<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 09:49:35 +0000</lastBuildDate>
    <item>
      <title>bdu:2025-01985</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-01985</link>
      <description>bdu:2025-01985</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-01985</guid>
    </item>
    <item>
      <title>certfr-2024-avi-0999 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de SUSE. Certaines d'entre elles permettent à un at…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0999</link>
      <description>certfr-2024-avi-0999</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2024-avi-0999</guid>
    </item>
    <item>
      <title>EUVD-2026-310305</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-310305</link>
      <description>EUVD-2026-310305</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-310305</guid>
    </item>
    <item>
      <title>fkie_cve-2022-49031</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-49031</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;iio: health: afe4403: Fix oob read in afe4403_read_raw&lt;/p&gt;
&lt;p&gt;KASAN report out-of-bounds read as follows:&lt;/p&gt;
&lt;p&gt;BUG: KASAN: global-out-of-bounds in afe4403_read_raw+0x42e/0x4c0
Read of size 4 at addr ffffffffc02ac638 by task cat/279&lt;/p&gt;
&lt;p&gt;Call Trace:
 afe4403_read_raw
 iio_read_channel_info
 dev_attr_show&lt;/p&gt;
&lt;p&gt;The buggy address belongs to the variable:
 afe4403_channel_leds+0x18/0xffffffffffffe9e0&lt;/p&gt;
&lt;p&gt;This issue can be reproduced by singe command:&lt;/p&gt;
&lt;p&gt;$ cat /sys/bus/spi/devices/spi0.0/iio\:device0/in_intensity6_raw&lt;/p&gt;
&lt;p&gt;The array size of afe4403_channel_leds is less than channels, so access
with chan-&amp;gt;address cause OOB read in afe4403_read_raw. Fix it by moving
access before use it.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;iio: health: afe4403: Fix oob read in afe4403_read_raw&lt;/p&gt;
&lt;p&gt;KASAN report out-of-bounds read as follows:&lt;/p&gt;
&lt;p&gt;BUG: KASAN: global-out-of-bounds in afe4403_read_raw+0x42e/0x4c0
Read of size 4 at addr ffffffffc02ac638 by task cat/279&lt;/p&gt;
&lt;p&gt;Call Trace:
 afe4403_read_raw
 iio_read_channel_info
 dev_attr_show&lt;/p&gt;
&lt;p&gt;The buggy address belongs to the variable:
 afe4403_channel_leds+0x18/0xffffffffffffe9e0&lt;/p&gt;
&lt;p&gt;This issue can be reproduced by singe command:&lt;/p&gt;
&lt;p&gt;$ cat /sys/bus/spi/devices/spi0.0/iio\:device0/in_intensity6_raw&lt;/p&gt;
&lt;p&gt;The array size of afe4403_channel_leds is less than channels, so access
with chan-&amp;gt;address cause OOB read in afe4403_read_raw. Fix it by moving
access before use it.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-49031</guid>
    </item>
    <item>
      <title>GHSA-4667-xxv8-3pq6</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-4667-xxv8-3pq6</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;iio: health: afe4403: Fix oob read in afe4403_read_raw&lt;/p&gt;
&lt;p&gt;KASAN report out-of-bounds read as follows:&lt;/p&gt;
&lt;p&gt;BUG: KASAN: global-out-of-bounds in afe4403_read_raw+0x42e/0x4c0
Read of size 4 at addr ffffffffc02ac638 by task cat/279&lt;/p&gt;
&lt;p&gt;Call Trace:
 afe4403_read_raw
 iio_read_channel_info
 dev_attr_show&lt;/p&gt;
&lt;p&gt;The buggy address belongs to the variable:
 afe4403_channel_leds+0x18/0xffffffffffffe9e0&lt;/p&gt;
&lt;p&gt;This issue can be reproduced by singe command:&lt;/p&gt;
&lt;p&gt;$ cat /sys/bus/spi/devices/spi0.0/iio\:device0/in_intensity6_raw&lt;/p&gt;
&lt;p&gt;The array size of afe4403_channel_leds is less than channels, so access
with chan-&amp;gt;address cause OOB read in afe4403_read_raw. Fix it by moving
access before use it.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;iio: health: afe4403: Fix oob read in afe4403_read_raw&lt;/p&gt;
&lt;p&gt;KASAN report out-of-bounds read as follows:&lt;/p&gt;
&lt;p&gt;BUG: KASAN: global-out-of-bounds in afe4403_read_raw+0x42e/0x4c0
Read of size 4 at addr ffffffffc02ac638 by task cat/279&lt;/p&gt;
&lt;p&gt;Call Trace:
 afe4403_read_raw
 iio_read_channel_info
 dev_attr_show&lt;/p&gt;
&lt;p&gt;The buggy address belongs to the variable:
 afe4403_channel_leds+0x18/0xffffffffffffe9e0&lt;/p&gt;
&lt;p&gt;This issue can be reproduced by singe command:&lt;/p&gt;
&lt;p&gt;$ cat /sys/bus/spi/devices/spi0.0/iio\:device0/in_intensity6_raw&lt;/p&gt;
&lt;p&gt;The array size of afe4403_channel_leds is less than channels, so access
with chan-&amp;gt;address cause OOB read in afe4403_read_raw. Fix it by moving
access before use it.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-4667-xxv8-3pq6</guid>
    </item>
    <item>
      <title>OESA-2024-2370 — kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2024-2370</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP4: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&#13;
&#13;
In the Linux kernel, the following vulnerability has been resolved:  usb: gadget: uvc: Prevent buffer overflow in setup handler  Setup function uvc_function_setup permits control transfer requests with up to 64 bytes of payload (UVC_MAX_REQUEST_SIZE), data stage handler for OUT transfer uses memcpy to copy req-&amp;amp;gt;actual bytes to uvc_event-&amp;amp;gt;data.data array of size 60. This may result in an overflow of 4 bytes.(CVE-2022-48948)&#13;
&#13;
In the Linux kernel, the following vulnerability has been resolved:  igb: Initialize mailbox message for VF reset  When a MAC address is not assigned to the VF, that portion of the message sent to the VF is not set. The memory, however, is allocated from the stack meaning that information may be leaked to the VM. Initialize the message buffer to 0 so that no information is passed to the VM in this case.(CVE-2022-48949)&#13;
&#13;
In the Linux kernel, the following vulnerability has been resolved:  net: hisilicon: Fix potential use-after-free in hix5hd2_rx()  The skb is delivered to napi_gro_receive() which may free it, after calling this, dereferencing skb may trigger use-after-free.(CVE-2022-48960)&#13;
&#13;
In the Linux kernel, the following vulnerability has been resolved:  net: hisilicon: Fix potential use-after-free in hisi_femac_rx()  The skb is delivered to napi_gro_receive() which may free it, after calling this, dereferencing skb may trigger use-after-free.(CVE-2022-48962)&#13;
&#13;
In…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP4: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&#13;
&#13;
In the Linux kernel, the following vulnerability has been resolved:  usb: gadget: uvc: Prevent buffer overflow in setup handler  Setup function uvc_function_setup permits control transfer requests with up to 64 bytes of payload (UVC_MAX_REQUEST_SIZE), data stage handler for OUT transfer uses memcpy to copy req-&amp;amp;gt;actual bytes to uvc_event-&amp;amp;gt;data.data array of size 60. This may result in an overflow of 4 bytes.(CVE-2022-48948)&#13;
&#13;
In the Linux kernel, the following vulnerability has been resolved:  igb: Initialize mailbox message for VF reset  When a MAC address is not assigned to the VF, that portion of the message sent to the VF is not set. The memory, however, is allocated from the stack meaning that information may be leaked to the VM. Initialize the message buffer to 0 so that no information is passed to the VM in this case.(CVE-2022-48949)&#13;
&#13;
In the Linux kernel, the following vulnerability has been resolved:  net: hisilicon: Fix potential use-after-free in hix5hd2_rx()  The skb is delivered to napi_gro_receive() which may free it, after calling this, dereferencing skb may trigger use-after-free.(CVE-2022-48960)&#13;
&#13;
In the Linux kernel, the following vulnerability has been resolved:  net: hisilicon: Fix potential use-after-free in hisi_femac_rx()  The skb is delivered to napi_gro_receive() which may free it, after calling this, dereferencing skb may trigger use-after-free.(CVE-2022-48962)&#13;
&#13;
In…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2024-2370</guid>
    </item>
    <item>
      <title>SUSE-SU-2024:3983-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2024:3983-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2024:3983-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2022-49031</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-49031</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe, Ubuntu:Pro:16.04:LTS: linux-oracle, Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux, Ubuntu:18.04:LTS: linux-aws, Ubuntu:18.04:LTS: linux-aws-5.4 and 140 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: iio: health: afe4403: Fix oob read in afe4403_read_raw KASAN report out-of-bounds read as follows: BUG: KASAN: global-out-of-bounds in afe4403_read_raw+0x42e/0x4c0 Read of size 4 at addr ffffffffc02ac638 by task cat/279 Call Trace:  afe4403_read_raw  iio_read_channel_info  dev_attr_show The buggy address belongs to the variable:  afe4403_channel_leds+0x18/0xffffffffffffe9e0 This issue can be reproduced by singe command:  $ cat /sys/bus/spi/devices/spi0.0/iio\:device0/in_intensity6_raw The array size of afe4403_channel_leds is less than channels, so access with chan-&amp;gt;address cause OOB read in afe4403_read_raw. Fix it by moving access before use it.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe, Ubuntu:Pro:16.04:LTS: linux-oracle, Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux, Ubuntu:18.04:LTS: linux-aws, Ubuntu:18.04:LTS: linux-aws-5.4 and 140 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: iio: health: afe4403: Fix oob read in afe4403_read_raw KASAN report out-of-bounds read as follows: BUG: KASAN: global-out-of-bounds in afe4403_read_raw+0x42e/0x4c0 Read of size 4 at addr ffffffffc02ac638 by task cat/279 Call Trace:  afe4403_read_raw  iio_read_channel_info  dev_attr_show The buggy address belongs to the variable:  afe4403_channel_leds+0x18/0xffffffffffffe9e0 This issue can be reproduced by singe command:  $ cat /sys/bus/spi/devices/spi0.0/iio\:device0/in_intensity6_raw The array size of afe4403_channel_leds is less than channels, so access with chan-&amp;gt;address cause OOB read in afe4403_read_raw. Fix it by moving access before use it.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-49031</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-3251 — Linux Kernel: Mehrere Schwachstellen ermöglichen Denial of Service</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-3251</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen oder andere, nicht näher bekannte Auswirkungen zu erzielen..&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen oder andere, nicht näher bekannte Auswirkungen zu erzielen..&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-3251</guid>
    </item>
  </channel>
</rss>
