<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T21:18:40.393391+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-72342</id>
    <title>BELL-CVE-2026-72342</title>
    <updated>2026-10-03T21:18:41.088582+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-72342"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1164</id>
    <title>certfr-2026-avi-1164 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de SUSE. Certaines d'entre elles permettent à un at…</title>
    <updated>2026-10-03T21:18:41.088657+00:00</updated>
    <content>certfr-2026-avi-1164</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-1164"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-354033</id>
    <title>EUVD-2026-354033</title>
    <updated>2026-10-03T21:18:41.088679+00:00</updated>
    <content>EUVD-2026-354033</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-354033"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-72342</id>
    <title>fkie_cve-2026-72342</title>
    <updated>2026-10-03T21:18:41.088691+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>net/mlx5e: Fix HV VHCA stats agent registration race</p>
<p>mlx5e_hv_vhca_stats_create() registers the stats agent through
mlx5_hv_vhca_agent_create(). The helper publishes the agent in
hv_vhca-&gt;agents[type] under agents_lock and immediately schedules an
asynchronous control invalidation on the HV VHCA workqueue before
returning to mlx5e.</p>
<p>The asynchronous invalidation invokes the control agent's invalidate
callback, which reads the hypervisor control block and forwards the
command to mlx5e_hv_vhca_stats_control(). That callback may either:</p>
<p>- call cancel_delayed_work_sync(&amp;priv-&gt;stats_agent.work), or
  - call queue_delayed_work(priv-&gt;wq, &amp;sagent-&gt;work, sagent-&gt;delay).</p>
<p>However, the delayed_work and priv-&gt;stats_agent.agent are only
initialized after mlx5_hv_vhca_agent_create() returns to mlx5e:</p>
<p>agent = mlx5_hv_vhca_agent_create(...);   /* publish + invalidate */
    ...
    priv-&gt;stats_agent.agent = agent;          /* too late */
    INIT_DELAYED_WORK(&amp;priv-&gt;stats_agent.work, ...); /* too late */</p>
<p>If the asynchronous control path runs before the two assignments
above, it can:</p>
<p>- Operate on an uninitialized delayed_work whose timer.function is
    NULL. queue_delayed_work() calls add_timer() unconditionally, so
    when the timer expires the timer softirq invokes a NULL function
    pointer.
  - Re-initialize the timer later through INIT_DELAYED_WORK() while
    the timer is already enqueued in the timer…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-72342"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-q42x-cp58-jpg7</id>
    <title>GHSA-q42x-cp58-jpg7</title>
    <updated>2026-10-03T21:18:41.088743+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>net/mlx5e: Fix HV VHCA stats agent registration race</p>
<p>mlx5e_hv_vhca_stats_create() registers the stats agent through
mlx5_hv_vhca_agent_create(). The helper publishes the agent in
hv_vhca-&gt;agents[type] under agents_lock and immediately schedules an
asynchronous control invalidation on the HV VHCA workqueue before
returning to mlx5e.</p>
<p>The asynchronous invalidation invokes the control agent's invalidate
callback, which reads the hypervisor control block and forwards the
command to mlx5e_hv_vhca_stats_control(). That callback may either:</p>
<p>- call cancel_delayed_work_sync(&amp;priv-&gt;stats_agent.work), or
  - call queue_delayed_work(priv-&gt;wq, &amp;sagent-&gt;work, sagent-&gt;delay).</p>
<p>However, the delayed_work and priv-&gt;stats_agent.agent are only
initialized after mlx5_hv_vhca_agent_create() returns to mlx5e:</p>
<p>agent = mlx5_hv_vhca_agent_create(...);   /* publish + invalidate */
    ...
    priv-&gt;stats_agent.agent = agent;          /* too late */
    INIT_DELAYED_WORK(&amp;priv-&gt;stats_agent.work, ...); /* too late */</p>
<p>If the asynchronous control path runs before the two assignments
above, it can:</p>
<p>- Operate on an uninitialized delayed_work whose timer.function is
    NULL. queue_delayed_work() calls add_timer() unconditionally, so
    when the timer expires the timer softirq invokes a NULL function
    pointer.
  - Re-initialize the timer later through INIT_DELAYED_WORK() while
    the timer is already enqueued in the timer…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-q42x-cp58-jpg7"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-3703</id>
    <title>OESA-2026-3703 — kernel security update</title>
    <updated>2026-10-03T21:18:41.088781+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS-SP1: kernel</p>
<p>The Linux Kernel, the operating system core itself.

Security Fix(es):</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>ASoC: qcom: Fix sc7280 lpass potential buffer overflow</p>
<p>Case values introduced in commit
5f78e1fb7a3e (&amp;quot;ASoC: qcom: Add driver support for audioreach solution&amp;quot;)
cause out of bounds access in arrays of sc7280 driver data (e.g. in case
of RX_CODEC_DMA_RX_0 in sc7280_snd_hw_params()).</p>
<p>Redefine LPASS_MAX_PORTS to consider the maximum possible port id for
q6dsp as sc7280 driver utilizes some of those values.</p>
<p>Found by Linux Verification Center (linuxtesting.org) with SVACE.(CVE-2025-37979)</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>net: usb: asix_devices: Fix PHY address mask in MDIO bus initialization</p>
<p>Syzbot reported shift-out-of-bounds exception on MDIO bus initialization.</p>
<p>The PHY address should be masked to 5 bits (0-31). Without this
mask, invalid PHY addresses could be used, potentially causing issues
with MDIO bus operations.</p>
<p>Fix this by masking the PHY address with 0x1f (31 decimal) to ensure
it stays within the valid range.(CVE-2025-38736)</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>crypto: af_alg - Fix page reassignment overflow in af_alg_pull_tsgl</p>
<p>When page reassignment was added to af_alg_pull_tsgl the original
loop wasn&amp;apos;t updated so it may try to reassign one more page than
necessary.</p>
<p>Add the check to the reassignment so that this does not happen.</p>
<p>Also u…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-3703"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:21910-1</id>
    <title>openSUSE-SU-2026:21910-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-03T21:18:41.088989+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:21910-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:23477-1</id>
    <title>SUSE-SU-2026:23477-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-03T21:18:41.089473+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:23477-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-72342</id>
    <title>UBUNTU-CVE-2026-72342</title>
    <updated>2026-10-03T21:18:41.089771+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:Pro:18.04:LTS: linux-aws-5.4, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:Pro:18.04:LTS: linux-azure-5.4, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3 and 219 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: Fix HV VHCA stats agent registration race mlx5e_hv_vhca_stats_create() registers the stats agent through mlx5_hv_vhca_agent_create(). The helper publishes the agent in hv_vhca-&gt;agents[type] under agents_lock and immediately schedules an asynchronous control invalidation on the HV VHCA workqueue before returning to mlx5e. The asynchronous invalidation invokes the control agent's invalidate callback, which reads the hypervisor control block and forwards the command to mlx5e_hv_vhca_stats_control(). That callback may either:   - call cancel_delayed_work_sync(&amp;priv-&gt;stats_agent.work), or   - call queue_delayed_work(priv-&gt;wq, &amp;sagent-&gt;work, sagent-&gt;delay). However, the delayed_work and priv-&gt;stats_agent.agent are only initialized after mlx5_hv_vhca_agent_create() returns to mlx5e:     agent = mlx5_hv_vhca_agent_create(...);   /* publish + invalidate */     ...     priv-&gt;stats_agent.agent = agent;          /* too late */     INIT_DELAYED_WORK(&amp;priv-&gt;stats_agent.work, ...); /* too late */ If the asynchronous control path runs before the two assignments above, it can:   - Operate on an uninitialized delayed_work whose timer.function is     NULL. queue_delayed_work() calls add_timer() unconditionally, so     when the timer expires the timer softirq invokes a NULL function     pointer.   - Re-initialize the timer later through INIT_DELAYED_WORK() while     the timer is already enqueued in the timer wheel, c…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-72342"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2852</id>
    <title>WID-SEC-W-2026-2852 — Linux Kernel: Mehrere Schwachstellen</title>
    <updated>2026-10-03T21:18:41.090033+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Linux Kernel ausnutzen, um root Rechte zu erlangen, um einen Denial of Service herbeizuführen oder einen nicht näher spezifizierten Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2852"/>
  </entry>
</feed>
