<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T12:12:00.512794+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-12571</id>
    <title>bdu:2026-12571</title>
    <updated>2026-10-04T12:12:01.352789+00:00</updated>
    <content>bdu:2026-12571</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-12571"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-31580</id>
    <title>BELL-CVE-2026-31580</title>
    <updated>2026-10-04T12:12:01.352873+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-31580"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0548</id>
    <title>certfr-2026-avi-0548 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de Debian. Certaines d'entre elles permettent à un…</title>
    <updated>2026-10-04T12:12:01.352910+00:00</updated>
    <content>certfr-2026-avi-0548</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0548"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-327012</id>
    <title>EUVD-2026-327012</title>
    <updated>2026-10-04T12:12:01.352929+00:00</updated>
    <content>EUVD-2026-327012</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-327012"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-31580</id>
    <title>fkie_cve-2026-31580</title>
    <updated>2026-10-04T12:12:01.352941+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>bcache: fix cached_dev.sb_bio use-after-free and crash</p>
<p>In our production environment, we have received multiple crash reports
regarding libceph, which have caught our attention:</p>
<p>```
[6888366.280350] Call Trace:
[6888366.280452]  blk_update_request+0x14e/0x370
[6888366.280561]  blk_mq_end_request+0x1a/0x130
[6888366.280671]  rbd_img_handle_request+0x1a0/0x1b0 [rbd]
[6888366.280792]  rbd_obj_handle_request+0x32/0x40 [rbd]
[6888366.280903]  __complete_request+0x22/0x70 [libceph]
[6888366.281032]  osd_dispatch+0x15e/0xb40 [libceph]
[6888366.281164]  ? inet_recvmsg+0x5b/0xd0
[6888366.281272]  ? ceph_tcp_recvmsg+0x6f/0xa0 [libceph]
[6888366.281405]  ceph_con_process_message+0x79/0x140 [libceph]
[6888366.281534]  ceph_con_v1_try_read+0x5d7/0xf30 [libceph]
[6888366.281661]  ceph_con_workfn+0x329/0x680 [libceph]
```</p>
<p>After analyzing the coredump file, we found that the address of
dc-&gt;sb_bio has been freed. We know that cached_dev is only freed when it
is stopped.</p>
<p>Since sb_bio is a part of struct cached_dev, rather than an alloc every
time.  If the device is stopped while writing to the superblock, the
released address will be accessed at endio.</p>
<p>This patch hopes to wait for sb_write to complete in cached_dev_free.</p>
<p>It should be noted that we analyzed the cause of the problem, then tell
all details to the QWEN and adopted the modifications it made.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-31580"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-g664-f62x-2rfm</id>
    <title>GHSA-g664-f62x-2rfm</title>
    <updated>2026-10-04T12:12:01.352982+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>bcache: fix cached_dev.sb_bio use-after-free and crash</p>
<p>In our production environment, we have received multiple crash reports
regarding libceph, which have caught our attention:</p>
<p>```
[6888366.280350] Call Trace:
[6888366.280452]  blk_update_request+0x14e/0x370
[6888366.280561]  blk_mq_end_request+0x1a/0x130
[6888366.280671]  rbd_img_handle_request+0x1a0/0x1b0 [rbd]
[6888366.280792]  rbd_obj_handle_request+0x32/0x40 [rbd]
[6888366.280903]  __complete_request+0x22/0x70 [libceph]
[6888366.281032]  osd_dispatch+0x15e/0xb40 [libceph]
[6888366.281164]  ? inet_recvmsg+0x5b/0xd0
[6888366.281272]  ? ceph_tcp_recvmsg+0x6f/0xa0 [libceph]
[6888366.281405]  ceph_con_process_message+0x79/0x140 [libceph]
[6888366.281534]  ceph_con_v1_try_read+0x5d7/0xf30 [libceph]
[6888366.281661]  ceph_con_workfn+0x329/0x680 [libceph]
```</p>
<p>After analyzing the coredump file, we found that the address of
dc-&gt;sb_bio has been freed. We know that cached_dev is only freed when it
is stopped.</p>
<p>Since sb_bio is a part of struct cached_dev, rather than an alloc every
time.  If the device is stopped while writing to the superblock, the
released address will be accessed at endio.</p>
<p>This patch hopes to wait for sb_write to complete in cached_dev_free.</p>
<p>It should be noted that we analyzed the cause of the problem, then tell
all details to the QWEN and adopted the modifications it made.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-g664-f62x-2rfm"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-31580</id>
    <title>msrc_CVE-2026-31580 — bcache: fix cached_dev.sb_bio use-after-free and crash</title>
    <updated>2026-10-04T12:12:01.353009+00:00</updated>
    <content>msrc_CVE-2026-31580</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-31580"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-2754</id>
    <title>OESA-2026-2754 — kernel security update</title>
    <updated>2026-10-04T12:12:01.353028+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:22.03-LTS-SP4: kernel</p>
<p>The Linux Kernel, the operating system core itself.

Security Fix(es):</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>fbdev: fix potential buffer overflow in do_register_framebuffer()</p>
<p>The current implementation may lead to buffer overflow when:
1.  Unregistration creates NULL gaps in registered_fb[]
2.  All array slots become occupied despite num_registered_fb &amp;lt; FB_MAX
3.  The registration loop exceeds array bounds</p>
<p>Add boundary check to prevent registered_fb[FB_MAX] access.(CVE-2025-38702)</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>hfs: validate record offset in hfsplus_bmap_alloc</p>
<p>hfsplus_bmap_alloc can trigger a crash if a
record offset or length is larger than node_size</p>
<p>[   15.264282] BUG: KASAN: slab-out-of-bounds in hfsplus_bmap_alloc+0x887/0x8b0
[   15.265192] Read of size 8 at addr ffff8881085ca188 by task test/183
[   15.265949]
[   15.266163] CPU: 0 UID: 0 PID: 183 Comm: test Not tainted 6.17.0-rc2-gc17b750b3ad9 #14 PREEMPT(voluntary)
[   15.266165] Hardware name: QEMU Ubuntu 24.04 PC (i440FX + PIIX, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
[   15.266167] Call Trace:
[   15.266168]  &amp;lt;TASK&amp;gt;
[   15.266169]  dump_stack_lvl+0x53/0x70
[   15.266173]  print_report+0xd0/0x660
[   15.266181]  kasan_report+0xce/0x100
[   15.266185]  hfsplus_bmap_alloc+0x887/0x8b0
[   15.266208]  hfs_btree_inc_height.isra.0+0xd5/0x7c0
[   15.266217]  hfsplus_brec_insert+0x870/0xb00
[   15.266222]  __hfsplus_ext_write_extent+…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-2754"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10703-1</id>
    <title>openSUSE-SU-2026:10703-1 — kernel-devel-7.0.3-1.1 on GA media</title>
    <updated>2026-10-04T12:12:01.353245+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>kernel-devel-7.0.3-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:10703-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:22043-1</id>
    <title>SUSE-SU-2026:22043-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-04T12:12:01.353300+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:22043-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-31580</id>
    <title>UBUNTU-CVE-2026-31580</title>
    <updated>2026-10-04T12:12:01.353345+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: linux, Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe and 244 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: bcache: fix cached_dev.sb_bio use-after-free and crash In our production environment, we have received multiple crash reports regarding libceph, which have caught our attention: ``` [6888366.280350] Call Trace: [6888366.280452]  blk_update_request+0x14e/0x370 [6888366.280561]  blk_mq_end_request+0x1a/0x130 [6888366.280671]  rbd_img_handle_request+0x1a0/0x1b0 [rbd] [6888366.280792]  rbd_obj_handle_request+0x32/0x40 [rbd] [6888366.280903]  __complete_request+0x22/0x70 [libceph] [6888366.281032]  osd_dispatch+0x15e/0xb40 [libceph] [6888366.281164]  ? inet_recvmsg+0x5b/0xd0 [6888366.281272]  ? ceph_tcp_recvmsg+0x6f/0xa0 [libceph] [6888366.281405]  ceph_con_process_message+0x79/0x140 [libceph] [6888366.281534]  ceph_con_v1_try_read+0x5d7/0xf30 [libceph] [6888366.281661]  ceph_con_workfn+0x329/0x680 [libceph] ``` After analyzing the coredump file, we found that the address of dc-&gt;sb_bio has been freed. We know that cached_dev is only freed when it is stopped. Since sb_bio is a part of struct cached_dev, rather than an alloc every time.  If the device is stopped while writing to the superblock, the released address will be accessed at endio. This patch hopes to wait for sb_write to complete in cached_dev_free. It should be noted that we analyzed the cause of the problem, then tell all details to the QWEN and adopted the modifications it made.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-31580"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1279</id>
    <title>WID-SEC-W-2026-1279 — Linux Kernel: Mehrere Schwachstellen</title>
    <updated>2026-10-04T12:12:01.353681+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um nicht näher spezifizierte Angriffe durchzuführen, welche zu einem Denial-of-Service-Zustand, einer Rechteausweitung, der Ausführung von Code oder einer Speicherbeschädigung führen könnten.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1279"/>
  </entry>
</feed>
