<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 10:39:54 +0000</lastBuildDate>
    <item>
      <title>CVE-2025-38136 — usb: renesas_usbhs: Reorder clock handling and power management in probe</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2025-38136</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Linux&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;usb: renesas_usbhs: Reorder clock handling and power management in probe&lt;/p&gt;
&lt;p&gt;Reorder the initialization sequence in `usbhs_probe()` to enable runtime
PM before accessing registers, preventing potential crashes due to
uninitialized clocks.&lt;/p&gt;
&lt;p&gt;Currently, in the probe path, registers are accessed before enabling the
clocks, leading to a synchronous external abort on the RZ/V2H SoC.
The problematic call flow is as follows:&lt;/p&gt;
&lt;p&gt;usbhs_probe()
        usbhs_sys_clock_ctrl()
            usbhs_bset()
                usbhs_write()
                    iowrite16()  &amp;lt;-- Register access before enabling clocks&lt;/p&gt;
&lt;p&gt;Since `iowrite16()` is performed without ensuring the required clocks are
enabled, this can lead to access errors. To fix this, enable PM runtime
early in the probe function and ensure clocks are acquired before register
access, preventing crashes like the following on RZ/V2H:&lt;/p&gt;
&lt;p&gt;[13.272640] Internal error: synchronous external abort: 0000000096000010 [#1] PREEMPT SMP
[13.280814] Modules linked in: cec renesas_usbhs(+) drm_kms_helper fuse drm backlight ipv6
[13.289088] CPU: 1 UID: 0 PID: 195 Comm: (udev-worker) Not tainted 6.14.0-rc7+ #98
[13.296640] Hardware name: Renesas RZ/V2H EVK Board based on r9a09g057h44 (DT)
[13.303834] pstate: 60400005 (nZCv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)
[13.310770] pc : usbhs_bset+0x14/0x4c [renesas_usbhs]
[13.315831] lr : usbhs_probe+0x2e4/0x5ac [renesas_usbhs]
[13.321138] sp : ffff…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Linux&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;usb: renesas_usbhs: Reorder clock handling and power management in probe&lt;/p&gt;
&lt;p&gt;Reorder the initialization sequence in `usbhs_probe()` to enable runtime
PM before accessing registers, preventing potential crashes due to
uninitialized clocks.&lt;/p&gt;
&lt;p&gt;Currently, in the probe path, registers are accessed before enabling the
clocks, leading to a synchronous external abort on the RZ/V2H SoC.
The problematic call flow is as follows:&lt;/p&gt;
&lt;p&gt;usbhs_probe()
        usbhs_sys_clock_ctrl()
            usbhs_bset()
                usbhs_write()
                    iowrite16()  &amp;lt;-- Register access before enabling clocks&lt;/p&gt;
&lt;p&gt;Since `iowrite16()` is performed without ensuring the required clocks are
enabled, this can lead to access errors. To fix this, enable PM runtime
early in the probe function and ensure clocks are acquired before register
access, preventing crashes like the following on RZ/V2H:&lt;/p&gt;
&lt;p&gt;[13.272640] Internal error: synchronous external abort: 0000000096000010 [#1] PREEMPT SMP
[13.280814] Modules linked in: cec renesas_usbhs(+) drm_kms_helper fuse drm backlight ipv6
[13.289088] CPU: 1 UID: 0 PID: 195 Comm: (udev-worker) Not tainted 6.14.0-rc7+ #98
[13.296640] Hardware name: Renesas RZ/V2H EVK Board based on r9a09g057h44 (DT)
[13.303834] pstate: 60400005 (nZCv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)
[13.310770] pc : usbhs_bset+0x14/0x4c [renesas_usbhs]
[13.315831] lr : usbhs_probe+0x2e4/0x5ac [renesas_usbhs]
[13.321138] sp : ffff…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2025-38136</guid>
    </item>
    <item>
      <title>USN-7769-1 — linux, linux-aws, linux-gcp, linux-gcp-6.14, linux-oracle, linux-realtime vulnerabilities</title>
      <link>https://cve.radiocsirt.org/vuln/usn-7769-1</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:24.04:LTS: linux-gcp-6.14&lt;/p&gt;
&lt;p&gt;Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
  - ARM64 architecture;
  - PowerPC architecture;
  - x86 architecture;
  - Block layer subsystem;
  - Cryptographic API;
  - ACPI drivers;
  - Android drivers;
  - Bluetooth drivers;
  - Bus devices;
  - Clock framework and drivers;
  - CPU frequency scaling framework;
  - Hardware crypto device drivers;
  - DMA engine subsystem;
  - EDAC drivers;
  - Arm Firmware Framework for ARMv8-A(FFA);
  - FPGA Framework;
  - GPIO subsystem;
  - GPU drivers;
  - HID subsystem;
  - Hardware monitoring drivers;
  - HW tracing;
  - InfiniBand drivers;
  - IOMMU subsystem;
  - Multiple devices driver;
  - Media drivers;
  - VMware VMCI Driver;
  - MTD block device drivers;
  - Network drivers;
  - Mellanox network drivers;
  - STMicroelectronics network drivers;
  - NVDIMM (Non-Volatile Memory Device) drivers;
  - NVME drivers;
  - NVMEM (Non Volatile Memory) drivers;
  - PCI subsystem;
  - Amlogic Meson DDR PMU;
  - NI-700 PMU driver;
  - PHY drivers;
  - Pin controllers subsystem;
  - x86 platform drivers;
  - PTP clock framework;
  - SCSI subsystem;
  - ASPEED SoC drivers;
  - SPI subsystem;
  - TCM subsystem;
  - Thunderbolt and USB4 drivers;
  - TTY drivers;
  - UFS subsystem;
  - USB core drivers;
  - USB Gadget drivers;
  - Renesas USBHS Controller drivers;
  - USB Type-C Port Controller Manager driver;…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:24.04:LTS: linux-gcp-6.14&lt;/p&gt;
&lt;p&gt;Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
  - ARM64 architecture;
  - PowerPC architecture;
  - x86 architecture;
  - Block layer subsystem;
  - Cryptographic API;
  - ACPI drivers;
  - Android drivers;
  - Bluetooth drivers;
  - Bus devices;
  - Clock framework and drivers;
  - CPU frequency scaling framework;
  - Hardware crypto device drivers;
  - DMA engine subsystem;
  - EDAC drivers;
  - Arm Firmware Framework for ARMv8-A(FFA);
  - FPGA Framework;
  - GPIO subsystem;
  - GPU drivers;
  - HID subsystem;
  - Hardware monitoring drivers;
  - HW tracing;
  - InfiniBand drivers;
  - IOMMU subsystem;
  - Multiple devices driver;
  - Media drivers;
  - VMware VMCI Driver;
  - MTD block device drivers;
  - Network drivers;
  - Mellanox network drivers;
  - STMicroelectronics network drivers;
  - NVDIMM (Non-Volatile Memory Device) drivers;
  - NVME drivers;
  - NVMEM (Non Volatile Memory) drivers;
  - PCI subsystem;
  - Amlogic Meson DDR PMU;
  - NI-700 PMU driver;
  - PHY drivers;
  - Pin controllers subsystem;
  - x86 platform drivers;
  - PTP clock framework;
  - SCSI subsystem;
  - ASPEED SoC drivers;
  - SPI subsystem;
  - TCM subsystem;
  - Thunderbolt and USB4 drivers;
  - TTY drivers;
  - UFS subsystem;
  - USB core drivers;
  - USB Gadget drivers;
  - Renesas USBHS Controller drivers;
  - USB Type-C Port Controller Manager driver;…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/usn-7769-1</guid>
    </item>
  </channel>
</rss>
