<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T10:43:18.081964+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-89775</id>
    <title>BELL-CVE-2026-89775</title>
    <updated>2026-10-02T10:43:18.120018+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:stream: linux-lts</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-89775"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-369799</id>
    <title>EUVD-2026-369799</title>
    <updated>2026-10-02T10:43:18.120068+00:00</updated>
    <content>EUVD-2026-369799</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-369799"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-89775</id>
    <title>fkie_cve-2026-89775</title>
    <updated>2026-10-02T10:43:18.120084+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>KVM: arm64: Handle negative S1 walk levels in VNCR TLB size evaluation</p>
<p>Computing the effects of a TLB invalidation involves looking at
the size of the mapping cached by the TLB. For S1 mappings such as
VNCR, this is deducted from the combination of the base granule size
and the mapping level.</p>
<p>However, this implies that the S1 MMU is *on*. When the MMU is off,
we indicate this with the level being set to a "creative" value of
-127 (S1_MMU_DISABLED).</p>
<p>This ends-up being misinterpreted by pgshift_level_to_ttl() as it
doesn't handle negative levels at all (the level is immediately cast
to a u8 and only the bottom two bits considered), leading to an
invalidation size of 0. Not helpful.</p>
<p>Tidy-up pgshift_level_to_ttl() to handle these negative levels, and
ttl_to_size() to always return SZ_1G when no valid TTL is present.
This allows the removal of open-coded checks for similar situations.</p>
<p>Note that the check for a negative value not explicitely checking for
S1_MMU_DISABLED is deliberate, so that actual negative levels introduced
with LVA2 and D128 can take the same path if we ever support them.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-89775"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-4h2c-gw77-f478</id>
    <title>GHSA-4h2c-gw77-f478</title>
    <updated>2026-10-02T10:43:18.120123+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>KVM: arm64: Handle negative S1 walk levels in VNCR TLB size evaluation</p>
<p>Computing the effects of a TLB invalidation involves looking at
the size of the mapping cached by the TLB. For S1 mappings such as
VNCR, this is deducted from the combination of the base granule size
and the mapping level.</p>
<p>However, this implies that the S1 MMU is *on*. When the MMU is off,
we indicate this with the level being set to a "creative" value of
-127 (S1_MMU_DISABLED).</p>
<p>This ends-up being misinterpreted by pgshift_level_to_ttl() as it
doesn't handle negative levels at all (the level is immediately cast
to a u8 and only the bottom two bits considered), leading to an
invalidation size of 0. Not helpful.</p>
<p>Tidy-up pgshift_level_to_ttl() to handle these negative levels, and
ttl_to_size() to always return SZ_1G when no valid TTL is present.
This allows the removal of open-coded checks for similar situations.</p>
<p>Note that the check for a negative value not explicitely checking for
S1_MMU_DISABLED is deliberate, so that actual negative levels introduced
with LVA2 and D128 can take the same path if we ever support them.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-4h2c-gw77-f478"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11880-1</id>
    <title>openSUSE-SU-2026:11880-1 — kernel-devel-7.2.7-1.1 on GA media</title>
    <updated>2026-10-02T10:43:18.120150+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>kernel-devel-7.2.7-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:11880-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:72624</id>
    <title>RHSA-2026:72624 — Red Hat Security Advisory: kernel security, bug fix, and enhancement update</title>
    <updated>2026-10-02T10:43:18.120597+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>kernel: ext4: fix e4b bitmap inconsistency reports kernel: KVM: nSVM: Raise #UD if unhandled VMMCALL isn't intercepted by L1 kernel: KVM: arm64: Reassign nested_mmus array behind mmu_lock kernel: fhandle: fix UAF due to unlocked -&gt;mnt_ns read in may_decode_fh() kernel: perf/core: Detach event groups during remove_on_exec kernel: vmxnet3: fix BUG_ON in vmxnet3_get_hdr_len() for Geneve packets kernel: perf: Reject exited events as group leaders kernel: crypto: tegra - fix rctx-&gt;cryptlen calculation in tegra_gcm_do_one_req() kernel: nvme-tcp: reject a read that transferred too few bytes kernel: KVM: arm64: Handle negative S1 walk levels in VNCR TLB size evaluation</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:72624"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:72624</id>
    <title>RLSA-2026:72624 — Important: kernel security, bug fix, and enhancement update</title>
    <updated>2026-10-02T10:43:18.120624+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:10: kernel</p>
<p>The kernel packages contain the Linux kernel, the core of any Linux operating system.</p>
<p>Security Fix(es):</p>
<p>* kernel: KVM: nSVM: Raise #UD if unhandled VMMCALL isn't intercepted by L1 (CVE-2026-46076)</p>
<p>* kernel: ext4: fix e4b bitmap inconsistency reports (CVE-2026-45942)</p>
<p>* kernel: KVM: arm64: Reassign nested_mmus array behind mmu_lock (CVE-2026-46317)</p>
<p>* kernel: fhandle: fix UAF due to unlocked -&gt;mnt_ns read in may_decode_fh() (CVE-2026-53341)</p>
<p>* kernel: perf/core: Detach event groups during remove_on_exec (CVE-2026-64556)</p>
<p>* kernel: vmxnet3: fix BUG_ON in vmxnet3_get_hdr_len() for Geneve packets (CVE-2026-68299)</p>
<p>* kernel: crypto: tegra - fix rctx-&gt;cryptlen calculation in tegra_gcm_do_one_req() (CVE-2026-80522)</p>
<p>* kernel: perf: Reject exited events as group leaders (CVE-2026-74753)</p>
<p>* kernel: nvme-tcp: reject a read that transferred too few bytes (CVE-2026-89480)</p>
<p>* kernel: KVM: arm64: Handle negative S1 walk levels in VNCR TLB size evaluation (CVE-2026-89775)</p>
<p>Bug Fix(es) and Enhancement(s):</p>
<p>* KVM: s390: Limit adapter indicator access to mapped page [rhel-10.2.z] (JIRA:Rocky Linux-188661)</p>
<p>* crypto: xxhash64 should not be fips approved [rhel-10.2.z] (JIRA:Rocky Linux-254943)</p>
<p>* kata-tdx TD vCPU stuck at reset vector (EIP=0xFFF0) on Intel Xeon 6 (Granite Rapids / Sierra Forest) ? guest never executes. (10.2.z) (JIRA:Rocky Linux-260402)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:72624"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-89775</id>
    <title>UBUNTU-CVE-2026-89775</title>
    <updated>2026-10-02T10:43:18.120671+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 120 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Handle negative S1 walk levels in VNCR TLB size evaluation Computing the effects of a TLB invalidation involves looking at the size of the mapping cached by the TLB. For S1 mappings such as VNCR, this is deducted from the combination of the base granule size and the mapping level. However, this implies that the S1 MMU is *on*. When the MMU is off, we indicate this with the level being set to a "creative" value of -127 (S1_MMU_DISABLED). This ends-up being misinterpreted by pgshift_level_to_ttl() as it doesn't handle negative levels at all (the level is immediately cast to a u8 and only the bottom two bits considered), leading to an invalidation size of 0. Not helpful. Tidy-up pgshift_level_to_ttl() to handle these negative levels, and ttl_to_size() to always return SZ_1G when no valid TTL is present. This allows the removal of open-coded checks for similar situations. Note that the check for a negative value not explicitely checking for S1_MMU_DISABLED is deliberate, so that actual negative levels introduced with LVA2 and D128 can take the same path if we ever support them.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-89775"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3412</id>
    <title>WID-SEC-W-2026-3412 — Linux Kernel: Mehrere Schwachstellen</title>
    <updated>2026-10-02T10:43:18.120807+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um Speicher zu beschädigen oder offenzulegen, den Kernel oder den Systemzustand zu manipulieren oder Denial-of-Service-Zustände, einschließlich Kernel-Abstürzen, zu verursachen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3412"/>
  </entry>
</feed>
