<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T18:39:44.817134+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-72028</id>
    <title>BELL-CVE-2026-72028</title>
    <updated>2026-10-03T18:39:44.825710+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-72028"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-353640</id>
    <title>EUVD-2026-353640</title>
    <updated>2026-10-03T18:39:44.825765+00:00</updated>
    <content>EUVD-2026-353640</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-353640"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-72028</id>
    <title>fkie_cve-2026-72028</title>
    <updated>2026-10-03T18:39:44.825781+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>riscv: probes: save original sp in rethook trampoline</p>
<p>Reading a word from the stack in a kretprobe crashes a risc-v kernel.</p>
<p>$ cd /sys/kernel/tracing/
$ echo 'r n_tty_write $stack0' &gt; dynamic_events
$ echo 1 &gt; events/kprobes/enable
Unable to handle kernel paging request at virtual address 0000000200000128
...
[&lt;ffffffff80016d16&gt;] regs_get_kernel_stack_nth+0x26/0x38
[&lt;ffffffff80177196&gt;] process_fetch_insn+0x3ee/0x760
[&lt;ffffffff80177836&gt;] kretprobe_trace_func+0x116/0x1f0
[&lt;ffffffff8017795a&gt;] kretprobe_dispatcher+0x4a/0x58
[&lt;ffffffff8013572e&gt;] kretprobe_rethook_handler+0x5e/0x90
[&lt;ffffffff80180838&gt;] rethook_trampoline_handler+0x70/0x108
[&lt;ffffffff8001ba32&gt;] arch_rethook_trampoline_callback+0x12/0x1c
[&lt;ffffffff8001ba84&gt;] arch_rethook_trampoline+0x48/0x94
[&lt;ffffffff8067872a&gt;] tty_write+0x1a/0x30</p>
<p>In regs_get_kernel_stack_nth, regs-&gt;sp contains an arbitrary value.</p>
<p>arch_rethook_trampoline saves the registers from the probed function in a
struct pt_regs. sp is not saved. Instead, sp is decremented for
arch_rethook_trampoline's local stack.</p>
<p>Fix this crash and save the original sp along with the other registers.
Use a0 as a temporary register, it is overwritten anyway.</p>
<p>[pjw@kernel.org: added Fixes tag; cc'ed stable]</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-72028"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-rj58-8r73-76rg</id>
    <title>GHSA-rj58-8r73-76rg</title>
    <updated>2026-10-03T18:39:44.825824+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>riscv: probes: save original sp in rethook trampoline</p>
<p>Reading a word from the stack in a kretprobe crashes a risc-v kernel.</p>
<p>$ cd /sys/kernel/tracing/
$ echo 'r n_tty_write $stack0' &gt; dynamic_events
$ echo 1 &gt; events/kprobes/enable
Unable to handle kernel paging request at virtual address 0000000200000128
...
[&lt;ffffffff80016d16&gt;] regs_get_kernel_stack_nth+0x26/0x38
[&lt;ffffffff80177196&gt;] process_fetch_insn+0x3ee/0x760
[&lt;ffffffff80177836&gt;] kretprobe_trace_func+0x116/0x1f0
[&lt;ffffffff8017795a&gt;] kretprobe_dispatcher+0x4a/0x58
[&lt;ffffffff8013572e&gt;] kretprobe_rethook_handler+0x5e/0x90
[&lt;ffffffff80180838&gt;] rethook_trampoline_handler+0x70/0x108
[&lt;ffffffff8001ba32&gt;] arch_rethook_trampoline_callback+0x12/0x1c
[&lt;ffffffff8001ba84&gt;] arch_rethook_trampoline+0x48/0x94
[&lt;ffffffff8067872a&gt;] tty_write+0x1a/0x30</p>
<p>In regs_get_kernel_stack_nth, regs-&gt;sp contains an arbitrary value.</p>
<p>arch_rethook_trampoline saves the registers from the probed function in a
struct pt_regs. sp is not saved. Instead, sp is decremented for
arch_rethook_trampoline's local stack.</p>
<p>Fix this crash and save the original sp along with the other registers.
Use a0 as a temporary register, it is overwritten anyway.</p>
<p>[pjw@kernel.org: added Fixes tag; cc'ed stable]</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-rj58-8r73-76rg"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-72028</id>
    <title>UBUNTU-CVE-2026-72028</title>
    <updated>2026-10-03T18:39:44.825853+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 193 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: riscv: probes: save original sp in rethook trampoline Reading a word from the stack in a kretprobe crashes a risc-v kernel. $ cd /sys/kernel/tracing/ $ echo 'r n_tty_write $stack0' &gt; dynamic_events $ echo 1 &gt; events/kprobes/enable Unable to handle kernel paging request at virtual address 0000000200000128 ... [&lt;ffffffff80016d16&gt;] regs_get_kernel_stack_nth+0x26/0x38 [&lt;ffffffff80177196&gt;] process_fetch_insn+0x3ee/0x760 [&lt;ffffffff80177836&gt;] kretprobe_trace_func+0x116/0x1f0 [&lt;ffffffff8017795a&gt;] kretprobe_dispatcher+0x4a/0x58 [&lt;ffffffff8013572e&gt;] kretprobe_rethook_handler+0x5e/0x90 [&lt;ffffffff80180838&gt;] rethook_trampoline_handler+0x70/0x108 [&lt;ffffffff8001ba32&gt;] arch_rethook_trampoline_callback+0x12/0x1c [&lt;ffffffff8001ba84&gt;] arch_rethook_trampoline+0x48/0x94 [&lt;ffffffff8067872a&gt;] tty_write+0x1a/0x30 In regs_get_kernel_stack_nth, regs-&gt;sp contains an arbitrary value. arch_rethook_trampoline saves the registers from the probed function in a struct pt_regs. sp is not saved. Instead, sp is decremented for arch_rethook_trampoline's local stack. Fix this crash and save the original sp along with the other registers. Use a0 as a temporary register, it is overwritten anyway. [pjw@kernel.org: added Fixes tag; cc'ed stable]</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-72028"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2852</id>
    <title>WID-SEC-W-2026-2852 — Linux Kernel: Mehrere Schwachstellen</title>
    <updated>2026-10-03T18:39:44.826125+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Linux Kernel ausnutzen, um root Rechte zu erlangen, um einen Denial of Service herbeizuführen oder einen nicht näher spezifizierten Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2852"/>
  </entry>
</feed>
