<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 06:59:25 +0000</lastBuildDate>
    <item>
      <title>ALSA-2025:13962 — Important: kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2025:13962</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: kernel, AlmaLinux:9: kernel-64k, AlmaLinux:9: kernel-64k-core, AlmaLinux:9: kernel-64k-debug, AlmaLinux:9: kernel-64k-debug-core, AlmaLinux:9: kernel-64k-debug-devel, AlmaLinux:9: kernel-64k-debug-devel-matched, AlmaLinux:9: kernel-64k-debug-modules, AlmaLinux:9: kernel-64k-debug-modules-core, AlmaLinux:9: kernel-64k-debug-modules-extra and 66 more&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: bpf, test_run: Fix use-after-free issue in eth_skb_pkt_type() (CVE-2025-21867)
  * microcode_ctl: From CVEorg collector (CVE-2024-28956)
  * kernel: mm/hugetlb: unshare page tables during VMA split, not before (CVE-2025-38084)
  * kernel: mm/hugetlb: fix huge_pmd_unshare() vs GUP-fast race (CVE-2025-38085)
  * kernel: net: fix udp gso skb_segment after pull from frag_list (CVE-2025-38124)
  * kernel: wifi: rtw88: fix the &amp;#39;para&amp;#39; buffer size to avoid reading out of bounds (CVE-2025-38159)
  * kernel: Bluetooth: hci_core: Fix use-after-free in vhci_flush() (CVE-2025-38250)
  * kernel: i2c/designware: Fix an initialization issue (CVE-2025-38380)
  * kernel: tls: always refresh the queue when reading sock (CVE-2025-38471)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: kernel, AlmaLinux:9: kernel-64k, AlmaLinux:9: kernel-64k-core, AlmaLinux:9: kernel-64k-debug, AlmaLinux:9: kernel-64k-debug-core, AlmaLinux:9: kernel-64k-debug-devel, AlmaLinux:9: kernel-64k-debug-devel-matched, AlmaLinux:9: kernel-64k-debug-modules, AlmaLinux:9: kernel-64k-debug-modules-core, AlmaLinux:9: kernel-64k-debug-modules-extra and 66 more&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: bpf, test_run: Fix use-after-free issue in eth_skb_pkt_type() (CVE-2025-21867)
  * microcode_ctl: From CVEorg collector (CVE-2024-28956)
  * kernel: mm/hugetlb: unshare page tables during VMA split, not before (CVE-2025-38084)
  * kernel: mm/hugetlb: fix huge_pmd_unshare() vs GUP-fast race (CVE-2025-38085)
  * kernel: net: fix udp gso skb_segment after pull from frag_list (CVE-2025-38124)
  * kernel: wifi: rtw88: fix the &amp;#39;para&amp;#39; buffer size to avoid reading out of bounds (CVE-2025-38159)
  * kernel: Bluetooth: hci_core: Fix use-after-free in vhci_flush() (CVE-2025-38250)
  * kernel: i2c/designware: Fix an initialization issue (CVE-2025-38380)
  * kernel: tls: always refresh the queue when reading sock (CVE-2025-38471)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2025:13962</guid>
    </item>
    <item>
      <title>bdu:2025-15825</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-15825</link>
      <description>bdu:2025-15825</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-15825</guid>
    </item>
    <item>
      <title>BELL-CVE-2025-38084</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2025-38084</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2025-38084</guid>
    </item>
    <item>
      <title>certfr-2025-avi-0698 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de Debian. Certaines d'entre elles permettent à un…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0698</link>
      <description>certfr-2025-avi-0698</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0698</guid>
    </item>
    <item>
      <title>EUVD-2026-346912</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-346912</link>
      <description>EUVD-2026-346912</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-346912</guid>
    </item>
    <item>
      <title>fkie_cve-2025-38084</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-38084</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;mm/hugetlb: unshare page tables during VMA split, not before&lt;/p&gt;
&lt;p&gt;Currently, __split_vma() triggers hugetlb page table unsharing through
vm_ops-&amp;gt;may_split().  This happens before the VMA lock and rmap locks are
taken - which is too early, it allows racing VMA-locked page faults in our
process and racing rmap walks from other processes to cause page tables to
be shared again before we actually perform the split.&lt;/p&gt;
&lt;p&gt;Fix it by explicitly calling into the hugetlb unshare logic from
__split_vma() in the same place where THP splitting also happens.  At that
point, both the VMA and the rmap(s) are write-locked.&lt;/p&gt;
&lt;p&gt;An annoying detail is that we can now call into the helper
hugetlb_unshare_pmds() from two different locking contexts:&lt;/p&gt;
&lt;p&gt;1. from hugetlb_split(), holding:
    - mmap lock (exclusively)
    - VMA lock
    - file rmap lock (exclusively)
2. hugetlb_unshare_all_pmds(), which I think is designed to be able to
   call us with only the mmap lock held (in shared mode), but currently
   only runs while holding mmap lock (exclusively) and VMA lock&lt;/p&gt;
&lt;p&gt;Backporting note:
This commit fixes a racy protection that was introduced in commit
b30c14cd6102 (&amp;#34;hugetlb: unshare some PMDs when splitting VMAs&amp;#34;); that
commit claimed to fix an issue introduced in 5.13, but it should actually
also go all the way back.&lt;/p&gt;
&lt;p&gt;[jannh@google.com: v2]&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;mm/hugetlb: unshare page tables during VMA split, not before&lt;/p&gt;
&lt;p&gt;Currently, __split_vma() triggers hugetlb page table unsharing through
vm_ops-&amp;gt;may_split().  This happens before the VMA lock and rmap locks are
taken - which is too early, it allows racing VMA-locked page faults in our
process and racing rmap walks from other processes to cause page tables to
be shared again before we actually perform the split.&lt;/p&gt;
&lt;p&gt;Fix it by explicitly calling into the hugetlb unshare logic from
__split_vma() in the same place where THP splitting also happens.  At that
point, both the VMA and the rmap(s) are write-locked.&lt;/p&gt;
&lt;p&gt;An annoying detail is that we can now call into the helper
hugetlb_unshare_pmds() from two different locking contexts:&lt;/p&gt;
&lt;p&gt;1. from hugetlb_split(), holding:
    - mmap lock (exclusively)
    - VMA lock
    - file rmap lock (exclusively)
2. hugetlb_unshare_all_pmds(), which I think is designed to be able to
   call us with only the mmap lock held (in shared mode), but currently
   only runs while holding mmap lock (exclusively) and VMA lock&lt;/p&gt;
&lt;p&gt;Backporting note:
This commit fixes a racy protection that was introduced in commit
b30c14cd6102 (&amp;#34;hugetlb: unshare some PMDs when splitting VMAs&amp;#34;); that
commit claimed to fix an issue introduced in 5.13, but it should actually
also go all the way back.&lt;/p&gt;
&lt;p&gt;[jannh@google.com: v2]&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-38084</guid>
    </item>
    <item>
      <title>GHSA-mfp4-4cfm-v388</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-mfp4-4cfm-v388</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;mm/hugetlb: unshare page tables during VMA split, not before&lt;/p&gt;
&lt;p&gt;Currently, __split_vma() triggers hugetlb page table unsharing through
vm_ops-&amp;gt;may_split().  This happens before the VMA lock and rmap locks are
taken - which is too early, it allows racing VMA-locked page faults in our
process and racing rmap walks from other processes to cause page tables to
be shared again before we actually perform the split.&lt;/p&gt;
&lt;p&gt;Fix it by explicitly calling into the hugetlb unshare logic from
__split_vma() in the same place where THP splitting also happens.  At that
point, both the VMA and the rmap(s) are write-locked.&lt;/p&gt;
&lt;p&gt;An annoying detail is that we can now call into the helper
hugetlb_unshare_pmds() from two different locking contexts:&lt;/p&gt;
&lt;p&gt;1. from hugetlb_split(), holding:
    - mmap lock (exclusively)
    - VMA lock
    - file rmap lock (exclusively)
2. hugetlb_unshare_all_pmds(), which I think is designed to be able to
   call us with only the mmap lock held (in shared mode), but currently
   only runs while holding mmap lock (exclusively) and VMA lock&lt;/p&gt;
&lt;p&gt;Backporting note:
This commit fixes a racy protection that was introduced in commit
b30c14cd6102 (&amp;#34;hugetlb: unshare some PMDs when splitting VMAs&amp;#34;); that
commit claimed to fix an issue introduced in 5.13, but it should actually
also go all the way back.&lt;/p&gt;
&lt;p&gt;[jannh@google.com: v2]&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;mm/hugetlb: unshare page tables during VMA split, not before&lt;/p&gt;
&lt;p&gt;Currently, __split_vma() triggers hugetlb page table unsharing through
vm_ops-&amp;gt;may_split().  This happens before the VMA lock and rmap locks are
taken - which is too early, it allows racing VMA-locked page faults in our
process and racing rmap walks from other processes to cause page tables to
be shared again before we actually perform the split.&lt;/p&gt;
&lt;p&gt;Fix it by explicitly calling into the hugetlb unshare logic from
__split_vma() in the same place where THP splitting also happens.  At that
point, both the VMA and the rmap(s) are write-locked.&lt;/p&gt;
&lt;p&gt;An annoying detail is that we can now call into the helper
hugetlb_unshare_pmds() from two different locking contexts:&lt;/p&gt;
&lt;p&gt;1. from hugetlb_split(), holding:
    - mmap lock (exclusively)
    - VMA lock
    - file rmap lock (exclusively)
2. hugetlb_unshare_all_pmds(), which I think is designed to be able to
   call us with only the mmap lock held (in shared mode), but currently
   only runs while holding mmap lock (exclusively) and VMA lock&lt;/p&gt;
&lt;p&gt;Backporting note:
This commit fixes a racy protection that was introduced in commit
b30c14cd6102 (&amp;#34;hugetlb: unshare some PMDs when splitting VMAs&amp;#34;); that
commit claimed to fix an issue introduced in 5.13, but it should actually
also go all the way back.&lt;/p&gt;
&lt;p&gt;[jannh@google.com: v2]&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-mfp4-4cfm-v388</guid>
    </item>
    <item>
      <title>ICSA-26-043-06 — Siemens SINEC OS</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-26-043-06</link>
      <description>&lt;p&gt;There is a stack overflow vulnerability in ash.c:6030 in busybox before 1.35. In the environment of Internet of Vehicles, this vulnerability can be executed from command to arbitrary code execution. In affected libpcap versions during the setup of a remote packet capture the internal function sock_initaddress() calls getaddrinfo() and possibly freeaddrinfo(), but does not clearly indicate to the caller function whether freeaddrinfo() still remains to be called after the function returns.  This makes it possible in some scenarios that both the function and its caller call freeaddrinfo() for the same allocated memory block.  A similar problem was reported in Apple libpcap, to which Apple assigned CVE-2023-40400. An issue in the CPIO command of Busybox v1.33.2 allows attackers to execute a directory traversal. A use-after-free vulnerability was discovered in xasprintf function in xfuncs_printf.c:344 in BusyBox v.1.36.1. A use-after-free vulnerability in BusyBox v.1.36.1 allows attackers to cause a denial of service via a crafted awk pattern in the awk.c evaluate function. A use-after-free vulnerability was discovered in BusyBox v.1.36.1 via a crafted awk pattern in the awk.c copyvar function. A heap-buffer-overflow was discovered in BusyBox v.1.36.1 in the next_token function at awk.c:1159. libcurl&amp;#39;s ASN1 parser has this utf8asn1str() function used for parsing an ASN.1 UTF-8 string. Itcan detect an invalid field and return error. Unfortunately, when doing so it also invokes `fr…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;There is a stack overflow vulnerability in ash.c:6030 in busybox before 1.35. In the environment of Internet of Vehicles, this vulnerability can be executed from command to arbitrary code execution. In affected libpcap versions during the setup of a remote packet capture the internal function sock_initaddress() calls getaddrinfo() and possibly freeaddrinfo(), but does not clearly indicate to the caller function whether freeaddrinfo() still remains to be called after the function returns.  This makes it possible in some scenarios that both the function and its caller call freeaddrinfo() for the same allocated memory block.  A similar problem was reported in Apple libpcap, to which Apple assigned CVE-2023-40400. An issue in the CPIO command of Busybox v1.33.2 allows attackers to execute a directory traversal. A use-after-free vulnerability was discovered in xasprintf function in xfuncs_printf.c:344 in BusyBox v.1.36.1. A use-after-free vulnerability in BusyBox v.1.36.1 allows attackers to cause a denial of service via a crafted awk pattern in the awk.c evaluate function. A use-after-free vulnerability was discovered in BusyBox v.1.36.1 via a crafted awk pattern in the awk.c copyvar function. A heap-buffer-overflow was discovered in BusyBox v.1.36.1 in the next_token function at awk.c:1159. libcurl&amp;#39;s ASN1 parser has this utf8asn1str() function used for parsing an ASN.1 UTF-8 string. Itcan detect an invalid field and return error. Unfortunately, when doing so it also invokes `fr…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-26-043-06</guid>
    </item>
    <item>
      <title>msrc_CVE-2025-38084 — mm/hugetlb: unshare page tables during VMA split, not before</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2025-38084</link>
      <description>msrc_CVE-2025-38084</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2025-38084</guid>
    </item>
    <item>
      <title>OESA-2025-2765 — kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2025-2765</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;A transient execution vulnerability in some AMD processors may allow an attacker to infer data in the L1D cache, potentially resulting in the leakage of sensitive information across privileged boundaries.(CVE-2024-36357)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;fs/ntfs3: Prevent integer overflow in hdr_first_de()&lt;/p&gt;
&lt;p&gt;The &amp;amp;quot;de_off&amp;amp;quot; and &amp;amp;quot;used&amp;amp;quot; variables come from the disk so they both need to
check.  The problem is that on 32bit systems if they&amp;amp;apos;re both greater than
UINT_MAX - 16 then the check does work as intended because of an integer
overflow.(CVE-2025-22080)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;ext4: fix off-by-one error in do_split&lt;/p&gt;
&lt;p&gt;Syzkaller detected a use-after-free issue in ext4_insert_dentry that was
caused by out-of-bounds access due to incorrect splitting in do_split.&lt;/p&gt;
&lt;p&gt;BUG: KASAN: use-after-free in ext4_insert_dentry+0x36a/0x6d0 fs/ext4/namei.c:2109
Write of size 251 at addr ffff888074572f14 by task syz-executor335/5847&lt;/p&gt;
&lt;p&gt;CPU: 0 UID: 0 PID: 5847 Comm: syz-executor335 Not tainted 6.12.0-rc6-syzkaller-00318-ga9cda7c0ffed #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 10/30/2024
Call Trace:
 &amp;amp;lt;TASK&amp;amp;gt;
 __dump_stack lib/dump_stack.c:94 [inline]
 dump_stack_lvl+0x241/0x360 lib/dump_stack.c:120
 print_address_description mm/kasan/report.c:377 [inline]
 print_report+0x169/0x550 mm/k…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;A transient execution vulnerability in some AMD processors may allow an attacker to infer data in the L1D cache, potentially resulting in the leakage of sensitive information across privileged boundaries.(CVE-2024-36357)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;fs/ntfs3: Prevent integer overflow in hdr_first_de()&lt;/p&gt;
&lt;p&gt;The &amp;amp;quot;de_off&amp;amp;quot; and &amp;amp;quot;used&amp;amp;quot; variables come from the disk so they both need to
check.  The problem is that on 32bit systems if they&amp;amp;apos;re both greater than
UINT_MAX - 16 then the check does work as intended because of an integer
overflow.(CVE-2025-22080)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;ext4: fix off-by-one error in do_split&lt;/p&gt;
&lt;p&gt;Syzkaller detected a use-after-free issue in ext4_insert_dentry that was
caused by out-of-bounds access due to incorrect splitting in do_split.&lt;/p&gt;
&lt;p&gt;BUG: KASAN: use-after-free in ext4_insert_dentry+0x36a/0x6d0 fs/ext4/namei.c:2109
Write of size 251 at addr ffff888074572f14 by task syz-executor335/5847&lt;/p&gt;
&lt;p&gt;CPU: 0 UID: 0 PID: 5847 Comm: syz-executor335 Not tainted 6.12.0-rc6-syzkaller-00318-ga9cda7c0ffed #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 10/30/2024
Call Trace:
 &amp;amp;lt;TASK&amp;amp;gt;
 __dump_stack lib/dump_stack.c:94 [inline]
 dump_stack_lvl+0x241/0x360 lib/dump_stack.c:120
 print_address_description mm/kasan/report.c:377 [inline]
 print_report+0x169/0x550 mm/k…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2025-2765</guid>
    </item>
    <item>
      <title>openSUSE-SU-2025:20172-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2025:20172-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2025:20172-1</guid>
    </item>
    <item>
      <title>RHSA-2025:13598 — Red Hat Security Advisory: kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2025:13598</link>
      <description>&lt;p&gt;kernel: x86/CPU/AMD: Terminate the erratum_1386_microcode array kernel: crypto: algif_hash - fix double free in hash_accept kernel: mm/hugetlb: unshare page tables during VMA split, not before kernel: mm/hugetlb: fix huge_pmd_unshare() vs GUP-fast race kernel: PCI/pwrctrl: Cancel outstanding rescan work when unregistering kernel: wifi: rtw88: fix the &amp;#39;para&amp;#39; buffer size to avoid reading out of bounds kernel: wifi: ath12k: fix invalid access to memory&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;kernel: x86/CPU/AMD: Terminate the erratum_1386_microcode array kernel: crypto: algif_hash - fix double free in hash_accept kernel: mm/hugetlb: unshare page tables during VMA split, not before kernel: mm/hugetlb: fix huge_pmd_unshare() vs GUP-fast race kernel: PCI/pwrctrl: Cancel outstanding rescan work when unregistering kernel: wifi: rtw88: fix the &amp;#39;para&amp;#39; buffer size to avoid reading out of bounds kernel: wifi: ath12k: fix invalid access to memory&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2025:13598</guid>
    </item>
    <item>
      <title>SSA-089022 — SSA-089022: Multiple Vulnerabilities in Third-Party Components in SINEC OS before V3.3</title>
      <link>https://cve.radiocsirt.org/vuln/ssa-089022</link>
      <description>&lt;p&gt;There is a stack overflow vulnerability in ash.c:6030 in busybox before 1.35. In the environment of Internet of Vehicles, this vulnerability can be executed from command to arbitrary code execution. In affected libpcap versions during the setup of a remote packet capture the internal function sock_initaddress() calls getaddrinfo() and possibly freeaddrinfo(), but does not clearly indicate to the caller function whether freeaddrinfo() still remains to be called after the function returns.  This makes it possible in some scenarios that both the function and its caller call freeaddrinfo() for the same allocated memory block.  A similar problem was reported in Apple libpcap, to which Apple assigned CVE-2023-40400. An issue in the CPIO command of Busybox v1.33.2 allows attackers to execute a directory traversal. A use-after-free vulnerability was discovered in xasprintf function in xfuncs_printf.c:344 in BusyBox v.1.36.1. A use-after-free vulnerability in BusyBox v.1.36.1 allows attackers to cause a denial of service via a crafted awk pattern in the awk.c evaluate function. A use-after-free vulnerability was discovered in BusyBox v.1.36.1 via a crafted awk pattern in the awk.c copyvar function. A heap-buffer-overflow was discovered in BusyBox v.1.36.1 in the next_token function at awk.c:1159. libcurl&amp;#39;s ASN1 parser has this utf8asn1str() function used for parsing an ASN.1 UTF-8 string. Itcan detect an invalid field and return error. Unfortunately, when doing so it also invokes `fr…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;There is a stack overflow vulnerability in ash.c:6030 in busybox before 1.35. In the environment of Internet of Vehicles, this vulnerability can be executed from command to arbitrary code execution. In affected libpcap versions during the setup of a remote packet capture the internal function sock_initaddress() calls getaddrinfo() and possibly freeaddrinfo(), but does not clearly indicate to the caller function whether freeaddrinfo() still remains to be called after the function returns.  This makes it possible in some scenarios that both the function and its caller call freeaddrinfo() for the same allocated memory block.  A similar problem was reported in Apple libpcap, to which Apple assigned CVE-2023-40400. An issue in the CPIO command of Busybox v1.33.2 allows attackers to execute a directory traversal. A use-after-free vulnerability was discovered in xasprintf function in xfuncs_printf.c:344 in BusyBox v.1.36.1. A use-after-free vulnerability in BusyBox v.1.36.1 allows attackers to cause a denial of service via a crafted awk pattern in the awk.c evaluate function. A use-after-free vulnerability was discovered in BusyBox v.1.36.1 via a crafted awk pattern in the awk.c copyvar function. A heap-buffer-overflow was discovered in BusyBox v.1.36.1 in the next_token function at awk.c:1159. libcurl&amp;#39;s ASN1 parser has this utf8asn1str() function used for parsing an ASN.1 UTF-8 string. Itcan detect an invalid field and return error. Unfortunately, when doing so it also invokes `fr…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ssa-089022</guid>
    </item>
    <item>
      <title>SUSE-SU-2025:02853-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2025:02853-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2025:02853-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-38084</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-38084</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux, Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe and 213 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: mm/hugetlb: unshare page tables during VMA split, not before Currently, __split_vma() triggers hugetlb page table unsharing through vm_ops-&amp;gt;may_split().  This happens before the VMA lock and rmap locks are taken - which is too early, it allows racing VMA-locked page faults in our process and racing rmap walks from other processes to cause page tables to be shared again before we actually perform the split. Fix it by explicitly calling into the hugetlb unshare logic from __split_vma() in the same place where THP splitting also happens.  At that point, both the VMA and the rmap(s) are write-locked. An annoying detail is that we can now call into the helper hugetlb_unshare_pmds() from two different locking contexts: 1. from hugetlb_split(), holding:     - mmap lock (exclusively)     - VMA lock     - file rmap lock (exclusively) 2. hugetlb_unshare_all_pmds(), which I think is designed to be able to    call us with only the mmap lock held (in shared mode), but currently    only runs while holding mmap lock (exclusively) and VMA lock Backporting note: This commit fixes a racy protection that was introduced in commit b30c14cd6102 (&amp;#34;hugetlb: unshare some PMDs when splitting VMAs&amp;#34;); that commit claimed to fix an issue introduced in 5.13, but it should actually also go all the way back. [jannh@google.com: v2]&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux, Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe and 213 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: mm/hugetlb: unshare page tables during VMA split, not before Currently, __split_vma() triggers hugetlb page table unsharing through vm_ops-&amp;gt;may_split().  This happens before the VMA lock and rmap locks are taken - which is too early, it allows racing VMA-locked page faults in our process and racing rmap walks from other processes to cause page tables to be shared again before we actually perform the split. Fix it by explicitly calling into the hugetlb unshare logic from __split_vma() in the same place where THP splitting also happens.  At that point, both the VMA and the rmap(s) are write-locked. An annoying detail is that we can now call into the helper hugetlb_unshare_pmds() from two different locking contexts: 1. from hugetlb_split(), holding:     - mmap lock (exclusively)     - VMA lock     - file rmap lock (exclusively) 2. hugetlb_unshare_all_pmds(), which I think is designed to be able to    call us with only the mmap lock held (in shared mode), but currently    only runs while holding mmap lock (exclusively) and VMA lock Backporting note: This commit fixes a racy protection that was introduced in commit b30c14cd6102 (&amp;#34;hugetlb: unshare some PMDs when splitting VMAs&amp;#34;); that commit claimed to fix an issue introduced in 5.13, but it should actually also go all the way back. [jannh@google.com: v2]&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-38084</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-1417 — Linux Kernel: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1417</link>
      <description>&lt;p&gt;Ein entfernter Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen und nicht näher spezifizierte Auswirkungen zu erzielen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen und nicht näher spezifizierte Auswirkungen zu erzielen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1417</guid>
    </item>
  </channel>
</rss>
