<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 11:05:36 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-12527</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-12527</link>
      <description>bdu:2026-12527</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-12527</guid>
    </item>
    <item>
      <title>BELL-CVE-2026-31476</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-31476</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-31476</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0519 — De multiples vulnérabilités ont été découvertes dans Microsoft Azure Linux. Elles permettent à un attaquant de provoque…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0519</link>
      <description>certfr-2026-avi-0519</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0519</guid>
    </item>
    <item>
      <title>EUVD-2026-347694</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-347694</link>
      <description>EUVD-2026-347694</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-347694</guid>
    </item>
    <item>
      <title>fkie_cve-2026-31476</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-31476</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;ksmbd: do not expire session on binding failure&lt;/p&gt;
&lt;p&gt;When a multichannel session binding request fails (e.g. wrong password),
the error path unconditionally sets sess-&amp;gt;state = SMB2_SESSION_EXPIRED.
However, during binding, sess points to the target session looked up via
ksmbd_session_lookup_slowpath() -- which belongs to another connection&amp;#39;s
user. This allows a remote attacker to invalidate any active session by
simply sending a binding request with a wrong password (DoS).&lt;/p&gt;
&lt;p&gt;Fix this by skipping session expiration when the failed request was
a binding attempt, since the session does not belong to the current
connection. The reference taken by ksmbd_session_lookup_slowpath() is
still correctly released via ksmbd_user_session_put().&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;ksmbd: do not expire session on binding failure&lt;/p&gt;
&lt;p&gt;When a multichannel session binding request fails (e.g. wrong password),
the error path unconditionally sets sess-&amp;gt;state = SMB2_SESSION_EXPIRED.
However, during binding, sess points to the target session looked up via
ksmbd_session_lookup_slowpath() -- which belongs to another connection&amp;#39;s
user. This allows a remote attacker to invalidate any active session by
simply sending a binding request with a wrong password (DoS).&lt;/p&gt;
&lt;p&gt;Fix this by skipping session expiration when the failed request was
a binding attempt, since the session does not belong to the current
connection. The reference taken by ksmbd_session_lookup_slowpath() is
still correctly released via ksmbd_user_session_put().&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-31476</guid>
    </item>
    <item>
      <title>GHSA-223f-gch2-xvq3</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-223f-gch2-xvq3</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;ksmbd: do not expire session on binding failure&lt;/p&gt;
&lt;p&gt;When a multichannel session binding request fails (e.g. wrong password),
the error path unconditionally sets sess-&amp;gt;state = SMB2_SESSION_EXPIRED.
However, during binding, sess points to the target session looked up via
ksmbd_session_lookup_slowpath() -- which belongs to another connection&amp;#39;s
user. This allows a remote attacker to invalidate any active session by
simply sending a binding request with a wrong password (DoS).&lt;/p&gt;
&lt;p&gt;Fix this by skipping session expiration when the failed request was
a binding attempt, since the session does not belong to the current
connection. The reference taken by ksmbd_session_lookup_slowpath() is
still correctly released via ksmbd_user_session_put().&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;ksmbd: do not expire session on binding failure&lt;/p&gt;
&lt;p&gt;When a multichannel session binding request fails (e.g. wrong password),
the error path unconditionally sets sess-&amp;gt;state = SMB2_SESSION_EXPIRED.
However, during binding, sess points to the target session looked up via
ksmbd_session_lookup_slowpath() -- which belongs to another connection&amp;#39;s
user. This allows a remote attacker to invalidate any active session by
simply sending a binding request with a wrong password (DoS).&lt;/p&gt;
&lt;p&gt;Fix this by skipping session expiration when the failed request was
a binding attempt, since the session does not belong to the current
connection. The reference taken by ksmbd_session_lookup_slowpath() is
still correctly released via ksmbd_user_session_put().&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-223f-gch2-xvq3</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-31476 — ksmbd: do not expire session on binding failure</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-31476</link>
      <description>msrc_CVE-2026-31476</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-31476</guid>
    </item>
    <item>
      <title>OESA-2026-2311 — kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-2311</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP4: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;drm/vmwgfx: Return the correct value in vmw_translate_ptr functions&lt;/p&gt;
&lt;p&gt;Before the referenced fixes these functions used a lookup function that
returned a pointer. This was changed to another lookup function that
returned an error code with the pointer becoming an out parameter.&lt;/p&gt;
&lt;p&gt;The error path when the lookup failed was not changed to reflect this
change and the code continued to return the PTR_ERR of the now
uninitialized pointer. This could cause the vmw_translate_ptr functions
to return success when they actually failed causing further uninitialized
and OOB accesses.(CVE-2026-23317)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;NFSD: Defer sub-object cleanup in export put callbacks&lt;/p&gt;
&lt;p&gt;svc_export_put() calls path_put() and auth_domain_put() immediately
when the last reference drops, before the RCU grace period. RCU
readers in e_show() and c_show() access both ex_path (via
seq_path/d_path) and ex_client-&amp;amp;gt;name (via seq_escape) without
holding a reference. If cache_clean removes the entry and drops the
last reference concurrently, the sub-objects are freed while still
in use, producing a NULL pointer dereference in d_path.&lt;/p&gt;
&lt;p&gt;Commit 2530766492ec (&amp;amp;quot;nfsd: fix UAF when access ex_uuid or
ex_stats&amp;amp;quot;) moved kfree of ex_uuid and ex_stats into the
call_rcu callback, but left path_put() and auth_domain_put() runnin…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP4: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;drm/vmwgfx: Return the correct value in vmw_translate_ptr functions&lt;/p&gt;
&lt;p&gt;Before the referenced fixes these functions used a lookup function that
returned a pointer. This was changed to another lookup function that
returned an error code with the pointer becoming an out parameter.&lt;/p&gt;
&lt;p&gt;The error path when the lookup failed was not changed to reflect this
change and the code continued to return the PTR_ERR of the now
uninitialized pointer. This could cause the vmw_translate_ptr functions
to return success when they actually failed causing further uninitialized
and OOB accesses.(CVE-2026-23317)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;NFSD: Defer sub-object cleanup in export put callbacks&lt;/p&gt;
&lt;p&gt;svc_export_put() calls path_put() and auth_domain_put() immediately
when the last reference drops, before the RCU grace period. RCU
readers in e_show() and c_show() access both ex_path (via
seq_path/d_path) and ex_client-&amp;amp;gt;name (via seq_escape) without
holding a reference. If cache_clean removes the entry and drops the
last reference concurrently, the sub-objects are freed while still
in use, producing a NULL pointer dereference in d_path.&lt;/p&gt;
&lt;p&gt;Commit 2530766492ec (&amp;amp;quot;nfsd: fix UAF when access ex_uuid or
ex_stats&amp;amp;quot;) moved kfree of ex_uuid and ex_stats into the
call_rcu callback, but left path_put() and auth_domain_put() runnin…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-2311</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-31476</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-31476</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 179 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: ksmbd: do not expire session on binding failure When a multichannel session binding request fails (e.g. wrong password), the error path unconditionally sets sess-&amp;gt;state = SMB2_SESSION_EXPIRED. However, during binding, sess points to the target session looked up via ksmbd_session_lookup_slowpath() -- which belongs to another connection&amp;#39;s user. This allows a remote attacker to invalidate any active session by simply sending a binding request with a wrong password (DoS). Fix this by skipping session expiration when the failed request was a binding attempt, since the session does not belong to the current connection. The reference taken by ksmbd_session_lookup_slowpath() is still correctly released via ksmbd_user_session_put().&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 179 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: ksmbd: do not expire session on binding failure When a multichannel session binding request fails (e.g. wrong password), the error path unconditionally sets sess-&amp;gt;state = SMB2_SESSION_EXPIRED. However, during binding, sess points to the target session looked up via ksmbd_session_lookup_slowpath() -- which belongs to another connection&amp;#39;s user. This allows a remote attacker to invalidate any active session by simply sending a binding request with a wrong password (DoS). Fix this by skipping session expiration when the failed request was a binding attempt, since the session does not belong to the current connection. The reference taken by ksmbd_session_lookup_slowpath() is still correctly released via ksmbd_user_session_put().&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-31476</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1252 — Linux Kernel: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1252</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen, Sicherheitsmaßnahmen zu umgehen, Informationen offenzulegen, andere nicht näher spezifizierte Auswirkungen zu verursachen und möglicherweise Code auszuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen, Sicherheitsmaßnahmen zu umgehen, Informationen offenzulegen, andere nicht näher spezifizierte Auswirkungen zu verursachen und möglicherweise Code auszuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1252</guid>
    </item>
  </channel>
</rss>
