<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T21:21:19.687185+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:59723</id>
    <title>ALSA-2026:59723 — Important: kernel security, bug fix, and enhancement update</title>
    <updated>2026-10-03T21:21:20.679131+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:9: kernel, AlmaLinux:9: kernel-64k, AlmaLinux:9: kernel-64k-core, AlmaLinux:9: kernel-64k-debug, AlmaLinux:9: kernel-64k-debug-core, AlmaLinux:9: kernel-64k-debug-devel, AlmaLinux:9: kernel-64k-debug-devel-matched, AlmaLinux:9: kernel-64k-debug-modules, AlmaLinux:9: kernel-64k-debug-modules-core, AlmaLinux:9: kernel-64k-debug-modules-extra and 64 more</p>
<p>The kernel packages contain the Linux kernel, the core of any Linux operating system.</p>
<p>Security Fix(es):</p>
<p>* kernel: ksm: use range-walk function to jump over holes in scan_get_next_rmap_item (CVE-2025-68211)
  * kernel: ip6_tunnel: use skb_vlan_inet_prepare() in __ip6_tnl_rcv() (CVE-2026-23003)
  * kernel: netfilter: nft_set_pipapo_avx2: don't return non-matching entry on expiry (CVE-2026-43114)
  * kernel: sctp: purge outqueue on stale COOKIE-ECHO handling (CVE-2026-52924)
  * kernel: netfilter: xt_policy: fix strict mode inbound policy matching (CVE-2026-52920)
  * kernel: zram: fix use-after-free in zram_bvec_write_partial() (CVE-2026-53185)
  * kernel: netfilter: require Ethernet MAC header before using eth_hdr() (CVE-2026-53131)
  * kernel: netfilter: conntrack_irc: fix possible out-of-bounds read (CVE-2026-53268)
  * kernel: i2c: stub: Reject I2C block transfers with invalid length (CVE-2026-64191)
  * kernel: netfilter: ipset: fix race between dump and ip_set_list resize (CVE-2026-64189)
  * kernel: Input: synaptics-rmi4 - bound the F3A keymap to the GPIO count (CVE-2026-64277)
  * kernel: Input: synaptics-rmi4 - bound the F30 keymap to the GPIO/LED count (CVE-2026-64276)
  * kernel: net: ipv6: use-after-free in fib6_rule_suppress due to stale res-&gt;rt6 pointer (CVE-2026-74581)</p>
<p>Bug Fix(es) and Enhancement(s):</p>
<p>* [AlmaLinux-9.8.z] Intel CWF: CPU is unable to obtain cstate1 on idle system (JIRA:AlmaLinux-166118)
  * ss core dumped when there is an SCTP sessio…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:59723"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-01113</id>
    <title>bdu:2026-01113</title>
    <updated>2026-10-03T21:21:20.679323+00:00</updated>
    <content>bdu:2026-01113</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-01113"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-23003</id>
    <title>BELL-CVE-2026-23003</title>
    <updated>2026-10-03T21:21:20.679351+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-23003"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0166</id>
    <title>certfr-2026-avi-0166 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de Debian. Elles permettent à un attaquant de provo…</title>
    <updated>2026-10-03T21:21:20.679383+00:00</updated>
    <content>certfr-2026-avi-0166</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0166"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-364647</id>
    <title>EUVD-2026-364647</title>
    <updated>2026-10-03T21:21:20.679401+00:00</updated>
    <content>EUVD-2026-364647</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-364647"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-23003</id>
    <title>fkie_cve-2026-23003</title>
    <updated>2026-10-03T21:21:20.679413+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>ip6_tunnel: use skb_vlan_inet_prepare() in __ip6_tnl_rcv()</p>
<p>Blamed commit did not take care of VLAN encapsulations
as spotted by syzbot [1].</p>
<p>Use skb_vlan_inet_prepare() instead of pskb_inet_may_pull().</p>
<p>[1]
 BUG: KMSAN: uninit-value in __INET_ECN_decapsulate include/net/inet_ecn.h:253 [inline]
 BUG: KMSAN: uninit-value in INET_ECN_decapsulate include/net/inet_ecn.h:275 [inline]
 BUG: KMSAN: uninit-value in IP6_ECN_decapsulate+0x7a8/0x1fa0 include/net/inet_ecn.h:321
  __INET_ECN_decapsulate include/net/inet_ecn.h:253 [inline]
  INET_ECN_decapsulate include/net/inet_ecn.h:275 [inline]
  IP6_ECN_decapsulate+0x7a8/0x1fa0 include/net/inet_ecn.h:321
  ip6ip6_dscp_ecn_decapsulate+0x16f/0x1b0 net/ipv6/ip6_tunnel.c:729
  __ip6_tnl_rcv+0xed9/0x1b50 net/ipv6/ip6_tunnel.c:860
  ip6_tnl_rcv+0xc3/0x100 net/ipv6/ip6_tunnel.c:903
 gre_rcv+0x1529/0x1b90 net/ipv6/ip6_gre.c:-1
  ip6_protocol_deliver_rcu+0x1c89/0x2c60 net/ipv6/ip6_input.c:438
  ip6_input_finish+0x1f4/0x4a0 net/ipv6/ip6_input.c:489
  NF_HOOK include/linux/netfilter.h:318 [inline]
  ip6_input+0x9c/0x330 net/ipv6/ip6_input.c:500
  ip6_mc_input+0x7ca/0xc10 net/ipv6/ip6_input.c:590
  dst_input include/net/dst.h:474 [inline]
  ip6_rcv_finish+0x958/0x990 net/ipv6/ip6_input.c:79
  NF_HOOK include/linux/netfilter.h:318 [inline]
  ipv6_rcv+0xf1/0x3c0 net/ipv6/ip6_input.c:311
  __netif_receive_skb_one_core net/core/dev.c:6139 [inline]
  __netif_receive_skb+0x1df/0xac0 n…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-23003"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-f9vv-4vcq-qjp3</id>
    <title>GHSA-f9vv-4vcq-qjp3</title>
    <updated>2026-10-03T21:21:20.679457+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>ip6_tunnel: use skb_vlan_inet_prepare() in __ip6_tnl_rcv()</p>
<p>Blamed commit did not take care of VLAN encapsulations
as spotted by syzbot [1].</p>
<p>Use skb_vlan_inet_prepare() instead of pskb_inet_may_pull().</p>
<p>[1]
 BUG: KMSAN: uninit-value in __INET_ECN_decapsulate include/net/inet_ecn.h:253 [inline]
 BUG: KMSAN: uninit-value in INET_ECN_decapsulate include/net/inet_ecn.h:275 [inline]
 BUG: KMSAN: uninit-value in IP6_ECN_decapsulate+0x7a8/0x1fa0 include/net/inet_ecn.h:321
  __INET_ECN_decapsulate include/net/inet_ecn.h:253 [inline]
  INET_ECN_decapsulate include/net/inet_ecn.h:275 [inline]
  IP6_ECN_decapsulate+0x7a8/0x1fa0 include/net/inet_ecn.h:321
  ip6ip6_dscp_ecn_decapsulate+0x16f/0x1b0 net/ipv6/ip6_tunnel.c:729
  __ip6_tnl_rcv+0xed9/0x1b50 net/ipv6/ip6_tunnel.c:860
  ip6_tnl_rcv+0xc3/0x100 net/ipv6/ip6_tunnel.c:903
 gre_rcv+0x1529/0x1b90 net/ipv6/ip6_gre.c:-1
  ip6_protocol_deliver_rcu+0x1c89/0x2c60 net/ipv6/ip6_input.c:438
  ip6_input_finish+0x1f4/0x4a0 net/ipv6/ip6_input.c:489
  NF_HOOK include/linux/netfilter.h:318 [inline]
  ip6_input+0x9c/0x330 net/ipv6/ip6_input.c:500
  ip6_mc_input+0x7ca/0xc10 net/ipv6/ip6_input.c:590
  dst_input include/net/dst.h:474 [inline]
  ip6_rcv_finish+0x958/0x990 net/ipv6/ip6_input.c:79
  NF_HOOK include/linux/netfilter.h:318 [inline]
  ipv6_rcv+0xf1/0x3c0 net/ipv6/ip6_input.c:311
  __netif_receive_skb_one_core net/core/dev.c:6139 [inline]
  __netif_receive_skb+0x1df/0xac0 n…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-f9vv-4vcq-qjp3"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-26-209-04</id>
    <title>ICSA-26-209-04 — Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</title>
    <updated>2026-10-03T21:21:20.679493+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.6 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant).</p>
<p>Siemens is preparing fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-26-209-04"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-1340</id>
    <title>OESA-2026-1340 — kernel security update</title>
    <updated>2026-10-03T21:21:20.679630+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP4: kernel</p>
<p>The Linux Kernel, the operating system core itself.

Security Fix(es):</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>media: av7110: prevent underflow in write_ts_to_decoder()</p>
<p>The buf[4] value comes from the user via ts_play().  It is a value in
the u8 range.  The final length we pass to av7110_ipack_instant_repack()
is &amp;quot;len - (buf[4] + 1) - 4&amp;quot; so add a check to ensure that the length is
not negative.  It&amp;apos;s not clear that passing a negative len value does
anything bad necessarily, but it&amp;apos;s not best practice.</p>
<p>With the new bounds checking the &amp;quot;if (!len)&amp;quot; condition is no longer
possible or required so remove that.(CVE-2023-54284)</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>ipvs: Defer ip_vs_ftp unregister during netns cleanup</p>
<p>On the netns cleanup path, __ip_vs_ftp_exit() may unregister ip_vs_ftp
before connections with valid cp-&amp;gt;app pointers are flushed, leading to a
use-after-free.</p>
<p>Fix this by introducing a global `exiting_module` flag, set to true in
ip_vs_ftp_exit() before unregistering the pernet subsystem. In
__ip_vs_ftp_exit(), skip ip_vs_ftp unregister if called during netns
cleanup (when exiting_module is false) and defer it to
__ip_vs_cleanup_batch(), which unregisters all apps after all connections
are flushed. If called during module exit, unregister ip_vs_ftp
immediately.(CVE-2025-40018)</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>libceph: fix potential…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-1340"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:20416-1</id>
    <title>openSUSE-SU-2026:20416-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-03T21:21:20.679692+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:20416-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:59723</id>
    <title>RLSA-2026:59723 — Important: kernel security, bug fix, and enhancement update</title>
    <updated>2026-10-03T21:21:20.679782+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:9: kernel</p>
<p>The kernel packages contain the Linux kernel, the core of any Linux operating system.</p>
<p>Security Fix(es):</p>
<p>* kernel: ksm: use range-walk function to jump over holes in scan_get_next_rmap_item (CVE-2025-68211)</p>
<p>* kernel: ip6_tunnel: use skb_vlan_inet_prepare() in __ip6_tnl_rcv() (CVE-2026-23003)</p>
<p>* kernel: netfilter: nft_set_pipapo_avx2: don't return non-matching entry on expiry (CVE-2026-43114)</p>
<p>* kernel: sctp: purge outqueue on stale COOKIE-ECHO handling (CVE-2026-52924)</p>
<p>* kernel: netfilter: xt_policy: fix strict mode inbound policy matching (CVE-2026-52920)</p>
<p>* kernel: zram: fix use-after-free in zram_bvec_write_partial() (CVE-2026-53185)</p>
<p>* kernel: netfilter: require Ethernet MAC header before using eth_hdr() (CVE-2026-53131)</p>
<p>* kernel: netfilter: conntrack_irc: fix possible out-of-bounds read (CVE-2026-53268)</p>
<p>* kernel: i2c: stub: Reject I2C block transfers with invalid length (CVE-2026-64191)</p>
<p>* kernel: netfilter: ipset: fix race between dump and ip_set_list resize (CVE-2026-64189)</p>
<p>* kernel: Input: synaptics-rmi4 - bound the F3A keymap to the GPIO count (CVE-2026-64277)</p>
<p>* kernel: Input: synaptics-rmi4 - bound the F30 keymap to the GPIO/LED count (CVE-2026-64276)</p>
<p>* kernel: net: ipv6: use-after-free in fib6_rule_suppress due to stale res-&gt;rt6 pointer (CVE-2026-74581)</p>
<p>Bug Fix(es) and Enhancement(s):</p>
<p>* [Rocky Linux-9.8.z] Intel CWF: CPU is unable to obtain cstate1 on idle system (JIRA:Rocky Linux-166118)</p>
<p>* ss core dumped when there is an SCTP session [rhel-9.8.z] (JIRA…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:59723"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ssa-019113</id>
    <title>SSA-019113 — SSA-019113: Vulnerabilities in the additional GNU/Linux subsystem of the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1.6</title>
    <updated>2026-10-03T21:21:20.679824+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.6 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant).</p>
<p>Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ssa-019113"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:0962-1</id>
    <title>SUSE-SU-2026:0962-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-03T21:21:20.679960+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:0962-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-23003</id>
    <title>UBUNTU-CVE-2026-23003</title>
    <updated>2026-10-03T21:21:20.680033+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe, Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:Pro:16.04:LTS: linux-oracle, Ubuntu:Pro:18.04:LTS: linux, Ubuntu:Pro:18.04:LTS: linux-aws, Ubuntu:18.04:LTS: linux-aws-5.0 and 212 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: ip6_tunnel: use skb_vlan_inet_prepare() in __ip6_tnl_rcv() Blamed commit did not take care of VLAN encapsulations as spotted by syzbot [1]. Use skb_vlan_inet_prepare() instead of pskb_inet_may_pull(). [1]  BUG: KMSAN: uninit-value in __INET_ECN_decapsulate include/net/inet_ecn.h:253 [inline]  BUG: KMSAN: uninit-value in INET_ECN_decapsulate include/net/inet_ecn.h:275 [inline]  BUG: KMSAN: uninit-value in IP6_ECN_decapsulate+0x7a8/0x1fa0 include/net/inet_ecn.h:321   __INET_ECN_decapsulate include/net/inet_ecn.h:253 [inline]   INET_ECN_decapsulate include/net/inet_ecn.h:275 [inline]   IP6_ECN_decapsulate+0x7a8/0x1fa0 include/net/inet_ecn.h:321   ip6ip6_dscp_ecn_decapsulate+0x16f/0x1b0 net/ipv6/ip6_tunnel.c:729   __ip6_tnl_rcv+0xed9/0x1b50 net/ipv6/ip6_tunnel.c:860   ip6_tnl_rcv+0xc3/0x100 net/ipv6/ip6_tunnel.c:903  gre_rcv+0x1529/0x1b90 net/ipv6/ip6_gre.c:-1   ip6_protocol_deliver_rcu+0x1c89/0x2c60 net/ipv6/ip6_input.c:438   ip6_input_finish+0x1f4/0x4a0 net/ipv6/ip6_input.c:489   NF_HOOK include/linux/netfilter.h:318 [inline]   ip6_input+0x9c/0x330 net/ipv6/ip6_input.c:500   ip6_mc_input+0x7ca/0xc10 net/ipv6/ip6_input.c:590   dst_input include/net/dst.h:474 [inline]   ip6_rcv_finish+0x958/0x990 net/ipv6/ip6_input.c:79   NF_HOOK include/linux/netfilter.h:318 [inline]   ipv6_rcv+0xf1/0x3c0 net/ipv6/ip6_input.c:311   __netif_receive_skb_one_core net/core/dev.c:6139 [inline]   __netif_receive_skb+0x1df/0xac0 net/c…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-23003"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0215</id>
    <title>WID-SEC-W-2026-0215 — Linux Kernel: Mehrere Schwachstellen</title>
    <updated>2026-10-03T21:21:20.680275+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um nicht näher spezifizierte Angriffe durchzuführen, die möglicherweise zu einer Denial-of-Service- Bedingung führen oder eine Speicherbeschädigung verursachen können.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0215"/>
  </entry>
</feed>
