<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 09:53:27 +0000</lastBuildDate>
    <item>
      <title>ALSA-2026:63013 — Important: kernel-rt security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:63013</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: kernel-rt, AlmaLinux:8: kernel-rt-core, AlmaLinux:8: kernel-rt-debug, AlmaLinux:8: kernel-rt-debug-core, AlmaLinux:8: kernel-rt-debug-devel, AlmaLinux:8: kernel-rt-debug-modules, AlmaLinux:8: kernel-rt-debug-modules-extra, AlmaLinux:8: kernel-rt-devel, AlmaLinux:8: kernel-rt-modules, AlmaLinux:8: kernel-rt-modules-extra&lt;/p&gt;
&lt;p&gt;The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: s390/cpum_sf: Handle CPU hotplug remove during sampling (CVE-2024-57849)
  * kernel: smc91x: fix broken irq-context in PREEMPT_RT (CVE-2025-71132)
  * kernel: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (CVE-2026-45970)
  * kernel: zram: fix use-after-free in zram_bvec_write_partial() (CVE-2026-53185)
  * kernel: pNFS: Fix use-after-free in pnfs_update_layout() (CVE-2026-63800)
  * kernel: nfsd: fix posix_acl leak on SETACL decode failure (CVE-2026-53397)
  * kernel: nfsd: release layout stid on setlease failure (CVE-2026-53399)
  * kernel: NFSv4/flexfiles: reject zero filehandle version count (CVE-2026-53392)
  * kernel: NFSv4/pNFS: reject zero-length r_addr in nfs4_decode_mp_ds_addr (CVE-2026-53391)
  * kernel: net: mana: validate rx_req_idx to prevent out-of-bounds array access (CVE-2026-64018)
  * kernel: Kernel: Remote out-of-bounds write in RDMA/siw (CVE-2026-64268)
  * kernel: NFSv4: include MAY_WRITE in open permission mask for O_TRUNC (CVE-2026-64298)
  * kernel: AMD-SN-7061: Safe RET Interrupt Vulnerability (CVE-2026-68480)
  * kernel: net: ipv6: use-after-free in fib6_rule_suppress due to stale res-&amp;gt;rt6 pointer (CVE-2026-74581)&lt;/p&gt;
&lt;p&gt;Bug Fix(es) and Enhancement(s):&lt;/p&gt;
&lt;p&gt;* qede: build_skb failure causes off-by-one BD ring corruption and kernel panic [almalinux-8.10.z] (JIRA:AlmaL…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: kernel-rt, AlmaLinux:8: kernel-rt-core, AlmaLinux:8: kernel-rt-debug, AlmaLinux:8: kernel-rt-debug-core, AlmaLinux:8: kernel-rt-debug-devel, AlmaLinux:8: kernel-rt-debug-modules, AlmaLinux:8: kernel-rt-debug-modules-extra, AlmaLinux:8: kernel-rt-devel, AlmaLinux:8: kernel-rt-modules, AlmaLinux:8: kernel-rt-modules-extra&lt;/p&gt;
&lt;p&gt;The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: s390/cpum_sf: Handle CPU hotplug remove during sampling (CVE-2024-57849)
  * kernel: smc91x: fix broken irq-context in PREEMPT_RT (CVE-2025-71132)
  * kernel: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (CVE-2026-45970)
  * kernel: zram: fix use-after-free in zram_bvec_write_partial() (CVE-2026-53185)
  * kernel: pNFS: Fix use-after-free in pnfs_update_layout() (CVE-2026-63800)
  * kernel: nfsd: fix posix_acl leak on SETACL decode failure (CVE-2026-53397)
  * kernel: nfsd: release layout stid on setlease failure (CVE-2026-53399)
  * kernel: NFSv4/flexfiles: reject zero filehandle version count (CVE-2026-53392)
  * kernel: NFSv4/pNFS: reject zero-length r_addr in nfs4_decode_mp_ds_addr (CVE-2026-53391)
  * kernel: net: mana: validate rx_req_idx to prevent out-of-bounds array access (CVE-2026-64018)
  * kernel: Kernel: Remote out-of-bounds write in RDMA/siw (CVE-2026-64268)
  * kernel: NFSv4: include MAY_WRITE in open permission mask for O_TRUNC (CVE-2026-64298)
  * kernel: AMD-SN-7061: Safe RET Interrupt Vulnerability (CVE-2026-68480)
  * kernel: net: ipv6: use-after-free in fib6_rule_suppress due to stale res-&amp;gt;rt6 pointer (CVE-2026-74581)&lt;/p&gt;
&lt;p&gt;Bug Fix(es) and Enhancement(s):&lt;/p&gt;
&lt;p&gt;* qede: build_skb failure causes off-by-one BD ring corruption and kernel panic [almalinux-8.10.z] (JIRA:AlmaL…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:63013</guid>
    </item>
    <item>
      <title>bdu:2025-06153</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-06153</link>
      <description>bdu:2025-06153</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-06153</guid>
    </item>
    <item>
      <title>BELL-CVE-2024-57849</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2024-57849</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2024-57849</guid>
    </item>
    <item>
      <title>certfr-2025-avi-0088 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de SUSE. Certaines d'entre elles permettent à un at…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0088</link>
      <description>certfr-2025-avi-0088</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0088</guid>
    </item>
    <item>
      <title>EUVD-2026-346548</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-346548</link>
      <description>EUVD-2026-346548</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-346548</guid>
    </item>
    <item>
      <title>fkie_cve-2024-57849</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-57849</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;s390/cpum_sf: Handle CPU hotplug remove during sampling&lt;/p&gt;
&lt;p&gt;CPU hotplug remove handling triggers the following function
call sequence:&lt;/p&gt;
&lt;p&gt;CPUHP_AP_PERF_S390_SF_ONLINE  --&amp;gt; s390_pmu_sf_offline_cpu()
   ...
   CPUHP_AP_PERF_ONLINE          --&amp;gt; perf_event_exit_cpu()&lt;/p&gt;
&lt;p&gt;The s390 CPUMF sampling CPU hotplug handler invokes:&lt;/p&gt;
&lt;p&gt;s390_pmu_sf_offline_cpu()
 +--&amp;gt;  cpusf_pmu_setup()
       +--&amp;gt; setup_pmc_cpu()
            +--&amp;gt; deallocate_buffers()&lt;/p&gt;
&lt;p&gt;This function de-allocates all sampling data buffers (SDBs) allocated
for that CPU at event initialization. It also clears the
PMU_F_RESERVED bit. The CPU is gone and can not be sampled.&lt;/p&gt;
&lt;p&gt;With the event still being active on the removed CPU, the CPU event
hotplug support in kernel performance subsystem triggers the
following function calls on the removed CPU:&lt;/p&gt;
&lt;p&gt;perf_event_exit_cpu()
  +--&amp;gt; perf_event_exit_cpu_context()
       +--&amp;gt; __perf_event_exit_context()
	    +--&amp;gt; __perf_remove_from_context()
	         +--&amp;gt; event_sched_out()
	              +--&amp;gt; cpumsf_pmu_del()
	                   +--&amp;gt; cpumsf_pmu_stop()
                                +--&amp;gt; hw_perf_event_update()&lt;/p&gt;
&lt;p&gt;to stop and remove the event. During removal of the event, the
sampling device driver tries to read out the remaining samples from
the sample data buffers (SDBs). But they have already been freed
(and may have been re-assigned). This may lead to a use after free
situation in which case the samples are most likely in…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;s390/cpum_sf: Handle CPU hotplug remove during sampling&lt;/p&gt;
&lt;p&gt;CPU hotplug remove handling triggers the following function
call sequence:&lt;/p&gt;
&lt;p&gt;CPUHP_AP_PERF_S390_SF_ONLINE  --&amp;gt; s390_pmu_sf_offline_cpu()
   ...
   CPUHP_AP_PERF_ONLINE          --&amp;gt; perf_event_exit_cpu()&lt;/p&gt;
&lt;p&gt;The s390 CPUMF sampling CPU hotplug handler invokes:&lt;/p&gt;
&lt;p&gt;s390_pmu_sf_offline_cpu()
 +--&amp;gt;  cpusf_pmu_setup()
       +--&amp;gt; setup_pmc_cpu()
            +--&amp;gt; deallocate_buffers()&lt;/p&gt;
&lt;p&gt;This function de-allocates all sampling data buffers (SDBs) allocated
for that CPU at event initialization. It also clears the
PMU_F_RESERVED bit. The CPU is gone and can not be sampled.&lt;/p&gt;
&lt;p&gt;With the event still being active on the removed CPU, the CPU event
hotplug support in kernel performance subsystem triggers the
following function calls on the removed CPU:&lt;/p&gt;
&lt;p&gt;perf_event_exit_cpu()
  +--&amp;gt; perf_event_exit_cpu_context()
       +--&amp;gt; __perf_event_exit_context()
	    +--&amp;gt; __perf_remove_from_context()
	         +--&amp;gt; event_sched_out()
	              +--&amp;gt; cpumsf_pmu_del()
	                   +--&amp;gt; cpumsf_pmu_stop()
                                +--&amp;gt; hw_perf_event_update()&lt;/p&gt;
&lt;p&gt;to stop and remove the event. During removal of the event, the
sampling device driver tries to read out the remaining samples from
the sample data buffers (SDBs). But they have already been freed
(and may have been re-assigned). This may lead to a use after free
situation in which case the samples are most likely in…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-57849</guid>
    </item>
    <item>
      <title>GHSA-q4cg-m7j8-ggr6</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-q4cg-m7j8-ggr6</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;s390/cpum_sf: Handle CPU hotplug remove during sampling&lt;/p&gt;
&lt;p&gt;CPU hotplug remove handling triggers the following function
call sequence:&lt;/p&gt;
&lt;p&gt;CPUHP_AP_PERF_S390_SF_ONLINE  --&amp;gt; s390_pmu_sf_offline_cpu()
   ...
   CPUHP_AP_PERF_ONLINE          --&amp;gt; perf_event_exit_cpu()&lt;/p&gt;
&lt;p&gt;The s390 CPUMF sampling CPU hotplug handler invokes:&lt;/p&gt;
&lt;p&gt;s390_pmu_sf_offline_cpu()
 +--&amp;gt;  cpusf_pmu_setup()
       +--&amp;gt; setup_pmc_cpu()
            +--&amp;gt; deallocate_buffers()&lt;/p&gt;
&lt;p&gt;This function de-allocates all sampling data buffers (SDBs) allocated
for that CPU at event initialization. It also clears the
PMU_F_RESERVED bit. The CPU is gone and can not be sampled.&lt;/p&gt;
&lt;p&gt;With the event still being active on the removed CPU, the CPU event
hotplug support in kernel performance subsystem triggers the
following function calls on the removed CPU:&lt;/p&gt;
&lt;p&gt;perf_event_exit_cpu()
  +--&amp;gt; perf_event_exit_cpu_context()
       +--&amp;gt; __perf_event_exit_context()
	    +--&amp;gt; __perf_remove_from_context()
	         +--&amp;gt; event_sched_out()
	              +--&amp;gt; cpumsf_pmu_del()
	                   +--&amp;gt; cpumsf_pmu_stop()
                                +--&amp;gt; hw_perf_event_update()&lt;/p&gt;
&lt;p&gt;to stop and remove the event. During removal of the event, the
sampling device driver tries to read out the remaining samples from
the sample data buffers (SDBs). But they have already been freed
(and may have been re-assigned). This may lead to a use after free
situation in which case the samples are most likely in…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;s390/cpum_sf: Handle CPU hotplug remove during sampling&lt;/p&gt;
&lt;p&gt;CPU hotplug remove handling triggers the following function
call sequence:&lt;/p&gt;
&lt;p&gt;CPUHP_AP_PERF_S390_SF_ONLINE  --&amp;gt; s390_pmu_sf_offline_cpu()
   ...
   CPUHP_AP_PERF_ONLINE          --&amp;gt; perf_event_exit_cpu()&lt;/p&gt;
&lt;p&gt;The s390 CPUMF sampling CPU hotplug handler invokes:&lt;/p&gt;
&lt;p&gt;s390_pmu_sf_offline_cpu()
 +--&amp;gt;  cpusf_pmu_setup()
       +--&amp;gt; setup_pmc_cpu()
            +--&amp;gt; deallocate_buffers()&lt;/p&gt;
&lt;p&gt;This function de-allocates all sampling data buffers (SDBs) allocated
for that CPU at event initialization. It also clears the
PMU_F_RESERVED bit. The CPU is gone and can not be sampled.&lt;/p&gt;
&lt;p&gt;With the event still being active on the removed CPU, the CPU event
hotplug support in kernel performance subsystem triggers the
following function calls on the removed CPU:&lt;/p&gt;
&lt;p&gt;perf_event_exit_cpu()
  +--&amp;gt; perf_event_exit_cpu_context()
       +--&amp;gt; __perf_event_exit_context()
	    +--&amp;gt; __perf_remove_from_context()
	         +--&amp;gt; event_sched_out()
	              +--&amp;gt; cpumsf_pmu_del()
	                   +--&amp;gt; cpumsf_pmu_stop()
                                +--&amp;gt; hw_perf_event_update()&lt;/p&gt;
&lt;p&gt;to stop and remove the event. During removal of the event, the
sampling device driver tries to read out the remaining samples from
the sample data buffers (SDBs). But they have already been freed
(and may have been re-assigned). This may lead to a use after free
situation in which case the samples are most likely in…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-q4cg-m7j8-ggr6</guid>
    </item>
    <item>
      <title>OESA-2025-1158 — kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2025-1158</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP4: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;ila: call nf_unregister_net_hooks() sooner&lt;/p&gt;
&lt;p&gt;syzbot found an use-after-free Read in ila_nf_input [1]&lt;/p&gt;
&lt;p&gt;Issue here is that ila_xlat_exit_net() frees the rhashtable,
then call nf_unregister_net_hooks().&lt;/p&gt;
&lt;p&gt;It should be done in the reverse way, with a synchronize_rcu().&lt;/p&gt;
&lt;p&gt;This is a good match for a pre_exit() method.&lt;/p&gt;
&lt;p&gt;[1]
 BUG: KASAN: use-after-free in rht_key_hashfn include/linux/rhashtable.h:159 [inline]
 BUG: KASAN: use-after-free in __rhashtable_lookup include/linux/rhashtable.h:604 [inline]
 BUG: KASAN: use-after-free in rhashtable_lookup include/linux/rhashtable.h:646 [inline]
 BUG: KASAN: use-after-free in rhashtable_lookup_fast+0x77a/0x9b0 include/linux/rhashtable.h:672
Read of size 4 at addr ffff888064620008 by task ksoftirqd/0/16&lt;/p&gt;
&lt;p&gt;CPU: 0 UID: 0 PID: 16 Comm: ksoftirqd/0 Not tainted 6.11.0-rc4-syzkaller-00238-g2ad6d23f465a #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 08/06/2024
Call Trace:
 &amp;amp;lt;TASK&amp;amp;gt;
  __dump_stack lib/dump_stack.c:93 [inline]
  dump_stack_lvl+0x241/0x360 lib/dump_stack.c:119
  print_address_description mm/kasan/report.c:377 [inline]
  print_report+0x169/0x550 mm/kasan/report.c:488
  kasan_report+0x143/0x180 mm/kasan/report.c:601
  rht_key_hashfn include/linux/rhashtable.h:159 [inline]
  __rhashtable_lookup include/linux/rhashtable.h:604 [inline]
  rhashtable_lookup include/lin…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP4: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;ila: call nf_unregister_net_hooks() sooner&lt;/p&gt;
&lt;p&gt;syzbot found an use-after-free Read in ila_nf_input [1]&lt;/p&gt;
&lt;p&gt;Issue here is that ila_xlat_exit_net() frees the rhashtable,
then call nf_unregister_net_hooks().&lt;/p&gt;
&lt;p&gt;It should be done in the reverse way, with a synchronize_rcu().&lt;/p&gt;
&lt;p&gt;This is a good match for a pre_exit() method.&lt;/p&gt;
&lt;p&gt;[1]
 BUG: KASAN: use-after-free in rht_key_hashfn include/linux/rhashtable.h:159 [inline]
 BUG: KASAN: use-after-free in __rhashtable_lookup include/linux/rhashtable.h:604 [inline]
 BUG: KASAN: use-after-free in rhashtable_lookup include/linux/rhashtable.h:646 [inline]
 BUG: KASAN: use-after-free in rhashtable_lookup_fast+0x77a/0x9b0 include/linux/rhashtable.h:672
Read of size 4 at addr ffff888064620008 by task ksoftirqd/0/16&lt;/p&gt;
&lt;p&gt;CPU: 0 UID: 0 PID: 16 Comm: ksoftirqd/0 Not tainted 6.11.0-rc4-syzkaller-00238-g2ad6d23f465a #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 08/06/2024
Call Trace:
 &amp;amp;lt;TASK&amp;amp;gt;
  __dump_stack lib/dump_stack.c:93 [inline]
  dump_stack_lvl+0x241/0x360 lib/dump_stack.c:119
  print_address_description mm/kasan/report.c:377 [inline]
  print_report+0x169/0x550 mm/kasan/report.c:488
  kasan_report+0x143/0x180 mm/kasan/report.c:601
  rht_key_hashfn include/linux/rhashtable.h:159 [inline]
  __rhashtable_lookup include/linux/rhashtable.h:604 [inline]
  rhashtable_lookup include/lin…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2025-1158</guid>
    </item>
    <item>
      <title>RHSA-2026:63013 — Red Hat Security Advisory: kernel-rt security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:63013</link>
      <description>&lt;p&gt;kernel: s390/cpum_sf: Handle CPU hotplug remove during sampling kernel: smc91x: fix broken irq-context in PREEMPT_RT kernel: bonding: alb: fix UAF in rlb_arp_recv during bond up/down kernel: zram: fix use-after-free in zram_bvec_write_partial() kernel: NFSv4/pNFS: reject zero-length r_addr in nfs4_decode_mp_ds_addr kernel: NFSv4/flexfiles: reject zero filehandle version count kernel: nfsd: fix posix_acl leak on SETACL decode failure kernel: nfsd: release layout stid on setlease failure kernel: pNFS: Fix use-after-free in pnfs_update_layout() kernel: net: mana: validate rx_req_idx to prevent out-of-bounds array access kernel: Kernel: Remote out-of-bounds write in RDMA/siw kernel: NFSv4: include MAY_WRITE in open permission mask for O_TRUNC kernel: AMD-SN-7061: Safe RET Interrupt Vulnerability kernel: net: ipv6: use-after-free in fib6_rule_suppress due to stale res-&amp;gt;rt6 pointer&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;kernel: s390/cpum_sf: Handle CPU hotplug remove during sampling kernel: smc91x: fix broken irq-context in PREEMPT_RT kernel: bonding: alb: fix UAF in rlb_arp_recv during bond up/down kernel: zram: fix use-after-free in zram_bvec_write_partial() kernel: NFSv4/pNFS: reject zero-length r_addr in nfs4_decode_mp_ds_addr kernel: NFSv4/flexfiles: reject zero filehandle version count kernel: nfsd: fix posix_acl leak on SETACL decode failure kernel: nfsd: release layout stid on setlease failure kernel: pNFS: Fix use-after-free in pnfs_update_layout() kernel: net: mana: validate rx_req_idx to prevent out-of-bounds array access kernel: Kernel: Remote out-of-bounds write in RDMA/siw kernel: NFSv4: include MAY_WRITE in open permission mask for O_TRUNC kernel: AMD-SN-7061: Safe RET Interrupt Vulnerability kernel: net: ipv6: use-after-free in fib6_rule_suppress due to stale res-&amp;gt;rt6 pointer&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:63013</guid>
    </item>
    <item>
      <title>RHSA-2026:63014 — Red Hat Security Advisory: kernel security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:63014</link>
      <description>&lt;p&gt;kernel: s390/cpum_sf: Handle CPU hotplug remove during sampling kernel: smc91x: fix broken irq-context in PREEMPT_RT kernel: bonding: alb: fix UAF in rlb_arp_recv during bond up/down kernel: zram: fix use-after-free in zram_bvec_write_partial() kernel: NFSv4/pNFS: reject zero-length r_addr in nfs4_decode_mp_ds_addr kernel: NFSv4/flexfiles: reject zero filehandle version count kernel: nfsd: fix posix_acl leak on SETACL decode failure kernel: nfsd: release layout stid on setlease failure kernel: pNFS: Fix use-after-free in pnfs_update_layout() kernel: net: mana: validate rx_req_idx to prevent out-of-bounds array access kernel: Kernel: Remote out-of-bounds write in RDMA/siw kernel: NFSv4: include MAY_WRITE in open permission mask for O_TRUNC kernel: AMD-SN-7061: Safe RET Interrupt Vulnerability kernel: net: ipv6: use-after-free in fib6_rule_suppress due to stale res-&amp;gt;rt6 pointer&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;kernel: s390/cpum_sf: Handle CPU hotplug remove during sampling kernel: smc91x: fix broken irq-context in PREEMPT_RT kernel: bonding: alb: fix UAF in rlb_arp_recv during bond up/down kernel: zram: fix use-after-free in zram_bvec_write_partial() kernel: NFSv4/pNFS: reject zero-length r_addr in nfs4_decode_mp_ds_addr kernel: NFSv4/flexfiles: reject zero filehandle version count kernel: nfsd: fix posix_acl leak on SETACL decode failure kernel: nfsd: release layout stid on setlease failure kernel: pNFS: Fix use-after-free in pnfs_update_layout() kernel: net: mana: validate rx_req_idx to prevent out-of-bounds array access kernel: Kernel: Remote out-of-bounds write in RDMA/siw kernel: NFSv4: include MAY_WRITE in open permission mask for O_TRUNC kernel: AMD-SN-7061: Safe RET Interrupt Vulnerability kernel: net: ipv6: use-after-free in fib6_rule_suppress due to stale res-&amp;gt;rt6 pointer&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:63014</guid>
    </item>
    <item>
      <title>RLSA-2026:63013 — Important: kernel-rt security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:63013</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:8: kernel-rt&lt;/p&gt;
&lt;p&gt;The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: s390/cpum_sf: Handle CPU hotplug remove during sampling (CVE-2024-57849)&lt;/p&gt;
&lt;p&gt;* kernel: smc91x: fix broken irq-context in PREEMPT_RT (CVE-2025-71132)&lt;/p&gt;
&lt;p&gt;* kernel: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (CVE-2026-45970)&lt;/p&gt;
&lt;p&gt;* kernel: zram: fix use-after-free in zram_bvec_write_partial() (CVE-2026-53185)&lt;/p&gt;
&lt;p&gt;* kernel: pNFS: Fix use-after-free in pnfs_update_layout() (CVE-2026-63800)&lt;/p&gt;
&lt;p&gt;* kernel: nfsd: fix posix_acl leak on SETACL decode failure (CVE-2026-53397)&lt;/p&gt;
&lt;p&gt;* kernel: nfsd: release layout stid on setlease failure (CVE-2026-53399)&lt;/p&gt;
&lt;p&gt;* kernel: NFSv4/flexfiles: reject zero filehandle version count (CVE-2026-53392)&lt;/p&gt;
&lt;p&gt;* kernel: NFSv4/pNFS: reject zero-length r_addr in nfs4_decode_mp_ds_addr (CVE-2026-53391)&lt;/p&gt;
&lt;p&gt;* kernel: net: mana: validate rx_req_idx to prevent out-of-bounds array access (CVE-2026-64018)&lt;/p&gt;
&lt;p&gt;* kernel: Kernel: Remote out-of-bounds write in RDMA/siw (CVE-2026-64268)&lt;/p&gt;
&lt;p&gt;* kernel: NFSv4: include MAY_WRITE in open permission mask for O_TRUNC (CVE-2026-64298)&lt;/p&gt;
&lt;p&gt;* kernel: AMD-SN-7061: Safe RET Interrupt Vulnerability (CVE-2026-68480)&lt;/p&gt;
&lt;p&gt;* kernel: net: ipv6: use-after-free in fib6_rule_suppress due to stale res-&amp;gt;rt6 pointer (CVE-2026-74581)&lt;/p&gt;
&lt;p&gt;Bug Fix(es) and Enhancement(s):&lt;/p&gt;
&lt;p&gt;* qede: build_skb failure causes off-by-one BD ring corruption and kernel panic [rhel-8.10.z] (JIRA:Rocky Linux-193045)&lt;/p&gt;
&lt;p&gt;* powerpc/pse…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:8: kernel-rt&lt;/p&gt;
&lt;p&gt;The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: s390/cpum_sf: Handle CPU hotplug remove during sampling (CVE-2024-57849)&lt;/p&gt;
&lt;p&gt;* kernel: smc91x: fix broken irq-context in PREEMPT_RT (CVE-2025-71132)&lt;/p&gt;
&lt;p&gt;* kernel: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (CVE-2026-45970)&lt;/p&gt;
&lt;p&gt;* kernel: zram: fix use-after-free in zram_bvec_write_partial() (CVE-2026-53185)&lt;/p&gt;
&lt;p&gt;* kernel: pNFS: Fix use-after-free in pnfs_update_layout() (CVE-2026-63800)&lt;/p&gt;
&lt;p&gt;* kernel: nfsd: fix posix_acl leak on SETACL decode failure (CVE-2026-53397)&lt;/p&gt;
&lt;p&gt;* kernel: nfsd: release layout stid on setlease failure (CVE-2026-53399)&lt;/p&gt;
&lt;p&gt;* kernel: NFSv4/flexfiles: reject zero filehandle version count (CVE-2026-53392)&lt;/p&gt;
&lt;p&gt;* kernel: NFSv4/pNFS: reject zero-length r_addr in nfs4_decode_mp_ds_addr (CVE-2026-53391)&lt;/p&gt;
&lt;p&gt;* kernel: net: mana: validate rx_req_idx to prevent out-of-bounds array access (CVE-2026-64018)&lt;/p&gt;
&lt;p&gt;* kernel: Kernel: Remote out-of-bounds write in RDMA/siw (CVE-2026-64268)&lt;/p&gt;
&lt;p&gt;* kernel: NFSv4: include MAY_WRITE in open permission mask for O_TRUNC (CVE-2026-64298)&lt;/p&gt;
&lt;p&gt;* kernel: AMD-SN-7061: Safe RET Interrupt Vulnerability (CVE-2026-68480)&lt;/p&gt;
&lt;p&gt;* kernel: net: ipv6: use-after-free in fib6_rule_suppress due to stale res-&amp;gt;rt6 pointer (CVE-2026-74581)&lt;/p&gt;
&lt;p&gt;Bug Fix(es) and Enhancement(s):&lt;/p&gt;
&lt;p&gt;* qede: build_skb failure causes off-by-one BD ring corruption and kernel panic [rhel-8.10.z] (JIRA:Rocky Linux-193045)&lt;/p&gt;
&lt;p&gt;* powerpc/pse…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:63013</guid>
    </item>
    <item>
      <title>SUSE-SU-2025:0236-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2025:0236-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2025:0236-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2024-57849</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-57849</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe, Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:Pro:16.04:LTS: linux-oracle, Ubuntu:Pro:18.04:LTS: linux, Ubuntu:Pro:18.04:LTS: linux-aws, Ubuntu:18.04:LTS: linux-aws-5.0 and 188 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: s390/cpum_sf: Handle CPU hotplug remove during sampling CPU hotplug remove handling triggers the following function call sequence:    CPUHP_AP_PERF_S390_SF_ONLINE  --&amp;gt; s390_pmu_sf_offline_cpu()    ...    CPUHP_AP_PERF_ONLINE          --&amp;gt; perf_event_exit_cpu() The s390 CPUMF sampling CPU hotplug handler invokes:  s390_pmu_sf_offline_cpu()  +--&amp;gt;  cpusf_pmu_setup()        +--&amp;gt; setup_pmc_cpu()             +--&amp;gt; deallocate_buffers() This function de-allocates all sampling data buffers (SDBs) allocated for that CPU at event initialization. It also clears the PMU_F_RESERVED bit. The CPU is gone and can not be sampled. With the event still being active on the removed CPU, the CPU event hotplug support in kernel performance subsystem triggers the following function calls on the removed CPU:   perf_event_exit_cpu()   +--&amp;gt; perf_event_exit_cpu_context()        +--&amp;gt; __perf_event_exit_context() 	    +--&amp;gt; __perf_remove_from_context() 	         +--&amp;gt; event_sched_out() 	              +--&amp;gt; cpumsf_pmu_del() 	                   +--&amp;gt; cpumsf_pmu_stop()                                 +--&amp;gt; hw_perf_event_update() to stop and remove the event. During removal of the event, the sampling device driver tries to read out the remaining samples from the sample data buffers (SDBs). But they have already been freed (and may have been re-assigned). This may lead to a use after free situation in which case the samples are most likely invalid. In…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe, Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:Pro:16.04:LTS: linux-oracle, Ubuntu:Pro:18.04:LTS: linux, Ubuntu:Pro:18.04:LTS: linux-aws, Ubuntu:18.04:LTS: linux-aws-5.0 and 188 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: s390/cpum_sf: Handle CPU hotplug remove during sampling CPU hotplug remove handling triggers the following function call sequence:    CPUHP_AP_PERF_S390_SF_ONLINE  --&amp;gt; s390_pmu_sf_offline_cpu()    ...    CPUHP_AP_PERF_ONLINE          --&amp;gt; perf_event_exit_cpu() The s390 CPUMF sampling CPU hotplug handler invokes:  s390_pmu_sf_offline_cpu()  +--&amp;gt;  cpusf_pmu_setup()        +--&amp;gt; setup_pmc_cpu()             +--&amp;gt; deallocate_buffers() This function de-allocates all sampling data buffers (SDBs) allocated for that CPU at event initialization. It also clears the PMU_F_RESERVED bit. The CPU is gone and can not be sampled. With the event still being active on the removed CPU, the CPU event hotplug support in kernel performance subsystem triggers the following function calls on the removed CPU:   perf_event_exit_cpu()   +--&amp;gt; perf_event_exit_cpu_context()        +--&amp;gt; __perf_event_exit_context() 	    +--&amp;gt; __perf_remove_from_context() 	         +--&amp;gt; event_sched_out() 	              +--&amp;gt; cpumsf_pmu_del() 	                   +--&amp;gt; cpumsf_pmu_stop()                                 +--&amp;gt; hw_perf_event_update() to stop and remove the event. During removal of the event, the sampling device driver tries to read out the remaining samples from the sample data buffers (SDBs). But they have already been freed (and may have been re-assigned). This may lead to a use after free situation in which case the samples are most likely invalid. In…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-57849</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-0047 — Linux Kernel: Mehrere Schwachstellen ermöglichen Denial of Service</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0047</link>
      <description>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen im Linux-Kernel ausnutzen, um einen Denial-of-Service-Zustand zu erzeugen und weitere nicht spezifizierte Angriffe zu starten.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen im Linux-Kernel ausnutzen, um einen Denial-of-Service-Zustand zu erzeugen und weitere nicht spezifizierte Angriffe zu starten.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0047</guid>
    </item>
  </channel>
</rss>
