<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 09:09:28 +0000</lastBuildDate>
    <item>
      <title>BELL-CVE-2026-43161</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-43161</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-43161</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0927 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de SUSE. Certaines d'entre elles permettent à un at…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0927</link>
      <description>certfr-2026-avi-0927</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0927</guid>
    </item>
    <item>
      <title>EUVD-2026-320987</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-320987</link>
      <description>EUVD-2026-320987</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-320987</guid>
    </item>
    <item>
      <title>fkie_cve-2026-43161</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-43161</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;iommu/vt-d: Skip dev-iotlb flush for inaccessible PCIe device without scalable mode&lt;/p&gt;
&lt;p&gt;PCIe endpoints with ATS enabled and passed through to userspace
(e.g., QEMU, DPDK) can hard-lock the host when their link drops,
either by surprise removal or by a link fault.&lt;/p&gt;
&lt;p&gt;Commit 4fc82cd907ac (&amp;#34;iommu/vt-d: Don&amp;#39;t issue ATS Invalidation
request when device is disconnected&amp;#34;) adds pci_dev_is_disconnected()
to devtlb_invalidation_with_pasid() so ATS invalidation is skipped
only when the device is being safely removed, but it applies only
when Intel IOMMU scalable mode is enabled.&lt;/p&gt;
&lt;p&gt;With scalable mode disabled or unsupported, a system hard-lock
occurs when a PCIe endpoint&amp;#39;s link drops because the Intel IOMMU
waits indefinitely for an ATS invalidation that cannot complete.&lt;/p&gt;
&lt;p&gt;Call Trace:
 qi_submit_sync
 qi_flush_dev_iotlb
 __context_flush_dev_iotlb.part.0
 domain_context_clear_one_cb
 pci_for_each_dma_alias
 device_block_translation
 blocking_domain_attach_dev
 iommu_deinit_device
 __iommu_group_remove_device
 iommu_release_device
 iommu_bus_notifier
 blocking_notifier_call_chain
 bus_notify
 device_del
 pci_remove_bus_device
 pci_stop_and_remove_bus_device
 pciehp_unconfigure_device
 pciehp_disable_slot
 pciehp_handle_presence_or_link_change
 pciehp_ist&lt;/p&gt;
&lt;p&gt;Commit 81e921fd3216 (&amp;#34;iommu/vt-d: Fix NULL domain on device release&amp;#34;)
adds intel_pasid_teardown_sm_context() to intel_iommu_release_device(),
which calls qi_flush_dev_iotlb()…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;iommu/vt-d: Skip dev-iotlb flush for inaccessible PCIe device without scalable mode&lt;/p&gt;
&lt;p&gt;PCIe endpoints with ATS enabled and passed through to userspace
(e.g., QEMU, DPDK) can hard-lock the host when their link drops,
either by surprise removal or by a link fault.&lt;/p&gt;
&lt;p&gt;Commit 4fc82cd907ac (&amp;#34;iommu/vt-d: Don&amp;#39;t issue ATS Invalidation
request when device is disconnected&amp;#34;) adds pci_dev_is_disconnected()
to devtlb_invalidation_with_pasid() so ATS invalidation is skipped
only when the device is being safely removed, but it applies only
when Intel IOMMU scalable mode is enabled.&lt;/p&gt;
&lt;p&gt;With scalable mode disabled or unsupported, a system hard-lock
occurs when a PCIe endpoint&amp;#39;s link drops because the Intel IOMMU
waits indefinitely for an ATS invalidation that cannot complete.&lt;/p&gt;
&lt;p&gt;Call Trace:
 qi_submit_sync
 qi_flush_dev_iotlb
 __context_flush_dev_iotlb.part.0
 domain_context_clear_one_cb
 pci_for_each_dma_alias
 device_block_translation
 blocking_domain_attach_dev
 iommu_deinit_device
 __iommu_group_remove_device
 iommu_release_device
 iommu_bus_notifier
 blocking_notifier_call_chain
 bus_notify
 device_del
 pci_remove_bus_device
 pci_stop_and_remove_bus_device
 pciehp_unconfigure_device
 pciehp_disable_slot
 pciehp_handle_presence_or_link_change
 pciehp_ist&lt;/p&gt;
&lt;p&gt;Commit 81e921fd3216 (&amp;#34;iommu/vt-d: Fix NULL domain on device release&amp;#34;)
adds intel_pasid_teardown_sm_context() to intel_iommu_release_device(),
which calls qi_flush_dev_iotlb()…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-43161</guid>
    </item>
    <item>
      <title>GHSA-jph2-qvw9-vvwq</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-jph2-qvw9-vvwq</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;iommu/vt-d: Skip dev-iotlb flush for inaccessible PCIe device without scalable mode&lt;/p&gt;
&lt;p&gt;PCIe endpoints with ATS enabled and passed through to userspace
(e.g., QEMU, DPDK) can hard-lock the host when their link drops,
either by surprise removal or by a link fault.&lt;/p&gt;
&lt;p&gt;Commit 4fc82cd907ac (&amp;#34;iommu/vt-d: Don&amp;#39;t issue ATS Invalidation
request when device is disconnected&amp;#34;) adds pci_dev_is_disconnected()
to devtlb_invalidation_with_pasid() so ATS invalidation is skipped
only when the device is being safely removed, but it applies only
when Intel IOMMU scalable mode is enabled.&lt;/p&gt;
&lt;p&gt;With scalable mode disabled or unsupported, a system hard-lock
occurs when a PCIe endpoint&amp;#39;s link drops because the Intel IOMMU
waits indefinitely for an ATS invalidation that cannot complete.&lt;/p&gt;
&lt;p&gt;Call Trace:
 qi_submit_sync
 qi_flush_dev_iotlb
 __context_flush_dev_iotlb.part.0
 domain_context_clear_one_cb
 pci_for_each_dma_alias
 device_block_translation
 blocking_domain_attach_dev
 iommu_deinit_device
 __iommu_group_remove_device
 iommu_release_device
 iommu_bus_notifier
 blocking_notifier_call_chain
 bus_notify
 device_del
 pci_remove_bus_device
 pci_stop_and_remove_bus_device
 pciehp_unconfigure_device
 pciehp_disable_slot
 pciehp_handle_presence_or_link_change
 pciehp_ist&lt;/p&gt;
&lt;p&gt;Commit 81e921fd3216 (&amp;#34;iommu/vt-d: Fix NULL domain on device release&amp;#34;)
adds intel_pasid_teardown_sm_context() to intel_iommu_release_device(),
which calls qi_flush_dev_iotlb()…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;iommu/vt-d: Skip dev-iotlb flush for inaccessible PCIe device without scalable mode&lt;/p&gt;
&lt;p&gt;PCIe endpoints with ATS enabled and passed through to userspace
(e.g., QEMU, DPDK) can hard-lock the host when their link drops,
either by surprise removal or by a link fault.&lt;/p&gt;
&lt;p&gt;Commit 4fc82cd907ac (&amp;#34;iommu/vt-d: Don&amp;#39;t issue ATS Invalidation
request when device is disconnected&amp;#34;) adds pci_dev_is_disconnected()
to devtlb_invalidation_with_pasid() so ATS invalidation is skipped
only when the device is being safely removed, but it applies only
when Intel IOMMU scalable mode is enabled.&lt;/p&gt;
&lt;p&gt;With scalable mode disabled or unsupported, a system hard-lock
occurs when a PCIe endpoint&amp;#39;s link drops because the Intel IOMMU
waits indefinitely for an ATS invalidation that cannot complete.&lt;/p&gt;
&lt;p&gt;Call Trace:
 qi_submit_sync
 qi_flush_dev_iotlb
 __context_flush_dev_iotlb.part.0
 domain_context_clear_one_cb
 pci_for_each_dma_alias
 device_block_translation
 blocking_domain_attach_dev
 iommu_deinit_device
 __iommu_group_remove_device
 iommu_release_device
 iommu_bus_notifier
 blocking_notifier_call_chain
 bus_notify
 device_del
 pci_remove_bus_device
 pci_stop_and_remove_bus_device
 pciehp_unconfigure_device
 pciehp_disable_slot
 pciehp_handle_presence_or_link_change
 pciehp_ist&lt;/p&gt;
&lt;p&gt;Commit 81e921fd3216 (&amp;#34;iommu/vt-d: Fix NULL domain on device release&amp;#34;)
adds intel_pasid_teardown_sm_context() to intel_iommu_release_device(),
which calls qi_flush_dev_iotlb()…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-jph2-qvw9-vvwq</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-43161 — iommu/vt-d: Skip dev-iotlb flush for inaccessible PCIe device without scalable mode</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-43161</link>
      <description>msrc_CVE-2026-43161</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-43161</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:21388-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:21388-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:21388-1</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:22742-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:22742-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:22742-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-43161</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-43161</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 180 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Skip dev-iotlb flush for inaccessible PCIe device without scalable mode PCIe endpoints with ATS enabled and passed through to userspace (e.g., QEMU, DPDK) can hard-lock the host when their link drops, either by surprise removal or by a link fault. Commit 4fc82cd907ac (&amp;#34;iommu/vt-d: Don&amp;#39;t issue ATS Invalidation request when device is disconnected&amp;#34;) adds pci_dev_is_disconnected() to devtlb_invalidation_with_pasid() so ATS invalidation is skipped only when the device is being safely removed, but it applies only when Intel IOMMU scalable mode is enabled. With scalable mode disabled or unsupported, a system hard-lock occurs when a PCIe endpoint&amp;#39;s link drops because the Intel IOMMU waits indefinitely for an ATS invalidation that cannot complete. Call Trace:  qi_submit_sync  qi_flush_dev_iotlb  __context_flush_dev_iotlb.part.0  domain_context_clear_one_cb  pci_for_each_dma_alias  device_block_translation  blocking_domain_attach_dev  iommu_deinit_device  __iommu_group_remove_device  iommu_release_device  iommu_bus_notifier  blocking_notifier_call_chain  bus_notify  device_del  pci_remove_bus_device  pci_stop_and_remove_bus_device  pciehp_unconfigure_device  pciehp_disable_slot  pciehp_handle_presence_or_link_change  pciehp_ist Commit 81e921fd3216 (&amp;#34;iommu/vt-d: Fix NULL domain on device release&amp;#34;) adds intel_pasid_teardown_sm_context() to intel_iommu_release_device(), which calls qi_flush_dev_iotlb() and ca…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 180 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Skip dev-iotlb flush for inaccessible PCIe device without scalable mode PCIe endpoints with ATS enabled and passed through to userspace (e.g., QEMU, DPDK) can hard-lock the host when their link drops, either by surprise removal or by a link fault. Commit 4fc82cd907ac (&amp;#34;iommu/vt-d: Don&amp;#39;t issue ATS Invalidation request when device is disconnected&amp;#34;) adds pci_dev_is_disconnected() to devtlb_invalidation_with_pasid() so ATS invalidation is skipped only when the device is being safely removed, but it applies only when Intel IOMMU scalable mode is enabled. With scalable mode disabled or unsupported, a system hard-lock occurs when a PCIe endpoint&amp;#39;s link drops because the Intel IOMMU waits indefinitely for an ATS invalidation that cannot complete. Call Trace:  qi_submit_sync  qi_flush_dev_iotlb  __context_flush_dev_iotlb.part.0  domain_context_clear_one_cb  pci_for_each_dma_alias  device_block_translation  blocking_domain_attach_dev  iommu_deinit_device  __iommu_group_remove_device  iommu_release_device  iommu_bus_notifier  blocking_notifier_call_chain  bus_notify  device_del  pci_remove_bus_device  pci_stop_and_remove_bus_device  pciehp_unconfigure_device  pciehp_disable_slot  pciehp_handle_presence_or_link_change  pciehp_ist Commit 81e921fd3216 (&amp;#34;iommu/vt-d: Fix NULL domain on device release&amp;#34;) adds intel_pasid_teardown_sm_context() to intel_iommu_release_device(), which calls qi_flush_dev_iotlb() and ca…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-43161</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1405 — Linux Kernel: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1405</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um nicht spezifizierte Angriffe durchzuführen, möglicherweise Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren oder offenzulegen oder einen Denial-of-Service-Zustand zu verursachen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um nicht spezifizierte Angriffe durchzuführen, möglicherweise Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren oder offenzulegen oder einen Denial-of-Service-Zustand zu verursachen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1405</guid>
    </item>
  </channel>
</rss>
