<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 04:30:29 +0000</lastBuildDate>
    <item>
      <title>ALSA-2026:27288 — Important: kernel security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:27288</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: kernel, AlmaLinux:10: kernel-64k, AlmaLinux:10: kernel-64k-core, AlmaLinux:10: kernel-64k-debug, AlmaLinux:10: kernel-64k-debug-core, AlmaLinux:10: kernel-64k-debug-devel, AlmaLinux:10: kernel-64k-debug-devel-matched, AlmaLinux:10: kernel-64k-debug-modules, AlmaLinux:10: kernel-64k-debug-modules-core, AlmaLinux:10: kernel-64k-debug-modules-extra and 65 more&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: can: isotp: fix tx.buf use-after-free in isotp_sendmsg() (CVE-2026-31474)
  * kernel: mptcp: fix slab-use-after-free in __inet_lookup_established (CVE-2026-31669)
  * kernel: rxrpc: Fix RxGK token loading to check bounds (CVE-2026-31641)
  * kernel: xen/privcmd: fix double free via VMA splitting (CVE-2026-31787)
  * kernel: Buffer overflow in drivers/xen/sys-hypervisor.c (CVE-2026-31786)
  * kernel: net: mana: fix use-after-free in add_adev() error path (CVE-2026-43056)
  * kernel: Bluetooth: hci_sync: fix stack buffer overflow in hci_le_big_create_sync (CVE-2026-31772)
  * kernel: bnxt_en: Fix RSS context delete logic (CVE-2026-43260)
  * kernel: crypto: caam - fix overflow on long hmac keys (CVE-2026-43330)
  * kernel: net/sched: act_pedit: extend the writable skb range per key (CVE-2026-46331)
  * kernel: Bluetooth: hci_event: fix potential UAF in SSP passkey handlers (CVE-2026-46056)
  * kernel: wifi: mac80211: drop stray &amp;#39;static&amp;#39; from fast-RX rx_result (CVE-2026-46152)
  * kernel: wifi: mac80211: remove station if connection prep fails (CVE-2026-46125)
  * kernel: exit: prevent preemption of oopsing TASK_DEAD task (CVE-2026-46173)
  * kernel: wifi: mac80211: use safe list iteration in radar detect work (CVE-2026-46166)&lt;/p&gt;
&lt;p&gt;Bug Fix(es) and Enhancement(s):&lt;/p&gt;
&lt;p&gt;* AlmaLinux10.0 - s390/ap: Expose ap_bindings_complete_count counter via sysfs [almalinux-10.2…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: kernel, AlmaLinux:10: kernel-64k, AlmaLinux:10: kernel-64k-core, AlmaLinux:10: kernel-64k-debug, AlmaLinux:10: kernel-64k-debug-core, AlmaLinux:10: kernel-64k-debug-devel, AlmaLinux:10: kernel-64k-debug-devel-matched, AlmaLinux:10: kernel-64k-debug-modules, AlmaLinux:10: kernel-64k-debug-modules-core, AlmaLinux:10: kernel-64k-debug-modules-extra and 65 more&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: can: isotp: fix tx.buf use-after-free in isotp_sendmsg() (CVE-2026-31474)
  * kernel: mptcp: fix slab-use-after-free in __inet_lookup_established (CVE-2026-31669)
  * kernel: rxrpc: Fix RxGK token loading to check bounds (CVE-2026-31641)
  * kernel: xen/privcmd: fix double free via VMA splitting (CVE-2026-31787)
  * kernel: Buffer overflow in drivers/xen/sys-hypervisor.c (CVE-2026-31786)
  * kernel: net: mana: fix use-after-free in add_adev() error path (CVE-2026-43056)
  * kernel: Bluetooth: hci_sync: fix stack buffer overflow in hci_le_big_create_sync (CVE-2026-31772)
  * kernel: bnxt_en: Fix RSS context delete logic (CVE-2026-43260)
  * kernel: crypto: caam - fix overflow on long hmac keys (CVE-2026-43330)
  * kernel: net/sched: act_pedit: extend the writable skb range per key (CVE-2026-46331)
  * kernel: Bluetooth: hci_event: fix potential UAF in SSP passkey handlers (CVE-2026-46056)
  * kernel: wifi: mac80211: drop stray &amp;#39;static&amp;#39; from fast-RX rx_result (CVE-2026-46152)
  * kernel: wifi: mac80211: remove station if connection prep fails (CVE-2026-46125)
  * kernel: exit: prevent preemption of oopsing TASK_DEAD task (CVE-2026-46173)
  * kernel: wifi: mac80211: use safe list iteration in radar detect work (CVE-2026-46166)&lt;/p&gt;
&lt;p&gt;Bug Fix(es) and Enhancement(s):&lt;/p&gt;
&lt;p&gt;* AlmaLinux10.0 - s390/ap: Expose ap_bindings_complete_count counter via sysfs [almalinux-10.2…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:27288</guid>
    </item>
    <item>
      <title>BELL-CVE-2026-31474</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-31474</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-31474</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0519 — De multiples vulnérabilités ont été découvertes dans Microsoft Azure Linux. Elles permettent à un attaquant de provoque…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0519</link>
      <description>certfr-2026-avi-0519</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0519</guid>
    </item>
    <item>
      <title>EUVD-2026-347692</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-347692</link>
      <description>EUVD-2026-347692</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-347692</guid>
    </item>
    <item>
      <title>fkie_cve-2026-31474</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-31474</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;can: isotp: fix tx.buf use-after-free in isotp_sendmsg()&lt;/p&gt;
&lt;p&gt;isotp_sendmsg() uses only cmpxchg() on so-&amp;gt;tx.state to serialize access
to so-&amp;gt;tx.buf. isotp_release() waits for ISOTP_IDLE via
wait_event_interruptible() and then calls kfree(so-&amp;gt;tx.buf).&lt;/p&gt;
&lt;p&gt;If a signal interrupts the wait_event_interruptible() inside close()
while tx.state is ISOTP_SENDING, the loop exits early and release
proceeds to force ISOTP_SHUTDOWN and continues to kfree(so-&amp;gt;tx.buf)
while sendmsg may still be reading so-&amp;gt;tx.buf for the final CAN frame
in isotp_fill_dataframe().&lt;/p&gt;
&lt;p&gt;The so-&amp;gt;tx.buf can be allocated once when the standard tx.buf length needs
to be extended. Move the kfree() of this potentially extended tx.buf to
sk_destruct time when either isotp_sendmsg() and isotp_release() are done.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;can: isotp: fix tx.buf use-after-free in isotp_sendmsg()&lt;/p&gt;
&lt;p&gt;isotp_sendmsg() uses only cmpxchg() on so-&amp;gt;tx.state to serialize access
to so-&amp;gt;tx.buf. isotp_release() waits for ISOTP_IDLE via
wait_event_interruptible() and then calls kfree(so-&amp;gt;tx.buf).&lt;/p&gt;
&lt;p&gt;If a signal interrupts the wait_event_interruptible() inside close()
while tx.state is ISOTP_SENDING, the loop exits early and release
proceeds to force ISOTP_SHUTDOWN and continues to kfree(so-&amp;gt;tx.buf)
while sendmsg may still be reading so-&amp;gt;tx.buf for the final CAN frame
in isotp_fill_dataframe().&lt;/p&gt;
&lt;p&gt;The so-&amp;gt;tx.buf can be allocated once when the standard tx.buf length needs
to be extended. Move the kfree() of this potentially extended tx.buf to
sk_destruct time when either isotp_sendmsg() and isotp_release() are done.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-31474</guid>
    </item>
    <item>
      <title>GHSA-6p7x-c5rv-9w7v</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-6p7x-c5rv-9w7v</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;can: isotp: fix tx.buf use-after-free in isotp_sendmsg()&lt;/p&gt;
&lt;p&gt;isotp_sendmsg() uses only cmpxchg() on so-&amp;gt;tx.state to serialize access
to so-&amp;gt;tx.buf. isotp_release() waits for ISOTP_IDLE via
wait_event_interruptible() and then calls kfree(so-&amp;gt;tx.buf).&lt;/p&gt;
&lt;p&gt;If a signal interrupts the wait_event_interruptible() inside close()
while tx.state is ISOTP_SENDING, the loop exits early and release
proceeds to force ISOTP_SHUTDOWN and continues to kfree(so-&amp;gt;tx.buf)
while sendmsg may still be reading so-&amp;gt;tx.buf for the final CAN frame
in isotp_fill_dataframe().&lt;/p&gt;
&lt;p&gt;The so-&amp;gt;tx.buf can be allocated once when the standard tx.buf length needs
to be extended. Move the kfree() of this potentially extended tx.buf to
sk_destruct time when either isotp_sendmsg() and isotp_release() are done.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;can: isotp: fix tx.buf use-after-free in isotp_sendmsg()&lt;/p&gt;
&lt;p&gt;isotp_sendmsg() uses only cmpxchg() on so-&amp;gt;tx.state to serialize access
to so-&amp;gt;tx.buf. isotp_release() waits for ISOTP_IDLE via
wait_event_interruptible() and then calls kfree(so-&amp;gt;tx.buf).&lt;/p&gt;
&lt;p&gt;If a signal interrupts the wait_event_interruptible() inside close()
while tx.state is ISOTP_SENDING, the loop exits early and release
proceeds to force ISOTP_SHUTDOWN and continues to kfree(so-&amp;gt;tx.buf)
while sendmsg may still be reading so-&amp;gt;tx.buf for the final CAN frame
in isotp_fill_dataframe().&lt;/p&gt;
&lt;p&gt;The so-&amp;gt;tx.buf can be allocated once when the standard tx.buf length needs
to be extended. Move the kfree() of this potentially extended tx.buf to
sk_destruct time when either isotp_sendmsg() and isotp_release() are done.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-6p7x-c5rv-9w7v</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-31474 — can: isotp: fix tx.buf use-after-free in isotp_sendmsg()</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-31474</link>
      <description>msrc_CVE-2026-31474</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-31474</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:21555-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:21555-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:21555-1</guid>
    </item>
    <item>
      <title>RHSA-2026:27731 — Red Hat Security Advisory: kernel security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:27731</link>
      <description>&lt;p&gt;kernel: ceph: kernel: Ceph: exploit of hardcoded IVECs, in a misuse of AES, resulting in authentication bypass kernel: Linux kernel: Use-after-free in BPF sockmap can lead to denial of service and privilege escalation kernel: ipv6: use RCU in ip6_xmit() kernel: ipv6: use RCU in ip6_output() kernel: net: use dst_dev_rcu() in sk_setup_caps() kernel: Linux kernel: Denial of Service in libceph OSD client due to unreset sparse-read state kernel: can: isotp: fix tx.buf use-after-free in isotp_sendmsg() kernel: netfilter: ctnetlink: ensure safe access to master conntrack kernel: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows kernel: RDMA/iwcm: Fix workqueue list corruption by removing work_list kernel: wifi: mac80211: remove station if connection prep fails kernel: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL kernel: Linux kernel: Use-After-Free in net/gro due to improper handling of zerocopy skbs kernel: net/sched: act_pedit: extend the writable skb range per key&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;kernel: ceph: kernel: Ceph: exploit of hardcoded IVECs, in a misuse of AES, resulting in authentication bypass kernel: Linux kernel: Use-after-free in BPF sockmap can lead to denial of service and privilege escalation kernel: ipv6: use RCU in ip6_xmit() kernel: ipv6: use RCU in ip6_output() kernel: net: use dst_dev_rcu() in sk_setup_caps() kernel: Linux kernel: Denial of Service in libceph OSD client due to unreset sparse-read state kernel: can: isotp: fix tx.buf use-after-free in isotp_sendmsg() kernel: netfilter: ctnetlink: ensure safe access to master conntrack kernel: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows kernel: RDMA/iwcm: Fix workqueue list corruption by removing work_list kernel: wifi: mac80211: remove station if connection prep fails kernel: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL kernel: Linux kernel: Use-After-Free in net/gro due to improper handling of zerocopy skbs kernel: net/sched: act_pedit: extend the writable skb range per key&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:27731</guid>
    </item>
    <item>
      <title>RLSA-2026:27288 — Important: kernel security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:27288</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: kernel&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: can: isotp: fix tx.buf use-after-free in isotp_sendmsg() (CVE-2026-31474)&lt;/p&gt;
&lt;p&gt;* kernel: mptcp: fix slab-use-after-free in __inet_lookup_established (CVE-2026-31669)&lt;/p&gt;
&lt;p&gt;* kernel: rxrpc: Fix RxGK token loading to check bounds (CVE-2026-31641)&lt;/p&gt;
&lt;p&gt;* kernel: xen/privcmd: fix double free via VMA splitting (CVE-2026-31787)&lt;/p&gt;
&lt;p&gt;* kernel: Buffer overflow in drivers/xen/sys-hypervisor.c (CVE-2026-31786)&lt;/p&gt;
&lt;p&gt;* kernel: net: mana: fix use-after-free in add_adev() error path (CVE-2026-43056)&lt;/p&gt;
&lt;p&gt;* kernel: Bluetooth: hci_sync: fix stack buffer overflow in hci_le_big_create_sync (CVE-2026-31772)&lt;/p&gt;
&lt;p&gt;* kernel: bnxt_en: Fix RSS context delete logic (CVE-2026-43260)&lt;/p&gt;
&lt;p&gt;* kernel: crypto: caam - fix overflow on long hmac keys (CVE-2026-43330)&lt;/p&gt;
&lt;p&gt;* kernel: net/sched: act_pedit: extend the writable skb range per key (CVE-2026-46331)&lt;/p&gt;
&lt;p&gt;* kernel: Bluetooth: hci_event: fix potential UAF in SSP passkey handlers (CVE-2026-46056)&lt;/p&gt;
&lt;p&gt;* kernel: wifi: mac80211: drop stray &amp;#39;static&amp;#39; from fast-RX rx_result (CVE-2026-46152)&lt;/p&gt;
&lt;p&gt;* kernel: wifi: mac80211: remove station if connection prep fails (CVE-2026-46125)&lt;/p&gt;
&lt;p&gt;* kernel: exit: prevent preemption of oopsing TASK_DEAD task (CVE-2026-46173)&lt;/p&gt;
&lt;p&gt;* kernel: wifi: mac80211: use safe list iteration in radar detect work (CVE-2026-46166)&lt;/p&gt;
&lt;p&gt;Bug Fix(es) and Enhancement(s):&lt;/p&gt;
&lt;p&gt;* Rocky Linux10.0 - s390/ap: Expose ap_bindings_complete_count counter via sysfs [rhel-10.2.z] (JIRA:Rocky Linux-166047…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: kernel&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: can: isotp: fix tx.buf use-after-free in isotp_sendmsg() (CVE-2026-31474)&lt;/p&gt;
&lt;p&gt;* kernel: mptcp: fix slab-use-after-free in __inet_lookup_established (CVE-2026-31669)&lt;/p&gt;
&lt;p&gt;* kernel: rxrpc: Fix RxGK token loading to check bounds (CVE-2026-31641)&lt;/p&gt;
&lt;p&gt;* kernel: xen/privcmd: fix double free via VMA splitting (CVE-2026-31787)&lt;/p&gt;
&lt;p&gt;* kernel: Buffer overflow in drivers/xen/sys-hypervisor.c (CVE-2026-31786)&lt;/p&gt;
&lt;p&gt;* kernel: net: mana: fix use-after-free in add_adev() error path (CVE-2026-43056)&lt;/p&gt;
&lt;p&gt;* kernel: Bluetooth: hci_sync: fix stack buffer overflow in hci_le_big_create_sync (CVE-2026-31772)&lt;/p&gt;
&lt;p&gt;* kernel: bnxt_en: Fix RSS context delete logic (CVE-2026-43260)&lt;/p&gt;
&lt;p&gt;* kernel: crypto: caam - fix overflow on long hmac keys (CVE-2026-43330)&lt;/p&gt;
&lt;p&gt;* kernel: net/sched: act_pedit: extend the writable skb range per key (CVE-2026-46331)&lt;/p&gt;
&lt;p&gt;* kernel: Bluetooth: hci_event: fix potential UAF in SSP passkey handlers (CVE-2026-46056)&lt;/p&gt;
&lt;p&gt;* kernel: wifi: mac80211: drop stray &amp;#39;static&amp;#39; from fast-RX rx_result (CVE-2026-46152)&lt;/p&gt;
&lt;p&gt;* kernel: wifi: mac80211: remove station if connection prep fails (CVE-2026-46125)&lt;/p&gt;
&lt;p&gt;* kernel: exit: prevent preemption of oopsing TASK_DEAD task (CVE-2026-46173)&lt;/p&gt;
&lt;p&gt;* kernel: wifi: mac80211: use safe list iteration in radar detect work (CVE-2026-46166)&lt;/p&gt;
&lt;p&gt;Bug Fix(es) and Enhancement(s):&lt;/p&gt;
&lt;p&gt;* Rocky Linux10.0 - s390/ap: Expose ap_bindings_complete_count counter via sysfs [rhel-10.2.z] (JIRA:Rocky Linux-166047…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:27288</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:23066-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:23066-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:23066-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-31474</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-31474</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 140 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: can: isotp: fix tx.buf use-after-free in isotp_sendmsg() isotp_sendmsg() uses only cmpxchg() on so-&amp;gt;tx.state to serialize access to so-&amp;gt;tx.buf. isotp_release() waits for ISOTP_IDLE via wait_event_interruptible() and then calls kfree(so-&amp;gt;tx.buf). If a signal interrupts the wait_event_interruptible() inside close() while tx.state is ISOTP_SENDING, the loop exits early and release proceeds to force ISOTP_SHUTDOWN and continues to kfree(so-&amp;gt;tx.buf) while sendmsg may still be reading so-&amp;gt;tx.buf for the final CAN frame in isotp_fill_dataframe(). The so-&amp;gt;tx.buf can be allocated once when the standard tx.buf length needs to be extended. Move the kfree() of this potentially extended tx.buf to sk_destruct time when either isotp_sendmsg() and isotp_release() are done.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 140 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: can: isotp: fix tx.buf use-after-free in isotp_sendmsg() isotp_sendmsg() uses only cmpxchg() on so-&amp;gt;tx.state to serialize access to so-&amp;gt;tx.buf. isotp_release() waits for ISOTP_IDLE via wait_event_interruptible() and then calls kfree(so-&amp;gt;tx.buf). If a signal interrupts the wait_event_interruptible() inside close() while tx.state is ISOTP_SENDING, the loop exits early and release proceeds to force ISOTP_SHUTDOWN and continues to kfree(so-&amp;gt;tx.buf) while sendmsg may still be reading so-&amp;gt;tx.buf for the final CAN frame in isotp_fill_dataframe(). The so-&amp;gt;tx.buf can be allocated once when the standard tx.buf length needs to be extended. Move the kfree() of this potentially extended tx.buf to sk_destruct time when either isotp_sendmsg() and isotp_release() are done.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-31474</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1252 — Linux Kernel: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1252</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen, Sicherheitsmaßnahmen zu umgehen, Informationen offenzulegen, andere nicht näher spezifizierte Auswirkungen zu verursachen und möglicherweise Code auszuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen, Sicherheitsmaßnahmen zu umgehen, Informationen offenzulegen, andere nicht näher spezifizierte Auswirkungen zu verursachen und möglicherweise Code auszuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1252</guid>
    </item>
  </channel>
</rss>
