<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T09:06:57.390949+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:34911</id>
    <title>ALSA-2026:34911 — Important: kernel security, bug fix, and enhancement update</title>
    <updated>2026-10-03T09:06:58.372854+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:10: kernel, AlmaLinux:10: kernel-64k, AlmaLinux:10: kernel-64k-core, AlmaLinux:10: kernel-64k-debug, AlmaLinux:10: kernel-64k-debug-core, AlmaLinux:10: kernel-64k-debug-devel, AlmaLinux:10: kernel-64k-debug-devel-matched, AlmaLinux:10: kernel-64k-debug-modules, AlmaLinux:10: kernel-64k-debug-modules-core, AlmaLinux:10: kernel-64k-debug-modules-extra and 65 more</p>
<p>The kernel packages contain the Linux kernel, the core of any Linux operating system.</p>
<p>Security Fix(es):</p>
<p>* kernel: fs/smb/client: fix out-of-bounds read in cifs_sanitize_prepath (CVE-2026-43112)
  * kernel: rxrpc: Fix potential UAF after skb_unshare() failure (CVE-2026-45998)
  * kernel: drm/gem: Fix inconsistent plane dimension calculation in drm_gem_fb_init_with_funcs() (CVE-2026-46209)
  * kernel: netfilter: nft_inner: Fix IPv6 inner_thoff desync (CVE-2026-46244)
  * kernel: Arm Processors: Privilege escalation or information disclosure via writes to higher exception level resources (CVE-2025-10263)
  * kernel: KVM: arm64: vgic-its: Drop the translation cache reference only for the erased entry (CVE-2026-46316)
  * kernel: kernel: ipv6 frag escape ()</p>
<p>Bug Fix(es) and Enhancement(s):</p>
<p>* crypto: testmgr - allow authenc(hmac(sha{256,384}),cts(cbc(aes))) in FIPS mode [almalinux-10.2.z] (JIRA:AlmaLinux-182537)
  * [ThinkPad Avon/Mario +AlmaLinux 10.2]The OS hang up with CapsLock fliker (JIRA:AlmaLinux-185110)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:34911"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-14223</id>
    <title>bdu:2026-14223</title>
    <updated>2026-10-03T09:06:58.373067+00:00</updated>
    <content>bdu:2026-14223</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-14223"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-46209</id>
    <title>BELL-CVE-2026-46209</title>
    <updated>2026-10-03T09:06:58.373088+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-46209"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0731</id>
    <title>certfr-2026-avi-0731 — De multiples vulnérabilités ont été découvertes dans les produits Microsoft. Certaines d'entre elles permettent à un at…</title>
    <updated>2026-10-03T09:06:58.373111+00:00</updated>
    <content>certfr-2026-avi-0731</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0731"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/essa-2026:0162</id>
    <title>ESSA-2026:0162 — Important: kernel security, bug fix, and enhancement update</title>
    <updated>2026-10-03T09:06:58.373128+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Important: kernel security, bug fix, and enhancement update</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/essa-2026:0162"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-348042</id>
    <title>EUVD-2026-348042</title>
    <updated>2026-10-03T09:06:58.373154+00:00</updated>
    <content>EUVD-2026-348042</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-348042"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-46209</id>
    <title>fkie_cve-2026-46209</title>
    <updated>2026-10-03T09:06:58.373165+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>drm/gem: Fix inconsistent plane dimension calculation in drm_gem_fb_init_with_funcs()</p>
<p>drm_gem_fb_init_with_funcs() computes sub-sampled plane dimensions
using plain integer division:</p>
<p>unsigned int width  = mode_cmd-&gt;width  / (i ? info-&gt;hsub : 1);
  unsigned int height = mode_cmd-&gt;height / (i ? info-&gt;vsub : 1);</p>
<p>However, the ioctl-level framebuffer_check() in drm_framebuffer.c uses
drm_format_info_plane_width/height() which round up dimensions via
DIV_ROUND_UP(). This inconsistency corrupts the subsequent GEM object
size check for certain pixel format and dimension combinations.</p>
<p>For example, with NV12 (vsub=2) and a 1-pixel-tall framebuffer the
GEM size validation path sees height=0 instead of height=1. The
expression (height - 1) then wraps to UINT_MAX as an unsigned int,
causing min_size to overflow and wrap back to a small value. A tiny
GEM object therefore passes the size guard, yet when the GPU accesses
the chroma plane it will read or write memory beyond the object's
bounds.</p>
<p>Fix by replacing the open-coded divisions with drm_format_info_plane_width()
and drm_format_info_plane_height(), which use DIV_ROUND_UP() and match
the calculation already used in framebuffer_check().</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-46209"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-f8g6-g8cv-582v</id>
    <title>GHSA-f8g6-g8cv-582v</title>
    <updated>2026-10-03T09:06:58.373199+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>drm/gem: Fix inconsistent plane dimension calculation in drm_gem_fb_init_with_funcs()</p>
<p>drm_gem_fb_init_with_funcs() computes sub-sampled plane dimensions
using plain integer division:</p>
<p>unsigned int width  = mode_cmd-&gt;width  / (i ? info-&gt;hsub : 1);
  unsigned int height = mode_cmd-&gt;height / (i ? info-&gt;vsub : 1);</p>
<p>However, the ioctl-level framebuffer_check() in drm_framebuffer.c uses
drm_format_info_plane_width/height() which round up dimensions via
DIV_ROUND_UP(). This inconsistency corrupts the subsequent GEM object
size check for certain pixel format and dimension combinations.</p>
<p>For example, with NV12 (vsub=2) and a 1-pixel-tall framebuffer the
GEM size validation path sees height=0 instead of height=1. The
expression (height - 1) then wraps to UINT_MAX as an unsigned int,
causing min_size to overflow and wrap back to a small value. A tiny
GEM object therefore passes the size guard, yet when the GPU accesses
the chroma plane it will read or write memory beyond the object's
bounds.</p>
<p>Fix by replacing the open-coded divisions with drm_format_info_plane_width()
and drm_format_info_plane_height(), which use DIV_ROUND_UP() and match
the calculation already used in framebuffer_check().</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-f8g6-g8cv-582v"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-46209</id>
    <title>msrc_CVE-2026-46209 — drm/gem: Fix inconsistent plane dimension calculation in drm_gem_fb_init_with_funcs()</title>
    <updated>2026-10-03T09:06:58.373224+00:00</updated>
    <content>msrc_CVE-2026-46209</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-46209"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-2673</id>
    <title>OESA-2026-2673 — kernel security update</title>
    <updated>2026-10-03T09:06:58.373241+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP4: kernel</p>
<p>The Linux Kernel, the operating system core itself.

Security Fix(es):</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>net: hamradio: fix memory leak in mkiss_close</p>
<p>My local syzbot instance hit memory leak in
mkiss_open()[1]. The problem was in missing
free_netdev() in mkiss_close().</p>
<p>In mkiss_open() netdevice is allocated and then
registered, but in mkiss_close() netdevice was
only unregistered, but not freed.</p>
<p>Fail log:</p>
<p>BUG: memory leak
unreferenced object 0xffff8880281ba000 (size 4096):
  comm &amp;quot;syz-executor.1&amp;quot;, pid 11443, jiffies 4295046091 (age 17.660s)
  hex dump (first 32 bytes):
    61 78 30 00 00 00 00 00 00 00 00 00 00 00 00 00  ax0.............
    00 27 fa 2a 80 88 ff ff 00 00 00 00 00 00 00 00  .&amp;apos;.*............
  backtrace:
    [&amp;lt;ffffffff81a27201&amp;gt;] kvmalloc_node+0x61/0xf0
    [&amp;lt;ffffffff8706e7e8&amp;gt;] alloc_netdev_mqs+0x98/0xe80
    [&amp;lt;ffffffff84e64192&amp;gt;] mkiss_open+0xb2/0x6f0 [1]
    [&amp;lt;ffffffff842355db&amp;gt;] tty_ldisc_open+0x9b/0x110
    [&amp;lt;ffffffff84236488&amp;gt;] tty_set_ldisc+0x2e8/0x670
    [&amp;lt;ffffffff8421f7f3&amp;gt;] tty_ioctl+0xda3/0x1440
    [&amp;lt;ffffffff81c9f273&amp;gt;] __x64_sys_ioctl+0x193/0x200
    [&amp;lt;ffffffff8911263a&amp;gt;] do_syscall_64+0x3a/0xb0
    [&amp;lt;ffffffff89200068&amp;gt;] entry_SYSCALL_64_after_hwframe+0x44/0xae</p>
<p>BUG: memory leak
unreferenced object 0xffff8880141a9a00 (size 96):
  comm &amp;quot;syz-executor.1&amp;quot;, pid 11443, jiffies 4295046091 (age 17.660s)
  hex dump (first 32 bytes):
    e8 a2 1…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-2673"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:36348</id>
    <title>RHSA-2026:36348 — Red Hat Security Advisory: kernel-rt security, bug fix, and enhancement update</title>
    <updated>2026-10-03T09:06:58.373352+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>kernel: Arm Processors: Privilege escalation or information disclosure via writes to higher exception level resources kernel: tcp: fix potential race in tcp_v6_syn_recv_sock() kernel: netfilter: nfnetlink_cthelper: fix OOB read in nfnl_cthelper_dump_table() kernel: drm/gem: Fix inconsistent plane dimension calculation in drm_gem_fb_init_with_funcs() kernel: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL kernel: procfs: fix missing RCU protection when reading real_parent in do_task_stat()</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:36348"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:36018</id>
    <title>RLSA-2026:36018 — Important: kernel security, bug fix, and enhancement update</title>
    <updated>2026-10-03T09:06:58.373380+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:9: kernel</p>
<p>The kernel packages contain the Linux kernel, the core of any Linux operating system.</p>
<p>Security Fix(es):</p>
<p>* kernel: fs/smb/client: fix out-of-bounds read in cifs_sanitize_prepath (CVE-2026-43112)</p>
<p>* kernel: net: mana: Fix double destroy_workqueue on service rescan PCI path (CVE-2026-43276)</p>
<p>* kernel: Linux kernel: Use-After-Free in net/gro due to improper handling of zerocopy skbs (CVE-2026-46323)</p>
<p>* kernel: xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete (CVE-2026-46116)</p>
<p>* kernel: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (CVE-2026-46227)</p>
<p>* kernel: drm/gem: Fix inconsistent plane dimension calculation in drm_gem_fb_init_with_funcs() (CVE-2026-46209)</p>
<p>* kernel: smb/client: fix out-of-bounds read in smb2_compound_op() (CVE-2026-46155)</p>
<p>* kernel: netfilter: nft_inner: Fix IPv6 inner_thoff desync (CVE-2026-46244)</p>
<p>* kernel: procfs: fix missing RCU protection when reading real_parent in do_task_stat() (CVE-2026-46259)</p>
<p>* kernel: Arm Processors: Privilege escalation or information disclosure via writes to higher exception level resources (CVE-2025-10263)</p>
<p>* kernel: KVM: arm64: vgic-its: Drop the translation cache reference only for the erased entry (CVE-2026-46316)</p>
<p>Bug Fix(es) and Enhancement(s):</p>
<p>* WARNING at drivers/gpu/drm/nouveau/nvkm/subdev/gsp/r535.c:1585 r535_gsp_fini+0x2fb/0x310 [nouveau] [rhel-9.8.z] (JIRA:Rocky Linux-160966)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgme…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:36018"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:22108-1</id>
    <title>SUSE-SU-2026:22108-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-03T09:06:58.373422+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:22108-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-46209</id>
    <title>UBUNTU-CVE-2026-46209</title>
    <updated>2026-10-03T09:06:58.373488+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe, Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:Pro:16.04:LTS: linux-oracle, Ubuntu:Pro:18.04:LTS: linux, Ubuntu:Pro:18.04:LTS: linux-aws, Ubuntu:18.04:LTS: linux-aws-5.0 and 246 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: drm/gem: Fix inconsistent plane dimension calculation in drm_gem_fb_init_with_funcs() drm_gem_fb_init_with_funcs() computes sub-sampled plane dimensions using plain integer division:   unsigned int width  = mode_cmd-&gt;width  / (i ? info-&gt;hsub : 1);   unsigned int height = mode_cmd-&gt;height / (i ? info-&gt;vsub : 1); However, the ioctl-level framebuffer_check() in drm_framebuffer.c uses drm_format_info_plane_width/height() which round up dimensions via DIV_ROUND_UP(). This inconsistency corrupts the subsequent GEM object size check for certain pixel format and dimension combinations. For example, with NV12 (vsub=2) and a 1-pixel-tall framebuffer the GEM size validation path sees height=0 instead of height=1. The expression (height - 1) then wraps to UINT_MAX as an unsigned int, causing min_size to overflow and wrap back to a small value. A tiny GEM object therefore passes the size guard, yet when the GPU accesses the chroma plane it will read or write memory beyond the object's bounds. Fix by replacing the open-coded divisions with drm_format_info_plane_width() and drm_format_info_plane_height(), which use DIV_ROUND_UP() and match the calculation already used in framebuffer_check().</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-46209"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1700</id>
    <title>WID-SEC-W-2026-1700 — Linux Kernel: Mehrere Schwachstellen</title>
    <updated>2026-10-03T09:06:58.373751+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen oder andere nicht näher spezifizierte Auswirkungen zu erzielen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1700"/>
  </entry>
</feed>
