<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 13:39:23 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-12229</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-12229</link>
      <description>bdu:2026-12229</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-12229</guid>
    </item>
    <item>
      <title>BELL-CVE-2026-23397</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-23397</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-23397</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0376 — De multiples vulnérabilités ont été découvertes dans les produits Microsoft. Elles permettent à un attaquant de provoqu…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0376</link>
      <description>certfr-2026-avi-0376</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0376</guid>
    </item>
    <item>
      <title>EUVD-2026-364699</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-364699</link>
      <description>EUVD-2026-364699</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-364699</guid>
    </item>
    <item>
      <title>fkie_cve-2026-23397</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-23397</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;nfnetlink_osf: validate individual option lengths in fingerprints&lt;/p&gt;
&lt;p&gt;nfnl_osf_add_callback() validates opt_num bounds and string
NUL-termination but does not check individual option length fields.
A zero-length option causes nf_osf_match_one() to enter the option
matching loop even when foptsize sums to zero, which matches packets
with no TCP options where ctx-&amp;gt;optp is NULL:&lt;/p&gt;
&lt;p&gt;Oops: general protection fault
 KASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007]
 RIP: 0010:nf_osf_match_one (net/netfilter/nfnetlink_osf.c:98)
 Call Trace:
  nf_osf_match (net/netfilter/nfnetlink_osf.c:227)
  xt_osf_match_packet (net/netfilter/xt_osf.c:32)
  ipt_do_table (net/ipv4/netfilter/ip_tables.c:293)
  nf_hook_slow (net/netfilter/core.c:623)
  ip_local_deliver (net/ipv4/ip_input.c:262)
  ip_rcv (net/ipv4/ip_input.c:573)&lt;/p&gt;
&lt;p&gt;Additionally, an MSS option (kind=2) with length &amp;lt; 4 causes
out-of-bounds reads when nf_osf_match_one() unconditionally accesses
optp[2] and optp[3] for MSS value extraction.  While RFC 9293
section 3.2 specifies that the MSS option is always exactly 4
bytes (Kind=2, Length=4), the check uses &amp;#34;&amp;lt; 4&amp;#34; rather than
&amp;#34;!= 4&amp;#34; because lengths greater than 4 do not cause memory
safety issues -- the buffer is guaranteed to be at least
foptsize bytes by the ctx-&amp;gt;optsize == foptsize check.&lt;/p&gt;
&lt;p&gt;Reject fingerprints where any option has zero length, or where an MSS
option has length less than 4, at add time ra…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;nfnetlink_osf: validate individual option lengths in fingerprints&lt;/p&gt;
&lt;p&gt;nfnl_osf_add_callback() validates opt_num bounds and string
NUL-termination but does not check individual option length fields.
A zero-length option causes nf_osf_match_one() to enter the option
matching loop even when foptsize sums to zero, which matches packets
with no TCP options where ctx-&amp;gt;optp is NULL:&lt;/p&gt;
&lt;p&gt;Oops: general protection fault
 KASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007]
 RIP: 0010:nf_osf_match_one (net/netfilter/nfnetlink_osf.c:98)
 Call Trace:
  nf_osf_match (net/netfilter/nfnetlink_osf.c:227)
  xt_osf_match_packet (net/netfilter/xt_osf.c:32)
  ipt_do_table (net/ipv4/netfilter/ip_tables.c:293)
  nf_hook_slow (net/netfilter/core.c:623)
  ip_local_deliver (net/ipv4/ip_input.c:262)
  ip_rcv (net/ipv4/ip_input.c:573)&lt;/p&gt;
&lt;p&gt;Additionally, an MSS option (kind=2) with length &amp;lt; 4 causes
out-of-bounds reads when nf_osf_match_one() unconditionally accesses
optp[2] and optp[3] for MSS value extraction.  While RFC 9293
section 3.2 specifies that the MSS option is always exactly 4
bytes (Kind=2, Length=4), the check uses &amp;#34;&amp;lt; 4&amp;#34; rather than
&amp;#34;!= 4&amp;#34; because lengths greater than 4 do not cause memory
safety issues -- the buffer is guaranteed to be at least
foptsize bytes by the ctx-&amp;gt;optsize == foptsize check.&lt;/p&gt;
&lt;p&gt;Reject fingerprints where any option has zero length, or where an MSS
option has length less than 4, at add time ra…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-23397</guid>
    </item>
    <item>
      <title>GHSA-3rcm-5vqm-53w6</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-3rcm-5vqm-53w6</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;nfnetlink_osf: validate individual option lengths in fingerprints&lt;/p&gt;
&lt;p&gt;nfnl_osf_add_callback() validates opt_num bounds and string
NUL-termination but does not check individual option length fields.
A zero-length option causes nf_osf_match_one() to enter the option
matching loop even when foptsize sums to zero, which matches packets
with no TCP options where ctx-&amp;gt;optp is NULL:&lt;/p&gt;
&lt;p&gt;Oops: general protection fault
 KASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007]
 RIP: 0010:nf_osf_match_one (net/netfilter/nfnetlink_osf.c:98)
 Call Trace:
  nf_osf_match (net/netfilter/nfnetlink_osf.c:227)
  xt_osf_match_packet (net/netfilter/xt_osf.c:32)
  ipt_do_table (net/ipv4/netfilter/ip_tables.c:293)
  nf_hook_slow (net/netfilter/core.c:623)
  ip_local_deliver (net/ipv4/ip_input.c:262)
  ip_rcv (net/ipv4/ip_input.c:573)&lt;/p&gt;
&lt;p&gt;Additionally, an MSS option (kind=2) with length &amp;lt; 4 causes
out-of-bounds reads when nf_osf_match_one() unconditionally accesses
optp[2] and optp[3] for MSS value extraction.  While RFC 9293
section 3.2 specifies that the MSS option is always exactly 4
bytes (Kind=2, Length=4), the check uses &amp;#34;&amp;lt; 4&amp;#34; rather than
&amp;#34;!= 4&amp;#34; because lengths greater than 4 do not cause memory
safety issues -- the buffer is guaranteed to be at least
foptsize bytes by the ctx-&amp;gt;optsize == foptsize check.&lt;/p&gt;
&lt;p&gt;Reject fingerprints where any option has zero length, or where an MSS
option has length less than 4, at add time ra…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;nfnetlink_osf: validate individual option lengths in fingerprints&lt;/p&gt;
&lt;p&gt;nfnl_osf_add_callback() validates opt_num bounds and string
NUL-termination but does not check individual option length fields.
A zero-length option causes nf_osf_match_one() to enter the option
matching loop even when foptsize sums to zero, which matches packets
with no TCP options where ctx-&amp;gt;optp is NULL:&lt;/p&gt;
&lt;p&gt;Oops: general protection fault
 KASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007]
 RIP: 0010:nf_osf_match_one (net/netfilter/nfnetlink_osf.c:98)
 Call Trace:
  nf_osf_match (net/netfilter/nfnetlink_osf.c:227)
  xt_osf_match_packet (net/netfilter/xt_osf.c:32)
  ipt_do_table (net/ipv4/netfilter/ip_tables.c:293)
  nf_hook_slow (net/netfilter/core.c:623)
  ip_local_deliver (net/ipv4/ip_input.c:262)
  ip_rcv (net/ipv4/ip_input.c:573)&lt;/p&gt;
&lt;p&gt;Additionally, an MSS option (kind=2) with length &amp;lt; 4 causes
out-of-bounds reads when nf_osf_match_one() unconditionally accesses
optp[2] and optp[3] for MSS value extraction.  While RFC 9293
section 3.2 specifies that the MSS option is always exactly 4
bytes (Kind=2, Length=4), the check uses &amp;#34;&amp;lt; 4&amp;#34; rather than
&amp;#34;!= 4&amp;#34; because lengths greater than 4 do not cause memory
safety issues -- the buffer is guaranteed to be at least
foptsize bytes by the ctx-&amp;gt;optsize == foptsize check.&lt;/p&gt;
&lt;p&gt;Reject fingerprints where any option has zero length, or where an MSS
option has length less than 4, at add time ra…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-3rcm-5vqm-53w6</guid>
    </item>
    <item>
      <title>ICSA-26-209-04 — Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-26-209-04</link>
      <description>&lt;p&gt;Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.6 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant).&lt;/p&gt;
&lt;p&gt;Siemens is preparing fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.6 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant).&lt;/p&gt;
&lt;p&gt;Siemens is preparing fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-26-209-04</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-23397 — nfnetlink_osf: validate individual option lengths in fingerprints</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-23397</link>
      <description>msrc_CVE-2026-23397</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-23397</guid>
    </item>
    <item>
      <title>OESA-2026-1862 — kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-1862</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;f2fs: fix to detect potential corrupted nid in free_nid_list&lt;/p&gt;
&lt;p&gt;As reported, on-disk footer.ino and footer.nid is the same and
out-of-range, let&amp;amp;apos;s add sanity check on f2fs_alloc_nid() to detect
any potential corruption in free_nid_list.(CVE-2025-68315)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;ntfs3: Fix uninit buffer allocated by __getname()&lt;/p&gt;
&lt;p&gt;Fix uninit errors caused after buffer allocation given to &amp;amp;apos;de&amp;amp;apos;; by
initializing the buffer with zeroes. The fix was found by using KMSAN.(CVE-2025-68727)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;netfilter: nf_tables: fix use-after-free in nf_tables_addchain()&lt;/p&gt;
&lt;p&gt;nf_tables_addchain() publishes the chain to table-&amp;amp;gt;chains via
list_add_tail_rcu() (in nft_chain_add()) before registering hooks.
If nf_tables_register_hook() then fails, the error path calls
nft_chain_del() (list_del_rcu()) followed by nf_tables_chain_destroy()
with no RCU grace period in between.&lt;/p&gt;
&lt;p&gt;This creates two use-after-free conditions:&lt;/p&gt;
&lt;p&gt;1) Control-plane: nf_tables_dump_chains() traverses table-&amp;amp;gt;chains
    under rcu_read_lock(). A concurrent dump can still be walking
    the chain when the error path frees it.&lt;/p&gt;
&lt;p&gt;2) Packet path: for NFPROTO_INET, nf_register_net_hook() briefly
    installs the IPv4 hook before IPv6 registration fails.  Packets
    entering nft…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;f2fs: fix to detect potential corrupted nid in free_nid_list&lt;/p&gt;
&lt;p&gt;As reported, on-disk footer.ino and footer.nid is the same and
out-of-range, let&amp;amp;apos;s add sanity check on f2fs_alloc_nid() to detect
any potential corruption in free_nid_list.(CVE-2025-68315)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;ntfs3: Fix uninit buffer allocated by __getname()&lt;/p&gt;
&lt;p&gt;Fix uninit errors caused after buffer allocation given to &amp;amp;apos;de&amp;amp;apos;; by
initializing the buffer with zeroes. The fix was found by using KMSAN.(CVE-2025-68727)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;netfilter: nf_tables: fix use-after-free in nf_tables_addchain()&lt;/p&gt;
&lt;p&gt;nf_tables_addchain() publishes the chain to table-&amp;amp;gt;chains via
list_add_tail_rcu() (in nft_chain_add()) before registering hooks.
If nf_tables_register_hook() then fails, the error path calls
nft_chain_del() (list_del_rcu()) followed by nf_tables_chain_destroy()
with no RCU grace period in between.&lt;/p&gt;
&lt;p&gt;This creates two use-after-free conditions:&lt;/p&gt;
&lt;p&gt;1) Control-plane: nf_tables_dump_chains() traverses table-&amp;amp;gt;chains
    under rcu_read_lock(). A concurrent dump can still be walking
    the chain when the error path frees it.&lt;/p&gt;
&lt;p&gt;2) Packet path: for NFPROTO_INET, nf_register_net_hook() briefly
    installs the IPv4 hook before IPv6 registration fails.  Packets
    entering nft…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-1862</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:20826-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:20826-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:20826-1</guid>
    </item>
    <item>
      <title>SSA-019113 — SSA-019113: Vulnerabilities in the additional GNU/Linux subsystem of the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1.6</title>
      <link>https://cve.radiocsirt.org/vuln/ssa-019113</link>
      <description>&lt;p&gt;Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.6 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant).&lt;/p&gt;
&lt;p&gt;Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.6 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant).&lt;/p&gt;
&lt;p&gt;Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ssa-019113</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:21834-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:21834-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:21834-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-23397</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-23397</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux, Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe and 232 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: nfnetlink_osf: validate individual option lengths in fingerprints nfnl_osf_add_callback() validates opt_num bounds and string NUL-termination but does not check individual option length fields. A zero-length option causes nf_osf_match_one() to enter the option matching loop even when foptsize sums to zero, which matches packets with no TCP options where ctx-&amp;gt;optp is NULL:  Oops: general protection fault  KASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007]  RIP: 0010:nf_osf_match_one (net/netfilter/nfnetlink_osf.c:98)  Call Trace:   nf_osf_match (net/netfilter/nfnetlink_osf.c:227)   xt_osf_match_packet (net/netfilter/xt_osf.c:32)   ipt_do_table (net/ipv4/netfilter/ip_tables.c:293)   nf_hook_slow (net/netfilter/core.c:623)   ip_local_deliver (net/ipv4/ip_input.c:262)   ip_rcv (net/ipv4/ip_input.c:573) Additionally, an MSS option (kind=2) with length &amp;lt; 4 causes out-of-bounds reads when nf_osf_match_one() unconditionally accesses optp[2] and optp[3] for MSS value extraction.  While RFC 9293 section 3.2 specifies that the MSS option is always exactly 4 bytes (Kind=2, Length=4), the check uses &amp;#34;&amp;lt; 4&amp;#34; rather than &amp;#34;!= 4&amp;#34; because lengths greater than 4 do not cause memory safety issues -- the buffer is guaranteed to be at least foptsize bytes by the ctx-&amp;gt;optsize == foptsize check. Reject fingerprints where any option has zero length, or where an MSS option has length less than 4, at add time rather…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux, Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe and 232 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: nfnetlink_osf: validate individual option lengths in fingerprints nfnl_osf_add_callback() validates opt_num bounds and string NUL-termination but does not check individual option length fields. A zero-length option causes nf_osf_match_one() to enter the option matching loop even when foptsize sums to zero, which matches packets with no TCP options where ctx-&amp;gt;optp is NULL:  Oops: general protection fault  KASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007]  RIP: 0010:nf_osf_match_one (net/netfilter/nfnetlink_osf.c:98)  Call Trace:   nf_osf_match (net/netfilter/nfnetlink_osf.c:227)   xt_osf_match_packet (net/netfilter/xt_osf.c:32)   ipt_do_table (net/ipv4/netfilter/ip_tables.c:293)   nf_hook_slow (net/netfilter/core.c:623)   ip_local_deliver (net/ipv4/ip_input.c:262)   ip_rcv (net/ipv4/ip_input.c:573) Additionally, an MSS option (kind=2) with length &amp;lt; 4 causes out-of-bounds reads when nf_osf_match_one() unconditionally accesses optp[2] and optp[3] for MSS value extraction.  While RFC 9293 section 3.2 specifies that the MSS option is always exactly 4 bytes (Kind=2, Length=4), the check uses &amp;#34;&amp;lt; 4&amp;#34; rather than &amp;#34;!= 4&amp;#34; because lengths greater than 4 do not cause memory safety issues -- the buffer is guaranteed to be at least foptsize bytes by the ctx-&amp;gt;optsize == foptsize check. Reject fingerprints where any option has zero length, or where an MSS option has length less than 4, at add time rather…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-23397</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-0879 — Linux Kernel: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0879</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen Denial of Service Zustand herbeizuführen oder einen nicht näher spezifizierten Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen Denial of Service Zustand herbeizuführen oder einen nicht näher spezifizierten Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0879</guid>
    </item>
  </channel>
</rss>
