<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 18:28:56 +0000</lastBuildDate>
    <item>
      <title>bdu:2025-12357</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-12357</link>
      <description>bdu:2025-12357</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-12357</guid>
    </item>
    <item>
      <title>BELL-CVE-2025-21959</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2025-21959</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2025-21959</guid>
    </item>
    <item>
      <title>certfr-2025-avi-0333 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de Debian. Elles permettent à un attaquant de provo…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0333</link>
      <description>certfr-2025-avi-0333</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0333</guid>
    </item>
    <item>
      <title>EUVD-2026-364513</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-364513</link>
      <description>EUVD-2026-364513</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-364513</guid>
    </item>
    <item>
      <title>fkie_cve-2025-21959</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-21959</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;netfilter: nf_conncount: Fully initialize struct nf_conncount_tuple in insert_tree()&lt;/p&gt;
&lt;p&gt;Since commit b36e4523d4d5 (&amp;#34;netfilter: nf_conncount: fix garbage
collection confirm race&amp;#34;), `cpu` and `jiffies32` were introduced to
the struct nf_conncount_tuple.&lt;/p&gt;
&lt;p&gt;The commit made nf_conncount_add() initialize `conn-&amp;gt;cpu` and
`conn-&amp;gt;jiffies32` when allocating the struct.
In contrast, count_tree() was not changed to initialize them.&lt;/p&gt;
&lt;p&gt;By commit 34848d5c896e (&amp;#34;netfilter: nf_conncount: Split insert and
traversal&amp;#34;), count_tree() was split and the relevant allocation
code now resides in insert_tree().
Initialize `conn-&amp;gt;cpu` and `conn-&amp;gt;jiffies32` in insert_tree().&lt;/p&gt;
&lt;p&gt;BUG: KMSAN: uninit-value in find_or_evict net/netfilter/nf_conncount.c:117 [inline]
BUG: KMSAN: uninit-value in __nf_conncount_add+0xd9c/0x2850 net/netfilter/nf_conncount.c:143
 find_or_evict net/netfilter/nf_conncount.c:117 [inline]
 __nf_conncount_add+0xd9c/0x2850 net/netfilter/nf_conncount.c:143
 count_tree net/netfilter/nf_conncount.c:438 [inline]
 nf_conncount_count+0x82f/0x1e80 net/netfilter/nf_conncount.c:521
 connlimit_mt+0x7f6/0xbd0 net/netfilter/xt_connlimit.c:72
 __nft_match_eval net/netfilter/nft_compat.c:403 [inline]
 nft_match_eval+0x1a5/0x300 net/netfilter/nft_compat.c:433
 expr_call_ops_eval net/netfilter/nf_tables_core.c:240 [inline]
 nft_do_chain+0x426/0x2290 net/netfilter/nf_tables_core.c:288
 nft_do_chain_ipv4+0x1a5/0x230 net/netfilter/nft_chain_fi…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;netfilter: nf_conncount: Fully initialize struct nf_conncount_tuple in insert_tree()&lt;/p&gt;
&lt;p&gt;Since commit b36e4523d4d5 (&amp;#34;netfilter: nf_conncount: fix garbage
collection confirm race&amp;#34;), `cpu` and `jiffies32` were introduced to
the struct nf_conncount_tuple.&lt;/p&gt;
&lt;p&gt;The commit made nf_conncount_add() initialize `conn-&amp;gt;cpu` and
`conn-&amp;gt;jiffies32` when allocating the struct.
In contrast, count_tree() was not changed to initialize them.&lt;/p&gt;
&lt;p&gt;By commit 34848d5c896e (&amp;#34;netfilter: nf_conncount: Split insert and
traversal&amp;#34;), count_tree() was split and the relevant allocation
code now resides in insert_tree().
Initialize `conn-&amp;gt;cpu` and `conn-&amp;gt;jiffies32` in insert_tree().&lt;/p&gt;
&lt;p&gt;BUG: KMSAN: uninit-value in find_or_evict net/netfilter/nf_conncount.c:117 [inline]
BUG: KMSAN: uninit-value in __nf_conncount_add+0xd9c/0x2850 net/netfilter/nf_conncount.c:143
 find_or_evict net/netfilter/nf_conncount.c:117 [inline]
 __nf_conncount_add+0xd9c/0x2850 net/netfilter/nf_conncount.c:143
 count_tree net/netfilter/nf_conncount.c:438 [inline]
 nf_conncount_count+0x82f/0x1e80 net/netfilter/nf_conncount.c:521
 connlimit_mt+0x7f6/0xbd0 net/netfilter/xt_connlimit.c:72
 __nft_match_eval net/netfilter/nft_compat.c:403 [inline]
 nft_match_eval+0x1a5/0x300 net/netfilter/nft_compat.c:433
 expr_call_ops_eval net/netfilter/nf_tables_core.c:240 [inline]
 nft_do_chain+0x426/0x2290 net/netfilter/nf_tables_core.c:288
 nft_do_chain_ipv4+0x1a5/0x230 net/netfilter/nft_chain_fi…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-21959</guid>
    </item>
    <item>
      <title>GHSA-hwhh-xm47-jghm</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-hwhh-xm47-jghm</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;netfilter: nf_conncount: Fully initialize struct nf_conncount_tuple in insert_tree()&lt;/p&gt;
&lt;p&gt;Since commit b36e4523d4d5 (&amp;#34;netfilter: nf_conncount: fix garbage
collection confirm race&amp;#34;), `cpu` and `jiffies32` were introduced to
the struct nf_conncount_tuple.&lt;/p&gt;
&lt;p&gt;The commit made nf_conncount_add() initialize `conn-&amp;gt;cpu` and
`conn-&amp;gt;jiffies32` when allocating the struct.
In contrast, count_tree() was not changed to initialize them.&lt;/p&gt;
&lt;p&gt;By commit 34848d5c896e (&amp;#34;netfilter: nf_conncount: Split insert and
traversal&amp;#34;), count_tree() was split and the relevant allocation
code now resides in insert_tree().
Initialize `conn-&amp;gt;cpu` and `conn-&amp;gt;jiffies32` in insert_tree().&lt;/p&gt;
&lt;p&gt;BUG: KMSAN: uninit-value in find_or_evict net/netfilter/nf_conncount.c:117 [inline]
BUG: KMSAN: uninit-value in __nf_conncount_add+0xd9c/0x2850 net/netfilter/nf_conncount.c:143
 find_or_evict net/netfilter/nf_conncount.c:117 [inline]
 __nf_conncount_add+0xd9c/0x2850 net/netfilter/nf_conncount.c:143
 count_tree net/netfilter/nf_conncount.c:438 [inline]
 nf_conncount_count+0x82f/0x1e80 net/netfilter/nf_conncount.c:521
 connlimit_mt+0x7f6/0xbd0 net/netfilter/xt_connlimit.c:72
 __nft_match_eval net/netfilter/nft_compat.c:403 [inline]
 nft_match_eval+0x1a5/0x300 net/netfilter/nft_compat.c:433
 expr_call_ops_eval net/netfilter/nf_tables_core.c:240 [inline]
 nft_do_chain+0x426/0x2290 net/netfilter/nf_tables_core.c:288
 nft_do_chain_ipv4+0x1a5/0x230 net/netfilter/nft_chain_fi…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;netfilter: nf_conncount: Fully initialize struct nf_conncount_tuple in insert_tree()&lt;/p&gt;
&lt;p&gt;Since commit b36e4523d4d5 (&amp;#34;netfilter: nf_conncount: fix garbage
collection confirm race&amp;#34;), `cpu` and `jiffies32` were introduced to
the struct nf_conncount_tuple.&lt;/p&gt;
&lt;p&gt;The commit made nf_conncount_add() initialize `conn-&amp;gt;cpu` and
`conn-&amp;gt;jiffies32` when allocating the struct.
In contrast, count_tree() was not changed to initialize them.&lt;/p&gt;
&lt;p&gt;By commit 34848d5c896e (&amp;#34;netfilter: nf_conncount: Split insert and
traversal&amp;#34;), count_tree() was split and the relevant allocation
code now resides in insert_tree().
Initialize `conn-&amp;gt;cpu` and `conn-&amp;gt;jiffies32` in insert_tree().&lt;/p&gt;
&lt;p&gt;BUG: KMSAN: uninit-value in find_or_evict net/netfilter/nf_conncount.c:117 [inline]
BUG: KMSAN: uninit-value in __nf_conncount_add+0xd9c/0x2850 net/netfilter/nf_conncount.c:143
 find_or_evict net/netfilter/nf_conncount.c:117 [inline]
 __nf_conncount_add+0xd9c/0x2850 net/netfilter/nf_conncount.c:143
 count_tree net/netfilter/nf_conncount.c:438 [inline]
 nf_conncount_count+0x82f/0x1e80 net/netfilter/nf_conncount.c:521
 connlimit_mt+0x7f6/0xbd0 net/netfilter/xt_connlimit.c:72
 __nft_match_eval net/netfilter/nft_compat.c:403 [inline]
 nft_match_eval+0x1a5/0x300 net/netfilter/nft_compat.c:433
 expr_call_ops_eval net/netfilter/nf_tables_core.c:240 [inline]
 nft_do_chain+0x426/0x2290 net/netfilter/nf_tables_core.c:288
 nft_do_chain_ipv4+0x1a5/0x230 net/netfilter/nft_chain_fi…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-hwhh-xm47-jghm</guid>
    </item>
    <item>
      <title>ICSA-26-209-04 — Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-26-209-04</link>
      <description>&lt;p&gt;Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.6 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant).&lt;/p&gt;
&lt;p&gt;Siemens is preparing fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.6 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant).&lt;/p&gt;
&lt;p&gt;Siemens is preparing fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-26-209-04</guid>
    </item>
    <item>
      <title>msrc_CVE-2025-21959 — netfilter: nf_conncount: Fully initialize struct nf_conncount_tuple in insert_tree()</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2025-21959</link>
      <description>msrc_CVE-2025-21959</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2025-21959</guid>
    </item>
    <item>
      <title>OESA-2025-2077 — kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2025-2077</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;mac802154: check local interfaces before deleting sdata list&lt;/p&gt;
&lt;p&gt;syzkaller reported a corrupted list in ieee802154_if_remove. [1]&lt;/p&gt;
&lt;p&gt;Remove an IEEE 802.15.4 network interface after unregister an IEEE 802.15.4
hardware device from the system.&lt;/p&gt;
&lt;p&gt;CPU0					CPU1
====					====
genl_family_rcv_msg_doit		ieee802154_unregister_hw
ieee802154_del_iface			ieee802154_remove_interfaces
rdev_del_virtual_intf_deprecated	list_del(&amp;amp;amp;sdata-&amp;amp;gt;list)
ieee802154_if_remove
list_del_rcu&lt;/p&gt;
&lt;p&gt;The net device has been unregistered, since the rcu grace period,
unregistration must be run before ieee802154_if_remove.&lt;/p&gt;
&lt;p&gt;To avoid this issue, add a check for local-&amp;amp;gt;interfaces before deleting
sdata list.&lt;/p&gt;
&lt;p&gt;[1]
kernel BUG at lib/list_debug.c:58!
Oops: invalid opcode: 0000 [#1] PREEMPT SMP KASAN PTI
CPU: 0 UID: 0 PID: 6277 Comm: syz-executor157 Not tainted 6.12.0-rc6-syzkaller-00005-g557329bcecc2 #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 09/13/2024
RIP: 0010:__list_del_entry_valid_or_report+0xf4/0x140 lib/list_debug.c:56
Code: e8 a1 7e 00 07 90 0f 0b 48 c7 c7 e0 37 60 8c 4c 89 fe e8 8f 7e 00 07 90 0f 0b 48 c7 c7 40 38 60 8c 4c 89 fe e8 7d 7e 00 07 90 &amp;amp;lt;0f&amp;amp;gt; 0b 48 c7 c7 a0 38 60 8c 4c 89 fe e8 6b 7e 00 07 90 0f 0b 48 c7
RSP: 0018:ffffc9000490f3d0 EFLAGS: 00010246
RAX: 000000000000004e RBX: dead000000000122 RCX: d211eee56bb28d00
RDX:…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;mac802154: check local interfaces before deleting sdata list&lt;/p&gt;
&lt;p&gt;syzkaller reported a corrupted list in ieee802154_if_remove. [1]&lt;/p&gt;
&lt;p&gt;Remove an IEEE 802.15.4 network interface after unregister an IEEE 802.15.4
hardware device from the system.&lt;/p&gt;
&lt;p&gt;CPU0					CPU1
====					====
genl_family_rcv_msg_doit		ieee802154_unregister_hw
ieee802154_del_iface			ieee802154_remove_interfaces
rdev_del_virtual_intf_deprecated	list_del(&amp;amp;amp;sdata-&amp;amp;gt;list)
ieee802154_if_remove
list_del_rcu&lt;/p&gt;
&lt;p&gt;The net device has been unregistered, since the rcu grace period,
unregistration must be run before ieee802154_if_remove.&lt;/p&gt;
&lt;p&gt;To avoid this issue, add a check for local-&amp;amp;gt;interfaces before deleting
sdata list.&lt;/p&gt;
&lt;p&gt;[1]
kernel BUG at lib/list_debug.c:58!
Oops: invalid opcode: 0000 [#1] PREEMPT SMP KASAN PTI
CPU: 0 UID: 0 PID: 6277 Comm: syz-executor157 Not tainted 6.12.0-rc6-syzkaller-00005-g557329bcecc2 #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 09/13/2024
RIP: 0010:__list_del_entry_valid_or_report+0xf4/0x140 lib/list_debug.c:56
Code: e8 a1 7e 00 07 90 0f 0b 48 c7 c7 e0 37 60 8c 4c 89 fe e8 8f 7e 00 07 90 0f 0b 48 c7 c7 40 38 60 8c 4c 89 fe e8 7d 7e 00 07 90 &amp;amp;lt;0f&amp;amp;gt; 0b 48 c7 c7 a0 38 60 8c 4c 89 fe e8 6b 7e 00 07 90 0f 0b 48 c7
RSP: 0018:ffffc9000490f3d0 EFLAGS: 00010246
RAX: 000000000000004e RBX: dead000000000122 RCX: d211eee56bb28d00
RDX:…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2025-2077</guid>
    </item>
    <item>
      <title>SSA-019113 — SSA-019113: Vulnerabilities in the additional GNU/Linux subsystem of the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1.6</title>
      <link>https://cve.radiocsirt.org/vuln/ssa-019113</link>
      <description>&lt;p&gt;Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.6 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant).&lt;/p&gt;
&lt;p&gt;Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.6 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant).&lt;/p&gt;
&lt;p&gt;Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ssa-019113</guid>
    </item>
    <item>
      <title>SUSE-SU-2025:02249-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2025:02249-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2025:02249-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-21959</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-21959</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux, Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe and 201 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conncount: Fully initialize struct nf_conncount_tuple in insert_tree() Since commit b36e4523d4d5 (&amp;#34;netfilter: nf_conncount: fix garbage collection confirm race&amp;#34;), `cpu` and `jiffies32` were introduced to the struct nf_conncount_tuple. The commit made nf_conncount_add() initialize `conn-&amp;gt;cpu` and `conn-&amp;gt;jiffies32` when allocating the struct. In contrast, count_tree() was not changed to initialize them. By commit 34848d5c896e (&amp;#34;netfilter: nf_conncount: Split insert and traversal&amp;#34;), count_tree() was split and the relevant allocation code now resides in insert_tree(). Initialize `conn-&amp;gt;cpu` and `conn-&amp;gt;jiffies32` in insert_tree(). BUG: KMSAN: uninit-value in find_or_evict net/netfilter/nf_conncount.c:117 [inline] BUG: KMSAN: uninit-value in __nf_conncount_add+0xd9c/0x2850 net/netfilter/nf_conncount.c:143  find_or_evict net/netfilter/nf_conncount.c:117 [inline]  __nf_conncount_add+0xd9c/0x2850 net/netfilter/nf_conncount.c:143  count_tree net/netfilter/nf_conncount.c:438 [inline]  nf_conncount_count+0x82f/0x1e80 net/netfilter/nf_conncount.c:521  connlimit_mt+0x7f6/0xbd0 net/netfilter/xt_connlimit.c:72  __nft_match_eval net/netfilter/nft_compat.c:403 [inline]  nft_match_eval+0x1a5/0x300 net/netfilter/nft_compat.c:433  expr_call_ops_eval net/netfilter/nf_tables_core.c:240 [inline]  nft_do_chain+0x426/0x2290 net/netfilter/nf_tables_core.c:288  nft_do_chain_ipv4+0x1a5/0x230 net/netfilter/nft_chain_filter.…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux, Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe and 201 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conncount: Fully initialize struct nf_conncount_tuple in insert_tree() Since commit b36e4523d4d5 (&amp;#34;netfilter: nf_conncount: fix garbage collection confirm race&amp;#34;), `cpu` and `jiffies32` were introduced to the struct nf_conncount_tuple. The commit made nf_conncount_add() initialize `conn-&amp;gt;cpu` and `conn-&amp;gt;jiffies32` when allocating the struct. In contrast, count_tree() was not changed to initialize them. By commit 34848d5c896e (&amp;#34;netfilter: nf_conncount: Split insert and traversal&amp;#34;), count_tree() was split and the relevant allocation code now resides in insert_tree(). Initialize `conn-&amp;gt;cpu` and `conn-&amp;gt;jiffies32` in insert_tree(). BUG: KMSAN: uninit-value in find_or_evict net/netfilter/nf_conncount.c:117 [inline] BUG: KMSAN: uninit-value in __nf_conncount_add+0xd9c/0x2850 net/netfilter/nf_conncount.c:143  find_or_evict net/netfilter/nf_conncount.c:117 [inline]  __nf_conncount_add+0xd9c/0x2850 net/netfilter/nf_conncount.c:143  count_tree net/netfilter/nf_conncount.c:438 [inline]  nf_conncount_count+0x82f/0x1e80 net/netfilter/nf_conncount.c:521  connlimit_mt+0x7f6/0xbd0 net/netfilter/xt_connlimit.c:72  __nft_match_eval net/netfilter/nft_compat.c:403 [inline]  nft_match_eval+0x1a5/0x300 net/netfilter/nft_compat.c:433  expr_call_ops_eval net/netfilter/nf_tables_core.c:240 [inline]  nft_do_chain+0x426/0x2290 net/netfilter/nf_tables_core.c:288  nft_do_chain_ipv4+0x1a5/0x230 net/netfilter/nft_chain_filter.…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-21959</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-0683 — Linux Kernel: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0683</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Linux Kernel ausnutzen, um einen Denial-of-Service auszulösen und um nicht näher spezifizierte Auswirkungen zu erzielen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Linux Kernel ausnutzen, um einen Denial-of-Service auszulösen und um nicht näher spezifizierte Auswirkungen zu erzielen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0683</guid>
    </item>
  </channel>
</rss>
