<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T13:10:11.976981+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-46132</id>
    <title>BELL-CVE-2026-46132</title>
    <updated>2026-10-02T13:10:12.842110+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-46132"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0731</id>
    <title>certfr-2026-avi-0731 — De multiples vulnérabilités ont été découvertes dans les produits Microsoft. Certaines d'entre elles permettent à un at…</title>
    <updated>2026-10-02T13:10:12.842203+00:00</updated>
    <content>certfr-2026-avi-0731</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0731"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-364815</id>
    <title>EUVD-2026-364815</title>
    <updated>2026-10-02T13:10:12.842226+00:00</updated>
    <content>EUVD-2026-364815</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-364815"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-46132</id>
    <title>fkie_cve-2026-46132</title>
    <updated>2026-10-02T13:10:12.842239+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>net: rtnetlink: zero ifla_vf_broadcast to avoid stack infoleak in rtnl_fill_vfinfo</p>
<p>rtnl_fill_vfinfo() declares struct ifla_vf_broadcast on the stack
without initialisation:</p>
<p>struct ifla_vf_broadcast vf_broadcast;</p>
<p>The struct contains a single fixed 32-byte field:</p>
<p>/* include/uapi/linux/if_link.h */
	struct ifla_vf_broadcast {
		__u8 broadcast[32];
	};</p>
<p>The function then copies dev-&gt;broadcast into it using dev-&gt;addr_len
as the length:</p>
<p>memcpy(vf_broadcast.broadcast, dev-&gt;broadcast, dev-&gt;addr_len);</p>
<p>On Ethernet devices (the overwhelming majority of SR-IOV NICs)
dev-&gt;addr_len is 6, so only the first 6 bytes of broadcast[] are
written. The remaining 26 bytes retain whatever was previously on
the kernel stack. The full struct is then handed to userspace via:</p>
<p>nla_put(skb, IFLA_VF_BROADCAST,
		sizeof(vf_broadcast), &amp;vf_broadcast)</p>
<p>leaking up to 26 bytes of uninitialised kernel stack per VF per
RTM_GETLINK request, repeatable.</p>
<p>The other vf_* structs in the same function are explicitly zeroed
for exactly this reason - see the memset() calls for ivi,
vf_vlan_info, node_guid and port_guid a few lines above.
vf_broadcast was simply missed when it was added.</p>
<p>Reachability: any unprivileged local process can open AF_NETLINK /
NETLINK_ROUTE without capabilities and send RTM_GETLINK with an
IFLA_EXT_MASK attribute carrying RTEXT_FILTER_VF. The kernel walks
each VF and emits IFLA_VF_BROADCAST, leaking 26 bytes of sta…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-46132"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-m5g9-vgm2-5cvw</id>
    <title>GHSA-m5g9-vgm2-5cvw</title>
    <updated>2026-10-02T13:10:12.842289+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>net: rtnetlink: zero ifla_vf_broadcast to avoid stack infoleak in rtnl_fill_vfinfo</p>
<p>rtnl_fill_vfinfo() declares struct ifla_vf_broadcast on the stack
without initialisation:</p>
<p>struct ifla_vf_broadcast vf_broadcast;</p>
<p>The struct contains a single fixed 32-byte field:</p>
<p>/* include/uapi/linux/if_link.h */
	struct ifla_vf_broadcast {
		__u8 broadcast[32];
	};</p>
<p>The function then copies dev-&gt;broadcast into it using dev-&gt;addr_len
as the length:</p>
<p>memcpy(vf_broadcast.broadcast, dev-&gt;broadcast, dev-&gt;addr_len);</p>
<p>On Ethernet devices (the overwhelming majority of SR-IOV NICs)
dev-&gt;addr_len is 6, so only the first 6 bytes of broadcast[] are
written. The remaining 26 bytes retain whatever was previously on
the kernel stack. The full struct is then handed to userspace via:</p>
<p>nla_put(skb, IFLA_VF_BROADCAST,
		sizeof(vf_broadcast), &amp;vf_broadcast)</p>
<p>leaking up to 26 bytes of uninitialised kernel stack per VF per
RTM_GETLINK request, repeatable.</p>
<p>The other vf_* structs in the same function are explicitly zeroed
for exactly this reason - see the memset() calls for ivi,
vf_vlan_info, node_guid and port_guid a few lines above.
vf_broadcast was simply missed when it was added.</p>
<p>Reachability: any unprivileged local process can open AF_NETLINK /
NETLINK_ROUTE without capabilities and send RTM_GETLINK with an
IFLA_EXT_MASK attribute carrying RTEXT_FILTER_VF. The kernel walks
each VF and emits IFLA_VF_BROADCAST, leaking 26 bytes of sta…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-m5g9-vgm2-5cvw"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-46132</id>
    <title>msrc_CVE-2026-46132 — net: rtnetlink: zero ifla_vf_broadcast to avoid stack infoleak in rtnl_fill_vfinfo</title>
    <updated>2026-10-02T13:10:12.842327+00:00</updated>
    <content>msrc_CVE-2026-46132</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-46132"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-2674</id>
    <title>OESA-2026-2674 — kernel security update</title>
    <updated>2026-10-02T13:10:12.842345+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:22.03-LTS-SP4: kernel</p>
<p>The Linux Kernel, the operating system core itself.

Security Fix(es):</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>btrfs: qgroup: fix race between quota disable and quota rescan ioctl</p>
<p>There&amp;apos;s a race between a task disabling quotas and another running the
rescan ioctl that can result in a use-after-free of qgroup records from
the fs_info-&amp;gt;qgroup_tree rbtree.</p>
<p>This happens as follows:</p>
<p>1) Task A enters btrfs_ioctl_quota_rescan() -&amp;gt; btrfs_qgroup_rescan();</p>
<p>2) Task B enters btrfs_quota_disable() and calls
   btrfs_qgroup_wait_for_completion(), which does nothing because at that
   point fs_info-&amp;gt;qgroup_rescan_running is false (it wasn&amp;apos;t set yet by
   task A);</p>
<p>3) Task B calls btrfs_free_qgroup_config() which starts freeing qgroups
   from fs_info-&amp;gt;qgroup_tree without taking the lock fs_info-&amp;gt;qgroup_lock;</p>
<p>4) Task A enters qgroup_rescan_zero_tracking() which starts iterating
   the fs_info-&amp;gt;qgroup_tree tree while holding fs_info-&amp;gt;qgroup_lock,
   but task B is freeing qgroup records from that tree without holding
   the lock, resulting in a use-after-free.</p>
<p>Fix this by taking fs_info-&amp;gt;qgroup_lock at btrfs_free_qgroup_config().
Also at btrfs_qgroup_rescan() don&amp;apos;t start the rescan worker if quotas
were already disabled.(CVE-2025-39759)</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>wifi: wilc1000: avoid buffer overflow in WID string configuration</p>
<p>Fix the following copy overflow warning identi…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-2674"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10954-1</id>
    <title>openSUSE-SU-2026:10954-1 — kernel-devel-7.0.11-1.1 on GA media</title>
    <updated>2026-10-02T13:10:12.842723+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>kernel-devel-7.0.11-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:10954-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ssa-019113</id>
    <title>SSA-019113 — SSA-019113: Vulnerabilities in the additional GNU/Linux subsystem of the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1.6</title>
    <updated>2026-10-02T13:10:12.842891+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.6 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant).</p>
<p>Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ssa-019113"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:23066-1</id>
    <title>SUSE-SU-2026:23066-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-02T13:10:12.843116+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:23066-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-46132</id>
    <title>UBUNTU-CVE-2026-46132</title>
    <updated>2026-10-02T13:10:12.843649+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:Pro:18.04:LTS: linux-aws-5.4, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:Pro:18.04:LTS: linux-azure-5.4, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3 and 226 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: net: rtnetlink: zero ifla_vf_broadcast to avoid stack infoleak in rtnl_fill_vfinfo rtnl_fill_vfinfo() declares struct ifla_vf_broadcast on the stack without initialisation: 	struct ifla_vf_broadcast vf_broadcast; The struct contains a single fixed 32-byte field: 	/* include/uapi/linux/if_link.h */ 	struct ifla_vf_broadcast { 		__u8 broadcast[32]; 	}; The function then copies dev-&gt;broadcast into it using dev-&gt;addr_len as the length: 	memcpy(vf_broadcast.broadcast, dev-&gt;broadcast, dev-&gt;addr_len); On Ethernet devices (the overwhelming majority of SR-IOV NICs) dev-&gt;addr_len is 6, so only the first 6 bytes of broadcast[] are written. The remaining 26 bytes retain whatever was previously on the kernel stack. The full struct is then handed to userspace via: 	nla_put(skb, IFLA_VF_BROADCAST, 		sizeof(vf_broadcast), &amp;vf_broadcast) leaking up to 26 bytes of uninitialised kernel stack per VF per RTM_GETLINK request, repeatable. The other vf_* structs in the same function are explicitly zeroed for exactly this reason - see the memset() calls for ivi, vf_vlan_info, node_guid and port_guid a few lines above. vf_broadcast was simply missed when it was added. Reachability: any unprivileged local process can open AF_NETLINK / NETLINK_ROUTE without capabilities and send RTM_GETLINK with an IFLA_EXT_MASK attribute carrying RTEXT_FILTER_VF. The kernel walks each VF and emits IFLA_VF_BROADCAST, leaking 26 bytes of stack per VF pe…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-46132"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1700</id>
    <title>WID-SEC-W-2026-1700 — Linux Kernel: Mehrere Schwachstellen</title>
    <updated>2026-10-02T13:10:12.843905+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen oder andere nicht näher spezifizierte Auswirkungen zu erzielen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1700"/>
  </entry>
</feed>
