<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T17:31:51.248863+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-12233</id>
    <title>bdu:2026-12233</title>
    <updated>2026-10-02T17:31:51.599299+00:00</updated>
    <content>bdu:2026-12233</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-12233"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-23100</id>
    <title>BELL-CVE-2026-23100</title>
    <updated>2026-10-02T17:31:51.599353+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: linux-lts, Alpaquita:stream: linux-lts</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-23100"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0291</id>
    <title>certfr-2026-avi-0291 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de Debian. Certaines d'entre elles permettent à un…</title>
    <updated>2026-10-02T17:31:51.599385+00:00</updated>
    <content>certfr-2026-avi-0291</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0291"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-364661</id>
    <title>EUVD-2026-364661</title>
    <updated>2026-10-02T17:31:51.599404+00:00</updated>
    <content>EUVD-2026-364661</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-364661"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-23100</id>
    <title>fkie_cve-2026-23100</title>
    <updated>2026-10-02T17:31:51.599416+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>mm/hugetlb: fix hugetlb_pmd_shared()</p>
<p>Patch series "mm/hugetlb: fixes for PMD table sharing (incl.  using
mmu_gather)", v3.</p>
<p>One functional fix, one performance regression fix, and two related
comment fixes.</p>
<p>I cleaned up my prototype I recently shared [1] for the performance fix,
deferring most of the cleanups I had in the prototype to a later point. 
While doing that I identified the other things.</p>
<p>The goal of this patch set is to be backported to stable trees "fairly"
easily. At least patch #1 and #4.</p>
<p>Patch #1 fixes hugetlb_pmd_shared() not detecting any sharing
Patch #2 + #3 are simple comment fixes that patch #4 interacts with.
Patch #4 is a fix for the reported performance regression due to excessive
IPI broadcasts during fork()+exit().</p>
<p>The last patch is all about TLB flushes, IPIs and mmu_gather.
Read: complicated</p>
<p>There are plenty of cleanups in the future to be had + one reasonable
optimization on x86. But that's all out of scope for this series.</p>
<p>Runtime tested, with a focus on fixing the performance regression using
the original reproducer [2] on x86.</p>
<p>This patch (of 4):</p>
<p>We switched from (wrongly) using the page count to an independent shared
count.  Now, shared page tables have a refcount of 1 (excluding
speculative references) and instead use ptdesc-&gt;pt_share_count to identify
sharing.</p>
<p>We didn't convert hugetlb_pmd_shared(), so right now, we would never
detect a shared PMD table as such, b…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-23100"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-4rhr-9xj2-x9gx</id>
    <title>GHSA-4rhr-9xj2-x9gx</title>
    <updated>2026-10-02T17:31:51.599467+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>mm/hugetlb: fix hugetlb_pmd_shared()</p>
<p>Patch series "mm/hugetlb: fixes for PMD table sharing (incl.  using
mmu_gather)", v3.</p>
<p>One functional fix, one performance regression fix, and two related
comment fixes.</p>
<p>I cleaned up my prototype I recently shared [1] for the performance fix,
deferring most of the cleanups I had in the prototype to a later point. 
While doing that I identified the other things.</p>
<p>The goal of this patch set is to be backported to stable trees "fairly"
easily. At least patch #1 and #4.</p>
<p>Patch #1 fixes hugetlb_pmd_shared() not detecting any sharing
Patch #2 + #3 are simple comment fixes that patch #4 interacts with.
Patch #4 is a fix for the reported performance regression due to excessive
IPI broadcasts during fork()+exit().</p>
<p>The last patch is all about TLB flushes, IPIs and mmu_gather.
Read: complicated</p>
<p>There are plenty of cleanups in the future to be had + one reasonable
optimization on x86. But that's all out of scope for this series.</p>
<p>Runtime tested, with a focus on fixing the performance regression using
the original reproducer [2] on x86.</p>
<p>This patch (of 4):</p>
<p>We switched from (wrongly) using the page count to an independent shared
count.  Now, shared page tables have a refcount of 1 (excluding
speculative references) and instead use ptdesc-&gt;pt_share_count to identify
sharing.</p>
<p>We didn't convert hugetlb_pmd_shared(), so right now, we would never
detect a shared PMD table as such, b…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-4rhr-9xj2-x9gx"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-26-209-04</id>
    <title>ICSA-26-209-04 — Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</title>
    <updated>2026-10-02T17:31:51.599504+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.6 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant).</p>
<p>Siemens is preparing fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-26-209-04"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-23100</id>
    <title>msrc_CVE-2026-23100 — mm/hugetlb: fix hugetlb_pmd_shared()</title>
    <updated>2026-10-02T17:31:51.599751+00:00</updated>
    <content>msrc_CVE-2026-23100</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-23100"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-1642</id>
    <title>OESA-2026-1642 — kernel security update</title>
    <updated>2026-10-02T17:31:51.599768+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS: kernel</p>
<p>The Linux Kernel, the operating system core itself.

Security Fix(es):</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>fs/xattr: missing fdput() in fremovexattr error path</p>
<p>In the Linux kernel, the fremovexattr() syscall calls fdget() to acquire a
file reference but returns early without calling fdput() when
strncpy_from_user() fails on the name argument. In multi-threaded processes
where fdget() takes the slow path, this permanently leaks one
file reference per call, pinning the struct file and associated kernel
objects in memory. An unprivileged local user can exploit this to cause
kernel memory exhaustion. The issue was inadvertently fixed by commit
a71874379ec8 (&amp;quot;xattr: switch to CLASS(fd)&amp;quot;).(CVE-2024-14027)</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>pps: Fix a use-after-free</p>
<p>On a board running ntpd and gpsd, I&amp;apos;m seeing a consistent use-after-free
in sys_exit() from gpsd when rebooting:</p>
<p>pps pps1: removed
    ------------[ cut here ]------------
    kobject: &amp;apos;(null)&amp;apos; (00000000db4bec24): is not initialized, yet kobject_put() is being called.
    WARNING: CPU: 2 PID: 440 at lib/kobject.c:734 kobject_put+0x120/0x150
    CPU: 2 UID: 299 PID: 440 Comm: gpsd Not tainted 6.11.0-rc6-00308-gb31c44928842 #1
    Hardware name: Raspberry Pi 4 Model B Rev 1.1 (DT)
    pstate: 60000005 (nZCv daif -PAN -UAO -TCO -DIT -SSBS BTYPE=--)
    pc : kobject_put+0x120/0x150
    lr : kobject_put+0x120/0x150
    sp :…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-1642"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:20416-1</id>
    <title>openSUSE-SU-2026:20416-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-02T17:31:51.599901+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:20416-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ssa-019113</id>
    <title>SSA-019113 — SSA-019113: Vulnerabilities in the additional GNU/Linux subsystem of the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1.6</title>
    <updated>2026-10-02T17:31:51.600024+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.6 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant).</p>
<p>Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ssa-019113"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:20838-1</id>
    <title>SUSE-SU-2026:20838-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-02T17:31:51.600281+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:20838-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-23100</id>
    <title>UBUNTU-CVE-2026-23100</title>
    <updated>2026-10-02T17:31:51.600392+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 175 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: mm/hugetlb: fix hugetlb_pmd_shared() Patch series "mm/hugetlb: fixes for PMD table sharing (incl.  using mmu_gather)", v3. One functional fix, one performance regression fix, and two related comment fixes. I cleaned up my prototype I recently shared [1] for the performance fix, deferring most of the cleanups I had in the prototype to a later point. While doing that I identified the other things. The goal of this patch set is to be backported to stable trees "fairly" easily. At least patch #1 and #4. Patch #1 fixes hugetlb_pmd_shared() not detecting any sharing Patch #2 + #3 are simple comment fixes that patch #4 interacts with. Patch #4 is a fix for the reported performance regression due to excessive IPI broadcasts during fork()+exit(). The last patch is all about TLB flushes, IPIs and mmu_gather. Read: complicated There are plenty of cleanups in the future to be had + one reasonable optimization on x86. But that's all out of scope for this series. Runtime tested, with a focus on fixing the performance regression using the original reproducer [2] on x86. This patch (of 4): We switched from (wrongly) using the page count to an independent shared count.  Now, shared page tables have a refcount of 1 (excluding speculative references) and instead use ptdesc-&gt;pt_share_count to identify sharing. We didn't convert hugetlb_pmd_shared(), so right now, we would never detect a shared PMD table as such, because sharing…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-23100"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0324</id>
    <title>WID-SEC-W-2026-0324 — Linux Kernel: Mehrere Schwachstellen</title>
    <updated>2026-10-02T17:31:51.600655+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen im Linux-Kernel ausnutzen, um nicht näher spezifizierte Angriffe durchzuführen, die möglicherweise zu einer Denial-of-Service- Bedingung führen oder eine Speicherbeschädigung verursachen können.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0324"/>
  </entry>
</feed>
