<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 19:42:54 +0000</lastBuildDate>
    <item>
      <title>bdu:2025-15789</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-15789</link>
      <description>bdu:2025-15789</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-15789</guid>
    </item>
    <item>
      <title>BELL-CVE-2025-38623</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2025-38623</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2025-38623</guid>
    </item>
    <item>
      <title>certfr-2025-avi-0894 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de Debian LTS. Certaines d'entre elles permettent à…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0894</link>
      <description>certfr-2025-avi-0894</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0894</guid>
    </item>
    <item>
      <title>EUVD-2026-314683</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-314683</link>
      <description>EUVD-2026-314683</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-314683</guid>
    </item>
    <item>
      <title>fkie_cve-2025-38623</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-38623</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;PCI: pnv_php: Fix surprise plug detection and recovery&lt;/p&gt;
&lt;p&gt;The existing PowerNV hotplug code did not handle surprise plug events
correctly, leading to a complete failure of the hotplug system after device
removal and a required reboot to detect new devices.&lt;/p&gt;
&lt;p&gt;This comes down to two issues:&lt;/p&gt;
&lt;p&gt;1) When a device is surprise removed, often the bridge upstream
    port will cause a PE freeze on the PHB.  If this freeze is not
    cleared, the MSI interrupts from the bridge hotplug notification
    logic will not be received by the kernel, stalling all plug events
    on all slots associated with the PE.&lt;/p&gt;
&lt;p&gt;2) When a device is removed from a slot, regardless of surprise or
    programmatic removal, the associated PHB/PE ls left frozen.
    If this freeze is not cleared via a fundamental reset, skiboot
    is unable to clear the freeze and cannot retrain / rescan the
    slot.  This also requires a reboot to clear the freeze and redetect
    the device in the slot.&lt;/p&gt;
&lt;p&gt;Issue the appropriate unfreeze and rescan commands on hotplug events,
and don&amp;#39;t oops on hotplug if pci_bus_to_OF_node() returns NULL.&lt;/p&gt;
&lt;p&gt;[bhelgaas: tidy comments]&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;PCI: pnv_php: Fix surprise plug detection and recovery&lt;/p&gt;
&lt;p&gt;The existing PowerNV hotplug code did not handle surprise plug events
correctly, leading to a complete failure of the hotplug system after device
removal and a required reboot to detect new devices.&lt;/p&gt;
&lt;p&gt;This comes down to two issues:&lt;/p&gt;
&lt;p&gt;1) When a device is surprise removed, often the bridge upstream
    port will cause a PE freeze on the PHB.  If this freeze is not
    cleared, the MSI interrupts from the bridge hotplug notification
    logic will not be received by the kernel, stalling all plug events
    on all slots associated with the PE.&lt;/p&gt;
&lt;p&gt;2) When a device is removed from a slot, regardless of surprise or
    programmatic removal, the associated PHB/PE ls left frozen.
    If this freeze is not cleared via a fundamental reset, skiboot
    is unable to clear the freeze and cannot retrain / rescan the
    slot.  This also requires a reboot to clear the freeze and redetect
    the device in the slot.&lt;/p&gt;
&lt;p&gt;Issue the appropriate unfreeze and rescan commands on hotplug events,
and don&amp;#39;t oops on hotplug if pci_bus_to_OF_node() returns NULL.&lt;/p&gt;
&lt;p&gt;[bhelgaas: tidy comments]&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-38623</guid>
    </item>
    <item>
      <title>GHSA-jm3q-7w4m-jc2w</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-jm3q-7w4m-jc2w</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;PCI: pnv_php: Fix surprise plug detection and recovery&lt;/p&gt;
&lt;p&gt;The existing PowerNV hotplug code did not handle surprise plug events
correctly, leading to a complete failure of the hotplug system after device
removal and a required reboot to detect new devices.&lt;/p&gt;
&lt;p&gt;This comes down to two issues:&lt;/p&gt;
&lt;p&gt;1) When a device is surprise removed, often the bridge upstream
    port will cause a PE freeze on the PHB.  If this freeze is not
    cleared, the MSI interrupts from the bridge hotplug notification
    logic will not be received by the kernel, stalling all plug events
    on all slots associated with the PE.&lt;/p&gt;
&lt;p&gt;2) When a device is removed from a slot, regardless of surprise or
    programmatic removal, the associated PHB/PE ls left frozen.
    If this freeze is not cleared via a fundamental reset, skiboot
    is unable to clear the freeze and cannot retrain / rescan the
    slot.  This also requires a reboot to clear the freeze and redetect
    the device in the slot.&lt;/p&gt;
&lt;p&gt;Issue the appropriate unfreeze and rescan commands on hotplug events,
and don&amp;#39;t oops on hotplug if pci_bus_to_OF_node() returns NULL.&lt;/p&gt;
&lt;p&gt;[bhelgaas: tidy comments]&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;PCI: pnv_php: Fix surprise plug detection and recovery&lt;/p&gt;
&lt;p&gt;The existing PowerNV hotplug code did not handle surprise plug events
correctly, leading to a complete failure of the hotplug system after device
removal and a required reboot to detect new devices.&lt;/p&gt;
&lt;p&gt;This comes down to two issues:&lt;/p&gt;
&lt;p&gt;1) When a device is surprise removed, often the bridge upstream
    port will cause a PE freeze on the PHB.  If this freeze is not
    cleared, the MSI interrupts from the bridge hotplug notification
    logic will not be received by the kernel, stalling all plug events
    on all slots associated with the PE.&lt;/p&gt;
&lt;p&gt;2) When a device is removed from a slot, regardless of surprise or
    programmatic removal, the associated PHB/PE ls left frozen.
    If this freeze is not cleared via a fundamental reset, skiboot
    is unable to clear the freeze and cannot retrain / rescan the
    slot.  This also requires a reboot to clear the freeze and redetect
    the device in the slot.&lt;/p&gt;
&lt;p&gt;Issue the appropriate unfreeze and rescan commands on hotplug events,
and don&amp;#39;t oops on hotplug if pci_bus_to_OF_node() returns NULL.&lt;/p&gt;
&lt;p&gt;[bhelgaas: tidy comments]&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-jm3q-7w4m-jc2w</guid>
    </item>
    <item>
      <title>msrc_CVE-2025-38623 — PCI: pnv_php: Fix surprise plug detection and recovery</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2025-38623</link>
      <description>msrc_CVE-2025-38623</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2025-38623</guid>
    </item>
    <item>
      <title>openSUSE-SU-2025:20081-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2025:20081-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2025:20081-1</guid>
    </item>
    <item>
      <title>SUSE-SU-2025:03600-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2025:03600-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2025:03600-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-38623</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-38623</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux, Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe and 215 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: PCI: pnv_php: Fix surprise plug detection and recovery The existing PowerNV hotplug code did not handle surprise plug events correctly, leading to a complete failure of the hotplug system after device removal and a required reboot to detect new devices. This comes down to two issues:  1) When a device is surprise removed, often the bridge upstream     port will cause a PE freeze on the PHB.  If this freeze is not     cleared, the MSI interrupts from the bridge hotplug notification     logic will not be received by the kernel, stalling all plug events     on all slots associated with the PE.  2) When a device is removed from a slot, regardless of surprise or     programmatic removal, the associated PHB/PE ls left frozen.     If this freeze is not cleared via a fundamental reset, skiboot     is unable to clear the freeze and cannot retrain / rescan the     slot.  This also requires a reboot to clear the freeze and redetect     the device in the slot. Issue the appropriate unfreeze and rescan commands on hotplug events, and don&amp;#39;t oops on hotplug if pci_bus_to_OF_node() returns NULL. [bhelgaas: tidy comments]&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux, Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe and 215 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: PCI: pnv_php: Fix surprise plug detection and recovery The existing PowerNV hotplug code did not handle surprise plug events correctly, leading to a complete failure of the hotplug system after device removal and a required reboot to detect new devices. This comes down to two issues:  1) When a device is surprise removed, often the bridge upstream     port will cause a PE freeze on the PHB.  If this freeze is not     cleared, the MSI interrupts from the bridge hotplug notification     logic will not be received by the kernel, stalling all plug events     on all slots associated with the PE.  2) When a device is removed from a slot, regardless of surprise or     programmatic removal, the associated PHB/PE ls left frozen.     If this freeze is not cleared via a fundamental reset, skiboot     is unable to clear the freeze and cannot retrain / rescan the     slot.  This also requires a reboot to clear the freeze and redetect     the device in the slot. Issue the appropriate unfreeze and rescan commands on hotplug events, and don&amp;#39;t oops on hotplug if pci_bus_to_OF_node() returns NULL. [bhelgaas: tidy comments]&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-38623</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-1898 — Linux Kernel: Mehrere Schwachstellen ermöglichen Denial of Service und Privilegieneskalation</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1898</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux-Kernel ausnutzen, um einen Denial-of-Service-Zustand zu erzeugen, um seine Privilegien zu erhöhen oder andere nicht spezifizierte Angriffe durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux-Kernel ausnutzen, um einen Denial-of-Service-Zustand zu erzeugen, um seine Privilegien zu erhöhen oder andere nicht spezifizierte Angriffe durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1898</guid>
    </item>
  </channel>
</rss>
