<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T23:55:52.689426+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-89635</id>
    <title>Withdrawn: BELL-CVE-2026-89635 — CVE-2026-89635 does not affect BellSoft software</title>
    <updated>2026-10-02T23:55:52.809219+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>
          <strong>Withdrawn by the publisher.</strong>
        </p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-89635"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-367317</id>
    <title>EUVD-2026-367317</title>
    <updated>2026-10-02T23:55:52.809261+00:00</updated>
    <content>EUVD-2026-367317</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-367317"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-89635</id>
    <title>fkie_cve-2026-89635</title>
    <updated>2026-10-02T23:55:52.809277+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>ksmbd: only rebind the reopened file's own oplock on durable reconnect</p>
<p>ksmbd_reopen_durable_fd() walks the inode's m_op_list and rebinds every
detached oplock to the reconnecting session:</p>
<p>list_for_each_entry_rcu(op, &amp;ci-&gt;m_op_list, op_entry,
				lockdep_is_held(&amp;ci-&gt;m_lock)) {
		if (op-&gt;conn)
			continue;
		op-&gt;conn = ksmbd_conn_get(fp-&gt;conn);
		op-&gt;sess = work-&gt;sess;
	}</p>
<p>The only key is op-&gt;conn == NULL, which every detached durable handle on
that inode matches, not just the one owned by fp.  When two sessions hold
durable handles on the same file and both disconnect, reconnecting one of
them adopts the other session's oplock: op-&gt;sess is overwritten with the
reconnecting session without taking a reference on it, while op-&gt;conn
pins the connection.</p>
<p>The sibling teardown path, session_fd_check(), keys on the identity of
the connection being torn down (op-&gt;conn == conn) rather than on shared
state, and so does not have this problem.</p>
<p>Once the adopting session is destroyed, ksmbd_session_destroy() frees it
while the foreign oplock still points at it.  The reader in
ksmbd_close_fd_app_instance_id() validates only opinfo-&gt;conn, which is
still live thanks to the reference taken above, and then dereferences the
stale session:</p>
<p>if (!opinfo-&gt;conn) {
		up_read(&amp;fp-&gt;f_ci-&gt;m_lock);
		goto out;
	}</p>
<p>ft = &amp;opinfo-&gt;sess-&gt;file_table;
	write_lock(&amp;ft-&gt;lock);</p>
<p>BUG: KASAN: slab-use-after-free in _raw_write_lock+0x74/0x…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-89635"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-rg7m-2q29-w52v</id>
    <title>GHSA-rg7m-2q29-w52v</title>
    <updated>2026-10-02T23:55:52.809348+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>ksmbd: only rebind the reopened file's own oplock on durable reconnect</p>
<p>ksmbd_reopen_durable_fd() walks the inode's m_op_list and rebinds every
detached oplock to the reconnecting session:</p>
<p>list_for_each_entry_rcu(op, &amp;ci-&gt;m_op_list, op_entry,
				lockdep_is_held(&amp;ci-&gt;m_lock)) {
		if (op-&gt;conn)
			continue;
		op-&gt;conn = ksmbd_conn_get(fp-&gt;conn);
		op-&gt;sess = work-&gt;sess;
	}</p>
<p>The only key is op-&gt;conn == NULL, which every detached durable handle on
that inode matches, not just the one owned by fp.  When two sessions hold
durable handles on the same file and both disconnect, reconnecting one of
them adopts the other session's oplock: op-&gt;sess is overwritten with the
reconnecting session without taking a reference on it, while op-&gt;conn
pins the connection.</p>
<p>The sibling teardown path, session_fd_check(), keys on the identity of
the connection being torn down (op-&gt;conn == conn) rather than on shared
state, and so does not have this problem.</p>
<p>Once the adopting session is destroyed, ksmbd_session_destroy() frees it
while the foreign oplock still points at it.  The reader in
ksmbd_close_fd_app_instance_id() validates only opinfo-&gt;conn, which is
still live thanks to the reference taken above, and then dereferences the
stale session:</p>
<p>if (!opinfo-&gt;conn) {
		up_read(&amp;fp-&gt;f_ci-&gt;m_lock);
		goto out;
	}</p>
<p>ft = &amp;opinfo-&gt;sess-&gt;file_table;
	write_lock(&amp;ft-&gt;lock);</p>
<p>BUG: KASAN: slab-use-after-free in _raw_write_lock+0x74/0x…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-rg7m-2q29-w52v"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11880-1</id>
    <title>openSUSE-SU-2026:11880-1 — kernel-devel-7.2.7-1.1 on GA media</title>
    <updated>2026-10-02T23:55:52.809387+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>kernel-devel-7.2.7-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:11880-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-89635</id>
    <title>UBUNTU-CVE-2026-89635</title>
    <updated>2026-10-02T23:55:52.809926+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 96 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: ksmbd: only rebind the reopened file's own oplock on durable reconnect ksmbd_reopen_durable_fd() walks the inode's m_op_list and rebinds every detached oplock to the reconnecting session: 	list_for_each_entry_rcu(op, &amp;ci-&gt;m_op_list, op_entry, 				lockdep_is_held(&amp;ci-&gt;m_lock)) { 		if (op-&gt;conn) 			continue; 		op-&gt;conn = ksmbd_conn_get(fp-&gt;conn); 		op-&gt;sess = work-&gt;sess; 	} The only key is op-&gt;conn == NULL, which every detached durable handle on that inode matches, not just the one owned by fp.  When two sessions hold durable handles on the same file and both disconnect, reconnecting one of them adopts the other session's oplock: op-&gt;sess is overwritten with the reconnecting session without taking a reference on it, while op-&gt;conn pins the connection. The sibling teardown path, session_fd_check(), keys on the identity of the connection being torn down (op-&gt;conn == conn) rather than on shared state, and so does not have this problem. Once the adopting session is destroyed, ksmbd_session_destroy() frees it while the foreign oplock still points at it.  The reader in ksmbd_close_fd_app_instance_id() validates only opinfo-&gt;conn, which is still live thanks to the reference taken above, and then dereferences the stale session: 	if (!opinfo-&gt;conn) { 		up_read(&amp;fp-&gt;f_ci-&gt;m_lock); 		goto out; 	} 	ft = &amp;opinfo-&gt;sess-&gt;file_table; 	write_lock(&amp;ft-&gt;lock);   BUG: KASAN: slab-use-after-free in _raw_write_lock+0x74/0xd0   Writ…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-89635"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3321</id>
    <title>WID-SEC-W-2026-3321 — Linux Kernel: Mehrere Schwachstellen</title>
    <updated>2026-10-02T23:55:52.810282+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um Sicherheitsmaßnahmen zu umgehen, Daten oder den Systemzustand zu manipulieren, Denial-of-Service-Zustände herbeizuführen oder andere, nicht näher spezifizierte Angriffe durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3321"/>
  </entry>
</feed>
