<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 06:22:09 +0000</lastBuildDate>
    <item>
      <title>bdu:2025-15781</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-15781</link>
      <description>bdu:2025-15781</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-15781</guid>
    </item>
    <item>
      <title>BELL-CVE-2025-38635</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2025-38635</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2025-38635</guid>
    </item>
    <item>
      <title>certfr-2025-avi-0787 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de SUSE. Certaines d'entre elles permettent à un at…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0787</link>
      <description>certfr-2025-avi-0787</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0787</guid>
    </item>
    <item>
      <title>EUVD-2026-314692</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-314692</link>
      <description>EUVD-2026-314692</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-314692</guid>
    </item>
    <item>
      <title>fkie_cve-2025-38635</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-38635</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;clk: davinci: Add NULL check in davinci_lpsc_clk_register()&lt;/p&gt;
&lt;p&gt;devm_kasprintf() returns NULL when memory allocation fails. Currently,
davinci_lpsc_clk_register() does not check for this case, which results
in a NULL pointer dereference.&lt;/p&gt;
&lt;p&gt;Add NULL check after devm_kasprintf() to prevent this issue and ensuring
no resources are left allocated.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;clk: davinci: Add NULL check in davinci_lpsc_clk_register()&lt;/p&gt;
&lt;p&gt;devm_kasprintf() returns NULL when memory allocation fails. Currently,
davinci_lpsc_clk_register() does not check for this case, which results
in a NULL pointer dereference.&lt;/p&gt;
&lt;p&gt;Add NULL check after devm_kasprintf() to prevent this issue and ensuring
no resources are left allocated.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-38635</guid>
    </item>
    <item>
      <title>GHSA-r59m-grjg-3vpv</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-r59m-grjg-3vpv</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;clk: davinci: Add NULL check in davinci_lpsc_clk_register()&lt;/p&gt;
&lt;p&gt;devm_kasprintf() returns NULL when memory allocation fails. Currently,
davinci_lpsc_clk_register() does not check for this case, which results
in a NULL pointer dereference.&lt;/p&gt;
&lt;p&gt;Add NULL check after devm_kasprintf() to prevent this issue and ensuring
no resources are left allocated.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;clk: davinci: Add NULL check in davinci_lpsc_clk_register()&lt;/p&gt;
&lt;p&gt;devm_kasprintf() returns NULL when memory allocation fails. Currently,
davinci_lpsc_clk_register() does not check for this case, which results
in a NULL pointer dereference.&lt;/p&gt;
&lt;p&gt;Add NULL check after devm_kasprintf() to prevent this issue and ensuring
no resources are left allocated.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-r59m-grjg-3vpv</guid>
    </item>
    <item>
      <title>msrc_CVE-2025-38635 — clk: davinci: Add NULL check in davinci_lpsc_clk_register()</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2025-38635</link>
      <description>msrc_CVE-2025-38635</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2025-38635</guid>
    </item>
    <item>
      <title>OESA-2025-2268 — kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2025-2268</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;rapidio: fix an API misues when rio_add_net() fails&lt;/p&gt;
&lt;p&gt;rio_add_net() calls device_register() and fails when device_register()
fails.  Thus, put_device() should be used rather than kfree().  Add
&amp;amp;quot;mport-&amp;amp;gt;net = NULL;&amp;amp;quot; to avoid a use after free issue.(CVE-2025-21934)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;cifs: Fix integer overflow while processing closetimeo mount option&lt;/p&gt;
&lt;p&gt;User-provided mount parameter closetimeo of type u32 is intended to have
an upper limit, but before it is validated, the value is converted from
seconds to jiffies which can lead to an integer overflow.&lt;/p&gt;
&lt;p&gt;Found by Linux Verification Center (linuxtesting.org) with SVACE.(CVE-2025-21962)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;ksmbd: fix use-after-free in ksmbd_free_work_struct&lt;/p&gt;
&lt;p&gt;-&amp;amp;gt;interim_entry of ksmbd_work could be deleted after oplock is freed.
We don&amp;amp;apos;t need to manage it with linked list. The interim request could be
immediately sent whenever a oplock break wait is needed.(CVE-2025-21967)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;ksmbd: fix use-after-free in kerberos authentication&lt;/p&gt;
&lt;p&gt;Setting sess-&amp;amp;gt;user = NULL was introduced to fix the dangling pointer
created by ksmbd_free_user. However, it is possible another thread could
be operating on the session and make us…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;rapidio: fix an API misues when rio_add_net() fails&lt;/p&gt;
&lt;p&gt;rio_add_net() calls device_register() and fails when device_register()
fails.  Thus, put_device() should be used rather than kfree().  Add
&amp;amp;quot;mport-&amp;amp;gt;net = NULL;&amp;amp;quot; to avoid a use after free issue.(CVE-2025-21934)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;cifs: Fix integer overflow while processing closetimeo mount option&lt;/p&gt;
&lt;p&gt;User-provided mount parameter closetimeo of type u32 is intended to have
an upper limit, but before it is validated, the value is converted from
seconds to jiffies which can lead to an integer overflow.&lt;/p&gt;
&lt;p&gt;Found by Linux Verification Center (linuxtesting.org) with SVACE.(CVE-2025-21962)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;ksmbd: fix use-after-free in ksmbd_free_work_struct&lt;/p&gt;
&lt;p&gt;-&amp;amp;gt;interim_entry of ksmbd_work could be deleted after oplock is freed.
We don&amp;amp;apos;t need to manage it with linked list. The interim request could be
immediately sent whenever a oplock break wait is needed.(CVE-2025-21967)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;ksmbd: fix use-after-free in kerberos authentication&lt;/p&gt;
&lt;p&gt;Setting sess-&amp;amp;gt;user = NULL was introduced to fix the dangling pointer
created by ksmbd_free_user. However, it is possible another thread could
be operating on the session and make us…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2025-2268</guid>
    </item>
    <item>
      <title>openSUSE-SU-2025:20081-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2025:20081-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2025:20081-1</guid>
    </item>
    <item>
      <title>SUSE-SU-2025:03272-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2025:03272-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2025:03272-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-38635</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-38635</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:Pro:18.04:LTS: linux-aws-5.4, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:Pro:18.04:LTS: linux-azure-5.4, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3 and 187 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: clk: davinci: Add NULL check in davinci_lpsc_clk_register() devm_kasprintf() returns NULL when memory allocation fails. Currently, davinci_lpsc_clk_register() does not check for this case, which results in a NULL pointer dereference. Add NULL check after devm_kasprintf() to prevent this issue and ensuring no resources are left allocated.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:Pro:18.04:LTS: linux-aws-5.4, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:Pro:18.04:LTS: linux-azure-5.4, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3 and 187 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: clk: davinci: Add NULL check in davinci_lpsc_clk_register() devm_kasprintf() returns NULL when memory allocation fails. Currently, davinci_lpsc_clk_register() does not check for this case, which results in a NULL pointer dereference. Add NULL check after devm_kasprintf() to prevent this issue and ensuring no resources are left allocated.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-38635</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-1898 — Linux Kernel: Mehrere Schwachstellen ermöglichen Denial of Service und Privilegieneskalation</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1898</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux-Kernel ausnutzen, um einen Denial-of-Service-Zustand zu erzeugen, um seine Privilegien zu erhöhen oder andere nicht spezifizierte Angriffe durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux-Kernel ausnutzen, um einen Denial-of-Service-Zustand zu erzeugen, um seine Privilegien zu erhöhen oder andere nicht spezifizierte Angriffe durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1898</guid>
    </item>
  </channel>
</rss>
