<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 09 Oct 2026 10:21:11 +0000</lastBuildDate>
    <item>
      <title>CVE-2025-71085 — ipv6: BUG() in pskb_expand_head() as part of calipso_skbuff_setattr()</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2025-71085</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Linux, Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, Siemens SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP, Siemens SIPLUS S7-1500 CPU 1518-4 PN/DP MFP&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;ipv6: BUG() in pskb_expand_head() as part of calipso_skbuff_setattr()&lt;/p&gt;
&lt;p&gt;There exists a kernel oops caused by a BUG_ON(nhead &amp;lt; 0) at
net/core/skbuff.c:2232 in pskb_expand_head().
This bug is triggered as part of the calipso_skbuff_setattr()
routine when skb_cow() is passed headroom &amp;gt; INT_MAX
(i.e. (int)(skb_headroom(skb) + len_delta) &amp;lt; 0).&lt;/p&gt;
&lt;p&gt;The root cause of the bug is due to an implicit integer cast in
__skb_cow(). The check (headroom &amp;gt; skb_headroom(skb)) is meant to ensure
that delta = headroom - skb_headroom(skb) is never negative, otherwise
we will trigger a BUG_ON in pskb_expand_head(). However, if
headroom &amp;gt; INT_MAX and delta &amp;lt;= -NET_SKB_PAD, the check passes, delta
becomes negative, and pskb_expand_head() is passed a negative value for
nhead.&lt;/p&gt;
&lt;p&gt;Fix the trigger condition in calipso_skbuff_setattr(). Avoid passing
&amp;#34;negative&amp;#34; headroom sizes to skb_cow() within calipso_skbuff_setattr()
by only using skb_cow() to grow headroom.&lt;/p&gt;
&lt;p&gt;PoC:
	Using `netlabelctl` tool:&lt;/p&gt;
&lt;p&gt;netlabelctl map del default
        netlabelctl calipso add pass doi:7
        netlabelctl map add default address:0::1/128 protocol:calipso,7&lt;/p&gt;
&lt;p&gt;Then run the following PoC:&lt;/p&gt;
&lt;p&gt;int fd = socket(AF_INET6, SOCK_DGRAM, IPPROTO_UDP);&lt;/p&gt;
&lt;p&gt;// setup msghdr
        int cmsg_size = 2;
        int cmsg_len = 0x60;
        struct msghdr msg;
        struct sockaddr_in6 dest_addr;
        struct cmsghdr * cmsg = (struct cmsghdr *) calloc(1…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Linux, Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, Siemens SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP, Siemens SIPLUS S7-1500 CPU 1518-4 PN/DP MFP&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;ipv6: BUG() in pskb_expand_head() as part of calipso_skbuff_setattr()&lt;/p&gt;
&lt;p&gt;There exists a kernel oops caused by a BUG_ON(nhead &amp;lt; 0) at
net/core/skbuff.c:2232 in pskb_expand_head().
This bug is triggered as part of the calipso_skbuff_setattr()
routine when skb_cow() is passed headroom &amp;gt; INT_MAX
(i.e. (int)(skb_headroom(skb) + len_delta) &amp;lt; 0).&lt;/p&gt;
&lt;p&gt;The root cause of the bug is due to an implicit integer cast in
__skb_cow(). The check (headroom &amp;gt; skb_headroom(skb)) is meant to ensure
that delta = headroom - skb_headroom(skb) is never negative, otherwise
we will trigger a BUG_ON in pskb_expand_head(). However, if
headroom &amp;gt; INT_MAX and delta &amp;lt;= -NET_SKB_PAD, the check passes, delta
becomes negative, and pskb_expand_head() is passed a negative value for
nhead.&lt;/p&gt;
&lt;p&gt;Fix the trigger condition in calipso_skbuff_setattr(). Avoid passing
&amp;#34;negative&amp;#34; headroom sizes to skb_cow() within calipso_skbuff_setattr()
by only using skb_cow() to grow headroom.&lt;/p&gt;
&lt;p&gt;PoC:
	Using `netlabelctl` tool:&lt;/p&gt;
&lt;p&gt;netlabelctl map del default
        netlabelctl calipso add pass doi:7
        netlabelctl map add default address:0::1/128 protocol:calipso,7&lt;/p&gt;
&lt;p&gt;Then run the following PoC:&lt;/p&gt;
&lt;p&gt;int fd = socket(AF_INET6, SOCK_DGRAM, IPPROTO_UDP);&lt;/p&gt;
&lt;p&gt;// setup msghdr
        int cmsg_size = 2;
        int cmsg_len = 0x60;
        struct msghdr msg;
        struct sockaddr_in6 dest_addr;
        struct cmsghdr * cmsg = (struct cmsghdr *) calloc(1…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2025-71085</guid>
    </item>
    <item>
      <title>USN-8096-1 — linux, linux-aws, linux-gcp, linux-gkeop, linux-ibm, linux-ibm-5.15, linux-intel-iotg, linux-kvm, linux-lowlatency, lin…</title>
      <link>https://cve.radiocsirt.org/vuln/usn-8096-1</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:20.04:LTS: linux-ibm-5.15, Ubuntu:Pro:20.04:LTS: linux-nvidia-tegra-5.15, Ubuntu:22.04:LTS: linux, Ubuntu:22.04:LTS: linux-aws, Ubuntu:22.04:LTS: linux-gcp, Ubuntu:22.04:LTS: linux-gkeop, Ubuntu:22.04:LTS: linux-ibm, Ubuntu:22.04:LTS: linux-intel-iotg, Ubuntu:22.04:LTS: linux-kvm, Ubuntu:22.04:LTS: linux-lowlatency and 4 more&lt;/p&gt;
&lt;p&gt;Qualys discovered that several vulnerabilities existed in the AppArmor
Linux kernel Security Module (LSM). An unprivileged local attacker could
use these issues to load, replace, and remove arbitrary AppArmor profiles
causing denial of service, exposure of sensitive information (kernel
memory), local privilege escalation, or possibly escape a container.
(LP: #2143853)&lt;/p&gt;
&lt;p&gt;Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
  - PowerPC architecture;
  - x86 architecture;
  - Block layer subsystem;
  - Cryptographic API;
  - ACPI drivers;
  - ATM drivers;
  - Drivers core;
  - Network block device driver;
  - Bluetooth drivers;
  - Character device driver;
  - TPM device driver;
  - Data acquisition framework and drivers;
  - Counter interface drivers;
  - CPU frequency scaling framework;
  - Intel Stratix 10 firmware drivers;
  - GPU drivers;
  - HID subsystem;
  - Hardware monitoring drivers;
  - IIO subsystem;
  - InfiniBand drivers;
  - Input Device core drivers;
  - Input Device (Tablet) drivers;
  - ISDN/mISDN subsystem;
  - Macintosh device drivers;
  - Media drivers;
  - MOST (Media Oriented Systems Transport) drivers;
  - MTD block device drivers;
  - Network drivers;
  - Mellanox network drivers;
  - Texas Instruments network drivers;
  - Ethernet team driver;
  - MediaTek network drivers;
  - NVME drivers;
  - PA-RISC drivers;
  - PCI subsyste…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:20.04:LTS: linux-ibm-5.15, Ubuntu:Pro:20.04:LTS: linux-nvidia-tegra-5.15, Ubuntu:22.04:LTS: linux, Ubuntu:22.04:LTS: linux-aws, Ubuntu:22.04:LTS: linux-gcp, Ubuntu:22.04:LTS: linux-gkeop, Ubuntu:22.04:LTS: linux-ibm, Ubuntu:22.04:LTS: linux-intel-iotg, Ubuntu:22.04:LTS: linux-kvm, Ubuntu:22.04:LTS: linux-lowlatency and 4 more&lt;/p&gt;
&lt;p&gt;Qualys discovered that several vulnerabilities existed in the AppArmor
Linux kernel Security Module (LSM). An unprivileged local attacker could
use these issues to load, replace, and remove arbitrary AppArmor profiles
causing denial of service, exposure of sensitive information (kernel
memory), local privilege escalation, or possibly escape a container.
(LP: #2143853)&lt;/p&gt;
&lt;p&gt;Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
  - PowerPC architecture;
  - x86 architecture;
  - Block layer subsystem;
  - Cryptographic API;
  - ACPI drivers;
  - ATM drivers;
  - Drivers core;
  - Network block device driver;
  - Bluetooth drivers;
  - Character device driver;
  - TPM device driver;
  - Data acquisition framework and drivers;
  - Counter interface drivers;
  - CPU frequency scaling framework;
  - Intel Stratix 10 firmware drivers;
  - GPU drivers;
  - HID subsystem;
  - Hardware monitoring drivers;
  - IIO subsystem;
  - InfiniBand drivers;
  - Input Device core drivers;
  - Input Device (Tablet) drivers;
  - ISDN/mISDN subsystem;
  - Macintosh device drivers;
  - Media drivers;
  - MOST (Media Oriented Systems Transport) drivers;
  - MTD block device drivers;
  - Network drivers;
  - Mellanox network drivers;
  - Texas Instruments network drivers;
  - Ethernet team driver;
  - MediaTek network drivers;
  - NVME drivers;
  - PA-RISC drivers;
  - PCI subsyste…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/usn-8096-1</guid>
    </item>
  </channel>
</rss>
