<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T11:58:11.742178+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:70459</id>
    <title>ALSA-2026:70459 — Important: kernel security, bug fix, and enhancement update</title>
    <updated>2026-10-03T11:58:12.645668+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:9: kernel, AlmaLinux:9: kernel-64k, AlmaLinux:9: kernel-64k-core, AlmaLinux:9: kernel-64k-debug, AlmaLinux:9: kernel-64k-debug-core, AlmaLinux:9: kernel-64k-debug-devel, AlmaLinux:9: kernel-64k-debug-devel-matched, AlmaLinux:9: kernel-64k-debug-modules, AlmaLinux:9: kernel-64k-debug-modules-core, AlmaLinux:9: kernel-64k-debug-modules-extra and 64 more</p>
<p>The kernel packages contain the Linux kernel, the core of any Linux operating system.</p>
<p>Security Fix(es):</p>
<p>* kernel: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg (CVE-2025-39964)
  * kernel: iommu/vt-d: Clear Present bit before tearing down PASID entry (CVE-2026-45894)
  * kernel: crypto: ccp - Fix a crash due to incorrect cleanup usage of kfree (CVE-2026-45959)
  * kernel: dm cache policy smq: fix missing locks in invalidating cache blocks (CVE-2026-53062)
  * kernel: keys: Pin request_key_auth payload in instantiate paths (CVE-2026-63823)
  * kernel: net/mlx5: Fix MCIA register buffer overflow on 32 dword reads (CVE-2026-68293)
  * kernel: Linux kernel: libceph null pointer dereference leads to denial of service (CVE-2026-68157)
  * kernel: Linux kernel Bluetooth RFCOMM: Denial of Service via use-after-free in set_termios (CVE-2026-68188)
  * kernel: libceph: refresh auth-&gt;authorizer_buf{,_len} after authorizer update (CVE-2026-68156)
  * kernel: Linux kernel (libceph): Denial of Service due to malformed monitor maps (CVE-2026-68155)
  * kernel: Bluetooth: mgmt: hold reference for hci_conn in mgmt_pending_cmds (CVE-2026-68391)
  * kernel: net/mlx5e: macsec: fix use-after-free of metadata_dst on RX SC delete (CVE-2026-72072)
  * kernel: mm/hugetlb: fix list corruption in allocate_file_region_entries() (CVE-2026-74518)</p>
<p>Bug Fix(es) and Enhancement(s):</p>
<p>* [Intel 9.8 FEAT] ice: Driver Update [almalinux-9.8.z] (JIRA:AlmaLinux-213003)
  * AlmaLinux 9.8…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:70459"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-68155</id>
    <title>BELL-CVE-2026-68155</title>
    <updated>2026-10-03T11:58:12.645864+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-68155"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1069</id>
    <title>certfr-2026-avi-1069 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de Debian LTS. Elles permettent à un attaquant de p…</title>
    <updated>2026-10-03T11:58:12.645893+00:00</updated>
    <content>certfr-2026-avi-1069</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-1069"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-356055</id>
    <title>EUVD-2026-356055</title>
    <updated>2026-10-03T11:58:12.645913+00:00</updated>
    <content>EUVD-2026-356055</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-356055"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-68155</id>
    <title>fkie_cve-2026-68155</title>
    <updated>2026-10-03T11:58:12.645925+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>libceph: Reject monmaps advertising zero monitors</p>
<p>A message of type CEPH_MSG_MON_MAP contains a monmap that is sent from a
monitor to the client. This monmap contains information about the
existing monitors in the cluster. Currently, a monmap indicating that
there are zero monitors in the cluster is treated as valid. However, it
is impossible to have zero monitors in the cluster and still receive a
valid monmap from a monitor. Therefore, such a monmap must be corrupted
and should be treated as invalid. Furthermore, a monmap with a monitor
count of zero can subsequently crash the client when attempting to open
a session with a monitor in __open_session(). This happens because the
"BUG_ON(monc-&gt;monmap-&gt;num_mon &lt; 1)" assertion in pick_new_mon() is
triggered.</p>
<p>This patch extends a check in ceph_monmap_decode() to also reject
arriving mon_maps with num_mon == 0 rather than only with
num_mon &gt; CEPH_MAX_MON.</p>
<p>[ idryomov: drop "log output for unusual values of num_mon" part ]</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-68155"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-2v58-jx7r-h3cm</id>
    <title>GHSA-2v58-jx7r-h3cm</title>
    <updated>2026-10-03T11:58:12.645958+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>libceph: Reject monmaps advertising zero monitors</p>
<p>A message of type CEPH_MSG_MON_MAP contains a monmap that is sent from a
monitor to the client. This monmap contains information about the
existing monitors in the cluster. Currently, a monmap indicating that
there are zero monitors in the cluster is treated as valid. However, it
is impossible to have zero monitors in the cluster and still receive a
valid monmap from a monitor. Therefore, such a monmap must be corrupted
and should be treated as invalid. Furthermore, a monmap with a monitor
count of zero can subsequently crash the client when attempting to open
a session with a monitor in __open_session(). This happens because the
"BUG_ON(monc-&gt;monmap-&gt;num_mon &lt; 1)" assertion in pick_new_mon() is
triggered.</p>
<p>This patch extends a check in ceph_monmap_decode() to also reject
arriving mon_maps with num_mon == 0 rather than only with
num_mon &gt; CEPH_MAX_MON.</p>
<p>[ idryomov: drop "log output for unusual values of num_mon" part ]</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-2v58-jx7r-h3cm"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-68155</id>
    <title>msrc_CVE-2026-68155 — libceph: Reject monmaps advertising zero monitors</title>
    <updated>2026-10-03T11:58:12.645982+00:00</updated>
    <content>msrc_CVE-2026-68155</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-68155"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-3702</id>
    <title>OESA-2026-3702 — kernel security update</title>
    <updated>2026-10-03T11:58:12.646001+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:22.03-LTS-SP4: kernel</p>
<p>The Linux Kernel, the operating system core itself.

Security Fix(es):</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>net/9p: fix double req put in p9_fd_cancelled</p>
<p>Syzkaller reports a KASAN issue as below:</p>
<p>general protection fault, probably for non-canonical address 0xfbd59c0000000021: 0000 [#1] PREEMPT SMP KASAN NOPTI
KASAN: maybe wild-memory-access in range [0xdead000000000108-0xdead00000000010f]
CPU: 0 PID: 5083 Comm: syz-executor.2 Not tainted 6.1.134-syzkaller-00037-g855bd1d7d838 #0
Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.12.0-1 04/01/2014
RIP: 0010:__list_del include/linux/list.h:114 [inline]
RIP: 0010:__list_del_entry include/linux/list.h:137 [inline]
RIP: 0010:list_del include/linux/list.h:148 [inline]
RIP: 0010:p9_fd_cancelled+0xe9/0x200 net/9p/trans_fd.c:734</p>
<p>Call Trace:
 &amp;lt;TASK&amp;gt;
 p9_client_flush+0x351/0x440 net/9p/client.c:614
 p9_client_rpc+0xb6b/0xc70 net/9p/client.c:734
 p9_client_version net/9p/client.c:920 [inline]
 p9_client_create+0xb51/0x1240 net/9p/client.c:1027
 v9fs_session_init+0x1f0/0x18f0 fs/9p/v9fs.c:408
 v9fs_mount+0xba/0xcb0 fs/9p/vfs_super.c:126
 legacy_get_tree+0x108/0x220 fs/fs_context.c:632
 vfs_get_tree+0x8e/0x300 fs/super.c:1573
 do_new_mount fs/namespace.c:3056 [inline]
 path_mount+0x6a6/0x1e90 fs/namespace.c:3386
 do_mount fs/namespace.c:3399 [inline]
 __do_sys_mount fs/namespace.c:3607 [inline]
 __se_sys_mount fs/namespace.c:3584 [inline]
 __x64_sys_mount+0x283/0x300 fs/namespace.c:358…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-3702"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:21910-1</id>
    <title>openSUSE-SU-2026:21910-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-03T11:58:12.646197+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:21910-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:70498</id>
    <title>RHSA-2026:70498 — Red Hat Security Advisory: kernel security, bug fix, and enhancement update</title>
    <updated>2026-10-03T11:58:12.646687+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>kernel: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg kernel: iommu/vt-d: Clear Present bit before tearing down PASID entry kernel: crypto: ccp - Fix a crash due to incorrect cleanup usage of kfree kernel: dm cache policy smq: fix missing locks in invalidating cache blocks kernel: keys: Pin request_key_auth payload in instantiate paths kernel: nvmet-tcp: check INIT_FAILED before nvmet_req_uninit in digest error path kernel: Linux kernel (libceph): Denial of Service due to malformed monitor maps kernel: Linux kernel: libceph stack out-of-bounds write via crafted OSDMap kernel: Linux kernel Bluetooth RFCOMM: Denial of Service via use-after-free in set_termios kernel: net/mlx5: Fix MCIA register buffer overflow on 32 dword reads kernel: Bluetooth: mgmt: hold reference for hci_conn in mgmt_pending_cmds kernel: mm/hugetlb: fix list corruption in allocate_file_region_entries()</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:70498"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:70459</id>
    <title>RLSA-2026:70459 — Important: kernel security, bug fix, and enhancement update</title>
    <updated>2026-10-03T11:58:12.646727+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:9: kernel</p>
<p>The kernel packages contain the Linux kernel, the core of any Linux operating system.</p>
<p>Security Fix(es):</p>
<p>* kernel: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg (CVE-2025-39964)</p>
<p>* kernel: iommu/vt-d: Clear Present bit before tearing down PASID entry (CVE-2026-45894)</p>
<p>* kernel: crypto: ccp - Fix a crash due to incorrect cleanup usage of kfree (CVE-2026-45959)</p>
<p>* kernel: dm cache policy smq: fix missing locks in invalidating cache blocks (CVE-2026-53062)</p>
<p>* kernel: keys: Pin request_key_auth payload in instantiate paths (CVE-2026-63823)</p>
<p>* kernel: net/mlx5: Fix MCIA register buffer overflow on 32 dword reads (CVE-2026-68293)</p>
<p>* kernel: Linux kernel: libceph null pointer dereference leads to denial of service (CVE-2026-68157)</p>
<p>* kernel: Linux kernel Bluetooth RFCOMM: Denial of Service via use-after-free in set_termios (CVE-2026-68188)</p>
<p>* kernel: libceph: refresh auth-&gt;authorizer_buf{,_len} after authorizer update (CVE-2026-68156)</p>
<p>* kernel: Linux kernel (libceph): Denial of Service due to malformed monitor maps (CVE-2026-68155)</p>
<p>* kernel: Bluetooth: mgmt: hold reference for hci_conn in mgmt_pending_cmds (CVE-2026-68391)</p>
<p>* kernel: net/mlx5e: macsec: fix use-after-free of metadata_dst on RX SC delete (CVE-2026-72072)</p>
<p>* kernel: mm/hugetlb: fix list corruption in allocate_file_region_entries() (CVE-2026-74518)</p>
<p>Bug Fix(es) and Enhancement(s):</p>
<p>* [Intel 9.8 FEAT] ice: Driver Update [rhel-9.8.z] (JIRA:Rocky Linux-213003)</p>
<p>* Rocky Linux 9.8: Multiuser Kerberized DF…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:70459"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:23477-1</id>
    <title>SUSE-SU-2026:23477-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-03T11:58:12.646774+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:23477-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-68155</id>
    <title>UBUNTU-CVE-2026-68155</title>
    <updated>2026-10-03T11:58:12.647087+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: linux, Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe and 246 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: libceph: Reject monmaps advertising zero monitors A message of type CEPH_MSG_MON_MAP contains a monmap that is sent from a monitor to the client. This monmap contains information about the existing monitors in the cluster. Currently, a monmap indicating that there are zero monitors in the cluster is treated as valid. However, it is impossible to have zero monitors in the cluster and still receive a valid monmap from a monitor. Therefore, such a monmap must be corrupted and should be treated as invalid. Furthermore, a monmap with a monitor count of zero can subsequently crash the client when attempting to open a session with a monitor in __open_session(). This happens because the "BUG_ON(monc-&gt;monmap-&gt;num_mon &lt; 1)" assertion in pick_new_mon() is triggered. This patch extends a check in ceph_monmap_decode() to also reject arriving mon_maps with num_mon == 0 rather than only with num_mon &gt; CEPH_MAX_MON. [ idryomov: drop "log output for unusual values of num_mon" part ]</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-68155"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2730</id>
    <title>WID-SEC-W-2026-2730 — Linux Kernel: Mehrere Schwachstellen</title>
    <updated>2026-10-03T11:58:12.647375+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen, darunter möglicherweise die Ausführung von beliebigem Code, die Ausweitung von Berechtigungen, die Offenlegung von Informationen, die Manipulation von Daten oder Denial-of-Service-Zustände.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2730"/>
  </entry>
</feed>
