<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T22:39:26.302096+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-80561</id>
    <title>BELL-CVE-2026-80561</title>
    <updated>2026-10-02T22:39:27.213829+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-80561"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1163</id>
    <title>certfr-2026-avi-1163 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de Debian LTS. Certaines d'entre elles permettent à…</title>
    <updated>2026-10-02T22:39:27.213960+00:00</updated>
    <content>certfr-2026-avi-1163</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-1163"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-359799</id>
    <title>EUVD-2026-359799</title>
    <updated>2026-10-02T22:39:27.213999+00:00</updated>
    <content>EUVD-2026-359799</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-359799"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-80561</id>
    <title>fkie_cve-2026-80561</title>
    <updated>2026-10-02T22:39:27.214039+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>libceph: fix multiple unsafe decodes in decode_locker()</p>
<p>decode_locker() in cls_lock_client.c contains three unsafe decode
operations that allow a malicious or compromised OSD to trigger
slab-out-of-bounds reads:</p>
<p>1. ceph_decode_copy() at the locker_id_t name field has no preceding
   bounds check. With p == end after ceph_start_decoding() accepts
   struct_len=0, this reads sizeof(ceph_entity_name) = 9 bytes past
   the validated buffer boundary.</p>
<p>2. *p += sizeof(struct ceph_timespec) after the locker_info_t header
   is an unchecked pointer advance. A malicious OSD can position p
   past end, causing all subsequent _safe checks to pass against a
   bogus boundary.</p>
<p>3. len = ceph_decode_32(p) has no preceding bounds check, and the
   immediately following *p += len is uncapped. A malicious OSD can
   send len=0xffffffff, advancing p gigabytes past end and escaping
   the decode window entirely.</p>
<p>Fix all three by replacing bare operations with their safe variants:
  ceph_decode_copy   -&gt; ceph_decode_copy_safe
  *p += sizeof(...)  -&gt; ceph_decode_skip_n
  ceph_decode_32(p)  -&gt; ceph_decode_32_safe
  *p += len          -&gt; ceph_decode_skip_n</p>
<p>A new label is added to return -EINVAL on any bounds violation.
-EINVAL is appropriate here: the data received from the OSD
is structurally malformed, which is an invalid argument to the decode
contract regardless of whether the caller or the wire is at fault.</p>
<p>Attacker mod…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-80561"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-g3cj-79m7-wg3j</id>
    <title>GHSA-g3cj-79m7-wg3j</title>
    <updated>2026-10-02T22:39:27.214128+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>libceph: fix multiple unsafe decodes in decode_locker()</p>
<p>decode_locker() in cls_lock_client.c contains three unsafe decode
operations that allow a malicious or compromised OSD to trigger
slab-out-of-bounds reads:</p>
<p>1. ceph_decode_copy() at the locker_id_t name field has no preceding
   bounds check. With p == end after ceph_start_decoding() accepts
   struct_len=0, this reads sizeof(ceph_entity_name) = 9 bytes past
   the validated buffer boundary.</p>
<p>2. *p += sizeof(struct ceph_timespec) after the locker_info_t header
   is an unchecked pointer advance. A malicious OSD can position p
   past end, causing all subsequent _safe checks to pass against a
   bogus boundary.</p>
<p>3. len = ceph_decode_32(p) has no preceding bounds check, and the
   immediately following *p += len is uncapped. A malicious OSD can
   send len=0xffffffff, advancing p gigabytes past end and escaping
   the decode window entirely.</p>
<p>Fix all three by replacing bare operations with their safe variants:
  ceph_decode_copy   -&gt; ceph_decode_copy_safe
  *p += sizeof(...)  -&gt; ceph_decode_skip_n
  ceph_decode_32(p)  -&gt; ceph_decode_32_safe
  *p += len          -&gt; ceph_decode_skip_n</p>
<p>A new label is added to return -EINVAL on any bounds violation.
-EINVAL is appropriate here: the data received from the OSD
is structurally malformed, which is an invalid argument to the decode
contract regardless of whether the caller or the wire is at fault.</p>
<p>Attacker mod…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-g3cj-79m7-wg3j"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-80561</id>
    <title>msrc_CVE-2026-80561 — libceph: fix multiple unsafe decodes in decode_locker()</title>
    <updated>2026-10-02T22:39:27.214190+00:00</updated>
    <content>msrc_CVE-2026-80561</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-80561"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:21910-1</id>
    <title>openSUSE-SU-2026:21910-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-02T22:39:27.214220+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:21910-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:23881-1</id>
    <title>SUSE-SU-2026:23881-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-02T22:39:27.214841+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:23881-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-80561</id>
    <title>UBUNTU-CVE-2026-80561</title>
    <updated>2026-10-02T22:39:27.215532+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe, Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:Pro:16.04:LTS: linux-oracle, Ubuntu:Pro:18.04:LTS: linux, Ubuntu:Pro:18.04:LTS: linux-aws, Ubuntu:18.04:LTS: linux-aws-5.0 and 239 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: libceph: fix multiple unsafe decodes in decode_locker() decode_locker() in cls_lock_client.c contains three unsafe decode operations that allow a malicious or compromised OSD to trigger slab-out-of-bounds reads: 1. ceph_decode_copy() at the locker_id_t name field has no preceding    bounds check. With p == end after ceph_start_decoding() accepts    struct_len=0, this reads sizeof(ceph_entity_name) = 9 bytes past    the validated buffer boundary. 2. *p += sizeof(struct ceph_timespec) after the locker_info_t header    is an unchecked pointer advance. A malicious OSD can position p    past end, causing all subsequent _safe checks to pass against a    bogus boundary. 3. len = ceph_decode_32(p) has no preceding bounds check, and the    immediately following *p += len is uncapped. A malicious OSD can    send len=0xffffffff, advancing p gigabytes past end and escaping    the decode window entirely. Fix all three by replacing bare operations with their safe variants:   ceph_decode_copy   -&gt; ceph_decode_copy_safe   *p += sizeof(...)  -&gt; ceph_decode_skip_n   ceph_decode_32(p)  -&gt; ceph_decode_32_safe   *p += len          -&gt; ceph_decode_skip_n A new label is added to return -EINVAL on any bounds violation. -EINVAL is appropriate here: the data received from the OSD is structurally malformed, which is an invalid argument to the decode contract regardless of whether the caller or the wire is at fault. Attacker model: a ma…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-80561"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3042</id>
    <title>WID-SEC-W-2026-3042 — Linux Kernel: Mehrere Schwachstellen</title>
    <updated>2026-10-02T22:39:27.216366+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen, darunter möglicherweise die Ausführung von beliebigem Code, die Ausweitung von Berechtigungen, die Offenlegung von Informationen, die Manipulation von Daten oder Denial-of-Service-Zustände.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3042"/>
  </entry>
</feed>
