<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T05:18:49.848364+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:67150</id>
    <title>ALSA-2026:67150 — Important: kernel security, bug fix, and enhancement update</title>
    <updated>2026-10-03T05:18:49.999999+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:9: kernel, AlmaLinux:9: kernel-64k, AlmaLinux:9: kernel-64k-core, AlmaLinux:9: kernel-64k-debug, AlmaLinux:9: kernel-64k-debug-core, AlmaLinux:9: kernel-64k-debug-devel, AlmaLinux:9: kernel-64k-debug-devel-matched, AlmaLinux:9: kernel-64k-debug-modules, AlmaLinux:9: kernel-64k-debug-modules-core, AlmaLinux:9: kernel-64k-debug-modules-extra and 64 more</p>
<p>The kernel packages contain the Linux kernel, the core of any Linux operating system.</p>
<p>Security Fix(es):</p>
<p>* kernel: Linux kernel: Denial of Service in qla2xxx SCSI driver due to improper command handling after chip reset (CVE-2025-68745)
  * kernel: drm/xe: Open-code GGTT MMIO access protection (CVE-2026-23466)
  * kernel: drm/xe: always keep track of remap prev/next (CVE-2026-31479)
  * kernel: drm/amdgpu: Fix fence put before wait in amdgpu_amdkfd_submit_ib (CVE-2026-31566)
  * kernel: drm/i915/gt: fix refcount underflow in intel_engine_park_heartbeat (CVE-2026-31656)
  * kernel: rtnetlink: add missing netlink_ns_capable() check for peer netns (CVE-2026-31692)
  * kernel: Bluetooth: SMP: force responder MITM requirements before building the pairing response (CVE-2026-43334)
  * kernel: drm/i915: Fix potential overflow of shmem scatterlist length (CVE-2026-43368)
  * kernel: drm/amdgpu: Fix use-after-free race in VM acquire (CVE-2026-43370)
  * kernel: Bluetooth: serialize accept_q access (CVE-2026-52918)
  * kernel: sctp: diag: reject stale associations in dump_one path (CVE-2026-52917)
  * kernel: net: pull headers in qdisc_pkt_len_segs_init() (CVE-2026-53091)
  * kernel: iommu/amd: Fix clone_alias() to use the original device's devid (CVE-2026-53053)
  * kernel: Bluetooth: fix locking in hci_conn_request_evt() with HCI_PROTO_DEFER (CVE-2026-53072)
  * kernel: net: qrtr: fix refcount saturation and potential UAF in qrtr_port_remove (CVE-2026-52947)
  * kernel: Bluet…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:67150"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-68264</id>
    <title>BELL-CVE-2026-68264</title>
    <updated>2026-10-03T05:18:50.000163+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-68264"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1090</id>
    <title>certfr-2026-avi-1090 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de Debian. Elles permettent à un attaquant de provo…</title>
    <updated>2026-10-03T05:18:50.000191+00:00</updated>
    <content>certfr-2026-avi-1090</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-1090"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-353525</id>
    <title>EUVD-2026-353525</title>
    <updated>2026-10-03T05:18:50.000209+00:00</updated>
    <content>EUVD-2026-353525</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-353525"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-68264</id>
    <title>fkie_cve-2026-68264</title>
    <updated>2026-10-03T05:18:50.000220+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>drm/xe/pt: Reset current_op in xe_pt_update_ops_init()</p>
<p>xe_pt_update_ops_init() fails to reset current_op to 0. On the
vm_bind path, ops_execute() calls xe_pt_update_ops_prepare() inside
the xe_validation_guard() / drm_exec_until_all_locked() loop. When
that loop retries due to lock contention or OOM eviction
(drm_exec_retry_on_contention() / xe_validation_retry_on_oom()),
xe_pt_update_ops_prepare() runs again on the same vops, and each
call to bind_op_prepare() increments current_op without resetting it.</p>
<p>After N retries current_op exceeds the array size allocated by
xe_vma_ops_alloc(), causing an out-of-bounds write into
SLUB-poisoned memory and a subsequent UAF crash in
xe_migrate_update_pgtables_cpu() when reading the corrupted pt_op-&gt;bind.</p>
<p>Also reset needs_svm_lock and needs_invalidation which are derived in
the same prepare pass and would otherwise cause wrong migrate ops
selection and redundant TLB invalidation on retry.</p>
<p>Fix this by resetting current_op, needs_svm_lock and needs_invalidation
in xe_pt_update_ops_init().</p>
<p>v2 (Matt):
   - Add details in commit message.
   - Add Fixes tag and Cc to stable@vger.kernel.org</p>
<p>(cherry picked from commit 046045543e530605c441063535e7dca0075369a6)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-68264"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-3g93-j9xq-65rg</id>
    <title>GHSA-3g93-j9xq-65rg</title>
    <updated>2026-10-03T05:18:50.000255+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>drm/xe/pt: Reset current_op in xe_pt_update_ops_init()</p>
<p>xe_pt_update_ops_init() fails to reset current_op to 0. On the
vm_bind path, ops_execute() calls xe_pt_update_ops_prepare() inside
the xe_validation_guard() / drm_exec_until_all_locked() loop. When
that loop retries due to lock contention or OOM eviction
(drm_exec_retry_on_contention() / xe_validation_retry_on_oom()),
xe_pt_update_ops_prepare() runs again on the same vops, and each
call to bind_op_prepare() increments current_op without resetting it.</p>
<p>After N retries current_op exceeds the array size allocated by
xe_vma_ops_alloc(), causing an out-of-bounds write into
SLUB-poisoned memory and a subsequent UAF crash in
xe_migrate_update_pgtables_cpu() when reading the corrupted pt_op-&gt;bind.</p>
<p>Also reset needs_svm_lock and needs_invalidation which are derived in
the same prepare pass and would otherwise cause wrong migrate ops
selection and redundant TLB invalidation on retry.</p>
<p>Fix this by resetting current_op, needs_svm_lock and needs_invalidation
in xe_pt_update_ops_init().</p>
<p>v2 (Matt):
   - Add details in commit message.
   - Add Fixes tag and Cc to stable@vger.kernel.org</p>
<p>(cherry picked from commit 046045543e530605c441063535e7dca0075369a6)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-3g93-j9xq-65rg"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:67150</id>
    <title>RHSA-2026:67150 — Red Hat Security Advisory: kernel security, bug fix, and enhancement update</title>
    <updated>2026-10-03T05:18:50.000281+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>kernel: Linux kernel: Denial of Service in qla2xxx SCSI driver due to improper command handling after chip reset kernel: drm/xe: Open-code GGTT MMIO access protection kernel: drm/xe: always keep track of remap prev/next kernel: drm/amdgpu: Fix fence put before wait in amdgpu_amdkfd_submit_ib kernel: drm/i915/gt: fix refcount underflow in intel_engine_park_heartbeat kernel: rtnetlink: add missing netlink_ns_capable() check for peer netns kernel: Bluetooth: SMP: force responder MITM requirements before building the pairing response kernel: drm/i915: Fix potential overflow of shmem scatterlist length kernel: drm/amdgpu: Fix use-after-free race in VM acquire kernel: sctp: diag: reject stale associations in dump_one path kernel: Bluetooth: serialize accept_q access kernel: net: qrtr: fix refcount saturation and potential UAF in qrtr_port_remove kernel: iommu/amd: Fix clone_alias() to use the original device's devid kernel: Bluetooth: fix locking in hci_conn_request_evt() with HCI_PROTO_DEFER kernel: net: pull headers in qdisc_pkt_len_segs_init() kernel: wifi: nl80211: reject oversized EMA RNR lists kernel: Bluetooth: hci_sync: reject oversized Broadcast Announcement prepend kernel: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing kernel: Bluetooth: RFCOMM: validate skb length in MCC handlers kernel: Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind() kernel: tipc: fix slab-use-after-free Read in tipc_aead_decrypt_done kernel: scsi: scsi_transport…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:67150"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:67150</id>
    <title>RLSA-2026:67150 — Important: kernel security, bug fix, and enhancement update</title>
    <updated>2026-10-03T05:18:50.000363+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:9: kernel</p>
<p>The kernel packages contain the Linux kernel, the core of any Linux operating system.</p>
<p>Security Fix(es):</p>
<p>* kernel: Linux kernel: Denial of Service in qla2xxx SCSI driver due to improper command handling after chip reset (CVE-2025-68745)</p>
<p>* kernel: drm/xe: Open-code GGTT MMIO access protection (CVE-2026-23466)</p>
<p>* kernel: drm/xe: always keep track of remap prev/next (CVE-2026-31479)</p>
<p>* kernel: drm/amdgpu: Fix fence put before wait in amdgpu_amdkfd_submit_ib (CVE-2026-31566)</p>
<p>* kernel: drm/i915/gt: fix refcount underflow in intel_engine_park_heartbeat (CVE-2026-31656)</p>
<p>* kernel: rtnetlink: add missing netlink_ns_capable() check for peer netns (CVE-2026-31692)</p>
<p>* kernel: Bluetooth: SMP: force responder MITM requirements before building the pairing response (CVE-2026-43334)</p>
<p>* kernel: drm/i915: Fix potential overflow of shmem scatterlist length (CVE-2026-43368)</p>
<p>* kernel: drm/amdgpu: Fix use-after-free race in VM acquire (CVE-2026-43370)</p>
<p>* kernel: Bluetooth: serialize accept_q access (CVE-2026-52918)</p>
<p>* kernel: sctp: diag: reject stale associations in dump_one path (CVE-2026-52917)</p>
<p>* kernel: net: pull headers in qdisc_pkt_len_segs_init() (CVE-2026-53091)</p>
<p>* kernel: iommu/amd: Fix clone_alias() to use the original device's devid (CVE-2026-53053)</p>
<p>* kernel: Bluetooth: fix locking in hci_conn_request_evt() with HCI_PROTO_DEFER (CVE-2026-53072)</p>
<p>* kernel: net: qrtr: fix refcount saturation and potential UAF in qrtr_port_remove (CVE-2026-52947)</p>
<p>* kernel: Bluetooth: RFCOMM: hold li…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:67150"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-68264</id>
    <title>UBUNTU-CVE-2026-68264</title>
    <updated>2026-10-03T05:18:50.000417+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 120 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: drm/xe/pt: Reset current_op in xe_pt_update_ops_init() xe_pt_update_ops_init() fails to reset current_op to 0. On the vm_bind path, ops_execute() calls xe_pt_update_ops_prepare() inside the xe_validation_guard() / drm_exec_until_all_locked() loop. When that loop retries due to lock contention or OOM eviction (drm_exec_retry_on_contention() / xe_validation_retry_on_oom()), xe_pt_update_ops_prepare() runs again on the same vops, and each call to bind_op_prepare() increments current_op without resetting it. After N retries current_op exceeds the array size allocated by xe_vma_ops_alloc(), causing an out-of-bounds write into SLUB-poisoned memory and a subsequent UAF crash in xe_migrate_update_pgtables_cpu() when reading the corrupted pt_op-&gt;bind. Also reset needs_svm_lock and needs_invalidation which are derived in the same prepare pass and would otherwise cause wrong migrate ops selection and redundant TLB invalidation on retry. Fix this by resetting current_op, needs_svm_lock and needs_invalidation in xe_pt_update_ops_init(). v2 (Matt):    - Add details in commit message.    - Add Fixes tag and Cc to stable@vger.kernel.org (cherry picked from commit 046045543e530605c441063535e7dca0075369a6)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-68264"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2730</id>
    <title>WID-SEC-W-2026-2730 — Linux Kernel: Mehrere Schwachstellen</title>
    <updated>2026-10-03T05:18:50.000595+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen, darunter möglicherweise die Ausführung von beliebigem Code, die Ausweitung von Berechtigungen, die Offenlegung von Informationen, die Manipulation von Daten oder Denial-of-Service-Zustände.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2730"/>
  </entry>
</feed>
