<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 22:39:57 +0000</lastBuildDate>
    <item>
      <title>bdu:2025-13517</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-13517</link>
      <description>bdu:2025-13517</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-13517</guid>
    </item>
    <item>
      <title>BELL-CVE-2025-38495</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2025-38495</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2025-38495</guid>
    </item>
    <item>
      <title>certfr-2025-avi-0698 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de Debian. Certaines d'entre elles permettent à un…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0698</link>
      <description>certfr-2025-avi-0698</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0698</guid>
    </item>
    <item>
      <title>EUVD-2026-347071</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-347071</link>
      <description>EUVD-2026-347071</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-347071</guid>
    </item>
    <item>
      <title>fkie_cve-2025-38495</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-38495</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;HID: core: ensure the allocated report buffer can contain the reserved report ID&lt;/p&gt;
&lt;p&gt;When the report ID is not used, the low level transport drivers expect
the first byte to be 0. However, currently the allocated buffer not
account for that extra byte, meaning that instead of having 8 guaranteed
bytes for implement to be working, we only have 7.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;HID: core: ensure the allocated report buffer can contain the reserved report ID&lt;/p&gt;
&lt;p&gt;When the report ID is not used, the low level transport drivers expect
the first byte to be 0. However, currently the allocated buffer not
account for that extra byte, meaning that instead of having 8 guaranteed
bytes for implement to be working, we only have 7.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-38495</guid>
    </item>
    <item>
      <title>GHSA-42gx-8xq5-j4pf</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-42gx-8xq5-j4pf</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;HID: core: ensure the allocated report buffer can contain the reserved report ID&lt;/p&gt;
&lt;p&gt;When the report ID is not used, the low level transport drivers expect
the first byte to be 0. However, currently the allocated buffer not
account for that extra byte, meaning that instead of having 8 guaranteed
bytes for implement to be working, we only have 7.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;HID: core: ensure the allocated report buffer can contain the reserved report ID&lt;/p&gt;
&lt;p&gt;When the report ID is not used, the low level transport drivers expect
the first byte to be 0. However, currently the allocated buffer not
account for that extra byte, meaning that instead of having 8 guaranteed
bytes for implement to be working, we only have 7.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-42gx-8xq5-j4pf</guid>
    </item>
    <item>
      <title>msrc_CVE-2025-38495 — HID: core: ensure the allocated report buffer can contain the reserved report ID</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2025-38495</link>
      <description>msrc_CVE-2025-38495</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2025-38495</guid>
    </item>
    <item>
      <title>OESA-2025-2054 — kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2025-2054</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;drm/vkms: Fix use after free and double free on init error&lt;/p&gt;
&lt;p&gt;If the driver initialization fails, the vkms_exit() function might
access an uninitialized or freed default_config pointer and it might
double free it.&lt;/p&gt;
&lt;p&gt;Fix both possible errors by initializing default_config only when the
driver initialization succeeded.(CVE-2025-22097)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;wifi: at76c50x: fix use after free access in at76_disconnect&lt;/p&gt;
&lt;p&gt;The memory pointed to by priv is freed at the end of at76_delete_device
function (using ieee80211_free_hw). But the code then accesses the udev
field of the freed object to put the USB device. This may also lead to a
memory leak of the usb device. Fix this by using udev from interface.(CVE-2025-37796)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;codel: remove sch-&amp;amp;gt;q.qlen check before qdisc_tree_reduce_backlog()&lt;/p&gt;
&lt;p&gt;After making all -&amp;amp;gt;qlen_notify() callbacks idempotent, now it is safe to
remove the check of qlen!=0 from both fq_codel_dequeue() and
codel_qdisc_dequeue().(CVE-2025-37798)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;net_sched: qfq: Fix double list add in class with netem as child qdisc&lt;/p&gt;
&lt;p&gt;As described in Gerrard&amp;amp;apos;s report [1], there are use cases where a netem
child qdisc will make the parent qdisc&amp;amp;apos;s enqueue…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;drm/vkms: Fix use after free and double free on init error&lt;/p&gt;
&lt;p&gt;If the driver initialization fails, the vkms_exit() function might
access an uninitialized or freed default_config pointer and it might
double free it.&lt;/p&gt;
&lt;p&gt;Fix both possible errors by initializing default_config only when the
driver initialization succeeded.(CVE-2025-22097)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;wifi: at76c50x: fix use after free access in at76_disconnect&lt;/p&gt;
&lt;p&gt;The memory pointed to by priv is freed at the end of at76_delete_device
function (using ieee80211_free_hw). But the code then accesses the udev
field of the freed object to put the USB device. This may also lead to a
memory leak of the usb device. Fix this by using udev from interface.(CVE-2025-37796)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;codel: remove sch-&amp;amp;gt;q.qlen check before qdisc_tree_reduce_backlog()&lt;/p&gt;
&lt;p&gt;After making all -&amp;amp;gt;qlen_notify() callbacks idempotent, now it is safe to
remove the check of qlen!=0 from both fq_codel_dequeue() and
codel_qdisc_dequeue().(CVE-2025-37798)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;net_sched: qfq: Fix double list add in class with netem as child qdisc&lt;/p&gt;
&lt;p&gt;As described in Gerrard&amp;amp;apos;s report [1], there are use cases where a netem
child qdisc will make the parent qdisc&amp;amp;apos;s enqueue…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2025-2054</guid>
    </item>
    <item>
      <title>openSUSE-SU-2025:20081-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2025:20081-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2025:20081-1</guid>
    </item>
    <item>
      <title>SUSE-SU-2025:02820-1 — Security update for the Linux Kernel RT (Live Patch 4 for SLE 15 SP6)</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2025:02820-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel RT (Live Patch 4 for SLE 15 SP6)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel RT (Live Patch 4 for SLE 15 SP6)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2025:02820-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-38495</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-38495</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe, Ubuntu:16.04:LTS: linux-hwe-edge and 213 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: HID: core: ensure the allocated report buffer can contain the reserved report ID When the report ID is not used, the low level transport drivers expect the first byte to be 0. However, currently the allocated buffer not account for that extra byte, meaning that instead of having 8 guaranteed bytes for implement to be working, we only have 7.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe, Ubuntu:16.04:LTS: linux-hwe-edge and 213 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: HID: core: ensure the allocated report buffer can contain the reserved report ID When the report ID is not used, the low level transport drivers expect the first byte to be 0. However, currently the allocated buffer not account for that extra byte, meaning that instead of having 8 guaranteed bytes for implement to be working, we only have 7.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-38495</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-1665 — Linux Kernel: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1665</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen oder andere nicht spezifizierte Angriffe durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen oder andere nicht spezifizierte Angriffe durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1665</guid>
    </item>
  </channel>
</rss>
