<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T01:51:58.315699+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:42550</id>
    <title>ALSA-2026:42550 — Important: kernel-rt security, bug fix, and enhancement update</title>
    <updated>2026-10-04T01:51:59.317542+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: kernel-rt, AlmaLinux:8: kernel-rt-core, AlmaLinux:8: kernel-rt-debug, AlmaLinux:8: kernel-rt-debug-core, AlmaLinux:8: kernel-rt-debug-devel, AlmaLinux:8: kernel-rt-debug-modules, AlmaLinux:8: kernel-rt-debug-modules-extra, AlmaLinux:8: kernel-rt-devel, AlmaLinux:8: kernel-rt-modules, AlmaLinux:8: kernel-rt-modules-extra</p>
<p>The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements.</p>
<p>Security Fix(es):</p>
<p>* kernel: RDMA/mana: Remove user triggerable WARN_ON() in mana_ib_create_qp_rss() (CVE-2026-46117)
  * kernel: Bluetooth: l2cap: Add missing chan lock in l2cap_ecred_reconf_rsp (CVE-2026-53071)</p>
<p>Bug Fix(es) and Enhancement(s):</p>
<p>* [almalinux-8] WARNING: HARDIRQ-safe -&gt; HARDIRQ-unsafe lock order detected - at: vmd_pci_write+0x85/0xe0 - deadlock (JIRA:AlmaLinux-174916)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:42550"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-13979</id>
    <title>bdu:2026-13979</title>
    <updated>2026-10-04T01:51:59.317638+00:00</updated>
    <content>bdu:2026-13979</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-13979"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-53071</id>
    <title>BELL-CVE-2026-53071</title>
    <updated>2026-10-04T01:51:59.317656+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-53071"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0862</id>
    <title>certfr-2026-avi-0862 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de Debian LTS. Certaines d'entre elles permettent à…</title>
    <updated>2026-10-04T01:51:59.317678+00:00</updated>
    <content>certfr-2026-avi-0862</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0862"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-369293</id>
    <title>EUVD-2026-369293</title>
    <updated>2026-10-04T01:51:59.317695+00:00</updated>
    <content>EUVD-2026-369293</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-369293"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-53071</id>
    <title>fkie_cve-2026-53071</title>
    <updated>2026-10-04T01:51:59.317706+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>Bluetooth: l2cap: Add missing chan lock in l2cap_ecred_reconf_rsp</p>
<p>l2cap_ecred_reconf_rsp() calls l2cap_chan_del() without holding
l2cap_chan_lock(). Every other l2cap_chan_del() caller in the file
acquires the lock first. A remote BLE device can send a crafted
L2CAP ECRED reconfiguration response to corrupt the channel list
while another thread is iterating it.</p>
<p>Add l2cap_chan_hold() and l2cap_chan_lock() before l2cap_chan_del(),
and l2cap_chan_unlock() and l2cap_chan_put() after, matching the
pattern used in l2cap_ecred_conn_rsp() and l2cap_conn_del().</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-53071"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-g7cw-xhg8-933g</id>
    <title>GHSA-g7cw-xhg8-933g</title>
    <updated>2026-10-04T01:51:59.317733+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>Bluetooth: l2cap: Add missing chan lock in l2cap_ecred_reconf_rsp</p>
<p>l2cap_ecred_reconf_rsp() calls l2cap_chan_del() without holding
l2cap_chan_lock(). Every other l2cap_chan_del() caller in the file
acquires the lock first. A remote BLE device can send a crafted
L2CAP ECRED reconfiguration response to corrupt the channel list
while another thread is iterating it.</p>
<p>Add l2cap_chan_hold() and l2cap_chan_lock() before l2cap_chan_del(),
and l2cap_chan_unlock() and l2cap_chan_put() after, matching the
pattern used in l2cap_ecred_conn_rsp() and l2cap_conn_del().</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-g7cw-xhg8-933g"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-53071</id>
    <title>msrc_CVE-2026-53071 — Bluetooth: l2cap: Add missing chan lock in l2cap_ecred_reconf_rsp</title>
    <updated>2026-10-04T01:51:59.317752+00:00</updated>
    <content>msrc_CVE-2026-53071</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-53071"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-2871</id>
    <title>OESA-2026-2871 — kernel security update</title>
    <updated>2026-10-04T01:51:59.317768+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:22.03-LTS-SP4: kernel</p>
<p>The Linux Kernel, the operating system core itself.

Security Fix(es):</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>netfilter: nf_conntrack_expect: use expect-&amp;gt;helper</p>
<p>Use expect-&amp;gt;helper in ctnetlink and /proc to dump the helper name.
Using nfct_help() without holding a reference to the master conntrack
is unsafe.</p>
<p>Use exp-&amp;gt;master-&amp;gt;helper in ctnetlink path if userspace does not provide
an explicit helper when creating an expectation to retain the existing
behaviour. The ctnetlink expectation path holds the reference on the
master conntrack and nf_conntrack_expect lock and the nfnetlink glue
path refers to the master ct that is attached to the skb.(CVE-2026-31414)</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>xfs: avoid dereferencing log items after push callbacks</p>
<p>After xfsaild_push_item() calls iop_push(), the log item may have been
freed if the AIL lock was dropped during the push. Background inode
reclaim or the dquot shrinker can free the log item while the AIL lock
is not held, and the tracepoints in the switch statement dereference
the log item after iop_push() returns.</p>
<p>Fix this by capturing the log item type, flags, and LSN before calling
xfsaild_push_item(), and introducing a new xfs_ail_push_class trace
event class that takes these pre-captured values and the ailp pointer
instead of the log item pointer.(CVE-2026-31453)</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>xfs: stop recl…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-2871"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:21555-1</id>
    <title>openSUSE-SU-2026:21555-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-04T01:51:59.317859+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:21555-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:42550</id>
    <title>RHSA-2026:42550 — Red Hat Security Advisory: kernel-rt security, bug fix, and enhancement update</title>
    <updated>2026-10-04T01:51:59.318480+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>kernel: RDMA/mana: Remove user triggerable WARN_ON() in mana_ib_create_qp_rss() kernel: Bluetooth: l2cap: Add missing chan lock in l2cap_ecred_reconf_rsp</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:42550"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:42550</id>
    <title>RLSA-2026:42550 — Important: kernel-rt security, bug fix, and enhancement update</title>
    <updated>2026-10-04T01:51:59.318524+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:8: kernel-rt</p>
<p>The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements.</p>
<p>Security Fix(es):</p>
<p>* kernel: RDMA/mana: Remove user triggerable WARN_ON() in mana_ib_create_qp_rss() (CVE-2026-46117)</p>
<p>* kernel: Bluetooth: l2cap: Add missing chan lock in l2cap_ecred_reconf_rsp (CVE-2026-53071)</p>
<p>Bug Fix(es) and Enhancement(s):</p>
<p>*  [rhel-8] WARNING: HARDIRQ-safe -&gt; HARDIRQ-unsafe lock order detected - at: vmd_pci_write+0x85/0xe0 - deadlock (JIRA:Rocky Linux-174916)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:42550"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:22521-1</id>
    <title>SUSE-SU-2026:22521-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-04T01:51:59.318568+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:22521-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-53071</id>
    <title>UBUNTU-CVE-2026-53071</title>
    <updated>2026-10-04T01:51:59.318660+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 200 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: Bluetooth: l2cap: Add missing chan lock in l2cap_ecred_reconf_rsp l2cap_ecred_reconf_rsp() calls l2cap_chan_del() without holding l2cap_chan_lock(). Every other l2cap_chan_del() caller in the file acquires the lock first. A remote BLE device can send a crafted L2CAP ECRED reconfiguration response to corrupt the channel list while another thread is iterating it. Add l2cap_chan_hold() and l2cap_chan_lock() before l2cap_chan_del(), and l2cap_chan_unlock() and l2cap_chan_put() after, matching the pattern used in l2cap_ecred_conn_rsp() and l2cap_conn_del().</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-53071"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2077</id>
    <title>WID-SEC-W-2026-2077 — Linux Kernel: Mehrere Schwachstellen</title>
    <updated>2026-10-04T01:51:59.318971+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um Sicherheitsvorkehrungen zu umgehen, einen Denial-of-Service-Zustand herbeizuführen und weitere, nicht näher spezifizierte Auswirkungen zu erzielen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2077"/>
  </entry>
</feed>
