<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T11:06:42.572303+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-14332</id>
    <title>bdu:2026-14332</title>
    <updated>2026-10-02T11:06:43.402785+00:00</updated>
    <content>bdu:2026-14332</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-14332"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-63959</id>
    <title>BELL-CVE-2026-63959</title>
    <updated>2026-10-02T11:06:43.402838+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-63959"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0926</id>
    <title>certfr-2026-avi-0926 — De multiples vulnérabilités ont été découvertes dans le noyau Linux d'Ubuntu. Certaines d'entre elles permettent à un a…</title>
    <updated>2026-10-02T11:06:43.402870+00:00</updated>
    <content>certfr-2026-avi-0926</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0926"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-338805</id>
    <title>EUVD-2026-338805</title>
    <updated>2026-10-02T11:06:43.402888+00:00</updated>
    <content>EUVD-2026-338805</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-338805"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-63959</id>
    <title>fkie_cve-2026-63959</title>
    <updated>2026-10-02T11:06:43.402900+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>usb: typec: tcpm/tcpci_maxim: validate header NDO against RX_BYTE_CNT</p>
<p>A broken/malicious port can transmit a CRC-valid frame whose header
advertises up to seven data objects but whose body carries fewer than
that.  Check for this, and rightfully reject the message, instead of
reading from uninitialized stack memory.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-63959"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-fwcg-qvj5-vv4j</id>
    <title>GHSA-fwcg-qvj5-vv4j</title>
    <updated>2026-10-02T11:06:43.402927+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>usb: typec: tcpm/tcpci_maxim: validate header NDO against RX_BYTE_CNT</p>
<p>A broken/malicious port can transmit a CRC-valid frame whose header
advertises up to seven data objects but whose body carries fewer than
that.  Check for this, and rightfully reject the message, instead of
reading from uninitialized stack memory.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-fwcg-qvj5-vv4j"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-63959</id>
    <title>msrc_CVE-2026-63959 — usb: typec: tcpm/tcpci_maxim: validate header NDO against RX_BYTE_CNT</title>
    <updated>2026-10-02T11:06:43.402944+00:00</updated>
    <content>msrc_CVE-2026-63959</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-63959"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-3206</id>
    <title>OESA-2026-3206 — kernel security update</title>
    <updated>2026-10-02T11:06:43.402961+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:22.03-LTS-SP4: kernel</p>
<p>The Linux Kernel, the operating system core itself.

Security Fix(es):</p>
<p>Arm C1-Ultra, C1-Premium, Neoverse V3 &amp;amp; V3AE, Neoverse V2, Neoverse V1, Neoverse-N2, Neoverse-N1, Cortex-X925, Cortex-X4, Cortex-X3, Cortex-X2, Cortex-X1 &amp;amp; X1C, Cortex-A710, Cortex-A78, A78AE &amp;amp; A78C, Cortex-A77, Cortex-A76 &amp;amp; A76A may allow writes to resources owned by a higher exception level.(CVE-2025-10263)</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>inet: RAW sockets using IPPROTO_RAW MUST drop incoming ICMP</p>
<p>Yizhou Zhao reported that simply having one RAW socket on protocol
IPPROTO_RAW (255) was dangerous.</p>
<p>socket(AF_INET, SOCK_RAW, 255);</p>
<p>A malicious incoming ICMP packet can set the protocol field to 255
and match this socket, leading to FNHE cache changes.</p>
<p>inner = IP(src=&amp;quot;192.168.2.1&amp;quot;, dst=&amp;quot;8.8.8.8&amp;quot;, proto=255)/Raw(&amp;quot;TEST&amp;quot;)
pkt = IP(src=&amp;quot;192.168.1.1&amp;quot;, dst=&amp;quot;192.168.2.1&amp;quot;)/ICMP(type=3, code=4, nexthopmtu=576)/inner</p>
<p>&amp;quot;man 7 raw&amp;quot; states:</p>
<p>A protocol of IPPROTO_RAW implies enabled IP_HDRINCL and is able
  to send any IP protocol that is specified in the passed header.
  Receiving of all IP protocols via IPPROTO_RAW is not possible
  using raw sockets.</p>
<p>Make sure we drop these malicious packets.(CVE-2026-46266)</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>tun: free page on build_skb failure in tun_xdp_one()</p>
<p>When build_skb() fails in tun_xdp_one(), the function sets ret to
-…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-3206"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:21555-1</id>
    <title>openSUSE-SU-2026:21555-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-02T11:06:43.403070+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:21555-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:23066-1</id>
    <title>SUSE-SU-2026:23066-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-02T11:06:43.403800+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:23066-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-63959</id>
    <title>UBUNTU-CVE-2026-63959</title>
    <updated>2026-10-02T11:06:43.404325+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: linux, Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe and 245 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: usb: typec: tcpm/tcpci_maxim: validate header NDO against RX_BYTE_CNT A broken/malicious port can transmit a CRC-valid frame whose header advertises up to seven data objects but whose body carries fewer than that.  Check for this, and rightfully reject the message, instead of reading from uninitialized stack memory.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-63959"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2403</id>
    <title>WID-SEC-W-2026-2403 — Linux Kernel: Mehrere Schwachstellen ermöglichen nicht spezifizierten Angriff</title>
    <updated>2026-10-02T11:06:43.404620+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen, möglicherweise Sicherheitsmaßnahmen zu umgehen, einen Denial-of-Service-Zustand herbeizuführen oder vertrauliche Informationen offenzulegen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2403"/>
  </entry>
</feed>
