<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T18:44:01.731679+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:71232</id>
    <title>ALSA-2026:71232 — Important: kernel security, bug fix, and enhancement update</title>
    <updated>2026-10-02T18:44:01.987124+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:9: kernel, AlmaLinux:9: kernel-64k, AlmaLinux:9: kernel-64k-core, AlmaLinux:9: kernel-64k-debug, AlmaLinux:9: kernel-64k-debug-core, AlmaLinux:9: kernel-64k-debug-modules, AlmaLinux:9: kernel-64k-debug-modules-core, AlmaLinux:9: kernel-64k-debug-modules-extra, AlmaLinux:9: kernel-64k-modules, AlmaLinux:9: kernel-64k-modules-core and 7 more</p>
<p>The kernel packages contain the Linux kernel, the core of any Linux operating system.</p>
<p>Security Fix(es):</p>
<p>* kernel: block: zero non-PI portion of auto integrity buffer (CVE-2026-23007)
  * kernel: af_unix: Drop all SCM attributes for SOCKMAP (CVE-2026-53005)
  * kernel: mac802154: llsec: add skb_cow_data() before in-place crypto (CVE-2026-63831)
  * kernel: blk-cgroup: fix UAF in __blkcg_rstat_flush() (CVE-2026-63802)
  * kernel: block: don't overwrite bip_vcnt in bio_integrity_copy_user() (CVE-2026-64053)
  * kernel: smb: client: fix double-free in SMB2_flush() replay (CVE-2026-64383)
  * kernel: nvmet-tcp: check INIT_FAILED before nvmet_req_uninit in digest error path (CVE-2026-64534)
  * kernel: sctp: don't free the ASCONF's own transport in DEL-IP processing (CVE-2026-64564)
  * kernel: ALSA: timer: drain a slave's callback before its master detaches it (CVE-2026-68201)
  * kernel: ASoC: SOF: ipc3-control: Validate size in snd_sof_update_control (CVE-2026-72261)
  * kernel: xfrm: ah6: validate routing header segments_left (CVE-2026-80844)
  * kernel: net: tun: bound receive headroom (CVE-2026-81000)
  * kernel: scsi: qla2xxx: Bound rsp_info_len to avoid OOB sense-data read (CVE-2026-89846)</p>
<p>Bug Fix(es) and Enhancement(s):</p>
<p>* sctp: prevent peer transport count overflow [almalinux-9.8.z] (JIRA:AlmaLinux-216251)
  * netfilter: nftables CVE and memory safety backports for 9.8 (JIRA:AlmaLinux-236634)</p>
<p>For more details about the security issue(s), including the imp…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:71232"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-04472</id>
    <title>bdu:2026-04472</title>
    <updated>2026-10-02T18:44:01.987410+00:00</updated>
    <content>bdu:2026-04472</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-04472"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-23007</id>
    <title>BELL-CVE-2026-23007</title>
    <updated>2026-10-02T18:44:01.987440+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-23007"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0926</id>
    <title>certfr-2026-avi-0926 — De multiples vulnérabilités ont été découvertes dans le noyau Linux d'Ubuntu. Certaines d'entre elles permettent à un a…</title>
    <updated>2026-10-02T18:44:01.987463+00:00</updated>
    <content>certfr-2026-avi-0926</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0926"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-315285</id>
    <title>EUVD-2026-315285</title>
    <updated>2026-10-02T18:44:01.987479+00:00</updated>
    <content>EUVD-2026-315285</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-315285"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-23007</id>
    <title>fkie_cve-2026-23007</title>
    <updated>2026-10-02T18:44:01.987490+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>block: zero non-PI portion of auto integrity buffer</p>
<p>The auto-generated integrity buffer for writes needs to be fully
initialized before being passed to the underlying block device,
otherwise the uninitialized memory can be read back by userspace or
anyone with physical access to the storage device. If protection
information is generated, that portion of the integrity buffer is
already initialized. The integrity data is also zeroed if PI generation
is disabled via sysfs or the PI tuple size is 0. However, this misses
the case where PI is generated and the PI tuple size is nonzero, but the
metadata size is larger than the PI tuple. In this case, the remainder
("opaque") of the metadata is left uninitialized.
Generalize the BLK_INTEGRITY_CSUM_NONE check to cover any case when the
metadata is larger than just the PI tuple.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-23007"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-2mvm-xgm9-r324</id>
    <title>GHSA-2mvm-xgm9-r324</title>
    <updated>2026-10-02T18:44:01.987532+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>block: zero non-PI portion of auto integrity buffer</p>
<p>The auto-generated integrity buffer for writes needs to be fully
initialized before being passed to the underlying block device,
otherwise the uninitialized memory can be read back by userspace or
anyone with physical access to the storage device. If protection
information is generated, that portion of the integrity buffer is
already initialized. The integrity data is also zeroed if PI generation
is disabled via sysfs or the PI tuple size is 0. However, this misses
the case where PI is generated and the PI tuple size is nonzero, but the
metadata size is larger than the PI tuple. In this case, the remainder
("opaque") of the metadata is left uninitialized.
Generalize the BLK_INTEGRITY_CSUM_NONE check to cover any case when the
metadata is larger than just the PI tuple.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-2mvm-xgm9-r324"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:71232</id>
    <title>RHSA-2026:71232 — Red Hat Security Advisory: kernel security, bug fix, and enhancement update</title>
    <updated>2026-10-02T18:44:01.987553+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>kernel: block: zero non-PI portion of auto integrity buffer kernel: af_unix: Drop all SCM attributes for SOCKMAP kernel: blk-cgroup: fix UAF in __blkcg_rstat_flush() kernel: mac802154: llsec: add skb_cow_data() before in-place crypto kernel: block: don't overwrite bip_vcnt in bio_integrity_copy_user() kernel: smb: client: fix double-free in SMB2_flush() replay kernel: nvmet-tcp: check INIT_FAILED before nvmet_req_uninit in digest error path kernel: sctp: don't free the ASCONF's own transport in DEL-IP processing kernel: ALSA: timer: drain a slave's callback before its master detaches it kernel: ASoC: SOF: ipc3-control: Validate size in snd_sof_update_control kernel: xfrm: ah6: validate routing header segments_left kernel: net: tun: bound receive headroom kernel: scsi: qla2xxx: Bound rsp_info_len to avoid OOB sense-data read</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:71232"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:71233</id>
    <title>RHSA-2026:71233 — Red Hat Security Advisory: kernel security, bug fix, and enhancement update</title>
    <updated>2026-10-02T18:44:01.987602+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>kernel: block: zero non-PI portion of auto integrity buffer kernel: netfilter: ebtables SNAT target writes to shared memory pages during ARP hardware address rewrite kernel: blk-cgroup: fix UAF in __blkcg_rstat_flush() kernel: mac802154: llsec: add skb_cow_data() before in-place crypto kernel: block: don't overwrite bip_vcnt in bio_integrity_copy_user() kernel: smb: client: fix double-free in SMB2_flush() replay kernel: sctp: don't free the ASCONF's own transport in DEL-IP processing kernel: ALSA: timer: drain a slave's callback before its master detaches it kernel: selinux: check connect-related permissions on TCP Fast Open kernel: netfilter: nf_conntrack_sip: widen NAT rewrite delta to s32 in sip_help_tcp() kernel: xfrm: ah6: validate routing header segments_left kernel: net: tun: bound receive headroom kernel: scsi: qla2xxx: Bound rsp_info_len to avoid OOB sense-data read</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:71233"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:71232</id>
    <title>RLSA-2026:71232 — Important: kernel security, bug fix, and enhancement update</title>
    <updated>2026-10-02T18:44:01.987642+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:9: kernel</p>
<p>The kernel packages contain the Linux kernel, the core of any Linux operating system.</p>
<p>Security Fix(es):</p>
<p>* kernel: block: zero non-PI portion of auto integrity buffer (CVE-2026-23007)</p>
<p>* kernel: af_unix: Drop all SCM attributes for SOCKMAP (CVE-2026-53005)</p>
<p>* kernel: mac802154: llsec: add skb_cow_data() before in-place crypto (CVE-2026-63831)</p>
<p>* kernel: blk-cgroup: fix UAF in __blkcg_rstat_flush() (CVE-2026-63802)</p>
<p>* kernel: block: don't overwrite bip_vcnt in bio_integrity_copy_user() (CVE-2026-64053)</p>
<p>* kernel: smb: client: fix double-free in SMB2_flush() replay (CVE-2026-64383)</p>
<p>* kernel: nvmet-tcp: check INIT_FAILED before nvmet_req_uninit in digest error path (CVE-2026-64534)</p>
<p>* kernel: sctp: don't free the ASCONF's own transport in DEL-IP processing (CVE-2026-64564)</p>
<p>* kernel: ALSA: timer: drain a slave's callback before its master detaches it (CVE-2026-68201)</p>
<p>* kernel: ASoC: SOF: ipc3-control: Validate size in snd_sof_update_control (CVE-2026-72261)</p>
<p>* kernel: xfrm: ah6: validate routing header segments_left (CVE-2026-80844)</p>
<p>* kernel: net: tun: bound receive headroom (CVE-2026-81000)</p>
<p>* kernel: scsi: qla2xxx: Bound rsp_info_len to avoid OOB sense-data read (CVE-2026-89846)</p>
<p>Bug Fix(es) and Enhancement(s):</p>
<p>* sctp: prevent peer transport count overflow [rhel-9.8.z] (JIRA:Rocky Linux-216251)</p>
<p>* netfilter: nftables CVE and memory safety backports for 9.8 (JIRA:Rocky Linux-236634)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowl…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:71232"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-23007</id>
    <title>UBUNTU-CVE-2026-23007</title>
    <updated>2026-10-02T18:44:01.987697+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 106 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: block: zero non-PI portion of auto integrity buffer The auto-generated integrity buffer for writes needs to be fully initialized before being passed to the underlying block device, otherwise the uninitialized memory can be read back by userspace or anyone with physical access to the storage device. If protection information is generated, that portion of the integrity buffer is already initialized. The integrity data is also zeroed if PI generation is disabled via sysfs or the PI tuple size is 0. However, this misses the case where PI is generated and the PI tuple size is nonzero, but the metadata size is larger than the PI tuple. In this case, the remainder ("opaque") of the metadata is left uninitialized. Generalize the BLK_INTEGRITY_CSUM_NONE check to cover any case when the metadata is larger than just the PI tuple.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-23007"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0215</id>
    <title>WID-SEC-W-2026-0215 — Linux Kernel: Mehrere Schwachstellen</title>
    <updated>2026-10-02T18:44:01.987982+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um nicht näher spezifizierte Angriffe durchzuführen, die möglicherweise zu einer Denial-of-Service- Bedingung führen oder eine Speicherbeschädigung verursachen können.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0215"/>
  </entry>
</feed>
