<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T20:46:50.380192+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:70459</id>
    <title>ALSA-2026:70459 — Important: kernel security, bug fix, and enhancement update</title>
    <updated>2026-10-03T20:46:51.159358+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:9: kernel, AlmaLinux:9: kernel-64k, AlmaLinux:9: kernel-64k-core, AlmaLinux:9: kernel-64k-debug, AlmaLinux:9: kernel-64k-debug-core, AlmaLinux:9: kernel-64k-debug-devel, AlmaLinux:9: kernel-64k-debug-devel-matched, AlmaLinux:9: kernel-64k-debug-modules, AlmaLinux:9: kernel-64k-debug-modules-core, AlmaLinux:9: kernel-64k-debug-modules-extra and 64 more</p>
<p>The kernel packages contain the Linux kernel, the core of any Linux operating system.</p>
<p>Security Fix(es):</p>
<p>* kernel: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg (CVE-2025-39964)
  * kernel: iommu/vt-d: Clear Present bit before tearing down PASID entry (CVE-2026-45894)
  * kernel: crypto: ccp - Fix a crash due to incorrect cleanup usage of kfree (CVE-2026-45959)
  * kernel: dm cache policy smq: fix missing locks in invalidating cache blocks (CVE-2026-53062)
  * kernel: keys: Pin request_key_auth payload in instantiate paths (CVE-2026-63823)
  * kernel: net/mlx5: Fix MCIA register buffer overflow on 32 dword reads (CVE-2026-68293)
  * kernel: Linux kernel: libceph null pointer dereference leads to denial of service (CVE-2026-68157)
  * kernel: Linux kernel Bluetooth RFCOMM: Denial of Service via use-after-free in set_termios (CVE-2026-68188)
  * kernel: libceph: refresh auth-&gt;authorizer_buf{,_len} after authorizer update (CVE-2026-68156)
  * kernel: Linux kernel (libceph): Denial of Service due to malformed monitor maps (CVE-2026-68155)
  * kernel: Bluetooth: mgmt: hold reference for hci_conn in mgmt_pending_cmds (CVE-2026-68391)
  * kernel: net/mlx5e: macsec: fix use-after-free of metadata_dst on RX SC delete (CVE-2026-72072)
  * kernel: mm/hugetlb: fix list corruption in allocate_file_region_entries() (CVE-2026-74518)</p>
<p>Bug Fix(es) and Enhancement(s):</p>
<p>* [Intel 9.8 FEAT] ice: Driver Update [almalinux-9.8.z] (JIRA:AlmaLinux-213003)
  * AlmaLinux 9.8…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:70459"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-68391</id>
    <title>BELL-CVE-2026-68391</title>
    <updated>2026-10-03T20:46:51.159545+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-68391"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1069</id>
    <title>certfr-2026-avi-1069 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de Debian LTS. Elles permettent à un attaquant de p…</title>
    <updated>2026-10-03T20:46:51.159574+00:00</updated>
    <content>certfr-2026-avi-1069</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-1069"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-353587</id>
    <title>EUVD-2026-353587</title>
    <updated>2026-10-03T20:46:51.159593+00:00</updated>
    <content>EUVD-2026-353587</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-353587"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-68391</id>
    <title>fkie_cve-2026-68391</title>
    <updated>2026-10-03T20:46:51.159605+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>Bluetooth: mgmt: hold reference for hci_conn in mgmt_pending_cmds</p>
<p>Dereferencing RCU-protected pointers outside critical sections is
invalid and may lead to UAF.  Use of hci_conn in hci_sync callbacks also
needs to hold refcount to avoid UAF.</p>
<p>Take appropriate locks for hci_conn lookups, and take refcount for
hci_conn pointers stored in mgmt_pending_cmd so that the pointer stays
valid.</p>
<p>When accessing conn-&gt;state, ensure hdev-&gt;lock is held to avoid data
race.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-68391"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-r93r-qrfp-h69j</id>
    <title>GHSA-r93r-qrfp-h69j</title>
    <updated>2026-10-03T20:46:51.159633+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>Bluetooth: mgmt: hold reference for hci_conn in mgmt_pending_cmds</p>
<p>Dereferencing RCU-protected pointers outside critical sections is
invalid and may lead to UAF.  Use of hci_conn in hci_sync callbacks also
needs to hold refcount to avoid UAF.</p>
<p>Take appropriate locks for hci_conn lookups, and take refcount for
hci_conn pointers stored in mgmt_pending_cmd so that the pointer stays
valid.</p>
<p>When accessing conn-&gt;state, ensure hdev-&gt;lock is held to avoid data
race.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-r93r-qrfp-h69j"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-68391</id>
    <title>msrc_CVE-2026-68391 — Bluetooth: mgmt: hold reference for hci_conn in mgmt_pending_cmds</title>
    <updated>2026-10-03T20:46:51.159652+00:00</updated>
    <content>msrc_CVE-2026-68391</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-68391"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:21910-1</id>
    <title>openSUSE-SU-2026:21910-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-03T20:46:51.159669+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:21910-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:70498</id>
    <title>RHSA-2026:70498 — Red Hat Security Advisory: kernel security, bug fix, and enhancement update</title>
    <updated>2026-10-03T20:46:51.160177+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>kernel: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg kernel: iommu/vt-d: Clear Present bit before tearing down PASID entry kernel: crypto: ccp - Fix a crash due to incorrect cleanup usage of kfree kernel: dm cache policy smq: fix missing locks in invalidating cache blocks kernel: keys: Pin request_key_auth payload in instantiate paths kernel: nvmet-tcp: check INIT_FAILED before nvmet_req_uninit in digest error path kernel: Linux kernel (libceph): Denial of Service due to malformed monitor maps kernel: Linux kernel: libceph stack out-of-bounds write via crafted OSDMap kernel: Linux kernel Bluetooth RFCOMM: Denial of Service via use-after-free in set_termios kernel: net/mlx5: Fix MCIA register buffer overflow on 32 dword reads kernel: Bluetooth: mgmt: hold reference for hci_conn in mgmt_pending_cmds kernel: mm/hugetlb: fix list corruption in allocate_file_region_entries()</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:70498"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:70459</id>
    <title>RLSA-2026:70459 — Important: kernel security, bug fix, and enhancement update</title>
    <updated>2026-10-03T20:46:51.160215+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:9: kernel</p>
<p>The kernel packages contain the Linux kernel, the core of any Linux operating system.</p>
<p>Security Fix(es):</p>
<p>* kernel: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg (CVE-2025-39964)</p>
<p>* kernel: iommu/vt-d: Clear Present bit before tearing down PASID entry (CVE-2026-45894)</p>
<p>* kernel: crypto: ccp - Fix a crash due to incorrect cleanup usage of kfree (CVE-2026-45959)</p>
<p>* kernel: dm cache policy smq: fix missing locks in invalidating cache blocks (CVE-2026-53062)</p>
<p>* kernel: keys: Pin request_key_auth payload in instantiate paths (CVE-2026-63823)</p>
<p>* kernel: net/mlx5: Fix MCIA register buffer overflow on 32 dword reads (CVE-2026-68293)</p>
<p>* kernel: Linux kernel: libceph null pointer dereference leads to denial of service (CVE-2026-68157)</p>
<p>* kernel: Linux kernel Bluetooth RFCOMM: Denial of Service via use-after-free in set_termios (CVE-2026-68188)</p>
<p>* kernel: libceph: refresh auth-&gt;authorizer_buf{,_len} after authorizer update (CVE-2026-68156)</p>
<p>* kernel: Linux kernel (libceph): Denial of Service due to malformed monitor maps (CVE-2026-68155)</p>
<p>* kernel: Bluetooth: mgmt: hold reference for hci_conn in mgmt_pending_cmds (CVE-2026-68391)</p>
<p>* kernel: net/mlx5e: macsec: fix use-after-free of metadata_dst on RX SC delete (CVE-2026-72072)</p>
<p>* kernel: mm/hugetlb: fix list corruption in allocate_file_region_entries() (CVE-2026-74518)</p>
<p>Bug Fix(es) and Enhancement(s):</p>
<p>* [Intel 9.8 FEAT] ice: Driver Update [rhel-9.8.z] (JIRA:Rocky Linux-213003)</p>
<p>* Rocky Linux 9.8: Multiuser Kerberized DF…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:70459"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:23477-1</id>
    <title>SUSE-SU-2026:23477-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-03T20:46:51.160266+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:23477-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-68391</id>
    <title>UBUNTU-CVE-2026-68391</title>
    <updated>2026-10-03T20:46:51.160587+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 154 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: Bluetooth: mgmt: hold reference for hci_conn in mgmt_pending_cmds Dereferencing RCU-protected pointers outside critical sections is invalid and may lead to UAF.  Use of hci_conn in hci_sync callbacks also needs to hold refcount to avoid UAF. Take appropriate locks for hci_conn lookups, and take refcount for hci_conn pointers stored in mgmt_pending_cmd so that the pointer stays valid. When accessing conn-&gt;state, ensure hdev-&gt;lock is held to avoid data race.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-68391"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2730</id>
    <title>WID-SEC-W-2026-2730 — Linux Kernel: Mehrere Schwachstellen</title>
    <updated>2026-10-03T20:46:51.160776+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen, darunter möglicherweise die Ausführung von beliebigem Code, die Ausweitung von Berechtigungen, die Offenlegung von Informationen, die Manipulation von Daten oder Denial-of-Service-Zustände.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2730"/>
  </entry>
</feed>
