<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T16:39:43.033115+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:27288</id>
    <title>ALSA-2026:27288 — Important: kernel security, bug fix, and enhancement update</title>
    <updated>2026-10-04T16:39:47.561184+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:10: kernel, AlmaLinux:10: kernel-64k, AlmaLinux:10: kernel-64k-core, AlmaLinux:10: kernel-64k-debug, AlmaLinux:10: kernel-64k-debug-core, AlmaLinux:10: kernel-64k-debug-devel, AlmaLinux:10: kernel-64k-debug-devel-matched, AlmaLinux:10: kernel-64k-debug-modules, AlmaLinux:10: kernel-64k-debug-modules-core, AlmaLinux:10: kernel-64k-debug-modules-extra and 65 more</p>
<p>The kernel packages contain the Linux kernel, the core of any Linux operating system.</p>
<p>Security Fix(es):</p>
<p>* kernel: can: isotp: fix tx.buf use-after-free in isotp_sendmsg() (CVE-2026-31474)
  * kernel: mptcp: fix slab-use-after-free in __inet_lookup_established (CVE-2026-31669)
  * kernel: rxrpc: Fix RxGK token loading to check bounds (CVE-2026-31641)
  * kernel: xen/privcmd: fix double free via VMA splitting (CVE-2026-31787)
  * kernel: Buffer overflow in drivers/xen/sys-hypervisor.c (CVE-2026-31786)
  * kernel: net: mana: fix use-after-free in add_adev() error path (CVE-2026-43056)
  * kernel: Bluetooth: hci_sync: fix stack buffer overflow in hci_le_big_create_sync (CVE-2026-31772)
  * kernel: bnxt_en: Fix RSS context delete logic (CVE-2026-43260)
  * kernel: crypto: caam - fix overflow on long hmac keys (CVE-2026-43330)
  * kernel: net/sched: act_pedit: extend the writable skb range per key (CVE-2026-46331)
  * kernel: Bluetooth: hci_event: fix potential UAF in SSP passkey handlers (CVE-2026-46056)
  * kernel: wifi: mac80211: drop stray 'static' from fast-RX rx_result (CVE-2026-46152)
  * kernel: wifi: mac80211: remove station if connection prep fails (CVE-2026-46125)
  * kernel: exit: prevent preemption of oopsing TASK_DEAD task (CVE-2026-46173)
  * kernel: wifi: mac80211: use safe list iteration in radar detect work (CVE-2026-46166)</p>
<p>Bug Fix(es) and Enhancement(s):</p>
<p>* AlmaLinux10.0 - s390/ap: Expose ap_bindings_complete_count counter via sysfs [almalinux-10.2…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:27288"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-14226</id>
    <title>bdu:2026-14226</title>
    <updated>2026-10-04T16:39:47.561430+00:00</updated>
    <content>bdu:2026-14226</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-14226"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-46173</id>
    <title>BELL-CVE-2026-46173</title>
    <updated>2026-10-04T16:39:47.561453+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-46173"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0731</id>
    <title>certfr-2026-avi-0731 — De multiples vulnérabilités ont été découvertes dans les produits Microsoft. Certaines d'entre elles permettent à un at…</title>
    <updated>2026-10-04T16:39:47.561476+00:00</updated>
    <content>certfr-2026-avi-0731</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0731"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/essa-2026:0153</id>
    <title>ESSA-2026:0153 — Important: kernel security, bug fix, and enhancement update</title>
    <updated>2026-10-04T16:39:47.561494+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Important: kernel security, bug fix, and enhancement update</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/essa-2026:0153"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-364817</id>
    <title>EUVD-2026-364817</title>
    <updated>2026-10-04T16:39:47.561528+00:00</updated>
    <content>EUVD-2026-364817</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-364817"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-46173</id>
    <title>fkie_cve-2026-46173</title>
    <updated>2026-10-04T16:39:47.561540+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>exit: prevent preemption of oopsing TASK_DEAD task</p>
<p>When an already-exiting task oopses, make_task_dead() currently calls
do_task_dead() with preemption enabled.  That is forbidden:
do_task_dead() calls __schedule(), which has a comment saying "WARNING:
must be called with preemption disabled!".</p>
<p>If an oopsing task is preempted in do_task_dead(), between becoming
TASK_DEAD and entering the scheduler explicitly, bad things happen:
finish_task_switch() assumes that once the scheduler has switched away
from a TASK_DEAD task, the task can never run again and its stack is no
longer needed; but that assumption apparently doesn't hold if the dead
task was preempted (the SM_PREEMPT case).</p>
<p>This means that the scheduler ends up repeatedly dropping references on
the dead task's stack, which can lead to use-after-free or double-free
of the entire task stack; in other words, two tasks can end up running
on the same stack, resulting in various kinds of memory corruption.</p>
<p>(This does not just affect "recursively oopsing" tasks; it is enough to
oops once during task exit, for example in a file_operations::release
handler)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-46173"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-mpr4-2mm3-rwm6</id>
    <title>GHSA-mpr4-2mm3-rwm6</title>
    <updated>2026-10-04T16:39:47.561576+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>exit: prevent preemption of oopsing TASK_DEAD task</p>
<p>When an already-exiting task oopses, make_task_dead() currently calls
do_task_dead() with preemption enabled.  That is forbidden:
do_task_dead() calls __schedule(), which has a comment saying "WARNING:
must be called with preemption disabled!".</p>
<p>If an oopsing task is preempted in do_task_dead(), between becoming
TASK_DEAD and entering the scheduler explicitly, bad things happen:
finish_task_switch() assumes that once the scheduler has switched away
from a TASK_DEAD task, the task can never run again and its stack is no
longer needed; but that assumption apparently doesn't hold if the dead
task was preempted (the SM_PREEMPT case).</p>
<p>This means that the scheduler ends up repeatedly dropping references on
the dead task's stack, which can lead to use-after-free or double-free
of the entire task stack; in other words, two tasks can end up running
on the same stack, resulting in various kinds of memory corruption.</p>
<p>(This does not just affect "recursively oopsing" tasks; it is enough to
oops once during task exit, for example in a file_operations::release
handler)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-mpr4-2mm3-rwm6"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-46173</id>
    <title>msrc_CVE-2026-46173 — exit: prevent preemption of oopsing TASK_DEAD task</title>
    <updated>2026-10-04T16:39:47.561602+00:00</updated>
    <content>msrc_CVE-2026-46173</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-46173"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:27713</id>
    <title>RHSA-2026:27713 — Red Hat Security Advisory: kernel security, bug fix, and enhancement update</title>
    <updated>2026-10-04T16:39:47.561619+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>kernel: netfilter: nf_conntrack_h323: check for zero length in DecodeQ931() kernel: mptcp: fix slab-use-after-free in __inet_lookup_established kernel: RDMA/umem: Fix double dma_buf_unpin in failure path kernel: netfilter: flowtable: strictly check for maximum number of actions kernel: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows kernel: RDMA/rxe: Fix double free in rxe_srq_from_init kernel: exit: prevent preemption of oopsing TASK_DEAD task kernel: net/sched: act_pedit: extend the writable skb range per key</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:27713"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:27288</id>
    <title>RLSA-2026:27288 — Important: kernel security, bug fix, and enhancement update</title>
    <updated>2026-10-04T16:39:47.561651+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:10: kernel</p>
<p>The kernel packages contain the Linux kernel, the core of any Linux operating system.</p>
<p>Security Fix(es):</p>
<p>* kernel: can: isotp: fix tx.buf use-after-free in isotp_sendmsg() (CVE-2026-31474)</p>
<p>* kernel: mptcp: fix slab-use-after-free in __inet_lookup_established (CVE-2026-31669)</p>
<p>* kernel: rxrpc: Fix RxGK token loading to check bounds (CVE-2026-31641)</p>
<p>* kernel: xen/privcmd: fix double free via VMA splitting (CVE-2026-31787)</p>
<p>* kernel: Buffer overflow in drivers/xen/sys-hypervisor.c (CVE-2026-31786)</p>
<p>* kernel: net: mana: fix use-after-free in add_adev() error path (CVE-2026-43056)</p>
<p>* kernel: Bluetooth: hci_sync: fix stack buffer overflow in hci_le_big_create_sync (CVE-2026-31772)</p>
<p>* kernel: bnxt_en: Fix RSS context delete logic (CVE-2026-43260)</p>
<p>* kernel: crypto: caam - fix overflow on long hmac keys (CVE-2026-43330)</p>
<p>* kernel: net/sched: act_pedit: extend the writable skb range per key (CVE-2026-46331)</p>
<p>* kernel: Bluetooth: hci_event: fix potential UAF in SSP passkey handlers (CVE-2026-46056)</p>
<p>* kernel: wifi: mac80211: drop stray 'static' from fast-RX rx_result (CVE-2026-46152)</p>
<p>* kernel: wifi: mac80211: remove station if connection prep fails (CVE-2026-46125)</p>
<p>* kernel: exit: prevent preemption of oopsing TASK_DEAD task (CVE-2026-46173)</p>
<p>* kernel: wifi: mac80211: use safe list iteration in radar detect work (CVE-2026-46166)</p>
<p>Bug Fix(es) and Enhancement(s):</p>
<p>* Rocky Linux10.0 - s390/ap: Expose ap_bindings_complete_count counter via sysfs [rhel-10.2.z] (JIRA:Rocky Linux-166047…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:27288"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ssa-019113</id>
    <title>SSA-019113 — SSA-019113: Vulnerabilities in the additional GNU/Linux subsystem of the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1.6</title>
    <updated>2026-10-04T16:39:47.561700+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.6 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant).</p>
<p>Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ssa-019113"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:22521-1</id>
    <title>SUSE-SU-2026:22521-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-04T16:39:47.561948+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:22521-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-46173</id>
    <title>UBUNTU-CVE-2026-46173</title>
    <updated>2026-10-04T16:39:47.562012+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 161 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: exit: prevent preemption of oopsing TASK_DEAD task When an already-exiting task oopses, make_task_dead() currently calls do_task_dead() with preemption enabled.  That is forbidden: do_task_dead() calls __schedule(), which has a comment saying "WARNING: must be called with preemption disabled!". If an oopsing task is preempted in do_task_dead(), between becoming TASK_DEAD and entering the scheduler explicitly, bad things happen: finish_task_switch() assumes that once the scheduler has switched away from a TASK_DEAD task, the task can never run again and its stack is no longer needed; but that assumption apparently doesn't hold if the dead task was preempted (the SM_PREEMPT case). This means that the scheduler ends up repeatedly dropping references on the dead task's stack, which can lead to use-after-free or double-free of the entire task stack; in other words, two tasks can end up running on the same stack, resulting in various kinds of memory corruption. (This does not just affect "recursively oopsing" tasks; it is enough to oops once during task exit, for example in a file_operations::release handler)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-46173"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1700</id>
    <title>WID-SEC-W-2026-1700 — Linux Kernel: Mehrere Schwachstellen</title>
    <updated>2026-10-04T16:39:47.562205+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen oder andere nicht näher spezifizierte Auswirkungen zu erzielen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1700"/>
  </entry>
</feed>
