<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 09 Oct 2026 07:28:23 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-04329</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-04329</link>
      <description>bdu:2026-04329</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-04329</guid>
    </item>
    <item>
      <title>BELL-CVE-2025-39904</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2025-39904</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2025-39904</guid>
    </item>
    <item>
      <title>EUVD-2026-314817</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-314817</link>
      <description>EUVD-2026-314817</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-314817</guid>
    </item>
    <item>
      <title>fkie_cve-2025-39904</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-39904</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;arm64: kexec: initialize kexec_buf struct in load_other_segments()&lt;/p&gt;
&lt;p&gt;Patch series &amp;#34;kexec: Fix invalid field access&amp;#34;.&lt;/p&gt;
&lt;p&gt;The kexec_buf structure was previously declared without initialization. 
commit bf454ec31add (&amp;#34;kexec_file: allow to place kexec_buf randomly&amp;#34;)
added a field that is always read but not consistently populated by all
architectures.  This un-initialized field will contain garbage.&lt;/p&gt;
&lt;p&gt;This is also triggering a UBSAN warning when the uninitialized data was
accessed:&lt;/p&gt;
&lt;p&gt;------------[ cut here ]------------
	UBSAN: invalid-load in ./include/linux/kexec.h:210:10
	load of value 252 is not a valid value for type &amp;#39;_Bool&amp;#39;&lt;/p&gt;
&lt;p&gt;Zero-initializing kexec_buf at declaration ensures all fields are cleanly
set, preventing future instances of uninitialized memory being used.&lt;/p&gt;
&lt;p&gt;An initial fix was already landed for arm64[0], and this patchset fixes
the problem on the remaining arm64 code and on riscv, as raised by Mark.&lt;/p&gt;
&lt;p&gt;Discussions about this problem could be found at[1][2].&lt;/p&gt;
&lt;p&gt;This patch (of 3):&lt;/p&gt;
&lt;p&gt;The kexec_buf structure was previously declared without initialization.
commit bf454ec31add (&amp;#34;kexec_file: allow to place kexec_buf randomly&amp;#34;)
added a field that is always read but not consistently populated by all
architectures. This un-initialized field will contain garbage.&lt;/p&gt;
&lt;p&gt;This is also triggering a UBSAN warning when the uninitialized data was
accessed:&lt;/p&gt;
&lt;p&gt;------------[ cut here ]------------
	UBSAN: invalid-load in ./includ…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;arm64: kexec: initialize kexec_buf struct in load_other_segments()&lt;/p&gt;
&lt;p&gt;Patch series &amp;#34;kexec: Fix invalid field access&amp;#34;.&lt;/p&gt;
&lt;p&gt;The kexec_buf structure was previously declared without initialization. 
commit bf454ec31add (&amp;#34;kexec_file: allow to place kexec_buf randomly&amp;#34;)
added a field that is always read but not consistently populated by all
architectures.  This un-initialized field will contain garbage.&lt;/p&gt;
&lt;p&gt;This is also triggering a UBSAN warning when the uninitialized data was
accessed:&lt;/p&gt;
&lt;p&gt;------------[ cut here ]------------
	UBSAN: invalid-load in ./include/linux/kexec.h:210:10
	load of value 252 is not a valid value for type &amp;#39;_Bool&amp;#39;&lt;/p&gt;
&lt;p&gt;Zero-initializing kexec_buf at declaration ensures all fields are cleanly
set, preventing future instances of uninitialized memory being used.&lt;/p&gt;
&lt;p&gt;An initial fix was already landed for arm64[0], and this patchset fixes
the problem on the remaining arm64 code and on riscv, as raised by Mark.&lt;/p&gt;
&lt;p&gt;Discussions about this problem could be found at[1][2].&lt;/p&gt;
&lt;p&gt;This patch (of 3):&lt;/p&gt;
&lt;p&gt;The kexec_buf structure was previously declared without initialization.
commit bf454ec31add (&amp;#34;kexec_file: allow to place kexec_buf randomly&amp;#34;)
added a field that is always read but not consistently populated by all
architectures. This un-initialized field will contain garbage.&lt;/p&gt;
&lt;p&gt;This is also triggering a UBSAN warning when the uninitialized data was
accessed:&lt;/p&gt;
&lt;p&gt;------------[ cut here ]------------
	UBSAN: invalid-load in ./includ…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-39904</guid>
    </item>
    <item>
      <title>GHSA-9j3f-w66p-jqvg</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-9j3f-w66p-jqvg</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;arm64: kexec: initialize kexec_buf struct in load_other_segments()&lt;/p&gt;
&lt;p&gt;Patch series &amp;#34;kexec: Fix invalid field access&amp;#34;.&lt;/p&gt;
&lt;p&gt;The kexec_buf structure was previously declared without initialization. 
commit bf454ec31add (&amp;#34;kexec_file: allow to place kexec_buf randomly&amp;#34;)
added a field that is always read but not consistently populated by all
architectures.  This un-initialized field will contain garbage.&lt;/p&gt;
&lt;p&gt;This is also triggering a UBSAN warning when the uninitialized data was
accessed:&lt;/p&gt;
&lt;p&gt;------------[ cut here ]------------
	UBSAN: invalid-load in ./include/linux/kexec.h:210:10
	load of value 252 is not a valid value for type &amp;#39;_Bool&amp;#39;&lt;/p&gt;
&lt;p&gt;Zero-initializing kexec_buf at declaration ensures all fields are cleanly
set, preventing future instances of uninitialized memory being used.&lt;/p&gt;
&lt;p&gt;An initial fix was already landed for arm64[0], and this patchset fixes
the problem on the remaining arm64 code and on riscv, as raised by Mark.&lt;/p&gt;
&lt;p&gt;Discussions about this problem could be found at[1][2].&lt;/p&gt;
&lt;p&gt;This patch (of 3):&lt;/p&gt;
&lt;p&gt;The kexec_buf structure was previously declared without initialization.
commit bf454ec31add (&amp;#34;kexec_file: allow to place kexec_buf randomly&amp;#34;)
added a field that is always read but not consistently populated by all
architectures. This un-initialized field will contain garbage.&lt;/p&gt;
&lt;p&gt;This is also triggering a UBSAN warning when the uninitialized data was
accessed:&lt;/p&gt;
&lt;p&gt;------------[ cut here ]------------
	UBSAN: invalid-load in ./includ…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;arm64: kexec: initialize kexec_buf struct in load_other_segments()&lt;/p&gt;
&lt;p&gt;Patch series &amp;#34;kexec: Fix invalid field access&amp;#34;.&lt;/p&gt;
&lt;p&gt;The kexec_buf structure was previously declared without initialization. 
commit bf454ec31add (&amp;#34;kexec_file: allow to place kexec_buf randomly&amp;#34;)
added a field that is always read but not consistently populated by all
architectures.  This un-initialized field will contain garbage.&lt;/p&gt;
&lt;p&gt;This is also triggering a UBSAN warning when the uninitialized data was
accessed:&lt;/p&gt;
&lt;p&gt;------------[ cut here ]------------
	UBSAN: invalid-load in ./include/linux/kexec.h:210:10
	load of value 252 is not a valid value for type &amp;#39;_Bool&amp;#39;&lt;/p&gt;
&lt;p&gt;Zero-initializing kexec_buf at declaration ensures all fields are cleanly
set, preventing future instances of uninitialized memory being used.&lt;/p&gt;
&lt;p&gt;An initial fix was already landed for arm64[0], and this patchset fixes
the problem on the remaining arm64 code and on riscv, as raised by Mark.&lt;/p&gt;
&lt;p&gt;Discussions about this problem could be found at[1][2].&lt;/p&gt;
&lt;p&gt;This patch (of 3):&lt;/p&gt;
&lt;p&gt;The kexec_buf structure was previously declared without initialization.
commit bf454ec31add (&amp;#34;kexec_file: allow to place kexec_buf randomly&amp;#34;)
added a field that is always read but not consistently populated by all
architectures. This un-initialized field will contain garbage.&lt;/p&gt;
&lt;p&gt;This is also triggering a UBSAN warning when the uninitialized data was
accessed:&lt;/p&gt;
&lt;p&gt;------------[ cut here ]------------
	UBSAN: invalid-load in ./includ…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-9j3f-w66p-jqvg</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-39904</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-39904</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 79 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: arm64: kexec: initialize kexec_buf struct in load_other_segments() Patch series &amp;#34;kexec: Fix invalid field access&amp;#34;. The kexec_buf structure was previously declared without initialization. commit bf454ec31add (&amp;#34;kexec_file: allow to place kexec_buf randomly&amp;#34;) added a field that is always read but not consistently populated by all architectures.  This un-initialized field will contain garbage. This is also triggering a UBSAN warning when the uninitialized data was accessed: 	------------[ cut here ]------------ 	UBSAN: invalid-load in ./include/linux/kexec.h:210:10 	load of value 252 is not a valid value for type &amp;#39;_Bool&amp;#39; Zero-initializing kexec_buf at declaration ensures all fields are cleanly set, preventing future instances of uninitialized memory being used. An initial fix was already landed for arm64[0], and this patchset fixes the problem on the remaining arm64 code and on riscv, as raised by Mark. Discussions about this problem could be found at[1][2]. This patch (of 3): The kexec_buf structure was previously declared without initialization. commit bf454ec31add (&amp;#34;kexec_file: allow to place kexec_buf randomly&amp;#34;) added a field that is always read but not consistently populated by all architectures. This un-initialized field will contain garbage. This is also triggering a UBSAN warning when the uninitialized data was accessed: 	------------[ cut here ]------------ 	UBSAN: invalid-load in ./include/linux/kexec.…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 79 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: arm64: kexec: initialize kexec_buf struct in load_other_segments() Patch series &amp;#34;kexec: Fix invalid field access&amp;#34;. The kexec_buf structure was previously declared without initialization. commit bf454ec31add (&amp;#34;kexec_file: allow to place kexec_buf randomly&amp;#34;) added a field that is always read but not consistently populated by all architectures.  This un-initialized field will contain garbage. This is also triggering a UBSAN warning when the uninitialized data was accessed: 	------------[ cut here ]------------ 	UBSAN: invalid-load in ./include/linux/kexec.h:210:10 	load of value 252 is not a valid value for type &amp;#39;_Bool&amp;#39; Zero-initializing kexec_buf at declaration ensures all fields are cleanly set, preventing future instances of uninitialized memory being used. An initial fix was already landed for arm64[0], and this patchset fixes the problem on the remaining arm64 code and on riscv, as raised by Mark. Discussions about this problem could be found at[1][2]. This patch (of 3): The kexec_buf structure was previously declared without initialization. commit bf454ec31add (&amp;#34;kexec_file: allow to place kexec_buf randomly&amp;#34;) added a field that is always read but not consistently populated by all architectures. This un-initialized field will contain garbage. This is also triggering a UBSAN warning when the uninitialized data was accessed: 	------------[ cut here ]------------ 	UBSAN: invalid-load in ./include/linux/kexec.…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-39904</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-2170 — Linux Kernel: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2170</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen und andere nicht näher spezifizierte Angriffe durchzuführen, möglicherweise um beliebigen Code auszuführen oder eine Speicherbeschädigung zu verursachen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen und andere nicht näher spezifizierte Angriffe durchzuführen, möglicherweise um beliebigen Code auszuführen oder eine Speicherbeschädigung zu verursachen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2170</guid>
    </item>
  </channel>
</rss>
