<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T00:37:05.300702+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:21556</id>
    <title>ALSA-2026:21556 — Important: kernel security update</title>
    <updated>2026-10-04T00:37:05.822593+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:9: kernel, AlmaLinux:9: kernel-64k, AlmaLinux:9: kernel-64k-core, AlmaLinux:9: kernel-64k-debug, AlmaLinux:9: kernel-64k-debug-core, AlmaLinux:9: kernel-64k-debug-devel, AlmaLinux:9: kernel-64k-debug-devel-matched, AlmaLinux:9: kernel-64k-debug-modules, AlmaLinux:9: kernel-64k-debug-modules-core, AlmaLinux:9: kernel-64k-debug-modules-extra and 64 more</p>
<p>The kernel packages contain the Linux kernel, the core of any Linux operating system.</p>
<p>Security Fix(es):</p>
<p>* kernel: proc: use the same treatment to check proc_lseek as ones for proc_read_iter et.al (CVE-2025-38653)
  * kernel: ima: don't clear IMA_DIGSIG flag when setting or removing non-IMA xattr (CVE-2025-68183)
  * kernel: nbd: defer config unlock in nbd_genl_connect (CVE-2025-68366)
  * kernel: crypto: asymmetric_keys - prevent overflow in asymmetric_key_generate_id (CVE-2025-68724)
  * kernel: iommu: disable SVA when CONFIG_X86 is set (CVE-2025-71089)
  * kernel: netfilter: nf_tables: release flowtable after rcu grace period on error (CVE-2026-23392)
  * kernel: netfilter: nf_conntrack_h323: check for zero length in DecodeQ931() (CVE-2026-23455)
  * kernel: Bluetooth: SCO: Fix use-after-free in sco_recv_frame() due to missing sock_hold (CVE-2026-31408)
  * kernel: net: sched: act_csum: validate nested VLAN headers (CVE-2026-31684)
  * kernel: netfilter: ip6t_eui64: reject invalid MAC header for all packets (CVE-2026-31685)
  * kernel: netfilter: nf_conntrack_helper: pass helper to expect cleanup (CVE-2026-43027)
  * kernel: Bluetooth: MGMT: validate LTK enc_size on load (CVE-2026-43020)
  * kernel: HID: wacom: fix out-of-bounds read in wacom_intuos_bt_irq (CVE-2026-43051)
  * kernel: smb: client: validate the whole DACL before rewriting it in cifsacl (CVE-2026-31709)
  * kernel: Bluetooth: SCO: fix race conditions in sco_sock_connect() (CVE-2026-43023)
  * kernel:…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:21556"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-10723</id>
    <title>bdu:2026-10723</title>
    <updated>2026-10-04T00:37:05.822793+00:00</updated>
    <content>bdu:2026-10723</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-10723"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-31684</id>
    <title>BELL-CVE-2026-31684</title>
    <updated>2026-10-04T00:37:05.822816+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-31684"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0526</id>
    <title>certfr-2026-avi-0526 — De multiples vulnérabilités ont été découvertes dans les produits Microsoft. Elles permettent à un attaquant de provoqu…</title>
    <updated>2026-10-04T00:37:05.822839+00:00</updated>
    <content>certfr-2026-avi-0526</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0526"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/essa-2026:0162</id>
    <title>ESSA-2026:0162 — Important: kernel security, bug fix, and enhancement update</title>
    <updated>2026-10-04T00:37:05.822856+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Important: kernel security, bug fix, and enhancement update</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/essa-2026:0162"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-323494</id>
    <title>EUVD-2026-323494</title>
    <updated>2026-10-04T00:37:05.822882+00:00</updated>
    <content>EUVD-2026-323494</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-323494"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-31684</id>
    <title>fkie_cve-2026-31684</title>
    <updated>2026-10-04T00:37:05.822894+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>net: sched: act_csum: validate nested VLAN headers</p>
<p>tcf_csum_act() walks nested VLAN headers directly from skb-&gt;data when an
skb still carries in-payload VLAN tags. The current code reads
vlan-&gt;h_vlan_encapsulated_proto and then pulls VLAN_HLEN bytes without
first ensuring that the full VLAN header is present in the linear area.</p>
<p>If only part of an inner VLAN header is linearized, accessing
h_vlan_encapsulated_proto reads past the linear area, and the following
skb_pull(VLAN_HLEN) may violate skb invariants.</p>
<p>Fix this by requiring pskb_may_pull(skb, VLAN_HLEN) before accessing and
pulling each nested VLAN header. If the header still is not fully
available, drop the packet through the existing error path.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-31684"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-gj33-f2q3-mjhg</id>
    <title>GHSA-gj33-f2q3-mjhg</title>
    <updated>2026-10-04T00:37:05.822924+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>net: sched: act_csum: validate nested VLAN headers</p>
<p>tcf_csum_act() walks nested VLAN headers directly from skb-&gt;data when an
skb still carries in-payload VLAN tags. The current code reads
vlan-&gt;h_vlan_encapsulated_proto and then pulls VLAN_HLEN bytes without
first ensuring that the full VLAN header is present in the linear area.</p>
<p>If only part of an inner VLAN header is linearized, accessing
h_vlan_encapsulated_proto reads past the linear area, and the following
skb_pull(VLAN_HLEN) may violate skb invariants.</p>
<p>Fix this by requiring pskb_may_pull(skb, VLAN_HLEN) before accessing and
pulling each nested VLAN header. If the header still is not fully
available, drop the packet through the existing error path.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-gj33-f2q3-mjhg"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-31684</id>
    <title>msrc_CVE-2026-31684 — net: sched: act_csum: validate nested VLAN headers</title>
    <updated>2026-10-04T00:37:05.822945+00:00</updated>
    <content>msrc_CVE-2026-31684</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-31684"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-2581</id>
    <title>OESA-2026-2581 — kernel security update</title>
    <updated>2026-10-04T00:37:05.822961+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS-SP1: kernel</p>
<p>The Linux Kernel, the operating system core itself.

Security Fix(es):</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>net: mvpp2: Prevent parser TCAM memory corruption</p>
<p>Protect the parser TCAM/SRAM memory, and the cached (shadow) SRAM
information, from concurrent modifications.</p>
<p>Both the TCAM and SRAM tables are indirectly accessed by configuring
an index register that selects the row to read or write to. This means
that operations must be atomic in order to, e.g., avoid spreading
writes across multiple rows. Since the shadow SRAM array is used to
find free rows in the hardware table, it must also be protected in
order to avoid TOCTOU errors where multiple cores allocate the same
row.</p>
<p>This issue was detected in a situation where `mvpp2_set_rx_mode()` ran
concurrently on two CPUs. In this particular case the
MVPP2_PE_MAC_UC_PROMISCUOUS entry was corrupted, causing the
classifier unit to drop all incoming unicast - indicated by the
`rx_classifier_drops` counter.(CVE-2025-22060)</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>mptcp: fix NULL pointer in can_accept_new_subflow</p>
<p>When testing valkey benchmark tool with MPTCP, the kernel panics in
&amp;apos;mptcp_can_accept_new_subflow&amp;apos; because subflow_req-&amp;gt;msk is NULL.</p>
<p>Call trace:</p>
<p>mptcp_can_accept_new_subflow (./net/mptcp/subflow.c:63 (discriminator 4)) (P)
  subflow_syn_recv_sock (./net/mptcp/subflow.c:854)
  tcp_check_req (./net/ipv4/tcp_minisocks.c:863)
  tcp_v4_rcv (./net/…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-2581"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:21745</id>
    <title>RHSA-2026:21745 — Red Hat Security Advisory: kernel-rt security update</title>
    <updated>2026-10-04T00:37:05.823432+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>kernel: Bluetooth: MGMT: Fix possible UAFs kernel: ima: don't clear IMA_DIGSIG flag when setting or removing non-IMA xattr kernel: ALSA: firewire-motu: fix buffer overflow in hwdep read for DSP events kernel: libceph: make decode_pool() more resilient against corrupted osdmaps kernel: Linux kernel: Denial of service and memory corruption in RDMA umad kernel: Linux kernel: Use-after-free in traffic control (act_ct) may lead to denial of service or privilege escalation kernel: netfilter: nf_conntrack_h323: check for zero length in DecodeQ931() kernel: Bluetooth: SCO: Fix use-after-free in sco_recv_frame() due to missing sock_hold kernel: can: raw: fix ro-&gt;uniq use-after-free in raw_rcv() kernel: net: sched: act_csum: validate nested VLAN headers kernel: netfilter: ip6t_eui64: reject invalid MAC header for all packets kernel: smb: client: validate the whole DACL before rewriting it in cifsacl kernel: Bluetooth: MGMT: validate LTK enc_size on load kernel: netfilter: nf_conntrack_helper: pass helper to expect cleanup kernel: HID: wacom: fix out-of-bounds read in wacom_intuos_bt_irq kernel: xfs: fix freemap adjustments when adding xattrs to leaf blocks kernel: md/bitmap: fix GPF in write_page caused by resize race kernel: netfilter: xt_tcpmss: check remaining length before reading optlen kernel: smb: client: validate dacloffset before building DACL pointers</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:21745"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:21556</id>
    <title>RLSA-2026:21556 — Important: kernel security update</title>
    <updated>2026-10-04T00:37:05.823486+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:9: kernel</p>
<p>The kernel packages contain the Linux kernel, the core of any Linux operating system.</p>
<p>Security Fix(es):</p>
<p>* kernel: proc: use the same treatment to check proc_lseek as ones for proc_read_iter et.al (CVE-2025-38653)</p>
<p>* kernel: ima: don't clear IMA_DIGSIG flag when setting or removing non-IMA xattr (CVE-2025-68183)</p>
<p>* kernel: nbd: defer config unlock in nbd_genl_connect (CVE-2025-68366)</p>
<p>* kernel: crypto: asymmetric_keys - prevent overflow in asymmetric_key_generate_id (CVE-2025-68724)</p>
<p>* kernel: iommu: disable SVA when CONFIG_X86 is set (CVE-2025-71089)</p>
<p>* kernel: netfilter: nf_tables: release flowtable after rcu grace period on error (CVE-2026-23392)</p>
<p>* kernel: netfilter: nf_conntrack_h323: check for zero length in DecodeQ931() (CVE-2026-23455)</p>
<p>* kernel: Bluetooth: SCO: Fix use-after-free in sco_recv_frame() due to missing sock_hold (CVE-2026-31408)</p>
<p>* kernel: net: sched: act_csum: validate nested VLAN headers (CVE-2026-31684)</p>
<p>* kernel: netfilter: ip6t_eui64: reject invalid MAC header for all packets (CVE-2026-31685)</p>
<p>* kernel: netfilter: nf_conntrack_helper: pass helper to expect cleanup (CVE-2026-43027)</p>
<p>* kernel: Bluetooth: MGMT: validate LTK enc_size on load (CVE-2026-43020)</p>
<p>* kernel: HID: wacom: fix out-of-bounds read in wacom_intuos_bt_irq (CVE-2026-43051)</p>
<p>* kernel: smb: client: validate the whole DACL before rewriting it in cifsacl (CVE-2026-31709)</p>
<p>* kernel: Bluetooth: SCO: fix race conditions in sco_sock_connect() (CVE-2026-43023)</p>
<p>* kernel: wifi: brcmfmac: vali…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:21556"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:21834-1</id>
    <title>SUSE-SU-2026:21834-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-04T00:37:05.823531+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:21834-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-31684</id>
    <title>UBUNTU-CVE-2026-31684</title>
    <updated>2026-10-04T00:37:05.823666+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:Pro:18.04:LTS: linux-aws-5.4, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:Pro:18.04:LTS: linux-azure-5.4, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3 and 206 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: net: sched: act_csum: validate nested VLAN headers tcf_csum_act() walks nested VLAN headers directly from skb-&gt;data when an skb still carries in-payload VLAN tags. The current code reads vlan-&gt;h_vlan_encapsulated_proto and then pulls VLAN_HLEN bytes without first ensuring that the full VLAN header is present in the linear area. If only part of an inner VLAN header is linearized, accessing h_vlan_encapsulated_proto reads past the linear area, and the following skb_pull(VLAN_HLEN) may violate skb invariants. Fix this by requiring pskb_may_pull(skb, VLAN_HLEN) before accessing and pulling each nested VLAN header. If the header still is not fully available, drop the packet through the existing error path.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-31684"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1279</id>
    <title>WID-SEC-W-2026-1279 — Linux Kernel: Mehrere Schwachstellen</title>
    <updated>2026-10-04T00:37:05.823905+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um nicht näher spezifizierte Angriffe durchzuführen, welche zu einem Denial-of-Service-Zustand, einer Rechteausweitung, der Ausführung von Code oder einer Speicherbeschädigung führen könnten.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1279"/>
  </entry>
</feed>
