<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T18:40:55.216362+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:21556</id>
    <title>ALSA-2026:21556 — Important: kernel security update</title>
    <updated>2026-10-02T18:40:56.077055+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:9: kernel, AlmaLinux:9: kernel-64k, AlmaLinux:9: kernel-64k-core, AlmaLinux:9: kernel-64k-debug, AlmaLinux:9: kernel-64k-debug-core, AlmaLinux:9: kernel-64k-debug-devel, AlmaLinux:9: kernel-64k-debug-devel-matched, AlmaLinux:9: kernel-64k-debug-modules, AlmaLinux:9: kernel-64k-debug-modules-core, AlmaLinux:9: kernel-64k-debug-modules-extra and 64 more</p>
<p>The kernel packages contain the Linux kernel, the core of any Linux operating system.</p>
<p>Security Fix(es):</p>
<p>* kernel: proc: use the same treatment to check proc_lseek as ones for proc_read_iter et.al (CVE-2025-38653)
  * kernel: ima: don't clear IMA_DIGSIG flag when setting or removing non-IMA xattr (CVE-2025-68183)
  * kernel: nbd: defer config unlock in nbd_genl_connect (CVE-2025-68366)
  * kernel: crypto: asymmetric_keys - prevent overflow in asymmetric_key_generate_id (CVE-2025-68724)
  * kernel: iommu: disable SVA when CONFIG_X86 is set (CVE-2025-71089)
  * kernel: netfilter: nf_tables: release flowtable after rcu grace period on error (CVE-2026-23392)
  * kernel: netfilter: nf_conntrack_h323: check for zero length in DecodeQ931() (CVE-2026-23455)
  * kernel: Bluetooth: SCO: Fix use-after-free in sco_recv_frame() due to missing sock_hold (CVE-2026-31408)
  * kernel: net: sched: act_csum: validate nested VLAN headers (CVE-2026-31684)
  * kernel: netfilter: ip6t_eui64: reject invalid MAC header for all packets (CVE-2026-31685)
  * kernel: netfilter: nf_conntrack_helper: pass helper to expect cleanup (CVE-2026-43027)
  * kernel: Bluetooth: MGMT: validate LTK enc_size on load (CVE-2026-43020)
  * kernel: HID: wacom: fix out-of-bounds read in wacom_intuos_bt_irq (CVE-2026-43051)
  * kernel: smb: client: validate the whole DACL before rewriting it in cifsacl (CVE-2026-31709)
  * kernel: Bluetooth: SCO: fix race conditions in sco_sock_connect() (CVE-2026-43023)
  * kernel:…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:21556"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2025-68183</id>
    <title>BELL-CVE-2025-68183</title>
    <updated>2026-10-02T18:40:56.077247+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2025-68183"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0108</id>
    <title>certfr-2026-avi-0108 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de SUSE. Certaines d'entre elles permettent à un at…</title>
    <updated>2026-10-02T18:40:56.077276+00:00</updated>
    <content>certfr-2026-avi-0108</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0108"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/essa-2026:0165</id>
    <title>ESSA-2026:0165 — Important: kernel security, bug fix, and enhancement update</title>
    <updated>2026-10-02T18:40:56.077295+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Important: kernel security, bug fix, and enhancement update</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/essa-2026:0165"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-347455</id>
    <title>EUVD-2026-347455</title>
    <updated>2026-10-02T18:40:56.077322+00:00</updated>
    <content>EUVD-2026-347455</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-347455"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-68183</id>
    <title>fkie_cve-2025-68183</title>
    <updated>2026-10-02T18:40:56.077334+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>ima: don't clear IMA_DIGSIG flag when setting or removing non-IMA xattr</p>
<p>Currently when both IMA and EVM are in fix mode, the IMA signature will
be reset to IMA hash if a program first stores IMA signature in
security.ima and then writes/removes some other security xattr for the
file.</p>
<p>For example, on Fedora, after booting the kernel with "ima_appraise=fix
evm=fix ima_policy=appraise_tcb" and installing rpm-plugin-ima,
installing/reinstalling a package will not make good reference IMA
signature generated. Instead IMA hash is generated,</p>
<p># getfattr -m - -d -e hex /usr/bin/bash
    # file: usr/bin/bash
    security.ima=0x0404...</p>
<p>This happens because when setting security.selinux, the IMA_DIGSIG flag
that had been set early was cleared. As a result, IMA hash is generated
when the file is closed.</p>
<p>Similarly, IMA signature can be cleared on file close after removing
security xattr like security.evm or setting/removing ACL.</p>
<p>Prevent replacing the IMA file signature with a file hash, by preventing
the IMA_DIGSIG flag from being reset.</p>
<p>Here's a minimal C reproducer which sets security.selinux as the last
step which can also replaced by removing security.evm or setting ACL,</p>
<p>#include &lt;stdio.h&gt;
    #include &lt;sys/xattr.h&gt;
    #include &lt;fcntl.h&gt;
    #include &lt;unistd.h&gt;
    #include &lt;string.h&gt;
    #include &lt;stdlib.h&gt;</p>
<p>int main() {
        const char* file_path = "/usr/sbin/test_binary";
        const char*…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-68183"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-w26q-x7h4-9gc5</id>
    <title>GHSA-w26q-x7h4-9gc5</title>
    <updated>2026-10-02T18:40:56.077379+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>ima: don't clear IMA_DIGSIG flag when setting or removing non-IMA xattr</p>
<p>Currently when both IMA and EVM are in fix mode, the IMA signature will
be reset to IMA hash if a program first stores IMA signature in
security.ima and then writes/removes some other security xattr for the
file.</p>
<p>For example, on Fedora, after booting the kernel with "ima_appraise=fix
evm=fix ima_policy=appraise_tcb" and installing rpm-plugin-ima,
installing/reinstalling a package will not make good reference IMA
signature generated. Instead IMA hash is generated,</p>
<p># getfattr -m - -d -e hex /usr/bin/bash
    # file: usr/bin/bash
    security.ima=0x0404...</p>
<p>This happens because when setting security.selinux, the IMA_DIGSIG flag
that had been set early was cleared. As a result, IMA hash is generated
when the file is closed.</p>
<p>Similarly, IMA signature can be cleared on file close after removing
security xattr like security.evm or setting/removing ACL.</p>
<p>Prevent replacing the IMA file signature with a file hash, by preventing
the IMA_DIGSIG flag from being reset.</p>
<p>Here's a minimal C reproducer which sets security.selinux as the last
step which can also replaced by removing security.evm or setting ACL,</p>
<p>#include &lt;stdio.h&gt;
    #include &lt;sys/xattr.h&gt;
    #include &lt;fcntl.h&gt;
    #include &lt;unistd.h&gt;
    #include &lt;string.h&gt;
    #include &lt;stdlib.h&gt;</p>
<p>int main() {
        const char* file_path = "/usr/sbin/test_binary";
        const char*…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-w26q-x7h4-9gc5"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-2675</id>
    <title>OESA-2026-2675 — kernel security update</title>
    <updated>2026-10-02T18:40:56.077416+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS-SP1: kernel</p>
<p>The Linux Kernel, the operating system core itself.

Security Fix(es):</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>drm/i915/gt: Fix timeline left held on VMA alloc error</p>
<p>The following error has been reported sporadically by CI when a test
unbinds the i915 driver on a ring submission platform:</p>
<p>&amp;lt;4&amp;gt; [239.330153] ------------[ cut here ]------------
&amp;lt;4&amp;gt; [239.330166] i915 0000:00:02.0: [drm] drm_WARN_ON(dev_priv-&amp;gt;mm.shrink_count)
&amp;lt;4&amp;gt; [239.330196] WARNING: CPU: 1 PID: 18570 at drivers/gpu/drm/i915/i915_gem.c:1309 i915_gem_cleanup_early+0x13e/0x150 [i915]
...
&amp;lt;4&amp;gt; [239.330640] RIP: 0010:i915_gem_cleanup_early+0x13e/0x150 [i915]
...
&amp;lt;4&amp;gt; [239.330942] Call Trace:
&amp;lt;4&amp;gt; [239.330944]  &amp;lt;TASK&amp;gt;
&amp;lt;4&amp;gt; [239.330949]  i915_driver_late_release+0x2b/0xa0 [i915]
&amp;lt;4&amp;gt; [239.331202]  i915_driver_release+0x86/0xa0 [i915]
&amp;lt;4&amp;gt; [239.331482]  devm_drm_dev_init_release+0x61/0x90
&amp;lt;4&amp;gt; [239.331494]  devm_action_release+0x15/0x30
&amp;lt;4&amp;gt; [239.331504]  release_nodes+0x3d/0x120
&amp;lt;4&amp;gt; [239.331517]  devres_release_all+0x96/0xd0
&amp;lt;4&amp;gt; [239.331533]  device_unbind_cleanup+0x12/0x80
&amp;lt;4&amp;gt; [239.331543]  device_release_driver_internal+0x23a/0x280
&amp;lt;4&amp;gt; [239.331550]  ? bus_find_device+0xa5/0xe0
&amp;lt;4&amp;gt; [239.331563]  device_driver_detach+0x14/0x20
...
&amp;lt;4&amp;gt; [357.719679] ---[ end trace 0000000000000000 ]---</p>
<p>If the test also unloads the i915 module then that&amp;apos;s followed with:</p>
<p>&amp;lt;3&amp;gt; [357.787478] ===…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-2675"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:21745</id>
    <title>RHSA-2026:21745 — Red Hat Security Advisory: kernel-rt security update</title>
    <updated>2026-10-02T18:40:56.077691+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>kernel: Bluetooth: MGMT: Fix possible UAFs kernel: ima: don't clear IMA_DIGSIG flag when setting or removing non-IMA xattr kernel: ALSA: firewire-motu: fix buffer overflow in hwdep read for DSP events kernel: libceph: make decode_pool() more resilient against corrupted osdmaps kernel: Linux kernel: Denial of service and memory corruption in RDMA umad kernel: Linux kernel: Use-after-free in traffic control (act_ct) may lead to denial of service or privilege escalation kernel: netfilter: nf_conntrack_h323: check for zero length in DecodeQ931() kernel: Bluetooth: SCO: Fix use-after-free in sco_recv_frame() due to missing sock_hold kernel: can: raw: fix ro-&gt;uniq use-after-free in raw_rcv() kernel: net: sched: act_csum: validate nested VLAN headers kernel: netfilter: ip6t_eui64: reject invalid MAC header for all packets kernel: smb: client: validate the whole DACL before rewriting it in cifsacl kernel: Bluetooth: MGMT: validate LTK enc_size on load kernel: netfilter: nf_conntrack_helper: pass helper to expect cleanup kernel: HID: wacom: fix out-of-bounds read in wacom_intuos_bt_irq kernel: xfs: fix freemap adjustments when adding xattrs to leaf blocks kernel: md/bitmap: fix GPF in write_page caused by resize race kernel: netfilter: xt_tcpmss: check remaining length before reading optlen kernel: smb: client: validate dacloffset before building DACL pointers</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:21745"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:21556</id>
    <title>RLSA-2026:21556 — Important: kernel security update</title>
    <updated>2026-10-02T18:40:56.077779+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:9: kernel</p>
<p>The kernel packages contain the Linux kernel, the core of any Linux operating system.</p>
<p>Security Fix(es):</p>
<p>* kernel: proc: use the same treatment to check proc_lseek as ones for proc_read_iter et.al (CVE-2025-38653)</p>
<p>* kernel: ima: don't clear IMA_DIGSIG flag when setting or removing non-IMA xattr (CVE-2025-68183)</p>
<p>* kernel: nbd: defer config unlock in nbd_genl_connect (CVE-2025-68366)</p>
<p>* kernel: crypto: asymmetric_keys - prevent overflow in asymmetric_key_generate_id (CVE-2025-68724)</p>
<p>* kernel: iommu: disable SVA when CONFIG_X86 is set (CVE-2025-71089)</p>
<p>* kernel: netfilter: nf_tables: release flowtable after rcu grace period on error (CVE-2026-23392)</p>
<p>* kernel: netfilter: nf_conntrack_h323: check for zero length in DecodeQ931() (CVE-2026-23455)</p>
<p>* kernel: Bluetooth: SCO: Fix use-after-free in sco_recv_frame() due to missing sock_hold (CVE-2026-31408)</p>
<p>* kernel: net: sched: act_csum: validate nested VLAN headers (CVE-2026-31684)</p>
<p>* kernel: netfilter: ip6t_eui64: reject invalid MAC header for all packets (CVE-2026-31685)</p>
<p>* kernel: netfilter: nf_conntrack_helper: pass helper to expect cleanup (CVE-2026-43027)</p>
<p>* kernel: Bluetooth: MGMT: validate LTK enc_size on load (CVE-2026-43020)</p>
<p>* kernel: HID: wacom: fix out-of-bounds read in wacom_intuos_bt_irq (CVE-2026-43051)</p>
<p>* kernel: smb: client: validate the whole DACL before rewriting it in cifsacl (CVE-2026-31709)</p>
<p>* kernel: Bluetooth: SCO: fix race conditions in sco_sock_connect() (CVE-2026-43023)</p>
<p>* kernel: wifi: brcmfmac: vali…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:21556"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:0278-1</id>
    <title>SUSE-SU-2026:0278-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-02T18:40:56.077821+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:0278-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-68183</id>
    <title>UBUNTU-CVE-2025-68183</title>
    <updated>2026-10-02T18:40:56.078018+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 176 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: ima: don't clear IMA_DIGSIG flag when setting or removing non-IMA xattr Currently when both IMA and EVM are in fix mode, the IMA signature will be reset to IMA hash if a program first stores IMA signature in security.ima and then writes/removes some other security xattr for the file. For example, on Fedora, after booting the kernel with "ima_appraise=fix evm=fix ima_policy=appraise_tcb" and installing rpm-plugin-ima, installing/reinstalling a package will not make good reference IMA signature generated. Instead IMA hash is generated,     # getfattr -m - -d -e hex /usr/bin/bash     # file: usr/bin/bash     security.ima=0x0404... This happens because when setting security.selinux, the IMA_DIGSIG flag that had been set early was cleared. As a result, IMA hash is generated when the file is closed. Similarly, IMA signature can be cleared on file close after removing security xattr like security.evm or setting/removing ACL. Prevent replacing the IMA file signature with a file hash, by preventing the IMA_DIGSIG flag from being reset. Here's a minimal C reproducer which sets security.selinux as the last step which can also replaced by removing security.evm or setting ACL,     #include &lt;stdio.h&gt;     #include &lt;sys/xattr.h&gt;     #include &lt;fcntl.h&gt;     #include &lt;unistd.h&gt;     #include &lt;string.h&gt;     #include &lt;stdlib.h&gt;     int main() {         const char* file_path = "/usr/sbin/test_binary";         const char* hex_strin…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-68183"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2868</id>
    <title>WID-SEC-W-2025-2868 — Linux Kernel: Mehrere Schwachstellen</title>
    <updated>2026-10-02T18:40:56.078229+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um nicht näher spezifizierte Angriffe durchzuführen, die möglicherweise zu einer Denial-of-Service- Bedingung führen oder eine Speicherbeschädigung verursachen können.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2868"/>
  </entry>
</feed>
