<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 11:16:53 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-02846</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-02846</link>
      <description>bdu:2026-02846</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-02846</guid>
    </item>
    <item>
      <title>BELL-CVE-2025-38590</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2025-38590</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2025-38590</guid>
    </item>
    <item>
      <title>certfr-2025-avi-0895 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de SUSE. Certaines d'entre elles permettent à un at…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0895</link>
      <description>certfr-2025-avi-0895</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0895</guid>
    </item>
    <item>
      <title>EUVD-2026-347113</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-347113</link>
      <description>EUVD-2026-347113</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-347113</guid>
    </item>
    <item>
      <title>fkie_cve-2025-38590</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-38590</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;net/mlx5e: Remove skb secpath if xfrm state is not found&lt;/p&gt;
&lt;p&gt;Hardware returns a unique identifier for a decrypted packet&amp;#39;s xfrm
state, this state is looked up in an xarray. However, the state might
have been freed by the time of this lookup.&lt;/p&gt;
&lt;p&gt;Currently, if the state is not found, only a counter is incremented.
The secpath (sp) extension on the skb is not removed, resulting in
sp-&amp;gt;len becoming 0.&lt;/p&gt;
&lt;p&gt;Subsequently, functions like __xfrm_policy_check() attempt to access
fields such as xfrm_input_state(skb)-&amp;gt;xso.type (which dereferences
sp-&amp;gt;xvec[sp-&amp;gt;len - 1]) without first validating sp-&amp;gt;len. This leads to
a crash when dereferencing an invalid state pointer.&lt;/p&gt;
&lt;p&gt;This patch prevents the crash by explicitly removing the secpath
extension from the skb if the xfrm state is not found after hardware
decryption. This ensures downstream functions do not operate on a
zero-length secpath.&lt;/p&gt;
&lt;p&gt;BUG: unable to handle page fault for address: ffffffff000002c8
 #PF: supervisor read access in kernel mode
 #PF: error_code(0x0000) - not-present page
 PGD 282e067 P4D 282e067 PUD 0
 Oops: Oops: 0000 [#1] SMP
 CPU: 12 UID: 0 PID: 0 Comm: swapper/12 Not tainted 6.15.0-rc7_for_upstream_min_debug_2025_05_27_22_44 #1 NONE
 Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.13.0-0-gf21b5a4aeb02-prebuilt.qemu.org 04/01/2014
 RIP: 0010:__xfrm_policy_check+0x61a/0xa30
 Code: b6 77 7f 83 e6 02 74 14 4d 8b af d8 00 00 00 41 0f b6 45 05 c1 e0…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;net/mlx5e: Remove skb secpath if xfrm state is not found&lt;/p&gt;
&lt;p&gt;Hardware returns a unique identifier for a decrypted packet&amp;#39;s xfrm
state, this state is looked up in an xarray. However, the state might
have been freed by the time of this lookup.&lt;/p&gt;
&lt;p&gt;Currently, if the state is not found, only a counter is incremented.
The secpath (sp) extension on the skb is not removed, resulting in
sp-&amp;gt;len becoming 0.&lt;/p&gt;
&lt;p&gt;Subsequently, functions like __xfrm_policy_check() attempt to access
fields such as xfrm_input_state(skb)-&amp;gt;xso.type (which dereferences
sp-&amp;gt;xvec[sp-&amp;gt;len - 1]) without first validating sp-&amp;gt;len. This leads to
a crash when dereferencing an invalid state pointer.&lt;/p&gt;
&lt;p&gt;This patch prevents the crash by explicitly removing the secpath
extension from the skb if the xfrm state is not found after hardware
decryption. This ensures downstream functions do not operate on a
zero-length secpath.&lt;/p&gt;
&lt;p&gt;BUG: unable to handle page fault for address: ffffffff000002c8
 #PF: supervisor read access in kernel mode
 #PF: error_code(0x0000) - not-present page
 PGD 282e067 P4D 282e067 PUD 0
 Oops: Oops: 0000 [#1] SMP
 CPU: 12 UID: 0 PID: 0 Comm: swapper/12 Not tainted 6.15.0-rc7_for_upstream_min_debug_2025_05_27_22_44 #1 NONE
 Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.13.0-0-gf21b5a4aeb02-prebuilt.qemu.org 04/01/2014
 RIP: 0010:__xfrm_policy_check+0x61a/0xa30
 Code: b6 77 7f 83 e6 02 74 14 4d 8b af d8 00 00 00 41 0f b6 45 05 c1 e0…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-38590</guid>
    </item>
    <item>
      <title>GHSA-wgrh-wq84-j2xm</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-wgrh-wq84-j2xm</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;net/mlx5e: Remove skb secpath if xfrm state is not found&lt;/p&gt;
&lt;p&gt;Hardware returns a unique identifier for a decrypted packet&amp;#39;s xfrm
state, this state is looked up in an xarray. However, the state might
have been freed by the time of this lookup.&lt;/p&gt;
&lt;p&gt;Currently, if the state is not found, only a counter is incremented.
The secpath (sp) extension on the skb is not removed, resulting in
sp-&amp;gt;len becoming 0.&lt;/p&gt;
&lt;p&gt;Subsequently, functions like __xfrm_policy_check() attempt to access
fields such as xfrm_input_state(skb)-&amp;gt;xso.type (which dereferences
sp-&amp;gt;xvec[sp-&amp;gt;len - 1]) without first validating sp-&amp;gt;len. This leads to
a crash when dereferencing an invalid state pointer.&lt;/p&gt;
&lt;p&gt;This patch prevents the crash by explicitly removing the secpath
extension from the skb if the xfrm state is not found after hardware
decryption. This ensures downstream functions do not operate on a
zero-length secpath.&lt;/p&gt;
&lt;p&gt;BUG: unable to handle page fault for address: ffffffff000002c8
 #PF: supervisor read access in kernel mode
 #PF: error_code(0x0000) - not-present page
 PGD 282e067 P4D 282e067 PUD 0
 Oops: Oops: 0000 [#1] SMP
 CPU: 12 UID: 0 PID: 0 Comm: swapper/12 Not tainted 6.15.0-rc7_for_upstream_min_debug_2025_05_27_22_44 #1 NONE
 Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.13.0-0-gf21b5a4aeb02-prebuilt.qemu.org 04/01/2014
 RIP: 0010:__xfrm_policy_check+0x61a/0xa30
 Code: b6 77 7f 83 e6 02 74 14 4d 8b af d8 00 00 00 41 0f b6 45 05 c1 e0…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;net/mlx5e: Remove skb secpath if xfrm state is not found&lt;/p&gt;
&lt;p&gt;Hardware returns a unique identifier for a decrypted packet&amp;#39;s xfrm
state, this state is looked up in an xarray. However, the state might
have been freed by the time of this lookup.&lt;/p&gt;
&lt;p&gt;Currently, if the state is not found, only a counter is incremented.
The secpath (sp) extension on the skb is not removed, resulting in
sp-&amp;gt;len becoming 0.&lt;/p&gt;
&lt;p&gt;Subsequently, functions like __xfrm_policy_check() attempt to access
fields such as xfrm_input_state(skb)-&amp;gt;xso.type (which dereferences
sp-&amp;gt;xvec[sp-&amp;gt;len - 1]) without first validating sp-&amp;gt;len. This leads to
a crash when dereferencing an invalid state pointer.&lt;/p&gt;
&lt;p&gt;This patch prevents the crash by explicitly removing the secpath
extension from the skb if the xfrm state is not found after hardware
decryption. This ensures downstream functions do not operate on a
zero-length secpath.&lt;/p&gt;
&lt;p&gt;BUG: unable to handle page fault for address: ffffffff000002c8
 #PF: supervisor read access in kernel mode
 #PF: error_code(0x0000) - not-present page
 PGD 282e067 P4D 282e067 PUD 0
 Oops: Oops: 0000 [#1] SMP
 CPU: 12 UID: 0 PID: 0 Comm: swapper/12 Not tainted 6.15.0-rc7_for_upstream_min_debug_2025_05_27_22_44 #1 NONE
 Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.13.0-0-gf21b5a4aeb02-prebuilt.qemu.org 04/01/2014
 RIP: 0010:__xfrm_policy_check+0x61a/0xa30
 Code: b6 77 7f 83 e6 02 74 14 4d 8b af d8 00 00 00 41 0f b6 45 05 c1 e0…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-wgrh-wq84-j2xm</guid>
    </item>
    <item>
      <title>msrc_CVE-2025-38590 — net/mlx5e: Remove skb secpath if xfrm state is not found</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2025-38590</link>
      <description>msrc_CVE-2025-38590</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2025-38590</guid>
    </item>
    <item>
      <title>OESA-2025-2268 — kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2025-2268</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;rapidio: fix an API misues when rio_add_net() fails&lt;/p&gt;
&lt;p&gt;rio_add_net() calls device_register() and fails when device_register()
fails.  Thus, put_device() should be used rather than kfree().  Add
&amp;amp;quot;mport-&amp;amp;gt;net = NULL;&amp;amp;quot; to avoid a use after free issue.(CVE-2025-21934)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;cifs: Fix integer overflow while processing closetimeo mount option&lt;/p&gt;
&lt;p&gt;User-provided mount parameter closetimeo of type u32 is intended to have
an upper limit, but before it is validated, the value is converted from
seconds to jiffies which can lead to an integer overflow.&lt;/p&gt;
&lt;p&gt;Found by Linux Verification Center (linuxtesting.org) with SVACE.(CVE-2025-21962)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;ksmbd: fix use-after-free in ksmbd_free_work_struct&lt;/p&gt;
&lt;p&gt;-&amp;amp;gt;interim_entry of ksmbd_work could be deleted after oplock is freed.
We don&amp;amp;apos;t need to manage it with linked list. The interim request could be
immediately sent whenever a oplock break wait is needed.(CVE-2025-21967)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;ksmbd: fix use-after-free in kerberos authentication&lt;/p&gt;
&lt;p&gt;Setting sess-&amp;amp;gt;user = NULL was introduced to fix the dangling pointer
created by ksmbd_free_user. However, it is possible another thread could
be operating on the session and make us…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;rapidio: fix an API misues when rio_add_net() fails&lt;/p&gt;
&lt;p&gt;rio_add_net() calls device_register() and fails when device_register()
fails.  Thus, put_device() should be used rather than kfree().  Add
&amp;amp;quot;mport-&amp;amp;gt;net = NULL;&amp;amp;quot; to avoid a use after free issue.(CVE-2025-21934)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;cifs: Fix integer overflow while processing closetimeo mount option&lt;/p&gt;
&lt;p&gt;User-provided mount parameter closetimeo of type u32 is intended to have
an upper limit, but before it is validated, the value is converted from
seconds to jiffies which can lead to an integer overflow.&lt;/p&gt;
&lt;p&gt;Found by Linux Verification Center (linuxtesting.org) with SVACE.(CVE-2025-21962)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;ksmbd: fix use-after-free in ksmbd_free_work_struct&lt;/p&gt;
&lt;p&gt;-&amp;amp;gt;interim_entry of ksmbd_work could be deleted after oplock is freed.
We don&amp;amp;apos;t need to manage it with linked list. The interim request could be
immediately sent whenever a oplock break wait is needed.(CVE-2025-21967)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;ksmbd: fix use-after-free in kerberos authentication&lt;/p&gt;
&lt;p&gt;Setting sess-&amp;amp;gt;user = NULL was introduced to fix the dangling pointer
created by ksmbd_free_user. However, it is possible another thread could
be operating on the session and make us…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2025-2268</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:20287-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:20287-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:20287-1</guid>
    </item>
    <item>
      <title>SUSE-SU-2025:03600-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2025:03600-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2025:03600-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-38590</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-38590</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 162 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: Remove skb secpath if xfrm state is not found Hardware returns a unique identifier for a decrypted packet&amp;#39;s xfrm state, this state is looked up in an xarray. However, the state might have been freed by the time of this lookup. Currently, if the state is not found, only a counter is incremented. The secpath (sp) extension on the skb is not removed, resulting in sp-&amp;gt;len becoming 0. Subsequently, functions like __xfrm_policy_check() attempt to access fields such as xfrm_input_state(skb)-&amp;gt;xso.type (which dereferences sp-&amp;gt;xvec[sp-&amp;gt;len - 1]) without first validating sp-&amp;gt;len. This leads to a crash when dereferencing an invalid state pointer. This patch prevents the crash by explicitly removing the secpath extension from the skb if the xfrm state is not found after hardware decryption. This ensures downstream functions do not operate on a zero-length secpath.  BUG: unable to handle page fault for address: ffffffff000002c8  #PF: supervisor read access in kernel mode  #PF: error_code(0x0000) - not-present page  PGD 282e067 P4D 282e067 PUD 0  Oops: Oops: 0000 [#1] SMP  CPU: 12 UID: 0 PID: 0 Comm: swapper/12 Not tainted 6.15.0-rc7_for_upstream_min_debug_2025_05_27_22_44 #1 NONE  Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.13.0-0-gf21b5a4aeb02-prebuilt.qemu.org 04/01/2014  RIP: 0010:__xfrm_policy_check+0x61a/0xa30  Code: b6 77 7f 83 e6 02 74 14 4d 8b af d8 00 00 00 41 0f b6 45 05 c1 e0 03 48…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 162 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: Remove skb secpath if xfrm state is not found Hardware returns a unique identifier for a decrypted packet&amp;#39;s xfrm state, this state is looked up in an xarray. However, the state might have been freed by the time of this lookup. Currently, if the state is not found, only a counter is incremented. The secpath (sp) extension on the skb is not removed, resulting in sp-&amp;gt;len becoming 0. Subsequently, functions like __xfrm_policy_check() attempt to access fields such as xfrm_input_state(skb)-&amp;gt;xso.type (which dereferences sp-&amp;gt;xvec[sp-&amp;gt;len - 1]) without first validating sp-&amp;gt;len. This leads to a crash when dereferencing an invalid state pointer. This patch prevents the crash by explicitly removing the secpath extension from the skb if the xfrm state is not found after hardware decryption. This ensures downstream functions do not operate on a zero-length secpath.  BUG: unable to handle page fault for address: ffffffff000002c8  #PF: supervisor read access in kernel mode  #PF: error_code(0x0000) - not-present page  PGD 282e067 P4D 282e067 PUD 0  Oops: Oops: 0000 [#1] SMP  CPU: 12 UID: 0 PID: 0 Comm: swapper/12 Not tainted 6.15.0-rc7_for_upstream_min_debug_2025_05_27_22_44 #1 NONE  Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.13.0-0-gf21b5a4aeb02-prebuilt.qemu.org 04/01/2014  RIP: 0010:__xfrm_policy_check+0x61a/0xa30  Code: b6 77 7f 83 e6 02 74 14 4d 8b af d8 00 00 00 41 0f b6 45 05 c1 e0 03 48…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-38590</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-1869 — Linux Kernel: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1869</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux-Kernel ausnutzen, um einen Denial-of-Service-Zustand zu erzeugen oder andere nicht spezifizierte Angriffe durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux-Kernel ausnutzen, um einen Denial-of-Service-Zustand zu erzeugen oder andere nicht spezifizierte Angriffe durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1869</guid>
    </item>
  </channel>
</rss>
