<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 12:24:51 +0000</lastBuildDate>
    <item>
      <title>BELL-CVE-2026-31527</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-31527</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-31527</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0548 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de Debian. Certaines d'entre elles permettent à un…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0548</link>
      <description>certfr-2026-avi-0548</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0548</guid>
    </item>
    <item>
      <title>EUVD-2026-323491</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-323491</link>
      <description>EUVD-2026-323491</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-323491</guid>
    </item>
    <item>
      <title>fkie_cve-2026-31527</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-31527</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;driver core: platform: use generic driver_override infrastructure&lt;/p&gt;
&lt;p&gt;When a driver is probed through __driver_attach(), the bus&amp;#39; match()
callback is called without the device lock held, thus accessing the
driver_override field without a lock, which can cause a UAF.&lt;/p&gt;
&lt;p&gt;Fix this by using the driver-core driver_override infrastructure taking
care of proper locking internally.&lt;/p&gt;
&lt;p&gt;Note that calling match() from __driver_attach() without the device lock
held is intentional. [1]&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;driver core: platform: use generic driver_override infrastructure&lt;/p&gt;
&lt;p&gt;When a driver is probed through __driver_attach(), the bus&amp;#39; match()
callback is called without the device lock held, thus accessing the
driver_override field without a lock, which can cause a UAF.&lt;/p&gt;
&lt;p&gt;Fix this by using the driver-core driver_override infrastructure taking
care of proper locking internally.&lt;/p&gt;
&lt;p&gt;Note that calling match() from __driver_attach() without the device lock
held is intentional. [1]&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-31527</guid>
    </item>
    <item>
      <title>GHSA-jr2g-46m2-f9rc</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-jr2g-46m2-f9rc</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;driver core: platform: use generic driver_override infrastructure&lt;/p&gt;
&lt;p&gt;When a driver is probed through __driver_attach(), the bus&amp;#39; match()
callback is called without the device lock held, thus accessing the
driver_override field without a lock, which can cause a UAF.&lt;/p&gt;
&lt;p&gt;Fix this by using the driver-core driver_override infrastructure taking
care of proper locking internally.&lt;/p&gt;
&lt;p&gt;Note that calling match() from __driver_attach() without the device lock
held is intentional. [1]&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;driver core: platform: use generic driver_override infrastructure&lt;/p&gt;
&lt;p&gt;When a driver is probed through __driver_attach(), the bus&amp;#39; match()
callback is called without the device lock held, thus accessing the
driver_override field without a lock, which can cause a UAF.&lt;/p&gt;
&lt;p&gt;Fix this by using the driver-core driver_override infrastructure taking
care of proper locking internally.&lt;/p&gt;
&lt;p&gt;Note that calling match() from __driver_attach() without the device lock
held is intentional. [1]&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-jr2g-46m2-f9rc</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-31527 — driver core: platform: use generic driver_override infrastructure</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-31527</link>
      <description>msrc_CVE-2026-31527</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-31527</guid>
    </item>
    <item>
      <title>OESA-2026-2415 — kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-2415</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP4: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;driver core: platform: use generic driver_override infrastructure&lt;/p&gt;
&lt;p&gt;When a driver is probed through __driver_attach(), the bus&amp;amp;apos; match()
callback is called without the device lock held, thus accessing the
driver_override field without a lock, which can cause a UAF.&lt;/p&gt;
&lt;p&gt;Fix this by using the driver-core driver_override infrastructure taking
care of proper locking internally.&lt;/p&gt;
&lt;p&gt;Note that calling match() from __driver_attach() without the device lock
held is intentional. [1](CVE-2026-31527)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;crypto: ccp: Don&amp;amp;apos;t attempt to copy PDH cert to userspace if PSP command failed&lt;/p&gt;
&lt;p&gt;When retrieving the PDH cert, don&amp;amp;apos;t attempt to copy the blobs to userspace
if the firmware command failed.  If the failure was due to an invalid
length, i.e. the userspace buffer+length was too small, copying the number
of bytes _firmware_ requires will overflow the kernel-allocated buffer and
leak data to userspace.&lt;/p&gt;
&lt;p&gt;BUG: KASAN: slab-out-of-bounds in instrument_copy_to_user ../include/linux/instrumented.h:129 [inline]
  BUG: KASAN: slab-out-of-bounds in _inline_copy_to_user ../include/linux/uaccess.h:205 [inline]
  BUG: KASAN: slab-out-of-bounds in _copy_to_user+0x66/0xa0 ../lib/usercopy.c:26
  Read of size 2084 at addr ffff8885c4ab8aa0 by task syz.0.186/21033&lt;/p&gt;
&lt;p&gt;CPU: 51 UID: 0 PID: 21033 Com…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP4: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;driver core: platform: use generic driver_override infrastructure&lt;/p&gt;
&lt;p&gt;When a driver is probed through __driver_attach(), the bus&amp;amp;apos; match()
callback is called without the device lock held, thus accessing the
driver_override field without a lock, which can cause a UAF.&lt;/p&gt;
&lt;p&gt;Fix this by using the driver-core driver_override infrastructure taking
care of proper locking internally.&lt;/p&gt;
&lt;p&gt;Note that calling match() from __driver_attach() without the device lock
held is intentional. [1](CVE-2026-31527)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;crypto: ccp: Don&amp;amp;apos;t attempt to copy PDH cert to userspace if PSP command failed&lt;/p&gt;
&lt;p&gt;When retrieving the PDH cert, don&amp;amp;apos;t attempt to copy the blobs to userspace
if the firmware command failed.  If the failure was due to an invalid
length, i.e. the userspace buffer+length was too small, copying the number
of bytes _firmware_ requires will overflow the kernel-allocated buffer and
leak data to userspace.&lt;/p&gt;
&lt;p&gt;BUG: KASAN: slab-out-of-bounds in instrument_copy_to_user ../include/linux/instrumented.h:129 [inline]
  BUG: KASAN: slab-out-of-bounds in _inline_copy_to_user ../include/linux/uaccess.h:205 [inline]
  BUG: KASAN: slab-out-of-bounds in _copy_to_user+0x66/0xa0 ../lib/usercopy.c:26
  Read of size 2084 at addr ffff8885c4ab8aa0 by task syz.0.186/21033&lt;/p&gt;
&lt;p&gt;CPU: 51 UID: 0 PID: 21033 Com…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-2415</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-31527</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-31527</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe, Ubuntu:16.04:LTS: linux-hwe-edge and 231 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: driver core: platform: use generic driver_override infrastructure When a driver is probed through __driver_attach(), the bus&amp;#39; match() callback is called without the device lock held, thus accessing the driver_override field without a lock, which can cause a UAF. Fix this by using the driver-core driver_override infrastructure taking care of proper locking internally. Note that calling match() from __driver_attach() without the device lock held is intentional. [1]&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe, Ubuntu:16.04:LTS: linux-hwe-edge and 231 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: driver core: platform: use generic driver_override infrastructure When a driver is probed through __driver_attach(), the bus&amp;#39; match() callback is called without the device lock held, thus accessing the driver_override field without a lock, which can cause a UAF. Fix this by using the driver-core driver_override infrastructure taking care of proper locking internally. Note that calling match() from __driver_attach() without the device lock held is intentional. [1]&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-31527</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1252 — Linux Kernel: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1252</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen, Sicherheitsmaßnahmen zu umgehen, Informationen offenzulegen, andere nicht näher spezifizierte Auswirkungen zu verursachen und möglicherweise Code auszuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen, Sicherheitsmaßnahmen zu umgehen, Informationen offenzulegen, andere nicht näher spezifizierte Auswirkungen zu verursachen und möglicherweise Code auszuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1252</guid>
    </item>
  </channel>
</rss>
