<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T13:28:28.111712+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:27288</id>
    <title>ALSA-2026:27288 — Important: kernel security, bug fix, and enhancement update</title>
    <updated>2026-10-03T13:28:29.071680+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:10: kernel, AlmaLinux:10: kernel-64k, AlmaLinux:10: kernel-64k-core, AlmaLinux:10: kernel-64k-debug, AlmaLinux:10: kernel-64k-debug-core, AlmaLinux:10: kernel-64k-debug-devel, AlmaLinux:10: kernel-64k-debug-devel-matched, AlmaLinux:10: kernel-64k-debug-modules, AlmaLinux:10: kernel-64k-debug-modules-core, AlmaLinux:10: kernel-64k-debug-modules-extra and 65 more</p>
<p>The kernel packages contain the Linux kernel, the core of any Linux operating system.</p>
<p>Security Fix(es):</p>
<p>* kernel: can: isotp: fix tx.buf use-after-free in isotp_sendmsg() (CVE-2026-31474)
  * kernel: mptcp: fix slab-use-after-free in __inet_lookup_established (CVE-2026-31669)
  * kernel: rxrpc: Fix RxGK token loading to check bounds (CVE-2026-31641)
  * kernel: xen/privcmd: fix double free via VMA splitting (CVE-2026-31787)
  * kernel: Buffer overflow in drivers/xen/sys-hypervisor.c (CVE-2026-31786)
  * kernel: net: mana: fix use-after-free in add_adev() error path (CVE-2026-43056)
  * kernel: Bluetooth: hci_sync: fix stack buffer overflow in hci_le_big_create_sync (CVE-2026-31772)
  * kernel: bnxt_en: Fix RSS context delete logic (CVE-2026-43260)
  * kernel: crypto: caam - fix overflow on long hmac keys (CVE-2026-43330)
  * kernel: net/sched: act_pedit: extend the writable skb range per key (CVE-2026-46331)
  * kernel: Bluetooth: hci_event: fix potential UAF in SSP passkey handlers (CVE-2026-46056)
  * kernel: wifi: mac80211: drop stray 'static' from fast-RX rx_result (CVE-2026-46152)
  * kernel: wifi: mac80211: remove station if connection prep fails (CVE-2026-46125)
  * kernel: exit: prevent preemption of oopsing TASK_DEAD task (CVE-2026-46173)
  * kernel: wifi: mac80211: use safe list iteration in radar detect work (CVE-2026-46166)</p>
<p>Bug Fix(es) and Enhancement(s):</p>
<p>* AlmaLinux10.0 - s390/ap: Expose ap_bindings_complete_count counter via sysfs [almalinux-10.2…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:27288"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-31474</id>
    <title>BELL-CVE-2026-31474</title>
    <updated>2026-10-03T13:28:29.071868+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-31474"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0519</id>
    <title>certfr-2026-avi-0519 — De multiples vulnérabilités ont été découvertes dans Microsoft Azure Linux. Elles permettent à un attaquant de provoque…</title>
    <updated>2026-10-03T13:28:29.071895+00:00</updated>
    <content>certfr-2026-avi-0519</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0519"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-347692</id>
    <title>EUVD-2026-347692</title>
    <updated>2026-10-03T13:28:29.071914+00:00</updated>
    <content>EUVD-2026-347692</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-347692"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-31474</id>
    <title>fkie_cve-2026-31474</title>
    <updated>2026-10-03T13:28:29.071926+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>can: isotp: fix tx.buf use-after-free in isotp_sendmsg()</p>
<p>isotp_sendmsg() uses only cmpxchg() on so-&gt;tx.state to serialize access
to so-&gt;tx.buf. isotp_release() waits for ISOTP_IDLE via
wait_event_interruptible() and then calls kfree(so-&gt;tx.buf).</p>
<p>If a signal interrupts the wait_event_interruptible() inside close()
while tx.state is ISOTP_SENDING, the loop exits early and release
proceeds to force ISOTP_SHUTDOWN and continues to kfree(so-&gt;tx.buf)
while sendmsg may still be reading so-&gt;tx.buf for the final CAN frame
in isotp_fill_dataframe().</p>
<p>The so-&gt;tx.buf can be allocated once when the standard tx.buf length needs
to be extended. Move the kfree() of this potentially extended tx.buf to
sk_destruct time when either isotp_sendmsg() and isotp_release() are done.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-31474"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-6p7x-c5rv-9w7v</id>
    <title>GHSA-6p7x-c5rv-9w7v</title>
    <updated>2026-10-03T13:28:29.071959+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>can: isotp: fix tx.buf use-after-free in isotp_sendmsg()</p>
<p>isotp_sendmsg() uses only cmpxchg() on so-&gt;tx.state to serialize access
to so-&gt;tx.buf. isotp_release() waits for ISOTP_IDLE via
wait_event_interruptible() and then calls kfree(so-&gt;tx.buf).</p>
<p>If a signal interrupts the wait_event_interruptible() inside close()
while tx.state is ISOTP_SENDING, the loop exits early and release
proceeds to force ISOTP_SHUTDOWN and continues to kfree(so-&gt;tx.buf)
while sendmsg may still be reading so-&gt;tx.buf for the final CAN frame
in isotp_fill_dataframe().</p>
<p>The so-&gt;tx.buf can be allocated once when the standard tx.buf length needs
to be extended. Move the kfree() of this potentially extended tx.buf to
sk_destruct time when either isotp_sendmsg() and isotp_release() are done.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-6p7x-c5rv-9w7v"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-31474</id>
    <title>msrc_CVE-2026-31474 — can: isotp: fix tx.buf use-after-free in isotp_sendmsg()</title>
    <updated>2026-10-03T13:28:29.071982+00:00</updated>
    <content>msrc_CVE-2026-31474</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-31474"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:21555-1</id>
    <title>openSUSE-SU-2026:21555-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-03T13:28:29.071999+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:21555-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:27731</id>
    <title>RHSA-2026:27731 — Red Hat Security Advisory: kernel security, bug fix, and enhancement update</title>
    <updated>2026-10-03T13:28:29.072503+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>kernel: ceph: kernel: Ceph: exploit of hardcoded IVECs, in a misuse of AES, resulting in authentication bypass kernel: Linux kernel: Use-after-free in BPF sockmap can lead to denial of service and privilege escalation kernel: ipv6: use RCU in ip6_xmit() kernel: ipv6: use RCU in ip6_output() kernel: net: use dst_dev_rcu() in sk_setup_caps() kernel: Linux kernel: Denial of Service in libceph OSD client due to unreset sparse-read state kernel: can: isotp: fix tx.buf use-after-free in isotp_sendmsg() kernel: netfilter: ctnetlink: ensure safe access to master conntrack kernel: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows kernel: RDMA/iwcm: Fix workqueue list corruption by removing work_list kernel: wifi: mac80211: remove station if connection prep fails kernel: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL kernel: Linux kernel: Use-After-Free in net/gro due to improper handling of zerocopy skbs kernel: net/sched: act_pedit: extend the writable skb range per key</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:27731"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:27288</id>
    <title>RLSA-2026:27288 — Important: kernel security, bug fix, and enhancement update</title>
    <updated>2026-10-03T13:28:29.072548+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:10: kernel</p>
<p>The kernel packages contain the Linux kernel, the core of any Linux operating system.</p>
<p>Security Fix(es):</p>
<p>* kernel: can: isotp: fix tx.buf use-after-free in isotp_sendmsg() (CVE-2026-31474)</p>
<p>* kernel: mptcp: fix slab-use-after-free in __inet_lookup_established (CVE-2026-31669)</p>
<p>* kernel: rxrpc: Fix RxGK token loading to check bounds (CVE-2026-31641)</p>
<p>* kernel: xen/privcmd: fix double free via VMA splitting (CVE-2026-31787)</p>
<p>* kernel: Buffer overflow in drivers/xen/sys-hypervisor.c (CVE-2026-31786)</p>
<p>* kernel: net: mana: fix use-after-free in add_adev() error path (CVE-2026-43056)</p>
<p>* kernel: Bluetooth: hci_sync: fix stack buffer overflow in hci_le_big_create_sync (CVE-2026-31772)</p>
<p>* kernel: bnxt_en: Fix RSS context delete logic (CVE-2026-43260)</p>
<p>* kernel: crypto: caam - fix overflow on long hmac keys (CVE-2026-43330)</p>
<p>* kernel: net/sched: act_pedit: extend the writable skb range per key (CVE-2026-46331)</p>
<p>* kernel: Bluetooth: hci_event: fix potential UAF in SSP passkey handlers (CVE-2026-46056)</p>
<p>* kernel: wifi: mac80211: drop stray 'static' from fast-RX rx_result (CVE-2026-46152)</p>
<p>* kernel: wifi: mac80211: remove station if connection prep fails (CVE-2026-46125)</p>
<p>* kernel: exit: prevent preemption of oopsing TASK_DEAD task (CVE-2026-46173)</p>
<p>* kernel: wifi: mac80211: use safe list iteration in radar detect work (CVE-2026-46166)</p>
<p>Bug Fix(es) and Enhancement(s):</p>
<p>* Rocky Linux10.0 - s390/ap: Expose ap_bindings_complete_count counter via sysfs [rhel-10.2.z] (JIRA:Rocky Linux-166047…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:27288"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:23066-1</id>
    <title>SUSE-SU-2026:23066-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-03T13:28:29.072621+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:23066-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-31474</id>
    <title>UBUNTU-CVE-2026-31474</title>
    <updated>2026-10-03T13:28:29.073106+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 140 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: can: isotp: fix tx.buf use-after-free in isotp_sendmsg() isotp_sendmsg() uses only cmpxchg() on so-&gt;tx.state to serialize access to so-&gt;tx.buf. isotp_release() waits for ISOTP_IDLE via wait_event_interruptible() and then calls kfree(so-&gt;tx.buf). If a signal interrupts the wait_event_interruptible() inside close() while tx.state is ISOTP_SENDING, the loop exits early and release proceeds to force ISOTP_SHUTDOWN and continues to kfree(so-&gt;tx.buf) while sendmsg may still be reading so-&gt;tx.buf for the final CAN frame in isotp_fill_dataframe(). The so-&gt;tx.buf can be allocated once when the standard tx.buf length needs to be extended. Move the kfree() of this potentially extended tx.buf to sk_destruct time when either isotp_sendmsg() and isotp_release() are done.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-31474"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1252</id>
    <title>WID-SEC-W-2026-1252 — Linux Kernel: Mehrere Schwachstellen</title>
    <updated>2026-10-03T13:28:29.073274+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen, Sicherheitsmaßnahmen zu umgehen, Informationen offenzulegen, andere nicht näher spezifizierte Auswirkungen zu verursachen und möglicherweise Code auszuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1252"/>
  </entry>
</feed>
