<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T17:01:44.954892+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:66324</id>
    <title>ALSA-2026:66324 — Important: kernel-rt security, bug fix, and enhancement update</title>
    <updated>2026-10-03T17:01:45.983132+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: kernel-rt, AlmaLinux:8: kernel-rt-core, AlmaLinux:8: kernel-rt-debug, AlmaLinux:8: kernel-rt-debug-core, AlmaLinux:8: kernel-rt-debug-devel, AlmaLinux:8: kernel-rt-debug-modules, AlmaLinux:8: kernel-rt-debug-modules-extra, AlmaLinux:8: kernel-rt-devel, AlmaLinux:8: kernel-rt-modules, AlmaLinux:8: kernel-rt-modules-extra</p>
<p>The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements.</p>
<p>Security Fix(es):</p>
<p>* kernel: Linux kernel: Denial of Service in qla2xxx SCSI driver due to improper command handling after chip reset (CVE-2025-68745)
  * kernel: scsi: target: configfs: Bound snprintf() return in tg_pt_gp_members_show() (CVE-2026-46149)
  * kernel: netfilter: nf_log: validate MAC header was set before dumping it (CVE-2026-52942)
  * kernel: sctp: diag: reject stale associations in dump_one path (CVE-2026-52917)
  * kernel: net: pull headers in qdisc_pkt_len_segs_init() (CVE-2026-53091)
  * kernel: netfilter: nf_conntrack_sip: don't use simple_strtoul (CVE-2026-52986)
  * kernel: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing (CVE-2026-53246)
  * kernel: tipc: fix slab-use-after-free Read in tipc_aead_decrypt_done (CVE-2026-63801)
  * kernel: sctp: fix race between sctp_wait_for_connect and peeloff (CVE-2026-63971)
  * kernel: security/keys: fix missed RCU read section on lookup (CVE-2026-64015)
  * kernel: ixgbevf: fix use-after-free in VEPA multicast source pruning (CVE-2026-64113)
  * kernel: sctp: fix auth_hmacs array size in struct sctp_cookie (CVE-2026-68376)
  * kernel: tipc: clear sock-&gt;sk on the failed-insert path in tipc_sk_create() (CVE-2026-68117)
  * kernel: sctp: auth: verify auth requirement when auth_chunk is NULL (CVE-2026-68300)
  * kernel: sctp: validate stream count i…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:66324"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-63801</id>
    <title>BELL-CVE-2026-63801</title>
    <updated>2026-10-03T17:01:45.983323+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-63801"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0957</id>
    <title>certfr-2026-avi-0957 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de Debian LTS. Certaines d'entre elles permettent à…</title>
    <updated>2026-10-03T17:01:45.983352+00:00</updated>
    <content>certfr-2026-avi-0957</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0957"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-353123</id>
    <title>EUVD-2026-353123</title>
    <updated>2026-10-03T17:01:45.983371+00:00</updated>
    <content>EUVD-2026-353123</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-353123"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-63801</id>
    <title>fkie_cve-2026-63801</title>
    <updated>2026-10-03T17:01:45.983384+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>tipc: fix slab-use-after-free Read in tipc_aead_decrypt_done</p>
<p>tipc_aead_decrypt() goes straight from tipc_bearer_hold(b) to
crypto_aead_decrypt(req) without taking a reference on the netns, unlike
the encrypt path. When crypto_aead_decrypt() is offloaded asynchronously
(e.g. the SIMD aead wrapper queuing to cryptd), the cryptd worker runs
tipc_aead_decrypt_done() later. If the bearer's netns is torn down in the
meantime, cleanup_net() -&gt; tipc_exit_net() -&gt; tipc_crypto_stop() frees the
per-netns tipc_crypto, and the completion then reads it:
tipc_aead_decrypt_done() dereferences aead-&gt;crypto-&gt;stats and
aead-&gt;crypto-&gt;net, and tipc_crypto_rcv_complete() dereferences
aead-&gt;crypto-&gt;aead[] and the node table -- reading freed memory.</p>
<p>Decoded KASAN splat (v7.1-rc7, CONFIG_KASAN_INLINE + TIPC + TIPC_CRYPTO):</p>
<p>BUG: KASAN: slab-use-after-free in tipc_aead_decrypt_done (net/tipc/crypto.c:999)
  Read of size 8 at addr ffff8881056258a8 by task kworker/u16:2/51
  Workqueue: events_unbound
  Call Trace:
   tipc_aead_decrypt_done (net/tipc/crypto.c:999)
   process_one_work (kernel/workqueue.c:3314)
   worker_thread (kernel/workqueue.c:3397 kernel/workqueue.c:3478)
   kthread (kernel/kthread.c:436)
   ret_from_fork (arch/x86/kernel/process.c:158)
   ret_from_fork_asm (arch/x86/entry/entry_64.S:245)</p>
<p>Allocated by task 169:
   __kasan_kmalloc (mm/kasan/common.c:398 mm/kasan/common.c:415)
   tipc_crypto_start (net/tipc/cry…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-63801"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-xqwj-phvh-5pp9</id>
    <title>GHSA-xqwj-phvh-5pp9</title>
    <updated>2026-10-03T17:01:45.983432+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>tipc: fix slab-use-after-free Read in tipc_aead_decrypt_done</p>
<p>tipc_aead_decrypt() goes straight from tipc_bearer_hold(b) to
crypto_aead_decrypt(req) without taking a reference on the netns, unlike
the encrypt path. When crypto_aead_decrypt() is offloaded asynchronously
(e.g. the SIMD aead wrapper queuing to cryptd), the cryptd worker runs
tipc_aead_decrypt_done() later. If the bearer's netns is torn down in the
meantime, cleanup_net() -&gt; tipc_exit_net() -&gt; tipc_crypto_stop() frees the
per-netns tipc_crypto, and the completion then reads it:
tipc_aead_decrypt_done() dereferences aead-&gt;crypto-&gt;stats and
aead-&gt;crypto-&gt;net, and tipc_crypto_rcv_complete() dereferences
aead-&gt;crypto-&gt;aead[] and the node table -- reading freed memory.</p>
<p>Decoded KASAN splat (v7.1-rc7, CONFIG_KASAN_INLINE + TIPC + TIPC_CRYPTO):</p>
<p>BUG: KASAN: slab-use-after-free in tipc_aead_decrypt_done (net/tipc/crypto.c:999)
  Read of size 8 at addr ffff8881056258a8 by task kworker/u16:2/51
  Workqueue: events_unbound
  Call Trace:
   tipc_aead_decrypt_done (net/tipc/crypto.c:999)
   process_one_work (kernel/workqueue.c:3314)
   worker_thread (kernel/workqueue.c:3397 kernel/workqueue.c:3478)
   kthread (kernel/kthread.c:436)
   ret_from_fork (arch/x86/kernel/process.c:158)
   ret_from_fork_asm (arch/x86/entry/entry_64.S:245)</p>
<p>Allocated by task 169:
   __kasan_kmalloc (mm/kasan/common.c:398 mm/kasan/common.c:415)
   tipc_crypto_start (net/tipc/cry…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-xqwj-phvh-5pp9"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-63801</id>
    <title>msrc_CVE-2026-63801 — tipc: fix slab-use-after-free Read in tipc_aead_decrypt_done</title>
    <updated>2026-10-03T17:01:45.983471+00:00</updated>
    <content>msrc_CVE-2026-63801</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-63801"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-3702</id>
    <title>OESA-2026-3702 — kernel security update</title>
    <updated>2026-10-03T17:01:45.983489+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:22.03-LTS-SP4: kernel</p>
<p>The Linux Kernel, the operating system core itself.

Security Fix(es):</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>net/9p: fix double req put in p9_fd_cancelled</p>
<p>Syzkaller reports a KASAN issue as below:</p>
<p>general protection fault, probably for non-canonical address 0xfbd59c0000000021: 0000 [#1] PREEMPT SMP KASAN NOPTI
KASAN: maybe wild-memory-access in range [0xdead000000000108-0xdead00000000010f]
CPU: 0 PID: 5083 Comm: syz-executor.2 Not tainted 6.1.134-syzkaller-00037-g855bd1d7d838 #0
Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.12.0-1 04/01/2014
RIP: 0010:__list_del include/linux/list.h:114 [inline]
RIP: 0010:__list_del_entry include/linux/list.h:137 [inline]
RIP: 0010:list_del include/linux/list.h:148 [inline]
RIP: 0010:p9_fd_cancelled+0xe9/0x200 net/9p/trans_fd.c:734</p>
<p>Call Trace:
 &amp;lt;TASK&amp;gt;
 p9_client_flush+0x351/0x440 net/9p/client.c:614
 p9_client_rpc+0xb6b/0xc70 net/9p/client.c:734
 p9_client_version net/9p/client.c:920 [inline]
 p9_client_create+0xb51/0x1240 net/9p/client.c:1027
 v9fs_session_init+0x1f0/0x18f0 fs/9p/v9fs.c:408
 v9fs_mount+0xba/0xcb0 fs/9p/vfs_super.c:126
 legacy_get_tree+0x108/0x220 fs/fs_context.c:632
 vfs_get_tree+0x8e/0x300 fs/super.c:1573
 do_new_mount fs/namespace.c:3056 [inline]
 path_mount+0x6a6/0x1e90 fs/namespace.c:3386
 do_mount fs/namespace.c:3399 [inline]
 __do_sys_mount fs/namespace.c:3607 [inline]
 __se_sys_mount fs/namespace.c:3584 [inline]
 __x64_sys_mount+0x283/0x300 fs/namespace.c:358…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-3702"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11339-1</id>
    <title>openSUSE-SU-2026:11339-1 — kernel-devel-7.1.4-1.1 on GA media</title>
    <updated>2026-10-03T17:01:45.983679+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>kernel-devel-7.1.4-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:11339-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:66324</id>
    <title>RHSA-2026:66324 — Red Hat Security Advisory: kernel-rt security, bug fix, and enhancement update</title>
    <updated>2026-10-03T17:01:45.983737+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>kernel: Linux kernel: Denial of Service in qla2xxx SCSI driver due to improper command handling after chip reset kernel: scsi: target: configfs: Bound snprintf() return in tg_pt_gp_members_show() kernel: sctp: diag: reject stale associations in dump_one path kernel: netfilter: nf_log: validate MAC header was set before dumping it kernel: netfilter: nf_conntrack_sip: don't use simple_strtoul kernel: net: pull headers in qdisc_pkt_len_segs_init() kernel: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing kernel: tipc: fix slab-use-after-free Read in tipc_aead_decrypt_done kernel: sctp: fix race between sctp_wait_for_connect and peeloff kernel: security/keys: fix missed RCU read section on lookup kernel: ixgbevf: fix use-after-free in VEPA multicast source pruning kernel: tipc: clear sock-&gt;sk on the failed-insert path in tipc_sk_create() kernel: sctp: auth: verify auth requirement when auth_chunk is NULL kernel: sctp: validate stream count in sctp_process_strreset_inreq() kernel: sctp: fix auth_hmacs array size in struct sctp_cookie</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:66324"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:66324</id>
    <title>RLSA-2026:66324 — Important: kernel-rt security, bug fix, and enhancement update</title>
    <updated>2026-10-03T17:01:45.983790+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:8: kernel-rt</p>
<p>The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements.</p>
<p>Security Fix(es):</p>
<p>* kernel: Linux kernel: Denial of Service in qla2xxx SCSI driver due to improper command handling after chip reset (CVE-2025-68745)</p>
<p>* kernel: scsi: target: configfs: Bound snprintf() return in tg_pt_gp_members_show() (CVE-2026-46149)</p>
<p>* kernel: netfilter: nf_log: validate MAC header was set before dumping it (CVE-2026-52942)</p>
<p>* kernel: sctp: diag: reject stale associations in dump_one path (CVE-2026-52917)</p>
<p>* kernel: net: pull headers in qdisc_pkt_len_segs_init() (CVE-2026-53091)</p>
<p>* kernel: netfilter: nf_conntrack_sip: don't use simple_strtoul (CVE-2026-52986)</p>
<p>* kernel: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing (CVE-2026-53246)</p>
<p>* kernel: tipc: fix slab-use-after-free Read in tipc_aead_decrypt_done (CVE-2026-63801)</p>
<p>* kernel: sctp: fix race between sctp_wait_for_connect and peeloff (CVE-2026-63971)</p>
<p>* kernel: security/keys: fix missed RCU read section on lookup (CVE-2026-64015)</p>
<p>* kernel: ixgbevf: fix use-after-free in VEPA multicast source pruning (CVE-2026-64113)</p>
<p>* kernel: sctp: fix auth_hmacs array size in struct sctp_cookie (CVE-2026-68376)</p>
<p>* kernel: tipc: clear sock-&gt;sk on the failed-insert path in tipc_sk_create() (CVE-2026-68117)</p>
<p>* kernel: sctp: auth: verify auth requirement when auth_chunk is NULL (CVE-2026-68300)</p>
<p>* kernel: sctp: validate stream count in sctp_process_strre…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:66324"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:23477-1</id>
    <title>SUSE-SU-2026:23477-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-03T17:01:45.983835+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:23477-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-63801</id>
    <title>UBUNTU-CVE-2026-63801</title>
    <updated>2026-10-03T17:01:45.984139+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 193 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: tipc: fix slab-use-after-free Read in tipc_aead_decrypt_done tipc_aead_decrypt() goes straight from tipc_bearer_hold(b) to crypto_aead_decrypt(req) without taking a reference on the netns, unlike the encrypt path. When crypto_aead_decrypt() is offloaded asynchronously (e.g. the SIMD aead wrapper queuing to cryptd), the cryptd worker runs tipc_aead_decrypt_done() later. If the bearer's netns is torn down in the meantime, cleanup_net() -&gt; tipc_exit_net() -&gt; tipc_crypto_stop() frees the per-netns tipc_crypto, and the completion then reads it: tipc_aead_decrypt_done() dereferences aead-&gt;crypto-&gt;stats and aead-&gt;crypto-&gt;net, and tipc_crypto_rcv_complete() dereferences aead-&gt;crypto-&gt;aead[] and the node table -- reading freed memory. Decoded KASAN splat (v7.1-rc7, CONFIG_KASAN_INLINE + TIPC + TIPC_CRYPTO):   BUG: KASAN: slab-use-after-free in tipc_aead_decrypt_done (net/tipc/crypto.c:999)   Read of size 8 at addr ffff8881056258a8 by task kworker/u16:2/51   Workqueue: events_unbound   Call Trace:    tipc_aead_decrypt_done (net/tipc/crypto.c:999)    process_one_work (kernel/workqueue.c:3314)    worker_thread (kernel/workqueue.c:3397 kernel/workqueue.c:3478)    kthread (kernel/kthread.c:436)    ret_from_fork (arch/x86/kernel/process.c:158)    ret_from_fork_asm (arch/x86/entry/entry_64.S:245)   Allocated by task 169:    __kasan_kmalloc (mm/kasan/common.c:398 mm/kasan/common.c:415)    tipc_crypto_start (net/tipc/crypto.c…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-63801"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2403</id>
    <title>WID-SEC-W-2026-2403 — Linux Kernel: Mehrere Schwachstellen ermöglichen nicht spezifizierten Angriff</title>
    <updated>2026-10-03T17:01:45.984378+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen, möglicherweise Sicherheitsmaßnahmen zu umgehen, einen Denial-of-Service-Zustand herbeizuführen oder vertrauliche Informationen offenzulegen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2403"/>
  </entry>
</feed>
