<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 17:14:05 +0000</lastBuildDate>
    <item>
      <title>ALSA-2026:13566 — Important: kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:13566</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: kernel-abi-stablelists, AlmaLinux:10: kernel-doc&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: Linux kernel: Use-after-free in traffic control (act_ct) may lead to denial of service or privilege escalation (CVE-2026-23270)
  * kernel: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (CVE-2026-31402)
  * kernel: Linux kernel: Use-after-free in bonding driver leads to denial of service (CVE-2026-31419)
  * kernel: crypto: algif_aead - Revert to operating out-of-place (CVE-2026-31431)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: kernel-abi-stablelists, AlmaLinux:10: kernel-doc&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: Linux kernel: Use-after-free in traffic control (act_ct) may lead to denial of service or privilege escalation (CVE-2026-23270)
  * kernel: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (CVE-2026-31402)
  * kernel: Linux kernel: Use-after-free in bonding driver leads to denial of service (CVE-2026-31419)
  * kernel: crypto: algif_aead - Revert to operating out-of-place (CVE-2026-31431)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:13566</guid>
    </item>
    <item>
      <title>bdu:2026-09718</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-09718</link>
      <description>bdu:2026-09718</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-09718</guid>
    </item>
    <item>
      <title>BELL-CVE-2026-31419</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-31419</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-31419</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0549 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de Red Hat. Certaines d'entre elles permettent à un…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0549</link>
      <description>certfr-2026-avi-0549</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0549</guid>
    </item>
    <item>
      <title>EUVD-2026-357816</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-357816</link>
      <description>EUVD-2026-357816</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-357816</guid>
    </item>
    <item>
      <title>fkie_cve-2026-31419</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-31419</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;net: bonding: fix use-after-free in bond_xmit_broadcast()&lt;/p&gt;
&lt;p&gt;bond_xmit_broadcast() reuses the original skb for the last slave
(determined by bond_is_last_slave()) and clones it for others.
Concurrent slave enslave/release can mutate the slave list during
RCU-protected iteration, changing which slave is &amp;#34;last&amp;#34; mid-loop.
This causes the original skb to be double-consumed (double-freed).&lt;/p&gt;
&lt;p&gt;Replace the racy bond_is_last_slave() check with a simple index
comparison (i + 1 == slaves_count) against the pre-snapshot slave
count taken via READ_ONCE() before the loop.  This preserves the
zero-copy optimization for the last slave while making the &amp;#34;last&amp;#34;
determination stable against concurrent list mutations.&lt;/p&gt;
&lt;p&gt;The UAF can trigger the following crash:&lt;/p&gt;
&lt;p&gt;==================================================================
BUG: KASAN: slab-use-after-free in skb_clone
Read of size 8 at addr ffff888100ef8d40 by task exploit/147&lt;/p&gt;
&lt;p&gt;CPU: 1 UID: 0 PID: 147 Comm: exploit Not tainted 7.0.0-rc3+ #4 PREEMPTLAZY
Call Trace:
 &amp;lt;TASK&amp;gt;
 dump_stack_lvl (lib/dump_stack.c:123)
 print_report (mm/kasan/report.c:379 mm/kasan/report.c:482)
 kasan_report (mm/kasan/report.c:597)
 skb_clone (include/linux/skbuff.h:1724 include/linux/skbuff.h:1792 include/linux/skbuff.h:3396 net/core/skbuff.c:2108)
 bond_xmit_broadcast (drivers/net/bonding/bond_main.c:5334)
 bond_start_xmit (drivers/net/bonding/bond_main.c:5567 drivers/net/bonding/bond_main.c:5593)
 dev_…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;net: bonding: fix use-after-free in bond_xmit_broadcast()&lt;/p&gt;
&lt;p&gt;bond_xmit_broadcast() reuses the original skb for the last slave
(determined by bond_is_last_slave()) and clones it for others.
Concurrent slave enslave/release can mutate the slave list during
RCU-protected iteration, changing which slave is &amp;#34;last&amp;#34; mid-loop.
This causes the original skb to be double-consumed (double-freed).&lt;/p&gt;
&lt;p&gt;Replace the racy bond_is_last_slave() check with a simple index
comparison (i + 1 == slaves_count) against the pre-snapshot slave
count taken via READ_ONCE() before the loop.  This preserves the
zero-copy optimization for the last slave while making the &amp;#34;last&amp;#34;
determination stable against concurrent list mutations.&lt;/p&gt;
&lt;p&gt;The UAF can trigger the following crash:&lt;/p&gt;
&lt;p&gt;==================================================================
BUG: KASAN: slab-use-after-free in skb_clone
Read of size 8 at addr ffff888100ef8d40 by task exploit/147&lt;/p&gt;
&lt;p&gt;CPU: 1 UID: 0 PID: 147 Comm: exploit Not tainted 7.0.0-rc3+ #4 PREEMPTLAZY
Call Trace:
 &amp;lt;TASK&amp;gt;
 dump_stack_lvl (lib/dump_stack.c:123)
 print_report (mm/kasan/report.c:379 mm/kasan/report.c:482)
 kasan_report (mm/kasan/report.c:597)
 skb_clone (include/linux/skbuff.h:1724 include/linux/skbuff.h:1792 include/linux/skbuff.h:3396 net/core/skbuff.c:2108)
 bond_xmit_broadcast (drivers/net/bonding/bond_main.c:5334)
 bond_start_xmit (drivers/net/bonding/bond_main.c:5567 drivers/net/bonding/bond_main.c:5593)
 dev_…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-31419</guid>
    </item>
    <item>
      <title>GHSA-47j5-hmhq-4c74</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-47j5-hmhq-4c74</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;net: bonding: fix use-after-free in bond_xmit_broadcast()&lt;/p&gt;
&lt;p&gt;bond_xmit_broadcast() reuses the original skb for the last slave
(determined by bond_is_last_slave()) and clones it for others.
Concurrent slave enslave/release can mutate the slave list during
RCU-protected iteration, changing which slave is &amp;#34;last&amp;#34; mid-loop.
This causes the original skb to be double-consumed (double-freed).&lt;/p&gt;
&lt;p&gt;Replace the racy bond_is_last_slave() check with a simple index
comparison (i + 1 == slaves_count) against the pre-snapshot slave
count taken via READ_ONCE() before the loop.  This preserves the
zero-copy optimization for the last slave while making the &amp;#34;last&amp;#34;
determination stable against concurrent list mutations.&lt;/p&gt;
&lt;p&gt;The UAF can trigger the following crash:&lt;/p&gt;
&lt;p&gt;==================================================================
BUG: KASAN: slab-use-after-free in skb_clone
Read of size 8 at addr ffff888100ef8d40 by task exploit/147&lt;/p&gt;
&lt;p&gt;CPU: 1 UID: 0 PID: 147 Comm: exploit Not tainted 7.0.0-rc3+ #4 PREEMPTLAZY
Call Trace:
 &amp;lt;TASK&amp;gt;
 dump_stack_lvl (lib/dump_stack.c:123)
 print_report (mm/kasan/report.c:379 mm/kasan/report.c:482)
 kasan_report (mm/kasan/report.c:597)
 skb_clone (include/linux/skbuff.h:1724 include/linux/skbuff.h:1792 include/linux/skbuff.h:3396 net/core/skbuff.c:2108)
 bond_xmit_broadcast (drivers/net/bonding/bond_main.c:5334)
 bond_start_xmit (drivers/net/bonding/bond_main.c:5567 drivers/net/bonding/bond_main.c:5593)
 dev_…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;net: bonding: fix use-after-free in bond_xmit_broadcast()&lt;/p&gt;
&lt;p&gt;bond_xmit_broadcast() reuses the original skb for the last slave
(determined by bond_is_last_slave()) and clones it for others.
Concurrent slave enslave/release can mutate the slave list during
RCU-protected iteration, changing which slave is &amp;#34;last&amp;#34; mid-loop.
This causes the original skb to be double-consumed (double-freed).&lt;/p&gt;
&lt;p&gt;Replace the racy bond_is_last_slave() check with a simple index
comparison (i + 1 == slaves_count) against the pre-snapshot slave
count taken via READ_ONCE() before the loop.  This preserves the
zero-copy optimization for the last slave while making the &amp;#34;last&amp;#34;
determination stable against concurrent list mutations.&lt;/p&gt;
&lt;p&gt;The UAF can trigger the following crash:&lt;/p&gt;
&lt;p&gt;==================================================================
BUG: KASAN: slab-use-after-free in skb_clone
Read of size 8 at addr ffff888100ef8d40 by task exploit/147&lt;/p&gt;
&lt;p&gt;CPU: 1 UID: 0 PID: 147 Comm: exploit Not tainted 7.0.0-rc3+ #4 PREEMPTLAZY
Call Trace:
 &amp;lt;TASK&amp;gt;
 dump_stack_lvl (lib/dump_stack.c:123)
 print_report (mm/kasan/report.c:379 mm/kasan/report.c:482)
 kasan_report (mm/kasan/report.c:597)
 skb_clone (include/linux/skbuff.h:1724 include/linux/skbuff.h:1792 include/linux/skbuff.h:3396 net/core/skbuff.c:2108)
 bond_xmit_broadcast (drivers/net/bonding/bond_main.c:5334)
 bond_start_xmit (drivers/net/bonding/bond_main.c:5567 drivers/net/bonding/bond_main.c:5593)
 dev_…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-47j5-hmhq-4c74</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-31419 — net: bonding: fix use-after-free in bond_xmit_broadcast()</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-31419</link>
      <description>msrc_CVE-2026-31419</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-31419</guid>
    </item>
    <item>
      <title>OESA-2026-2311 — kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-2311</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP4: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;drm/vmwgfx: Return the correct value in vmw_translate_ptr functions&lt;/p&gt;
&lt;p&gt;Before the referenced fixes these functions used a lookup function that
returned a pointer. This was changed to another lookup function that
returned an error code with the pointer becoming an out parameter.&lt;/p&gt;
&lt;p&gt;The error path when the lookup failed was not changed to reflect this
change and the code continued to return the PTR_ERR of the now
uninitialized pointer. This could cause the vmw_translate_ptr functions
to return success when they actually failed causing further uninitialized
and OOB accesses.(CVE-2026-23317)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;NFSD: Defer sub-object cleanup in export put callbacks&lt;/p&gt;
&lt;p&gt;svc_export_put() calls path_put() and auth_domain_put() immediately
when the last reference drops, before the RCU grace period. RCU
readers in e_show() and c_show() access both ex_path (via
seq_path/d_path) and ex_client-&amp;amp;gt;name (via seq_escape) without
holding a reference. If cache_clean removes the entry and drops the
last reference concurrently, the sub-objects are freed while still
in use, producing a NULL pointer dereference in d_path.&lt;/p&gt;
&lt;p&gt;Commit 2530766492ec (&amp;amp;quot;nfsd: fix UAF when access ex_uuid or
ex_stats&amp;amp;quot;) moved kfree of ex_uuid and ex_stats into the
call_rcu callback, but left path_put() and auth_domain_put() runnin…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP4: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;drm/vmwgfx: Return the correct value in vmw_translate_ptr functions&lt;/p&gt;
&lt;p&gt;Before the referenced fixes these functions used a lookup function that
returned a pointer. This was changed to another lookup function that
returned an error code with the pointer becoming an out parameter.&lt;/p&gt;
&lt;p&gt;The error path when the lookup failed was not changed to reflect this
change and the code continued to return the PTR_ERR of the now
uninitialized pointer. This could cause the vmw_translate_ptr functions
to return success when they actually failed causing further uninitialized
and OOB accesses.(CVE-2026-23317)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;NFSD: Defer sub-object cleanup in export put callbacks&lt;/p&gt;
&lt;p&gt;svc_export_put() calls path_put() and auth_domain_put() immediately
when the last reference drops, before the RCU grace period. RCU
readers in e_show() and c_show() access both ex_path (via
seq_path/d_path) and ex_client-&amp;amp;gt;name (via seq_escape) without
holding a reference. If cache_clean removes the entry and drops the
last reference concurrently, the sub-objects are freed while still
in use, producing a NULL pointer dereference in d_path.&lt;/p&gt;
&lt;p&gt;Commit 2530766492ec (&amp;amp;quot;nfsd: fix UAF when access ex_uuid or
ex_stats&amp;amp;quot;) moved kfree of ex_uuid and ex_stats into the
call_rcu callback, but left path_put() and auth_domain_put() runnin…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-2311</guid>
    </item>
    <item>
      <title>RHSA-2026:13566 — Red Hat Security Advisory: kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:13566</link>
      <description>&lt;p&gt;kernel: Linux kernel: Use-after-free in traffic control (act_ct) may lead to denial of service or privilege escalation kernel: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache kernel: Linux kernel: Use-after-free in bonding driver leads to denial of service kernel: crypto: algif_aead - Revert to operating out-of-place kernel: crypto: algif_aead - Fix minimum RX size check for decryption&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;kernel: Linux kernel: Use-after-free in traffic control (act_ct) may lead to denial of service or privilege escalation kernel: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache kernel: Linux kernel: Use-after-free in bonding driver leads to denial of service kernel: crypto: algif_aead - Revert to operating out-of-place kernel: crypto: algif_aead - Fix minimum RX size check for decryption&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:13566</guid>
    </item>
    <item>
      <title>RHSA-2026:19521 — Red Hat Security Advisory: kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:19521</link>
      <description>&lt;p&gt;kernel: Linux kernel: RDMA/rxe use-after-free vulnerability leading to potential arbitrary code execution kernel: ALSA: aloop: Fix racy access at PCM trigger kernel: Linux kernel: Denial of service and memory corruption in RDMA umad kernel: Linux kernel KVM: Privilege escalation or denial of service due to improper shadow page table entry handling kernel: Linux kernel: Use-after-free in bonding driver leads to denial of service kernel: can: raw: fix ro-&amp;gt;uniq use-after-free in raw_rcv() kernel: net: skbuff: propagate shared-frag marker through frag-transfer helpers kernel: &amp;#34;Fragnesia&amp;#34; is a variant of Dirty Frag vulnerability in the ESP/XFRM leading to Local Privilege Escalation (LPE) vulnerability in the Linux kernel kernel: Read root-owned files as an unprivileged user&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;kernel: Linux kernel: RDMA/rxe use-after-free vulnerability leading to potential arbitrary code execution kernel: ALSA: aloop: Fix racy access at PCM trigger kernel: Linux kernel: Denial of service and memory corruption in RDMA umad kernel: Linux kernel KVM: Privilege escalation or denial of service due to improper shadow page table entry handling kernel: Linux kernel: Use-after-free in bonding driver leads to denial of service kernel: can: raw: fix ro-&amp;gt;uniq use-after-free in raw_rcv() kernel: net: skbuff: propagate shared-frag marker through frag-transfer helpers kernel: &amp;#34;Fragnesia&amp;#34; is a variant of Dirty Frag vulnerability in the ESP/XFRM leading to Local Privilege Escalation (LPE) vulnerability in the Linux kernel kernel: Read root-owned files as an unprivileged user&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:19521</guid>
    </item>
    <item>
      <title>RLSA-2026:25191 — Critical: kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:25191</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: kernel&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: Linux kernel: Use-after-free in bonding driver leads to denial of service (CVE-2026-31419)&lt;/p&gt;
&lt;p&gt;* kernel: Linux kernel: Denial of Service in erofs filesystem (CVE-2026-31467)&lt;/p&gt;
&lt;p&gt;* kernel: can: raw: fix ro-&amp;gt;uniq use-after-free in raw_rcv() (CVE-2026-31532)&lt;/p&gt;
&lt;p&gt;* kernel: ALSA: 6fire: fix use-after-free on disconnect (CVE-2026-31581)&lt;/p&gt;
&lt;p&gt;* kernel: ip6_tunnel: clear skb2-&amp;gt;cb[] in ip4ip6_err() (CVE-2026-43037)&lt;/p&gt;
&lt;p&gt;* kernel: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (CVE-2026-43501)&lt;/p&gt;
&lt;p&gt;* kernel: selinux: fix overlayfs mmap() and mprotect() access checks (CVE-2026-46054)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: kernel&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: Linux kernel: Use-after-free in bonding driver leads to denial of service (CVE-2026-31419)&lt;/p&gt;
&lt;p&gt;* kernel: Linux kernel: Denial of Service in erofs filesystem (CVE-2026-31467)&lt;/p&gt;
&lt;p&gt;* kernel: can: raw: fix ro-&amp;gt;uniq use-after-free in raw_rcv() (CVE-2026-31532)&lt;/p&gt;
&lt;p&gt;* kernel: ALSA: 6fire: fix use-after-free on disconnect (CVE-2026-31581)&lt;/p&gt;
&lt;p&gt;* kernel: ip6_tunnel: clear skb2-&amp;gt;cb[] in ip4ip6_err() (CVE-2026-43037)&lt;/p&gt;
&lt;p&gt;* kernel: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (CVE-2026-43501)&lt;/p&gt;
&lt;p&gt;* kernel: selinux: fix overlayfs mmap() and mprotect() access checks (CVE-2026-46054)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:25191</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-31419</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-31419</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 179 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: net: bonding: fix use-after-free in bond_xmit_broadcast() bond_xmit_broadcast() reuses the original skb for the last slave (determined by bond_is_last_slave()) and clones it for others. Concurrent slave enslave/release can mutate the slave list during RCU-protected iteration, changing which slave is &amp;#34;last&amp;#34; mid-loop. This causes the original skb to be double-consumed (double-freed). Replace the racy bond_is_last_slave() check with a simple index comparison (i + 1 == slaves_count) against the pre-snapshot slave count taken via READ_ONCE() before the loop.  This preserves the zero-copy optimization for the last slave while making the &amp;#34;last&amp;#34; determination stable against concurrent list mutations. The UAF can trigger the following crash: ================================================================== BUG: KASAN: slab-use-after-free in skb_clone Read of size 8 at addr ffff888100ef8d40 by task exploit/147 CPU: 1 UID: 0 PID: 147 Comm: exploit Not tainted 7.0.0-rc3+ #4 PREEMPTLAZY Call Trace:  &amp;lt;TASK&amp;gt;  dump_stack_lvl (lib/dump_stack.c:123)  print_report (mm/kasan/report.c:379 mm/kasan/report.c:482)  kasan_report (mm/kasan/report.c:597)  skb_clone (include/linux/skbuff.h:1724 include/linux/skbuff.h:1792 include/linux/skbuff.h:3396 net/core/skbuff.c:2108)  bond_xmit_broadcast (drivers/net/bonding/bond_main.c:5334)  bond_start_xmit (drivers/net/bonding/bond_main.c:5567 drivers/net/bonding/bond_main.c:5593)  dev_hard_s…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 179 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: net: bonding: fix use-after-free in bond_xmit_broadcast() bond_xmit_broadcast() reuses the original skb for the last slave (determined by bond_is_last_slave()) and clones it for others. Concurrent slave enslave/release can mutate the slave list during RCU-protected iteration, changing which slave is &amp;#34;last&amp;#34; mid-loop. This causes the original skb to be double-consumed (double-freed). Replace the racy bond_is_last_slave() check with a simple index comparison (i + 1 == slaves_count) against the pre-snapshot slave count taken via READ_ONCE() before the loop.  This preserves the zero-copy optimization for the last slave while making the &amp;#34;last&amp;#34; determination stable against concurrent list mutations. The UAF can trigger the following crash: ================================================================== BUG: KASAN: slab-use-after-free in skb_clone Read of size 8 at addr ffff888100ef8d40 by task exploit/147 CPU: 1 UID: 0 PID: 147 Comm: exploit Not tainted 7.0.0-rc3+ #4 PREEMPTLAZY Call Trace:  &amp;lt;TASK&amp;gt;  dump_stack_lvl (lib/dump_stack.c:123)  print_report (mm/kasan/report.c:379 mm/kasan/report.c:482)  kasan_report (mm/kasan/report.c:597)  skb_clone (include/linux/skbuff.h:1724 include/linux/skbuff.h:1792 include/linux/skbuff.h:3396 net/core/skbuff.c:2108)  bond_xmit_broadcast (drivers/net/bonding/bond_main.c:5334)  bond_start_xmit (drivers/net/bonding/bond_main.c:5567 drivers/net/bonding/bond_main.c:5593)  dev_hard_s…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-31419</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1088 — Linux Kernel: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1088</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um nicht näher spezifizierte Angriffe durchzuführen, darunter möglicherweise DoS-Angriffe, die Manipulation oder Offenlegung von Daten sowie die Umgehung von Sicherheitsmaßnahmen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um nicht näher spezifizierte Angriffe durchzuführen, darunter möglicherweise DoS-Angriffe, die Manipulation oder Offenlegung von Daten sowie die Umgehung von Sicherheitsmaßnahmen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1088</guid>
    </item>
  </channel>
</rss>
