<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 14:21:59 +0000</lastBuildDate>
    <item>
      <title>ALSA-2026:21556 — Important: kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:21556</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: kernel, AlmaLinux:9: kernel-64k, AlmaLinux:9: kernel-64k-core, AlmaLinux:9: kernel-64k-debug, AlmaLinux:9: kernel-64k-debug-core, AlmaLinux:9: kernel-64k-debug-devel, AlmaLinux:9: kernel-64k-debug-devel-matched, AlmaLinux:9: kernel-64k-debug-modules, AlmaLinux:9: kernel-64k-debug-modules-core, AlmaLinux:9: kernel-64k-debug-modules-extra and 64 more&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: proc: use the same treatment to check proc_lseek as ones for proc_read_iter et.al (CVE-2025-38653)
  * kernel: ima: don&amp;#39;t clear IMA_DIGSIG flag when setting or removing non-IMA xattr (CVE-2025-68183)
  * kernel: nbd: defer config unlock in nbd_genl_connect (CVE-2025-68366)
  * kernel: crypto: asymmetric_keys - prevent overflow in asymmetric_key_generate_id (CVE-2025-68724)
  * kernel: iommu: disable SVA when CONFIG_X86 is set (CVE-2025-71089)
  * kernel: netfilter: nf_tables: release flowtable after rcu grace period on error (CVE-2026-23392)
  * kernel: netfilter: nf_conntrack_h323: check for zero length in DecodeQ931() (CVE-2026-23455)
  * kernel: Bluetooth: SCO: Fix use-after-free in sco_recv_frame() due to missing sock_hold (CVE-2026-31408)
  * kernel: net: sched: act_csum: validate nested VLAN headers (CVE-2026-31684)
  * kernel: netfilter: ip6t_eui64: reject invalid MAC header for all packets (CVE-2026-31685)
  * kernel: netfilter: nf_conntrack_helper: pass helper to expect cleanup (CVE-2026-43027)
  * kernel: Bluetooth: MGMT: validate LTK enc_size on load (CVE-2026-43020)
  * kernel: HID: wacom: fix out-of-bounds read in wacom_intuos_bt_irq (CVE-2026-43051)
  * kernel: smb: client: validate the whole DACL before rewriting it in cifsacl (CVE-2026-31709)
  * kernel: Bluetooth: SCO: fix race conditions in sco_sock_connect() (CVE-2026-43023)
  * kernel:…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: kernel, AlmaLinux:9: kernel-64k, AlmaLinux:9: kernel-64k-core, AlmaLinux:9: kernel-64k-debug, AlmaLinux:9: kernel-64k-debug-core, AlmaLinux:9: kernel-64k-debug-devel, AlmaLinux:9: kernel-64k-debug-devel-matched, AlmaLinux:9: kernel-64k-debug-modules, AlmaLinux:9: kernel-64k-debug-modules-core, AlmaLinux:9: kernel-64k-debug-modules-extra and 64 more&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: proc: use the same treatment to check proc_lseek as ones for proc_read_iter et.al (CVE-2025-38653)
  * kernel: ima: don&amp;#39;t clear IMA_DIGSIG flag when setting or removing non-IMA xattr (CVE-2025-68183)
  * kernel: nbd: defer config unlock in nbd_genl_connect (CVE-2025-68366)
  * kernel: crypto: asymmetric_keys - prevent overflow in asymmetric_key_generate_id (CVE-2025-68724)
  * kernel: iommu: disable SVA when CONFIG_X86 is set (CVE-2025-71089)
  * kernel: netfilter: nf_tables: release flowtable after rcu grace period on error (CVE-2026-23392)
  * kernel: netfilter: nf_conntrack_h323: check for zero length in DecodeQ931() (CVE-2026-23455)
  * kernel: Bluetooth: SCO: Fix use-after-free in sco_recv_frame() due to missing sock_hold (CVE-2026-31408)
  * kernel: net: sched: act_csum: validate nested VLAN headers (CVE-2026-31684)
  * kernel: netfilter: ip6t_eui64: reject invalid MAC header for all packets (CVE-2026-31685)
  * kernel: netfilter: nf_conntrack_helper: pass helper to expect cleanup (CVE-2026-43027)
  * kernel: Bluetooth: MGMT: validate LTK enc_size on load (CVE-2026-43020)
  * kernel: HID: wacom: fix out-of-bounds read in wacom_intuos_bt_irq (CVE-2026-43051)
  * kernel: smb: client: validate the whole DACL before rewriting it in cifsacl (CVE-2026-31709)
  * kernel: Bluetooth: SCO: fix race conditions in sco_sock_connect() (CVE-2026-43023)
  * kernel:…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:21556</guid>
    </item>
    <item>
      <title>bdu:2026-08760</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-08760</link>
      <description>bdu:2026-08760</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-08760</guid>
    </item>
    <item>
      <title>BELL-CVE-2026-31685</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-31685</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-31685</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0526 — De multiples vulnérabilités ont été découvertes dans les produits Microsoft. Elles permettent à un attaquant de provoqu…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0526</link>
      <description>certfr-2026-avi-0526</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0526</guid>
    </item>
    <item>
      <title>EUVD-2026-347763</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-347763</link>
      <description>EUVD-2026-347763</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-347763</guid>
    </item>
    <item>
      <title>fkie_cve-2026-31685</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-31685</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;netfilter: ip6t_eui64: reject invalid MAC header for all packets&lt;/p&gt;
&lt;p&gt;`eui64_mt6()` derives a modified EUI-64 from the Ethernet source address
and compares it with the low 64 bits of the IPv6 source address.&lt;/p&gt;
&lt;p&gt;The existing guard only rejects an invalid MAC header when
`par-&amp;gt;fragoff != 0`. For packets with `par-&amp;gt;fragoff == 0`, `eui64_mt6()`
can still reach `eth_hdr(skb)` even when the MAC header is not valid.&lt;/p&gt;
&lt;p&gt;Fix this by removing the `par-&amp;gt;fragoff != 0` condition so that packets
with an invalid MAC header are rejected before accessing `eth_hdr(skb)`.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;netfilter: ip6t_eui64: reject invalid MAC header for all packets&lt;/p&gt;
&lt;p&gt;`eui64_mt6()` derives a modified EUI-64 from the Ethernet source address
and compares it with the low 64 bits of the IPv6 source address.&lt;/p&gt;
&lt;p&gt;The existing guard only rejects an invalid MAC header when
`par-&amp;gt;fragoff != 0`. For packets with `par-&amp;gt;fragoff == 0`, `eui64_mt6()`
can still reach `eth_hdr(skb)` even when the MAC header is not valid.&lt;/p&gt;
&lt;p&gt;Fix this by removing the `par-&amp;gt;fragoff != 0` condition so that packets
with an invalid MAC header are rejected before accessing `eth_hdr(skb)`.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-31685</guid>
    </item>
    <item>
      <title>GHSA-hf2p-g3jq-w2mx</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-hf2p-g3jq-w2mx</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;netfilter: ip6t_eui64: reject invalid MAC header for all packets&lt;/p&gt;
&lt;p&gt;`eui64_mt6()` derives a modified EUI-64 from the Ethernet source address
and compares it with the low 64 bits of the IPv6 source address.&lt;/p&gt;
&lt;p&gt;The existing guard only rejects an invalid MAC header when
`par-&amp;gt;fragoff != 0`. For packets with `par-&amp;gt;fragoff == 0`, `eui64_mt6()`
can still reach `eth_hdr(skb)` even when the MAC header is not valid.&lt;/p&gt;
&lt;p&gt;Fix this by removing the `par-&amp;gt;fragoff != 0` condition so that packets
with an invalid MAC header are rejected before accessing `eth_hdr(skb)`.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;netfilter: ip6t_eui64: reject invalid MAC header for all packets&lt;/p&gt;
&lt;p&gt;`eui64_mt6()` derives a modified EUI-64 from the Ethernet source address
and compares it with the low 64 bits of the IPv6 source address.&lt;/p&gt;
&lt;p&gt;The existing guard only rejects an invalid MAC header when
`par-&amp;gt;fragoff != 0`. For packets with `par-&amp;gt;fragoff == 0`, `eui64_mt6()`
can still reach `eth_hdr(skb)` even when the MAC header is not valid.&lt;/p&gt;
&lt;p&gt;Fix this by removing the `par-&amp;gt;fragoff != 0` condition so that packets
with an invalid MAC header are rejected before accessing `eth_hdr(skb)`.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-hf2p-g3jq-w2mx</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-31685 — netfilter: ip6t_eui64: reject invalid MAC header for all packets</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-31685</link>
      <description>msrc_CVE-2026-31685</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-31685</guid>
    </item>
    <item>
      <title>OESA-2026-2581 — kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-2581</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP1: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;net: mvpp2: Prevent parser TCAM memory corruption&lt;/p&gt;
&lt;p&gt;Protect the parser TCAM/SRAM memory, and the cached (shadow) SRAM
information, from concurrent modifications.&lt;/p&gt;
&lt;p&gt;Both the TCAM and SRAM tables are indirectly accessed by configuring
an index register that selects the row to read or write to. This means
that operations must be atomic in order to, e.g., avoid spreading
writes across multiple rows. Since the shadow SRAM array is used to
find free rows in the hardware table, it must also be protected in
order to avoid TOCTOU errors where multiple cores allocate the same
row.&lt;/p&gt;
&lt;p&gt;This issue was detected in a situation where `mvpp2_set_rx_mode()` ran
concurrently on two CPUs. In this particular case the
MVPP2_PE_MAC_UC_PROMISCUOUS entry was corrupted, causing the
classifier unit to drop all incoming unicast - indicated by the
`rx_classifier_drops` counter.(CVE-2025-22060)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;mptcp: fix NULL pointer in can_accept_new_subflow&lt;/p&gt;
&lt;p&gt;When testing valkey benchmark tool with MPTCP, the kernel panics in
&amp;amp;apos;mptcp_can_accept_new_subflow&amp;amp;apos; because subflow_req-&amp;amp;gt;msk is NULL.&lt;/p&gt;
&lt;p&gt;Call trace:&lt;/p&gt;
&lt;p&gt;mptcp_can_accept_new_subflow (./net/mptcp/subflow.c:63 (discriminator 4)) (P)
  subflow_syn_recv_sock (./net/mptcp/subflow.c:854)
  tcp_check_req (./net/ipv4/tcp_minisocks.c:863)
  tcp_v4_rcv (./net/…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP1: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;net: mvpp2: Prevent parser TCAM memory corruption&lt;/p&gt;
&lt;p&gt;Protect the parser TCAM/SRAM memory, and the cached (shadow) SRAM
information, from concurrent modifications.&lt;/p&gt;
&lt;p&gt;Both the TCAM and SRAM tables are indirectly accessed by configuring
an index register that selects the row to read or write to. This means
that operations must be atomic in order to, e.g., avoid spreading
writes across multiple rows. Since the shadow SRAM array is used to
find free rows in the hardware table, it must also be protected in
order to avoid TOCTOU errors where multiple cores allocate the same
row.&lt;/p&gt;
&lt;p&gt;This issue was detected in a situation where `mvpp2_set_rx_mode()` ran
concurrently on two CPUs. In this particular case the
MVPP2_PE_MAC_UC_PROMISCUOUS entry was corrupted, causing the
classifier unit to drop all incoming unicast - indicated by the
`rx_classifier_drops` counter.(CVE-2025-22060)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;mptcp: fix NULL pointer in can_accept_new_subflow&lt;/p&gt;
&lt;p&gt;When testing valkey benchmark tool with MPTCP, the kernel panics in
&amp;amp;apos;mptcp_can_accept_new_subflow&amp;amp;apos; because subflow_req-&amp;amp;gt;msk is NULL.&lt;/p&gt;
&lt;p&gt;Call trace:&lt;/p&gt;
&lt;p&gt;mptcp_can_accept_new_subflow (./net/mptcp/subflow.c:63 (discriminator 4)) (P)
  subflow_syn_recv_sock (./net/mptcp/subflow.c:854)
  tcp_check_req (./net/ipv4/tcp_minisocks.c:863)
  tcp_v4_rcv (./net/…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-2581</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:20826-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:20826-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:20826-1</guid>
    </item>
    <item>
      <title>RHSA-2026:21745 — Red Hat Security Advisory: kernel-rt security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:21745</link>
      <description>&lt;p&gt;kernel: Bluetooth: MGMT: Fix possible UAFs kernel: ima: don&amp;#39;t clear IMA_DIGSIG flag when setting or removing non-IMA xattr kernel: ALSA: firewire-motu: fix buffer overflow in hwdep read for DSP events kernel: libceph: make decode_pool() more resilient against corrupted osdmaps kernel: Linux kernel: Denial of service and memory corruption in RDMA umad kernel: Linux kernel: Use-after-free in traffic control (act_ct) may lead to denial of service or privilege escalation kernel: netfilter: nf_conntrack_h323: check for zero length in DecodeQ931() kernel: Bluetooth: SCO: Fix use-after-free in sco_recv_frame() due to missing sock_hold kernel: can: raw: fix ro-&amp;gt;uniq use-after-free in raw_rcv() kernel: net: sched: act_csum: validate nested VLAN headers kernel: netfilter: ip6t_eui64: reject invalid MAC header for all packets kernel: smb: client: validate the whole DACL before rewriting it in cifsacl kernel: Bluetooth: MGMT: validate LTK enc_size on load kernel: netfilter: nf_conntrack_helper: pass helper to expect cleanup kernel: HID: wacom: fix out-of-bounds read in wacom_intuos_bt_irq kernel: xfs: fix freemap adjustments when adding xattrs to leaf blocks kernel: md/bitmap: fix GPF in write_page caused by resize race kernel: netfilter: xt_tcpmss: check remaining length before reading optlen kernel: smb: client: validate dacloffset before building DACL pointers&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;kernel: Bluetooth: MGMT: Fix possible UAFs kernel: ima: don&amp;#39;t clear IMA_DIGSIG flag when setting or removing non-IMA xattr kernel: ALSA: firewire-motu: fix buffer overflow in hwdep read for DSP events kernel: libceph: make decode_pool() more resilient against corrupted osdmaps kernel: Linux kernel: Denial of service and memory corruption in RDMA umad kernel: Linux kernel: Use-after-free in traffic control (act_ct) may lead to denial of service or privilege escalation kernel: netfilter: nf_conntrack_h323: check for zero length in DecodeQ931() kernel: Bluetooth: SCO: Fix use-after-free in sco_recv_frame() due to missing sock_hold kernel: can: raw: fix ro-&amp;gt;uniq use-after-free in raw_rcv() kernel: net: sched: act_csum: validate nested VLAN headers kernel: netfilter: ip6t_eui64: reject invalid MAC header for all packets kernel: smb: client: validate the whole DACL before rewriting it in cifsacl kernel: Bluetooth: MGMT: validate LTK enc_size on load kernel: netfilter: nf_conntrack_helper: pass helper to expect cleanup kernel: HID: wacom: fix out-of-bounds read in wacom_intuos_bt_irq kernel: xfs: fix freemap adjustments when adding xattrs to leaf blocks kernel: md/bitmap: fix GPF in write_page caused by resize race kernel: netfilter: xt_tcpmss: check remaining length before reading optlen kernel: smb: client: validate dacloffset before building DACL pointers&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:21745</guid>
    </item>
    <item>
      <title>RLSA-2026:21556 — Important: kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:21556</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:9: kernel&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: proc: use the same treatment to check proc_lseek as ones for proc_read_iter et.al (CVE-2025-38653)&lt;/p&gt;
&lt;p&gt;* kernel: ima: don&amp;#39;t clear IMA_DIGSIG flag when setting or removing non-IMA xattr (CVE-2025-68183)&lt;/p&gt;
&lt;p&gt;* kernel: nbd: defer config unlock in nbd_genl_connect (CVE-2025-68366)&lt;/p&gt;
&lt;p&gt;* kernel: crypto: asymmetric_keys - prevent overflow in asymmetric_key_generate_id (CVE-2025-68724)&lt;/p&gt;
&lt;p&gt;* kernel: iommu: disable SVA when CONFIG_X86 is set (CVE-2025-71089)&lt;/p&gt;
&lt;p&gt;* kernel: netfilter: nf_tables: release flowtable after rcu grace period on error (CVE-2026-23392)&lt;/p&gt;
&lt;p&gt;* kernel: netfilter: nf_conntrack_h323: check for zero length in DecodeQ931() (CVE-2026-23455)&lt;/p&gt;
&lt;p&gt;* kernel: Bluetooth: SCO: Fix use-after-free in sco_recv_frame() due to missing sock_hold (CVE-2026-31408)&lt;/p&gt;
&lt;p&gt;* kernel: net: sched: act_csum: validate nested VLAN headers (CVE-2026-31684)&lt;/p&gt;
&lt;p&gt;* kernel: netfilter: ip6t_eui64: reject invalid MAC header for all packets (CVE-2026-31685)&lt;/p&gt;
&lt;p&gt;* kernel: netfilter: nf_conntrack_helper: pass helper to expect cleanup (CVE-2026-43027)&lt;/p&gt;
&lt;p&gt;* kernel: Bluetooth: MGMT: validate LTK enc_size on load (CVE-2026-43020)&lt;/p&gt;
&lt;p&gt;* kernel: HID: wacom: fix out-of-bounds read in wacom_intuos_bt_irq (CVE-2026-43051)&lt;/p&gt;
&lt;p&gt;* kernel: smb: client: validate the whole DACL before rewriting it in cifsacl (CVE-2026-31709)&lt;/p&gt;
&lt;p&gt;* kernel: Bluetooth: SCO: fix race conditions in sco_sock_connect() (CVE-2026-43023)&lt;/p&gt;
&lt;p&gt;* kernel: wifi: brcmfmac: vali…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:9: kernel&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: proc: use the same treatment to check proc_lseek as ones for proc_read_iter et.al (CVE-2025-38653)&lt;/p&gt;
&lt;p&gt;* kernel: ima: don&amp;#39;t clear IMA_DIGSIG flag when setting or removing non-IMA xattr (CVE-2025-68183)&lt;/p&gt;
&lt;p&gt;* kernel: nbd: defer config unlock in nbd_genl_connect (CVE-2025-68366)&lt;/p&gt;
&lt;p&gt;* kernel: crypto: asymmetric_keys - prevent overflow in asymmetric_key_generate_id (CVE-2025-68724)&lt;/p&gt;
&lt;p&gt;* kernel: iommu: disable SVA when CONFIG_X86 is set (CVE-2025-71089)&lt;/p&gt;
&lt;p&gt;* kernel: netfilter: nf_tables: release flowtable after rcu grace period on error (CVE-2026-23392)&lt;/p&gt;
&lt;p&gt;* kernel: netfilter: nf_conntrack_h323: check for zero length in DecodeQ931() (CVE-2026-23455)&lt;/p&gt;
&lt;p&gt;* kernel: Bluetooth: SCO: Fix use-after-free in sco_recv_frame() due to missing sock_hold (CVE-2026-31408)&lt;/p&gt;
&lt;p&gt;* kernel: net: sched: act_csum: validate nested VLAN headers (CVE-2026-31684)&lt;/p&gt;
&lt;p&gt;* kernel: netfilter: ip6t_eui64: reject invalid MAC header for all packets (CVE-2026-31685)&lt;/p&gt;
&lt;p&gt;* kernel: netfilter: nf_conntrack_helper: pass helper to expect cleanup (CVE-2026-43027)&lt;/p&gt;
&lt;p&gt;* kernel: Bluetooth: MGMT: validate LTK enc_size on load (CVE-2026-43020)&lt;/p&gt;
&lt;p&gt;* kernel: HID: wacom: fix out-of-bounds read in wacom_intuos_bt_irq (CVE-2026-43051)&lt;/p&gt;
&lt;p&gt;* kernel: smb: client: validate the whole DACL before rewriting it in cifsacl (CVE-2026-31709)&lt;/p&gt;
&lt;p&gt;* kernel: Bluetooth: SCO: fix race conditions in sco_sock_connect() (CVE-2026-43023)&lt;/p&gt;
&lt;p&gt;* kernel: wifi: brcmfmac: vali…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:21556</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:2068-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:2068-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:2068-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-31685</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-31685</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux, Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe and 233 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: netfilter: ip6t_eui64: reject invalid MAC header for all packets `eui64_mt6()` derives a modified EUI-64 from the Ethernet source address and compares it with the low 64 bits of the IPv6 source address. The existing guard only rejects an invalid MAC header when `par-&amp;gt;fragoff != 0`. For packets with `par-&amp;gt;fragoff == 0`, `eui64_mt6()` can still reach `eth_hdr(skb)` even when the MAC header is not valid. Fix this by removing the `par-&amp;gt;fragoff != 0` condition so that packets with an invalid MAC header are rejected before accessing `eth_hdr(skb)`.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux, Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe and 233 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: netfilter: ip6t_eui64: reject invalid MAC header for all packets `eui64_mt6()` derives a modified EUI-64 from the Ethernet source address and compares it with the low 64 bits of the IPv6 source address. The existing guard only rejects an invalid MAC header when `par-&amp;gt;fragoff != 0`. For packets with `par-&amp;gt;fragoff == 0`, `eui64_mt6()` can still reach `eth_hdr(skb)` even when the MAC header is not valid. Fix this by removing the `par-&amp;gt;fragoff != 0` condition so that packets with an invalid MAC header are rejected before accessing `eth_hdr(skb)`.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-31685</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1279 — Linux Kernel: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1279</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um nicht näher spezifizierte Angriffe durchzuführen, welche zu einem Denial-of-Service-Zustand, einer Rechteausweitung, der Ausführung von Code oder einer Speicherbeschädigung führen könnten.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um nicht näher spezifizierte Angriffe durchzuführen, welche zu einem Denial-of-Service-Zustand, einer Rechteausweitung, der Ausführung von Code oder einer Speicherbeschädigung führen könnten.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1279</guid>
    </item>
  </channel>
</rss>
