<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T00:42:44.660123+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-13903</id>
    <title>bdu:2026-13903</title>
    <updated>2026-10-04T00:42:45.635152+00:00</updated>
    <content>bdu:2026-13903</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-13903"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-52927</id>
    <title>BELL-CVE-2026-52927</title>
    <updated>2026-10-04T00:42:45.635231+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-52927"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0812</id>
    <title>certfr-2026-avi-0812 — De multiples vulnérabilités ont été découvertes dans Microsoft Azure Linux. Elles permettent à un attaquant de provoque…</title>
    <updated>2026-10-04T00:42:45.635343+00:00</updated>
    <content>certfr-2026-avi-0812</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0812"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-348096</id>
    <title>EUVD-2026-348096</title>
    <updated>2026-10-04T00:42:45.635362+00:00</updated>
    <content>EUVD-2026-348096</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-348096"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-52927</id>
    <title>fkie_cve-2026-52927</title>
    <updated>2026-10-04T00:42:45.635375+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>netfilter: ebtables: fix OOB read in compat_mtw_from_user</p>
<p>Luxiao Xu says:</p>
<p>The function compat_mtw_from_user() converts ebtables extensions from
 32-bit user structures to kernel native structures. However, it lacks
 proper validation of the user-supplied match_size/target_size.</p>
<p>When certain extensions are processed, the kernel-side translation
 logic may perform memory accesses based on the extension's expected
 size. If the user provides a size smaller than what the extension
 requires, it results in an out-of-bounds read as reported by KASAN.</p>
<p>This fix introduces a check to ensure match_size is at least as large
 as the extension's required compatsize. This covers matches, watchers,
 and targets, while maintaining compatibility with standard targets.</p>
<p>AFAIU this is relevant for matches that need to go though
match-&gt;compat_from_user() call.  Those that use plain memcpy with the
user-provided size are ok because the caller checks that size vs the
start of the next rule entry offset (which itself is checked vs. total
size copied from userspace).</p>
<p>The -&gt;compat_from_user() callbacks assume they can read compatsize bytes,
so they need this extra check.</p>
<p>Based on an earlier patch from Luxiao Xu.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-52927"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-c6h6-mmcc-x4qj</id>
    <title>GHSA-c6h6-mmcc-x4qj</title>
    <updated>2026-10-04T00:42:45.635417+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>netfilter: ebtables: fix OOB read in compat_mtw_from_user</p>
<p>Luxiao Xu says:</p>
<p>The function compat_mtw_from_user() converts ebtables extensions from
 32-bit user structures to kernel native structures. However, it lacks
 proper validation of the user-supplied match_size/target_size.</p>
<p>When certain extensions are processed, the kernel-side translation
 logic may perform memory accesses based on the extension's expected
 size. If the user provides a size smaller than what the extension
 requires, it results in an out-of-bounds read as reported by KASAN.</p>
<p>This fix introduces a check to ensure match_size is at least as large
 as the extension's required compatsize. This covers matches, watchers,
 and targets, while maintaining compatibility with standard targets.</p>
<p>AFAIU this is relevant for matches that need to go though
match-&gt;compat_from_user() call.  Those that use plain memcpy with the
user-provided size are ok because the caller checks that size vs the
start of the next rule entry offset (which itself is checked vs. total
size copied from userspace).</p>
<p>The -&gt;compat_from_user() callbacks assume they can read compatsize bytes,
so they need this extra check.</p>
<p>Based on an earlier patch from Luxiao Xu.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-c6h6-mmcc-x4qj"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-52927</id>
    <title>msrc_CVE-2026-52927 — netfilter: ebtables: fix OOB read in compat_mtw_from_user</title>
    <updated>2026-10-04T00:42:45.635446+00:00</updated>
    <content>msrc_CVE-2026-52927</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-52927"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-3206</id>
    <title>OESA-2026-3206 — kernel security update</title>
    <updated>2026-10-04T00:42:45.635464+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:22.03-LTS-SP4: kernel</p>
<p>The Linux Kernel, the operating system core itself.

Security Fix(es):</p>
<p>Arm C1-Ultra, C1-Premium, Neoverse V3 &amp;amp; V3AE, Neoverse V2, Neoverse V1, Neoverse-N2, Neoverse-N1, Cortex-X925, Cortex-X4, Cortex-X3, Cortex-X2, Cortex-X1 &amp;amp; X1C, Cortex-A710, Cortex-A78, A78AE &amp;amp; A78C, Cortex-A77, Cortex-A76 &amp;amp; A76A may allow writes to resources owned by a higher exception level.(CVE-2025-10263)</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>inet: RAW sockets using IPPROTO_RAW MUST drop incoming ICMP</p>
<p>Yizhou Zhao reported that simply having one RAW socket on protocol
IPPROTO_RAW (255) was dangerous.</p>
<p>socket(AF_INET, SOCK_RAW, 255);</p>
<p>A malicious incoming ICMP packet can set the protocol field to 255
and match this socket, leading to FNHE cache changes.</p>
<p>inner = IP(src=&amp;quot;192.168.2.1&amp;quot;, dst=&amp;quot;8.8.8.8&amp;quot;, proto=255)/Raw(&amp;quot;TEST&amp;quot;)
pkt = IP(src=&amp;quot;192.168.1.1&amp;quot;, dst=&amp;quot;192.168.2.1&amp;quot;)/ICMP(type=3, code=4, nexthopmtu=576)/inner</p>
<p>&amp;quot;man 7 raw&amp;quot; states:</p>
<p>A protocol of IPPROTO_RAW implies enabled IP_HDRINCL and is able
  to send any IP protocol that is specified in the passed header.
  Receiving of all IP protocols via IPPROTO_RAW is not possible
  using raw sockets.</p>
<p>Make sure we drop these malicious packets.(CVE-2026-46266)</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>tun: free page on build_skb failure in tun_xdp_one()</p>
<p>When build_skb() fails in tun_xdp_one(), the function sets ret to
-…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-3206"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:21555-1</id>
    <title>openSUSE-SU-2026:21555-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-04T00:42:45.635574+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:21555-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:23066-1</id>
    <title>SUSE-SU-2026:23066-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-04T00:42:45.636150+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:23066-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-52927</id>
    <title>UBUNTU-CVE-2026-52927</title>
    <updated>2026-10-04T00:42:45.636665+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: linux, Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe and 254 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: netfilter: ebtables: fix OOB read in compat_mtw_from_user Luxiao Xu says:  The function compat_mtw_from_user() converts ebtables extensions from  32-bit user structures to kernel native structures. However, it lacks  proper validation of the user-supplied match_size/target_size.  When certain extensions are processed, the kernel-side translation  logic may perform memory accesses based on the extension's expected  size. If the user provides a size smaller than what the extension  requires, it results in an out-of-bounds read as reported by KASAN.  This fix introduces a check to ensure match_size is at least as large  as the extension's required compatsize. This covers matches, watchers,  and targets, while maintaining compatibility with standard targets. AFAIU this is relevant for matches that need to go though match-&gt;compat_from_user() call.  Those that use plain memcpy with the user-provided size are ok because the caller checks that size vs the start of the next rule entry offset (which itself is checked vs. total size copied from userspace). The -&gt;compat_from_user() callbacks assume they can read compatsize bytes, so they need this extra check. Based on an earlier patch from Luxiao Xu.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-52927"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2056</id>
    <title>WID-SEC-W-2026-2056 — Linux Kernel: Mehrere Schwachstellen</title>
    <updated>2026-10-04T00:42:45.636954+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen Denial-of-Service-Angriff  auszulösen oder andere, nicht näher spezifizierte Angriffe durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2056"/>
  </entry>
</feed>
