<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T14:26:18.039943+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:25120</id>
    <title>ALSA-2026:25120 — Critical: kernel-rt security update</title>
    <updated>2026-10-02T14:26:20.127096+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: kernel-rt, AlmaLinux:8: kernel-rt-core, AlmaLinux:8: kernel-rt-debug, AlmaLinux:8: kernel-rt-debug-core, AlmaLinux:8: kernel-rt-debug-devel, AlmaLinux:8: kernel-rt-debug-modules, AlmaLinux:8: kernel-rt-debug-modules-extra, AlmaLinux:8: kernel-rt-devel, AlmaLinux:8: kernel-rt-modules, AlmaLinux:8: kernel-rt-modules-extra</p>
<p>The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements.</p>
<p>Security Fix(es):</p>
<p>* kernel: geneve: Fix use-after-free in geneve_find_dev(). (CVE-2025-21858)
  * kernel: smc: Fix use-after-free in tcp_write_timer_handler() (CVE-2023-53781)
  * kernel: nbd: defer config unlock in nbd_genl_connect (CVE-2025-68366)
  * kernel: libceph: prevent potential out-of-bounds reads in handle_auth_done() (CVE-2026-22984)
  * kernel: libceph: replace overzealous BUG_ON in osdmap_apply_incremental() (CVE-2026-22990)
  * kernel: netfilter: nf_tables: release flowtable after rcu grace period on error (CVE-2026-23392)
  * kernel: ALSA: 6fire: fix use-after-free on disconnect (CVE-2026-31581)
  * kernel: smb: client: fix OOB reads parsing symlink error response (CVE-2026-31613)
  * kernel: ip6_tunnel: clear skb2-&gt;cb[] in ip4ip6_err() (CVE-2026-43037)
  * kernel: ipv6: icmp: clear skb2-&gt;cb[] in ip6_err_gen_icmpv6_unreach() (CVE-2026-43038)
  * kernel: dlm: validate length in dlm_search_rsb_tree (CVE-2026-43125)
  * kernel: RDMA/rxe: Fix double free in rxe_srq_from_init (CVE-2026-45852)
  * kernel: RDMA/mlx4: Fix mis-use of RCU in mlx4_srq_event() (CVE-2026-46181)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:25120"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-08754</id>
    <title>bdu:2026-08754</title>
    <updated>2026-10-02T14:26:20.127231+00:00</updated>
    <content>bdu:2026-08754</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-08754"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-43038</id>
    <title>BELL-CVE-2026-43038</title>
    <updated>2026-10-02T14:26:20.127264+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-43038"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0547</id>
    <title>certfr-2026-avi-0547 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de Debian LTS. Certaines d'entre elles permettent à…</title>
    <updated>2026-10-02T14:26:20.127301+00:00</updated>
    <content>certfr-2026-avi-0547</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0547"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-364793</id>
    <title>EUVD-2026-364793</title>
    <updated>2026-10-02T14:26:20.127328+00:00</updated>
    <content>EUVD-2026-364793</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-364793"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-43038</id>
    <title>fkie_cve-2026-43038</title>
    <updated>2026-10-02T14:26:20.127347+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>ipv6: icmp: clear skb2-&gt;cb[] in ip6_err_gen_icmpv6_unreach()</p>
<p>Sashiko AI-review observed:</p>
<p>In ip6_err_gen_icmpv6_unreach(), the skb is an outer IPv4 ICMP error packet
  where its cb contains an IPv4 inet_skb_parm. When skb is cloned into skb2
  and passed to icmp6_send(), it uses IP6CB(skb2).</p>
<p>IP6CB interprets the IPv4 inet_skb_parm as an inet6_skb_parm. The cipso
  offset in inet_skb_parm.opt directly overlaps with dsthao in inet6_skb_parm
  at offset 18.</p>
<p>If an attacker sends a forged ICMPv4 error with a CIPSO IP option, dsthao
  would be a non-zero offset. Inside icmp6_send(), mip6_addr_swap() is called
  and uses ipv6_find_tlv(skb, opt-&gt;dsthao, IPV6_TLV_HAO).</p>
<p>This would scan the inner, attacker-controlled IPv6 packet starting at that
  offset, potentially returning a fake TLV without checking if the remaining
  packet length can hold the full 18-byte struct ipv6_destopt_hao.</p>
<p>Could mip6_addr_swap() then perform a 16-byte swap that extends past the end
  of the packet data into skb_shared_info?</p>
<p>Should the cb array also be cleared in ip6_err_gen_icmpv6_unreach() and
  ip6ip6_err() to prevent this?</p>
<p>This patch implements the first suggestion.</p>
<p>I am not sure if ip6ip6_err() needs to be changed.
A separate patch would be better anyway.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-43038"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-78m7-4xgc-xrrq</id>
    <title>GHSA-78m7-4xgc-xrrq</title>
    <updated>2026-10-02T14:26:20.127405+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>ipv6: icmp: clear skb2-&gt;cb[] in ip6_err_gen_icmpv6_unreach()</p>
<p>Sashiko AI-review observed:</p>
<p>In ip6_err_gen_icmpv6_unreach(), the skb is an outer IPv4 ICMP error packet
  where its cb contains an IPv4 inet_skb_parm. When skb is cloned into skb2
  and passed to icmp6_send(), it uses IP6CB(skb2).</p>
<p>IP6CB interprets the IPv4 inet_skb_parm as an inet6_skb_parm. The cipso
  offset in inet_skb_parm.opt directly overlaps with dsthao in inet6_skb_parm
  at offset 18.</p>
<p>If an attacker sends a forged ICMPv4 error with a CIPSO IP option, dsthao
  would be a non-zero offset. Inside icmp6_send(), mip6_addr_swap() is called
  and uses ipv6_find_tlv(skb, opt-&gt;dsthao, IPV6_TLV_HAO).</p>
<p>This would scan the inner, attacker-controlled IPv6 packet starting at that
  offset, potentially returning a fake TLV without checking if the remaining
  packet length can hold the full 18-byte struct ipv6_destopt_hao.</p>
<p>Could mip6_addr_swap() then perform a 16-byte swap that extends past the end
  of the packet data into skb_shared_info?</p>
<p>Should the cb array also be cleared in ip6_err_gen_icmpv6_unreach() and
  ip6ip6_err() to prevent this?</p>
<p>This patch implements the first suggestion.</p>
<p>I am not sure if ip6ip6_err() needs to be changed.
A separate patch would be better anyway.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-78m7-4xgc-xrrq"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-26-209-04</id>
    <title>ICSA-26-209-04 — Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</title>
    <updated>2026-10-02T14:26:20.127436+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.6 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant).</p>
<p>Siemens is preparing fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-26-209-04"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-2579</id>
    <title>OESA-2026-2579 — kernel security update</title>
    <updated>2026-10-02T14:26:20.127595+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP4: kernel</p>
<p>The Linux Kernel, the operating system core itself.

Security Fix(es):</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>bcache: fix NULL pointer in cache_set_flush()</p>
<p>1. LINE#1794 - LINE#1887 is some codes about function of
   bch_cache_set_alloc().
2. LINE#2078 - LINE#2142 is some codes about function of
   register_cache_set().
3. register_cache_set() will call bch_cache_set_alloc() in LINE#2098.</p>
<p>1794 struct cache_set *bch_cache_set_alloc(struct cache_sb *sb)
 1795 {
 ...
 1860         if (!(c-&amp;gt;devices = kcalloc(c-&amp;gt;nr_uuids, sizeof(void *), GFP_KERNEL)) ||
 1861             mempool_init_slab_pool(&amp;amp;c-&amp;gt;search, 32, bch_search_cache) ||
 1862             mempool_init_kmalloc_pool(&amp;amp;c-&amp;gt;bio_meta, 2,
 1863                                 sizeof(struct bbio) + sizeof(struct bio_vec) *
 1864                                 bucket_pages(c)) ||
 1865             mempool_init_kmalloc_pool(&amp;amp;c-&amp;gt;fill_iter, 1, iter_size) ||
 1866             bioset_init(&amp;amp;c-&amp;gt;bio_split, 4, offsetof(struct bbio, bio),
 1867                         BIOSET_NEED_BVECS|BIOSET_NEED_RESCUER) ||
 1868             !(c-&amp;gt;uuids = alloc_bucket_pages(GFP_KERNEL, c)) ||
 1869             !(c-&amp;gt;moving_gc_wq = alloc_workqueue(&amp;quot;bcache_gc&amp;quot;,
 1870                                                 WQ_MEM_RECLAIM, 0)) ||
 1871             bch_journal_alloc(c) ||
 1872             bch_btree_cache_alloc(c) ||
 1873             bch_open_buckets_alloc(c) ||
 1874…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-2579"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:20826-1</id>
    <title>openSUSE-SU-2026:20826-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-02T14:26:20.127800+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:20826-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:22900</id>
    <title>RHSA-2026:22900 — Red Hat Security Advisory: kernel-rt security update</title>
    <updated>2026-10-02T14:26:20.127913+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>kernel: net/sched: Make cake_enqueue return NET_XMIT_CN when past buffer_limit kernel: Linux kernel: Use-after-free in traffic control (act_ct) may lead to denial of service or privilege escalation kernel: Linux kernel: Use-after-free in bonding driver leads to denial of service kernel: smb: client: validate the whole DACL before rewriting it in cifsacl kernel: ip6_tunnel: clear skb2-&gt;cb[] in ip4ip6_err() kernel: ipv6: icmp: clear skb2-&gt;cb[] in ip6_err_gen_icmpv6_unreach() kernel: md/bitmap: fix GPF in write_page caused by resize race</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:22900"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:25120</id>
    <title>RLSA-2026:25120 — Critical: kernel-rt security update</title>
    <updated>2026-10-02T14:26:20.127939+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:8: kernel-rt</p>
<p>The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements.</p>
<p>Security Fix(es):</p>
<p>* kernel: geneve: Fix use-after-free in geneve_find_dev(). (CVE-2025-21858)</p>
<p>* kernel: smc: Fix use-after-free in tcp_write_timer_handler() (CVE-2023-53781)</p>
<p>* kernel: nbd: defer config unlock in nbd_genl_connect (CVE-2025-68366)</p>
<p>* kernel: libceph: prevent potential out-of-bounds reads in handle_auth_done() (CVE-2026-22984)</p>
<p>* kernel: libceph: replace overzealous BUG_ON in osdmap_apply_incremental() (CVE-2026-22990)</p>
<p>* kernel: netfilter: nf_tables: release flowtable after rcu grace period on error (CVE-2026-23392)</p>
<p>* kernel: ALSA: 6fire: fix use-after-free on disconnect (CVE-2026-31581)</p>
<p>* kernel: smb: client: fix OOB reads parsing symlink error response (CVE-2026-31613)</p>
<p>* kernel: ip6_tunnel: clear skb2-&gt;cb[] in ip4ip6_err() (CVE-2026-43037)</p>
<p>* kernel: ipv6: icmp: clear skb2-&gt;cb[] in ip6_err_gen_icmpv6_unreach() (CVE-2026-43038)</p>
<p>* kernel: dlm: validate length in dlm_search_rsb_tree (CVE-2026-43125)</p>
<p>* kernel: RDMA/rxe: Fix double free in rxe_srq_from_init (CVE-2026-45852)</p>
<p>* kernel: RDMA/mlx4: Fix mis-use of RCU in mlx4_srq_event() (CVE-2026-46181)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:25120"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ssa-019113</id>
    <title>SSA-019113 — SSA-019113: Vulnerabilities in the additional GNU/Linux subsystem of the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1.6</title>
    <updated>2026-10-02T14:26:20.127976+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.6 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant).</p>
<p>Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ssa-019113"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:21834-1</id>
    <title>SUSE-SU-2026:21834-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-02T14:26:20.128126+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:21834-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-43038</id>
    <title>UBUNTU-CVE-2026-43038</title>
    <updated>2026-10-02T14:26:20.128240+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: linux, Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe and 233 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: ipv6: icmp: clear skb2-&gt;cb[] in ip6_err_gen_icmpv6_unreach() Sashiko AI-review observed:   In ip6_err_gen_icmpv6_unreach(), the skb is an outer IPv4 ICMP error packet   where its cb contains an IPv4 inet_skb_parm. When skb is cloned into skb2   and passed to icmp6_send(), it uses IP6CB(skb2).   IP6CB interprets the IPv4 inet_skb_parm as an inet6_skb_parm. The cipso   offset in inet_skb_parm.opt directly overlaps with dsthao in inet6_skb_parm   at offset 18.   If an attacker sends a forged ICMPv4 error with a CIPSO IP option, dsthao   would be a non-zero offset. Inside icmp6_send(), mip6_addr_swap() is called   and uses ipv6_find_tlv(skb, opt-&gt;dsthao, IPV6_TLV_HAO).   This would scan the inner, attacker-controlled IPv6 packet starting at that   offset, potentially returning a fake TLV without checking if the remaining   packet length can hold the full 18-byte struct ipv6_destopt_hao.   Could mip6_addr_swap() then perform a 16-byte swap that extends past the end   of the packet data into skb_shared_info?   Should the cb array also be cleared in ip6_err_gen_icmpv6_unreach() and   ip6ip6_err() to prevent this? This patch implements the first suggestion. I am not sure if ip6ip6_err() needs to be changed. A separate patch would be better anyway.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-43038"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1346</id>
    <title>WID-SEC-W-2026-1346 — Linux Kernel: Mehrere Schwachstellen</title>
    <updated>2026-10-02T14:26:20.128684+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um Root-Rechte zu erlangen, um Sicherheitsmechanismen zu umgehen, einen Denial-of-Service-Zustand herbeizuführen oder Auswirkungen unbestimmter Art zu erzielen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1346"/>
  </entry>
</feed>
