<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 11:31:54 +0000</lastBuildDate>
    <item>
      <title>bdu:2025-01978</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-01978</link>
      <description>bdu:2025-01978</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-01978</guid>
    </item>
    <item>
      <title>certfr-2024-avi-0999 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de SUSE. Certaines d'entre elles permettent à un at…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0999</link>
      <description>certfr-2024-avi-0999</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2024-avi-0999</guid>
    </item>
    <item>
      <title>EUVD-2026-310306</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-310306</link>
      <description>EUVD-2026-310306</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-310306</guid>
    </item>
    <item>
      <title>fkie_cve-2022-49032</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-49032</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;iio: health: afe4404: Fix oob read in afe4404_[read|write]_raw&lt;/p&gt;
&lt;p&gt;KASAN report out-of-bounds read as follows:&lt;/p&gt;
&lt;p&gt;BUG: KASAN: global-out-of-bounds in afe4404_read_raw+0x2ce/0x380
Read of size 4 at addr ffffffffc00e4658 by task cat/278&lt;/p&gt;
&lt;p&gt;Call Trace:
 afe4404_read_raw
 iio_read_channel_info
 dev_attr_show&lt;/p&gt;
&lt;p&gt;The buggy address belongs to the variable:
 afe4404_channel_leds+0x18/0xffffffffffffe9c0&lt;/p&gt;
&lt;p&gt;This issue can be reproduce by singe command:&lt;/p&gt;
&lt;p&gt;$ cat /sys/bus/i2c/devices/0-0058/iio\:device0/in_intensity6_raw&lt;/p&gt;
&lt;p&gt;The array size of afe4404_channel_leds and afe4404_channel_offdacs
are less than channels, so access with chan-&amp;gt;address cause OOB read
in afe4404_[read|write]_raw. Fix it by moving access before use them.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;iio: health: afe4404: Fix oob read in afe4404_[read|write]_raw&lt;/p&gt;
&lt;p&gt;KASAN report out-of-bounds read as follows:&lt;/p&gt;
&lt;p&gt;BUG: KASAN: global-out-of-bounds in afe4404_read_raw+0x2ce/0x380
Read of size 4 at addr ffffffffc00e4658 by task cat/278&lt;/p&gt;
&lt;p&gt;Call Trace:
 afe4404_read_raw
 iio_read_channel_info
 dev_attr_show&lt;/p&gt;
&lt;p&gt;The buggy address belongs to the variable:
 afe4404_channel_leds+0x18/0xffffffffffffe9c0&lt;/p&gt;
&lt;p&gt;This issue can be reproduce by singe command:&lt;/p&gt;
&lt;p&gt;$ cat /sys/bus/i2c/devices/0-0058/iio\:device0/in_intensity6_raw&lt;/p&gt;
&lt;p&gt;The array size of afe4404_channel_leds and afe4404_channel_offdacs
are less than channels, so access with chan-&amp;gt;address cause OOB read
in afe4404_[read|write]_raw. Fix it by moving access before use them.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-49032</guid>
    </item>
    <item>
      <title>GHSA-76p7-pw4c-r85f</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-76p7-pw4c-r85f</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;iio: health: afe4404: Fix oob read in afe4404_[read|write]_raw&lt;/p&gt;
&lt;p&gt;KASAN report out-of-bounds read as follows:&lt;/p&gt;
&lt;p&gt;BUG: KASAN: global-out-of-bounds in afe4404_read_raw+0x2ce/0x380
Read of size 4 at addr ffffffffc00e4658 by task cat/278&lt;/p&gt;
&lt;p&gt;Call Trace:
 afe4404_read_raw
 iio_read_channel_info
 dev_attr_show&lt;/p&gt;
&lt;p&gt;The buggy address belongs to the variable:
 afe4404_channel_leds+0x18/0xffffffffffffe9c0&lt;/p&gt;
&lt;p&gt;This issue can be reproduce by singe command:&lt;/p&gt;
&lt;p&gt;$ cat /sys/bus/i2c/devices/0-0058/iio\:device0/in_intensity6_raw&lt;/p&gt;
&lt;p&gt;The array size of afe4404_channel_leds and afe4404_channel_offdacs
are less than channels, so access with chan-&amp;gt;address cause OOB read
in afe4404_[read|write]_raw. Fix it by moving access before use them.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;iio: health: afe4404: Fix oob read in afe4404_[read|write]_raw&lt;/p&gt;
&lt;p&gt;KASAN report out-of-bounds read as follows:&lt;/p&gt;
&lt;p&gt;BUG: KASAN: global-out-of-bounds in afe4404_read_raw+0x2ce/0x380
Read of size 4 at addr ffffffffc00e4658 by task cat/278&lt;/p&gt;
&lt;p&gt;Call Trace:
 afe4404_read_raw
 iio_read_channel_info
 dev_attr_show&lt;/p&gt;
&lt;p&gt;The buggy address belongs to the variable:
 afe4404_channel_leds+0x18/0xffffffffffffe9c0&lt;/p&gt;
&lt;p&gt;This issue can be reproduce by singe command:&lt;/p&gt;
&lt;p&gt;$ cat /sys/bus/i2c/devices/0-0058/iio\:device0/in_intensity6_raw&lt;/p&gt;
&lt;p&gt;The array size of afe4404_channel_leds and afe4404_channel_offdacs
are less than channels, so access with chan-&amp;gt;address cause OOB read
in afe4404_[read|write]_raw. Fix it by moving access before use them.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-76p7-pw4c-r85f</guid>
    </item>
    <item>
      <title>OESA-2024-2370 — kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2024-2370</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP4: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&#13;
&#13;
In the Linux kernel, the following vulnerability has been resolved:  usb: gadget: uvc: Prevent buffer overflow in setup handler  Setup function uvc_function_setup permits control transfer requests with up to 64 bytes of payload (UVC_MAX_REQUEST_SIZE), data stage handler for OUT transfer uses memcpy to copy req-&amp;amp;gt;actual bytes to uvc_event-&amp;amp;gt;data.data array of size 60. This may result in an overflow of 4 bytes.(CVE-2022-48948)&#13;
&#13;
In the Linux kernel, the following vulnerability has been resolved:  igb: Initialize mailbox message for VF reset  When a MAC address is not assigned to the VF, that portion of the message sent to the VF is not set. The memory, however, is allocated from the stack meaning that information may be leaked to the VM. Initialize the message buffer to 0 so that no information is passed to the VM in this case.(CVE-2022-48949)&#13;
&#13;
In the Linux kernel, the following vulnerability has been resolved:  net: hisilicon: Fix potential use-after-free in hix5hd2_rx()  The skb is delivered to napi_gro_receive() which may free it, after calling this, dereferencing skb may trigger use-after-free.(CVE-2022-48960)&#13;
&#13;
In the Linux kernel, the following vulnerability has been resolved:  net: hisilicon: Fix potential use-after-free in hisi_femac_rx()  The skb is delivered to napi_gro_receive() which may free it, after calling this, dereferencing skb may trigger use-after-free.(CVE-2022-48962)&#13;
&#13;
In…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP4: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&#13;
&#13;
In the Linux kernel, the following vulnerability has been resolved:  usb: gadget: uvc: Prevent buffer overflow in setup handler  Setup function uvc_function_setup permits control transfer requests with up to 64 bytes of payload (UVC_MAX_REQUEST_SIZE), data stage handler for OUT transfer uses memcpy to copy req-&amp;amp;gt;actual bytes to uvc_event-&amp;amp;gt;data.data array of size 60. This may result in an overflow of 4 bytes.(CVE-2022-48948)&#13;
&#13;
In the Linux kernel, the following vulnerability has been resolved:  igb: Initialize mailbox message for VF reset  When a MAC address is not assigned to the VF, that portion of the message sent to the VF is not set. The memory, however, is allocated from the stack meaning that information may be leaked to the VM. Initialize the message buffer to 0 so that no information is passed to the VM in this case.(CVE-2022-48949)&#13;
&#13;
In the Linux kernel, the following vulnerability has been resolved:  net: hisilicon: Fix potential use-after-free in hix5hd2_rx()  The skb is delivered to napi_gro_receive() which may free it, after calling this, dereferencing skb may trigger use-after-free.(CVE-2022-48960)&#13;
&#13;
In the Linux kernel, the following vulnerability has been resolved:  net: hisilicon: Fix potential use-after-free in hisi_femac_rx()  The skb is delivered to napi_gro_receive() which may free it, after calling this, dereferencing skb may trigger use-after-free.(CVE-2022-48962)&#13;
&#13;
In…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2024-2370</guid>
    </item>
    <item>
      <title>SUSE-SU-2024:3983-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2024:3983-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2024:3983-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2022-49032</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-49032</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe, Ubuntu:Pro:16.04:LTS: linux-oracle, Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux, Ubuntu:18.04:LTS: linux-aws, Ubuntu:18.04:LTS: linux-aws-5.4 and 140 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: iio: health: afe4404: Fix oob read in afe4404_[read|write]_raw KASAN report out-of-bounds read as follows: BUG: KASAN: global-out-of-bounds in afe4404_read_raw+0x2ce/0x380 Read of size 4 at addr ffffffffc00e4658 by task cat/278 Call Trace:  afe4404_read_raw  iio_read_channel_info  dev_attr_show The buggy address belongs to the variable:  afe4404_channel_leds+0x18/0xffffffffffffe9c0 This issue can be reproduce by singe command:  $ cat /sys/bus/i2c/devices/0-0058/iio\:device0/in_intensity6_raw The array size of afe4404_channel_leds and afe4404_channel_offdacs are less than channels, so access with chan-&amp;gt;address cause OOB read in afe4404_[read|write]_raw. Fix it by moving access before use them.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe, Ubuntu:Pro:16.04:LTS: linux-oracle, Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux, Ubuntu:18.04:LTS: linux-aws, Ubuntu:18.04:LTS: linux-aws-5.4 and 140 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: iio: health: afe4404: Fix oob read in afe4404_[read|write]_raw KASAN report out-of-bounds read as follows: BUG: KASAN: global-out-of-bounds in afe4404_read_raw+0x2ce/0x380 Read of size 4 at addr ffffffffc00e4658 by task cat/278 Call Trace:  afe4404_read_raw  iio_read_channel_info  dev_attr_show The buggy address belongs to the variable:  afe4404_channel_leds+0x18/0xffffffffffffe9c0 This issue can be reproduce by singe command:  $ cat /sys/bus/i2c/devices/0-0058/iio\:device0/in_intensity6_raw The array size of afe4404_channel_leds and afe4404_channel_offdacs are less than channels, so access with chan-&amp;gt;address cause OOB read in afe4404_[read|write]_raw. Fix it by moving access before use them.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-49032</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-3251 — Linux Kernel: Mehrere Schwachstellen ermöglichen Denial of Service</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-3251</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen oder andere, nicht näher bekannte Auswirkungen zu erzielen..&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen oder andere, nicht näher bekannte Auswirkungen zu erzielen..&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-3251</guid>
    </item>
  </channel>
</rss>
