<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 16:56:30 +0000</lastBuildDate>
    <item>
      <title>bdu:2025-10759</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-10759</link>
      <description>bdu:2025-10759</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-10759</guid>
    </item>
    <item>
      <title>BELL-CVE-2025-38019</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2025-38019</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2025-38019</guid>
    </item>
    <item>
      <title>certfr-2025-avi-0721 — De multiples vulnérabilités ont été découvertes dans le noyau Linux d'Ubuntu. Certaines d'entre elles permettent à un a…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0721</link>
      <description>certfr-2025-avi-0721</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0721</guid>
    </item>
    <item>
      <title>EUVD-2026-314376</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-314376</link>
      <description>EUVD-2026-314376</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-314376</guid>
    </item>
    <item>
      <title>fkie_cve-2025-38019</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-38019</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;mlxsw: spectrum_router: Fix use-after-free when deleting GRE net devices&lt;/p&gt;
&lt;p&gt;The driver only offloads neighbors that are constructed on top of net
devices registered by it or their uppers (which are all Ethernet). The
device supports GRE encapsulation and decapsulation of forwarded
traffic, but the driver will not offload dummy neighbors constructed on
top of GRE net devices as they are not uppers of its net devices:&lt;/p&gt;
&lt;p&gt;# ip link add name gre1 up type gre tos inherit local 192.0.2.1 remote 198.51.100.1
 # ip neigh add 0.0.0.0 lladdr 0.0.0.0 nud noarp dev gre1
 $ ip neigh show dev gre1 nud noarp
 0.0.0.0 lladdr 0.0.0.0 NOARP&lt;/p&gt;
&lt;p&gt;(Note that the neighbor is not marked with &amp;#39;offload&amp;#39;)&lt;/p&gt;
&lt;p&gt;When the driver is reloaded and the existing configuration is replayed,
the driver does not perform the same check regarding existing neighbors
and offloads the previously added one:&lt;/p&gt;
&lt;p&gt;# devlink dev reload pci/0000:01:00.0
 $ ip neigh show dev gre1 nud noarp
 0.0.0.0 lladdr 0.0.0.0 offload NOARP&lt;/p&gt;
&lt;p&gt;If the neighbor is later deleted, the driver will ignore the
notification (given the GRE net device is not its upper) and will
therefore keep referencing freed memory, resulting in a use-after-free
[1] when the net device is deleted:&lt;/p&gt;
&lt;p&gt;# ip neigh del 0.0.0.0 lladdr 0.0.0.0 dev gre1
 # ip link del dev gre1&lt;/p&gt;
&lt;p&gt;Fix by skipping neighbor replay if the net device for which the replay
is performed is not our upper.&lt;/p&gt;
&lt;p&gt;[1]
BUG: KASAN: slab-use-after-free i…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;mlxsw: spectrum_router: Fix use-after-free when deleting GRE net devices&lt;/p&gt;
&lt;p&gt;The driver only offloads neighbors that are constructed on top of net
devices registered by it or their uppers (which are all Ethernet). The
device supports GRE encapsulation and decapsulation of forwarded
traffic, but the driver will not offload dummy neighbors constructed on
top of GRE net devices as they are not uppers of its net devices:&lt;/p&gt;
&lt;p&gt;# ip link add name gre1 up type gre tos inherit local 192.0.2.1 remote 198.51.100.1
 # ip neigh add 0.0.0.0 lladdr 0.0.0.0 nud noarp dev gre1
 $ ip neigh show dev gre1 nud noarp
 0.0.0.0 lladdr 0.0.0.0 NOARP&lt;/p&gt;
&lt;p&gt;(Note that the neighbor is not marked with &amp;#39;offload&amp;#39;)&lt;/p&gt;
&lt;p&gt;When the driver is reloaded and the existing configuration is replayed,
the driver does not perform the same check regarding existing neighbors
and offloads the previously added one:&lt;/p&gt;
&lt;p&gt;# devlink dev reload pci/0000:01:00.0
 $ ip neigh show dev gre1 nud noarp
 0.0.0.0 lladdr 0.0.0.0 offload NOARP&lt;/p&gt;
&lt;p&gt;If the neighbor is later deleted, the driver will ignore the
notification (given the GRE net device is not its upper) and will
therefore keep referencing freed memory, resulting in a use-after-free
[1] when the net device is deleted:&lt;/p&gt;
&lt;p&gt;# ip neigh del 0.0.0.0 lladdr 0.0.0.0 dev gre1
 # ip link del dev gre1&lt;/p&gt;
&lt;p&gt;Fix by skipping neighbor replay if the net device for which the replay
is performed is not our upper.&lt;/p&gt;
&lt;p&gt;[1]
BUG: KASAN: slab-use-after-free i…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-38019</guid>
    </item>
    <item>
      <title>GHSA-cpc7-gmm2-93c8</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-cpc7-gmm2-93c8</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;mlxsw: spectrum_router: Fix use-after-free when deleting GRE net devices&lt;/p&gt;
&lt;p&gt;The driver only offloads neighbors that are constructed on top of net
devices registered by it or their uppers (which are all Ethernet). The
device supports GRE encapsulation and decapsulation of forwarded
traffic, but the driver will not offload dummy neighbors constructed on
top of GRE net devices as they are not uppers of its net devices:&lt;/p&gt;
&lt;p&gt;# ip link add name gre1 up type gre tos inherit local 192.0.2.1 remote 198.51.100.1
 # ip neigh add 0.0.0.0 lladdr 0.0.0.0 nud noarp dev gre1
 $ ip neigh show dev gre1 nud noarp
 0.0.0.0 lladdr 0.0.0.0 NOARP&lt;/p&gt;
&lt;p&gt;(Note that the neighbor is not marked with &amp;#39;offload&amp;#39;)&lt;/p&gt;
&lt;p&gt;When the driver is reloaded and the existing configuration is replayed,
the driver does not perform the same check regarding existing neighbors
and offloads the previously added one:&lt;/p&gt;
&lt;p&gt;# devlink dev reload pci/0000:01:00.0
 $ ip neigh show dev gre1 nud noarp
 0.0.0.0 lladdr 0.0.0.0 offload NOARP&lt;/p&gt;
&lt;p&gt;If the neighbor is later deleted, the driver will ignore the
notification (given the GRE net device is not its upper) and will
therefore keep referencing freed memory, resulting in a use-after-free
[1] when the net device is deleted:&lt;/p&gt;
&lt;p&gt;# ip neigh del 0.0.0.0 lladdr 0.0.0.0 dev gre1
 # ip link del dev gre1&lt;/p&gt;
&lt;p&gt;Fix by skipping neighbor replay if the net device for which the replay
is performed is not our upper.&lt;/p&gt;
&lt;p&gt;[1]
BUG: KASAN: slab-use-after-free i…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;mlxsw: spectrum_router: Fix use-after-free when deleting GRE net devices&lt;/p&gt;
&lt;p&gt;The driver only offloads neighbors that are constructed on top of net
devices registered by it or their uppers (which are all Ethernet). The
device supports GRE encapsulation and decapsulation of forwarded
traffic, but the driver will not offload dummy neighbors constructed on
top of GRE net devices as they are not uppers of its net devices:&lt;/p&gt;
&lt;p&gt;# ip link add name gre1 up type gre tos inherit local 192.0.2.1 remote 198.51.100.1
 # ip neigh add 0.0.0.0 lladdr 0.0.0.0 nud noarp dev gre1
 $ ip neigh show dev gre1 nud noarp
 0.0.0.0 lladdr 0.0.0.0 NOARP&lt;/p&gt;
&lt;p&gt;(Note that the neighbor is not marked with &amp;#39;offload&amp;#39;)&lt;/p&gt;
&lt;p&gt;When the driver is reloaded and the existing configuration is replayed,
the driver does not perform the same check regarding existing neighbors
and offloads the previously added one:&lt;/p&gt;
&lt;p&gt;# devlink dev reload pci/0000:01:00.0
 $ ip neigh show dev gre1 nud noarp
 0.0.0.0 lladdr 0.0.0.0 offload NOARP&lt;/p&gt;
&lt;p&gt;If the neighbor is later deleted, the driver will ignore the
notification (given the GRE net device is not its upper) and will
therefore keep referencing freed memory, resulting in a use-after-free
[1] when the net device is deleted:&lt;/p&gt;
&lt;p&gt;# ip neigh del 0.0.0.0 lladdr 0.0.0.0 dev gre1
 # ip link del dev gre1&lt;/p&gt;
&lt;p&gt;Fix by skipping neighbor replay if the net device for which the replay
is performed is not our upper.&lt;/p&gt;
&lt;p&gt;[1]
BUG: KASAN: slab-use-after-free i…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-cpc7-gmm2-93c8</guid>
    </item>
    <item>
      <title>OESA-2025-2120 — kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2025-2120</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;gtp: Destroy device along with udp socket&amp;amp;apos;s netns dismantle.&lt;/p&gt;
&lt;p&gt;gtp_newlink() links the device to a list in dev_net(dev) instead of
src_net, where a udp tunnel socket is created.&lt;/p&gt;
&lt;p&gt;Even when src_net is removed, the device stays alive on dev_net(dev).
Then, removing src_net triggers the splat below. [0]&lt;/p&gt;
&lt;p&gt;In this example, gtp0 is created in ns2, and the udp socket is created
in ns1.&lt;/p&gt;
&lt;p&gt;ip netns add ns1
  ip netns add ns2
  ip -n ns1 link add netns ns2 name gtp0 type gtp role sgsn
  ip netns del ns1&lt;/p&gt;
&lt;p&gt;Let&amp;amp;apos;s link the device to the socket&amp;amp;apos;s netns instead.&lt;/p&gt;
&lt;p&gt;Now, gtp_net_exit_batch_rtnl() needs another netdev iteration to remove
all gtp devices in the netns.&lt;/p&gt;
&lt;p&gt;[0]:
ref_tracker: net notrefcnt@000000003d6e7d05 has 1/2 users at
     sk_alloc (./include/net/net_namespace.h:345 net/core/sock.c:2236)
     inet_create (net/ipv4/af_inet.c:326 net/ipv4/af_inet.c:252)
     __sock_create (net/socket.c:1558)
     udp_sock_create4 (net/ipv4/udp_tunnel_core.c:18)
     gtp_create_sock (./include/net/udp_tunnel.h:59 drivers/net/gtp.c:1423)
     gtp_create_sockets (drivers/net/gtp.c:1447)
     gtp_newlink (drivers/net/gtp.c:1507)
     rtnl_newlink (net/core/rtnetlink.c:3786 net/core/rtnetlink.c:3897 net/core/rtnetlink.c:4012)
     rtnetlink_rcv_msg (net/core/rtnetlink.c:6922)
     netlink_rcv_skb (net/netlink/af_netlink.c:2542)
     netlink_unicast…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;gtp: Destroy device along with udp socket&amp;amp;apos;s netns dismantle.&lt;/p&gt;
&lt;p&gt;gtp_newlink() links the device to a list in dev_net(dev) instead of
src_net, where a udp tunnel socket is created.&lt;/p&gt;
&lt;p&gt;Even when src_net is removed, the device stays alive on dev_net(dev).
Then, removing src_net triggers the splat below. [0]&lt;/p&gt;
&lt;p&gt;In this example, gtp0 is created in ns2, and the udp socket is created
in ns1.&lt;/p&gt;
&lt;p&gt;ip netns add ns1
  ip netns add ns2
  ip -n ns1 link add netns ns2 name gtp0 type gtp role sgsn
  ip netns del ns1&lt;/p&gt;
&lt;p&gt;Let&amp;amp;apos;s link the device to the socket&amp;amp;apos;s netns instead.&lt;/p&gt;
&lt;p&gt;Now, gtp_net_exit_batch_rtnl() needs another netdev iteration to remove
all gtp devices in the netns.&lt;/p&gt;
&lt;p&gt;[0]:
ref_tracker: net notrefcnt@000000003d6e7d05 has 1/2 users at
     sk_alloc (./include/net/net_namespace.h:345 net/core/sock.c:2236)
     inet_create (net/ipv4/af_inet.c:326 net/ipv4/af_inet.c:252)
     __sock_create (net/socket.c:1558)
     udp_sock_create4 (net/ipv4/udp_tunnel_core.c:18)
     gtp_create_sock (./include/net/udp_tunnel.h:59 drivers/net/gtp.c:1423)
     gtp_create_sockets (drivers/net/gtp.c:1447)
     gtp_newlink (drivers/net/gtp.c:1507)
     rtnl_newlink (net/core/rtnetlink.c:3786 net/core/rtnetlink.c:3897 net/core/rtnetlink.c:4012)
     rtnetlink_rcv_msg (net/core/rtnetlink.c:6922)
     netlink_rcv_skb (net/netlink/af_netlink.c:2542)
     netlink_unicast…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2025-2120</guid>
    </item>
    <item>
      <title>openSUSE-SU-2025:20081-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2025:20081-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2025:20081-1</guid>
    </item>
    <item>
      <title>SUSE-SU-2025:21074-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2025:21074-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2025:21074-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-38019</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-38019</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 120 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: mlxsw: spectrum_router: Fix use-after-free when deleting GRE net devices The driver only offloads neighbors that are constructed on top of net devices registered by it or their uppers (which are all Ethernet). The device supports GRE encapsulation and decapsulation of forwarded traffic, but the driver will not offload dummy neighbors constructed on top of GRE net devices as they are not uppers of its net devices:  # ip link add name gre1 up type gre tos inherit local 192.0.2.1 remote 198.51.100.1  # ip neigh add 0.0.0.0 lladdr 0.0.0.0 nud noarp dev gre1  $ ip neigh show dev gre1 nud noarp  0.0.0.0 lladdr 0.0.0.0 NOARP (Note that the neighbor is not marked with &amp;#39;offload&amp;#39;) When the driver is reloaded and the existing configuration is replayed, the driver does not perform the same check regarding existing neighbors and offloads the previously added one:  # devlink dev reload pci/0000:01:00.0  $ ip neigh show dev gre1 nud noarp  0.0.0.0 lladdr 0.0.0.0 offload NOARP If the neighbor is later deleted, the driver will ignore the notification (given the GRE net device is not its upper) and will therefore keep referencing freed memory, resulting in a use-after-free [1] when the net device is deleted:  # ip neigh del 0.0.0.0 lladdr 0.0.0.0 dev gre1  # ip link del dev gre1 Fix by skipping neighbor replay if the net device for which the replay is performed is not our upper. [1] BUG: KASAN: slab-use-after-free in mlxsw_sp…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 120 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: mlxsw: spectrum_router: Fix use-after-free when deleting GRE net devices The driver only offloads neighbors that are constructed on top of net devices registered by it or their uppers (which are all Ethernet). The device supports GRE encapsulation and decapsulation of forwarded traffic, but the driver will not offload dummy neighbors constructed on top of GRE net devices as they are not uppers of its net devices:  # ip link add name gre1 up type gre tos inherit local 192.0.2.1 remote 198.51.100.1  # ip neigh add 0.0.0.0 lladdr 0.0.0.0 nud noarp dev gre1  $ ip neigh show dev gre1 nud noarp  0.0.0.0 lladdr 0.0.0.0 NOARP (Note that the neighbor is not marked with &amp;#39;offload&amp;#39;) When the driver is reloaded and the existing configuration is replayed, the driver does not perform the same check regarding existing neighbors and offloads the previously added one:  # devlink dev reload pci/0000:01:00.0  $ ip neigh show dev gre1 nud noarp  0.0.0.0 lladdr 0.0.0.0 offload NOARP If the neighbor is later deleted, the driver will ignore the notification (given the GRE net device is not its upper) and will therefore keep referencing freed memory, resulting in a use-after-free [1] when the net device is deleted:  # ip neigh del 0.0.0.0 lladdr 0.0.0.0 dev gre1  # ip link del dev gre1 Fix by skipping neighbor replay if the net device for which the replay is performed is not our upper. [1] BUG: KASAN: slab-use-after-free in mlxsw_sp…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-38019</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-1350 — Linux Kernel: Mehrere Schwachstellen ermöglichen Denial of Service</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1350</link>
      <description>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen in Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen in Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1350</guid>
    </item>
  </channel>
</rss>
