<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T23:15:46.243932+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:21556</id>
    <title>ALSA-2026:21556 — Important: kernel security update</title>
    <updated>2026-10-02T23:15:46.808905+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:9: kernel, AlmaLinux:9: kernel-64k, AlmaLinux:9: kernel-64k-core, AlmaLinux:9: kernel-64k-debug, AlmaLinux:9: kernel-64k-debug-core, AlmaLinux:9: kernel-64k-debug-devel, AlmaLinux:9: kernel-64k-debug-devel-matched, AlmaLinux:9: kernel-64k-debug-modules, AlmaLinux:9: kernel-64k-debug-modules-core, AlmaLinux:9: kernel-64k-debug-modules-extra and 64 more</p>
<p>The kernel packages contain the Linux kernel, the core of any Linux operating system.</p>
<p>Security Fix(es):</p>
<p>* kernel: proc: use the same treatment to check proc_lseek as ones for proc_read_iter et.al (CVE-2025-38653)
  * kernel: ima: don't clear IMA_DIGSIG flag when setting or removing non-IMA xattr (CVE-2025-68183)
  * kernel: nbd: defer config unlock in nbd_genl_connect (CVE-2025-68366)
  * kernel: crypto: asymmetric_keys - prevent overflow in asymmetric_key_generate_id (CVE-2025-68724)
  * kernel: iommu: disable SVA when CONFIG_X86 is set (CVE-2025-71089)
  * kernel: netfilter: nf_tables: release flowtable after rcu grace period on error (CVE-2026-23392)
  * kernel: netfilter: nf_conntrack_h323: check for zero length in DecodeQ931() (CVE-2026-23455)
  * kernel: Bluetooth: SCO: Fix use-after-free in sco_recv_frame() due to missing sock_hold (CVE-2026-31408)
  * kernel: net: sched: act_csum: validate nested VLAN headers (CVE-2026-31684)
  * kernel: netfilter: ip6t_eui64: reject invalid MAC header for all packets (CVE-2026-31685)
  * kernel: netfilter: nf_conntrack_helper: pass helper to expect cleanup (CVE-2026-43027)
  * kernel: Bluetooth: MGMT: validate LTK enc_size on load (CVE-2026-43020)
  * kernel: HID: wacom: fix out-of-bounds read in wacom_intuos_bt_irq (CVE-2026-43051)
  * kernel: smb: client: validate the whole DACL before rewriting it in cifsacl (CVE-2026-31709)
  * kernel: Bluetooth: SCO: fix race conditions in sco_sock_connect() (CVE-2026-43023)
  * kernel:…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:21556"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-08859</id>
    <title>bdu:2026-08859</title>
    <updated>2026-10-02T23:15:46.809084+00:00</updated>
    <content>bdu:2026-08859</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-08859"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2025-71089</id>
    <title>BELL-CVE-2025-71089</title>
    <updated>2026-10-02T23:15:46.809104+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2025-71089"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0166</id>
    <title>certfr-2026-avi-0166 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de Debian. Elles permettent à un attaquant de provo…</title>
    <updated>2026-10-02T23:15:46.809126+00:00</updated>
    <content>certfr-2026-avi-0166</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0166"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-347541</id>
    <title>EUVD-2026-347541</title>
    <updated>2026-10-02T23:15:46.809143+00:00</updated>
    <content>EUVD-2026-347541</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-347541"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-71089</id>
    <title>fkie_cve-2025-71089</title>
    <updated>2026-10-02T23:15:46.809154+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>iommu: disable SVA when CONFIG_X86 is set</p>
<p>Patch series "Fix stale IOTLB entries for kernel address space", v7.</p>
<p>This proposes a fix for a security vulnerability related to IOMMU Shared
Virtual Addressing (SVA).  In an SVA context, an IOMMU can cache kernel
page table entries.  When a kernel page table page is freed and
reallocated for another purpose, the IOMMU might still hold stale,
incorrect entries.  This can be exploited to cause a use-after-free or
write-after-free condition, potentially leading to privilege escalation or
data corruption.</p>
<p>This solution introduces a deferred freeing mechanism for kernel page
table pages, which provides a safe window to notify the IOMMU to
invalidate its caches before the page is reused.</p>
<p>This patch (of 8):</p>
<p>In the IOMMU Shared Virtual Addressing (SVA) context, the IOMMU hardware
shares and walks the CPU's page tables.  The x86 architecture maps the
kernel's virtual address space into the upper portion of every process's
page table.  Consequently, in an SVA context, the IOMMU hardware can walk
and cache kernel page table entries.</p>
<p>The Linux kernel currently lacks a notification mechanism for kernel page
table changes, specifically when page table pages are freed and reused. 
The IOMMU driver is only notified of changes to user virtual address
mappings.  This can cause the IOMMU's internal caches to retain stale
entries for kernel VA.</p>
<p>Use-After-Free (UAF) and Write-A…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-71089"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-r6cc-j9rp-4f85</id>
    <title>GHSA-r6cc-j9rp-4f85</title>
    <updated>2026-10-02T23:15:46.809197+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>iommu: disable SVA when CONFIG_X86 is set</p>
<p>Patch series "Fix stale IOTLB entries for kernel address space", v7.</p>
<p>This proposes a fix for a security vulnerability related to IOMMU Shared
Virtual Addressing (SVA).  In an SVA context, an IOMMU can cache kernel
page table entries.  When a kernel page table page is freed and
reallocated for another purpose, the IOMMU might still hold stale,
incorrect entries.  This can be exploited to cause a use-after-free or
write-after-free condition, potentially leading to privilege escalation or
data corruption.</p>
<p>This solution introduces a deferred freeing mechanism for kernel page
table pages, which provides a safe window to notify the IOMMU to
invalidate its caches before the page is reused.</p>
<p>This patch (of 8):</p>
<p>In the IOMMU Shared Virtual Addressing (SVA) context, the IOMMU hardware
shares and walks the CPU's page tables.  The x86 architecture maps the
kernel's virtual address space into the upper portion of every process's
page table.  Consequently, in an SVA context, the IOMMU hardware can walk
and cache kernel page table entries.</p>
<p>The Linux kernel currently lacks a notification mechanism for kernel page
table changes, specifically when page table pages are freed and reused. 
The IOMMU driver is only notified of changes to user virtual address
mappings.  This can cause the IOMMU's internal caches to retain stale
entries for kernel VA.</p>
<p>Use-After-Free (UAF) and Write-A…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-r6cc-j9rp-4f85"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2025-71089</id>
    <title>msrc_CVE-2025-71089 — iommu: disable SVA when CONFIG_X86 is set</title>
    <updated>2026-10-02T23:15:46.809231+00:00</updated>
    <content>msrc_CVE-2025-71089</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2025-71089"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-1863</id>
    <title>OESA-2026-1863 — kernel security update</title>
    <updated>2026-10-02T23:15:46.809248+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS-SP1: kernel</p>
<p>The Linux Kernel, the operating system core itself.

Security Fix(es):</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>f2fs: fix to detect potential corrupted nid in free_nid_list</p>
<p>As reported, on-disk footer.ino and footer.nid is the same and
out-of-range, let&amp;apos;s add sanity check on f2fs_alloc_nid() to detect
any potential corruption in free_nid_list.(CVE-2025-68315)</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>ntfs3: Fix uninit buffer allocated by __getname()</p>
<p>Fix uninit errors caused after buffer allocation given to &amp;apos;de&amp;apos;; by
initializing the buffer with zeroes. The fix was found by using KMSAN.(CVE-2025-68727)</p>
<p>In the Linux kernel, a security vulnerability exists in the IOMMU Shared Virtual Addressing (SVA) feature. On x86 architecture when CONFIG_X86 is set, IOMMU hardware caches kernel page table entries. Due to the lack of notification mechanism for kernel page table changes, when kernel page table pages are freed and reused, the IOMMU may retain stale entries, leading to Use-After-Free (UAF) and Write-After-Free (WAF) conditions. This can be exploited to cause arbitrary physical memory DMA access or privilege escalation.(CVE-2025-71089)</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>uacce: fix cdev handling in the cleanup path</p>
<p>When cdev_device_add fails, it internally releases the cdev memory,
and if cdev_device_del is then executed, it will cause a hang error.
To fix it, we check t…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-1863"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:20287-1</id>
    <title>openSUSE-SU-2026:20287-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-02T23:15:46.809487+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:20287-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:23237</id>
    <title>RHSA-2026:23237 — Red Hat Security Advisory: kernel security update</title>
    <updated>2026-10-02T23:15:46.809613+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>kernel: ipv6: use RCU in ip6_xmit() kernel: ipv6: use RCU in ip6_output() kernel: net: use dst_dev_rcu() in sk_setup_caps() kernel: crypto: asymmetric_keys - prevent overflow in asymmetric_key_generate_id kernel: iommu: disable SVA when CONFIG_X86 is set kernel: scsi: target: iscsi: Fix use-after-free in iscsit_dec_conn_usage_count() kernel: netfilter: nf_tables: release flowtable after rcu grace period on error kernel: netfilter: ip6t_eui64: reject invalid MAC header for all packets kernel: smb: client: validate the whole DACL before rewriting it in cifsacl kernel: ip6_tunnel: clear skb2-&gt;cb[] in ip4ip6_err() kernel: ipv6: icmp: clear skb2-&gt;cb[] in ip6_err_gen_icmpv6_unreach() kernel: wifi: brcmfmac: validate bsscfg indices in IF events</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:23237"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:21556</id>
    <title>RLSA-2026:21556 — Important: kernel security update</title>
    <updated>2026-10-02T23:15:46.809651+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:9: kernel</p>
<p>The kernel packages contain the Linux kernel, the core of any Linux operating system.</p>
<p>Security Fix(es):</p>
<p>* kernel: proc: use the same treatment to check proc_lseek as ones for proc_read_iter et.al (CVE-2025-38653)</p>
<p>* kernel: ima: don't clear IMA_DIGSIG flag when setting or removing non-IMA xattr (CVE-2025-68183)</p>
<p>* kernel: nbd: defer config unlock in nbd_genl_connect (CVE-2025-68366)</p>
<p>* kernel: crypto: asymmetric_keys - prevent overflow in asymmetric_key_generate_id (CVE-2025-68724)</p>
<p>* kernel: iommu: disable SVA when CONFIG_X86 is set (CVE-2025-71089)</p>
<p>* kernel: netfilter: nf_tables: release flowtable after rcu grace period on error (CVE-2026-23392)</p>
<p>* kernel: netfilter: nf_conntrack_h323: check for zero length in DecodeQ931() (CVE-2026-23455)</p>
<p>* kernel: Bluetooth: SCO: Fix use-after-free in sco_recv_frame() due to missing sock_hold (CVE-2026-31408)</p>
<p>* kernel: net: sched: act_csum: validate nested VLAN headers (CVE-2026-31684)</p>
<p>* kernel: netfilter: ip6t_eui64: reject invalid MAC header for all packets (CVE-2026-31685)</p>
<p>* kernel: netfilter: nf_conntrack_helper: pass helper to expect cleanup (CVE-2026-43027)</p>
<p>* kernel: Bluetooth: MGMT: validate LTK enc_size on load (CVE-2026-43020)</p>
<p>* kernel: HID: wacom: fix out-of-bounds read in wacom_intuos_bt_irq (CVE-2026-43051)</p>
<p>* kernel: smb: client: validate the whole DACL before rewriting it in cifsacl (CVE-2026-31709)</p>
<p>* kernel: Bluetooth: SCO: fix race conditions in sco_sock_connect() (CVE-2026-43023)</p>
<p>* kernel: wifi: brcmfmac: vali…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:21556"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:0411-1</id>
    <title>SUSE-SU-2026:0411-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-02T23:15:46.809693+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:0411-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-71089</id>
    <title>UBUNTU-CVE-2025-71089</title>
    <updated>2026-10-02T23:15:46.809903+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:Pro:18.04:LTS: linux-aws-5.4, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:Pro:18.04:LTS: linux-azure-5.4, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3 and 205 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: iommu: disable SVA when CONFIG_X86 is set Patch series "Fix stale IOTLB entries for kernel address space", v7. This proposes a fix for a security vulnerability related to IOMMU Shared Virtual Addressing (SVA).  In an SVA context, an IOMMU can cache kernel page table entries.  When a kernel page table page is freed and reallocated for another purpose, the IOMMU might still hold stale, incorrect entries.  This can be exploited to cause a use-after-free or write-after-free condition, potentially leading to privilege escalation or data corruption. This solution introduces a deferred freeing mechanism for kernel page table pages, which provides a safe window to notify the IOMMU to invalidate its caches before the page is reused. This patch (of 8): In the IOMMU Shared Virtual Addressing (SVA) context, the IOMMU hardware shares and walks the CPU's page tables.  The x86 architecture maps the kernel's virtual address space into the upper portion of every process's page table.  Consequently, in an SVA context, the IOMMU hardware can walk and cache kernel page table entries. The Linux kernel currently lacks a notification mechanism for kernel page table changes, specifically when page table pages are freed and reused. The IOMMU driver is only notified of changes to user virtual address mappings.  This can cause the IOMMU's internal caches to retain stale entries for kernel VA. Use-After-Free (UAF) and Write-After-Free…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-71089"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0086</id>
    <title>WID-SEC-W-2026-0086 — Linux Kernel: Mehrere Schwachstellen</title>
    <updated>2026-10-02T23:15:46.810148+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen um nicht näher spezifizierte Angriffe durchzuführen, die möglicherweise zu einer Denial-of-Service- Bedingung führen oder eine Speicherbeschädigung verursachen können.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0086"/>
  </entry>
</feed>
