<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T14:45:00.248925+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:36348</id>
    <title>ALSA-2026:36348 — Important: kernel-rt security, bug fix, and enhancement update</title>
    <updated>2026-10-03T14:45:00.728217+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: kernel-rt, AlmaLinux:8: kernel-rt-core, AlmaLinux:8: kernel-rt-debug, AlmaLinux:8: kernel-rt-debug-core, AlmaLinux:8: kernel-rt-debug-devel, AlmaLinux:8: kernel-rt-debug-modules, AlmaLinux:8: kernel-rt-debug-modules-extra, AlmaLinux:8: kernel-rt-devel, AlmaLinux:8: kernel-rt-modules, AlmaLinux:8: kernel-rt-modules-extra</p>
<p>The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements.</p>
<p>Security Fix(es):</p>
<p>* kernel: tcp: fix potential race in tcp_v6_syn_recv_sock() (CVE-2026-43198)
  * kernel: netfilter: nfnetlink_cthelper: fix OOB read in nfnl_cthelper_dump_table() (CVE-2026-43450)
  * kernel: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (CVE-2026-46227)
  * kernel: drm/gem: Fix inconsistent plane dimension calculation in drm_gem_fb_init_with_funcs() (CVE-2026-46209)
  * kernel: procfs: fix missing RCU protection when reading real_parent in do_task_stat() (CVE-2026-46259)
  * kernel: Arm Processors: Privilege escalation or information disclosure via writes to higher exception level resources (CVE-2025-10263)</p>
<p>Bug Fix(es) and Enhancement(s):</p>
<p>* kernel panic at trailing_symlink while the task wdavdaemon runs even after 4c4f7c19b3c7 (JIRA:AlmaLinux-152759)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:36348"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-43450</id>
    <title>BELL-CVE-2026-43450</title>
    <updated>2026-10-03T14:45:00.728332+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-43450"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0696</id>
    <title>certfr-2026-avi-0696 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de Debian LTS. Certaines d'entre elles permettent à…</title>
    <updated>2026-10-03T14:45:00.728378+00:00</updated>
    <content>certfr-2026-avi-0696</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0696"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-315953</id>
    <title>EUVD-2026-315953</title>
    <updated>2026-10-03T14:45:00.728417+00:00</updated>
    <content>EUVD-2026-315953</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-315953"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-43450</id>
    <title>fkie_cve-2026-43450</title>
    <updated>2026-10-03T14:45:00.728441+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>netfilter: nfnetlink_cthelper: fix OOB read in nfnl_cthelper_dump_table()</p>
<p>nfnl_cthelper_dump_table() has a 'goto restart' that jumps to a label
inside the for loop body.  When the "last" helper saved in cb-&gt;args[1]
is deleted between dump rounds, every entry fails the (cur != last)
check, so cb-&gt;args[1] is never cleared.  The for loop finishes with
cb-&gt;args[0] == nf_ct_helper_hsize, and the 'goto restart' jumps back
into the loop body bypassing the bounds check, causing an 8-byte
out-of-bounds read on nf_ct_helper_hash[nf_ct_helper_hsize].</p>
<p>The 'goto restart' block was meant to re-traverse the current bucket
when "last" is no longer found, but it was placed after the for loop
instead of inside it.  Move the block into the for loop body so that
the restart only occurs while cb-&gt;args[0] is still within bounds.</p>
<p>BUG: KASAN: slab-out-of-bounds in nfnl_cthelper_dump_table+0x9f/0x1b0
 Read of size 8 at addr ffff888104ca3000 by task poc_cthelper/131
 Call Trace:
  nfnl_cthelper_dump_table+0x9f/0x1b0
  netlink_dump+0x333/0x880
  netlink_recvmsg+0x3e2/0x4b0
  sock_recvmsg+0xde/0xf0
  __sys_recvfrom+0x150/0x200
  __x64_sys_recvfrom+0x76/0x90
  do_syscall_64+0xc3/0x6e0</p>
<p>Allocated by task 1:
  __kvmalloc_node_noprof+0x21b/0x700
  nf_ct_alloc_hashtable+0x65/0xd0
  nf_conntrack_helper_init+0x21/0x60
  nf_conntrack_init_start+0x18d/0x300
  nf_conntrack_standalone_init+0x12/0xc0</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-43450"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-4jv3-xpmj-f4vf</id>
    <title>GHSA-4jv3-xpmj-f4vf</title>
    <updated>2026-10-03T14:45:00.728493+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>netfilter: nfnetlink_cthelper: fix OOB read in nfnl_cthelper_dump_table()</p>
<p>nfnl_cthelper_dump_table() has a 'goto restart' that jumps to a label
inside the for loop body.  When the "last" helper saved in cb-&gt;args[1]
is deleted between dump rounds, every entry fails the (cur != last)
check, so cb-&gt;args[1] is never cleared.  The for loop finishes with
cb-&gt;args[0] == nf_ct_helper_hsize, and the 'goto restart' jumps back
into the loop body bypassing the bounds check, causing an 8-byte
out-of-bounds read on nf_ct_helper_hash[nf_ct_helper_hsize].</p>
<p>The 'goto restart' block was meant to re-traverse the current bucket
when "last" is no longer found, but it was placed after the for loop
instead of inside it.  Move the block into the for loop body so that
the restart only occurs while cb-&gt;args[0] is still within bounds.</p>
<p>BUG: KASAN: slab-out-of-bounds in nfnl_cthelper_dump_table+0x9f/0x1b0
 Read of size 8 at addr ffff888104ca3000 by task poc_cthelper/131
 Call Trace:
  nfnl_cthelper_dump_table+0x9f/0x1b0
  netlink_dump+0x333/0x880
  netlink_recvmsg+0x3e2/0x4b0
  sock_recvmsg+0xde/0xf0
  __sys_recvfrom+0x150/0x200
  __x64_sys_recvfrom+0x76/0x90
  do_syscall_64+0xc3/0x6e0</p>
<p>Allocated by task 1:
  __kvmalloc_node_noprof+0x21b/0x700
  nf_ct_alloc_hashtable+0x65/0xd0
  nf_conntrack_helper_init+0x21/0x60
  nf_conntrack_init_start+0x18d/0x300
  nf_conntrack_standalone_init+0x12/0xc0</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-4jv3-xpmj-f4vf"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-2674</id>
    <title>OESA-2026-2674 — kernel security update</title>
    <updated>2026-10-03T14:45:00.728523+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:22.03-LTS-SP4: kernel</p>
<p>The Linux Kernel, the operating system core itself.

Security Fix(es):</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>btrfs: qgroup: fix race between quota disable and quota rescan ioctl</p>
<p>There&amp;apos;s a race between a task disabling quotas and another running the
rescan ioctl that can result in a use-after-free of qgroup records from
the fs_info-&amp;gt;qgroup_tree rbtree.</p>
<p>This happens as follows:</p>
<p>1) Task A enters btrfs_ioctl_quota_rescan() -&amp;gt; btrfs_qgroup_rescan();</p>
<p>2) Task B enters btrfs_quota_disable() and calls
   btrfs_qgroup_wait_for_completion(), which does nothing because at that
   point fs_info-&amp;gt;qgroup_rescan_running is false (it wasn&amp;apos;t set yet by
   task A);</p>
<p>3) Task B calls btrfs_free_qgroup_config() which starts freeing qgroups
   from fs_info-&amp;gt;qgroup_tree without taking the lock fs_info-&amp;gt;qgroup_lock;</p>
<p>4) Task A enters qgroup_rescan_zero_tracking() which starts iterating
   the fs_info-&amp;gt;qgroup_tree tree while holding fs_info-&amp;gt;qgroup_lock,
   but task B is freeing qgroup records from that tree without holding
   the lock, resulting in a use-after-free.</p>
<p>Fix this by taking fs_info-&amp;gt;qgroup_lock at btrfs_free_qgroup_config().
Also at btrfs_qgroup_rescan() don&amp;apos;t start the rescan worker if quotas
were already disabled.(CVE-2025-39759)</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>wifi: wilc1000: avoid buffer overflow in WID string configuration</p>
<p>Fix the following copy overflow warning identi…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-2674"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:21388-1</id>
    <title>openSUSE-SU-2026:21388-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-03T14:45:00.729026+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:21388-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:36348</id>
    <title>RHSA-2026:36348 — Red Hat Security Advisory: kernel-rt security, bug fix, and enhancement update</title>
    <updated>2026-10-03T14:45:00.729195+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>kernel: Arm Processors: Privilege escalation or information disclosure via writes to higher exception level resources kernel: tcp: fix potential race in tcp_v6_syn_recv_sock() kernel: netfilter: nfnetlink_cthelper: fix OOB read in nfnl_cthelper_dump_table() kernel: drm/gem: Fix inconsistent plane dimension calculation in drm_gem_fb_init_with_funcs() kernel: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL kernel: procfs: fix missing RCU protection when reading real_parent in do_task_stat()</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:36348"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:51035</id>
    <title>RLSA-2026:51035 — Moderate: kernel security, bug fix, and enhancement update</title>
    <updated>2026-10-03T14:45:00.729224+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:9: kernel</p>
<p>The kernel packages contain the Linux kernel, the core of any Linux operating system.</p>
<p>Security Fix(es):</p>
<p>* kernel: futex: Fix UaF between futex_key_to_node_opt() and vma_replace_policy() (CVE-2026-23415)</p>
<p>* kernel: netfilter: nfnetlink_cthelper: fix OOB read in nfnl_cthelper_dump_table() (CVE-2026-43450)</p>
<p>Bug Fix(es) and Enhancement(s):</p>
<p>* kernel panics caused by NULL pointer dereferences within octeon_ep_vf [rhel-9.8.z] (JIRA:Rocky Linux-186331)</p>
<p>* [Rocky Linux 9.4] Kernel memory reclaim bug  [rhel-9.8.z] (JIRA:Rocky Linux-211058)</p>
<p>* Bond network interface is not coming up with MTU 9000 while vPMEM is enabled [rhel-9.8.z] (JIRA:Rocky Linux-215575)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:51035"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:22742-1</id>
    <title>SUSE-SU-2026:22742-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-03T14:45:00.729256+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:22742-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-43450</id>
    <title>UBUNTU-CVE-2026-43450</title>
    <updated>2026-10-03T14:45:00.729416+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: linux, Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe and 232 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: netfilter: nfnetlink_cthelper: fix OOB read in nfnl_cthelper_dump_table() nfnl_cthelper_dump_table() has a 'goto restart' that jumps to a label inside the for loop body.  When the "last" helper saved in cb-&gt;args[1] is deleted between dump rounds, every entry fails the (cur != last) check, so cb-&gt;args[1] is never cleared.  The for loop finishes with cb-&gt;args[0] == nf_ct_helper_hsize, and the 'goto restart' jumps back into the loop body bypassing the bounds check, causing an 8-byte out-of-bounds read on nf_ct_helper_hash[nf_ct_helper_hsize]. The 'goto restart' block was meant to re-traverse the current bucket when "last" is no longer found, but it was placed after the for loop instead of inside it.  Move the block into the for loop body so that the restart only occurs while cb-&gt;args[0] is still within bounds.  BUG: KASAN: slab-out-of-bounds in nfnl_cthelper_dump_table+0x9f/0x1b0  Read of size 8 at addr ffff888104ca3000 by task poc_cthelper/131  Call Trace:   nfnl_cthelper_dump_table+0x9f/0x1b0   netlink_dump+0x333/0x880   netlink_recvmsg+0x3e2/0x4b0   sock_recvmsg+0xde/0xf0   __sys_recvfrom+0x150/0x200   __x64_sys_recvfrom+0x76/0x90   do_syscall_64+0xc3/0x6e0  Allocated by task 1:   __kvmalloc_node_noprof+0x21b/0x700   nf_ct_alloc_hashtable+0x65/0xd0   nf_conntrack_helper_init+0x21/0x60   nf_conntrack_init_start+0x18d/0x300   nf_conntrack_standalone_init+0x12/0xc0</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-43450"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1454</id>
    <title>WID-SEC-W-2026-1454 — Linux Kernel: Mehrere Schwachstellen</title>
    <updated>2026-10-03T14:45:00.729734+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen, möglicherweise Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren oder offenzulegen oder einen Denial-of-Service-Zustand zu verursachen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1454"/>
  </entry>
</feed>
