<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T19:29:53.038336+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:42919</id>
    <title>ALSA-2026:42919 — Important: kernel security, bug fix, and enhancement update</title>
    <updated>2026-10-02T19:29:54.283201+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:10: kernel, AlmaLinux:10: kernel-64k, AlmaLinux:10: kernel-64k-core, AlmaLinux:10: kernel-64k-debug, AlmaLinux:10: kernel-64k-debug-core, AlmaLinux:10: kernel-64k-debug-devel, AlmaLinux:10: kernel-64k-debug-devel-matched, AlmaLinux:10: kernel-64k-debug-modules, AlmaLinux:10: kernel-64k-debug-modules-core, AlmaLinux:10: kernel-64k-debug-modules-extra and 65 more</p>
<p>The kernel packages contain the Linux kernel, the core of any Linux operating system.</p>
<p>Security Fix(es):</p>
<p>* kernel: crypto: af_alg - zero initialize memory allocated via sock_kmalloc (CVE-2025-71113)
  * kernel: Linux kernel: Denial of Service due to memory leak in tpm2_load_cmd (CVE-2025-71147)
  * kernel: flex_proportions: make fprop_new_period() hardirq safe (CVE-2026-23168)
  * kernel: cxl/port: Fix use after free of parent_port in cxl_detach_ep() (CVE-2026-31530)
  * kernel: xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete (CVE-2026-46116)
  * kernel: fanotify: fix false positive on permission events (CVE-2026-46150)
  * kernel: drm: Set old handle to NULL before prime swap in change_handle (CVE-2026-46215)
  * kernel: drm/xe: Fix error cleanup in xe_exec_queue_create_ioctl() (CVE-2026-52976)
  * kernel: drm/xe/dma-buf: fix UAF with retry loop (CVE-2026-52950)
  * kernel: ice: fix double-free of tx_buf skb (CVE-2026-53009)
  * kernel: Bluetooth: l2cap: Add missing chan lock in l2cap_ecred_reconf_rsp (CVE-2026-53071)
  * kernel: can: bcm: thrtimer use-after-free during RX operation teardown ()</p>
<p>Bug Fix(es) and Enhancement(s):</p>
<p>* nfsd_file slab cache objects remaining on kmem_cache_shutdown during nfsd teardown while running bz1477872 testcase (JIRA:AlmaLinux-173103)
  * tools/lib/perf/Makefile: libperf includes appended after CFLAGS causes parallel build race, breaking kernel builds [almalinux-10.2.z] (JIRA:AlmaLinux-183975)
  * [AlmaLinux10-de…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:42919"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-13949</id>
    <title>bdu:2026-13949</title>
    <updated>2026-10-02T19:29:54.283478+00:00</updated>
    <content>bdu:2026-13949</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-13949"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-53009</id>
    <title>BELL-CVE-2026-53009</title>
    <updated>2026-10-02T19:29:54.283500+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-53009"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0926</id>
    <title>certfr-2026-avi-0926 — De multiples vulnérabilités ont été découvertes dans le noyau Linux d'Ubuntu. Certaines d'entre elles permettent à un a…</title>
    <updated>2026-10-02T19:29:54.283523+00:00</updated>
    <content>certfr-2026-avi-0926</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0926"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-365495</id>
    <title>EUVD-2026-365495</title>
    <updated>2026-10-02T19:29:54.283540+00:00</updated>
    <content>EUVD-2026-365495</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-365495"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-53009</id>
    <title>fkie_cve-2026-53009</title>
    <updated>2026-10-02T19:29:54.283559+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>ice: fix double-free of tx_buf skb</p>
<p>If ice_tso() or ice_tx_csum() fail, the error path in
ice_xmit_frame_ring() frees the skb, but the 'first' tx_buf still points
to it and is marked as valid (ICE_TX_BUF_SKB).
'next_to_use' remains unchanged, so the potential problem will
likely fix itself when the next packet is transmitted and the tx_buf
gets overwritten. But if there is no next packet and the interface is
brought down instead, ice_clean_tx_ring() -&gt; ice_unmap_and_free_tx_buf()
will find the tx_buf and free the skb for the second time.</p>
<p>The fix is to reset the tx_buf type to ICE_TX_BUF_EMPTY in the error
path, so that ice_unmap_and_free_tx_buf().
Move the initialization of 'first' up, to ensure it's already valid in
case we hit the linearization error path.</p>
<p>The bug was spotted by AI while I had it looking for something else.
It also proposed an initial version of the patch.</p>
<p>I reproduced the bug and tested the fix by adding code to inject
failures, on a build with KASAN.</p>
<p>I looked for similar bugs in related Intel drivers and did not find any.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-53009"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-67p5-53x6-9j7q</id>
    <title>GHSA-67p5-53x6-9j7q</title>
    <updated>2026-10-02T19:29:54.283596+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>ice: fix double-free of tx_buf skb</p>
<p>If ice_tso() or ice_tx_csum() fail, the error path in
ice_xmit_frame_ring() frees the skb, but the 'first' tx_buf still points
to it and is marked as valid (ICE_TX_BUF_SKB).
'next_to_use' remains unchanged, so the potential problem will
likely fix itself when the next packet is transmitted and the tx_buf
gets overwritten. But if there is no next packet and the interface is
brought down instead, ice_clean_tx_ring() -&gt; ice_unmap_and_free_tx_buf()
will find the tx_buf and free the skb for the second time.</p>
<p>The fix is to reset the tx_buf type to ICE_TX_BUF_EMPTY in the error
path, so that ice_unmap_and_free_tx_buf().
Move the initialization of 'first' up, to ensure it's already valid in
case we hit the linearization error path.</p>
<p>The bug was spotted by AI while I had it looking for something else.
It also proposed an initial version of the patch.</p>
<p>I reproduced the bug and tested the fix by adding code to inject
failures, on a build with KASAN.</p>
<p>I looked for similar bugs in related Intel drivers and did not find any.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-67p5-53x6-9j7q"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-53009</id>
    <title>msrc_CVE-2026-53009 — ice: fix double-free of tx_buf skb</title>
    <updated>2026-10-02T19:29:54.283621+00:00</updated>
    <content>msrc_CVE-2026-53009</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-53009"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-3156</id>
    <title>OESA-2026-3156 — kernel security update</title>
    <updated>2026-10-02T19:29:54.283639+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:22.03-LTS-SP4: kernel</p>
<p>The Linux Kernel, the operating system core itself.

Security Fix(es):</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>drbd: add missing kref_get in handle_write_conflicts</p>
<p>With `two-primaries` enabled, DRBD tries to detect &amp;quot;concurrent&amp;quot; writes
and handle write conflicts, so that even if you write to the same sector
simultaneously on both nodes, they end up with the identical data once
the writes are completed.</p>
<p>In handling &amp;quot;superseeded&amp;quot; writes, we forgot a kref_get,
resulting in a premature drbd_destroy_device and use after free,
and further to kernel crashes with symptoms.</p>
<p>Relevance: No one should use DRBD as a random data generator, and apparently
all users of &amp;quot;two-primaries&amp;quot; handle concurrent writes correctly on layer up.
That is cluster file systems use some distributed lock manager,
and live migration in virtualization environments stops writes on one node
before starting writes on the other node.</p>
<p>Which means that other than for &amp;quot;test cases&amp;quot;,
this code path is never taken in real life.</p>
<p>FYI, in DRBD 9, things are handled differently nowadays.  We still detect
&amp;quot;write conflicts&amp;quot;, but no longer try to be smart about them.
We decided to disconnect hard instead: upper layers must not submit concurrent
writes. If they do, that&amp;apos;s their fault.(CVE-2025-38708)</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>wifi: mwifiex: Initialize the chan_stats array to zero</p>
<p>The adapter-&amp;gt…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-3156"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:21555-1</id>
    <title>openSUSE-SU-2026:21555-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-02T19:29:54.283768+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:21555-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:54246</id>
    <title>RHSA-2026:54246 — Red Hat Security Advisory: kernel security update</title>
    <updated>2026-10-02T19:29:54.284245+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>kernel: udf: fix partition descriptor append bookkeeping kernel: ice: fix double-free of tx_buf skb</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:54246"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:42919</id>
    <title>RLSA-2026:42919 — Important: kernel security, bug fix, and enhancement update</title>
    <updated>2026-10-02T19:29:54.284266+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:10: kernel</p>
<p>The kernel packages contain the Linux kernel, the core of any Linux operating system.</p>
<p>Security Fix(es):</p>
<p>* kernel: crypto: af_alg - zero initialize memory allocated via sock_kmalloc (CVE-2025-71113)</p>
<p>* kernel: Linux kernel: Denial of Service due to memory leak in tpm2_load_cmd (CVE-2025-71147)</p>
<p>* kernel: flex_proportions: make fprop_new_period() hardirq safe (CVE-2026-23168)</p>
<p>* kernel: cxl/port: Fix use after free of parent_port in cxl_detach_ep() (CVE-2026-31530)</p>
<p>* kernel: xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete (CVE-2026-46116)</p>
<p>* kernel: fanotify: fix false positive on permission events (CVE-2026-46150)</p>
<p>* kernel: drm: Set old handle to NULL before prime swap in change_handle (CVE-2026-46215)</p>
<p>* kernel: drm/xe: Fix error cleanup in xe_exec_queue_create_ioctl() (CVE-2026-52976)</p>
<p>* kernel: drm/xe/dma-buf: fix UAF with retry loop (CVE-2026-52950)</p>
<p>* kernel: ice: fix double-free of tx_buf skb (CVE-2026-53009)</p>
<p>* kernel: Bluetooth: l2cap: Add missing chan lock in l2cap_ecred_reconf_rsp (CVE-2026-53071)</p>
<p>* kernel: can: bcm: thrtimer use-after-free during RX operation teardown ()</p>
<p>Bug Fix(es) and Enhancement(s):</p>
<p>* nfsd_file slab cache objects remaining on kmem_cache_shutdown during nfsd teardown while running bz1477872 testcase (JIRA:Rocky Linux-173103)</p>
<p>* tools/lib/perf/Makefile: libperf includes appended after CFLAGS causes parallel build race, breaking kernel builds [rhel-10.2.z] (JIRA:Rocky Linux-183975)</p>
<p>* [Rocky Linux10-debug]: BUG: KASAN: slab-…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:42919"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:23066-1</id>
    <title>SUSE-SU-2026:23066-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-02T19:29:54.284310+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:23066-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-53009</id>
    <title>UBUNTU-CVE-2026-53009</title>
    <updated>2026-10-02T19:29:54.284771+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:Pro:18.04:LTS: linux-aws-5.4, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:Pro:18.04:LTS: linux-azure-5.4, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3 and 227 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: ice: fix double-free of tx_buf skb If ice_tso() or ice_tx_csum() fail, the error path in ice_xmit_frame_ring() frees the skb, but the 'first' tx_buf still points to it and is marked as valid (ICE_TX_BUF_SKB). 'next_to_use' remains unchanged, so the potential problem will likely fix itself when the next packet is transmitted and the tx_buf gets overwritten. But if there is no next packet and the interface is brought down instead, ice_clean_tx_ring() -&gt; ice_unmap_and_free_tx_buf() will find the tx_buf and free the skb for the second time. The fix is to reset the tx_buf type to ICE_TX_BUF_EMPTY in the error path, so that ice_unmap_and_free_tx_buf(). Move the initialization of 'first' up, to ensure it's already valid in case we hit the linearization error path. The bug was spotted by AI while I had it looking for something else. It also proposed an initial version of the patch. I reproduced the bug and tested the fix by adding code to inject failures, on a build with KASAN. I looked for similar bugs in related Intel drivers and did not find any.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-53009"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2077</id>
    <title>WID-SEC-W-2026-2077 — Linux Kernel: Mehrere Schwachstellen</title>
    <updated>2026-10-02T19:29:54.285025+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um Sicherheitsvorkehrungen zu umgehen, einen Denial-of-Service-Zustand herbeizuführen und weitere, nicht näher spezifizierte Auswirkungen zu erzielen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2077"/>
  </entry>
</feed>
