<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 20:52:08 +0000</lastBuildDate>
    <item>
      <title>ALSA-2026:18134 — Moderate: kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:18134</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: kernel, AlmaLinux:10: kernel-64k, AlmaLinux:10: kernel-64k-core, AlmaLinux:10: kernel-64k-debug, AlmaLinux:10: kernel-64k-debug-core, AlmaLinux:10: kernel-64k-debug-devel, AlmaLinux:10: kernel-64k-debug-devel-matched, AlmaLinux:10: kernel-64k-debug-modules, AlmaLinux:10: kernel-64k-debug-modules-core, AlmaLinux:10: kernel-64k-debug-modules-extra and 65 more&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: tcp_bpf: Fix the sk_mem_uncharge logic in tcp_bpf_sendmsg (CVE-2024-56633)
  * kernel: KVM: x86: Load DR6 with guest value only before entering .vcpu_run() loop (CVE-2025-21839)
  * kernel: block: fix resource leak in blk_register_queue() error path (CVE-2025-37980)
  * kernel: dmaengine: idxd: fix memory leak in error handling path of idxd_alloc (CVE-2025-38015)
  * kernel: espintcp: remove encap socket caching to avoid reference leak (CVE-2025-38097)
  * kernel: bpf: fix ktls panic with sockmap (CVE-2025-38166)
  * kernel: bpf: Check rcu_read_lock_trace_held() in bpf_map_lookup_percpu_elem() (CVE-2025-38202)
  * kernel: bpf: Do not include stack ptr register in precision backtracking bookkeeping (CVE-2025-38279)
  * kernel: ring-buffer: Do not trigger WARN_ON() due to a commit_overrun (CVE-2025-38267)
  * kernel: phy: qcom-qmp-usb: Fix an NULL vs IS_ERR() bug (CVE-2025-38275)
  * kernel: ftrace: Fix UAF when lookup kallsym after ftrace disabled (CVE-2025-38346)
  * kernel: ACPICA: fix acpi operand cache leak in dswstate.c (CVE-2025-38345)
  * kernel: nvmet: fix memory leak of bio integrity (CVE-2025-38405)
  * kernel: netfilter: flowtable: account for Ethernet header in nf_flow_pppoe_proto() (CVE-2025-38441)
  * kernel: net: vlan: fix VLAN 0 refcount imbalance of toggling filtering during runtime (CVE-2025-38470)
  * kernel: fs: writeback: fix use-after…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: kernel, AlmaLinux:10: kernel-64k, AlmaLinux:10: kernel-64k-core, AlmaLinux:10: kernel-64k-debug, AlmaLinux:10: kernel-64k-debug-core, AlmaLinux:10: kernel-64k-debug-devel, AlmaLinux:10: kernel-64k-debug-devel-matched, AlmaLinux:10: kernel-64k-debug-modules, AlmaLinux:10: kernel-64k-debug-modules-core, AlmaLinux:10: kernel-64k-debug-modules-extra and 65 more&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: tcp_bpf: Fix the sk_mem_uncharge logic in tcp_bpf_sendmsg (CVE-2024-56633)
  * kernel: KVM: x86: Load DR6 with guest value only before entering .vcpu_run() loop (CVE-2025-21839)
  * kernel: block: fix resource leak in blk_register_queue() error path (CVE-2025-37980)
  * kernel: dmaengine: idxd: fix memory leak in error handling path of idxd_alloc (CVE-2025-38015)
  * kernel: espintcp: remove encap socket caching to avoid reference leak (CVE-2025-38097)
  * kernel: bpf: fix ktls panic with sockmap (CVE-2025-38166)
  * kernel: bpf: Check rcu_read_lock_trace_held() in bpf_map_lookup_percpu_elem() (CVE-2025-38202)
  * kernel: bpf: Do not include stack ptr register in precision backtracking bookkeeping (CVE-2025-38279)
  * kernel: ring-buffer: Do not trigger WARN_ON() due to a commit_overrun (CVE-2025-38267)
  * kernel: phy: qcom-qmp-usb: Fix an NULL vs IS_ERR() bug (CVE-2025-38275)
  * kernel: ftrace: Fix UAF when lookup kallsym after ftrace disabled (CVE-2025-38346)
  * kernel: ACPICA: fix acpi operand cache leak in dswstate.c (CVE-2025-38345)
  * kernel: nvmet: fix memory leak of bio integrity (CVE-2025-38405)
  * kernel: netfilter: flowtable: account for Ethernet header in nf_flow_pppoe_proto() (CVE-2025-38441)
  * kernel: net: vlan: fix VLAN 0 refcount imbalance of toggling filtering during runtime (CVE-2025-38470)
  * kernel: fs: writeback: fix use-after…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:18134</guid>
    </item>
    <item>
      <title>bdu:2026-11665</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-11665</link>
      <description>bdu:2026-11665</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-11665</guid>
    </item>
    <item>
      <title>BELL-CVE-2026-23243</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-23243</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-23243</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0341 — De multiples vulnérabilités ont été découvertes dans les produits Microsoft. Elles permettent à un attaquant de provoqu…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0341</link>
      <description>certfr-2026-avi-0341</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0341</guid>
    </item>
    <item>
      <title>EUVD-2026-364670</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-364670</link>
      <description>EUVD-2026-364670</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-364670</guid>
    </item>
    <item>
      <title>fkie_cve-2026-23243</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-23243</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;RDMA/umad: Reject negative data_len in ib_umad_write&lt;/p&gt;
&lt;p&gt;ib_umad_write computes data_len from user-controlled count and the
MAD header sizes. With a mismatched user MAD header size and RMPP
header length, data_len can become negative and reach ib_create_send_mad().
This can make the padding calculation exceed the segment size and trigger
an out-of-bounds memset in alloc_send_rmpp_list().&lt;/p&gt;
&lt;p&gt;Add an explicit check to reject negative data_len before creating the
send buffer.&lt;/p&gt;
&lt;p&gt;KASAN splat:
[  211.363464] BUG: KASAN: slab-out-of-bounds in ib_create_send_mad+0xa01/0x11b0
[  211.364077] Write of size 220 at addr ffff88800c3fa1f8 by task spray_thread/102
[  211.365867] ib_create_send_mad+0xa01/0x11b0
[  211.365887] ib_umad_write+0x853/0x1c80&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;RDMA/umad: Reject negative data_len in ib_umad_write&lt;/p&gt;
&lt;p&gt;ib_umad_write computes data_len from user-controlled count and the
MAD header sizes. With a mismatched user MAD header size and RMPP
header length, data_len can become negative and reach ib_create_send_mad().
This can make the padding calculation exceed the segment size and trigger
an out-of-bounds memset in alloc_send_rmpp_list().&lt;/p&gt;
&lt;p&gt;Add an explicit check to reject negative data_len before creating the
send buffer.&lt;/p&gt;
&lt;p&gt;KASAN splat:
[  211.363464] BUG: KASAN: slab-out-of-bounds in ib_create_send_mad+0xa01/0x11b0
[  211.364077] Write of size 220 at addr ffff88800c3fa1f8 by task spray_thread/102
[  211.365867] ib_create_send_mad+0xa01/0x11b0
[  211.365887] ib_umad_write+0x853/0x1c80&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-23243</guid>
    </item>
    <item>
      <title>GHSA-85rq-57vx-88q2</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-85rq-57vx-88q2</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;RDMA/umad: Reject negative data_len in ib_umad_write&lt;/p&gt;
&lt;p&gt;ib_umad_write computes data_len from user-controlled count and the
MAD header sizes. With a mismatched user MAD header size and RMPP
header length, data_len can become negative and reach ib_create_send_mad().
This can make the padding calculation exceed the segment size and trigger
an out-of-bounds memset in alloc_send_rmpp_list().&lt;/p&gt;
&lt;p&gt;Add an explicit check to reject negative data_len before creating the
send buffer.&lt;/p&gt;
&lt;p&gt;KASAN splat:
[  211.363464] BUG: KASAN: slab-out-of-bounds in ib_create_send_mad+0xa01/0x11b0
[  211.364077] Write of size 220 at addr ffff88800c3fa1f8 by task spray_thread/102
[  211.365867] ib_create_send_mad+0xa01/0x11b0
[  211.365887] ib_umad_write+0x853/0x1c80&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;RDMA/umad: Reject negative data_len in ib_umad_write&lt;/p&gt;
&lt;p&gt;ib_umad_write computes data_len from user-controlled count and the
MAD header sizes. With a mismatched user MAD header size and RMPP
header length, data_len can become negative and reach ib_create_send_mad().
This can make the padding calculation exceed the segment size and trigger
an out-of-bounds memset in alloc_send_rmpp_list().&lt;/p&gt;
&lt;p&gt;Add an explicit check to reject negative data_len before creating the
send buffer.&lt;/p&gt;
&lt;p&gt;KASAN splat:
[  211.363464] BUG: KASAN: slab-out-of-bounds in ib_create_send_mad+0xa01/0x11b0
[  211.364077] Write of size 220 at addr ffff88800c3fa1f8 by task spray_thread/102
[  211.365867] ib_create_send_mad+0xa01/0x11b0
[  211.365887] ib_umad_write+0x853/0x1c80&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-85rq-57vx-88q2</guid>
    </item>
    <item>
      <title>ICSA-26-209-04 — Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-26-209-04</link>
      <description>&lt;p&gt;Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.6 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant).&lt;/p&gt;
&lt;p&gt;Siemens is preparing fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.6 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant).&lt;/p&gt;
&lt;p&gt;Siemens is preparing fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-26-209-04</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-23243 — RDMA/umad: Reject negative data_len in ib_umad_write</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-23243</link>
      <description>msrc_CVE-2026-23243</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-23243</guid>
    </item>
    <item>
      <title>OESA-2026-1831 — kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-1831</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP4: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;A vulnerability exists in the RDMA/umad component of the Linux kernel when processing user-space data. The ib_umad_write function calculates data_len based on user-controlled count and MAD header sizes. When a mismatched user MAD header size and RMPP header length are provided, data_len can become negative and be passed to the ib_create_send_mad() function. This can cause subsequent padding calculations to exceed the segment size, ultimately triggering an out-of-bounds memory write (memset) in the alloc_send_rmpp_list() function. An attacker could potentially exploit this vulnerability to cause kernel memory corruption, affecting system stability and confidentiality.(CVE-2026-23243)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;x86/efi: defer freeing of boot services memory&lt;/p&gt;
&lt;p&gt;efi_free_boot_services() frees memory occupied by EFI_BOOT_SERVICES_CODE and EFI_BOOT_SERVICES_DATA using memblock_free_late().&lt;/p&gt;
&lt;p&gt;There are two issue with that: memblock_free_late() should be used for memory allocated with memblock_alloc() while the memory reserved with memblock_reserve() should be freed with free_reserved_area().&lt;/p&gt;
&lt;p&gt;More acutely, with CONFIG_DEFERRED_STRUCT_PAGE_INIT=y efi_free_boot_services() is called before deferred initialization of the memory map is complete.&lt;/p&gt;
&lt;p&gt;Benjamin Herrenschmidt reports that this causes a leak of ~140MB of RAM on EC2 t3a.nano instances which only have 512MB or RAM.&lt;/p&gt;
&lt;p&gt;I…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP4: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;A vulnerability exists in the RDMA/umad component of the Linux kernel when processing user-space data. The ib_umad_write function calculates data_len based on user-controlled count and MAD header sizes. When a mismatched user MAD header size and RMPP header length are provided, data_len can become negative and be passed to the ib_create_send_mad() function. This can cause subsequent padding calculations to exceed the segment size, ultimately triggering an out-of-bounds memory write (memset) in the alloc_send_rmpp_list() function. An attacker could potentially exploit this vulnerability to cause kernel memory corruption, affecting system stability and confidentiality.(CVE-2026-23243)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;x86/efi: defer freeing of boot services memory&lt;/p&gt;
&lt;p&gt;efi_free_boot_services() frees memory occupied by EFI_BOOT_SERVICES_CODE and EFI_BOOT_SERVICES_DATA using memblock_free_late().&lt;/p&gt;
&lt;p&gt;There are two issue with that: memblock_free_late() should be used for memory allocated with memblock_alloc() while the memory reserved with memblock_reserve() should be freed with free_reserved_area().&lt;/p&gt;
&lt;p&gt;More acutely, with CONFIG_DEFERRED_STRUCT_PAGE_INIT=y efi_free_boot_services() is called before deferred initialization of the memory map is complete.&lt;/p&gt;
&lt;p&gt;Benjamin Herrenschmidt reports that this causes a leak of ~140MB of RAM on EC2 t3a.nano instances which only have 512MB or RAM.&lt;/p&gt;
&lt;p&gt;I…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-1831</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:20572-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:20572-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:20572-1</guid>
    </item>
    <item>
      <title>RHSA-2026:13936 — Red Hat Security Advisory: kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:13936</link>
      <description>&lt;p&gt;kernel: scsi: mpi3mr: Synchronous access b/w reset and tm thread for reply queue kernel: Linux kernel: Denial of Service due to a deadlock in hugetlb folio migration kernel: ALSA: aloop: Fix racy access at PCM trigger kernel: scsi: target: iscsi: Fix use-after-free in iscsit_dec_session_usage_count() kernel: Linux kernel: Denial of service and memory corruption in RDMA umad kernel: Linux kernel KVM: Privilege escalation or denial of service due to improper shadow page table entry handling kernel: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache kernel: crypto: algif_aead - Revert to operating out-of-place kernel: crypto: algif_aead - Fix minimum RX size check for decryption&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;kernel: scsi: mpi3mr: Synchronous access b/w reset and tm thread for reply queue kernel: Linux kernel: Denial of Service due to a deadlock in hugetlb folio migration kernel: ALSA: aloop: Fix racy access at PCM trigger kernel: scsi: target: iscsi: Fix use-after-free in iscsit_dec_session_usage_count() kernel: Linux kernel: Denial of service and memory corruption in RDMA umad kernel: Linux kernel KVM: Privilege escalation or denial of service due to improper shadow page table entry handling kernel: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache kernel: crypto: algif_aead - Revert to operating out-of-place kernel: crypto: algif_aead - Fix minimum RX size check for decryption&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:13936</guid>
    </item>
    <item>
      <title>RLSA-2026:21706 — Important: kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:21706</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:8: kernel&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: Bluetooth: MGMT: Fix possible UAFs (CVE-2025-39981)&lt;/p&gt;
&lt;p&gt;* kernel: ima: don&amp;#39;t clear IMA_DIGSIG flag when setting or removing non-IMA xattr (CVE-2025-68183)&lt;/p&gt;
&lt;p&gt;* kernel: ALSA: firewire-motu: fix buffer overflow in hwdep read for DSP events (CVE-2025-68347)&lt;/p&gt;
&lt;p&gt;* kernel: libceph: make decode_pool() more resilient against corrupted osdmaps (CVE-2025-71116)&lt;/p&gt;
&lt;p&gt;* kernel: Linux kernel: Denial of service and memory corruption in RDMA umad (CVE-2026-23243)&lt;/p&gt;
&lt;p&gt;* kernel: Linux kernel: Use-after-free in traffic control (act_ct) may lead to denial of service or privilege escalation (CVE-2026-23270)&lt;/p&gt;
&lt;p&gt;* kernel: netfilter: nf_conntrack_h323: check for zero length in DecodeQ931() (CVE-2026-23455)&lt;/p&gt;
&lt;p&gt;* kernel: Bluetooth: SCO: Fix use-after-free in sco_recv_frame() due to missing sock_hold (CVE-2026-31408)&lt;/p&gt;
&lt;p&gt;* kernel: can: raw: fix ro-&amp;gt;uniq use-after-free in raw_rcv() (CVE-2026-31532)&lt;/p&gt;
&lt;p&gt;* kernel: net: sched: act_csum: validate nested VLAN headers (CVE-2026-31684)&lt;/p&gt;
&lt;p&gt;* kernel: netfilter: ip6t_eui64: reject invalid MAC header for all packets (CVE-2026-31685)&lt;/p&gt;
&lt;p&gt;* kernel: netfilter: nf_conntrack_helper: pass helper to expect cleanup (CVE-2026-43027)&lt;/p&gt;
&lt;p&gt;* kernel: Bluetooth: MGMT: validate LTK enc_size on load (CVE-2026-43020)&lt;/p&gt;
&lt;p&gt;* kernel: HID: wacom: fix out-of-bounds read in wacom_intuos_bt_irq (CVE-2026-43051)&lt;/p&gt;
&lt;p&gt;* kernel: smb: client: validate the whole DACL before rewriting it in cifsacl (CVE-2026-31709)…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:8: kernel&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: Bluetooth: MGMT: Fix possible UAFs (CVE-2025-39981)&lt;/p&gt;
&lt;p&gt;* kernel: ima: don&amp;#39;t clear IMA_DIGSIG flag when setting or removing non-IMA xattr (CVE-2025-68183)&lt;/p&gt;
&lt;p&gt;* kernel: ALSA: firewire-motu: fix buffer overflow in hwdep read for DSP events (CVE-2025-68347)&lt;/p&gt;
&lt;p&gt;* kernel: libceph: make decode_pool() more resilient against corrupted osdmaps (CVE-2025-71116)&lt;/p&gt;
&lt;p&gt;* kernel: Linux kernel: Denial of service and memory corruption in RDMA umad (CVE-2026-23243)&lt;/p&gt;
&lt;p&gt;* kernel: Linux kernel: Use-after-free in traffic control (act_ct) may lead to denial of service or privilege escalation (CVE-2026-23270)&lt;/p&gt;
&lt;p&gt;* kernel: netfilter: nf_conntrack_h323: check for zero length in DecodeQ931() (CVE-2026-23455)&lt;/p&gt;
&lt;p&gt;* kernel: Bluetooth: SCO: Fix use-after-free in sco_recv_frame() due to missing sock_hold (CVE-2026-31408)&lt;/p&gt;
&lt;p&gt;* kernel: can: raw: fix ro-&amp;gt;uniq use-after-free in raw_rcv() (CVE-2026-31532)&lt;/p&gt;
&lt;p&gt;* kernel: net: sched: act_csum: validate nested VLAN headers (CVE-2026-31684)&lt;/p&gt;
&lt;p&gt;* kernel: netfilter: ip6t_eui64: reject invalid MAC header for all packets (CVE-2026-31685)&lt;/p&gt;
&lt;p&gt;* kernel: netfilter: nf_conntrack_helper: pass helper to expect cleanup (CVE-2026-43027)&lt;/p&gt;
&lt;p&gt;* kernel: Bluetooth: MGMT: validate LTK enc_size on load (CVE-2026-43020)&lt;/p&gt;
&lt;p&gt;* kernel: HID: wacom: fix out-of-bounds read in wacom_intuos_bt_irq (CVE-2026-43051)&lt;/p&gt;
&lt;p&gt;* kernel: smb: client: validate the whole DACL before rewriting it in cifsacl (CVE-2026-31709)…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:21706</guid>
    </item>
    <item>
      <title>SSA-019113 — SSA-019113: Vulnerabilities in the additional GNU/Linux subsystem of the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1.6</title>
      <link>https://cve.radiocsirt.org/vuln/ssa-019113</link>
      <description>&lt;p&gt;Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.6 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant).&lt;/p&gt;
&lt;p&gt;Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.6 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant).&lt;/p&gt;
&lt;p&gt;Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ssa-019113</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:1342-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:1342-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:1342-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-23243</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-23243</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux, Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe and 232 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: RDMA/umad: Reject negative data_len in ib_umad_write ib_umad_write computes data_len from user-controlled count and the MAD header sizes. With a mismatched user MAD header size and RMPP header length, data_len can become negative and reach ib_create_send_mad(). This can make the padding calculation exceed the segment size and trigger an out-of-bounds memset in alloc_send_rmpp_list(). Add an explicit check to reject negative data_len before creating the send buffer. KASAN splat: [  211.363464] BUG: KASAN: slab-out-of-bounds in ib_create_send_mad+0xa01/0x11b0 [  211.364077] Write of size 220 at addr ffff88800c3fa1f8 by task spray_thread/102 [  211.365867] ib_create_send_mad+0xa01/0x11b0 [  211.365887] ib_umad_write+0x853/0x1c80&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux, Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe and 232 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: RDMA/umad: Reject negative data_len in ib_umad_write ib_umad_write computes data_len from user-controlled count and the MAD header sizes. With a mismatched user MAD header size and RMPP header length, data_len can become negative and reach ib_create_send_mad(). This can make the padding calculation exceed the segment size and trigger an out-of-bounds memset in alloc_send_rmpp_list(). Add an explicit check to reject negative data_len before creating the send buffer. KASAN splat: [  211.363464] BUG: KASAN: slab-out-of-bounds in ib_create_send_mad+0xa01/0x11b0 [  211.364077] Write of size 220 at addr ffff88800c3fa1f8 by task spray_thread/102 [  211.365867] ib_create_send_mad+0xa01/0x11b0 [  211.365887] ib_umad_write+0x853/0x1c80&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-23243</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-0774 — Linux Kernel: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0774</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux-Kernel ausnutzen, um nicht näher spezifizierte Angriffe durchzuführen, die möglicherweise zu einer Denial-of-Service- Bedingung führen oder eine Speicherbeschädigung verursachen können.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux-Kernel ausnutzen, um nicht näher spezifizierte Angriffe durchzuführen, die möglicherweise zu einer Denial-of-Service- Bedingung führen oder eine Speicherbeschädigung verursachen können.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0774</guid>
    </item>
  </channel>
</rss>
