<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T08:07:28.384573+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:30129</id>
    <title>ALSA-2026:30129 — Important: kernel security, bug fix, and enhancement update</title>
    <updated>2026-10-03T08:07:28.472329+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:10: kernel, AlmaLinux:10: kernel-64k, AlmaLinux:10: kernel-64k-core, AlmaLinux:10: kernel-64k-debug, AlmaLinux:10: kernel-64k-debug-core, AlmaLinux:10: kernel-64k-debug-devel, AlmaLinux:10: kernel-64k-debug-devel-matched, AlmaLinux:10: kernel-64k-debug-modules, AlmaLinux:10: kernel-64k-debug-modules-core, AlmaLinux:10: kernel-64k-debug-modules-extra and 65 more</p>
<p>The kernel packages contain the Linux kernel, the core of any Linux operating system.</p>
<p>Security Fix(es):</p>
<p>* kernel: rxrpc: fix RESPONSE authenticator parser OOB read (CVE-2026-31636)
  * kernel: ipv6: icmp: clear skb2-&gt;cb[] in ip6_err_gen_icmpv6_unreach() (CVE-2026-43038)
  * kernel: tcp: fix potential race in tcp_v6_syn_recv_sock() (CVE-2026-43198)
  * kernel: scsi: qla2xxx: Completely fix fcport double free (CVE-2026-43414)
  * kernel: RDMA/iwcm: Fix workqueue list corruption by removing work_list (CVE-2026-45898)
  * kernel: RDMA/mana: Remove user triggerable WARN_ON() in mana_ib_create_qp_rss() (CVE-2026-46117)
  * kernel: RDMA/mana: Validate rx_hash_key_len (CVE-2026-46145)
  * kernel: nvmet-tcp: fix race between ICReq handling and queue teardown (CVE-2026-46135)
  * kernel: KVM: arm64: vgic-its: Drop the translation cache reference only for the erased entry (CVE-2026-46316)</p>
<p>Bug Fix(es) and Enhancement(s):</p>
<p>* Unexpected execmem SELinux denials after CVE-2026-46054 fix [rhel-10.2.z] (JIRA:RHEL-185117)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:30129"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-08088</id>
    <title>bdu:2026-08088</title>
    <updated>2026-10-03T08:07:28.472509+00:00</updated>
    <content>bdu:2026-08088</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-08088"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-46316</id>
    <title>BELL-CVE-2026-46316</title>
    <updated>2026-10-03T08:07:28.472530+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-46316"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0782</id>
    <title>certfr-2026-avi-0782 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de SUSE. Certaines d'entre elles permettent à un at…</title>
    <updated>2026-10-03T08:07:28.472551+00:00</updated>
    <content>certfr-2026-avi-0782</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0782"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/essa-2026:0165</id>
    <title>ESSA-2026:0165 — Important: kernel security, bug fix, and enhancement update</title>
    <updated>2026-10-03T08:07:28.472567+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Important: kernel security, bug fix, and enhancement update</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/essa-2026:0165"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-369282</id>
    <title>EUVD-2026-369282</title>
    <updated>2026-10-03T08:07:28.472592+00:00</updated>
    <content>EUVD-2026-369282</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-369282"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-46316</id>
    <title>fkie_cve-2026-46316</title>
    <updated>2026-10-03T08:07:28.472604+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>KVM: arm64: vgic-its: Drop the translation cache reference only for the erased entry</p>
<p>vgic_its_invalidate_cache() walks the per-ITS translation cache with
xa_for_each() and drops the cache's reference on each entry with
vgic_put_irq(). It puts the iterated pointer, though, rather than the
value returned by xa_erase().</p>
<p>The function is called from contexts that do not exclude one another: the
ITS command handlers hold its_lock, the GITS_CTLR write path holds
cmd_lock, and the path that clears EnableLPIs in a redistributor's
GICR_CTLR holds neither. Two or more of them can drain the same cache
concurrently, and if each one observes the same entry, erases it and then
puts it, the single reference the cache holds on that entry is dropped
more than once. The entry can then be freed while an ITE still maps it.</p>
<p>xa_erase() is atomic and returns the previous entry, so put only the entry
that this context actually removed. The cache reference is then dropped
exactly once per entry even when the invalidations run concurrently, and
the behavior is unchanged when only one context runs.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-46316"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-qcxh-2cm7-9fcc</id>
    <title>GHSA-qcxh-2cm7-9fcc</title>
    <updated>2026-10-03T08:07:28.472636+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>KVM: arm64: vgic-its: Drop the translation cache reference only for the erased entry</p>
<p>vgic_its_invalidate_cache() walks the per-ITS translation cache with
xa_for_each() and drops the cache's reference on each entry with
vgic_put_irq(). It puts the iterated pointer, though, rather than the
value returned by xa_erase().</p>
<p>The function is called from contexts that do not exclude one another: the
ITS command handlers hold its_lock, the GITS_CTLR write path holds
cmd_lock, and the path that clears EnableLPIs in a redistributor's
GICR_CTLR holds neither. Two or more of them can drain the same cache
concurrently, and if each one observes the same entry, erases it and then
puts it, the single reference the cache holds on that entry is dropped
more than once. The entry can then be freed while an ITE still maps it.</p>
<p>xa_erase() is atomic and returns the previous entry, so put only the entry
that this context actually removed. The cache reference is then dropped
exactly once per entry even when the invalidations run concurrently, and
the behavior is unchanged when only one context runs.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-qcxh-2cm7-9fcc"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:38902</id>
    <title>RHSA-2026:38902 — Red Hat Security Advisory: kernel security, bug fix, and enhancement update</title>
    <updated>2026-10-03T08:07:28.472660+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>kernel: ima: don't clear IMA_DIGSIG flag when setting or removing non-IMA xattr kernel: Bluetooth: SCO: Fix use-after-free in sco_recv_frame() due to missing sock_hold kernel: eventpoll: defer struct eventpoll free to RCU grace period kernel: ALSA: usb-audio: Add sanity check for OOB writes at silencing kernel: gfs2: Fix use-after-free in iomap inline data write path kernel: KVM: x86: Fix shadow paging use-after-free due to unexpected GFN kernel: nvmet-tcp: fix race between ICReq handling and queue teardown kernel: wifi: mac80211: drop stray 'static' from fast-RX rx_result kernel: RDMA/vmw_pvrdma: Fix double free on pvrdma_alloc_ucontext() error path kernel: eventpoll: fix ep_remove struct eventpoll / struct file UAF kernel: KVM: arm64: vgic-its: Drop the translation cache reference only for the erased entry kernel: KVM: x86: Fix shadow paging use-after-free due to unexpected role</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:38902"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:36018</id>
    <title>RLSA-2026:36018 — Important: kernel security, bug fix, and enhancement update</title>
    <updated>2026-10-03T08:07:28.472699+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:9: kernel</p>
<p>The kernel packages contain the Linux kernel, the core of any Linux operating system.</p>
<p>Security Fix(es):</p>
<p>* kernel: fs/smb/client: fix out-of-bounds read in cifs_sanitize_prepath (CVE-2026-43112)</p>
<p>* kernel: net: mana: Fix double destroy_workqueue on service rescan PCI path (CVE-2026-43276)</p>
<p>* kernel: Linux kernel: Use-After-Free in net/gro due to improper handling of zerocopy skbs (CVE-2026-46323)</p>
<p>* kernel: xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete (CVE-2026-46116)</p>
<p>* kernel: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (CVE-2026-46227)</p>
<p>* kernel: drm/gem: Fix inconsistent plane dimension calculation in drm_gem_fb_init_with_funcs() (CVE-2026-46209)</p>
<p>* kernel: smb/client: fix out-of-bounds read in smb2_compound_op() (CVE-2026-46155)</p>
<p>* kernel: netfilter: nft_inner: Fix IPv6 inner_thoff desync (CVE-2026-46244)</p>
<p>* kernel: procfs: fix missing RCU protection when reading real_parent in do_task_stat() (CVE-2026-46259)</p>
<p>* kernel: Arm Processors: Privilege escalation or information disclosure via writes to higher exception level resources (CVE-2025-10263)</p>
<p>* kernel: KVM: arm64: vgic-its: Drop the translation cache reference only for the erased entry (CVE-2026-46316)</p>
<p>Bug Fix(es) and Enhancement(s):</p>
<p>* WARNING at drivers/gpu/drm/nouveau/nvkm/subdev/gsp/r535.c:1585 r535_gsp_fini+0x2fb/0x310 [nouveau] [rhel-9.8.z] (JIRA:Rocky Linux-160966)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgme…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:36018"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:22099-1</id>
    <title>SUSE-SU-2026:22099-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-03T08:07:28.472742+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:22099-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-46316</id>
    <title>UBUNTU-CVE-2026-46316</title>
    <updated>2026-10-03T08:07:28.472798+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 123 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic-its: Drop the translation cache reference only for the erased entry vgic_its_invalidate_cache() walks the per-ITS translation cache with xa_for_each() and drops the cache's reference on each entry with vgic_put_irq(). It puts the iterated pointer, though, rather than the value returned by xa_erase(). The function is called from contexts that do not exclude one another: the ITS command handlers hold its_lock, the GITS_CTLR write path holds cmd_lock, and the path that clears EnableLPIs in a redistributor's GICR_CTLR holds neither. Two or more of them can drain the same cache concurrently, and if each one observes the same entry, erases it and then puts it, the single reference the cache holds on that entry is dropped more than once. The entry can then be freed while an ITE still maps it. xa_erase() is atomic and returns the previous entry, so put only the entry that this context actually removed. The cache reference is then dropped exactly once per entry even when the invalidations run concurrently, and the behavior is unchanged when only one context runs.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-46316"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1870</id>
    <title>WID-SEC-W-2026-1870 — Linux Kernel: Mehrere Schwachstellen ermöglichen Denial of Service</title>
    <updated>2026-10-03T08:07:28.472974+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Eiin Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen Denial-of-Service-Zustand zu erzeugen oder andere, nicht näher bezeichnete Angriffe durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1870"/>
  </entry>
</feed>
