<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T22:00:44.527788+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:55764</id>
    <title>ALSA-2026:55764 — Important: kernel security, bug fix, and enhancement update</title>
    <updated>2026-10-02T22:00:45.247366+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: bpftool, AlmaLinux:8: kernel, AlmaLinux:8: kernel-abi-stablelists, AlmaLinux:8: kernel-core, AlmaLinux:8: kernel-cross-headers, AlmaLinux:8: kernel-debug, AlmaLinux:8: kernel-debug-core, AlmaLinux:8: kernel-debug-devel, AlmaLinux:8: kernel-debug-modules, AlmaLinux:8: kernel-debug-modules-extra and 15 more</p>
<p>The kernel packages contain the Linux kernel, the core of any Linux operating system.</p>
<p>Security Fix(es):</p>
<p>* kernel: mm/slub: avoid accessing metadata when pointer is invalid in object_err() (CVE-2025-39902)
  * kernel: drm/amdkfd: Fix out-of-bounds write in kfd_event_page_set() (CVE-2026-43206)
  * kernel: crypto: ccp - copy IV using skcipher ivsize (CVE-2026-53016)
  * kernel: drm/amd/display: Clamp VBIOS HDMI retimer register count to array size (CVE-2026-53136)
  * kernel: drm/amd/display: Use krealloc_array() in dal_vector_reserve() (CVE-2026-53329)
  * kernel: drm/amdgpu: zero-initialize GART table on allocation (CVE-2026-53374)
  * kernel: drm/i915: Fix potential UAF in TTM object purge (CVE-2026-63884)
  * kernel: drm/amdgpu: fix amdgpu_hmm_range_get_pages (CVE-2026-63879)
  * kernel: drm/amd/display: Validate payload length and link_index in dc_process_dmub_aux_transfer_async (CVE-2026-64219)
  * kernel: can:bcm: arbitrary kernel code execution leading to escalate privileges (CVE-2026-17523)</p>
<p>Bug Fix(es) and Enhancement(s):</p>
<p>* Backport "sched/deadline: Fix bandwidth reclaim equation in GRUB" to AlmaLinux 8.10 (JIRA:AlmaLinux-189997)
  * vhost: reset the vring metadata cache on vring reconfiguration [almalinux-8.10.z] (JIRA:AlmaLinux-224556)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:55764"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-53136</id>
    <title>BELL-CVE-2026-53136</title>
    <updated>2026-10-02T22:00:45.247515+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-53136"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0862</id>
    <title>certfr-2026-avi-0862 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de Debian LTS. Certaines d'entre elles permettent à…</title>
    <updated>2026-10-02T22:00:45.247544+00:00</updated>
    <content>certfr-2026-avi-0862</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0862"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-330920</id>
    <title>EUVD-2026-330920</title>
    <updated>2026-10-02T22:00:45.247564+00:00</updated>
    <content>EUVD-2026-330920</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-330920"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-53136</id>
    <title>fkie_cve-2026-53136</title>
    <updated>2026-10-02T22:00:45.247576+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>drm/amd/display: Clamp VBIOS HDMI retimer register count to array size</p>
<p>[Why &amp; How]
The VBIOS integrated info tables (v1_11 and v2_1) contain HdmiRegNum and
Hdmi6GRegNum fields that are used as loop bounds when copying retimer I2C
register settings into fixed-size arrays (dp*_ext_hdmi_reg_settings[9]
and dp*_ext_hdmi_6g_reg_settings[3]). These u8 fields are not validated
before use, so a malformed VBIOS can specify values up to 255, causing an
out-of-bounds heap write during driver probe.</p>
<p>Clamp each register count to the destination array size using min_t()
before the copy loops, in both get_integrated_info_v11() and
get_integrated_info_v2_1().</p>
<p>(cherry picked from commit 5a7f0ef90195940c54b0f5bb85b87da55f038c69)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-53136"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-rg3c-j3j2-x6pc</id>
    <title>GHSA-rg3c-j3j2-x6pc</title>
    <updated>2026-10-02T22:00:45.247605+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>drm/amd/display: Clamp VBIOS HDMI retimer register count to array size</p>
<p>[Why &amp; How]
The VBIOS integrated info tables (v1_11 and v2_1) contain HdmiRegNum and
Hdmi6GRegNum fields that are used as loop bounds when copying retimer I2C
register settings into fixed-size arrays (dp*_ext_hdmi_reg_settings[9]
and dp*_ext_hdmi_6g_reg_settings[3]). These u8 fields are not validated
before use, so a malformed VBIOS can specify values up to 255, causing an
out-of-bounds heap write during driver probe.</p>
<p>Clamp each register count to the destination array size using min_t()
before the copy loops, in both get_integrated_info_v11() and
get_integrated_info_v2_1().</p>
<p>(cherry picked from commit 5a7f0ef90195940c54b0f5bb85b87da55f038c69)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-rg3c-j3j2-x6pc"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-53136</id>
    <title>msrc_CVE-2026-53136 — drm/amd/display: Clamp VBIOS HDMI retimer register count to array size</title>
    <updated>2026-10-02T22:00:45.247626+00:00</updated>
    <content>msrc_CVE-2026-53136</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-53136"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-3204</id>
    <title>OESA-2026-3204 — kernel security update</title>
    <updated>2026-10-02T22:00:45.247644+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS-SP1: kernel</p>
<p>The Linux Kernel, the operating system core itself.

Security Fix(es):</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>wifi: rtw88: Use devm_kmemdup() in rtw_set_supported_band()</p>
<p>Simplify the code by using device managed memory allocations.</p>
<p>This also fixes a memory leak in rtw_register_hw(). The supported bands
were not freed in the error path.</p>
<p>Copied from commit 145df52a8671 (&amp;quot;wifi: rtw89: Convert
rtw89_core_set_supported_band to use devm_*&amp;quot;).(CVE-2025-71273)</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>xfrm: hold dev ref until after transport_finish NF_HOOK</p>
<p>After async crypto completes, xfrm_input_resume() calls dev_put()
immediately on re-entry before the skb reaches transport_finish.
The skb-&amp;gt;dev pointer is then used inside NF_HOOK and its okfn,
which can race with device teardown.</p>
<p>Remove the dev_put from the async resumption entry and instead
drop the reference after the NF_HOOK call in transport_finish,
using a saved device pointer since NF_HOOK may consume the skb.
This covers NF_DROP, NF_QUEUE and NF_STOLEN paths that skip
the okfn.</p>
<p>For non-transport exits (decaps, gro, drop) and secondary
async return points, release the reference inline when
async is set.(CVE-2026-31663)</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>x86: shadow stacks: proper error handling for mmap lock</p>
<p>김영민 reports that shstk_pop_sigframe() doesn&amp;apos;t check for errors from
mmap_read_lock_killable(), whic…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-3204"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:21555-1</id>
    <title>openSUSE-SU-2026:21555-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-02T22:00:45.248025+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:21555-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:55764</id>
    <title>RHSA-2026:55764 — Red Hat Security Advisory: kernel security, bug fix, and enhancement update</title>
    <updated>2026-10-02T22:00:45.248557+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>kernel: mm/slub: avoid accessing metadata when pointer is invalid in object_err() kernel: can:bcm: arbitrary kernel code execution leading to escalate privileges kernel: drm/amdkfd: Fix out-of-bounds write in kfd_event_page_set() kernel: crypto: ccp - copy IV using skcipher ivsize kernel: drm/amd/display: Clamp VBIOS HDMI retimer register count to array size kernel: drm/amd/display: Use krealloc_array() in dal_vector_reserve() kernel: drm/amdgpu: zero-initialize GART table on allocation kernel: drm/amdgpu: fix amdgpu_hmm_range_get_pages kernel: drm/i915: Fix potential UAF in TTM object purge kernel: drm/amd/display: Validate payload length and link_index in dc_process_dmub_aux_transfer_async</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:55764"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:55764</id>
    <title>RLSA-2026:55764 — Important: kernel security, bug fix, and enhancement update</title>
    <updated>2026-10-02T22:00:45.248593+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:8: kernel</p>
<p>The kernel packages contain the Linux kernel, the core of any Linux operating system.</p>
<p>Security Fix(es):</p>
<p>* kernel: mm/slub: avoid accessing metadata when pointer is invalid in object_err() (CVE-2025-39902)</p>
<p>* kernel: drm/amdkfd: Fix out-of-bounds write in kfd_event_page_set() (CVE-2026-43206)</p>
<p>* kernel: crypto: ccp - copy IV using skcipher ivsize (CVE-2026-53016)</p>
<p>* kernel: drm/amd/display: Clamp VBIOS HDMI retimer register count to array size (CVE-2026-53136)</p>
<p>* kernel: drm/amd/display: Use krealloc_array() in dal_vector_reserve() (CVE-2026-53329)</p>
<p>* kernel: drm/amdgpu: zero-initialize GART table on allocation (CVE-2026-53374)</p>
<p>* kernel: drm/i915: Fix potential UAF in TTM object purge (CVE-2026-63884)</p>
<p>* kernel: drm/amdgpu: fix amdgpu_hmm_range_get_pages (CVE-2026-63879)</p>
<p>* kernel: drm/amd/display: Validate payload length and link_index in dc_process_dmub_aux_transfer_async (CVE-2026-64219)</p>
<p>* kernel: can:bcm: arbitrary kernel code execution leading to escalate privileges (CVE-2026-17523)</p>
<p>Bug Fix(es) and Enhancement(s):</p>
<p>* Backport "sched/deadline: Fix bandwidth reclaim equation in GRUB" to Rocky Linux 8.10 (JIRA:Rocky Linux-189997)</p>
<p>* vhost: reset the vring metadata cache on vring reconfiguration [rhel-8.10.z] (JIRA:Rocky Linux-224556)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:55764"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:23066-1</id>
    <title>SUSE-SU-2026:23066-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-02T22:00:45.248632+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:23066-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-53136</id>
    <title>UBUNTU-CVE-2026-53136</title>
    <updated>2026-10-02T22:00:45.249120+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe, Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:Pro:16.04:LTS: linux-oracle, Ubuntu:Pro:18.04:LTS: linux, Ubuntu:Pro:18.04:LTS: linux-aws, Ubuntu:18.04:LTS: linux-aws-5.0 and 248 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Clamp VBIOS HDMI retimer register count to array size [Why &amp; How] The VBIOS integrated info tables (v1_11 and v2_1) contain HdmiRegNum and Hdmi6GRegNum fields that are used as loop bounds when copying retimer I2C register settings into fixed-size arrays (dp*_ext_hdmi_reg_settings[9] and dp*_ext_hdmi_6g_reg_settings[3]). These u8 fields are not validated before use, so a malformed VBIOS can specify values up to 255, causing an out-of-bounds heap write during driver probe. Clamp each register count to the destination array size using min_t() before the copy loops, in both get_integrated_info_v11() and get_integrated_info_v2_1(). (cherry picked from commit 5a7f0ef90195940c54b0f5bb85b87da55f038c69)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-53136"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2077</id>
    <title>WID-SEC-W-2026-2077 — Linux Kernel: Mehrere Schwachstellen</title>
    <updated>2026-10-02T22:00:45.249398+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um Sicherheitsvorkehrungen zu umgehen, einen Denial-of-Service-Zustand herbeizuführen und weitere, nicht näher spezifizierte Auswirkungen zu erzielen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2077"/>
  </entry>
</feed>
