<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 14:33:30 +0000</lastBuildDate>
    <item>
      <title>ALSA-2026:21556 — Important: kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:21556</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: kernel, AlmaLinux:9: kernel-64k, AlmaLinux:9: kernel-64k-core, AlmaLinux:9: kernel-64k-debug, AlmaLinux:9: kernel-64k-debug-core, AlmaLinux:9: kernel-64k-debug-devel, AlmaLinux:9: kernel-64k-debug-devel-matched, AlmaLinux:9: kernel-64k-debug-modules, AlmaLinux:9: kernel-64k-debug-modules-core, AlmaLinux:9: kernel-64k-debug-modules-extra and 64 more&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: proc: use the same treatment to check proc_lseek as ones for proc_read_iter et.al (CVE-2025-38653)
  * kernel: ima: don&amp;#39;t clear IMA_DIGSIG flag when setting or removing non-IMA xattr (CVE-2025-68183)
  * kernel: nbd: defer config unlock in nbd_genl_connect (CVE-2025-68366)
  * kernel: crypto: asymmetric_keys - prevent overflow in asymmetric_key_generate_id (CVE-2025-68724)
  * kernel: iommu: disable SVA when CONFIG_X86 is set (CVE-2025-71089)
  * kernel: netfilter: nf_tables: release flowtable after rcu grace period on error (CVE-2026-23392)
  * kernel: netfilter: nf_conntrack_h323: check for zero length in DecodeQ931() (CVE-2026-23455)
  * kernel: Bluetooth: SCO: Fix use-after-free in sco_recv_frame() due to missing sock_hold (CVE-2026-31408)
  * kernel: net: sched: act_csum: validate nested VLAN headers (CVE-2026-31684)
  * kernel: netfilter: ip6t_eui64: reject invalid MAC header for all packets (CVE-2026-31685)
  * kernel: netfilter: nf_conntrack_helper: pass helper to expect cleanup (CVE-2026-43027)
  * kernel: Bluetooth: MGMT: validate LTK enc_size on load (CVE-2026-43020)
  * kernel: HID: wacom: fix out-of-bounds read in wacom_intuos_bt_irq (CVE-2026-43051)
  * kernel: smb: client: validate the whole DACL before rewriting it in cifsacl (CVE-2026-31709)
  * kernel: Bluetooth: SCO: fix race conditions in sco_sock_connect() (CVE-2026-43023)
  * kernel:…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: kernel, AlmaLinux:9: kernel-64k, AlmaLinux:9: kernel-64k-core, AlmaLinux:9: kernel-64k-debug, AlmaLinux:9: kernel-64k-debug-core, AlmaLinux:9: kernel-64k-debug-devel, AlmaLinux:9: kernel-64k-debug-devel-matched, AlmaLinux:9: kernel-64k-debug-modules, AlmaLinux:9: kernel-64k-debug-modules-core, AlmaLinux:9: kernel-64k-debug-modules-extra and 64 more&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: proc: use the same treatment to check proc_lseek as ones for proc_read_iter et.al (CVE-2025-38653)
  * kernel: ima: don&amp;#39;t clear IMA_DIGSIG flag when setting or removing non-IMA xattr (CVE-2025-68183)
  * kernel: nbd: defer config unlock in nbd_genl_connect (CVE-2025-68366)
  * kernel: crypto: asymmetric_keys - prevent overflow in asymmetric_key_generate_id (CVE-2025-68724)
  * kernel: iommu: disable SVA when CONFIG_X86 is set (CVE-2025-71089)
  * kernel: netfilter: nf_tables: release flowtable after rcu grace period on error (CVE-2026-23392)
  * kernel: netfilter: nf_conntrack_h323: check for zero length in DecodeQ931() (CVE-2026-23455)
  * kernel: Bluetooth: SCO: Fix use-after-free in sco_recv_frame() due to missing sock_hold (CVE-2026-31408)
  * kernel: net: sched: act_csum: validate nested VLAN headers (CVE-2026-31684)
  * kernel: netfilter: ip6t_eui64: reject invalid MAC header for all packets (CVE-2026-31685)
  * kernel: netfilter: nf_conntrack_helper: pass helper to expect cleanup (CVE-2026-43027)
  * kernel: Bluetooth: MGMT: validate LTK enc_size on load (CVE-2026-43020)
  * kernel: HID: wacom: fix out-of-bounds read in wacom_intuos_bt_irq (CVE-2026-43051)
  * kernel: smb: client: validate the whole DACL before rewriting it in cifsacl (CVE-2026-31709)
  * kernel: Bluetooth: SCO: fix race conditions in sco_sock_connect() (CVE-2026-43023)
  * kernel:…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:21556</guid>
    </item>
    <item>
      <title>BELL-CVE-2026-43303</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-43303</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-43303</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0781 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de Red Hat. Certaines d'entre elles permettent à un…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0781</link>
      <description>certfr-2026-avi-0781</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0781</guid>
    </item>
    <item>
      <title>ESSA-2026:0155 — Important: kernel security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/essa-2026:0155</link>
      <description>&lt;p&gt;Important: kernel security, bug fix, and enhancement update&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Important: kernel security, bug fix, and enhancement update&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/essa-2026:0155</guid>
    </item>
    <item>
      <title>EUVD-2026-364802</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-364802</link>
      <description>EUVD-2026-364802</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-364802</guid>
    </item>
    <item>
      <title>fkie_cve-2026-43303</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-43303</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;mm/page_alloc: clear page-&amp;gt;private in free_pages_prepare()&lt;/p&gt;
&lt;p&gt;Several subsystems (slub, shmem, ttm, etc.) use page-&amp;gt;private but don&amp;#39;t
clear it before freeing pages.  When these pages are later allocated as
high-order pages and split via split_page(), tail pages retain stale
page-&amp;gt;private values.&lt;/p&gt;
&lt;p&gt;This causes a use-after-free in the swap subsystem.  The swap code uses
page-&amp;gt;private to track swap count continuations, assuming freshly
allocated pages have page-&amp;gt;private == 0.  When stale values are present,
swap_count_continued() incorrectly assumes the continuation list is valid
and iterates over uninitialized page-&amp;gt;lru containing LIST_POISON values,
causing a crash:&lt;/p&gt;
&lt;p&gt;KASAN: maybe wild-memory-access in range [0xdead000000000100-0xdead000000000107]
  RIP: 0010:__do_sys_swapoff+0x1151/0x1860&lt;/p&gt;
&lt;p&gt;Fix this by clearing page-&amp;gt;private in free_pages_prepare(), ensuring all
freed pages have clean state regardless of previous use.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;mm/page_alloc: clear page-&amp;gt;private in free_pages_prepare()&lt;/p&gt;
&lt;p&gt;Several subsystems (slub, shmem, ttm, etc.) use page-&amp;gt;private but don&amp;#39;t
clear it before freeing pages.  When these pages are later allocated as
high-order pages and split via split_page(), tail pages retain stale
page-&amp;gt;private values.&lt;/p&gt;
&lt;p&gt;This causes a use-after-free in the swap subsystem.  The swap code uses
page-&amp;gt;private to track swap count continuations, assuming freshly
allocated pages have page-&amp;gt;private == 0.  When stale values are present,
swap_count_continued() incorrectly assumes the continuation list is valid
and iterates over uninitialized page-&amp;gt;lru containing LIST_POISON values,
causing a crash:&lt;/p&gt;
&lt;p&gt;KASAN: maybe wild-memory-access in range [0xdead000000000100-0xdead000000000107]
  RIP: 0010:__do_sys_swapoff+0x1151/0x1860&lt;/p&gt;
&lt;p&gt;Fix this by clearing page-&amp;gt;private in free_pages_prepare(), ensuring all
freed pages have clean state regardless of previous use.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-43303</guid>
    </item>
    <item>
      <title>GHSA-6fh9-96ww-pvwq</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-6fh9-96ww-pvwq</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;mm/page_alloc: clear page-&amp;gt;private in free_pages_prepare()&lt;/p&gt;
&lt;p&gt;Several subsystems (slub, shmem, ttm, etc.) use page-&amp;gt;private but don&amp;#39;t
clear it before freeing pages.  When these pages are later allocated as
high-order pages and split via split_page(), tail pages retain stale
page-&amp;gt;private values.&lt;/p&gt;
&lt;p&gt;This causes a use-after-free in the swap subsystem.  The swap code uses
page-&amp;gt;private to track swap count continuations, assuming freshly
allocated pages have page-&amp;gt;private == 0.  When stale values are present,
swap_count_continued() incorrectly assumes the continuation list is valid
and iterates over uninitialized page-&amp;gt;lru containing LIST_POISON values,
causing a crash:&lt;/p&gt;
&lt;p&gt;KASAN: maybe wild-memory-access in range [0xdead000000000100-0xdead000000000107]
  RIP: 0010:__do_sys_swapoff+0x1151/0x1860&lt;/p&gt;
&lt;p&gt;Fix this by clearing page-&amp;gt;private in free_pages_prepare(), ensuring all
freed pages have clean state regardless of previous use.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;mm/page_alloc: clear page-&amp;gt;private in free_pages_prepare()&lt;/p&gt;
&lt;p&gt;Several subsystems (slub, shmem, ttm, etc.) use page-&amp;gt;private but don&amp;#39;t
clear it before freeing pages.  When these pages are later allocated as
high-order pages and split via split_page(), tail pages retain stale
page-&amp;gt;private values.&lt;/p&gt;
&lt;p&gt;This causes a use-after-free in the swap subsystem.  The swap code uses
page-&amp;gt;private to track swap count continuations, assuming freshly
allocated pages have page-&amp;gt;private == 0.  When stale values are present,
swap_count_continued() incorrectly assumes the continuation list is valid
and iterates over uninitialized page-&amp;gt;lru containing LIST_POISON values,
causing a crash:&lt;/p&gt;
&lt;p&gt;KASAN: maybe wild-memory-access in range [0xdead000000000100-0xdead000000000107]
  RIP: 0010:__do_sys_swapoff+0x1151/0x1860&lt;/p&gt;
&lt;p&gt;Fix this by clearing page-&amp;gt;private in free_pages_prepare(), ensuring all
freed pages have clean state regardless of previous use.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-6fh9-96ww-pvwq</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-43303 — mm/page_alloc: clear page-&gt;private in free_pages_prepare()</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-43303</link>
      <description>msrc_CVE-2026-43303</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-43303</guid>
    </item>
    <item>
      <title>OESA-2026-2675 — kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-2675</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP1: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;drm/i915/gt: Fix timeline left held on VMA alloc error&lt;/p&gt;
&lt;p&gt;The following error has been reported sporadically by CI when a test
unbinds the i915 driver on a ring submission platform:&lt;/p&gt;
&lt;p&gt;&amp;amp;lt;4&amp;amp;gt; [239.330153] ------------[ cut here ]------------
&amp;amp;lt;4&amp;amp;gt; [239.330166] i915 0000:00:02.0: [drm] drm_WARN_ON(dev_priv-&amp;amp;gt;mm.shrink_count)
&amp;amp;lt;4&amp;amp;gt; [239.330196] WARNING: CPU: 1 PID: 18570 at drivers/gpu/drm/i915/i915_gem.c:1309 i915_gem_cleanup_early+0x13e/0x150 [i915]
...
&amp;amp;lt;4&amp;amp;gt; [239.330640] RIP: 0010:i915_gem_cleanup_early+0x13e/0x150 [i915]
...
&amp;amp;lt;4&amp;amp;gt; [239.330942] Call Trace:
&amp;amp;lt;4&amp;amp;gt; [239.330944]  &amp;amp;lt;TASK&amp;amp;gt;
&amp;amp;lt;4&amp;amp;gt; [239.330949]  i915_driver_late_release+0x2b/0xa0 [i915]
&amp;amp;lt;4&amp;amp;gt; [239.331202]  i915_driver_release+0x86/0xa0 [i915]
&amp;amp;lt;4&amp;amp;gt; [239.331482]  devm_drm_dev_init_release+0x61/0x90
&amp;amp;lt;4&amp;amp;gt; [239.331494]  devm_action_release+0x15/0x30
&amp;amp;lt;4&amp;amp;gt; [239.331504]  release_nodes+0x3d/0x120
&amp;amp;lt;4&amp;amp;gt; [239.331517]  devres_release_all+0x96/0xd0
&amp;amp;lt;4&amp;amp;gt; [239.331533]  device_unbind_cleanup+0x12/0x80
&amp;amp;lt;4&amp;amp;gt; [239.331543]  device_release_driver_internal+0x23a/0x280
&amp;amp;lt;4&amp;amp;gt; [239.331550]  ? bus_find_device+0xa5/0xe0
&amp;amp;lt;4&amp;amp;gt; [239.331563]  device_driver_detach+0x14/0x20
...
&amp;amp;lt;4&amp;amp;gt; [357.719679] ---[ end trace 0000000000000000 ]---&lt;/p&gt;
&lt;p&gt;If the test also unloads the i915 module then that&amp;amp;apos;s followed with:&lt;/p&gt;
&lt;p&gt;&amp;amp;lt;3&amp;amp;gt; [357.787478] ===…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP1: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;drm/i915/gt: Fix timeline left held on VMA alloc error&lt;/p&gt;
&lt;p&gt;The following error has been reported sporadically by CI when a test
unbinds the i915 driver on a ring submission platform:&lt;/p&gt;
&lt;p&gt;&amp;amp;lt;4&amp;amp;gt; [239.330153] ------------[ cut here ]------------
&amp;amp;lt;4&amp;amp;gt; [239.330166] i915 0000:00:02.0: [drm] drm_WARN_ON(dev_priv-&amp;amp;gt;mm.shrink_count)
&amp;amp;lt;4&amp;amp;gt; [239.330196] WARNING: CPU: 1 PID: 18570 at drivers/gpu/drm/i915/i915_gem.c:1309 i915_gem_cleanup_early+0x13e/0x150 [i915]
...
&amp;amp;lt;4&amp;amp;gt; [239.330640] RIP: 0010:i915_gem_cleanup_early+0x13e/0x150 [i915]
...
&amp;amp;lt;4&amp;amp;gt; [239.330942] Call Trace:
&amp;amp;lt;4&amp;amp;gt; [239.330944]  &amp;amp;lt;TASK&amp;amp;gt;
&amp;amp;lt;4&amp;amp;gt; [239.330949]  i915_driver_late_release+0x2b/0xa0 [i915]
&amp;amp;lt;4&amp;amp;gt; [239.331202]  i915_driver_release+0x86/0xa0 [i915]
&amp;amp;lt;4&amp;amp;gt; [239.331482]  devm_drm_dev_init_release+0x61/0x90
&amp;amp;lt;4&amp;amp;gt; [239.331494]  devm_action_release+0x15/0x30
&amp;amp;lt;4&amp;amp;gt; [239.331504]  release_nodes+0x3d/0x120
&amp;amp;lt;4&amp;amp;gt; [239.331517]  devres_release_all+0x96/0xd0
&amp;amp;lt;4&amp;amp;gt; [239.331533]  device_unbind_cleanup+0x12/0x80
&amp;amp;lt;4&amp;amp;gt; [239.331543]  device_release_driver_internal+0x23a/0x280
&amp;amp;lt;4&amp;amp;gt; [239.331550]  ? bus_find_device+0xa5/0xe0
&amp;amp;lt;4&amp;amp;gt; [239.331563]  device_driver_detach+0x14/0x20
...
&amp;amp;lt;4&amp;amp;gt; [357.719679] ---[ end trace 0000000000000000 ]---&lt;/p&gt;
&lt;p&gt;If the test also unloads the i915 module then that&amp;amp;apos;s followed with:&lt;/p&gt;
&lt;p&gt;&amp;amp;lt;3&amp;amp;gt; [357.787478] ===…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-2675</guid>
    </item>
    <item>
      <title>RHSA-2026:26462 — Red Hat Security Advisory: kernel-rt security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:26462</link>
      <description>&lt;p&gt;kernel: ipv6: use RCU in ip6_xmit() kernel: ipv6: use RCU in ip6_output() kernel: net: use dst_dev_rcu() in sk_setup_caps() kernel: nbd: defer config unlock in nbd_genl_connect kernel: crypto: asymmetric_keys - prevent overflow in asymmetric_key_generate_id kernel: iommu: disable SVA when CONFIG_X86 is set kernel: libceph: make decode_pool() more resilient against corrupted osdmaps kernel: libceph: prevent potential out-of-bounds reads in handle_auth_done() kernel: libceph: replace overzealous BUG_ON in osdmap_apply_incremental() kernel: scsi: target: iscsi: Fix use-after-free in iscsit_dec_conn_usage_count() kernel: netfilter: nf_tables: release flowtable after rcu grace period on error kernel: netfilter: nf_conntrack_h323: check for zero length in DecodeQ931() kernel: netfilter: ip6t_eui64: reject invalid MAC header for all packets kernel: wifi: brcmfmac: validate bsscfg indices in IF events kernel: netfilter: ctnetlink: ensure safe access to master conntrack kernel: xfs: fix freemap adjustments when adding xattrs to leaf blocks kernel: netfilter: xt_tcpmss: check remaining length before reading optlen kernel: mm/page_alloc: clear page-&amp;gt;private in free_pages_prepare() kernel: wifi: mac80211: remove station if connection prep fails kernel: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL kernel: Linux kernel: smb: client: reject userspace cifs.spnego descriptions&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;kernel: ipv6: use RCU in ip6_xmit() kernel: ipv6: use RCU in ip6_output() kernel: net: use dst_dev_rcu() in sk_setup_caps() kernel: nbd: defer config unlock in nbd_genl_connect kernel: crypto: asymmetric_keys - prevent overflow in asymmetric_key_generate_id kernel: iommu: disable SVA when CONFIG_X86 is set kernel: libceph: make decode_pool() more resilient against corrupted osdmaps kernel: libceph: prevent potential out-of-bounds reads in handle_auth_done() kernel: libceph: replace overzealous BUG_ON in osdmap_apply_incremental() kernel: scsi: target: iscsi: Fix use-after-free in iscsit_dec_conn_usage_count() kernel: netfilter: nf_tables: release flowtable after rcu grace period on error kernel: netfilter: nf_conntrack_h323: check for zero length in DecodeQ931() kernel: netfilter: ip6t_eui64: reject invalid MAC header for all packets kernel: wifi: brcmfmac: validate bsscfg indices in IF events kernel: netfilter: ctnetlink: ensure safe access to master conntrack kernel: xfs: fix freemap adjustments when adding xattrs to leaf blocks kernel: netfilter: xt_tcpmss: check remaining length before reading optlen kernel: mm/page_alloc: clear page-&amp;gt;private in free_pages_prepare() kernel: wifi: mac80211: remove station if connection prep fails kernel: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL kernel: Linux kernel: smb: client: reject userspace cifs.spnego descriptions&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:26462</guid>
    </item>
    <item>
      <title>RLSA-2026:21556 — Important: kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:21556</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:9: kernel&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: proc: use the same treatment to check proc_lseek as ones for proc_read_iter et.al (CVE-2025-38653)&lt;/p&gt;
&lt;p&gt;* kernel: ima: don&amp;#39;t clear IMA_DIGSIG flag when setting or removing non-IMA xattr (CVE-2025-68183)&lt;/p&gt;
&lt;p&gt;* kernel: nbd: defer config unlock in nbd_genl_connect (CVE-2025-68366)&lt;/p&gt;
&lt;p&gt;* kernel: crypto: asymmetric_keys - prevent overflow in asymmetric_key_generate_id (CVE-2025-68724)&lt;/p&gt;
&lt;p&gt;* kernel: iommu: disable SVA when CONFIG_X86 is set (CVE-2025-71089)&lt;/p&gt;
&lt;p&gt;* kernel: netfilter: nf_tables: release flowtable after rcu grace period on error (CVE-2026-23392)&lt;/p&gt;
&lt;p&gt;* kernel: netfilter: nf_conntrack_h323: check for zero length in DecodeQ931() (CVE-2026-23455)&lt;/p&gt;
&lt;p&gt;* kernel: Bluetooth: SCO: Fix use-after-free in sco_recv_frame() due to missing sock_hold (CVE-2026-31408)&lt;/p&gt;
&lt;p&gt;* kernel: net: sched: act_csum: validate nested VLAN headers (CVE-2026-31684)&lt;/p&gt;
&lt;p&gt;* kernel: netfilter: ip6t_eui64: reject invalid MAC header for all packets (CVE-2026-31685)&lt;/p&gt;
&lt;p&gt;* kernel: netfilter: nf_conntrack_helper: pass helper to expect cleanup (CVE-2026-43027)&lt;/p&gt;
&lt;p&gt;* kernel: Bluetooth: MGMT: validate LTK enc_size on load (CVE-2026-43020)&lt;/p&gt;
&lt;p&gt;* kernel: HID: wacom: fix out-of-bounds read in wacom_intuos_bt_irq (CVE-2026-43051)&lt;/p&gt;
&lt;p&gt;* kernel: smb: client: validate the whole DACL before rewriting it in cifsacl (CVE-2026-31709)&lt;/p&gt;
&lt;p&gt;* kernel: Bluetooth: SCO: fix race conditions in sco_sock_connect() (CVE-2026-43023)&lt;/p&gt;
&lt;p&gt;* kernel: wifi: brcmfmac: vali…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:9: kernel&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: proc: use the same treatment to check proc_lseek as ones for proc_read_iter et.al (CVE-2025-38653)&lt;/p&gt;
&lt;p&gt;* kernel: ima: don&amp;#39;t clear IMA_DIGSIG flag when setting or removing non-IMA xattr (CVE-2025-68183)&lt;/p&gt;
&lt;p&gt;* kernel: nbd: defer config unlock in nbd_genl_connect (CVE-2025-68366)&lt;/p&gt;
&lt;p&gt;* kernel: crypto: asymmetric_keys - prevent overflow in asymmetric_key_generate_id (CVE-2025-68724)&lt;/p&gt;
&lt;p&gt;* kernel: iommu: disable SVA when CONFIG_X86 is set (CVE-2025-71089)&lt;/p&gt;
&lt;p&gt;* kernel: netfilter: nf_tables: release flowtable after rcu grace period on error (CVE-2026-23392)&lt;/p&gt;
&lt;p&gt;* kernel: netfilter: nf_conntrack_h323: check for zero length in DecodeQ931() (CVE-2026-23455)&lt;/p&gt;
&lt;p&gt;* kernel: Bluetooth: SCO: Fix use-after-free in sco_recv_frame() due to missing sock_hold (CVE-2026-31408)&lt;/p&gt;
&lt;p&gt;* kernel: net: sched: act_csum: validate nested VLAN headers (CVE-2026-31684)&lt;/p&gt;
&lt;p&gt;* kernel: netfilter: ip6t_eui64: reject invalid MAC header for all packets (CVE-2026-31685)&lt;/p&gt;
&lt;p&gt;* kernel: netfilter: nf_conntrack_helper: pass helper to expect cleanup (CVE-2026-43027)&lt;/p&gt;
&lt;p&gt;* kernel: Bluetooth: MGMT: validate LTK enc_size on load (CVE-2026-43020)&lt;/p&gt;
&lt;p&gt;* kernel: HID: wacom: fix out-of-bounds read in wacom_intuos_bt_irq (CVE-2026-43051)&lt;/p&gt;
&lt;p&gt;* kernel: smb: client: validate the whole DACL before rewriting it in cifsacl (CVE-2026-31709)&lt;/p&gt;
&lt;p&gt;* kernel: Bluetooth: SCO: fix race conditions in sco_sock_connect() (CVE-2026-43023)&lt;/p&gt;
&lt;p&gt;* kernel: wifi: brcmfmac: vali…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:21556</guid>
    </item>
    <item>
      <title>SSA-019113 — SSA-019113: Vulnerabilities in the additional GNU/Linux subsystem of the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1.6</title>
      <link>https://cve.radiocsirt.org/vuln/ssa-019113</link>
      <description>&lt;p&gt;Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.6 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant).&lt;/p&gt;
&lt;p&gt;Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.6 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant).&lt;/p&gt;
&lt;p&gt;Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ssa-019113</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:22521-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:22521-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:22521-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-43303</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-43303</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 141 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: mm/page_alloc: clear page-&amp;gt;private in free_pages_prepare() Several subsystems (slub, shmem, ttm, etc.) use page-&amp;gt;private but don&amp;#39;t clear it before freeing pages.  When these pages are later allocated as high-order pages and split via split_page(), tail pages retain stale page-&amp;gt;private values. This causes a use-after-free in the swap subsystem.  The swap code uses page-&amp;gt;private to track swap count continuations, assuming freshly allocated pages have page-&amp;gt;private == 0.  When stale values are present, swap_count_continued() incorrectly assumes the continuation list is valid and iterates over uninitialized page-&amp;gt;lru containing LIST_POISON values, causing a crash:   KASAN: maybe wild-memory-access in range [0xdead000000000100-0xdead000000000107]   RIP: 0010:__do_sys_swapoff+0x1151/0x1860 Fix this by clearing page-&amp;gt;private in free_pages_prepare(), ensuring all freed pages have clean state regardless of previous use.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 141 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: mm/page_alloc: clear page-&amp;gt;private in free_pages_prepare() Several subsystems (slub, shmem, ttm, etc.) use page-&amp;gt;private but don&amp;#39;t clear it before freeing pages.  When these pages are later allocated as high-order pages and split via split_page(), tail pages retain stale page-&amp;gt;private values. This causes a use-after-free in the swap subsystem.  The swap code uses page-&amp;gt;private to track swap count continuations, assuming freshly allocated pages have page-&amp;gt;private == 0.  When stale values are present, swap_count_continued() incorrectly assumes the continuation list is valid and iterates over uninitialized page-&amp;gt;lru containing LIST_POISON values, causing a crash:   KASAN: maybe wild-memory-access in range [0xdead000000000100-0xdead000000000107]   RIP: 0010:__do_sys_swapoff+0x1151/0x1860 Fix this by clearing page-&amp;gt;private in free_pages_prepare(), ensuring all freed pages have clean state regardless of previous use.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-43303</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1454 — Linux Kernel: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1454</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen, möglicherweise Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren oder offenzulegen oder einen Denial-of-Service-Zustand zu verursachen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen, möglicherweise Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren oder offenzulegen oder einen Denial-of-Service-Zustand zu verursachen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1454</guid>
    </item>
  </channel>
</rss>
