<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T03:21:51.754941+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:71329</id>
    <title>ALSA-2026:71329 — Important: kernel security update</title>
    <updated>2026-10-04T03:21:52.630544+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: bpftool, AlmaLinux:8: kernel, AlmaLinux:8: kernel-abi-stablelists, AlmaLinux:8: kernel-core, AlmaLinux:8: kernel-cross-headers, AlmaLinux:8: kernel-debug, AlmaLinux:8: kernel-debug-core, AlmaLinux:8: kernel-debug-devel, AlmaLinux:8: kernel-debug-modules, AlmaLinux:8: kernel-debug-modules-extra and 15 more</p>
<p>The kernel packages contain the Linux kernel, the core of any Linux operating system.</p>
<p>Security Fix(es):</p>
<p>* kernel: drm/amdgpu: Fix fence put before wait in amdgpu_amdkfd_submit_ib (CVE-2026-31566)
  * kernel: netfilter: nf_queue: hold bridge skb-&gt;dev while queued (CVE-2026-52912)
  * kernel: Linux kernel: PPPoE memory corruption via stale pointer (CVE-2026-68121)
  * kernel: Linux kernel IPVS: Denial of Service due to stale memory references (CVE-2026-80714)
  * kernel: nvme-tcp: reject a read that transferred too few bytes (CVE-2026-89480)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:71329"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-14801</id>
    <title>bdu:2026-14801</title>
    <updated>2026-10-04T03:21:52.630672+00:00</updated>
    <content>bdu:2026-14801</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-14801"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-52912</id>
    <title>BELL-CVE-2026-52912</title>
    <updated>2026-10-04T03:21:52.630692+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-52912"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0812</id>
    <title>certfr-2026-avi-0812 — De multiples vulnérabilités ont été découvertes dans Microsoft Azure Linux. Elles permettent à un attaquant de provoque…</title>
    <updated>2026-10-04T03:21:52.630714+00:00</updated>
    <content>certfr-2026-avi-0812</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0812"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-364826</id>
    <title>EUVD-2026-364826</title>
    <updated>2026-10-04T03:21:52.630730+00:00</updated>
    <content>EUVD-2026-364826</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-364826"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-52912</id>
    <title>fkie_cve-2026-52912</title>
    <updated>2026-10-04T03:21:52.630742+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>netfilter: nf_queue: hold bridge skb-&gt;dev while queued</p>
<p>br_pass_frame_up() rewrites skb-&gt;dev from the ingress port to the bridge
master before queueing bridge LOCAL_IN packets. NFQUEUE only holds
references on state.in/out and bridge physdevs, so a queued bridge
packet can retain a freed bridge master in skb-&gt;dev until reinjection.</p>
<p>When the verdict is reinjected later, br_netif_receive_skb() re-enters
the receive path with skb-&gt;dev still pointing at the freed bridge master,
triggering a use-after-free.</p>
<p>Store skb-&gt;dev in the queue entry, hold a reference on it for the queue
lifetime, and use the saved device when dropping queued packets during
NETDEV_DOWN handling.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-52912"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-ffm7-9f73-pvmf</id>
    <title>GHSA-ffm7-9f73-pvmf</title>
    <updated>2026-10-04T03:21:52.630772+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>netfilter: nf_queue: hold bridge skb-&gt;dev while queued</p>
<p>br_pass_frame_up() rewrites skb-&gt;dev from the ingress port to the bridge
master before queueing bridge LOCAL_IN packets. NFQUEUE only holds
references on state.in/out and bridge physdevs, so a queued bridge
packet can retain a freed bridge master in skb-&gt;dev until reinjection.</p>
<p>When the verdict is reinjected later, br_netif_receive_skb() re-enters
the receive path with skb-&gt;dev still pointing at the freed bridge master,
triggering a use-after-free.</p>
<p>Store skb-&gt;dev in the queue entry, hold a reference on it for the queue
lifetime, and use the saved device when dropping queued packets during
NETDEV_DOWN handling.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-ffm7-9f73-pvmf"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-52912</id>
    <title>msrc_CVE-2026-52912 — netfilter: nf_queue: hold bridge skb-&gt;dev while queued</title>
    <updated>2026-10-04T03:21:52.630793+00:00</updated>
    <content>msrc_CVE-2026-52912</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-52912"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-3206</id>
    <title>OESA-2026-3206 — kernel security update</title>
    <updated>2026-10-04T03:21:52.630809+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:22.03-LTS-SP4: kernel</p>
<p>The Linux Kernel, the operating system core itself.

Security Fix(es):</p>
<p>Arm C1-Ultra, C1-Premium, Neoverse V3 &amp;amp; V3AE, Neoverse V2, Neoverse V1, Neoverse-N2, Neoverse-N1, Cortex-X925, Cortex-X4, Cortex-X3, Cortex-X2, Cortex-X1 &amp;amp; X1C, Cortex-A710, Cortex-A78, A78AE &amp;amp; A78C, Cortex-A77, Cortex-A76 &amp;amp; A76A may allow writes to resources owned by a higher exception level.(CVE-2025-10263)</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>inet: RAW sockets using IPPROTO_RAW MUST drop incoming ICMP</p>
<p>Yizhou Zhao reported that simply having one RAW socket on protocol
IPPROTO_RAW (255) was dangerous.</p>
<p>socket(AF_INET, SOCK_RAW, 255);</p>
<p>A malicious incoming ICMP packet can set the protocol field to 255
and match this socket, leading to FNHE cache changes.</p>
<p>inner = IP(src=&amp;quot;192.168.2.1&amp;quot;, dst=&amp;quot;8.8.8.8&amp;quot;, proto=255)/Raw(&amp;quot;TEST&amp;quot;)
pkt = IP(src=&amp;quot;192.168.1.1&amp;quot;, dst=&amp;quot;192.168.2.1&amp;quot;)/ICMP(type=3, code=4, nexthopmtu=576)/inner</p>
<p>&amp;quot;man 7 raw&amp;quot; states:</p>
<p>A protocol of IPPROTO_RAW implies enabled IP_HDRINCL and is able
  to send any IP protocol that is specified in the passed header.
  Receiving of all IP protocols via IPPROTO_RAW is not possible
  using raw sockets.</p>
<p>Make sure we drop these malicious packets.(CVE-2026-46266)</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>tun: free page on build_skb failure in tun_xdp_one()</p>
<p>When build_skb() fails in tun_xdp_one(), the function sets ret to
-…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-3206"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:21910-1</id>
    <title>openSUSE-SU-2026:21910-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-04T03:21:52.630917+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:21910-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:71330</id>
    <title>RHSA-2026:71330 — Red Hat Security Advisory: kernel-rt security update</title>
    <updated>2026-10-04T03:21:52.631414+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>kernel: drm/amdgpu: Fix fence put before wait in amdgpu_amdkfd_submit_ib kernel: netfilter: nf_queue: hold bridge skb-&gt;dev while queued kernel: pppoe: reload header pointer after dev_hard_header() kernel: ipvs: do not propagate one-packet flag to synced conns kernel: nvme-tcp: reject a read that transferred too few bytes</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:71330"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:71329</id>
    <title>RLSA-2026:71329 — Important: kernel security update</title>
    <updated>2026-10-04T03:21:52.631438+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:8: kernel</p>
<p>The kernel packages contain the Linux kernel, the core of any Linux operating system.</p>
<p>Security Fix(es):</p>
<p>* kernel: drm/amdgpu: Fix fence put before wait in amdgpu_amdkfd_submit_ib (CVE-2026-31566)</p>
<p>* kernel: netfilter: nf_queue: hold bridge skb-&gt;dev while queued (CVE-2026-52912)</p>
<p>* kernel: Linux kernel: PPPoE memory corruption via stale pointer (CVE-2026-68121)</p>
<p>* kernel: Linux kernel IPVS: Denial of Service due to stale memory references (CVE-2026-80714)</p>
<p>* kernel: nvme-tcp: reject a read that transferred too few bytes (CVE-2026-89480)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:71329"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ssa-019113</id>
    <title>SSA-019113 — SSA-019113: Vulnerabilities in the additional GNU/Linux subsystem of the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1.6</title>
    <updated>2026-10-04T03:21:52.631467+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.6 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant).</p>
<p>Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ssa-019113"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:23881-1</id>
    <title>SUSE-SU-2026:23881-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-04T03:21:52.631687+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:23881-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-52912</id>
    <title>UBUNTU-CVE-2026-52912</title>
    <updated>2026-10-04T03:21:52.632119+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe, Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:Pro:16.04:LTS: linux-oracle, Ubuntu:Pro:18.04:LTS: linux, Ubuntu:Pro:18.04:LTS: linux-aws, Ubuntu:18.04:LTS: linux-aws-5.0 and 247 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_queue: hold bridge skb-&gt;dev while queued br_pass_frame_up() rewrites skb-&gt;dev from the ingress port to the bridge master before queueing bridge LOCAL_IN packets. NFQUEUE only holds references on state.in/out and bridge physdevs, so a queued bridge packet can retain a freed bridge master in skb-&gt;dev until reinjection. When the verdict is reinjected later, br_netif_receive_skb() re-enters the receive path with skb-&gt;dev still pointing at the freed bridge master, triggering a use-after-free. Store skb-&gt;dev in the queue entry, hold a reference on it for the queue lifetime, and use the saved device when dropping queued packets during NETDEV_DOWN handling.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-52912"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2056</id>
    <title>WID-SEC-W-2026-2056 — Linux Kernel: Mehrere Schwachstellen</title>
    <updated>2026-10-04T03:21:52.632391+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen Denial-of-Service-Angriff  auszulösen oder andere, nicht näher spezifizierte Angriffe durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2056"/>
  </entry>
</feed>
