<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 10:20:32 +0000</lastBuildDate>
    <item>
      <title>bdu:2025-11783</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-11783</link>
      <description>bdu:2025-11783</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-11783</guid>
    </item>
    <item>
      <title>BELL-CVE-2025-22014</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2025-22014</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2025-22014</guid>
    </item>
    <item>
      <title>certfr-2025-avi-0333 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de Debian. Elles permettent à un attaquant de provo…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0333</link>
      <description>certfr-2025-avi-0333</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0333</guid>
    </item>
    <item>
      <title>EUVD-2026-314150</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-314150</link>
      <description>EUVD-2026-314150</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-314150</guid>
    </item>
    <item>
      <title>fkie_cve-2025-22014</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-22014</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;soc: qcom: pdr: Fix the potential deadlock&lt;/p&gt;
&lt;p&gt;When some client process A call pdr_add_lookup() to add the look up for
the service and does schedule locator work, later a process B got a new
server packet indicating locator is up and call pdr_locator_new_server()
which eventually sets pdr-&amp;gt;locator_init_complete to true which process A
sees and takes list lock and queries domain list but it will timeout due
to deadlock as the response will queued to the same qmi-&amp;gt;wq and it is
ordered workqueue and process B is not able to complete new server
request work due to deadlock on list lock.&lt;/p&gt;
&lt;p&gt;Fix it by removing the unnecessary list iteration as the list iteration
is already being done inside locator work, so avoid it here and just
call schedule_work() here.&lt;/p&gt;
&lt;p&gt;Process A                        Process B&lt;/p&gt;
&lt;p&gt;process_scheduled_works()
pdr_add_lookup()                      qmi_data_ready_work()
 process_scheduled_works()             pdr_locator_new_server()
                                         pdr-&amp;gt;locator_init_complete=true;
   pdr_locator_work()
    mutex_lock(&amp;amp;pdr-&amp;gt;list_lock);&lt;/p&gt;
&lt;p&gt;pdr_locate_service()                  mutex_lock(&amp;amp;pdr-&amp;gt;list_lock);&lt;/p&gt;
&lt;p&gt;pdr_get_domain_list()
       pr_err(&amp;#34;PDR: %s get domain list
               txn wait failed: %d\n&amp;#34;,
               req-&amp;gt;service_name,
               ret);&lt;/p&gt;
&lt;p&gt;Timeout error log due to deadlock:&lt;/p&gt;
&lt;p&gt;&amp;#34;
 PDR: tms/servreg get domain lis…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;soc: qcom: pdr: Fix the potential deadlock&lt;/p&gt;
&lt;p&gt;When some client process A call pdr_add_lookup() to add the look up for
the service and does schedule locator work, later a process B got a new
server packet indicating locator is up and call pdr_locator_new_server()
which eventually sets pdr-&amp;gt;locator_init_complete to true which process A
sees and takes list lock and queries domain list but it will timeout due
to deadlock as the response will queued to the same qmi-&amp;gt;wq and it is
ordered workqueue and process B is not able to complete new server
request work due to deadlock on list lock.&lt;/p&gt;
&lt;p&gt;Fix it by removing the unnecessary list iteration as the list iteration
is already being done inside locator work, so avoid it here and just
call schedule_work() here.&lt;/p&gt;
&lt;p&gt;Process A                        Process B&lt;/p&gt;
&lt;p&gt;process_scheduled_works()
pdr_add_lookup()                      qmi_data_ready_work()
 process_scheduled_works()             pdr_locator_new_server()
                                         pdr-&amp;gt;locator_init_complete=true;
   pdr_locator_work()
    mutex_lock(&amp;amp;pdr-&amp;gt;list_lock);&lt;/p&gt;
&lt;p&gt;pdr_locate_service()                  mutex_lock(&amp;amp;pdr-&amp;gt;list_lock);&lt;/p&gt;
&lt;p&gt;pdr_get_domain_list()
       pr_err(&amp;#34;PDR: %s get domain list
               txn wait failed: %d\n&amp;#34;,
               req-&amp;gt;service_name,
               ret);&lt;/p&gt;
&lt;p&gt;Timeout error log due to deadlock:&lt;/p&gt;
&lt;p&gt;&amp;#34;
 PDR: tms/servreg get domain lis…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-22014</guid>
    </item>
    <item>
      <title>GHSA-93xm-x65x-hgxh</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-93xm-x65x-hgxh</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;soc: qcom: pdr: Fix the potential deadlock&lt;/p&gt;
&lt;p&gt;When some client process A call pdr_add_lookup() to add the look up for
the service and does schedule locator work, later a process B got a new
server packet indicating locator is up and call pdr_locator_new_server()
which eventually sets pdr-&amp;gt;locator_init_complete to true which process A
sees and takes list lock and queries domain list but it will timeout due
to deadlock as the response will queued to the same qmi-&amp;gt;wq and it is
ordered workqueue and process B is not able to complete new server
request work due to deadlock on list lock.&lt;/p&gt;
&lt;p&gt;Fix it by removing the unnecessary list iteration as the list iteration
is already being done inside locator work, so avoid it here and just
call schedule_work() here.&lt;/p&gt;
&lt;p&gt;Process A                        Process B&lt;/p&gt;
&lt;p&gt;process_scheduled_works()
pdr_add_lookup()                      qmi_data_ready_work()
 process_scheduled_works()             pdr_locator_new_server()
                                         pdr-&amp;gt;locator_init_complete=true;
   pdr_locator_work()
    mutex_lock(&amp;amp;pdr-&amp;gt;list_lock);&lt;/p&gt;
&lt;p&gt;pdr_locate_service()                  mutex_lock(&amp;amp;pdr-&amp;gt;list_lock);&lt;/p&gt;
&lt;p&gt;pdr_get_domain_list()
       pr_err(&amp;#34;PDR: %s get domain list
               txn wait failed: %d\n&amp;#34;,
               req-&amp;gt;service_name,
               ret);&lt;/p&gt;
&lt;p&gt;Timeout error log due to deadlock:&lt;/p&gt;
&lt;p&gt;&amp;#34;
 PDR: tms/servreg get domain lis…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;soc: qcom: pdr: Fix the potential deadlock&lt;/p&gt;
&lt;p&gt;When some client process A call pdr_add_lookup() to add the look up for
the service and does schedule locator work, later a process B got a new
server packet indicating locator is up and call pdr_locator_new_server()
which eventually sets pdr-&amp;gt;locator_init_complete to true which process A
sees and takes list lock and queries domain list but it will timeout due
to deadlock as the response will queued to the same qmi-&amp;gt;wq and it is
ordered workqueue and process B is not able to complete new server
request work due to deadlock on list lock.&lt;/p&gt;
&lt;p&gt;Fix it by removing the unnecessary list iteration as the list iteration
is already being done inside locator work, so avoid it here and just
call schedule_work() here.&lt;/p&gt;
&lt;p&gt;Process A                        Process B&lt;/p&gt;
&lt;p&gt;process_scheduled_works()
pdr_add_lookup()                      qmi_data_ready_work()
 process_scheduled_works()             pdr_locator_new_server()
                                         pdr-&amp;gt;locator_init_complete=true;
   pdr_locator_work()
    mutex_lock(&amp;amp;pdr-&amp;gt;list_lock);&lt;/p&gt;
&lt;p&gt;pdr_locate_service()                  mutex_lock(&amp;amp;pdr-&amp;gt;list_lock);&lt;/p&gt;
&lt;p&gt;pdr_get_domain_list()
       pr_err(&amp;#34;PDR: %s get domain list
               txn wait failed: %d\n&amp;#34;,
               req-&amp;gt;service_name,
               ret);&lt;/p&gt;
&lt;p&gt;Timeout error log due to deadlock:&lt;/p&gt;
&lt;p&gt;&amp;#34;
 PDR: tms/servreg get domain lis…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-93xm-x65x-hgxh</guid>
    </item>
    <item>
      <title>msrc_CVE-2025-22014 — soc: qcom: pdr: Fix the potential deadlock</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2025-22014</link>
      <description>msrc_CVE-2025-22014</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2025-22014</guid>
    </item>
    <item>
      <title>OESA-2025-1463 — kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2025-1463</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;PCI/ASPM: Fix link state exit during switch upstream function removal&lt;/p&gt;
&lt;p&gt;Before 456d8aa37d0f (&amp;amp;quot;PCI/ASPM: Disable ASPM on MFD function removal to
avoid use-after-free&amp;amp;quot;), we would free the ASPM link only after the last
function on the bus pertaining to the given link was removed.&lt;/p&gt;
&lt;p&gt;That was too late. If function 0 is removed before sibling function,
link-&amp;amp;gt;downstream would point to free&amp;amp;apos;d memory after.&lt;/p&gt;
&lt;p&gt;After above change, we freed the ASPM parent link state upon any function
removal on the bus pertaining to a given link.&lt;/p&gt;
&lt;p&gt;That is too early. If the link is to a PCIe switch with MFD on the upstream
port, then removing functions other than 0 first would free a link which
still remains parent_link to the remaining downstream ports.&lt;/p&gt;
&lt;p&gt;The resulting GPFs are especially frequent during hot-unplug, because
pciehp removes devices on the link bus in reverse order.&lt;/p&gt;
&lt;p&gt;On that switch, function 0 is the virtual P2P bridge to the internal bus.
Free exactly when function 0 is removed -- before the parent link is
obsolete, but after all subordinate links are gone.&lt;/p&gt;
&lt;p&gt;[kwilczynski: commit log](CVE-2024-58093)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;jfs: add check read-only before truncation in jfs_truncate_nolock()&lt;/p&gt;
&lt;p&gt;Added a check for &amp;amp;quot;read-only&amp;amp;quot; mode in the `jfs_truncate_nolock`
function to avoid errors…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;PCI/ASPM: Fix link state exit during switch upstream function removal&lt;/p&gt;
&lt;p&gt;Before 456d8aa37d0f (&amp;amp;quot;PCI/ASPM: Disable ASPM on MFD function removal to
avoid use-after-free&amp;amp;quot;), we would free the ASPM link only after the last
function on the bus pertaining to the given link was removed.&lt;/p&gt;
&lt;p&gt;That was too late. If function 0 is removed before sibling function,
link-&amp;amp;gt;downstream would point to free&amp;amp;apos;d memory after.&lt;/p&gt;
&lt;p&gt;After above change, we freed the ASPM parent link state upon any function
removal on the bus pertaining to a given link.&lt;/p&gt;
&lt;p&gt;That is too early. If the link is to a PCIe switch with MFD on the upstream
port, then removing functions other than 0 first would free a link which
still remains parent_link to the remaining downstream ports.&lt;/p&gt;
&lt;p&gt;The resulting GPFs are especially frequent during hot-unplug, because
pciehp removes devices on the link bus in reverse order.&lt;/p&gt;
&lt;p&gt;On that switch, function 0 is the virtual P2P bridge to the internal bus.
Free exactly when function 0 is removed -- before the parent link is
obsolete, but after all subordinate links are gone.&lt;/p&gt;
&lt;p&gt;[kwilczynski: commit log](CVE-2024-58093)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;jfs: add check read-only before truncation in jfs_truncate_nolock()&lt;/p&gt;
&lt;p&gt;Added a check for &amp;amp;quot;read-only&amp;amp;quot; mode in the `jfs_truncate_nolock`
function to avoid errors…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2025-1463</guid>
    </item>
    <item>
      <title>SUSE-SU-2025:01614-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2025:01614-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2025:01614-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-22014</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-22014</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 148 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: soc: qcom: pdr: Fix the potential deadlock When some client process A call pdr_add_lookup() to add the look up for the service and does schedule locator work, later a process B got a new server packet indicating locator is up and call pdr_locator_new_server() which eventually sets pdr-&amp;gt;locator_init_complete to true which process A sees and takes list lock and queries domain list but it will timeout due to deadlock as the response will queued to the same qmi-&amp;gt;wq and it is ordered workqueue and process B is not able to complete new server request work due to deadlock on list lock. Fix it by removing the unnecessary list iteration as the list iteration is already being done inside locator work, so avoid it here and just call schedule_work() here.        Process A                        Process B                                      process_scheduled_works() pdr_add_lookup()                      qmi_data_ready_work()  process_scheduled_works()             pdr_locator_new_server()                                          pdr-&amp;gt;locator_init_complete=true;    pdr_locator_work()     mutex_lock(&amp;amp;pdr-&amp;gt;list_lock);      pdr_locate_service()                  mutex_lock(&amp;amp;pdr-&amp;gt;list_lock);       pdr_get_domain_list()        pr_err(&amp;#34;PDR: %s get domain list                txn wait failed: %d\n&amp;#34;,                req-&amp;gt;service_name,                ret); Timeout error log due to deadlock: &amp;#34;  PDR: tms/servreg get domain list txn wai…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 148 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: soc: qcom: pdr: Fix the potential deadlock When some client process A call pdr_add_lookup() to add the look up for the service and does schedule locator work, later a process B got a new server packet indicating locator is up and call pdr_locator_new_server() which eventually sets pdr-&amp;gt;locator_init_complete to true which process A sees and takes list lock and queries domain list but it will timeout due to deadlock as the response will queued to the same qmi-&amp;gt;wq and it is ordered workqueue and process B is not able to complete new server request work due to deadlock on list lock. Fix it by removing the unnecessary list iteration as the list iteration is already being done inside locator work, so avoid it here and just call schedule_work() here.        Process A                        Process B                                      process_scheduled_works() pdr_add_lookup()                      qmi_data_ready_work()  process_scheduled_works()             pdr_locator_new_server()                                          pdr-&amp;gt;locator_init_complete=true;    pdr_locator_work()     mutex_lock(&amp;amp;pdr-&amp;gt;list_lock);      pdr_locate_service()                  mutex_lock(&amp;amp;pdr-&amp;gt;list_lock);       pdr_get_domain_list()        pr_err(&amp;#34;PDR: %s get domain list                txn wait failed: %d\n&amp;#34;,                req-&amp;gt;service_name,                ret); Timeout error log due to deadlock: &amp;#34;  PDR: tms/servreg get domain list txn wai…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-22014</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-0732 — Linux Kernel: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0732</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux-Kernel ausnutzen, um einen Denial-of-Service-Zustand zu erzeugen oder nicht spezifizierte Angriffe durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux-Kernel ausnutzen, um einen Denial-of-Service-Zustand zu erzeugen oder nicht spezifizierte Angriffe durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0732</guid>
    </item>
  </channel>
</rss>
