<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T23:00:07.921578+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:66180</id>
    <title>ALSA-2026:66180 — Important: kernel security, bug fix, and enhancement update</title>
    <updated>2026-10-03T23:00:08.175826+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:9: kernel, AlmaLinux:9: kernel-64k, AlmaLinux:9: kernel-64k-core, AlmaLinux:9: kernel-64k-debug, AlmaLinux:9: kernel-64k-debug-core, AlmaLinux:9: kernel-64k-debug-devel, AlmaLinux:9: kernel-64k-debug-devel-matched, AlmaLinux:9: kernel-64k-debug-modules, AlmaLinux:9: kernel-64k-debug-modules-core, AlmaLinux:9: kernel-64k-debug-modules-extra and 64 more</p>
<p>The kernel packages contain the Linux kernel, the core of any Linux operating system.</p>
<p>Security Fix(es):</p>
<p>* kernel: KVM: nSVM: Always use vmcb01 in VMLOAD/VMSAVE emulation (CVE-2026-43133)
  * kernel: ipv6: prevent possible UaF in addrconf_permanent_addr() (CVE-2026-43339)
  * kernel: crypto: pcrypt - Fix handling of MAY_BACKLOG requests (CVE-2026-43493)
  * kernel: tcp: call sk_data_ready() after listener migration (CVE-2026-46015)
  * kernel: scsi: target: configfs: Bound snprintf() return in tg_pt_gp_members_show() (CVE-2026-46149)
  * kernel: inet: RAW sockets using IPPROTO_RAW MUST drop incoming ICMP (CVE-2026-46266)
  * kernel: flow_dissector: do not dissect PPPoE PFC frames (CVE-2026-46306)
  * kernel: Revert "net/smc: Introduce TCP ULP support" (CVE-2026-46330)
  * kernel: netfilter: conntrack: remove sprintf usage (CVE-2026-53002)
  * kernel: net: guard timestamp cmsgs to real error queue skbs (CVE-2026-53223)
  * kernel: ipv6: mcast: Fix use-after-free when processing MLD queries (CVE-2026-53275)
  * kernel: ipv4: account for fraggap on the paged allocation path (CVE-2026-53366)
  * kernel: net: mana: Fix TOCTOU double-fetch of hwc_msg_id from DMA buffer (CVE-2026-64034)
  * kernel: rhashtable: clear stale iter-&gt;p on table restart (CVE-2026-64563)
  * kernel: smb: client: fix double-free in SMB2_close() replay (CVE-2026-64597)
  * kernel: nvmet-rdma: handle inline data with a nonzero offset (CVE-2026-72129)
  * kernel: net: bridge: stop fast-leave after delet…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:66180"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-46330</id>
    <title>BELL-CVE-2026-46330</title>
    <updated>2026-10-03T23:00:08.176029+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-46330"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0864</id>
    <title>certfr-2026-avi-0864 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de SUSE. Certaines d'entre elles permettent à un at…</title>
    <updated>2026-10-03T23:00:08.176060+00:00</updated>
    <content>certfr-2026-avi-0864</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0864"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-348082</id>
    <title>EUVD-2026-348082</title>
    <updated>2026-10-03T23:00:08.176080+00:00</updated>
    <content>EUVD-2026-348082</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-348082"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-46330</id>
    <title>fkie_cve-2026-46330</title>
    <updated>2026-10-03T23:00:08.176092+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>Revert "net/smc: Introduce TCP ULP support"</p>
<p>This reverts commit d7cd421da9da2cc7b4d25b8537f66db5c8331c40.</p>
<p>As reported by Al Viro, the TCP ULP support for SMC is fundamentally
broken. The implementation attempts to convert an active TCP socket
into an SMC socket by modifying the underlying `struct file`, dentry,
and inode in-place, which violates core VFS invariants that assume
these structures are immutable for an open file, creating a risk of
use after free errors and general system instability.</p>
<p>Given the severity of this design flaw and the fact that cleaner
alternatives (e.g., LD_PRELOAD, BPF) exist for legacy application
transparency, the correct course of action is to remove this feature
entirely.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-46330"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-fm5x-69c3-7mfj</id>
    <title>GHSA-fm5x-69c3-7mfj</title>
    <updated>2026-10-03T23:00:08.176125+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>Revert "net/smc: Introduce TCP ULP support"</p>
<p>This reverts commit d7cd421da9da2cc7b4d25b8537f66db5c8331c40.</p>
<p>As reported by Al Viro, the TCP ULP support for SMC is fundamentally
broken. The implementation attempts to convert an active TCP socket
into an SMC socket by modifying the underlying `struct file`, dentry,
and inode in-place, which violates core VFS invariants that assume
these structures are immutable for an open file, creating a risk of
use after free errors and general system instability.</p>
<p>Given the severity of this design flaw and the fact that cleaner
alternatives (e.g., LD_PRELOAD, BPF) exist for legacy application
transparency, the correct course of action is to remove this feature
entirely.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-fm5x-69c3-7mfj"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-46330</id>
    <title>msrc_CVE-2026-46330 — Revert "net/smc: Introduce TCP ULP support"</title>
    <updated>2026-10-03T23:00:08.176147+00:00</updated>
    <content>msrc_CVE-2026-46330</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-46330"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-2869</id>
    <title>OESA-2026-2869 — kernel security update</title>
    <updated>2026-10-03T23:00:08.176167+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS-SP3: kernel</p>
<p>The Linux Kernel, the operating system core itself.

Security Fix(es):</p>
<p>Arm C1-Ultra, C1-Premium, Neoverse V3 &amp;amp; V3AE, Neoverse V2, Neoverse V1, Neoverse-N2, Neoverse-N1, Cortex-X925, Cortex-X4, Cortex-X3, Cortex-X2, Cortex-X1 &amp;amp; X1C, Cortex-A710, Cortex-A78, A78AE &amp;amp; A78C, Cortex-A77, Cortex-A76 &amp;amp; A76A may allow writes to resources owned by a higher exception level.(CVE-2025-10263)</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>smb: client: let smbd_destroy() call disable_work_sync(&amp;amp;info-&amp;gt;post_send_credits_work)</p>
<p>In smbd_destroy() we may destroy the memory so we better
wait until post_send_credits_work is no longer pending
and will never be started again.</p>
<p>I actually just hit the case using rxe:</p>
<p>WARNING: CPU: 0 PID: 138 at drivers/infiniband/sw/rxe/rxe_verbs.c:1032 rxe_post_recv+0x1ee/0x480 [rdma_rxe]
...
[ 5305.686979] [    T138]  smbd_post_recv+0x445/0xc10 [cifs]
[ 5305.687135] [    T138]  ? srso_alias_return_thunk+0x5/0xfbef5
[ 5305.687149] [    T138]  ? __kasan_check_write+0x14/0x30
[ 5305.687185] [    T138]  ? __pfx_smbd_post_recv+0x10/0x10 [cifs]
[ 5305.687329] [    T138]  ? __pfx__raw_spin_lock_irqsave+0x10/0x10
[ 5305.687356] [    T138]  ? srso_alias_return_thunk+0x5/0xfbef5
[ 5305.687368] [    T138]  ? srso_alias_return_thunk+0x5/0xfbef5
[ 5305.687378] [    T138]  ? _raw_spin_unlock_irqrestore+0x11/0x60
[ 5305.687389] [    T138]  ? srso_alias_return_thunk+0x5/0xfbef5
[ 5305.687399] [    T138]  ? get_receive_buffer+0x168…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-2869"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:66180</id>
    <title>RHSA-2026:66180 — Red Hat Security Advisory: kernel security, bug fix, and enhancement update</title>
    <updated>2026-10-03T23:00:08.176456+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>kernel: KVM: nSVM: Always use vmcb01 in VMLOAD/VMSAVE emulation kernel: ipv6: prevent possible UaF in addrconf_permanent_addr() kernel: crypto: pcrypt - Fix handling of MAY_BACKLOG requests kernel: tcp: call sk_data_ready() after listener migration kernel: scsi: target: configfs: Bound snprintf() return in tg_pt_gp_members_show() kernel: inet: RAW sockets using IPPROTO_RAW MUST drop incoming ICMP kernel: flow_dissector: do not dissect PPPoE PFC frames kernel: Revert "net/smc: Introduce TCP ULP support" kernel: netfilter: conntrack: remove sprintf usage kernel: net: guard timestamp cmsgs to real error queue skbs kernel: ipv6: mcast: Fix use-after-free when processing MLD queries kernel: ipv4: account for fraggap on the paged allocation path kernel: net: mana: Fix TOCTOU double-fetch of hwc_msg_id from DMA buffer kernel: rhashtable: clear stale iter-&gt;p on table restart kernel: smb: client: fix double-free in SMB2_close() replay kernel: nvmet-rdma: handle inline data with a nonzero offset kernel: net: bridge: stop fast-leave after deleting a port group</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:66180"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:66180</id>
    <title>RLSA-2026:66180 — Important: kernel security, bug fix, and enhancement update</title>
    <updated>2026-10-03T23:00:08.176512+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:9: kernel</p>
<p>The kernel packages contain the Linux kernel, the core of any Linux operating system.</p>
<p>Security Fix(es):</p>
<p>* kernel: KVM: nSVM: Always use vmcb01 in VMLOAD/VMSAVE emulation (CVE-2026-43133)</p>
<p>* kernel: ipv6: prevent possible UaF in addrconf_permanent_addr() (CVE-2026-43339)</p>
<p>* kernel: crypto: pcrypt - Fix handling of MAY_BACKLOG requests (CVE-2026-43493)</p>
<p>* kernel: tcp: call sk_data_ready() after listener migration (CVE-2026-46015)</p>
<p>* kernel: scsi: target: configfs: Bound snprintf() return in tg_pt_gp_members_show() (CVE-2026-46149)</p>
<p>* kernel: inet: RAW sockets using IPPROTO_RAW MUST drop incoming ICMP (CVE-2026-46266)</p>
<p>* kernel: flow_dissector: do not dissect PPPoE PFC frames (CVE-2026-46306)</p>
<p>* kernel: Revert "net/smc: Introduce TCP ULP support" (CVE-2026-46330)</p>
<p>* kernel: netfilter: conntrack: remove sprintf usage (CVE-2026-53002)</p>
<p>* kernel: net: guard timestamp cmsgs to real error queue skbs (CVE-2026-53223)</p>
<p>* kernel: ipv6: mcast: Fix use-after-free when processing MLD queries (CVE-2026-53275)</p>
<p>* kernel: ipv4: account for fraggap on the paged allocation path (CVE-2026-53366)</p>
<p>* kernel: net: mana: Fix TOCTOU double-fetch of hwc_msg_id from DMA buffer (CVE-2026-64034)</p>
<p>* kernel: rhashtable: clear stale iter-&gt;p on table restart (CVE-2026-64563)</p>
<p>* kernel: smb: client: fix double-free in SMB2_close() replay (CVE-2026-64597)</p>
<p>* kernel: nvmet-rdma: handle inline data with a nonzero offset (CVE-2026-72129)</p>
<p>* kernel: net: bridge: stop fast-leave after deleting a port group (CVE-…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:66180"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:2840-1</id>
    <title>SUSE-SU-2026:2840-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-03T23:00:08.176558+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:2840-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-46330</id>
    <title>UBUNTU-CVE-2026-46330</title>
    <updated>2026-10-03T23:00:08.176594+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 141 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: Revert "net/smc: Introduce TCP ULP support" This reverts commit d7cd421da9da2cc7b4d25b8537f66db5c8331c40. As reported by Al Viro, the TCP ULP support for SMC is fundamentally broken. The implementation attempts to convert an active TCP socket into an SMC socket by modifying the underlying `struct file`, dentry, and inode in-place, which violates core VFS invariants that assume these structures are immutable for an open file, creating a risk of use after free errors and general system instability. Given the severity of this design flaw and the fact that cleaner alternatives (e.g., LD_PRELOAD, BPF) exist for legacy application transparency, the correct course of action is to remove this feature entirely.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-46330"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1870</id>
    <title>WID-SEC-W-2026-1870 — Linux Kernel: Mehrere Schwachstellen ermöglichen Denial of Service</title>
    <updated>2026-10-03T23:00:08.176835+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Eiin Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen Denial-of-Service-Zustand zu erzeugen oder andere, nicht näher bezeichnete Angriffe durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1870"/>
  </entry>
</feed>
