<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 00:32:53 +0000</lastBuildDate>
    <item>
      <title>BELL-CVE-2025-23139</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2025-23139</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2025-23139</guid>
    </item>
    <item>
      <title>fkie_cve-2025-23139</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-23139</link>
      <description>&lt;p&gt;Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-23139</guid>
    </item>
    <item>
      <title>GHSA-j8gp-j2vw-f2f6</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-j8gp-j2vw-f2f6</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;Bluetooth: hci_uart: Fix another race during initialization&lt;/p&gt;
&lt;p&gt;Do not set &amp;#39;HCI_UART_PROTO_READY&amp;#39; before call &amp;#39;hci_uart_register_dev()&amp;#39;.
Possible race is when someone calls &amp;#39;hci_tty_uart_close()&amp;#39; after this bit
is set, but &amp;#39;hci_uart_register_dev()&amp;#39; wasn&amp;#39;t done. This leads to access
to uninitialized fields. To fix it let&amp;#39;s set this bit after device was
registered (as before patch c411c62cc133) and to fix previous problem let&amp;#39;s
add one more bit in addition to &amp;#39;HCI_UART_PROTO_READY&amp;#39; which allows to
perform power up without original bit set (pls see commit c411c62cc133).&lt;/p&gt;
&lt;p&gt;Crash backtrace from syzbot report:&lt;/p&gt;
&lt;p&gt;RIP: 0010:skb_queue_empty_lockless include/linux/skbuff.h:1887 [inline]
RIP: 0010:skb_queue_purge_reason+0x6d/0x140 net/core/skbuff.c:3936&lt;/p&gt;
&lt;p&gt;Call Trace:
 &amp;lt;TASK&amp;gt;
 skb_queue_purge include/linux/skbuff.h:3364 [inline]
 mrvl_close+0x2f/0x90 drivers/bluetooth/hci_mrvl.c:100
 hci_uart_tty_close+0xb6/0x120 drivers/bluetooth/hci_ldisc.c:557
 tty_ldisc_close drivers/tty/tty_ldisc.c:455 [inline]
 tty_ldisc_kill+0x66/0xc0 drivers/tty/tty_ldisc.c:613
 tty_ldisc_release+0xc9/0x120 drivers/tty/tty_ldisc.c:781
 tty_release_struct+0x10/0x80 drivers/tty/tty_io.c:1690
 tty_release+0x4ef/0x640 drivers/tty/tty_io.c:1861
 __fput+0x86/0x2a0 fs/file_table.c:450
 task_work_run+0x82/0xb0 kernel/task_work.c:239
 resume_user_mode_work include/linux/resume_user_mode.h:50 [inline]
 exit_to_user_mode_loop kernel/entry/common.c:114 [inline]…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;Bluetooth: hci_uart: Fix another race during initialization&lt;/p&gt;
&lt;p&gt;Do not set &amp;#39;HCI_UART_PROTO_READY&amp;#39; before call &amp;#39;hci_uart_register_dev()&amp;#39;.
Possible race is when someone calls &amp;#39;hci_tty_uart_close()&amp;#39; after this bit
is set, but &amp;#39;hci_uart_register_dev()&amp;#39; wasn&amp;#39;t done. This leads to access
to uninitialized fields. To fix it let&amp;#39;s set this bit after device was
registered (as before patch c411c62cc133) and to fix previous problem let&amp;#39;s
add one more bit in addition to &amp;#39;HCI_UART_PROTO_READY&amp;#39; which allows to
perform power up without original bit set (pls see commit c411c62cc133).&lt;/p&gt;
&lt;p&gt;Crash backtrace from syzbot report:&lt;/p&gt;
&lt;p&gt;RIP: 0010:skb_queue_empty_lockless include/linux/skbuff.h:1887 [inline]
RIP: 0010:skb_queue_purge_reason+0x6d/0x140 net/core/skbuff.c:3936&lt;/p&gt;
&lt;p&gt;Call Trace:
 &amp;lt;TASK&amp;gt;
 skb_queue_purge include/linux/skbuff.h:3364 [inline]
 mrvl_close+0x2f/0x90 drivers/bluetooth/hci_mrvl.c:100
 hci_uart_tty_close+0xb6/0x120 drivers/bluetooth/hci_ldisc.c:557
 tty_ldisc_close drivers/tty/tty_ldisc.c:455 [inline]
 tty_ldisc_kill+0x66/0xc0 drivers/tty/tty_ldisc.c:613
 tty_ldisc_release+0xc9/0x120 drivers/tty/tty_ldisc.c:781
 tty_release_struct+0x10/0x80 drivers/tty/tty_io.c:1690
 tty_release+0x4ef/0x640 drivers/tty/tty_io.c:1861
 __fput+0x86/0x2a0 fs/file_table.c:450
 task_work_run+0x82/0xb0 kernel/task_work.c:239
 resume_user_mode_work include/linux/resume_user_mode.h:50 [inline]
 exit_to_user_mode_loop kernel/entry/common.c:114 [inline]…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-j8gp-j2vw-f2f6</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-23139</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-23139</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 70 more&lt;/p&gt;
&lt;p&gt;Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 70 more&lt;/p&gt;
&lt;p&gt;Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-23139</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-0922 — Linux Kernel: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0922</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Linux Kernel ausnutzen, um einen Denial of Service Angriff und nicht näher spezifizierte Angriffe durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Linux Kernel ausnutzen, um einen Denial of Service Angriff und nicht näher spezifizierte Angriffe durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0922</guid>
    </item>
  </channel>
</rss>
