<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 03:39:42 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-12725</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-12725</link>
      <description>bdu:2026-12725</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-12725</guid>
    </item>
    <item>
      <title>BELL-CVE-2025-71299</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2025-71299</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2025-71299</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0558 — De multiples vulnérabilités ont été découvertes dans Microsoft Azure Linux. Elles permettent à un attaquant de provoque…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0558</link>
      <description>certfr-2026-avi-0558</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0558</guid>
    </item>
    <item>
      <title>EUVD-2026-320931</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-320931</link>
      <description>EUVD-2026-320931</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-320931</guid>
    </item>
    <item>
      <title>fkie_cve-2025-71299</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-71299</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;spi: cadence-quadspi: Parse DT for flashes with the rest of the DT parsing&lt;/p&gt;
&lt;p&gt;The recent refactoring of where runtime PM is enabled done in commit
f1eb4e792bb1 (&amp;#34;spi: spi-cadence-quadspi: Enable pm runtime earlier to
avoid imbalance&amp;#34;) made the fact that when we do a pm_runtime_disable()
in the error paths of probe() we can trigger a runtime disable which in
turn results in duplicate clock disables.  This is particularly likely
to happen when there is missing or broken DT description for the flashes
attached to the controller.&lt;/p&gt;
&lt;p&gt;Early on in the probe function we do a pm_runtime_get_noresume() since
the probe function leaves the device in a powered up state but in the
error path we can&amp;#39;t assume that PM is enabled so we also manually
disable everything, including clocks. This means that when runtime PM is
active both it and the probe function release the same reference to the
main clock for the IP, triggering warnings from the clock subsystem:&lt;/p&gt;
&lt;p&gt;[    8.693719] clk:75:7 already disabled
[    8.693791] WARNING: CPU: 1 PID: 185 at /usr/src/kernel/drivers/clk/clk.c:1188 clk_core_disable+0xa0/0xb
...
[    8.694261]  clk_core_disable+0xa0/0xb4 (P)
[    8.694272]  clk_disable+0x38/0x60
[    8.694283]  cqspi_probe+0x7c8/0xc5c [spi_cadence_quadspi]
[    8.694309]  platform_probe+0x5c/0xa4&lt;/p&gt;
&lt;p&gt;Dealing with this issue properly is complicated by the fact that we
don&amp;#39;t know if runtime PM is active so can&amp;#39;t tell if it will disable…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;spi: cadence-quadspi: Parse DT for flashes with the rest of the DT parsing&lt;/p&gt;
&lt;p&gt;The recent refactoring of where runtime PM is enabled done in commit
f1eb4e792bb1 (&amp;#34;spi: spi-cadence-quadspi: Enable pm runtime earlier to
avoid imbalance&amp;#34;) made the fact that when we do a pm_runtime_disable()
in the error paths of probe() we can trigger a runtime disable which in
turn results in duplicate clock disables.  This is particularly likely
to happen when there is missing or broken DT description for the flashes
attached to the controller.&lt;/p&gt;
&lt;p&gt;Early on in the probe function we do a pm_runtime_get_noresume() since
the probe function leaves the device in a powered up state but in the
error path we can&amp;#39;t assume that PM is enabled so we also manually
disable everything, including clocks. This means that when runtime PM is
active both it and the probe function release the same reference to the
main clock for the IP, triggering warnings from the clock subsystem:&lt;/p&gt;
&lt;p&gt;[    8.693719] clk:75:7 already disabled
[    8.693791] WARNING: CPU: 1 PID: 185 at /usr/src/kernel/drivers/clk/clk.c:1188 clk_core_disable+0xa0/0xb
...
[    8.694261]  clk_core_disable+0xa0/0xb4 (P)
[    8.694272]  clk_disable+0x38/0x60
[    8.694283]  cqspi_probe+0x7c8/0xc5c [spi_cadence_quadspi]
[    8.694309]  platform_probe+0x5c/0xa4&lt;/p&gt;
&lt;p&gt;Dealing with this issue properly is complicated by the fact that we
don&amp;#39;t know if runtime PM is active so can&amp;#39;t tell if it will disable…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-71299</guid>
    </item>
    <item>
      <title>GHSA-wcrj-2m2g-27wm</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-wcrj-2m2g-27wm</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;spi: cadence-quadspi: Parse DT for flashes with the rest of the DT parsing&lt;/p&gt;
&lt;p&gt;The recent refactoring of where runtime PM is enabled done in commit
f1eb4e792bb1 (&amp;#34;spi: spi-cadence-quadspi: Enable pm runtime earlier to
avoid imbalance&amp;#34;) made the fact that when we do a pm_runtime_disable()
in the error paths of probe() we can trigger a runtime disable which in
turn results in duplicate clock disables.  This is particularly likely
to happen when there is missing or broken DT description for the flashes
attached to the controller.&lt;/p&gt;
&lt;p&gt;Early on in the probe function we do a pm_runtime_get_noresume() since
the probe function leaves the device in a powered up state but in the
error path we can&amp;#39;t assume that PM is enabled so we also manually
disable everything, including clocks. This means that when runtime PM is
active both it and the probe function release the same reference to the
main clock for the IP, triggering warnings from the clock subsystem:&lt;/p&gt;
&lt;p&gt;[    8.693719] clk:75:7 already disabled
[    8.693791] WARNING: CPU: 1 PID: 185 at /usr/src/kernel/drivers/clk/clk.c:1188 clk_core_disable+0xa0/0xb
...
[    8.694261]  clk_core_disable+0xa0/0xb4 (P)
[    8.694272]  clk_disable+0x38/0x60
[    8.694283]  cqspi_probe+0x7c8/0xc5c [spi_cadence_quadspi]
[    8.694309]  platform_probe+0x5c/0xa4&lt;/p&gt;
&lt;p&gt;Dealing with this issue properly is complicated by the fact that we
don&amp;#39;t know if runtime PM is active so can&amp;#39;t tell if it will disable…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;spi: cadence-quadspi: Parse DT for flashes with the rest of the DT parsing&lt;/p&gt;
&lt;p&gt;The recent refactoring of where runtime PM is enabled done in commit
f1eb4e792bb1 (&amp;#34;spi: spi-cadence-quadspi: Enable pm runtime earlier to
avoid imbalance&amp;#34;) made the fact that when we do a pm_runtime_disable()
in the error paths of probe() we can trigger a runtime disable which in
turn results in duplicate clock disables.  This is particularly likely
to happen when there is missing or broken DT description for the flashes
attached to the controller.&lt;/p&gt;
&lt;p&gt;Early on in the probe function we do a pm_runtime_get_noresume() since
the probe function leaves the device in a powered up state but in the
error path we can&amp;#39;t assume that PM is enabled so we also manually
disable everything, including clocks. This means that when runtime PM is
active both it and the probe function release the same reference to the
main clock for the IP, triggering warnings from the clock subsystem:&lt;/p&gt;
&lt;p&gt;[    8.693719] clk:75:7 already disabled
[    8.693791] WARNING: CPU: 1 PID: 185 at /usr/src/kernel/drivers/clk/clk.c:1188 clk_core_disable+0xa0/0xb
...
[    8.694261]  clk_core_disable+0xa0/0xb4 (P)
[    8.694272]  clk_disable+0x38/0x60
[    8.694283]  cqspi_probe+0x7c8/0xc5c [spi_cadence_quadspi]
[    8.694309]  platform_probe+0x5c/0xa4&lt;/p&gt;
&lt;p&gt;Dealing with this issue properly is complicated by the fact that we
don&amp;#39;t know if runtime PM is active so can&amp;#39;t tell if it will disable…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-wcrj-2m2g-27wm</guid>
    </item>
    <item>
      <title>msrc_CVE-2025-71299 — spi: cadence-quadspi: Parse DT for flashes with the rest of the DT parsing</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2025-71299</link>
      <description>msrc_CVE-2025-71299</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2025-71299</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-71299</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-71299</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux, Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe and 233 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: spi: cadence-quadspi: Parse DT for flashes with the rest of the DT parsing The recent refactoring of where runtime PM is enabled done in commit f1eb4e792bb1 (&amp;#34;spi: spi-cadence-quadspi: Enable pm runtime earlier to avoid imbalance&amp;#34;) made the fact that when we do a pm_runtime_disable() in the error paths of probe() we can trigger a runtime disable which in turn results in duplicate clock disables.  This is particularly likely to happen when there is missing or broken DT description for the flashes attached to the controller. Early on in the probe function we do a pm_runtime_get_noresume() since the probe function leaves the device in a powered up state but in the error path we can&amp;#39;t assume that PM is enabled so we also manually disable everything, including clocks. This means that when runtime PM is active both it and the probe function release the same reference to the main clock for the IP, triggering warnings from the clock subsystem: [    8.693719] clk:75:7 already disabled [    8.693791] WARNING: CPU: 1 PID: 185 at /usr/src/kernel/drivers/clk/clk.c:1188 clk_core_disable+0xa0/0xb ... [    8.694261]  clk_core_disable+0xa0/0xb4 (P) [    8.694272]  clk_disable+0x38/0x60 [    8.694283]  cqspi_probe+0x7c8/0xc5c [spi_cadence_quadspi] [    8.694309]  platform_probe+0x5c/0xa4 Dealing with this issue properly is complicated by the fact that we don&amp;#39;t know if runtime PM is active so can&amp;#39;t tell if it will disable the…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux, Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe and 233 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: spi: cadence-quadspi: Parse DT for flashes with the rest of the DT parsing The recent refactoring of where runtime PM is enabled done in commit f1eb4e792bb1 (&amp;#34;spi: spi-cadence-quadspi: Enable pm runtime earlier to avoid imbalance&amp;#34;) made the fact that when we do a pm_runtime_disable() in the error paths of probe() we can trigger a runtime disable which in turn results in duplicate clock disables.  This is particularly likely to happen when there is missing or broken DT description for the flashes attached to the controller. Early on in the probe function we do a pm_runtime_get_noresume() since the probe function leaves the device in a powered up state but in the error path we can&amp;#39;t assume that PM is enabled so we also manually disable everything, including clocks. This means that when runtime PM is active both it and the probe function release the same reference to the main clock for the IP, triggering warnings from the clock subsystem: [    8.693719] clk:75:7 already disabled [    8.693791] WARNING: CPU: 1 PID: 185 at /usr/src/kernel/drivers/clk/clk.c:1188 clk_core_disable+0xa0/0xb ... [    8.694261]  clk_core_disable+0xa0/0xb4 (P) [    8.694272]  clk_disable+0x38/0x60 [    8.694283]  cqspi_probe+0x7c8/0xc5c [spi_cadence_quadspi] [    8.694309]  platform_probe+0x5c/0xa4 Dealing with this issue properly is complicated by the fact that we don&amp;#39;t know if runtime PM is active so can&amp;#39;t tell if it will disable the…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-71299</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1454 — Linux Kernel: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1454</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen, möglicherweise Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren oder offenzulegen oder einen Denial-of-Service-Zustand zu verursachen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen, möglicherweise Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren oder offenzulegen oder einen Denial-of-Service-Zustand zu verursachen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1454</guid>
    </item>
  </channel>
</rss>
