<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 18:26:23 +0000</lastBuildDate>
    <item>
      <title>ALSA-2026:53330 — Important: kernel security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:53330</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: kernel, AlmaLinux:10: kernel-64k, AlmaLinux:10: kernel-64k-core, AlmaLinux:10: kernel-64k-debug, AlmaLinux:10: kernel-64k-debug-core, AlmaLinux:10: kernel-64k-debug-devel, AlmaLinux:10: kernel-64k-debug-devel-matched, AlmaLinux:10: kernel-64k-debug-modules, AlmaLinux:10: kernel-64k-debug-modules-core, AlmaLinux:10: kernel-64k-debug-modules-extra and 65 more&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: fsnotify: Fix ordering of iput() and watched_objects decrement (CVE-2024-53143)
  * kernel: shmem: fix recovery on rename failures (CVE-2025-71072)
  * kernel: futex: Fix UaF between futex_key_to_node_opt() and vma_replace_policy() (CVE-2026-23415)
  * kernel: drm/amd/display: Do not skip unrelated mode changes in DSC validation (CVE-2026-31488)
  * kernel: ipc: limit next_id allocation to the valid ID range (CVE-2026-52923)
  * kernel: mm/slab: do not limit zeroing to orig_size when only red zoning is enabled (CVE-2026-64368)
  * kernel: net: openvswitch: reject oversized nested action attrs (CVE-2026-64531)&lt;/p&gt;
&lt;p&gt;Bug Fix(es) and Enhancement(s):&lt;/p&gt;
&lt;p&gt;* Kernel oops after increasing max number of mac addresses of a mlx5 VF [almalinux-10.2.z] (JIRA:AlmaLinux-213035)
  * AlmaLinux10.0 - s390/pkey: Check length in PKEY_VERIFYPROTK ioctl [almalinux-10.2.z] (JIRA:AlmaLinux-222503)
  * AlmaLinux10.0 - s390/pkey: Check length in pkey_pckmo handler implementation [almalinux-10.2.z] (JIRA:AlmaLinux-222505)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: kernel, AlmaLinux:10: kernel-64k, AlmaLinux:10: kernel-64k-core, AlmaLinux:10: kernel-64k-debug, AlmaLinux:10: kernel-64k-debug-core, AlmaLinux:10: kernel-64k-debug-devel, AlmaLinux:10: kernel-64k-debug-devel-matched, AlmaLinux:10: kernel-64k-debug-modules, AlmaLinux:10: kernel-64k-debug-modules-core, AlmaLinux:10: kernel-64k-debug-modules-extra and 65 more&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: fsnotify: Fix ordering of iput() and watched_objects decrement (CVE-2024-53143)
  * kernel: shmem: fix recovery on rename failures (CVE-2025-71072)
  * kernel: futex: Fix UaF between futex_key_to_node_opt() and vma_replace_policy() (CVE-2026-23415)
  * kernel: drm/amd/display: Do not skip unrelated mode changes in DSC validation (CVE-2026-31488)
  * kernel: ipc: limit next_id allocation to the valid ID range (CVE-2026-52923)
  * kernel: mm/slab: do not limit zeroing to orig_size when only red zoning is enabled (CVE-2026-64368)
  * kernel: net: openvswitch: reject oversized nested action attrs (CVE-2026-64531)&lt;/p&gt;
&lt;p&gt;Bug Fix(es) and Enhancement(s):&lt;/p&gt;
&lt;p&gt;* Kernel oops after increasing max number of mac addresses of a mlx5 VF [almalinux-10.2.z] (JIRA:AlmaLinux-213035)
  * AlmaLinux10.0 - s390/pkey: Check length in PKEY_VERIFYPROTK ioctl [almalinux-10.2.z] (JIRA:AlmaLinux-222503)
  * AlmaLinux10.0 - s390/pkey: Check length in pkey_pckmo handler implementation [almalinux-10.2.z] (JIRA:AlmaLinux-222505)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:53330</guid>
    </item>
    <item>
      <title>bdu:2025-07285</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-07285</link>
      <description>bdu:2025-07285</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-07285</guid>
    </item>
    <item>
      <title>BELL-CVE-2024-53143</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2024-53143</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2024-53143</guid>
    </item>
    <item>
      <title>certfr-2025-avi-0152 — De multiples vulnérabilités ont été découvertes dans le noyau Linux d'Ubuntu. Certaines d'entre elles permettent à un a…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0152</link>
      <description>certfr-2025-avi-0152</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0152</guid>
    </item>
    <item>
      <title>EUVD-2026-346417</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-346417</link>
      <description>EUVD-2026-346417</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-346417</guid>
    </item>
    <item>
      <title>fkie_cve-2024-53143</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-53143</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;fsnotify: Fix ordering of iput() and watched_objects decrement&lt;/p&gt;
&lt;p&gt;Ensure the superblock is kept alive until we&amp;#39;re done with iput().
Holding a reference to an inode is not allowed unless we ensure the
superblock stays alive, which fsnotify does by keeping the
watched_objects count elevated, so iput() must happen before the
watched_objects decrement.
This can lead to a UAF of something like sb-&amp;gt;s_fs_info in tmpfs, but the
UAF is hard to hit because race orderings that oops are more likely, thanks
to the CHECK_DATA_CORRUPTION() block in generic_shutdown_super().&lt;/p&gt;
&lt;p&gt;Also, ensure that fsnotify_put_sb_watched_objects() doesn&amp;#39;t call
fsnotify_sb_watched_objects() on a superblock that may have already been
freed, which would cause a UAF read of sb-&amp;gt;s_fsnotify_info.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;fsnotify: Fix ordering of iput() and watched_objects decrement&lt;/p&gt;
&lt;p&gt;Ensure the superblock is kept alive until we&amp;#39;re done with iput().
Holding a reference to an inode is not allowed unless we ensure the
superblock stays alive, which fsnotify does by keeping the
watched_objects count elevated, so iput() must happen before the
watched_objects decrement.
This can lead to a UAF of something like sb-&amp;gt;s_fs_info in tmpfs, but the
UAF is hard to hit because race orderings that oops are more likely, thanks
to the CHECK_DATA_CORRUPTION() block in generic_shutdown_super().&lt;/p&gt;
&lt;p&gt;Also, ensure that fsnotify_put_sb_watched_objects() doesn&amp;#39;t call
fsnotify_sb_watched_objects() on a superblock that may have already been
freed, which would cause a UAF read of sb-&amp;gt;s_fsnotify_info.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-53143</guid>
    </item>
    <item>
      <title>GHSA-rfr4-95g9-6vf3</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-rfr4-95g9-6vf3</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;fsnotify: Fix ordering of iput() and watched_objects decrement&lt;/p&gt;
&lt;p&gt;Ensure the superblock is kept alive until we&amp;#39;re done with iput().
Holding a reference to an inode is not allowed unless we ensure the
superblock stays alive, which fsnotify does by keeping the
watched_objects count elevated, so iput() must happen before the
watched_objects decrement.
This can lead to a UAF of something like sb-&amp;gt;s_fs_info in tmpfs, but the
UAF is hard to hit because race orderings that oops are more likely, thanks
to the CHECK_DATA_CORRUPTION() block in generic_shutdown_super().&lt;/p&gt;
&lt;p&gt;Also, ensure that fsnotify_put_sb_watched_objects() doesn&amp;#39;t call
fsnotify_sb_watched_objects() on a superblock that may have already been
freed, which would cause a UAF read of sb-&amp;gt;s_fsnotify_info.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;fsnotify: Fix ordering of iput() and watched_objects decrement&lt;/p&gt;
&lt;p&gt;Ensure the superblock is kept alive until we&amp;#39;re done with iput().
Holding a reference to an inode is not allowed unless we ensure the
superblock stays alive, which fsnotify does by keeping the
watched_objects count elevated, so iput() must happen before the
watched_objects decrement.
This can lead to a UAF of something like sb-&amp;gt;s_fs_info in tmpfs, but the
UAF is hard to hit because race orderings that oops are more likely, thanks
to the CHECK_DATA_CORRUPTION() block in generic_shutdown_super().&lt;/p&gt;
&lt;p&gt;Also, ensure that fsnotify_put_sb_watched_objects() doesn&amp;#39;t call
fsnotify_sb_watched_objects() on a superblock that may have already been
freed, which would cause a UAF read of sb-&amp;gt;s_fsnotify_info.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-rfr4-95g9-6vf3</guid>
    </item>
    <item>
      <title>RHSA-2026:53330 — Red Hat Security Advisory: kernel security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:53330</link>
      <description>&lt;p&gt;kernel: fsnotify: Fix ordering of iput() and watched_objects decrement kernel: shmem: fix recovery on rename failures kernel: futex: Fix UaF between futex_key_to_node_opt() and vma_replace_policy() kernel: drm/amd/display: Do not skip unrelated mode changes in DSC validation kernel: ipc: limit next_id allocation to the valid ID range kernel: mm/slab: do not limit zeroing to orig_size when only red zoning is enabled kernel: net: openvswitch: reject oversized nested action attrs&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;kernel: fsnotify: Fix ordering of iput() and watched_objects decrement kernel: shmem: fix recovery on rename failures kernel: futex: Fix UaF between futex_key_to_node_opt() and vma_replace_policy() kernel: drm/amd/display: Do not skip unrelated mode changes in DSC validation kernel: ipc: limit next_id allocation to the valid ID range kernel: mm/slab: do not limit zeroing to orig_size when only red zoning is enabled kernel: net: openvswitch: reject oversized nested action attrs&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:53330</guid>
    </item>
    <item>
      <title>RLSA-2026:53330 — Important: kernel security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:53330</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: kernel&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: fsnotify: Fix ordering of iput() and watched_objects decrement (CVE-2024-53143)&lt;/p&gt;
&lt;p&gt;* kernel: shmem: fix recovery on rename failures (CVE-2025-71072)&lt;/p&gt;
&lt;p&gt;* kernel: futex: Fix UaF between futex_key_to_node_opt() and vma_replace_policy() (CVE-2026-23415)&lt;/p&gt;
&lt;p&gt;* kernel: drm/amd/display: Do not skip unrelated mode changes in DSC validation (CVE-2026-31488)&lt;/p&gt;
&lt;p&gt;* kernel: ipc: limit next_id allocation to the valid ID range (CVE-2026-52923)&lt;/p&gt;
&lt;p&gt;* kernel: mm/slab: do not limit zeroing to orig_size when only red zoning is enabled (CVE-2026-64368)&lt;/p&gt;
&lt;p&gt;* kernel: net: openvswitch: reject oversized nested action attrs (CVE-2026-64531)&lt;/p&gt;
&lt;p&gt;Bug Fix(es) and Enhancement(s):&lt;/p&gt;
&lt;p&gt;* Kernel oops after increasing max number of mac addresses of a mlx5 VF [rhel-10.2.z] (JIRA:Rocky Linux-213035)&lt;/p&gt;
&lt;p&gt;* Rocky Linux10.0 - s390/pkey: Check length in PKEY_VERIFYPROTK ioctl [rhel-10.2.z] (JIRA:Rocky Linux-222503)&lt;/p&gt;
&lt;p&gt;* Rocky Linux10.0 - s390/pkey: Check length in pkey_pckmo handler implementation [rhel-10.2.z] (JIRA:Rocky Linux-222505)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: kernel&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: fsnotify: Fix ordering of iput() and watched_objects decrement (CVE-2024-53143)&lt;/p&gt;
&lt;p&gt;* kernel: shmem: fix recovery on rename failures (CVE-2025-71072)&lt;/p&gt;
&lt;p&gt;* kernel: futex: Fix UaF between futex_key_to_node_opt() and vma_replace_policy() (CVE-2026-23415)&lt;/p&gt;
&lt;p&gt;* kernel: drm/amd/display: Do not skip unrelated mode changes in DSC validation (CVE-2026-31488)&lt;/p&gt;
&lt;p&gt;* kernel: ipc: limit next_id allocation to the valid ID range (CVE-2026-52923)&lt;/p&gt;
&lt;p&gt;* kernel: mm/slab: do not limit zeroing to orig_size when only red zoning is enabled (CVE-2026-64368)&lt;/p&gt;
&lt;p&gt;* kernel: net: openvswitch: reject oversized nested action attrs (CVE-2026-64531)&lt;/p&gt;
&lt;p&gt;Bug Fix(es) and Enhancement(s):&lt;/p&gt;
&lt;p&gt;* Kernel oops after increasing max number of mac addresses of a mlx5 VF [rhel-10.2.z] (JIRA:Rocky Linux-213035)&lt;/p&gt;
&lt;p&gt;* Rocky Linux10.0 - s390/pkey: Check length in PKEY_VERIFYPROTK ioctl [rhel-10.2.z] (JIRA:Rocky Linux-222503)&lt;/p&gt;
&lt;p&gt;* Rocky Linux10.0 - s390/pkey: Check length in pkey_pckmo handler implementation [rhel-10.2.z] (JIRA:Rocky Linux-222505)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:53330</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2024-53143</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-53143</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 69 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: fsnotify: Fix ordering of iput() and watched_objects decrement Ensure the superblock is kept alive until we&amp;#39;re done with iput(). Holding a reference to an inode is not allowed unless we ensure the superblock stays alive, which fsnotify does by keeping the watched_objects count elevated, so iput() must happen before the watched_objects decrement. This can lead to a UAF of something like sb-&amp;gt;s_fs_info in tmpfs, but the UAF is hard to hit because race orderings that oops are more likely, thanks to the CHECK_DATA_CORRUPTION() block in generic_shutdown_super(). Also, ensure that fsnotify_put_sb_watched_objects() doesn&amp;#39;t call fsnotify_sb_watched_objects() on a superblock that may have already been freed, which would cause a UAF read of sb-&amp;gt;s_fsnotify_info.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 69 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: fsnotify: Fix ordering of iput() and watched_objects decrement Ensure the superblock is kept alive until we&amp;#39;re done with iput(). Holding a reference to an inode is not allowed unless we ensure the superblock stays alive, which fsnotify does by keeping the watched_objects count elevated, so iput() must happen before the watched_objects decrement. This can lead to a UAF of something like sb-&amp;gt;s_fs_info in tmpfs, but the UAF is hard to hit because race orderings that oops are more likely, thanks to the CHECK_DATA_CORRUPTION() block in generic_shutdown_super(). Also, ensure that fsnotify_put_sb_watched_objects() doesn&amp;#39;t call fsnotify_sb_watched_objects() on a superblock that may have already been freed, which would cause a UAF read of sb-&amp;gt;s_fsnotify_info.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-53143</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-3635 — Linux Kernel: Schwachstelle ermöglicht Denial of Service</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-3635</link>
      <description>&lt;p&gt;Ein lokaler Angreifer kann eine Schwachstelle im Linux-Kernel ausnutzen, um einen Denial-of-Service-Zustand zu erzeugen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein lokaler Angreifer kann eine Schwachstelle im Linux-Kernel ausnutzen, um einen Denial-of-Service-Zustand zu erzeugen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-3635</guid>
    </item>
  </channel>
</rss>
