<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 09:41:04 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-06506</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-06506</link>
      <description>bdu:2026-06506</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-06506</guid>
    </item>
    <item>
      <title>BELL-CVE-2026-43033</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-43033</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-43033</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0526 — De multiples vulnérabilités ont été découvertes dans les produits Microsoft. Elles permettent à un attaquant de provoqu…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0526</link>
      <description>certfr-2026-avi-0526</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0526</guid>
    </item>
    <item>
      <title>EUVD-2026-364791</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-364791</link>
      <description>EUVD-2026-364791</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-364791</guid>
    </item>
    <item>
      <title>fkie_cve-2026-43033</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-43033</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;crypto: authencesn - Do not place hiseq at end of dst for out-of-place decryption&lt;/p&gt;
&lt;p&gt;When decrypting data that is not in-place (src != dst), there is
no need to save the high-order sequence bits in dst as it could
simply be re-copied from the source.&lt;/p&gt;
&lt;p&gt;However, the data to be hashed need to be rearranged accordingly.&lt;/p&gt;
&lt;p&gt;Thanks,&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;crypto: authencesn - Do not place hiseq at end of dst for out-of-place decryption&lt;/p&gt;
&lt;p&gt;When decrypting data that is not in-place (src != dst), there is
no need to save the high-order sequence bits in dst as it could
simply be re-copied from the source.&lt;/p&gt;
&lt;p&gt;However, the data to be hashed need to be rearranged accordingly.&lt;/p&gt;
&lt;p&gt;Thanks,&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-43033</guid>
    </item>
    <item>
      <title>GHSA-r324-r22p-vp8m</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-r324-r22p-vp8m</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;crypto: authencesn - Do not place hiseq at end of dst for out-of-place decryption&lt;/p&gt;
&lt;p&gt;When decrypting data that is not in-place (src != dst), there is
no need to save the high-order sequence bits in dst as it could
simply be re-copied from the source.&lt;/p&gt;
&lt;p&gt;However, the data to be hashed need to be rearranged accordingly.&lt;/p&gt;
&lt;p&gt;Thanks,&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;crypto: authencesn - Do not place hiseq at end of dst for out-of-place decryption&lt;/p&gt;
&lt;p&gt;When decrypting data that is not in-place (src != dst), there is
no need to save the high-order sequence bits in dst as it could
simply be re-copied from the source.&lt;/p&gt;
&lt;p&gt;However, the data to be hashed need to be rearranged accordingly.&lt;/p&gt;
&lt;p&gt;Thanks,&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-r324-r22p-vp8m</guid>
    </item>
    <item>
      <title>ICSA-26-209-04 — Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-26-209-04</link>
      <description>&lt;p&gt;Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.6 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant).&lt;/p&gt;
&lt;p&gt;Siemens is preparing fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.6 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant).&lt;/p&gt;
&lt;p&gt;Siemens is preparing fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-26-209-04</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-43033 — crypto: authencesn - Do not place hiseq at end of dst for out-of-place decryption</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-43033</link>
      <description>msrc_CVE-2026-43033</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-43033</guid>
    </item>
    <item>
      <title>OESA-2026-2496 — kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-2496</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP4: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;Revert &amp;amp;quot;smb: client: fix TCP timers deadlock after rmmod&amp;amp;quot;&lt;/p&gt;
&lt;p&gt;This reverts commit e9f2517a3e18a54a3943c098d2226b245d488801.&lt;/p&gt;
&lt;p&gt;Commit e9f2517a3e18 (&amp;amp;quot;smb: client: fix TCP timers deadlock after
rmmod&amp;amp;quot;) is intended to fix a null-ptr-deref in LOCKDEP, which is
mentioned as CVE-2024-54680, but is actually did not fix anything;
The issue can be reproduced on top of it. [0]&lt;/p&gt;
&lt;p&gt;Also, it reverted the change by commit ef7134c7fc48 (&amp;amp;quot;smb: client:
Fix use-after-free of network namespace.&amp;amp;quot;) and introduced a real
issue by reviving the kernel TCP socket.&lt;/p&gt;
&lt;p&gt;When a reconnect happens for a CIFS connection, the socket state
transitions to FIN_WAIT_1.  Then, inet_csk_clear_xmit_timers_sync()
in tcp_close() stops all timers for the socket.&lt;/p&gt;
&lt;p&gt;If an incoming FIN packet is lost, the socket will stay at FIN_WAIT_1
forever, and such sockets could be leaked up to net.ipv4.tcp_max_orphans.&lt;/p&gt;
&lt;p&gt;Usually, FIN can be retransmitted by the peer, but if the peer aborts
the connection, the issue comes into reality.&lt;/p&gt;
&lt;p&gt;I warned about this privately by pointing out the exact report [1],
but the bogus fix was finally merged.&lt;/p&gt;
&lt;p&gt;So, we should not stop the timers to finally kill the connection on
our side in that case, meaning we must not use a kernel socket for
TCP whose sk-&amp;amp;gt;sk_net_refcnt is 0.&lt;/p&gt;
&lt;p&gt;The kernel socket does not have a reference to its netns to ma…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP4: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;Revert &amp;amp;quot;smb: client: fix TCP timers deadlock after rmmod&amp;amp;quot;&lt;/p&gt;
&lt;p&gt;This reverts commit e9f2517a3e18a54a3943c098d2226b245d488801.&lt;/p&gt;
&lt;p&gt;Commit e9f2517a3e18 (&amp;amp;quot;smb: client: fix TCP timers deadlock after
rmmod&amp;amp;quot;) is intended to fix a null-ptr-deref in LOCKDEP, which is
mentioned as CVE-2024-54680, but is actually did not fix anything;
The issue can be reproduced on top of it. [0]&lt;/p&gt;
&lt;p&gt;Also, it reverted the change by commit ef7134c7fc48 (&amp;amp;quot;smb: client:
Fix use-after-free of network namespace.&amp;amp;quot;) and introduced a real
issue by reviving the kernel TCP socket.&lt;/p&gt;
&lt;p&gt;When a reconnect happens for a CIFS connection, the socket state
transitions to FIN_WAIT_1.  Then, inet_csk_clear_xmit_timers_sync()
in tcp_close() stops all timers for the socket.&lt;/p&gt;
&lt;p&gt;If an incoming FIN packet is lost, the socket will stay at FIN_WAIT_1
forever, and such sockets could be leaked up to net.ipv4.tcp_max_orphans.&lt;/p&gt;
&lt;p&gt;Usually, FIN can be retransmitted by the peer, but if the peer aborts
the connection, the issue comes into reality.&lt;/p&gt;
&lt;p&gt;I warned about this privately by pointing out the exact report [1],
but the bogus fix was finally merged.&lt;/p&gt;
&lt;p&gt;So, we should not stop the timers to finally kill the connection on
our side in that case, meaning we must not use a kernel socket for
TCP whose sk-&amp;amp;gt;sk_net_refcnt is 0.&lt;/p&gt;
&lt;p&gt;The kernel socket does not have a reference to its netns to ma…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-2496</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:21555-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:21555-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:21555-1</guid>
    </item>
    <item>
      <title>SSA-019113 — SSA-019113: Vulnerabilities in the additional GNU/Linux subsystem of the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1.6</title>
      <link>https://cve.radiocsirt.org/vuln/ssa-019113</link>
      <description>&lt;p&gt;Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.6 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant).&lt;/p&gt;
&lt;p&gt;Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.6 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant).&lt;/p&gt;
&lt;p&gt;Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ssa-019113</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:23066-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:23066-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:23066-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-43033</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-43033</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe, Ubuntu:Pro:16.04:LTS: linux-oracle, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:16.04:LTS: linux-hwe-edge and 230 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: crypto: authencesn - Do not place hiseq at end of dst for out-of-place decryption When decrypting data that is not in-place (src != dst), there is no need to save the high-order sequence bits in dst as it could simply be re-copied from the source. However, the data to be hashed need to be rearranged accordingly. Thanks,&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe, Ubuntu:Pro:16.04:LTS: linux-oracle, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:16.04:LTS: linux-hwe-edge and 230 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: crypto: authencesn - Do not place hiseq at end of dst for out-of-place decryption When decrypting data that is not in-place (src != dst), there is no need to save the high-order sequence bits in dst as it could simply be re-copied from the source. However, the data to be hashed need to be rearranged accordingly. Thanks,&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-43033</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1346 — Linux Kernel: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1346</link>
      <description>&lt;p&gt;Ein entfernter Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um Root-Rechte zu erlangen, um Sicherheitsmechanismen zu umgehen, einen Denial-of-Service-Zustand herbeizuführen oder Auswirkungen unbestimmter Art zu erzielen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um Root-Rechte zu erlangen, um Sicherheitsmechanismen zu umgehen, einen Denial-of-Service-Zustand herbeizuführen oder Auswirkungen unbestimmter Art zu erzielen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1346</guid>
    </item>
  </channel>
</rss>
