<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 05:58:13 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-12536</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-12536</link>
      <description>bdu:2026-12536</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-12536</guid>
    </item>
    <item>
      <title>BELL-CVE-2026-31500</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-31500</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-31500</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0519 — De multiples vulnérabilités ont été découvertes dans Microsoft Azure Linux. Elles permettent à un attaquant de provoque…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0519</link>
      <description>certfr-2026-avi-0519</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0519</guid>
    </item>
    <item>
      <title>EUVD-2026-323490</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-323490</link>
      <description>EUVD-2026-323490</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-323490</guid>
    </item>
    <item>
      <title>fkie_cve-2026-31500</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-31500</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;Bluetooth: btintel: serialize btintel_hw_error() with hci_req_sync_lock&lt;/p&gt;
&lt;p&gt;btintel_hw_error() issues two __hci_cmd_sync() calls (HCI_OP_RESET
and Intel exception-info retrieval) without holding
hci_req_sync_lock().  This lets it race against
hci_dev_do_close() -&amp;gt; btintel_shutdown_combined(), which also runs
__hci_cmd_sync() under the same lock.  When both paths manipulate
hdev-&amp;gt;req_status/req_rsp concurrently, the close path may free the
response skb first, and the still-running hw_error path hits a
slab-use-after-free in kfree_skb().&lt;/p&gt;
&lt;p&gt;Wrap the whole recovery sequence in hci_req_sync_lock/unlock so it
is serialized with every other synchronous HCI command issuer.&lt;/p&gt;
&lt;p&gt;Below is the data race report and the kasan report:&lt;/p&gt;
&lt;p&gt;BUG: data-race in __hci_cmd_sync_sk / btintel_shutdown_combined&lt;/p&gt;
&lt;p&gt;read of hdev-&amp;gt;req_rsp at net/bluetooth/hci_sync.c:199
  by task kworker/u17:1/83:
   __hci_cmd_sync_sk+0x12f2/0x1c30 net/bluetooth/hci_sync.c:200
   __hci_cmd_sync+0x55/0x80 net/bluetooth/hci_sync.c:223
   btintel_hw_error+0x114/0x670 drivers/bluetooth/btintel.c:254
   hci_error_reset+0x348/0xa30 net/bluetooth/hci_core.c:1030&lt;/p&gt;
&lt;p&gt;write/free by task ioctl/22580:
   btintel_shutdown_combined+0xd0/0x360
    drivers/bluetooth/btintel.c:3648
   hci_dev_close_sync+0x9ae/0x2c10 net/bluetooth/hci_sync.c:5246
   hci_dev_do_close+0x232/0x460 net/bluetooth/hci_core.c:526&lt;/p&gt;
&lt;p&gt;BUG: KASAN: slab-use-after-free in
   sk_skb_reason_drop+0x43/0x380…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;Bluetooth: btintel: serialize btintel_hw_error() with hci_req_sync_lock&lt;/p&gt;
&lt;p&gt;btintel_hw_error() issues two __hci_cmd_sync() calls (HCI_OP_RESET
and Intel exception-info retrieval) without holding
hci_req_sync_lock().  This lets it race against
hci_dev_do_close() -&amp;gt; btintel_shutdown_combined(), which also runs
__hci_cmd_sync() under the same lock.  When both paths manipulate
hdev-&amp;gt;req_status/req_rsp concurrently, the close path may free the
response skb first, and the still-running hw_error path hits a
slab-use-after-free in kfree_skb().&lt;/p&gt;
&lt;p&gt;Wrap the whole recovery sequence in hci_req_sync_lock/unlock so it
is serialized with every other synchronous HCI command issuer.&lt;/p&gt;
&lt;p&gt;Below is the data race report and the kasan report:&lt;/p&gt;
&lt;p&gt;BUG: data-race in __hci_cmd_sync_sk / btintel_shutdown_combined&lt;/p&gt;
&lt;p&gt;read of hdev-&amp;gt;req_rsp at net/bluetooth/hci_sync.c:199
  by task kworker/u17:1/83:
   __hci_cmd_sync_sk+0x12f2/0x1c30 net/bluetooth/hci_sync.c:200
   __hci_cmd_sync+0x55/0x80 net/bluetooth/hci_sync.c:223
   btintel_hw_error+0x114/0x670 drivers/bluetooth/btintel.c:254
   hci_error_reset+0x348/0xa30 net/bluetooth/hci_core.c:1030&lt;/p&gt;
&lt;p&gt;write/free by task ioctl/22580:
   btintel_shutdown_combined+0xd0/0x360
    drivers/bluetooth/btintel.c:3648
   hci_dev_close_sync+0x9ae/0x2c10 net/bluetooth/hci_sync.c:5246
   hci_dev_do_close+0x232/0x460 net/bluetooth/hci_core.c:526&lt;/p&gt;
&lt;p&gt;BUG: KASAN: slab-use-after-free in
   sk_skb_reason_drop+0x43/0x380…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-31500</guid>
    </item>
    <item>
      <title>GHSA-vv93-v48r-h8pj</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-vv93-v48r-h8pj</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;Bluetooth: btintel: serialize btintel_hw_error() with hci_req_sync_lock&lt;/p&gt;
&lt;p&gt;btintel_hw_error() issues two __hci_cmd_sync() calls (HCI_OP_RESET
and Intel exception-info retrieval) without holding
hci_req_sync_lock().  This lets it race against
hci_dev_do_close() -&amp;gt; btintel_shutdown_combined(), which also runs
__hci_cmd_sync() under the same lock.  When both paths manipulate
hdev-&amp;gt;req_status/req_rsp concurrently, the close path may free the
response skb first, and the still-running hw_error path hits a
slab-use-after-free in kfree_skb().&lt;/p&gt;
&lt;p&gt;Wrap the whole recovery sequence in hci_req_sync_lock/unlock so it
is serialized with every other synchronous HCI command issuer.&lt;/p&gt;
&lt;p&gt;Below is the data race report and the kasan report:&lt;/p&gt;
&lt;p&gt;BUG: data-race in __hci_cmd_sync_sk / btintel_shutdown_combined&lt;/p&gt;
&lt;p&gt;read of hdev-&amp;gt;req_rsp at net/bluetooth/hci_sync.c:199
  by task kworker/u17:1/83:
   __hci_cmd_sync_sk+0x12f2/0x1c30 net/bluetooth/hci_sync.c:200
   __hci_cmd_sync+0x55/0x80 net/bluetooth/hci_sync.c:223
   btintel_hw_error+0x114/0x670 drivers/bluetooth/btintel.c:254
   hci_error_reset+0x348/0xa30 net/bluetooth/hci_core.c:1030&lt;/p&gt;
&lt;p&gt;write/free by task ioctl/22580:
   btintel_shutdown_combined+0xd0/0x360
    drivers/bluetooth/btintel.c:3648
   hci_dev_close_sync+0x9ae/0x2c10 net/bluetooth/hci_sync.c:5246
   hci_dev_do_close+0x232/0x460 net/bluetooth/hci_core.c:526&lt;/p&gt;
&lt;p&gt;BUG: KASAN: slab-use-after-free in
   sk_skb_reason_drop+0x43/0x380…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;Bluetooth: btintel: serialize btintel_hw_error() with hci_req_sync_lock&lt;/p&gt;
&lt;p&gt;btintel_hw_error() issues two __hci_cmd_sync() calls (HCI_OP_RESET
and Intel exception-info retrieval) without holding
hci_req_sync_lock().  This lets it race against
hci_dev_do_close() -&amp;gt; btintel_shutdown_combined(), which also runs
__hci_cmd_sync() under the same lock.  When both paths manipulate
hdev-&amp;gt;req_status/req_rsp concurrently, the close path may free the
response skb first, and the still-running hw_error path hits a
slab-use-after-free in kfree_skb().&lt;/p&gt;
&lt;p&gt;Wrap the whole recovery sequence in hci_req_sync_lock/unlock so it
is serialized with every other synchronous HCI command issuer.&lt;/p&gt;
&lt;p&gt;Below is the data race report and the kasan report:&lt;/p&gt;
&lt;p&gt;BUG: data-race in __hci_cmd_sync_sk / btintel_shutdown_combined&lt;/p&gt;
&lt;p&gt;read of hdev-&amp;gt;req_rsp at net/bluetooth/hci_sync.c:199
  by task kworker/u17:1/83:
   __hci_cmd_sync_sk+0x12f2/0x1c30 net/bluetooth/hci_sync.c:200
   __hci_cmd_sync+0x55/0x80 net/bluetooth/hci_sync.c:223
   btintel_hw_error+0x114/0x670 drivers/bluetooth/btintel.c:254
   hci_error_reset+0x348/0xa30 net/bluetooth/hci_core.c:1030&lt;/p&gt;
&lt;p&gt;write/free by task ioctl/22580:
   btintel_shutdown_combined+0xd0/0x360
    drivers/bluetooth/btintel.c:3648
   hci_dev_close_sync+0x9ae/0x2c10 net/bluetooth/hci_sync.c:5246
   hci_dev_do_close+0x232/0x460 net/bluetooth/hci_core.c:526&lt;/p&gt;
&lt;p&gt;BUG: KASAN: slab-use-after-free in
   sk_skb_reason_drop+0x43/0x380…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-vv93-v48r-h8pj</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-31500 — Bluetooth: btintel: serialize btintel_hw_error() with hci_req_sync_lock</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-31500</link>
      <description>msrc_CVE-2026-31500</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-31500</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:21555-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:21555-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:21555-1</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:22433-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:22433-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:22433-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-31500</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-31500</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe, Ubuntu:16.04:LTS: linux-hwe-edge and 231 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btintel: serialize btintel_hw_error() with hci_req_sync_lock btintel_hw_error() issues two __hci_cmd_sync() calls (HCI_OP_RESET and Intel exception-info retrieval) without holding hci_req_sync_lock().  This lets it race against hci_dev_do_close() -&amp;gt; btintel_shutdown_combined(), which also runs __hci_cmd_sync() under the same lock.  When both paths manipulate hdev-&amp;gt;req_status/req_rsp concurrently, the close path may free the response skb first, and the still-running hw_error path hits a slab-use-after-free in kfree_skb(). Wrap the whole recovery sequence in hci_req_sync_lock/unlock so it is serialized with every other synchronous HCI command issuer. Below is the data race report and the kasan report:   BUG: data-race in __hci_cmd_sync_sk / btintel_shutdown_combined   read of hdev-&amp;gt;req_rsp at net/bluetooth/hci_sync.c:199   by task kworker/u17:1/83:    __hci_cmd_sync_sk+0x12f2/0x1c30 net/bluetooth/hci_sync.c:200    __hci_cmd_sync+0x55/0x80 net/bluetooth/hci_sync.c:223    btintel_hw_error+0x114/0x670 drivers/bluetooth/btintel.c:254    hci_error_reset+0x348/0xa30 net/bluetooth/hci_core.c:1030   write/free by task ioctl/22580:    btintel_shutdown_combined+0xd0/0x360     drivers/bluetooth/btintel.c:3648    hci_dev_close_sync+0x9ae/0x2c10 net/bluetooth/hci_sync.c:5246    hci_dev_do_close+0x232/0x460 net/bluetooth/hci_core.c:526   BUG: KASAN: slab-use-after-free in    sk_skb_reason_drop+0x43/0x380 net/core…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe, Ubuntu:16.04:LTS: linux-hwe-edge and 231 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btintel: serialize btintel_hw_error() with hci_req_sync_lock btintel_hw_error() issues two __hci_cmd_sync() calls (HCI_OP_RESET and Intel exception-info retrieval) without holding hci_req_sync_lock().  This lets it race against hci_dev_do_close() -&amp;gt; btintel_shutdown_combined(), which also runs __hci_cmd_sync() under the same lock.  When both paths manipulate hdev-&amp;gt;req_status/req_rsp concurrently, the close path may free the response skb first, and the still-running hw_error path hits a slab-use-after-free in kfree_skb(). Wrap the whole recovery sequence in hci_req_sync_lock/unlock so it is serialized with every other synchronous HCI command issuer. Below is the data race report and the kasan report:   BUG: data-race in __hci_cmd_sync_sk / btintel_shutdown_combined   read of hdev-&amp;gt;req_rsp at net/bluetooth/hci_sync.c:199   by task kworker/u17:1/83:    __hci_cmd_sync_sk+0x12f2/0x1c30 net/bluetooth/hci_sync.c:200    __hci_cmd_sync+0x55/0x80 net/bluetooth/hci_sync.c:223    btintel_hw_error+0x114/0x670 drivers/bluetooth/btintel.c:254    hci_error_reset+0x348/0xa30 net/bluetooth/hci_core.c:1030   write/free by task ioctl/22580:    btintel_shutdown_combined+0xd0/0x360     drivers/bluetooth/btintel.c:3648    hci_dev_close_sync+0x9ae/0x2c10 net/bluetooth/hci_sync.c:5246    hci_dev_do_close+0x232/0x460 net/bluetooth/hci_core.c:526   BUG: KASAN: slab-use-after-free in    sk_skb_reason_drop+0x43/0x380 net/core…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-31500</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1252 — Linux Kernel: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1252</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen, Sicherheitsmaßnahmen zu umgehen, Informationen offenzulegen, andere nicht näher spezifizierte Auswirkungen zu verursachen und möglicherweise Code auszuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen, Sicherheitsmaßnahmen zu umgehen, Informationen offenzulegen, andere nicht näher spezifizierte Auswirkungen zu verursachen und möglicherweise Code auszuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1252</guid>
    </item>
  </channel>
</rss>
