<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 17:33:29 +0000</lastBuildDate>
    <item>
      <title>ALSA-2026:47040 — Important: kernel security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:47040</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: kernel, AlmaLinux:9: kernel-64k, AlmaLinux:9: kernel-64k-core, AlmaLinux:9: kernel-64k-debug, AlmaLinux:9: kernel-64k-debug-core, AlmaLinux:9: kernel-64k-debug-devel, AlmaLinux:9: kernel-64k-debug-devel-matched, AlmaLinux:9: kernel-64k-debug-modules, AlmaLinux:9: kernel-64k-debug-modules-core, AlmaLinux:9: kernel-64k-debug-modules-extra and 64 more&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: xfrm: Duplicate SPI Handling (CVE-2025-39797)
  * kernel: lib/buildid: use __kernel_read() for sleepable context (CVE-2026-23002)
  * kernel: futex: Drop CLONE_THREAD requirement for private default hash alloc (CVE-2026-52973)
  * kernel: iommu/vt-d: Avoid NULL pointer dereference or refcount corruption (CVE-2026-53281)
  * kernel: blk-mq: pop cached request if it is usable (CVE-2026-64017)&lt;/p&gt;
&lt;p&gt;Bug Fix(es) and Enhancement(s):&lt;/p&gt;
&lt;p&gt;* general protection fault during exportfs / nfsd4_revoke_states [almalinux-9.8.z] (JIRA:AlmaLinux-188257)
  * Enable Pretimeout Watchdog Panic Functionality on x86 [almalinux-9.8.z] (JIRA:AlmaLinux-193729)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: kernel, AlmaLinux:9: kernel-64k, AlmaLinux:9: kernel-64k-core, AlmaLinux:9: kernel-64k-debug, AlmaLinux:9: kernel-64k-debug-core, AlmaLinux:9: kernel-64k-debug-devel, AlmaLinux:9: kernel-64k-debug-devel-matched, AlmaLinux:9: kernel-64k-debug-modules, AlmaLinux:9: kernel-64k-debug-modules-core, AlmaLinux:9: kernel-64k-debug-modules-extra and 64 more&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: xfrm: Duplicate SPI Handling (CVE-2025-39797)
  * kernel: lib/buildid: use __kernel_read() for sleepable context (CVE-2026-23002)
  * kernel: futex: Drop CLONE_THREAD requirement for private default hash alloc (CVE-2026-52973)
  * kernel: iommu/vt-d: Avoid NULL pointer dereference or refcount corruption (CVE-2026-53281)
  * kernel: blk-mq: pop cached request if it is usable (CVE-2026-64017)&lt;/p&gt;
&lt;p&gt;Bug Fix(es) and Enhancement(s):&lt;/p&gt;
&lt;p&gt;* general protection fault during exportfs / nfsd4_revoke_states [almalinux-9.8.z] (JIRA:AlmaLinux-188257)
  * Enable Pretimeout Watchdog Panic Functionality on x86 [almalinux-9.8.z] (JIRA:AlmaLinux-193729)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:47040</guid>
    </item>
    <item>
      <title>bdu:2026-02247</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-02247</link>
      <description>bdu:2026-02247</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-02247</guid>
    </item>
    <item>
      <title>BELL-CVE-2025-39797</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2025-39797</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2025-39797</guid>
    </item>
    <item>
      <title>certfr-2025-avi-0895 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de SUSE. Certaines d'entre elles permettent à un at…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0895</link>
      <description>certfr-2025-avi-0895</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0895</guid>
    </item>
    <item>
      <title>EUVD-2026-314771</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-314771</link>
      <description>EUVD-2026-314771</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-314771</guid>
    </item>
    <item>
      <title>fkie_cve-2025-39797</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-39797</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;xfrm: Duplicate SPI Handling&lt;/p&gt;
&lt;p&gt;The issue originates when Strongswan initiates an XFRM_MSG_ALLOCSPI
Netlink message, which triggers the kernel function xfrm_alloc_spi().
This function is expected to ensure uniqueness of the Security Parameter
Index (SPI) for inbound Security Associations (SAs). However, it can
return success even when the requested SPI is already in use, leading
to duplicate SPIs assigned to multiple inbound SAs, differentiated
only by their destination addresses.&lt;/p&gt;
&lt;p&gt;This behavior causes inconsistencies during SPI lookups for inbound packets.
Since the lookup may return an arbitrary SA among those with the same SPI,
packet processing can fail, resulting in packet drops.&lt;/p&gt;
&lt;p&gt;According to RFC 4301 section 4.4.2 , for inbound processing a unicast SA
is uniquely identified by the SPI and optionally protocol.&lt;/p&gt;
&lt;p&gt;Reproducing the Issue Reliably:
To consistently reproduce the problem, restrict the available SPI range in
charon.conf : spi_min = 0x10000000 spi_max = 0x10000002
This limits the system to only 2 usable SPI values.
Next, create more than 2 Child SA. each using unique pair of src/dst address.
As soon as the 3rd Child SA is initiated, it will be assigned a duplicate
SPI, since the SPI pool is already exhausted.
With a narrow SPI range, the issue is consistently reproducible.
With a broader/default range, it becomes rare and unpredictable.&lt;/p&gt;
&lt;p&gt;Current implementation:
xfrm_spi_hash() lookup function com…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;xfrm: Duplicate SPI Handling&lt;/p&gt;
&lt;p&gt;The issue originates when Strongswan initiates an XFRM_MSG_ALLOCSPI
Netlink message, which triggers the kernel function xfrm_alloc_spi().
This function is expected to ensure uniqueness of the Security Parameter
Index (SPI) for inbound Security Associations (SAs). However, it can
return success even when the requested SPI is already in use, leading
to duplicate SPIs assigned to multiple inbound SAs, differentiated
only by their destination addresses.&lt;/p&gt;
&lt;p&gt;This behavior causes inconsistencies during SPI lookups for inbound packets.
Since the lookup may return an arbitrary SA among those with the same SPI,
packet processing can fail, resulting in packet drops.&lt;/p&gt;
&lt;p&gt;According to RFC 4301 section 4.4.2 , for inbound processing a unicast SA
is uniquely identified by the SPI and optionally protocol.&lt;/p&gt;
&lt;p&gt;Reproducing the Issue Reliably:
To consistently reproduce the problem, restrict the available SPI range in
charon.conf : spi_min = 0x10000000 spi_max = 0x10000002
This limits the system to only 2 usable SPI values.
Next, create more than 2 Child SA. each using unique pair of src/dst address.
As soon as the 3rd Child SA is initiated, it will be assigned a duplicate
SPI, since the SPI pool is already exhausted.
With a narrow SPI range, the issue is consistently reproducible.
With a broader/default range, it becomes rare and unpredictable.&lt;/p&gt;
&lt;p&gt;Current implementation:
xfrm_spi_hash() lookup function com…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-39797</guid>
    </item>
    <item>
      <title>GHSA-p94f-8hph-rvrp</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-p94f-8hph-rvrp</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;xfrm: Duplicate SPI Handling&lt;/p&gt;
&lt;p&gt;The issue originates when Strongswan initiates an XFRM_MSG_ALLOCSPI
Netlink message, which triggers the kernel function xfrm_alloc_spi().
This function is expected to ensure uniqueness of the Security Parameter
Index (SPI) for inbound Security Associations (SAs). However, it can
return success even when the requested SPI is already in use, leading
to duplicate SPIs assigned to multiple inbound SAs, differentiated
only by their destination addresses.&lt;/p&gt;
&lt;p&gt;This behavior causes inconsistencies during SPI lookups for inbound packets.
Since the lookup may return an arbitrary SA among those with the same SPI,
packet processing can fail, resulting in packet drops.&lt;/p&gt;
&lt;p&gt;According to RFC 4301 section 4.4.2 , for inbound processing a unicast SA
is uniquely identified by the SPI and optionally protocol.&lt;/p&gt;
&lt;p&gt;Reproducing the Issue Reliably:
To consistently reproduce the problem, restrict the available SPI range in
charon.conf : spi_min = 0x10000000 spi_max = 0x10000002
This limits the system to only 2 usable SPI values.
Next, create more than 2 Child SA. each using unique pair of src/dst address.
As soon as the 3rd Child SA is initiated, it will be assigned a duplicate
SPI, since the SPI pool is already exhausted.
With a narrow SPI range, the issue is consistently reproducible.
With a broader/default range, it becomes rare and unpredictable.&lt;/p&gt;
&lt;p&gt;Current implementation:
xfrm_spi_hash() lookup function com…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;xfrm: Duplicate SPI Handling&lt;/p&gt;
&lt;p&gt;The issue originates when Strongswan initiates an XFRM_MSG_ALLOCSPI
Netlink message, which triggers the kernel function xfrm_alloc_spi().
This function is expected to ensure uniqueness of the Security Parameter
Index (SPI) for inbound Security Associations (SAs). However, it can
return success even when the requested SPI is already in use, leading
to duplicate SPIs assigned to multiple inbound SAs, differentiated
only by their destination addresses.&lt;/p&gt;
&lt;p&gt;This behavior causes inconsistencies during SPI lookups for inbound packets.
Since the lookup may return an arbitrary SA among those with the same SPI,
packet processing can fail, resulting in packet drops.&lt;/p&gt;
&lt;p&gt;According to RFC 4301 section 4.4.2 , for inbound processing a unicast SA
is uniquely identified by the SPI and optionally protocol.&lt;/p&gt;
&lt;p&gt;Reproducing the Issue Reliably:
To consistently reproduce the problem, restrict the available SPI range in
charon.conf : spi_min = 0x10000000 spi_max = 0x10000002
This limits the system to only 2 usable SPI values.
Next, create more than 2 Child SA. each using unique pair of src/dst address.
As soon as the 3rd Child SA is initiated, it will be assigned a duplicate
SPI, since the SPI pool is already exhausted.
With a narrow SPI range, the issue is consistently reproducible.
With a broader/default range, it becomes rare and unpredictable.&lt;/p&gt;
&lt;p&gt;Current implementation:
xfrm_spi_hash() lookup function com…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-p94f-8hph-rvrp</guid>
    </item>
    <item>
      <title>msrc_CVE-2025-39797 — xfrm: Duplicate SPI Handling</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2025-39797</link>
      <description>msrc_CVE-2025-39797</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2025-39797</guid>
    </item>
    <item>
      <title>OESA-2026-1341 — kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-1341</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP4: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:kernel/resource: fix kfree() of bootmem memory againSince commit ebff7d8f270d ( mem hotunplug: fix kfree() of bootmemmemory ), we could get a resource allocated during boot viaalloc_resource().  And it s required to release the resource usingfree_resource().  Howerver, many people use kfree directly which willresult in kernel BUG.  In order to fix this without fixing every callsite, just leak a couple of bytes in such corner case.(CVE-2022-49190)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:drivers: staging: rtl8723bs: Fix deadlock in rtw_surveydone_event_callback()There is a deadlock in rtw_surveydone_event_callback(),which is shown below:   (Thread 1)                  |      (Thread 2)                               | _set_timer()rtw_surveydone_event_callback()|  mod_timer() spin_lock_bh() //(1)          |  (wait a time) ...                           | rtw_scan_timeout_handler() del_timer_sync()              |  spin_lock_bh() //(2) (wait timer to stop)          |  ...We hold pmlmepriv-&amp;amp;gt;lock in position (1) of thread 1 and usedel_timer_sync() to wait timer to stop, but timer handleralso need pmlmepriv-&amp;amp;gt;lock in position (2) of thread 2.As a result, rtw_surveydone_event_callback() will block forever.This patch extracts del_timer_sync() from the protection ofspin_lock_bh(), which could let timer handler to obta…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP4: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:kernel/resource: fix kfree() of bootmem memory againSince commit ebff7d8f270d ( mem hotunplug: fix kfree() of bootmemmemory ), we could get a resource allocated during boot viaalloc_resource().  And it s required to release the resource usingfree_resource().  Howerver, many people use kfree directly which willresult in kernel BUG.  In order to fix this without fixing every callsite, just leak a couple of bytes in such corner case.(CVE-2022-49190)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:drivers: staging: rtl8723bs: Fix deadlock in rtw_surveydone_event_callback()There is a deadlock in rtw_surveydone_event_callback(),which is shown below:   (Thread 1)                  |      (Thread 2)                               | _set_timer()rtw_surveydone_event_callback()|  mod_timer() spin_lock_bh() //(1)          |  (wait a time) ...                           | rtw_scan_timeout_handler() del_timer_sync()              |  spin_lock_bh() //(2) (wait timer to stop)          |  ...We hold pmlmepriv-&amp;amp;gt;lock in position (1) of thread 1 and usedel_timer_sync() to wait timer to stop, but timer handleralso need pmlmepriv-&amp;amp;gt;lock in position (2) of thread 2.As a result, rtw_surveydone_event_callback() will block forever.This patch extracts del_timer_sync() from the protection ofspin_lock_bh(), which could let timer handler to obta…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-1341</guid>
    </item>
    <item>
      <title>openSUSE-SU-2025:20081-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2025:20081-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2025:20081-1</guid>
    </item>
    <item>
      <title>RHSA-2026:18134 — Red Hat Security Advisory: kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:18134</link>
      <description>&lt;p&gt;kernel: tcp_bpf: Fix the sk_mem_uncharge logic in tcp_bpf_sendmsg kernel: KVM: x86: Load DR6 with guest value only before entering .vcpu_run() loop kernel: ceph: kernel: Ceph: exploit of hardcoded IVECs, in a misuse of AES, resulting in authentication bypass kernel: block: fix resource leak in blk_register_queue() error path kernel: dmaengine: idxd: fix memory leak in error handling path of idxd_alloc kernel: espintcp: remove encap socket caching to avoid reference leak kernel: bpf: fix ktls panic with sockmap kernel: bpf: Check rcu_read_lock_trace_held() in bpf_map_lookup_percpu_elem() kernel: ring-buffer: Do not trigger WARN_ON() due to a commit_overrun kernel: phy: qcom-qmp-usb: Fix an NULL vs IS_ERR() bug kernel: bpf: Do not include stack ptr register in precision backtracking bookkeeping kernel: ACPICA: fix acpi operand cache leak in dswstate.c kernel: ftrace: Fix UAF when lookup kallsym after ftrace disabled kernel: nvmet: fix memory leak of bio integrity kernel: netfilter: flowtable: account for Ethernet header in nf_flow_pppoe_proto() kernel: net: vlan: fix VLAN 0 refcount imbalance of toggling filtering during runtime kernel: xfrm: Duplicate SPI Handling kernel: fs: writeback: fix use-after-free in __mark_inode_dirty() kernel: PCI/AER: Avoid NULL pointer dereference in aer_ratelimit() kernel: dm: fix NULL pointer dereference in __dm_suspend() kernel: Revert &amp;#34;NFSD: Remove the cap on number of operations per NFSv4 COMPOUND&amp;#34; kernel: Linux kernel MPTCP: Privilege escala…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;kernel: tcp_bpf: Fix the sk_mem_uncharge logic in tcp_bpf_sendmsg kernel: KVM: x86: Load DR6 with guest value only before entering .vcpu_run() loop kernel: ceph: kernel: Ceph: exploit of hardcoded IVECs, in a misuse of AES, resulting in authentication bypass kernel: block: fix resource leak in blk_register_queue() error path kernel: dmaengine: idxd: fix memory leak in error handling path of idxd_alloc kernel: espintcp: remove encap socket caching to avoid reference leak kernel: bpf: fix ktls panic with sockmap kernel: bpf: Check rcu_read_lock_trace_held() in bpf_map_lookup_percpu_elem() kernel: ring-buffer: Do not trigger WARN_ON() due to a commit_overrun kernel: phy: qcom-qmp-usb: Fix an NULL vs IS_ERR() bug kernel: bpf: Do not include stack ptr register in precision backtracking bookkeeping kernel: ACPICA: fix acpi operand cache leak in dswstate.c kernel: ftrace: Fix UAF when lookup kallsym after ftrace disabled kernel: nvmet: fix memory leak of bio integrity kernel: netfilter: flowtable: account for Ethernet header in nf_flow_pppoe_proto() kernel: net: vlan: fix VLAN 0 refcount imbalance of toggling filtering during runtime kernel: xfrm: Duplicate SPI Handling kernel: fs: writeback: fix use-after-free in __mark_inode_dirty() kernel: PCI/AER: Avoid NULL pointer dereference in aer_ratelimit() kernel: dm: fix NULL pointer dereference in __dm_suspend() kernel: Revert &amp;#34;NFSD: Remove the cap on number of operations per NFSv4 COMPOUND&amp;#34; kernel: Linux kernel MPTCP: Privilege escala…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:18134</guid>
    </item>
    <item>
      <title>RLSA-2026:47040 — Important: kernel security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:47040</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:9: kernel&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: xfrm: Duplicate SPI Handling (CVE-2025-39797)&lt;/p&gt;
&lt;p&gt;* kernel: lib/buildid: use __kernel_read() for sleepable context (CVE-2026-23002)&lt;/p&gt;
&lt;p&gt;* kernel: futex: Drop CLONE_THREAD requirement for private default hash alloc (CVE-2026-52973)&lt;/p&gt;
&lt;p&gt;* kernel: iommu/vt-d: Avoid NULL pointer dereference or refcount corruption (CVE-2026-53281)&lt;/p&gt;
&lt;p&gt;* kernel: blk-mq: pop cached request if it is usable (CVE-2026-64017)&lt;/p&gt;
&lt;p&gt;Bug Fix(es) and Enhancement(s):&lt;/p&gt;
&lt;p&gt;* general protection fault during exportfs / nfsd4_revoke_states [rhel-9.8.z] (JIRA:Rocky Linux-188257)&lt;/p&gt;
&lt;p&gt;* Enable Pretimeout Watchdog Panic Functionality on x86 [rhel-9.8.z] (JIRA:Rocky Linux-193729)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:9: kernel&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: xfrm: Duplicate SPI Handling (CVE-2025-39797)&lt;/p&gt;
&lt;p&gt;* kernel: lib/buildid: use __kernel_read() for sleepable context (CVE-2026-23002)&lt;/p&gt;
&lt;p&gt;* kernel: futex: Drop CLONE_THREAD requirement for private default hash alloc (CVE-2026-52973)&lt;/p&gt;
&lt;p&gt;* kernel: iommu/vt-d: Avoid NULL pointer dereference or refcount corruption (CVE-2026-53281)&lt;/p&gt;
&lt;p&gt;* kernel: blk-mq: pop cached request if it is usable (CVE-2026-64017)&lt;/p&gt;
&lt;p&gt;Bug Fix(es) and Enhancement(s):&lt;/p&gt;
&lt;p&gt;* general protection fault during exportfs / nfsd4_revoke_states [rhel-9.8.z] (JIRA:Rocky Linux-188257)&lt;/p&gt;
&lt;p&gt;* Enable Pretimeout Watchdog Panic Functionality on x86 [rhel-9.8.z] (JIRA:Rocky Linux-193729)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:47040</guid>
    </item>
    <item>
      <title>SUSE-SU-2025:03600-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2025:03600-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2025:03600-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-39797</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-39797</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux, Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe and 216 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: xfrm: Duplicate SPI Handling The issue originates when Strongswan initiates an XFRM_MSG_ALLOCSPI Netlink message, which triggers the kernel function xfrm_alloc_spi(). This function is expected to ensure uniqueness of the Security Parameter Index (SPI) for inbound Security Associations (SAs). However, it can return success even when the requested SPI is already in use, leading to duplicate SPIs assigned to multiple inbound SAs, differentiated only by their destination addresses. This behavior causes inconsistencies during SPI lookups for inbound packets. Since the lookup may return an arbitrary SA among those with the same SPI, packet processing can fail, resulting in packet drops. According to RFC 4301 section 4.4.2 , for inbound processing a unicast SA is uniquely identified by the SPI and optionally protocol. Reproducing the Issue Reliably: To consistently reproduce the problem, restrict the available SPI range in charon.conf : spi_min = 0x10000000 spi_max = 0x10000002 This limits the system to only 2 usable SPI values. Next, create more than 2 Child SA. each using unique pair of src/dst address. As soon as the 3rd Child SA is initiated, it will be assigned a duplicate SPI, since the SPI pool is already exhausted. With a narrow SPI range, the issue is consistently reproducible. With a broader/default range, it becomes rare and unpredictable. Current implementation: xfrm_spi_hash() lookup function computes…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux, Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe and 216 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: xfrm: Duplicate SPI Handling The issue originates when Strongswan initiates an XFRM_MSG_ALLOCSPI Netlink message, which triggers the kernel function xfrm_alloc_spi(). This function is expected to ensure uniqueness of the Security Parameter Index (SPI) for inbound Security Associations (SAs). However, it can return success even when the requested SPI is already in use, leading to duplicate SPIs assigned to multiple inbound SAs, differentiated only by their destination addresses. This behavior causes inconsistencies during SPI lookups for inbound packets. Since the lookup may return an arbitrary SA among those with the same SPI, packet processing can fail, resulting in packet drops. According to RFC 4301 section 4.4.2 , for inbound processing a unicast SA is uniquely identified by the SPI and optionally protocol. Reproducing the Issue Reliably: To consistently reproduce the problem, restrict the available SPI range in charon.conf : spi_min = 0x10000000 spi_max = 0x10000002 This limits the system to only 2 usable SPI values. Next, create more than 2 Child SA. each using unique pair of src/dst address. As soon as the 3rd Child SA is initiated, it will be assigned a duplicate SPI, since the SPI pool is already exhausted. With a narrow SPI range, the issue is consistently reproducible. With a broader/default range, it becomes rare and unpredictable. Current implementation: xfrm_spi_hash() lookup function computes…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-39797</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-2051 — Linux Kernel: Mehrere Schwachstellen ermöglichen Denial of Service</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2051</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen oder andere nicht näher spezifizierte Angriffe durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen oder andere nicht näher spezifizierte Angriffe durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2051</guid>
    </item>
  </channel>
</rss>
