<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 05:50:21 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-02547</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-02547</link>
      <description>bdu:2026-02547</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-02547</guid>
    </item>
    <item>
      <title>BELL-CVE-2025-22083</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2025-22083</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2025-22083</guid>
    </item>
    <item>
      <title>certfr-2025-avi-0559 — De multiples vulnérabilités ont été découvertes dans le noyau Linux d'Ubuntu. Certaines d'entre elles permettent à un a…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0559</link>
      <description>certfr-2025-avi-0559</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0559</guid>
    </item>
    <item>
      <title>EUVD-2026-364520</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-364520</link>
      <description>EUVD-2026-364520</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-364520</guid>
    </item>
    <item>
      <title>fkie_cve-2025-22083</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-22083</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;vhost-scsi: Fix handling of multiple calls to vhost_scsi_set_endpoint&lt;/p&gt;
&lt;p&gt;If vhost_scsi_set_endpoint is called multiple times without a
vhost_scsi_clear_endpoint between them, we can hit multiple bugs
found by Haoran Zhang:&lt;/p&gt;
&lt;p&gt;1. Use-after-free when no tpgs are found:&lt;/p&gt;
&lt;p&gt;This fixes a use after free that occurs when vhost_scsi_set_endpoint is
called more than once and calls after the first call do not find any
tpgs to add to the vs_tpg. When vhost_scsi_set_endpoint first finds
tpgs to add to the vs_tpg array match=true, so we will do:&lt;/p&gt;
&lt;p&gt;vhost_vq_set_backend(vq, vs_tpg);
...&lt;/p&gt;
&lt;p&gt;kfree(vs-&amp;gt;vs_tpg);
vs-&amp;gt;vs_tpg = vs_tpg;&lt;/p&gt;
&lt;p&gt;If vhost_scsi_set_endpoint is called again and no tpgs are found
match=false so we skip the vhost_vq_set_backend call leaving the
pointer to the vs_tpg we then free via:&lt;/p&gt;
&lt;p&gt;kfree(vs-&amp;gt;vs_tpg);
vs-&amp;gt;vs_tpg = vs_tpg;&lt;/p&gt;
&lt;p&gt;If a scsi request is then sent we do:&lt;/p&gt;
&lt;p&gt;vhost_scsi_handle_vq -&amp;gt; vhost_scsi_get_req -&amp;gt; vhost_vq_get_backend&lt;/p&gt;
&lt;p&gt;which sees the vs_tpg we just did a kfree on.&lt;/p&gt;
&lt;p&gt;2. Tpg dir removal hang:&lt;/p&gt;
&lt;p&gt;This patch fixes an issue where we cannot remove a LIO/target layer
tpg (and structs above it like the target) dir due to the refcount
dropping to -1.&lt;/p&gt;
&lt;p&gt;The problem is that if vhost_scsi_set_endpoint detects a tpg is already
in the vs-&amp;gt;vs_tpg array or if the tpg has been removed so
target_depend_item fails, the undepend goto handler will do
target_undepend_item on all tpgs in the vs_tpg array dropping their
refcount to 0.…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;vhost-scsi: Fix handling of multiple calls to vhost_scsi_set_endpoint&lt;/p&gt;
&lt;p&gt;If vhost_scsi_set_endpoint is called multiple times without a
vhost_scsi_clear_endpoint between them, we can hit multiple bugs
found by Haoran Zhang:&lt;/p&gt;
&lt;p&gt;1. Use-after-free when no tpgs are found:&lt;/p&gt;
&lt;p&gt;This fixes a use after free that occurs when vhost_scsi_set_endpoint is
called more than once and calls after the first call do not find any
tpgs to add to the vs_tpg. When vhost_scsi_set_endpoint first finds
tpgs to add to the vs_tpg array match=true, so we will do:&lt;/p&gt;
&lt;p&gt;vhost_vq_set_backend(vq, vs_tpg);
...&lt;/p&gt;
&lt;p&gt;kfree(vs-&amp;gt;vs_tpg);
vs-&amp;gt;vs_tpg = vs_tpg;&lt;/p&gt;
&lt;p&gt;If vhost_scsi_set_endpoint is called again and no tpgs are found
match=false so we skip the vhost_vq_set_backend call leaving the
pointer to the vs_tpg we then free via:&lt;/p&gt;
&lt;p&gt;kfree(vs-&amp;gt;vs_tpg);
vs-&amp;gt;vs_tpg = vs_tpg;&lt;/p&gt;
&lt;p&gt;If a scsi request is then sent we do:&lt;/p&gt;
&lt;p&gt;vhost_scsi_handle_vq -&amp;gt; vhost_scsi_get_req -&amp;gt; vhost_vq_get_backend&lt;/p&gt;
&lt;p&gt;which sees the vs_tpg we just did a kfree on.&lt;/p&gt;
&lt;p&gt;2. Tpg dir removal hang:&lt;/p&gt;
&lt;p&gt;This patch fixes an issue where we cannot remove a LIO/target layer
tpg (and structs above it like the target) dir due to the refcount
dropping to -1.&lt;/p&gt;
&lt;p&gt;The problem is that if vhost_scsi_set_endpoint detects a tpg is already
in the vs-&amp;gt;vs_tpg array or if the tpg has been removed so
target_depend_item fails, the undepend goto handler will do
target_undepend_item on all tpgs in the vs_tpg array dropping their
refcount to 0.…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-22083</guid>
    </item>
    <item>
      <title>GHSA-vcjc-q999-g4p2</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-vcjc-q999-g4p2</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;vhost-scsi: Fix handling of multiple calls to vhost_scsi_set_endpoint&lt;/p&gt;
&lt;p&gt;If vhost_scsi_set_endpoint is called multiple times without a
vhost_scsi_clear_endpoint between them, we can hit multiple bugs
found by Haoran Zhang:&lt;/p&gt;
&lt;p&gt;1. Use-after-free when no tpgs are found:&lt;/p&gt;
&lt;p&gt;This fixes a use after free that occurs when vhost_scsi_set_endpoint is
called more than once and calls after the first call do not find any
tpgs to add to the vs_tpg. When vhost_scsi_set_endpoint first finds
tpgs to add to the vs_tpg array match=true, so we will do:&lt;/p&gt;
&lt;p&gt;vhost_vq_set_backend(vq, vs_tpg);
...&lt;/p&gt;
&lt;p&gt;kfree(vs-&amp;gt;vs_tpg);
vs-&amp;gt;vs_tpg = vs_tpg;&lt;/p&gt;
&lt;p&gt;If vhost_scsi_set_endpoint is called again and no tpgs are found
match=false so we skip the vhost_vq_set_backend call leaving the
pointer to the vs_tpg we then free via:&lt;/p&gt;
&lt;p&gt;kfree(vs-&amp;gt;vs_tpg);
vs-&amp;gt;vs_tpg = vs_tpg;&lt;/p&gt;
&lt;p&gt;If a scsi request is then sent we do:&lt;/p&gt;
&lt;p&gt;vhost_scsi_handle_vq -&amp;gt; vhost_scsi_get_req -&amp;gt; vhost_vq_get_backend&lt;/p&gt;
&lt;p&gt;which sees the vs_tpg we just did a kfree on.&lt;/p&gt;
&lt;p&gt;2. Tpg dir removal hang:&lt;/p&gt;
&lt;p&gt;This patch fixes an issue where we cannot remove a LIO/target layer
tpg (and structs above it like the target) dir due to the refcount
dropping to -1.&lt;/p&gt;
&lt;p&gt;The problem is that if vhost_scsi_set_endpoint detects a tpg is already
in the vs-&amp;gt;vs_tpg array or if the tpg has been removed so
target_depend_item fails, the undepend goto handler will do
target_undepend_item on all tpgs in the vs_tpg array dropping their
refcount to 0.…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;vhost-scsi: Fix handling of multiple calls to vhost_scsi_set_endpoint&lt;/p&gt;
&lt;p&gt;If vhost_scsi_set_endpoint is called multiple times without a
vhost_scsi_clear_endpoint between them, we can hit multiple bugs
found by Haoran Zhang:&lt;/p&gt;
&lt;p&gt;1. Use-after-free when no tpgs are found:&lt;/p&gt;
&lt;p&gt;This fixes a use after free that occurs when vhost_scsi_set_endpoint is
called more than once and calls after the first call do not find any
tpgs to add to the vs_tpg. When vhost_scsi_set_endpoint first finds
tpgs to add to the vs_tpg array match=true, so we will do:&lt;/p&gt;
&lt;p&gt;vhost_vq_set_backend(vq, vs_tpg);
...&lt;/p&gt;
&lt;p&gt;kfree(vs-&amp;gt;vs_tpg);
vs-&amp;gt;vs_tpg = vs_tpg;&lt;/p&gt;
&lt;p&gt;If vhost_scsi_set_endpoint is called again and no tpgs are found
match=false so we skip the vhost_vq_set_backend call leaving the
pointer to the vs_tpg we then free via:&lt;/p&gt;
&lt;p&gt;kfree(vs-&amp;gt;vs_tpg);
vs-&amp;gt;vs_tpg = vs_tpg;&lt;/p&gt;
&lt;p&gt;If a scsi request is then sent we do:&lt;/p&gt;
&lt;p&gt;vhost_scsi_handle_vq -&amp;gt; vhost_scsi_get_req -&amp;gt; vhost_vq_get_backend&lt;/p&gt;
&lt;p&gt;which sees the vs_tpg we just did a kfree on.&lt;/p&gt;
&lt;p&gt;2. Tpg dir removal hang:&lt;/p&gt;
&lt;p&gt;This patch fixes an issue where we cannot remove a LIO/target layer
tpg (and structs above it like the target) dir due to the refcount
dropping to -1.&lt;/p&gt;
&lt;p&gt;The problem is that if vhost_scsi_set_endpoint detects a tpg is already
in the vs-&amp;gt;vs_tpg array or if the tpg has been removed so
target_depend_item fails, the undepend goto handler will do
target_undepend_item on all tpgs in the vs_tpg array dropping their
refcount to 0.…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-vcjc-q999-g4p2</guid>
    </item>
    <item>
      <title>ICSA-26-209-04 — Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-26-209-04</link>
      <description>&lt;p&gt;Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.6 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant).&lt;/p&gt;
&lt;p&gt;Siemens is preparing fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.6 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant).&lt;/p&gt;
&lt;p&gt;Siemens is preparing fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-26-209-04</guid>
    </item>
    <item>
      <title>msrc_CVE-2025-22083 — vhost-scsi: Fix handling of multiple calls to vhost_scsi_set_endpoint</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2025-22083</link>
      <description>msrc_CVE-2025-22083</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2025-22083</guid>
    </item>
    <item>
      <title>OESA-2025-2774 — kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2025-2774</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;mm: zswap: properly synchronize freeing resources during CPU hotunplug&lt;/p&gt;
&lt;p&gt;In zswap_compress() and zswap_decompress(), the per-CPU acomp_ctx of the
current CPU at the beginning of the operation is retrieved and used
throughout.  However, since neither preemption nor migration are disabled,
it is possible that the operation continues on a different CPU.&lt;/p&gt;
&lt;p&gt;If the original CPU is hotunplugged while the acomp_ctx is still in use,
we run into a UAF bug as some of the resources attached to the acomp_ctx
are freed during hotunplug in zswap_cpu_comp_dead() (i.e. 
acomp_ctx.buffer, acomp_ctx.req, or acomp_ctx.acomp).&lt;/p&gt;
&lt;p&gt;The problem was introduced in commit 1ec3b5fe6eec (&amp;amp;quot;mm/zswap: move to use
crypto_acomp API for hardware acceleration&amp;amp;quot;) when the switch to the
crypto_acomp API was made.  Prior to that, the per-CPU crypto_comp was
retrieved using get_cpu_ptr() which disables preemption and makes sure the
CPU cannot go away from under us.  Preemption cannot be disabled with the
crypto_acomp API as a sleepable context is needed.&lt;/p&gt;
&lt;p&gt;Use the acomp_ctx.mutex to synchronize CPU hotplug callbacks allocating
and freeing resources with compression/decompression paths.  Make sure
that acomp_ctx.req is NULL when the resources are freed.  In the
compression/decompression paths, check if acomp_ctx.req is NULL after
acquiring the mutex (meaning the CPU was…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;mm: zswap: properly synchronize freeing resources during CPU hotunplug&lt;/p&gt;
&lt;p&gt;In zswap_compress() and zswap_decompress(), the per-CPU acomp_ctx of the
current CPU at the beginning of the operation is retrieved and used
throughout.  However, since neither preemption nor migration are disabled,
it is possible that the operation continues on a different CPU.&lt;/p&gt;
&lt;p&gt;If the original CPU is hotunplugged while the acomp_ctx is still in use,
we run into a UAF bug as some of the resources attached to the acomp_ctx
are freed during hotunplug in zswap_cpu_comp_dead() (i.e. 
acomp_ctx.buffer, acomp_ctx.req, or acomp_ctx.acomp).&lt;/p&gt;
&lt;p&gt;The problem was introduced in commit 1ec3b5fe6eec (&amp;amp;quot;mm/zswap: move to use
crypto_acomp API for hardware acceleration&amp;amp;quot;) when the switch to the
crypto_acomp API was made.  Prior to that, the per-CPU crypto_comp was
retrieved using get_cpu_ptr() which disables preemption and makes sure the
CPU cannot go away from under us.  Preemption cannot be disabled with the
crypto_acomp API as a sleepable context is needed.&lt;/p&gt;
&lt;p&gt;Use the acomp_ctx.mutex to synchronize CPU hotplug callbacks allocating
and freeing resources with compression/decompression paths.  Make sure
that acomp_ctx.req is NULL when the resources are freed.  In the
compression/decompression paths, check if acomp_ctx.req is NULL after
acquiring the mutex (meaning the CPU was…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2025-2774</guid>
    </item>
    <item>
      <title>SSA-019113 — SSA-019113: Vulnerabilities in the additional GNU/Linux subsystem of the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1.6</title>
      <link>https://cve.radiocsirt.org/vuln/ssa-019113</link>
      <description>&lt;p&gt;Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.6 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant).&lt;/p&gt;
&lt;p&gt;Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.6 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant).&lt;/p&gt;
&lt;p&gt;Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ssa-019113</guid>
    </item>
    <item>
      <title>SUSE-SU-2025:02249-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2025:02249-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2025:02249-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-22083</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-22083</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux, Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe and 204 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: vhost-scsi: Fix handling of multiple calls to vhost_scsi_set_endpoint If vhost_scsi_set_endpoint is called multiple times without a vhost_scsi_clear_endpoint between them, we can hit multiple bugs found by Haoran Zhang: 1. Use-after-free when no tpgs are found: This fixes a use after free that occurs when vhost_scsi_set_endpoint is called more than once and calls after the first call do not find any tpgs to add to the vs_tpg. When vhost_scsi_set_endpoint first finds tpgs to add to the vs_tpg array match=true, so we will do: vhost_vq_set_backend(vq, vs_tpg); ... kfree(vs-&amp;gt;vs_tpg); vs-&amp;gt;vs_tpg = vs_tpg; If vhost_scsi_set_endpoint is called again and no tpgs are found match=false so we skip the vhost_vq_set_backend call leaving the pointer to the vs_tpg we then free via: kfree(vs-&amp;gt;vs_tpg); vs-&amp;gt;vs_tpg = vs_tpg; If a scsi request is then sent we do: vhost_scsi_handle_vq -&amp;gt; vhost_scsi_get_req -&amp;gt; vhost_vq_get_backend which sees the vs_tpg we just did a kfree on. 2. Tpg dir removal hang: This patch fixes an issue where we cannot remove a LIO/target layer tpg (and structs above it like the target) dir due to the refcount dropping to -1. The problem is that if vhost_scsi_set_endpoint detects a tpg is already in the vs-&amp;gt;vs_tpg array or if the tpg has been removed so target_depend_item fails, the undepend goto handler will do target_undepend_item on all tpgs in the vs_tpg array dropping their refcount to 0. At this time…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux, Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe and 204 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: vhost-scsi: Fix handling of multiple calls to vhost_scsi_set_endpoint If vhost_scsi_set_endpoint is called multiple times without a vhost_scsi_clear_endpoint between them, we can hit multiple bugs found by Haoran Zhang: 1. Use-after-free when no tpgs are found: This fixes a use after free that occurs when vhost_scsi_set_endpoint is called more than once and calls after the first call do not find any tpgs to add to the vs_tpg. When vhost_scsi_set_endpoint first finds tpgs to add to the vs_tpg array match=true, so we will do: vhost_vq_set_backend(vq, vs_tpg); ... kfree(vs-&amp;gt;vs_tpg); vs-&amp;gt;vs_tpg = vs_tpg; If vhost_scsi_set_endpoint is called again and no tpgs are found match=false so we skip the vhost_vq_set_backend call leaving the pointer to the vs_tpg we then free via: kfree(vs-&amp;gt;vs_tpg); vs-&amp;gt;vs_tpg = vs_tpg; If a scsi request is then sent we do: vhost_scsi_handle_vq -&amp;gt; vhost_scsi_get_req -&amp;gt; vhost_vq_get_backend which sees the vs_tpg we just did a kfree on. 2. Tpg dir removal hang: This patch fixes an issue where we cannot remove a LIO/target layer tpg (and structs above it like the target) dir due to the refcount dropping to -1. The problem is that if vhost_scsi_set_endpoint detects a tpg is already in the vs-&amp;gt;vs_tpg array or if the tpg has been removed so target_depend_item fails, the undepend goto handler will do target_undepend_item on all tpgs in the vs_tpg array dropping their refcount to 0. At this time…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-22083</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-0844 — Linux Kernel: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0844</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen oder andere, nicht genauer beschriebene Auswirkungen erzielen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen oder andere, nicht genauer beschriebene Auswirkungen erzielen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0844</guid>
    </item>
  </channel>
</rss>
