<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-10T16:58:17.079359+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-74752</id>
    <title>CVE-2026-74752 — sctp: validate cookie AUTH state before use</title>
    <updated>2026-10-10T16:58:17.098456+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Linux</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>sctp: validate cookie AUTH state before use</p>
<p>When cookie authentication is disabled, COOKIE_ECHO restores fixed-size
AUTH fields directly from peer-controlled cookie bytes.  A forged RANDOM
length, HMAC list, or CHUNKS list can then reach association consumers
with lengths or identifiers that were never validated against the local
backing arrays.</p>
<p>A forged RANDOM length can cause out-of-bounds reads during key-vector
construction.  A forged HMAC identifier also caused a 32-byte write past
a zero-length AUTH chunk, providing a primitive for a local privilege
escalation chain.</p>
<p>Validate the cookie's RANDOM, HMACS, and CHUNKS parameters at the cookie
trust boundary before copying them into the association.  Reject invalid
types, malformed lengths, unsupported HMAC identifiers, HMAC lists
without SHA1, and forbidden chunk ids.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-74752"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/usn-8886-1</id>
    <title>USN-8886-1 — linux-nvidia-tegra vulnerabilities</title>
    <updated>2026-10-10T16:58:17.098524+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:24.04:LTS: linux-nvidia-tegra</p>
<p>Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
  - NVDIMM (Non-Volatile Memory Device) drivers;
  - Handshake API;
  - ARM32 architecture;
  - ARM64 architecture;
  - MIPS architecture;
  - OpenRISC architecture;
  - PowerPC architecture;
  - S390 architecture;
  - x86 architecture;
  - Block layer subsystem;
  - Cryptographic API;
  - Intel NPU Driver;
  - Android drivers;
  - Rados block device (RBD) driver;
  - Bluetooth drivers;
  - Hardware random number generator core;
  - TPM device driver;
  - CPU frequency scaling framework;
  - Hardware crypto device drivers;
  - DMA engine subsystem;
  - FireWire subsystem;
  - Arm Firmware Framework for ARMv8-A(FFA);
  - GPIO subsystem;
  - GPU drivers;
  - HID subsystem;
  - Hardware monitoring drivers;
  - CoreSight HW tracing drivers;
  - I2C subsystem;
  - IIO ADC drivers;
  - IIO subsystem;
  - InfiniBand drivers;
  - Input Device core drivers;
  - Input Device (Mouse) drivers;
  - IOMMU subsystem;
  - Multiple devices driver;
  - Media drivers;
  - Multifunction device drivers;
  - Fastrpc Driver;
  - Amazon Nitro Secure Module driver;
  - MMC subsystem;
  - MTD block device drivers;
  - Ethernet bonding driver;
  - Network drivers;
  - Mellanox network drivers;
  - Texas Instruments network drivers;
  - NTB driver;
  - NVME drivers;
  - NVMEM (Non Volatile Memory) drivers;
  - Parport drivers…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/usn-8886-1"/>
  </entry>
</feed>
