<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 04:05:32 +0000</lastBuildDate>
    <item>
      <title>bdu:2025-13447</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-13447</link>
      <description>bdu:2025-13447</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-13447</guid>
    </item>
    <item>
      <title>BELL-CVE-2025-39863</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2025-39863</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2025-39863</guid>
    </item>
    <item>
      <title>certfr-2025-avi-0825 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de Debian. Elles permettent à un attaquant de provo…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0825</link>
      <description>certfr-2025-avi-0825</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0825</guid>
    </item>
    <item>
      <title>EUVD-2026-347232</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-347232</link>
      <description>EUVD-2026-347232</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-347232</guid>
    </item>
    <item>
      <title>fkie_cve-2025-39863</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-39863</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;wifi: brcmfmac: fix use-after-free when rescheduling brcmf_btcoex_info work&lt;/p&gt;
&lt;p&gt;The brcmf_btcoex_detach() only shuts down the btcoex timer, if the
flag timer_on is false. However, the brcmf_btcoex_timerfunc(), which
runs as timer handler, sets timer_on to false. This creates critical
race conditions:&lt;/p&gt;
&lt;p&gt;1.If brcmf_btcoex_detach() is called while brcmf_btcoex_timerfunc()
is executing, it may observe timer_on as false and skip the call to
timer_shutdown_sync().&lt;/p&gt;
&lt;p&gt;2.The brcmf_btcoex_timerfunc() may then reschedule the brcmf_btcoex_info
worker after the cancel_work_sync() has been executed, resulting in
use-after-free bugs.&lt;/p&gt;
&lt;p&gt;The use-after-free bugs occur in two distinct scenarios, depending on
the timing of when the brcmf_btcoex_info struct is freed relative to
the execution of its worker thread.&lt;/p&gt;
&lt;p&gt;Scenario 1: Freed before the worker is scheduled&lt;/p&gt;
&lt;p&gt;The brcmf_btcoex_info is deallocated before the worker is scheduled.
A race condition can occur when schedule_work(&amp;amp;bt_local-&amp;gt;work) is
called after the target memory has been freed. The sequence of events
is detailed below:&lt;/p&gt;
&lt;p&gt;CPU0                           | CPU1
brcmf_btcoex_detach            | brcmf_btcoex_timerfunc
                               |   bt_local-&amp;gt;timer_on = false;
  if (cfg-&amp;gt;btcoex-&amp;gt;timer_on)   |
    ...                        |
  cancel_work_sync();          |
  ...                          |
  kfree(cfg-&amp;gt;btcoex); // FREE  |
                               |…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;wifi: brcmfmac: fix use-after-free when rescheduling brcmf_btcoex_info work&lt;/p&gt;
&lt;p&gt;The brcmf_btcoex_detach() only shuts down the btcoex timer, if the
flag timer_on is false. However, the brcmf_btcoex_timerfunc(), which
runs as timer handler, sets timer_on to false. This creates critical
race conditions:&lt;/p&gt;
&lt;p&gt;1.If brcmf_btcoex_detach() is called while brcmf_btcoex_timerfunc()
is executing, it may observe timer_on as false and skip the call to
timer_shutdown_sync().&lt;/p&gt;
&lt;p&gt;2.The brcmf_btcoex_timerfunc() may then reschedule the brcmf_btcoex_info
worker after the cancel_work_sync() has been executed, resulting in
use-after-free bugs.&lt;/p&gt;
&lt;p&gt;The use-after-free bugs occur in two distinct scenarios, depending on
the timing of when the brcmf_btcoex_info struct is freed relative to
the execution of its worker thread.&lt;/p&gt;
&lt;p&gt;Scenario 1: Freed before the worker is scheduled&lt;/p&gt;
&lt;p&gt;The brcmf_btcoex_info is deallocated before the worker is scheduled.
A race condition can occur when schedule_work(&amp;amp;bt_local-&amp;gt;work) is
called after the target memory has been freed. The sequence of events
is detailed below:&lt;/p&gt;
&lt;p&gt;CPU0                           | CPU1
brcmf_btcoex_detach            | brcmf_btcoex_timerfunc
                               |   bt_local-&amp;gt;timer_on = false;
  if (cfg-&amp;gt;btcoex-&amp;gt;timer_on)   |
    ...                        |
  cancel_work_sync();          |
  ...                          |
  kfree(cfg-&amp;gt;btcoex); // FREE  |
                               |…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-39863</guid>
    </item>
    <item>
      <title>GHSA-c7cr-ch33-3xr3</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-c7cr-ch33-3xr3</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;wifi: brcmfmac: fix use-after-free when rescheduling brcmf_btcoex_info work&lt;/p&gt;
&lt;p&gt;The brcmf_btcoex_detach() only shuts down the btcoex timer, if the
flag timer_on is false. However, the brcmf_btcoex_timerfunc(), which
runs as timer handler, sets timer_on to false. This creates critical
race conditions:&lt;/p&gt;
&lt;p&gt;1.If brcmf_btcoex_detach() is called while brcmf_btcoex_timerfunc()
is executing, it may observe timer_on as false and skip the call to
timer_shutdown_sync().&lt;/p&gt;
&lt;p&gt;2.The brcmf_btcoex_timerfunc() may then reschedule the brcmf_btcoex_info
worker after the cancel_work_sync() has been executed, resulting in
use-after-free bugs.&lt;/p&gt;
&lt;p&gt;The use-after-free bugs occur in two distinct scenarios, depending on
the timing of when the brcmf_btcoex_info struct is freed relative to
the execution of its worker thread.&lt;/p&gt;
&lt;p&gt;Scenario 1: Freed before the worker is scheduled&lt;/p&gt;
&lt;p&gt;The brcmf_btcoex_info is deallocated before the worker is scheduled.
A race condition can occur when schedule_work(&amp;amp;bt_local-&amp;gt;work) is
called after the target memory has been freed. The sequence of events
is detailed below:&lt;/p&gt;
&lt;p&gt;CPU0                           | CPU1
brcmf_btcoex_detach            | brcmf_btcoex_timerfunc
                               |   bt_local-&amp;gt;timer_on = false;
  if (cfg-&amp;gt;btcoex-&amp;gt;timer_on)   |
    ...                        |
  cancel_work_sync();          |
  ...                          |
  kfree(cfg-&amp;gt;btcoex); // FREE  |
                               |…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;wifi: brcmfmac: fix use-after-free when rescheduling brcmf_btcoex_info work&lt;/p&gt;
&lt;p&gt;The brcmf_btcoex_detach() only shuts down the btcoex timer, if the
flag timer_on is false. However, the brcmf_btcoex_timerfunc(), which
runs as timer handler, sets timer_on to false. This creates critical
race conditions:&lt;/p&gt;
&lt;p&gt;1.If brcmf_btcoex_detach() is called while brcmf_btcoex_timerfunc()
is executing, it may observe timer_on as false and skip the call to
timer_shutdown_sync().&lt;/p&gt;
&lt;p&gt;2.The brcmf_btcoex_timerfunc() may then reschedule the brcmf_btcoex_info
worker after the cancel_work_sync() has been executed, resulting in
use-after-free bugs.&lt;/p&gt;
&lt;p&gt;The use-after-free bugs occur in two distinct scenarios, depending on
the timing of when the brcmf_btcoex_info struct is freed relative to
the execution of its worker thread.&lt;/p&gt;
&lt;p&gt;Scenario 1: Freed before the worker is scheduled&lt;/p&gt;
&lt;p&gt;The brcmf_btcoex_info is deallocated before the worker is scheduled.
A race condition can occur when schedule_work(&amp;amp;bt_local-&amp;gt;work) is
called after the target memory has been freed. The sequence of events
is detailed below:&lt;/p&gt;
&lt;p&gt;CPU0                           | CPU1
brcmf_btcoex_detach            | brcmf_btcoex_timerfunc
                               |   bt_local-&amp;gt;timer_on = false;
  if (cfg-&amp;gt;btcoex-&amp;gt;timer_on)   |
    ...                        |
  cancel_work_sync();          |
  ...                          |
  kfree(cfg-&amp;gt;btcoex); // FREE  |
                               |…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-c7cr-ch33-3xr3</guid>
    </item>
    <item>
      <title>msrc_CVE-2025-39863 — wifi: brcmfmac: fix use-after-free when rescheduling brcmf_btcoex_info work</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2025-39863</link>
      <description>msrc_CVE-2025-39863</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2025-39863</guid>
    </item>
    <item>
      <title>OESA-2025-2695 — kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2025-2695</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP1: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;misc: pci_endpoint_test: Avoid issue of interrupts remaining after request_irq error&lt;/p&gt;
&lt;p&gt;After devm_request_irq() fails with error in pci_endpoint_test_request_irq(),
the pci_endpoint_test_free_irq_vectors() is called assuming that all IRQs
have been released.&lt;/p&gt;
&lt;p&gt;However, some requested IRQs remain unreleased, so there are still
/proc/irq/* entries remaining, and this results in WARN() with the
following message:&lt;/p&gt;
&lt;p&gt;remove_proc_entry: removing non-empty directory &amp;amp;apos;irq/30&amp;amp;apos;, leaking at least &amp;amp;apos;pci-endpoint-test.0&amp;amp;apos;
  WARNING: CPU: 0 PID: 202 at fs/proc/generic.c:719 remove_proc_entry +0x190/0x19c&lt;/p&gt;
&lt;p&gt;To solve this issue, set the number of remaining IRQs to test-&amp;amp;gt;num_irqs,
and release IRQs in advance by calling pci_endpoint_test_release_irq().&lt;/p&gt;
&lt;p&gt;[kwilczynski: commit log](CVE-2025-23140)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;drm/amdgpu: csa unmap use uninterruptible lock&lt;/p&gt;
&lt;p&gt;After process exit to unmap csa and free GPU vm, if signal is accepted
and then waiting to take vm lock is interrupted and return, it causes
memory leaking and below warning backtrace.&lt;/p&gt;
&lt;p&gt;Change to use uninterruptible wait lock fix the issue.&lt;/p&gt;
&lt;p&gt;WARNING: CPU: 69 PID: 167800 at amd/amdgpu/amdgpu_kms.c:1525
 amdgpu_driver_postclose_kms+0x294/0x2a0 [amdgpu]
 Call Trace:
  &amp;amp;lt;TASK&amp;amp;gt;
  drm_file_free.part.0+0x1da/0x230 [drm]
  drm_clo…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP1: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;misc: pci_endpoint_test: Avoid issue of interrupts remaining after request_irq error&lt;/p&gt;
&lt;p&gt;After devm_request_irq() fails with error in pci_endpoint_test_request_irq(),
the pci_endpoint_test_free_irq_vectors() is called assuming that all IRQs
have been released.&lt;/p&gt;
&lt;p&gt;However, some requested IRQs remain unreleased, so there are still
/proc/irq/* entries remaining, and this results in WARN() with the
following message:&lt;/p&gt;
&lt;p&gt;remove_proc_entry: removing non-empty directory &amp;amp;apos;irq/30&amp;amp;apos;, leaking at least &amp;amp;apos;pci-endpoint-test.0&amp;amp;apos;
  WARNING: CPU: 0 PID: 202 at fs/proc/generic.c:719 remove_proc_entry +0x190/0x19c&lt;/p&gt;
&lt;p&gt;To solve this issue, set the number of remaining IRQs to test-&amp;amp;gt;num_irqs,
and release IRQs in advance by calling pci_endpoint_test_release_irq().&lt;/p&gt;
&lt;p&gt;[kwilczynski: commit log](CVE-2025-23140)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;drm/amdgpu: csa unmap use uninterruptible lock&lt;/p&gt;
&lt;p&gt;After process exit to unmap csa and free GPU vm, if signal is accepted
and then waiting to take vm lock is interrupted and return, it causes
memory leaking and below warning backtrace.&lt;/p&gt;
&lt;p&gt;Change to use uninterruptible wait lock fix the issue.&lt;/p&gt;
&lt;p&gt;WARNING: CPU: 69 PID: 167800 at amd/amdgpu/amdgpu_kms.c:1525
 amdgpu_driver_postclose_kms+0x294/0x2a0 [amdgpu]
 Call Trace:
  &amp;amp;lt;TASK&amp;amp;gt;
  drm_file_free.part.0+0x1da/0x230 [drm]
  drm_clo…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2025-2695</guid>
    </item>
    <item>
      <title>openSUSE-SU-2025:20081-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2025:20081-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2025:20081-1</guid>
    </item>
    <item>
      <title>SUSE-SU-2025:03600-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2025:03600-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2025:03600-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-39863</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-39863</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux, Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe and 216 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: wifi: brcmfmac: fix use-after-free when rescheduling brcmf_btcoex_info work The brcmf_btcoex_detach() only shuts down the btcoex timer, if the flag timer_on is false. However, the brcmf_btcoex_timerfunc(), which runs as timer handler, sets timer_on to false. This creates critical race conditions: 1.If brcmf_btcoex_detach() is called while brcmf_btcoex_timerfunc() is executing, it may observe timer_on as false and skip the call to timer_shutdown_sync(). 2.The brcmf_btcoex_timerfunc() may then reschedule the brcmf_btcoex_info worker after the cancel_work_sync() has been executed, resulting in use-after-free bugs. The use-after-free bugs occur in two distinct scenarios, depending on the timing of when the brcmf_btcoex_info struct is freed relative to the execution of its worker thread. Scenario 1: Freed before the worker is scheduled The brcmf_btcoex_info is deallocated before the worker is scheduled. A race condition can occur when schedule_work(&amp;amp;bt_local-&amp;gt;work) is called after the target memory has been freed. The sequence of events is detailed below: CPU0                           | CPU1 brcmf_btcoex_detach            | brcmf_btcoex_timerfunc                                |   bt_local-&amp;gt;timer_on = false;   if (cfg-&amp;gt;btcoex-&amp;gt;timer_on)   |     ...                        |   cancel_work_sync();          |   ...                          |   kfree(cfg-&amp;gt;btcoex); // FREE  |                                |   schedul…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux, Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe and 216 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: wifi: brcmfmac: fix use-after-free when rescheduling brcmf_btcoex_info work The brcmf_btcoex_detach() only shuts down the btcoex timer, if the flag timer_on is false. However, the brcmf_btcoex_timerfunc(), which runs as timer handler, sets timer_on to false. This creates critical race conditions: 1.If brcmf_btcoex_detach() is called while brcmf_btcoex_timerfunc() is executing, it may observe timer_on as false and skip the call to timer_shutdown_sync(). 2.The brcmf_btcoex_timerfunc() may then reschedule the brcmf_btcoex_info worker after the cancel_work_sync() has been executed, resulting in use-after-free bugs. The use-after-free bugs occur in two distinct scenarios, depending on the timing of when the brcmf_btcoex_info struct is freed relative to the execution of its worker thread. Scenario 1: Freed before the worker is scheduled The brcmf_btcoex_info is deallocated before the worker is scheduled. A race condition can occur when schedule_work(&amp;amp;bt_local-&amp;gt;work) is called after the target memory has been freed. The sequence of events is detailed below: CPU0                           | CPU1 brcmf_btcoex_detach            | brcmf_btcoex_timerfunc                                |   bt_local-&amp;gt;timer_on = false;   if (cfg-&amp;gt;btcoex-&amp;gt;timer_on)   |     ...                        |   cancel_work_sync();          |   ...                          |   kfree(cfg-&amp;gt;btcoex); // FREE  |                                |   schedul…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-39863</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-2099 — Linux Kernel: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2099</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen oder nicht näher beschriebene Auswirkungen zu erzielen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen oder nicht näher beschriebene Auswirkungen zu erzielen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2099</guid>
    </item>
  </channel>
</rss>
