<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 04:05:41 +0000</lastBuildDate>
    <item>
      <title>ALSA-2026:67471 — Important: kernel security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:67471</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: kernel, AlmaLinux:10: kernel-64k, AlmaLinux:10: kernel-64k-core, AlmaLinux:10: kernel-64k-debug, AlmaLinux:10: kernel-64k-debug-core, AlmaLinux:10: kernel-64k-debug-devel, AlmaLinux:10: kernel-64k-debug-devel-matched, AlmaLinux:10: kernel-64k-debug-modules, AlmaLinux:10: kernel-64k-debug-modules-core, AlmaLinux:10: kernel-64k-debug-modules-extra and 65 more&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: tls: Use __sk_dst_get() and dst_dev_rcu() in get_netdev_for_sock() (CVE-2025-40149)
  * kernel: Linux kernel: Denial of Service in qla2xxx SCSI driver due to improper command handling after chip reset (CVE-2025-68745)
  * kernel: drm/xe: Open-code GGTT MMIO access protection (CVE-2026-23466)
  * kernel: drm/xe: always keep track of remap prev/next (CVE-2026-31479)
  * kernel: drm/amdgpu: Fix fence put before wait in amdgpu_amdkfd_submit_ib (CVE-2026-31566)
  * kernel: xfrm: hold dev ref until after transport_finish NF_HOOK (CVE-2026-31663)
  * kernel: drm/i915/gt: fix refcount underflow in intel_engine_park_heartbeat (CVE-2026-31656)
  * kernel: smb: smbdirect: introduce smbdirect_socket.recv_io.credits.available (CVE-2026-31539)
  * kernel: vhost: move vdpa group bound check to vhost_vdpa (CVE-2026-43248)
  * kernel: drm/i915: Fix potential overflow of shmem scatterlist length (CVE-2026-43368)
  * kernel: drm/amdgpu: Fix use-after-free race in VM acquire (CVE-2026-43370)
  * kernel: scsi: target: configfs: Bound snprintf() return in tg_pt_gp_members_show() (CVE-2026-46149)
  * kernel: sctp: purge outqueue on stale COOKIE-ECHO handling (CVE-2026-52924)
  * kernel: netfilter: require Ethernet MAC header before using eth_hdr() (CVE-2026-53131)
  * kernel: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing (CVE-2026-53246)
  * kernel: xfr…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: kernel, AlmaLinux:10: kernel-64k, AlmaLinux:10: kernel-64k-core, AlmaLinux:10: kernel-64k-debug, AlmaLinux:10: kernel-64k-debug-core, AlmaLinux:10: kernel-64k-debug-devel, AlmaLinux:10: kernel-64k-debug-devel-matched, AlmaLinux:10: kernel-64k-debug-modules, AlmaLinux:10: kernel-64k-debug-modules-core, AlmaLinux:10: kernel-64k-debug-modules-extra and 65 more&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: tls: Use __sk_dst_get() and dst_dev_rcu() in get_netdev_for_sock() (CVE-2025-40149)
  * kernel: Linux kernel: Denial of Service in qla2xxx SCSI driver due to improper command handling after chip reset (CVE-2025-68745)
  * kernel: drm/xe: Open-code GGTT MMIO access protection (CVE-2026-23466)
  * kernel: drm/xe: always keep track of remap prev/next (CVE-2026-31479)
  * kernel: drm/amdgpu: Fix fence put before wait in amdgpu_amdkfd_submit_ib (CVE-2026-31566)
  * kernel: xfrm: hold dev ref until after transport_finish NF_HOOK (CVE-2026-31663)
  * kernel: drm/i915/gt: fix refcount underflow in intel_engine_park_heartbeat (CVE-2026-31656)
  * kernel: smb: smbdirect: introduce smbdirect_socket.recv_io.credits.available (CVE-2026-31539)
  * kernel: vhost: move vdpa group bound check to vhost_vdpa (CVE-2026-43248)
  * kernel: drm/i915: Fix potential overflow of shmem scatterlist length (CVE-2026-43368)
  * kernel: drm/amdgpu: Fix use-after-free race in VM acquire (CVE-2026-43370)
  * kernel: scsi: target: configfs: Bound snprintf() return in tg_pt_gp_members_show() (CVE-2026-46149)
  * kernel: sctp: purge outqueue on stale COOKIE-ECHO handling (CVE-2026-52924)
  * kernel: netfilter: require Ethernet MAC header before using eth_hdr() (CVE-2026-53131)
  * kernel: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing (CVE-2026-53246)
  * kernel: xfr…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:67471</guid>
    </item>
    <item>
      <title>bdu:2025-14952</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-14952</link>
      <description>bdu:2025-14952</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-14952</guid>
    </item>
    <item>
      <title>BELL-CVE-2025-40149</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2025-40149</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2025-40149</guid>
    </item>
    <item>
      <title>certfr-2025-avi-1133 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de SUSE. Certaines d'entre elles permettent à un at…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-1133</link>
      <description>certfr-2025-avi-1133</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-1133</guid>
    </item>
    <item>
      <title>EUVD-2026-364577</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-364577</link>
      <description>EUVD-2026-364577</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-364577</guid>
    </item>
    <item>
      <title>fkie_cve-2025-40149</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-40149</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;tls: Use __sk_dst_get() and dst_dev_rcu() in get_netdev_for_sock().&lt;/p&gt;
&lt;p&gt;get_netdev_for_sock() is called during setsockopt(),
so not under RCU.&lt;/p&gt;
&lt;p&gt;Using sk_dst_get(sk)-&amp;gt;dev could trigger UAF.&lt;/p&gt;
&lt;p&gt;Let&amp;#39;s use __sk_dst_get() and dst_dev_rcu().&lt;/p&gt;
&lt;p&gt;Note that the only -&amp;gt;ndo_sk_get_lower_dev() user is
bond_sk_get_lower_dev(), which uses RCU.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;tls: Use __sk_dst_get() and dst_dev_rcu() in get_netdev_for_sock().&lt;/p&gt;
&lt;p&gt;get_netdev_for_sock() is called during setsockopt(),
so not under RCU.&lt;/p&gt;
&lt;p&gt;Using sk_dst_get(sk)-&amp;gt;dev could trigger UAF.&lt;/p&gt;
&lt;p&gt;Let&amp;#39;s use __sk_dst_get() and dst_dev_rcu().&lt;/p&gt;
&lt;p&gt;Note that the only -&amp;gt;ndo_sk_get_lower_dev() user is
bond_sk_get_lower_dev(), which uses RCU.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-40149</guid>
    </item>
    <item>
      <title>GHSA-f2w5-mmwp-c76h</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-f2w5-mmwp-c76h</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;tls: Use __sk_dst_get() and dst_dev_rcu() in get_netdev_for_sock().&lt;/p&gt;
&lt;p&gt;get_netdev_for_sock() is called during setsockopt(),
so not under RCU.&lt;/p&gt;
&lt;p&gt;Using sk_dst_get(sk)-&amp;gt;dev could trigger UAF.&lt;/p&gt;
&lt;p&gt;Let&amp;#39;s use __sk_dst_get() and dst_dev_rcu().&lt;/p&gt;
&lt;p&gt;Note that the only -&amp;gt;ndo_sk_get_lower_dev() user is
bond_sk_get_lower_dev(), which uses RCU.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;tls: Use __sk_dst_get() and dst_dev_rcu() in get_netdev_for_sock().&lt;/p&gt;
&lt;p&gt;get_netdev_for_sock() is called during setsockopt(),
so not under RCU.&lt;/p&gt;
&lt;p&gt;Using sk_dst_get(sk)-&amp;gt;dev could trigger UAF.&lt;/p&gt;
&lt;p&gt;Let&amp;#39;s use __sk_dst_get() and dst_dev_rcu().&lt;/p&gt;
&lt;p&gt;Note that the only -&amp;gt;ndo_sk_get_lower_dev() user is
bond_sk_get_lower_dev(), which uses RCU.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-f2w5-mmwp-c76h</guid>
    </item>
    <item>
      <title>ICSA-26-209-04 — Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-26-209-04</link>
      <description>&lt;p&gt;Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.6 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant).&lt;/p&gt;
&lt;p&gt;Siemens is preparing fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.6 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant).&lt;/p&gt;
&lt;p&gt;Siemens is preparing fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-26-209-04</guid>
    </item>
    <item>
      <title>msrc_CVE-2025-40149 — tls: Use __sk_dst_get() and dst_dev_rcu() in get_netdev_for_sock().</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2025-40149</link>
      <description>msrc_CVE-2025-40149</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2025-40149</guid>
    </item>
    <item>
      <title>OESA-2025-2772 — kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2025-2772</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP3: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;media: davinci: vpif: fix use-after-free on driver unbind&lt;/p&gt;
&lt;p&gt;The driver allocates and registers two platform device structures during
probe, but the devices were never deregistered on driver unbind.&lt;/p&gt;
&lt;p&gt;This results in a use-after-free on driver unbind as the device
structures were allocated using devres and would be freed by driver
core when remove() returns.&lt;/p&gt;
&lt;p&gt;Fix this by adding the missing deregistration calls to the remove()
callback and failing probe on registration errors.&lt;/p&gt;
&lt;p&gt;Note that the platform device structures must be freed using a proper
release callback to avoid leaking associated resources like device
names.(CVE-2021-47653)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;mmc: core: use sysfs_emit() instead of sprintf()&lt;/p&gt;
&lt;p&gt;sprintf() (still used in the MMC core for the sysfs output) is vulnerable
to the buffer overflow.  Use the new-fangled sysfs_emit() instead.&lt;/p&gt;
&lt;p&gt;Found by Linux Verification Center (linuxtesting.org) with the SVACE static
analysis tool.(CVE-2022-49267)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;Bluetooth: btmtksdio: fix use-after-free at btmtksdio_recv_event&lt;/p&gt;
&lt;p&gt;We should not access skb buffer data anymore after hci_recv_frame was
called.&lt;/p&gt;
&lt;p&gt;[   39.634809] BUG: KASAN: use-after-free in btmtksdio_recv_event+0x1b0
[   39.634855] Read of size 1 at addr ffffff80cf28a60d by tas…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP3: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;media: davinci: vpif: fix use-after-free on driver unbind&lt;/p&gt;
&lt;p&gt;The driver allocates and registers two platform device structures during
probe, but the devices were never deregistered on driver unbind.&lt;/p&gt;
&lt;p&gt;This results in a use-after-free on driver unbind as the device
structures were allocated using devres and would be freed by driver
core when remove() returns.&lt;/p&gt;
&lt;p&gt;Fix this by adding the missing deregistration calls to the remove()
callback and failing probe on registration errors.&lt;/p&gt;
&lt;p&gt;Note that the platform device structures must be freed using a proper
release callback to avoid leaking associated resources like device
names.(CVE-2021-47653)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;mmc: core: use sysfs_emit() instead of sprintf()&lt;/p&gt;
&lt;p&gt;sprintf() (still used in the MMC core for the sysfs output) is vulnerable
to the buffer overflow.  Use the new-fangled sysfs_emit() instead.&lt;/p&gt;
&lt;p&gt;Found by Linux Verification Center (linuxtesting.org) with the SVACE static
analysis tool.(CVE-2022-49267)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;Bluetooth: btmtksdio: fix use-after-free at btmtksdio_recv_event&lt;/p&gt;
&lt;p&gt;We should not access skb buffer data anymore after hci_recv_frame was
called.&lt;/p&gt;
&lt;p&gt;[   39.634809] BUG: KASAN: use-after-free in btmtksdio_recv_event+0x1b0
[   39.634855] Read of size 1 at addr ffffff80cf28a60d by tas…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2025-2772</guid>
    </item>
    <item>
      <title>openSUSE-SU-2025:20172-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2025:20172-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2025:20172-1</guid>
    </item>
    <item>
      <title>RHSA-2026:64767 — Red Hat Security Advisory: kernel security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:64767</link>
      <description>&lt;p&gt;kernel: tls: Use __sk_dst_get() and dst_dev_rcu() in get_netdev_for_sock() kernel: netfilter: nft_set_pipapo_avx2: don&amp;#39;t return non-matching entry on expiry kernel: Bluetooth: hci_event: fix potential UAF in SSP passkey handlers kernel: net: ipv6: fix NOREF dst use in seg6 and rpl lwtunnels kernel: RDMA/mana: Validate rx_hash_key_len kernel: smb/client: fix out-of-bounds read in smb2_compound_op() kernel: ipv6: fix possible UAF in icmpv6_rcv() kernel: crypto: ccp - copy IV using skcipher ivsize kernel: scsi: target: iscsi: Validate CHAP_R length before base64 decode kernel: crypto: qat - validate RSA CRT component lengths&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;kernel: tls: Use __sk_dst_get() and dst_dev_rcu() in get_netdev_for_sock() kernel: netfilter: nft_set_pipapo_avx2: don&amp;#39;t return non-matching entry on expiry kernel: Bluetooth: hci_event: fix potential UAF in SSP passkey handlers kernel: net: ipv6: fix NOREF dst use in seg6 and rpl lwtunnels kernel: RDMA/mana: Validate rx_hash_key_len kernel: smb/client: fix out-of-bounds read in smb2_compound_op() kernel: ipv6: fix possible UAF in icmpv6_rcv() kernel: crypto: ccp - copy IV using skcipher ivsize kernel: scsi: target: iscsi: Validate CHAP_R length before base64 decode kernel: crypto: qat - validate RSA CRT component lengths&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:64767</guid>
    </item>
    <item>
      <title>RLSA-2026:67471 — Important: kernel security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:67471</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: kernel&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: tls: Use __sk_dst_get() and dst_dev_rcu() in get_netdev_for_sock() (CVE-2025-40149)&lt;/p&gt;
&lt;p&gt;* kernel: Linux kernel: Denial of Service in qla2xxx SCSI driver due to improper command handling after chip reset (CVE-2025-68745)&lt;/p&gt;
&lt;p&gt;* kernel: drm/xe: Open-code GGTT MMIO access protection (CVE-2026-23466)&lt;/p&gt;
&lt;p&gt;* kernel: drm/xe: always keep track of remap prev/next (CVE-2026-31479)&lt;/p&gt;
&lt;p&gt;* kernel: drm/amdgpu: Fix fence put before wait in amdgpu_amdkfd_submit_ib (CVE-2026-31566)&lt;/p&gt;
&lt;p&gt;* kernel: xfrm: hold dev ref until after transport_finish NF_HOOK (CVE-2026-31663)&lt;/p&gt;
&lt;p&gt;* kernel: drm/i915/gt: fix refcount underflow in intel_engine_park_heartbeat (CVE-2026-31656)&lt;/p&gt;
&lt;p&gt;* kernel: smb: smbdirect: introduce smbdirect_socket.recv_io.credits.available (CVE-2026-31539)&lt;/p&gt;
&lt;p&gt;* kernel: vhost: move vdpa group bound check to vhost_vdpa (CVE-2026-43248)&lt;/p&gt;
&lt;p&gt;* kernel: drm/i915: Fix potential overflow of shmem scatterlist length (CVE-2026-43368)&lt;/p&gt;
&lt;p&gt;* kernel: drm/amdgpu: Fix use-after-free race in VM acquire (CVE-2026-43370)&lt;/p&gt;
&lt;p&gt;* kernel: scsi: target: configfs: Bound snprintf() return in tg_pt_gp_members_show() (CVE-2026-46149)&lt;/p&gt;
&lt;p&gt;* kernel: sctp: purge outqueue on stale COOKIE-ECHO handling (CVE-2026-52924)&lt;/p&gt;
&lt;p&gt;* kernel: netfilter: require Ethernet MAC header before using eth_hdr() (CVE-2026-53131)&lt;/p&gt;
&lt;p&gt;* kernel: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing (CVE-2026-53246)&lt;/p&gt;
&lt;p&gt;* kernel: xfrm: policy: fix use-af…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: kernel&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: tls: Use __sk_dst_get() and dst_dev_rcu() in get_netdev_for_sock() (CVE-2025-40149)&lt;/p&gt;
&lt;p&gt;* kernel: Linux kernel: Denial of Service in qla2xxx SCSI driver due to improper command handling after chip reset (CVE-2025-68745)&lt;/p&gt;
&lt;p&gt;* kernel: drm/xe: Open-code GGTT MMIO access protection (CVE-2026-23466)&lt;/p&gt;
&lt;p&gt;* kernel: drm/xe: always keep track of remap prev/next (CVE-2026-31479)&lt;/p&gt;
&lt;p&gt;* kernel: drm/amdgpu: Fix fence put before wait in amdgpu_amdkfd_submit_ib (CVE-2026-31566)&lt;/p&gt;
&lt;p&gt;* kernel: xfrm: hold dev ref until after transport_finish NF_HOOK (CVE-2026-31663)&lt;/p&gt;
&lt;p&gt;* kernel: drm/i915/gt: fix refcount underflow in intel_engine_park_heartbeat (CVE-2026-31656)&lt;/p&gt;
&lt;p&gt;* kernel: smb: smbdirect: introduce smbdirect_socket.recv_io.credits.available (CVE-2026-31539)&lt;/p&gt;
&lt;p&gt;* kernel: vhost: move vdpa group bound check to vhost_vdpa (CVE-2026-43248)&lt;/p&gt;
&lt;p&gt;* kernel: drm/i915: Fix potential overflow of shmem scatterlist length (CVE-2026-43368)&lt;/p&gt;
&lt;p&gt;* kernel: drm/amdgpu: Fix use-after-free race in VM acquire (CVE-2026-43370)&lt;/p&gt;
&lt;p&gt;* kernel: scsi: target: configfs: Bound snprintf() return in tg_pt_gp_members_show() (CVE-2026-46149)&lt;/p&gt;
&lt;p&gt;* kernel: sctp: purge outqueue on stale COOKIE-ECHO handling (CVE-2026-52924)&lt;/p&gt;
&lt;p&gt;* kernel: netfilter: require Ethernet MAC header before using eth_hdr() (CVE-2026-53131)&lt;/p&gt;
&lt;p&gt;* kernel: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing (CVE-2026-53246)&lt;/p&gt;
&lt;p&gt;* kernel: xfrm: policy: fix use-af…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:67471</guid>
    </item>
    <item>
      <title>SSA-019113 — SSA-019113: Vulnerabilities in the additional GNU/Linux subsystem of the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1.6</title>
      <link>https://cve.radiocsirt.org/vuln/ssa-019113</link>
      <description>&lt;p&gt;Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.6 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant).&lt;/p&gt;
&lt;p&gt;Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.6 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant).&lt;/p&gt;
&lt;p&gt;Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ssa-019113</guid>
    </item>
    <item>
      <title>SUSE-SU-2025:4422-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2025:4422-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2025:4422-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-40149</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-40149</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:Pro:18.04:LTS: linux-aws-5.4, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:Pro:18.04:LTS: linux-azure-5.4, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3 and 201 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: tls: Use __sk_dst_get() and dst_dev_rcu() in get_netdev_for_sock(). get_netdev_for_sock() is called during setsockopt(), so not under RCU. Using sk_dst_get(sk)-&amp;gt;dev could trigger UAF. Let&amp;#39;s use __sk_dst_get() and dst_dev_rcu(). Note that the only -&amp;gt;ndo_sk_get_lower_dev() user is bond_sk_get_lower_dev(), which uses RCU.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:Pro:18.04:LTS: linux-aws-5.4, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:Pro:18.04:LTS: linux-azure-5.4, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3 and 201 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: tls: Use __sk_dst_get() and dst_dev_rcu() in get_netdev_for_sock(). get_netdev_for_sock() is called during setsockopt(), so not under RCU. Using sk_dst_get(sk)-&amp;gt;dev could trigger UAF. Let&amp;#39;s use __sk_dst_get() and dst_dev_rcu(). Note that the only -&amp;gt;ndo_sk_get_lower_dev() user is bond_sk_get_lower_dev(), which uses RCU.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-40149</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-2579 — Linux Kernel: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2579</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux-Kernel ausnutzen, um nicht näher spezifizierte Angriffe durchzuführen, die möglicherweise zu einer Denial-of-Service- Bedingung führen oder eine Speicherbeschädigung verursachen können.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux-Kernel ausnutzen, um nicht näher spezifizierte Angriffe durchzuführen, die möglicherweise zu einer Denial-of-Service- Bedingung führen oder eine Speicherbeschädigung verursachen können.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2579</guid>
    </item>
  </channel>
</rss>
