<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T04:32:31.233048+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:21557</id>
    <title>ALSA-2026:21557 — Important: kernel security update</title>
    <updated>2026-10-03T04:32:31.363309+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:10: kernel, AlmaLinux:10: kernel-64k, AlmaLinux:10: kernel-64k-core, AlmaLinux:10: kernel-64k-debug, AlmaLinux:10: kernel-64k-debug-core, AlmaLinux:10: kernel-64k-debug-devel, AlmaLinux:10: kernel-64k-debug-devel-matched, AlmaLinux:10: kernel-64k-debug-modules, AlmaLinux:10: kernel-64k-debug-modules-core, AlmaLinux:10: kernel-64k-debug-modules-extra and 65 more</p>
<p>The kernel packages contain the Linux kernel, the core of any Linux operating system.</p>
<p>Security Fix(es):</p>
<p>* kernel: can: j1939: j1939_session_new(): fix skb reference counting (CVE-2024-56645)
  * kernel: ima: don't clear IMA_DIGSIG flag when setting or removing non-IMA xattr (CVE-2025-68183)
  * kernel: mm: thp: deny THP for files on anonymous inodes (CVE-2026-23375)
  * kernel: netfilter: nf_tables: release flowtable after rcu grace period on error (CVE-2026-23392)
  * kernel: netfilter: nf_conntrack_h323: check for zero length in DecodeQ931() (CVE-2026-23455)
  * kernel: net: sched: act_csum: validate nested VLAN headers (CVE-2026-31684)
  * kernel: netfilter: ip6t_eui64: reject invalid MAC header for all packets (CVE-2026-31685)
  * kernel: netfilter: nf_conntrack_helper: pass helper to expect cleanup (CVE-2026-43027)
  * kernel: io_uring/rsrc: reject zero-length fixed buffer import (CVE-2026-43006)
  * kernel: Bluetooth: MGMT: validate LTK enc_size on load (CVE-2026-43020)
  * kernel: HID: wacom: fix out-of-bounds read in wacom_intuos_bt_irq (CVE-2026-43051)
  * kernel: Bluetooth: SCO: fix race conditions in sco_sock_connect() (CVE-2026-43023)
  * kernel: netfilter: ctnetlink: ensure safe access to master conntrack (CVE-2026-43116)
  * kernel: wifi: brcmfmac: validate bsscfg indices in IF events (CVE-2026-43110)
  * kernel: netfilter: xt_tcpmss: check remaining length before reading optlen (CVE-2026-43190)
  * kernel: Linux kernel dpaa2-switch: Kernel memory corru…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:21557"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-43006</id>
    <title>BELL-CVE-2026-43006</title>
    <updated>2026-10-03T04:32:31.363535+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:stream: linux-lts</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-43006"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2026-20417</id>
    <title>cnvd-2026-20417</title>
    <updated>2026-10-03T04:32:31.363571+00:00</updated>
    <content>cnvd-2026-20417</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2026-20417"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-347799</id>
    <title>EUVD-2026-347799</title>
    <updated>2026-10-03T04:32:31.363595+00:00</updated>
    <content>EUVD-2026-347799</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-347799"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-43006</id>
    <title>fkie_cve-2026-43006</title>
    <updated>2026-10-03T04:32:31.363617+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>io_uring/rsrc: reject zero-length fixed buffer import</p>
<p>validate_fixed_range() admits buf_addr at the exact end of the
registered region when len is zero, because the check uses strict
greater-than (buf_end &gt; imu-&gt;ubuf + imu-&gt;len).  io_import_fixed()
then computes offset == imu-&gt;len, which causes the bvec skip logic
to advance past the last bio_vec entry and read bv_offset from
out-of-bounds slab memory.</p>
<p>Return early from io_import_fixed() when len is zero.  A zero-length
import has no data to transfer and should not walk the bvec array
at all.</p>
<p>BUG: KASAN: slab-out-of-bounds in io_import_reg_buf+0x697/0x7f0
  Read of size 4 at addr ffff888002bcc254 by task poc/103
  Call Trace:
   io_import_reg_buf+0x697/0x7f0
   io_write_fixed+0xd9/0x250
   __io_issue_sqe+0xad/0x710
   io_issue_sqe+0x7d/0x1100
   io_submit_sqes+0x86a/0x23c0
   __do_sys_io_uring_enter+0xa98/0x1590
  Allocated by task 103:
  The buggy address is located 12 bytes to the right of
   allocated 584-byte region [ffff888002bcc000, ffff888002bcc248)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-43006"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-5mwr-6pqp-c5qm</id>
    <title>GHSA-5mwr-6pqp-c5qm</title>
    <updated>2026-10-03T04:32:31.363674+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>io_uring/rsrc: reject zero-length fixed buffer import</p>
<p>validate_fixed_range() admits buf_addr at the exact end of the
registered region when len is zero, because the check uses strict
greater-than (buf_end &gt; imu-&gt;ubuf + imu-&gt;len).  io_import_fixed()
then computes offset == imu-&gt;len, which causes the bvec skip logic
to advance past the last bio_vec entry and read bv_offset from
out-of-bounds slab memory.</p>
<p>Return early from io_import_fixed() when len is zero.  A zero-length
import has no data to transfer and should not walk the bvec array
at all.</p>
<p>BUG: KASAN: slab-out-of-bounds in io_import_reg_buf+0x697/0x7f0
  Read of size 4 at addr ffff888002bcc254 by task poc/103
  Call Trace:
   io_import_reg_buf+0x697/0x7f0
   io_write_fixed+0xd9/0x250
   __io_issue_sqe+0xad/0x710
   io_issue_sqe+0x7d/0x1100
   io_submit_sqes+0x86a/0x23c0
   __do_sys_io_uring_enter+0xa98/0x1590
  Allocated by task 103:
  The buggy address is located 12 bytes to the right of
   allocated 584-byte region [ffff888002bcc000, ffff888002bcc248)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-5mwr-6pqp-c5qm"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:21557</id>
    <title>RHSA-2026:21557 — Red Hat Security Advisory: kernel security update</title>
    <updated>2026-10-03T04:32:31.363742+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>kernel: can: j1939: j1939_session_new(): fix skb reference counting kernel: ima: don't clear IMA_DIGSIG flag when setting or removing non-IMA xattr kernel: mm: thp: deny THP for files on anonymous inodes kernel: netfilter: nf_tables: release flowtable after rcu grace period on error kernel: netfilter: nf_conntrack_h323: check for zero length in DecodeQ931() kernel: net: sched: act_csum: validate nested VLAN headers kernel: netfilter: ip6t_eui64: reject invalid MAC header for all packets kernel: io_uring/rsrc: reject zero-length fixed buffer import kernel: Bluetooth: MGMT: validate LTK enc_size on load kernel: Bluetooth: SCO: fix race conditions in sco_sock_connect() kernel: netfilter: nf_conntrack_helper: pass helper to expect cleanup kernel: HID: wacom: fix out-of-bounds read in wacom_intuos_bt_irq kernel: wifi: brcmfmac: validate bsscfg indices in IF events kernel: netfilter: ctnetlink: ensure safe access to master conntrack kernel: xfs: fix freemap adjustments when adding xattrs to leaf blocks kernel: netfilter: xt_tcpmss: check remaining length before reading optlen kernel: Linux kernel dpaa2-switch: Kernel memory corruption via out-of-bounds write kernel: mm/page_alloc: clear page-&gt;private in free_pages_prepare()</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:21557"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:21557</id>
    <title>RLSA-2026:21557 — Important: kernel security update</title>
    <updated>2026-10-03T04:32:31.363826+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:10: kernel</p>
<p>The kernel packages contain the Linux kernel, the core of any Linux operating system.</p>
<p>Security Fix(es):</p>
<p>* kernel: can: j1939: j1939_session_new(): fix skb reference counting (CVE-2024-56645)</p>
<p>* kernel: ima: don't clear IMA_DIGSIG flag when setting or removing non-IMA xattr (CVE-2025-68183)</p>
<p>* kernel: mm: thp: deny THP for files on anonymous inodes (CVE-2026-23375)</p>
<p>* kernel: netfilter: nf_tables: release flowtable after rcu grace period on error (CVE-2026-23392)</p>
<p>* kernel: netfilter: nf_conntrack_h323: check for zero length in DecodeQ931() (CVE-2026-23455)</p>
<p>* kernel: net: sched: act_csum: validate nested VLAN headers (CVE-2026-31684)</p>
<p>* kernel: netfilter: ip6t_eui64: reject invalid MAC header for all packets (CVE-2026-31685)</p>
<p>* kernel: netfilter: nf_conntrack_helper: pass helper to expect cleanup (CVE-2026-43027)</p>
<p>* kernel: io_uring/rsrc: reject zero-length fixed buffer import (CVE-2026-43006)</p>
<p>* kernel: Bluetooth: MGMT: validate LTK enc_size on load (CVE-2026-43020)</p>
<p>* kernel: HID: wacom: fix out-of-bounds read in wacom_intuos_bt_irq (CVE-2026-43051)</p>
<p>* kernel: Bluetooth: SCO: fix race conditions in sco_sock_connect() (CVE-2026-43023)</p>
<p>* kernel: netfilter: ctnetlink: ensure safe access to master conntrack (CVE-2026-43116)</p>
<p>* kernel: wifi: brcmfmac: validate bsscfg indices in IF events (CVE-2026-43110)</p>
<p>* kernel: netfilter: xt_tcpmss: check remaining length before reading optlen (CVE-2026-43190)</p>
<p>* kernel: Linux kernel dpaa2-switch: Kernel memory corruption via out-of-boun…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:21557"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-43006</id>
    <title>UBUNTU-CVE-2026-43006</title>
    <updated>2026-10-03T04:32:31.363911+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 104 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: io_uring/rsrc: reject zero-length fixed buffer import validate_fixed_range() admits buf_addr at the exact end of the registered region when len is zero, because the check uses strict greater-than (buf_end &gt; imu-&gt;ubuf + imu-&gt;len).  io_import_fixed() then computes offset == imu-&gt;len, which causes the bvec skip logic to advance past the last bio_vec entry and read bv_offset from out-of-bounds slab memory. Return early from io_import_fixed() when len is zero.  A zero-length import has no data to transfer and should not walk the bvec array at all.   BUG: KASAN: slab-out-of-bounds in io_import_reg_buf+0x697/0x7f0   Read of size 4 at addr ffff888002bcc254 by task poc/103   Call Trace:    io_import_reg_buf+0x697/0x7f0    io_write_fixed+0xd9/0x250    __io_issue_sqe+0xad/0x710    io_issue_sqe+0x7d/0x1100    io_submit_sqes+0x86a/0x23c0    __do_sys_io_uring_enter+0xa98/0x1590   Allocated by task 103:   The buggy address is located 12 bytes to the right of    allocated 584-byte region [ffff888002bcc000, ffff888002bcc248)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-43006"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1346</id>
    <title>WID-SEC-W-2026-1346 — Linux Kernel: Mehrere Schwachstellen</title>
    <updated>2026-10-03T04:32:31.364204+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um Root-Rechte zu erlangen, um Sicherheitsmechanismen zu umgehen, einen Denial-of-Service-Zustand herbeizuführen oder Auswirkungen unbestimmter Art zu erzielen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1346"/>
  </entry>
</feed>
