<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T14:21:49.567058+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:72623</id>
    <title>ALSA-2026:72623 — Important: kernel security, bug fix, and enhancement update</title>
    <updated>2026-10-03T14:21:49.800699+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:9: kernel, AlmaLinux:9: kernel-64k, AlmaLinux:9: kernel-64k-core, AlmaLinux:9: kernel-64k-debug, AlmaLinux:9: kernel-64k-debug-core, AlmaLinux:9: kernel-64k-debug-devel, AlmaLinux:9: kernel-64k-debug-devel-matched, AlmaLinux:9: kernel-64k-debug-modules, AlmaLinux:9: kernel-64k-debug-modules-core, AlmaLinux:9: kernel-64k-debug-modules-extra and 64 more</p>
<p>The kernel packages contain the Linux kernel, the core of any Linux operating system.</p>
<p>Security Fix(es):</p>
<p>* kernel: ext4: fix e4b bitmap inconsistency reports (CVE-2026-45942)
  * kernel: RDMA/rxe: Fix iova-to-va conversion for MR page sizes != PAGE_SIZE (CVE-2026-46325)
  * kernel: crypto: af_alg - Cap AEAD AD length to 0x80000000 (CVE-2026-52972)
  * kernel: fhandle: fix UAF due to unlocked -&gt;mnt_ns read in may_decode_fh() (CVE-2026-53341)
  * kernel: arm64: tlb: Flush walk cache when unsharing PMD tables (CVE-2026-63875)
  * kernel: RDMA/siw: Reject MPA FPDU length underflow before signed receive math (CVE-2026-64102)
  * kernel: perf/core: Detach event groups during remove_on_exec (CVE-2026-64556)
  * kernel: crypto: tegra - fix rctx-&gt;cryptlen calculation in tegra_gcm_do_one_req() (CVE-2026-80522)
  * kernel: perf: Reject exited events as group leaders (CVE-2026-74753)</p>
<p>Bug Fix(es) and Enhancement(s):</p>
<p>* KVM: s390: Limit adapter indicator access to mapped page [almalinux-9.8.z] (JIRA:AlmaLinux-188656)
  * crypto: xxhash64 should not be fips approved [almalinux-9.8.z] (JIRA:AlmaLinux-256437)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:72623"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-46325</id>
    <title>BELL-CVE-2026-46325</title>
    <updated>2026-10-03T14:21:49.800856+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-46325"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0831</id>
    <title>certfr-2026-avi-0831 — De multiples vulnérabilités ont été découvertes dans le noyau Linux d'Ubuntu. Certaines d'entre elles permettent à un a…</title>
    <updated>2026-10-03T14:21:49.800882+00:00</updated>
    <content>certfr-2026-avi-0831</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0831"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-348078</id>
    <title>EUVD-2026-348078</title>
    <updated>2026-10-03T14:21:49.800901+00:00</updated>
    <content>EUVD-2026-348078</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-348078"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-46325</id>
    <title>fkie_cve-2026-46325</title>
    <updated>2026-10-03T14:21:49.800912+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>RDMA/rxe: Fix iova-to-va conversion for MR page sizes != PAGE_SIZE</p>
<p>The current implementation incorrectly handles memory regions (MRs) with
page sizes different from the system PAGE_SIZE. The core issue is that
rxe_set_page() is called with mr-&gt;page_size step increments, but the
page_list stores individual struct page pointers, each representing
PAGE_SIZE of memory.</p>
<p>ib_sg_to_page() has ensured that when i&gt;=1 either
a) SG[i-1].dma_end and SG[i].dma_addr are contiguous
or
b) SG[i-1].dma_end and SG[i].dma_addr are mr-&gt;page_size aligned.</p>
<p>This leads to incorrect iova-to-va conversion in scenarios:</p>
<p>1) page_size &lt; PAGE_SIZE (e.g., MR: 4K, system: 64K):
   ibmr-&gt;iova = 0x181800
   sg[0]: dma_addr=0x181800, len=0x800
   sg[1]: dma_addr=0x173000, len=0x1000</p>
<p>Access iova = 0x181800 + 0x810 = 0x182010
   Expected VA: 0x173010 (second SG, offset 0x10)
   Before fix:
     - index = (0x182010 &gt;&gt; 12) - (0x181800 &gt;&gt; 12) = 1
     - page_offset = 0x182010 &amp; 0xFFF = 0x10
     - xarray[1] stores system page base 0x170000
     - Resulting VA: 0x170000 + 0x10 = 0x170010 (wrong)</p>
<p>2) page_size &gt; PAGE_SIZE (e.g., MR: 64K, system: 4K):
   ibmr-&gt;iova = 0x18f800
   sg[0]: dma_addr=0x18f800, len=0x800
   sg[1]: dma_addr=0x170000, len=0x1000</p>
<p>Access iova = 0x18f800 + 0x810 = 0x190010
   Expected VA: 0x170010 (second SG, offset 0x10)
   Before fix:
     - index = (0x190010 &gt;&gt; 16) - (0x18f800 &gt;&gt; 16) = 1
     - page_offset = 0x190…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-46325"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-rmw9-5h46-94mm</id>
    <title>GHSA-rmw9-5h46-94mm</title>
    <updated>2026-10-03T14:21:49.800962+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>RDMA/rxe: Fix iova-to-va conversion for MR page sizes != PAGE_SIZE</p>
<p>The current implementation incorrectly handles memory regions (MRs) with
page sizes different from the system PAGE_SIZE. The core issue is that
rxe_set_page() is called with mr-&gt;page_size step increments, but the
page_list stores individual struct page pointers, each representing
PAGE_SIZE of memory.</p>
<p>ib_sg_to_page() has ensured that when i&gt;=1 either
a) SG[i-1].dma_end and SG[i].dma_addr are contiguous
or
b) SG[i-1].dma_end and SG[i].dma_addr are mr-&gt;page_size aligned.</p>
<p>This leads to incorrect iova-to-va conversion in scenarios:</p>
<p>1) page_size &lt; PAGE_SIZE (e.g., MR: 4K, system: 64K):
   ibmr-&gt;iova = 0x181800
   sg[0]: dma_addr=0x181800, len=0x800
   sg[1]: dma_addr=0x173000, len=0x1000</p>
<p>Access iova = 0x181800 + 0x810 = 0x182010
   Expected VA: 0x173010 (second SG, offset 0x10)
   Before fix:
     - index = (0x182010 &gt;&gt; 12) - (0x181800 &gt;&gt; 12) = 1
     - page_offset = 0x182010 &amp; 0xFFF = 0x10
     - xarray[1] stores system page base 0x170000
     - Resulting VA: 0x170000 + 0x10 = 0x170010 (wrong)</p>
<p>2) page_size &gt; PAGE_SIZE (e.g., MR: 64K, system: 4K):
   ibmr-&gt;iova = 0x18f800
   sg[0]: dma_addr=0x18f800, len=0x800
   sg[1]: dma_addr=0x170000, len=0x1000</p>
<p>Access iova = 0x18f800 + 0x810 = 0x190010
   Expected VA: 0x170010 (second SG, offset 0x10)
   Before fix:
     - index = (0x190010 &gt;&gt; 16) - (0x18f800 &gt;&gt; 16) = 1
     - page_offset = 0x190…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-rmw9-5h46-94mm"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-46325</id>
    <title>msrc_CVE-2026-46325 — RDMA/rxe: Fix iova-to-va conversion for MR page sizes != PAGE_SIZE</title>
    <updated>2026-10-03T14:21:49.801002+00:00</updated>
    <content>msrc_CVE-2026-46325</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-46325"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-3707</id>
    <title>OESA-2026-3707 — kernel security update</title>
    <updated>2026-10-03T14:21:49.801019+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS-SP1: kernel</p>
<p>The Linux Kernel, the operating system core itself.

Security Fix(es):</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>seg6: separate dst_cache for input and output paths in seg6 lwtunnel</p>
<p>The seg6 lwtunnel uses a single dst_cache per encap route, shared
between seg6_input_core() and seg6_output_core(). These two paths
can perform the post-encap SID lookup in different routing contexts
(e.g., ip rules matching on the ingress interface, or VRF table
separation). Whichever path runs first populates the cache, and the
other reuses it blindly, bypassing its own lookup.</p>
<p>Fix this by splitting the cache into cache_input and cache_output,
so each path maintains its own cached dst independently.(CVE-2026-31668)</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>RDMA/rxe: Fix iova-to-va conversion for MR page sizes != PAGE_SIZE</p>
<p>The current implementation incorrectly handles memory regions (MRs) with
page sizes different from the system PAGE_SIZE. The core issue is that
rxe_set_page() is called with mr-&amp;gt;page_size step increments, but the
page_list stores individual struct page pointers, each representing
PAGE_SIZE of memory.</p>
<p>ib_sg_to_page() has ensured that when i&amp;gt;=1 either
a) SG[i-1].dma_end and SG[i].dma_addr are contiguous
or
b) SG[i-1].dma_end and SG[i].dma_addr are mr-&amp;gt;page_size aligned.</p>
<p>This leads to incorrect iova-to-va conversion in scenarios:</p>
<p>1) page_size &amp;lt; PAGE_SIZE (e.g., MR: 4K, system: 64K):
   ibmr-&amp;gt;iova = 0x1…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-3707"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:72623</id>
    <title>RHSA-2026:72623 — Red Hat Security Advisory: kernel security, bug fix, and enhancement update</title>
    <updated>2026-10-03T14:21:49.801540+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>kernel: ext4: fix e4b bitmap inconsistency reports kernel: RDMA/rxe: Fix iova-to-va conversion for MR page sizes != PAGE_SIZE kernel: crypto: af_alg - Cap AEAD AD length to 0x80000000 kernel: fhandle: fix UAF due to unlocked -&gt;mnt_ns read in may_decode_fh() kernel: arm64: tlb: Flush walk cache when unsharing PMD tables kernel: RDMA/siw: Reject MPA FPDU length underflow before signed receive math kernel: perf/core: Detach event groups during remove_on_exec kernel: perf: Reject exited events as group leaders kernel: crypto: tegra - fix rctx-&gt;cryptlen calculation in tegra_gcm_do_one_req()</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:72623"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:72623</id>
    <title>RLSA-2026:72623 — Important: kernel security, bug fix, and enhancement update</title>
    <updated>2026-10-03T14:21:49.801604+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:9: kernel</p>
<p>The kernel packages contain the Linux kernel, the core of any Linux operating system.</p>
<p>Security Fix(es):</p>
<p>* kernel: ext4: fix e4b bitmap inconsistency reports (CVE-2026-45942)</p>
<p>* kernel: RDMA/rxe: Fix iova-to-va conversion for MR page sizes != PAGE_SIZE (CVE-2026-46325)</p>
<p>* kernel: crypto: af_alg - Cap AEAD AD length to 0x80000000 (CVE-2026-52972)</p>
<p>* kernel: fhandle: fix UAF due to unlocked -&gt;mnt_ns read in may_decode_fh() (CVE-2026-53341)</p>
<p>* kernel: arm64: tlb: Flush walk cache when unsharing PMD tables (CVE-2026-63875)</p>
<p>* kernel: RDMA/siw: Reject MPA FPDU length underflow before signed receive math (CVE-2026-64102)</p>
<p>* kernel: perf/core: Detach event groups during remove_on_exec (CVE-2026-64556)</p>
<p>* kernel: crypto: tegra - fix rctx-&gt;cryptlen calculation in tegra_gcm_do_one_req() (CVE-2026-80522)</p>
<p>* kernel: perf: Reject exited events as group leaders (CVE-2026-74753)</p>
<p>Bug Fix(es) and Enhancement(s):</p>
<p>* KVM: s390: Limit adapter indicator access to mapped page [rhel-9.8.z] (JIRA:Rocky Linux-188656)</p>
<p>* crypto: xxhash64 should not be fips approved [rhel-9.8.z] (JIRA:Rocky Linux-256437)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:72623"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-46325</id>
    <title>UBUNTU-CVE-2026-46325</title>
    <updated>2026-10-03T14:21:49.801656+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 141 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix iova-to-va conversion for MR page sizes != PAGE_SIZE The current implementation incorrectly handles memory regions (MRs) with page sizes different from the system PAGE_SIZE. The core issue is that rxe_set_page() is called with mr-&gt;page_size step increments, but the page_list stores individual struct page pointers, each representing PAGE_SIZE of memory. ib_sg_to_page() has ensured that when i&gt;=1 either a) SG[i-1].dma_end and SG[i].dma_addr are contiguous or b) SG[i-1].dma_end and SG[i].dma_addr are mr-&gt;page_size aligned. This leads to incorrect iova-to-va conversion in scenarios: 1) page_size &lt; PAGE_SIZE (e.g., MR: 4K, system: 64K):    ibmr-&gt;iova = 0x181800    sg[0]: dma_addr=0x181800, len=0x800    sg[1]: dma_addr=0x173000, len=0x1000    Access iova = 0x181800 + 0x810 = 0x182010    Expected VA: 0x173010 (second SG, offset 0x10)    Before fix:      - index = (0x182010 &gt;&gt; 12) - (0x181800 &gt;&gt; 12) = 1      - page_offset = 0x182010 &amp; 0xFFF = 0x10      - xarray[1] stores system page base 0x170000      - Resulting VA: 0x170000 + 0x10 = 0x170010 (wrong) 2) page_size &gt; PAGE_SIZE (e.g., MR: 64K, system: 4K):    ibmr-&gt;iova = 0x18f800    sg[0]: dma_addr=0x18f800, len=0x800    sg[1]: dma_addr=0x170000, len=0x1000    Access iova = 0x18f800 + 0x810 = 0x190010    Expected VA: 0x170010 (second SG, offset 0x10)    Before fix:      - index = (0x190010 &gt;&gt; 16) - (0x18f800 &gt;&gt; 16) = 1      - page_offset = 0x190010 &amp; 0x…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-46325"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1870</id>
    <title>WID-SEC-W-2026-1870 — Linux Kernel: Mehrere Schwachstellen ermöglichen Denial of Service</title>
    <updated>2026-10-03T14:21:49.801876+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Eiin Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen Denial-of-Service-Zustand zu erzeugen oder andere, nicht näher bezeichnete Angriffe durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1870"/>
  </entry>
</feed>
