<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-05T15:37:59.780305+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-12151</id>
    <title>bdu:2026-12151</title>
    <updated>2026-10-05T15:37:59.812083+00:00</updated>
    <content>bdu:2026-12151</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-12151"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-23072</id>
    <title>BELL-CVE-2026-23072</title>
    <updated>2026-10-05T15:37:59.812175+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-23072"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0166</id>
    <title>certfr-2026-avi-0166 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de Debian. Elles permettent à un attaquant de provo…</title>
    <updated>2026-10-05T15:37:59.812206+00:00</updated>
    <content>certfr-2026-avi-0166</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0166"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-315331</id>
    <title>EUVD-2026-315331</title>
    <updated>2026-10-05T15:37:59.812224+00:00</updated>
    <content>EUVD-2026-315331</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-315331"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-23072</id>
    <title>fkie_cve-2026-23072</title>
    <updated>2026-10-05T15:37:59.812235+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>l2tp: Fix memleak in l2tp_udp_encap_recv().</p>
<p>syzbot reported memleak of struct l2tp_session, l2tp_tunnel,
sock, etc. [0]</p>
<p>The cited commit moved down the validation of the protocol
version in l2tp_udp_encap_recv().</p>
<p>The new place requires an extra error handling to avoid the
memleak.</p>
<p>Let's call l2tp_session_put() there.</p>
<p>[0]:
BUG: memory leak
unreferenced object 0xffff88810a290200 (size 512):
  comm "syz.0.17", pid 6086, jiffies 4294944299
  hex dump (first 32 bytes):
    7d eb 04 0c 00 00 00 00 01 00 00 00 00 00 00 00  }...............
    00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
  backtrace (crc babb6a4f):
    kmemleak_alloc_recursive include/linux/kmemleak.h:44 [inline]
    slab_post_alloc_hook mm/slub.c:4958 [inline]
    slab_alloc_node mm/slub.c:5263 [inline]
    __do_kmalloc_node mm/slub.c:5656 [inline]
    __kmalloc_noprof+0x3e0/0x660 mm/slub.c:5669
    kmalloc_noprof include/linux/slab.h:961 [inline]
    kzalloc_noprof include/linux/slab.h:1094 [inline]
    l2tp_session_create+0x3a/0x3b0 net/l2tp/l2tp_core.c:1778
    pppol2tp_connect+0x48b/0x920 net/l2tp/l2tp_ppp.c:755
    __sys_connect_file+0x7a/0xb0 net/socket.c:2089
    __sys_connect+0xde/0x110 net/socket.c:2108
    __do_sys_connect net/socket.c:2114 [inline]
    __se_sys_connect net/socket.c:2111 [inline]
    __x64_sys_connect+0x1c/0x30 net/socket.c:2111
    do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]
    do_…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-23072"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-fm5m-5cr7-5q35</id>
    <title>GHSA-fm5m-5cr7-5q35</title>
    <updated>2026-10-05T15:37:59.812280+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>l2tp: Fix memleak in l2tp_udp_encap_recv().</p>
<p>syzbot reported memleak of struct l2tp_session, l2tp_tunnel,
sock, etc. [0]</p>
<p>The cited commit moved down the validation of the protocol
version in l2tp_udp_encap_recv().</p>
<p>The new place requires an extra error handling to avoid the
memleak.</p>
<p>Let's call l2tp_session_put() there.</p>
<p>[0]:
BUG: memory leak
unreferenced object 0xffff88810a290200 (size 512):
  comm "syz.0.17", pid 6086, jiffies 4294944299
  hex dump (first 32 bytes):
    7d eb 04 0c 00 00 00 00 01 00 00 00 00 00 00 00  }...............
    00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
  backtrace (crc babb6a4f):
    kmemleak_alloc_recursive include/linux/kmemleak.h:44 [inline]
    slab_post_alloc_hook mm/slub.c:4958 [inline]
    slab_alloc_node mm/slub.c:5263 [inline]
    __do_kmalloc_node mm/slub.c:5656 [inline]
    __kmalloc_noprof+0x3e0/0x660 mm/slub.c:5669
    kmalloc_noprof include/linux/slab.h:961 [inline]
    kzalloc_noprof include/linux/slab.h:1094 [inline]
    l2tp_session_create+0x3a/0x3b0 net/l2tp/l2tp_core.c:1778
    pppol2tp_connect+0x48b/0x920 net/l2tp/l2tp_ppp.c:755
    __sys_connect_file+0x7a/0xb0 net/socket.c:2089
    __sys_connect+0xde/0x110 net/socket.c:2108
    __do_sys_connect net/socket.c:2114 [inline]
    __se_sys_connect net/socket.c:2111 [inline]
    __x64_sys_connect+0x1c/0x30 net/socket.c:2111
    do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]
    do_…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-fm5m-5cr7-5q35"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:20572-1</id>
    <title>openSUSE-SU-2026:20572-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-05T15:37:59.812313+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:20572-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:21230-1</id>
    <title>SUSE-SU-2026:21230-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-05T15:37:59.812361+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:21230-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-23072</id>
    <title>UBUNTU-CVE-2026-23072</title>
    <updated>2026-10-05T15:37:59.812405+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 106 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: l2tp: Fix memleak in l2tp_udp_encap_recv(). syzbot reported memleak of struct l2tp_session, l2tp_tunnel, sock, etc. [0] The cited commit moved down the validation of the protocol version in l2tp_udp_encap_recv(). The new place requires an extra error handling to avoid the memleak. Let's call l2tp_session_put() there. [0]: BUG: memory leak unreferenced object 0xffff88810a290200 (size 512):   comm "syz.0.17", pid 6086, jiffies 4294944299   hex dump (first 32 bytes):     7d eb 04 0c 00 00 00 00 01 00 00 00 00 00 00 00  }...............     00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................   backtrace (crc babb6a4f):     kmemleak_alloc_recursive include/linux/kmemleak.h:44 [inline]     slab_post_alloc_hook mm/slub.c:4958 [inline]     slab_alloc_node mm/slub.c:5263 [inline]     __do_kmalloc_node mm/slub.c:5656 [inline]     __kmalloc_noprof+0x3e0/0x660 mm/slub.c:5669     kmalloc_noprof include/linux/slab.h:961 [inline]     kzalloc_noprof include/linux/slab.h:1094 [inline]     l2tp_session_create+0x3a/0x3b0 net/l2tp/l2tp_core.c:1778     pppol2tp_connect+0x48b/0x920 net/l2tp/l2tp_ppp.c:755     __sys_connect_file+0x7a/0xb0 net/socket.c:2089     __sys_connect+0xde/0x110 net/socket.c:2108     __do_sys_connect net/socket.c:2114 [inline]     __se_sys_connect net/socket.c:2111 [inline]     __x64_sys_connect+0x1c/0x30 net/socket.c:2111     do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]     do_syscal…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-23072"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0324</id>
    <title>WID-SEC-W-2026-0324 — Linux Kernel: Mehrere Schwachstellen</title>
    <updated>2026-10-05T15:37:59.812550+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen im Linux-Kernel ausnutzen, um nicht näher spezifizierte Angriffe durchzuführen, die möglicherweise zu einer Denial-of-Service- Bedingung führen oder eine Speicherbeschädigung verursachen können.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0324"/>
  </entry>
</feed>
