<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 10:10:50 +0000</lastBuildDate>
    <item>
      <title>BELL-CVE-2026-23294</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-23294</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-23294</guid>
    </item>
    <item>
      <title>EUVD-2026-347632</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-347632</link>
      <description>EUVD-2026-347632</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-347632</guid>
    </item>
    <item>
      <title>fkie_cve-2026-23294</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-23294</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;bpf: Fix race in devmap on PREEMPT_RT&lt;/p&gt;
&lt;p&gt;On PREEMPT_RT kernels, the per-CPU xdp_dev_bulk_queue (bq) can be
accessed concurrently by multiple preemptible tasks on the same CPU.&lt;/p&gt;
&lt;p&gt;The original code assumes bq_enqueue() and __dev_flush() run atomically
with respect to each other on the same CPU, relying on
local_bh_disable() to prevent preemption. However, on PREEMPT_RT,
local_bh_disable() only calls migrate_disable() (when
PREEMPT_RT_NEEDS_BH_LOCK is not set) and does not disable
preemption, which allows CFS scheduling to preempt a task during
bq_xmit_all(), enabling another task on the same CPU to enter
bq_enqueue() and operate on the same per-CPU bq concurrently.&lt;/p&gt;
&lt;p&gt;This leads to several races:&lt;/p&gt;
&lt;p&gt;1. Double-free / use-after-free on bq-&amp;gt;q[]: bq_xmit_all() snapshots
   cnt = bq-&amp;gt;count, then iterates bq-&amp;gt;q[0..cnt-1] to transmit frames.
   If preempted after the snapshot, a second task can call bq_enqueue()
   -&amp;gt; bq_xmit_all() on the same bq, transmitting (and freeing) the
   same frames. When the first task resumes, it operates on stale
   pointers in bq-&amp;gt;q[], causing use-after-free.&lt;/p&gt;
&lt;p&gt;2. bq-&amp;gt;count and bq-&amp;gt;q[] corruption: concurrent bq_enqueue() modifying
   bq-&amp;gt;count and bq-&amp;gt;q[] while bq_xmit_all() is reading them.&lt;/p&gt;
&lt;p&gt;3. dev_rx/xdp_prog teardown race: __dev_flush() clears bq-&amp;gt;dev_rx and
   bq-&amp;gt;xdp_prog after bq_xmit_all(). If preempted between
   bq_xmit_all() return and bq-&amp;gt;dev_rx = NULL, a preempting
   bq_enqueue()…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;bpf: Fix race in devmap on PREEMPT_RT&lt;/p&gt;
&lt;p&gt;On PREEMPT_RT kernels, the per-CPU xdp_dev_bulk_queue (bq) can be
accessed concurrently by multiple preemptible tasks on the same CPU.&lt;/p&gt;
&lt;p&gt;The original code assumes bq_enqueue() and __dev_flush() run atomically
with respect to each other on the same CPU, relying on
local_bh_disable() to prevent preemption. However, on PREEMPT_RT,
local_bh_disable() only calls migrate_disable() (when
PREEMPT_RT_NEEDS_BH_LOCK is not set) and does not disable
preemption, which allows CFS scheduling to preempt a task during
bq_xmit_all(), enabling another task on the same CPU to enter
bq_enqueue() and operate on the same per-CPU bq concurrently.&lt;/p&gt;
&lt;p&gt;This leads to several races:&lt;/p&gt;
&lt;p&gt;1. Double-free / use-after-free on bq-&amp;gt;q[]: bq_xmit_all() snapshots
   cnt = bq-&amp;gt;count, then iterates bq-&amp;gt;q[0..cnt-1] to transmit frames.
   If preempted after the snapshot, a second task can call bq_enqueue()
   -&amp;gt; bq_xmit_all() on the same bq, transmitting (and freeing) the
   same frames. When the first task resumes, it operates on stale
   pointers in bq-&amp;gt;q[], causing use-after-free.&lt;/p&gt;
&lt;p&gt;2. bq-&amp;gt;count and bq-&amp;gt;q[] corruption: concurrent bq_enqueue() modifying
   bq-&amp;gt;count and bq-&amp;gt;q[] while bq_xmit_all() is reading them.&lt;/p&gt;
&lt;p&gt;3. dev_rx/xdp_prog teardown race: __dev_flush() clears bq-&amp;gt;dev_rx and
   bq-&amp;gt;xdp_prog after bq_xmit_all(). If preempted between
   bq_xmit_all() return and bq-&amp;gt;dev_rx = NULL, a preempting
   bq_enqueue()…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-23294</guid>
    </item>
    <item>
      <title>GHSA-4h26-3w83-pfh6</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-4h26-3w83-pfh6</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;bpf: Fix race in devmap on PREEMPT_RT&lt;/p&gt;
&lt;p&gt;On PREEMPT_RT kernels, the per-CPU xdp_dev_bulk_queue (bq) can be
accessed concurrently by multiple preemptible tasks on the same CPU.&lt;/p&gt;
&lt;p&gt;The original code assumes bq_enqueue() and __dev_flush() run atomically
with respect to each other on the same CPU, relying on
local_bh_disable() to prevent preemption. However, on PREEMPT_RT,
local_bh_disable() only calls migrate_disable() (when
PREEMPT_RT_NEEDS_BH_LOCK is not set) and does not disable
preemption, which allows CFS scheduling to preempt a task during
bq_xmit_all(), enabling another task on the same CPU to enter
bq_enqueue() and operate on the same per-CPU bq concurrently.&lt;/p&gt;
&lt;p&gt;This leads to several races:&lt;/p&gt;
&lt;p&gt;1. Double-free / use-after-free on bq-&amp;gt;q[]: bq_xmit_all() snapshots
   cnt = bq-&amp;gt;count, then iterates bq-&amp;gt;q[0..cnt-1] to transmit frames.
   If preempted after the snapshot, a second task can call bq_enqueue()
   -&amp;gt; bq_xmit_all() on the same bq, transmitting (and freeing) the
   same frames. When the first task resumes, it operates on stale
   pointers in bq-&amp;gt;q[], causing use-after-free.&lt;/p&gt;
&lt;p&gt;2. bq-&amp;gt;count and bq-&amp;gt;q[] corruption: concurrent bq_enqueue() modifying
   bq-&amp;gt;count and bq-&amp;gt;q[] while bq_xmit_all() is reading them.&lt;/p&gt;
&lt;p&gt;3. dev_rx/xdp_prog teardown race: __dev_flush() clears bq-&amp;gt;dev_rx and
   bq-&amp;gt;xdp_prog after bq_xmit_all(). If preempted between
   bq_xmit_all() return and bq-&amp;gt;dev_rx = NULL, a preempting
   bq_enqueue()…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;bpf: Fix race in devmap on PREEMPT_RT&lt;/p&gt;
&lt;p&gt;On PREEMPT_RT kernels, the per-CPU xdp_dev_bulk_queue (bq) can be
accessed concurrently by multiple preemptible tasks on the same CPU.&lt;/p&gt;
&lt;p&gt;The original code assumes bq_enqueue() and __dev_flush() run atomically
with respect to each other on the same CPU, relying on
local_bh_disable() to prevent preemption. However, on PREEMPT_RT,
local_bh_disable() only calls migrate_disable() (when
PREEMPT_RT_NEEDS_BH_LOCK is not set) and does not disable
preemption, which allows CFS scheduling to preempt a task during
bq_xmit_all(), enabling another task on the same CPU to enter
bq_enqueue() and operate on the same per-CPU bq concurrently.&lt;/p&gt;
&lt;p&gt;This leads to several races:&lt;/p&gt;
&lt;p&gt;1. Double-free / use-after-free on bq-&amp;gt;q[]: bq_xmit_all() snapshots
   cnt = bq-&amp;gt;count, then iterates bq-&amp;gt;q[0..cnt-1] to transmit frames.
   If preempted after the snapshot, a second task can call bq_enqueue()
   -&amp;gt; bq_xmit_all() on the same bq, transmitting (and freeing) the
   same frames. When the first task resumes, it operates on stale
   pointers in bq-&amp;gt;q[], causing use-after-free.&lt;/p&gt;
&lt;p&gt;2. bq-&amp;gt;count and bq-&amp;gt;q[] corruption: concurrent bq_enqueue() modifying
   bq-&amp;gt;count and bq-&amp;gt;q[] while bq_xmit_all() is reading them.&lt;/p&gt;
&lt;p&gt;3. dev_rx/xdp_prog teardown race: __dev_flush() clears bq-&amp;gt;dev_rx and
   bq-&amp;gt;xdp_prog after bq_xmit_all(). If preempted between
   bq_xmit_all() return and bq-&amp;gt;dev_rx = NULL, a preempting
   bq_enqueue()…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-4h26-3w83-pfh6</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-23294</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-23294</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 82 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: bpf: Fix race in devmap on PREEMPT_RT On PREEMPT_RT kernels, the per-CPU xdp_dev_bulk_queue (bq) can be accessed concurrently by multiple preemptible tasks on the same CPU. The original code assumes bq_enqueue() and __dev_flush() run atomically with respect to each other on the same CPU, relying on local_bh_disable() to prevent preemption. However, on PREEMPT_RT, local_bh_disable() only calls migrate_disable() (when PREEMPT_RT_NEEDS_BH_LOCK is not set) and does not disable preemption, which allows CFS scheduling to preempt a task during bq_xmit_all(), enabling another task on the same CPU to enter bq_enqueue() and operate on the same per-CPU bq concurrently. This leads to several races: 1. Double-free / use-after-free on bq-&amp;gt;q[]: bq_xmit_all() snapshots    cnt = bq-&amp;gt;count, then iterates bq-&amp;gt;q[0..cnt-1] to transmit frames.    If preempted after the snapshot, a second task can call bq_enqueue()    -&amp;gt; bq_xmit_all() on the same bq, transmitting (and freeing) the    same frames. When the first task resumes, it operates on stale    pointers in bq-&amp;gt;q[], causing use-after-free. 2. bq-&amp;gt;count and bq-&amp;gt;q[] corruption: concurrent bq_enqueue() modifying    bq-&amp;gt;count and bq-&amp;gt;q[] while bq_xmit_all() is reading them. 3. dev_rx/xdp_prog teardown race: __dev_flush() clears bq-&amp;gt;dev_rx and    bq-&amp;gt;xdp_prog after bq_xmit_all(). If preempted between    bq_xmit_all() return and bq-&amp;gt;dev_rx = NULL, a preempting    bq_enqueue() sees de…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 82 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: bpf: Fix race in devmap on PREEMPT_RT On PREEMPT_RT kernels, the per-CPU xdp_dev_bulk_queue (bq) can be accessed concurrently by multiple preemptible tasks on the same CPU. The original code assumes bq_enqueue() and __dev_flush() run atomically with respect to each other on the same CPU, relying on local_bh_disable() to prevent preemption. However, on PREEMPT_RT, local_bh_disable() only calls migrate_disable() (when PREEMPT_RT_NEEDS_BH_LOCK is not set) and does not disable preemption, which allows CFS scheduling to preempt a task during bq_xmit_all(), enabling another task on the same CPU to enter bq_enqueue() and operate on the same per-CPU bq concurrently. This leads to several races: 1. Double-free / use-after-free on bq-&amp;gt;q[]: bq_xmit_all() snapshots    cnt = bq-&amp;gt;count, then iterates bq-&amp;gt;q[0..cnt-1] to transmit frames.    If preempted after the snapshot, a second task can call bq_enqueue()    -&amp;gt; bq_xmit_all() on the same bq, transmitting (and freeing) the    same frames. When the first task resumes, it operates on stale    pointers in bq-&amp;gt;q[], causing use-after-free. 2. bq-&amp;gt;count and bq-&amp;gt;q[] corruption: concurrent bq_enqueue() modifying    bq-&amp;gt;count and bq-&amp;gt;q[] while bq_xmit_all() is reading them. 3. dev_rx/xdp_prog teardown race: __dev_flush() clears bq-&amp;gt;dev_rx and    bq-&amp;gt;xdp_prog after bq_xmit_all(). If preempted between    bq_xmit_all() return and bq-&amp;gt;dev_rx = NULL, a preempting    bq_enqueue() sees de…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-23294</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-0861 — Linux Kernel: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0861</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Linux Kernel ausnutzen, um einen Denial of Service zu verursachen, Sicherheitsmaßnahmen zu umgehen, Informationen offenzulegen, weitere nicht spezifizierte Auswirkungen zu verursachen und potentiell Code auszuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Linux Kernel ausnutzen, um einen Denial of Service zu verursachen, Sicherheitsmaßnahmen zu umgehen, Informationen offenzulegen, weitere nicht spezifizierte Auswirkungen zu verursachen und potentiell Code auszuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0861</guid>
    </item>
  </channel>
</rss>
