<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T11:58:31.138001+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-89637</id>
    <title>BELL-CVE-2026-89637</title>
    <updated>2026-10-03T11:58:31.278607+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-89637"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-367318</id>
    <title>EUVD-2026-367318</title>
    <updated>2026-10-03T11:58:31.278660+00:00</updated>
    <content>EUVD-2026-367318</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-367318"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-89637</id>
    <title>fkie_cve-2026-89637</title>
    <updated>2026-10-03T11:58:31.278675+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>smb: client: fix UAF and buffer leak in cifs_check_trans2() for malformed secondary T2</p>
<p>When a valid primary TRANSACT2 response has been received (mid-&gt;resp_buf
set, mid-&gt;multiRsp true) and a subsequent secondary response causes
cifs_check_trans2() to return false -- either because the SMB header is
invalid (malformed != 0) or because check2ndT2() rejects the PDU --
handle_mid() overwrites mid-&gt;resp_buf with the new buffer (leaking the
primary buffer) and, because mid-&gt;multiRsp is set, skips the
server-&gt;smallbuf/bigbuf NULL-out.  When the user thread frees
mid-&gt;resp_buf, server-&gt;smallbuf or server-&gt;bigbuf is left dangling; the
demux thread reuses it for the next packet, resulting in a use-after-free.</p>
<p>Combine both early-exit conditions and, when mid-&gt;multiRsp is already
set, abort the pending transaction inline: set multiEnd, call
dequeue_mid() with malformed=true, and return true so handle_mid() exits
without touching mid-&gt;resp_buf or the server buffer pointers.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-89637"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-q27p-5553-xhrr</id>
    <title>GHSA-q27p-5553-xhrr</title>
    <updated>2026-10-03T11:58:31.278721+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>smb: client: fix UAF and buffer leak in cifs_check_trans2() for malformed secondary T2</p>
<p>When a valid primary TRANSACT2 response has been received (mid-&gt;resp_buf
set, mid-&gt;multiRsp true) and a subsequent secondary response causes
cifs_check_trans2() to return false -- either because the SMB header is
invalid (malformed != 0) or because check2ndT2() rejects the PDU --
handle_mid() overwrites mid-&gt;resp_buf with the new buffer (leaking the
primary buffer) and, because mid-&gt;multiRsp is set, skips the
server-&gt;smallbuf/bigbuf NULL-out.  When the user thread frees
mid-&gt;resp_buf, server-&gt;smallbuf or server-&gt;bigbuf is left dangling; the
demux thread reuses it for the next packet, resulting in a use-after-free.</p>
<p>Combine both early-exit conditions and, when mid-&gt;multiRsp is already
set, abort the pending transaction inline: set multiEnd, call
dequeue_mid() with malformed=true, and return true so handle_mid() exits
without touching mid-&gt;resp_buf or the server buffer pointers.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-q27p-5553-xhrr"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-89637</id>
    <title>msrc_CVE-2026-89637 — smb: client: fix UAF and buffer leak in cifs_check_trans2() for malformed secondary T2</title>
    <updated>2026-10-03T11:58:31.278747+00:00</updated>
    <content>msrc_CVE-2026-89637</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-89637"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-4039</id>
    <title>OESA-2026-4039 — kernel security update</title>
    <updated>2026-10-03T11:58:31.278765+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:22.03-LTS-SP4: kernel</p>
<p>The Linux Kernel, the operating system core itself.

Security Fix(es):</p>
<p>In the Linux kernel, the following vulnerability has been resolved:ALSA: caiaq: Use snd_card_free_when_closed() at disconnectionThe USB disconnect callback is supposed to be short and not too-longwaiting.  OTOH, the current code uses snd_card_free() atdisconnection, but this waits for the close of all used fds, hence itcan take long.  It eventually blocks the upper layer USB ioctls, whichmay trigger a soft lockup.An easy workaround is to replace snd_card_free() withsnd_card_free_when_closed().  This variant returns immediately whilethe release of resources is done asynchronously by the card devicerelease at the last close.This patch also splits the code to the disconnect and the free phases;the former is called immediately at the USB disconnect callback whilethe latter is called from the card destructor.(CVE-2024-56531)</p>
<p>In the Linux kernel, the following vulnerability has been resolved:xsk: fix OOB map writes when deleting elementsJordy says: In the xsk_map_delete_elem function an unsigned integer(map-&amp;gt;max_entries) is compared with a user-controlled signed integer(k). Due to implicit type conversion, a large unsigned value formap-&amp;gt;max_entries can bypass the intended bounds check: if (k &amp;gt;= map-&amp;gt;max_entries)  return -EINVAL;This allows k to hold a negative value (between -2147483648 and -2),which is then used as an array index in m-&amp;gt;xsk_map[k], which resultsin an out-of-bounds access. spi…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-4039"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11880-1</id>
    <title>openSUSE-SU-2026:11880-1 — kernel-devel-7.2.7-1.1 on GA media</title>
    <updated>2026-10-03T11:58:31.279096+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>kernel-devel-7.2.7-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:11880-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-89637</id>
    <title>UBUNTU-CVE-2026-89637</title>
    <updated>2026-10-03T11:58:31.279622+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: linux, Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe and 246 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: smb: client: fix UAF and buffer leak in cifs_check_trans2() for malformed secondary T2 When a valid primary TRANSACT2 response has been received (mid-&gt;resp_buf set, mid-&gt;multiRsp true) and a subsequent secondary response causes cifs_check_trans2() to return false -- either because the SMB header is invalid (malformed != 0) or because check2ndT2() rejects the PDU -- handle_mid() overwrites mid-&gt;resp_buf with the new buffer (leaking the primary buffer) and, because mid-&gt;multiRsp is set, skips the server-&gt;smallbuf/bigbuf NULL-out.  When the user thread frees mid-&gt;resp_buf, server-&gt;smallbuf or server-&gt;bigbuf is left dangling; the demux thread reuses it for the next packet, resulting in a use-after-free. Combine both early-exit conditions and, when mid-&gt;multiRsp is already set, abort the pending transaction inline: set multiEnd, call dequeue_mid() with malformed=true, and return true so handle_mid() exits without touching mid-&gt;resp_buf or the server buffer pointers.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-89637"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3321</id>
    <title>WID-SEC-W-2026-3321 — Linux Kernel: Mehrere Schwachstellen</title>
    <updated>2026-10-03T11:58:31.279937+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um Sicherheitsmaßnahmen zu umgehen, Daten oder den Systemzustand zu manipulieren, Denial-of-Service-Zustände herbeizuführen oder andere, nicht näher spezifizierte Angriffe durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3321"/>
  </entry>
</feed>
