<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T17:11:24.469167+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-46309</id>
    <title>BELL-CVE-2026-46309</title>
    <updated>2026-10-03T17:11:24.574998+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:stream: linux-lts</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-46309"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0926</id>
    <title>certfr-2026-avi-0926 — De multiples vulnérabilités ont été découvertes dans le noyau Linux d'Ubuntu. Certaines d'entre elles permettent à un a…</title>
    <updated>2026-10-03T17:11:24.575049+00:00</updated>
    <content>certfr-2026-avi-0926</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0926"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-337225</id>
    <title>EUVD-2026-337225</title>
    <updated>2026-10-03T17:11:24.575069+00:00</updated>
    <content>EUVD-2026-337225</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-337225"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-46309</id>
    <title>fkie_cve-2026-46309</title>
    <updated>2026-10-03T17:11:24.575081+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>drm/xe/uapi: Reject coh_none PAT index for CPU cached memory in madvise</p>
<p>Add validation in xe_vm_madvise_ioctl() to reject PAT indices with
XE_COH_NONE coherency mode when applied to CPU cached memory.</p>
<p>Using coh_none with CPU cached buffers is a security issue. When the
kernel clears pages before reallocation, the clear operation stays in
CPU cache (dirty). GPU with coh_none can bypass CPU caches and read
stale sensitive data directly from DRAM, potentially leaking data from
previously freed pages of other processes.</p>
<p>This aligns with the existing validation in vm_bind path
(xe_vm_bind_ioctl_validate_bo).</p>
<p>v2(Matthew brost)
- Add fixes
- Move one debug print to better place</p>
<p>v3(Matthew Auld)
- Should be drm/xe/uapi
- More Cc</p>
<p>v4(Shuicheng Lin)
- Fix kmem leak issues by the way</p>
<p>v5
- Remove kmem leak because it has been merged by another patch</p>
<p>v6
- Remove the fix which is not related to current fix</p>
<p>v7
- No change</p>
<p>v8
- Rebase</p>
<p>v9
- Limit the restrictions to iGPU</p>
<p>v10
- No change</p>
<p>(cherry picked from commit 016ccdb674b8c899940b3944952c96a6a490d10a)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-46309"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-vpjp-gfpq-57c9</id>
    <title>GHSA-vpjp-gfpq-57c9</title>
    <updated>2026-10-03T17:11:24.575121+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>drm/xe/uapi: Reject coh_none PAT index for CPU cached memory in madvise</p>
<p>Add validation in xe_vm_madvise_ioctl() to reject PAT indices with
XE_COH_NONE coherency mode when applied to CPU cached memory.</p>
<p>Using coh_none with CPU cached buffers is a security issue. When the
kernel clears pages before reallocation, the clear operation stays in
CPU cache (dirty). GPU with coh_none can bypass CPU caches and read
stale sensitive data directly from DRAM, potentially leaking data from
previously freed pages of other processes.</p>
<p>This aligns with the existing validation in vm_bind path
(xe_vm_bind_ioctl_validate_bo).</p>
<p>v2(Matthew brost)
- Add fixes
- Move one debug print to better place</p>
<p>v3(Matthew Auld)
- Should be drm/xe/uapi
- More Cc</p>
<p>v4(Shuicheng Lin)
- Fix kmem leak issues by the way</p>
<p>v5
- Remove kmem leak because it has been merged by another patch</p>
<p>v6
- Remove the fix which is not related to current fix</p>
<p>v7
- No change</p>
<p>v8
- Rebase</p>
<p>v9
- Limit the restrictions to iGPU</p>
<p>v10
- No change</p>
<p>(cherry picked from commit 016ccdb674b8c899940b3944952c96a6a490d10a)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-vpjp-gfpq-57c9"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11014-1</id>
    <title>openSUSE-SU-2026:11014-1 — kernel-devel-7.0.12-1.1 on GA media</title>
    <updated>2026-10-03T17:11:24.575151+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>kernel-devel-7.0.12-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:11014-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-46309</id>
    <title>UBUNTU-CVE-2026-46309</title>
    <updated>2026-10-03T17:11:24.575199+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 106 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: drm/xe/uapi: Reject coh_none PAT index for CPU cached memory in madvise Add validation in xe_vm_madvise_ioctl() to reject PAT indices with XE_COH_NONE coherency mode when applied to CPU cached memory. Using coh_none with CPU cached buffers is a security issue. When the kernel clears pages before reallocation, the clear operation stays in CPU cache (dirty). GPU with coh_none can bypass CPU caches and read stale sensitive data directly from DRAM, potentially leaking data from previously freed pages of other processes. This aligns with the existing validation in vm_bind path (xe_vm_bind_ioctl_validate_bo). v2(Matthew brost) - Add fixes - Move one debug print to better place v3(Matthew Auld) - Should be drm/xe/uapi - More Cc v4(Shuicheng Lin) - Fix kmem leak issues by the way v5 - Remove kmem leak because it has been merged by another patch v6 - Remove the fix which is not related to current fix v7 - No change v8 - Rebase v9 - Limit the restrictions to iGPU v10 - No change (cherry picked from commit 016ccdb674b8c899940b3944952c96a6a490d10a)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-46309"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1827</id>
    <title>WID-SEC-W-2026-1827 — Linux Kernel: Mehrere Schwachstellen ermöglichen Denial of Service</title>
    <updated>2026-10-03T17:11:24.575394+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen oder nicht bekannte Auswirkungen zu erzielen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1827"/>
  </entry>
</feed>
