<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 19:52:35 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-11084</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-11084</link>
      <description>bdu:2026-11084</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-11084</guid>
    </item>
    <item>
      <title>BELL-CVE-2026-23237</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-23237</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-23237</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0291 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de Debian. Certaines d'entre elles permettent à un…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0291</link>
      <description>certfr-2026-avi-0291</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0291</guid>
    </item>
    <item>
      <title>EUVD-2026-315421</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-315421</link>
      <description>EUVD-2026-315421</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-315421</guid>
    </item>
    <item>
      <title>fkie_cve-2026-23237</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-23237</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;platform/x86: classmate-laptop: Add missing NULL pointer checks&lt;/p&gt;
&lt;p&gt;In a few places in the Classmate laptop driver, code using the accel
object may run before that object&amp;#39;s address is stored in the driver
data of the input device using it.&lt;/p&gt;
&lt;p&gt;For example, cmpc_accel_sensitivity_store_v4() is the &amp;#34;show&amp;#34; method
of cmpc_accel_sensitivity_attr_v4 which is added in cmpc_accel_add_v4(),
before calling dev_set_drvdata() for inputdev-&amp;gt;dev.  If the sysfs
attribute is accessed prematurely, the dev_get_drvdata(&amp;amp;inputdev-&amp;gt;dev)
call in in cmpc_accel_sensitivity_store_v4() returns NULL which
leads to a NULL pointer dereference going forward.&lt;/p&gt;
&lt;p&gt;Moreover, sysfs attributes using the input device are added before
initializing that device by cmpc_add_acpi_notify_device() and if one
of them is accessed before running that function, a NULL pointer
dereference will occur.&lt;/p&gt;
&lt;p&gt;For example, cmpc_accel_sensitivity_attr_v4 is added before calling
cmpc_add_acpi_notify_device() and if it is read prematurely, the
dev_get_drvdata(&amp;amp;acpi-&amp;gt;dev) call in cmpc_accel_sensitivity_show_v4()
returns NULL which leads to a NULL pointer dereference going forward.&lt;/p&gt;
&lt;p&gt;Fix this by adding NULL pointer checks in all of the relevant places.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;platform/x86: classmate-laptop: Add missing NULL pointer checks&lt;/p&gt;
&lt;p&gt;In a few places in the Classmate laptop driver, code using the accel
object may run before that object&amp;#39;s address is stored in the driver
data of the input device using it.&lt;/p&gt;
&lt;p&gt;For example, cmpc_accel_sensitivity_store_v4() is the &amp;#34;show&amp;#34; method
of cmpc_accel_sensitivity_attr_v4 which is added in cmpc_accel_add_v4(),
before calling dev_set_drvdata() for inputdev-&amp;gt;dev.  If the sysfs
attribute is accessed prematurely, the dev_get_drvdata(&amp;amp;inputdev-&amp;gt;dev)
call in in cmpc_accel_sensitivity_store_v4() returns NULL which
leads to a NULL pointer dereference going forward.&lt;/p&gt;
&lt;p&gt;Moreover, sysfs attributes using the input device are added before
initializing that device by cmpc_add_acpi_notify_device() and if one
of them is accessed before running that function, a NULL pointer
dereference will occur.&lt;/p&gt;
&lt;p&gt;For example, cmpc_accel_sensitivity_attr_v4 is added before calling
cmpc_add_acpi_notify_device() and if it is read prematurely, the
dev_get_drvdata(&amp;amp;acpi-&amp;gt;dev) call in cmpc_accel_sensitivity_show_v4()
returns NULL which leads to a NULL pointer dereference going forward.&lt;/p&gt;
&lt;p&gt;Fix this by adding NULL pointer checks in all of the relevant places.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-23237</guid>
    </item>
    <item>
      <title>GHSA-9438-9qfw-m4v5</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-9438-9qfw-m4v5</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;platform/x86: classmate-laptop: Add missing NULL pointer checks&lt;/p&gt;
&lt;p&gt;In a few places in the Classmate laptop driver, code using the accel
object may run before that object&amp;#39;s address is stored in the driver
data of the input device using it.&lt;/p&gt;
&lt;p&gt;For example, cmpc_accel_sensitivity_store_v4() is the &amp;#34;show&amp;#34; method
of cmpc_accel_sensitivity_attr_v4 which is added in cmpc_accel_add_v4(),
before calling dev_set_drvdata() for inputdev-&amp;gt;dev.  If the sysfs
attribute is accessed prematurely, the dev_get_drvdata(&amp;amp;inputdev-&amp;gt;dev)
call in in cmpc_accel_sensitivity_store_v4() returns NULL which
leads to a NULL pointer dereference going forward.&lt;/p&gt;
&lt;p&gt;Moreover, sysfs attributes using the input device are added before
initializing that device by cmpc_add_acpi_notify_device() and if one
of them is accessed before running that function, a NULL pointer
dereference will occur.&lt;/p&gt;
&lt;p&gt;For example, cmpc_accel_sensitivity_attr_v4 is added before calling
cmpc_add_acpi_notify_device() and if it is read prematurely, the
dev_get_drvdata(&amp;amp;acpi-&amp;gt;dev) call in cmpc_accel_sensitivity_show_v4()
returns NULL which leads to a NULL pointer dereference going forward.&lt;/p&gt;
&lt;p&gt;Fix this by adding NULL pointer checks in all of the relevant places.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;platform/x86: classmate-laptop: Add missing NULL pointer checks&lt;/p&gt;
&lt;p&gt;In a few places in the Classmate laptop driver, code using the accel
object may run before that object&amp;#39;s address is stored in the driver
data of the input device using it.&lt;/p&gt;
&lt;p&gt;For example, cmpc_accel_sensitivity_store_v4() is the &amp;#34;show&amp;#34; method
of cmpc_accel_sensitivity_attr_v4 which is added in cmpc_accel_add_v4(),
before calling dev_set_drvdata() for inputdev-&amp;gt;dev.  If the sysfs
attribute is accessed prematurely, the dev_get_drvdata(&amp;amp;inputdev-&amp;gt;dev)
call in in cmpc_accel_sensitivity_store_v4() returns NULL which
leads to a NULL pointer dereference going forward.&lt;/p&gt;
&lt;p&gt;Moreover, sysfs attributes using the input device are added before
initializing that device by cmpc_add_acpi_notify_device() and if one
of them is accessed before running that function, a NULL pointer
dereference will occur.&lt;/p&gt;
&lt;p&gt;For example, cmpc_accel_sensitivity_attr_v4 is added before calling
cmpc_add_acpi_notify_device() and if it is read prematurely, the
dev_get_drvdata(&amp;amp;acpi-&amp;gt;dev) call in cmpc_accel_sensitivity_show_v4()
returns NULL which leads to a NULL pointer dereference going forward.&lt;/p&gt;
&lt;p&gt;Fix this by adding NULL pointer checks in all of the relevant places.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-9438-9qfw-m4v5</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-23237 — platform/x86: classmate-laptop: Add missing NULL pointer checks</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-23237</link>
      <description>msrc_CVE-2026-23237</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-23237</guid>
    </item>
    <item>
      <title>OESA-2026-1642 — kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-1642</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;fs/xattr: missing fdput() in fremovexattr error path&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the fremovexattr() syscall calls fdget() to acquire a
file reference but returns early without calling fdput() when
strncpy_from_user() fails on the name argument. In multi-threaded processes
where fdget() takes the slow path, this permanently leaks one
file reference per call, pinning the struct file and associated kernel
objects in memory. An unprivileged local user can exploit this to cause
kernel memory exhaustion. The issue was inadvertently fixed by commit
a71874379ec8 (&amp;amp;quot;xattr: switch to CLASS(fd)&amp;amp;quot;).(CVE-2024-14027)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;pps: Fix a use-after-free&lt;/p&gt;
&lt;p&gt;On a board running ntpd and gpsd, I&amp;amp;apos;m seeing a consistent use-after-free
in sys_exit() from gpsd when rebooting:&lt;/p&gt;
&lt;p&gt;pps pps1: removed
    ------------[ cut here ]------------
    kobject: &amp;amp;apos;(null)&amp;amp;apos; (00000000db4bec24): is not initialized, yet kobject_put() is being called.
    WARNING: CPU: 2 PID: 440 at lib/kobject.c:734 kobject_put+0x120/0x150
    CPU: 2 UID: 299 PID: 440 Comm: gpsd Not tainted 6.11.0-rc6-00308-gb31c44928842 #1
    Hardware name: Raspberry Pi 4 Model B Rev 1.1 (DT)
    pstate: 60000005 (nZCv daif -PAN -UAO -TCO -DIT -SSBS BTYPE=--)
    pc : kobject_put+0x120/0x150
    lr : kobject_put+0x120/0x150
    sp :…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;fs/xattr: missing fdput() in fremovexattr error path&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the fremovexattr() syscall calls fdget() to acquire a
file reference but returns early without calling fdput() when
strncpy_from_user() fails on the name argument. In multi-threaded processes
where fdget() takes the slow path, this permanently leaks one
file reference per call, pinning the struct file and associated kernel
objects in memory. An unprivileged local user can exploit this to cause
kernel memory exhaustion. The issue was inadvertently fixed by commit
a71874379ec8 (&amp;amp;quot;xattr: switch to CLASS(fd)&amp;amp;quot;).(CVE-2024-14027)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;pps: Fix a use-after-free&lt;/p&gt;
&lt;p&gt;On a board running ntpd and gpsd, I&amp;amp;apos;m seeing a consistent use-after-free
in sys_exit() from gpsd when rebooting:&lt;/p&gt;
&lt;p&gt;pps pps1: removed
    ------------[ cut here ]------------
    kobject: &amp;amp;apos;(null)&amp;amp;apos; (00000000db4bec24): is not initialized, yet kobject_put() is being called.
    WARNING: CPU: 2 PID: 440 at lib/kobject.c:734 kobject_put+0x120/0x150
    CPU: 2 UID: 299 PID: 440 Comm: gpsd Not tainted 6.11.0-rc6-00308-gb31c44928842 #1
    Hardware name: Raspberry Pi 4 Model B Rev 1.1 (DT)
    pstate: 60000005 (nZCv daif -PAN -UAO -TCO -DIT -SSBS BTYPE=--)
    pc : kobject_put+0x120/0x150
    lr : kobject_put+0x120/0x150
    sp :…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-1642</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:20826-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:20826-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:20826-1</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:21834-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:21834-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:21834-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-23237</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-23237</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux, Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe and 232 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: platform/x86: classmate-laptop: Add missing NULL pointer checks In a few places in the Classmate laptop driver, code using the accel object may run before that object&amp;#39;s address is stored in the driver data of the input device using it. For example, cmpc_accel_sensitivity_store_v4() is the &amp;#34;show&amp;#34; method of cmpc_accel_sensitivity_attr_v4 which is added in cmpc_accel_add_v4(), before calling dev_set_drvdata() for inputdev-&amp;gt;dev.  If the sysfs attribute is accessed prematurely, the dev_get_drvdata(&amp;amp;inputdev-&amp;gt;dev) call in in cmpc_accel_sensitivity_store_v4() returns NULL which leads to a NULL pointer dereference going forward. Moreover, sysfs attributes using the input device are added before initializing that device by cmpc_add_acpi_notify_device() and if one of them is accessed before running that function, a NULL pointer dereference will occur. For example, cmpc_accel_sensitivity_attr_v4 is added before calling cmpc_add_acpi_notify_device() and if it is read prematurely, the dev_get_drvdata(&amp;amp;acpi-&amp;gt;dev) call in cmpc_accel_sensitivity_show_v4() returns NULL which leads to a NULL pointer dereference going forward. Fix this by adding NULL pointer checks in all of the relevant places.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux, Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe and 232 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: platform/x86: classmate-laptop: Add missing NULL pointer checks In a few places in the Classmate laptop driver, code using the accel object may run before that object&amp;#39;s address is stored in the driver data of the input device using it. For example, cmpc_accel_sensitivity_store_v4() is the &amp;#34;show&amp;#34; method of cmpc_accel_sensitivity_attr_v4 which is added in cmpc_accel_add_v4(), before calling dev_set_drvdata() for inputdev-&amp;gt;dev.  If the sysfs attribute is accessed prematurely, the dev_get_drvdata(&amp;amp;inputdev-&amp;gt;dev) call in in cmpc_accel_sensitivity_store_v4() returns NULL which leads to a NULL pointer dereference going forward. Moreover, sysfs attributes using the input device are added before initializing that device by cmpc_add_acpi_notify_device() and if one of them is accessed before running that function, a NULL pointer dereference will occur. For example, cmpc_accel_sensitivity_attr_v4 is added before calling cmpc_add_acpi_notify_device() and if it is read prematurely, the dev_get_drvdata(&amp;amp;acpi-&amp;gt;dev) call in cmpc_accel_sensitivity_show_v4() returns NULL which leads to a NULL pointer dereference going forward. Fix this by adding NULL pointer checks in all of the relevant places.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-23237</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-0614 — Linux Kernel: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0614</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux-Kernel ausnutzen, um nicht näher spezifizierte Angriffe durchzuführen, die möglicherweise zu einer Denial-of-Service-Bedingung führen oder eine Speicherbeschädigung verursachen können.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux-Kernel ausnutzen, um nicht näher spezifizierte Angriffe durchzuführen, die möglicherweise zu einer Denial-of-Service-Bedingung führen oder eine Speicherbeschädigung verursachen können.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0614</guid>
    </item>
  </channel>
</rss>
