<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 19:10:11 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-00897</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-00897</link>
      <description>bdu:2026-00897</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-00897</guid>
    </item>
    <item>
      <title>BELL-CVE-2025-68758</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2025-68758</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2025-68758</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0108 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de SUSE. Certaines d'entre elles permettent à un at…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0108</link>
      <description>certfr-2026-avi-0108</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0108</guid>
    </item>
    <item>
      <title>EUVD-2026-315168</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-315168</link>
      <description>EUVD-2026-315168</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-315168</guid>
    </item>
    <item>
      <title>fkie_cve-2025-68758</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-68758</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;backlight: led-bl: Add devlink to supplier LEDs&lt;/p&gt;
&lt;p&gt;LED Backlight is a consumer of one or multiple LED class devices, but
devlink is currently unable to create correct supplier-producer links when
the supplier is a class device. It creates instead a link where the
supplier is the parent of the expected device.&lt;/p&gt;
&lt;p&gt;One consequence is that removal order is not correctly enforced.&lt;/p&gt;
&lt;p&gt;Issues happen for example with the following sections in a device tree
overlay:&lt;/p&gt;
&lt;p&gt;// An LED driver chip
    pca9632@62 {
        compatible = &amp;#34;nxp,pca9632&amp;#34;;
        reg = &amp;lt;0x62&amp;gt;;&lt;/p&gt;
&lt;p&gt;// ...&lt;/p&gt;
&lt;p&gt;addon_led_pwm: led-pwm@3 {
            reg = &amp;lt;3&amp;gt;;
            label = &amp;#34;addon:led:pwm&amp;#34;;
        };
    };&lt;/p&gt;
&lt;p&gt;backlight-addon {
        compatible = &amp;#34;led-backlight&amp;#34;;
        leds = &amp;lt;&amp;amp;addon_led_pwm&amp;gt;;
        brightness-levels = &amp;lt;255&amp;gt;;
        default-brightness-level = &amp;lt;255&amp;gt;;
    };&lt;/p&gt;
&lt;p&gt;In this example, the devlink should be created between the backlight-addon
(consumer) and the pca9632@62 (supplier). Instead it is created between the
backlight-addon (consumer) and the parent of the pca9632@62, which is
typically the I2C bus adapter.&lt;/p&gt;
&lt;p&gt;On removal of the above overlay, the LED driver can be removed before the
backlight device, resulting in:&lt;/p&gt;
&lt;p&gt;Unable to handle kernel NULL pointer dereference at virtual address 0000000000000010
    ...
    Call trace:
     led_put+0xe0/0x140
     devm_led_release+0x6c/0x98&lt;/p&gt;
&lt;p&gt;Another way to reproduce the bug without…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;backlight: led-bl: Add devlink to supplier LEDs&lt;/p&gt;
&lt;p&gt;LED Backlight is a consumer of one or multiple LED class devices, but
devlink is currently unable to create correct supplier-producer links when
the supplier is a class device. It creates instead a link where the
supplier is the parent of the expected device.&lt;/p&gt;
&lt;p&gt;One consequence is that removal order is not correctly enforced.&lt;/p&gt;
&lt;p&gt;Issues happen for example with the following sections in a device tree
overlay:&lt;/p&gt;
&lt;p&gt;// An LED driver chip
    pca9632@62 {
        compatible = &amp;#34;nxp,pca9632&amp;#34;;
        reg = &amp;lt;0x62&amp;gt;;&lt;/p&gt;
&lt;p&gt;// ...&lt;/p&gt;
&lt;p&gt;addon_led_pwm: led-pwm@3 {
            reg = &amp;lt;3&amp;gt;;
            label = &amp;#34;addon:led:pwm&amp;#34;;
        };
    };&lt;/p&gt;
&lt;p&gt;backlight-addon {
        compatible = &amp;#34;led-backlight&amp;#34;;
        leds = &amp;lt;&amp;amp;addon_led_pwm&amp;gt;;
        brightness-levels = &amp;lt;255&amp;gt;;
        default-brightness-level = &amp;lt;255&amp;gt;;
    };&lt;/p&gt;
&lt;p&gt;In this example, the devlink should be created between the backlight-addon
(consumer) and the pca9632@62 (supplier). Instead it is created between the
backlight-addon (consumer) and the parent of the pca9632@62, which is
typically the I2C bus adapter.&lt;/p&gt;
&lt;p&gt;On removal of the above overlay, the LED driver can be removed before the
backlight device, resulting in:&lt;/p&gt;
&lt;p&gt;Unable to handle kernel NULL pointer dereference at virtual address 0000000000000010
    ...
    Call trace:
     led_put+0xe0/0x140
     devm_led_release+0x6c/0x98&lt;/p&gt;
&lt;p&gt;Another way to reproduce the bug without…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-68758</guid>
    </item>
    <item>
      <title>GHSA-whh2-h34g-xx55</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-whh2-h34g-xx55</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;backlight: led-bl: Add devlink to supplier LEDs&lt;/p&gt;
&lt;p&gt;LED Backlight is a consumer of one or multiple LED class devices, but
devlink is currently unable to create correct supplier-producer links when
the supplier is a class device. It creates instead a link where the
supplier is the parent of the expected device.&lt;/p&gt;
&lt;p&gt;One consequence is that removal order is not correctly enforced.&lt;/p&gt;
&lt;p&gt;Issues happen for example with the following sections in a device tree
overlay:&lt;/p&gt;
&lt;p&gt;// An LED driver chip
    pca9632@62 {
        compatible = &amp;#34;nxp,pca9632&amp;#34;;
        reg = &amp;lt;0x62&amp;gt;;&lt;/p&gt;
&lt;p&gt;// ...&lt;/p&gt;
&lt;p&gt;addon_led_pwm: led-pwm@3 {
            reg = &amp;lt;3&amp;gt;;
            label = &amp;#34;addon:led:pwm&amp;#34;;
        };
    };&lt;/p&gt;
&lt;p&gt;backlight-addon {
        compatible = &amp;#34;led-backlight&amp;#34;;
        leds = &amp;lt;&amp;amp;addon_led_pwm&amp;gt;;
        brightness-levels = &amp;lt;255&amp;gt;;
        default-brightness-level = &amp;lt;255&amp;gt;;
    };&lt;/p&gt;
&lt;p&gt;In this example, the devlink should be created between the backlight-addon
(consumer) and the pca9632@62 (supplier). Instead it is created between the
backlight-addon (consumer) and the parent of the pca9632@62, which is
typically the I2C bus adapter.&lt;/p&gt;
&lt;p&gt;On removal of the above overlay, the LED driver can be removed before the
backlight device, resulting in:&lt;/p&gt;
&lt;p&gt;Unable to handle kernel NULL pointer dereference at virtual address 0000000000000010
    ...
    Call trace:
     led_put+0xe0/0x140
     devm_led_release+0x6c/0x98&lt;/p&gt;
&lt;p&gt;Another way to reproduce the bug without…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;backlight: led-bl: Add devlink to supplier LEDs&lt;/p&gt;
&lt;p&gt;LED Backlight is a consumer of one or multiple LED class devices, but
devlink is currently unable to create correct supplier-producer links when
the supplier is a class device. It creates instead a link where the
supplier is the parent of the expected device.&lt;/p&gt;
&lt;p&gt;One consequence is that removal order is not correctly enforced.&lt;/p&gt;
&lt;p&gt;Issues happen for example with the following sections in a device tree
overlay:&lt;/p&gt;
&lt;p&gt;// An LED driver chip
    pca9632@62 {
        compatible = &amp;#34;nxp,pca9632&amp;#34;;
        reg = &amp;lt;0x62&amp;gt;;&lt;/p&gt;
&lt;p&gt;// ...&lt;/p&gt;
&lt;p&gt;addon_led_pwm: led-pwm@3 {
            reg = &amp;lt;3&amp;gt;;
            label = &amp;#34;addon:led:pwm&amp;#34;;
        };
    };&lt;/p&gt;
&lt;p&gt;backlight-addon {
        compatible = &amp;#34;led-backlight&amp;#34;;
        leds = &amp;lt;&amp;amp;addon_led_pwm&amp;gt;;
        brightness-levels = &amp;lt;255&amp;gt;;
        default-brightness-level = &amp;lt;255&amp;gt;;
    };&lt;/p&gt;
&lt;p&gt;In this example, the devlink should be created between the backlight-addon
(consumer) and the pca9632@62 (supplier). Instead it is created between the
backlight-addon (consumer) and the parent of the pca9632@62, which is
typically the I2C bus adapter.&lt;/p&gt;
&lt;p&gt;On removal of the above overlay, the LED driver can be removed before the
backlight device, resulting in:&lt;/p&gt;
&lt;p&gt;Unable to handle kernel NULL pointer dereference at virtual address 0000000000000010
    ...
    Call trace:
     led_put+0xe0/0x140
     devm_led_release+0x6c/0x98&lt;/p&gt;
&lt;p&gt;Another way to reproduce the bug without…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-whh2-h34g-xx55</guid>
    </item>
    <item>
      <title>msrc_CVE-2025-68758 — backlight: led-bl: Add devlink to supplier LEDs</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2025-68758</link>
      <description>msrc_CVE-2025-68758</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2025-68758</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:10039-1 — kernel-devel-6.18.5-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10039-1</link>
      <description>&lt;p&gt;kernel-devel-6.18.5-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;kernel-devel-6.18.5-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:10039-1</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:0278-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:0278-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:0278-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-68758</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-68758</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 178 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: backlight: led-bl: Add devlink to supplier LEDs LED Backlight is a consumer of one or multiple LED class devices, but devlink is currently unable to create correct supplier-producer links when the supplier is a class device. It creates instead a link where the supplier is the parent of the expected device. One consequence is that removal order is not correctly enforced. Issues happen for example with the following sections in a device tree overlay:     // An LED driver chip     pca9632@62 {         compatible = &amp;#34;nxp,pca9632&amp;#34;;         reg = &amp;lt;0x62&amp;gt;; 	// ...         addon_led_pwm: led-pwm@3 {             reg = &amp;lt;3&amp;gt;;             label = &amp;#34;addon:led:pwm&amp;#34;;         };     };     backlight-addon {         compatible = &amp;#34;led-backlight&amp;#34;;         leds = &amp;lt;&amp;amp;addon_led_pwm&amp;gt;;         brightness-levels = &amp;lt;255&amp;gt;;         default-brightness-level = &amp;lt;255&amp;gt;;     }; In this example, the devlink should be created between the backlight-addon (consumer) and the pca9632@62 (supplier). Instead it is created between the backlight-addon (consumer) and the parent of the pca9632@62, which is typically the I2C bus adapter. On removal of the above overlay, the LED driver can be removed before the backlight device, resulting in:     Unable to handle kernel NULL pointer dereference at virtual address 0000000000000010     ...     Call trace:      led_put+0xe0/0x140      devm_led_release+0x6c/0x98 Another way to reproduce the bug without any device…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 178 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: backlight: led-bl: Add devlink to supplier LEDs LED Backlight is a consumer of one or multiple LED class devices, but devlink is currently unable to create correct supplier-producer links when the supplier is a class device. It creates instead a link where the supplier is the parent of the expected device. One consequence is that removal order is not correctly enforced. Issues happen for example with the following sections in a device tree overlay:     // An LED driver chip     pca9632@62 {         compatible = &amp;#34;nxp,pca9632&amp;#34;;         reg = &amp;lt;0x62&amp;gt;; 	// ...         addon_led_pwm: led-pwm@3 {             reg = &amp;lt;3&amp;gt;;             label = &amp;#34;addon:led:pwm&amp;#34;;         };     };     backlight-addon {         compatible = &amp;#34;led-backlight&amp;#34;;         leds = &amp;lt;&amp;amp;addon_led_pwm&amp;gt;;         brightness-levels = &amp;lt;255&amp;gt;;         default-brightness-level = &amp;lt;255&amp;gt;;     }; In this example, the devlink should be created between the backlight-addon (consumer) and the pca9632@62 (supplier). Instead it is created between the backlight-addon (consumer) and the parent of the pca9632@62, which is typically the I2C bus adapter. On removal of the above overlay, the LED driver can be removed before the backlight device, resulting in:     Unable to handle kernel NULL pointer dereference at virtual address 0000000000000010     ...     Call trace:      led_put+0xe0/0x140      devm_led_release+0x6c/0x98 Another way to reproduce the bug without any device…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-68758</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-0009 — Linux Kernel: Mehrere Schwachstellen ermöglichen Denial of Service</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0009</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen oder um nicht spezifizierte Auswirkungen zu erzielen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen oder um nicht spezifizierte Auswirkungen zu erzielen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0009</guid>
    </item>
  </channel>
</rss>
