<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-10T21:54:15.986370+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-23213</id>
    <title>CVE-2026-23213 — drm/amd/pm: Disable MMIO access during SMU Mode 1 reset</title>
    <updated>2026-10-10T21:54:16.018663+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Linux</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>drm/amd/pm: Disable MMIO access during SMU Mode 1 reset</p>
<p>During Mode 1 reset, the ASIC undergoes a reset cycle and becomes
temporarily inaccessible via PCIe. Any attempt to access MMIO registers
during this window (e.g., from interrupt handlers or other driver threads)
can result in uncompleted PCIe transactions, leading to NMI panics or
system hangs.</p>
<p>To prevent this, set the `no_hw_access` flag to true immediately after
triggering the reset. This signals other driver components to skip
register accesses while the device is offline.</p>
<p>A memory barrier `smp_mb()` is added to ensure the flag update is
globally visible to all cores before the driver enters the sleep/wait
state.</p>
<p>(cherry picked from commit 7edb503fe4b6d67f47d8bb0dfafb8e699bb0f8a4)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-23213"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/usn-8278-1</id>
    <title>USN-8278-1 — linux, linux-aws, linux-aws-fips, linux-gcp, linux-gcp-fips, linux-gke, linux-gkeop, linux-ibm, linux-ibm-6.8, linux-lo…</title>
    <updated>2026-10-10T21:54:16.018736+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:22.04:LTS: linux-ibm-6.8, Ubuntu:22.04:LTS: linux-lowlatency-hwe-6.8, Ubuntu:Pro:Realtime:22.04:LTS: linux-realtime-6.8, Ubuntu:24.04:LTS: linux, Ubuntu:24.04:LTS: linux-aws, Ubuntu:24.04:LTS: linux-gcp, Ubuntu:24.04:LTS: linux-gke, Ubuntu:24.04:LTS: linux-gkeop, Ubuntu:24.04:LTS: linux-ibm, Ubuntu:24.04:LTS: linux-lowlatency and 5 more</p>
<p>It was discovered that the Linux kernel algif_aead module did not properly
handle in-place cryptographic operations. This flaw is known as Copy Fail.
A local attacker could use this to escalate privileges, or possibly escape
a container. (CVE-2026-31431)</p>
<p>Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
  - ARM64 architecture;
  - x86 architecture;
  - Cryptographic API;
  - Compute Acceleration Framework;
  - Drivers core;
  - Null block device driver;
  - Ublk userspace block driver;
  - Bluetooth drivers;
  - Counter interface drivers;
  - DMA engine subsystem;
  - DPLL subsystem;
  - GPU drivers;
  - HID subsystem;
  - Intel Trace Hub HW tracing drivers;
  - IIO ADC drivers;
  - IIO subsystem;
  - On-Chip Interconnect management framework;
  - IRQ chip drivers;
  - Modular ISDN driver;
  - LED subsystem;
  - Multiple devices driver;
  - UACCE accelerator framework;
  - MMC subsystem;
  - Ethernet bonding driver;
  - Network drivers;
  - Mellanox network drivers;
  - NVME drivers;
  - PHY drivers;
  - x86 platform drivers;
  - i.MX PM domains;
  - SCSI subsystem;
  - SLIMbus drivers;
  - SPI subsystem;
  - TCM subsystem;
  - W1 Dallas's 1-wire bus driver;
  - Xen hypervisor drivers;
  - BTRFS file system;
  - EFI Variable file system;
  - exFAT file system;
  - Ext4 file system;
  - HFS+ file system;
  - Network file system (NFS) client;
  - N…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/usn-8278-1"/>
  </entry>
</feed>
