<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 16:14:41 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-01236</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-01236</link>
      <description>bdu:2026-01236</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-01236</guid>
    </item>
    <item>
      <title>BELL-CVE-2023-54091</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2023-54091</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2023-54091</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0108 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de SUSE. Certaines d'entre elles permettent à un at…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0108</link>
      <description>certfr-2026-avi-0108</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0108</guid>
    </item>
    <item>
      <title>EUVD-2026-312363</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-312363</link>
      <description>EUVD-2026-312363</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-312363</guid>
    </item>
    <item>
      <title>fkie_cve-2023-54091</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2023-54091</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;drm/client: Fix memory leak in drm_client_target_cloned&lt;/p&gt;
&lt;p&gt;dmt_mode is allocated and never freed in this function.
It was found with the ast driver, but most drivers using generic fbdev
setup are probably affected.&lt;/p&gt;
&lt;p&gt;This fixes the following kmemleak report:
  backtrace:
    [&amp;lt;00000000b391296d&amp;gt;] drm_mode_duplicate+0x45/0x220 [drm]
    [&amp;lt;00000000e45bb5b3&amp;gt;] drm_client_target_cloned.constprop.0+0x27b/0x480 [drm]
    [&amp;lt;00000000ed2d3a37&amp;gt;] drm_client_modeset_probe+0x6bd/0xf50 [drm]
    [&amp;lt;0000000010e5cc9d&amp;gt;] __drm_fb_helper_initial_config_and_unlock+0xb4/0x2c0 [drm_kms_helper]
    [&amp;lt;00000000909f82ca&amp;gt;] drm_fbdev_client_hotplug+0x2bc/0x4d0 [drm_kms_helper]
    [&amp;lt;00000000063a69aa&amp;gt;] drm_client_register+0x169/0x240 [drm]
    [&amp;lt;00000000a8c61525&amp;gt;] ast_pci_probe+0x142/0x190 [ast]
    [&amp;lt;00000000987f19bb&amp;gt;] local_pci_probe+0xdc/0x180
    [&amp;lt;000000004fca231b&amp;gt;] work_for_cpu_fn+0x4e/0xa0
    [&amp;lt;0000000000b85301&amp;gt;] process_one_work+0x8b7/0x1540
    [&amp;lt;000000003375b17c&amp;gt;] worker_thread+0x70a/0xed0
    [&amp;lt;00000000b0d43cd9&amp;gt;] kthread+0x29f/0x340
    [&amp;lt;000000008d770833&amp;gt;] ret_from_fork+0x1f/0x30
unreferenced object 0xff11000333089a00 (size 128):&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;drm/client: Fix memory leak in drm_client_target_cloned&lt;/p&gt;
&lt;p&gt;dmt_mode is allocated and never freed in this function.
It was found with the ast driver, but most drivers using generic fbdev
setup are probably affected.&lt;/p&gt;
&lt;p&gt;This fixes the following kmemleak report:
  backtrace:
    [&amp;lt;00000000b391296d&amp;gt;] drm_mode_duplicate+0x45/0x220 [drm]
    [&amp;lt;00000000e45bb5b3&amp;gt;] drm_client_target_cloned.constprop.0+0x27b/0x480 [drm]
    [&amp;lt;00000000ed2d3a37&amp;gt;] drm_client_modeset_probe+0x6bd/0xf50 [drm]
    [&amp;lt;0000000010e5cc9d&amp;gt;] __drm_fb_helper_initial_config_and_unlock+0xb4/0x2c0 [drm_kms_helper]
    [&amp;lt;00000000909f82ca&amp;gt;] drm_fbdev_client_hotplug+0x2bc/0x4d0 [drm_kms_helper]
    [&amp;lt;00000000063a69aa&amp;gt;] drm_client_register+0x169/0x240 [drm]
    [&amp;lt;00000000a8c61525&amp;gt;] ast_pci_probe+0x142/0x190 [ast]
    [&amp;lt;00000000987f19bb&amp;gt;] local_pci_probe+0xdc/0x180
    [&amp;lt;000000004fca231b&amp;gt;] work_for_cpu_fn+0x4e/0xa0
    [&amp;lt;0000000000b85301&amp;gt;] process_one_work+0x8b7/0x1540
    [&amp;lt;000000003375b17c&amp;gt;] worker_thread+0x70a/0xed0
    [&amp;lt;00000000b0d43cd9&amp;gt;] kthread+0x29f/0x340
    [&amp;lt;000000008d770833&amp;gt;] ret_from_fork+0x1f/0x30
unreferenced object 0xff11000333089a00 (size 128):&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2023-54091</guid>
    </item>
    <item>
      <title>GHSA-h228-354g-ppq4</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-h228-354g-ppq4</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;drm/client: Fix memory leak in drm_client_target_cloned&lt;/p&gt;
&lt;p&gt;dmt_mode is allocated and never freed in this function.
It was found with the ast driver, but most drivers using generic fbdev
setup are probably affected.&lt;/p&gt;
&lt;p&gt;This fixes the following kmemleak report:
  backtrace:
    [&amp;lt;00000000b391296d&amp;gt;] drm_mode_duplicate+0x45/0x220 [drm]
    [&amp;lt;00000000e45bb5b3&amp;gt;] drm_client_target_cloned.constprop.0+0x27b/0x480 [drm]
    [&amp;lt;00000000ed2d3a37&amp;gt;] drm_client_modeset_probe+0x6bd/0xf50 [drm]
    [&amp;lt;0000000010e5cc9d&amp;gt;] __drm_fb_helper_initial_config_and_unlock+0xb4/0x2c0 [drm_kms_helper]
    [&amp;lt;00000000909f82ca&amp;gt;] drm_fbdev_client_hotplug+0x2bc/0x4d0 [drm_kms_helper]
    [&amp;lt;00000000063a69aa&amp;gt;] drm_client_register+0x169/0x240 [drm]
    [&amp;lt;00000000a8c61525&amp;gt;] ast_pci_probe+0x142/0x190 [ast]
    [&amp;lt;00000000987f19bb&amp;gt;] local_pci_probe+0xdc/0x180
    [&amp;lt;000000004fca231b&amp;gt;] work_for_cpu_fn+0x4e/0xa0
    [&amp;lt;0000000000b85301&amp;gt;] process_one_work+0x8b7/0x1540
    [&amp;lt;000000003375b17c&amp;gt;] worker_thread+0x70a/0xed0
    [&amp;lt;00000000b0d43cd9&amp;gt;] kthread+0x29f/0x340
    [&amp;lt;000000008d770833&amp;gt;] ret_from_fork+0x1f/0x30
unreferenced object 0xff11000333089a00 (size 128):&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;drm/client: Fix memory leak in drm_client_target_cloned&lt;/p&gt;
&lt;p&gt;dmt_mode is allocated and never freed in this function.
It was found with the ast driver, but most drivers using generic fbdev
setup are probably affected.&lt;/p&gt;
&lt;p&gt;This fixes the following kmemleak report:
  backtrace:
    [&amp;lt;00000000b391296d&amp;gt;] drm_mode_duplicate+0x45/0x220 [drm]
    [&amp;lt;00000000e45bb5b3&amp;gt;] drm_client_target_cloned.constprop.0+0x27b/0x480 [drm]
    [&amp;lt;00000000ed2d3a37&amp;gt;] drm_client_modeset_probe+0x6bd/0xf50 [drm]
    [&amp;lt;0000000010e5cc9d&amp;gt;] __drm_fb_helper_initial_config_and_unlock+0xb4/0x2c0 [drm_kms_helper]
    [&amp;lt;00000000909f82ca&amp;gt;] drm_fbdev_client_hotplug+0x2bc/0x4d0 [drm_kms_helper]
    [&amp;lt;00000000063a69aa&amp;gt;] drm_client_register+0x169/0x240 [drm]
    [&amp;lt;00000000a8c61525&amp;gt;] ast_pci_probe+0x142/0x190 [ast]
    [&amp;lt;00000000987f19bb&amp;gt;] local_pci_probe+0xdc/0x180
    [&amp;lt;000000004fca231b&amp;gt;] work_for_cpu_fn+0x4e/0xa0
    [&amp;lt;0000000000b85301&amp;gt;] process_one_work+0x8b7/0x1540
    [&amp;lt;000000003375b17c&amp;gt;] worker_thread+0x70a/0xed0
    [&amp;lt;00000000b0d43cd9&amp;gt;] kthread+0x29f/0x340
    [&amp;lt;000000008d770833&amp;gt;] ret_from_fork+0x1f/0x30
unreferenced object 0xff11000333089a00 (size 128):&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-h228-354g-ppq4</guid>
    </item>
    <item>
      <title>OESA-2026-1231 — kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-1231</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP4: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;scsi: libsas: Fix use-after-free bug in smp_execute_task_sg()&lt;/p&gt;
&lt;p&gt;When executing SMP task failed, the smp_execute_task_sg() calls del_timer()
to delete &amp;amp;quot;slow_task-&amp;amp;gt;timer&amp;amp;quot;. However, if the timer handler
sas_task_internal_timedout() is running, the del_timer() in
smp_execute_task_sg() will not stop it and a UAF will happen. The process
is shown below:&lt;/p&gt;
&lt;p&gt;(thread 1)               |        (thread 2)
smp_execute_task_sg()          | sas_task_internal_timedout()
 ...                           |
 del_timer()                   |
 ...                           |  ...
 sas_free_task(task)           |
  kfree(task-&amp;amp;gt;slow_task) //FREE|
                               |  task-&amp;amp;gt;slow_task-&amp;amp;gt;... //USE&lt;/p&gt;
&lt;p&gt;Fix by calling del_timer_sync() in smp_execute_task_sg(), which makes sure
the timer handler have finished before the &amp;amp;quot;task-&amp;amp;gt;slow_task&amp;amp;quot; is
deallocated.(CVE-2022-50422)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;ppp: associate skb with a device at tx&lt;/p&gt;
&lt;p&gt;Syzkaller triggered flow dissector warning with the following:&lt;/p&gt;
&lt;p&gt;r0 = openat$ppp(0xffffffffffffff9c, &amp;amp;amp;(0x7f0000000000), 0xc0802, 0x0)
ioctl$PPPIOCNEWUNIT(r0, 0xc004743e, &amp;amp;amp;(0x7f00000000c0))
ioctl$PPPIOCSACTIVE(r0, 0x40107446, &amp;amp;amp;(0x7f0000000240)={0x2, &amp;amp;amp;(0x7f0000000180)=[{0x20, 0x0, 0x0, 0xfffff034}, {0x6}]})
pwritev(r0, &amp;amp;amp;(0x7f0000…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP4: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;scsi: libsas: Fix use-after-free bug in smp_execute_task_sg()&lt;/p&gt;
&lt;p&gt;When executing SMP task failed, the smp_execute_task_sg() calls del_timer()
to delete &amp;amp;quot;slow_task-&amp;amp;gt;timer&amp;amp;quot;. However, if the timer handler
sas_task_internal_timedout() is running, the del_timer() in
smp_execute_task_sg() will not stop it and a UAF will happen. The process
is shown below:&lt;/p&gt;
&lt;p&gt;(thread 1)               |        (thread 2)
smp_execute_task_sg()          | sas_task_internal_timedout()
 ...                           |
 del_timer()                   |
 ...                           |  ...
 sas_free_task(task)           |
  kfree(task-&amp;amp;gt;slow_task) //FREE|
                               |  task-&amp;amp;gt;slow_task-&amp;amp;gt;... //USE&lt;/p&gt;
&lt;p&gt;Fix by calling del_timer_sync() in smp_execute_task_sg(), which makes sure
the timer handler have finished before the &amp;amp;quot;task-&amp;amp;gt;slow_task&amp;amp;quot; is
deallocated.(CVE-2022-50422)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;ppp: associate skb with a device at tx&lt;/p&gt;
&lt;p&gt;Syzkaller triggered flow dissector warning with the following:&lt;/p&gt;
&lt;p&gt;r0 = openat$ppp(0xffffffffffffff9c, &amp;amp;amp;(0x7f0000000000), 0xc0802, 0x0)
ioctl$PPPIOCNEWUNIT(r0, 0xc004743e, &amp;amp;amp;(0x7f00000000c0))
ioctl$PPPIOCSACTIVE(r0, 0x40107446, &amp;amp;amp;(0x7f0000000240)={0x2, &amp;amp;amp;(0x7f0000000180)=[{0x20, 0x0, 0x0, 0xfffff034}, {0x6}]})
pwritev(r0, &amp;amp;amp;(0x7f0000…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-1231</guid>
    </item>
    <item>
      <title>RHSA-2023:7077 — security update for kernel</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2023:7077</link>
      <description>&lt;p&gt;security update for kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;security update for kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2023:7077</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:0263-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:0263-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:0263-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2023-54091</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-54091</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux, Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe and 163 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: drm/client: Fix memory leak in drm_client_target_cloned dmt_mode is allocated and never freed in this function. It was found with the ast driver, but most drivers using generic fbdev setup are probably affected. This fixes the following kmemleak report:   backtrace:     [&amp;lt;00000000b391296d&amp;gt;] drm_mode_duplicate+0x45/0x220 [drm]     [&amp;lt;00000000e45bb5b3&amp;gt;] drm_client_target_cloned.constprop.0+0x27b/0x480 [drm]     [&amp;lt;00000000ed2d3a37&amp;gt;] drm_client_modeset_probe+0x6bd/0xf50 [drm]     [&amp;lt;0000000010e5cc9d&amp;gt;] __drm_fb_helper_initial_config_and_unlock+0xb4/0x2c0 [drm_kms_helper]     [&amp;lt;00000000909f82ca&amp;gt;] drm_fbdev_client_hotplug+0x2bc/0x4d0 [drm_kms_helper]     [&amp;lt;00000000063a69aa&amp;gt;] drm_client_register+0x169/0x240 [drm]     [&amp;lt;00000000a8c61525&amp;gt;] ast_pci_probe+0x142/0x190 [ast]     [&amp;lt;00000000987f19bb&amp;gt;] local_pci_probe+0xdc/0x180     [&amp;lt;000000004fca231b&amp;gt;] work_for_cpu_fn+0x4e/0xa0     [&amp;lt;0000000000b85301&amp;gt;] process_one_work+0x8b7/0x1540     [&amp;lt;000000003375b17c&amp;gt;] worker_thread+0x70a/0xed0     [&amp;lt;00000000b0d43cd9&amp;gt;] kthread+0x29f/0x340     [&amp;lt;000000008d770833&amp;gt;] ret_from_fork+0x1f/0x30 unreferenced object 0xff11000333089a00 (size 128):&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux, Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe and 163 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: drm/client: Fix memory leak in drm_client_target_cloned dmt_mode is allocated and never freed in this function. It was found with the ast driver, but most drivers using generic fbdev setup are probably affected. This fixes the following kmemleak report:   backtrace:     [&amp;lt;00000000b391296d&amp;gt;] drm_mode_duplicate+0x45/0x220 [drm]     [&amp;lt;00000000e45bb5b3&amp;gt;] drm_client_target_cloned.constprop.0+0x27b/0x480 [drm]     [&amp;lt;00000000ed2d3a37&amp;gt;] drm_client_modeset_probe+0x6bd/0xf50 [drm]     [&amp;lt;0000000010e5cc9d&amp;gt;] __drm_fb_helper_initial_config_and_unlock+0xb4/0x2c0 [drm_kms_helper]     [&amp;lt;00000000909f82ca&amp;gt;] drm_fbdev_client_hotplug+0x2bc/0x4d0 [drm_kms_helper]     [&amp;lt;00000000063a69aa&amp;gt;] drm_client_register+0x169/0x240 [drm]     [&amp;lt;00000000a8c61525&amp;gt;] ast_pci_probe+0x142/0x190 [ast]     [&amp;lt;00000000987f19bb&amp;gt;] local_pci_probe+0xdc/0x180     [&amp;lt;000000004fca231b&amp;gt;] work_for_cpu_fn+0x4e/0xa0     [&amp;lt;0000000000b85301&amp;gt;] process_one_work+0x8b7/0x1540     [&amp;lt;000000003375b17c&amp;gt;] worker_thread+0x70a/0xed0     [&amp;lt;00000000b0d43cd9&amp;gt;] kthread+0x29f/0x340     [&amp;lt;000000008d770833&amp;gt;] ret_from_fork+0x1f/0x30 unreferenced object 0xff11000333089a00 (size 128):&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-54091</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-2929 — Linux Kernel: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2929</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux-Kernel ausnutzen, um nicht näher spezifizierte Angriffe durchzuführen, die möglicherweise zu einer Denial-of-Service- Bedingung führen oder eine Speicherbeschädigung verursachen können.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux-Kernel ausnutzen, um nicht näher spezifizierte Angriffe durchzuführen, die möglicherweise zu einer Denial-of-Service- Bedingung führen oder eine Speicherbeschädigung verursachen können.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2929</guid>
    </item>
  </channel>
</rss>
