<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T10:26:15.526995+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-11319</id>
    <title>bdu:2026-11319</title>
    <updated>2026-10-04T10:26:15.542587+00:00</updated>
    <content>bdu:2026-11319</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-11319"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-31444</id>
    <title>BELL-CVE-2026-31444</title>
    <updated>2026-10-04T10:26:15.542654+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-31444"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0519</id>
    <title>certfr-2026-avi-0519 — De multiples vulnérabilités ont été découvertes dans Microsoft Azure Linux. Elles permettent à un attaquant de provoque…</title>
    <updated>2026-10-04T10:26:15.542689+00:00</updated>
    <content>certfr-2026-avi-0519</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0519"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-347682</id>
    <title>EUVD-2026-347682</title>
    <updated>2026-10-04T10:26:15.542711+00:00</updated>
    <content>EUVD-2026-347682</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-347682"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-31444</id>
    <title>fkie_cve-2026-31444</title>
    <updated>2026-10-04T10:26:15.542725+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>ksmbd: fix use-after-free and NULL deref in smb_grant_oplock()</p>
<p>smb_grant_oplock() has two issues in the oplock publication sequence:</p>
<p>1) opinfo is linked into ci-&gt;m_op_list (via opinfo_add) before
   add_lease_global_list() is called.  If add_lease_global_list()
   fails (kmalloc returns NULL), the error path frees the opinfo
   via __free_opinfo() while it is still linked in ci-&gt;m_op_list.
   Concurrent m_op_list readers (opinfo_get_list, or direct iteration
   in smb_break_all_levII_oplock) dereference the freed node.</p>
<p>2) opinfo-&gt;o_fp is assigned after add_lease_global_list() publishes
   the opinfo on the global lease list.  A concurrent
   find_same_lease_key() can walk the lease list and dereference
   opinfo-&gt;o_fp-&gt;f_ci while o_fp is still NULL.</p>
<p>Fix by restructuring the publication sequence to eliminate post-publish
failure:</p>
<p>- Set opinfo-&gt;o_fp before any list publication (fixes NULL deref).
- Preallocate lease_table via alloc_lease_table() before opinfo_add()
  so add_lease_global_list() becomes infallible after publication.
- Keep the original m_op_list publication order (opinfo_add before
  lease list) so concurrent opens via same_client_has_lease() and
  opinfo_get_list() still see the in-flight grant.
- Use opinfo_put() instead of __free_opinfo() on err_out so that
  the RCU-deferred free path is used.</p>
<p>This also requires splitting add_lease_global_list() to take a
preallocated lease_table and…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-31444"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-8vw8-r4jr-vp93</id>
    <title>GHSA-8vw8-r4jr-vp93</title>
    <updated>2026-10-04T10:26:15.542782+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>ksmbd: fix use-after-free and NULL deref in smb_grant_oplock()</p>
<p>smb_grant_oplock() has two issues in the oplock publication sequence:</p>
<p>1) opinfo is linked into ci-&gt;m_op_list (via opinfo_add) before
   add_lease_global_list() is called.  If add_lease_global_list()
   fails (kmalloc returns NULL), the error path frees the opinfo
   via __free_opinfo() while it is still linked in ci-&gt;m_op_list.
   Concurrent m_op_list readers (opinfo_get_list, or direct iteration
   in smb_break_all_levII_oplock) dereference the freed node.</p>
<p>2) opinfo-&gt;o_fp is assigned after add_lease_global_list() publishes
   the opinfo on the global lease list.  A concurrent
   find_same_lease_key() can walk the lease list and dereference
   opinfo-&gt;o_fp-&gt;f_ci while o_fp is still NULL.</p>
<p>Fix by restructuring the publication sequence to eliminate post-publish
failure:</p>
<p>- Set opinfo-&gt;o_fp before any list publication (fixes NULL deref).
- Preallocate lease_table via alloc_lease_table() before opinfo_add()
  so add_lease_global_list() becomes infallible after publication.
- Keep the original m_op_list publication order (opinfo_add before
  lease list) so concurrent opens via same_client_has_lease() and
  opinfo_get_list() still see the in-flight grant.
- Use opinfo_put() instead of __free_opinfo() on err_out so that
  the RCU-deferred free path is used.</p>
<p>This also requires splitting add_lease_global_list() to take a
preallocated lease_table and…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-8vw8-r4jr-vp93"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-31444</id>
    <title>msrc_CVE-2026-31444 — ksmbd: fix use-after-free and NULL deref in smb_grant_oplock()</title>
    <updated>2026-10-04T10:26:15.542817+00:00</updated>
    <content>msrc_CVE-2026-31444</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-31444"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-31444</id>
    <title>UBUNTU-CVE-2026-31444</title>
    <updated>2026-10-04T10:26:15.542835+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 98 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free and NULL deref in smb_grant_oplock() smb_grant_oplock() has two issues in the oplock publication sequence: 1) opinfo is linked into ci-&gt;m_op_list (via opinfo_add) before    add_lease_global_list() is called.  If add_lease_global_list()    fails (kmalloc returns NULL), the error path frees the opinfo    via __free_opinfo() while it is still linked in ci-&gt;m_op_list.    Concurrent m_op_list readers (opinfo_get_list, or direct iteration    in smb_break_all_levII_oplock) dereference the freed node. 2) opinfo-&gt;o_fp is assigned after add_lease_global_list() publishes    the opinfo on the global lease list.  A concurrent    find_same_lease_key() can walk the lease list and dereference    opinfo-&gt;o_fp-&gt;f_ci while o_fp is still NULL. Fix by restructuring the publication sequence to eliminate post-publish failure: - Set opinfo-&gt;o_fp before any list publication (fixes NULL deref). - Preallocate lease_table via alloc_lease_table() before opinfo_add()   so add_lease_global_list() becomes infallible after publication. - Keep the original m_op_list publication order (opinfo_add before   lease list) so concurrent opens via same_client_has_lease() and   opinfo_get_list() still see the in-flight grant. - Use opinfo_put() instead of __free_opinfo() on err_out so that   the RCU-deferred free path is used. This also requires splitting add_lease_global_list() to take a preallocated lease_table and changin…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-31444"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1252</id>
    <title>WID-SEC-W-2026-1252 — Linux Kernel: Mehrere Schwachstellen</title>
    <updated>2026-10-04T10:26:15.543166+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen, Sicherheitsmaßnahmen zu umgehen, Informationen offenzulegen, andere nicht näher spezifizierte Auswirkungen zu verursachen und möglicherweise Code auszuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1252"/>
  </entry>
</feed>
