<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T16:15:01.745261+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-08879</id>
    <title>bdu:2026-08879</title>
    <updated>2026-10-02T16:15:04.037356+00:00</updated>
    <content>bdu:2026-08879</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-08879"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-43503</id>
    <title>BELL-CVE-2026-43503</title>
    <updated>2026-10-02T16:15:04.037441+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-43503"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0666</id>
    <title>certfr-2026-avi-0666 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de Debian. Certaines d'entre elles permettent à un…</title>
    <updated>2026-10-02T16:15:04.037477+00:00</updated>
    <content>certfr-2026-avi-0666</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0666"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-357978</id>
    <title>EUVD-2026-357978</title>
    <updated>2026-10-02T16:15:04.037496+00:00</updated>
    <content>EUVD-2026-357978</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-357978"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-43503</id>
    <title>fkie_cve-2026-43503</title>
    <updated>2026-10-02T16:15:04.037508+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>net: skbuff: propagate shared-frag marker through frag-transfer helpers</p>
<p>Two frag-transfer helpers (__pskb_copy_fclone() and skb_shift()) fail
to propagate the SKBFL_SHARED_FRAG bit in skb_shinfo()-&gt;flags when
moving frags from source to destination.  __pskb_copy_fclone() defers
the rest of the shinfo metadata to skb_copy_header() after copying
frag descriptors, but that helper only carries over gso_{size,segs,
type} and never touches skb_shinfo()-&gt;flags; skb_shift() moves frag
descriptors directly and leaves flags untouched.  As a result, the
destination skb keeps a reference to the same externally-owned or
page-cache-backed pages while reporting skb_has_shared_frag() as
false.</p>
<p>The mismatch is harmful in any in-place writer that uses
skb_has_shared_frag() to decide whether shared pages must be detoured
through skb_cow_data().  ESP input is one such writer (esp4.c,
esp6.c), and a single nft 'dup to &lt;local&gt;' rule -- or any other
nf_dup_ipv4() / xt_TEE caller -- is enough to land a pskb_copy()'d
skb in esp_input() with the marker stripped, letting an unprivileged
user write into the page cache of a root-owned read-only file via
authencesn-ESN stray writes.</p>
<p>Set SKBFL_SHARED_FRAG on the destination whenever frag descriptors
were actually moved from the source.  skb_copy() and skb_copy_expand()
share skb_copy_header() too but linearize all paged data into freshly
allocated head storage and emerge with nr_frags…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-43503"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-494p-q444-9xf7</id>
    <title>GHSA-494p-q444-9xf7</title>
    <updated>2026-10-02T16:15:04.037556+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>net: skbuff: propagate shared-frag marker through frag-transfer helpers</p>
<p>Two frag-transfer helpers (__pskb_copy_fclone() and skb_shift()) fail
to propagate the SKBFL_SHARED_FRAG bit in skb_shinfo()-&gt;flags when
moving frags from source to destination.  __pskb_copy_fclone() defers
the rest of the shinfo metadata to skb_copy_header() after copying
frag descriptors, but that helper only carries over gso_{size,segs,
type} and never touches skb_shinfo()-&gt;flags; skb_shift() moves frag
descriptors directly and leaves flags untouched.  As a result, the
destination skb keeps a reference to the same externally-owned or
page-cache-backed pages while reporting skb_has_shared_frag() as
false.</p>
<p>The mismatch is harmful in any in-place writer that uses
skb_has_shared_frag() to decide whether shared pages must be detoured
through skb_cow_data().  ESP input is one such writer (esp4.c,
esp6.c), and a single nft 'dup to &lt;local&gt;' rule -- or any other
nf_dup_ipv4() / xt_TEE caller -- is enough to land a pskb_copy()'d
skb in esp_input() with the marker stripped, letting an unprivileged
user write into the page cache of a root-owned read-only file via
authencesn-ESN stray writes.</p>
<p>Set SKBFL_SHARED_FRAG on the destination whenever frag descriptors
were actually moved from the source.  skb_copy() and skb_copy_expand()
share skb_copy_header() too but linearize all paged data into freshly
allocated head storage and emerge with nr_frags…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-494p-q444-9xf7"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-43503</id>
    <title>msrc_CVE-2026-43503 — net: skbuff: propagate shared-frag marker through frag-transfer helpers</title>
    <updated>2026-10-02T16:15:04.037592+00:00</updated>
    <content>msrc_CVE-2026-43503</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-43503"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-2496</id>
    <title>OESA-2026-2496 — kernel security update</title>
    <updated>2026-10-02T16:15:04.037609+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP4: kernel</p>
<p>The Linux Kernel, the operating system core itself.

Security Fix(es):</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>Revert &amp;quot;smb: client: fix TCP timers deadlock after rmmod&amp;quot;</p>
<p>This reverts commit e9f2517a3e18a54a3943c098d2226b245d488801.</p>
<p>Commit e9f2517a3e18 (&amp;quot;smb: client: fix TCP timers deadlock after
rmmod&amp;quot;) is intended to fix a null-ptr-deref in LOCKDEP, which is
mentioned as CVE-2024-54680, but is actually did not fix anything;
The issue can be reproduced on top of it. [0]</p>
<p>Also, it reverted the change by commit ef7134c7fc48 (&amp;quot;smb: client:
Fix use-after-free of network namespace.&amp;quot;) and introduced a real
issue by reviving the kernel TCP socket.</p>
<p>When a reconnect happens for a CIFS connection, the socket state
transitions to FIN_WAIT_1.  Then, inet_csk_clear_xmit_timers_sync()
in tcp_close() stops all timers for the socket.</p>
<p>If an incoming FIN packet is lost, the socket will stay at FIN_WAIT_1
forever, and such sockets could be leaked up to net.ipv4.tcp_max_orphans.</p>
<p>Usually, FIN can be retransmitted by the peer, but if the peer aborts
the connection, the issue comes into reality.</p>
<p>I warned about this privately by pointing out the exact report [1],
but the bogus fix was finally merged.</p>
<p>So, we should not stop the timers to finally kill the connection on
our side in that case, meaning we must not use a kernel socket for
TCP whose sk-&amp;gt;sk_net_refcnt is 0.</p>
<p>The kernel socket does not have a reference to its netns to ma…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-2496"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10954-1</id>
    <title>openSUSE-SU-2026:10954-1 — kernel-devel-7.0.11-1.1 on GA media</title>
    <updated>2026-10-02T16:15:04.037674+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>kernel-devel-7.0.11-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:10954-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:19521</id>
    <title>RHSA-2026:19521 — Red Hat Security Advisory: kernel security update</title>
    <updated>2026-10-02T16:15:04.037842+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>kernel: Linux kernel: RDMA/rxe use-after-free vulnerability leading to potential arbitrary code execution kernel: ALSA: aloop: Fix racy access at PCM trigger kernel: Linux kernel: Denial of service and memory corruption in RDMA umad kernel: Linux kernel KVM: Privilege escalation or denial of service due to improper shadow page table entry handling kernel: Linux kernel: Use-after-free in bonding driver leads to denial of service kernel: can: raw: fix ro-&gt;uniq use-after-free in raw_rcv() kernel: net: skbuff: propagate shared-frag marker through frag-transfer helpers kernel: "Fragnesia" is a variant of Dirty Frag vulnerability in the ESP/XFRM leading to Local Privilege Escalation (LPE) vulnerability in the Linux kernel kernel: Read root-owned files as an unprivileged user</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:19521"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:2111-1</id>
    <title>SUSE-SU-2026:2111-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-02T16:15:04.037877+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:2111-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-43503</id>
    <title>UBUNTU-CVE-2026-43503</title>
    <updated>2026-10-02T16:15:04.037931+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: linux, Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe and 244 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: net: skbuff: propagate shared-frag marker through frag-transfer helpers Two frag-transfer helpers (__pskb_copy_fclone() and skb_shift()) fail to propagate the SKBFL_SHARED_FRAG bit in skb_shinfo()-&gt;flags when moving frags from source to destination.  __pskb_copy_fclone() defers the rest of the shinfo metadata to skb_copy_header() after copying frag descriptors, but that helper only carries over gso_{size,segs, type} and never touches skb_shinfo()-&gt;flags; skb_shift() moves frag descriptors directly and leaves flags untouched.  As a result, the destination skb keeps a reference to the same externally-owned or page-cache-backed pages while reporting skb_has_shared_frag() as false. The mismatch is harmful in any in-place writer that uses skb_has_shared_frag() to decide whether shared pages must be detoured through skb_cow_data().  ESP input is one such writer (esp4.c, esp6.c), and a single nft 'dup to &lt;local&gt;' rule -- or any other nf_dup_ipv4() / xt_TEE caller -- is enough to land a pskb_copy()'d skb in esp_input() with the marker stripped, letting an unprivileged user write into the page cache of a root-owned read-only file via authencesn-ESN stray writes. Set SKBFL_SHARED_FRAG on the destination whenever frag descriptors were actually moved from the source.  skb_copy() and skb_copy_expand() share skb_copy_header() too but linearize all paged data into freshly allocated head storage and emerge with nr_frags ==…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-43503"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2102</id>
    <title>WID-SEC-W-2026-2102 — Linux Kernel: Schwachstelle ermöglicht Erlangen von Administratorrechten</title>
    <updated>2026-10-02T16:15:04.038235+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein lokaler Angreifer kann eine Schwachstelle in Linux Kernel ausnutzen, um Administratorrechte zu erlangen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2102"/>
  </entry>
</feed>
