<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T21:11:18.287887+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-89544</id>
    <title>BELL-CVE-2026-89544</title>
    <updated>2026-10-03T21:11:18.423756+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-89544"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1253</id>
    <title>certfr-2026-avi-1253 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de Debian. Certaines d'entre elles permettent à un…</title>
    <updated>2026-10-03T21:11:18.423808+00:00</updated>
    <content>certfr-2026-avi-1253</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-1253"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-372832</id>
    <title>EUVD-2026-372832</title>
    <updated>2026-10-03T21:11:18.423830+00:00</updated>
    <content>EUVD-2026-372832</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-372832"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-89544</id>
    <title>fkie_cve-2026-89544</title>
    <updated>2026-10-03T21:11:18.423843+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>SUNRPC: fix gssx_dec_option_array error path bugs</p>
<p>Four coupled defects in the gssx XDR option-array decoder make the
error paths unsafe: a NULL deref in the caller, a refcount leak on
the decoded group_info, and a latent use-after-free that the leak
fix would otherwise expose.</p>
<p>gssx_dec_option_array() sets oa-&gt;count = 1 before allocating
oa-&gt;data.  If that allocation fails, -ENOMEM is returned with
oa-&gt;count == 1 and oa-&gt;data == NULL.  All other error paths jump
to free_oa: which frees oa-&gt;data and NULLs it but also leaves
oa-&gt;count == 1.  The caller trusts the count:</p>
<p>gssp_accept_sec_context_upcall()
      gssx_dec_accept_sec_context()
        gssx_dec_option_array()        /* fails, count=1 data=NULL */
      data = res.options.data[0].value /* NULL deref */</p>
<p>Independently, free_creds: releases the partially decoded svc_cred
with a bare kfree(creds).  gssx_dec_linux_creds() installs a
groups_alloc() result into creds-&gt;cr_group_info; that object is
kvmalloc-backed and refcounted, and only put_group_info() reaches
kvfree().  A plain kfree(creds) drops the wrapper and leaks the
group_info allocation.</p>
<p>The natural fix for the leak is to call free_svc_cred(creds) before
kfree(creds), but free_svc_cred() invokes put_group_info() on
creds-&gt;cr_group_info unconditionally when non-NULL.  The existing
out_free_groups: path in gssx_dec_linux_creds() already called
groups_free() on that pointer without clearing i…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-89544"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-xwc4-2qqp-pxh3</id>
    <title>GHSA-xwc4-2qqp-pxh3</title>
    <updated>2026-10-03T21:11:18.423893+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>SUNRPC: fix gssx_dec_option_array error path bugs</p>
<p>Four coupled defects in the gssx XDR option-array decoder make the
error paths unsafe: a NULL deref in the caller, a refcount leak on
the decoded group_info, and a latent use-after-free that the leak
fix would otherwise expose.</p>
<p>gssx_dec_option_array() sets oa-&gt;count = 1 before allocating
oa-&gt;data.  If that allocation fails, -ENOMEM is returned with
oa-&gt;count == 1 and oa-&gt;data == NULL.  All other error paths jump
to free_oa: which frees oa-&gt;data and NULLs it but also leaves
oa-&gt;count == 1.  The caller trusts the count:</p>
<p>gssp_accept_sec_context_upcall()
      gssx_dec_accept_sec_context()
        gssx_dec_option_array()        /* fails, count=1 data=NULL */
      data = res.options.data[0].value /* NULL deref */</p>
<p>Independently, free_creds: releases the partially decoded svc_cred
with a bare kfree(creds).  gssx_dec_linux_creds() installs a
groups_alloc() result into creds-&gt;cr_group_info; that object is
kvmalloc-backed and refcounted, and only put_group_info() reaches
kvfree().  A plain kfree(creds) drops the wrapper and leaks the
group_info allocation.</p>
<p>The natural fix for the leak is to call free_svc_cred(creds) before
kfree(creds), but free_svc_cred() invokes put_group_info() on
creds-&gt;cr_group_info unconditionally when non-NULL.  The existing
out_free_groups: path in gssx_dec_linux_creds() already called
groups_free() on that pointer without clearing i…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-xwc4-2qqp-pxh3"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-89544</id>
    <title>msrc_CVE-2026-89544 — SUNRPC: fix gssx_dec_option_array error path bugs</title>
    <updated>2026-10-03T21:11:18.423930+00:00</updated>
    <content>msrc_CVE-2026-89544</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-89544"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11880-1</id>
    <title>openSUSE-SU-2026:11880-1 — kernel-devel-7.2.7-1.1 on GA media</title>
    <updated>2026-10-03T21:11:18.423948+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>kernel-devel-7.2.7-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:11880-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-89544</id>
    <title>UBUNTU-CVE-2026-89544</title>
    <updated>2026-10-03T21:11:18.424466+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe, Ubuntu:16.04:LTS: linux-hwe-edge and 233 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: SUNRPC: fix gssx_dec_option_array error path bugs Four coupled defects in the gssx XDR option-array decoder make the error paths unsafe: a NULL deref in the caller, a refcount leak on the decoded group_info, and a latent use-after-free that the leak fix would otherwise expose. gssx_dec_option_array() sets oa-&gt;count = 1 before allocating oa-&gt;data.  If that allocation fails, -ENOMEM is returned with oa-&gt;count == 1 and oa-&gt;data == NULL.  All other error paths jump to free_oa: which frees oa-&gt;data and NULLs it but also leaves oa-&gt;count == 1.  The caller trusts the count:     gssp_accept_sec_context_upcall()       gssx_dec_accept_sec_context()         gssx_dec_option_array()        /* fails, count=1 data=NULL */       data = res.options.data[0].value /* NULL deref */ Independently, free_creds: releases the partially decoded svc_cred with a bare kfree(creds).  gssx_dec_linux_creds() installs a groups_alloc() result into creds-&gt;cr_group_info; that object is kvmalloc-backed and refcounted, and only put_group_info() reaches kvfree().  A plain kfree(creds) drops the wrapper and leaks the group_info allocation. The natural fix for the leak is to call free_svc_cred(creds) before kfree(creds), but free_svc_cred() invokes put_group_info() on creds-&gt;cr_group_info unconditionally when non-NULL.  The existing out_free_groups: path in gssx_dec_linux_creds() already called groups_free() on that pointer without clearing it, so…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-89544"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3321</id>
    <title>WID-SEC-W-2026-3321 — Linux Kernel: Mehrere Schwachstellen</title>
    <updated>2026-10-03T21:11:18.424795+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um Sicherheitsmaßnahmen zu umgehen, Daten oder den Systemzustand zu manipulieren, Denial-of-Service-Zustände herbeizuführen oder andere, nicht näher spezifizierte Angriffe durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3321"/>
  </entry>
</feed>
