<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T06:45:26.402109+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:70402</id>
    <title>ALSA-2026:70402 — Important: kernel security, bug fix, and enhancement update</title>
    <updated>2026-10-03T06:45:27.077846+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: bpftool, AlmaLinux:8: kernel, AlmaLinux:8: kernel-abi-stablelists, AlmaLinux:8: kernel-core, AlmaLinux:8: kernel-cross-headers, AlmaLinux:8: kernel-debug, AlmaLinux:8: kernel-debug-core, AlmaLinux:8: kernel-debug-devel, AlmaLinux:8: kernel-debug-modules, AlmaLinux:8: kernel-debug-modules-extra and 15 more</p>
<p>The kernel packages contain the Linux kernel, the core of any Linux operating system.</p>
<p>Security Fix(es):</p>
<p>* kernel: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg (CVE-2025-39964)
  * kernel: Linux kernel Bluetooth: Denial of Service via race condition in hidp_session_thread (CVE-2023-54120)
  * kernel: Bluetooth: L2CAP: Fix potential user-after-free (CVE-2023-54214)
  * kernel: Bluetooth: btusb: revert use of devm_kzalloc in btusb (CVE-2025-71082)
  * kernel: Bluetooth: SMP: force responder MITM requirements before building the pairing response (CVE-2026-43334)
  * kernel: iommu/vt-d: Clear Present bit before tearing down PASID entry (CVE-2026-45894)
  * kernel: RDMA/rxe: Validate pad and ICRC before payload_size() in rxe_rcv (CVE-2026-46043)
  * kernel: RDMA/rxe: Reject unknown opcodes before ICRC processing (CVE-2026-46133)
  * kernel: Bluetooth: serialize accept_q access (CVE-2026-52918)
  * kernel: dm cache policy smq: fix missing locks in invalidating cache blocks (CVE-2026-53062)
  * kernel: iommu/amd: Fix clone_alias() to use the original device's devid (CVE-2026-53053)
  * kernel: Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind() (CVE-2026-53256)
  * kernel: Bluetooth: RFCOMM: validate skb length in MCC handlers (CVE-2026-53254)
  * kernel: keys: Pin request_key_auth payload in instantiate paths (CVE-2026-63823)
  * kernel: Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp (CVE-2026-63975)
  * kernel: Bluetooth: HIDP: fi…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:70402"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-64534</id>
    <title>BELL-CVE-2026-64534</title>
    <updated>2026-10-03T06:45:27.077979+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-64534"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0981</id>
    <title>certfr-2026-avi-0981 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de Debian. Elles permettent à un attaquant de provo…</title>
    <updated>2026-10-03T06:45:27.078007+00:00</updated>
    <content>certfr-2026-avi-0981</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0981"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-348460</id>
    <title>EUVD-2026-348460</title>
    <updated>2026-10-03T06:45:27.078025+00:00</updated>
    <content>EUVD-2026-348460</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-348460"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-64534</id>
    <title>fkie_cve-2026-64534</title>
    <updated>2026-10-03T06:45:27.078037+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>nvmet-tcp: check INIT_FAILED before nvmet_req_uninit in digest error path</p>
<p>In nvmet_tcp_try_recv_ddgst(), when a data digest mismatch is detected,
nvmet_req_uninit() is called unconditionally. However, if the command
arrived via the nvmet_tcp_handle_req_failure() path, nvmet_req_init()
had returned false and percpu_ref_tryget_live() was never executed. The
unconditional percpu_ref_put() inside nvmet_req_uninit() then causes a
refcount underflow, leading to a WARNING in
percpu_ref_switch_to_atomic_rcu, a use-after-free diagnostic, and
eventually a permanent workqueue deadlock.</p>
<p>Check cmd-&gt;flags &amp; NVMET_TCP_F_INIT_FAILED before calling
nvmet_req_uninit(), matching the existing pattern in
nvmet_tcp_execute_request().</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-64534"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-6vg3-7hp6-mqc5</id>
    <title>GHSA-6vg3-7hp6-mqc5</title>
    <updated>2026-10-03T06:45:27.078066+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>nvmet-tcp: check INIT_FAILED before nvmet_req_uninit in digest error path</p>
<p>In nvmet_tcp_try_recv_ddgst(), when a data digest mismatch is detected,
nvmet_req_uninit() is called unconditionally. However, if the command
arrived via the nvmet_tcp_handle_req_failure() path, nvmet_req_init()
had returned false and percpu_ref_tryget_live() was never executed. The
unconditional percpu_ref_put() inside nvmet_req_uninit() then causes a
refcount underflow, leading to a WARNING in
percpu_ref_switch_to_atomic_rcu, a use-after-free diagnostic, and
eventually a permanent workqueue deadlock.</p>
<p>Check cmd-&gt;flags &amp; NVMET_TCP_F_INIT_FAILED before calling
nvmet_req_uninit(), matching the existing pattern in
nvmet_tcp_execute_request().</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-6vg3-7hp6-mqc5"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-64534</id>
    <title>msrc_CVE-2026-64534 — nvmet-tcp: check INIT_FAILED before nvmet_req_uninit in digest error path</title>
    <updated>2026-10-03T06:45:27.078086+00:00</updated>
    <content>msrc_CVE-2026-64534</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-64534"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-3317</id>
    <title>OESA-2026-3317 — kernel security update</title>
    <updated>2026-10-03T06:45:27.078104+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:22.03-LTS-SP4: kernel</p>
<p>The Linux Kernel, the operating system core itself.

Security Fix(es):</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>drm/amdgpu: prevent immediate PASID reuse case</p>
<p>PASID resue could cause interrupt issue when process
immediately runs into hw state left by previous
process exited with the same PASID, it&amp;apos;s possible that
page faults are still pending in the IH ring buffer when
the process exits and frees up its PASID. To prevent the
case, it uses idr cyclic allocator same as kernel pid&amp;apos;s.</p>
<p>(cherry picked from commit 8f1de51f49be692de137c8525106e0fce2d1912d)(CVE-2026-31462)</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>media: hackrf: fix to not free memory after the device is registered in hackrf_probe()</p>
<p>In hackrf driver, the following race condition occurs:
```
		CPU0						CPU1
hackrf_probe()
  kzalloc(); // alloc hackrf_dev
  ....
  v4l2_device_register();
  ....
						fd = sys_open(&amp;quot;/path/to/dev&amp;quot;); // open hackrf fd
						....
  v4l2_device_unregister();
  ....
  kfree(); // free hackrf_dev
  ....
						sys_ioctl(fd, ...);
						  v4l2_ioctl();
						    video_is_registered() // UAF!!
						....
						sys_close(fd);
						  v4l2_release() // UAF!!
						    hackrf_video_release()
						      kfree(); // DFB!!
```</p>
<p>When a V4L2 or video device is unregistered, the device node is removed so
new open() calls are blocked.</p>
<p>However, file descriptors that are already open-and any in-flight I/O-do
not terminate i…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-3317"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:21910-1</id>
    <title>openSUSE-SU-2026:21910-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-03T06:45:27.078340+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:21910-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:70402</id>
    <title>RHSA-2026:70402 — Red Hat Security Advisory: kernel security, bug fix, and enhancement update</title>
    <updated>2026-10-03T06:45:27.078856+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>kernel: Linux kernel Bluetooth: Denial of Service via race condition in hidp_session_thread kernel: Bluetooth: L2CAP: Fix potential user-after-free kernel: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg kernel: Bluetooth: btusb: revert use of devm_kzalloc in btusb kernel: Bluetooth: SMP: force responder MITM requirements before building the pairing response kernel: iommu/vt-d: Clear Present bit before tearing down PASID entry kernel: RDMA/rxe: Validate pad and ICRC before payload_size() in rxe_rcv kernel: RDMA/rxe: Reject unknown opcodes before ICRC processing kernel: Bluetooth: serialize accept_q access kernel: iommu/amd: Fix clone_alias() to use the original device's devid kernel: dm cache policy smq: fix missing locks in invalidating cache blocks kernel: Bluetooth: RFCOMM: validate skb length in MCC handlers kernel: Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind() kernel: keys: Pin request_key_auth payload in instantiate paths kernel: Bluetooth: HIDP: fix missing length checks in hidp_input_report() kernel: Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp kernel: nvmet-tcp: check INIT_FAILED before nvmet_req_uninit in digest error path kernel: RDMA/rxe: Fix a use-after-free problem in rxe_mmap kernel: Linux kernel Bluetooth RFCOMM: Denial of Service via use-after-free in set_termios kernel: net/mlx5: Fix MCIA register buffer overflow on 32 dword reads</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:70402"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:70402</id>
    <title>RLSA-2026:70402 — Important: kernel security, bug fix, and enhancement update</title>
    <updated>2026-10-03T06:45:27.078909+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:8: kernel</p>
<p>The kernel packages contain the Linux kernel, the core of any Linux operating system.</p>
<p>Security Fix(es):</p>
<p>* kernel: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg (CVE-2025-39964)</p>
<p>* kernel: Linux kernel Bluetooth: Denial of Service via race condition in hidp_session_thread (CVE-2023-54120)</p>
<p>* kernel: Bluetooth: L2CAP: Fix potential user-after-free (CVE-2023-54214)</p>
<p>* kernel: Bluetooth: btusb: revert use of devm_kzalloc in btusb (CVE-2025-71082)</p>
<p>* kernel: Bluetooth: SMP: force responder MITM requirements before building the pairing response (CVE-2026-43334)</p>
<p>* kernel: iommu/vt-d: Clear Present bit before tearing down PASID entry (CVE-2026-45894)</p>
<p>* kernel: RDMA/rxe: Validate pad and ICRC before payload_size() in rxe_rcv (CVE-2026-46043)</p>
<p>* kernel: RDMA/rxe: Reject unknown opcodes before ICRC processing (CVE-2026-46133)</p>
<p>* kernel: Bluetooth: serialize accept_q access (CVE-2026-52918)</p>
<p>* kernel: dm cache policy smq: fix missing locks in invalidating cache blocks (CVE-2026-53062)</p>
<p>* kernel: iommu/amd: Fix clone_alias() to use the original device's devid (CVE-2026-53053)</p>
<p>* kernel: Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind() (CVE-2026-53256)</p>
<p>* kernel: Bluetooth: RFCOMM: validate skb length in MCC handlers (CVE-2026-53254)</p>
<p>* kernel: keys: Pin request_key_auth payload in instantiate paths (CVE-2026-63823)</p>
<p>* kernel: Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp (CVE-2026-63975)</p>
<p>* kernel: Bluetooth: HIDP: fix missing length chec…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:70402"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:23881-1</id>
    <title>SUSE-SU-2026:23881-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-03T06:45:27.078956+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:23881-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-64534</id>
    <title>UBUNTU-CVE-2026-64534</title>
    <updated>2026-10-03T06:45:27.079523+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 193 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: check INIT_FAILED before nvmet_req_uninit in digest error path In nvmet_tcp_try_recv_ddgst(), when a data digest mismatch is detected, nvmet_req_uninit() is called unconditionally. However, if the command arrived via the nvmet_tcp_handle_req_failure() path, nvmet_req_init() had returned false and percpu_ref_tryget_live() was never executed. The unconditional percpu_ref_put() inside nvmet_req_uninit() then causes a refcount underflow, leading to a WARNING in percpu_ref_switch_to_atomic_rcu, a use-after-free diagnostic, and eventually a permanent workqueue deadlock. Check cmd-&gt;flags &amp; NVMET_TCP_F_INIT_FAILED before calling nvmet_req_uninit(), matching the existing pattern in nvmet_tcp_execute_request().</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-64534"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2527</id>
    <title>WID-SEC-W-2026-2527 — Linux Kernel: Mehrere Schwachstellen</title>
    <updated>2026-10-03T06:45:27.079753+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um nicht näher spezifizierte Angriffe durchzuführen, dazu können DoS-Angriffe, die Offenlegung von Informationen, die Beschädigung des Speichers oder die Umgehung von Sicherheitsmaßnahmen gehören.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2527"/>
  </entry>
</feed>
