<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T14:27:12.309255+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:71700</id>
    <title>ALSA-2026:71700 — Important: kernel security, bug fix, and enhancement update</title>
    <updated>2026-10-03T14:27:12.573591+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:9: kernel, AlmaLinux:9: kernel-64k, AlmaLinux:9: kernel-64k-core, AlmaLinux:9: kernel-64k-debug, AlmaLinux:9: kernel-64k-debug-core, AlmaLinux:9: kernel-64k-debug-devel, AlmaLinux:9: kernel-64k-debug-devel-matched, AlmaLinux:9: kernel-64k-debug-modules, AlmaLinux:9: kernel-64k-debug-modules-core, AlmaLinux:9: kernel-64k-debug-modules-extra and 64 more</p>
<p>The kernel packages contain the Linux kernel, the core of any Linux operating system.</p>
<p>Security Fix(es):</p>
<p>* kernel: fbcon: Set fb_display[i]-&gt;mode to NULL when the mode is released (CVE-2025-40323)
  * kernel: smb: smbdirect: introduce smbdirect_socket.recv_io.credits.available (CVE-2026-31539)
  * kernel: drm/amdgpu/vcn3: Prevent OOB reads when parsing dec msg (CVE-2026-46230)
  * kernel: drm/amdgpu/vcn4: Prevent OOB reads when parsing IB (CVE-2026-46204)
  * kernel: drm/amdgpu/vcn4: Prevent OOB reads when parsing dec msg (CVE-2026-46199)
  * kernel: drm/amdgpu/userq: fix access to stale wptr mapping (CVE-2026-46311)
  * kernel: netfilter: nf_queue: hold bridge skb-&gt;dev while queued (CVE-2026-52912)
  * kernel: accel/ivpu: Add buffer overflow check in MS get_info_ioctl (CVE-2026-53203)
  * kernel: drm/xe/eustall: Fix drm_dev_put called before stream disable in close (CVE-2026-53290)
  * kernel: drm/virtio: use uninterruptible resv lock for plane updates (CVE-2026-64098)
  * kernel: Linux kernel: PPPoE memory corruption via stale pointer (CVE-2026-68121)
  * kernel: drm/amdgpu/vce: fix integer overflow in image size (CVE-2026-68108)
  * kernel: drm/amdkfd: fix 32-bit overflow in CWSR total size calculation (CVE-2026-68257)
  * kernel: drm/xe/rtp: Add RING_FORCE_TO_NONPRIV_DENY to OA whitelists (CVE-2026-68267)
  * kernel: drm/xe: Hold a dma-buf reference for imported BOs (CVE-2026-68266)
  * kernel: drm/amdgpu: Fix context pstate override handling (CVE-2026-68273)
  *…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:71700"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-14080</id>
    <title>bdu:2026-14080</title>
    <updated>2026-10-03T14:27:12.573802+00:00</updated>
    <content>bdu:2026-14080</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-14080"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-53290</id>
    <title>BELL-CVE-2026-53290</title>
    <updated>2026-10-03T14:27:12.573824+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:stream: linux-lts</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-53290"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0926</id>
    <title>certfr-2026-avi-0926 — De multiples vulnérabilités ont été découvertes dans le noyau Linux d'Ubuntu. Certaines d'entre elles permettent à un a…</title>
    <updated>2026-10-03T14:27:12.573845+00:00</updated>
    <content>certfr-2026-avi-0926</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0926"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-348230</id>
    <title>EUVD-2026-348230</title>
    <updated>2026-10-03T14:27:12.573861+00:00</updated>
    <content>EUVD-2026-348230</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-348230"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-53290</id>
    <title>fkie_cve-2026-53290</title>
    <updated>2026-10-03T14:27:12.573872+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>drm/xe/eustall: Fix drm_dev_put called before stream disable in close</p>
<p>In xe_eu_stall_stream_close(), drm_dev_put() is called before the
stream is disabled and its resources are freed. If this drops the
last reference, the device structures could be freed while the
subsequent cleanup code still accesses them, leading to a
use-after-free.</p>
<p>Fix this by moving drm_dev_put() after all device accesses are
complete. This matches the ordering in xe_oa_release().</p>
<p>(cherry picked from commit 35aff528f7297e949e5e19c9cd7fd748cf1cf21c)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-53290"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-7j5g-6r5q-hq8r</id>
    <title>GHSA-7j5g-6r5q-hq8r</title>
    <updated>2026-10-03T14:27:12.573900+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>drm/xe/eustall: Fix drm_dev_put called before stream disable in close</p>
<p>In xe_eu_stall_stream_close(), drm_dev_put() is called before the
stream is disabled and its resources are freed. If this drops the
last reference, the device structures could be freed while the
subsequent cleanup code still accesses them, leading to a
use-after-free.</p>
<p>Fix this by moving drm_dev_put() after all device accesses are
complete. This matches the ordering in xe_oa_release().</p>
<p>(cherry picked from commit 35aff528f7297e949e5e19c9cd7fd748cf1cf21c)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-7j5g-6r5q-hq8r"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:71602</id>
    <title>RHSA-2026:71602 — Red Hat Security Advisory: kernel security, bug fix, and enhancement update</title>
    <updated>2026-10-03T14:27:12.573919+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>kernel: fbcon: Set fb_display[i]-&gt;mode to NULL when the mode is released kernel: libceph: fix potential use-after-free in have_mon_and_osd_map() kernel: libceph: make decode_pool() more resilient against corrupted osdmaps kernel: libceph: prevent potential out-of-bounds reads in handle_auth_done() kernel: libceph: replace overzealous BUG_ON in osdmap_apply_incremental() kernel: Linux kernel: Denial of Service in libceph OSD client due to unreset sparse-read state kernel: drm/amdgpu/vcn4: Prevent OOB reads when parsing dec msg kernel: drm/amdgpu/vcn4: Prevent OOB reads when parsing IB kernel: drm/amdgpu/vcn3: Prevent OOB reads when parsing dec msg kernel: drm/amdgpu/userq: fix access to stale wptr mapping kernel: af_unix: Drop all SCM attributes for SOCKMAP kernel: accel/ivpu: Add buffer overflow check in MS get_info_ioctl kernel: drm/xe/eustall: Fix drm_dev_put called before stream disable in close kernel: drm/virtio: use uninterruptible resv lock for plane updates kernel: drm/amdgpu/vce: fix integer overflow in image size kernel: pppoe: reload header pointer after dev_hard_header() kernel: drm/amdkfd: fix 32-bit overflow in CWSR total size calculation kernel: drm/xe: Hold a dma-buf reference for imported BOs kernel: drm/xe/rtp: Add RING_FORCE_TO_NONPRIV_DENY to OA whitelists kernel: drm/amdgpu: Fix context pstate override handling kernel: ipvs: do not propagate one-packet flag to synced conns kernel: nvme-tcp: fix host memory disclosure on R2T for a read command</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:71602"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:71700</id>
    <title>RHSA-2026:71700 — Red Hat Security Advisory: kernel security, bug fix, and enhancement update</title>
    <updated>2026-10-03T14:27:12.573975+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>kernel: fbcon: Set fb_display[i]-&gt;mode to NULL when the mode is released kernel: smb: smbdirect: introduce smbdirect_socket.recv_io.credits.available kernel: drm/amdgpu/vcn4: Prevent OOB reads when parsing dec msg kernel: drm/amdgpu/vcn4: Prevent OOB reads when parsing IB kernel: drm/amdgpu/vcn3: Prevent OOB reads when parsing dec msg kernel: drm/amdgpu/userq: fix access to stale wptr mapping kernel: netfilter: nf_queue: hold bridge skb-&gt;dev while queued kernel: accel/ivpu: Add buffer overflow check in MS get_info_ioctl kernel: drm/xe/eustall: Fix drm_dev_put called before stream disable in close kernel: drm/virtio: use uninterruptible resv lock for plane updates kernel: drm/amdgpu/vce: fix integer overflow in image size kernel: pppoe: reload header pointer after dev_hard_header() kernel: drm/amdkfd: fix 32-bit overflow in CWSR total size calculation kernel: drm/xe: Hold a dma-buf reference for imported BOs kernel: drm/xe/rtp: Add RING_FORCE_TO_NONPRIV_DENY to OA whitelists kernel: drm/amdgpu: Fix context pstate override handling kernel: ipvs: do not propagate one-packet flag to synced conns</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:71700"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:71602</id>
    <title>RLSA-2026:71602 — Important: kernel security, bug fix, and enhancement update</title>
    <updated>2026-10-03T14:27:12.574020+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:10: kernel</p>
<p>The kernel packages contain the Linux kernel, the core of any Linux operating system.</p>
<p>Security Fix(es):</p>
<p>* kernel: fbcon: Set fb_display[i]-&gt;mode to NULL when the mode is released (CVE-2025-40323)</p>
<p>* kernel: libceph: fix potential use-after-free in have_mon_and_osd_map() (CVE-2025-68285)</p>
<p>* kernel: libceph: make decode_pool() more resilient against corrupted osdmaps (CVE-2025-71116)</p>
<p>* kernel: libceph: prevent potential out-of-bounds reads in handle_auth_done() (CVE-2026-22984)</p>
<p>* kernel: libceph: replace overzealous BUG_ON in osdmap_apply_incremental() (CVE-2026-22990)</p>
<p>* kernel: Linux kernel: Denial of Service in libceph OSD client due to unreset sparse-read state (CVE-2026-23136)</p>
<p>* kernel: drm/amdgpu/vcn3: Prevent OOB reads when parsing dec msg (CVE-2026-46230)</p>
<p>* kernel: drm/amdgpu/vcn4: Prevent OOB reads when parsing IB (CVE-2026-46204)</p>
<p>* kernel: drm/amdgpu/vcn4: Prevent OOB reads when parsing dec msg (CVE-2026-46199)</p>
<p>* kernel: drm/amdgpu/userq: fix access to stale wptr mapping (CVE-2026-46311)</p>
<p>* kernel: af_unix: Drop all SCM attributes for SOCKMAP (CVE-2026-53005)</p>
<p>* kernel: accel/ivpu: Add buffer overflow check in MS get_info_ioctl (CVE-2026-53203)</p>
<p>* kernel: drm/xe/eustall: Fix drm_dev_put called before stream disable in close (CVE-2026-53290)</p>
<p>* kernel: drm/virtio: use uninterruptible resv lock for plane updates (CVE-2026-64098)</p>
<p>* kernel: Linux kernel: PPPoE memory corruption via stale pointer (CVE-2026-68121)</p>
<p>* kernel: drm/amdgpu/vce: fix integer overflow in…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:71602"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-53290</id>
    <title>UBUNTU-CVE-2026-53290</title>
    <updated>2026-10-03T14:27:12.574065+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 127 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: drm/xe/eustall: Fix drm_dev_put called before stream disable in close In xe_eu_stall_stream_close(), drm_dev_put() is called before the stream is disabled and its resources are freed. If this drops the last reference, the device structures could be freed while the subsequent cleanup code still accesses them, leading to a use-after-free. Fix this by moving drm_dev_put() after all device accesses are complete. This matches the ordering in xe_oa_release(). (cherry picked from commit 35aff528f7297e949e5e19c9cd7fd748cf1cf21c)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-53290"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2119</id>
    <title>WID-SEC-W-2026-2119 — Linux Kernel: Mehrere Schwachstellen</title>
    <updated>2026-10-03T14:27:12.574250+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein lokaler Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um Sicherheitsmaßnahmen zu umgehen, einen Denial of Service zu verursachen und potentiell Code auszuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2119"/>
  </entry>
</feed>
