<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 20:49:28 +0000</lastBuildDate>
    <item>
      <title>ALSA-2025:22854 — Moderate: kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2025:22854</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: kernel-abi-stablelists, AlmaLinux:10: kernel-doc&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: cifs: Fix oops due to uninitialised variable (CVE-2025-38737)
  * kernel: can: j1939: implement NETDEV_UNREGISTER notification handler (CVE-2025-39925)
  * kernel: Bluetooth: hci_event: Fix UAF in hci_acl_create_conn_sync (CVE-2025-39982)
  * kernel: Bluetooth: MGMT: Fix possible UAFs (CVE-2025-39981)
  * kernel: net/mlx5: fs, fix UAF in flow counter release (CVE-2025-39979)
  * kernel: Bluetooth: hci_event: Fix UAF in hci_conn_tx_dequeue (CVE-2025-39983)
  * kernel: io_uring/waitid: always prune wait queue entry in io_waitid_wait() (CVE-2025-40047)
  * kernel: iommu/vt-d: Disallow dirty tracking if incoherent page walk (CVE-2025-40058)
  * kernel: ice: ice_adapter: release xa entry on adapter allocation failure (CVE-2025-40185)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: kernel-abi-stablelists, AlmaLinux:10: kernel-doc&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: cifs: Fix oops due to uninitialised variable (CVE-2025-38737)
  * kernel: can: j1939: implement NETDEV_UNREGISTER notification handler (CVE-2025-39925)
  * kernel: Bluetooth: hci_event: Fix UAF in hci_acl_create_conn_sync (CVE-2025-39982)
  * kernel: Bluetooth: MGMT: Fix possible UAFs (CVE-2025-39981)
  * kernel: net/mlx5: fs, fix UAF in flow counter release (CVE-2025-39979)
  * kernel: Bluetooth: hci_event: Fix UAF in hci_conn_tx_dequeue (CVE-2025-39983)
  * kernel: io_uring/waitid: always prune wait queue entry in io_waitid_wait() (CVE-2025-40047)
  * kernel: iommu/vt-d: Disallow dirty tracking if incoherent page walk (CVE-2025-40058)
  * kernel: ice: ice_adapter: release xa entry on adapter allocation failure (CVE-2025-40185)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2025:22854</guid>
    </item>
    <item>
      <title>BELL-CVE-2025-39979</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2025-39979</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2025-39979</guid>
    </item>
    <item>
      <title>certfr-2025-avi-1073 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de SUSE. Certaines d'entre elles permettent à un at…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-1073</link>
      <description>certfr-2025-avi-1073</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-1073</guid>
    </item>
    <item>
      <title>EUVD-2026-347287</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-347287</link>
      <description>EUVD-2026-347287</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-347287</guid>
    </item>
    <item>
      <title>fkie_cve-2025-39979</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-39979</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;net/mlx5: fs, fix UAF in flow counter release&lt;/p&gt;
&lt;p&gt;Fix a kernel trace [1] caused by releasing an HWS action of a local flow
counter in mlx5_cmd_hws_delete_fte(), where the HWS action refcount and
mutex were not initialized and the counter struct could already be freed
when deleting the rule.&lt;/p&gt;
&lt;p&gt;Fix it by adding the missing initializations and adding refcount for the
local flow counter struct.&lt;/p&gt;
&lt;p&gt;[1] Kernel log:
 Call Trace:
  &amp;lt;TASK&amp;gt;
  dump_stack_lvl+0x34/0x48
  mlx5_fs_put_hws_action.part.0.cold+0x21/0x94 [mlx5_core]
  mlx5_fc_put_hws_action+0x96/0xad [mlx5_core]
  mlx5_fs_destroy_fs_actions+0x8b/0x152 [mlx5_core]
  mlx5_cmd_hws_delete_fte+0x5a/0xa0 [mlx5_core]
  del_hw_fte+0x1ce/0x260 [mlx5_core]
  mlx5_del_flow_rules+0x12d/0x240 [mlx5_core]
  ? ttwu_queue_wakelist+0xf4/0x110
  mlx5_ib_destroy_flow+0x103/0x1b0 [mlx5_ib]
  uverbs_free_flow+0x20/0x50 [ib_uverbs]
  destroy_hw_idr_uobject+0x1b/0x50 [ib_uverbs]
  uverbs_destroy_uobject+0x34/0x1a0 [ib_uverbs]
  uobj_destroy+0x3c/0x80 [ib_uverbs]
  ib_uverbs_run_method+0x23e/0x360 [ib_uverbs]
  ? uverbs_finalize_object+0x60/0x60 [ib_uverbs]
  ib_uverbs_cmd_verbs+0x14f/0x2c0 [ib_uverbs]
  ? do_tty_write+0x1a9/0x270
  ? file_tty_write.constprop.0+0x98/0xc0
  ? new_sync_write+0xfc/0x190
  ib_uverbs_ioctl+0xd7/0x160 [ib_uverbs]
  __x64_sys_ioctl+0x87/0xc0
  do_syscall_64+0x59/0x90&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;net/mlx5: fs, fix UAF in flow counter release&lt;/p&gt;
&lt;p&gt;Fix a kernel trace [1] caused by releasing an HWS action of a local flow
counter in mlx5_cmd_hws_delete_fte(), where the HWS action refcount and
mutex were not initialized and the counter struct could already be freed
when deleting the rule.&lt;/p&gt;
&lt;p&gt;Fix it by adding the missing initializations and adding refcount for the
local flow counter struct.&lt;/p&gt;
&lt;p&gt;[1] Kernel log:
 Call Trace:
  &amp;lt;TASK&amp;gt;
  dump_stack_lvl+0x34/0x48
  mlx5_fs_put_hws_action.part.0.cold+0x21/0x94 [mlx5_core]
  mlx5_fc_put_hws_action+0x96/0xad [mlx5_core]
  mlx5_fs_destroy_fs_actions+0x8b/0x152 [mlx5_core]
  mlx5_cmd_hws_delete_fte+0x5a/0xa0 [mlx5_core]
  del_hw_fte+0x1ce/0x260 [mlx5_core]
  mlx5_del_flow_rules+0x12d/0x240 [mlx5_core]
  ? ttwu_queue_wakelist+0xf4/0x110
  mlx5_ib_destroy_flow+0x103/0x1b0 [mlx5_ib]
  uverbs_free_flow+0x20/0x50 [ib_uverbs]
  destroy_hw_idr_uobject+0x1b/0x50 [ib_uverbs]
  uverbs_destroy_uobject+0x34/0x1a0 [ib_uverbs]
  uobj_destroy+0x3c/0x80 [ib_uverbs]
  ib_uverbs_run_method+0x23e/0x360 [ib_uverbs]
  ? uverbs_finalize_object+0x60/0x60 [ib_uverbs]
  ib_uverbs_cmd_verbs+0x14f/0x2c0 [ib_uverbs]
  ? do_tty_write+0x1a9/0x270
  ? file_tty_write.constprop.0+0x98/0xc0
  ? new_sync_write+0xfc/0x190
  ib_uverbs_ioctl+0xd7/0x160 [ib_uverbs]
  __x64_sys_ioctl+0x87/0xc0
  do_syscall_64+0x59/0x90&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-39979</guid>
    </item>
    <item>
      <title>GHSA-52rq-cpwv-rvvm</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-52rq-cpwv-rvvm</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;net/mlx5: fs, fix UAF in flow counter release&lt;/p&gt;
&lt;p&gt;Fix a kernel trace [1] caused by releasing an HWS action of a local flow
counter in mlx5_cmd_hws_delete_fte(), where the HWS action refcount and
mutex were not initialized and the counter struct could already be freed
when deleting the rule.&lt;/p&gt;
&lt;p&gt;Fix it by adding the missing initializations and adding refcount for the
local flow counter struct.&lt;/p&gt;
&lt;p&gt;[1] Kernel log:
 Call Trace:
  &amp;lt;TASK&amp;gt;
  dump_stack_lvl+0x34/0x48
  mlx5_fs_put_hws_action.part.0.cold+0x21/0x94 [mlx5_core]
  mlx5_fc_put_hws_action+0x96/0xad [mlx5_core]
  mlx5_fs_destroy_fs_actions+0x8b/0x152 [mlx5_core]
  mlx5_cmd_hws_delete_fte+0x5a/0xa0 [mlx5_core]
  del_hw_fte+0x1ce/0x260 [mlx5_core]
  mlx5_del_flow_rules+0x12d/0x240 [mlx5_core]
  ? ttwu_queue_wakelist+0xf4/0x110
  mlx5_ib_destroy_flow+0x103/0x1b0 [mlx5_ib]
  uverbs_free_flow+0x20/0x50 [ib_uverbs]
  destroy_hw_idr_uobject+0x1b/0x50 [ib_uverbs]
  uverbs_destroy_uobject+0x34/0x1a0 [ib_uverbs]
  uobj_destroy+0x3c/0x80 [ib_uverbs]
  ib_uverbs_run_method+0x23e/0x360 [ib_uverbs]
  ? uverbs_finalize_object+0x60/0x60 [ib_uverbs]
  ib_uverbs_cmd_verbs+0x14f/0x2c0 [ib_uverbs]
  ? do_tty_write+0x1a9/0x270
  ? file_tty_write.constprop.0+0x98/0xc0
  ? new_sync_write+0xfc/0x190
  ib_uverbs_ioctl+0xd7/0x160 [ib_uverbs]
  __x64_sys_ioctl+0x87/0xc0
  do_syscall_64+0x59/0x90&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;net/mlx5: fs, fix UAF in flow counter release&lt;/p&gt;
&lt;p&gt;Fix a kernel trace [1] caused by releasing an HWS action of a local flow
counter in mlx5_cmd_hws_delete_fte(), where the HWS action refcount and
mutex were not initialized and the counter struct could already be freed
when deleting the rule.&lt;/p&gt;
&lt;p&gt;Fix it by adding the missing initializations and adding refcount for the
local flow counter struct.&lt;/p&gt;
&lt;p&gt;[1] Kernel log:
 Call Trace:
  &amp;lt;TASK&amp;gt;
  dump_stack_lvl+0x34/0x48
  mlx5_fs_put_hws_action.part.0.cold+0x21/0x94 [mlx5_core]
  mlx5_fc_put_hws_action+0x96/0xad [mlx5_core]
  mlx5_fs_destroy_fs_actions+0x8b/0x152 [mlx5_core]
  mlx5_cmd_hws_delete_fte+0x5a/0xa0 [mlx5_core]
  del_hw_fte+0x1ce/0x260 [mlx5_core]
  mlx5_del_flow_rules+0x12d/0x240 [mlx5_core]
  ? ttwu_queue_wakelist+0xf4/0x110
  mlx5_ib_destroy_flow+0x103/0x1b0 [mlx5_ib]
  uverbs_free_flow+0x20/0x50 [ib_uverbs]
  destroy_hw_idr_uobject+0x1b/0x50 [ib_uverbs]
  uverbs_destroy_uobject+0x34/0x1a0 [ib_uverbs]
  uobj_destroy+0x3c/0x80 [ib_uverbs]
  ib_uverbs_run_method+0x23e/0x360 [ib_uverbs]
  ? uverbs_finalize_object+0x60/0x60 [ib_uverbs]
  ib_uverbs_cmd_verbs+0x14f/0x2c0 [ib_uverbs]
  ? do_tty_write+0x1a9/0x270
  ? file_tty_write.constprop.0+0x98/0xc0
  ? new_sync_write+0xfc/0x190
  ib_uverbs_ioctl+0xd7/0x160 [ib_uverbs]
  __x64_sys_ioctl+0x87/0xc0
  do_syscall_64+0x59/0x90&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-52rq-cpwv-rvvm</guid>
    </item>
    <item>
      <title>openSUSE-SU-2025:20091-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2025:20091-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2025:20091-1</guid>
    </item>
    <item>
      <title>SUSE-SU-2025:21080-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2025:21080-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2025:21080-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-39979</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-39979</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 96 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: net/mlx5: fs, fix UAF in flow counter release Fix a kernel trace [1] caused by releasing an HWS action of a local flow counter in mlx5_cmd_hws_delete_fte(), where the HWS action refcount and mutex were not initialized and the counter struct could already be freed when deleting the rule. Fix it by adding the missing initializations and adding refcount for the local flow counter struct. [1] Kernel log:  Call Trace:   &amp;lt;TASK&amp;gt;   dump_stack_lvl+0x34/0x48   mlx5_fs_put_hws_action.part.0.cold+0x21/0x94 [mlx5_core]   mlx5_fc_put_hws_action+0x96/0xad [mlx5_core]   mlx5_fs_destroy_fs_actions+0x8b/0x152 [mlx5_core]   mlx5_cmd_hws_delete_fte+0x5a/0xa0 [mlx5_core]   del_hw_fte+0x1ce/0x260 [mlx5_core]   mlx5_del_flow_rules+0x12d/0x240 [mlx5_core]   ? ttwu_queue_wakelist+0xf4/0x110   mlx5_ib_destroy_flow+0x103/0x1b0 [mlx5_ib]   uverbs_free_flow+0x20/0x50 [ib_uverbs]   destroy_hw_idr_uobject+0x1b/0x50 [ib_uverbs]   uverbs_destroy_uobject+0x34/0x1a0 [ib_uverbs]   uobj_destroy+0x3c/0x80 [ib_uverbs]   ib_uverbs_run_method+0x23e/0x360 [ib_uverbs]   ? uverbs_finalize_object+0x60/0x60 [ib_uverbs]   ib_uverbs_cmd_verbs+0x14f/0x2c0 [ib_uverbs]   ? do_tty_write+0x1a9/0x270   ? file_tty_write.constprop.0+0x98/0xc0   ? new_sync_write+0xfc/0x190   ib_uverbs_ioctl+0xd7/0x160 [ib_uverbs]   __x64_sys_ioctl+0x87/0xc0   do_syscall_64+0x59/0x90&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 96 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: net/mlx5: fs, fix UAF in flow counter release Fix a kernel trace [1] caused by releasing an HWS action of a local flow counter in mlx5_cmd_hws_delete_fte(), where the HWS action refcount and mutex were not initialized and the counter struct could already be freed when deleting the rule. Fix it by adding the missing initializations and adding refcount for the local flow counter struct. [1] Kernel log:  Call Trace:   &amp;lt;TASK&amp;gt;   dump_stack_lvl+0x34/0x48   mlx5_fs_put_hws_action.part.0.cold+0x21/0x94 [mlx5_core]   mlx5_fc_put_hws_action+0x96/0xad [mlx5_core]   mlx5_fs_destroy_fs_actions+0x8b/0x152 [mlx5_core]   mlx5_cmd_hws_delete_fte+0x5a/0xa0 [mlx5_core]   del_hw_fte+0x1ce/0x260 [mlx5_core]   mlx5_del_flow_rules+0x12d/0x240 [mlx5_core]   ? ttwu_queue_wakelist+0xf4/0x110   mlx5_ib_destroy_flow+0x103/0x1b0 [mlx5_ib]   uverbs_free_flow+0x20/0x50 [ib_uverbs]   destroy_hw_idr_uobject+0x1b/0x50 [ib_uverbs]   uverbs_destroy_uobject+0x34/0x1a0 [ib_uverbs]   uobj_destroy+0x3c/0x80 [ib_uverbs]   ib_uverbs_run_method+0x23e/0x360 [ib_uverbs]   ? uverbs_finalize_object+0x60/0x60 [ib_uverbs]   ib_uverbs_cmd_verbs+0x14f/0x2c0 [ib_uverbs]   ? do_tty_write+0x1a9/0x270   ? file_tty_write.constprop.0+0x98/0xc0   ? new_sync_write+0xfc/0x190   ib_uverbs_ioctl+0xd7/0x160 [ib_uverbs]   __x64_sys_ioctl+0x87/0xc0   do_syscall_64+0x59/0x90&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-39979</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-2298 — Linux Kernel: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2298</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux-Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen, Daten zu manipulieren und andere, nicht näher spezifizierte Angriffe durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux-Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen, Daten zu manipulieren und andere, nicht näher spezifizierte Angriffe durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2298</guid>
    </item>
  </channel>
</rss>
