<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 10 Oct 2026 16:58:11 +0000</lastBuildDate>
    <item>
      <title>CVE-2025-38232 — NFSD: fix race between nfsd registration and exports_proc</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2025-38232</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Linux, Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, Siemens SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP, Siemens SIPLUS S7-1500 CPU 1518-4 PN/DP MFP&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;NFSD: fix race between nfsd registration and exports_proc&lt;/p&gt;
&lt;p&gt;As of now nfsd calls create_proc_exports_entry() at start of init_nfsd
and cleanup by remove_proc_entry() at last of exit_nfsd.&lt;/p&gt;
&lt;p&gt;Which causes kernel OOPs if there is race between below 2 operations:
(i) exportfs -r
(ii) mount -t nfsd none /proc/fs/nfsd&lt;/p&gt;
&lt;p&gt;for 5.4 kernel ARM64:&lt;/p&gt;
&lt;p&gt;CPU 1:
el1_irq+0xbc/0x180
arch_counter_get_cntvct+0x14/0x18
running_clock+0xc/0x18
preempt_count_add+0x88/0x110
prep_new_page+0xb0/0x220
get_page_from_freelist+0x2d8/0x1778
__alloc_pages_nodemask+0x15c/0xef0
__vmalloc_node_range+0x28c/0x478
__vmalloc_node_flags_caller+0x8c/0xb0
kvmalloc_node+0x88/0xe0
nfsd_init_net+0x6c/0x108 [nfsd]
ops_init+0x44/0x170
register_pernet_operations+0x114/0x270
register_pernet_subsys+0x34/0x50
init_nfsd+0xa8/0x718 [nfsd]
do_one_initcall+0x54/0x2e0&lt;/p&gt;
&lt;p&gt;CPU 2 :
Unable to handle kernel NULL pointer dereference at virtual address 0000000000000010&lt;/p&gt;
&lt;p&gt;PC is at : exports_net_open+0x50/0x68 [nfsd]&lt;/p&gt;
&lt;p&gt;Call trace:
exports_net_open+0x50/0x68 [nfsd]
exports_proc_open+0x2c/0x38 [nfsd]
proc_reg_open+0xb8/0x198
do_dentry_open+0x1c4/0x418
vfs_open+0x38/0x48
path_openat+0x28c/0xf18
do_filp_open+0x70/0xe8
do_sys_open+0x154/0x248&lt;/p&gt;
&lt;p&gt;Sometimes it crashes at exports_net_open() and sometimes cache_seq_next_rcu().&lt;/p&gt;
&lt;p&gt;and same is happening on latest 6.14 kernel as well:&lt;/p&gt;
&lt;p&gt;[    0.000000] Linux version 6.14.0-rc5-next-20250304-dirty
...
[  285.455918] Unable to handle kernel paging req…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Linux, Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, Siemens SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP, Siemens SIPLUS S7-1500 CPU 1518-4 PN/DP MFP&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;NFSD: fix race between nfsd registration and exports_proc&lt;/p&gt;
&lt;p&gt;As of now nfsd calls create_proc_exports_entry() at start of init_nfsd
and cleanup by remove_proc_entry() at last of exit_nfsd.&lt;/p&gt;
&lt;p&gt;Which causes kernel OOPs if there is race between below 2 operations:
(i) exportfs -r
(ii) mount -t nfsd none /proc/fs/nfsd&lt;/p&gt;
&lt;p&gt;for 5.4 kernel ARM64:&lt;/p&gt;
&lt;p&gt;CPU 1:
el1_irq+0xbc/0x180
arch_counter_get_cntvct+0x14/0x18
running_clock+0xc/0x18
preempt_count_add+0x88/0x110
prep_new_page+0xb0/0x220
get_page_from_freelist+0x2d8/0x1778
__alloc_pages_nodemask+0x15c/0xef0
__vmalloc_node_range+0x28c/0x478
__vmalloc_node_flags_caller+0x8c/0xb0
kvmalloc_node+0x88/0xe0
nfsd_init_net+0x6c/0x108 [nfsd]
ops_init+0x44/0x170
register_pernet_operations+0x114/0x270
register_pernet_subsys+0x34/0x50
init_nfsd+0xa8/0x718 [nfsd]
do_one_initcall+0x54/0x2e0&lt;/p&gt;
&lt;p&gt;CPU 2 :
Unable to handle kernel NULL pointer dereference at virtual address 0000000000000010&lt;/p&gt;
&lt;p&gt;PC is at : exports_net_open+0x50/0x68 [nfsd]&lt;/p&gt;
&lt;p&gt;Call trace:
exports_net_open+0x50/0x68 [nfsd]
exports_proc_open+0x2c/0x38 [nfsd]
proc_reg_open+0xb8/0x198
do_dentry_open+0x1c4/0x418
vfs_open+0x38/0x48
path_openat+0x28c/0xf18
do_filp_open+0x70/0xe8
do_sys_open+0x154/0x248&lt;/p&gt;
&lt;p&gt;Sometimes it crashes at exports_net_open() and sometimes cache_seq_next_rcu().&lt;/p&gt;
&lt;p&gt;and same is happening on latest 6.14 kernel as well:&lt;/p&gt;
&lt;p&gt;[    0.000000] Linux version 6.14.0-rc5-next-20250304-dirty
...
[  285.455918] Unable to handle kernel paging req…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2025-38232</guid>
    </item>
    <item>
      <title>USN-7833-1 — linux, linux-aws, linux-gcp, linux-oem-6.14, linux-oracle, linux-oracle-6.14, linux-raspi, linux-realtime vulnerabiliti…</title>
      <link>https://cve.radiocsirt.org/vuln/usn-7833-1</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:24.04:LTS: linux-oem-6.14, Ubuntu:24.04:LTS: linux-oracle-6.14&lt;/p&gt;
&lt;p&gt;Oleksii Oleksenko, Cedric Fournet, Jana Hofmann, Boris Köpf, Stavros Volos,
and Flavien Solt discovered that some AMD processors may allow an attacker
to infer data from previous stores, potentially resulting in the leakage of
privileged information. A local attacker could possibly use this to expose
sensitive information. (CVE-2024-36350, CVE-2024-36357)&lt;/p&gt;
&lt;p&gt;Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
  - ARM64 architecture;
  - PowerPC architecture;
  - RISC-V architecture;
  - S390 architecture;
  - x86 architecture;
  - ACPI drivers;
  - Serial ATA and Parallel ATA drivers;
  - Drivers core;
  - ATA over ethernet (AOE) driver;
  - Ublk userspace block driver;
  - Bus devices;
  - DMA engine subsystem;
  - Arm Firmware Framework for ARMv8-A(FFA);
  - Cirrus firmware drivers;
  - GPU drivers;
  - HID subsystem;
  - Hardware monitoring drivers;
  - I2C subsystem;
  - InfiniBand drivers;
  - Input Device (Miscellaneous) drivers;
  - Multiple devices driver;
  - Media drivers;
  - TI TPS6594 PFSM driver;
  - MMC subsystem;
  - MTD block device drivers;
  - Network drivers;
  - NVME drivers;
  - x86 platform drivers;
  - RapidIO drivers;
  - Voltage and Current Regulator drivers;
  - Remote Processor subsystem;
  - S/390 drivers;
  - SCSI subsystem;
  - TCM subsystem;
  - Trusted Execution Environment drivers;
  - TTY drivers;
  - ChipIdea USB dr…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:24.04:LTS: linux-oem-6.14, Ubuntu:24.04:LTS: linux-oracle-6.14&lt;/p&gt;
&lt;p&gt;Oleksii Oleksenko, Cedric Fournet, Jana Hofmann, Boris Köpf, Stavros Volos,
and Flavien Solt discovered that some AMD processors may allow an attacker
to infer data from previous stores, potentially resulting in the leakage of
privileged information. A local attacker could possibly use this to expose
sensitive information. (CVE-2024-36350, CVE-2024-36357)&lt;/p&gt;
&lt;p&gt;Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
  - ARM64 architecture;
  - PowerPC architecture;
  - RISC-V architecture;
  - S390 architecture;
  - x86 architecture;
  - ACPI drivers;
  - Serial ATA and Parallel ATA drivers;
  - Drivers core;
  - ATA over ethernet (AOE) driver;
  - Ublk userspace block driver;
  - Bus devices;
  - DMA engine subsystem;
  - Arm Firmware Framework for ARMv8-A(FFA);
  - Cirrus firmware drivers;
  - GPU drivers;
  - HID subsystem;
  - Hardware monitoring drivers;
  - I2C subsystem;
  - InfiniBand drivers;
  - Input Device (Miscellaneous) drivers;
  - Multiple devices driver;
  - Media drivers;
  - TI TPS6594 PFSM driver;
  - MMC subsystem;
  - MTD block device drivers;
  - Network drivers;
  - NVME drivers;
  - x86 platform drivers;
  - RapidIO drivers;
  - Voltage and Current Regulator drivers;
  - Remote Processor subsystem;
  - S/390 drivers;
  - SCSI subsystem;
  - TCM subsystem;
  - Trusted Execution Environment drivers;
  - TTY drivers;
  - ChipIdea USB dr…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/usn-7833-1</guid>
    </item>
  </channel>
</rss>
