<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 18:53:51 +0000</lastBuildDate>
    <item>
      <title>ALSA-2026:3488 — Moderate: kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:3488</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: kernel, AlmaLinux:9: kernel-64k, AlmaLinux:9: kernel-64k-core, AlmaLinux:9: kernel-64k-debug, AlmaLinux:9: kernel-64k-debug-core, AlmaLinux:9: kernel-64k-debug-devel, AlmaLinux:9: kernel-64k-debug-devel-matched, AlmaLinux:9: kernel-64k-debug-modules, AlmaLinux:9: kernel-64k-debug-modules-core, AlmaLinux:9: kernel-64k-debug-modules-extra and 64 more&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: smc: Use __sk_dst_get() and dst_dev_rcu() in smc_clc_prfx_match() (CVE-2025-40168)
  * kernel: ipv6: BUG() in pskb_expand_head() as part of calipso_skbuff_setattr() (CVE-2025-71085)
  * kernel: Linux kernel: Denial of Service due to a deadlock in hugetlb folio migration (CVE-2026-23097)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: kernel, AlmaLinux:9: kernel-64k, AlmaLinux:9: kernel-64k-core, AlmaLinux:9: kernel-64k-debug, AlmaLinux:9: kernel-64k-debug-core, AlmaLinux:9: kernel-64k-debug-devel, AlmaLinux:9: kernel-64k-debug-devel-matched, AlmaLinux:9: kernel-64k-debug-modules, AlmaLinux:9: kernel-64k-debug-modules-core, AlmaLinux:9: kernel-64k-debug-modules-extra and 64 more&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: smc: Use __sk_dst_get() and dst_dev_rcu() in smc_clc_prfx_match() (CVE-2025-40168)
  * kernel: ipv6: BUG() in pskb_expand_head() as part of calipso_skbuff_setattr() (CVE-2025-71085)
  * kernel: Linux kernel: Denial of Service due to a deadlock in hugetlb folio migration (CVE-2026-23097)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:3488</guid>
    </item>
    <item>
      <title>bdu:2026-08527</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-08527</link>
      <description>bdu:2026-08527</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-08527</guid>
    </item>
    <item>
      <title>BELL-CVE-2025-71085</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2025-71085</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2025-71085</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0166 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de Debian. Elles permettent à un attaquant de provo…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0166</link>
      <description>certfr-2026-avi-0166</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0166</guid>
    </item>
    <item>
      <title>EUVD-2026-364613</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-364613</link>
      <description>EUVD-2026-364613</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-364613</guid>
    </item>
    <item>
      <title>fkie_cve-2025-71085</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-71085</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;ipv6: BUG() in pskb_expand_head() as part of calipso_skbuff_setattr()&lt;/p&gt;
&lt;p&gt;There exists a kernel oops caused by a BUG_ON(nhead &amp;lt; 0) at
net/core/skbuff.c:2232 in pskb_expand_head().
This bug is triggered as part of the calipso_skbuff_setattr()
routine when skb_cow() is passed headroom &amp;gt; INT_MAX
(i.e. (int)(skb_headroom(skb) + len_delta) &amp;lt; 0).&lt;/p&gt;
&lt;p&gt;The root cause of the bug is due to an implicit integer cast in
__skb_cow(). The check (headroom &amp;gt; skb_headroom(skb)) is meant to ensure
that delta = headroom - skb_headroom(skb) is never negative, otherwise
we will trigger a BUG_ON in pskb_expand_head(). However, if
headroom &amp;gt; INT_MAX and delta &amp;lt;= -NET_SKB_PAD, the check passes, delta
becomes negative, and pskb_expand_head() is passed a negative value for
nhead.&lt;/p&gt;
&lt;p&gt;Fix the trigger condition in calipso_skbuff_setattr(). Avoid passing
&amp;#34;negative&amp;#34; headroom sizes to skb_cow() within calipso_skbuff_setattr()
by only using skb_cow() to grow headroom.&lt;/p&gt;
&lt;p&gt;PoC:
	Using `netlabelctl` tool:&lt;/p&gt;
&lt;p&gt;netlabelctl map del default
        netlabelctl calipso add pass doi:7
        netlabelctl map add default address:0::1/128 protocol:calipso,7&lt;/p&gt;
&lt;p&gt;Then run the following PoC:&lt;/p&gt;
&lt;p&gt;int fd = socket(AF_INET6, SOCK_DGRAM, IPPROTO_UDP);&lt;/p&gt;
&lt;p&gt;// setup msghdr
        int cmsg_size = 2;
        int cmsg_len = 0x60;
        struct msghdr msg;
        struct sockaddr_in6 dest_addr;
        struct cmsghdr * cmsg = (struct cmsghdr *) calloc(1…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;ipv6: BUG() in pskb_expand_head() as part of calipso_skbuff_setattr()&lt;/p&gt;
&lt;p&gt;There exists a kernel oops caused by a BUG_ON(nhead &amp;lt; 0) at
net/core/skbuff.c:2232 in pskb_expand_head().
This bug is triggered as part of the calipso_skbuff_setattr()
routine when skb_cow() is passed headroom &amp;gt; INT_MAX
(i.e. (int)(skb_headroom(skb) + len_delta) &amp;lt; 0).&lt;/p&gt;
&lt;p&gt;The root cause of the bug is due to an implicit integer cast in
__skb_cow(). The check (headroom &amp;gt; skb_headroom(skb)) is meant to ensure
that delta = headroom - skb_headroom(skb) is never negative, otherwise
we will trigger a BUG_ON in pskb_expand_head(). However, if
headroom &amp;gt; INT_MAX and delta &amp;lt;= -NET_SKB_PAD, the check passes, delta
becomes negative, and pskb_expand_head() is passed a negative value for
nhead.&lt;/p&gt;
&lt;p&gt;Fix the trigger condition in calipso_skbuff_setattr(). Avoid passing
&amp;#34;negative&amp;#34; headroom sizes to skb_cow() within calipso_skbuff_setattr()
by only using skb_cow() to grow headroom.&lt;/p&gt;
&lt;p&gt;PoC:
	Using `netlabelctl` tool:&lt;/p&gt;
&lt;p&gt;netlabelctl map del default
        netlabelctl calipso add pass doi:7
        netlabelctl map add default address:0::1/128 protocol:calipso,7&lt;/p&gt;
&lt;p&gt;Then run the following PoC:&lt;/p&gt;
&lt;p&gt;int fd = socket(AF_INET6, SOCK_DGRAM, IPPROTO_UDP);&lt;/p&gt;
&lt;p&gt;// setup msghdr
        int cmsg_size = 2;
        int cmsg_len = 0x60;
        struct msghdr msg;
        struct sockaddr_in6 dest_addr;
        struct cmsghdr * cmsg = (struct cmsghdr *) calloc(1…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-71085</guid>
    </item>
    <item>
      <title>GHSA-hjpx-f2r6-rr4q</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-hjpx-f2r6-rr4q</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;ipv6: BUG() in pskb_expand_head() as part of calipso_skbuff_setattr()&lt;/p&gt;
&lt;p&gt;There exists a kernel oops caused by a BUG_ON(nhead &amp;lt; 0) at
net/core/skbuff.c:2232 in pskb_expand_head().
This bug is triggered as part of the calipso_skbuff_setattr()
routine when skb_cow() is passed headroom &amp;gt; INT_MAX
(i.e. (int)(skb_headroom(skb) + len_delta) &amp;lt; 0).&lt;/p&gt;
&lt;p&gt;The root cause of the bug is due to an implicit integer cast in
__skb_cow(). The check (headroom &amp;gt; skb_headroom(skb)) is meant to ensure
that delta = headroom - skb_headroom(skb) is never negative, otherwise
we will trigger a BUG_ON in pskb_expand_head(). However, if
headroom &amp;gt; INT_MAX and delta &amp;lt;= -NET_SKB_PAD, the check passes, delta
becomes negative, and pskb_expand_head() is passed a negative value for
nhead.&lt;/p&gt;
&lt;p&gt;Fix the trigger condition in calipso_skbuff_setattr(). Avoid passing
&amp;#34;negative&amp;#34; headroom sizes to skb_cow() within calipso_skbuff_setattr()
by only using skb_cow() to grow headroom.&lt;/p&gt;
&lt;p&gt;PoC:
	Using `netlabelctl` tool:&lt;/p&gt;
&lt;p&gt;netlabelctl map del default
        netlabelctl calipso add pass doi:7
        netlabelctl map add default address:0::1/128 protocol:calipso,7&lt;/p&gt;
&lt;p&gt;Then run the following PoC:&lt;/p&gt;
&lt;p&gt;int fd = socket(AF_INET6, SOCK_DGRAM, IPPROTO_UDP);&lt;/p&gt;
&lt;p&gt;// setup msghdr
        int cmsg_size = 2;
        int cmsg_len = 0x60;
        struct msghdr msg;
        struct sockaddr_in6 dest_addr;
        struct cmsghdr * cmsg = (struct cmsghdr *) calloc(1…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;ipv6: BUG() in pskb_expand_head() as part of calipso_skbuff_setattr()&lt;/p&gt;
&lt;p&gt;There exists a kernel oops caused by a BUG_ON(nhead &amp;lt; 0) at
net/core/skbuff.c:2232 in pskb_expand_head().
This bug is triggered as part of the calipso_skbuff_setattr()
routine when skb_cow() is passed headroom &amp;gt; INT_MAX
(i.e. (int)(skb_headroom(skb) + len_delta) &amp;lt; 0).&lt;/p&gt;
&lt;p&gt;The root cause of the bug is due to an implicit integer cast in
__skb_cow(). The check (headroom &amp;gt; skb_headroom(skb)) is meant to ensure
that delta = headroom - skb_headroom(skb) is never negative, otherwise
we will trigger a BUG_ON in pskb_expand_head(). However, if
headroom &amp;gt; INT_MAX and delta &amp;lt;= -NET_SKB_PAD, the check passes, delta
becomes negative, and pskb_expand_head() is passed a negative value for
nhead.&lt;/p&gt;
&lt;p&gt;Fix the trigger condition in calipso_skbuff_setattr(). Avoid passing
&amp;#34;negative&amp;#34; headroom sizes to skb_cow() within calipso_skbuff_setattr()
by only using skb_cow() to grow headroom.&lt;/p&gt;
&lt;p&gt;PoC:
	Using `netlabelctl` tool:&lt;/p&gt;
&lt;p&gt;netlabelctl map del default
        netlabelctl calipso add pass doi:7
        netlabelctl map add default address:0::1/128 protocol:calipso,7&lt;/p&gt;
&lt;p&gt;Then run the following PoC:&lt;/p&gt;
&lt;p&gt;int fd = socket(AF_INET6, SOCK_DGRAM, IPPROTO_UDP);&lt;/p&gt;
&lt;p&gt;// setup msghdr
        int cmsg_size = 2;
        int cmsg_len = 0x60;
        struct msghdr msg;
        struct sockaddr_in6 dest_addr;
        struct cmsghdr * cmsg = (struct cmsghdr *) calloc(1…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-hjpx-f2r6-rr4q</guid>
    </item>
    <item>
      <title>ICSA-26-209-04 — Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-26-209-04</link>
      <description>&lt;p&gt;Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.6 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant).&lt;/p&gt;
&lt;p&gt;Siemens is preparing fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.6 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant).&lt;/p&gt;
&lt;p&gt;Siemens is preparing fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-26-209-04</guid>
    </item>
    <item>
      <title>OESA-2026-2580 — kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-2580</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP4: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;iomap: Fix possible overflow condition in iomap_write_delalloc_scan&lt;/p&gt;
&lt;p&gt;folio_next_index() returns an unsigned long value which left shifted
by PAGE_SHIFT could possibly cause an overflow on 32-bit system. Instead
use folio_pos(folio) + folio_size(folio), which does this correctly.(CVE-2023-54285)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;bcache: fix NULL pointer in cache_set_flush()&lt;/p&gt;
&lt;p&gt;1. LINE#1794 - LINE#1887 is some codes about function of
   bch_cache_set_alloc().
2. LINE#2078 - LINE#2142 is some codes about function of
   register_cache_set().
3. register_cache_set() will call bch_cache_set_alloc() in LINE#2098.&lt;/p&gt;
&lt;p&gt;1794 struct cache_set *bch_cache_set_alloc(struct cache_sb *sb)
 1795 {
 ...
 1860         if (!(c-&amp;amp;gt;devices = kcalloc(c-&amp;amp;gt;nr_uuids, sizeof(void *), GFP_KERNEL)) ||
 1861             mempool_init_slab_pool(&amp;amp;amp;c-&amp;amp;gt;search, 32, bch_search_cache) ||
 1862             mempool_init_kmalloc_pool(&amp;amp;amp;c-&amp;amp;gt;bio_meta, 2,
 1863                                 sizeof(struct bbio) + sizeof(struct bio_vec) *
 1864                                 bucket_pages(c)) ||
 1865             mempool_init_kmalloc_pool(&amp;amp;amp;c-&amp;amp;gt;fill_iter, 1, iter_size) ||
 1866             bioset_init(&amp;amp;amp;c-&amp;amp;gt;bio_split, 4, offsetof(struct bbio, bio),
 1867                         BIOSET_NEED_BVECS|BIOSET_NEED_RESCUER) ||
 18…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP4: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;iomap: Fix possible overflow condition in iomap_write_delalloc_scan&lt;/p&gt;
&lt;p&gt;folio_next_index() returns an unsigned long value which left shifted
by PAGE_SHIFT could possibly cause an overflow on 32-bit system. Instead
use folio_pos(folio) + folio_size(folio), which does this correctly.(CVE-2023-54285)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;bcache: fix NULL pointer in cache_set_flush()&lt;/p&gt;
&lt;p&gt;1. LINE#1794 - LINE#1887 is some codes about function of
   bch_cache_set_alloc().
2. LINE#2078 - LINE#2142 is some codes about function of
   register_cache_set().
3. register_cache_set() will call bch_cache_set_alloc() in LINE#2098.&lt;/p&gt;
&lt;p&gt;1794 struct cache_set *bch_cache_set_alloc(struct cache_sb *sb)
 1795 {
 ...
 1860         if (!(c-&amp;amp;gt;devices = kcalloc(c-&amp;amp;gt;nr_uuids, sizeof(void *), GFP_KERNEL)) ||
 1861             mempool_init_slab_pool(&amp;amp;amp;c-&amp;amp;gt;search, 32, bch_search_cache) ||
 1862             mempool_init_kmalloc_pool(&amp;amp;amp;c-&amp;amp;gt;bio_meta, 2,
 1863                                 sizeof(struct bbio) + sizeof(struct bio_vec) *
 1864                                 bucket_pages(c)) ||
 1865             mempool_init_kmalloc_pool(&amp;amp;amp;c-&amp;amp;gt;fill_iter, 1, iter_size) ||
 1866             bioset_init(&amp;amp;amp;c-&amp;amp;gt;bio_split, 4, offsetof(struct bbio, bio),
 1867                         BIOSET_NEED_BVECS|BIOSET_NEED_RESCUER) ||
 18…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-2580</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:20287-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:20287-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:20287-1</guid>
    </item>
    <item>
      <title>RHSA-2026:3964 — Red Hat Security Advisory: kernel-rt security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:3964</link>
      <description>&lt;p&gt;kernel: ipv6: BUG() in pskb_expand_head() as part of calipso_skbuff_setattr() kernel: macvlan: fix possible UAF in macvlan_forward_source()&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;kernel: ipv6: BUG() in pskb_expand_head() as part of calipso_skbuff_setattr() kernel: macvlan: fix possible UAF in macvlan_forward_source()&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:3964</guid>
    </item>
    <item>
      <title>SSA-019113 — SSA-019113: Vulnerabilities in the additional GNU/Linux subsystem of the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1.6</title>
      <link>https://cve.radiocsirt.org/vuln/ssa-019113</link>
      <description>&lt;p&gt;Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.6 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant).&lt;/p&gt;
&lt;p&gt;Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.6 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant).&lt;/p&gt;
&lt;p&gt;Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ssa-019113</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:0471-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:0471-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:0471-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-71085</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-71085</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe, Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:Pro:16.04:LTS: linux-oracle, Ubuntu:Pro:18.04:LTS: linux, Ubuntu:Pro:18.04:LTS: linux-aws, Ubuntu:18.04:LTS: linux-aws-5.0 and 224 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: ipv6: BUG() in pskb_expand_head() as part of calipso_skbuff_setattr() There exists a kernel oops caused by a BUG_ON(nhead &amp;lt; 0) at net/core/skbuff.c:2232 in pskb_expand_head(). This bug is triggered as part of the calipso_skbuff_setattr() routine when skb_cow() is passed headroom &amp;gt; INT_MAX (i.e. (int)(skb_headroom(skb) + len_delta) &amp;lt; 0). The root cause of the bug is due to an implicit integer cast in __skb_cow(). The check (headroom &amp;gt; skb_headroom(skb)) is meant to ensure that delta = headroom - skb_headroom(skb) is never negative, otherwise we will trigger a BUG_ON in pskb_expand_head(). However, if headroom &amp;gt; INT_MAX and delta &amp;lt;= -NET_SKB_PAD, the check passes, delta becomes negative, and pskb_expand_head() is passed a negative value for nhead. Fix the trigger condition in calipso_skbuff_setattr(). Avoid passing &amp;#34;negative&amp;#34; headroom sizes to skb_cow() within calipso_skbuff_setattr() by only using skb_cow() to grow headroom. PoC: 	Using `netlabelctl` tool:         netlabelctl map del default         netlabelctl calipso add pass doi:7         netlabelctl map add default address:0::1/128 protocol:calipso,7         Then run the following PoC:         int fd = socket(AF_INET6, SOCK_DGRAM, IPPROTO_UDP);         // setup msghdr         int cmsg_size = 2;         int cmsg_len = 0x60;         struct msghdr msg;         struct sockaddr_in6 dest_addr;         struct cmsghdr * cmsg = (struct cmsghdr *) calloc(1,…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe, Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:Pro:16.04:LTS: linux-oracle, Ubuntu:Pro:18.04:LTS: linux, Ubuntu:Pro:18.04:LTS: linux-aws, Ubuntu:18.04:LTS: linux-aws-5.0 and 224 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: ipv6: BUG() in pskb_expand_head() as part of calipso_skbuff_setattr() There exists a kernel oops caused by a BUG_ON(nhead &amp;lt; 0) at net/core/skbuff.c:2232 in pskb_expand_head(). This bug is triggered as part of the calipso_skbuff_setattr() routine when skb_cow() is passed headroom &amp;gt; INT_MAX (i.e. (int)(skb_headroom(skb) + len_delta) &amp;lt; 0). The root cause of the bug is due to an implicit integer cast in __skb_cow(). The check (headroom &amp;gt; skb_headroom(skb)) is meant to ensure that delta = headroom - skb_headroom(skb) is never negative, otherwise we will trigger a BUG_ON in pskb_expand_head(). However, if headroom &amp;gt; INT_MAX and delta &amp;lt;= -NET_SKB_PAD, the check passes, delta becomes negative, and pskb_expand_head() is passed a negative value for nhead. Fix the trigger condition in calipso_skbuff_setattr(). Avoid passing &amp;#34;negative&amp;#34; headroom sizes to skb_cow() within calipso_skbuff_setattr() by only using skb_cow() to grow headroom. PoC: 	Using `netlabelctl` tool:         netlabelctl map del default         netlabelctl calipso add pass doi:7         netlabelctl map add default address:0::1/128 protocol:calipso,7         Then run the following PoC:         int fd = socket(AF_INET6, SOCK_DGRAM, IPPROTO_UDP);         // setup msghdr         int cmsg_size = 2;         int cmsg_len = 0x60;         struct msghdr msg;         struct sockaddr_in6 dest_addr;         struct cmsghdr * cmsg = (struct cmsghdr *) calloc(1,…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-71085</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-0086 — Linux Kernel: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0086</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen um nicht näher spezifizierte Angriffe durchzuführen, die möglicherweise zu einer Denial-of-Service- Bedingung führen oder eine Speicherbeschädigung verursachen können.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen um nicht näher spezifizierte Angriffe durchzuführen, die möglicherweise zu einer Denial-of-Service- Bedingung führen oder eine Speicherbeschädigung verursachen können.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0086</guid>
    </item>
  </channel>
</rss>
