<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T16:29:20.066968+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-08743</id>
    <title>bdu:2026-08743</title>
    <updated>2026-10-02T16:29:20.218350+00:00</updated>
    <content>bdu:2026-08743</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-08743"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-43048</id>
    <title>BELL-CVE-2026-43048</title>
    <updated>2026-10-02T16:29:20.218391+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-43048"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1203</id>
    <title>certfr-2026-avi-1203 — De multiples vulnérabilités ont été découvertes dans le noyau Linux d'Ubuntu. Elles permettent à un attaquant de provoq…</title>
    <updated>2026-10-02T16:29:20.218422+00:00</updated>
    <content>certfr-2026-avi-1203</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-1203"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-347810</id>
    <title>EUVD-2026-347810</title>
    <updated>2026-10-02T16:29:20.218440+00:00</updated>
    <content>EUVD-2026-347810</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-347810"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-43048</id>
    <title>fkie_cve-2026-43048</title>
    <updated>2026-10-02T16:29:20.218451+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>HID: core: Mitigate potential OOB by removing bogus memset()</p>
<p>The memset() in hid_report_raw_event() has the good intention of
clearing out bogus data by zeroing the area from the end of the incoming
data string to the assumed end of the buffer.  However, as we have
previously seen, doing so can easily result in OOB reads and writes in
the subsequent thread of execution.</p>
<p>The current suggestion from one of the HID maintainers is to remove the
memset() and simply return if the incoming event buffer size is not
large enough to fill the associated report.</p>
<p>Suggested-by Benjamin Tissoires &lt;bentiss@kernel.org&gt;</p>
<p>[bentiss: changed the return value]</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-43048"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-7r6r-545m-fqv3</id>
    <title>GHSA-7r6r-545m-fqv3</title>
    <updated>2026-10-02T16:29:20.218483+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>HID: core: Mitigate potential OOB by removing bogus memset()</p>
<p>The memset() in hid_report_raw_event() has the good intention of
clearing out bogus data by zeroing the area from the end of the incoming
data string to the assumed end of the buffer.  However, as we have
previously seen, doing so can easily result in OOB reads and writes in
the subsequent thread of execution.</p>
<p>The current suggestion from one of the HID maintainers is to remove the
memset() and simply return if the incoming event buffer size is not
large enough to fill the associated report.</p>
<p>Suggested-by Benjamin Tissoires &lt;bentiss@kernel.org&gt;</p>
<p>[bentiss: changed the return value]</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-7r6r-545m-fqv3"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-43048</id>
    <title>msrc_CVE-2026-43048 — HID: core: Mitigate potential OOB by removing bogus memset()</title>
    <updated>2026-10-02T16:29:20.218504+00:00</updated>
    <content>msrc_CVE-2026-43048</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-43048"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-2415</id>
    <title>OESA-2026-2415 — kernel security update</title>
    <updated>2026-10-02T16:29:20.218520+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP4: kernel</p>
<p>The Linux Kernel, the operating system core itself.

Security Fix(es):</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>driver core: platform: use generic driver_override infrastructure</p>
<p>When a driver is probed through __driver_attach(), the bus&amp;apos; match()
callback is called without the device lock held, thus accessing the
driver_override field without a lock, which can cause a UAF.</p>
<p>Fix this by using the driver-core driver_override infrastructure taking
care of proper locking internally.</p>
<p>Note that calling match() from __driver_attach() without the device lock
held is intentional. [1](CVE-2026-31527)</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>crypto: ccp: Don&amp;apos;t attempt to copy PDH cert to userspace if PSP command failed</p>
<p>When retrieving the PDH cert, don&amp;apos;t attempt to copy the blobs to userspace
if the firmware command failed.  If the failure was due to an invalid
length, i.e. the userspace buffer+length was too small, copying the number
of bytes _firmware_ requires will overflow the kernel-allocated buffer and
leak data to userspace.</p>
<p>BUG: KASAN: slab-out-of-bounds in instrument_copy_to_user ../include/linux/instrumented.h:129 [inline]
  BUG: KASAN: slab-out-of-bounds in _inline_copy_to_user ../include/linux/uaccess.h:205 [inline]
  BUG: KASAN: slab-out-of-bounds in _copy_to_user+0x66/0xa0 ../lib/usercopy.c:26
  Read of size 2084 at addr ffff8885c4ab8aa0 by task syz.0.186/21033</p>
<p>CPU: 51 UID: 0 PID: 21033 Com…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-2415"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-43048</id>
    <title>UBUNTU-CVE-2026-43048</title>
    <updated>2026-10-02T16:29:20.218582+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: linux, Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe and 233 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: HID: core: Mitigate potential OOB by removing bogus memset() The memset() in hid_report_raw_event() has the good intention of clearing out bogus data by zeroing the area from the end of the incoming data string to the assumed end of the buffer.  However, as we have previously seen, doing so can easily result in OOB reads and writes in the subsequent thread of execution. The current suggestion from one of the HID maintainers is to remove the memset() and simply return if the incoming event buffer size is not large enough to fill the associated report. Suggested-by Benjamin Tissoires &lt;bentiss@kernel.org&gt; [bentiss: changed the return value]</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-43048"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1346</id>
    <title>WID-SEC-W-2026-1346 — Linux Kernel: Mehrere Schwachstellen</title>
    <updated>2026-10-02T16:29:20.218881+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um Root-Rechte zu erlangen, um Sicherheitsmechanismen zu umgehen, einen Denial-of-Service-Zustand herbeizuführen oder Auswirkungen unbestimmter Art zu erzielen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1346"/>
  </entry>
</feed>
