<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 12:32:04 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-12355</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-12355</link>
      <description>bdu:2026-12355</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-12355</guid>
    </item>
    <item>
      <title>BELL-CVE-2026-31561</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-31561</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-31561</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0548 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de Debian. Certaines d'entre elles permettent à un…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0548</link>
      <description>certfr-2026-avi-0548</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0548</guid>
    </item>
    <item>
      <title>EUVD-2026-315624</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-315624</link>
      <description>EUVD-2026-315624</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-315624</guid>
    </item>
    <item>
      <title>fkie_cve-2026-31561</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-31561</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;x86/cpu: Remove X86_CR4_FRED from the CR4 pinned bits mask&lt;/p&gt;
&lt;p&gt;Commit in Fixes added the FRED CR4 bit to the CR4 pinned bits mask so
that whenever something else modifies CR4, that bit remains set. Which
in itself is a perfectly fine idea.&lt;/p&gt;
&lt;p&gt;However, there&amp;#39;s an issue when during boot FRED is initialized: first on
the BSP and later on the APs. Thus, there&amp;#39;s a window in time when
exceptions cannot be handled.&lt;/p&gt;
&lt;p&gt;This becomes particularly nasty when running as SEV-{ES,SNP} or TDX
guests which, when they manage to trigger exceptions during that short
window described above, triple fault due to FRED MSRs not being set up
yet.&lt;/p&gt;
&lt;p&gt;See Link tag below for a much more detailed explanation of the
situation.&lt;/p&gt;
&lt;p&gt;So, as a result, the commit in that Link URL tried to address this
shortcoming by temporarily disabling CR4 pinning when an AP is not
online yet.&lt;/p&gt;
&lt;p&gt;However, that is a problem in itself because in this case, an attack on
the kernel needs to only modify the online bit - a single bit in RW
memory - and then disable CR4 pinning and then disable SM*P, leading to
more and worse things to happen to the system.&lt;/p&gt;
&lt;p&gt;So, instead, remove the FRED bit from the CR4 pinning mask, thus
obviating the need to temporarily disable CR4 pinning.&lt;/p&gt;
&lt;p&gt;If someone manages to disable FRED when poking at CR4, then
idt_invalidate() would make sure the system would crash&amp;#39;n&amp;#39;burn on the
first exception triggered, which is a much better outcome security-wise.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;x86/cpu: Remove X86_CR4_FRED from the CR4 pinned bits mask&lt;/p&gt;
&lt;p&gt;Commit in Fixes added the FRED CR4 bit to the CR4 pinned bits mask so
that whenever something else modifies CR4, that bit remains set. Which
in itself is a perfectly fine idea.&lt;/p&gt;
&lt;p&gt;However, there&amp;#39;s an issue when during boot FRED is initialized: first on
the BSP and later on the APs. Thus, there&amp;#39;s a window in time when
exceptions cannot be handled.&lt;/p&gt;
&lt;p&gt;This becomes particularly nasty when running as SEV-{ES,SNP} or TDX
guests which, when they manage to trigger exceptions during that short
window described above, triple fault due to FRED MSRs not being set up
yet.&lt;/p&gt;
&lt;p&gt;See Link tag below for a much more detailed explanation of the
situation.&lt;/p&gt;
&lt;p&gt;So, as a result, the commit in that Link URL tried to address this
shortcoming by temporarily disabling CR4 pinning when an AP is not
online yet.&lt;/p&gt;
&lt;p&gt;However, that is a problem in itself because in this case, an attack on
the kernel needs to only modify the online bit - a single bit in RW
memory - and then disable CR4 pinning and then disable SM*P, leading to
more and worse things to happen to the system.&lt;/p&gt;
&lt;p&gt;So, instead, remove the FRED bit from the CR4 pinning mask, thus
obviating the need to temporarily disable CR4 pinning.&lt;/p&gt;
&lt;p&gt;If someone manages to disable FRED when poking at CR4, then
idt_invalidate() would make sure the system would crash&amp;#39;n&amp;#39;burn on the
first exception triggered, which is a much better outcome security-wise.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-31561</guid>
    </item>
    <item>
      <title>GHSA-pgvp-p3vq-7q7h</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-pgvp-p3vq-7q7h</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;x86/cpu: Remove X86_CR4_FRED from the CR4 pinned bits mask&lt;/p&gt;
&lt;p&gt;Commit in Fixes added the FRED CR4 bit to the CR4 pinned bits mask so
that whenever something else modifies CR4, that bit remains set. Which
in itself is a perfectly fine idea.&lt;/p&gt;
&lt;p&gt;However, there&amp;#39;s an issue when during boot FRED is initialized: first on
the BSP and later on the APs. Thus, there&amp;#39;s a window in time when
exceptions cannot be handled.&lt;/p&gt;
&lt;p&gt;This becomes particularly nasty when running as SEV-{ES,SNP} or TDX
guests which, when they manage to trigger exceptions during that short
window described above, triple fault due to FRED MSRs not being set up
yet.&lt;/p&gt;
&lt;p&gt;See Link tag below for a much more detailed explanation of the
situation.&lt;/p&gt;
&lt;p&gt;So, as a result, the commit in that Link URL tried to address this
shortcoming by temporarily disabling CR4 pinning when an AP is not
online yet.&lt;/p&gt;
&lt;p&gt;However, that is a problem in itself because in this case, an attack on
the kernel needs to only modify the online bit - a single bit in RW
memory - and then disable CR4 pinning and then disable SM*P, leading to
more and worse things to happen to the system.&lt;/p&gt;
&lt;p&gt;So, instead, remove the FRED bit from the CR4 pinning mask, thus
obviating the need to temporarily disable CR4 pinning.&lt;/p&gt;
&lt;p&gt;If someone manages to disable FRED when poking at CR4, then
idt_invalidate() would make sure the system would crash&amp;#39;n&amp;#39;burn on the
first exception triggered, which is a much better outcome security-wise.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;x86/cpu: Remove X86_CR4_FRED from the CR4 pinned bits mask&lt;/p&gt;
&lt;p&gt;Commit in Fixes added the FRED CR4 bit to the CR4 pinned bits mask so
that whenever something else modifies CR4, that bit remains set. Which
in itself is a perfectly fine idea.&lt;/p&gt;
&lt;p&gt;However, there&amp;#39;s an issue when during boot FRED is initialized: first on
the BSP and later on the APs. Thus, there&amp;#39;s a window in time when
exceptions cannot be handled.&lt;/p&gt;
&lt;p&gt;This becomes particularly nasty when running as SEV-{ES,SNP} or TDX
guests which, when they manage to trigger exceptions during that short
window described above, triple fault due to FRED MSRs not being set up
yet.&lt;/p&gt;
&lt;p&gt;See Link tag below for a much more detailed explanation of the
situation.&lt;/p&gt;
&lt;p&gt;So, as a result, the commit in that Link URL tried to address this
shortcoming by temporarily disabling CR4 pinning when an AP is not
online yet.&lt;/p&gt;
&lt;p&gt;However, that is a problem in itself because in this case, an attack on
the kernel needs to only modify the online bit - a single bit in RW
memory - and then disable CR4 pinning and then disable SM*P, leading to
more and worse things to happen to the system.&lt;/p&gt;
&lt;p&gt;So, instead, remove the FRED bit from the CR4 pinning mask, thus
obviating the need to temporarily disable CR4 pinning.&lt;/p&gt;
&lt;p&gt;If someone manages to disable FRED when poking at CR4, then
idt_invalidate() would make sure the system would crash&amp;#39;n&amp;#39;burn on the
first exception triggered, which is a much better outcome security-wise.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-pgvp-p3vq-7q7h</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:21555-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:21555-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:21555-1</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:23066-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:23066-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:23066-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-31561</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-31561</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 106 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: x86/cpu: Remove X86_CR4_FRED from the CR4 pinned bits mask Commit in Fixes added the FRED CR4 bit to the CR4 pinned bits mask so that whenever something else modifies CR4, that bit remains set. Which in itself is a perfectly fine idea. However, there&amp;#39;s an issue when during boot FRED is initialized: first on the BSP and later on the APs. Thus, there&amp;#39;s a window in time when exceptions cannot be handled. This becomes particularly nasty when running as SEV-{ES,SNP} or TDX guests which, when they manage to trigger exceptions during that short window described above, triple fault due to FRED MSRs not being set up yet. See Link tag below for a much more detailed explanation of the situation. So, as a result, the commit in that Link URL tried to address this shortcoming by temporarily disabling CR4 pinning when an AP is not online yet. However, that is a problem in itself because in this case, an attack on the kernel needs to only modify the online bit - a single bit in RW memory - and then disable CR4 pinning and then disable SM*P, leading to more and worse things to happen to the system. So, instead, remove the FRED bit from the CR4 pinning mask, thus obviating the need to temporarily disable CR4 pinning. If someone manages to disable FRED when poking at CR4, then idt_invalidate() would make sure the system would crash&amp;#39;n&amp;#39;burn on the first exception triggered, which is a much better outcome security-wise.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 106 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: x86/cpu: Remove X86_CR4_FRED from the CR4 pinned bits mask Commit in Fixes added the FRED CR4 bit to the CR4 pinned bits mask so that whenever something else modifies CR4, that bit remains set. Which in itself is a perfectly fine idea. However, there&amp;#39;s an issue when during boot FRED is initialized: first on the BSP and later on the APs. Thus, there&amp;#39;s a window in time when exceptions cannot be handled. This becomes particularly nasty when running as SEV-{ES,SNP} or TDX guests which, when they manage to trigger exceptions during that short window described above, triple fault due to FRED MSRs not being set up yet. See Link tag below for a much more detailed explanation of the situation. So, as a result, the commit in that Link URL tried to address this shortcoming by temporarily disabling CR4 pinning when an AP is not online yet. However, that is a problem in itself because in this case, an attack on the kernel needs to only modify the online bit - a single bit in RW memory - and then disable CR4 pinning and then disable SM*P, leading to more and worse things to happen to the system. So, instead, remove the FRED bit from the CR4 pinning mask, thus obviating the need to temporarily disable CR4 pinning. If someone manages to disable FRED when poking at CR4, then idt_invalidate() would make sure the system would crash&amp;#39;n&amp;#39;burn on the first exception triggered, which is a much better outcome security-wise.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-31561</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1279 — Linux Kernel: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1279</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um nicht näher spezifizierte Angriffe durchzuführen, welche zu einem Denial-of-Service-Zustand, einer Rechteausweitung, der Ausführung von Code oder einer Speicherbeschädigung führen könnten.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um nicht näher spezifizierte Angriffe durchzuführen, welche zu einem Denial-of-Service-Zustand, einer Rechteausweitung, der Ausführung von Code oder einer Speicherbeschädigung führen könnten.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1279</guid>
    </item>
  </channel>
</rss>
