<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T15:07:46.016177+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:54343</id>
    <title>ALSA-2026:54343 — Important: kernel security, bug fix, and enhancement update</title>
    <updated>2026-10-02T15:07:47.491684+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:10: kernel, AlmaLinux:10: kernel-64k, AlmaLinux:10: kernel-64k-core, AlmaLinux:10: kernel-64k-debug, AlmaLinux:10: kernel-64k-debug-core, AlmaLinux:10: kernel-64k-debug-devel, AlmaLinux:10: kernel-64k-debug-devel-matched, AlmaLinux:10: kernel-64k-debug-modules, AlmaLinux:10: kernel-64k-debug-modules-core, AlmaLinux:10: kernel-64k-debug-modules-extra and 65 more</p>
<p>The kernel packages contain the Linux kernel, the core of any Linux operating system.</p>
<p>Security Fix(es):</p>
<p>* kernel: accel/ivpu: Fix signed integer truncation in IPC receive (CVE-2026-53202)
  * kernel: net/sched: act_api: use RCU with deferred freeing for action lifecycle (CVE-2026-53264)
  * kernel: scsi: target: iscsi: Bound iscsi_encode_text_output() appends to rsp_buf (CVE-2026-63887)
  * kernel: perf/aux: Fix page UAF in map_range() (CVE-2026-64300)
  * kernel: af_unix: set gc_in_progress to true in unix_gc() (CVE-2026-53361)</p>
<p>Bug Fix(es) and Enhancement(s):</p>
<p>* netfilter: CVE backports for AlmaLinux 10.2.z (JIRA:AlmaLinux-185311)
  * tlbflush - Windows Driver Verifier catches FLTMGR/Ntfs crashes during KVM 42-VM soak test on AMD EPYC Turin [almalinux-10.2.z] (JIRA:AlmaLinux-214436)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:54343"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-14230</id>
    <title>bdu:2026-14230</title>
    <updated>2026-10-02T15:07:47.491855+00:00</updated>
    <content>bdu:2026-14230</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-14230"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-53264</id>
    <title>BELL-CVE-2026-53264</title>
    <updated>2026-10-02T15:07:47.491875+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-53264"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0812</id>
    <title>certfr-2026-avi-0812 — De multiples vulnérabilités ont été découvertes dans Microsoft Azure Linux. Elles permettent à un attaquant de provoque…</title>
    <updated>2026-10-02T15:07:47.491897+00:00</updated>
    <content>certfr-2026-avi-0812</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0812"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-348222</id>
    <title>EUVD-2026-348222</title>
    <updated>2026-10-02T15:07:47.491913+00:00</updated>
    <content>EUVD-2026-348222</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-348222"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-53264</id>
    <title>fkie_cve-2026-53264</title>
    <updated>2026-10-02T15:07:47.491925+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>net/sched: act_api: use RCU with deferred freeing for action lifecycle</p>
<p>When NEWTFILTER and DELFILTER are run concurrently it is possible to create a
race with an associated action.</p>
<p>Let's illustrate with CPU0 running NEWTFILTER and CPU1 running DELFILTER:</p>
<p>0: mutex_lock() &lt;-- holds the idr lock
 0: rcu_read_lock()
 0: p = idr_find(idr, index) &lt;-- action p is valid (RCU protects IDR)
 0: mutex_unlock() &lt;-- releases the idr lock
 1: refcount_dec_and_mutex_lock() &lt;-- refcnt 1-&gt;0, mutex held
 1: idr_remove(idr, index) &lt;-- Action removed from IDR
 1: mutex_unlock() &lt;-- mutex released allowing us to delete the action
 1: tcf_action_cleanup(p); kfree(p) &lt;-- Kfrees p immediately, no deferral
 0: refcount_inc_not_zero(&amp;p-&gt;tcfa_refcnt) &lt;-- ouch, UAF p points to freed memory</p>
<p>This patch fixes the race condition between NEWTFILTER and DELFILTER by
adding struct rcu_head to tc_action used in the deferral and introducing a
call_rcu() in the delete path to defer the final kfree().</p>
<p>Note: this is a revert of commit d7fb60b9cafb ("net_sched: get rid of tcfa_rcu")
but also modernization/simplification to directly use kfree_rcu().</p>
<p>Let's illustrate the new restored code path:</p>
<p>0: rcu_read_lock()
 1: refcount_dec_and_mutex_lock() &lt;-- refcnt 1-&gt;0, mutex held
 1: idr_remove(idr, index)
 1: mutex_unlock()
 1: call_rcu(&amp;p-&gt;tcfa_rcu, tcf_action_rcu_free) &lt;-- defer kfree after grace period
 0: p = idr_find(idr, index)
 0: refcoun…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-53264"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-vq3g-6qwh-5wj2</id>
    <title>GHSA-vq3g-6qwh-5wj2</title>
    <updated>2026-10-02T15:07:47.493605+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>net/sched: act_api: use RCU with deferred freeing for action lifecycle</p>
<p>When NEWTFILTER and DELFILTER are run concurrently it is possible to create a
race with an associated action.</p>
<p>Let's illustrate with CPU0 running NEWTFILTER and CPU1 running DELFILTER:</p>
<p>0: mutex_lock() &lt;-- holds the idr lock
 0: rcu_read_lock()
 0: p = idr_find(idr, index) &lt;-- action p is valid (RCU protects IDR)
 0: mutex_unlock() &lt;-- releases the idr lock
 1: refcount_dec_and_mutex_lock() &lt;-- refcnt 1-&gt;0, mutex held
 1: idr_remove(idr, index) &lt;-- Action removed from IDR
 1: mutex_unlock() &lt;-- mutex released allowing us to delete the action
 1: tcf_action_cleanup(p); kfree(p) &lt;-- Kfrees p immediately, no deferral
 0: refcount_inc_not_zero(&amp;p-&gt;tcfa_refcnt) &lt;-- ouch, UAF p points to freed memory</p>
<p>This patch fixes the race condition between NEWTFILTER and DELFILTER by
adding struct rcu_head to tc_action used in the deferral and introducing a
call_rcu() in the delete path to defer the final kfree().</p>
<p>Note: this is a revert of commit d7fb60b9cafb ("net_sched: get rid of tcfa_rcu")
but also modernization/simplification to directly use kfree_rcu().</p>
<p>Let's illustrate the new restored code path:</p>
<p>0: rcu_read_lock()
 1: refcount_dec_and_mutex_lock() &lt;-- refcnt 1-&gt;0, mutex held
 1: idr_remove(idr, index)
 1: mutex_unlock()
 1: call_rcu(&amp;p-&gt;tcfa_rcu, tcf_action_rcu_free) &lt;-- defer kfree after grace period
 0: p = idr_find(idr, index)
 0: refcoun…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-vq3g-6qwh-5wj2"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-53264</id>
    <title>msrc_CVE-2026-53264 — net/sched: act_api: use RCU with deferred freeing for action lifecycle</title>
    <updated>2026-10-02T15:07:47.493647+00:00</updated>
    <content>msrc_CVE-2026-53264</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-53264"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-3204</id>
    <title>OESA-2026-3204 — kernel security update</title>
    <updated>2026-10-02T15:07:47.493667+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS-SP1: kernel</p>
<p>The Linux Kernel, the operating system core itself.

Security Fix(es):</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>wifi: rtw88: Use devm_kmemdup() in rtw_set_supported_band()</p>
<p>Simplify the code by using device managed memory allocations.</p>
<p>This also fixes a memory leak in rtw_register_hw(). The supported bands
were not freed in the error path.</p>
<p>Copied from commit 145df52a8671 (&amp;quot;wifi: rtw89: Convert
rtw89_core_set_supported_band to use devm_*&amp;quot;).(CVE-2025-71273)</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>xfrm: hold dev ref until after transport_finish NF_HOOK</p>
<p>After async crypto completes, xfrm_input_resume() calls dev_put()
immediately on re-entry before the skb reaches transport_finish.
The skb-&amp;gt;dev pointer is then used inside NF_HOOK and its okfn,
which can race with device teardown.</p>
<p>Remove the dev_put from the async resumption entry and instead
drop the reference after the NF_HOOK call in transport_finish,
using a saved device pointer since NF_HOOK may consume the skb.
This covers NF_DROP, NF_QUEUE and NF_STOLEN paths that skip
the okfn.</p>
<p>For non-transport exits (decaps, gro, drop) and secondary
async return points, release the reference inline when
async is set.(CVE-2026-31663)</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>x86: shadow stacks: proper error handling for mmap lock</p>
<p>김영민 reports that shstk_pop_sigframe() doesn&amp;apos;t check for errors from
mmap_read_lock_killable(), whic…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-3204"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:21910-1</id>
    <title>openSUSE-SU-2026:21910-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-02T15:07:47.494047+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:21910-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:53990</id>
    <title>RHSA-2026:53990 — Red Hat Security Advisory: kernel security, bug fix, and enhancement update</title>
    <updated>2026-10-02T15:07:47.494537+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>kernel: fs/smb/client: fix out-of-bounds read in cifs_sanitize_prepath kernel: net/sched: act_api: use RCU with deferred freeing for action lifecycle</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:53990"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:54343</id>
    <title>RLSA-2026:54343 — Important: kernel security, bug fix, and enhancement update</title>
    <updated>2026-10-02T15:07:47.494559+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:10: kernel</p>
<p>The kernel packages contain the Linux kernel, the core of any Linux operating system.</p>
<p>Security Fix(es):</p>
<p>* kernel: accel/ivpu: Fix signed integer truncation in IPC receive (CVE-2026-53202)</p>
<p>* kernel: net/sched: act_api: use RCU with deferred freeing for action lifecycle (CVE-2026-53264)</p>
<p>* kernel: scsi: target: iscsi: Bound iscsi_encode_text_output() appends to rsp_buf (CVE-2026-63887)</p>
<p>* kernel: perf/aux: Fix page UAF in map_range() (CVE-2026-64300)</p>
<p>Bug Fix(es) and Enhancement(s):</p>
<p>* netfilter: CVE backports for Rocky Linux 10.2.z (JIRA:Rocky Linux-185311)</p>
<p>* tlbflush - Windows Driver Verifier catches FLTMGR/Ntfs crashes during KVM 42-VM soak test on AMD EPYC Turin [rhel-10.2.z] (JIRA:Rocky Linux-214436)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:54343"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:23477-1</id>
    <title>SUSE-SU-2026:23477-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-02T15:07:47.494589+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:23477-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-53264</id>
    <title>UBUNTU-CVE-2026-53264</title>
    <updated>2026-10-02T15:07:47.494885+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe, Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:Pro:16.04:LTS: linux-oracle, Ubuntu:Pro:18.04:LTS: linux, Ubuntu:Pro:18.04:LTS: linux-aws, Ubuntu:18.04:LTS: linux-aws-5.0 and 248 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: net/sched: act_api: use RCU with deferred freeing for action lifecycle When NEWTFILTER and DELFILTER are run concurrently it is possible to create a race with an associated action. Let's illustrate with CPU0 running NEWTFILTER and CPU1 running DELFILTER:  0: mutex_lock() &lt;-- holds the idr lock  0: rcu_read_lock()  0: p = idr_find(idr, index) &lt;-- action p is valid (RCU protects IDR)  0: mutex_unlock() &lt;-- releases the idr lock  1: refcount_dec_and_mutex_lock() &lt;-- refcnt 1-&gt;0, mutex held  1: idr_remove(idr, index) &lt;-- Action removed from IDR  1: mutex_unlock() &lt;-- mutex released allowing us to delete the action  1: tcf_action_cleanup(p); kfree(p) &lt;-- Kfrees p immediately, no deferral  0: refcount_inc_not_zero(&amp;p-&gt;tcfa_refcnt) &lt;-- ouch, UAF p points to freed memory This patch fixes the race condition between NEWTFILTER and DELFILTER by adding struct rcu_head to tc_action used in the deferral and introducing a call_rcu() in the delete path to defer the final kfree(). Note: this is a revert of commit d7fb60b9cafb ("net_sched: get rid of tcfa_rcu") but also modernization/simplification to directly use kfree_rcu(). Let's illustrate the new restored code path:  0: rcu_read_lock()  1: refcount_dec_and_mutex_lock() &lt;-- refcnt 1-&gt;0, mutex held  1: idr_remove(idr, index)  1: mutex_unlock()  1: call_rcu(&amp;p-&gt;tcfa_rcu, tcf_action_rcu_free) &lt;-- defer kfree after grace period  0: p = idr_find(idr, index)  0: refcount_inc_no…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-53264"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2077</id>
    <title>WID-SEC-W-2026-2077 — Linux Kernel: Mehrere Schwachstellen</title>
    <updated>2026-10-02T15:07:47.495169+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um Sicherheitsvorkehrungen zu umgehen, einen Denial-of-Service-Zustand herbeizuführen und weitere, nicht näher spezifizierte Auswirkungen zu erzielen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2077"/>
  </entry>
</feed>
