<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T21:15:29.779712+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:27353</id>
    <title>ALSA-2026:27353 — Important: kernel security, bug fix, and enhancement update</title>
    <updated>2026-10-03T21:15:30.872537+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: bpftool, AlmaLinux:8: kernel, AlmaLinux:8: kernel-abi-stablelists, AlmaLinux:8: kernel-core, AlmaLinux:8: kernel-cross-headers, AlmaLinux:8: kernel-debug, AlmaLinux:8: kernel-debug-core, AlmaLinux:8: kernel-debug-devel, AlmaLinux:8: kernel-debug-modules, AlmaLinux:8: kernel-debug-modules-extra and 15 more</p>
<p>The kernel packages contain the Linux kernel, the core of any Linux operating system.</p>
<p>Security Fix(es):</p>
<p>* kernel: Linux kernel: Use-after-free in bonding driver leads to denial of service (CVE-2026-31419)
  * kernel: drm/amd/display: Do not skip unrelated mode changes in DSC validation (CVE-2026-31488)
  * kernel: net: mana: fix use-after-free in add_adev() error path (CVE-2026-43056)
  * kernel: ALSA: usb-audio: Add sanity check for OOB writes at silencing (CVE-2026-43279)
  * kernel: net/sched: act_pedit: extend the writable skb range per key (CVE-2026-46331)
  * kernel: ALSA: aloop: Fix peer runtime UAF during format-change stop (CVE-2026-46090)
  * kernel: RDMA/mana: Validate rx_hash_key_len (CVE-2026-46145)
  * kernel: nvmet-tcp: fix race between ICReq handling and queue teardown (CVE-2026-46135)</p>
<p>Bug Fix(es) and Enhancement(s):</p>
<p>* AlmaLinux8 RT kernel panic in replenish_dl_entity() caused by stale DEADLINE PI state during rt_mutex de-boosting (JIRA:AlmaLinux-178520)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:27353"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-46135</id>
    <title>BELL-CVE-2026-46135</title>
    <updated>2026-10-03T21:15:30.872694+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-46135"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0808</id>
    <title>certfr-2026-avi-0808 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de Red Hat. Certaines d'entre elles permettent à un…</title>
    <updated>2026-10-03T21:15:30.872722+00:00</updated>
    <content>certfr-2026-avi-0808</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0808"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/essa-2026:0165</id>
    <title>ESSA-2026:0165 — Important: kernel security, bug fix, and enhancement update</title>
    <updated>2026-10-03T21:15:30.872741+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Important: kernel security, bug fix, and enhancement update</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/essa-2026:0165"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-348018</id>
    <title>EUVD-2026-348018</title>
    <updated>2026-10-03T21:15:30.872767+00:00</updated>
    <content>EUVD-2026-348018</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-348018"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-46135</id>
    <title>fkie_cve-2026-46135</title>
    <updated>2026-10-03T21:15:30.872779+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>nvmet-tcp: fix race between ICReq handling and queue teardown</p>
<p>nvmet_tcp_handle_icreq() updates queue-&gt;state after sending an
Initialization Connection Response (ICResp), but it does so without
serializing against target-side queue teardown.</p>
<p>If an NVMe/TCP host sends an Initialization Connection Request
(ICReq) and immediately closes the connection, target-side teardown
may start in softirq context before io_work drains the already
buffered ICReq. In that case, nvmet_tcp_schedule_release_queue()
sets queue-&gt;state to NVMET_TCP_Q_DISCONNECTING and drops the queue
reference under state_lock.</p>
<p>If io_work later processes that ICReq, nvmet_tcp_handle_icreq() can
still overwrite the state back to NVMET_TCP_Q_LIVE. That defeats the
DISCONNECTING-state guard in nvmet_tcp_schedule_release_queue() and
allows a later socket state change to re-enter teardown and issue a
second kref_put() on an already released queue.</p>
<p>The ICResp send failure path has the same problem. If teardown has
already moved the queue to DISCONNECTING, a send error can still
overwrite the state with NVMET_TCP_Q_FAILED, again reopening the
window for a second teardown path to drop the queue reference.</p>
<p>Fix this by serializing both post-send state transitions with
state_lock and bailing out if teardown has already started.</p>
<p>Use -ESHUTDOWN as an internal sentinel for that bail-out path rather
than propagating it as a transport error like -ECONNRESET…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-46135"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-pp4w-65w8-f5f3</id>
    <title>GHSA-pp4w-65w8-f5f3</title>
    <updated>2026-10-03T21:15:30.872820+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>nvmet-tcp: fix race between ICReq handling and queue teardown</p>
<p>nvmet_tcp_handle_icreq() updates queue-&gt;state after sending an
Initialization Connection Response (ICResp), but it does so without
serializing against target-side queue teardown.</p>
<p>If an NVMe/TCP host sends an Initialization Connection Request
(ICReq) and immediately closes the connection, target-side teardown
may start in softirq context before io_work drains the already
buffered ICReq. In that case, nvmet_tcp_schedule_release_queue()
sets queue-&gt;state to NVMET_TCP_Q_DISCONNECTING and drops the queue
reference under state_lock.</p>
<p>If io_work later processes that ICReq, nvmet_tcp_handle_icreq() can
still overwrite the state back to NVMET_TCP_Q_LIVE. That defeats the
DISCONNECTING-state guard in nvmet_tcp_schedule_release_queue() and
allows a later socket state change to re-enter teardown and issue a
second kref_put() on an already released queue.</p>
<p>The ICResp send failure path has the same problem. If teardown has
already moved the queue to DISCONNECTING, a send error can still
overwrite the state with NVMET_TCP_Q_FAILED, again reopening the
window for a second teardown path to drop the queue reference.</p>
<p>Fix this by serializing both post-send state transitions with
state_lock and bailing out if teardown has already started.</p>
<p>Use -ESHUTDOWN as an internal sentinel for that bail-out path rather
than propagating it as a transport error like -ECONNRESET…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-pp4w-65w8-f5f3"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-46135</id>
    <title>msrc_CVE-2026-46135 — nvmet-tcp: fix race between ICReq handling and queue teardown</title>
    <updated>2026-10-03T21:15:30.872851+00:00</updated>
    <content>msrc_CVE-2026-46135</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-46135"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-2871</id>
    <title>OESA-2026-2871 — kernel security update</title>
    <updated>2026-10-03T21:15:30.872868+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:22.03-LTS-SP4: kernel</p>
<p>The Linux Kernel, the operating system core itself.

Security Fix(es):</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>netfilter: nf_conntrack_expect: use expect-&amp;gt;helper</p>
<p>Use expect-&amp;gt;helper in ctnetlink and /proc to dump the helper name.
Using nfct_help() without holding a reference to the master conntrack
is unsafe.</p>
<p>Use exp-&amp;gt;master-&amp;gt;helper in ctnetlink path if userspace does not provide
an explicit helper when creating an expectation to retain the existing
behaviour. The ctnetlink expectation path holds the reference on the
master conntrack and nf_conntrack_expect lock and the nfnetlink glue
path refers to the master ct that is attached to the skb.(CVE-2026-31414)</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>xfs: avoid dereferencing log items after push callbacks</p>
<p>After xfsaild_push_item() calls iop_push(), the log item may have been
freed if the AIL lock was dropped during the push. Background inode
reclaim or the dquot shrinker can free the log item while the AIL lock
is not held, and the tracepoints in the switch statement dereference
the log item after iop_push() returns.</p>
<p>Fix this by capturing the log item type, flags, and LSN before calling
xfsaild_push_item(), and introducing a new xfs_ail_push_class trace
event class that takes these pre-captured values and the ailp pointer
instead of the log item pointer.(CVE-2026-31453)</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>xfs: stop recl…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-2871"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:27354</id>
    <title>RHSA-2026:27354 — Red Hat Security Advisory: kernel-rt security, bug fix, and enhancement update</title>
    <updated>2026-10-03T21:15:30.872957+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>kernel: Linux kernel: Use-after-free in bonding driver leads to denial of service kernel: drm/amd/display: Do not skip unrelated mode changes in DSC validation kernel: net: mana: fix use-after-free in add_adev() error path kernel: ALSA: usb-audio: Add sanity check for OOB writes at silencing kernel: ALSA: aloop: Fix peer runtime UAF during format-change stop kernel: nvmet-tcp: fix race between ICReq handling and queue teardown kernel: RDMA/mana: Validate rx_hash_key_len kernel: net/sched: act_pedit: extend the writable skb range per key</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:27354"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:27353</id>
    <title>RLSA-2026:27353 — Important: kernel security, bug fix, and enhancement update</title>
    <updated>2026-10-03T21:15:30.872989+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:8: kernel</p>
<p>The kernel packages contain the Linux kernel, the core of any Linux operating system.</p>
<p>Security Fix(es):</p>
<p>* kernel: Linux kernel: Use-after-free in bonding driver leads to denial of service (CVE-2026-31419)</p>
<p>* kernel: drm/amd/display: Do not skip unrelated mode changes in DSC validation (CVE-2026-31488)</p>
<p>* kernel: net: mana: fix use-after-free in add_adev() error path (CVE-2026-43056)</p>
<p>* kernel: ALSA: usb-audio: Add sanity check for OOB writes at silencing (CVE-2026-43279)</p>
<p>* kernel: net/sched: act_pedit: extend the writable skb range per key (CVE-2026-46331)</p>
<p>* kernel: ALSA: aloop: Fix peer runtime UAF during format-change stop (CVE-2026-46090)</p>
<p>* kernel: RDMA/mana: Validate rx_hash_key_len (CVE-2026-46145)</p>
<p>* kernel: nvmet-tcp: fix race between ICReq handling and queue teardown (CVE-2026-46135)</p>
<p>Bug Fix(es) and Enhancement(s):</p>
<p>* Rocky Linux8 RT kernel panic in replenish_dl_entity() caused by stale DEADLINE PI state during rt_mutex de-boosting (JIRA:Rocky Linux-178520)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:27353"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:23881-1</id>
    <title>SUSE-SU-2026:23881-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-03T21:15:30.873023+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:23881-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-46135</id>
    <title>UBUNTU-CVE-2026-46135</title>
    <updated>2026-10-03T21:15:30.873499+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:Pro:18.04:LTS: linux-aws-5.4, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:Pro:18.04:LTS: linux-azure-5.4, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3 and 222 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: fix race between ICReq handling and queue teardown nvmet_tcp_handle_icreq() updates queue-&gt;state after sending an Initialization Connection Response (ICResp), but it does so without serializing against target-side queue teardown. If an NVMe/TCP host sends an Initialization Connection Request (ICReq) and immediately closes the connection, target-side teardown may start in softirq context before io_work drains the already buffered ICReq. In that case, nvmet_tcp_schedule_release_queue() sets queue-&gt;state to NVMET_TCP_Q_DISCONNECTING and drops the queue reference under state_lock. If io_work later processes that ICReq, nvmet_tcp_handle_icreq() can still overwrite the state back to NVMET_TCP_Q_LIVE. That defeats the DISCONNECTING-state guard in nvmet_tcp_schedule_release_queue() and allows a later socket state change to re-enter teardown and issue a second kref_put() on an already released queue. The ICResp send failure path has the same problem. If teardown has already moved the queue to DISCONNECTING, a send error can still overwrite the state with NVMET_TCP_Q_FAILED, again reopening the window for a second teardown path to drop the queue reference. Fix this by serializing both post-send state transitions with state_lock and bailing out if teardown has already started. Use -ESHUTDOWN as an internal sentinel for that bail-out path rather than propagating it as a transport error like -ECONNRESET. Keep…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-46135"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1700</id>
    <title>WID-SEC-W-2026-1700 — Linux Kernel: Mehrere Schwachstellen</title>
    <updated>2026-10-03T21:15:30.873765+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen oder andere nicht näher spezifizierte Auswirkungen zu erzielen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1700"/>
  </entry>
</feed>
