<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T17:31:45.041043+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:21556</id>
    <title>ALSA-2026:21556 — Important: kernel security update</title>
    <updated>2026-10-03T17:31:45.609244+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:9: kernel, AlmaLinux:9: kernel-64k, AlmaLinux:9: kernel-64k-core, AlmaLinux:9: kernel-64k-debug, AlmaLinux:9: kernel-64k-debug-core, AlmaLinux:9: kernel-64k-debug-devel, AlmaLinux:9: kernel-64k-debug-devel-matched, AlmaLinux:9: kernel-64k-debug-modules, AlmaLinux:9: kernel-64k-debug-modules-core, AlmaLinux:9: kernel-64k-debug-modules-extra and 64 more</p>
<p>The kernel packages contain the Linux kernel, the core of any Linux operating system.</p>
<p>Security Fix(es):</p>
<p>* kernel: proc: use the same treatment to check proc_lseek as ones for proc_read_iter et.al (CVE-2025-38653)
  * kernel: ima: don't clear IMA_DIGSIG flag when setting or removing non-IMA xattr (CVE-2025-68183)
  * kernel: nbd: defer config unlock in nbd_genl_connect (CVE-2025-68366)
  * kernel: crypto: asymmetric_keys - prevent overflow in asymmetric_key_generate_id (CVE-2025-68724)
  * kernel: iommu: disable SVA when CONFIG_X86 is set (CVE-2025-71089)
  * kernel: netfilter: nf_tables: release flowtable after rcu grace period on error (CVE-2026-23392)
  * kernel: netfilter: nf_conntrack_h323: check for zero length in DecodeQ931() (CVE-2026-23455)
  * kernel: Bluetooth: SCO: Fix use-after-free in sco_recv_frame() due to missing sock_hold (CVE-2026-31408)
  * kernel: net: sched: act_csum: validate nested VLAN headers (CVE-2026-31684)
  * kernel: netfilter: ip6t_eui64: reject invalid MAC header for all packets (CVE-2026-31685)
  * kernel: netfilter: nf_conntrack_helper: pass helper to expect cleanup (CVE-2026-43027)
  * kernel: Bluetooth: MGMT: validate LTK enc_size on load (CVE-2026-43020)
  * kernel: HID: wacom: fix out-of-bounds read in wacom_intuos_bt_irq (CVE-2026-43051)
  * kernel: smb: client: validate the whole DACL before rewriting it in cifsacl (CVE-2026-31709)
  * kernel: Bluetooth: SCO: fix race conditions in sco_sock_connect() (CVE-2026-43023)
  * kernel:…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:21556"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-43303</id>
    <title>BELL-CVE-2026-43303</title>
    <updated>2026-10-03T17:31:45.609446+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-43303"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0781</id>
    <title>certfr-2026-avi-0781 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de Red Hat. Certaines d'entre elles permettent à un…</title>
    <updated>2026-10-03T17:31:45.609475+00:00</updated>
    <content>certfr-2026-avi-0781</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0781"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/essa-2026:0155</id>
    <title>ESSA-2026:0155 — Important: kernel security, bug fix, and enhancement update</title>
    <updated>2026-10-03T17:31:45.609494+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Important: kernel security, bug fix, and enhancement update</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/essa-2026:0155"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-364802</id>
    <title>EUVD-2026-364802</title>
    <updated>2026-10-03T17:31:45.609520+00:00</updated>
    <content>EUVD-2026-364802</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-364802"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-43303</id>
    <title>fkie_cve-2026-43303</title>
    <updated>2026-10-03T17:31:45.609532+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>mm/page_alloc: clear page-&gt;private in free_pages_prepare()</p>
<p>Several subsystems (slub, shmem, ttm, etc.) use page-&gt;private but don't
clear it before freeing pages.  When these pages are later allocated as
high-order pages and split via split_page(), tail pages retain stale
page-&gt;private values.</p>
<p>This causes a use-after-free in the swap subsystem.  The swap code uses
page-&gt;private to track swap count continuations, assuming freshly
allocated pages have page-&gt;private == 0.  When stale values are present,
swap_count_continued() incorrectly assumes the continuation list is valid
and iterates over uninitialized page-&gt;lru containing LIST_POISON values,
causing a crash:</p>
<p>KASAN: maybe wild-memory-access in range [0xdead000000000100-0xdead000000000107]
  RIP: 0010:__do_sys_swapoff+0x1151/0x1860</p>
<p>Fix this by clearing page-&gt;private in free_pages_prepare(), ensuring all
freed pages have clean state regardless of previous use.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-43303"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-6fh9-96ww-pvwq</id>
    <title>GHSA-6fh9-96ww-pvwq</title>
    <updated>2026-10-03T17:31:45.609564+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>mm/page_alloc: clear page-&gt;private in free_pages_prepare()</p>
<p>Several subsystems (slub, shmem, ttm, etc.) use page-&gt;private but don't
clear it before freeing pages.  When these pages are later allocated as
high-order pages and split via split_page(), tail pages retain stale
page-&gt;private values.</p>
<p>This causes a use-after-free in the swap subsystem.  The swap code uses
page-&gt;private to track swap count continuations, assuming freshly
allocated pages have page-&gt;private == 0.  When stale values are present,
swap_count_continued() incorrectly assumes the continuation list is valid
and iterates over uninitialized page-&gt;lru containing LIST_POISON values,
causing a crash:</p>
<p>KASAN: maybe wild-memory-access in range [0xdead000000000100-0xdead000000000107]
  RIP: 0010:__do_sys_swapoff+0x1151/0x1860</p>
<p>Fix this by clearing page-&gt;private in free_pages_prepare(), ensuring all
freed pages have clean state regardless of previous use.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-6fh9-96ww-pvwq"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-43303</id>
    <title>msrc_CVE-2026-43303 — mm/page_alloc: clear page-&gt;private in free_pages_prepare()</title>
    <updated>2026-10-03T17:31:45.609594+00:00</updated>
    <content>msrc_CVE-2026-43303</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-43303"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-2675</id>
    <title>OESA-2026-2675 — kernel security update</title>
    <updated>2026-10-03T17:31:45.609610+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS-SP1: kernel</p>
<p>The Linux Kernel, the operating system core itself.

Security Fix(es):</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>drm/i915/gt: Fix timeline left held on VMA alloc error</p>
<p>The following error has been reported sporadically by CI when a test
unbinds the i915 driver on a ring submission platform:</p>
<p>&amp;lt;4&amp;gt; [239.330153] ------------[ cut here ]------------
&amp;lt;4&amp;gt; [239.330166] i915 0000:00:02.0: [drm] drm_WARN_ON(dev_priv-&amp;gt;mm.shrink_count)
&amp;lt;4&amp;gt; [239.330196] WARNING: CPU: 1 PID: 18570 at drivers/gpu/drm/i915/i915_gem.c:1309 i915_gem_cleanup_early+0x13e/0x150 [i915]
...
&amp;lt;4&amp;gt; [239.330640] RIP: 0010:i915_gem_cleanup_early+0x13e/0x150 [i915]
...
&amp;lt;4&amp;gt; [239.330942] Call Trace:
&amp;lt;4&amp;gt; [239.330944]  &amp;lt;TASK&amp;gt;
&amp;lt;4&amp;gt; [239.330949]  i915_driver_late_release+0x2b/0xa0 [i915]
&amp;lt;4&amp;gt; [239.331202]  i915_driver_release+0x86/0xa0 [i915]
&amp;lt;4&amp;gt; [239.331482]  devm_drm_dev_init_release+0x61/0x90
&amp;lt;4&amp;gt; [239.331494]  devm_action_release+0x15/0x30
&amp;lt;4&amp;gt; [239.331504]  release_nodes+0x3d/0x120
&amp;lt;4&amp;gt; [239.331517]  devres_release_all+0x96/0xd0
&amp;lt;4&amp;gt; [239.331533]  device_unbind_cleanup+0x12/0x80
&amp;lt;4&amp;gt; [239.331543]  device_release_driver_internal+0x23a/0x280
&amp;lt;4&amp;gt; [239.331550]  ? bus_find_device+0xa5/0xe0
&amp;lt;4&amp;gt; [239.331563]  device_driver_detach+0x14/0x20
...
&amp;lt;4&amp;gt; [357.719679] ---[ end trace 0000000000000000 ]---</p>
<p>If the test also unloads the i915 module then that&amp;apos;s followed with:</p>
<p>&amp;lt;3&amp;gt; [357.787478] ===…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-2675"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:26462</id>
    <title>RHSA-2026:26462 — Red Hat Security Advisory: kernel-rt security update</title>
    <updated>2026-10-03T17:31:45.609880+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>kernel: ipv6: use RCU in ip6_xmit() kernel: ipv6: use RCU in ip6_output() kernel: net: use dst_dev_rcu() in sk_setup_caps() kernel: nbd: defer config unlock in nbd_genl_connect kernel: crypto: asymmetric_keys - prevent overflow in asymmetric_key_generate_id kernel: iommu: disable SVA when CONFIG_X86 is set kernel: libceph: make decode_pool() more resilient against corrupted osdmaps kernel: libceph: prevent potential out-of-bounds reads in handle_auth_done() kernel: libceph: replace overzealous BUG_ON in osdmap_apply_incremental() kernel: scsi: target: iscsi: Fix use-after-free in iscsit_dec_conn_usage_count() kernel: netfilter: nf_tables: release flowtable after rcu grace period on error kernel: netfilter: nf_conntrack_h323: check for zero length in DecodeQ931() kernel: netfilter: ip6t_eui64: reject invalid MAC header for all packets kernel: wifi: brcmfmac: validate bsscfg indices in IF events kernel: netfilter: ctnetlink: ensure safe access to master conntrack kernel: xfs: fix freemap adjustments when adding xattrs to leaf blocks kernel: netfilter: xt_tcpmss: check remaining length before reading optlen kernel: mm/page_alloc: clear page-&gt;private in free_pages_prepare() kernel: wifi: mac80211: remove station if connection prep fails kernel: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL kernel: Linux kernel: smb: client: reject userspace cifs.spnego descriptions</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:26462"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:21556</id>
    <title>RLSA-2026:21556 — Important: kernel security update</title>
    <updated>2026-10-03T17:31:45.609932+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:9: kernel</p>
<p>The kernel packages contain the Linux kernel, the core of any Linux operating system.</p>
<p>Security Fix(es):</p>
<p>* kernel: proc: use the same treatment to check proc_lseek as ones for proc_read_iter et.al (CVE-2025-38653)</p>
<p>* kernel: ima: don't clear IMA_DIGSIG flag when setting or removing non-IMA xattr (CVE-2025-68183)</p>
<p>* kernel: nbd: defer config unlock in nbd_genl_connect (CVE-2025-68366)</p>
<p>* kernel: crypto: asymmetric_keys - prevent overflow in asymmetric_key_generate_id (CVE-2025-68724)</p>
<p>* kernel: iommu: disable SVA when CONFIG_X86 is set (CVE-2025-71089)</p>
<p>* kernel: netfilter: nf_tables: release flowtable after rcu grace period on error (CVE-2026-23392)</p>
<p>* kernel: netfilter: nf_conntrack_h323: check for zero length in DecodeQ931() (CVE-2026-23455)</p>
<p>* kernel: Bluetooth: SCO: Fix use-after-free in sco_recv_frame() due to missing sock_hold (CVE-2026-31408)</p>
<p>* kernel: net: sched: act_csum: validate nested VLAN headers (CVE-2026-31684)</p>
<p>* kernel: netfilter: ip6t_eui64: reject invalid MAC header for all packets (CVE-2026-31685)</p>
<p>* kernel: netfilter: nf_conntrack_helper: pass helper to expect cleanup (CVE-2026-43027)</p>
<p>* kernel: Bluetooth: MGMT: validate LTK enc_size on load (CVE-2026-43020)</p>
<p>* kernel: HID: wacom: fix out-of-bounds read in wacom_intuos_bt_irq (CVE-2026-43051)</p>
<p>* kernel: smb: client: validate the whole DACL before rewriting it in cifsacl (CVE-2026-31709)</p>
<p>* kernel: Bluetooth: SCO: fix race conditions in sco_sock_connect() (CVE-2026-43023)</p>
<p>* kernel: wifi: brcmfmac: vali…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:21556"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ssa-019113</id>
    <title>SSA-019113 — SSA-019113: Vulnerabilities in the additional GNU/Linux subsystem of the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1.6</title>
    <updated>2026-10-03T17:31:45.609977+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.6 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant).</p>
<p>Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ssa-019113"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:22521-1</id>
    <title>SUSE-SU-2026:22521-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-03T17:31:45.610217+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:22521-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-43303</id>
    <title>UBUNTU-CVE-2026-43303</title>
    <updated>2026-10-03T17:31:45.610277+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 141 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: mm/page_alloc: clear page-&gt;private in free_pages_prepare() Several subsystems (slub, shmem, ttm, etc.) use page-&gt;private but don't clear it before freeing pages.  When these pages are later allocated as high-order pages and split via split_page(), tail pages retain stale page-&gt;private values. This causes a use-after-free in the swap subsystem.  The swap code uses page-&gt;private to track swap count continuations, assuming freshly allocated pages have page-&gt;private == 0.  When stale values are present, swap_count_continued() incorrectly assumes the continuation list is valid and iterates over uninitialized page-&gt;lru containing LIST_POISON values, causing a crash:   KASAN: maybe wild-memory-access in range [0xdead000000000100-0xdead000000000107]   RIP: 0010:__do_sys_swapoff+0x1151/0x1860 Fix this by clearing page-&gt;private in free_pages_prepare(), ensuring all freed pages have clean state regardless of previous use.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-43303"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1454</id>
    <title>WID-SEC-W-2026-1454 — Linux Kernel: Mehrere Schwachstellen</title>
    <updated>2026-10-03T17:31:45.610475+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen, möglicherweise Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren oder offenzulegen oder einen Denial-of-Service-Zustand zu verursachen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1454"/>
  </entry>
</feed>
