<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 16:10:33 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-02685</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-02685</link>
      <description>bdu:2026-02685</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-02685</guid>
    </item>
    <item>
      <title>BELL-CVE-2025-39950</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2025-39950</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2025-39950</guid>
    </item>
    <item>
      <title>certfr-2025-avi-1073 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de SUSE. Certaines d'entre elles permettent à un at…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-1073</link>
      <description>certfr-2025-avi-1073</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-1073</guid>
    </item>
    <item>
      <title>EUVD-2026-314837</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-314837</link>
      <description>EUVD-2026-314837</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-314837</guid>
    </item>
    <item>
      <title>fkie_cve-2025-39950</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-39950</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;net/tcp: Fix a NULL pointer dereference when using TCP-AO with TCP_REPAIR&lt;/p&gt;
&lt;p&gt;A NULL pointer dereference can occur in tcp_ao_finish_connect() during a
connect() system call on a socket with a TCP-AO key added and TCP_REPAIR
enabled.&lt;/p&gt;
&lt;p&gt;The function is called with skb being NULL and attempts to dereference it
on tcp_hdr(skb)-&amp;gt;seq without a prior skb validation.&lt;/p&gt;
&lt;p&gt;Fix this by checking if skb is NULL before dereferencing it.&lt;/p&gt;
&lt;p&gt;The commentary is taken from bpf_skops_established(), which is also called
in the same flow. Unlike the function being patched,
bpf_skops_established() validates the skb before dereferencing it.&lt;/p&gt;
&lt;p&gt;int main(void){
	struct sockaddr_in sockaddr;
	struct tcp_ao_add tcp_ao;
	int sk;
	int one = 1;&lt;/p&gt;
&lt;p&gt;memset(&amp;amp;sockaddr,&amp;#39;\0&amp;#39;,sizeof(sockaddr));
	memset(&amp;amp;tcp_ao,&amp;#39;\0&amp;#39;,sizeof(tcp_ao));&lt;/p&gt;
&lt;p&gt;sk = socket(AF_INET, SOCK_STREAM, IPPROTO_TCP);&lt;/p&gt;
&lt;p&gt;sockaddr.sin_family = AF_INET;&lt;/p&gt;
&lt;p&gt;memcpy(tcp_ao.alg_name,&amp;#34;cmac(aes128)&amp;#34;,12);
	memcpy(tcp_ao.key,&amp;#34;ABCDEFGHABCDEFGH&amp;#34;,16);
	tcp_ao.keylen = 16;&lt;/p&gt;
&lt;p&gt;memcpy(&amp;amp;tcp_ao.addr,&amp;amp;sockaddr,sizeof(sockaddr));&lt;/p&gt;
&lt;p&gt;setsockopt(sk, IPPROTO_TCP, TCP_AO_ADD_KEY, &amp;amp;tcp_ao,
	sizeof(tcp_ao));
	setsockopt(sk, IPPROTO_TCP, TCP_REPAIR, &amp;amp;one, sizeof(one));&lt;/p&gt;
&lt;p&gt;sockaddr.sin_family = AF_INET;
	sockaddr.sin_port = htobe16(123);&lt;/p&gt;
&lt;p&gt;inet_aton(&amp;#34;127.0.0.1&amp;#34;, &amp;amp;sockaddr.sin_addr);&lt;/p&gt;
&lt;p&gt;connect(sk,(struct sockaddr *)&amp;amp;sockaddr,sizeof(sockaddr));&lt;/p&gt;
&lt;p&gt;return 0;
}&lt;/p&gt;
&lt;p&gt;$ gcc tcp-ao-nullptr.c -o tcp-ao-nullptr -Wall
$ unshare -Urn&lt;/p&gt;
&lt;p&gt;BUG: ke…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;net/tcp: Fix a NULL pointer dereference when using TCP-AO with TCP_REPAIR&lt;/p&gt;
&lt;p&gt;A NULL pointer dereference can occur in tcp_ao_finish_connect() during a
connect() system call on a socket with a TCP-AO key added and TCP_REPAIR
enabled.&lt;/p&gt;
&lt;p&gt;The function is called with skb being NULL and attempts to dereference it
on tcp_hdr(skb)-&amp;gt;seq without a prior skb validation.&lt;/p&gt;
&lt;p&gt;Fix this by checking if skb is NULL before dereferencing it.&lt;/p&gt;
&lt;p&gt;The commentary is taken from bpf_skops_established(), which is also called
in the same flow. Unlike the function being patched,
bpf_skops_established() validates the skb before dereferencing it.&lt;/p&gt;
&lt;p&gt;int main(void){
	struct sockaddr_in sockaddr;
	struct tcp_ao_add tcp_ao;
	int sk;
	int one = 1;&lt;/p&gt;
&lt;p&gt;memset(&amp;amp;sockaddr,&amp;#39;\0&amp;#39;,sizeof(sockaddr));
	memset(&amp;amp;tcp_ao,&amp;#39;\0&amp;#39;,sizeof(tcp_ao));&lt;/p&gt;
&lt;p&gt;sk = socket(AF_INET, SOCK_STREAM, IPPROTO_TCP);&lt;/p&gt;
&lt;p&gt;sockaddr.sin_family = AF_INET;&lt;/p&gt;
&lt;p&gt;memcpy(tcp_ao.alg_name,&amp;#34;cmac(aes128)&amp;#34;,12);
	memcpy(tcp_ao.key,&amp;#34;ABCDEFGHABCDEFGH&amp;#34;,16);
	tcp_ao.keylen = 16;&lt;/p&gt;
&lt;p&gt;memcpy(&amp;amp;tcp_ao.addr,&amp;amp;sockaddr,sizeof(sockaddr));&lt;/p&gt;
&lt;p&gt;setsockopt(sk, IPPROTO_TCP, TCP_AO_ADD_KEY, &amp;amp;tcp_ao,
	sizeof(tcp_ao));
	setsockopt(sk, IPPROTO_TCP, TCP_REPAIR, &amp;amp;one, sizeof(one));&lt;/p&gt;
&lt;p&gt;sockaddr.sin_family = AF_INET;
	sockaddr.sin_port = htobe16(123);&lt;/p&gt;
&lt;p&gt;inet_aton(&amp;#34;127.0.0.1&amp;#34;, &amp;amp;sockaddr.sin_addr);&lt;/p&gt;
&lt;p&gt;connect(sk,(struct sockaddr *)&amp;amp;sockaddr,sizeof(sockaddr));&lt;/p&gt;
&lt;p&gt;return 0;
}&lt;/p&gt;
&lt;p&gt;$ gcc tcp-ao-nullptr.c -o tcp-ao-nullptr -Wall
$ unshare -Urn&lt;/p&gt;
&lt;p&gt;BUG: ke…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-39950</guid>
    </item>
    <item>
      <title>GHSA-f4h6-hf7g-852r</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-f4h6-hf7g-852r</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;net/tcp: Fix a NULL pointer dereference when using TCP-AO with TCP_REPAIR&lt;/p&gt;
&lt;p&gt;A NULL pointer dereference can occur in tcp_ao_finish_connect() during a
connect() system call on a socket with a TCP-AO key added and TCP_REPAIR
enabled.&lt;/p&gt;
&lt;p&gt;The function is called with skb being NULL and attempts to dereference it
on tcp_hdr(skb)-&amp;gt;seq without a prior skb validation.&lt;/p&gt;
&lt;p&gt;Fix this by checking if skb is NULL before dereferencing it.&lt;/p&gt;
&lt;p&gt;The commentary is taken from bpf_skops_established(), which is also called
in the same flow. Unlike the function being patched,
bpf_skops_established() validates the skb before dereferencing it.&lt;/p&gt;
&lt;p&gt;int main(void){
	struct sockaddr_in sockaddr;
	struct tcp_ao_add tcp_ao;
	int sk;
	int one = 1;&lt;/p&gt;
&lt;p&gt;memset(&amp;amp;sockaddr,&amp;#39;\0&amp;#39;,sizeof(sockaddr));
	memset(&amp;amp;tcp_ao,&amp;#39;\0&amp;#39;,sizeof(tcp_ao));&lt;/p&gt;
&lt;p&gt;sk = socket(AF_INET, SOCK_STREAM, IPPROTO_TCP);&lt;/p&gt;
&lt;p&gt;sockaddr.sin_family = AF_INET;&lt;/p&gt;
&lt;p&gt;memcpy(tcp_ao.alg_name,&amp;#34;cmac(aes128)&amp;#34;,12);
	memcpy(tcp_ao.key,&amp;#34;ABCDEFGHABCDEFGH&amp;#34;,16);
	tcp_ao.keylen = 16;&lt;/p&gt;
&lt;p&gt;memcpy(&amp;amp;tcp_ao.addr,&amp;amp;sockaddr,sizeof(sockaddr));&lt;/p&gt;
&lt;p&gt;setsockopt(sk, IPPROTO_TCP, TCP_AO_ADD_KEY, &amp;amp;tcp_ao,
	sizeof(tcp_ao));
	setsockopt(sk, IPPROTO_TCP, TCP_REPAIR, &amp;amp;one, sizeof(one));&lt;/p&gt;
&lt;p&gt;sockaddr.sin_family = AF_INET;
	sockaddr.sin_port = htobe16(123);&lt;/p&gt;
&lt;p&gt;inet_aton(&amp;#34;127.0.0.1&amp;#34;, &amp;amp;sockaddr.sin_addr);&lt;/p&gt;
&lt;p&gt;connect(sk,(struct sockaddr *)&amp;amp;sockaddr,sizeof(sockaddr));&lt;/p&gt;
&lt;p&gt;return 0;
}&lt;/p&gt;
&lt;p&gt;$ gcc tcp-ao-nullptr.c -o tcp-ao-nullptr -Wall
$ unshare -Urn&lt;/p&gt;
&lt;p&gt;BUG: ke…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;net/tcp: Fix a NULL pointer dereference when using TCP-AO with TCP_REPAIR&lt;/p&gt;
&lt;p&gt;A NULL pointer dereference can occur in tcp_ao_finish_connect() during a
connect() system call on a socket with a TCP-AO key added and TCP_REPAIR
enabled.&lt;/p&gt;
&lt;p&gt;The function is called with skb being NULL and attempts to dereference it
on tcp_hdr(skb)-&amp;gt;seq without a prior skb validation.&lt;/p&gt;
&lt;p&gt;Fix this by checking if skb is NULL before dereferencing it.&lt;/p&gt;
&lt;p&gt;The commentary is taken from bpf_skops_established(), which is also called
in the same flow. Unlike the function being patched,
bpf_skops_established() validates the skb before dereferencing it.&lt;/p&gt;
&lt;p&gt;int main(void){
	struct sockaddr_in sockaddr;
	struct tcp_ao_add tcp_ao;
	int sk;
	int one = 1;&lt;/p&gt;
&lt;p&gt;memset(&amp;amp;sockaddr,&amp;#39;\0&amp;#39;,sizeof(sockaddr));
	memset(&amp;amp;tcp_ao,&amp;#39;\0&amp;#39;,sizeof(tcp_ao));&lt;/p&gt;
&lt;p&gt;sk = socket(AF_INET, SOCK_STREAM, IPPROTO_TCP);&lt;/p&gt;
&lt;p&gt;sockaddr.sin_family = AF_INET;&lt;/p&gt;
&lt;p&gt;memcpy(tcp_ao.alg_name,&amp;#34;cmac(aes128)&amp;#34;,12);
	memcpy(tcp_ao.key,&amp;#34;ABCDEFGHABCDEFGH&amp;#34;,16);
	tcp_ao.keylen = 16;&lt;/p&gt;
&lt;p&gt;memcpy(&amp;amp;tcp_ao.addr,&amp;amp;sockaddr,sizeof(sockaddr));&lt;/p&gt;
&lt;p&gt;setsockopt(sk, IPPROTO_TCP, TCP_AO_ADD_KEY, &amp;amp;tcp_ao,
	sizeof(tcp_ao));
	setsockopt(sk, IPPROTO_TCP, TCP_REPAIR, &amp;amp;one, sizeof(one));&lt;/p&gt;
&lt;p&gt;sockaddr.sin_family = AF_INET;
	sockaddr.sin_port = htobe16(123);&lt;/p&gt;
&lt;p&gt;inet_aton(&amp;#34;127.0.0.1&amp;#34;, &amp;amp;sockaddr.sin_addr);&lt;/p&gt;
&lt;p&gt;connect(sk,(struct sockaddr *)&amp;amp;sockaddr,sizeof(sockaddr));&lt;/p&gt;
&lt;p&gt;return 0;
}&lt;/p&gt;
&lt;p&gt;$ gcc tcp-ao-nullptr.c -o tcp-ao-nullptr -Wall
$ unshare -Urn&lt;/p&gt;
&lt;p&gt;BUG: ke…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-f4h6-hf7g-852r</guid>
    </item>
    <item>
      <title>openSUSE-SU-2025:20091-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2025:20091-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2025:20091-1</guid>
    </item>
    <item>
      <title>SUSE-SU-2025:21080-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2025:21080-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2025:21080-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-39950</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-39950</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 124 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: net/tcp: Fix a NULL pointer dereference when using TCP-AO with TCP_REPAIR A NULL pointer dereference can occur in tcp_ao_finish_connect() during a connect() system call on a socket with a TCP-AO key added and TCP_REPAIR enabled. The function is called with skb being NULL and attempts to dereference it on tcp_hdr(skb)-&amp;gt;seq without a prior skb validation. Fix this by checking if skb is NULL before dereferencing it. The commentary is taken from bpf_skops_established(), which is also called in the same flow. Unlike the function being patched, bpf_skops_established() validates the skb before dereferencing it. int main(void){ 	struct sockaddr_in sockaddr; 	struct tcp_ao_add tcp_ao; 	int sk; 	int one = 1; 	memset(&amp;amp;sockaddr,&amp;#39;\0&amp;#39;,sizeof(sockaddr)); 	memset(&amp;amp;tcp_ao,&amp;#39;\0&amp;#39;,sizeof(tcp_ao)); 	sk = socket(AF_INET, SOCK_STREAM, IPPROTO_TCP); 	sockaddr.sin_family = AF_INET; 	memcpy(tcp_ao.alg_name,&amp;#34;cmac(aes128)&amp;#34;,12); 	memcpy(tcp_ao.key,&amp;#34;ABCDEFGHABCDEFGH&amp;#34;,16); 	tcp_ao.keylen = 16; 	memcpy(&amp;amp;tcp_ao.addr,&amp;amp;sockaddr,sizeof(sockaddr)); 	setsockopt(sk, IPPROTO_TCP, TCP_AO_ADD_KEY, &amp;amp;tcp_ao, 	sizeof(tcp_ao)); 	setsockopt(sk, IPPROTO_TCP, TCP_REPAIR, &amp;amp;one, sizeof(one)); 	sockaddr.sin_family = AF_INET; 	sockaddr.sin_port = htobe16(123); 	inet_aton(&amp;#34;127.0.0.1&amp;#34;, &amp;amp;sockaddr.sin_addr); 	connect(sk,(struct sockaddr *)&amp;amp;sockaddr,sizeof(sockaddr)); return 0; } $ gcc tcp-ao-nullptr.c -o tcp-ao-nullptr -Wall $ unshare -Urn BUG: kernel NULL pointer…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 124 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: net/tcp: Fix a NULL pointer dereference when using TCP-AO with TCP_REPAIR A NULL pointer dereference can occur in tcp_ao_finish_connect() during a connect() system call on a socket with a TCP-AO key added and TCP_REPAIR enabled. The function is called with skb being NULL and attempts to dereference it on tcp_hdr(skb)-&amp;gt;seq without a prior skb validation. Fix this by checking if skb is NULL before dereferencing it. The commentary is taken from bpf_skops_established(), which is also called in the same flow. Unlike the function being patched, bpf_skops_established() validates the skb before dereferencing it. int main(void){ 	struct sockaddr_in sockaddr; 	struct tcp_ao_add tcp_ao; 	int sk; 	int one = 1; 	memset(&amp;amp;sockaddr,&amp;#39;\0&amp;#39;,sizeof(sockaddr)); 	memset(&amp;amp;tcp_ao,&amp;#39;\0&amp;#39;,sizeof(tcp_ao)); 	sk = socket(AF_INET, SOCK_STREAM, IPPROTO_TCP); 	sockaddr.sin_family = AF_INET; 	memcpy(tcp_ao.alg_name,&amp;#34;cmac(aes128)&amp;#34;,12); 	memcpy(tcp_ao.key,&amp;#34;ABCDEFGHABCDEFGH&amp;#34;,16); 	tcp_ao.keylen = 16; 	memcpy(&amp;amp;tcp_ao.addr,&amp;amp;sockaddr,sizeof(sockaddr)); 	setsockopt(sk, IPPROTO_TCP, TCP_AO_ADD_KEY, &amp;amp;tcp_ao, 	sizeof(tcp_ao)); 	setsockopt(sk, IPPROTO_TCP, TCP_REPAIR, &amp;amp;one, sizeof(one)); 	sockaddr.sin_family = AF_INET; 	sockaddr.sin_port = htobe16(123); 	inet_aton(&amp;#34;127.0.0.1&amp;#34;, &amp;amp;sockaddr.sin_addr); 	connect(sk,(struct sockaddr *)&amp;amp;sockaddr,sizeof(sockaddr)); return 0; } $ gcc tcp-ao-nullptr.c -o tcp-ao-nullptr -Wall $ unshare -Urn BUG: kernel NULL pointer…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-39950</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-2194 — Linux Kernel: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2194</link>
      <description>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen in Linux Kernel ausnutzen, um nicht näher spezifizierte Angriffe durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen in Linux Kernel ausnutzen, um nicht näher spezifizierte Angriffe durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2194</guid>
    </item>
  </channel>
</rss>
