<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 22:33:27 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-02671</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-02671</link>
      <description>bdu:2026-02671</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-02671</guid>
    </item>
    <item>
      <title>BELL-CVE-2025-39949</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2025-39949</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2025-39949</guid>
    </item>
    <item>
      <title>certfr-2025-avi-0899 — De multiples vulnérabilités ont été découvertes dans les produits Microsoft. Certaines d'entre elles permettent à un at…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0899</link>
      <description>certfr-2025-avi-0899</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0899</guid>
    </item>
    <item>
      <title>EUVD-2026-347267</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-347267</link>
      <description>EUVD-2026-347267</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-347267</guid>
    </item>
    <item>
      <title>fkie_cve-2025-39949</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-39949</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;qed: Don&amp;#39;t collect too many protection override GRC elements&lt;/p&gt;
&lt;p&gt;In the protection override dump path, the firmware can return far too
many GRC elements, resulting in attempting to write past the end of the
previously-kmalloc&amp;#39;ed dump buffer.&lt;/p&gt;
&lt;p&gt;This will result in a kernel panic with reason:&lt;/p&gt;
&lt;p&gt;BUG: unable to handle kernel paging request at ADDRESS&lt;/p&gt;
&lt;p&gt;where &amp;#34;ADDRESS&amp;#34; is just past the end of the protection override dump
buffer. The start address of the buffer is:
 p_hwfn-&amp;gt;cdev-&amp;gt;dbg_features[DBG_FEATURE_PROTECTION_OVERRIDE].dump_buf
and the size of the buffer is buf_size in the same data structure.&lt;/p&gt;
&lt;p&gt;The panic can be arrived at from either the qede Ethernet driver path:&lt;/p&gt;
&lt;p&gt;[exception RIP: qed_grc_dump_addr_range+0x108]
 qed_protection_override_dump at ffffffffc02662ed [qed]
 qed_dbg_protection_override_dump at ffffffffc0267792 [qed]
 qed_dbg_feature at ffffffffc026aa8f [qed]
 qed_dbg_all_data at ffffffffc026b211 [qed]
 qed_fw_fatal_reporter_dump at ffffffffc027298a [qed]
 devlink_health_do_dump at ffffffff82497f61
 devlink_health_report at ffffffff8249cf29
 qed_report_fatal_error at ffffffffc0272baf [qed]
 qede_sp_task at ffffffffc045ed32 [qede]
 process_one_work at ffffffff81d19783&lt;/p&gt;
&lt;p&gt;or the qedf storage driver path:&lt;/p&gt;
&lt;p&gt;[exception RIP: qed_grc_dump_addr_range+0x108]
 qed_protection_override_dump at ffffffffc068b2ed [qed]
 qed_dbg_protection_override_dump at ffffffffc068c792 [qed]
 qed_dbg_feature at ffffffffc068fa8…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;qed: Don&amp;#39;t collect too many protection override GRC elements&lt;/p&gt;
&lt;p&gt;In the protection override dump path, the firmware can return far too
many GRC elements, resulting in attempting to write past the end of the
previously-kmalloc&amp;#39;ed dump buffer.&lt;/p&gt;
&lt;p&gt;This will result in a kernel panic with reason:&lt;/p&gt;
&lt;p&gt;BUG: unable to handle kernel paging request at ADDRESS&lt;/p&gt;
&lt;p&gt;where &amp;#34;ADDRESS&amp;#34; is just past the end of the protection override dump
buffer. The start address of the buffer is:
 p_hwfn-&amp;gt;cdev-&amp;gt;dbg_features[DBG_FEATURE_PROTECTION_OVERRIDE].dump_buf
and the size of the buffer is buf_size in the same data structure.&lt;/p&gt;
&lt;p&gt;The panic can be arrived at from either the qede Ethernet driver path:&lt;/p&gt;
&lt;p&gt;[exception RIP: qed_grc_dump_addr_range+0x108]
 qed_protection_override_dump at ffffffffc02662ed [qed]
 qed_dbg_protection_override_dump at ffffffffc0267792 [qed]
 qed_dbg_feature at ffffffffc026aa8f [qed]
 qed_dbg_all_data at ffffffffc026b211 [qed]
 qed_fw_fatal_reporter_dump at ffffffffc027298a [qed]
 devlink_health_do_dump at ffffffff82497f61
 devlink_health_report at ffffffff8249cf29
 qed_report_fatal_error at ffffffffc0272baf [qed]
 qede_sp_task at ffffffffc045ed32 [qede]
 process_one_work at ffffffff81d19783&lt;/p&gt;
&lt;p&gt;or the qedf storage driver path:&lt;/p&gt;
&lt;p&gt;[exception RIP: qed_grc_dump_addr_range+0x108]
 qed_protection_override_dump at ffffffffc068b2ed [qed]
 qed_dbg_protection_override_dump at ffffffffc068c792 [qed]
 qed_dbg_feature at ffffffffc068fa8…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-39949</guid>
    </item>
    <item>
      <title>GHSA-ph27-9pw7-jv35</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-ph27-9pw7-jv35</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;qed: Don&amp;#39;t collect too many protection override GRC elements&lt;/p&gt;
&lt;p&gt;In the protection override dump path, the firmware can return far too
many GRC elements, resulting in attempting to write past the end of the
previously-kmalloc&amp;#39;ed dump buffer.&lt;/p&gt;
&lt;p&gt;This will result in a kernel panic with reason:&lt;/p&gt;
&lt;p&gt;BUG: unable to handle kernel paging request at ADDRESS&lt;/p&gt;
&lt;p&gt;where &amp;#34;ADDRESS&amp;#34; is just past the end of the protection override dump
buffer. The start address of the buffer is:
 p_hwfn-&amp;gt;cdev-&amp;gt;dbg_features[DBG_FEATURE_PROTECTION_OVERRIDE].dump_buf
and the size of the buffer is buf_size in the same data structure.&lt;/p&gt;
&lt;p&gt;The panic can be arrived at from either the qede Ethernet driver path:&lt;/p&gt;
&lt;p&gt;[exception RIP: qed_grc_dump_addr_range+0x108]
 qed_protection_override_dump at ffffffffc02662ed [qed]
 qed_dbg_protection_override_dump at ffffffffc0267792 [qed]
 qed_dbg_feature at ffffffffc026aa8f [qed]
 qed_dbg_all_data at ffffffffc026b211 [qed]
 qed_fw_fatal_reporter_dump at ffffffffc027298a [qed]
 devlink_health_do_dump at ffffffff82497f61
 devlink_health_report at ffffffff8249cf29
 qed_report_fatal_error at ffffffffc0272baf [qed]
 qede_sp_task at ffffffffc045ed32 [qede]
 process_one_work at ffffffff81d19783&lt;/p&gt;
&lt;p&gt;or the qedf storage driver path:&lt;/p&gt;
&lt;p&gt;[exception RIP: qed_grc_dump_addr_range+0x108]
 qed_protection_override_dump at ffffffffc068b2ed [qed]
 qed_dbg_protection_override_dump at ffffffffc068c792 [qed]
 qed_dbg_feature at ffffffffc068fa8…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;qed: Don&amp;#39;t collect too many protection override GRC elements&lt;/p&gt;
&lt;p&gt;In the protection override dump path, the firmware can return far too
many GRC elements, resulting in attempting to write past the end of the
previously-kmalloc&amp;#39;ed dump buffer.&lt;/p&gt;
&lt;p&gt;This will result in a kernel panic with reason:&lt;/p&gt;
&lt;p&gt;BUG: unable to handle kernel paging request at ADDRESS&lt;/p&gt;
&lt;p&gt;where &amp;#34;ADDRESS&amp;#34; is just past the end of the protection override dump
buffer. The start address of the buffer is:
 p_hwfn-&amp;gt;cdev-&amp;gt;dbg_features[DBG_FEATURE_PROTECTION_OVERRIDE].dump_buf
and the size of the buffer is buf_size in the same data structure.&lt;/p&gt;
&lt;p&gt;The panic can be arrived at from either the qede Ethernet driver path:&lt;/p&gt;
&lt;p&gt;[exception RIP: qed_grc_dump_addr_range+0x108]
 qed_protection_override_dump at ffffffffc02662ed [qed]
 qed_dbg_protection_override_dump at ffffffffc0267792 [qed]
 qed_dbg_feature at ffffffffc026aa8f [qed]
 qed_dbg_all_data at ffffffffc026b211 [qed]
 qed_fw_fatal_reporter_dump at ffffffffc027298a [qed]
 devlink_health_do_dump at ffffffff82497f61
 devlink_health_report at ffffffff8249cf29
 qed_report_fatal_error at ffffffffc0272baf [qed]
 qede_sp_task at ffffffffc045ed32 [qede]
 process_one_work at ffffffff81d19783&lt;/p&gt;
&lt;p&gt;or the qedf storage driver path:&lt;/p&gt;
&lt;p&gt;[exception RIP: qed_grc_dump_addr_range+0x108]
 qed_protection_override_dump at ffffffffc068b2ed [qed]
 qed_dbg_protection_override_dump at ffffffffc068c792 [qed]
 qed_dbg_feature at ffffffffc068fa8…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-ph27-9pw7-jv35</guid>
    </item>
    <item>
      <title>msrc_CVE-2025-39949 — qed: Don't collect too many protection override GRC elements</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2025-39949</link>
      <description>msrc_CVE-2025-39949</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2025-39949</guid>
    </item>
    <item>
      <title>OESA-2025-2633 — kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2025-2633</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:x86/microcode/AMD: Fix out-of-bounds on systems with CPU-less NUMA nodesCurrently, load_microcode_amd() iterates over all NUMA nodes, retrieves theirCPU masks and unconditionally accesses per-CPU data for the first CPU of eachmask.According to Documentation/admin-guide/mm/numaperf.rst:   Some memory may share the same node as a CPU, and others are provided as  memory only nodes. Therefore, some node CPU masks may be empty and wouldn t have a  first CPU .On a machine with far memory (and therefore CPU-less NUMA nodes):- cpumask_of_node(nid) is 0- cpumask_first(0) is CONFIG_NR_CPUS- cpu_data(CONFIG_NR_CPUS) accesses the cpu_info per-CPU array at an  index that is 1 out of boundsThis does not have any security implications since flashing microcode isa privileged operation but I believe this has reliability implications bypotentially corrupting memory while flashing a microcode update.When booting with CONFIG_UBSAN_BOUNDS=y on an AMD machine that flashesa microcode update. I get the following splat:  UBSAN: array-index-out-of-bounds in arch/x86/kernel/cpu/microcode/amd.c:X:Y  index 512 is out of range for type  unsigned long[512]   [...]  Call Trace:   dump_stack   __ubsan_handle_out_of_bounds   load_microcode_amd   request_microcode_amd   reload_store   kernfs_fop_write_iter   vfs_write   ksys_write   do_syscall_64   entry_SYSCALL_64_after…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:x86/microcode/AMD: Fix out-of-bounds on systems with CPU-less NUMA nodesCurrently, load_microcode_amd() iterates over all NUMA nodes, retrieves theirCPU masks and unconditionally accesses per-CPU data for the first CPU of eachmask.According to Documentation/admin-guide/mm/numaperf.rst:   Some memory may share the same node as a CPU, and others are provided as  memory only nodes. Therefore, some node CPU masks may be empty and wouldn t have a  first CPU .On a machine with far memory (and therefore CPU-less NUMA nodes):- cpumask_of_node(nid) is 0- cpumask_first(0) is CONFIG_NR_CPUS- cpu_data(CONFIG_NR_CPUS) accesses the cpu_info per-CPU array at an  index that is 1 out of boundsThis does not have any security implications since flashing microcode isa privileged operation but I believe this has reliability implications bypotentially corrupting memory while flashing a microcode update.When booting with CONFIG_UBSAN_BOUNDS=y on an AMD machine that flashesa microcode update. I get the following splat:  UBSAN: array-index-out-of-bounds in arch/x86/kernel/cpu/microcode/amd.c:X:Y  index 512 is out of range for type  unsigned long[512]   [...]  Call Trace:   dump_stack   __ubsan_handle_out_of_bounds   load_microcode_amd   request_microcode_amd   reload_store   kernfs_fop_write_iter   vfs_write   ksys_write   do_syscall_64   entry_SYSCALL_64_after…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2025-2633</guid>
    </item>
    <item>
      <title>openSUSE-SU-2025:20091-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2025:20091-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2025:20091-1</guid>
    </item>
    <item>
      <title>SUSE-SU-2025:21040-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2025:21040-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2025:21040-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-39949</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-39949</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:Pro:18.04:LTS: linux-aws-5.4, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:Pro:18.04:LTS: linux-azure-5.4, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3 and 188 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: qed: Don&amp;#39;t collect too many protection override GRC elements In the protection override dump path, the firmware can return far too many GRC elements, resulting in attempting to write past the end of the previously-kmalloc&amp;#39;ed dump buffer. This will result in a kernel panic with reason:  BUG: unable to handle kernel paging request at ADDRESS where &amp;#34;ADDRESS&amp;#34; is just past the end of the protection override dump buffer. The start address of the buffer is:  p_hwfn-&amp;gt;cdev-&amp;gt;dbg_features[DBG_FEATURE_PROTECTION_OVERRIDE].dump_buf and the size of the buffer is buf_size in the same data structure. The panic can be arrived at from either the qede Ethernet driver path:     [exception RIP: qed_grc_dump_addr_range+0x108]  qed_protection_override_dump at ffffffffc02662ed [qed]  qed_dbg_protection_override_dump at ffffffffc0267792 [qed]  qed_dbg_feature at ffffffffc026aa8f [qed]  qed_dbg_all_data at ffffffffc026b211 [qed]  qed_fw_fatal_reporter_dump at ffffffffc027298a [qed]  devlink_health_do_dump at ffffffff82497f61  devlink_health_report at ffffffff8249cf29  qed_report_fatal_error at ffffffffc0272baf [qed]  qede_sp_task at ffffffffc045ed32 [qede]  process_one_work at ffffffff81d19783 or the qedf storage driver path:     [exception RIP: qed_grc_dump_addr_range+0x108]  qed_protection_override_dump at ffffffffc068b2ed [qed]  qed_dbg_protection_override_dump at ffffffffc068c792 [qed]  qed_dbg_feature at ffffffffc068fa8f [qed]…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:Pro:18.04:LTS: linux-aws-5.4, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:Pro:18.04:LTS: linux-azure-5.4, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3 and 188 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: qed: Don&amp;#39;t collect too many protection override GRC elements In the protection override dump path, the firmware can return far too many GRC elements, resulting in attempting to write past the end of the previously-kmalloc&amp;#39;ed dump buffer. This will result in a kernel panic with reason:  BUG: unable to handle kernel paging request at ADDRESS where &amp;#34;ADDRESS&amp;#34; is just past the end of the protection override dump buffer. The start address of the buffer is:  p_hwfn-&amp;gt;cdev-&amp;gt;dbg_features[DBG_FEATURE_PROTECTION_OVERRIDE].dump_buf and the size of the buffer is buf_size in the same data structure. The panic can be arrived at from either the qede Ethernet driver path:     [exception RIP: qed_grc_dump_addr_range+0x108]  qed_protection_override_dump at ffffffffc02662ed [qed]  qed_dbg_protection_override_dump at ffffffffc0267792 [qed]  qed_dbg_feature at ffffffffc026aa8f [qed]  qed_dbg_all_data at ffffffffc026b211 [qed]  qed_fw_fatal_reporter_dump at ffffffffc027298a [qed]  devlink_health_do_dump at ffffffff82497f61  devlink_health_report at ffffffff8249cf29  qed_report_fatal_error at ffffffffc0272baf [qed]  qede_sp_task at ffffffffc045ed32 [qede]  process_one_work at ffffffff81d19783 or the qedf storage driver path:     [exception RIP: qed_grc_dump_addr_range+0x108]  qed_protection_override_dump at ffffffffc068b2ed [qed]  qed_dbg_protection_override_dump at ffffffffc068c792 [qed]  qed_dbg_feature at ffffffffc068fa8f [qed]…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-39949</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-2194 — Linux Kernel: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2194</link>
      <description>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen in Linux Kernel ausnutzen, um nicht näher spezifizierte Angriffe durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen in Linux Kernel ausnutzen, um nicht näher spezifizierte Angriffe durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2194</guid>
    </item>
  </channel>
</rss>
