<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T23:29:10.966007+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:27353</id>
    <title>ALSA-2026:27353 — Important: kernel security, bug fix, and enhancement update</title>
    <updated>2026-10-03T23:29:12.584593+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: bpftool, AlmaLinux:8: kernel, AlmaLinux:8: kernel-abi-stablelists, AlmaLinux:8: kernel-core, AlmaLinux:8: kernel-cross-headers, AlmaLinux:8: kernel-debug, AlmaLinux:8: kernel-debug-core, AlmaLinux:8: kernel-debug-devel, AlmaLinux:8: kernel-debug-modules, AlmaLinux:8: kernel-debug-modules-extra and 15 more</p>
<p>The kernel packages contain the Linux kernel, the core of any Linux operating system.</p>
<p>Security Fix(es):</p>
<p>* kernel: Linux kernel: Use-after-free in bonding driver leads to denial of service (CVE-2026-31419)
  * kernel: drm/amd/display: Do not skip unrelated mode changes in DSC validation (CVE-2026-31488)
  * kernel: net: mana: fix use-after-free in add_adev() error path (CVE-2026-43056)
  * kernel: ALSA: usb-audio: Add sanity check for OOB writes at silencing (CVE-2026-43279)
  * kernel: net/sched: act_pedit: extend the writable skb range per key (CVE-2026-46331)
  * kernel: ALSA: aloop: Fix peer runtime UAF during format-change stop (CVE-2026-46090)
  * kernel: RDMA/mana: Validate rx_hash_key_len (CVE-2026-46145)
  * kernel: nvmet-tcp: fix race between ICReq handling and queue teardown (CVE-2026-46135)</p>
<p>Bug Fix(es) and Enhancement(s):</p>
<p>* AlmaLinux8 RT kernel panic in replenish_dl_entity() caused by stale DEADLINE PI state during rt_mutex de-boosting (JIRA:AlmaLinux-178520)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:27353"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-11735</id>
    <title>bdu:2026-11735</title>
    <updated>2026-10-03T23:29:12.584763+00:00</updated>
    <content>bdu:2026-11735</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-11735"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-43279</id>
    <title>BELL-CVE-2026-43279</title>
    <updated>2026-10-03T23:29:12.584785+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-43279"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0808</id>
    <title>certfr-2026-avi-0808 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de Red Hat. Certaines d'entre elles permettent à un…</title>
    <updated>2026-10-03T23:29:12.584809+00:00</updated>
    <content>certfr-2026-avi-0808</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0808"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/essa-2026:0165</id>
    <title>ESSA-2026:0165 — Important: kernel security, bug fix, and enhancement update</title>
    <updated>2026-10-03T23:29:12.584826+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Important: kernel security, bug fix, and enhancement update</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/essa-2026:0165"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-347882</id>
    <title>EUVD-2026-347882</title>
    <updated>2026-10-03T23:29:12.584853+00:00</updated>
    <content>EUVD-2026-347882</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-347882"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-43279</id>
    <title>fkie_cve-2026-43279</title>
    <updated>2026-10-03T23:29:12.584865+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>ALSA: usb-audio: Add sanity check for OOB writes at silencing</p>
<p>At silencing the playback URB packets in the implicit fb mode before
the actual playback, we blindly assume that the received packets fit
with the buffer size.  But when the setup in the capture stream
differs from the playback stream (e.g. due to the USB core limitation
of max packet size), such an inconsistency may lead to OOB writes to
the buffer, resulting in a crash.</p>
<p>For addressing it, add a sanity check of the transfer buffer size at
prepare_silent_urb(), and stop the data copy if the received data
overflows.  Also, report back the transfer error properly from there,
too.</p>
<p>Note that this doesn't fix the root cause of the playback error
itself, but this merely covers the kernel Oops.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-43279"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-2hw8-5267-5p9j</id>
    <title>GHSA-2hw8-5267-5p9j</title>
    <updated>2026-10-03T23:29:12.584894+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>ALSA: usb-audio: Add sanity check for OOB writes at silencing</p>
<p>At silencing the playback URB packets in the implicit fb mode before
the actual playback, we blindly assume that the received packets fit
with the buffer size.  But when the setup in the capture stream
differs from the playback stream (e.g. due to the USB core limitation
of max packet size), such an inconsistency may lead to OOB writes to
the buffer, resulting in a crash.</p>
<p>For addressing it, add a sanity check of the transfer buffer size at
prepare_silent_urb(), and stop the data copy if the received data
overflows.  Also, report back the transfer error properly from there,
too.</p>
<p>Note that this doesn't fix the root cause of the playback error
itself, but this merely covers the kernel Oops.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-2hw8-5267-5p9j"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:27354</id>
    <title>RHSA-2026:27354 — Red Hat Security Advisory: kernel-rt security, bug fix, and enhancement update</title>
    <updated>2026-10-03T23:29:12.584916+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>kernel: Linux kernel: Use-after-free in bonding driver leads to denial of service kernel: drm/amd/display: Do not skip unrelated mode changes in DSC validation kernel: net: mana: fix use-after-free in add_adev() error path kernel: ALSA: usb-audio: Add sanity check for OOB writes at silencing kernel: ALSA: aloop: Fix peer runtime UAF during format-change stop kernel: nvmet-tcp: fix race between ICReq handling and queue teardown kernel: RDMA/mana: Validate rx_hash_key_len kernel: net/sched: act_pedit: extend the writable skb range per key</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:27354"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:27353</id>
    <title>RLSA-2026:27353 — Important: kernel security, bug fix, and enhancement update</title>
    <updated>2026-10-03T23:29:12.584946+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:8: kernel</p>
<p>The kernel packages contain the Linux kernel, the core of any Linux operating system.</p>
<p>Security Fix(es):</p>
<p>* kernel: Linux kernel: Use-after-free in bonding driver leads to denial of service (CVE-2026-31419)</p>
<p>* kernel: drm/amd/display: Do not skip unrelated mode changes in DSC validation (CVE-2026-31488)</p>
<p>* kernel: net: mana: fix use-after-free in add_adev() error path (CVE-2026-43056)</p>
<p>* kernel: ALSA: usb-audio: Add sanity check for OOB writes at silencing (CVE-2026-43279)</p>
<p>* kernel: net/sched: act_pedit: extend the writable skb range per key (CVE-2026-46331)</p>
<p>* kernel: ALSA: aloop: Fix peer runtime UAF during format-change stop (CVE-2026-46090)</p>
<p>* kernel: RDMA/mana: Validate rx_hash_key_len (CVE-2026-46145)</p>
<p>* kernel: nvmet-tcp: fix race between ICReq handling and queue teardown (CVE-2026-46135)</p>
<p>Bug Fix(es) and Enhancement(s):</p>
<p>* Rocky Linux8 RT kernel panic in replenish_dl_entity() caused by stale DEADLINE PI state during rt_mutex de-boosting (JIRA:Rocky Linux-178520)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:27353"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:23066-1</id>
    <title>SUSE-SU-2026:23066-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-03T23:29:12.584980+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:23066-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-43279</id>
    <title>UBUNTU-CVE-2026-43279</title>
    <updated>2026-10-03T23:29:12.585429+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: linux, Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe and 232 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Add sanity check for OOB writes at silencing At silencing the playback URB packets in the implicit fb mode before the actual playback, we blindly assume that the received packets fit with the buffer size.  But when the setup in the capture stream differs from the playback stream (e.g. due to the USB core limitation of max packet size), such an inconsistency may lead to OOB writes to the buffer, resulting in a crash. For addressing it, add a sanity check of the transfer buffer size at prepare_silent_urb(), and stop the data copy if the received data overflows.  Also, report back the transfer error properly from there, too. Note that this doesn't fix the root cause of the playback error itself, but this merely covers the kernel Oops.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-43279"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1405</id>
    <title>WID-SEC-W-2026-1405 — Linux Kernel: Mehrere Schwachstellen</title>
    <updated>2026-10-03T23:29:12.585703+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um nicht spezifizierte Angriffe durchzuführen, möglicherweise Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren oder offenzulegen oder einen Denial-of-Service-Zustand zu verursachen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1405"/>
  </entry>
</feed>
