<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 15:29:11 +0000</lastBuildDate>
    <item>
      <title>ALSA-2026:3083 — Important: kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:3083</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: bpftool, AlmaLinux:8: kernel, AlmaLinux:8: kernel-abi-stablelists, AlmaLinux:8: kernel-core, AlmaLinux:8: kernel-cross-headers, AlmaLinux:8: kernel-debug, AlmaLinux:8: kernel-debug-core, AlmaLinux:8: kernel-debug-devel, AlmaLinux:8: kernel-debug-modules, AlmaLinux:8: kernel-debug-modules-extra and 15 more&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: page_pool: Fix use-after-free in page_pool_recycle_in_ring (CVE-2025-38129)
  * kernel: Linux kernel:A use-after-free in bridge multicast in br_multicast_port_ctx_init (CVE-2025-38248)
  * kernel: smc: Fix use-after-free in __pnet_find_base_ndev() (CVE-2025-40064)
  * kernel: mlxsw: spectrum_mr: Fix use-after-free when updating multicast route stats (CVE-2025-68800)
  * kernel: Linux kernel: Use-after-free in teql queueing discipline can lead to privilege escalation (CVE-2026-23074)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: bpftool, AlmaLinux:8: kernel, AlmaLinux:8: kernel-abi-stablelists, AlmaLinux:8: kernel-core, AlmaLinux:8: kernel-cross-headers, AlmaLinux:8: kernel-debug, AlmaLinux:8: kernel-debug-core, AlmaLinux:8: kernel-debug-devel, AlmaLinux:8: kernel-debug-modules, AlmaLinux:8: kernel-debug-modules-extra and 15 more&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: page_pool: Fix use-after-free in page_pool_recycle_in_ring (CVE-2025-38129)
  * kernel: Linux kernel:A use-after-free in bridge multicast in br_multicast_port_ctx_init (CVE-2025-38248)
  * kernel: smc: Fix use-after-free in __pnet_find_base_ndev() (CVE-2025-40064)
  * kernel: mlxsw: spectrum_mr: Fix use-after-free when updating multicast route stats (CVE-2025-68800)
  * kernel: Linux kernel: Use-after-free in teql queueing discipline can lead to privilege escalation (CVE-2026-23074)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:3083</guid>
    </item>
    <item>
      <title>bdu:2025-09588</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-09588</link>
      <description>bdu:2025-09588</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-09588</guid>
    </item>
    <item>
      <title>BELL-CVE-2025-38248</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2025-38248</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2025-38248</guid>
    </item>
    <item>
      <title>certfr-2025-avi-0723 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de SUSE. Certaines d'entre elles permettent à un at…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0723</link>
      <description>certfr-2025-avi-0723</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0723</guid>
    </item>
    <item>
      <title>EUVD-2026-346980</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-346980</link>
      <description>EUVD-2026-346980</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-346980</guid>
    </item>
    <item>
      <title>fkie_cve-2025-38248</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-38248</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;bridge: mcast: Fix use-after-free during router port configuration&lt;/p&gt;
&lt;p&gt;The bridge maintains a global list of ports behind which a multicast
router resides. The list is consulted during forwarding to ensure
multicast packets are forwarded to these ports even if the ports are not
member in the matching MDB entry.&lt;/p&gt;
&lt;p&gt;When per-VLAN multicast snooping is enabled, the per-port multicast
context is disabled on each port and the port is removed from the global
router port list:&lt;/p&gt;
&lt;p&gt;# ip link add name br1 up type bridge vlan_filtering 1 mcast_snooping 1
 # ip link add name dummy1 up master br1 type dummy
 # ip link set dev dummy1 type bridge_slave mcast_router 2
 $ bridge -d mdb show | grep router
 router ports on br1: dummy1
 # ip link set dev br1 type bridge mcast_vlan_snooping 1
 $ bridge -d mdb show | grep router&lt;/p&gt;
&lt;p&gt;However, the port can be re-added to the global list even when per-VLAN
multicast snooping is enabled:&lt;/p&gt;
&lt;p&gt;# ip link set dev dummy1 type bridge_slave mcast_router 0
 # ip link set dev dummy1 type bridge_slave mcast_router 2
 $ bridge -d mdb show | grep router
 router ports on br1: dummy1&lt;/p&gt;
&lt;p&gt;Since commit 4b30ae9adb04 (&amp;#34;net: bridge: mcast: re-implement
br_multicast_{enable, disable}_port functions&amp;#34;), when per-VLAN multicast
snooping is enabled, multicast disablement on a port will disable the
per-{port, VLAN} multicast contexts and not the per-port one. As a
result, a port will remain in the global router port list…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;bridge: mcast: Fix use-after-free during router port configuration&lt;/p&gt;
&lt;p&gt;The bridge maintains a global list of ports behind which a multicast
router resides. The list is consulted during forwarding to ensure
multicast packets are forwarded to these ports even if the ports are not
member in the matching MDB entry.&lt;/p&gt;
&lt;p&gt;When per-VLAN multicast snooping is enabled, the per-port multicast
context is disabled on each port and the port is removed from the global
router port list:&lt;/p&gt;
&lt;p&gt;# ip link add name br1 up type bridge vlan_filtering 1 mcast_snooping 1
 # ip link add name dummy1 up master br1 type dummy
 # ip link set dev dummy1 type bridge_slave mcast_router 2
 $ bridge -d mdb show | grep router
 router ports on br1: dummy1
 # ip link set dev br1 type bridge mcast_vlan_snooping 1
 $ bridge -d mdb show | grep router&lt;/p&gt;
&lt;p&gt;However, the port can be re-added to the global list even when per-VLAN
multicast snooping is enabled:&lt;/p&gt;
&lt;p&gt;# ip link set dev dummy1 type bridge_slave mcast_router 0
 # ip link set dev dummy1 type bridge_slave mcast_router 2
 $ bridge -d mdb show | grep router
 router ports on br1: dummy1&lt;/p&gt;
&lt;p&gt;Since commit 4b30ae9adb04 (&amp;#34;net: bridge: mcast: re-implement
br_multicast_{enable, disable}_port functions&amp;#34;), when per-VLAN multicast
snooping is enabled, multicast disablement on a port will disable the
per-{port, VLAN} multicast contexts and not the per-port one. As a
result, a port will remain in the global router port list…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-38248</guid>
    </item>
    <item>
      <title>GHSA-2838-84rj-32xc</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-2838-84rj-32xc</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;bridge: mcast: Fix use-after-free during router port configuration&lt;/p&gt;
&lt;p&gt;The bridge maintains a global list of ports behind which a multicast
router resides. The list is consulted during forwarding to ensure
multicast packets are forwarded to these ports even if the ports are not
member in the matching MDB entry.&lt;/p&gt;
&lt;p&gt;When per-VLAN multicast snooping is enabled, the per-port multicast
context is disabled on each port and the port is removed from the global
router port list:&lt;/p&gt;
&lt;p&gt;# ip link add name br1 up type bridge vlan_filtering 1 mcast_snooping 1
 # ip link add name dummy1 up master br1 type dummy
 # ip link set dev dummy1 type bridge_slave mcast_router 2
 $ bridge -d mdb show | grep router
 router ports on br1: dummy1
 # ip link set dev br1 type bridge mcast_vlan_snooping 1
 $ bridge -d mdb show | grep router&lt;/p&gt;
&lt;p&gt;However, the port can be re-added to the global list even when per-VLAN
multicast snooping is enabled:&lt;/p&gt;
&lt;p&gt;# ip link set dev dummy1 type bridge_slave mcast_router 0
 # ip link set dev dummy1 type bridge_slave mcast_router 2
 $ bridge -d mdb show | grep router
 router ports on br1: dummy1&lt;/p&gt;
&lt;p&gt;Since commit 4b30ae9adb04 (&amp;#34;net: bridge: mcast: re-implement
br_multicast_{enable, disable}_port functions&amp;#34;), when per-VLAN multicast
snooping is enabled, multicast disablement on a port will disable the
per-{port, VLAN} multicast contexts and not the per-port one. As a
result, a port will remain in the global router port list…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;bridge: mcast: Fix use-after-free during router port configuration&lt;/p&gt;
&lt;p&gt;The bridge maintains a global list of ports behind which a multicast
router resides. The list is consulted during forwarding to ensure
multicast packets are forwarded to these ports even if the ports are not
member in the matching MDB entry.&lt;/p&gt;
&lt;p&gt;When per-VLAN multicast snooping is enabled, the per-port multicast
context is disabled on each port and the port is removed from the global
router port list:&lt;/p&gt;
&lt;p&gt;# ip link add name br1 up type bridge vlan_filtering 1 mcast_snooping 1
 # ip link add name dummy1 up master br1 type dummy
 # ip link set dev dummy1 type bridge_slave mcast_router 2
 $ bridge -d mdb show | grep router
 router ports on br1: dummy1
 # ip link set dev br1 type bridge mcast_vlan_snooping 1
 $ bridge -d mdb show | grep router&lt;/p&gt;
&lt;p&gt;However, the port can be re-added to the global list even when per-VLAN
multicast snooping is enabled:&lt;/p&gt;
&lt;p&gt;# ip link set dev dummy1 type bridge_slave mcast_router 0
 # ip link set dev dummy1 type bridge_slave mcast_router 2
 $ bridge -d mdb show | grep router
 router ports on br1: dummy1&lt;/p&gt;
&lt;p&gt;Since commit 4b30ae9adb04 (&amp;#34;net: bridge: mcast: re-implement
br_multicast_{enable, disable}_port functions&amp;#34;), when per-VLAN multicast
snooping is enabled, multicast disablement on a port will disable the
per-{port, VLAN} multicast contexts and not the per-port one. As a
result, a port will remain in the global router port list…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-2838-84rj-32xc</guid>
    </item>
    <item>
      <title>msrc_CVE-2025-38248 — bridge: mcast: Fix use-after-free during router port configuration</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2025-38248</link>
      <description>msrc_CVE-2025-38248</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2025-38248</guid>
    </item>
    <item>
      <title>OESA-2025-2077 — kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2025-2077</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;mac802154: check local interfaces before deleting sdata list&lt;/p&gt;
&lt;p&gt;syzkaller reported a corrupted list in ieee802154_if_remove. [1]&lt;/p&gt;
&lt;p&gt;Remove an IEEE 802.15.4 network interface after unregister an IEEE 802.15.4
hardware device from the system.&lt;/p&gt;
&lt;p&gt;CPU0					CPU1
====					====
genl_family_rcv_msg_doit		ieee802154_unregister_hw
ieee802154_del_iface			ieee802154_remove_interfaces
rdev_del_virtual_intf_deprecated	list_del(&amp;amp;amp;sdata-&amp;amp;gt;list)
ieee802154_if_remove
list_del_rcu&lt;/p&gt;
&lt;p&gt;The net device has been unregistered, since the rcu grace period,
unregistration must be run before ieee802154_if_remove.&lt;/p&gt;
&lt;p&gt;To avoid this issue, add a check for local-&amp;amp;gt;interfaces before deleting
sdata list.&lt;/p&gt;
&lt;p&gt;[1]
kernel BUG at lib/list_debug.c:58!
Oops: invalid opcode: 0000 [#1] PREEMPT SMP KASAN PTI
CPU: 0 UID: 0 PID: 6277 Comm: syz-executor157 Not tainted 6.12.0-rc6-syzkaller-00005-g557329bcecc2 #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 09/13/2024
RIP: 0010:__list_del_entry_valid_or_report+0xf4/0x140 lib/list_debug.c:56
Code: e8 a1 7e 00 07 90 0f 0b 48 c7 c7 e0 37 60 8c 4c 89 fe e8 8f 7e 00 07 90 0f 0b 48 c7 c7 40 38 60 8c 4c 89 fe e8 7d 7e 00 07 90 &amp;amp;lt;0f&amp;amp;gt; 0b 48 c7 c7 a0 38 60 8c 4c 89 fe e8 6b 7e 00 07 90 0f 0b 48 c7
RSP: 0018:ffffc9000490f3d0 EFLAGS: 00010246
RAX: 000000000000004e RBX: dead000000000122 RCX: d211eee56bb28d00
RDX:…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;mac802154: check local interfaces before deleting sdata list&lt;/p&gt;
&lt;p&gt;syzkaller reported a corrupted list in ieee802154_if_remove. [1]&lt;/p&gt;
&lt;p&gt;Remove an IEEE 802.15.4 network interface after unregister an IEEE 802.15.4
hardware device from the system.&lt;/p&gt;
&lt;p&gt;CPU0					CPU1
====					====
genl_family_rcv_msg_doit		ieee802154_unregister_hw
ieee802154_del_iface			ieee802154_remove_interfaces
rdev_del_virtual_intf_deprecated	list_del(&amp;amp;amp;sdata-&amp;amp;gt;list)
ieee802154_if_remove
list_del_rcu&lt;/p&gt;
&lt;p&gt;The net device has been unregistered, since the rcu grace period,
unregistration must be run before ieee802154_if_remove.&lt;/p&gt;
&lt;p&gt;To avoid this issue, add a check for local-&amp;amp;gt;interfaces before deleting
sdata list.&lt;/p&gt;
&lt;p&gt;[1]
kernel BUG at lib/list_debug.c:58!
Oops: invalid opcode: 0000 [#1] PREEMPT SMP KASAN PTI
CPU: 0 UID: 0 PID: 6277 Comm: syz-executor157 Not tainted 6.12.0-rc6-syzkaller-00005-g557329bcecc2 #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 09/13/2024
RIP: 0010:__list_del_entry_valid_or_report+0xf4/0x140 lib/list_debug.c:56
Code: e8 a1 7e 00 07 90 0f 0b 48 c7 c7 e0 37 60 8c 4c 89 fe e8 8f 7e 00 07 90 0f 0b 48 c7 c7 40 38 60 8c 4c 89 fe e8 7d 7e 00 07 90 &amp;amp;lt;0f&amp;amp;gt; 0b 48 c7 c7 a0 38 60 8c 4c 89 fe e8 6b 7e 00 07 90 0f 0b 48 c7
RSP: 0018:ffffc9000490f3d0 EFLAGS: 00010246
RAX: 000000000000004e RBX: dead000000000122 RCX: d211eee56bb28d00
RDX:…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2025-2077</guid>
    </item>
    <item>
      <title>RHSA-2026:3083 — Red Hat Security Advisory: kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:3083</link>
      <description>&lt;p&gt;kernel: Linux kernel: Use-after-free vulnerability in page_pool_recycle_in_ring can lead to arbitrary code execution kernel: Linux kernel:A use-after-free in bridge multicast in br_multicast_port_ctx_init kernel: smc: Fix use-after-free in __pnet_find_base_ndev() kernel: mlxsw: spectrum_mr: Fix use-after-free when updating multicast route stats kernel: Linux kernel: Use-after-free in teql queueing discipline can lead to privilege escalation&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;kernel: Linux kernel: Use-after-free vulnerability in page_pool_recycle_in_ring can lead to arbitrary code execution kernel: Linux kernel:A use-after-free in bridge multicast in br_multicast_port_ctx_init kernel: smc: Fix use-after-free in __pnet_find_base_ndev() kernel: mlxsw: spectrum_mr: Fix use-after-free when updating multicast route stats kernel: Linux kernel: Use-after-free in teql queueing discipline can lead to privilege escalation&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:3083</guid>
    </item>
    <item>
      <title>RHSA-2026:3110 — Red Hat Security Advisory: kernel-rt security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:3110</link>
      <description>&lt;p&gt;kernel: Linux kernel: Use-after-free vulnerability in page_pool_recycle_in_ring can lead to arbitrary code execution kernel: Linux kernel:A use-after-free in bridge multicast in br_multicast_port_ctx_init kernel: smc: Fix use-after-free in __pnet_find_base_ndev() kernel: mlxsw: spectrum_mr: Fix use-after-free when updating multicast route stats kernel: Linux kernel: Use-after-free in teql queueing discipline can lead to privilege escalation&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;kernel: Linux kernel: Use-after-free vulnerability in page_pool_recycle_in_ring can lead to arbitrary code execution kernel: Linux kernel:A use-after-free in bridge multicast in br_multicast_port_ctx_init kernel: smc: Fix use-after-free in __pnet_find_base_ndev() kernel: mlxsw: spectrum_mr: Fix use-after-free when updating multicast route stats kernel: Linux kernel: Use-after-free in teql queueing discipline can lead to privilege escalation&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:3110</guid>
    </item>
    <item>
      <title>SUSE-SU-2025:02853-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2025:02853-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2025:02853-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-38248</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-38248</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 160 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: bridge: mcast: Fix use-after-free during router port configuration The bridge maintains a global list of ports behind which a multicast router resides. The list is consulted during forwarding to ensure multicast packets are forwarded to these ports even if the ports are not member in the matching MDB entry. When per-VLAN multicast snooping is enabled, the per-port multicast context is disabled on each port and the port is removed from the global router port list:  # ip link add name br1 up type bridge vlan_filtering 1 mcast_snooping 1  # ip link add name dummy1 up master br1 type dummy  # ip link set dev dummy1 type bridge_slave mcast_router 2  $ bridge -d mdb show | grep router  router ports on br1: dummy1  # ip link set dev br1 type bridge mcast_vlan_snooping 1  $ bridge -d mdb show | grep router However, the port can be re-added to the global list even when per-VLAN multicast snooping is enabled:  # ip link set dev dummy1 type bridge_slave mcast_router 0  # ip link set dev dummy1 type bridge_slave mcast_router 2  $ bridge -d mdb show | grep router  router ports on br1: dummy1 Since commit 4b30ae9adb04 (&amp;#34;net: bridge: mcast: re-implement br_multicast_{enable, disable}_port functions&amp;#34;), when per-VLAN multicast snooping is enabled, multicast disablement on a port will disable the per-{port, VLAN} multicast contexts and not the per-port one. As a result, a port will remain in the global router port list even a…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 160 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: bridge: mcast: Fix use-after-free during router port configuration The bridge maintains a global list of ports behind which a multicast router resides. The list is consulted during forwarding to ensure multicast packets are forwarded to these ports even if the ports are not member in the matching MDB entry. When per-VLAN multicast snooping is enabled, the per-port multicast context is disabled on each port and the port is removed from the global router port list:  # ip link add name br1 up type bridge vlan_filtering 1 mcast_snooping 1  # ip link add name dummy1 up master br1 type dummy  # ip link set dev dummy1 type bridge_slave mcast_router 2  $ bridge -d mdb show | grep router  router ports on br1: dummy1  # ip link set dev br1 type bridge mcast_vlan_snooping 1  $ bridge -d mdb show | grep router However, the port can be re-added to the global list even when per-VLAN multicast snooping is enabled:  # ip link set dev dummy1 type bridge_slave mcast_router 0  # ip link set dev dummy1 type bridge_slave mcast_router 2  $ bridge -d mdb show | grep router  router ports on br1: dummy1 Since commit 4b30ae9adb04 (&amp;#34;net: bridge: mcast: re-implement br_multicast_{enable, disable}_port functions&amp;#34;), when per-VLAN multicast snooping is enabled, multicast disablement on a port will disable the per-{port, VLAN} multicast contexts and not the per-port one. As a result, a port will remain in the global router port list even a…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-38248</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-1517 — Linux Kernel: Mehrere Schwachstellen ermöglichen Denial of Service</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1517</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen oder nicht näher spezifizierte Auswirkungen zu erzielen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen oder nicht näher spezifizierte Auswirkungen zu erzielen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1517</guid>
    </item>
  </channel>
</rss>
