<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 17:15:13 +0000</lastBuildDate>
    <item>
      <title>bdu:2025-09044</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-09044</link>
      <description>bdu:2025-09044</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-09044</guid>
    </item>
    <item>
      <title>BELL-CVE-2025-38010</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2025-38010</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2025-38010</guid>
    </item>
    <item>
      <title>certfr-2025-avi-0587 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de SUSE. Certaines d'entre elles permettent à un at…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0587</link>
      <description>certfr-2025-avi-0587</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0587</guid>
    </item>
    <item>
      <title>EUVD-2026-314370</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-314370</link>
      <description>EUVD-2026-314370</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-314370</guid>
    </item>
    <item>
      <title>fkie_cve-2025-38010</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-38010</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;phy: tegra: xusb: Use a bitmask for UTMI pad power state tracking&lt;/p&gt;
&lt;p&gt;The current implementation uses bias_pad_enable as a reference count to
manage the shared bias pad for all UTMI PHYs. However, during system
suspension with connected USB devices, multiple power-down requests for
the UTMI pad result in a mismatch in the reference count, which in turn
produces warnings such as:&lt;/p&gt;
&lt;p&gt;[  237.762967] WARNING: CPU: 10 PID: 1618 at tegra186_utmi_pad_power_down+0x160/0x170
[  237.763103] Call trace:
[  237.763104]  tegra186_utmi_pad_power_down+0x160/0x170
[  237.763107]  tegra186_utmi_phy_power_off+0x10/0x30
[  237.763110]  phy_power_off+0x48/0x100
[  237.763113]  tegra_xusb_enter_elpg+0x204/0x500
[  237.763119]  tegra_xusb_suspend+0x48/0x140
[  237.763122]  platform_pm_suspend+0x2c/0xb0
[  237.763125]  dpm_run_callback.isra.0+0x20/0xa0
[  237.763127]  __device_suspend+0x118/0x330
[  237.763129]  dpm_suspend+0x10c/0x1f0
[  237.763130]  dpm_suspend_start+0x88/0xb0
[  237.763132]  suspend_devices_and_enter+0x120/0x500
[  237.763135]  pm_suspend+0x1ec/0x270&lt;/p&gt;
&lt;p&gt;The root cause was traced back to the dynamic power-down changes
introduced in commit a30951d31b25 (&amp;#34;xhci: tegra: USB2 pad power controls&amp;#34;),
where the UTMI pad was being powered down without verifying its current
state. This unbalanced behavior led to discrepancies in the reference
count.&lt;/p&gt;
&lt;p&gt;To rectify this issue, this patch replaces the single reference counter
with a…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;phy: tegra: xusb: Use a bitmask for UTMI pad power state tracking&lt;/p&gt;
&lt;p&gt;The current implementation uses bias_pad_enable as a reference count to
manage the shared bias pad for all UTMI PHYs. However, during system
suspension with connected USB devices, multiple power-down requests for
the UTMI pad result in a mismatch in the reference count, which in turn
produces warnings such as:&lt;/p&gt;
&lt;p&gt;[  237.762967] WARNING: CPU: 10 PID: 1618 at tegra186_utmi_pad_power_down+0x160/0x170
[  237.763103] Call trace:
[  237.763104]  tegra186_utmi_pad_power_down+0x160/0x170
[  237.763107]  tegra186_utmi_phy_power_off+0x10/0x30
[  237.763110]  phy_power_off+0x48/0x100
[  237.763113]  tegra_xusb_enter_elpg+0x204/0x500
[  237.763119]  tegra_xusb_suspend+0x48/0x140
[  237.763122]  platform_pm_suspend+0x2c/0xb0
[  237.763125]  dpm_run_callback.isra.0+0x20/0xa0
[  237.763127]  __device_suspend+0x118/0x330
[  237.763129]  dpm_suspend+0x10c/0x1f0
[  237.763130]  dpm_suspend_start+0x88/0xb0
[  237.763132]  suspend_devices_and_enter+0x120/0x500
[  237.763135]  pm_suspend+0x1ec/0x270&lt;/p&gt;
&lt;p&gt;The root cause was traced back to the dynamic power-down changes
introduced in commit a30951d31b25 (&amp;#34;xhci: tegra: USB2 pad power controls&amp;#34;),
where the UTMI pad was being powered down without verifying its current
state. This unbalanced behavior led to discrepancies in the reference
count.&lt;/p&gt;
&lt;p&gt;To rectify this issue, this patch replaces the single reference counter
with a…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-38010</guid>
    </item>
    <item>
      <title>GHSA-q4fh-5qfm-8423</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-q4fh-5qfm-8423</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;phy: tegra: xusb: Use a bitmask for UTMI pad power state tracking&lt;/p&gt;
&lt;p&gt;The current implementation uses bias_pad_enable as a reference count to
manage the shared bias pad for all UTMI PHYs. However, during system
suspension with connected USB devices, multiple power-down requests for
the UTMI pad result in a mismatch in the reference count, which in turn
produces warnings such as:&lt;/p&gt;
&lt;p&gt;[  237.762967] WARNING: CPU: 10 PID: 1618 at tegra186_utmi_pad_power_down+0x160/0x170
[  237.763103] Call trace:
[  237.763104]  tegra186_utmi_pad_power_down+0x160/0x170
[  237.763107]  tegra186_utmi_phy_power_off+0x10/0x30
[  237.763110]  phy_power_off+0x48/0x100
[  237.763113]  tegra_xusb_enter_elpg+0x204/0x500
[  237.763119]  tegra_xusb_suspend+0x48/0x140
[  237.763122]  platform_pm_suspend+0x2c/0xb0
[  237.763125]  dpm_run_callback.isra.0+0x20/0xa0
[  237.763127]  __device_suspend+0x118/0x330
[  237.763129]  dpm_suspend+0x10c/0x1f0
[  237.763130]  dpm_suspend_start+0x88/0xb0
[  237.763132]  suspend_devices_and_enter+0x120/0x500
[  237.763135]  pm_suspend+0x1ec/0x270&lt;/p&gt;
&lt;p&gt;The root cause was traced back to the dynamic power-down changes
introduced in commit a30951d31b25 (&amp;#34;xhci: tegra: USB2 pad power controls&amp;#34;),
where the UTMI pad was being powered down without verifying its current
state. This unbalanced behavior led to discrepancies in the reference
count.&lt;/p&gt;
&lt;p&gt;To rectify this issue, this patch replaces the single reference counter
with a…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;phy: tegra: xusb: Use a bitmask for UTMI pad power state tracking&lt;/p&gt;
&lt;p&gt;The current implementation uses bias_pad_enable as a reference count to
manage the shared bias pad for all UTMI PHYs. However, during system
suspension with connected USB devices, multiple power-down requests for
the UTMI pad result in a mismatch in the reference count, which in turn
produces warnings such as:&lt;/p&gt;
&lt;p&gt;[  237.762967] WARNING: CPU: 10 PID: 1618 at tegra186_utmi_pad_power_down+0x160/0x170
[  237.763103] Call trace:
[  237.763104]  tegra186_utmi_pad_power_down+0x160/0x170
[  237.763107]  tegra186_utmi_phy_power_off+0x10/0x30
[  237.763110]  phy_power_off+0x48/0x100
[  237.763113]  tegra_xusb_enter_elpg+0x204/0x500
[  237.763119]  tegra_xusb_suspend+0x48/0x140
[  237.763122]  platform_pm_suspend+0x2c/0xb0
[  237.763125]  dpm_run_callback.isra.0+0x20/0xa0
[  237.763127]  __device_suspend+0x118/0x330
[  237.763129]  dpm_suspend+0x10c/0x1f0
[  237.763130]  dpm_suspend_start+0x88/0xb0
[  237.763132]  suspend_devices_and_enter+0x120/0x500
[  237.763135]  pm_suspend+0x1ec/0x270&lt;/p&gt;
&lt;p&gt;The root cause was traced back to the dynamic power-down changes
introduced in commit a30951d31b25 (&amp;#34;xhci: tegra: USB2 pad power controls&amp;#34;),
where the UTMI pad was being powered down without verifying its current
state. This unbalanced behavior led to discrepancies in the reference
count.&lt;/p&gt;
&lt;p&gt;To rectify this issue, this patch replaces the single reference counter
with a…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-q4fh-5qfm-8423</guid>
    </item>
    <item>
      <title>OESA-2025-2120 — kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2025-2120</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;gtp: Destroy device along with udp socket&amp;amp;apos;s netns dismantle.&lt;/p&gt;
&lt;p&gt;gtp_newlink() links the device to a list in dev_net(dev) instead of
src_net, where a udp tunnel socket is created.&lt;/p&gt;
&lt;p&gt;Even when src_net is removed, the device stays alive on dev_net(dev).
Then, removing src_net triggers the splat below. [0]&lt;/p&gt;
&lt;p&gt;In this example, gtp0 is created in ns2, and the udp socket is created
in ns1.&lt;/p&gt;
&lt;p&gt;ip netns add ns1
  ip netns add ns2
  ip -n ns1 link add netns ns2 name gtp0 type gtp role sgsn
  ip netns del ns1&lt;/p&gt;
&lt;p&gt;Let&amp;amp;apos;s link the device to the socket&amp;amp;apos;s netns instead.&lt;/p&gt;
&lt;p&gt;Now, gtp_net_exit_batch_rtnl() needs another netdev iteration to remove
all gtp devices in the netns.&lt;/p&gt;
&lt;p&gt;[0]:
ref_tracker: net notrefcnt@000000003d6e7d05 has 1/2 users at
     sk_alloc (./include/net/net_namespace.h:345 net/core/sock.c:2236)
     inet_create (net/ipv4/af_inet.c:326 net/ipv4/af_inet.c:252)
     __sock_create (net/socket.c:1558)
     udp_sock_create4 (net/ipv4/udp_tunnel_core.c:18)
     gtp_create_sock (./include/net/udp_tunnel.h:59 drivers/net/gtp.c:1423)
     gtp_create_sockets (drivers/net/gtp.c:1447)
     gtp_newlink (drivers/net/gtp.c:1507)
     rtnl_newlink (net/core/rtnetlink.c:3786 net/core/rtnetlink.c:3897 net/core/rtnetlink.c:4012)
     rtnetlink_rcv_msg (net/core/rtnetlink.c:6922)
     netlink_rcv_skb (net/netlink/af_netlink.c:2542)
     netlink_unicast…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;gtp: Destroy device along with udp socket&amp;amp;apos;s netns dismantle.&lt;/p&gt;
&lt;p&gt;gtp_newlink() links the device to a list in dev_net(dev) instead of
src_net, where a udp tunnel socket is created.&lt;/p&gt;
&lt;p&gt;Even when src_net is removed, the device stays alive on dev_net(dev).
Then, removing src_net triggers the splat below. [0]&lt;/p&gt;
&lt;p&gt;In this example, gtp0 is created in ns2, and the udp socket is created
in ns1.&lt;/p&gt;
&lt;p&gt;ip netns add ns1
  ip netns add ns2
  ip -n ns1 link add netns ns2 name gtp0 type gtp role sgsn
  ip netns del ns1&lt;/p&gt;
&lt;p&gt;Let&amp;amp;apos;s link the device to the socket&amp;amp;apos;s netns instead.&lt;/p&gt;
&lt;p&gt;Now, gtp_net_exit_batch_rtnl() needs another netdev iteration to remove
all gtp devices in the netns.&lt;/p&gt;
&lt;p&gt;[0]:
ref_tracker: net notrefcnt@000000003d6e7d05 has 1/2 users at
     sk_alloc (./include/net/net_namespace.h:345 net/core/sock.c:2236)
     inet_create (net/ipv4/af_inet.c:326 net/ipv4/af_inet.c:252)
     __sock_create (net/socket.c:1558)
     udp_sock_create4 (net/ipv4/udp_tunnel_core.c:18)
     gtp_create_sock (./include/net/udp_tunnel.h:59 drivers/net/gtp.c:1423)
     gtp_create_sockets (drivers/net/gtp.c:1447)
     gtp_newlink (drivers/net/gtp.c:1507)
     rtnl_newlink (net/core/rtnetlink.c:3786 net/core/rtnetlink.c:3897 net/core/rtnetlink.c:4012)
     rtnetlink_rcv_msg (net/core/rtnetlink.c:6922)
     netlink_rcv_skb (net/netlink/af_netlink.c:2542)
     netlink_unicast…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2025-2120</guid>
    </item>
    <item>
      <title>SUSE-SU-2025:02249-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2025:02249-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2025:02249-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-38010</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-38010</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 123 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: phy: tegra: xusb: Use a bitmask for UTMI pad power state tracking The current implementation uses bias_pad_enable as a reference count to manage the shared bias pad for all UTMI PHYs. However, during system suspension with connected USB devices, multiple power-down requests for the UTMI pad result in a mismatch in the reference count, which in turn produces warnings such as: [  237.762967] WARNING: CPU: 10 PID: 1618 at tegra186_utmi_pad_power_down+0x160/0x170 [  237.763103] Call trace: [  237.763104]  tegra186_utmi_pad_power_down+0x160/0x170 [  237.763107]  tegra186_utmi_phy_power_off+0x10/0x30 [  237.763110]  phy_power_off+0x48/0x100 [  237.763113]  tegra_xusb_enter_elpg+0x204/0x500 [  237.763119]  tegra_xusb_suspend+0x48/0x140 [  237.763122]  platform_pm_suspend+0x2c/0xb0 [  237.763125]  dpm_run_callback.isra.0+0x20/0xa0 [  237.763127]  __device_suspend+0x118/0x330 [  237.763129]  dpm_suspend+0x10c/0x1f0 [  237.763130]  dpm_suspend_start+0x88/0xb0 [  237.763132]  suspend_devices_and_enter+0x120/0x500 [  237.763135]  pm_suspend+0x1ec/0x270 The root cause was traced back to the dynamic power-down changes introduced in commit a30951d31b25 (&amp;#34;xhci: tegra: USB2 pad power controls&amp;#34;), where the UTMI pad was being powered down without verifying its current state. This unbalanced behavior led to discrepancies in the reference count. To rectify this issue, this patch replaces the single reference counter with a bitma…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 123 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: phy: tegra: xusb: Use a bitmask for UTMI pad power state tracking The current implementation uses bias_pad_enable as a reference count to manage the shared bias pad for all UTMI PHYs. However, during system suspension with connected USB devices, multiple power-down requests for the UTMI pad result in a mismatch in the reference count, which in turn produces warnings such as: [  237.762967] WARNING: CPU: 10 PID: 1618 at tegra186_utmi_pad_power_down+0x160/0x170 [  237.763103] Call trace: [  237.763104]  tegra186_utmi_pad_power_down+0x160/0x170 [  237.763107]  tegra186_utmi_phy_power_off+0x10/0x30 [  237.763110]  phy_power_off+0x48/0x100 [  237.763113]  tegra_xusb_enter_elpg+0x204/0x500 [  237.763119]  tegra_xusb_suspend+0x48/0x140 [  237.763122]  platform_pm_suspend+0x2c/0xb0 [  237.763125]  dpm_run_callback.isra.0+0x20/0xa0 [  237.763127]  __device_suspend+0x118/0x330 [  237.763129]  dpm_suspend+0x10c/0x1f0 [  237.763130]  dpm_suspend_start+0x88/0xb0 [  237.763132]  suspend_devices_and_enter+0x120/0x500 [  237.763135]  pm_suspend+0x1ec/0x270 The root cause was traced back to the dynamic power-down changes introduced in commit a30951d31b25 (&amp;#34;xhci: tegra: USB2 pad power controls&amp;#34;), where the UTMI pad was being powered down without verifying its current state. This unbalanced behavior led to discrepancies in the reference count. To rectify this issue, this patch replaces the single reference counter with a bitma…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-38010</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-1350 — Linux Kernel: Mehrere Schwachstellen ermöglichen Denial of Service</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1350</link>
      <description>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen in Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen in Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1350</guid>
    </item>
  </channel>
</rss>
