<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T12:47:12.901221+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:66324</id>
    <title>ALSA-2026:66324 — Important: kernel-rt security, bug fix, and enhancement update</title>
    <updated>2026-10-03T12:47:13.919365+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: kernel-rt, AlmaLinux:8: kernel-rt-core, AlmaLinux:8: kernel-rt-debug, AlmaLinux:8: kernel-rt-debug-core, AlmaLinux:8: kernel-rt-debug-devel, AlmaLinux:8: kernel-rt-debug-modules, AlmaLinux:8: kernel-rt-debug-modules-extra, AlmaLinux:8: kernel-rt-devel, AlmaLinux:8: kernel-rt-modules, AlmaLinux:8: kernel-rt-modules-extra</p>
<p>The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements.</p>
<p>Security Fix(es):</p>
<p>* kernel: Linux kernel: Denial of Service in qla2xxx SCSI driver due to improper command handling after chip reset (CVE-2025-68745)
  * kernel: scsi: target: configfs: Bound snprintf() return in tg_pt_gp_members_show() (CVE-2026-46149)
  * kernel: netfilter: nf_log: validate MAC header was set before dumping it (CVE-2026-52942)
  * kernel: sctp: diag: reject stale associations in dump_one path (CVE-2026-52917)
  * kernel: net: pull headers in qdisc_pkt_len_segs_init() (CVE-2026-53091)
  * kernel: netfilter: nf_conntrack_sip: don't use simple_strtoul (CVE-2026-52986)
  * kernel: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing (CVE-2026-53246)
  * kernel: tipc: fix slab-use-after-free Read in tipc_aead_decrypt_done (CVE-2026-63801)
  * kernel: sctp: fix race between sctp_wait_for_connect and peeloff (CVE-2026-63971)
  * kernel: security/keys: fix missed RCU read section on lookup (CVE-2026-64015)
  * kernel: ixgbevf: fix use-after-free in VEPA multicast source pruning (CVE-2026-64113)
  * kernel: sctp: fix auth_hmacs array size in struct sctp_cookie (CVE-2026-68376)
  * kernel: tipc: clear sock-&gt;sk on the failed-insert path in tipc_sk_create() (CVE-2026-68117)
  * kernel: sctp: auth: verify auth requirement when auth_chunk is NULL (CVE-2026-68300)
  * kernel: sctp: validate stream count i…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:66324"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-68117</id>
    <title>BELL-CVE-2026-68117</title>
    <updated>2026-10-03T12:47:13.919492+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-68117"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1069</id>
    <title>certfr-2026-avi-1069 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de Debian LTS. Elles permettent à un attaquant de p…</title>
    <updated>2026-10-03T12:47:13.919522+00:00</updated>
    <content>certfr-2026-avi-1069</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-1069"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-356001</id>
    <title>EUVD-2026-356001</title>
    <updated>2026-10-03T12:47:13.919541+00:00</updated>
    <content>EUVD-2026-356001</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-356001"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-68117</id>
    <title>fkie_cve-2026-68117</title>
    <updated>2026-10-03T12:47:13.919554+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>tipc: clear sock-&gt;sk on the failed-insert path in tipc_sk_create()</p>
<p>When tipc_sk_create() fails to insert the new socket (tipc_sk_insert()
returns non-zero), its error path frees the sk with sk_free() but leaves
sock-&gt;sk pointing at the freed object:</p>
<p>if (tipc_sk_insert(tsk)) {
		sk_free(sk);
		pr_warn("Socket create failed; port number exhausted\n");
		return -EINVAL;
	}</p>
<p>This is harmless for plain socket(): the syscall layer clears sock-&gt;ops
before releasing, so tipc_release() is never called. It is not harmless
on the accept() path. tipc_accept() creates the pre-allocated child
socket with tipc_sk_create(net, new_sock, 0, kern); on failure it leaves
new_sock-&gt;sk dangling and new_sock-&gt;ops non-NULL, and do_accept() then
fput()s the new file, so __sock_release() -&gt; tipc_release() runs
lock_sock(new_sock-&gt;sk) on the freed sk -- a use-after-free write of the
sk_lock spinlock.</p>
<p>tipc_release() already guards this exact "failed accept() releases a
pre-allocated child" case with "if (sk == NULL) return 0;", but the
guard is bypassed because tipc_sk_create() left sock-&gt;sk non-NULL
(dangling) rather than NULL.</p>
<p>Clear sock-&gt;sk on the failed-insert path so the existing tipc_release()
NULL check fires and the use-after-free is avoided.</p>
<p>The tipc_sk_insert() failure is reached when the per-netns socket
rhashtable hits its max_size (tsk_rht_params.max_size = 1048576, ~2M
elements) -- i.e. once a netns holds ~2M TIPC s…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-68117"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-qmxc-qv48-vp67</id>
    <title>GHSA-qmxc-qv48-vp67</title>
    <updated>2026-10-03T12:47:13.919600+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>tipc: clear sock-&gt;sk on the failed-insert path in tipc_sk_create()</p>
<p>When tipc_sk_create() fails to insert the new socket (tipc_sk_insert()
returns non-zero), its error path frees the sk with sk_free() but leaves
sock-&gt;sk pointing at the freed object:</p>
<p>if (tipc_sk_insert(tsk)) {
		sk_free(sk);
		pr_warn("Socket create failed; port number exhausted\n");
		return -EINVAL;
	}</p>
<p>This is harmless for plain socket(): the syscall layer clears sock-&gt;ops
before releasing, so tipc_release() is never called. It is not harmless
on the accept() path. tipc_accept() creates the pre-allocated child
socket with tipc_sk_create(net, new_sock, 0, kern); on failure it leaves
new_sock-&gt;sk dangling and new_sock-&gt;ops non-NULL, and do_accept() then
fput()s the new file, so __sock_release() -&gt; tipc_release() runs
lock_sock(new_sock-&gt;sk) on the freed sk -- a use-after-free write of the
sk_lock spinlock.</p>
<p>tipc_release() already guards this exact "failed accept() releases a
pre-allocated child" case with "if (sk == NULL) return 0;", but the
guard is bypassed because tipc_sk_create() left sock-&gt;sk non-NULL
(dangling) rather than NULL.</p>
<p>Clear sock-&gt;sk on the failed-insert path so the existing tipc_release()
NULL check fires and the use-after-free is avoided.</p>
<p>The tipc_sk_insert() failure is reached when the per-netns socket
rhashtable hits its max_size (tsk_rht_params.max_size = 1048576, ~2M
elements) -- i.e. once a netns holds ~2M TIPC s…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-qmxc-qv48-vp67"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-68117</id>
    <title>msrc_CVE-2026-68117 — tipc: clear sock-&gt;sk on the failed-insert path in tipc_sk_create()</title>
    <updated>2026-10-03T12:47:13.919701+00:00</updated>
    <content>msrc_CVE-2026-68117</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-68117"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:21910-1</id>
    <title>openSUSE-SU-2026:21910-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-03T12:47:13.919721+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:21910-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:66324</id>
    <title>RHSA-2026:66324 — Red Hat Security Advisory: kernel-rt security, bug fix, and enhancement update</title>
    <updated>2026-10-03T12:47:13.920208+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>kernel: Linux kernel: Denial of Service in qla2xxx SCSI driver due to improper command handling after chip reset kernel: scsi: target: configfs: Bound snprintf() return in tg_pt_gp_members_show() kernel: sctp: diag: reject stale associations in dump_one path kernel: netfilter: nf_log: validate MAC header was set before dumping it kernel: netfilter: nf_conntrack_sip: don't use simple_strtoul kernel: net: pull headers in qdisc_pkt_len_segs_init() kernel: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing kernel: tipc: fix slab-use-after-free Read in tipc_aead_decrypt_done kernel: sctp: fix race between sctp_wait_for_connect and peeloff kernel: security/keys: fix missed RCU read section on lookup kernel: ixgbevf: fix use-after-free in VEPA multicast source pruning kernel: tipc: clear sock-&gt;sk on the failed-insert path in tipc_sk_create() kernel: sctp: auth: verify auth requirement when auth_chunk is NULL kernel: sctp: validate stream count in sctp_process_strreset_inreq() kernel: sctp: fix auth_hmacs array size in struct sctp_cookie</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:66324"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:66324</id>
    <title>RLSA-2026:66324 — Important: kernel-rt security, bug fix, and enhancement update</title>
    <updated>2026-10-03T12:47:13.920250+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:8: kernel-rt</p>
<p>The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements.</p>
<p>Security Fix(es):</p>
<p>* kernel: Linux kernel: Denial of Service in qla2xxx SCSI driver due to improper command handling after chip reset (CVE-2025-68745)</p>
<p>* kernel: scsi: target: configfs: Bound snprintf() return in tg_pt_gp_members_show() (CVE-2026-46149)</p>
<p>* kernel: netfilter: nf_log: validate MAC header was set before dumping it (CVE-2026-52942)</p>
<p>* kernel: sctp: diag: reject stale associations in dump_one path (CVE-2026-52917)</p>
<p>* kernel: net: pull headers in qdisc_pkt_len_segs_init() (CVE-2026-53091)</p>
<p>* kernel: netfilter: nf_conntrack_sip: don't use simple_strtoul (CVE-2026-52986)</p>
<p>* kernel: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing (CVE-2026-53246)</p>
<p>* kernel: tipc: fix slab-use-after-free Read in tipc_aead_decrypt_done (CVE-2026-63801)</p>
<p>* kernel: sctp: fix race between sctp_wait_for_connect and peeloff (CVE-2026-63971)</p>
<p>* kernel: security/keys: fix missed RCU read section on lookup (CVE-2026-64015)</p>
<p>* kernel: ixgbevf: fix use-after-free in VEPA multicast source pruning (CVE-2026-64113)</p>
<p>* kernel: sctp: fix auth_hmacs array size in struct sctp_cookie (CVE-2026-68376)</p>
<p>* kernel: tipc: clear sock-&gt;sk on the failed-insert path in tipc_sk_create() (CVE-2026-68117)</p>
<p>* kernel: sctp: auth: verify auth requirement when auth_chunk is NULL (CVE-2026-68300)</p>
<p>* kernel: sctp: validate stream count in sctp_process_strre…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:66324"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:23477-1</id>
    <title>SUSE-SU-2026:23477-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-03T12:47:13.920296+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:23477-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-68117</id>
    <title>UBUNTU-CVE-2026-68117</title>
    <updated>2026-10-03T12:47:13.920602+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe, Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:Pro:16.04:LTS: linux-oracle, Ubuntu:Pro:18.04:LTS: linux, Ubuntu:Pro:18.04:LTS: linux-aws, Ubuntu:18.04:LTS: linux-aws-5.0 and 231 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: tipc: clear sock-&gt;sk on the failed-insert path in tipc_sk_create() When tipc_sk_create() fails to insert the new socket (tipc_sk_insert() returns non-zero), its error path frees the sk with sk_free() but leaves sock-&gt;sk pointing at the freed object: 	if (tipc_sk_insert(tsk)) { 		sk_free(sk); 		pr_warn("Socket create failed; port number exhausted\n"); 		return -EINVAL; 	} This is harmless for plain socket(): the syscall layer clears sock-&gt;ops before releasing, so tipc_release() is never called. It is not harmless on the accept() path. tipc_accept() creates the pre-allocated child socket with tipc_sk_create(net, new_sock, 0, kern); on failure it leaves new_sock-&gt;sk dangling and new_sock-&gt;ops non-NULL, and do_accept() then fput()s the new file, so __sock_release() -&gt; tipc_release() runs lock_sock(new_sock-&gt;sk) on the freed sk -- a use-after-free write of the sk_lock spinlock. tipc_release() already guards this exact "failed accept() releases a pre-allocated child" case with "if (sk == NULL) return 0;", but the guard is bypassed because tipc_sk_create() left sock-&gt;sk non-NULL (dangling) rather than NULL. Clear sock-&gt;sk on the failed-insert path so the existing tipc_release() NULL check fires and the use-after-free is avoided. The tipc_sk_insert() failure is reached when the per-netns socket rhashtable hits its max_size (tsk_rht_params.max_size = 1048576, ~2M elements) -- i.e. once a netns holds ~2M TIPC sockets…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-68117"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2730</id>
    <title>WID-SEC-W-2026-2730 — Linux Kernel: Mehrere Schwachstellen</title>
    <updated>2026-10-03T12:47:13.920873+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen, darunter möglicherweise die Ausführung von beliebigem Code, die Ausweitung von Berechtigungen, die Offenlegung von Informationen, die Manipulation von Daten oder Denial-of-Service-Zustände.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2730"/>
  </entry>
</feed>
