<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T21:34:03.397214+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:21557</id>
    <title>ALSA-2026:21557 — Important: kernel security update</title>
    <updated>2026-10-03T21:34:03.746861+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:10: kernel, AlmaLinux:10: kernel-64k, AlmaLinux:10: kernel-64k-core, AlmaLinux:10: kernel-64k-debug, AlmaLinux:10: kernel-64k-debug-core, AlmaLinux:10: kernel-64k-debug-devel, AlmaLinux:10: kernel-64k-debug-devel-matched, AlmaLinux:10: kernel-64k-debug-modules, AlmaLinux:10: kernel-64k-debug-modules-core, AlmaLinux:10: kernel-64k-debug-modules-extra and 65 more</p>
<p>The kernel packages contain the Linux kernel, the core of any Linux operating system.</p>
<p>Security Fix(es):</p>
<p>* kernel: can: j1939: j1939_session_new(): fix skb reference counting (CVE-2024-56645)
  * kernel: ima: don't clear IMA_DIGSIG flag when setting or removing non-IMA xattr (CVE-2025-68183)
  * kernel: mm: thp: deny THP for files on anonymous inodes (CVE-2026-23375)
  * kernel: netfilter: nf_tables: release flowtable after rcu grace period on error (CVE-2026-23392)
  * kernel: netfilter: nf_conntrack_h323: check for zero length in DecodeQ931() (CVE-2026-23455)
  * kernel: net: sched: act_csum: validate nested VLAN headers (CVE-2026-31684)
  * kernel: netfilter: ip6t_eui64: reject invalid MAC header for all packets (CVE-2026-31685)
  * kernel: netfilter: nf_conntrack_helper: pass helper to expect cleanup (CVE-2026-43027)
  * kernel: io_uring/rsrc: reject zero-length fixed buffer import (CVE-2026-43006)
  * kernel: Bluetooth: MGMT: validate LTK enc_size on load (CVE-2026-43020)
  * kernel: HID: wacom: fix out-of-bounds read in wacom_intuos_bt_irq (CVE-2026-43051)
  * kernel: Bluetooth: SCO: fix race conditions in sco_sock_connect() (CVE-2026-43023)
  * kernel: netfilter: ctnetlink: ensure safe access to master conntrack (CVE-2026-43116)
  * kernel: wifi: brcmfmac: validate bsscfg indices in IF events (CVE-2026-43110)
  * kernel: netfilter: xt_tcpmss: check remaining length before reading optlen (CVE-2026-43190)
  * kernel: Linux kernel dpaa2-switch: Kernel memory corru…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:21557"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-12298</id>
    <title>bdu:2026-12298</title>
    <updated>2026-10-03T21:34:03.747025+00:00</updated>
    <content>bdu:2026-12298</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-12298"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-23375</id>
    <title>BELL-CVE-2026-23375</title>
    <updated>2026-10-03T21:34:03.747046+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-23375"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0548</id>
    <title>certfr-2026-avi-0548 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de Debian. Certaines d'entre elles permettent à un…</title>
    <updated>2026-10-03T21:34:03.747067+00:00</updated>
    <content>certfr-2026-avi-0548</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0548"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-315508</id>
    <title>EUVD-2026-315508</title>
    <updated>2026-10-03T21:34:03.747084+00:00</updated>
    <content>EUVD-2026-315508</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-315508"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-23375</id>
    <title>fkie_cve-2026-23375</title>
    <updated>2026-10-03T21:34:03.747095+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>mm: thp: deny THP for files on anonymous inodes</p>
<p>file_thp_enabled() incorrectly allows THP for files on anonymous inodes
(e.g. guest_memfd and secretmem). These files are created via
alloc_file_pseudo(), which does not call get_write_access() and leaves
inode-&gt;i_writecount at 0. Combined with S_ISREG(inode-&gt;i_mode) being
true, they appear as read-only regular files when
CONFIG_READ_ONLY_THP_FOR_FS is enabled, making them eligible for THP
collapse.</p>
<p>Anonymous inodes can never pass the inode_is_open_for_write() check
since their i_writecount is never incremented through the normal VFS
open path. The right thing to do is to exclude them from THP eligibility
altogether, since CONFIG_READ_ONLY_THP_FOR_FS was designed for real
filesystem files (e.g. shared libraries), not for pseudo-filesystem
inodes.</p>
<p>For guest_memfd, this allows khugepaged and MADV_COLLAPSE to create
large folios in the page cache via the collapse path, but the
guest_memfd fault handler does not support large folios. This triggers
WARN_ON_ONCE(folio_test_large(folio)) in kvm_gmem_fault_user_mapping().</p>
<p>For secretmem, collapse_file() tries to copy page contents through the
direct map, but secretmem pages are removed from the direct map. This
can result in a kernel crash:</p>
<p>BUG: unable to handle page fault for address: ffff88810284d000
    RIP: 0010:memcpy_orig+0x16/0x130
    Call Trace:
     collapse_file
     hpage_collapse_scan_file
     ma…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-23375"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-9ghh-p583-m6m8</id>
    <title>GHSA-9ghh-p583-m6m8</title>
    <updated>2026-10-03T21:34:03.747135+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>mm: thp: deny THP for files on anonymous inodes</p>
<p>file_thp_enabled() incorrectly allows THP for files on anonymous inodes
(e.g. guest_memfd and secretmem). These files are created via
alloc_file_pseudo(), which does not call get_write_access() and leaves
inode-&gt;i_writecount at 0. Combined with S_ISREG(inode-&gt;i_mode) being
true, they appear as read-only regular files when
CONFIG_READ_ONLY_THP_FOR_FS is enabled, making them eligible for THP
collapse.</p>
<p>Anonymous inodes can never pass the inode_is_open_for_write() check
since their i_writecount is never incremented through the normal VFS
open path. The right thing to do is to exclude them from THP eligibility
altogether, since CONFIG_READ_ONLY_THP_FOR_FS was designed for real
filesystem files (e.g. shared libraries), not for pseudo-filesystem
inodes.</p>
<p>For guest_memfd, this allows khugepaged and MADV_COLLAPSE to create
large folios in the page cache via the collapse path, but the
guest_memfd fault handler does not support large folios. This triggers
WARN_ON_ONCE(folio_test_large(folio)) in kvm_gmem_fault_user_mapping().</p>
<p>For secretmem, collapse_file() tries to copy page contents through the
direct map, but secretmem pages are removed from the direct map. This
can result in a kernel crash:</p>
<p>BUG: unable to handle page fault for address: ffff88810284d000
    RIP: 0010:memcpy_orig+0x16/0x130
    Call Trace:
     collapse_file
     hpage_collapse_scan_file
     ma…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-9ghh-p583-m6m8"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-1862</id>
    <title>OESA-2026-1862 — kernel security update</title>
    <updated>2026-10-03T21:34:03.747167+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS: kernel</p>
<p>The Linux Kernel, the operating system core itself.

Security Fix(es):</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>f2fs: fix to detect potential corrupted nid in free_nid_list</p>
<p>As reported, on-disk footer.ino and footer.nid is the same and
out-of-range, let&amp;apos;s add sanity check on f2fs_alloc_nid() to detect
any potential corruption in free_nid_list.(CVE-2025-68315)</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>ntfs3: Fix uninit buffer allocated by __getname()</p>
<p>Fix uninit errors caused after buffer allocation given to &amp;apos;de&amp;apos;; by
initializing the buffer with zeroes. The fix was found by using KMSAN.(CVE-2025-68727)</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>netfilter: nf_tables: fix use-after-free in nf_tables_addchain()</p>
<p>nf_tables_addchain() publishes the chain to table-&amp;gt;chains via
list_add_tail_rcu() (in nft_chain_add()) before registering hooks.
If nf_tables_register_hook() then fails, the error path calls
nft_chain_del() (list_del_rcu()) followed by nf_tables_chain_destroy()
with no RCU grace period in between.</p>
<p>This creates two use-after-free conditions:</p>
<p>1) Control-plane: nf_tables_dump_chains() traverses table-&amp;gt;chains
    under rcu_read_lock(). A concurrent dump can still be walking
    the chain when the error path frees it.</p>
<p>2) Packet path: for NFPROTO_INET, nf_register_net_hook() briefly
    installs the IPv4 hook before IPv6 registration fails.  Packets
    entering nft…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-1862"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:20826-1</id>
    <title>openSUSE-SU-2026:20826-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-03T21:34:03.747423+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:20826-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:55445</id>
    <title>RHSA-2026:55445 — Red Hat Security Advisory: kernel security, bug fix, and enhancement update</title>
    <updated>2026-10-03T21:34:03.747558+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>kernel: Arm Processors: Privilege escalation or information disclosure via writes to higher exception level resources kernel: iommu: disable SVA when CONFIG_X86 is set kernel: crypto: seqiv - Do not use req-&gt;iv after crypto_aead_encrypt kernel: scsi: core: Wake up the error handler when final completions race against each other kernel: mm: thp: deny THP for files on anonymous inodes kernel: netfilter: nf_conntrack_h323: check for zero length in DecodeQ931() kernel: drm/amd/display: Do not skip unrelated mode changes in DSC validation kernel: ALSA: usb-audio: Add sanity check for OOB writes at silencing kernel: rxrpc: Fix potential UAF after skb_unshare() failure kernel: netfilter: nat: use kfree_rcu to release ops kernel: dm log: fix out-of-bounds write due to region_count overflow kernel: net/sched: act_api: use RCU with deferred freeing for action lifecycle</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:55445"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:21557</id>
    <title>RLSA-2026:21557 — Important: kernel security update</title>
    <updated>2026-10-03T21:34:03.747597+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:10: kernel</p>
<p>The kernel packages contain the Linux kernel, the core of any Linux operating system.</p>
<p>Security Fix(es):</p>
<p>* kernel: can: j1939: j1939_session_new(): fix skb reference counting (CVE-2024-56645)</p>
<p>* kernel: ima: don't clear IMA_DIGSIG flag when setting or removing non-IMA xattr (CVE-2025-68183)</p>
<p>* kernel: mm: thp: deny THP for files on anonymous inodes (CVE-2026-23375)</p>
<p>* kernel: netfilter: nf_tables: release flowtable after rcu grace period on error (CVE-2026-23392)</p>
<p>* kernel: netfilter: nf_conntrack_h323: check for zero length in DecodeQ931() (CVE-2026-23455)</p>
<p>* kernel: net: sched: act_csum: validate nested VLAN headers (CVE-2026-31684)</p>
<p>* kernel: netfilter: ip6t_eui64: reject invalid MAC header for all packets (CVE-2026-31685)</p>
<p>* kernel: netfilter: nf_conntrack_helper: pass helper to expect cleanup (CVE-2026-43027)</p>
<p>* kernel: io_uring/rsrc: reject zero-length fixed buffer import (CVE-2026-43006)</p>
<p>* kernel: Bluetooth: MGMT: validate LTK enc_size on load (CVE-2026-43020)</p>
<p>* kernel: HID: wacom: fix out-of-bounds read in wacom_intuos_bt_irq (CVE-2026-43051)</p>
<p>* kernel: Bluetooth: SCO: fix race conditions in sco_sock_connect() (CVE-2026-43023)</p>
<p>* kernel: netfilter: ctnetlink: ensure safe access to master conntrack (CVE-2026-43116)</p>
<p>* kernel: wifi: brcmfmac: validate bsscfg indices in IF events (CVE-2026-43110)</p>
<p>* kernel: netfilter: xt_tcpmss: check remaining length before reading optlen (CVE-2026-43190)</p>
<p>* kernel: Linux kernel dpaa2-switch: Kernel memory corruption via out-of-boun…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:21557"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:21834-1</id>
    <title>SUSE-SU-2026:21834-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-03T21:34:03.747640+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:21834-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-23375</id>
    <title>UBUNTU-CVE-2026-23375</title>
    <updated>2026-10-03T21:34:03.747768+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 140 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: mm: thp: deny THP for files on anonymous inodes file_thp_enabled() incorrectly allows THP for files on anonymous inodes (e.g. guest_memfd and secretmem). These files are created via alloc_file_pseudo(), which does not call get_write_access() and leaves inode-&gt;i_writecount at 0. Combined with S_ISREG(inode-&gt;i_mode) being true, they appear as read-only regular files when CONFIG_READ_ONLY_THP_FOR_FS is enabled, making them eligible for THP collapse. Anonymous inodes can never pass the inode_is_open_for_write() check since their i_writecount is never incremented through the normal VFS open path. The right thing to do is to exclude them from THP eligibility altogether, since CONFIG_READ_ONLY_THP_FOR_FS was designed for real filesystem files (e.g. shared libraries), not for pseudo-filesystem inodes. For guest_memfd, this allows khugepaged and MADV_COLLAPSE to create large folios in the page cache via the collapse path, but the guest_memfd fault handler does not support large folios. This triggers WARN_ON_ONCE(folio_test_large(folio)) in kvm_gmem_fault_user_mapping(). For secretmem, collapse_file() tries to copy page contents through the direct map, but secretmem pages are removed from the direct map. This can result in a kernel crash:     BUG: unable to handle page fault for address: ffff88810284d000     RIP: 0010:memcpy_orig+0x16/0x130     Call Trace:      collapse_file      hpage_collapse_scan_file      madvise_…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-23375"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0861</id>
    <title>WID-SEC-W-2026-0861 — Linux Kernel: Mehrere Schwachstellen</title>
    <updated>2026-10-03T21:34:03.747952+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Linux Kernel ausnutzen, um einen Denial of Service zu verursachen, Sicherheitsmaßnahmen zu umgehen, Informationen offenzulegen, weitere nicht spezifizierte Auswirkungen zu verursachen und potentiell Code auszuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0861"/>
  </entry>
</feed>
