<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T22:11:22.966017+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:55764</id>
    <title>ALSA-2026:55764 — Important: kernel security, bug fix, and enhancement update</title>
    <updated>2026-10-02T22:11:23.802101+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: bpftool, AlmaLinux:8: kernel, AlmaLinux:8: kernel-abi-stablelists, AlmaLinux:8: kernel-core, AlmaLinux:8: kernel-cross-headers, AlmaLinux:8: kernel-debug, AlmaLinux:8: kernel-debug-core, AlmaLinux:8: kernel-debug-devel, AlmaLinux:8: kernel-debug-modules, AlmaLinux:8: kernel-debug-modules-extra and 15 more</p>
<p>The kernel packages contain the Linux kernel, the core of any Linux operating system.</p>
<p>Security Fix(es):</p>
<p>* kernel: mm/slub: avoid accessing metadata when pointer is invalid in object_err() (CVE-2025-39902)
  * kernel: drm/amdkfd: Fix out-of-bounds write in kfd_event_page_set() (CVE-2026-43206)
  * kernel: crypto: ccp - copy IV using skcipher ivsize (CVE-2026-53016)
  * kernel: drm/amd/display: Clamp VBIOS HDMI retimer register count to array size (CVE-2026-53136)
  * kernel: drm/amd/display: Use krealloc_array() in dal_vector_reserve() (CVE-2026-53329)
  * kernel: drm/amdgpu: zero-initialize GART table on allocation (CVE-2026-53374)
  * kernel: drm/i915: Fix potential UAF in TTM object purge (CVE-2026-63884)
  * kernel: drm/amdgpu: fix amdgpu_hmm_range_get_pages (CVE-2026-63879)
  * kernel: drm/amd/display: Validate payload length and link_index in dc_process_dmub_aux_transfer_async (CVE-2026-64219)
  * kernel: can:bcm: arbitrary kernel code execution leading to escalate privileges (CVE-2026-17523)</p>
<p>Bug Fix(es) and Enhancement(s):</p>
<p>* Backport "sched/deadline: Fix bandwidth reclaim equation in GRUB" to AlmaLinux 8.10 (JIRA:AlmaLinux-189997)
  * vhost: reset the vring metadata cache on vring reconfiguration [almalinux-8.10.z] (JIRA:AlmaLinux-224556)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:55764"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-13870</id>
    <title>bdu:2026-13870</title>
    <updated>2026-10-02T22:11:23.802228+00:00</updated>
    <content>bdu:2026-13870</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-13870"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-53329</id>
    <title>BELL-CVE-2026-53329</title>
    <updated>2026-10-02T22:11:23.802249+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-53329"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0862</id>
    <title>certfr-2026-avi-0862 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de Debian LTS. Certaines d'entre elles permettent à…</title>
    <updated>2026-10-02T22:11:23.802273+00:00</updated>
    <content>certfr-2026-avi-0862</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0862"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-348233</id>
    <title>EUVD-2026-348233</title>
    <updated>2026-10-02T22:11:23.802291+00:00</updated>
    <content>EUVD-2026-348233</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-348233"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-53329</id>
    <title>fkie_cve-2026-53329</title>
    <updated>2026-10-02T22:11:23.802303+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>drm/amd/display: Use krealloc_array() in dal_vector_reserve()</p>
<p>[Why &amp; How]
dal_vector_reserve() computes the allocation size as
"capacity * vector-&gt;struct_size" using uint32_t arithmetic, which can
silently wrap to a small value on overflow. This would cause krealloc to
return a smaller buffer than expected, leading to heap overflows on
subsequent vector appends.</p>
<p>Replace krealloc() with krealloc_array() which performs an internal
overflow check and returns NULL on wrap, preventing the issue.</p>
<p>(cherry picked from commit 37668568641ccc4cc1dbca4923d0a16609dd5707)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-53329"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-j7g7-x525-gxgj</id>
    <title>GHSA-j7g7-x525-gxgj</title>
    <updated>2026-10-02T22:11:23.802332+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>drm/amd/display: Use krealloc_array() in dal_vector_reserve()</p>
<p>[Why &amp; How]
dal_vector_reserve() computes the allocation size as
"capacity * vector-&gt;struct_size" using uint32_t arithmetic, which can
silently wrap to a small value on overflow. This would cause krealloc to
return a smaller buffer than expected, leading to heap overflows on
subsequent vector appends.</p>
<p>Replace krealloc() with krealloc_array() which performs an internal
overflow check and returns NULL on wrap, preventing the issue.</p>
<p>(cherry picked from commit 37668568641ccc4cc1dbca4923d0a16609dd5707)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-j7g7-x525-gxgj"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-53329</id>
    <title>msrc_CVE-2026-53329 — drm/amd/display: Use krealloc_array() in dal_vector_reserve()</title>
    <updated>2026-10-02T22:11:23.802352+00:00</updated>
    <content>msrc_CVE-2026-53329</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-53329"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:21555-1</id>
    <title>openSUSE-SU-2026:21555-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-02T22:11:23.802369+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:21555-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:55764</id>
    <title>RHSA-2026:55764 — Red Hat Security Advisory: kernel security, bug fix, and enhancement update</title>
    <updated>2026-10-02T22:11:23.802927+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>kernel: mm/slub: avoid accessing metadata when pointer is invalid in object_err() kernel: can:bcm: arbitrary kernel code execution leading to escalate privileges kernel: drm/amdkfd: Fix out-of-bounds write in kfd_event_page_set() kernel: crypto: ccp - copy IV using skcipher ivsize kernel: drm/amd/display: Clamp VBIOS HDMI retimer register count to array size kernel: drm/amd/display: Use krealloc_array() in dal_vector_reserve() kernel: drm/amdgpu: zero-initialize GART table on allocation kernel: drm/amdgpu: fix amdgpu_hmm_range_get_pages kernel: drm/i915: Fix potential UAF in TTM object purge kernel: drm/amd/display: Validate payload length and link_index in dc_process_dmub_aux_transfer_async</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:55764"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:55764</id>
    <title>RLSA-2026:55764 — Important: kernel security, bug fix, and enhancement update</title>
    <updated>2026-10-02T22:11:23.802960+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:8: kernel</p>
<p>The kernel packages contain the Linux kernel, the core of any Linux operating system.</p>
<p>Security Fix(es):</p>
<p>* kernel: mm/slub: avoid accessing metadata when pointer is invalid in object_err() (CVE-2025-39902)</p>
<p>* kernel: drm/amdkfd: Fix out-of-bounds write in kfd_event_page_set() (CVE-2026-43206)</p>
<p>* kernel: crypto: ccp - copy IV using skcipher ivsize (CVE-2026-53016)</p>
<p>* kernel: drm/amd/display: Clamp VBIOS HDMI retimer register count to array size (CVE-2026-53136)</p>
<p>* kernel: drm/amd/display: Use krealloc_array() in dal_vector_reserve() (CVE-2026-53329)</p>
<p>* kernel: drm/amdgpu: zero-initialize GART table on allocation (CVE-2026-53374)</p>
<p>* kernel: drm/i915: Fix potential UAF in TTM object purge (CVE-2026-63884)</p>
<p>* kernel: drm/amdgpu: fix amdgpu_hmm_range_get_pages (CVE-2026-63879)</p>
<p>* kernel: drm/amd/display: Validate payload length and link_index in dc_process_dmub_aux_transfer_async (CVE-2026-64219)</p>
<p>* kernel: can:bcm: arbitrary kernel code execution leading to escalate privileges (CVE-2026-17523)</p>
<p>Bug Fix(es) and Enhancement(s):</p>
<p>* Backport "sched/deadline: Fix bandwidth reclaim equation in GRUB" to Rocky Linux 8.10 (JIRA:Rocky Linux-189997)</p>
<p>* vhost: reset the vring metadata cache on vring reconfiguration [rhel-8.10.z] (JIRA:Rocky Linux-224556)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:55764"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:23066-1</id>
    <title>SUSE-SU-2026:23066-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-02T22:11:23.803000+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:23066-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-53329</id>
    <title>UBUNTU-CVE-2026-53329</title>
    <updated>2026-10-02T22:11:23.803565+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe, Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:Pro:16.04:LTS: linux-oracle, Ubuntu:Pro:18.04:LTS: linux, Ubuntu:Pro:18.04:LTS: linux-aws, Ubuntu:18.04:LTS: linux-aws-5.0 and 248 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Use krealloc_array() in dal_vector_reserve() [Why &amp; How] dal_vector_reserve() computes the allocation size as "capacity * vector-&gt;struct_size" using uint32_t arithmetic, which can silently wrap to a small value on overflow. This would cause krealloc to return a smaller buffer than expected, leading to heap overflows on subsequent vector appends. Replace krealloc() with krealloc_array() which performs an internal overflow check and returns NULL on wrap, preventing the issue. (cherry picked from commit 37668568641ccc4cc1dbca4923d0a16609dd5707)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-53329"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2175</id>
    <title>WID-SEC-W-2026-2175 — Linux Kernel: Mehrere Schwachstellen</title>
    <updated>2026-10-02T22:11:23.803839+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen, darunter möglicherweise das Auslösen eines Denial-of-Service-Zustands, die Umgehung von Sicherheitsmaßnahmen oder das Verursachen von Speicherbeschädigungen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2175"/>
  </entry>
</feed>
