<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T10:06:53.637219+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:19568</id>
    <title>ALSA-2026:19568 — Important: kernel security update</title>
    <updated>2026-10-02T10:06:55.782289+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:9: kernel, AlmaLinux:9: kernel-64k, AlmaLinux:9: kernel-64k-core, AlmaLinux:9: kernel-64k-debug, AlmaLinux:9: kernel-64k-debug-core, AlmaLinux:9: kernel-64k-debug-devel, AlmaLinux:9: kernel-64k-debug-devel-matched, AlmaLinux:9: kernel-64k-debug-modules, AlmaLinux:9: kernel-64k-debug-modules-core, AlmaLinux:9: kernel-64k-debug-modules-extra and 64 more</p>
<p>The kernel packages contain the Linux kernel, the core of any Linux operating system.</p>
<p>Security Fix(es):</p>
<p>* kernel: net/sched: Make cake_enqueue return NET_XMIT_CN when past buffer_limit (CVE-2025-39766)
  * kernel: scsi: qla2xxx: Fix improper freeing of purex item (CVE-2025-68741)
  * kernel: libceph: make decode_pool() more resilient against corrupted osdmaps (CVE-2025-71116)
  * kernel: libceph: prevent potential out-of-bounds reads in handle_auth_done() (CVE-2026-22984)
  * kernel: libceph: replace overzealous BUG_ON in osdmap_apply_incremental() (CVE-2026-22990)
  * kernel: Linux kernel: Denial of Service in libceph OSD client due to unreset sparse-read state (CVE-2026-23136)
  * kernel: net/sched: cls_u32: use skb_header_pointer_careful() (CVE-2026-23204)
  * kernel: Linux kernel: Use-after-free in traffic control (act_ct) may lead to denial of service or privilege escalation (CVE-2026-23270)
  * kernel: Linux kernel KVM: Privilege escalation or denial of service due to improper shadow page table entry handling (CVE-2026-23401)
  * kernel: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (CVE-2026-31402)
  * kernel: can: raw: fix ro-&gt;uniq use-after-free in raw_rcv() (CVE-2026-31532)
  * kernel: usbip: validate number_of_packets in usbip_pack_ret_submit() (CVE-2026-31607)
  * kernel: md/bitmap: fix GPF in write_page caused by resize race (CVE-2026-43163)
  * kernel: RDMA/umem: Fix double dma_buf_unpin in failure path (CVE-2026-43128)
  * kernel: "Dirty Frag" i…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:19568"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-06785</id>
    <title>bdu:2026-06785</title>
    <updated>2026-10-02T10:06:55.782471+00:00</updated>
    <content>bdu:2026-06785</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-06785"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-46300</id>
    <title>BELL-CVE-2026-46300</title>
    <updated>2026-10-02T10:06:55.782492+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-46300"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0639</id>
    <title>certfr-2026-avi-0639 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de SUSE. Elles permettent à un attaquant de provoqu…</title>
    <updated>2026-10-02T10:06:55.782515+00:00</updated>
    <content>certfr-2026-avi-0639</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0639"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2026-21361</id>
    <title>cnvd-2026-21361</title>
    <updated>2026-10-02T10:06:55.782531+00:00</updated>
    <content>cnvd-2026-21361</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2026-21361"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-364820</id>
    <title>EUVD-2026-364820</title>
    <updated>2026-10-02T10:06:55.782543+00:00</updated>
    <content>EUVD-2026-364820</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-364820"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-46300</id>
    <title>fkie_cve-2026-46300</title>
    <updated>2026-10-02T10:06:55.782553+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>net: skbuff: preserve shared-frag marker during coalescing</p>
<p>skb_try_coalesce() can attach paged frags from @from to @to.  If @from
has SKBFL_SHARED_FRAG set, the resulting @to skb can contain the same
externally-owned or page-cache-backed frags, but the shared-frag marker
is currently lost.</p>
<p>That breaks the invariant relied on by later in-place writers.  In
particular, ESP input checks skb_has_shared_frag() before deciding
whether an uncloned nonlinear skb can skip skb_cow_data().  If TCP
receive coalescing has moved shared frags into an unmarked skb, ESP can
see skb_has_shared_frag() as false and decrypt in place over page-cache
backed frags.</p>
<p>Propagate SKBFL_SHARED_FRAG when skb_try_coalesce() transfers paged
frags.  The tailroom copy path does not need the marker because it copies
bytes into @to's linear data rather than transferring frag descriptors.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-46300"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-47jg-vqrv-5f8v</id>
    <title>GHSA-47jg-vqrv-5f8v</title>
    <updated>2026-10-02T10:06:55.782582+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>net: skbuff: preserve shared-frag marker during coalescing</p>
<p>skb_try_coalesce() can attach paged frags from @from to @to.  If @from
has SKBFL_SHARED_FRAG set, the resulting @to skb can contain the same
externally-owned or page-cache-backed frags, but the shared-frag marker
is currently lost.</p>
<p>That breaks the invariant relied on by later in-place writers.  In
particular, ESP input checks skb_has_shared_frag() before deciding
whether an uncloned nonlinear skb can skip skb_cow_data().  If TCP
receive coalescing has moved shared frags into an unmarked skb, ESP can
see skb_has_shared_frag() as false and decrypt in place over page-cache
backed frags.</p>
<p>Propagate SKBFL_SHARED_FRAG when skb_try_coalesce() transfers paged
frags.  The tailroom copy path does not need the marker because it copies
bytes into @to's linear data rather than transferring frag descriptors.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-47jg-vqrv-5f8v"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-26-174-06</id>
    <title>ICSA-26-174-06 — Impact of Linux Kernel vulnerabilities on B&amp;R products</title>
    <updated>2026-10-02T10:06:55.782603+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>B&amp;R is aware of publicly reported vulnerabilities affecting the Linux kernel versions shipped with the products listed as affected in the advisory.</p>
<p>Successful local exploitation of these vulnerabilities could allow an attacker to escalate privileges on the affected system. Public proof-of-concept exploits are available for the vulnerabilities described herein. At the time of publication of this advisory, B&amp;R had no evidence of active exploitation targeting B&amp;R products.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-26-174-06"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-46300</id>
    <title>msrc_CVE-2026-46300 — net: skbuff: preserve shared-frag marker during coalescing</title>
    <updated>2026-10-02T10:06:55.782629+00:00</updated>
    <content>msrc_CVE-2026-46300</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-46300"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10954-1</id>
    <title>openSUSE-SU-2026:10954-1 — kernel-devel-7.0.11-1.1 on GA media</title>
    <updated>2026-10-02T10:06:55.782646+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>kernel-devel-7.0.11-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:10954-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ppsa-2026-003</id>
    <title>PPSA-2026-003 — Pilz: Multiple Vulnerabilities affecting industrial PC IndustrialPI</title>
    <updated>2026-10-02T10:06:55.782860+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The Linux kernel used in the IndustrialPI, 'linux-image-revpi-v8', prior to version 6.12.91-revpi0-rpi-v8 contains multiple vulnerabilities. Successful exploitation of these vulnerabilities can give an attacker full control over the device.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ppsa-2026-003"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhba-2026:20032</id>
    <title>RHBA-2026:20032 — Red Hat Bug Fix Advisory: OpenShift Container Platform 4.21.17 packages update</title>
    <updated>2026-10-02T10:06:55.782889+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>kernel: "Fragnesia" is a variant of Dirty Frag vulnerability in the ESP/XFRM leading to Local Privilege Escalation (LPE) vulnerability in the Linux kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhba-2026:20032"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:19569</id>
    <title>RLSA-2026:19569 — Important: kernel security update</title>
    <updated>2026-10-02T10:06:55.782914+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:10: kernel</p>
<p>The kernel packages contain the Linux kernel, the core of any Linux operating system.</p>
<p>Security Fix(es):</p>
<p>* kernel: net: af_can: do not leave a dangling sk pointer in can_create() (CVE-2024-56603)</p>
<p>* kernel: net/sched: Make cake_enqueue return NET_XMIT_CN when past buffer_limit (CVE-2025-39766)</p>
<p>* kernel: crypto: asymmetric_keys - prevent overflow in asymmetric_key_generate_id (CVE-2025-68724)</p>
<p>* kernel: scsi: qla2xxx: Fix improper freeing of purex item (CVE-2025-68741)</p>
<p>* kernel: Linux kernel: Use-after-free in traffic control (act_ct) may lead to denial of service or privilege escalation (CVE-2026-23270)</p>
<p>* kernel: Linux kernel KVM: Privilege escalation or denial of service due to improper shadow page table entry handling (CVE-2026-23401)</p>
<p>* kernel: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (CVE-2026-31402)</p>
<p>* kernel: Bluetooth: SCO: Fix use-after-free in sco_recv_frame() due to missing sock_hold (CVE-2026-31408)</p>
<p>* kernel: usbip: validate number_of_packets in usbip_pack_ret_submit() (CVE-2026-31607)</p>
<p>* kernel: RDMA/umem: Fix double dma_buf_unpin in failure path (CVE-2026-43128)</p>
<p>* kernel: "Dirty Frag" is a new universal Local Privilege Escalation (LPE) vulnerability in the Linux kernel (CVE-2026-43284)</p>
<p>* kernel: "Fragnesia" is a variant of Dirty Frag vulnerability in the ESP/XFRM leading to Local Privilege Escalation (LPE) vulnerability in the Linux kernel (CVE-2026-46300)</p>
<p>* kernel: Read root-owned files as an unprivileged user (CVE-2026-46333)</p>
<p>For more deta…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:19569"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/sa26p010</id>
    <title>SA26P010 — Impact of Linux Kernel vulnerabilities on B&amp;R products</title>
    <updated>2026-10-02T10:06:55.782977+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>B&amp;R is aware of publicly reported vulnerabilities affecting the Linux kernel versions shipped with the products listed as affected in the advisory.</p>
<p>Successful local exploitation of these vulnerabilities could allow an attacker to escalate privileges on the affected system. Public proof-of-concept exploits are available for the vulnerabilities described herein. At the time of publication of this advisory, B&amp;R had no evidence of active exploitation targeting B&amp;R products.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/sa26p010"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ssa-019113</id>
    <title>SSA-019113 — SSA-019113: Vulnerabilities in the additional GNU/Linux subsystem of the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1.6</title>
    <updated>2026-10-02T10:06:55.783009+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.6 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant).</p>
<p>Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ssa-019113"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:1899-1</id>
    <title>SUSE-SU-2026:1899-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-02T10:06:55.783293+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:1899-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-46300</id>
    <title>UBUNTU-CVE-2026-46300</title>
    <updated>2026-10-02T10:06:55.783319+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 191 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: net: skbuff: preserve shared-frag marker during coalescing skb_try_coalesce() can attach paged frags from @from to @to.  If @from has SKBFL_SHARED_FRAG set, the resulting @to skb can contain the same externally-owned or page-cache-backed frags, but the shared-frag marker is currently lost. That breaks the invariant relied on by later in-place writers.  In particular, ESP input checks skb_has_shared_frag() before deciding whether an uncloned nonlinear skb can skip skb_cow_data().  If TCP receive coalescing has moved shared frags into an unmarked skb, ESP can see skb_has_shared_frag() as false and decrypt in place over page-cache backed frags. Propagate SKBFL_SHARED_FRAG when skb_try_coalesce() transfers paged frags.  The tailroom copy path does not need the marker because it copies bytes into @to's linear data rather than transferring frag descriptors.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-46300"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1530</id>
    <title>WID-SEC-W-2026-1530 — Linux Kernel (Fragnesia): Schwachstelle ermöglicht Erlangen von Administratorrechten</title>
    <updated>2026-10-02T10:06:55.783664+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein lokaler Angreifer kann eine Schwachstelle in Linux Kernel ausnutzen, um Administratorrechte zu erlangen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1530"/>
  </entry>
</feed>
