<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 11:41:08 +0000</lastBuildDate>
    <item>
      <title>ALSA-2026:21557 — Important: kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:21557</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: kernel, AlmaLinux:10: kernel-64k, AlmaLinux:10: kernel-64k-core, AlmaLinux:10: kernel-64k-debug, AlmaLinux:10: kernel-64k-debug-core, AlmaLinux:10: kernel-64k-debug-devel, AlmaLinux:10: kernel-64k-debug-devel-matched, AlmaLinux:10: kernel-64k-debug-modules, AlmaLinux:10: kernel-64k-debug-modules-core, AlmaLinux:10: kernel-64k-debug-modules-extra and 65 more&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: can: j1939: j1939_session_new(): fix skb reference counting (CVE-2024-56645)
  * kernel: ima: don&amp;#39;t clear IMA_DIGSIG flag when setting or removing non-IMA xattr (CVE-2025-68183)
  * kernel: mm: thp: deny THP for files on anonymous inodes (CVE-2026-23375)
  * kernel: netfilter: nf_tables: release flowtable after rcu grace period on error (CVE-2026-23392)
  * kernel: netfilter: nf_conntrack_h323: check for zero length in DecodeQ931() (CVE-2026-23455)
  * kernel: net: sched: act_csum: validate nested VLAN headers (CVE-2026-31684)
  * kernel: netfilter: ip6t_eui64: reject invalid MAC header for all packets (CVE-2026-31685)
  * kernel: netfilter: nf_conntrack_helper: pass helper to expect cleanup (CVE-2026-43027)
  * kernel: io_uring/rsrc: reject zero-length fixed buffer import (CVE-2026-43006)
  * kernel: Bluetooth: MGMT: validate LTK enc_size on load (CVE-2026-43020)
  * kernel: HID: wacom: fix out-of-bounds read in wacom_intuos_bt_irq (CVE-2026-43051)
  * kernel: Bluetooth: SCO: fix race conditions in sco_sock_connect() (CVE-2026-43023)
  * kernel: netfilter: ctnetlink: ensure safe access to master conntrack (CVE-2026-43116)
  * kernel: wifi: brcmfmac: validate bsscfg indices in IF events (CVE-2026-43110)
  * kernel: netfilter: xt_tcpmss: check remaining length before reading optlen (CVE-2026-43190)
  * kernel: Linux kernel dpaa2-switch: Kernel memory corru…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: kernel, AlmaLinux:10: kernel-64k, AlmaLinux:10: kernel-64k-core, AlmaLinux:10: kernel-64k-debug, AlmaLinux:10: kernel-64k-debug-core, AlmaLinux:10: kernel-64k-debug-devel, AlmaLinux:10: kernel-64k-debug-devel-matched, AlmaLinux:10: kernel-64k-debug-modules, AlmaLinux:10: kernel-64k-debug-modules-core, AlmaLinux:10: kernel-64k-debug-modules-extra and 65 more&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: can: j1939: j1939_session_new(): fix skb reference counting (CVE-2024-56645)
  * kernel: ima: don&amp;#39;t clear IMA_DIGSIG flag when setting or removing non-IMA xattr (CVE-2025-68183)
  * kernel: mm: thp: deny THP for files on anonymous inodes (CVE-2026-23375)
  * kernel: netfilter: nf_tables: release flowtable after rcu grace period on error (CVE-2026-23392)
  * kernel: netfilter: nf_conntrack_h323: check for zero length in DecodeQ931() (CVE-2026-23455)
  * kernel: net: sched: act_csum: validate nested VLAN headers (CVE-2026-31684)
  * kernel: netfilter: ip6t_eui64: reject invalid MAC header for all packets (CVE-2026-31685)
  * kernel: netfilter: nf_conntrack_helper: pass helper to expect cleanup (CVE-2026-43027)
  * kernel: io_uring/rsrc: reject zero-length fixed buffer import (CVE-2026-43006)
  * kernel: Bluetooth: MGMT: validate LTK enc_size on load (CVE-2026-43020)
  * kernel: HID: wacom: fix out-of-bounds read in wacom_intuos_bt_irq (CVE-2026-43051)
  * kernel: Bluetooth: SCO: fix race conditions in sco_sock_connect() (CVE-2026-43023)
  * kernel: netfilter: ctnetlink: ensure safe access to master conntrack (CVE-2026-43116)
  * kernel: wifi: brcmfmac: validate bsscfg indices in IF events (CVE-2026-43110)
  * kernel: netfilter: xt_tcpmss: check remaining length before reading optlen (CVE-2026-43190)
  * kernel: Linux kernel dpaa2-switch: Kernel memory corru…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:21557</guid>
    </item>
    <item>
      <title>BELL-CVE-2026-43116</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-43116</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-43116</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0747 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de Red Hat. Certaines d'entre elles permettent à un…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0747</link>
      <description>certfr-2026-avi-0747</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0747</guid>
    </item>
    <item>
      <title>ESSA-2026:0155 — Important: kernel security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/essa-2026:0155</link>
      <description>&lt;p&gt;Important: kernel security, bug fix, and enhancement update&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Important: kernel security, bug fix, and enhancement update&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/essa-2026:0155</guid>
    </item>
    <item>
      <title>EUVD-2026-364799</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-364799</link>
      <description>EUVD-2026-364799</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-364799</guid>
    </item>
    <item>
      <title>fkie_cve-2026-43116</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-43116</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;netfilter: ctnetlink: ensure safe access to master conntrack&lt;/p&gt;
&lt;p&gt;Holding reference on the expectation is not sufficient, the master
conntrack object can just go away, making exp-&amp;gt;master invalid.&lt;/p&gt;
&lt;p&gt;To access exp-&amp;gt;master safely:&lt;/p&gt;
&lt;p&gt;- Grab the nf_conntrack_expect_lock, this gets serialized with
  clean_from_lists() which also holds this lock when the master
  conntrack goes away.&lt;/p&gt;
&lt;p&gt;- Hold reference on master conntrack via nf_conntrack_find_get().
  Not so easy since the master tuple to look up for the master conntrack
  is not available in the existing problematic paths.&lt;/p&gt;
&lt;p&gt;This patch goes for extending the nf_conntrack_expect_lock section
to address this issue for simplicity, in the cases that are described
below this is just slightly extending the lock section.&lt;/p&gt;
&lt;p&gt;The add expectation command already holds a reference to the master
conntrack from ctnetlink_create_expect().&lt;/p&gt;
&lt;p&gt;However, the delete expectation command needs to grab the spinlock
before looking up for the expectation. Expand the existing spinlock
section to address this to cover the expectation lookup. Note that,
the nf_ct_expect_iterate_net() calls already grabs the spinlock while
iterating over the expectation table, which is correct.&lt;/p&gt;
&lt;p&gt;The get expectation command needs to grab the spinlock to ensure master
conntrack does not go away. This also expands the existing spinlock
section to cover the expectation lookup too. I needed to move the
netlink skb allocati…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;netfilter: ctnetlink: ensure safe access to master conntrack&lt;/p&gt;
&lt;p&gt;Holding reference on the expectation is not sufficient, the master
conntrack object can just go away, making exp-&amp;gt;master invalid.&lt;/p&gt;
&lt;p&gt;To access exp-&amp;gt;master safely:&lt;/p&gt;
&lt;p&gt;- Grab the nf_conntrack_expect_lock, this gets serialized with
  clean_from_lists() which also holds this lock when the master
  conntrack goes away.&lt;/p&gt;
&lt;p&gt;- Hold reference on master conntrack via nf_conntrack_find_get().
  Not so easy since the master tuple to look up for the master conntrack
  is not available in the existing problematic paths.&lt;/p&gt;
&lt;p&gt;This patch goes for extending the nf_conntrack_expect_lock section
to address this issue for simplicity, in the cases that are described
below this is just slightly extending the lock section.&lt;/p&gt;
&lt;p&gt;The add expectation command already holds a reference to the master
conntrack from ctnetlink_create_expect().&lt;/p&gt;
&lt;p&gt;However, the delete expectation command needs to grab the spinlock
before looking up for the expectation. Expand the existing spinlock
section to address this to cover the expectation lookup. Note that,
the nf_ct_expect_iterate_net() calls already grabs the spinlock while
iterating over the expectation table, which is correct.&lt;/p&gt;
&lt;p&gt;The get expectation command needs to grab the spinlock to ensure master
conntrack does not go away. This also expands the existing spinlock
section to cover the expectation lookup too. I needed to move the
netlink skb allocati…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-43116</guid>
    </item>
    <item>
      <title>GHSA-88rv-c8gv-rfv7</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-88rv-c8gv-rfv7</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;netfilter: ctnetlink: ensure safe access to master conntrack&lt;/p&gt;
&lt;p&gt;Holding reference on the expectation is not sufficient, the master
conntrack object can just go away, making exp-&amp;gt;master invalid.&lt;/p&gt;
&lt;p&gt;To access exp-&amp;gt;master safely:&lt;/p&gt;
&lt;p&gt;- Grab the nf_conntrack_expect_lock, this gets serialized with
  clean_from_lists() which also holds this lock when the master
  conntrack goes away.&lt;/p&gt;
&lt;p&gt;- Hold reference on master conntrack via nf_conntrack_find_get().
  Not so easy since the master tuple to look up for the master conntrack
  is not available in the existing problematic paths.&lt;/p&gt;
&lt;p&gt;This patch goes for extending the nf_conntrack_expect_lock section
to address this issue for simplicity, in the cases that are described
below this is just slightly extending the lock section.&lt;/p&gt;
&lt;p&gt;The add expectation command already holds a reference to the master
conntrack from ctnetlink_create_expect().&lt;/p&gt;
&lt;p&gt;However, the delete expectation command needs to grab the spinlock
before looking up for the expectation. Expand the existing spinlock
section to address this to cover the expectation lookup. Note that,
the nf_ct_expect_iterate_net() calls already grabs the spinlock while
iterating over the expectation table, which is correct.&lt;/p&gt;
&lt;p&gt;The get expectation command needs to grab the spinlock to ensure master
conntrack does not go away. This also expands the existing spinlock
section to cover the expectation lookup too. I needed to move the
netlink skb allocati…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;netfilter: ctnetlink: ensure safe access to master conntrack&lt;/p&gt;
&lt;p&gt;Holding reference on the expectation is not sufficient, the master
conntrack object can just go away, making exp-&amp;gt;master invalid.&lt;/p&gt;
&lt;p&gt;To access exp-&amp;gt;master safely:&lt;/p&gt;
&lt;p&gt;- Grab the nf_conntrack_expect_lock, this gets serialized with
  clean_from_lists() which also holds this lock when the master
  conntrack goes away.&lt;/p&gt;
&lt;p&gt;- Hold reference on master conntrack via nf_conntrack_find_get().
  Not so easy since the master tuple to look up for the master conntrack
  is not available in the existing problematic paths.&lt;/p&gt;
&lt;p&gt;This patch goes for extending the nf_conntrack_expect_lock section
to address this issue for simplicity, in the cases that are described
below this is just slightly extending the lock section.&lt;/p&gt;
&lt;p&gt;The add expectation command already holds a reference to the master
conntrack from ctnetlink_create_expect().&lt;/p&gt;
&lt;p&gt;However, the delete expectation command needs to grab the spinlock
before looking up for the expectation. Expand the existing spinlock
section to address this to cover the expectation lookup. Note that,
the nf_ct_expect_iterate_net() calls already grabs the spinlock while
iterating over the expectation table, which is correct.&lt;/p&gt;
&lt;p&gt;The get expectation command needs to grab the spinlock to ensure master
conntrack does not go away. This also expands the existing spinlock
section to cover the expectation lookup too. I needed to move the
netlink skb allocati…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-88rv-c8gv-rfv7</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-43116 — netfilter: ctnetlink: ensure safe access to master conntrack</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-43116</link>
      <description>msrc_CVE-2026-43116</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-43116</guid>
    </item>
    <item>
      <title>OESA-2026-2674 — kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-2674</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP4: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;btrfs: qgroup: fix race between quota disable and quota rescan ioctl&lt;/p&gt;
&lt;p&gt;There&amp;amp;apos;s a race between a task disabling quotas and another running the
rescan ioctl that can result in a use-after-free of qgroup records from
the fs_info-&amp;amp;gt;qgroup_tree rbtree.&lt;/p&gt;
&lt;p&gt;This happens as follows:&lt;/p&gt;
&lt;p&gt;1) Task A enters btrfs_ioctl_quota_rescan() -&amp;amp;gt; btrfs_qgroup_rescan();&lt;/p&gt;
&lt;p&gt;2) Task B enters btrfs_quota_disable() and calls
   btrfs_qgroup_wait_for_completion(), which does nothing because at that
   point fs_info-&amp;amp;gt;qgroup_rescan_running is false (it wasn&amp;amp;apos;t set yet by
   task A);&lt;/p&gt;
&lt;p&gt;3) Task B calls btrfs_free_qgroup_config() which starts freeing qgroups
   from fs_info-&amp;amp;gt;qgroup_tree without taking the lock fs_info-&amp;amp;gt;qgroup_lock;&lt;/p&gt;
&lt;p&gt;4) Task A enters qgroup_rescan_zero_tracking() which starts iterating
   the fs_info-&amp;amp;gt;qgroup_tree tree while holding fs_info-&amp;amp;gt;qgroup_lock,
   but task B is freeing qgroup records from that tree without holding
   the lock, resulting in a use-after-free.&lt;/p&gt;
&lt;p&gt;Fix this by taking fs_info-&amp;amp;gt;qgroup_lock at btrfs_free_qgroup_config().
Also at btrfs_qgroup_rescan() don&amp;amp;apos;t start the rescan worker if quotas
were already disabled.(CVE-2025-39759)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;wifi: wilc1000: avoid buffer overflow in WID string configuration&lt;/p&gt;
&lt;p&gt;Fix the following copy overflow warning identi…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP4: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;btrfs: qgroup: fix race between quota disable and quota rescan ioctl&lt;/p&gt;
&lt;p&gt;There&amp;amp;apos;s a race between a task disabling quotas and another running the
rescan ioctl that can result in a use-after-free of qgroup records from
the fs_info-&amp;amp;gt;qgroup_tree rbtree.&lt;/p&gt;
&lt;p&gt;This happens as follows:&lt;/p&gt;
&lt;p&gt;1) Task A enters btrfs_ioctl_quota_rescan() -&amp;amp;gt; btrfs_qgroup_rescan();&lt;/p&gt;
&lt;p&gt;2) Task B enters btrfs_quota_disable() and calls
   btrfs_qgroup_wait_for_completion(), which does nothing because at that
   point fs_info-&amp;amp;gt;qgroup_rescan_running is false (it wasn&amp;amp;apos;t set yet by
   task A);&lt;/p&gt;
&lt;p&gt;3) Task B calls btrfs_free_qgroup_config() which starts freeing qgroups
   from fs_info-&amp;amp;gt;qgroup_tree without taking the lock fs_info-&amp;amp;gt;qgroup_lock;&lt;/p&gt;
&lt;p&gt;4) Task A enters qgroup_rescan_zero_tracking() which starts iterating
   the fs_info-&amp;amp;gt;qgroup_tree tree while holding fs_info-&amp;amp;gt;qgroup_lock,
   but task B is freeing qgroup records from that tree without holding
   the lock, resulting in a use-after-free.&lt;/p&gt;
&lt;p&gt;Fix this by taking fs_info-&amp;amp;gt;qgroup_lock at btrfs_free_qgroup_config().
Also at btrfs_qgroup_rescan() don&amp;amp;apos;t start the rescan worker if quotas
were already disabled.(CVE-2025-39759)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;wifi: wilc1000: avoid buffer overflow in WID string configuration&lt;/p&gt;
&lt;p&gt;Fix the following copy overflow warning identi…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-2674</guid>
    </item>
    <item>
      <title>RHSA-2026:26462 — Red Hat Security Advisory: kernel-rt security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:26462</link>
      <description>&lt;p&gt;kernel: ipv6: use RCU in ip6_xmit() kernel: ipv6: use RCU in ip6_output() kernel: net: use dst_dev_rcu() in sk_setup_caps() kernel: nbd: defer config unlock in nbd_genl_connect kernel: crypto: asymmetric_keys - prevent overflow in asymmetric_key_generate_id kernel: iommu: disable SVA when CONFIG_X86 is set kernel: libceph: make decode_pool() more resilient against corrupted osdmaps kernel: libceph: prevent potential out-of-bounds reads in handle_auth_done() kernel: libceph: replace overzealous BUG_ON in osdmap_apply_incremental() kernel: scsi: target: iscsi: Fix use-after-free in iscsit_dec_conn_usage_count() kernel: netfilter: nf_tables: release flowtable after rcu grace period on error kernel: netfilter: nf_conntrack_h323: check for zero length in DecodeQ931() kernel: netfilter: ip6t_eui64: reject invalid MAC header for all packets kernel: wifi: brcmfmac: validate bsscfg indices in IF events kernel: netfilter: ctnetlink: ensure safe access to master conntrack kernel: xfs: fix freemap adjustments when adding xattrs to leaf blocks kernel: netfilter: xt_tcpmss: check remaining length before reading optlen kernel: mm/page_alloc: clear page-&amp;gt;private in free_pages_prepare() kernel: wifi: mac80211: remove station if connection prep fails kernel: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL kernel: Linux kernel: smb: client: reject userspace cifs.spnego descriptions&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;kernel: ipv6: use RCU in ip6_xmit() kernel: ipv6: use RCU in ip6_output() kernel: net: use dst_dev_rcu() in sk_setup_caps() kernel: nbd: defer config unlock in nbd_genl_connect kernel: crypto: asymmetric_keys - prevent overflow in asymmetric_key_generate_id kernel: iommu: disable SVA when CONFIG_X86 is set kernel: libceph: make decode_pool() more resilient against corrupted osdmaps kernel: libceph: prevent potential out-of-bounds reads in handle_auth_done() kernel: libceph: replace overzealous BUG_ON in osdmap_apply_incremental() kernel: scsi: target: iscsi: Fix use-after-free in iscsit_dec_conn_usage_count() kernel: netfilter: nf_tables: release flowtable after rcu grace period on error kernel: netfilter: nf_conntrack_h323: check for zero length in DecodeQ931() kernel: netfilter: ip6t_eui64: reject invalid MAC header for all packets kernel: wifi: brcmfmac: validate bsscfg indices in IF events kernel: netfilter: ctnetlink: ensure safe access to master conntrack kernel: xfs: fix freemap adjustments when adding xattrs to leaf blocks kernel: netfilter: xt_tcpmss: check remaining length before reading optlen kernel: mm/page_alloc: clear page-&amp;gt;private in free_pages_prepare() kernel: wifi: mac80211: remove station if connection prep fails kernel: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL kernel: Linux kernel: smb: client: reject userspace cifs.spnego descriptions&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:26462</guid>
    </item>
    <item>
      <title>RLSA-2026:21557 — Important: kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:21557</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: kernel&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: can: j1939: j1939_session_new(): fix skb reference counting (CVE-2024-56645)&lt;/p&gt;
&lt;p&gt;* kernel: ima: don&amp;#39;t clear IMA_DIGSIG flag when setting or removing non-IMA xattr (CVE-2025-68183)&lt;/p&gt;
&lt;p&gt;* kernel: mm: thp: deny THP for files on anonymous inodes (CVE-2026-23375)&lt;/p&gt;
&lt;p&gt;* kernel: netfilter: nf_tables: release flowtable after rcu grace period on error (CVE-2026-23392)&lt;/p&gt;
&lt;p&gt;* kernel: netfilter: nf_conntrack_h323: check for zero length in DecodeQ931() (CVE-2026-23455)&lt;/p&gt;
&lt;p&gt;* kernel: net: sched: act_csum: validate nested VLAN headers (CVE-2026-31684)&lt;/p&gt;
&lt;p&gt;* kernel: netfilter: ip6t_eui64: reject invalid MAC header for all packets (CVE-2026-31685)&lt;/p&gt;
&lt;p&gt;* kernel: netfilter: nf_conntrack_helper: pass helper to expect cleanup (CVE-2026-43027)&lt;/p&gt;
&lt;p&gt;* kernel: io_uring/rsrc: reject zero-length fixed buffer import (CVE-2026-43006)&lt;/p&gt;
&lt;p&gt;* kernel: Bluetooth: MGMT: validate LTK enc_size on load (CVE-2026-43020)&lt;/p&gt;
&lt;p&gt;* kernel: HID: wacom: fix out-of-bounds read in wacom_intuos_bt_irq (CVE-2026-43051)&lt;/p&gt;
&lt;p&gt;* kernel: Bluetooth: SCO: fix race conditions in sco_sock_connect() (CVE-2026-43023)&lt;/p&gt;
&lt;p&gt;* kernel: netfilter: ctnetlink: ensure safe access to master conntrack (CVE-2026-43116)&lt;/p&gt;
&lt;p&gt;* kernel: wifi: brcmfmac: validate bsscfg indices in IF events (CVE-2026-43110)&lt;/p&gt;
&lt;p&gt;* kernel: netfilter: xt_tcpmss: check remaining length before reading optlen (CVE-2026-43190)&lt;/p&gt;
&lt;p&gt;* kernel: Linux kernel dpaa2-switch: Kernel memory corruption via out-of-boun…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: kernel&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: can: j1939: j1939_session_new(): fix skb reference counting (CVE-2024-56645)&lt;/p&gt;
&lt;p&gt;* kernel: ima: don&amp;#39;t clear IMA_DIGSIG flag when setting or removing non-IMA xattr (CVE-2025-68183)&lt;/p&gt;
&lt;p&gt;* kernel: mm: thp: deny THP for files on anonymous inodes (CVE-2026-23375)&lt;/p&gt;
&lt;p&gt;* kernel: netfilter: nf_tables: release flowtable after rcu grace period on error (CVE-2026-23392)&lt;/p&gt;
&lt;p&gt;* kernel: netfilter: nf_conntrack_h323: check for zero length in DecodeQ931() (CVE-2026-23455)&lt;/p&gt;
&lt;p&gt;* kernel: net: sched: act_csum: validate nested VLAN headers (CVE-2026-31684)&lt;/p&gt;
&lt;p&gt;* kernel: netfilter: ip6t_eui64: reject invalid MAC header for all packets (CVE-2026-31685)&lt;/p&gt;
&lt;p&gt;* kernel: netfilter: nf_conntrack_helper: pass helper to expect cleanup (CVE-2026-43027)&lt;/p&gt;
&lt;p&gt;* kernel: io_uring/rsrc: reject zero-length fixed buffer import (CVE-2026-43006)&lt;/p&gt;
&lt;p&gt;* kernel: Bluetooth: MGMT: validate LTK enc_size on load (CVE-2026-43020)&lt;/p&gt;
&lt;p&gt;* kernel: HID: wacom: fix out-of-bounds read in wacom_intuos_bt_irq (CVE-2026-43051)&lt;/p&gt;
&lt;p&gt;* kernel: Bluetooth: SCO: fix race conditions in sco_sock_connect() (CVE-2026-43023)&lt;/p&gt;
&lt;p&gt;* kernel: netfilter: ctnetlink: ensure safe access to master conntrack (CVE-2026-43116)&lt;/p&gt;
&lt;p&gt;* kernel: wifi: brcmfmac: validate bsscfg indices in IF events (CVE-2026-43110)&lt;/p&gt;
&lt;p&gt;* kernel: netfilter: xt_tcpmss: check remaining length before reading optlen (CVE-2026-43190)&lt;/p&gt;
&lt;p&gt;* kernel: Linux kernel dpaa2-switch: Kernel memory corruption via out-of-boun…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:21557</guid>
    </item>
    <item>
      <title>SSA-019113 — SSA-019113: Vulnerabilities in the additional GNU/Linux subsystem of the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1.6</title>
      <link>https://cve.radiocsirt.org/vuln/ssa-019113</link>
      <description>&lt;p&gt;Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.6 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant).&lt;/p&gt;
&lt;p&gt;Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.6 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant).&lt;/p&gt;
&lt;p&gt;Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ssa-019113</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:23477-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:23477-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:23477-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-43116</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-43116</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux, Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe and 233 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: netfilter: ctnetlink: ensure safe access to master conntrack Holding reference on the expectation is not sufficient, the master conntrack object can just go away, making exp-&amp;gt;master invalid. To access exp-&amp;gt;master safely: - Grab the nf_conntrack_expect_lock, this gets serialized with   clean_from_lists() which also holds this lock when the master   conntrack goes away. - Hold reference on master conntrack via nf_conntrack_find_get().   Not so easy since the master tuple to look up for the master conntrack   is not available in the existing problematic paths. This patch goes for extending the nf_conntrack_expect_lock section to address this issue for simplicity, in the cases that are described below this is just slightly extending the lock section. The add expectation command already holds a reference to the master conntrack from ctnetlink_create_expect(). However, the delete expectation command needs to grab the spinlock before looking up for the expectation. Expand the existing spinlock section to address this to cover the expectation lookup. Note that, the nf_ct_expect_iterate_net() calls already grabs the spinlock while iterating over the expectation table, which is correct. The get expectation command needs to grab the spinlock to ensure master conntrack does not go away. This also expands the existing spinlock section to cover the expectation lookup too. I needed to move the netlink skb allocation out of…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux, Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe and 233 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: netfilter: ctnetlink: ensure safe access to master conntrack Holding reference on the expectation is not sufficient, the master conntrack object can just go away, making exp-&amp;gt;master invalid. To access exp-&amp;gt;master safely: - Grab the nf_conntrack_expect_lock, this gets serialized with   clean_from_lists() which also holds this lock when the master   conntrack goes away. - Hold reference on master conntrack via nf_conntrack_find_get().   Not so easy since the master tuple to look up for the master conntrack   is not available in the existing problematic paths. This patch goes for extending the nf_conntrack_expect_lock section to address this issue for simplicity, in the cases that are described below this is just slightly extending the lock section. The add expectation command already holds a reference to the master conntrack from ctnetlink_create_expect(). However, the delete expectation command needs to grab the spinlock before looking up for the expectation. Expand the existing spinlock section to address this to cover the expectation lookup. Note that, the nf_ct_expect_iterate_net() calls already grabs the spinlock while iterating over the expectation table, which is correct. The get expectation command needs to grab the spinlock to ensure master conntrack does not go away. This also expands the existing spinlock section to cover the expectation lookup too. I needed to move the netlink skb allocation out of…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-43116</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1385 — Linux Kernel: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1385</link>
      <description>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen Denial of Service zu verursachen, Informationen offenzulegen, Sicherheitsmaßnahmen zu umgehen oder potentiell beliebigen Programmcode auszuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen Denial of Service zu verursachen, Informationen offenzulegen, Sicherheitsmaßnahmen zu umgehen oder potentiell beliebigen Programmcode auszuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1385</guid>
    </item>
  </channel>
</rss>
