<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 07:44:02 +0000</lastBuildDate>
    <item>
      <title>ALSA-2026:21557 — Important: kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:21557</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: kernel, AlmaLinux:10: kernel-64k, AlmaLinux:10: kernel-64k-core, AlmaLinux:10: kernel-64k-debug, AlmaLinux:10: kernel-64k-debug-core, AlmaLinux:10: kernel-64k-debug-devel, AlmaLinux:10: kernel-64k-debug-devel-matched, AlmaLinux:10: kernel-64k-debug-modules, AlmaLinux:10: kernel-64k-debug-modules-core, AlmaLinux:10: kernel-64k-debug-modules-extra and 65 more&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: can: j1939: j1939_session_new(): fix skb reference counting (CVE-2024-56645)
  * kernel: ima: don&amp;#39;t clear IMA_DIGSIG flag when setting or removing non-IMA xattr (CVE-2025-68183)
  * kernel: mm: thp: deny THP for files on anonymous inodes (CVE-2026-23375)
  * kernel: netfilter: nf_tables: release flowtable after rcu grace period on error (CVE-2026-23392)
  * kernel: netfilter: nf_conntrack_h323: check for zero length in DecodeQ931() (CVE-2026-23455)
  * kernel: net: sched: act_csum: validate nested VLAN headers (CVE-2026-31684)
  * kernel: netfilter: ip6t_eui64: reject invalid MAC header for all packets (CVE-2026-31685)
  * kernel: netfilter: nf_conntrack_helper: pass helper to expect cleanup (CVE-2026-43027)
  * kernel: io_uring/rsrc: reject zero-length fixed buffer import (CVE-2026-43006)
  * kernel: Bluetooth: MGMT: validate LTK enc_size on load (CVE-2026-43020)
  * kernel: HID: wacom: fix out-of-bounds read in wacom_intuos_bt_irq (CVE-2026-43051)
  * kernel: Bluetooth: SCO: fix race conditions in sco_sock_connect() (CVE-2026-43023)
  * kernel: netfilter: ctnetlink: ensure safe access to master conntrack (CVE-2026-43116)
  * kernel: wifi: brcmfmac: validate bsscfg indices in IF events (CVE-2026-43110)
  * kernel: netfilter: xt_tcpmss: check remaining length before reading optlen (CVE-2026-43190)
  * kernel: Linux kernel dpaa2-switch: Kernel memory corru…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: kernel, AlmaLinux:10: kernel-64k, AlmaLinux:10: kernel-64k-core, AlmaLinux:10: kernel-64k-debug, AlmaLinux:10: kernel-64k-debug-core, AlmaLinux:10: kernel-64k-debug-devel, AlmaLinux:10: kernel-64k-debug-devel-matched, AlmaLinux:10: kernel-64k-debug-modules, AlmaLinux:10: kernel-64k-debug-modules-core, AlmaLinux:10: kernel-64k-debug-modules-extra and 65 more&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: can: j1939: j1939_session_new(): fix skb reference counting (CVE-2024-56645)
  * kernel: ima: don&amp;#39;t clear IMA_DIGSIG flag when setting or removing non-IMA xattr (CVE-2025-68183)
  * kernel: mm: thp: deny THP for files on anonymous inodes (CVE-2026-23375)
  * kernel: netfilter: nf_tables: release flowtable after rcu grace period on error (CVE-2026-23392)
  * kernel: netfilter: nf_conntrack_h323: check for zero length in DecodeQ931() (CVE-2026-23455)
  * kernel: net: sched: act_csum: validate nested VLAN headers (CVE-2026-31684)
  * kernel: netfilter: ip6t_eui64: reject invalid MAC header for all packets (CVE-2026-31685)
  * kernel: netfilter: nf_conntrack_helper: pass helper to expect cleanup (CVE-2026-43027)
  * kernel: io_uring/rsrc: reject zero-length fixed buffer import (CVE-2026-43006)
  * kernel: Bluetooth: MGMT: validate LTK enc_size on load (CVE-2026-43020)
  * kernel: HID: wacom: fix out-of-bounds read in wacom_intuos_bt_irq (CVE-2026-43051)
  * kernel: Bluetooth: SCO: fix race conditions in sco_sock_connect() (CVE-2026-43023)
  * kernel: netfilter: ctnetlink: ensure safe access to master conntrack (CVE-2026-43116)
  * kernel: wifi: brcmfmac: validate bsscfg indices in IF events (CVE-2026-43110)
  * kernel: netfilter: xt_tcpmss: check remaining length before reading optlen (CVE-2026-43190)
  * kernel: Linux kernel dpaa2-switch: Kernel memory corru…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:21557</guid>
    </item>
    <item>
      <title>BELL-CVE-2026-43006</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-43006</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-43006</guid>
    </item>
    <item>
      <title>cnvd-2026-20417</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2026-20417</link>
      <description>cnvd-2026-20417</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2026-20417</guid>
    </item>
    <item>
      <title>EUVD-2026-347799</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-347799</link>
      <description>EUVD-2026-347799</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-347799</guid>
    </item>
    <item>
      <title>fkie_cve-2026-43006</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-43006</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;io_uring/rsrc: reject zero-length fixed buffer import&lt;/p&gt;
&lt;p&gt;validate_fixed_range() admits buf_addr at the exact end of the
registered region when len is zero, because the check uses strict
greater-than (buf_end &amp;gt; imu-&amp;gt;ubuf + imu-&amp;gt;len).  io_import_fixed()
then computes offset == imu-&amp;gt;len, which causes the bvec skip logic
to advance past the last bio_vec entry and read bv_offset from
out-of-bounds slab memory.&lt;/p&gt;
&lt;p&gt;Return early from io_import_fixed() when len is zero.  A zero-length
import has no data to transfer and should not walk the bvec array
at all.&lt;/p&gt;
&lt;p&gt;BUG: KASAN: slab-out-of-bounds in io_import_reg_buf+0x697/0x7f0
  Read of size 4 at addr ffff888002bcc254 by task poc/103
  Call Trace:
   io_import_reg_buf+0x697/0x7f0
   io_write_fixed+0xd9/0x250
   __io_issue_sqe+0xad/0x710
   io_issue_sqe+0x7d/0x1100
   io_submit_sqes+0x86a/0x23c0
   __do_sys_io_uring_enter+0xa98/0x1590
  Allocated by task 103:
  The buggy address is located 12 bytes to the right of
   allocated 584-byte region [ffff888002bcc000, ffff888002bcc248)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;io_uring/rsrc: reject zero-length fixed buffer import&lt;/p&gt;
&lt;p&gt;validate_fixed_range() admits buf_addr at the exact end of the
registered region when len is zero, because the check uses strict
greater-than (buf_end &amp;gt; imu-&amp;gt;ubuf + imu-&amp;gt;len).  io_import_fixed()
then computes offset == imu-&amp;gt;len, which causes the bvec skip logic
to advance past the last bio_vec entry and read bv_offset from
out-of-bounds slab memory.&lt;/p&gt;
&lt;p&gt;Return early from io_import_fixed() when len is zero.  A zero-length
import has no data to transfer and should not walk the bvec array
at all.&lt;/p&gt;
&lt;p&gt;BUG: KASAN: slab-out-of-bounds in io_import_reg_buf+0x697/0x7f0
  Read of size 4 at addr ffff888002bcc254 by task poc/103
  Call Trace:
   io_import_reg_buf+0x697/0x7f0
   io_write_fixed+0xd9/0x250
   __io_issue_sqe+0xad/0x710
   io_issue_sqe+0x7d/0x1100
   io_submit_sqes+0x86a/0x23c0
   __do_sys_io_uring_enter+0xa98/0x1590
  Allocated by task 103:
  The buggy address is located 12 bytes to the right of
   allocated 584-byte region [ffff888002bcc000, ffff888002bcc248)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-43006</guid>
    </item>
    <item>
      <title>GHSA-5mwr-6pqp-c5qm</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-5mwr-6pqp-c5qm</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;io_uring/rsrc: reject zero-length fixed buffer import&lt;/p&gt;
&lt;p&gt;validate_fixed_range() admits buf_addr at the exact end of the
registered region when len is zero, because the check uses strict
greater-than (buf_end &amp;gt; imu-&amp;gt;ubuf + imu-&amp;gt;len).  io_import_fixed()
then computes offset == imu-&amp;gt;len, which causes the bvec skip logic
to advance past the last bio_vec entry and read bv_offset from
out-of-bounds slab memory.&lt;/p&gt;
&lt;p&gt;Return early from io_import_fixed() when len is zero.  A zero-length
import has no data to transfer and should not walk the bvec array
at all.&lt;/p&gt;
&lt;p&gt;BUG: KASAN: slab-out-of-bounds in io_import_reg_buf+0x697/0x7f0
  Read of size 4 at addr ffff888002bcc254 by task poc/103
  Call Trace:
   io_import_reg_buf+0x697/0x7f0
   io_write_fixed+0xd9/0x250
   __io_issue_sqe+0xad/0x710
   io_issue_sqe+0x7d/0x1100
   io_submit_sqes+0x86a/0x23c0
   __do_sys_io_uring_enter+0xa98/0x1590
  Allocated by task 103:
  The buggy address is located 12 bytes to the right of
   allocated 584-byte region [ffff888002bcc000, ffff888002bcc248)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;io_uring/rsrc: reject zero-length fixed buffer import&lt;/p&gt;
&lt;p&gt;validate_fixed_range() admits buf_addr at the exact end of the
registered region when len is zero, because the check uses strict
greater-than (buf_end &amp;gt; imu-&amp;gt;ubuf + imu-&amp;gt;len).  io_import_fixed()
then computes offset == imu-&amp;gt;len, which causes the bvec skip logic
to advance past the last bio_vec entry and read bv_offset from
out-of-bounds slab memory.&lt;/p&gt;
&lt;p&gt;Return early from io_import_fixed() when len is zero.  A zero-length
import has no data to transfer and should not walk the bvec array
at all.&lt;/p&gt;
&lt;p&gt;BUG: KASAN: slab-out-of-bounds in io_import_reg_buf+0x697/0x7f0
  Read of size 4 at addr ffff888002bcc254 by task poc/103
  Call Trace:
   io_import_reg_buf+0x697/0x7f0
   io_write_fixed+0xd9/0x250
   __io_issue_sqe+0xad/0x710
   io_issue_sqe+0x7d/0x1100
   io_submit_sqes+0x86a/0x23c0
   __do_sys_io_uring_enter+0xa98/0x1590
  Allocated by task 103:
  The buggy address is located 12 bytes to the right of
   allocated 584-byte region [ffff888002bcc000, ffff888002bcc248)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-5mwr-6pqp-c5qm</guid>
    </item>
    <item>
      <title>RHSA-2026:21557 — Red Hat Security Advisory: kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:21557</link>
      <description>&lt;p&gt;kernel: can: j1939: j1939_session_new(): fix skb reference counting kernel: ima: don&amp;#39;t clear IMA_DIGSIG flag when setting or removing non-IMA xattr kernel: mm: thp: deny THP for files on anonymous inodes kernel: netfilter: nf_tables: release flowtable after rcu grace period on error kernel: netfilter: nf_conntrack_h323: check for zero length in DecodeQ931() kernel: net: sched: act_csum: validate nested VLAN headers kernel: netfilter: ip6t_eui64: reject invalid MAC header for all packets kernel: io_uring/rsrc: reject zero-length fixed buffer import kernel: Bluetooth: MGMT: validate LTK enc_size on load kernel: Bluetooth: SCO: fix race conditions in sco_sock_connect() kernel: netfilter: nf_conntrack_helper: pass helper to expect cleanup kernel: HID: wacom: fix out-of-bounds read in wacom_intuos_bt_irq kernel: wifi: brcmfmac: validate bsscfg indices in IF events kernel: netfilter: ctnetlink: ensure safe access to master conntrack kernel: xfs: fix freemap adjustments when adding xattrs to leaf blocks kernel: netfilter: xt_tcpmss: check remaining length before reading optlen kernel: Linux kernel dpaa2-switch: Kernel memory corruption via out-of-bounds write kernel: mm/page_alloc: clear page-&amp;gt;private in free_pages_prepare()&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;kernel: can: j1939: j1939_session_new(): fix skb reference counting kernel: ima: don&amp;#39;t clear IMA_DIGSIG flag when setting or removing non-IMA xattr kernel: mm: thp: deny THP for files on anonymous inodes kernel: netfilter: nf_tables: release flowtable after rcu grace period on error kernel: netfilter: nf_conntrack_h323: check for zero length in DecodeQ931() kernel: net: sched: act_csum: validate nested VLAN headers kernel: netfilter: ip6t_eui64: reject invalid MAC header for all packets kernel: io_uring/rsrc: reject zero-length fixed buffer import kernel: Bluetooth: MGMT: validate LTK enc_size on load kernel: Bluetooth: SCO: fix race conditions in sco_sock_connect() kernel: netfilter: nf_conntrack_helper: pass helper to expect cleanup kernel: HID: wacom: fix out-of-bounds read in wacom_intuos_bt_irq kernel: wifi: brcmfmac: validate bsscfg indices in IF events kernel: netfilter: ctnetlink: ensure safe access to master conntrack kernel: xfs: fix freemap adjustments when adding xattrs to leaf blocks kernel: netfilter: xt_tcpmss: check remaining length before reading optlen kernel: Linux kernel dpaa2-switch: Kernel memory corruption via out-of-bounds write kernel: mm/page_alloc: clear page-&amp;gt;private in free_pages_prepare()&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:21557</guid>
    </item>
    <item>
      <title>RLSA-2026:21557 — Important: kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:21557</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: kernel&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: can: j1939: j1939_session_new(): fix skb reference counting (CVE-2024-56645)&lt;/p&gt;
&lt;p&gt;* kernel: ima: don&amp;#39;t clear IMA_DIGSIG flag when setting or removing non-IMA xattr (CVE-2025-68183)&lt;/p&gt;
&lt;p&gt;* kernel: mm: thp: deny THP for files on anonymous inodes (CVE-2026-23375)&lt;/p&gt;
&lt;p&gt;* kernel: netfilter: nf_tables: release flowtable after rcu grace period on error (CVE-2026-23392)&lt;/p&gt;
&lt;p&gt;* kernel: netfilter: nf_conntrack_h323: check for zero length in DecodeQ931() (CVE-2026-23455)&lt;/p&gt;
&lt;p&gt;* kernel: net: sched: act_csum: validate nested VLAN headers (CVE-2026-31684)&lt;/p&gt;
&lt;p&gt;* kernel: netfilter: ip6t_eui64: reject invalid MAC header for all packets (CVE-2026-31685)&lt;/p&gt;
&lt;p&gt;* kernel: netfilter: nf_conntrack_helper: pass helper to expect cleanup (CVE-2026-43027)&lt;/p&gt;
&lt;p&gt;* kernel: io_uring/rsrc: reject zero-length fixed buffer import (CVE-2026-43006)&lt;/p&gt;
&lt;p&gt;* kernel: Bluetooth: MGMT: validate LTK enc_size on load (CVE-2026-43020)&lt;/p&gt;
&lt;p&gt;* kernel: HID: wacom: fix out-of-bounds read in wacom_intuos_bt_irq (CVE-2026-43051)&lt;/p&gt;
&lt;p&gt;* kernel: Bluetooth: SCO: fix race conditions in sco_sock_connect() (CVE-2026-43023)&lt;/p&gt;
&lt;p&gt;* kernel: netfilter: ctnetlink: ensure safe access to master conntrack (CVE-2026-43116)&lt;/p&gt;
&lt;p&gt;* kernel: wifi: brcmfmac: validate bsscfg indices in IF events (CVE-2026-43110)&lt;/p&gt;
&lt;p&gt;* kernel: netfilter: xt_tcpmss: check remaining length before reading optlen (CVE-2026-43190)&lt;/p&gt;
&lt;p&gt;* kernel: Linux kernel dpaa2-switch: Kernel memory corruption via out-of-boun…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: kernel&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: can: j1939: j1939_session_new(): fix skb reference counting (CVE-2024-56645)&lt;/p&gt;
&lt;p&gt;* kernel: ima: don&amp;#39;t clear IMA_DIGSIG flag when setting or removing non-IMA xattr (CVE-2025-68183)&lt;/p&gt;
&lt;p&gt;* kernel: mm: thp: deny THP for files on anonymous inodes (CVE-2026-23375)&lt;/p&gt;
&lt;p&gt;* kernel: netfilter: nf_tables: release flowtable after rcu grace period on error (CVE-2026-23392)&lt;/p&gt;
&lt;p&gt;* kernel: netfilter: nf_conntrack_h323: check for zero length in DecodeQ931() (CVE-2026-23455)&lt;/p&gt;
&lt;p&gt;* kernel: net: sched: act_csum: validate nested VLAN headers (CVE-2026-31684)&lt;/p&gt;
&lt;p&gt;* kernel: netfilter: ip6t_eui64: reject invalid MAC header for all packets (CVE-2026-31685)&lt;/p&gt;
&lt;p&gt;* kernel: netfilter: nf_conntrack_helper: pass helper to expect cleanup (CVE-2026-43027)&lt;/p&gt;
&lt;p&gt;* kernel: io_uring/rsrc: reject zero-length fixed buffer import (CVE-2026-43006)&lt;/p&gt;
&lt;p&gt;* kernel: Bluetooth: MGMT: validate LTK enc_size on load (CVE-2026-43020)&lt;/p&gt;
&lt;p&gt;* kernel: HID: wacom: fix out-of-bounds read in wacom_intuos_bt_irq (CVE-2026-43051)&lt;/p&gt;
&lt;p&gt;* kernel: Bluetooth: SCO: fix race conditions in sco_sock_connect() (CVE-2026-43023)&lt;/p&gt;
&lt;p&gt;* kernel: netfilter: ctnetlink: ensure safe access to master conntrack (CVE-2026-43116)&lt;/p&gt;
&lt;p&gt;* kernel: wifi: brcmfmac: validate bsscfg indices in IF events (CVE-2026-43110)&lt;/p&gt;
&lt;p&gt;* kernel: netfilter: xt_tcpmss: check remaining length before reading optlen (CVE-2026-43190)&lt;/p&gt;
&lt;p&gt;* kernel: Linux kernel dpaa2-switch: Kernel memory corruption via out-of-boun…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:21557</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-43006</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-43006</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 104 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: io_uring/rsrc: reject zero-length fixed buffer import validate_fixed_range() admits buf_addr at the exact end of the registered region when len is zero, because the check uses strict greater-than (buf_end &amp;gt; imu-&amp;gt;ubuf + imu-&amp;gt;len).  io_import_fixed() then computes offset == imu-&amp;gt;len, which causes the bvec skip logic to advance past the last bio_vec entry and read bv_offset from out-of-bounds slab memory. Return early from io_import_fixed() when len is zero.  A zero-length import has no data to transfer and should not walk the bvec array at all.   BUG: KASAN: slab-out-of-bounds in io_import_reg_buf+0x697/0x7f0   Read of size 4 at addr ffff888002bcc254 by task poc/103   Call Trace:    io_import_reg_buf+0x697/0x7f0    io_write_fixed+0xd9/0x250    __io_issue_sqe+0xad/0x710    io_issue_sqe+0x7d/0x1100    io_submit_sqes+0x86a/0x23c0    __do_sys_io_uring_enter+0xa98/0x1590   Allocated by task 103:   The buggy address is located 12 bytes to the right of    allocated 584-byte region [ffff888002bcc000, ffff888002bcc248)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 104 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: io_uring/rsrc: reject zero-length fixed buffer import validate_fixed_range() admits buf_addr at the exact end of the registered region when len is zero, because the check uses strict greater-than (buf_end &amp;gt; imu-&amp;gt;ubuf + imu-&amp;gt;len).  io_import_fixed() then computes offset == imu-&amp;gt;len, which causes the bvec skip logic to advance past the last bio_vec entry and read bv_offset from out-of-bounds slab memory. Return early from io_import_fixed() when len is zero.  A zero-length import has no data to transfer and should not walk the bvec array at all.   BUG: KASAN: slab-out-of-bounds in io_import_reg_buf+0x697/0x7f0   Read of size 4 at addr ffff888002bcc254 by task poc/103   Call Trace:    io_import_reg_buf+0x697/0x7f0    io_write_fixed+0xd9/0x250    __io_issue_sqe+0xad/0x710    io_issue_sqe+0x7d/0x1100    io_submit_sqes+0x86a/0x23c0    __do_sys_io_uring_enter+0xa98/0x1590   Allocated by task 103:   The buggy address is located 12 bytes to the right of    allocated 584-byte region [ffff888002bcc000, ffff888002bcc248)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-43006</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1346 — Linux Kernel: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1346</link>
      <description>&lt;p&gt;Ein entfernter Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um Root-Rechte zu erlangen, um Sicherheitsmechanismen zu umgehen, einen Denial-of-Service-Zustand herbeizuführen oder Auswirkungen unbestimmter Art zu erzielen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um Root-Rechte zu erlangen, um Sicherheitsmechanismen zu umgehen, einen Denial-of-Service-Zustand herbeizuführen oder Auswirkungen unbestimmter Art zu erzielen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1346</guid>
    </item>
  </channel>
</rss>
