: blk-rq-qos: fix crash on rq_qos_wait vs. rq_qos_wake_function race kernel: ovl: fix UAF in ovl_dentry_update_reval by moving dput() in ovl_link_up kernel: wifi: iwlwifi: limit printed string from FW file kernel: ibmvnic: Use kernel helpers for hex dumps kernel: ext4: avoid journaling sb update on error if journal is destroying kernel: udmabuf: fix a buf size overflow issue during udmabuf creation kernel: net/sched: fix use-after-free in taprio_dev_notifier kernel: sunrpc: handle SVC_GARBAGE during svc auth processing as auth error&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;kernel: tty: tty_buffer: Fix the softlockup issue in flush_to_ldisc kernel: perf/core: Bail out early if the request AUX area is out of bound kernel: rcu-tasks: Avoid pr_info() with spin lock in cblist_init_generic() kernel: drm/amd/display: Implement bounds check for stream encoder creation in DCN301 kernel: nbd: null check for nla_nest_start kernel: firmware: cs_dsp: Fix overflow checking of wmfw header kernel: powerpc/pseries: Whitelist dtl slub object for copying to userspace kernel: usb: xhci: prevent potential failure in handle_tx_event() for Transfer events without TRB kernel: parport: Proper fix for array out-of-bounds access kernel: blk-rq-qos: fix crash on rq_qos_wait vs. rq_qos_wake_function race kernel: ovl: fix UAF in ovl_dentry_update_reval by moving dput() in ovl_link_up kernel: wifi: iwlwifi: limit printed string from FW file kernel: ibmvnic: Use kernel helpers for hex dumps kernel: ext4: avoid journaling sb update on error if journal is destroying kernel: udmabuf: fix a buf size overflow issue during udmabuf creation kernel: net/sched: fix use-after-free in taprio_dev_notifier kernel: sunrpc: handle SVC_GARBAGE during svc auth processing as auth error&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2025:11810</guid>
    </item>
    <item>
      <title>SSA-019113 — SSA-019113: Vulnerabilities in the additional GNU/Linux subsystem of the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1.6</title>
      <link>https://cve.radiocsirt.org/vuln/ssa-019113</link>
      <description>&lt;p&gt;Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.6 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant).&lt;/p&gt;
&lt;p&gt;Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.6 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant).&lt;/p&gt;
&lt;p&gt;Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ssa-019113</guid>
    </item>
    <item>
      <title>SUSE-SU-2025:01614-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2025:01614-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2025:01614-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-21887</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-21887</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 147 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: ovl: fix UAF in ovl_dentry_update_reval by moving dput() in ovl_link_up The issue was caused by dput(upper) being called before ovl_dentry_update_reval(), while upper-&amp;gt;d_flags was still accessed in ovl_dentry_remote(). Move dput(upper) after its last use to prevent use-after-free. BUG: KASAN: slab-use-after-free in ovl_dentry_remote fs/overlayfs/util.c:162 [inline] BUG: KASAN: slab-use-after-free in ovl_dentry_update_reval+0xd2/0xf0 fs/overlayfs/util.c:167 Call Trace:  &amp;lt;TASK&amp;gt;  __dump_stack lib/dump_stack.c:88 [inline]  dump_stack_lvl+0x116/0x1f0 lib/dump_stack.c:114  print_address_description mm/kasan/report.c:377 [inline]  print_report+0xc3/0x620 mm/kasan/report.c:488  kasan_report+0xd9/0x110 mm/kasan/report.c:601  ovl_dentry_remote fs/overlayfs/util.c:162 [inline]  ovl_dentry_update_reval+0xd2/0xf0 fs/overlayfs/util.c:167  ovl_link_up fs/overlayfs/copy_up.c:610 [inline]  ovl_copy_up_one+0x2105/0x3490 fs/overlayfs/copy_up.c:1170  ovl_copy_up_flags+0x18d/0x200 fs/overlayfs/copy_up.c:1223  ovl_rename+0x39e/0x18c0 fs/overlayfs/dir.c:1136  vfs_rename+0xf84/0x20a0 fs/namei.c:4893 ...  &amp;lt;/TASK&amp;gt;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 147 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: ovl: fix UAF in ovl_dentry_update_reval by moving dput() in ovl_link_up The issue was caused by dput(upper) being called before ovl_dentry_update_reval(), while upper-&amp;gt;d_flags was still accessed in ovl_dentry_remote(). Move dput(upper) after its last use to prevent use-after-free. BUG: KASAN: slab-use-after-free in ovl_dentry_remote fs/overlayfs/util.c:162 [inline] BUG: KASAN: slab-use-after-free in ovl_dentry_update_reval+0xd2/0xf0 fs/overlayfs/util.c:167 Call Trace:  &amp;lt;TASK&amp;gt;  __dump_stack lib/dump_stack.c:88 [inline]  dump_stack_lvl+0x116/0x1f0 lib/dump_stack.c:114  print_address_description mm/kasan/report.c:377 [inline]  print_report+0xc3/0x620 mm/kasan/report.c:488  kasan_report+0xd9/0x110 mm/kasan/report.c:601  ovl_dentry_remote fs/overlayfs/util.c:162 [inline]  ovl_dentry_update_reval+0xd2/0xf0 fs/overlayfs/util.c:167  ovl_link_up fs/overlayfs/copy_up.c:610 [inline]  ovl_copy_up_one+0x2105/0x3490 fs/overlayfs/copy_up.c:1170  ovl_copy_up_flags+0x18d/0x200 fs/overlayfs/copy_up.c:1223  ovl_rename+0x39e/0x18c0 fs/overlayfs/dir.c:1136  vfs_rename+0xf84/0x20a0 fs/namei.c:4893 ...  &amp;lt;/TASK&amp;gt;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-21887</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-0649 — Linux Kernel: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0649</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen oder nicht spezifizierte Effekte zu erzielen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen oder nicht spezifizierte Effekte zu erzielen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0649</guid>
    </item>
  </channel>
</rss>
