<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 03:27:50 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-01384</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-01384</link>
      <description>bdu:2026-01384</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-01384</guid>
    </item>
    <item>
      <title>BELL-CVE-2025-38064</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2025-38064</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2025-38064</guid>
    </item>
    <item>
      <title>certfr-2025-avi-0723 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de SUSE. Certaines d'entre elles permettent à un at…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0723</link>
      <description>certfr-2025-avi-0723</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0723</guid>
    </item>
    <item>
      <title>EUVD-2026-346902</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-346902</link>
      <description>EUVD-2026-346902</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-346902</guid>
    </item>
    <item>
      <title>fkie_cve-2025-38064</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-38064</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;virtio: break and reset virtio devices on device_shutdown()&lt;/p&gt;
&lt;p&gt;Hongyu reported a hang on kexec in a VM. QEMU reported invalid memory
accesses during the hang.&lt;/p&gt;
&lt;p&gt;Invalid read at addr 0x102877002, size 2, region &amp;#39;(null)&amp;#39;, reason: rejected
	Invalid write at addr 0x102877A44, size 2, region &amp;#39;(null)&amp;#39;, reason: rejected
	...&lt;/p&gt;
&lt;p&gt;It was traced down to virtio-console. Kexec works fine if virtio-console
is not in use.&lt;/p&gt;
&lt;p&gt;The issue is that virtio-console continues to write to the MMIO even after
underlying virtio-pci device is reset.&lt;/p&gt;
&lt;p&gt;Additionally, Eric noticed that IOMMUs are reset before devices, if
devices are not reset on shutdown they continue to poke at guest memory
and get errors from the IOMMU. Some devices get wedged then.&lt;/p&gt;
&lt;p&gt;The problem can be solved by breaking all virtio devices on virtio
bus shutdown, then resetting them.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;virtio: break and reset virtio devices on device_shutdown()&lt;/p&gt;
&lt;p&gt;Hongyu reported a hang on kexec in a VM. QEMU reported invalid memory
accesses during the hang.&lt;/p&gt;
&lt;p&gt;Invalid read at addr 0x102877002, size 2, region &amp;#39;(null)&amp;#39;, reason: rejected
	Invalid write at addr 0x102877A44, size 2, region &amp;#39;(null)&amp;#39;, reason: rejected
	...&lt;/p&gt;
&lt;p&gt;It was traced down to virtio-console. Kexec works fine if virtio-console
is not in use.&lt;/p&gt;
&lt;p&gt;The issue is that virtio-console continues to write to the MMIO even after
underlying virtio-pci device is reset.&lt;/p&gt;
&lt;p&gt;Additionally, Eric noticed that IOMMUs are reset before devices, if
devices are not reset on shutdown they continue to poke at guest memory
and get errors from the IOMMU. Some devices get wedged then.&lt;/p&gt;
&lt;p&gt;The problem can be solved by breaking all virtio devices on virtio
bus shutdown, then resetting them.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-38064</guid>
    </item>
    <item>
      <title>GHSA-3cmh-pcxh-6v9p</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-3cmh-pcxh-6v9p</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;virtio: break and reset virtio devices on device_shutdown()&lt;/p&gt;
&lt;p&gt;Hongyu reported a hang on kexec in a VM. QEMU reported invalid memory
accesses during the hang.&lt;/p&gt;
&lt;p&gt;Invalid read at addr 0x102877002, size 2, region &amp;#39;(null)&amp;#39;, reason: rejected
	Invalid write at addr 0x102877A44, size 2, region &amp;#39;(null)&amp;#39;, reason: rejected
	...&lt;/p&gt;
&lt;p&gt;It was traced down to virtio-console. Kexec works fine if virtio-console
is not in use.&lt;/p&gt;
&lt;p&gt;The issue is that virtio-console continues to write to the MMIO even after
underlying virtio-pci device is reset.&lt;/p&gt;
&lt;p&gt;Additionally, Eric noticed that IOMMUs are reset before devices, if
devices are not reset on shutdown they continue to poke at guest memory
and get errors from the IOMMU. Some devices get wedged then.&lt;/p&gt;
&lt;p&gt;The problem can be solved by breaking all virtio devices on virtio
bus shutdown, then resetting them.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;virtio: break and reset virtio devices on device_shutdown()&lt;/p&gt;
&lt;p&gt;Hongyu reported a hang on kexec in a VM. QEMU reported invalid memory
accesses during the hang.&lt;/p&gt;
&lt;p&gt;Invalid read at addr 0x102877002, size 2, region &amp;#39;(null)&amp;#39;, reason: rejected
	Invalid write at addr 0x102877A44, size 2, region &amp;#39;(null)&amp;#39;, reason: rejected
	...&lt;/p&gt;
&lt;p&gt;It was traced down to virtio-console. Kexec works fine if virtio-console
is not in use.&lt;/p&gt;
&lt;p&gt;The issue is that virtio-console continues to write to the MMIO even after
underlying virtio-pci device is reset.&lt;/p&gt;
&lt;p&gt;Additionally, Eric noticed that IOMMUs are reset before devices, if
devices are not reset on shutdown they continue to poke at guest memory
and get errors from the IOMMU. Some devices get wedged then.&lt;/p&gt;
&lt;p&gt;The problem can be solved by breaking all virtio devices on virtio
bus shutdown, then resetting them.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-3cmh-pcxh-6v9p</guid>
    </item>
    <item>
      <title>msrc_CVE-2025-38064 — virtio: break and reset virtio devices on device_shutdown()</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2025-38064</link>
      <description>msrc_CVE-2025-38064</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2025-38064</guid>
    </item>
    <item>
      <title>OESA-2026-2417 — kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-2417</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:mm/mempolicy: fix migrate_to_node() assuming there is at least one VMA in a MMWe currently assume that there is at least one VMA in a MM, which isn ttrue.So we might end up having find_vma() return NULL, to then de-referenceNULL.  So properly handle find_vma() returning NULL.This fixes the report:Oops: general protection fault, probably for non-canonical address 0xdffffc0000000000: 0000 [#1] PREEMPT SMP KASAN PTIKASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007]CPU: 1 UID: 0 PID: 6021 Comm: syz-executor284 Not tainted 6.12.0-rc7-syzkaller-00187-gf868cd251776 #0Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 10/30/2024RIP: 0010:migrate_to_node mm/mempolicy.c:1090 [inline]RIP: 0010:do_migrate_pages+0x403/0x6f0 mm/mempolicy.c:1194Code: ...RSP: 0018:ffffc9000375fd08 EFLAGS: 00010246RAX: 0000000000000000 RBX: ffffc9000375fd78 RCX: 0000000000000000RDX: ffff88807e171300 RSI: dffffc0000000000 RDI: ffff88803390c044RBP: ffff88807e171428 R08: 0000000000000014 R09: fffffbfff2039ef1R10: ffffffff901cf78f R11: 0000000000000000 R12: 0000000000000003R13: ffffc9000375fe90 R14: ffffc9000375fe98 R15: ffffc9000375fdf8FS:  00005555919e1380(0000) GS:ffff8880b8700000(0000) knlGS:0000000000000000CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033CR2: 00005555919e1ca8 CR3: 000000007f12a000 CR4: 00000000003526f0DR0…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:mm/mempolicy: fix migrate_to_node() assuming there is at least one VMA in a MMWe currently assume that there is at least one VMA in a MM, which isn ttrue.So we might end up having find_vma() return NULL, to then de-referenceNULL.  So properly handle find_vma() returning NULL.This fixes the report:Oops: general protection fault, probably for non-canonical address 0xdffffc0000000000: 0000 [#1] PREEMPT SMP KASAN PTIKASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007]CPU: 1 UID: 0 PID: 6021 Comm: syz-executor284 Not tainted 6.12.0-rc7-syzkaller-00187-gf868cd251776 #0Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 10/30/2024RIP: 0010:migrate_to_node mm/mempolicy.c:1090 [inline]RIP: 0010:do_migrate_pages+0x403/0x6f0 mm/mempolicy.c:1194Code: ...RSP: 0018:ffffc9000375fd08 EFLAGS: 00010246RAX: 0000000000000000 RBX: ffffc9000375fd78 RCX: 0000000000000000RDX: ffff88807e171300 RSI: dffffc0000000000 RDI: ffff88803390c044RBP: ffff88807e171428 R08: 0000000000000014 R09: fffffbfff2039ef1R10: ffffffff901cf78f R11: 0000000000000000 R12: 0000000000000003R13: ffffc9000375fe90 R14: ffffc9000375fe98 R15: ffffc9000375fdf8FS:  00005555919e1380(0000) GS:ffff8880b8700000(0000) knlGS:0000000000000000CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033CR2: 00005555919e1ca8 CR3: 000000007f12a000 CR4: 00000000003526f0DR0…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-2417</guid>
    </item>
    <item>
      <title>SUSE-SU-2025:02846-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2025:02846-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2025:02846-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-38064</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-38064</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux, Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe and 214 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: virtio: break and reset virtio devices on device_shutdown() Hongyu reported a hang on kexec in a VM. QEMU reported invalid memory accesses during the hang. 	Invalid read at addr 0x102877002, size 2, region &amp;#39;(null)&amp;#39;, reason: rejected 	Invalid write at addr 0x102877A44, size 2, region &amp;#39;(null)&amp;#39;, reason: rejected 	... It was traced down to virtio-console. Kexec works fine if virtio-console is not in use. The issue is that virtio-console continues to write to the MMIO even after underlying virtio-pci device is reset. Additionally, Eric noticed that IOMMUs are reset before devices, if devices are not reset on shutdown they continue to poke at guest memory and get errors from the IOMMU. Some devices get wedged then. The problem can be solved by breaking all virtio devices on virtio bus shutdown, then resetting them.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux, Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe and 214 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: virtio: break and reset virtio devices on device_shutdown() Hongyu reported a hang on kexec in a VM. QEMU reported invalid memory accesses during the hang. 	Invalid read at addr 0x102877002, size 2, region &amp;#39;(null)&amp;#39;, reason: rejected 	Invalid write at addr 0x102877A44, size 2, region &amp;#39;(null)&amp;#39;, reason: rejected 	... It was traced down to virtio-console. Kexec works fine if virtio-console is not in use. The issue is that virtio-console continues to write to the MMIO even after underlying virtio-pci device is reset. Additionally, Eric noticed that IOMMUs are reset before devices, if devices are not reset on shutdown they continue to poke at guest memory and get errors from the IOMMU. Some devices get wedged then. The problem can be solved by breaking all virtio devices on virtio bus shutdown, then resetting them.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-38064</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-1350 — Linux Kernel: Mehrere Schwachstellen ermöglichen Denial of Service</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1350</link>
      <description>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen in Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen in Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1350</guid>
    </item>
  </channel>
</rss>
