<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 11:57:29 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-12542</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-12542</link>
      <description>bdu:2026-12542</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-12542</guid>
    </item>
    <item>
      <title>BELL-CVE-2026-31509</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-31509</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-31509</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0519 — De multiples vulnérabilités ont été découvertes dans Microsoft Azure Linux. Elles permettent à un attaquant de provoque…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0519</link>
      <description>certfr-2026-avi-0519</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0519</guid>
    </item>
    <item>
      <title>EUVD-2026-315595</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-315595</link>
      <description>EUVD-2026-315595</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-315595</guid>
    </item>
    <item>
      <title>fkie_cve-2026-31509</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-31509</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;nfc: nci: fix circular locking dependency in nci_close_device&lt;/p&gt;
&lt;p&gt;nci_close_device() flushes rx_wq and tx_wq while holding req_lock.
This causes a circular locking dependency because nci_rx_work()
running on rx_wq can end up taking req_lock too:&lt;/p&gt;
&lt;p&gt;nci_rx_work -&amp;gt; nci_rx_data_packet -&amp;gt; nci_data_exchange_complete
    -&amp;gt; __sk_destruct -&amp;gt; rawsock_destruct -&amp;gt; nfc_deactivate_target
    -&amp;gt; nci_deactivate_target -&amp;gt; nci_request -&amp;gt; mutex_lock(&amp;amp;ndev-&amp;gt;req_lock)&lt;/p&gt;
&lt;p&gt;Move the flush of rx_wq after req_lock has been released.
This should safe (I think) because NCI_UP has already been cleared
and the transport is closed, so the work will see it and return
-ENETDOWN.&lt;/p&gt;
&lt;p&gt;NIPA has been hitting this running the nci selftest with a debug
kernel on roughly 4% of the runs.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;nfc: nci: fix circular locking dependency in nci_close_device&lt;/p&gt;
&lt;p&gt;nci_close_device() flushes rx_wq and tx_wq while holding req_lock.
This causes a circular locking dependency because nci_rx_work()
running on rx_wq can end up taking req_lock too:&lt;/p&gt;
&lt;p&gt;nci_rx_work -&amp;gt; nci_rx_data_packet -&amp;gt; nci_data_exchange_complete
    -&amp;gt; __sk_destruct -&amp;gt; rawsock_destruct -&amp;gt; nfc_deactivate_target
    -&amp;gt; nci_deactivate_target -&amp;gt; nci_request -&amp;gt; mutex_lock(&amp;amp;ndev-&amp;gt;req_lock)&lt;/p&gt;
&lt;p&gt;Move the flush of rx_wq after req_lock has been released.
This should safe (I think) because NCI_UP has already been cleared
and the transport is closed, so the work will see it and return
-ENETDOWN.&lt;/p&gt;
&lt;p&gt;NIPA has been hitting this running the nci selftest with a debug
kernel on roughly 4% of the runs.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-31509</guid>
    </item>
    <item>
      <title>GHSA-x33w-8476-hwm3</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-x33w-8476-hwm3</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;nfc: nci: fix circular locking dependency in nci_close_device&lt;/p&gt;
&lt;p&gt;nci_close_device() flushes rx_wq and tx_wq while holding req_lock.
This causes a circular locking dependency because nci_rx_work()
running on rx_wq can end up taking req_lock too:&lt;/p&gt;
&lt;p&gt;nci_rx_work -&amp;gt; nci_rx_data_packet -&amp;gt; nci_data_exchange_complete
    -&amp;gt; __sk_destruct -&amp;gt; rawsock_destruct -&amp;gt; nfc_deactivate_target
    -&amp;gt; nci_deactivate_target -&amp;gt; nci_request -&amp;gt; mutex_lock(&amp;amp;ndev-&amp;gt;req_lock)&lt;/p&gt;
&lt;p&gt;Move the flush of rx_wq after req_lock has been released.
This should safe (I think) because NCI_UP has already been cleared
and the transport is closed, so the work will see it and return
-ENETDOWN.&lt;/p&gt;
&lt;p&gt;NIPA has been hitting this running the nci selftest with a debug
kernel on roughly 4% of the runs.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;nfc: nci: fix circular locking dependency in nci_close_device&lt;/p&gt;
&lt;p&gt;nci_close_device() flushes rx_wq and tx_wq while holding req_lock.
This causes a circular locking dependency because nci_rx_work()
running on rx_wq can end up taking req_lock too:&lt;/p&gt;
&lt;p&gt;nci_rx_work -&amp;gt; nci_rx_data_packet -&amp;gt; nci_data_exchange_complete
    -&amp;gt; __sk_destruct -&amp;gt; rawsock_destruct -&amp;gt; nfc_deactivate_target
    -&amp;gt; nci_deactivate_target -&amp;gt; nci_request -&amp;gt; mutex_lock(&amp;amp;ndev-&amp;gt;req_lock)&lt;/p&gt;
&lt;p&gt;Move the flush of rx_wq after req_lock has been released.
This should safe (I think) because NCI_UP has already been cleared
and the transport is closed, so the work will see it and return
-ENETDOWN.&lt;/p&gt;
&lt;p&gt;NIPA has been hitting this running the nci selftest with a debug
kernel on roughly 4% of the runs.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-x33w-8476-hwm3</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-31509 — nfc: nci: fix circular locking dependency in nci_close_device</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-31509</link>
      <description>msrc_CVE-2026-31509</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-31509</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:21555-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:21555-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:21555-1</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:23066-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:23066-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:23066-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-31509</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-31509</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux, Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe and 232 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: nfc: nci: fix circular locking dependency in nci_close_device nci_close_device() flushes rx_wq and tx_wq while holding req_lock. This causes a circular locking dependency because nci_rx_work() running on rx_wq can end up taking req_lock too:   nci_rx_work -&amp;gt; nci_rx_data_packet -&amp;gt; nci_data_exchange_complete     -&amp;gt; __sk_destruct -&amp;gt; rawsock_destruct -&amp;gt; nfc_deactivate_target     -&amp;gt; nci_deactivate_target -&amp;gt; nci_request -&amp;gt; mutex_lock(&amp;amp;ndev-&amp;gt;req_lock) Move the flush of rx_wq after req_lock has been released. This should safe (I think) because NCI_UP has already been cleared and the transport is closed, so the work will see it and return -ENETDOWN. NIPA has been hitting this running the nci selftest with a debug kernel on roughly 4% of the runs.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux, Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe and 232 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: nfc: nci: fix circular locking dependency in nci_close_device nci_close_device() flushes rx_wq and tx_wq while holding req_lock. This causes a circular locking dependency because nci_rx_work() running on rx_wq can end up taking req_lock too:   nci_rx_work -&amp;gt; nci_rx_data_packet -&amp;gt; nci_data_exchange_complete     -&amp;gt; __sk_destruct -&amp;gt; rawsock_destruct -&amp;gt; nfc_deactivate_target     -&amp;gt; nci_deactivate_target -&amp;gt; nci_request -&amp;gt; mutex_lock(&amp;amp;ndev-&amp;gt;req_lock) Move the flush of rx_wq after req_lock has been released. This should safe (I think) because NCI_UP has already been cleared and the transport is closed, so the work will see it and return -ENETDOWN. NIPA has been hitting this running the nci selftest with a debug kernel on roughly 4% of the runs.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-31509</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1252 — Linux Kernel: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1252</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen, Sicherheitsmaßnahmen zu umgehen, Informationen offenzulegen, andere nicht näher spezifizierte Auswirkungen zu verursachen und möglicherweise Code auszuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen, Sicherheitsmaßnahmen zu umgehen, Informationen offenzulegen, andere nicht näher spezifizierte Auswirkungen zu verursachen und möglicherweise Code auszuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1252</guid>
    </item>
  </channel>
</rss>
