<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 03:36:06 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-02676</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-02676</link>
      <description>bdu:2026-02676</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-02676</guid>
    </item>
    <item>
      <title>BELL-CVE-2025-39917</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2025-39917</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2025-39917</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0059 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de SUSE. Certaines d'entre elles permettent à un at…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0059</link>
      <description>certfr-2026-avi-0059</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0059</guid>
    </item>
    <item>
      <title>EUVD-2026-314827</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-314827</link>
      <description>EUVD-2026-314827</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-314827</guid>
    </item>
    <item>
      <title>fkie_cve-2025-39917</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-39917</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;bpf: Fix out-of-bounds dynptr write in bpf_crypto_crypt&lt;/p&gt;
&lt;p&gt;Stanislav reported that in bpf_crypto_crypt() the destination dynptr&amp;#39;s
size is not validated to be at least as large as the source dynptr&amp;#39;s
size before calling into the crypto backend with &amp;#39;len = src_len&amp;#39;. This
can result in an OOB write when the destination is smaller than the
source.&lt;/p&gt;
&lt;p&gt;Concretely, in mentioned function, psrc and pdst are both linear
buffers fetched from each dynptr:&lt;/p&gt;
&lt;p&gt;psrc = __bpf_dynptr_data(src, src_len);
  [...]
  pdst = __bpf_dynptr_data_rw(dst, dst_len);
  [...]
  err = decrypt ?
        ctx-&amp;gt;type-&amp;gt;decrypt(ctx-&amp;gt;tfm, psrc, pdst, src_len, piv) :
        ctx-&amp;gt;type-&amp;gt;encrypt(ctx-&amp;gt;tfm, psrc, pdst, src_len, piv);&lt;/p&gt;
&lt;p&gt;The crypto backend expects pdst to be large enough with a src_len length
that can be written. Add an additional src_len &amp;gt; dst_len check and bail
out if it&amp;#39;s the case. Note that these kfuncs are accessible under root
privileges only.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;bpf: Fix out-of-bounds dynptr write in bpf_crypto_crypt&lt;/p&gt;
&lt;p&gt;Stanislav reported that in bpf_crypto_crypt() the destination dynptr&amp;#39;s
size is not validated to be at least as large as the source dynptr&amp;#39;s
size before calling into the crypto backend with &amp;#39;len = src_len&amp;#39;. This
can result in an OOB write when the destination is smaller than the
source.&lt;/p&gt;
&lt;p&gt;Concretely, in mentioned function, psrc and pdst are both linear
buffers fetched from each dynptr:&lt;/p&gt;
&lt;p&gt;psrc = __bpf_dynptr_data(src, src_len);
  [...]
  pdst = __bpf_dynptr_data_rw(dst, dst_len);
  [...]
  err = decrypt ?
        ctx-&amp;gt;type-&amp;gt;decrypt(ctx-&amp;gt;tfm, psrc, pdst, src_len, piv) :
        ctx-&amp;gt;type-&amp;gt;encrypt(ctx-&amp;gt;tfm, psrc, pdst, src_len, piv);&lt;/p&gt;
&lt;p&gt;The crypto backend expects pdst to be large enough with a src_len length
that can be written. Add an additional src_len &amp;gt; dst_len check and bail
out if it&amp;#39;s the case. Note that these kfuncs are accessible under root
privileges only.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-39917</guid>
    </item>
    <item>
      <title>GHSA-8xqx-42cr-fv84</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-8xqx-42cr-fv84</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;bpf: Fix out-of-bounds dynptr write in bpf_crypto_crypt&lt;/p&gt;
&lt;p&gt;Stanislav reported that in bpf_crypto_crypt() the destination dynptr&amp;#39;s
size is not validated to be at least as large as the source dynptr&amp;#39;s
size before calling into the crypto backend with &amp;#39;len = src_len&amp;#39;. This
can result in an OOB write when the destination is smaller than the
source.&lt;/p&gt;
&lt;p&gt;Concretely, in mentioned function, psrc and pdst are both linear
buffers fetched from each dynptr:&lt;/p&gt;
&lt;p&gt;psrc = __bpf_dynptr_data(src, src_len);
  [...]
  pdst = __bpf_dynptr_data_rw(dst, dst_len);
  [...]
  err = decrypt ?
        ctx-&amp;gt;type-&amp;gt;decrypt(ctx-&amp;gt;tfm, psrc, pdst, src_len, piv) :
        ctx-&amp;gt;type-&amp;gt;encrypt(ctx-&amp;gt;tfm, psrc, pdst, src_len, piv);&lt;/p&gt;
&lt;p&gt;The crypto backend expects pdst to be large enough with a src_len length
that can be written. Add an additional src_len &amp;gt; dst_len check and bail
out if it&amp;#39;s the case. Note that these kfuncs are accessible under root
privileges only.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;bpf: Fix out-of-bounds dynptr write in bpf_crypto_crypt&lt;/p&gt;
&lt;p&gt;Stanislav reported that in bpf_crypto_crypt() the destination dynptr&amp;#39;s
size is not validated to be at least as large as the source dynptr&amp;#39;s
size before calling into the crypto backend with &amp;#39;len = src_len&amp;#39;. This
can result in an OOB write when the destination is smaller than the
source.&lt;/p&gt;
&lt;p&gt;Concretely, in mentioned function, psrc and pdst are both linear
buffers fetched from each dynptr:&lt;/p&gt;
&lt;p&gt;psrc = __bpf_dynptr_data(src, src_len);
  [...]
  pdst = __bpf_dynptr_data_rw(dst, dst_len);
  [...]
  err = decrypt ?
        ctx-&amp;gt;type-&amp;gt;decrypt(ctx-&amp;gt;tfm, psrc, pdst, src_len, piv) :
        ctx-&amp;gt;type-&amp;gt;encrypt(ctx-&amp;gt;tfm, psrc, pdst, src_len, piv);&lt;/p&gt;
&lt;p&gt;The crypto backend expects pdst to be large enough with a src_len length
that can be written. Add an additional src_len &amp;gt; dst_len check and bail
out if it&amp;#39;s the case. Note that these kfuncs are accessible under root
privileges only.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-8xqx-42cr-fv84</guid>
    </item>
    <item>
      <title>openSUSE-SU-2025:20172-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2025:20172-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2025:20172-1</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:20012-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:20012-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:20012-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-39917</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-39917</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 90 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: bpf: Fix out-of-bounds dynptr write in bpf_crypto_crypt Stanislav reported that in bpf_crypto_crypt() the destination dynptr&amp;#39;s size is not validated to be at least as large as the source dynptr&amp;#39;s size before calling into the crypto backend with &amp;#39;len = src_len&amp;#39;. This can result in an OOB write when the destination is smaller than the source. Concretely, in mentioned function, psrc and pdst are both linear buffers fetched from each dynptr:   psrc = __bpf_dynptr_data(src, src_len);   [...]   pdst = __bpf_dynptr_data_rw(dst, dst_len);   [...]   err = decrypt ?         ctx-&amp;gt;type-&amp;gt;decrypt(ctx-&amp;gt;tfm, psrc, pdst, src_len, piv) :         ctx-&amp;gt;type-&amp;gt;encrypt(ctx-&amp;gt;tfm, psrc, pdst, src_len, piv); The crypto backend expects pdst to be large enough with a src_len length that can be written. Add an additional src_len &amp;gt; dst_len check and bail out if it&amp;#39;s the case. Note that these kfuncs are accessible under root privileges only.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 90 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: bpf: Fix out-of-bounds dynptr write in bpf_crypto_crypt Stanislav reported that in bpf_crypto_crypt() the destination dynptr&amp;#39;s size is not validated to be at least as large as the source dynptr&amp;#39;s size before calling into the crypto backend with &amp;#39;len = src_len&amp;#39;. This can result in an OOB write when the destination is smaller than the source. Concretely, in mentioned function, psrc and pdst are both linear buffers fetched from each dynptr:   psrc = __bpf_dynptr_data(src, src_len);   [...]   pdst = __bpf_dynptr_data_rw(dst, dst_len);   [...]   err = decrypt ?         ctx-&amp;gt;type-&amp;gt;decrypt(ctx-&amp;gt;tfm, psrc, pdst, src_len, piv) :         ctx-&amp;gt;type-&amp;gt;encrypt(ctx-&amp;gt;tfm, psrc, pdst, src_len, piv); The crypto backend expects pdst to be large enough with a src_len length that can be written. Add an additional src_len &amp;gt; dst_len check and bail out if it&amp;#39;s the case. Note that these kfuncs are accessible under root privileges only.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-39917</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-2170 — Linux Kernel: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2170</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen und andere nicht näher spezifizierte Angriffe durchzuführen, möglicherweise um beliebigen Code auszuführen oder eine Speicherbeschädigung zu verursachen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen und andere nicht näher spezifizierte Angriffe durchzuführen, möglicherweise um beliebigen Code auszuführen oder eine Speicherbeschädigung zu verursachen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2170</guid>
    </item>
  </channel>
</rss>
