<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T11:41:33.333655+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:36018</id>
    <title>ALSA-2026:36018 — Important: kernel security, bug fix, and enhancement update</title>
    <updated>2026-10-02T11:41:33.655911+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:9: kernel, AlmaLinux:9: kernel-64k, AlmaLinux:9: kernel-64k-core, AlmaLinux:9: kernel-64k-debug, AlmaLinux:9: kernel-64k-debug-core, AlmaLinux:9: kernel-64k-debug-devel, AlmaLinux:9: kernel-64k-debug-devel-matched, AlmaLinux:9: kernel-64k-debug-modules, AlmaLinux:9: kernel-64k-debug-modules-core, AlmaLinux:9: kernel-64k-debug-modules-extra and 64 more</p>
<p>The kernel packages contain the Linux kernel, the core of any Linux operating system.</p>
<p>Security Fix(es):</p>
<p>* kernel: fs/smb/client: fix out-of-bounds read in cifs_sanitize_prepath (CVE-2026-43112)
  * kernel: net: mana: Fix double destroy_workqueue on service rescan PCI path (CVE-2026-43276)
  * kernel: Linux kernel: Use-After-Free in net/gro due to improper handling of zerocopy skbs (CVE-2026-46323)
  * kernel: xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete (CVE-2026-46116)
  * kernel: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (CVE-2026-46227)
  * kernel: drm/gem: Fix inconsistent plane dimension calculation in drm_gem_fb_init_with_funcs() (CVE-2026-46209)
  * kernel: smb/client: fix out-of-bounds read in smb2_compound_op() (CVE-2026-46155)
  * kernel: netfilter: nft_inner: Fix IPv6 inner_thoff desync (CVE-2026-46244)
  * kernel: procfs: fix missing RCU protection when reading real_parent in do_task_stat() (CVE-2026-46259)
  * kernel: Arm Processors: Privilege escalation or information disclosure via writes to higher exception level resources (CVE-2025-10263)
  * kernel: KVM: arm64: vgic-its: Drop the translation cache reference only for the erased entry (CVE-2026-46316)</p>
<p>Bug Fix(es) and Enhancement(s):</p>
<p>* WARNING at drivers/gpu/drm/nouveau/nvkm/subdev/gsp/r535.c:1585 r535_gsp_fini+0x2fb/0x310 [nouveau] [almalinux-9.8.z] (JIRA:AlmaLinux-160966)</p>
<p>For more details about the security issue(s), including the impact, a…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:36018"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-11328</id>
    <title>bdu:2026-11328</title>
    <updated>2026-10-02T11:41:33.656106+00:00</updated>
    <content>bdu:2026-11328</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-11328"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-46116</id>
    <title>BELL-CVE-2026-46116</title>
    <updated>2026-10-02T11:41:33.656126+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-46116"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0731</id>
    <title>certfr-2026-avi-0731 — De multiples vulnérabilités ont été découvertes dans les produits Microsoft. Certaines d'entre elles permettent à un at…</title>
    <updated>2026-10-02T11:41:33.656149+00:00</updated>
    <content>certfr-2026-avi-0731</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0731"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/essa-2026:0162</id>
    <title>ESSA-2026:0162 — Important: kernel security, bug fix, and enhancement update</title>
    <updated>2026-10-02T11:41:33.656165+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Important: kernel security, bug fix, and enhancement update</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/essa-2026:0162"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-368461</id>
    <title>EUVD-2026-368461</title>
    <updated>2026-10-02T11:41:33.656190+00:00</updated>
    <content>EUVD-2026-368461</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-368461"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-46116</id>
    <title>fkie_cve-2026-46116</title>
    <updated>2026-10-02T11:41:33.656202+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete</p>
<p>KASAN reproduces a slab-use-after-free in __xfrm_state_delete()'s
hlist_del_rcu calls under syzkaller load on linux-6.12.y stable
(reproduced on 6.12.47, also reachable via the same code path on
torvalds/master and on the ipsec tree). Nine unique signatures cluster
in the xfrm_state lifecycle, the load-bearing one being:</p>
<p>BUG: KASAN: slab-use-after-free in __hlist_del include/linux/list.h:990 [inline]
  BUG: KASAN: slab-use-after-free in hlist_del_rcu include/linux/rculist.h:516 [inline]
  BUG: KASAN: slab-use-after-free in __xfrm_state_delete net/xfrm/xfrm_state.c
  Write of size 8 at addr ffff8881198bcb70 by task kworker/u8:9/435</p>
<p>Workqueue: netns cleanup_net
  Call Trace:
   __hlist_del / hlist_del_rcu
   __xfrm_state_delete
   xfrm_state_delete
   xfrm_state_flush
   xfrm_state_fini
   ops_exit_list
   cleanup_net</p>
<p>The other observed signatures hit the same slab object from
__xfrm_state_lookup, xfrm_alloc_spi, __xfrm_state_insert and an OOB
write variant of __xfrm_state_delete, all on the byseq/byspi
hash chains.</p>
<p>__xfrm_state_delete() guards its byseq and byspi unhashes with
value-based predicates:</p>
<p>if (x-&gt;km.seq)
		hlist_del_rcu(&amp;x-&gt;byseq);
	if (x-&gt;id.spi)
		hlist_del_rcu(&amp;x-&gt;byspi);</p>
<p>while everywhere else in the file (e.g. state_cache, state_cache_input)
the safer hlist_unhashed() check is used. xfrm_alloc_spi() sets
x-&gt;id.spi = n…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-46116"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-96hg-7p79-ggx2</id>
    <title>GHSA-96hg-7p79-ggx2</title>
    <updated>2026-10-02T11:41:33.656258+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete</p>
<p>KASAN reproduces a slab-use-after-free in __xfrm_state_delete()'s
hlist_del_rcu calls under syzkaller load on linux-6.12.y stable
(reproduced on 6.12.47, also reachable via the same code path on
torvalds/master and on the ipsec tree). Nine unique signatures cluster
in the xfrm_state lifecycle, the load-bearing one being:</p>
<p>BUG: KASAN: slab-use-after-free in __hlist_del include/linux/list.h:990 [inline]
  BUG: KASAN: slab-use-after-free in hlist_del_rcu include/linux/rculist.h:516 [inline]
  BUG: KASAN: slab-use-after-free in __xfrm_state_delete net/xfrm/xfrm_state.c
  Write of size 8 at addr ffff8881198bcb70 by task kworker/u8:9/435</p>
<p>Workqueue: netns cleanup_net
  Call Trace:
   __hlist_del / hlist_del_rcu
   __xfrm_state_delete
   xfrm_state_delete
   xfrm_state_flush
   xfrm_state_fini
   ops_exit_list
   cleanup_net</p>
<p>The other observed signatures hit the same slab object from
__xfrm_state_lookup, xfrm_alloc_spi, __xfrm_state_insert and an OOB
write variant of __xfrm_state_delete, all on the byseq/byspi
hash chains.</p>
<p>__xfrm_state_delete() guards its byseq and byspi unhashes with
value-based predicates:</p>
<p>if (x-&gt;km.seq)
		hlist_del_rcu(&amp;x-&gt;byseq);
	if (x-&gt;id.spi)
		hlist_del_rcu(&amp;x-&gt;byspi);</p>
<p>while everywhere else in the file (e.g. state_cache, state_cache_input)
the safer hlist_unhashed() check is used. xfrm_alloc_spi() sets
x-&gt;id.spi = n…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-96hg-7p79-ggx2"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-46116</id>
    <title>msrc_CVE-2026-46116 — xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete</title>
    <updated>2026-10-02T11:41:33.656298+00:00</updated>
    <content>msrc_CVE-2026-46116</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-46116"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-2674</id>
    <title>OESA-2026-2674 — kernel security update</title>
    <updated>2026-10-02T11:41:33.656314+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:22.03-LTS-SP4: kernel</p>
<p>The Linux Kernel, the operating system core itself.

Security Fix(es):</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>btrfs: qgroup: fix race between quota disable and quota rescan ioctl</p>
<p>There&amp;apos;s a race between a task disabling quotas and another running the
rescan ioctl that can result in a use-after-free of qgroup records from
the fs_info-&amp;gt;qgroup_tree rbtree.</p>
<p>This happens as follows:</p>
<p>1) Task A enters btrfs_ioctl_quota_rescan() -&amp;gt; btrfs_qgroup_rescan();</p>
<p>2) Task B enters btrfs_quota_disable() and calls
   btrfs_qgroup_wait_for_completion(), which does nothing because at that
   point fs_info-&amp;gt;qgroup_rescan_running is false (it wasn&amp;apos;t set yet by
   task A);</p>
<p>3) Task B calls btrfs_free_qgroup_config() which starts freeing qgroups
   from fs_info-&amp;gt;qgroup_tree without taking the lock fs_info-&amp;gt;qgroup_lock;</p>
<p>4) Task A enters qgroup_rescan_zero_tracking() which starts iterating
   the fs_info-&amp;gt;qgroup_tree tree while holding fs_info-&amp;gt;qgroup_lock,
   but task B is freeing qgroup records from that tree without holding
   the lock, resulting in a use-after-free.</p>
<p>Fix this by taking fs_info-&amp;gt;qgroup_lock at btrfs_free_qgroup_config().
Also at btrfs_qgroup_rescan() don&amp;apos;t start the rescan worker if quotas
were already disabled.(CVE-2025-39759)</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>wifi: wilc1000: avoid buffer overflow in WID string configuration</p>
<p>Fix the following copy overflow warning identi…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-2674"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:39180</id>
    <title>RHSA-2026:39180 — Red Hat Security Advisory: kernel-rt security update</title>
    <updated>2026-10-02T11:41:33.656686+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>kernel: net: bridge: use a stable FDB dst snapshot in RCU readers kernel: xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete kernel: XFS data corruption using reflink</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:39180"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:36018</id>
    <title>RLSA-2026:36018 — Important: kernel security, bug fix, and enhancement update</title>
    <updated>2026-10-02T11:41:33.656709+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:9: kernel</p>
<p>The kernel packages contain the Linux kernel, the core of any Linux operating system.</p>
<p>Security Fix(es):</p>
<p>* kernel: fs/smb/client: fix out-of-bounds read in cifs_sanitize_prepath (CVE-2026-43112)</p>
<p>* kernel: net: mana: Fix double destroy_workqueue on service rescan PCI path (CVE-2026-43276)</p>
<p>* kernel: Linux kernel: Use-After-Free in net/gro due to improper handling of zerocopy skbs (CVE-2026-46323)</p>
<p>* kernel: xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete (CVE-2026-46116)</p>
<p>* kernel: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (CVE-2026-46227)</p>
<p>* kernel: drm/gem: Fix inconsistent plane dimension calculation in drm_gem_fb_init_with_funcs() (CVE-2026-46209)</p>
<p>* kernel: smb/client: fix out-of-bounds read in smb2_compound_op() (CVE-2026-46155)</p>
<p>* kernel: netfilter: nft_inner: Fix IPv6 inner_thoff desync (CVE-2026-46244)</p>
<p>* kernel: procfs: fix missing RCU protection when reading real_parent in do_task_stat() (CVE-2026-46259)</p>
<p>* kernel: Arm Processors: Privilege escalation or information disclosure via writes to higher exception level resources (CVE-2025-10263)</p>
<p>* kernel: KVM: arm64: vgic-its: Drop the translation cache reference only for the erased entry (CVE-2026-46316)</p>
<p>Bug Fix(es) and Enhancement(s):</p>
<p>* WARNING at drivers/gpu/drm/nouveau/nvkm/subdev/gsp/r535.c:1585 r535_gsp_fini+0x2fb/0x310 [nouveau] [rhel-9.8.z] (JIRA:Rocky Linux-160966)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgme…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:36018"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ssa-019113</id>
    <title>SSA-019113 — SSA-019113: Vulnerabilities in the additional GNU/Linux subsystem of the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1.6</title>
    <updated>2026-10-02T11:41:33.656748+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.6 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant).</p>
<p>Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ssa-019113"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:22521-1</id>
    <title>SUSE-SU-2026:22521-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-02T11:41:33.656965+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:22521-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-46116</id>
    <title>UBUNTU-CVE-2026-46116</title>
    <updated>2026-10-02T11:41:33.657022+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: linux, Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe and 253 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete KASAN reproduces a slab-use-after-free in __xfrm_state_delete()'s hlist_del_rcu calls under syzkaller load on linux-6.12.y stable (reproduced on 6.12.47, also reachable via the same code path on torvalds/master and on the ipsec tree). Nine unique signatures cluster in the xfrm_state lifecycle, the load-bearing one being:   BUG: KASAN: slab-use-after-free in __hlist_del include/linux/list.h:990 [inline]   BUG: KASAN: slab-use-after-free in hlist_del_rcu include/linux/rculist.h:516 [inline]   BUG: KASAN: slab-use-after-free in __xfrm_state_delete net/xfrm/xfrm_state.c   Write of size 8 at addr ffff8881198bcb70 by task kworker/u8:9/435   Workqueue: netns cleanup_net   Call Trace:    __hlist_del / hlist_del_rcu    __xfrm_state_delete    xfrm_state_delete    xfrm_state_flush    xfrm_state_fini    ops_exit_list    cleanup_net The other observed signatures hit the same slab object from __xfrm_state_lookup, xfrm_alloc_spi, __xfrm_state_insert and an OOB write variant of __xfrm_state_delete, all on the byseq/byspi hash chains. __xfrm_state_delete() guards its byseq and byspi unhashes with value-based predicates: 	if (x-&gt;km.seq) 		hlist_del_rcu(&amp;x-&gt;byseq); 	if (x-&gt;id.spi) 		hlist_del_rcu(&amp;x-&gt;byspi); while everywhere else in the file (e.g. state_cache, state_cache_input) the safer hlist_unhashed() check is used. xfrm_alloc_spi() sets x-&gt;id.spi = newspi in…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-46116"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1700</id>
    <title>WID-SEC-W-2026-1700 — Linux Kernel: Mehrere Schwachstellen</title>
    <updated>2026-10-02T11:41:33.657446+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen oder andere nicht näher spezifizierte Auswirkungen zu erzielen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1700"/>
  </entry>
</feed>
