<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T00:31:41.965965+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:16195</id>
    <title>ALSA-2026:16195 — Important: kernel security update</title>
    <updated>2026-10-04T00:31:44.654029+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: bpftool, AlmaLinux:8: kernel, AlmaLinux:8: kernel-abi-stablelists, AlmaLinux:8: kernel-core, AlmaLinux:8: kernel-cross-headers, AlmaLinux:8: kernel-debug, AlmaLinux:8: kernel-debug-core, AlmaLinux:8: kernel-debug-devel, AlmaLinux:8: kernel-debug-modules, AlmaLinux:8: kernel-debug-modules-extra and 15 more</p>
<p>The kernel packages contain the Linux kernel, the core of any Linux operating system.</p>
<p>Security Fix(es):</p>
<p>* kernel: "Dirty Frag" is a new universal Local Privilege Escalation (LPE) vulnerability in the Linux kernel (CVE-2026-43284)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:16195"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-06439</id>
    <title>bdu:2026-06439</title>
    <updated>2026-10-04T00:31:44.654176+00:00</updated>
    <content>bdu:2026-06439</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-06439"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-43284</id>
    <title>BELL-CVE-2026-43284</title>
    <updated>2026-10-04T00:31:44.654195+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-43284"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0558</id>
    <title>certfr-2026-avi-0558 — De multiples vulnérabilités ont été découvertes dans Microsoft Azure Linux. Elles permettent à un attaquant de provoque…</title>
    <updated>2026-10-04T00:31:44.654218+00:00</updated>
    <content>certfr-2026-avi-0558</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0558"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2026-21358</id>
    <title>cnvd-2026-21358</title>
    <updated>2026-10-04T00:31:44.654234+00:00</updated>
    <content>cnvd-2026-21358</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2026-21358"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/esba-2026:0090</id>
    <title>ESBA-2026:0090 — security update for kernel</title>
    <updated>2026-10-04T00:31:44.654246+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>security update for kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/esba-2026:0090"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-364801</id>
    <title>EUVD-2026-364801</title>
    <updated>2026-10-04T00:31:44.654265+00:00</updated>
    <content>EUVD-2026-364801</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-364801"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-43284</id>
    <title>fkie_cve-2026-43284</title>
    <updated>2026-10-04T00:31:44.654276+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>xfrm: esp: avoid in-place decrypt on shared skb frags</p>
<p>MSG_SPLICE_PAGES can attach pages from a pipe directly to an skb. TCP
marks such skbs with SKBFL_SHARED_FRAG after skb_splice_from_iter(),
so later paths that may modify packet data can first make a private
copy. The IPv4/IPv6 datagram append paths did not set this flag when
splicing pages into UDP skbs.</p>
<p>That leaves an ESP-in-UDP packet made from shared pipe pages looking
like an ordinary uncloned nonlinear skb. ESP input then takes the no-COW
fast path for uncloned skbs without a frag_list and decrypts in place
over data that is not owned privately by the skb.</p>
<p>Mark IPv4/IPv6 datagram splice frags with SKBFL_SHARED_FRAG, matching
TCP. Also make ESP input fall back to skb_cow_data() when the flag is
present, so ESP does not decrypt externally backed frags in place.
Private nonlinear skb frags still use the existing fast path.</p>
<p>This intentionally does not change ESP output. In esp_output_head(),
the path that appends the ESP trailer to existing skb tailroom without
calling skb_cow_data() is not reachable for nonlinear skbs:
skb_tailroom() returns zero when skb-&gt;data_len is nonzero, while ESP
tailen is positive. Thus ESP output will either use the separate
destination-frag path or fall back to skb_cow_data().</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-43284"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-mmw8-mxmc-8w2r</id>
    <title>GHSA-mmw8-mxmc-8w2r</title>
    <updated>2026-10-04T00:31:44.654311+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>xfrm: esp: avoid in-place decrypt on shared skb frags</p>
<p>MSG_SPLICE_PAGES can attach pages from a pipe directly to an skb. TCP
marks such skbs with SKBFL_SHARED_FRAG after skb_splice_from_iter(),
so later paths that may modify packet data can first make a private
copy. The IPv4/IPv6 datagram append paths did not set this flag when
splicing pages into UDP skbs.</p>
<p>That leaves an ESP-in-UDP packet made from shared pipe pages looking
like an ordinary uncloned nonlinear skb. ESP input then takes the no-COW
fast path for uncloned skbs without a frag_list and decrypts in place
over data that is not owned privately by the skb.</p>
<p>Mark IPv4/IPv6 datagram splice frags with SKBFL_SHARED_FRAG, matching
TCP. Also make ESP input fall back to skb_cow_data() when the flag is
present, so ESP does not decrypt externally backed frags in place.
Private nonlinear skb frags still use the existing fast path.</p>
<p>This intentionally does not change ESP output. In esp_output_head(),
the path that appends the ESP trailer to existing skb tailroom without
calling skb_cow_data() is not reachable for nonlinear skbs:
skb_tailroom() returns zero when skb-&gt;data_len is nonzero, while ESP
tailen is positive. Thus ESP output will either use the separate
destination-frag path or fall back to skb_cow_data().</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-mmw8-mxmc-8w2r"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-26-174-06</id>
    <title>ICSA-26-174-06 — Impact of Linux Kernel vulnerabilities on B&amp;R products</title>
    <updated>2026-10-04T00:31:44.654336+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>B&amp;R is aware of publicly reported vulnerabilities affecting the Linux kernel versions shipped with the products listed as affected in the advisory.</p>
<p>Successful local exploitation of these vulnerabilities could allow an attacker to escalate privileges on the affected system. Public proof-of-concept exploits are available for the vulnerabilities described herein. At the time of publication of this advisory, B&amp;R had no evidence of active exploitation targeting B&amp;R products.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-26-174-06"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-43284</id>
    <title>msrc_CVE-2026-43284 — xfrm: esp: avoid in-place decrypt on shared skb frags</title>
    <updated>2026-10-04T00:31:44.654360+00:00</updated>
    <content>msrc_CVE-2026-43284</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-43284"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-2310</id>
    <title>OESA-2026-2310 — kernel security update</title>
    <updated>2026-10-04T00:31:44.654376+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP4: kernel</p>
<p>The Linux Kernel, the operating system core itself.

Security Fix(es):</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>net: fix fanout UAF in packet_release() via NETDEV_UP race</p>
<p>`packet_release()` has a race window where `NETDEV_UP` can re-register a
socket into a fanout group&amp;apos;s `arr[]` array. The re-registration is not
cleaned up by `fanout_release()`, leaving a dangling pointer in the fanout
array.
`packet_release()` does NOT zero `po-&amp;gt;num` in its `bind_lock` section.
After releasing `bind_lock`, `po-&amp;gt;num` is still non-zero and `po-&amp;gt;ifindex`
still matches the bound device. A concurrent `packet_notifier(NETDEV_UP)`
that already found the socket in `sklist` can re-register the hook.
For fanout sockets, this re-registration calls `__fanout_link(sk, po)`
which adds the socket back into `f-&amp;gt;arr[]` and increments `f-&amp;gt;num_members`,
but does NOT increment `f-&amp;gt;sk_ref`.</p>
<p>The fix sets `po-&amp;gt;num` to zero in `packet_release` while `bind_lock` is
held to prevent NETDEV_UP from linking, preventing the race window.</p>
<p>This bug was found following an additional audit with Claude Code based
on CVE-2025-38617.(CVE-2026-31504)</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>af_key: validate families in pfkey_send_migrate()</p>
<p>syzbot was able to trigger a crash in skb_put() [1]</p>
<p>Issue is that pfkey_send_migrate() does not check old/new families,
and that set_ipsecrequest() @family argument was truncated,
thus possibly overfill…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-2310"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ppsa-2026-003</id>
    <title>PPSA-2026-003 — Pilz: Multiple Vulnerabilities affecting industrial PC IndustrialPI</title>
    <updated>2026-10-04T00:31:44.654430+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The Linux kernel used in the IndustrialPI, 'linux-image-revpi-v8', prior to version 6.12.91-revpi0-rpi-v8 contains multiple vulnerabilities. Successful exploitation of these vulnerabilities can give an attacker full control over the device.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ppsa-2026-003"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:16061</id>
    <title>RHSA-2026:16061 — Red Hat Security Advisory: kernel security update</title>
    <updated>2026-10-04T00:31:44.654450+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>kernel: "Dirty Frag" ESP XFRM variant is a new universal Local Privilege Escalation (LPE) vulnerability in the Linux kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:16061"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:19569</id>
    <title>RLSA-2026:19569 — Important: kernel security update</title>
    <updated>2026-10-04T00:31:44.654467+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:10: kernel</p>
<p>The kernel packages contain the Linux kernel, the core of any Linux operating system.</p>
<p>Security Fix(es):</p>
<p>* kernel: net: af_can: do not leave a dangling sk pointer in can_create() (CVE-2024-56603)</p>
<p>* kernel: net/sched: Make cake_enqueue return NET_XMIT_CN when past buffer_limit (CVE-2025-39766)</p>
<p>* kernel: crypto: asymmetric_keys - prevent overflow in asymmetric_key_generate_id (CVE-2025-68724)</p>
<p>* kernel: scsi: qla2xxx: Fix improper freeing of purex item (CVE-2025-68741)</p>
<p>* kernel: Linux kernel: Use-after-free in traffic control (act_ct) may lead to denial of service or privilege escalation (CVE-2026-23270)</p>
<p>* kernel: Linux kernel KVM: Privilege escalation or denial of service due to improper shadow page table entry handling (CVE-2026-23401)</p>
<p>* kernel: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (CVE-2026-31402)</p>
<p>* kernel: Bluetooth: SCO: Fix use-after-free in sco_recv_frame() due to missing sock_hold (CVE-2026-31408)</p>
<p>* kernel: usbip: validate number_of_packets in usbip_pack_ret_submit() (CVE-2026-31607)</p>
<p>* kernel: RDMA/umem: Fix double dma_buf_unpin in failure path (CVE-2026-43128)</p>
<p>* kernel: "Dirty Frag" is a new universal Local Privilege Escalation (LPE) vulnerability in the Linux kernel (CVE-2026-43284)</p>
<p>* kernel: "Fragnesia" is a variant of Dirty Frag vulnerability in the ESP/XFRM leading to Local Privilege Escalation (LPE) vulnerability in the Linux kernel (CVE-2026-46300)</p>
<p>* kernel: Read root-owned files as an unprivileged user (CVE-2026-46333)</p>
<p>For more deta…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:19569"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/sa26p010</id>
    <title>SA26P010 — Impact of Linux Kernel vulnerabilities on B&amp;R products</title>
    <updated>2026-10-04T00:31:44.654508+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>B&amp;R is aware of publicly reported vulnerabilities affecting the Linux kernel versions shipped with the products listed as affected in the advisory.</p>
<p>Successful local exploitation of these vulnerabilities could allow an attacker to escalate privileges on the affected system. Public proof-of-concept exploits are available for the vulnerabilities described herein. At the time of publication of this advisory, B&amp;R had no evidence of active exploitation targeting B&amp;R products.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/sa26p010"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ssa-019113</id>
    <title>SSA-019113 — SSA-019113: Vulnerabilities in the additional GNU/Linux subsystem of the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1.6</title>
    <updated>2026-10-04T00:31:44.654530+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.6 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant).</p>
<p>Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ssa-019113"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:1778-1</id>
    <title>SUSE-SU-2026:1778-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-04T00:31:44.654739+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:1778-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-43284</id>
    <title>UBUNTU-CVE-2026-43284</title>
    <updated>2026-10-04T00:31:44.654758+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:Pro:18.04:LTS: linux, Ubuntu:Pro:18.04:LTS: linux-aws, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:Pro:18.04:LTS: linux-aws-5.4, Ubuntu:18.04:LTS: linux-azure, Ubuntu:Pro:18.04:LTS: linux-azure-4.15 and 233 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: xfrm: esp: avoid in-place decrypt on shared skb frags MSG_SPLICE_PAGES can attach pages from a pipe directly to an skb. TCP marks such skbs with SKBFL_SHARED_FRAG after skb_splice_from_iter(), so later paths that may modify packet data can first make a private copy. The IPv4/IPv6 datagram append paths did not set this flag when splicing pages into UDP skbs. That leaves an ESP-in-UDP packet made from shared pipe pages looking like an ordinary uncloned nonlinear skb. ESP input then takes the no-COW fast path for uncloned skbs without a frag_list and decrypts in place over data that is not owned privately by the skb. Mark IPv4/IPv6 datagram splice frags with SKBFL_SHARED_FRAG, matching TCP. Also make ESP input fall back to skb_cow_data() when the flag is present, so ESP does not decrypt externally backed frags in place. Private nonlinear skb frags still use the existing fast path. This intentionally does not change ESP output. In esp_output_head(), the path that appends the ESP trailer to existing skb tailroom without calling skb_cow_data() is not reachable for nonlinear skbs: skb_tailroom() returns zero when skb-&gt;data_len is nonzero, while ESP tailen is positive. Thus ESP output will either use the separate destination-frag path or fall back to skb_cow_data().</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-43284"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1430</id>
    <title>WID-SEC-W-2026-1430 — Linux Kernel (Dirty Frag): Mehrere Schwachstellen ermöglichen Erlangen von Administratorrechten</title>
    <updated>2026-10-04T00:31:44.655143+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein lokaler Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um Administratorrechte zu erlangen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1430"/>
  </entry>
</feed>
