<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-08T23:02:22.114452+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-64561</id>
    <title>CVE-2026-64561 — KVM: x86: Check for invalid/obsolete root *after* making MMU pages available</title>
    <updated>2026-10-08T23:02:22.262025+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Linux</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>KVM: x86: Check for invalid/obsolete root *after* making MMU pages available</p>
<p>Check for a "stale" page fault, i.e. for an invalid and/or obsolete root,
after making MMU pages available for the shadow MMU.  If reclaiming shadow
pages zaps an in-use root, i.e. marks it invalid, then KVM will attempt to
map memory into an invalid root.  On its own, populating an invalid root is
"fine", but because child shadow pages inherit their parent's role, any
children created during the map/fetch will be created as invalid pages,
thus violating KVM's invariant that invalid pages are never on the list of
active MMU pages.</p>
<p>Note, the underlying flaw has existed since KVM first started tracking
invalid roots in 2008 (commit 2e53d63acba7, "KVM: MMU: ignore zapped root
pagetables"), but the true badness only came along in 2020 (Linux 5.9)
with the invariant that invalid shadow pages can't be on the list of
active pages.</p>
<p>Note #2, inheriting role.invalid when creating child shadow pages is also
far from ideal; that flaw will be addressed separately.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-64561"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:45114</id>
    <title>RHSA-2026:45114 — Red Hat Security Advisory: kernel security update</title>
    <updated>2026-10-08T23:02:22.262115+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>kernel: fs/notify: call exportfs_encode_fid with s_umount kernel: scsi: core: Wake up the error handler when final completions race against each other kernel: rtnetlink: add missing netlink_ns_capable() check for peer netns kernel: net: ipv6: fix NOREF dst use in seg6 and rpl lwtunnels kernel: futex: Drop CLONE_THREAD requirement for private default hash alloc kernel: dm log: fix out-of-bounds write due to region_count overflow kernel: KVM: x86: Check for invalid/obsolete root *after* making MMU pages available</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:45114"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:45116</id>
    <title>RHSA-2026:45116 — Red Hat Security Advisory: kernel-rt security update</title>
    <updated>2026-10-08T23:02:22.262148+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>kernel: KVM: x86: Don't (re)check L1 intercepts when completing userspace I/O kernel: tipc: fix double-free in tipc_buf_append() kernel: dm log: fix out-of-bounds write due to region_count overflow kernel: KVM: x86: Check for invalid/obsolete root *after* making MMU pages available</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:45116"/>
  </entry>
</feed>
