<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T13:39:25.709240+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:70402</id>
    <title>ALSA-2026:70402 — Important: kernel security, bug fix, and enhancement update</title>
    <updated>2026-10-02T13:39:26.035119+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: bpftool, AlmaLinux:8: kernel, AlmaLinux:8: kernel-abi-stablelists, AlmaLinux:8: kernel-core, AlmaLinux:8: kernel-cross-headers, AlmaLinux:8: kernel-debug, AlmaLinux:8: kernel-debug-core, AlmaLinux:8: kernel-debug-devel, AlmaLinux:8: kernel-debug-modules, AlmaLinux:8: kernel-debug-modules-extra and 15 more</p>
<p>The kernel packages contain the Linux kernel, the core of any Linux operating system.</p>
<p>Security Fix(es):</p>
<p>* kernel: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg (CVE-2025-39964)
  * kernel: Linux kernel Bluetooth: Denial of Service via race condition in hidp_session_thread (CVE-2023-54120)
  * kernel: Bluetooth: L2CAP: Fix potential user-after-free (CVE-2023-54214)
  * kernel: Bluetooth: btusb: revert use of devm_kzalloc in btusb (CVE-2025-71082)
  * kernel: Bluetooth: SMP: force responder MITM requirements before building the pairing response (CVE-2026-43334)
  * kernel: iommu/vt-d: Clear Present bit before tearing down PASID entry (CVE-2026-45894)
  * kernel: RDMA/rxe: Validate pad and ICRC before payload_size() in rxe_rcv (CVE-2026-46043)
  * kernel: RDMA/rxe: Reject unknown opcodes before ICRC processing (CVE-2026-46133)
  * kernel: Bluetooth: serialize accept_q access (CVE-2026-52918)
  * kernel: dm cache policy smq: fix missing locks in invalidating cache blocks (CVE-2026-53062)
  * kernel: iommu/amd: Fix clone_alias() to use the original device's devid (CVE-2026-53053)
  * kernel: Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind() (CVE-2026-53256)
  * kernel: Bluetooth: RFCOMM: validate skb length in MCC handlers (CVE-2026-53254)
  * kernel: keys: Pin request_key_auth payload in instantiate paths (CVE-2026-63823)
  * kernel: Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp (CVE-2026-63975)
  * kernel: Bluetooth: HIDP: fi…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:70402"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-45894</id>
    <title>BELL-CVE-2026-45894</title>
    <updated>2026-10-02T13:39:26.035290+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-45894"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0833</id>
    <title>certfr-2026-avi-0833 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de SUSE. Certaines d'entre elles permettent à un at…</title>
    <updated>2026-10-02T13:39:26.035336+00:00</updated>
    <content>certfr-2026-avi-0833</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0833"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-347957</id>
    <title>EUVD-2026-347957</title>
    <updated>2026-10-02T13:39:26.035356+00:00</updated>
    <content>EUVD-2026-347957</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-347957"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-45894</id>
    <title>fkie_cve-2026-45894</title>
    <updated>2026-10-02T13:39:26.035368+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>iommu/vt-d: Clear Present bit before tearing down PASID entry</p>
<p>The Intel VT-d Scalable Mode PASID table entry consists of 512 bits (64
bytes). When tearing down an entry, the current implementation zeros the
entire 64-byte structure immediately using multiple 64-bit writes.</p>
<p>Since the IOMMU hardware may fetch these 64 bytes using multiple
internal transactions (e.g., four 128-bit bursts), updating or zeroing
the entire entry while it is active (P=1) risks a "torn" read. If a
hardware fetch occurs simultaneously with the CPU zeroing the entry, the
hardware could observe an inconsistent state, leading to unpredictable
behavior or spurious faults.</p>
<p>Follow the "Guidance to Software for Invalidations" in the VT-d spec
(Section 6.5.3.3) by implementing the recommended ownership handshake:</p>
<p>1. Clear only the 'Present' (P) bit of the PASID entry.
2. Use a dma_wmb() to ensure the cleared bit is visible to hardware
   before proceeding.
3. Execute the required invalidation sequence (PASID cache, IOTLB, and
   Device-TLB flush) to ensure the hardware has released all cached
   references.
4. Only after the flushes are complete, zero out the remaining fields
   of the PASID entry.</p>
<p>Also, add a dma_wmb() in pasid_set_present() to ensure that all other
fields of the PASID entry are visible to the hardware before the Present
bit is set.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-45894"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-8pm8-q9qq-gqgp</id>
    <title>GHSA-8pm8-q9qq-gqgp</title>
    <updated>2026-10-02T13:39:26.035407+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>iommu/vt-d: Clear Present bit before tearing down PASID entry</p>
<p>The Intel VT-d Scalable Mode PASID table entry consists of 512 bits (64
bytes). When tearing down an entry, the current implementation zeros the
entire 64-byte structure immediately using multiple 64-bit writes.</p>
<p>Since the IOMMU hardware may fetch these 64 bytes using multiple
internal transactions (e.g., four 128-bit bursts), updating or zeroing
the entire entry while it is active (P=1) risks a "torn" read. If a
hardware fetch occurs simultaneously with the CPU zeroing the entry, the
hardware could observe an inconsistent state, leading to unpredictable
behavior or spurious faults.</p>
<p>Follow the "Guidance to Software for Invalidations" in the VT-d spec
(Section 6.5.3.3) by implementing the recommended ownership handshake:</p>
<p>1. Clear only the 'Present' (P) bit of the PASID entry.
2. Use a dma_wmb() to ensure the cleared bit is visible to hardware
   before proceeding.
3. Execute the required invalidation sequence (PASID cache, IOTLB, and
   Device-TLB flush) to ensure the hardware has released all cached
   references.
4. Only after the flushes are complete, zero out the remaining fields
   of the PASID entry.</p>
<p>Also, add a dma_wmb() in pasid_set_present() to ensure that all other
fields of the PASID entry are visible to the hardware before the Present
bit is set.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-8pm8-q9qq-gqgp"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-45894</id>
    <title>msrc_CVE-2026-45894 — iommu/vt-d: Clear Present bit before tearing down PASID entry</title>
    <updated>2026-10-02T13:39:26.035435+00:00</updated>
    <content>msrc_CVE-2026-45894</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-45894"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-2674</id>
    <title>OESA-2026-2674 — kernel security update</title>
    <updated>2026-10-02T13:39:26.035453+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:22.03-LTS-SP4: kernel</p>
<p>The Linux Kernel, the operating system core itself.

Security Fix(es):</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>btrfs: qgroup: fix race between quota disable and quota rescan ioctl</p>
<p>There&amp;apos;s a race between a task disabling quotas and another running the
rescan ioctl that can result in a use-after-free of qgroup records from
the fs_info-&amp;gt;qgroup_tree rbtree.</p>
<p>This happens as follows:</p>
<p>1) Task A enters btrfs_ioctl_quota_rescan() -&amp;gt; btrfs_qgroup_rescan();</p>
<p>2) Task B enters btrfs_quota_disable() and calls
   btrfs_qgroup_wait_for_completion(), which does nothing because at that
   point fs_info-&amp;gt;qgroup_rescan_running is false (it wasn&amp;apos;t set yet by
   task A);</p>
<p>3) Task B calls btrfs_free_qgroup_config() which starts freeing qgroups
   from fs_info-&amp;gt;qgroup_tree without taking the lock fs_info-&amp;gt;qgroup_lock;</p>
<p>4) Task A enters qgroup_rescan_zero_tracking() which starts iterating
   the fs_info-&amp;gt;qgroup_tree tree while holding fs_info-&amp;gt;qgroup_lock,
   but task B is freeing qgroup records from that tree without holding
   the lock, resulting in a use-after-free.</p>
<p>Fix this by taking fs_info-&amp;gt;qgroup_lock at btrfs_free_qgroup_config().
Also at btrfs_qgroup_rescan() don&amp;apos;t start the rescan worker if quotas
were already disabled.(CVE-2025-39759)</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>wifi: wilc1000: avoid buffer overflow in WID string configuration</p>
<p>Fix the following copy overflow warning identi…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-2674"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:21388-1</id>
    <title>openSUSE-SU-2026:21388-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-02T13:39:26.035826+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:21388-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:70402</id>
    <title>RHSA-2026:70402 — Red Hat Security Advisory: kernel security, bug fix, and enhancement update</title>
    <updated>2026-10-02T13:39:26.035976+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>kernel: Linux kernel Bluetooth: Denial of Service via race condition in hidp_session_thread kernel: Bluetooth: L2CAP: Fix potential user-after-free kernel: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg kernel: Bluetooth: btusb: revert use of devm_kzalloc in btusb kernel: Bluetooth: SMP: force responder MITM requirements before building the pairing response kernel: iommu/vt-d: Clear Present bit before tearing down PASID entry kernel: RDMA/rxe: Validate pad and ICRC before payload_size() in rxe_rcv kernel: RDMA/rxe: Reject unknown opcodes before ICRC processing kernel: Bluetooth: serialize accept_q access kernel: iommu/amd: Fix clone_alias() to use the original device's devid kernel: dm cache policy smq: fix missing locks in invalidating cache blocks kernel: Bluetooth: RFCOMM: validate skb length in MCC handlers kernel: Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind() kernel: keys: Pin request_key_auth payload in instantiate paths kernel: Bluetooth: HIDP: fix missing length checks in hidp_input_report() kernel: Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp kernel: nvmet-tcp: check INIT_FAILED before nvmet_req_uninit in digest error path kernel: RDMA/rxe: Fix a use-after-free problem in rxe_mmap kernel: Linux kernel Bluetooth RFCOMM: Denial of Service via use-after-free in set_termios kernel: net/mlx5: Fix MCIA register buffer overflow on 32 dword reads</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:70402"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:70402</id>
    <title>RLSA-2026:70402 — Important: kernel security, bug fix, and enhancement update</title>
    <updated>2026-10-02T13:39:26.036028+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:8: kernel</p>
<p>The kernel packages contain the Linux kernel, the core of any Linux operating system.</p>
<p>Security Fix(es):</p>
<p>* kernel: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg (CVE-2025-39964)</p>
<p>* kernel: Linux kernel Bluetooth: Denial of Service via race condition in hidp_session_thread (CVE-2023-54120)</p>
<p>* kernel: Bluetooth: L2CAP: Fix potential user-after-free (CVE-2023-54214)</p>
<p>* kernel: Bluetooth: btusb: revert use of devm_kzalloc in btusb (CVE-2025-71082)</p>
<p>* kernel: Bluetooth: SMP: force responder MITM requirements before building the pairing response (CVE-2026-43334)</p>
<p>* kernel: iommu/vt-d: Clear Present bit before tearing down PASID entry (CVE-2026-45894)</p>
<p>* kernel: RDMA/rxe: Validate pad and ICRC before payload_size() in rxe_rcv (CVE-2026-46043)</p>
<p>* kernel: RDMA/rxe: Reject unknown opcodes before ICRC processing (CVE-2026-46133)</p>
<p>* kernel: Bluetooth: serialize accept_q access (CVE-2026-52918)</p>
<p>* kernel: dm cache policy smq: fix missing locks in invalidating cache blocks (CVE-2026-53062)</p>
<p>* kernel: iommu/amd: Fix clone_alias() to use the original device's devid (CVE-2026-53053)</p>
<p>* kernel: Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind() (CVE-2026-53256)</p>
<p>* kernel: Bluetooth: RFCOMM: validate skb length in MCC handlers (CVE-2026-53254)</p>
<p>* kernel: keys: Pin request_key_auth payload in instantiate paths (CVE-2026-63823)</p>
<p>* kernel: Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp (CVE-2026-63975)</p>
<p>* kernel: Bluetooth: HIDP: fix missing length chec…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:70402"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:22433-1</id>
    <title>SUSE-SU-2026:22433-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-02T13:39:26.036073+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:22433-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-45894</id>
    <title>UBUNTU-CVE-2026-45894</title>
    <updated>2026-10-02T13:39:26.036171+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:Pro:18.04:LTS: linux-aws-5.4, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:Pro:18.04:LTS: linux-azure-5.4, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3 and 206 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Clear Present bit before tearing down PASID entry The Intel VT-d Scalable Mode PASID table entry consists of 512 bits (64 bytes). When tearing down an entry, the current implementation zeros the entire 64-byte structure immediately using multiple 64-bit writes. Since the IOMMU hardware may fetch these 64 bytes using multiple internal transactions (e.g., four 128-bit bursts), updating or zeroing the entire entry while it is active (P=1) risks a "torn" read. If a hardware fetch occurs simultaneously with the CPU zeroing the entry, the hardware could observe an inconsistent state, leading to unpredictable behavior or spurious faults. Follow the "Guidance to Software for Invalidations" in the VT-d spec (Section 6.5.3.3) by implementing the recommended ownership handshake: 1. Clear only the 'Present' (P) bit of the PASID entry. 2. Use a dma_wmb() to ensure the cleared bit is visible to hardware    before proceeding. 3. Execute the required invalidation sequence (PASID cache, IOTLB, and    Device-TLB flush) to ensure the hardware has released all cached    references. 4. Only after the flushes are complete, zero out the remaining fields    of the PASID entry. Also, add a dma_wmb() in pasid_set_present() to ensure that all other fields of the PASID entry are visible to the hardware before the Present bit is set.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-45894"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1700</id>
    <title>WID-SEC-W-2026-1700 — Linux Kernel: Mehrere Schwachstellen</title>
    <updated>2026-10-02T13:39:26.036499+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen oder andere nicht näher spezifizierte Auswirkungen zu erzielen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1700"/>
  </entry>
</feed>
