<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T10:03:17.488612+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-74746</id>
    <title>BELL-CVE-2026-74746</title>
    <updated>2026-10-06T10:03:17.693203+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-74746"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1163</id>
    <title>certfr-2026-avi-1163 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de Debian LTS. Certaines d'entre elles permettent à…</title>
    <updated>2026-10-06T10:03:17.693280+00:00</updated>
    <content>certfr-2026-avi-1163</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-1163"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-359772</id>
    <title>EUVD-2026-359772</title>
    <updated>2026-10-06T10:03:17.693301+00:00</updated>
    <content>EUVD-2026-359772</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-359772"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-74746</id>
    <title>fkie_cve-2026-74746</title>
    <updated>2026-10-06T10:03:17.693314+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>netfilter: flowtable: publish GC-visible tuple last</p>
<p>nf_flow_table_iterate() only treats original-direction tuple nodes as
owning entries. Publishing the original node first lets GC observe and
free a flow while flow_offload_add() is still inserting the reply node.
Publish the reply node first and the original node last so GC never
sees a partially installed flow.</p>
<p>KASAN can trigger slab-use-after-free read and write reports in the
flowtable/rhashtable path (rht_deferred_worker, jhash, flow_offload_del,
flow_offload_lookup, etc.).</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-74746"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-4hwc-233g-5mv3</id>
    <title>GHSA-4hwc-233g-5mv3</title>
    <updated>2026-10-06T10:03:17.693343+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>netfilter: flowtable: publish GC-visible tuple last</p>
<p>nf_flow_table_iterate() only treats original-direction tuple nodes as
owning entries. Publishing the original node first lets GC observe and
free a flow while flow_offload_add() is still inserting the reply node.
Publish the reply node first and the original node last so GC never
sees a partially installed flow.</p>
<p>KASAN can trigger slab-use-after-free read and write reports in the
flowtable/rhashtable path (rht_deferred_worker, jhash, flow_offload_del,
flow_offload_lookup, etc.).</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-4hwc-233g-5mv3"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-74746</id>
    <title>msrc_CVE-2026-74746 — netfilter: flowtable: publish GC-visible tuple last</title>
    <updated>2026-10-06T10:03:17.693363+00:00</updated>
    <content>msrc_CVE-2026-74746</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-74746"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:73645</id>
    <title>RHSA-2026:73645 — Red Hat Security Advisory: kernel security, bug fix, and enhancement update</title>
    <updated>2026-10-06T10:03:17.693379+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>kernel: linux/dim: Fix divide by 0 in RDMA DIM kernel: ALSA: 6fire: fix use-after-free on disconnect kernel: sctp: purge outqueue on stale COOKIE-ECHO handling kernel: tipc: fix double-free in tipc_buf_append() kernel: netfilter: conntrack: remove sprintf usage kernel: dm log: fix out-of-bounds write due to region_count overflow kernel: Bluetooth: l2cap: Add missing chan lock in l2cap_ecred_reconf_rsp kernel: net: pull headers in qdisc_pkt_len_segs_init() kernel: zram: fix use-after-free in zram_bvec_write_partial() kernel: i2c: stub: Reject I2C block transfers with invalid length kernel: net: qrtr: restrict socket creation to the initial network namespace kernel: AMD-SN-7061: Safe RET Interrupt Vulnerability kernel: dm-verity: fix buffer overflow in FEC calculation kernel: netfilter: flowtable: publish GC-visible tuple last</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:73645"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:75746</id>
    <title>RLSA-2026:75746 — Important: kernel-rt security, bug fix, and enhancement update</title>
    <updated>2026-10-06T10:03:17.693418+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:8: kernel-rt</p>
<p>The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements.</p>
<p>Security Fix(es):</p>
<p>* kernel: Linux kernel: Use-after-free in xc5000 tuner driver due to race condition (CVE-2025-39994)</p>
<p>* kernel: gfs2: Fix unlikely race in gdlm_put_lock (CVE-2025-40242)</p>
<p>* kernel: Linux kernel: Denial of Service in RDMA/bnxt_re driver due to race condition during QP destruction (CVE-2023-54048)</p>
<p>* kernel: nvme-pci: fix mempool alloc size (CVE-2022-50756)</p>
<p>* kernel: Linux kernel: Denial of Service in QFQ scheduler via child qlen manipulation (CVE-2026-23105)</p>
<p>* kernel: RDMA/uverbs: Validate wqe_size before using it in ib_uverbs_post_send (CVE-2026-45856)</p>
<p>* kernel: gfs2: Fix slab-use-after-free in qd_put (CVE-2026-45861)</p>
<p>* kernel: net/sched: act_ct: Only release RCU read lock after ct_ft (CVE-2026-46319)</p>
<p>* kernel: gfs2: add some missing log locking (CVE-2026-53049)</p>
<p>* kernel: crypto: af_alg - Cap AEAD AD length to 0x80000000 (CVE-2026-52972)</p>
<p>* kernel: net/mlx5: Fix slab-out-of-bounds in mlx5_query_nic_vport_mac_list (CVE-2026-53230)</p>
<p>* kernel: ipvs: clear the svc scheduler ptr early on edit (CVE-2026-53270)</p>
<p>* kernel: net: ip_gre: require CAP_NET_ADMIN in the device netns for changelink (CVE-2026-63829)</p>
<p>* kernel: KVM: SVM: Fix page overflow in sev_dbg_crypt() for ENCRYPT path (CVE-2026-63794)</p>
<p>* kernel: tunnels: do not assume transport header in iptunnel_pmtud_check_icmp() (CVE-2026-63992)</p>
<p>* kernel: tunnels: l…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:75746"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-74746</id>
    <title>UBUNTU-CVE-2026-74746</title>
    <updated>2026-10-06T10:03:17.693467+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:Pro:18.04:LTS: linux-aws-5.4, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:Pro:18.04:LTS: linux-azure-5.4, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3 and 219 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: netfilter: flowtable: publish GC-visible tuple last nf_flow_table_iterate() only treats original-direction tuple nodes as owning entries. Publishing the original node first lets GC observe and free a flow while flow_offload_add() is still inserting the reply node. Publish the reply node first and the original node last so GC never sees a partially installed flow. KASAN can trigger slab-use-after-free read and write reports in the flowtable/rhashtable path (rht_deferred_worker, jhash, flow_offload_del, flow_offload_lookup, etc.).</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-74746"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3042</id>
    <title>WID-SEC-W-2026-3042 — Linux Kernel: Mehrere Schwachstellen</title>
    <updated>2026-10-06T10:03:17.693757+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen, darunter möglicherweise die Ausführung von beliebigem Code, die Ausweitung von Berechtigungen, die Offenlegung von Informationen, die Manipulation von Daten oder Denial-of-Service-Zustände.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3042"/>
  </entry>
</feed>
