<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T05:18:16.575166+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:66180</id>
    <title>ALSA-2026:66180 — Important: kernel security, bug fix, and enhancement update</title>
    <updated>2026-10-03T05:18:19.227805+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:9: kernel, AlmaLinux:9: kernel-64k, AlmaLinux:9: kernel-64k-core, AlmaLinux:9: kernel-64k-debug, AlmaLinux:9: kernel-64k-debug-core, AlmaLinux:9: kernel-64k-debug-devel, AlmaLinux:9: kernel-64k-debug-devel-matched, AlmaLinux:9: kernel-64k-debug-modules, AlmaLinux:9: kernel-64k-debug-modules-core, AlmaLinux:9: kernel-64k-debug-modules-extra and 64 more</p>
<p>The kernel packages contain the Linux kernel, the core of any Linux operating system.</p>
<p>Security Fix(es):</p>
<p>* kernel: KVM: nSVM: Always use vmcb01 in VMLOAD/VMSAVE emulation (CVE-2026-43133)
  * kernel: ipv6: prevent possible UaF in addrconf_permanent_addr() (CVE-2026-43339)
  * kernel: crypto: pcrypt - Fix handling of MAY_BACKLOG requests (CVE-2026-43493)
  * kernel: tcp: call sk_data_ready() after listener migration (CVE-2026-46015)
  * kernel: scsi: target: configfs: Bound snprintf() return in tg_pt_gp_members_show() (CVE-2026-46149)
  * kernel: inet: RAW sockets using IPPROTO_RAW MUST drop incoming ICMP (CVE-2026-46266)
  * kernel: flow_dissector: do not dissect PPPoE PFC frames (CVE-2026-46306)
  * kernel: Revert "net/smc: Introduce TCP ULP support" (CVE-2026-46330)
  * kernel: netfilter: conntrack: remove sprintf usage (CVE-2026-53002)
  * kernel: net: guard timestamp cmsgs to real error queue skbs (CVE-2026-53223)
  * kernel: ipv6: mcast: Fix use-after-free when processing MLD queries (CVE-2026-53275)
  * kernel: ipv4: account for fraggap on the paged allocation path (CVE-2026-53366)
  * kernel: net: mana: Fix TOCTOU double-fetch of hwc_msg_id from DMA buffer (CVE-2026-64034)
  * kernel: rhashtable: clear stale iter-&gt;p on table restart (CVE-2026-64563)
  * kernel: smb: client: fix double-free in SMB2_close() replay (CVE-2026-64597)
  * kernel: nvmet-rdma: handle inline data with a nonzero offset (CVE-2026-72129)
  * kernel: net: bridge: stop fast-leave after delet…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:66180"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-10626</id>
    <title>bdu:2026-10626</title>
    <updated>2026-10-03T05:18:19.228094+00:00</updated>
    <content>bdu:2026-10626</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-10626"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-53366</id>
    <title>BELL-CVE-2026-53366</title>
    <updated>2026-10-03T05:18:19.228128+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-53366"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0927</id>
    <title>certfr-2026-avi-0927 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de SUSE. Certaines d'entre elles permettent à un at…</title>
    <updated>2026-10-03T05:18:19.228168+00:00</updated>
    <content>certfr-2026-avi-0927</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0927"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-353092</id>
    <title>EUVD-2026-353092</title>
    <updated>2026-10-03T05:18:19.228202+00:00</updated>
    <content>EUVD-2026-353092</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-353092"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-53366</id>
    <title>fkie_cve-2026-53366</title>
    <updated>2026-10-03T05:18:19.228219+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>ipv4: account for fraggap on the paged allocation path</p>
<p>In __ip_append_data(), when the paged-allocation branch is taken,
alloclen and pagedlen are computed as</p>
<p>alloclen = fragheaderlen + transhdrlen;
	pagedlen = datalen - transhdrlen;</p>
<p>datalen already includes fraggap, but the fraggap bytes carried over
from the previous skb are copied into the new skb's linear area at
offset transhdrlen by the subsequent skb_copy_and_csum_bits(). The
linear area is therefore undersized by fraggap bytes while pagedlen is
overstated by the same amount.</p>
<p>The non-paged branch sets alloclen to fraglen, which already accounts
for fraggap because datalen does. Bring the paged branch in line by
adding fraggap to alloclen and subtracting it from pagedlen.</p>
<p>After this adjustment, copy no longer collapses to -fraggap on the
paged path, so remove the stale comment describing that old arithmetic.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-53366"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-r67c-r6r6-mj6m</id>
    <title>GHSA-r67c-r6r6-mj6m</title>
    <updated>2026-10-03T05:18:19.228276+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>ipv4: account for fraggap on the paged allocation path</p>
<p>In __ip_append_data(), when the paged-allocation branch is taken,
alloclen and pagedlen are computed as</p>
<p>alloclen = fragheaderlen + transhdrlen;
	pagedlen = datalen - transhdrlen;</p>
<p>datalen already includes fraggap, but the fraggap bytes carried over
from the previous skb are copied into the new skb's linear area at
offset transhdrlen by the subsequent skb_copy_and_csum_bits(). The
linear area is therefore undersized by fraggap bytes while pagedlen is
overstated by the same amount.</p>
<p>The non-paged branch sets alloclen to fraglen, which already accounts
for fraggap because datalen does. Bring the paged branch in line by
adding fraggap to alloclen and subtracting it from pagedlen.</p>
<p>After this adjustment, copy no longer collapses to -fraggap on the
paged path, so remove the stale comment describing that old arithmetic.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-r67c-r6r6-mj6m"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-53366</id>
    <title>msrc_CVE-2026-53366 — ipv4: account for fraggap on the paged allocation path</title>
    <updated>2026-10-03T05:18:19.228326+00:00</updated>
    <content>msrc_CVE-2026-53366</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-53366"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11339-1</id>
    <title>openSUSE-SU-2026:11339-1 — kernel-devel-7.1.4-1.1 on GA media</title>
    <updated>2026-10-03T05:18:19.228346+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>kernel-devel-7.1.4-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:11339-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:35840</id>
    <title>RHSA-2026:35840 — Red Hat Security Advisory: kernel security, bug fix, and enhancement update</title>
    <updated>2026-10-03T05:18:19.228401+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>kernel: kernel: ipv6 frag escape kernel: ipv4: account for fraggap on the paged allocation path</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:35840"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:66180</id>
    <title>RLSA-2026:66180 — Important: kernel security, bug fix, and enhancement update</title>
    <updated>2026-10-03T05:18:19.228420+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:9: kernel</p>
<p>The kernel packages contain the Linux kernel, the core of any Linux operating system.</p>
<p>Security Fix(es):</p>
<p>* kernel: KVM: nSVM: Always use vmcb01 in VMLOAD/VMSAVE emulation (CVE-2026-43133)</p>
<p>* kernel: ipv6: prevent possible UaF in addrconf_permanent_addr() (CVE-2026-43339)</p>
<p>* kernel: crypto: pcrypt - Fix handling of MAY_BACKLOG requests (CVE-2026-43493)</p>
<p>* kernel: tcp: call sk_data_ready() after listener migration (CVE-2026-46015)</p>
<p>* kernel: scsi: target: configfs: Bound snprintf() return in tg_pt_gp_members_show() (CVE-2026-46149)</p>
<p>* kernel: inet: RAW sockets using IPPROTO_RAW MUST drop incoming ICMP (CVE-2026-46266)</p>
<p>* kernel: flow_dissector: do not dissect PPPoE PFC frames (CVE-2026-46306)</p>
<p>* kernel: Revert "net/smc: Introduce TCP ULP support" (CVE-2026-46330)</p>
<p>* kernel: netfilter: conntrack: remove sprintf usage (CVE-2026-53002)</p>
<p>* kernel: net: guard timestamp cmsgs to real error queue skbs (CVE-2026-53223)</p>
<p>* kernel: ipv6: mcast: Fix use-after-free when processing MLD queries (CVE-2026-53275)</p>
<p>* kernel: ipv4: account for fraggap on the paged allocation path (CVE-2026-53366)</p>
<p>* kernel: net: mana: Fix TOCTOU double-fetch of hwc_msg_id from DMA buffer (CVE-2026-64034)</p>
<p>* kernel: rhashtable: clear stale iter-&gt;p on table restart (CVE-2026-64563)</p>
<p>* kernel: smb: client: fix double-free in SMB2_close() replay (CVE-2026-64597)</p>
<p>* kernel: nvmet-rdma: handle inline data with a nonzero offset (CVE-2026-72129)</p>
<p>* kernel: net: bridge: stop fast-leave after deleting a port group (CVE-…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:66180"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:22809-1</id>
    <title>SUSE-SU-2026:22809-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-03T05:18:19.228469+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:22809-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-53366</id>
    <title>UBUNTU-CVE-2026-53366</title>
    <updated>2026-10-03T05:18:19.228530+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 154 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: ipv4: account for fraggap on the paged allocation path In __ip_append_data(), when the paged-allocation branch is taken, alloclen and pagedlen are computed as 	alloclen = fragheaderlen + transhdrlen; 	pagedlen = datalen - transhdrlen; datalen already includes fraggap, but the fraggap bytes carried over from the previous skb are copied into the new skb's linear area at offset transhdrlen by the subsequent skb_copy_and_csum_bits(). The linear area is therefore undersized by fraggap bytes while pagedlen is overstated by the same amount. The non-paged branch sets alloclen to fraglen, which already accounts for fraggap because datalen does. Bring the paged branch in line by adding fraggap to alloclen and subtracting it from pagedlen. After this adjustment, copy no longer collapses to -fraggap on the paged path, so remove the stale comment describing that old arithmetic.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-53366"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2382</id>
    <title>WID-SEC-W-2026-2382 — Linux Kernel: Schwachstelle ermöglicht Denial of Service</title>
    <updated>2026-10-03T05:18:19.228793+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann eine Schwachstelle im Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2382"/>
  </entry>
</feed>
