<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T22:07:03.758753+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-53259</id>
    <title>BELL-CVE-2026-53259</title>
    <updated>2026-10-02T22:07:03.891729+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:stream: linux-lts</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-53259"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1162</id>
    <title>certfr-2026-avi-1162 — De multiples vulnérabilités ont été découvertes dans le noyau Linux d'Ubuntu. Certaines d'entre elles permettent à un a…</title>
    <updated>2026-10-02T22:07:03.891781+00:00</updated>
    <content>certfr-2026-avi-1162</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-1162"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-348219</id>
    <title>EUVD-2026-348219</title>
    <updated>2026-10-02T22:07:03.891802+00:00</updated>
    <content>EUVD-2026-348219</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-348219"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-53259</id>
    <title>fkie_cve-2026-53259</title>
    <updated>2026-10-02T22:07:03.891814+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>ipv6: anycast: insert aca into global hash under idev-&gt;lock</p>
<p>syzbot reported a splat [1]: a slab-use-after-free in
ipv6_chk_acast_addr(), which walks the global inet6_acaddr_lst[] hash
under RCU and dereferences a struct ifacaddr6 that has already been
freed while still linked in the hash, so a later reader walks into a
dangling node.</p>
<p>In __ipv6_dev_ac_inc() the aca is allocated with refcount 1, then
aca_get() bumps it to 2 to keep it alive across the unlocked region.
It is published to idev-&gt;ac_list under idev-&gt;lock, but
ipv6_add_acaddr_hash() runs after write_unlock_bh(). A concurrent
teardown (ipv6_ac_destroy_dev() from addrconf_ifdown(), under RTNL)
can slip into that window:</p>
<p>CPU0 __ipv6_dev_ac_inc           CPU1 ipv6_ac_destroy_dev (RTNL)
  ------------------------------   ------------------------------------
  aca_alloc()              refcnt 1
  aca_get()               refcnt 2
  write_lock_bh(idev-&gt;lock)
    add aca to ac_list
  write_unlock_bh(idev-&gt;lock)
                                   write_lock_bh(idev-&gt;lock)
                                     pull aca off ac_list
                                   write_unlock_bh(idev-&gt;lock)
                                   ipv6_del_acaddr_hash(aca)
                                     hlist_del_init_rcu() is a no-op,
                                     aca is not in the hash yet
                                   aca_put()           refcnt 2-&gt;1
  ipv…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-53259"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-hqjh-c323-5jv8</id>
    <title>GHSA-hqjh-c323-5jv8</title>
    <updated>2026-10-02T22:07:03.891862+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>ipv6: anycast: insert aca into global hash under idev-&gt;lock</p>
<p>syzbot reported a splat [1]: a slab-use-after-free in
ipv6_chk_acast_addr(), which walks the global inet6_acaddr_lst[] hash
under RCU and dereferences a struct ifacaddr6 that has already been
freed while still linked in the hash, so a later reader walks into a
dangling node.</p>
<p>In __ipv6_dev_ac_inc() the aca is allocated with refcount 1, then
aca_get() bumps it to 2 to keep it alive across the unlocked region.
It is published to idev-&gt;ac_list under idev-&gt;lock, but
ipv6_add_acaddr_hash() runs after write_unlock_bh(). A concurrent
teardown (ipv6_ac_destroy_dev() from addrconf_ifdown(), under RTNL)
can slip into that window:</p>
<p>CPU0 __ipv6_dev_ac_inc           CPU1 ipv6_ac_destroy_dev (RTNL)
  ------------------------------   ------------------------------------
  aca_alloc()              refcnt 1
  aca_get()               refcnt 2
  write_lock_bh(idev-&gt;lock)
    add aca to ac_list
  write_unlock_bh(idev-&gt;lock)
                                   write_lock_bh(idev-&gt;lock)
                                     pull aca off ac_list
                                   write_unlock_bh(idev-&gt;lock)
                                   ipv6_del_acaddr_hash(aca)
                                     hlist_del_init_rcu() is a no-op,
                                     aca is not in the hash yet
                                   aca_put()           refcnt 2-&gt;1
  ipv…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-hqjh-c323-5jv8"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:64775</id>
    <title>RHSA-2026:64775 — Red Hat Security Advisory: kernel security, bug fix, and enhancement update</title>
    <updated>2026-10-02T22:07:03.891897+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>kernel: can: bcm: add locking for bcm_op runtime updates kernel: ipv6: add NULL checks for idev in SRv6 paths kernel: udp: Fix wildcard bind conflict check when using hash2 kernel: ipv6: prevent possible UaF in addrconf_permanent_addr() kernel: tcp: call sk_data_ready() after listener migration kernel: inet: RAW sockets using IPPROTO_RAW MUST drop incoming ICMP kernel: flow_dissector: do not dissect PPPoE PFC frames kernel: io_uring/poll: fix signed comparison in io_poll_get_ownership() kernel: ppp: require CAP_NET_ADMIN in target netns for unattached ioctls kernel: net: guard timestamp cmsgs to real error queue skbs kernel: ipv6: sit: reload inner IPv6 header after GSO offloads kernel: net: add pskb_may_pull() to skb_gro_receive_list() kernel: ipv6: anycast: insert aca into global hash under idev-&gt;lock kernel: ipv6: mcast: Fix use-after-free when processing MLD queries kernel: KVM: arm64: Take the SRCU lock for page table walks in fault injection and AT emulation kernel: vxlan: do not reuse cached ip_hdr() value after skb_tunnel_check_pmtu() kernel: ipv4: free net-&gt;ipv4.sysctl_local_reserved_ports after unregister_net_sysctl_table() kernel: fuse: clear intr_entry in fuse_resend and fuse_remove_pending_req kernel: KVM: arm64: Bound used_lrs when flushing the pKVM hyp vCPU kernel: nvmet-auth: validate reply message payload bounds against transfer length kernel: rhashtable: clear stale iter-&gt;p on table restart kernel: smb: client: fix double-free in SMB2_close() replay</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:64775"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:64775</id>
    <title>RLSA-2026:64775 — Important: kernel security, bug fix, and enhancement update</title>
    <updated>2026-10-02T22:07:03.891955+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:10: kernel</p>
<p>The kernel packages contain the Linux kernel, the core of any Linux operating system.</p>
<p>Security Fix(es):</p>
<p>* kernel: can: bcm: add locking for bcm_op runtime updates (CVE-2025-38004)</p>
<p>* kernel: ipv6: add NULL checks for idev in SRv6 paths (CVE-2026-23442)</p>
<p>* kernel: udp: Fix wildcard bind conflict check when using hash2 (CVE-2026-31503)</p>
<p>* kernel: ipv6: prevent possible UaF in addrconf_permanent_addr() (CVE-2026-43339)</p>
<p>* kernel: tcp: call sk_data_ready() after listener migration (CVE-2026-46015)</p>
<p>* kernel: inet: RAW sockets using IPPROTO_RAW MUST drop incoming ICMP (CVE-2026-46266)</p>
<p>* kernel: flow_dissector: do not dissect PPPoE PFC frames (CVE-2026-46306)</p>
<p>* kernel: io_uring/poll: fix signed comparison in io_poll_get_ownership() (CVE-2026-52933)</p>
<p>* kernel: ppp: require CAP_NET_ADMIN in target netns for unattached ioctls (CVE-2026-53075)</p>
<p>* kernel: KVM: arm64: Take the SRCU lock for page table walks in fault injection and AT emulation (CVE-2026-53277)</p>
<p>* kernel: ipv6: sit: reload inner IPv6 header after GSO offloads (CVE-2026-53228)</p>
<p>* kernel: net: add pskb_may_pull() to skb_gro_receive_list() (CVE-2026-53235)</p>
<p>* kernel: net: guard timestamp cmsgs to real error queue skbs (CVE-2026-53223)</p>
<p>* kernel: ipv6: mcast: Fix use-after-free when processing MLD queries (CVE-2026-53275)</p>
<p>* kernel: ipv6: anycast: insert aca into global hash under idev-&gt;lock (CVE-2026-53259)</p>
<p>* kernel: ipv4: free net-&gt;ipv4.sysctl_local_reserved_ports after unregister_net_sysctl_table() (CVE-2026-64002)</p>
<p>*…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:64775"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-53259</id>
    <title>UBUNTU-CVE-2026-53259</title>
    <updated>2026-10-02T22:07:03.892002+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 128 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: ipv6: anycast: insert aca into global hash under idev-&gt;lock syzbot reported a splat [1]: a slab-use-after-free in ipv6_chk_acast_addr(), which walks the global inet6_acaddr_lst[] hash under RCU and dereferences a struct ifacaddr6 that has already been freed while still linked in the hash, so a later reader walks into a dangling node. In __ipv6_dev_ac_inc() the aca is allocated with refcount 1, then aca_get() bumps it to 2 to keep it alive across the unlocked region. It is published to idev-&gt;ac_list under idev-&gt;lock, but ipv6_add_acaddr_hash() runs after write_unlock_bh(). A concurrent teardown (ipv6_ac_destroy_dev() from addrconf_ifdown(), under RTNL) can slip into that window:   CPU0 __ipv6_dev_ac_inc           CPU1 ipv6_ac_destroy_dev (RTNL)   ------------------------------   ------------------------------------   aca_alloc()              refcnt 1   aca_get()               refcnt 2   write_lock_bh(idev-&gt;lock)     add aca to ac_list   write_unlock_bh(idev-&gt;lock)                                    write_lock_bh(idev-&gt;lock)                                      pull aca off ac_list                                    write_unlock_bh(idev-&gt;lock)                                    ipv6_del_acaddr_hash(aca)                                      hlist_del_init_rcu() is a no-op,                                      aca is not in the hash yet                                    aca_put()           refcnt 2-&gt;1   ipv6_ad…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-53259"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2077</id>
    <title>WID-SEC-W-2026-2077 — Linux Kernel: Mehrere Schwachstellen</title>
    <updated>2026-10-02T22:07:03.892179+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um Sicherheitsvorkehrungen zu umgehen, einen Denial-of-Service-Zustand herbeizuführen und weitere, nicht näher spezifizierte Auswirkungen zu erzielen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2077"/>
  </entry>
</feed>
