<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-05T04:28:45.021581+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-11098</id>
    <title>bdu:2026-11098</title>
    <updated>2026-10-05T04:28:46.738623+00:00</updated>
    <content>bdu:2026-11098</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-11098"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-43214</id>
    <title>BELL-CVE-2026-43214</title>
    <updated>2026-10-05T04:28:46.738696+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-43214"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0697</id>
    <title>certfr-2026-avi-0697 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de SUSE. Certaines d'entre elles permettent à un at…</title>
    <updated>2026-10-05T04:28:46.738730+00:00</updated>
    <content>certfr-2026-avi-0697</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0697"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-347862</id>
    <title>EUVD-2026-347862</title>
    <updated>2026-10-05T04:28:46.738750+00:00</updated>
    <content>EUVD-2026-347862</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-347862"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-43214</id>
    <title>fkie_cve-2026-43214</title>
    <updated>2026-10-05T04:28:46.738762+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>KVM: x86: Add SRCU protection for reading PDPTRs in __get_sregs2()</p>
<p>Add SRCU read-side protection when reading PDPTR registers in
__get_sregs2().</p>
<p>Reading PDPTRs may trigger access to guest memory:
kvm_pdptr_read() -&gt; svm_cache_reg() -&gt; load_pdptrs() -&gt;
kvm_vcpu_read_guest_page() -&gt; kvm_vcpu_gfn_to_memslot()</p>
<p>kvm_vcpu_gfn_to_memslot() dereferences memslots via __kvm_memslots(),
which uses srcu_dereference_check() and requires either kvm-&gt;srcu or
kvm-&gt;slots_lock to be held. Currently only vcpu-&gt;mutex is held,
triggering lockdep warning:</p>
<p>=============================
WARNING: suspicious RCU usage in kvm_vcpu_gfn_to_memslot
6.12.59+ #3 Not tainted</p>
<p>include/linux/kvm_host.h:1062 suspicious rcu_dereference_check() usage!</p>
<p>other info that might help us debug this:</p>
<p>rcu_scheduler_active = 2, debug_locks = 1
1 lock held by syz.5.1717/15100:
 #0: ff1100002f4b00b0 (&amp;vcpu-&gt;mutex){+.+.}-{3:3}, at: kvm_vcpu_ioctl+0x1d5/0x1590</p>
<p>Call Trace:
 &lt;TASK&gt;
 __dump_stack lib/dump_stack.c:94 [inline]
 dump_stack_lvl+0xf0/0x120 lib/dump_stack.c:120
 lockdep_rcu_suspicious+0x1e3/0x270 kernel/locking/lockdep.c:6824
 __kvm_memslots include/linux/kvm_host.h:1062 [inline]
 __kvm_memslots include/linux/kvm_host.h:1059 [inline]
 kvm_vcpu_memslots include/linux/kvm_host.h:1076 [inline]
 kvm_vcpu_gfn_to_memslot+0x518/0x5e0 virt/kvm/kvm_main.c:2617
 kvm_vcpu_read_guest_page+0x27/0x50 virt/kvm/kvm_main.c:3302
 load_pdptrs+0xff/0x4b0 arch/x86/…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-43214"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-5c3f-mcw3-6q2w</id>
    <title>GHSA-5c3f-mcw3-6q2w</title>
    <updated>2026-10-05T04:28:46.738812+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>KVM: x86: Add SRCU protection for reading PDPTRs in __get_sregs2()</p>
<p>Add SRCU read-side protection when reading PDPTR registers in
__get_sregs2().</p>
<p>Reading PDPTRs may trigger access to guest memory:
kvm_pdptr_read() -&gt; svm_cache_reg() -&gt; load_pdptrs() -&gt;
kvm_vcpu_read_guest_page() -&gt; kvm_vcpu_gfn_to_memslot()</p>
<p>kvm_vcpu_gfn_to_memslot() dereferences memslots via __kvm_memslots(),
which uses srcu_dereference_check() and requires either kvm-&gt;srcu or
kvm-&gt;slots_lock to be held. Currently only vcpu-&gt;mutex is held,
triggering lockdep warning:</p>
<p>=============================
WARNING: suspicious RCU usage in kvm_vcpu_gfn_to_memslot
6.12.59+ #3 Not tainted</p>
<p>include/linux/kvm_host.h:1062 suspicious rcu_dereference_check() usage!</p>
<p>other info that might help us debug this:</p>
<p>rcu_scheduler_active = 2, debug_locks = 1
1 lock held by syz.5.1717/15100:
 #0: ff1100002f4b00b0 (&amp;vcpu-&gt;mutex){+.+.}-{3:3}, at: kvm_vcpu_ioctl+0x1d5/0x1590</p>
<p>Call Trace:
 &lt;TASK&gt;
 __dump_stack lib/dump_stack.c:94 [inline]
 dump_stack_lvl+0xf0/0x120 lib/dump_stack.c:120
 lockdep_rcu_suspicious+0x1e3/0x270 kernel/locking/lockdep.c:6824
 __kvm_memslots include/linux/kvm_host.h:1062 [inline]
 __kvm_memslots include/linux/kvm_host.h:1059 [inline]
 kvm_vcpu_memslots include/linux/kvm_host.h:1076 [inline]
 kvm_vcpu_gfn_to_memslot+0x518/0x5e0 virt/kvm/kvm_main.c:2617
 kvm_vcpu_read_guest_page+0x27/0x50 virt/kvm/kvm_main.c:3302
 load_pdptrs+0xff/0x4b0 arch/x86/…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-5c3f-mcw3-6q2w"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-2312</id>
    <title>OESA-2026-2312 — kernel security update</title>
    <updated>2026-10-05T04:28:46.738849+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS: kernel</p>
<p>The Linux Kernel, the operating system core itself.

Security Fix(es):</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>dmaengine: idxd: fix possible wrong descriptor completion in llist_abort_desc()</p>
<p>At the end of this function, d is the traversal cursor of flist, but the
code completes found instead. This can lead to issues such as NULL pointer
dereferences, double completion, or descriptor leaks.</p>
<p>Fix this by completing d instead of found in the final
list_for_each_entry_safe() loop.(CVE-2026-31436)</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>hwmon: (pmbus/core) Protect regulator operations with mutex</p>
<p>The regulator operations pmbus_regulator_get_voltage(),
pmbus_regulator_set_voltage(), and pmbus_regulator_list_voltage()
access PMBus registers and shared data but were not protected by
the update_lock mutex. This could lead to race conditions.</p>
<p>However, adding mutex protection directly to these functions causes
a deadlock because pmbus_regulator_notify() (which calls
regulator_notifier_call_chain()) is often called with the mutex
already held (e.g., from pmbus_fault_handler()). If a regulator
callback then calls one of the now-protected voltage functions,
it will attempt to acquire the same mutex.</p>
<p>Rework pmbus_regulator_notify() to utilize a worker function to
send notifications outside of the mutex protection. Events are
stored as atomics in a per-page bitmask and processed by the worker.</p>
<p>Initialize the worker and its as…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-2312"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:21555-1</id>
    <title>openSUSE-SU-2026:21555-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-05T04:28:46.738940+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:21555-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:2111-1</id>
    <title>SUSE-SU-2026:2111-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-05T04:28:46.739456+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:2111-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-43214</id>
    <title>UBUNTU-CVE-2026-43214</title>
    <updated>2026-10-05T04:28:46.739504+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 179 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Add SRCU protection for reading PDPTRs in __get_sregs2() Add SRCU read-side protection when reading PDPTR registers in __get_sregs2(). Reading PDPTRs may trigger access to guest memory: kvm_pdptr_read() -&gt; svm_cache_reg() -&gt; load_pdptrs() -&gt; kvm_vcpu_read_guest_page() -&gt; kvm_vcpu_gfn_to_memslot() kvm_vcpu_gfn_to_memslot() dereferences memslots via __kvm_memslots(), which uses srcu_dereference_check() and requires either kvm-&gt;srcu or kvm-&gt;slots_lock to be held. Currently only vcpu-&gt;mutex is held, triggering lockdep warning: ============================= WARNING: suspicious RCU usage in kvm_vcpu_gfn_to_memslot 6.12.59+ #3 Not tainted include/linux/kvm_host.h:1062 suspicious rcu_dereference_check() usage! other info that might help us debug this: rcu_scheduler_active = 2, debug_locks = 1 1 lock held by syz.5.1717/15100:  #0: ff1100002f4b00b0 (&amp;vcpu-&gt;mutex){+.+.}-{3:3}, at: kvm_vcpu_ioctl+0x1d5/0x1590 Call Trace:  &lt;TASK&gt;  __dump_stack lib/dump_stack.c:94 [inline]  dump_stack_lvl+0xf0/0x120 lib/dump_stack.c:120  lockdep_rcu_suspicious+0x1e3/0x270 kernel/locking/lockdep.c:6824  __kvm_memslots include/linux/kvm_host.h:1062 [inline]  __kvm_memslots include/linux/kvm_host.h:1059 [inline]  kvm_vcpu_memslots include/linux/kvm_host.h:1076 [inline]  kvm_vcpu_gfn_to_memslot+0x518/0x5e0 virt/kvm/kvm_main.c:2617  kvm_vcpu_read_guest_page+0x27/0x50 virt/kvm/kvm_main.c:3302  load_pdptrs+0xff/0x4b0 arch/x86/kvm/x86.c…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-43214"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1405</id>
    <title>WID-SEC-W-2026-1405 — Linux Kernel: Mehrere Schwachstellen</title>
    <updated>2026-10-05T04:28:46.739760+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um nicht spezifizierte Angriffe durchzuführen, möglicherweise Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren oder offenzulegen oder einen Denial-of-Service-Zustand zu verursachen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1405"/>
  </entry>
</feed>
