<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 18:39:17 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-04164</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-04164</link>
      <description>bdu:2026-04164</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-04164</guid>
    </item>
    <item>
      <title>BELL-CVE-2026-23255</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-23255</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-23255</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0497 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de SUSE. Certaines d'entre elles permettent à un at…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0497</link>
      <description>certfr-2026-avi-0497</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0497</guid>
    </item>
    <item>
      <title>EUVD-2026-364672</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-364672</link>
      <description>EUVD-2026-364672</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-364672</guid>
    </item>
    <item>
      <title>fkie_cve-2026-23255</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-23255</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;net: add proper RCU protection to /proc/net/ptype&lt;/p&gt;
&lt;p&gt;Yin Fengwei reported an RCU stall in ptype_seq_show() and provided
a patch.&lt;/p&gt;
&lt;p&gt;Real issue is that ptype_seq_next() and ptype_seq_show() violate
RCU rules.&lt;/p&gt;
&lt;p&gt;ptype_seq_show() runs under rcu_read_lock(), and reads pt-&amp;gt;dev
to get device name without any barrier.&lt;/p&gt;
&lt;p&gt;At the same time, concurrent writers can remove a packet_type structure
(which is correctly freed after an RCU grace period) and clear pt-&amp;gt;dev
without an RCU grace period.&lt;/p&gt;
&lt;p&gt;Define ptype_iter_state to carry a dev pointer along seq_net_private:&lt;/p&gt;
&lt;p&gt;struct ptype_iter_state {
	struct seq_net_private	p;
	struct net_device	*dev; // added in this patch
};&lt;/p&gt;
&lt;p&gt;We need to record the device pointer in ptype_get_idx() and
ptype_seq_next() so that ptype_seq_show() is safe against
concurrent pt-&amp;gt;dev changes.&lt;/p&gt;
&lt;p&gt;We also need to add full RCU protection in ptype_seq_next().
(Missing READ_ONCE() when reading list.next values)&lt;/p&gt;
&lt;p&gt;Many thanks to Dong Chenchen for providing a repro.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;net: add proper RCU protection to /proc/net/ptype&lt;/p&gt;
&lt;p&gt;Yin Fengwei reported an RCU stall in ptype_seq_show() and provided
a patch.&lt;/p&gt;
&lt;p&gt;Real issue is that ptype_seq_next() and ptype_seq_show() violate
RCU rules.&lt;/p&gt;
&lt;p&gt;ptype_seq_show() runs under rcu_read_lock(), and reads pt-&amp;gt;dev
to get device name without any barrier.&lt;/p&gt;
&lt;p&gt;At the same time, concurrent writers can remove a packet_type structure
(which is correctly freed after an RCU grace period) and clear pt-&amp;gt;dev
without an RCU grace period.&lt;/p&gt;
&lt;p&gt;Define ptype_iter_state to carry a dev pointer along seq_net_private:&lt;/p&gt;
&lt;p&gt;struct ptype_iter_state {
	struct seq_net_private	p;
	struct net_device	*dev; // added in this patch
};&lt;/p&gt;
&lt;p&gt;We need to record the device pointer in ptype_get_idx() and
ptype_seq_next() so that ptype_seq_show() is safe against
concurrent pt-&amp;gt;dev changes.&lt;/p&gt;
&lt;p&gt;We also need to add full RCU protection in ptype_seq_next().
(Missing READ_ONCE() when reading list.next values)&lt;/p&gt;
&lt;p&gt;Many thanks to Dong Chenchen for providing a repro.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-23255</guid>
    </item>
    <item>
      <title>GHSA-9w39-mw48-92gc</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-9w39-mw48-92gc</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;net: add proper RCU protection to /proc/net/ptype&lt;/p&gt;
&lt;p&gt;Yin Fengwei reported an RCU stall in ptype_seq_show() and provided
a patch.&lt;/p&gt;
&lt;p&gt;Real issue is that ptype_seq_next() and ptype_seq_show() violate
RCU rules.&lt;/p&gt;
&lt;p&gt;ptype_seq_show() runs under rcu_read_lock(), and reads pt-&amp;gt;dev
to get device name without any barrier.&lt;/p&gt;
&lt;p&gt;At the same time, concurrent writers can remove a packet_type structure
(which is correctly freed after an RCU grace period) and clear pt-&amp;gt;dev
without an RCU grace period.&lt;/p&gt;
&lt;p&gt;Define ptype_iter_state to carry a dev pointer along seq_net_private:&lt;/p&gt;
&lt;p&gt;struct ptype_iter_state {
	struct seq_net_private	p;
	struct net_device	*dev; // added in this patch
};&lt;/p&gt;
&lt;p&gt;We need to record the device pointer in ptype_get_idx() and
ptype_seq_next() so that ptype_seq_show() is safe against
concurrent pt-&amp;gt;dev changes.&lt;/p&gt;
&lt;p&gt;We also need to add full RCU protection in ptype_seq_next().
(Missing READ_ONCE() when reading list.next values)&lt;/p&gt;
&lt;p&gt;Many thanks to Dong Chenchen for providing a repro.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;net: add proper RCU protection to /proc/net/ptype&lt;/p&gt;
&lt;p&gt;Yin Fengwei reported an RCU stall in ptype_seq_show() and provided
a patch.&lt;/p&gt;
&lt;p&gt;Real issue is that ptype_seq_next() and ptype_seq_show() violate
RCU rules.&lt;/p&gt;
&lt;p&gt;ptype_seq_show() runs under rcu_read_lock(), and reads pt-&amp;gt;dev
to get device name without any barrier.&lt;/p&gt;
&lt;p&gt;At the same time, concurrent writers can remove a packet_type structure
(which is correctly freed after an RCU grace period) and clear pt-&amp;gt;dev
without an RCU grace period.&lt;/p&gt;
&lt;p&gt;Define ptype_iter_state to carry a dev pointer along seq_net_private:&lt;/p&gt;
&lt;p&gt;struct ptype_iter_state {
	struct seq_net_private	p;
	struct net_device	*dev; // added in this patch
};&lt;/p&gt;
&lt;p&gt;We need to record the device pointer in ptype_get_idx() and
ptype_seq_next() so that ptype_seq_show() is safe against
concurrent pt-&amp;gt;dev changes.&lt;/p&gt;
&lt;p&gt;We also need to add full RCU protection in ptype_seq_next().
(Missing READ_ONCE() when reading list.next values)&lt;/p&gt;
&lt;p&gt;Many thanks to Dong Chenchen for providing a repro.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-9w39-mw48-92gc</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-23255 — net: add proper RCU protection to /proc/net/ptype</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-23255</link>
      <description>msrc_CVE-2026-23255</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-23255</guid>
    </item>
    <item>
      <title>OESA-2026-1862 — kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-1862</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;f2fs: fix to detect potential corrupted nid in free_nid_list&lt;/p&gt;
&lt;p&gt;As reported, on-disk footer.ino and footer.nid is the same and
out-of-range, let&amp;amp;apos;s add sanity check on f2fs_alloc_nid() to detect
any potential corruption in free_nid_list.(CVE-2025-68315)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;ntfs3: Fix uninit buffer allocated by __getname()&lt;/p&gt;
&lt;p&gt;Fix uninit errors caused after buffer allocation given to &amp;amp;apos;de&amp;amp;apos;; by
initializing the buffer with zeroes. The fix was found by using KMSAN.(CVE-2025-68727)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;netfilter: nf_tables: fix use-after-free in nf_tables_addchain()&lt;/p&gt;
&lt;p&gt;nf_tables_addchain() publishes the chain to table-&amp;amp;gt;chains via
list_add_tail_rcu() (in nft_chain_add()) before registering hooks.
If nf_tables_register_hook() then fails, the error path calls
nft_chain_del() (list_del_rcu()) followed by nf_tables_chain_destroy()
with no RCU grace period in between.&lt;/p&gt;
&lt;p&gt;This creates two use-after-free conditions:&lt;/p&gt;
&lt;p&gt;1) Control-plane: nf_tables_dump_chains() traverses table-&amp;amp;gt;chains
    under rcu_read_lock(). A concurrent dump can still be walking
    the chain when the error path frees it.&lt;/p&gt;
&lt;p&gt;2) Packet path: for NFPROTO_INET, nf_register_net_hook() briefly
    installs the IPv4 hook before IPv6 registration fails.  Packets
    entering nft…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;f2fs: fix to detect potential corrupted nid in free_nid_list&lt;/p&gt;
&lt;p&gt;As reported, on-disk footer.ino and footer.nid is the same and
out-of-range, let&amp;amp;apos;s add sanity check on f2fs_alloc_nid() to detect
any potential corruption in free_nid_list.(CVE-2025-68315)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;ntfs3: Fix uninit buffer allocated by __getname()&lt;/p&gt;
&lt;p&gt;Fix uninit errors caused after buffer allocation given to &amp;amp;apos;de&amp;amp;apos;; by
initializing the buffer with zeroes. The fix was found by using KMSAN.(CVE-2025-68727)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;netfilter: nf_tables: fix use-after-free in nf_tables_addchain()&lt;/p&gt;
&lt;p&gt;nf_tables_addchain() publishes the chain to table-&amp;amp;gt;chains via
list_add_tail_rcu() (in nft_chain_add()) before registering hooks.
If nf_tables_register_hook() then fails, the error path calls
nft_chain_del() (list_del_rcu()) followed by nf_tables_chain_destroy()
with no RCU grace period in between.&lt;/p&gt;
&lt;p&gt;This creates two use-after-free conditions:&lt;/p&gt;
&lt;p&gt;1) Control-plane: nf_tables_dump_chains() traverses table-&amp;amp;gt;chains
    under rcu_read_lock(). A concurrent dump can still be walking
    the chain when the error path frees it.&lt;/p&gt;
&lt;p&gt;2) Packet path: for NFPROTO_INET, nf_register_net_hook() briefly
    installs the IPv4 hook before IPv6 registration fails.  Packets
    entering nft…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-1862</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:20572-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:20572-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:20572-1</guid>
    </item>
    <item>
      <title>SSA-019113 — SSA-019113: Vulnerabilities in the additional GNU/Linux subsystem of the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1.6</title>
      <link>https://cve.radiocsirt.org/vuln/ssa-019113</link>
      <description>&lt;p&gt;Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.6 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant).&lt;/p&gt;
&lt;p&gt;Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.6 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant).&lt;/p&gt;
&lt;p&gt;Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ssa-019113</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:1573-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:1573-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:1573-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-23255</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-23255</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux, Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe and 232 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: net: add proper RCU protection to /proc/net/ptype Yin Fengwei reported an RCU stall in ptype_seq_show() and provided a patch. Real issue is that ptype_seq_next() and ptype_seq_show() violate RCU rules. ptype_seq_show() runs under rcu_read_lock(), and reads pt-&amp;gt;dev to get device name without any barrier. At the same time, concurrent writers can remove a packet_type structure (which is correctly freed after an RCU grace period) and clear pt-&amp;gt;dev without an RCU grace period. Define ptype_iter_state to carry a dev pointer along seq_net_private: struct ptype_iter_state { 	struct seq_net_private	p; 	struct net_device	*dev; // added in this patch }; We need to record the device pointer in ptype_get_idx() and ptype_seq_next() so that ptype_seq_show() is safe against concurrent pt-&amp;gt;dev changes. We also need to add full RCU protection in ptype_seq_next(). (Missing READ_ONCE() when reading list.next values) Many thanks to Dong Chenchen for providing a repro.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux, Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe and 232 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: net: add proper RCU protection to /proc/net/ptype Yin Fengwei reported an RCU stall in ptype_seq_show() and provided a patch. Real issue is that ptype_seq_next() and ptype_seq_show() violate RCU rules. ptype_seq_show() runs under rcu_read_lock(), and reads pt-&amp;gt;dev to get device name without any barrier. At the same time, concurrent writers can remove a packet_type structure (which is correctly freed after an RCU grace period) and clear pt-&amp;gt;dev without an RCU grace period. Define ptype_iter_state to carry a dev pointer along seq_net_private: struct ptype_iter_state { 	struct seq_net_private	p; 	struct net_device	*dev; // added in this patch }; We need to record the device pointer in ptype_get_idx() and ptype_seq_next() so that ptype_seq_show() is safe against concurrent pt-&amp;gt;dev changes. We also need to add full RCU protection in ptype_seq_next(). (Missing READ_ONCE() when reading list.next values) Many thanks to Dong Chenchen for providing a repro.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-23255</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-0790 — Linux Kernel: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0790</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Linux Kernel ausnutzen, um nicht näher spezifizierte Angriffe durchzuführen, die möglicherweise zu einem Denial-of-Service-Zustand, einer Rechteausweitung oder einer Speicherbeschädigung führen können.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Linux Kernel ausnutzen, um nicht näher spezifizierte Angriffe durchzuführen, die möglicherweise zu einem Denial-of-Service-Zustand, einer Rechteausweitung oder einer Speicherbeschädigung führen können.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0790</guid>
    </item>
  </channel>
</rss>
