<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T15:27:50.648939+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-68189</id>
    <title>BELL-CVE-2026-68189</title>
    <updated>2026-10-02T15:27:51.332361+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-68189"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1069</id>
    <title>certfr-2026-avi-1069 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de Debian LTS. Elles permettent à un attaquant de p…</title>
    <updated>2026-10-02T15:27:51.332446+00:00</updated>
    <content>certfr-2026-avi-1069</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-1069"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-356123</id>
    <title>EUVD-2026-356123</title>
    <updated>2026-10-02T15:27:51.332469+00:00</updated>
    <content>EUVD-2026-356123</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-356123"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-68189</id>
    <title>fkie_cve-2026-68189</title>
    <updated>2026-10-02T15:27:51.332482+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>Bluetooth: hci_sync: Protect UUID list traversal</p>
<p>The hci_sync conversion moved class-of-device and EIR generation from an
HCI request built under hdev-&gt;lock to asynchronous command sync work.
The worker holds hdev-&gt;req_lock, but that lock does not serialize access
to hdev-&gt;uuids against add_uuid() and remove_uuid(), which update the
list under hdev-&gt;lock.</p>
<p>The following interleaving can therefore occur:</p>
<p>CPU0 (command sync work)       CPU1 (management socket)
  fetch uuid from the list
                                list_del(&amp;uuid-&gt;list)
                                kfree(uuid)
  read uuid-&gt;size</p>
<p>KASAN reports the resulting use-after-free:</p>
<p>BUG: KASAN: slab-use-after-free in eir_create+0xb8f/0xee0
  Read of size 1 at addr ffff88810dbd8620 by task kworker/u17:0/87
  Workqueue: hci0 hci_cmd_sync_work
  Call Trace:
   eir_create+0xb8f/0xee0
   hci_update_eir_sync+0x1c0/0x330
   hci_cmd_sync_work+0x13c/0x290
   process_one_work+0x63a/0x1070
   worker_thread+0x45b/0xd10</p>
<p>Allocated by task 86:
   __kasan_kmalloc+0x8f/0xa0
   add_uuid+0x18a/0x4b0
   hci_sock_sendmsg+0x1033/0x1ea0</p>
<p>Freed by task 92:
   __kasan_slab_free+0x43/0x70
   kfree+0x131/0x3c0
   remove_uuid+0x25e/0x560
   hci_sock_sendmsg+0x1033/0x1ea0</p>
<p>Hold hdev-&gt;lock while generating and committing the class-of-device and
EIR snapshots.  Release it before sending an HCI command, so controller
waits do not happen under the device lock.  This p…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-68189"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-jprq-4ghp-p3f9</id>
    <title>GHSA-jprq-4ghp-p3f9</title>
    <updated>2026-10-02T15:27:51.332532+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>Bluetooth: hci_sync: Protect UUID list traversal</p>
<p>The hci_sync conversion moved class-of-device and EIR generation from an
HCI request built under hdev-&gt;lock to asynchronous command sync work.
The worker holds hdev-&gt;req_lock, but that lock does not serialize access
to hdev-&gt;uuids against add_uuid() and remove_uuid(), which update the
list under hdev-&gt;lock.</p>
<p>The following interleaving can therefore occur:</p>
<p>CPU0 (command sync work)       CPU1 (management socket)
  fetch uuid from the list
                                list_del(&amp;uuid-&gt;list)
                                kfree(uuid)
  read uuid-&gt;size</p>
<p>KASAN reports the resulting use-after-free:</p>
<p>BUG: KASAN: slab-use-after-free in eir_create+0xb8f/0xee0
  Read of size 1 at addr ffff88810dbd8620 by task kworker/u17:0/87
  Workqueue: hci0 hci_cmd_sync_work
  Call Trace:
   eir_create+0xb8f/0xee0
   hci_update_eir_sync+0x1c0/0x330
   hci_cmd_sync_work+0x13c/0x290
   process_one_work+0x63a/0x1070
   worker_thread+0x45b/0xd10</p>
<p>Allocated by task 86:
   __kasan_kmalloc+0x8f/0xa0
   add_uuid+0x18a/0x4b0
   hci_sock_sendmsg+0x1033/0x1ea0</p>
<p>Freed by task 92:
   __kasan_slab_free+0x43/0x70
   kfree+0x131/0x3c0
   remove_uuid+0x25e/0x560
   hci_sock_sendmsg+0x1033/0x1ea0</p>
<p>Hold hdev-&gt;lock while generating and committing the class-of-device and
EIR snapshots.  Release it before sending an HCI command, so controller
waits do not happen under the device lock.  This p…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-jprq-4ghp-p3f9"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-68189</id>
    <title>msrc_CVE-2026-68189 — Bluetooth: hci_sync: Protect UUID list traversal</title>
    <updated>2026-10-02T15:27:51.332568+00:00</updated>
    <content>msrc_CVE-2026-68189</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-68189"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:21910-1</id>
    <title>openSUSE-SU-2026:21910-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-02T15:27:51.332586+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:21910-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:23477-1</id>
    <title>SUSE-SU-2026:23477-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-02T15:27:51.333065+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:23477-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-68189</id>
    <title>UBUNTU-CVE-2026-68189</title>
    <updated>2026-10-02T15:27:51.333371+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 154 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sync: Protect UUID list traversal The hci_sync conversion moved class-of-device and EIR generation from an HCI request built under hdev-&gt;lock to asynchronous command sync work. The worker holds hdev-&gt;req_lock, but that lock does not serialize access to hdev-&gt;uuids against add_uuid() and remove_uuid(), which update the list under hdev-&gt;lock. The following interleaving can therefore occur:   CPU0 (command sync work)       CPU1 (management socket)   fetch uuid from the list                                 list_del(&amp;uuid-&gt;list)                                 kfree(uuid)   read uuid-&gt;size KASAN reports the resulting use-after-free:   BUG: KASAN: slab-use-after-free in eir_create+0xb8f/0xee0   Read of size 1 at addr ffff88810dbd8620 by task kworker/u17:0/87   Workqueue: hci0 hci_cmd_sync_work   Call Trace:    eir_create+0xb8f/0xee0    hci_update_eir_sync+0x1c0/0x330    hci_cmd_sync_work+0x13c/0x290    process_one_work+0x63a/0x1070    worker_thread+0x45b/0xd10   Allocated by task 86:    __kasan_kmalloc+0x8f/0xa0    add_uuid+0x18a/0x4b0    hci_sock_sendmsg+0x1033/0x1ea0   Freed by task 92:    __kasan_slab_free+0x43/0x70    kfree+0x131/0x3c0    remove_uuid+0x25e/0x560    hci_sock_sendmsg+0x1033/0x1ea0 Hold hdev-&gt;lock while generating and committing the class-of-device and EIR snapshots.  Release it before sending an HCI command, so controller waits do not happen under the device lock.  This protects a…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-68189"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2730</id>
    <title>WID-SEC-W-2026-2730 — Linux Kernel: Mehrere Schwachstellen</title>
    <updated>2026-10-02T15:27:51.333565+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen, darunter möglicherweise die Ausführung von beliebigem Code, die Ausweitung von Berechtigungen, die Offenlegung von Informationen, die Manipulation von Daten oder Denial-of-Service-Zustände.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2730"/>
  </entry>
</feed>
