<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T01:20:19.498437+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-74682</id>
    <title>BELL-CVE-2026-74682</title>
    <updated>2026-10-03T01:20:19.604933+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-74682"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1090</id>
    <title>certfr-2026-avi-1090 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de Debian. Elles permettent à un attaquant de provo…</title>
    <updated>2026-10-03T01:20:19.604987+00:00</updated>
    <content>certfr-2026-avi-1090</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-1090"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-357787</id>
    <title>EUVD-2026-357787</title>
    <updated>2026-10-03T01:20:19.605008+00:00</updated>
    <content>EUVD-2026-357787</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-357787"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-74682</id>
    <title>fkie_cve-2026-74682</title>
    <updated>2026-10-03T01:20:19.605021+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>ALSA: usb-audio: fix OOB write on Type II inbound URBs</p>
<p>data_ep_set_params() sizes each URB transfer buffer before it adds the
Format Type II transfer delimiter:</p>
<p>u-&gt;packets = urb_packs;
	u-&gt;buffer_size = maxsize * u-&gt;packets;</p>
<p>if (fmt-&gt;fmt_type == UAC_FORMAT_TYPE_II)
		u-&gt;packets++; /* for transfer delimiter */
	u-&gt;urb = usb_alloc_urb(u-&gt;packets, GFP_KERNEL);</p>
<p>buffer_size is computed from the pre-increment packet count and never
recomputed, so for a Type II endpoint the buffer is one packet short of
the packet count the URB is built with.</p>
<p>prepare_inbound_urb() then lays out one iso frame per packet and never
consults buffer_size:</p>
<p>offs = 0;
	for (i = 0; i &lt; urb_ctx-&gt;packets; i++) {
		urb-&gt;iso_frame_desc[i].offset = offs;
		urb-&gt;iso_frame_desc[i].length = ep-&gt;curpacksize;
		offs += ep-&gt;curpacksize;
	}</p>
<p>urb-&gt;transfer_buffer_length = offs;
	urb-&gt;number_of_packets = urb_ctx-&gt;packets;</p>
<p>The last descriptor therefore points one packet past the end of the
transfer buffer, where the host controller writes device data on every
inbound transfer.  prepare_silent_urb() and prepare_playback_urb() bound
their fill loops by ctx-&gt;buffer_size, so only capture is affected.</p>
<p>fmt_type comes from the device's audio streaming descriptors, so any
device advertising a Type II capture format hits this once userspace sets
hw_params on the stream.</p>
<p>KASAN on 7.2.0-rc5 (arm64) with a dummy_hcd/raw-gadget device, one report
per inb…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-74682"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-f9hx-h75g-5vp2</id>
    <title>GHSA-f9hx-h75g-5vp2</title>
    <updated>2026-10-03T01:20:19.605072+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>ALSA: usb-audio: fix OOB write on Type II inbound URBs</p>
<p>data_ep_set_params() sizes each URB transfer buffer before it adds the
Format Type II transfer delimiter:</p>
<p>u-&gt;packets = urb_packs;
	u-&gt;buffer_size = maxsize * u-&gt;packets;</p>
<p>if (fmt-&gt;fmt_type == UAC_FORMAT_TYPE_II)
		u-&gt;packets++; /* for transfer delimiter */
	u-&gt;urb = usb_alloc_urb(u-&gt;packets, GFP_KERNEL);</p>
<p>buffer_size is computed from the pre-increment packet count and never
recomputed, so for a Type II endpoint the buffer is one packet short of
the packet count the URB is built with.</p>
<p>prepare_inbound_urb() then lays out one iso frame per packet and never
consults buffer_size:</p>
<p>offs = 0;
	for (i = 0; i &lt; urb_ctx-&gt;packets; i++) {
		urb-&gt;iso_frame_desc[i].offset = offs;
		urb-&gt;iso_frame_desc[i].length = ep-&gt;curpacksize;
		offs += ep-&gt;curpacksize;
	}</p>
<p>urb-&gt;transfer_buffer_length = offs;
	urb-&gt;number_of_packets = urb_ctx-&gt;packets;</p>
<p>The last descriptor therefore points one packet past the end of the
transfer buffer, where the host controller writes device data on every
inbound transfer.  prepare_silent_urb() and prepare_playback_urb() bound
their fill loops by ctx-&gt;buffer_size, so only capture is affected.</p>
<p>fmt_type comes from the device's audio streaming descriptors, so any
device advertising a Type II capture format hits this once userspace sets
hw_params on the stream.</p>
<p>KASAN on 7.2.0-rc5 (arm64) with a dummy_hcd/raw-gadget device, one report
per inb…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-f9hx-h75g-5vp2"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-74682</id>
    <title>msrc_CVE-2026-74682 — ALSA: usb-audio: fix OOB write on Type II inbound URBs</title>
    <updated>2026-10-03T01:20:19.605110+00:00</updated>
    <content>msrc_CVE-2026-74682</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-74682"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-74682</id>
    <title>UBUNTU-CVE-2026-74682</title>
    <updated>2026-10-03T01:20:19.605129+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: linux, Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe and 246 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: fix OOB write on Type II inbound URBs data_ep_set_params() sizes each URB transfer buffer before it adds the Format Type II transfer delimiter: 	u-&gt;packets = urb_packs; 	u-&gt;buffer_size = maxsize * u-&gt;packets; 	if (fmt-&gt;fmt_type == UAC_FORMAT_TYPE_II) 		u-&gt;packets++; /* for transfer delimiter */ 	u-&gt;urb = usb_alloc_urb(u-&gt;packets, GFP_KERNEL); buffer_size is computed from the pre-increment packet count and never recomputed, so for a Type II endpoint the buffer is one packet short of the packet count the URB is built with. prepare_inbound_urb() then lays out one iso frame per packet and never consults buffer_size: 	offs = 0; 	for (i = 0; i &lt; urb_ctx-&gt;packets; i++) { 		urb-&gt;iso_frame_desc[i].offset = offs; 		urb-&gt;iso_frame_desc[i].length = ep-&gt;curpacksize; 		offs += ep-&gt;curpacksize; 	} 	urb-&gt;transfer_buffer_length = offs; 	urb-&gt;number_of_packets = urb_ctx-&gt;packets; The last descriptor therefore points one packet past the end of the transfer buffer, where the host controller writes device data on every inbound transfer.  prepare_silent_urb() and prepare_playback_urb() bound their fill loops by ctx-&gt;buffer_size, so only capture is affected. fmt_type comes from the device's audio streaming descriptors, so any device advertising a Type II capture format hits this once userspace sets hw_params on the stream. KASAN on 7.2.0-rc5 (arm64) with a dummy_hcd/raw-gadget device, one report per inbound transf…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-74682"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2970</id>
    <title>WID-SEC-W-2026-2970 — Linux Kernel: Mehrere Schwachstellen ermöglichen nicht spezifizierten Angriff</title>
    <updated>2026-10-03T01:20:19.605467+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen, möglicherweise Sicherheitsmaßnahmen zu umgehen, einen Denial-of-Service-Zustand herbeizuführen oder vertrauliche Informationen offenzulegen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2970"/>
  </entry>
</feed>
