<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 07:50:16 +0000</lastBuildDate>
    <item>
      <title>bdu:2025-11810</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-11810</link>
      <description>bdu:2025-11810</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-11810</guid>
    </item>
    <item>
      <title>BELL-CVE-2025-22095</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2025-22095</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2025-22095</guid>
    </item>
    <item>
      <title>certfr-2025-avi-0368 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de Debian. Elles permettent à un attaquant de provo…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0368</link>
      <description>certfr-2025-avi-0368</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0368</guid>
    </item>
    <item>
      <title>EUVD-2026-364522</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-364522</link>
      <description>EUVD-2026-364522</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-364522</guid>
    </item>
    <item>
      <title>fkie_cve-2025-22095</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-22095</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;PCI: brcmstb: Fix error path after a call to regulator_bulk_get()&lt;/p&gt;
&lt;p&gt;If the regulator_bulk_get() returns an error and no regulators
are created, we need to set their number to zero.&lt;/p&gt;
&lt;p&gt;If we don&amp;#39;t do this and the PCIe link up fails, a call to the
regulator_bulk_free() will result in a kernel panic.&lt;/p&gt;
&lt;p&gt;While at it, print the error value, as we cannot return an error
upwards as the kernel will WARN() on an error from add_bus().&lt;/p&gt;
&lt;p&gt;[kwilczynski: commit log, use comma in the message to match style with
other similar messages]&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;PCI: brcmstb: Fix error path after a call to regulator_bulk_get()&lt;/p&gt;
&lt;p&gt;If the regulator_bulk_get() returns an error and no regulators
are created, we need to set their number to zero.&lt;/p&gt;
&lt;p&gt;If we don&amp;#39;t do this and the PCIe link up fails, a call to the
regulator_bulk_free() will result in a kernel panic.&lt;/p&gt;
&lt;p&gt;While at it, print the error value, as we cannot return an error
upwards as the kernel will WARN() on an error from add_bus().&lt;/p&gt;
&lt;p&gt;[kwilczynski: commit log, use comma in the message to match style with
other similar messages]&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-22095</guid>
    </item>
    <item>
      <title>GHSA-6hqx-m227-83p9</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-6hqx-m227-83p9</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;PCI: brcmstb: Fix error path after a call to regulator_bulk_get()&lt;/p&gt;
&lt;p&gt;If the regulator_bulk_get() returns an error and no regulators
are created, we need to set their number to zero.&lt;/p&gt;
&lt;p&gt;If we don&amp;#39;t do this and the PCIe link up fails, a call to the
regulator_bulk_free() will result in a kernel panic.&lt;/p&gt;
&lt;p&gt;While at it, print the error value, as we cannot return an error
upwards as the kernel will WARN() on an error from add_bus().&lt;/p&gt;
&lt;p&gt;[kwilczynski: commit log, use comma in the message to match style with
other similar messages]&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;PCI: brcmstb: Fix error path after a call to regulator_bulk_get()&lt;/p&gt;
&lt;p&gt;If the regulator_bulk_get() returns an error and no regulators
are created, we need to set their number to zero.&lt;/p&gt;
&lt;p&gt;If we don&amp;#39;t do this and the PCIe link up fails, a call to the
regulator_bulk_free() will result in a kernel panic.&lt;/p&gt;
&lt;p&gt;While at it, print the error value, as we cannot return an error
upwards as the kernel will WARN() on an error from add_bus().&lt;/p&gt;
&lt;p&gt;[kwilczynski: commit log, use comma in the message to match style with
other similar messages]&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-6hqx-m227-83p9</guid>
    </item>
    <item>
      <title>ICSA-26-209-04 — Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-26-209-04</link>
      <description>&lt;p&gt;Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.6 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant).&lt;/p&gt;
&lt;p&gt;Siemens is preparing fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.6 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant).&lt;/p&gt;
&lt;p&gt;Siemens is preparing fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-26-209-04</guid>
    </item>
    <item>
      <title>OESA-2025-1463 — kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2025-1463</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;PCI/ASPM: Fix link state exit during switch upstream function removal&lt;/p&gt;
&lt;p&gt;Before 456d8aa37d0f (&amp;amp;quot;PCI/ASPM: Disable ASPM on MFD function removal to
avoid use-after-free&amp;amp;quot;), we would free the ASPM link only after the last
function on the bus pertaining to the given link was removed.&lt;/p&gt;
&lt;p&gt;That was too late. If function 0 is removed before sibling function,
link-&amp;amp;gt;downstream would point to free&amp;amp;apos;d memory after.&lt;/p&gt;
&lt;p&gt;After above change, we freed the ASPM parent link state upon any function
removal on the bus pertaining to a given link.&lt;/p&gt;
&lt;p&gt;That is too early. If the link is to a PCIe switch with MFD on the upstream
port, then removing functions other than 0 first would free a link which
still remains parent_link to the remaining downstream ports.&lt;/p&gt;
&lt;p&gt;The resulting GPFs are especially frequent during hot-unplug, because
pciehp removes devices on the link bus in reverse order.&lt;/p&gt;
&lt;p&gt;On that switch, function 0 is the virtual P2P bridge to the internal bus.
Free exactly when function 0 is removed -- before the parent link is
obsolete, but after all subordinate links are gone.&lt;/p&gt;
&lt;p&gt;[kwilczynski: commit log](CVE-2024-58093)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;jfs: add check read-only before truncation in jfs_truncate_nolock()&lt;/p&gt;
&lt;p&gt;Added a check for &amp;amp;quot;read-only&amp;amp;quot; mode in the `jfs_truncate_nolock`
function to avoid errors…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;PCI/ASPM: Fix link state exit during switch upstream function removal&lt;/p&gt;
&lt;p&gt;Before 456d8aa37d0f (&amp;amp;quot;PCI/ASPM: Disable ASPM on MFD function removal to
avoid use-after-free&amp;amp;quot;), we would free the ASPM link only after the last
function on the bus pertaining to the given link was removed.&lt;/p&gt;
&lt;p&gt;That was too late. If function 0 is removed before sibling function,
link-&amp;amp;gt;downstream would point to free&amp;amp;apos;d memory after.&lt;/p&gt;
&lt;p&gt;After above change, we freed the ASPM parent link state upon any function
removal on the bus pertaining to a given link.&lt;/p&gt;
&lt;p&gt;That is too early. If the link is to a PCIe switch with MFD on the upstream
port, then removing functions other than 0 first would free a link which
still remains parent_link to the remaining downstream ports.&lt;/p&gt;
&lt;p&gt;The resulting GPFs are especially frequent during hot-unplug, because
pciehp removes devices on the link bus in reverse order.&lt;/p&gt;
&lt;p&gt;On that switch, function 0 is the virtual P2P bridge to the internal bus.
Free exactly when function 0 is removed -- before the parent link is
obsolete, but after all subordinate links are gone.&lt;/p&gt;
&lt;p&gt;[kwilczynski: commit log](CVE-2024-58093)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;jfs: add check read-only before truncation in jfs_truncate_nolock()&lt;/p&gt;
&lt;p&gt;Added a check for &amp;amp;quot;read-only&amp;amp;quot; mode in the `jfs_truncate_nolock`
function to avoid errors…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2025-1463</guid>
    </item>
    <item>
      <title>SSA-019113 — SSA-019113: Vulnerabilities in the additional GNU/Linux subsystem of the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1.6</title>
      <link>https://cve.radiocsirt.org/vuln/ssa-019113</link>
      <description>&lt;p&gt;Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.6 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant).&lt;/p&gt;
&lt;p&gt;Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.6 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant).&lt;/p&gt;
&lt;p&gt;Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ssa-019113</guid>
    </item>
    <item>
      <title>SUSE-SU-2025:01964-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2025:01964-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2025:01964-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-22095</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-22095</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 112 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: PCI: brcmstb: Fix error path after a call to regulator_bulk_get() If the regulator_bulk_get() returns an error and no regulators are created, we need to set their number to zero. If we don&amp;#39;t do this and the PCIe link up fails, a call to the regulator_bulk_free() will result in a kernel panic. While at it, print the error value, as we cannot return an error upwards as the kernel will WARN() on an error from add_bus(). [kwilczynski: commit log, use comma in the message to match style with other similar messages]&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 112 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: PCI: brcmstb: Fix error path after a call to regulator_bulk_get() If the regulator_bulk_get() returns an error and no regulators are created, we need to set their number to zero. If we don&amp;#39;t do this and the PCIe link up fails, a call to the regulator_bulk_free() will result in a kernel panic. While at it, print the error value, as we cannot return an error upwards as the kernel will WARN() on an error from add_bus(). [kwilczynski: commit log, use comma in the message to match style with other similar messages]&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-22095</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-0844 — Linux Kernel: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0844</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen oder andere, nicht genauer beschriebene Auswirkungen erzielen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen oder andere, nicht genauer beschriebene Auswirkungen erzielen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0844</guid>
    </item>
  </channel>
</rss>
