<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 09 Oct 2026 08:31:02 +0000</lastBuildDate>
    <item>
      <title>CVE-2025-68296 — drm, fbcon, vga_switcheroo: Avoid race condition in fbcon setup</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2025-68296</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Linux&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;drm, fbcon, vga_switcheroo: Avoid race condition in fbcon setup&lt;/p&gt;
&lt;p&gt;Protect vga_switcheroo_client_fb_set() with console lock. Avoids OOB
access in fbcon_remap_all(). Without holding the console lock the call
races with switching outputs.&lt;/p&gt;
&lt;p&gt;VGA switcheroo calls fbcon_remap_all() when switching clients. The fbcon
function uses struct fb_info.node, which is set by register_framebuffer().
As the fb-helper code currently sets up VGA switcheroo before registering
the framebuffer, the value of node is -1 and therefore not a legal value.
For example, fbcon uses the value within set_con2fb_map() [1] as an index
into an array.&lt;/p&gt;
&lt;p&gt;Moving vga_switcheroo_client_fb_set() after register_framebuffer() can
result in VGA switching that does not switch fbcon correctly.&lt;/p&gt;
&lt;p&gt;Therefore move vga_switcheroo_client_fb_set() under fbcon_fb_registered(),
which already holds the console lock. Fbdev calls fbcon_fb_registered()
from within register_framebuffer(). Serializes the helper with VGA
switcheroo&amp;#39;s call to fbcon_remap_all().&lt;/p&gt;
&lt;p&gt;Although vga_switcheroo_client_fb_set() takes an instance of struct fb_info
as parameter, it really only needs the contained fbcon state. Moving the
call to fbcon initialization is therefore cleaner than before. Only amdgpu,
i915, nouveau and radeon support vga_switcheroo. For all other drivers,
this change does nothing.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Linux&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;drm, fbcon, vga_switcheroo: Avoid race condition in fbcon setup&lt;/p&gt;
&lt;p&gt;Protect vga_switcheroo_client_fb_set() with console lock. Avoids OOB
access in fbcon_remap_all(). Without holding the console lock the call
races with switching outputs.&lt;/p&gt;
&lt;p&gt;VGA switcheroo calls fbcon_remap_all() when switching clients. The fbcon
function uses struct fb_info.node, which is set by register_framebuffer().
As the fb-helper code currently sets up VGA switcheroo before registering
the framebuffer, the value of node is -1 and therefore not a legal value.
For example, fbcon uses the value within set_con2fb_map() [1] as an index
into an array.&lt;/p&gt;
&lt;p&gt;Moving vga_switcheroo_client_fb_set() after register_framebuffer() can
result in VGA switching that does not switch fbcon correctly.&lt;/p&gt;
&lt;p&gt;Therefore move vga_switcheroo_client_fb_set() under fbcon_fb_registered(),
which already holds the console lock. Fbdev calls fbcon_fb_registered()
from within register_framebuffer(). Serializes the helper with VGA
switcheroo&amp;#39;s call to fbcon_remap_all().&lt;/p&gt;
&lt;p&gt;Although vga_switcheroo_client_fb_set() takes an instance of struct fb_info
as parameter, it really only needs the contained fbcon state. Moving the
call to fbcon initialization is therefore cleaner than before. Only amdgpu,
i915, nouveau and radeon support vga_switcheroo. For all other drivers,
this change does nothing.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2025-68296</guid>
    </item>
    <item>
      <title>USN-8094-1 — linux, linux-aws, linux-aws-6.17, linux-gcp, linux-hwe-6.17, linux-oracle, linux-oracle-6.17 vulnerabilities</title>
      <link>https://cve.radiocsirt.org/vuln/usn-8094-1</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:24.04:LTS: linux-aws-6.17, Ubuntu:24.04:LTS: linux-hwe-6.17, Ubuntu:24.04:LTS: linux-oracle-6.17, Ubuntu:25.10: linux, Ubuntu:25.10: linux-aws, Ubuntu:25.10: linux-gcp, Ubuntu:25.10: linux-oracle&lt;/p&gt;
&lt;p&gt;Qualys discovered that several vulnerabilities existed in the AppArmor
Linux kernel Security Module (LSM). An unprivileged local attacker could
use these issues to load, replace, and remove arbitrary AppArmor profiles
causing denial of service, exposure of sensitive information (kernel
memory), local privilege escalation, or possibly escape a container.
(LP: #2143853)&lt;/p&gt;
&lt;p&gt;It was discovered that some AMD Zen 5 processors supporting RDSEED
instruction did not properly handle entropy, potentially resulting in the
consumption of insufficiently random values. A local attacker could
possibly use this issue to influence the values returned by the RDSEED
instruction causing loss of confidentiality and integrity. (CVE-2025-62626)&lt;/p&gt;
&lt;p&gt;Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
  - ARM64 architecture;
  - S390 architecture;
  - x86 architecture;
  - Block layer subsystem;
  - Cryptographic API;
  - Compute Acceleration Framework;
  - ATM drivers;
  - Network block device driver;
  - Bluetooth drivers;
  - Data acquisition framework and drivers;
  - Hardware crypto device drivers;
  - Device frequency scaling framework;
  - Intel Stratix 10 firmware drivers;
  - GPIO subsystem;
  - GPU drivers;
  - Microsoft Hyper-V drivers;
  - CoreSight HW tracing drivers;
  - IIO subsystem;
  - InfiniBand drivers;
  - Input Device core drivers;
  - Input Device (Tablet) d…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:24.04:LTS: linux-aws-6.17, Ubuntu:24.04:LTS: linux-hwe-6.17, Ubuntu:24.04:LTS: linux-oracle-6.17, Ubuntu:25.10: linux, Ubuntu:25.10: linux-aws, Ubuntu:25.10: linux-gcp, Ubuntu:25.10: linux-oracle&lt;/p&gt;
&lt;p&gt;Qualys discovered that several vulnerabilities existed in the AppArmor
Linux kernel Security Module (LSM). An unprivileged local attacker could
use these issues to load, replace, and remove arbitrary AppArmor profiles
causing denial of service, exposure of sensitive information (kernel
memory), local privilege escalation, or possibly escape a container.
(LP: #2143853)&lt;/p&gt;
&lt;p&gt;It was discovered that some AMD Zen 5 processors supporting RDSEED
instruction did not properly handle entropy, potentially resulting in the
consumption of insufficiently random values. A local attacker could
possibly use this issue to influence the values returned by the RDSEED
instruction causing loss of confidentiality and integrity. (CVE-2025-62626)&lt;/p&gt;
&lt;p&gt;Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
  - ARM64 architecture;
  - S390 architecture;
  - x86 architecture;
  - Block layer subsystem;
  - Cryptographic API;
  - Compute Acceleration Framework;
  - ATM drivers;
  - Network block device driver;
  - Bluetooth drivers;
  - Data acquisition framework and drivers;
  - Hardware crypto device drivers;
  - Device frequency scaling framework;
  - Intel Stratix 10 firmware drivers;
  - GPIO subsystem;
  - GPU drivers;
  - Microsoft Hyper-V drivers;
  - CoreSight HW tracing drivers;
  - IIO subsystem;
  - InfiniBand drivers;
  - Input Device core drivers;
  - Input Device (Tablet) d…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/usn-8094-1</guid>
    </item>
  </channel>
</rss>
