<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-08T08:24:35.847107+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-23270</id>
    <title>CVE-2026-23270 — net/sched: Only allow act_ct to bind to clsact/ingress qdiscs and shared blocks</title>
    <updated>2026-10-08T08:24:35.895845+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Linux, Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, Siemens SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP, Siemens SIPLUS S7-1500 CPU 1518-4 PN/DP MFP</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>net/sched: Only allow act_ct to bind to clsact/ingress qdiscs and shared blocks</p>
<p>As Paolo said earlier [1]:</p>
<p>"Since the blamed commit below, classify can return TC_ACT_CONSUMED while
the current skb being held by the defragmentation engine. As reported by
GangMin Kim, if such packet is that may cause a UaF when the defrag engine
later on tries to tuch again such packet."</p>
<p>act_ct was never meant to be used in the egress path, however some users
are attaching it to egress today [2]. Attempting to reach a middle
ground, we noticed that, while most qdiscs are not handling
TC_ACT_CONSUMED, clsact/ingress qdiscs are. With that in mind, we
address the issue by only allowing act_ct to bind to clsact/ingress
qdiscs and shared blocks. That way it's still possible to attach act_ct to
egress (albeit only with clsact).</p>
<p>[1] https://lore.kernel.org/netdev/674b8cbfc385c6f37fb29a1de08d8fe5c2b0fbee.1771321118.git.pabeni@redhat.com/
[2] https://lore.kernel.org/netdev/cc6bfb4a-4a2b-42d8-b9ce-7ef6644fb22b@ovn.org/</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-23270"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:13565</id>
    <title>RHSA-2026:13565 — Red Hat Security Advisory: kernel security update</title>
    <updated>2026-10-08T08:24:35.895976+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>kernel: Linux kernel: Denial of Service in libceph OSD client due to unreset sparse-read state kernel: Linux kernel: Use-after-free in traffic control (act_ct) may lead to denial of service or privilege escalation kernel: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache kernel: crypto: algif_aead - Revert to operating out-of-place kernel: crypto: algif_aead - Fix minimum RX size check for decryption</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:13565"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:21209</id>
    <title>RHSA-2026:21209 — Red Hat Security Advisory: kernel security update</title>
    <updated>2026-10-08T08:24:35.896011+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>kernel: proc: fix UAF in proc_get_inode() kernel: proc: use the same treatment to check proc_lseek as ones for proc_read_iter et.al kernel: net/sched: Make cake_enqueue return NET_XMIT_CN when past buffer_limit kernel: nbd: defer config unlock in nbd_genl_connect kernel: scsi: qla2xxx: Fix improper freeing of purex item kernel: Linux kernel: Denial of service and memory corruption in RDMA umad kernel: Linux kernel: Use-after-free in traffic control (act_ct) may lead to denial of service or privilege escalation kernel: Linux kernel: Use-after-free in bonding driver leads to denial of service kernel: md/bitmap: fix GPF in write_page caused by resize race</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:21209"/>
  </entry>
</feed>
