<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 16:59:43 +0000</lastBuildDate>
    <item>
      <title>ALSA-2025:16880 — Moderate: kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2025:16880</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: kernel, AlmaLinux:9: kernel-64k, AlmaLinux:9: kernel-64k-core, AlmaLinux:9: kernel-64k-debug, AlmaLinux:9: kernel-64k-debug-core, AlmaLinux:9: kernel-64k-debug-devel, AlmaLinux:9: kernel-64k-debug-devel-matched, AlmaLinux:9: kernel-64k-debug-modules, AlmaLinux:9: kernel-64k-debug-modules-core, AlmaLinux:9: kernel-64k-debug-modules-extra and 66 more&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: netfilter: nf_conntrack: fix crash due to removal of uninitialised entry (CVE-2025-38472)
  * kernel: smb: client: fix use-after-free in cifs_oplock_break (CVE-2025-38527)
  * kernel: sctp: linearize cloned gso packets in sctp_rcv (CVE-2025-38718)
  * kernel: tls: fix handling of zero-length records on the rx_list (CVE-2025-39682)
  * kernel: io_uring/futex: ensure io_futex_wait() cleans up properly on failure (CVE-2025-39698)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: kernel, AlmaLinux:9: kernel-64k, AlmaLinux:9: kernel-64k-core, AlmaLinux:9: kernel-64k-debug, AlmaLinux:9: kernel-64k-debug-core, AlmaLinux:9: kernel-64k-debug-devel, AlmaLinux:9: kernel-64k-debug-devel-matched, AlmaLinux:9: kernel-64k-debug-modules, AlmaLinux:9: kernel-64k-debug-modules-core, AlmaLinux:9: kernel-64k-debug-modules-extra and 66 more&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: netfilter: nf_conntrack: fix crash due to removal of uninitialised entry (CVE-2025-38472)
  * kernel: smb: client: fix use-after-free in cifs_oplock_break (CVE-2025-38527)
  * kernel: sctp: linearize cloned gso packets in sctp_rcv (CVE-2025-38718)
  * kernel: tls: fix handling of zero-length records on the rx_list (CVE-2025-39682)
  * kernel: io_uring/futex: ensure io_futex_wait() cleans up properly on failure (CVE-2025-39698)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2025:16880</guid>
    </item>
    <item>
      <title>bdu:2025-15816</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-15816</link>
      <description>bdu:2025-15816</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-15816</guid>
    </item>
    <item>
      <title>BELL-CVE-2025-38527</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2025-38527</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2025-38527</guid>
    </item>
    <item>
      <title>certfr-2025-avi-0842 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de Red Hat. Certaines d'entre elles permettent à un…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0842</link>
      <description>certfr-2025-avi-0842</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0842</guid>
    </item>
    <item>
      <title>EUVD-2026-347084</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-347084</link>
      <description>EUVD-2026-347084</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-347084</guid>
    </item>
    <item>
      <title>fkie_cve-2025-38527</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-38527</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;smb: client: fix use-after-free in cifs_oplock_break&lt;/p&gt;
&lt;p&gt;A race condition can occur in cifs_oplock_break() leading to a
use-after-free of the cinode structure when unmounting:&lt;/p&gt;
&lt;p&gt;cifs_oplock_break()
    _cifsFileInfo_put(cfile)
      cifsFileInfo_put_final()
        cifs_sb_deactive()
          [last ref, start releasing sb]
            kill_sb()
              kill_anon_super()
                generic_shutdown_super()
                  evict_inodes()
                    dispose_list()
                      evict()
                        destroy_inode()
                          call_rcu(&amp;amp;inode-&amp;gt;i_rcu, i_callback)
    spin_lock(&amp;amp;cinode-&amp;gt;open_file_lock)  &amp;lt;- OK
                            [later] i_callback()
                              cifs_free_inode()
                                kmem_cache_free(cinode)
    spin_unlock(&amp;amp;cinode-&amp;gt;open_file_lock)  &amp;lt;- UAF
    cifs_done_oplock_break(cinode)       &amp;lt;- UAF&lt;/p&gt;
&lt;p&gt;The issue occurs when umount has already released its reference to the
superblock. When _cifsFileInfo_put() calls cifs_sb_deactive(), this
releases the last reference, triggering the immediate cleanup of all
inodes under RCU. However, cifs_oplock_break() continues to access the
cinode after this point, resulting in use-after-free.&lt;/p&gt;
&lt;p&gt;Fix this by holding an extra reference to the superblock during the
entire oplock break operation. This ensures that the superblock and
its inodes remain valid until the oplock bre…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;smb: client: fix use-after-free in cifs_oplock_break&lt;/p&gt;
&lt;p&gt;A race condition can occur in cifs_oplock_break() leading to a
use-after-free of the cinode structure when unmounting:&lt;/p&gt;
&lt;p&gt;cifs_oplock_break()
    _cifsFileInfo_put(cfile)
      cifsFileInfo_put_final()
        cifs_sb_deactive()
          [last ref, start releasing sb]
            kill_sb()
              kill_anon_super()
                generic_shutdown_super()
                  evict_inodes()
                    dispose_list()
                      evict()
                        destroy_inode()
                          call_rcu(&amp;amp;inode-&amp;gt;i_rcu, i_callback)
    spin_lock(&amp;amp;cinode-&amp;gt;open_file_lock)  &amp;lt;- OK
                            [later] i_callback()
                              cifs_free_inode()
                                kmem_cache_free(cinode)
    spin_unlock(&amp;amp;cinode-&amp;gt;open_file_lock)  &amp;lt;- UAF
    cifs_done_oplock_break(cinode)       &amp;lt;- UAF&lt;/p&gt;
&lt;p&gt;The issue occurs when umount has already released its reference to the
superblock. When _cifsFileInfo_put() calls cifs_sb_deactive(), this
releases the last reference, triggering the immediate cleanup of all
inodes under RCU. However, cifs_oplock_break() continues to access the
cinode after this point, resulting in use-after-free.&lt;/p&gt;
&lt;p&gt;Fix this by holding an extra reference to the superblock during the
entire oplock break operation. This ensures that the superblock and
its inodes remain valid until the oplock bre…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-38527</guid>
    </item>
    <item>
      <title>GHSA-hm6q-hprh-4f22</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-hm6q-hprh-4f22</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;smb: client: fix use-after-free in cifs_oplock_break&lt;/p&gt;
&lt;p&gt;A race condition can occur in cifs_oplock_break() leading to a
use-after-free of the cinode structure when unmounting:&lt;/p&gt;
&lt;p&gt;cifs_oplock_break()
    _cifsFileInfo_put(cfile)
      cifsFileInfo_put_final()
        cifs_sb_deactive()
          [last ref, start releasing sb]
            kill_sb()
              kill_anon_super()
                generic_shutdown_super()
                  evict_inodes()
                    dispose_list()
                      evict()
                        destroy_inode()
                          call_rcu(&amp;amp;inode-&amp;gt;i_rcu, i_callback)
    spin_lock(&amp;amp;cinode-&amp;gt;open_file_lock)  &amp;lt;- OK
                            [later] i_callback()
                              cifs_free_inode()
                                kmem_cache_free(cinode)
    spin_unlock(&amp;amp;cinode-&amp;gt;open_file_lock)  &amp;lt;- UAF
    cifs_done_oplock_break(cinode)       &amp;lt;- UAF&lt;/p&gt;
&lt;p&gt;The issue occurs when umount has already released its reference to the
superblock. When _cifsFileInfo_put() calls cifs_sb_deactive(), this
releases the last reference, triggering the immediate cleanup of all
inodes under RCU. However, cifs_oplock_break() continues to access the
cinode after this point, resulting in use-after-free.&lt;/p&gt;
&lt;p&gt;Fix this by holding an extra reference to the superblock during the
entire oplock break operation. This ensures that the superblock and
its inodes remain valid until the oplock bre…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;smb: client: fix use-after-free in cifs_oplock_break&lt;/p&gt;
&lt;p&gt;A race condition can occur in cifs_oplock_break() leading to a
use-after-free of the cinode structure when unmounting:&lt;/p&gt;
&lt;p&gt;cifs_oplock_break()
    _cifsFileInfo_put(cfile)
      cifsFileInfo_put_final()
        cifs_sb_deactive()
          [last ref, start releasing sb]
            kill_sb()
              kill_anon_super()
                generic_shutdown_super()
                  evict_inodes()
                    dispose_list()
                      evict()
                        destroy_inode()
                          call_rcu(&amp;amp;inode-&amp;gt;i_rcu, i_callback)
    spin_lock(&amp;amp;cinode-&amp;gt;open_file_lock)  &amp;lt;- OK
                            [later] i_callback()
                              cifs_free_inode()
                                kmem_cache_free(cinode)
    spin_unlock(&amp;amp;cinode-&amp;gt;open_file_lock)  &amp;lt;- UAF
    cifs_done_oplock_break(cinode)       &amp;lt;- UAF&lt;/p&gt;
&lt;p&gt;The issue occurs when umount has already released its reference to the
superblock. When _cifsFileInfo_put() calls cifs_sb_deactive(), this
releases the last reference, triggering the immediate cleanup of all
inodes under RCU. However, cifs_oplock_break() continues to access the
cinode after this point, resulting in use-after-free.&lt;/p&gt;
&lt;p&gt;Fix this by holding an extra reference to the superblock during the
entire oplock break operation. This ensures that the superblock and
its inodes remain valid until the oplock bre…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-hm6q-hprh-4f22</guid>
    </item>
    <item>
      <title>msrc_CVE-2025-38527 — smb: client: fix use-after-free in cifs_oplock_break</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2025-38527</link>
      <description>msrc_CVE-2025-38527</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2025-38527</guid>
    </item>
    <item>
      <title>OESA-2025-2800 — kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2025-2800</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP3: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;ext4: update s_journal_inum if it changes after journal replay&lt;/p&gt;
&lt;p&gt;When mounting a crafted ext4 image, s_journal_inum may change after journal
replay, which is obviously unreasonable because we have successfully loaded
and replayed the journal through the old s_journal_inum. And the new
s_journal_inum bypasses some of the checks in ext4_get_journal(), which
may trigger a null pointer dereference problem. So if s_journal_inum
changes after the journal replay, we ignore the change, and rewrite the
current journal_inum to the superblock.(CVE-2023-53091)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;vxlan: Fix nexthop hash size&lt;/p&gt;
&lt;p&gt;The nexthop code expects a 31 bit hash, such as what is returned by
fib_multipath_hash() and rt6_multipath_hash(). Passing the 32 bit hash
returned by skb_get_hash() can lead to problems related to the fact that
&amp;amp;apos;int hash&amp;amp;apos; is a negative number when the MSB is set.&lt;/p&gt;
&lt;p&gt;In the case of hash threshold nexthop groups, nexthop_select_path_hthr()
will disproportionately select the first nexthop group entry. In the case
of resilient nexthop groups, nexthop_select_path_res() may do an out of
bounds access in nh_buckets[], for example:
    hash = -912054133
    num_nh_buckets = 2
    bucket_index = 65535&lt;/p&gt;
&lt;p&gt;which leads to the following panic:&lt;/p&gt;
&lt;p&gt;BUG: unable to handle page fault for address: ffffc9000…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP3: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;ext4: update s_journal_inum if it changes after journal replay&lt;/p&gt;
&lt;p&gt;When mounting a crafted ext4 image, s_journal_inum may change after journal
replay, which is obviously unreasonable because we have successfully loaded
and replayed the journal through the old s_journal_inum. And the new
s_journal_inum bypasses some of the checks in ext4_get_journal(), which
may trigger a null pointer dereference problem. So if s_journal_inum
changes after the journal replay, we ignore the change, and rewrite the
current journal_inum to the superblock.(CVE-2023-53091)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;vxlan: Fix nexthop hash size&lt;/p&gt;
&lt;p&gt;The nexthop code expects a 31 bit hash, such as what is returned by
fib_multipath_hash() and rt6_multipath_hash(). Passing the 32 bit hash
returned by skb_get_hash() can lead to problems related to the fact that
&amp;amp;apos;int hash&amp;amp;apos; is a negative number when the MSB is set.&lt;/p&gt;
&lt;p&gt;In the case of hash threshold nexthop groups, nexthop_select_path_hthr()
will disproportionately select the first nexthop group entry. In the case
of resilient nexthop groups, nexthop_select_path_res() may do an out of
bounds access in nh_buckets[], for example:
    hash = -912054133
    num_nh_buckets = 2
    bucket_index = 65535&lt;/p&gt;
&lt;p&gt;which leads to the following panic:&lt;/p&gt;
&lt;p&gt;BUG: unable to handle page fault for address: ffffc9000…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2025-2800</guid>
    </item>
    <item>
      <title>openSUSE-SU-2025:20081-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2025:20081-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2025:20081-1</guid>
    </item>
    <item>
      <title>RHSA-2025:16904 — Red Hat Security Advisory: kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2025:16904</link>
      <description>&lt;p&gt;kernel: fs: export anon_inode_make_secure_inode() and fix secretmem LSM bypass kernel: cifs: Fix the smbd_response slab to allow usercopy kernel: smb: client: fix use-after-free in cifs_oplock_break kernel: tls: fix handling of zero-length records on the rx_list kernel: s390/sclp: Fix SCCB present check kernel: io_uring/futex: ensure io_futex_wait() cleans up properly on failure&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;kernel: fs: export anon_inode_make_secure_inode() and fix secretmem LSM bypass kernel: cifs: Fix the smbd_response slab to allow usercopy kernel: smb: client: fix use-after-free in cifs_oplock_break kernel: tls: fix handling of zero-length records on the rx_list kernel: s390/sclp: Fix SCCB present check kernel: io_uring/futex: ensure io_futex_wait() cleans up properly on failure&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2025:16904</guid>
    </item>
    <item>
      <title>SUSE-SU-2025:03600-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2025:03600-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2025:03600-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-38527</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-38527</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe, Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:Pro:16.04:LTS: linux-oracle, Ubuntu:Pro:18.04:LTS: linux, Ubuntu:Pro:18.04:LTS: linux-aws, Ubuntu:18.04:LTS: linux-aws-5.0 and 204 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: smb: client: fix use-after-free in cifs_oplock_break A race condition can occur in cifs_oplock_break() leading to a use-after-free of the cinode structure when unmounting:   cifs_oplock_break()     _cifsFileInfo_put(cfile)       cifsFileInfo_put_final()         cifs_sb_deactive()           [last ref, start releasing sb]             kill_sb()               kill_anon_super()                 generic_shutdown_super()                   evict_inodes()                     dispose_list()                       evict()                         destroy_inode()                           call_rcu(&amp;amp;inode-&amp;gt;i_rcu, i_callback)     spin_lock(&amp;amp;cinode-&amp;gt;open_file_lock)  &amp;lt;- OK                             [later] i_callback()                               cifs_free_inode()                                 kmem_cache_free(cinode)     spin_unlock(&amp;amp;cinode-&amp;gt;open_file_lock)  &amp;lt;- UAF     cifs_done_oplock_break(cinode)       &amp;lt;- UAF The issue occurs when umount has already released its reference to the superblock. When _cifsFileInfo_put() calls cifs_sb_deactive(), this releases the last reference, triggering the immediate cleanup of all inodes under RCU. However, cifs_oplock_break() continues to access the cinode after this point, resulting in use-after-free. Fix this by holding an extra reference to the superblock during the entire oplock break operation. This ensures that the superblock and its inodes remain valid until the oplock break co…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe, Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:Pro:16.04:LTS: linux-oracle, Ubuntu:Pro:18.04:LTS: linux, Ubuntu:Pro:18.04:LTS: linux-aws, Ubuntu:18.04:LTS: linux-aws-5.0 and 204 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: smb: client: fix use-after-free in cifs_oplock_break A race condition can occur in cifs_oplock_break() leading to a use-after-free of the cinode structure when unmounting:   cifs_oplock_break()     _cifsFileInfo_put(cfile)       cifsFileInfo_put_final()         cifs_sb_deactive()           [last ref, start releasing sb]             kill_sb()               kill_anon_super()                 generic_shutdown_super()                   evict_inodes()                     dispose_list()                       evict()                         destroy_inode()                           call_rcu(&amp;amp;inode-&amp;gt;i_rcu, i_callback)     spin_lock(&amp;amp;cinode-&amp;gt;open_file_lock)  &amp;lt;- OK                             [later] i_callback()                               cifs_free_inode()                                 kmem_cache_free(cinode)     spin_unlock(&amp;amp;cinode-&amp;gt;open_file_lock)  &amp;lt;- UAF     cifs_done_oplock_break(cinode)       &amp;lt;- UAF The issue occurs when umount has already released its reference to the superblock. When _cifsFileInfo_put() calls cifs_sb_deactive(), this releases the last reference, triggering the immediate cleanup of all inodes under RCU. However, cifs_oplock_break() continues to access the cinode after this point, resulting in use-after-free. Fix this by holding an extra reference to the superblock during the entire oplock break operation. This ensures that the superblock and its inodes remain valid until the oplock break co…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-38527</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-1858 — Linux Kernel: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1858</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen oder andere nicht spezifizierte Angriffe durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen oder andere nicht spezifizierte Angriffe durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1858</guid>
    </item>
  </channel>
</rss>
