<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Thu, 08 Oct 2026 04:16:15 +0000</lastBuildDate>
    <item>
      <title>CVE-2025-68331 — usb: uas: fix urb unmapping issue when the uas device is remove during ongoing data transfer</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2025-68331</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Linux&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;usb: uas: fix urb unmapping issue when the uas device is remove during ongoing data transfer&lt;/p&gt;
&lt;p&gt;When a UAS device is unplugged during data transfer, there is
a probability of a system panic occurring. The root cause is
an access to an invalid memory address during URB callback handling.
Specifically, this happens when the dma_direct_unmap_sg() function
is called within the usb_hcd_unmap_urb_for_dma() interface, but the
sg-&amp;gt;dma_address field is 0 and the sg data structure has already been
freed.&lt;/p&gt;
&lt;p&gt;The SCSI driver sends transfer commands by invoking uas_queuecommand_lck()
in uas.c, using the uas_submit_urbs() function to submit requests to USB.
Within the uas_submit_urbs() implementation, three URBs (sense_urb,
data_urb, and cmd_urb) are sequentially submitted. Device removal may
occur at any point during uas_submit_urbs execution, which may result
in URB submission failure. However, some URBs might have been successfully
submitted before the failure, and uas_submit_urbs will return the -ENODEV
error code in this case. The current error handling directly calls
scsi_done(). In the SCSI driver, this eventually triggers scsi_complete()
to invoke scsi_end_request() for releasing the sgtable. The successfully
submitted URBs, when being unlinked to giveback, call
usb_hcd_unmap_urb_for_dma() in hcd.c, leading to exceptions during sg
unmapping operations since the sg data structure has already been freed.&lt;/p&gt;
&lt;p&gt;This patch mo…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Linux&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;usb: uas: fix urb unmapping issue when the uas device is remove during ongoing data transfer&lt;/p&gt;
&lt;p&gt;When a UAS device is unplugged during data transfer, there is
a probability of a system panic occurring. The root cause is
an access to an invalid memory address during URB callback handling.
Specifically, this happens when the dma_direct_unmap_sg() function
is called within the usb_hcd_unmap_urb_for_dma() interface, but the
sg-&amp;gt;dma_address field is 0 and the sg data structure has already been
freed.&lt;/p&gt;
&lt;p&gt;The SCSI driver sends transfer commands by invoking uas_queuecommand_lck()
in uas.c, using the uas_submit_urbs() function to submit requests to USB.
Within the uas_submit_urbs() implementation, three URBs (sense_urb,
data_urb, and cmd_urb) are sequentially submitted. Device removal may
occur at any point during uas_submit_urbs execution, which may result
in URB submission failure. However, some URBs might have been successfully
submitted before the failure, and uas_submit_urbs will return the -ENODEV
error code in this case. The current error handling directly calls
scsi_done(). In the SCSI driver, this eventually triggers scsi_complete()
to invoke scsi_end_request() for releasing the sgtable. The successfully
submitted URBs, when being unlinked to giveback, call
usb_hcd_unmap_urb_for_dma() in hcd.c, leading to exceptions during sg
unmapping operations since the sg data structure has already been freed.&lt;/p&gt;
&lt;p&gt;This patch mo…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2025-68331</guid>
    </item>
    <item>
      <title>USN-8094-1 — linux, linux-aws, linux-aws-6.17, linux-gcp, linux-hwe-6.17, linux-oracle, linux-oracle-6.17 vulnerabilities</title>
      <link>https://cve.radiocsirt.org/vuln/usn-8094-1</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:24.04:LTS: linux-aws-6.17, Ubuntu:24.04:LTS: linux-hwe-6.17, Ubuntu:24.04:LTS: linux-oracle-6.17, Ubuntu:25.10: linux, Ubuntu:25.10: linux-aws, Ubuntu:25.10: linux-gcp, Ubuntu:25.10: linux-oracle&lt;/p&gt;
&lt;p&gt;Qualys discovered that several vulnerabilities existed in the AppArmor
Linux kernel Security Module (LSM). An unprivileged local attacker could
use these issues to load, replace, and remove arbitrary AppArmor profiles
causing denial of service, exposure of sensitive information (kernel
memory), local privilege escalation, or possibly escape a container.
(LP: #2143853)&lt;/p&gt;
&lt;p&gt;It was discovered that some AMD Zen 5 processors supporting RDSEED
instruction did not properly handle entropy, potentially resulting in the
consumption of insufficiently random values. A local attacker could
possibly use this issue to influence the values returned by the RDSEED
instruction causing loss of confidentiality and integrity. (CVE-2025-62626)&lt;/p&gt;
&lt;p&gt;Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
  - ARM64 architecture;
  - S390 architecture;
  - x86 architecture;
  - Block layer subsystem;
  - Cryptographic API;
  - Compute Acceleration Framework;
  - ATM drivers;
  - Network block device driver;
  - Bluetooth drivers;
  - Data acquisition framework and drivers;
  - Hardware crypto device drivers;
  - Device frequency scaling framework;
  - Intel Stratix 10 firmware drivers;
  - GPIO subsystem;
  - GPU drivers;
  - Microsoft Hyper-V drivers;
  - CoreSight HW tracing drivers;
  - IIO subsystem;
  - InfiniBand drivers;
  - Input Device core drivers;
  - Input Device (Tablet) d…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:24.04:LTS: linux-aws-6.17, Ubuntu:24.04:LTS: linux-hwe-6.17, Ubuntu:24.04:LTS: linux-oracle-6.17, Ubuntu:25.10: linux, Ubuntu:25.10: linux-aws, Ubuntu:25.10: linux-gcp, Ubuntu:25.10: linux-oracle&lt;/p&gt;
&lt;p&gt;Qualys discovered that several vulnerabilities existed in the AppArmor
Linux kernel Security Module (LSM). An unprivileged local attacker could
use these issues to load, replace, and remove arbitrary AppArmor profiles
causing denial of service, exposure of sensitive information (kernel
memory), local privilege escalation, or possibly escape a container.
(LP: #2143853)&lt;/p&gt;
&lt;p&gt;It was discovered that some AMD Zen 5 processors supporting RDSEED
instruction did not properly handle entropy, potentially resulting in the
consumption of insufficiently random values. A local attacker could
possibly use this issue to influence the values returned by the RDSEED
instruction causing loss of confidentiality and integrity. (CVE-2025-62626)&lt;/p&gt;
&lt;p&gt;Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
  - ARM64 architecture;
  - S390 architecture;
  - x86 architecture;
  - Block layer subsystem;
  - Cryptographic API;
  - Compute Acceleration Framework;
  - ATM drivers;
  - Network block device driver;
  - Bluetooth drivers;
  - Data acquisition framework and drivers;
  - Hardware crypto device drivers;
  - Device frequency scaling framework;
  - Intel Stratix 10 firmware drivers;
  - GPIO subsystem;
  - GPU drivers;
  - Microsoft Hyper-V drivers;
  - CoreSight HW tracing drivers;
  - IIO subsystem;
  - InfiniBand drivers;
  - Input Device core drivers;
  - Input Device (Tablet) d…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/usn-8094-1</guid>
    </item>
  </channel>
</rss>
