<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T12:48:23.959059+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-74714</id>
    <title>BELL-CVE-2026-74714</title>
    <updated>2026-10-03T12:48:24.057373+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-74714"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1090</id>
    <title>certfr-2026-avi-1090 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de Debian. Elles permettent à un attaquant de provo…</title>
    <updated>2026-10-03T12:48:24.057423+00:00</updated>
    <content>certfr-2026-avi-1090</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-1090"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-358569</id>
    <title>EUVD-2026-358569</title>
    <updated>2026-10-03T12:48:24.057444+00:00</updated>
    <content>EUVD-2026-358569</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-358569"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-74714</id>
    <title>fkie_cve-2026-74714</title>
    <updated>2026-10-03T12:48:24.057456+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>bpf: tcp: Fix use-after-free in bpf_iter_tcp_established_batch()</p>
<p>reqsk_queue_hash_req() publishes a TCP_NEW_SYN_RECV request_sock onto
the ehash chain, drops the bucket lock, and only afterwards sets
rsk_refcnt to 3.</p>
<p>Lockless readers such as __inet_lookup_established() handle this with
refcount_inc_not_zero(), but bpf_iter_tcp_established_batch() uses plain
sock_hold() while holding the bucket lock, on the assumption that the
lock guarantees sk_refcnt &gt; 0. That assumption does not hold for
request_sock:</p>
<p>CPU 0                                CPU 1
  -----                                -----
  tcp_conn_request()
   reqsk_queue_hash_req()
    inet_ehash_insert(req)
     spin_lock(bucket)
     __sk_nulls_add_node_rcu(req)      // rsk_refcnt == 0
     spin_unlock(bucket)
                                       bpf_iter_tcp_established_batch()
                                        spin_lock(bucket)
                                        sock_hold(req)   &lt;-- addition on 0
                                        spin_unlock(bucket)
    refcount_set(&amp;req-&gt;rsk_refcnt, 3)  // clobbers saturated value</p>
<p>which surfaces as:</p>
<p>refcount_t: addition on 0; use-after-free.
  WARNING: lib/refcount.c:25 at refcount_warn_saturate+0x48/0x90, CPU#1
  Call Trace:
   bpf_iter_tcp_established_batch+0x14e/0x170
   bpf_iter_tcp_batch+0x53/0x200
   bpf_iter_tcp_seq_next+0x27/0x70
   bpf_seq_read+0x107/0x410
   vfs_read+0xb9/0x380…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-74714"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-cqmm-fv72-p7f7</id>
    <title>GHSA-cqmm-fv72-p7f7</title>
    <updated>2026-10-03T12:48:24.057504+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>bpf: tcp: Fix use-after-free in bpf_iter_tcp_established_batch()</p>
<p>reqsk_queue_hash_req() publishes a TCP_NEW_SYN_RECV request_sock onto
the ehash chain, drops the bucket lock, and only afterwards sets
rsk_refcnt to 3.</p>
<p>Lockless readers such as __inet_lookup_established() handle this with
refcount_inc_not_zero(), but bpf_iter_tcp_established_batch() uses plain
sock_hold() while holding the bucket lock, on the assumption that the
lock guarantees sk_refcnt &gt; 0. That assumption does not hold for
request_sock:</p>
<p>CPU 0                                CPU 1
  -----                                -----
  tcp_conn_request()
   reqsk_queue_hash_req()
    inet_ehash_insert(req)
     spin_lock(bucket)
     __sk_nulls_add_node_rcu(req)      // rsk_refcnt == 0
     spin_unlock(bucket)
                                       bpf_iter_tcp_established_batch()
                                        spin_lock(bucket)
                                        sock_hold(req)   &lt;-- addition on 0
                                        spin_unlock(bucket)
    refcount_set(&amp;req-&gt;rsk_refcnt, 3)  // clobbers saturated value</p>
<p>which surfaces as:</p>
<p>refcount_t: addition on 0; use-after-free.
  WARNING: lib/refcount.c:25 at refcount_warn_saturate+0x48/0x90, CPU#1
  Call Trace:
   bpf_iter_tcp_established_batch+0x14e/0x170
   bpf_iter_tcp_batch+0x53/0x200
   bpf_iter_tcp_seq_next+0x27/0x70
   bpf_seq_read+0x107/0x410
   vfs_read+0xb9/0x380…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-cqmm-fv72-p7f7"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-74714</id>
    <title>msrc_CVE-2026-74714 — bpf: tcp: Fix use-after-free in bpf_iter_tcp_established_batch()</title>
    <updated>2026-10-03T12:48:24.057542+00:00</updated>
    <content>msrc_CVE-2026-74714</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-74714"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-74714</id>
    <title>UBUNTU-CVE-2026-74714</title>
    <updated>2026-10-03T12:48:24.057559+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 193 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: bpf: tcp: Fix use-after-free in bpf_iter_tcp_established_batch() reqsk_queue_hash_req() publishes a TCP_NEW_SYN_RECV request_sock onto the ehash chain, drops the bucket lock, and only afterwards sets rsk_refcnt to 3. Lockless readers such as __inet_lookup_established() handle this with refcount_inc_not_zero(), but bpf_iter_tcp_established_batch() uses plain sock_hold() while holding the bucket lock, on the assumption that the lock guarantees sk_refcnt &gt; 0. That assumption does not hold for request_sock:   CPU 0                                CPU 1   -----                                -----   tcp_conn_request()    reqsk_queue_hash_req()     inet_ehash_insert(req)      spin_lock(bucket)      __sk_nulls_add_node_rcu(req)      // rsk_refcnt == 0      spin_unlock(bucket)                                        bpf_iter_tcp_established_batch()                                         spin_lock(bucket)                                         sock_hold(req)   &lt;-- addition on 0                                         spin_unlock(bucket)     refcount_set(&amp;req-&gt;rsk_refcnt, 3)  // clobbers saturated value which surfaces as:   refcount_t: addition on 0; use-after-free.   WARNING: lib/refcount.c:25 at refcount_warn_saturate+0x48/0x90, CPU#1   Call Trace:    bpf_iter_tcp_established_batch+0x14e/0x170    bpf_iter_tcp_batch+0x53/0x200    bpf_iter_tcp_seq_next+0x27/0x70    bpf_seq_read+0x107/0x410    vfs_read+0xb9/0x380 The i…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-74714"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2970</id>
    <title>WID-SEC-W-2026-2970 — Linux Kernel: Mehrere Schwachstellen ermöglichen nicht spezifizierten Angriff</title>
    <updated>2026-10-03T12:48:24.057847+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen, möglicherweise Sicherheitsmaßnahmen zu umgehen, einen Denial-of-Service-Zustand herbeizuführen oder vertrauliche Informationen offenzulegen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2970"/>
  </entry>
</feed>
