<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T08:51:05.871564+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-68132</id>
    <title>BELL-CVE-2026-68132</title>
    <updated>2026-10-04T08:51:06.703539+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-68132"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1090</id>
    <title>certfr-2026-avi-1090 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de Debian. Elles permettent à un attaquant de provo…</title>
    <updated>2026-10-04T08:51:06.703617+00:00</updated>
    <content>certfr-2026-avi-1090</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-1090"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-357836</id>
    <title>EUVD-2026-357836</title>
    <updated>2026-10-04T08:51:06.703640+00:00</updated>
    <content>EUVD-2026-357836</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-357836"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-68132</id>
    <title>fkie_cve-2026-68132</title>
    <updated>2026-10-04T08:51:06.703654+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>super: fix emergency thaw deadlock on frozen block devices</p>
<p>do_thaw_all_callback() calls bdev_thaw() while holding sb-&gt;s_umount
exclusively. If the block device was frozen via bdev_freeze() dropping
the last block layer freeze reference calls fs_bdev_thaw() which
reacquires s_umount:</p>
<p>do_thaw_all_callback(sb)
    super_lock_excl(sb)                     # holds sb-&gt;s_umount
    bdev_thaw(sb-&gt;s_bdev)
      mutex_lock(&amp;bdev-&gt;bd_fsfreeze_mutex)
      # bd_fsfreeze_count drops 1 -&gt; 0
      bd_holder_ops-&gt;thaw == fs_bdev_thaw
        get_bdev_super(bdev)
          bdev_super_lock(bdev, true)
            super_lock(sb, true)
              down_write(&amp;sb-&gt;s_umount)     # same task: deadlock</p>
<p>The emergency thaw worker deadlocks against itself holding both
s_umount and bd_fsfreeze_mutex. That fscks any subsequent unmount,
freeze, or thaw of that filesystem and block device.</p>
<p>[   81.878470] sysrq: Show Blocked State
  [   81.880140] task:kworker/0:1     state:D stack:0     pid:11    tgid:11    ppid:2      task_flags:0x4208060 flags:0x00080000
  [   81.884876] Workqueue: events do_thaw_all
  [   81.886656] Call Trace:
  [   81.887759]  &lt;TASK&gt;
  [   81.888763]  __schedule+0x579/0x1420
  [   81.890372]  schedule+0x3a/0x100
  [   81.891794]  schedule_preempt_disabled+0x15/0x30
  [   81.893848]  rwsem_down_write_slowpath+0x1ea/0x900
  [   81.895191]  ? __pfx_do_thaw_all_callback+0x10/0x10
  [   81.896528]  down_write+0…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-68132"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-6xrq-v3x4-xfc7</id>
    <title>GHSA-6xrq-v3x4-xfc7</title>
    <updated>2026-10-04T08:51:06.703708+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>super: fix emergency thaw deadlock on frozen block devices</p>
<p>do_thaw_all_callback() calls bdev_thaw() while holding sb-&gt;s_umount
exclusively. If the block device was frozen via bdev_freeze() dropping
the last block layer freeze reference calls fs_bdev_thaw() which
reacquires s_umount:</p>
<p>do_thaw_all_callback(sb)
    super_lock_excl(sb)                     # holds sb-&gt;s_umount
    bdev_thaw(sb-&gt;s_bdev)
      mutex_lock(&amp;bdev-&gt;bd_fsfreeze_mutex)
      # bd_fsfreeze_count drops 1 -&gt; 0
      bd_holder_ops-&gt;thaw == fs_bdev_thaw
        get_bdev_super(bdev)
          bdev_super_lock(bdev, true)
            super_lock(sb, true)
              down_write(&amp;sb-&gt;s_umount)     # same task: deadlock</p>
<p>The emergency thaw worker deadlocks against itself holding both
s_umount and bd_fsfreeze_mutex. That fscks any subsequent unmount,
freeze, or thaw of that filesystem and block device.</p>
<p>[   81.878470] sysrq: Show Blocked State
  [   81.880140] task:kworker/0:1     state:D stack:0     pid:11    tgid:11    ppid:2      task_flags:0x4208060 flags:0x00080000
  [   81.884876] Workqueue: events do_thaw_all
  [   81.886656] Call Trace:
  [   81.887759]  &lt;TASK&gt;
  [   81.888763]  __schedule+0x579/0x1420
  [   81.890372]  schedule+0x3a/0x100
  [   81.891794]  schedule_preempt_disabled+0x15/0x30
  [   81.893848]  rwsem_down_write_slowpath+0x1ea/0x900
  [   81.895191]  ? __pfx_do_thaw_all_callback+0x10/0x10
  [   81.896528]  down_write+0…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-6xrq-v3x4-xfc7"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-68132</id>
    <title>msrc_CVE-2026-68132 — super: fix emergency thaw deadlock on frozen block devices</title>
    <updated>2026-10-04T08:51:06.703749+00:00</updated>
    <content>msrc_CVE-2026-68132</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-68132"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:21910-1</id>
    <title>openSUSE-SU-2026:21910-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-04T08:51:06.703768+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:21910-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:23477-1</id>
    <title>SUSE-SU-2026:23477-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-04T08:51:06.704436+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:23477-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-68132</id>
    <title>UBUNTU-CVE-2026-68132</title>
    <updated>2026-10-04T08:51:06.704747+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:Pro:18.04:LTS: linux-aws-5.4, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:Pro:18.04:LTS: linux-azure-5.4, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3 and 219 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: super: fix emergency thaw deadlock on frozen block devices do_thaw_all_callback() calls bdev_thaw() while holding sb-&gt;s_umount exclusively. If the block device was frozen via bdev_freeze() dropping the last block layer freeze reference calls fs_bdev_thaw() which reacquires s_umount:   do_thaw_all_callback(sb)     super_lock_excl(sb)                     # holds sb-&gt;s_umount     bdev_thaw(sb-&gt;s_bdev)       mutex_lock(&amp;bdev-&gt;bd_fsfreeze_mutex)       # bd_fsfreeze_count drops 1 -&gt; 0       bd_holder_ops-&gt;thaw == fs_bdev_thaw         get_bdev_super(bdev)           bdev_super_lock(bdev, true)             super_lock(sb, true)               down_write(&amp;sb-&gt;s_umount)     # same task: deadlock The emergency thaw worker deadlocks against itself holding both s_umount and bd_fsfreeze_mutex. That fscks any subsequent unmount, freeze, or thaw of that filesystem and block device.   [   81.878470] sysrq: Show Blocked State   [   81.880140] task:kworker/0:1     state:D stack:0     pid:11    tgid:11    ppid:2      task_flags:0x4208060 flags:0x00080000   [   81.884876] Workqueue: events do_thaw_all   [   81.886656] Call Trace:   [   81.887759]  &lt;TASK&gt;   [   81.888763]  __schedule+0x579/0x1420   [   81.890372]  schedule+0x3a/0x100   [   81.891794]  schedule_preempt_disabled+0x15/0x30   [   81.893848]  rwsem_down_write_slowpath+0x1ea/0x900   [   81.895191]  ? __pfx_do_thaw_all_callback+0x10/0x10   [   81.896528]  down_write+0xbd/0…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-68132"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2730</id>
    <title>WID-SEC-W-2026-2730 — Linux Kernel: Mehrere Schwachstellen</title>
    <updated>2026-10-04T08:51:06.705023+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen, darunter möglicherweise die Ausführung von beliebigem Code, die Ausweitung von Berechtigungen, die Offenlegung von Informationen, die Manipulation von Daten oder Denial-of-Service-Zustände.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2730"/>
  </entry>
</feed>
