<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Thu, 08 Oct 2026 15:44:03 +0000</lastBuildDate>
    <item>
      <title>CVE-2024-49865 — drm/xe/vm: move xa_alloc to prevent UAF</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2024-49865</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Linux&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;drm/xe/vm: move xa_alloc to prevent UAF&lt;/p&gt;
&lt;p&gt;Evil user can guess the next id of the vm before the ioctl completes and
then call vm destroy ioctl to trigger UAF since create ioctl is still
referencing the same vm. Move the xa_alloc all the way to the end to
prevent this.&lt;/p&gt;
&lt;p&gt;v2:
 - Rebase&lt;/p&gt;
&lt;p&gt;(cherry picked from commit dcfd3971327f3ee92765154baebbaece833d3ca9)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Linux&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;drm/xe/vm: move xa_alloc to prevent UAF&lt;/p&gt;
&lt;p&gt;Evil user can guess the next id of the vm before the ioctl completes and
then call vm destroy ioctl to trigger UAF since create ioctl is still
referencing the same vm. Move the xa_alloc all the way to the end to
prevent this.&lt;/p&gt;
&lt;p&gt;v2:
 - Rebase&lt;/p&gt;
&lt;p&gt;(cherry picked from commit dcfd3971327f3ee92765154baebbaece833d3ca9)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2024-49865</guid>
    </item>
    <item>
      <title>USN-7276-1 — linux, linux-lowlatency vulnerabilities</title>
      <link>https://cve.radiocsirt.org/vuln/usn-7276-1</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:24.10: linux, Ubuntu:24.10: linux-lowlatency&lt;/p&gt;
&lt;p&gt;Attila Szász discovered that the HFS+ file system implementation in the
Linux Kernel contained a heap overflow vulnerability. An attacker could use
a specially crafted file system image that, when mounted, could cause a
denial of service (system crash) or possibly execute arbitrary code.
(CVE-2025-0927)&lt;/p&gt;
&lt;p&gt;Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
  - ARM32 architecture;
  - ARM64 architecture;
  - PowerPC architecture;
  - RISC-V architecture;
  - S390 architecture;
  - SuperH RISC architecture;
  - User-Mode Linux (UML);
  - x86 architecture;
  - Block layer subsystem;
  - Cryptographic API;
  - Compute Acceleration Framework;
  - ACPI drivers;
  - Drivers core;
  - ATA over ethernet (AOE) driver;
  - RAM backed block device driver;
  - Network block device driver;
  - Ublk userspace block driver;
  - Compressed RAM block device driver;
  - Bluetooth drivers;
  - TPM device driver;
  - Clock framework and drivers;
  - Data acquisition framework and drivers;
  - CPU frequency scaling framework;
  - Hardware crypto device drivers;
  - CXL (Compute Express Link) drivers;
  - DAX dirext access to differentiated memory framework;
  - Buffer Sharing and Synchronization framework;
  - EDAC drivers;
  - FireWire subsystem;
  - ARM SCMI message protocol;
  - ARM SCPI message protocol;
  - EFI core;
  - Qualcomm firmware drivers;
  - GPIO subsystem;…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:24.10: linux, Ubuntu:24.10: linux-lowlatency&lt;/p&gt;
&lt;p&gt;Attila Szász discovered that the HFS+ file system implementation in the
Linux Kernel contained a heap overflow vulnerability. An attacker could use
a specially crafted file system image that, when mounted, could cause a
denial of service (system crash) or possibly execute arbitrary code.
(CVE-2025-0927)&lt;/p&gt;
&lt;p&gt;Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
  - ARM32 architecture;
  - ARM64 architecture;
  - PowerPC architecture;
  - RISC-V architecture;
  - S390 architecture;
  - SuperH RISC architecture;
  - User-Mode Linux (UML);
  - x86 architecture;
  - Block layer subsystem;
  - Cryptographic API;
  - Compute Acceleration Framework;
  - ACPI drivers;
  - Drivers core;
  - ATA over ethernet (AOE) driver;
  - RAM backed block device driver;
  - Network block device driver;
  - Ublk userspace block driver;
  - Compressed RAM block device driver;
  - Bluetooth drivers;
  - TPM device driver;
  - Clock framework and drivers;
  - Data acquisition framework and drivers;
  - CPU frequency scaling framework;
  - Hardware crypto device drivers;
  - CXL (Compute Express Link) drivers;
  - DAX dirext access to differentiated memory framework;
  - Buffer Sharing and Synchronization framework;
  - EDAC drivers;
  - FireWire subsystem;
  - ARM SCMI message protocol;
  - ARM SCPI message protocol;
  - EFI core;
  - Qualcomm firmware drivers;
  - GPIO subsystem;…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/usn-7276-1</guid>
    </item>
  </channel>
</rss>
