<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T19:29:16.141518+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:71016</id>
    <title>ALSA-2026:71016 — Important: kernel-rt security, bug fix, and enhancement update</title>
    <updated>2026-10-02T19:29:16.199162+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: kernel-rt, AlmaLinux:8: kernel-rt-core, AlmaLinux:8: kernel-rt-debug, AlmaLinux:8: kernel-rt-debug-core, AlmaLinux:8: kernel-rt-debug-devel, AlmaLinux:8: kernel-rt-debug-modules, AlmaLinux:8: kernel-rt-debug-modules-extra, AlmaLinux:8: kernel-rt-devel, AlmaLinux:8: kernel-rt-modules, AlmaLinux:8: kernel-rt-modules-extra</p>
<p>The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements.</p>
<p>Security Fix(es):</p>
<p>* kernel: drm/amdgpu: Fix use-after-free race in VM acquire (CVE-2026-43370)
  * kernel: mac802154: llsec: add skb_cow_data() before in-place crypto (CVE-2026-63831)
  * kernel: sctp: don't free the ASCONF's own transport in DEL-IP processing (CVE-2026-64564)
  * kernel: ASoC: SOF: ipc3-control: Validate size in snd_sof_update_control (CVE-2026-72261)
  * kernel: xfrm: ah6: validate routing header segments_left (CVE-2026-80844)
  * kernel: net: tun: bound receive headroom (CVE-2026-81000)
  * kernel: scsi: qla2xxx: Bound rsp_info_len to avoid OOB sense-data read (CVE-2026-89846)</p>
<p>Bug Fix(es) and Enhancement(s):</p>
<p>* sctp: prevent peer transport count overflow [almalinux-8.10.z] (JIRA:AlmaLinux-216297)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:71016"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-89846</id>
    <title>BELL-CVE-2026-89846</title>
    <updated>2026-10-02T19:29:16.199264+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-89846"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1230</id>
    <title>certfr-2026-avi-1230 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de Red Hat. Certaines d'entre elles permettent à un…</title>
    <updated>2026-10-02T19:29:16.199290+00:00</updated>
    <content>certfr-2026-avi-1230</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-1230"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-369435</id>
    <title>EUVD-2026-369435</title>
    <updated>2026-10-02T19:29:16.199308+00:00</updated>
    <content>EUVD-2026-369435</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-369435"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-89846</id>
    <title>fkie_cve-2026-89846</title>
    <updated>2026-10-02T19:29:16.199320+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>scsi: qla2xxx: Bound rsp_info_len to avoid OOB sense-data read</p>
<p>In qla2x00_status_entry(), the FWI2 status path advances sense_data and
shrinks par_sense_len by rsp_info_len:</p>
<p>if (IS_FWI2_CAPABLE(ha)) {
		sense_data += rsp_info_len;
		par_sense_len -= rsp_info_len;
	}</p>
<p>rsp_info_len is a 32-bit value taken directly from the target's FCP
response (sf.rsp_data_len), while par_sense_len is the IOCB data area
size (28 bytes for 24xx, 60 bytes for 29xx). A hostile or buggy target
reporting an rsp_info_len larger than par_sense_len makes the unsigned
subtraction underflow to a huge value and advances sense_data out of
bounds.</p>
<p>The underflowed par_sense_len then defeats the cap in
qla2x00_handle_sense():</p>
<p>if (sense_len &gt; par_sense_len)
		sense_len = par_sense_len;
	memcpy(cp-&gt;sense_buffer, sense_data, sense_len);</p>
<p>so the memcpy reads up to SCSI_SENSE_BUFFERSIZE bytes from the
out-of-bounds sense_data pointer, leaking adjacent response-ring/heap
memory into the command's sense buffer.</p>
<p>Clamp rsp_info_len to par_sense_len before the subtraction so
par_sense_len can never underflow and sense_data stays within the IOCB
data area. The fix sits before the comp_status switch, covering both
qla2x00_handle_sense() call sites.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-89846"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-w8mp-89wx-m5rw</id>
    <title>GHSA-w8mp-89wx-m5rw</title>
    <updated>2026-10-02T19:29:16.199356+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>scsi: qla2xxx: Bound rsp_info_len to avoid OOB sense-data read</p>
<p>In qla2x00_status_entry(), the FWI2 status path advances sense_data and
shrinks par_sense_len by rsp_info_len:</p>
<p>if (IS_FWI2_CAPABLE(ha)) {
		sense_data += rsp_info_len;
		par_sense_len -= rsp_info_len;
	}</p>
<p>rsp_info_len is a 32-bit value taken directly from the target's FCP
response (sf.rsp_data_len), while par_sense_len is the IOCB data area
size (28 bytes for 24xx, 60 bytes for 29xx). A hostile or buggy target
reporting an rsp_info_len larger than par_sense_len makes the unsigned
subtraction underflow to a huge value and advances sense_data out of
bounds.</p>
<p>The underflowed par_sense_len then defeats the cap in
qla2x00_handle_sense():</p>
<p>if (sense_len &gt; par_sense_len)
		sense_len = par_sense_len;
	memcpy(cp-&gt;sense_buffer, sense_data, sense_len);</p>
<p>so the memcpy reads up to SCSI_SENSE_BUFFERSIZE bytes from the
out-of-bounds sense_data pointer, leaking adjacent response-ring/heap
memory into the command's sense buffer.</p>
<p>Clamp rsp_info_len to par_sense_len before the subtraction so
par_sense_len can never underflow and sense_data stays within the IOCB
data area. The fix sits before the comp_status switch, covering both
qla2x00_handle_sense() call sites.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-w8mp-89wx-m5rw"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-4039</id>
    <title>OESA-2026-4039 — kernel security update</title>
    <updated>2026-10-02T19:29:16.199383+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:22.03-LTS-SP4: kernel</p>
<p>The Linux Kernel, the operating system core itself.

Security Fix(es):</p>
<p>In the Linux kernel, the following vulnerability has been resolved:ALSA: caiaq: Use snd_card_free_when_closed() at disconnectionThe USB disconnect callback is supposed to be short and not too-longwaiting.  OTOH, the current code uses snd_card_free() atdisconnection, but this waits for the close of all used fds, hence itcan take long.  It eventually blocks the upper layer USB ioctls, whichmay trigger a soft lockup.An easy workaround is to replace snd_card_free() withsnd_card_free_when_closed().  This variant returns immediately whilethe release of resources is done asynchronously by the card devicerelease at the last close.This patch also splits the code to the disconnect and the free phases;the former is called immediately at the USB disconnect callback whilethe latter is called from the card destructor.(CVE-2024-56531)</p>
<p>In the Linux kernel, the following vulnerability has been resolved:xsk: fix OOB map writes when deleting elementsJordy says: In the xsk_map_delete_elem function an unsigned integer(map-&amp;gt;max_entries) is compared with a user-controlled signed integer(k). Due to implicit type conversion, a large unsigned value formap-&amp;gt;max_entries can bypass the intended bounds check: if (k &amp;gt;= map-&amp;gt;max_entries)  return -EINVAL;This allows k to hold a negative value (between -2147483648 and -2),which is then used as an array index in m-&amp;gt;xsk_map[k], which resultsin an out-of-bounds access. spi…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-4039"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11880-1</id>
    <title>openSUSE-SU-2026:11880-1 — kernel-devel-7.2.7-1.1 on GA media</title>
    <updated>2026-10-02T19:29:16.199721+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>kernel-devel-7.2.7-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:11880-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:71016</id>
    <title>RHSA-2026:71016 — Red Hat Security Advisory: kernel-rt security, bug fix, and enhancement update</title>
    <updated>2026-10-02T19:29:16.200234+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>kernel: drm/amdgpu: Fix use-after-free race in VM acquire kernel: mac802154: llsec: add skb_cow_data() before in-place crypto kernel: sctp: don't free the ASCONF's own transport in DEL-IP processing kernel: ASoC: SOF: ipc3-control: Validate size in snd_sof_update_control kernel: xfrm: ah6: validate routing header segments_left kernel: net: tun: bound receive headroom kernel: scsi: qla2xxx: Bound rsp_info_len to avoid OOB sense-data read</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:71016"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:71232</id>
    <title>RLSA-2026:71232 — Important: kernel security, bug fix, and enhancement update</title>
    <updated>2026-10-02T19:29:16.200262+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:9: kernel</p>
<p>The kernel packages contain the Linux kernel, the core of any Linux operating system.</p>
<p>Security Fix(es):</p>
<p>* kernel: block: zero non-PI portion of auto integrity buffer (CVE-2026-23007)</p>
<p>* kernel: af_unix: Drop all SCM attributes for SOCKMAP (CVE-2026-53005)</p>
<p>* kernel: mac802154: llsec: add skb_cow_data() before in-place crypto (CVE-2026-63831)</p>
<p>* kernel: blk-cgroup: fix UAF in __blkcg_rstat_flush() (CVE-2026-63802)</p>
<p>* kernel: block: don't overwrite bip_vcnt in bio_integrity_copy_user() (CVE-2026-64053)</p>
<p>* kernel: smb: client: fix double-free in SMB2_flush() replay (CVE-2026-64383)</p>
<p>* kernel: nvmet-tcp: check INIT_FAILED before nvmet_req_uninit in digest error path (CVE-2026-64534)</p>
<p>* kernel: sctp: don't free the ASCONF's own transport in DEL-IP processing (CVE-2026-64564)</p>
<p>* kernel: ALSA: timer: drain a slave's callback before its master detaches it (CVE-2026-68201)</p>
<p>* kernel: ASoC: SOF: ipc3-control: Validate size in snd_sof_update_control (CVE-2026-72261)</p>
<p>* kernel: xfrm: ah6: validate routing header segments_left (CVE-2026-80844)</p>
<p>* kernel: net: tun: bound receive headroom (CVE-2026-81000)</p>
<p>* kernel: scsi: qla2xxx: Bound rsp_info_len to avoid OOB sense-data read (CVE-2026-89846)</p>
<p>Bug Fix(es) and Enhancement(s):</p>
<p>* sctp: prevent peer transport count overflow [rhel-9.8.z] (JIRA:Rocky Linux-216251)</p>
<p>* netfilter: nftables CVE and memory safety backports for 9.8 (JIRA:Rocky Linux-236634)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowl…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:71232"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-89846</id>
    <title>UBUNTU-CVE-2026-89846</title>
    <updated>2026-10-02T19:29:16.200304+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: linux, Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe and 246 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Bound rsp_info_len to avoid OOB sense-data read In qla2x00_status_entry(), the FWI2 status path advances sense_data and shrinks par_sense_len by rsp_info_len: 	if (IS_FWI2_CAPABLE(ha)) { 		sense_data += rsp_info_len; 		par_sense_len -= rsp_info_len; 	} rsp_info_len is a 32-bit value taken directly from the target's FCP response (sf.rsp_data_len), while par_sense_len is the IOCB data area size (28 bytes for 24xx, 60 bytes for 29xx). A hostile or buggy target reporting an rsp_info_len larger than par_sense_len makes the unsigned subtraction underflow to a huge value and advances sense_data out of bounds. The underflowed par_sense_len then defeats the cap in qla2x00_handle_sense(): 	if (sense_len &gt; par_sense_len) 		sense_len = par_sense_len; 	memcpy(cp-&gt;sense_buffer, sense_data, sense_len); so the memcpy reads up to SCSI_SENSE_BUFFERSIZE bytes from the out-of-bounds sense_data pointer, leaking adjacent response-ring/heap memory into the command's sense buffer. Clamp rsp_info_len to par_sense_len before the subtraction so par_sense_len can never underflow and sense_data stays within the IOCB data area. The fix sits before the comp_status switch, covering both qla2x00_handle_sense() call sites.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-89846"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3438</id>
    <title>WID-SEC-W-2026-3438 — Linux Kernel: Mehrere Schwachstellen</title>
    <updated>2026-10-02T19:29:16.200560+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein lokaler Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen Denial of Service zu verursachen oder eine nicht näher spezifizierte Auswirkung zu erzielen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3438"/>
  </entry>
</feed>
