<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T14:49:44.896064+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:71232</id>
    <title>ALSA-2026:71232 — Important: kernel security, bug fix, and enhancement update</title>
    <updated>2026-10-02T14:49:45.523613+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:9: kernel, AlmaLinux:9: kernel-64k, AlmaLinux:9: kernel-64k-core, AlmaLinux:9: kernel-64k-debug, AlmaLinux:9: kernel-64k-debug-core, AlmaLinux:9: kernel-64k-debug-modules, AlmaLinux:9: kernel-64k-debug-modules-core, AlmaLinux:9: kernel-64k-debug-modules-extra, AlmaLinux:9: kernel-64k-modules, AlmaLinux:9: kernel-64k-modules-core and 7 more</p>
<p>The kernel packages contain the Linux kernel, the core of any Linux operating system.</p>
<p>Security Fix(es):</p>
<p>* kernel: block: zero non-PI portion of auto integrity buffer (CVE-2026-23007)
  * kernel: af_unix: Drop all SCM attributes for SOCKMAP (CVE-2026-53005)
  * kernel: mac802154: llsec: add skb_cow_data() before in-place crypto (CVE-2026-63831)
  * kernel: blk-cgroup: fix UAF in __blkcg_rstat_flush() (CVE-2026-63802)
  * kernel: block: don't overwrite bip_vcnt in bio_integrity_copy_user() (CVE-2026-64053)
  * kernel: smb: client: fix double-free in SMB2_flush() replay (CVE-2026-64383)
  * kernel: nvmet-tcp: check INIT_FAILED before nvmet_req_uninit in digest error path (CVE-2026-64534)
  * kernel: sctp: don't free the ASCONF's own transport in DEL-IP processing (CVE-2026-64564)
  * kernel: ALSA: timer: drain a slave's callback before its master detaches it (CVE-2026-68201)
  * kernel: ASoC: SOF: ipc3-control: Validate size in snd_sof_update_control (CVE-2026-72261)
  * kernel: xfrm: ah6: validate routing header segments_left (CVE-2026-80844)
  * kernel: net: tun: bound receive headroom (CVE-2026-81000)
  * kernel: scsi: qla2xxx: Bound rsp_info_len to avoid OOB sense-data read (CVE-2026-89846)</p>
<p>Bug Fix(es) and Enhancement(s):</p>
<p>* sctp: prevent peer transport count overflow [almalinux-9.8.z] (JIRA:AlmaLinux-216251)
  * netfilter: nftables CVE and memory safety backports for 9.8 (JIRA:AlmaLinux-236634)</p>
<p>For more details about the security issue(s), including the imp…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:71232"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-53005</id>
    <title>BELL-CVE-2026-53005</title>
    <updated>2026-10-02T14:49:45.523764+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-53005"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0926</id>
    <title>certfr-2026-avi-0926 — De multiples vulnérabilités ont été découvertes dans le noyau Linux d'Ubuntu. Certaines d'entre elles permettent à un a…</title>
    <updated>2026-10-02T14:49:45.523791+00:00</updated>
    <content>certfr-2026-avi-0926</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0926"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-348126</id>
    <title>EUVD-2026-348126</title>
    <updated>2026-10-02T14:49:45.523810+00:00</updated>
    <content>EUVD-2026-348126</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-348126"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-53005</id>
    <title>fkie_cve-2026-53005</title>
    <updated>2026-10-02T14:49:45.523822+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>af_unix: Drop all SCM attributes for SOCKMAP.</p>
<p>SOCKMAP can hide inflight fd from AF_UNIX GC.</p>
<p>When a socket in SOCKMAP receives skb with inflight fd,
sk_psock_verdict_data_ready() looks up the mapped socket and
enqueue skb to its psock-&gt;ingress_skb.</p>
<p>Since neither the old nor the new GC can inspect the psock
queue, the hidden skb leaks the inflight sockets.  Note that
this cannot be detected via kmemleak because inflight sockets
are linked to a global list.</p>
<p>In addition, SOCKMAP redirect breaks the Tarjan-based GC's
assumption that unix_edge.successor is always alive, which
is no longer true once skb is redirected, resulting in
use-after-free below. [0]</p>
<p>Moreover, SOCKMAP does not call scm_stat_del() properly,
so unix_show_fdinfo() could report an incorrect fd count.</p>
<p>sk_msg_recvmsg() does not support any SCM attributes in the
first place.</p>
<p>Let's drop all SCM attributes before passing skb to the
SOCKMAP layer.</p>
<p>[0]:
BUG: KASAN: slab-use-after-free in unix_del_edges (net/unix/garbage.c:118 net/unix/garbage.c:181 net/unix/garbage.c:251)
Read of size 8 at addr ffff888125362670 by task kworker/56:1/496</p>
<p>CPU: 56 UID: 0 PID: 496 Comm: kworker/56:1 Not tainted 7.0.0-rc7-00263-gb9d8b856689d #3 PREEMPT(lazy)
Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.17.0-debian-1.17.0-1 04/01/2014
Workqueue: events sk_psock_backlog
Call Trace:
 &lt;TASK&gt;
 dump_stack_lvl (lib/dump_stack.c:122)
 print_report (mm/kasan…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-53005"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-6qfx-pmxg-8gxp</id>
    <title>GHSA-6qfx-pmxg-8gxp</title>
    <updated>2026-10-02T14:49:45.523871+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>af_unix: Drop all SCM attributes for SOCKMAP.</p>
<p>SOCKMAP can hide inflight fd from AF_UNIX GC.</p>
<p>When a socket in SOCKMAP receives skb with inflight fd,
sk_psock_verdict_data_ready() looks up the mapped socket and
enqueue skb to its psock-&gt;ingress_skb.</p>
<p>Since neither the old nor the new GC can inspect the psock
queue, the hidden skb leaks the inflight sockets.  Note that
this cannot be detected via kmemleak because inflight sockets
are linked to a global list.</p>
<p>In addition, SOCKMAP redirect breaks the Tarjan-based GC's
assumption that unix_edge.successor is always alive, which
is no longer true once skb is redirected, resulting in
use-after-free below. [0]</p>
<p>Moreover, SOCKMAP does not call scm_stat_del() properly,
so unix_show_fdinfo() could report an incorrect fd count.</p>
<p>sk_msg_recvmsg() does not support any SCM attributes in the
first place.</p>
<p>Let's drop all SCM attributes before passing skb to the
SOCKMAP layer.</p>
<p>[0]:
BUG: KASAN: slab-use-after-free in unix_del_edges (net/unix/garbage.c:118 net/unix/garbage.c:181 net/unix/garbage.c:251)
Read of size 8 at addr ffff888125362670 by task kworker/56:1/496</p>
<p>CPU: 56 UID: 0 PID: 496 Comm: kworker/56:1 Not tainted 7.0.0-rc7-00263-gb9d8b856689d #3 PREEMPT(lazy)
Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.17.0-debian-1.17.0-1 04/01/2014
Workqueue: events sk_psock_backlog
Call Trace:
 &lt;TASK&gt;
 dump_stack_lvl (lib/dump_stack.c:122)
 print_report (mm/kasan…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-6qfx-pmxg-8gxp"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-53005</id>
    <title>msrc_CVE-2026-53005 — af_unix: Drop all SCM attributes for SOCKMAP.</title>
    <updated>2026-10-02T14:49:45.523910+00:00</updated>
    <content>msrc_CVE-2026-53005</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-53005"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:21555-1</id>
    <title>openSUSE-SU-2026:21555-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-02T14:49:45.523927+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:21555-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:71602</id>
    <title>RHSA-2026:71602 — Red Hat Security Advisory: kernel security, bug fix, and enhancement update</title>
    <updated>2026-10-02T14:49:45.524468+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>kernel: fbcon: Set fb_display[i]-&gt;mode to NULL when the mode is released kernel: libceph: fix potential use-after-free in have_mon_and_osd_map() kernel: libceph: make decode_pool() more resilient against corrupted osdmaps kernel: libceph: prevent potential out-of-bounds reads in handle_auth_done() kernel: libceph: replace overzealous BUG_ON in osdmap_apply_incremental() kernel: Linux kernel: Denial of Service in libceph OSD client due to unreset sparse-read state kernel: drm/amdgpu/vcn4: Prevent OOB reads when parsing dec msg kernel: drm/amdgpu/vcn4: Prevent OOB reads when parsing IB kernel: drm/amdgpu/vcn3: Prevent OOB reads when parsing dec msg kernel: drm/amdgpu/userq: fix access to stale wptr mapping kernel: af_unix: Drop all SCM attributes for SOCKMAP kernel: accel/ivpu: Add buffer overflow check in MS get_info_ioctl kernel: drm/xe/eustall: Fix drm_dev_put called before stream disable in close kernel: drm/virtio: use uninterruptible resv lock for plane updates kernel: drm/amdgpu/vce: fix integer overflow in image size kernel: pppoe: reload header pointer after dev_hard_header() kernel: drm/amdkfd: fix 32-bit overflow in CWSR total size calculation kernel: drm/xe: Hold a dma-buf reference for imported BOs kernel: drm/xe/rtp: Add RING_FORCE_TO_NONPRIV_DENY to OA whitelists kernel: drm/amdgpu: Fix context pstate override handling kernel: ipvs: do not propagate one-packet flag to synced conns kernel: nvme-tcp: fix host memory disclosure on R2T for a read command</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:71602"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:71232</id>
    <title>RLSA-2026:71232 — Important: kernel security, bug fix, and enhancement update</title>
    <updated>2026-10-02T14:49:45.524524+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:9: kernel</p>
<p>The kernel packages contain the Linux kernel, the core of any Linux operating system.</p>
<p>Security Fix(es):</p>
<p>* kernel: block: zero non-PI portion of auto integrity buffer (CVE-2026-23007)</p>
<p>* kernel: af_unix: Drop all SCM attributes for SOCKMAP (CVE-2026-53005)</p>
<p>* kernel: mac802154: llsec: add skb_cow_data() before in-place crypto (CVE-2026-63831)</p>
<p>* kernel: blk-cgroup: fix UAF in __blkcg_rstat_flush() (CVE-2026-63802)</p>
<p>* kernel: block: don't overwrite bip_vcnt in bio_integrity_copy_user() (CVE-2026-64053)</p>
<p>* kernel: smb: client: fix double-free in SMB2_flush() replay (CVE-2026-64383)</p>
<p>* kernel: nvmet-tcp: check INIT_FAILED before nvmet_req_uninit in digest error path (CVE-2026-64534)</p>
<p>* kernel: sctp: don't free the ASCONF's own transport in DEL-IP processing (CVE-2026-64564)</p>
<p>* kernel: ALSA: timer: drain a slave's callback before its master detaches it (CVE-2026-68201)</p>
<p>* kernel: ASoC: SOF: ipc3-control: Validate size in snd_sof_update_control (CVE-2026-72261)</p>
<p>* kernel: xfrm: ah6: validate routing header segments_left (CVE-2026-80844)</p>
<p>* kernel: net: tun: bound receive headroom (CVE-2026-81000)</p>
<p>* kernel: scsi: qla2xxx: Bound rsp_info_len to avoid OOB sense-data read (CVE-2026-89846)</p>
<p>Bug Fix(es) and Enhancement(s):</p>
<p>* sctp: prevent peer transport count overflow [rhel-9.8.z] (JIRA:Rocky Linux-216251)</p>
<p>* netfilter: nftables CVE and memory safety backports for 9.8 (JIRA:Rocky Linux-236634)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowl…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:71232"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:23066-1</id>
    <title>SUSE-SU-2026:23066-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-02T14:49:45.524568+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:23066-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-53005</id>
    <title>UBUNTU-CVE-2026-53005</title>
    <updated>2026-10-02T14:49:45.525027+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 201 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: af_unix: Drop all SCM attributes for SOCKMAP. SOCKMAP can hide inflight fd from AF_UNIX GC. When a socket in SOCKMAP receives skb with inflight fd, sk_psock_verdict_data_ready() looks up the mapped socket and enqueue skb to its psock-&gt;ingress_skb. Since neither the old nor the new GC can inspect the psock queue, the hidden skb leaks the inflight sockets.  Note that this cannot be detected via kmemleak because inflight sockets are linked to a global list. In addition, SOCKMAP redirect breaks the Tarjan-based GC's assumption that unix_edge.successor is always alive, which is no longer true once skb is redirected, resulting in use-after-free below. [0] Moreover, SOCKMAP does not call scm_stat_del() properly, so unix_show_fdinfo() could report an incorrect fd count. sk_msg_recvmsg() does not support any SCM attributes in the first place. Let's drop all SCM attributes before passing skb to the SOCKMAP layer. [0]: BUG: KASAN: slab-use-after-free in unix_del_edges (net/unix/garbage.c:118 net/unix/garbage.c:181 net/unix/garbage.c:251) Read of size 8 at addr ffff888125362670 by task kworker/56:1/496 CPU: 56 UID: 0 PID: 496 Comm: kworker/56:1 Not tainted 7.0.0-rc7-00263-gb9d8b856689d #3 PREEMPT(lazy) Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.17.0-debian-1.17.0-1 04/01/2014 Workqueue: events sk_psock_backlog Call Trace:  &lt;TASK&gt;  dump_stack_lvl (lib/dump_stack.c:122)  print_report (mm/kasan/report.c:…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-53005"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2077</id>
    <title>WID-SEC-W-2026-2077 — Linux Kernel: Mehrere Schwachstellen</title>
    <updated>2026-10-02T14:49:45.525266+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um Sicherheitsvorkehrungen zu umgehen, einen Denial-of-Service-Zustand herbeizuführen und weitere, nicht näher spezifizierte Auswirkungen zu erzielen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2077"/>
  </entry>
</feed>
