<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 19:39:57 +0000</lastBuildDate>
    <item>
      <title>ALSA-2026:1143 — Important: kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:1143</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: kernel, AlmaLinux:9: kernel-64k, AlmaLinux:9: kernel-64k-core, AlmaLinux:9: kernel-64k-debug, AlmaLinux:9: kernel-64k-debug-core, AlmaLinux:9: kernel-64k-debug-devel, AlmaLinux:9: kernel-64k-debug-devel-matched, AlmaLinux:9: kernel-64k-debug-modules, AlmaLinux:9: kernel-64k-debug-modules-core, AlmaLinux:9: kernel-64k-debug-modules-extra and 64 more&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: Linux kernel: Use-after-free in device mapper due to race condition in zone reporting (CVE-2025-38141)
  * kernel: Linux kernel use-after-free in eventpoll (CVE-2025-38349)
  * kernel: drm/xe: Fix vm_bind_ioctl double free bug (CVE-2025-38731)
  * kernel: Linux kernel: vsock vulnerability may lead to memory corruption (CVE-2025-40248)
  * kernel: mptcp: fix race condition in mptcp_schedule_work() (CVE-2025-40258)
  * kernel: Linux kernel: Out-of-bounds write in Bluetooth MGMT can lead to information disclosure and denial of service (CVE-2025-40294)
  * kernel: net: atlantic: fix fragment overflow handling in RX path (CVE-2025-68301)
  * kernel: Bluetooth: hci_sock: Prevent race in socket write iter and sock bind (CVE-2025-68305)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: kernel, AlmaLinux:9: kernel-64k, AlmaLinux:9: kernel-64k-core, AlmaLinux:9: kernel-64k-debug, AlmaLinux:9: kernel-64k-debug-core, AlmaLinux:9: kernel-64k-debug-devel, AlmaLinux:9: kernel-64k-debug-devel-matched, AlmaLinux:9: kernel-64k-debug-modules, AlmaLinux:9: kernel-64k-debug-modules-core, AlmaLinux:9: kernel-64k-debug-modules-extra and 64 more&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: Linux kernel: Use-after-free in device mapper due to race condition in zone reporting (CVE-2025-38141)
  * kernel: Linux kernel use-after-free in eventpoll (CVE-2025-38349)
  * kernel: drm/xe: Fix vm_bind_ioctl double free bug (CVE-2025-38731)
  * kernel: Linux kernel: vsock vulnerability may lead to memory corruption (CVE-2025-40248)
  * kernel: mptcp: fix race condition in mptcp_schedule_work() (CVE-2025-40258)
  * kernel: Linux kernel: Out-of-bounds write in Bluetooth MGMT can lead to information disclosure and denial of service (CVE-2025-40294)
  * kernel: net: atlantic: fix fragment overflow handling in RX path (CVE-2025-68301)
  * kernel: Bluetooth: hci_sock: Prevent race in socket write iter and sock bind (CVE-2025-68305)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:1143</guid>
    </item>
    <item>
      <title>bdu:2025-15941</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-15941</link>
      <description>bdu:2025-15941</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-15941</guid>
    </item>
    <item>
      <title>BELL-CVE-2025-40258</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2025-40258</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2025-40258</guid>
    </item>
    <item>
      <title>certfr-2025-avi-1078 — De multiples vulnérabilités ont été découvertes dans les produits Microsoft. Elles permettent à un attaquant de provoqu…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-1078</link>
      <description>certfr-2025-avi-1078</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-1078</guid>
    </item>
    <item>
      <title>EUVD-2026-347396</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-347396</link>
      <description>EUVD-2026-347396</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-347396</guid>
    </item>
    <item>
      <title>fkie_cve-2025-40258</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-40258</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;mptcp: fix race condition in mptcp_schedule_work()&lt;/p&gt;
&lt;p&gt;syzbot reported use-after-free in mptcp_schedule_work() [1]&lt;/p&gt;
&lt;p&gt;Issue here is that mptcp_schedule_work() schedules a work,
then gets a refcount on sk-&amp;gt;sk_refcnt if the work was scheduled.
This refcount will be released by mptcp_worker().&lt;/p&gt;
&lt;p&gt;[A] if (schedule_work(...)) {
[B]     sock_hold(sk);
        return true;
    }&lt;/p&gt;
&lt;p&gt;Problem is that mptcp_worker() can run immediately and complete before [B]&lt;/p&gt;
&lt;p&gt;We need instead :&lt;/p&gt;
&lt;p&gt;sock_hold(sk);
    if (schedule_work(...))
        return true;
    sock_put(sk);&lt;/p&gt;
&lt;p&gt;[1]
refcount_t: addition on 0; use-after-free.
 WARNING: CPU: 1 PID: 29 at lib/refcount.c:25 refcount_warn_saturate+0xfa/0x1d0 lib/refcount.c:25
Call Trace:
 &amp;lt;TASK&amp;gt;
 __refcount_add include/linux/refcount.h:-1 [inline]
  __refcount_inc include/linux/refcount.h:366 [inline]
  refcount_inc include/linux/refcount.h:383 [inline]
  sock_hold include/net/sock.h:816 [inline]
  mptcp_schedule_work+0x164/0x1a0 net/mptcp/protocol.c:943
  mptcp_tout_timer+0x21/0xa0 net/mptcp/protocol.c:2316
  call_timer_fn+0x17e/0x5f0 kernel/time/timer.c:1747
  expire_timers kernel/time/timer.c:1798 [inline]
  __run_timers kernel/time/timer.c:2372 [inline]
  __run_timer_base+0x648/0x970 kernel/time/timer.c:2384
  run_timer_base kernel/time/timer.c:2393 [inline]
  run_timer_softirq+0xb7/0x180 kernel/time/timer.c:2403
  handle_softirqs+0x22f/0x710 kernel/softirq.c:622
  __do_softirq kernel/softirq…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;mptcp: fix race condition in mptcp_schedule_work()&lt;/p&gt;
&lt;p&gt;syzbot reported use-after-free in mptcp_schedule_work() [1]&lt;/p&gt;
&lt;p&gt;Issue here is that mptcp_schedule_work() schedules a work,
then gets a refcount on sk-&amp;gt;sk_refcnt if the work was scheduled.
This refcount will be released by mptcp_worker().&lt;/p&gt;
&lt;p&gt;[A] if (schedule_work(...)) {
[B]     sock_hold(sk);
        return true;
    }&lt;/p&gt;
&lt;p&gt;Problem is that mptcp_worker() can run immediately and complete before [B]&lt;/p&gt;
&lt;p&gt;We need instead :&lt;/p&gt;
&lt;p&gt;sock_hold(sk);
    if (schedule_work(...))
        return true;
    sock_put(sk);&lt;/p&gt;
&lt;p&gt;[1]
refcount_t: addition on 0; use-after-free.
 WARNING: CPU: 1 PID: 29 at lib/refcount.c:25 refcount_warn_saturate+0xfa/0x1d0 lib/refcount.c:25
Call Trace:
 &amp;lt;TASK&amp;gt;
 __refcount_add include/linux/refcount.h:-1 [inline]
  __refcount_inc include/linux/refcount.h:366 [inline]
  refcount_inc include/linux/refcount.h:383 [inline]
  sock_hold include/net/sock.h:816 [inline]
  mptcp_schedule_work+0x164/0x1a0 net/mptcp/protocol.c:943
  mptcp_tout_timer+0x21/0xa0 net/mptcp/protocol.c:2316
  call_timer_fn+0x17e/0x5f0 kernel/time/timer.c:1747
  expire_timers kernel/time/timer.c:1798 [inline]
  __run_timers kernel/time/timer.c:2372 [inline]
  __run_timer_base+0x648/0x970 kernel/time/timer.c:2384
  run_timer_base kernel/time/timer.c:2393 [inline]
  run_timer_softirq+0xb7/0x180 kernel/time/timer.c:2403
  handle_softirqs+0x22f/0x710 kernel/softirq.c:622
  __do_softirq kernel/softirq…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-40258</guid>
    </item>
    <item>
      <title>GHSA-86fp-6jqc-qg25</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-86fp-6jqc-qg25</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;mptcp: fix race condition in mptcp_schedule_work()&lt;/p&gt;
&lt;p&gt;syzbot reported use-after-free in mptcp_schedule_work() [1]&lt;/p&gt;
&lt;p&gt;Issue here is that mptcp_schedule_work() schedules a work,
then gets a refcount on sk-&amp;gt;sk_refcnt if the work was scheduled.
This refcount will be released by mptcp_worker().&lt;/p&gt;
&lt;p&gt;[A] if (schedule_work(...)) {
[B]     sock_hold(sk);
        return true;
    }&lt;/p&gt;
&lt;p&gt;Problem is that mptcp_worker() can run immediately and complete before [B]&lt;/p&gt;
&lt;p&gt;We need instead :&lt;/p&gt;
&lt;p&gt;sock_hold(sk);
    if (schedule_work(...))
        return true;
    sock_put(sk);&lt;/p&gt;
&lt;p&gt;[1]
refcount_t: addition on 0; use-after-free.
 WARNING: CPU: 1 PID: 29 at lib/refcount.c:25 refcount_warn_saturate+0xfa/0x1d0 lib/refcount.c:25
Call Trace:
 &amp;lt;TASK&amp;gt;
 __refcount_add include/linux/refcount.h:-1 [inline]
  __refcount_inc include/linux/refcount.h:366 [inline]
  refcount_inc include/linux/refcount.h:383 [inline]
  sock_hold include/net/sock.h:816 [inline]
  mptcp_schedule_work+0x164/0x1a0 net/mptcp/protocol.c:943
  mptcp_tout_timer+0x21/0xa0 net/mptcp/protocol.c:2316
  call_timer_fn+0x17e/0x5f0 kernel/time/timer.c:1747
  expire_timers kernel/time/timer.c:1798 [inline]
  __run_timers kernel/time/timer.c:2372 [inline]
  __run_timer_base+0x648/0x970 kernel/time/timer.c:2384
  run_timer_base kernel/time/timer.c:2393 [inline]
  run_timer_softirq+0xb7/0x180 kernel/time/timer.c:2403
  handle_softirqs+0x22f/0x710 kernel/softirq.c:622
  __do_softirq kernel/softirq…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;mptcp: fix race condition in mptcp_schedule_work()&lt;/p&gt;
&lt;p&gt;syzbot reported use-after-free in mptcp_schedule_work() [1]&lt;/p&gt;
&lt;p&gt;Issue here is that mptcp_schedule_work() schedules a work,
then gets a refcount on sk-&amp;gt;sk_refcnt if the work was scheduled.
This refcount will be released by mptcp_worker().&lt;/p&gt;
&lt;p&gt;[A] if (schedule_work(...)) {
[B]     sock_hold(sk);
        return true;
    }&lt;/p&gt;
&lt;p&gt;Problem is that mptcp_worker() can run immediately and complete before [B]&lt;/p&gt;
&lt;p&gt;We need instead :&lt;/p&gt;
&lt;p&gt;sock_hold(sk);
    if (schedule_work(...))
        return true;
    sock_put(sk);&lt;/p&gt;
&lt;p&gt;[1]
refcount_t: addition on 0; use-after-free.
 WARNING: CPU: 1 PID: 29 at lib/refcount.c:25 refcount_warn_saturate+0xfa/0x1d0 lib/refcount.c:25
Call Trace:
 &amp;lt;TASK&amp;gt;
 __refcount_add include/linux/refcount.h:-1 [inline]
  __refcount_inc include/linux/refcount.h:366 [inline]
  refcount_inc include/linux/refcount.h:383 [inline]
  sock_hold include/net/sock.h:816 [inline]
  mptcp_schedule_work+0x164/0x1a0 net/mptcp/protocol.c:943
  mptcp_tout_timer+0x21/0xa0 net/mptcp/protocol.c:2316
  call_timer_fn+0x17e/0x5f0 kernel/time/timer.c:1747
  expire_timers kernel/time/timer.c:1798 [inline]
  __run_timers kernel/time/timer.c:2372 [inline]
  __run_timer_base+0x648/0x970 kernel/time/timer.c:2384
  run_timer_base kernel/time/timer.c:2393 [inline]
  run_timer_softirq+0xb7/0x180 kernel/time/timer.c:2403
  handle_softirqs+0x22f/0x710 kernel/softirq.c:622
  __do_softirq kernel/softirq…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-86fp-6jqc-qg25</guid>
    </item>
    <item>
      <title>ICSA-26-188-05 — Siemens SINEC OS</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-26-188-05</link>
      <description>&lt;p&gt;A vulnerability has been found in GNU elfutils 0.192 and classified as critical. This vulnerability affects the function __libdw_thread_tail in the library libdw_alloc.c of the component eu-readelf. The manipulation of the argument w leads to memory corruption. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The name of the patch is 2636426a091bd6c6f7f02e49ab20d4cdc6bfc753. It is recommended to apply a patch to fix this issue. A vulnerability classified as problematic was found in GNU elfutils 0.192. This vulnerability affects the function elf_strptr in the library /libelf/elf_strptr.c of the component eu-strip. The manipulation leads to denial of service. It is possible to launch the attack on the local host. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The name of the patch is b16f441cca0a4841050e3215a9f120a6d8aea918. It is recommended to apply a patch to fix this issue. A flaw was found in how GLib’s GString manages memory when adding data to strings. If a string is already very large, combining it with more input can cause a hidden overflow in the size calculation. This makes the system think it has enough memory when it doesn’t. As a result, data may be written past the end of the allocated memory, leading to crashes or memory corrup…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability has been found in GNU elfutils 0.192 and classified as critical. This vulnerability affects the function __libdw_thread_tail in the library libdw_alloc.c of the component eu-readelf. The manipulation of the argument w leads to memory corruption. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The name of the patch is 2636426a091bd6c6f7f02e49ab20d4cdc6bfc753. It is recommended to apply a patch to fix this issue. A vulnerability classified as problematic was found in GNU elfutils 0.192. This vulnerability affects the function elf_strptr in the library /libelf/elf_strptr.c of the component eu-strip. The manipulation leads to denial of service. It is possible to launch the attack on the local host. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The name of the patch is b16f441cca0a4841050e3215a9f120a6d8aea918. It is recommended to apply a patch to fix this issue. A flaw was found in how GLib’s GString manages memory when adding data to strings. If a string is already very large, combining it with more input can cause a hidden overflow in the size calculation. This makes the system think it has enough memory when it doesn’t. As a result, data may be written past the end of the allocated memory, leading to crashes or memory corrup…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-26-188-05</guid>
    </item>
    <item>
      <title>msrc_CVE-2025-40258 — mptcp: fix race condition in mptcp_schedule_work()</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2025-40258</link>
      <description>msrc_CVE-2025-40258</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2025-40258</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:20145-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:20145-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:20145-1</guid>
    </item>
    <item>
      <title>RHSA-2026:1194 — Red Hat Security Advisory: kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:1194</link>
      <description>&lt;p&gt;kernel: Linux kernel: Information disclosure and denial of service in ntb_hw_switchtec module kernel: Linux kernel drm/xe: Out-of-bounds shift in TLB invalidation kernel: Linux kernel (openvswitch): Denial of Service and limited data exposure via improper key length validation kernel: Linux kernel: irqchip/gic-v2m use-after-free vulnerability kernel: drm/xe: Use local fence in error path of xe_migrate_clear kernel: Linux kernel: Denial of service due to use-after-free in scsi: lpfc kernel: Bluetooth: ISO: Fix possible UAF on iso_conn_free kernel: devlink: rate: Unset parent pointer in devl_rate_nodes_destroy kernel: mptcp: fix race condition in mptcp_schedule_work() kernel: drm/vmwgfx: Validate command header size against SVGA_CMD_MAX_DATASIZE kernel: Bluetooth: hci_sync: fix race in hci_cmd_sync_dequeue_once&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;kernel: Linux kernel: Information disclosure and denial of service in ntb_hw_switchtec module kernel: Linux kernel drm/xe: Out-of-bounds shift in TLB invalidation kernel: Linux kernel (openvswitch): Denial of Service and limited data exposure via improper key length validation kernel: Linux kernel: irqchip/gic-v2m use-after-free vulnerability kernel: drm/xe: Use local fence in error path of xe_migrate_clear kernel: Linux kernel: Denial of service due to use-after-free in scsi: lpfc kernel: Bluetooth: ISO: Fix possible UAF on iso_conn_free kernel: devlink: rate: Unset parent pointer in devl_rate_nodes_destroy kernel: mptcp: fix race condition in mptcp_schedule_work() kernel: drm/vmwgfx: Validate command header size against SVGA_CMD_MAX_DATASIZE kernel: Bluetooth: hci_sync: fix race in hci_cmd_sync_dequeue_once&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:1194</guid>
    </item>
    <item>
      <title>SSA-253495 — SSA-253495: Multiple Vulnerabilities in SINEC OS before V4.0</title>
      <link>https://cve.radiocsirt.org/vuln/ssa-253495</link>
      <description>&lt;p&gt;A vulnerability has been found in GNU elfutils 0.192 and classified as critical. This vulnerability affects the function __libdw_thread_tail in the library libdw_alloc.c of the component eu-readelf. The manipulation of the argument w leads to memory corruption. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The name of the patch is 2636426a091bd6c6f7f02e49ab20d4cdc6bfc753. It is recommended to apply a patch to fix this issue. A vulnerability classified as problematic was found in GNU elfutils 0.192. This vulnerability affects the function elf_strptr in the library /libelf/elf_strptr.c of the component eu-strip. The manipulation leads to denial of service. It is possible to launch the attack on the local host. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The name of the patch is b16f441cca0a4841050e3215a9f120a6d8aea918. It is recommended to apply a patch to fix this issue. A flaw was found in how GLib’s GString manages memory when adding data to strings. If a string is already very large, combining it with more input can cause a hidden overflow in the size calculation. This makes the system think it has enough memory when it doesn’t. As a result, data may be written past the end of the allocated memory, leading to crashes or memory corrup…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability has been found in GNU elfutils 0.192 and classified as critical. This vulnerability affects the function __libdw_thread_tail in the library libdw_alloc.c of the component eu-readelf. The manipulation of the argument w leads to memory corruption. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The name of the patch is 2636426a091bd6c6f7f02e49ab20d4cdc6bfc753. It is recommended to apply a patch to fix this issue. A vulnerability classified as problematic was found in GNU elfutils 0.192. This vulnerability affects the function elf_strptr in the library /libelf/elf_strptr.c of the component eu-strip. The manipulation leads to denial of service. It is possible to launch the attack on the local host. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The name of the patch is b16f441cca0a4841050e3215a9f120a6d8aea918. It is recommended to apply a patch to fix this issue. A flaw was found in how GLib’s GString manages memory when adding data to strings. If a string is already very large, combining it with more input can cause a hidden overflow in the size calculation. This makes the system think it has enough memory when it doesn’t. As a result, data may be written past the end of the allocated memory, leading to crashes or memory corrup…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ssa-253495</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:0263-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:0263-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:0263-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-40258</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-40258</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 178 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: mptcp: fix race condition in mptcp_schedule_work() syzbot reported use-after-free in mptcp_schedule_work() [1] Issue here is that mptcp_schedule_work() schedules a work, then gets a refcount on sk-&amp;gt;sk_refcnt if the work was scheduled. This refcount will be released by mptcp_worker(). [A] if (schedule_work(...)) { [B]     sock_hold(sk);         return true;     } Problem is that mptcp_worker() can run immediately and complete before [B] We need instead :     sock_hold(sk);     if (schedule_work(...))         return true;     sock_put(sk); [1] refcount_t: addition on 0; use-after-free.  WARNING: CPU: 1 PID: 29 at lib/refcount.c:25 refcount_warn_saturate+0xfa/0x1d0 lib/refcount.c:25 Call Trace:  &amp;lt;TASK&amp;gt;  __refcount_add include/linux/refcount.h:-1 [inline]   __refcount_inc include/linux/refcount.h:366 [inline]   refcount_inc include/linux/refcount.h:383 [inline]   sock_hold include/net/sock.h:816 [inline]   mptcp_schedule_work+0x164/0x1a0 net/mptcp/protocol.c:943   mptcp_tout_timer+0x21/0xa0 net/mptcp/protocol.c:2316   call_timer_fn+0x17e/0x5f0 kernel/time/timer.c:1747   expire_timers kernel/time/timer.c:1798 [inline]   __run_timers kernel/time/timer.c:2372 [inline]   __run_timer_base+0x648/0x970 kernel/time/timer.c:2384   run_timer_base kernel/time/timer.c:2393 [inline]   run_timer_softirq+0xb7/0x180 kernel/time/timer.c:2403   handle_softirqs+0x22f/0x710 kernel/softirq.c:622   __do_softirq kernel/softirq.c:656 […&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 178 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: mptcp: fix race condition in mptcp_schedule_work() syzbot reported use-after-free in mptcp_schedule_work() [1] Issue here is that mptcp_schedule_work() schedules a work, then gets a refcount on sk-&amp;gt;sk_refcnt if the work was scheduled. This refcount will be released by mptcp_worker(). [A] if (schedule_work(...)) { [B]     sock_hold(sk);         return true;     } Problem is that mptcp_worker() can run immediately and complete before [B] We need instead :     sock_hold(sk);     if (schedule_work(...))         return true;     sock_put(sk); [1] refcount_t: addition on 0; use-after-free.  WARNING: CPU: 1 PID: 29 at lib/refcount.c:25 refcount_warn_saturate+0xfa/0x1d0 lib/refcount.c:25 Call Trace:  &amp;lt;TASK&amp;gt;  __refcount_add include/linux/refcount.h:-1 [inline]   __refcount_inc include/linux/refcount.h:366 [inline]   refcount_inc include/linux/refcount.h:383 [inline]   sock_hold include/net/sock.h:816 [inline]   mptcp_schedule_work+0x164/0x1a0 net/mptcp/protocol.c:943   mptcp_tout_timer+0x21/0xa0 net/mptcp/protocol.c:2316   call_timer_fn+0x17e/0x5f0 kernel/time/timer.c:1747   expire_timers kernel/time/timer.c:1798 [inline]   __run_timers kernel/time/timer.c:2372 [inline]   __run_timer_base+0x648/0x970 kernel/time/timer.c:2384   run_timer_base kernel/time/timer.c:2393 [inline]   run_timer_softirq+0xb7/0x180 kernel/time/timer.c:2403   handle_softirqs+0x22f/0x710 kernel/softirq.c:622   __do_softirq kernel/softirq.c:656 […&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-40258</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-2747 — Linux Kernel: Mehrere Schwachstellen ermöglichen Denial of Service</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2747</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen Denial-of-Service-Zustand zu erzeugen oder weitere, nicht spezifizierte Auswirkungen zu erlangen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen Denial-of-Service-Zustand zu erzeugen oder weitere, nicht spezifizierte Auswirkungen zu erlangen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2747</guid>
    </item>
  </channel>
</rss>
