<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 18:39:56 +0000</lastBuildDate>
    <item>
      <title>bdu:2025-14699</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-14699</link>
      <description>bdu:2025-14699</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-14699</guid>
    </item>
    <item>
      <title>BELL-CVE-2025-40186</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2025-40186</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2025-40186</guid>
    </item>
    <item>
      <title>certfr-2025-avi-1048 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de Debian LTS. Certaines d'entre elles permettent à…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-1048</link>
      <description>certfr-2025-avi-1048</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-1048</guid>
    </item>
    <item>
      <title>EUVD-2026-347366</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-347366</link>
      <description>EUVD-2026-347366</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-347366</guid>
    </item>
    <item>
      <title>fkie_cve-2025-40186</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-40186</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;tcp: Don&amp;#39;t call reqsk_fastopen_remove() in tcp_conn_request().&lt;/p&gt;
&lt;p&gt;syzbot reported the splat below in tcp_conn_request(). [0]&lt;/p&gt;
&lt;p&gt;If a listener is close()d while a TFO socket is being processed in
tcp_conn_request(), inet_csk_reqsk_queue_add() does not set reqsk-&amp;gt;sk
and calls inet_child_forget(), which calls tcp_disconnect() for the
TFO socket.&lt;/p&gt;
&lt;p&gt;After the cited commit, tcp_disconnect() calls reqsk_fastopen_remove(),
where reqsk_put() is called due to !reqsk-&amp;gt;sk.&lt;/p&gt;
&lt;p&gt;Then, reqsk_fastopen_remove() in tcp_conn_request() decrements the
last req-&amp;gt;rsk_refcnt and frees reqsk, and __reqsk_free() at the
drop_and_free label causes the refcount underflow for the listener
and double-free of the reqsk.&lt;/p&gt;
&lt;p&gt;Let&amp;#39;s remove reqsk_fastopen_remove() in tcp_conn_request().&lt;/p&gt;
&lt;p&gt;Note that other callers make sure tp-&amp;gt;fastopen_rsk is not NULL.&lt;/p&gt;
&lt;p&gt;[0]:
refcount_t: underflow; use-after-free.
WARNING: CPU: 12 PID: 5563 at lib/refcount.c:28 refcount_warn_saturate (lib/refcount.c:28)
Modules linked in:
CPU: 12 UID: 0 PID: 5563 Comm: syz-executor Not tainted syzkaller #0 PREEMPT(full)
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 07/12/2025
RIP: 0010:refcount_warn_saturate (lib/refcount.c:28)
Code: ab e8 8e b4 98 ff 0f 0b c3 cc cc cc cc cc 80 3d a4 e4 d6 01 00 75 9c c6 05 9b e4 d6 01 01 48 c7 c7 e8 df fb ab e8 6a b4 98 ff &amp;lt;0f&amp;gt; 0b e9 03 5b 76 00 cc 80 3d 7d e4 d6 01 00 0f 85 74 ff ff ff c6
RSP: 0018:ffffa79fc0304a98 EFLAGS…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;tcp: Don&amp;#39;t call reqsk_fastopen_remove() in tcp_conn_request().&lt;/p&gt;
&lt;p&gt;syzbot reported the splat below in tcp_conn_request(). [0]&lt;/p&gt;
&lt;p&gt;If a listener is close()d while a TFO socket is being processed in
tcp_conn_request(), inet_csk_reqsk_queue_add() does not set reqsk-&amp;gt;sk
and calls inet_child_forget(), which calls tcp_disconnect() for the
TFO socket.&lt;/p&gt;
&lt;p&gt;After the cited commit, tcp_disconnect() calls reqsk_fastopen_remove(),
where reqsk_put() is called due to !reqsk-&amp;gt;sk.&lt;/p&gt;
&lt;p&gt;Then, reqsk_fastopen_remove() in tcp_conn_request() decrements the
last req-&amp;gt;rsk_refcnt and frees reqsk, and __reqsk_free() at the
drop_and_free label causes the refcount underflow for the listener
and double-free of the reqsk.&lt;/p&gt;
&lt;p&gt;Let&amp;#39;s remove reqsk_fastopen_remove() in tcp_conn_request().&lt;/p&gt;
&lt;p&gt;Note that other callers make sure tp-&amp;gt;fastopen_rsk is not NULL.&lt;/p&gt;
&lt;p&gt;[0]:
refcount_t: underflow; use-after-free.
WARNING: CPU: 12 PID: 5563 at lib/refcount.c:28 refcount_warn_saturate (lib/refcount.c:28)
Modules linked in:
CPU: 12 UID: 0 PID: 5563 Comm: syz-executor Not tainted syzkaller #0 PREEMPT(full)
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 07/12/2025
RIP: 0010:refcount_warn_saturate (lib/refcount.c:28)
Code: ab e8 8e b4 98 ff 0f 0b c3 cc cc cc cc cc 80 3d a4 e4 d6 01 00 75 9c c6 05 9b e4 d6 01 01 48 c7 c7 e8 df fb ab e8 6a b4 98 ff &amp;lt;0f&amp;gt; 0b e9 03 5b 76 00 cc 80 3d 7d e4 d6 01 00 0f 85 74 ff ff ff c6
RSP: 0018:ffffa79fc0304a98 EFLAGS…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-40186</guid>
    </item>
    <item>
      <title>GHSA-qx52-pj36-489j</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-qx52-pj36-489j</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;tcp: Don&amp;#39;t call reqsk_fastopen_remove() in tcp_conn_request().&lt;/p&gt;
&lt;p&gt;syzbot reported the splat below in tcp_conn_request(). [0]&lt;/p&gt;
&lt;p&gt;If a listener is close()d while a TFO socket is being processed in
tcp_conn_request(), inet_csk_reqsk_queue_add() does not set reqsk-&amp;gt;sk
and calls inet_child_forget(), which calls tcp_disconnect() for the
TFO socket.&lt;/p&gt;
&lt;p&gt;After the cited commit, tcp_disconnect() calls reqsk_fastopen_remove(),
where reqsk_put() is called due to !reqsk-&amp;gt;sk.&lt;/p&gt;
&lt;p&gt;Then, reqsk_fastopen_remove() in tcp_conn_request() decrements the
last req-&amp;gt;rsk_refcnt and frees reqsk, and __reqsk_free() at the
drop_and_free label causes the refcount underflow for the listener
and double-free of the reqsk.&lt;/p&gt;
&lt;p&gt;Let&amp;#39;s remove reqsk_fastopen_remove() in tcp_conn_request().&lt;/p&gt;
&lt;p&gt;Note that other callers make sure tp-&amp;gt;fastopen_rsk is not NULL.&lt;/p&gt;
&lt;p&gt;[0]:
refcount_t: underflow; use-after-free.
WARNING: CPU: 12 PID: 5563 at lib/refcount.c:28 refcount_warn_saturate (lib/refcount.c:28)
Modules linked in:
CPU: 12 UID: 0 PID: 5563 Comm: syz-executor Not tainted syzkaller #0 PREEMPT(full)
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 07/12/2025
RIP: 0010:refcount_warn_saturate (lib/refcount.c:28)
Code: ab e8 8e b4 98 ff 0f 0b c3 cc cc cc cc cc 80 3d a4 e4 d6 01 00 75 9c c6 05 9b e4 d6 01 01 48 c7 c7 e8 df fb ab e8 6a b4 98 ff &amp;lt;0f&amp;gt; 0b e9 03 5b 76 00 cc 80 3d 7d e4 d6 01 00 0f 85 74 ff ff ff c6
RSP: 0018:ffffa79fc0304a98 EFLAGS…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;tcp: Don&amp;#39;t call reqsk_fastopen_remove() in tcp_conn_request().&lt;/p&gt;
&lt;p&gt;syzbot reported the splat below in tcp_conn_request(). [0]&lt;/p&gt;
&lt;p&gt;If a listener is close()d while a TFO socket is being processed in
tcp_conn_request(), inet_csk_reqsk_queue_add() does not set reqsk-&amp;gt;sk
and calls inet_child_forget(), which calls tcp_disconnect() for the
TFO socket.&lt;/p&gt;
&lt;p&gt;After the cited commit, tcp_disconnect() calls reqsk_fastopen_remove(),
where reqsk_put() is called due to !reqsk-&amp;gt;sk.&lt;/p&gt;
&lt;p&gt;Then, reqsk_fastopen_remove() in tcp_conn_request() decrements the
last req-&amp;gt;rsk_refcnt and frees reqsk, and __reqsk_free() at the
drop_and_free label causes the refcount underflow for the listener
and double-free of the reqsk.&lt;/p&gt;
&lt;p&gt;Let&amp;#39;s remove reqsk_fastopen_remove() in tcp_conn_request().&lt;/p&gt;
&lt;p&gt;Note that other callers make sure tp-&amp;gt;fastopen_rsk is not NULL.&lt;/p&gt;
&lt;p&gt;[0]:
refcount_t: underflow; use-after-free.
WARNING: CPU: 12 PID: 5563 at lib/refcount.c:28 refcount_warn_saturate (lib/refcount.c:28)
Modules linked in:
CPU: 12 UID: 0 PID: 5563 Comm: syz-executor Not tainted syzkaller #0 PREEMPT(full)
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 07/12/2025
RIP: 0010:refcount_warn_saturate (lib/refcount.c:28)
Code: ab e8 8e b4 98 ff 0f 0b c3 cc cc cc cc cc 80 3d a4 e4 d6 01 00 75 9c c6 05 9b e4 d6 01 01 48 c7 c7 e8 df fb ab e8 6a b4 98 ff &amp;lt;0f&amp;gt; 0b e9 03 5b 76 00 cc 80 3d 7d e4 d6 01 00 0f 85 74 ff ff ff c6
RSP: 0018:ffffa79fc0304a98 EFLAGS…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-qx52-pj36-489j</guid>
    </item>
    <item>
      <title>openSUSE-SU-2025:20172-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2025:20172-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2025:20172-1</guid>
    </item>
    <item>
      <title>RHSA-2025:22387 — Red Hat Security Advisory: kernel-rt security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2025:22387</link>
      <description>&lt;p&gt;kernel: nbd: fix incomplete validation of ioctl arg kernel: nfsd: handle get_client_locked() failure in nfsd4_setclientid_confirm() kernel: smb: client: fix race with concurrent opens in rename(2) kernel: mm/memory-failure: fix VM_BUG_ON_PAGE(PagePoisoned(page)) when unpoison memory kernel: e1000e: fix heap overflow in e1000_set_eeprom kernel: tcp: Clear tcp_sk(sk)-&amp;gt;fastopen_rsk in tcp_disconnect() kernel: Linux kernel: Privilege escalation or Denial of Service via TCP Fast Open vulnerability&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;kernel: nbd: fix incomplete validation of ioctl arg kernel: nfsd: handle get_client_locked() failure in nfsd4_setclientid_confirm() kernel: smb: client: fix race with concurrent opens in rename(2) kernel: mm/memory-failure: fix VM_BUG_ON_PAGE(PagePoisoned(page)) when unpoison memory kernel: e1000e: fix heap overflow in e1000_set_eeprom kernel: tcp: Clear tcp_sk(sk)-&amp;gt;fastopen_rsk in tcp_disconnect() kernel: Linux kernel: Privilege escalation or Denial of Service via TCP Fast Open vulnerability&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2025:22387</guid>
    </item>
    <item>
      <title>SUSE-SU-2025:4422-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2025:4422-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2025:4422-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-40186</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-40186</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 92 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: tcp: Don&amp;#39;t call reqsk_fastopen_remove() in tcp_conn_request(). syzbot reported the splat below in tcp_conn_request(). [0] If a listener is close()d while a TFO socket is being processed in tcp_conn_request(), inet_csk_reqsk_queue_add() does not set reqsk-&amp;gt;sk and calls inet_child_forget(), which calls tcp_disconnect() for the TFO socket. After the cited commit, tcp_disconnect() calls reqsk_fastopen_remove(), where reqsk_put() is called due to !reqsk-&amp;gt;sk. Then, reqsk_fastopen_remove() in tcp_conn_request() decrements the last req-&amp;gt;rsk_refcnt and frees reqsk, and __reqsk_free() at the drop_and_free label causes the refcount underflow for the listener and double-free of the reqsk. Let&amp;#39;s remove reqsk_fastopen_remove() in tcp_conn_request(). Note that other callers make sure tp-&amp;gt;fastopen_rsk is not NULL. [0]: refcount_t: underflow; use-after-free. WARNING: CPU: 12 PID: 5563 at lib/refcount.c:28 refcount_warn_saturate (lib/refcount.c:28) Modules linked in: CPU: 12 UID: 0 PID: 5563 Comm: syz-executor Not tainted syzkaller #0 PREEMPT(full) Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 07/12/2025 RIP: 0010:refcount_warn_saturate (lib/refcount.c:28) Code: ab e8 8e b4 98 ff 0f 0b c3 cc cc cc cc cc 80 3d a4 e4 d6 01 00 75 9c c6 05 9b e4 d6 01 01 48 c7 c7 e8 df fb ab e8 6a b4 98 ff &amp;lt;0f&amp;gt; 0b e9 03 5b 76 00 cc 80 3d 7d e4 d6 01 00 0f 85 74 ff ff ff c6 RSP: 0018:ffffa79fc0304a98 EFLAGS: 000102…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 92 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: tcp: Don&amp;#39;t call reqsk_fastopen_remove() in tcp_conn_request(). syzbot reported the splat below in tcp_conn_request(). [0] If a listener is close()d while a TFO socket is being processed in tcp_conn_request(), inet_csk_reqsk_queue_add() does not set reqsk-&amp;gt;sk and calls inet_child_forget(), which calls tcp_disconnect() for the TFO socket. After the cited commit, tcp_disconnect() calls reqsk_fastopen_remove(), where reqsk_put() is called due to !reqsk-&amp;gt;sk. Then, reqsk_fastopen_remove() in tcp_conn_request() decrements the last req-&amp;gt;rsk_refcnt and frees reqsk, and __reqsk_free() at the drop_and_free label causes the refcount underflow for the listener and double-free of the reqsk. Let&amp;#39;s remove reqsk_fastopen_remove() in tcp_conn_request(). Note that other callers make sure tp-&amp;gt;fastopen_rsk is not NULL. [0]: refcount_t: underflow; use-after-free. WARNING: CPU: 12 PID: 5563 at lib/refcount.c:28 refcount_warn_saturate (lib/refcount.c:28) Modules linked in: CPU: 12 UID: 0 PID: 5563 Comm: syz-executor Not tainted syzkaller #0 PREEMPT(full) Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 07/12/2025 RIP: 0010:refcount_warn_saturate (lib/refcount.c:28) Code: ab e8 8e b4 98 ff 0f 0b c3 cc cc cc cc cc 80 3d a4 e4 d6 01 00 75 9c c6 05 9b e4 d6 01 01 48 c7 c7 e8 df fb ab e8 6a b4 98 ff &amp;lt;0f&amp;gt; 0b e9 03 5b 76 00 cc 80 3d 7d e4 d6 01 00 0f 85 74 ff ff ff c6 RSP: 0018:ffffa79fc0304a98 EFLAGS: 000102…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-40186</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-2595 — Linux Kernel: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2595</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux-Kernel ausnutzen, um nicht näher spezifizierte Angriffe durchzuführen, die möglicherweise zu einer Denial-of-Service- Bedingung führen oder eine Speicherbeschädigung verursachen können.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux-Kernel ausnutzen, um nicht näher spezifizierte Angriffe durchzuführen, die möglicherweise zu einer Denial-of-Service- Bedingung führen oder eine Speicherbeschädigung verursachen können.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2595</guid>
    </item>
  </channel>
</rss>
