<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 07:51:39 +0000</lastBuildDate>
    <item>
      <title>ALSA-2025:22854 — Moderate: kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2025:22854</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: kernel-abi-stablelists, AlmaLinux:10: kernel-doc&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: cifs: Fix oops due to uninitialised variable (CVE-2025-38737)
  * kernel: can: j1939: implement NETDEV_UNREGISTER notification handler (CVE-2025-39925)
  * kernel: Bluetooth: hci_event: Fix UAF in hci_acl_create_conn_sync (CVE-2025-39982)
  * kernel: Bluetooth: MGMT: Fix possible UAFs (CVE-2025-39981)
  * kernel: net/mlx5: fs, fix UAF in flow counter release (CVE-2025-39979)
  * kernel: Bluetooth: hci_event: Fix UAF in hci_conn_tx_dequeue (CVE-2025-39983)
  * kernel: io_uring/waitid: always prune wait queue entry in io_waitid_wait() (CVE-2025-40047)
  * kernel: iommu/vt-d: Disallow dirty tracking if incoherent page walk (CVE-2025-40058)
  * kernel: ice: ice_adapter: release xa entry on adapter allocation failure (CVE-2025-40185)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: kernel-abi-stablelists, AlmaLinux:10: kernel-doc&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: cifs: Fix oops due to uninitialised variable (CVE-2025-38737)
  * kernel: can: j1939: implement NETDEV_UNREGISTER notification handler (CVE-2025-39925)
  * kernel: Bluetooth: hci_event: Fix UAF in hci_acl_create_conn_sync (CVE-2025-39982)
  * kernel: Bluetooth: MGMT: Fix possible UAFs (CVE-2025-39981)
  * kernel: net/mlx5: fs, fix UAF in flow counter release (CVE-2025-39979)
  * kernel: Bluetooth: hci_event: Fix UAF in hci_conn_tx_dequeue (CVE-2025-39983)
  * kernel: io_uring/waitid: always prune wait queue entry in io_waitid_wait() (CVE-2025-40047)
  * kernel: iommu/vt-d: Disallow dirty tracking if incoherent page walk (CVE-2025-40058)
  * kernel: ice: ice_adapter: release xa entry on adapter allocation failure (CVE-2025-40185)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2025:22854</guid>
    </item>
    <item>
      <title>bdu:2026-03273</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-03273</link>
      <description>bdu:2026-03273</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-03273</guid>
    </item>
    <item>
      <title>BELL-CVE-2025-39925</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2025-39925</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2025-39925</guid>
    </item>
    <item>
      <title>certfr-2025-avi-0895 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de SUSE. Certaines d'entre elles permettent à un at…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0895</link>
      <description>certfr-2025-avi-0895</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0895</guid>
    </item>
    <item>
      <title>EUVD-2026-362954</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-362954</link>
      <description>EUVD-2026-362954</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-362954</guid>
    </item>
    <item>
      <title>fkie_cve-2025-39925</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-39925</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;can: j1939: implement NETDEV_UNREGISTER notification handler&lt;/p&gt;
&lt;p&gt;syzbot is reporting&lt;/p&gt;
&lt;p&gt;unregister_netdevice: waiting for vcan0 to become free. Usage count = 2&lt;/p&gt;
&lt;p&gt;problem, for j1939 protocol did not have NETDEV_UNREGISTER notification
handler for undoing changes made by j1939_sk_bind().&lt;/p&gt;
&lt;p&gt;Commit 25fe97cb7620 (&amp;#34;can: j1939: move j1939_priv_put() into sk_destruct
callback&amp;#34;) expects that a call to j1939_priv_put() can be unconditionally
delayed until j1939_sk_sock_destruct() is called. But we need to call
j1939_priv_put() against an extra ref held by j1939_sk_bind() call
(as a part of undoing changes made by j1939_sk_bind()) as soon as
NETDEV_UNREGISTER notification fires (i.e. before j1939_sk_sock_destruct()
is called via j1939_sk_release()). Otherwise, the extra ref on &amp;#34;struct
j1939_priv&amp;#34; held by j1939_sk_bind() call prevents &amp;#34;struct net_device&amp;#34; from
dropping the usage count to 1; making it impossible for
unregister_netdevice() to continue.&lt;/p&gt;
&lt;p&gt;[mkl: remove space in front of label]&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;can: j1939: implement NETDEV_UNREGISTER notification handler&lt;/p&gt;
&lt;p&gt;syzbot is reporting&lt;/p&gt;
&lt;p&gt;unregister_netdevice: waiting for vcan0 to become free. Usage count = 2&lt;/p&gt;
&lt;p&gt;problem, for j1939 protocol did not have NETDEV_UNREGISTER notification
handler for undoing changes made by j1939_sk_bind().&lt;/p&gt;
&lt;p&gt;Commit 25fe97cb7620 (&amp;#34;can: j1939: move j1939_priv_put() into sk_destruct
callback&amp;#34;) expects that a call to j1939_priv_put() can be unconditionally
delayed until j1939_sk_sock_destruct() is called. But we need to call
j1939_priv_put() against an extra ref held by j1939_sk_bind() call
(as a part of undoing changes made by j1939_sk_bind()) as soon as
NETDEV_UNREGISTER notification fires (i.e. before j1939_sk_sock_destruct()
is called via j1939_sk_release()). Otherwise, the extra ref on &amp;#34;struct
j1939_priv&amp;#34; held by j1939_sk_bind() call prevents &amp;#34;struct net_device&amp;#34; from
dropping the usage count to 1; making it impossible for
unregister_netdevice() to continue.&lt;/p&gt;
&lt;p&gt;[mkl: remove space in front of label]&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-39925</guid>
    </item>
    <item>
      <title>GHSA-g35j-5v93-p28m</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-g35j-5v93-p28m</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;can: j1939: implement NETDEV_UNREGISTER notification handler&lt;/p&gt;
&lt;p&gt;syzbot is reporting&lt;/p&gt;
&lt;p&gt;unregister_netdevice: waiting for vcan0 to become free. Usage count = 2&lt;/p&gt;
&lt;p&gt;problem, for j1939 protocol did not have NETDEV_UNREGISTER notification
handler for undoing changes made by j1939_sk_bind().&lt;/p&gt;
&lt;p&gt;Commit 25fe97cb7620 (&amp;#34;can: j1939: move j1939_priv_put() into sk_destruct
callback&amp;#34;) expects that a call to j1939_priv_put() can be unconditionally
delayed until j1939_sk_sock_destruct() is called. But we need to call
j1939_priv_put() against an extra ref held by j1939_sk_bind() call
(as a part of undoing changes made by j1939_sk_bind()) as soon as
NETDEV_UNREGISTER notification fires (i.e. before j1939_sk_sock_destruct()
is called via j1939_sk_release()). Otherwise, the extra ref on &amp;#34;struct
j1939_priv&amp;#34; held by j1939_sk_bind() call prevents &amp;#34;struct net_device&amp;#34; from
dropping the usage count to 1; making it impossible for
unregister_netdevice() to continue.&lt;/p&gt;
&lt;p&gt;[mkl: remove space in front of label]&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;can: j1939: implement NETDEV_UNREGISTER notification handler&lt;/p&gt;
&lt;p&gt;syzbot is reporting&lt;/p&gt;
&lt;p&gt;unregister_netdevice: waiting for vcan0 to become free. Usage count = 2&lt;/p&gt;
&lt;p&gt;problem, for j1939 protocol did not have NETDEV_UNREGISTER notification
handler for undoing changes made by j1939_sk_bind().&lt;/p&gt;
&lt;p&gt;Commit 25fe97cb7620 (&amp;#34;can: j1939: move j1939_priv_put() into sk_destruct
callback&amp;#34;) expects that a call to j1939_priv_put() can be unconditionally
delayed until j1939_sk_sock_destruct() is called. But we need to call
j1939_priv_put() against an extra ref held by j1939_sk_bind() call
(as a part of undoing changes made by j1939_sk_bind()) as soon as
NETDEV_UNREGISTER notification fires (i.e. before j1939_sk_sock_destruct()
is called via j1939_sk_release()). Otherwise, the extra ref on &amp;#34;struct
j1939_priv&amp;#34; held by j1939_sk_bind() call prevents &amp;#34;struct net_device&amp;#34; from
dropping the usage count to 1; making it impossible for
unregister_netdevice() to continue.&lt;/p&gt;
&lt;p&gt;[mkl: remove space in front of label]&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-g35j-5v93-p28m</guid>
    </item>
    <item>
      <title>msrc_CVE-2025-39925 — can: j1939: implement NETDEV_UNREGISTER notification handler</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2025-39925</link>
      <description>msrc_CVE-2025-39925</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2025-39925</guid>
    </item>
    <item>
      <title>OESA-2026-1228 — kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-1228</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;net: fec: remove .ndo_poll_controller to avoid deadlocks&lt;/p&gt;
&lt;p&gt;There is a deadlock issue found in sungem driver, please refer to the
commit ac0a230f719b (&amp;amp;quot;eth: sungem: remove .ndo_poll_controller to avoid
deadlocks&amp;amp;quot;). The root cause of the issue is that netpoll is in atomic
context and disable_irq() is called by .ndo_poll_controller interface
of sungem driver, however, disable_irq() might sleep. After analyzing
the implementation of fec_poll_controller(), the fec driver should have
the same issue. Due to the fec driver uses NAPI for TX completions, the
.ndo_poll_controller is unnecessary to be implemented in the fec driver,
so fec_poll_controller() can be safely removed.(CVE-2024-38553)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;ceph: give up on paths longer than PATH_MAX&lt;/p&gt;
&lt;p&gt;If the full path to be built by ceph_mdsc_build_path() happens to be
longer than PATH_MAX, then this function will enter an endless (retry)
loop, effectively blocking the whole task.  Most of the machine
becomes unusable, making this a very simple and effective DoS
vulnerability.&lt;/p&gt;
&lt;p&gt;I cannot imagine why this retry was ever implemented, but it seems
rather useless and harmful to me.  Let&amp;amp;apos;s remove it and fail with
ENAMETOOLONG instead.(CVE-2024-53685)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;Bluetooth: hc…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;net: fec: remove .ndo_poll_controller to avoid deadlocks&lt;/p&gt;
&lt;p&gt;There is a deadlock issue found in sungem driver, please refer to the
commit ac0a230f719b (&amp;amp;quot;eth: sungem: remove .ndo_poll_controller to avoid
deadlocks&amp;amp;quot;). The root cause of the issue is that netpoll is in atomic
context and disable_irq() is called by .ndo_poll_controller interface
of sungem driver, however, disable_irq() might sleep. After analyzing
the implementation of fec_poll_controller(), the fec driver should have
the same issue. Due to the fec driver uses NAPI for TX completions, the
.ndo_poll_controller is unnecessary to be implemented in the fec driver,
so fec_poll_controller() can be safely removed.(CVE-2024-38553)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;ceph: give up on paths longer than PATH_MAX&lt;/p&gt;
&lt;p&gt;If the full path to be built by ceph_mdsc_build_path() happens to be
longer than PATH_MAX, then this function will enter an endless (retry)
loop, effectively blocking the whole task.  Most of the machine
becomes unusable, making this a very simple and effective DoS
vulnerability.&lt;/p&gt;
&lt;p&gt;I cannot imagine why this retry was ever implemented, but it seems
rather useless and harmful to me.  Let&amp;amp;apos;s remove it and fail with
ENAMETOOLONG instead.(CVE-2024-53685)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;Bluetooth: hc…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-1228</guid>
    </item>
    <item>
      <title>openSUSE-SU-2025:20081-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2025:20081-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2025:20081-1</guid>
    </item>
    <item>
      <title>RHSA-2025:23789 — Red Hat Security Advisory: kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2025:23789</link>
      <description>&lt;p&gt;kernel: mm: slub: avoid wake up kswapd in set_track_prepare kernel: can: j1939: implement NETDEV_UNREGISTER notification handler&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;kernel: mm: slub: avoid wake up kswapd in set_track_prepare kernel: can: j1939: implement NETDEV_UNREGISTER notification handler&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2025:23789</guid>
    </item>
    <item>
      <title>SUSE-SU-2025:03600-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2025:03600-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2025:03600-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-39925</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-39925</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:Pro:18.04:LTS: linux-aws-5.4, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:Pro:18.04:LTS: linux-azure-5.4, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3 and 190 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: can: j1939: implement NETDEV_UNREGISTER notification handler syzbot is reporting   unregister_netdevice: waiting for vcan0 to become free. Usage count = 2 problem, for j1939 protocol did not have NETDEV_UNREGISTER notification handler for undoing changes made by j1939_sk_bind(). Commit 25fe97cb7620 (&amp;#34;can: j1939: move j1939_priv_put() into sk_destruct callback&amp;#34;) expects that a call to j1939_priv_put() can be unconditionally delayed until j1939_sk_sock_destruct() is called. But we need to call j1939_priv_put() against an extra ref held by j1939_sk_bind() call (as a part of undoing changes made by j1939_sk_bind()) as soon as NETDEV_UNREGISTER notification fires (i.e. before j1939_sk_sock_destruct() is called via j1939_sk_release()). Otherwise, the extra ref on &amp;#34;struct j1939_priv&amp;#34; held by j1939_sk_bind() call prevents &amp;#34;struct net_device&amp;#34; from dropping the usage count to 1; making it impossible for unregister_netdevice() to continue. [mkl: remove space in front of label]&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:Pro:18.04:LTS: linux-aws-5.4, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:Pro:18.04:LTS: linux-azure-5.4, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3 and 190 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: can: j1939: implement NETDEV_UNREGISTER notification handler syzbot is reporting   unregister_netdevice: waiting for vcan0 to become free. Usage count = 2 problem, for j1939 protocol did not have NETDEV_UNREGISTER notification handler for undoing changes made by j1939_sk_bind(). Commit 25fe97cb7620 (&amp;#34;can: j1939: move j1939_priv_put() into sk_destruct callback&amp;#34;) expects that a call to j1939_priv_put() can be unconditionally delayed until j1939_sk_sock_destruct() is called. But we need to call j1939_priv_put() against an extra ref held by j1939_sk_bind() call (as a part of undoing changes made by j1939_sk_bind()) as soon as NETDEV_UNREGISTER notification fires (i.e. before j1939_sk_sock_destruct() is called via j1939_sk_release()). Otherwise, the extra ref on &amp;#34;struct j1939_priv&amp;#34; held by j1939_sk_bind() call prevents &amp;#34;struct net_device&amp;#34; from dropping the usage count to 1; making it impossible for unregister_netdevice() to continue. [mkl: remove space in front of label]&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-39925</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-2170 — Linux Kernel: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2170</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen und andere nicht näher spezifizierte Angriffe durchzuführen, möglicherweise um beliebigen Code auszuführen oder eine Speicherbeschädigung zu verursachen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen und andere nicht näher spezifizierte Angriffe durchzuführen, möglicherweise um beliebigen Code auszuführen oder eine Speicherbeschädigung zu verursachen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2170</guid>
    </item>
  </channel>
</rss>
