<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 15:26:07 +0000</lastBuildDate>
    <item>
      <title>ALSA-2026:38491 — Important: kernel security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:38491</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: kernel, AlmaLinux:9: kernel-64k, AlmaLinux:9: kernel-64k-core, AlmaLinux:9: kernel-64k-debug, AlmaLinux:9: kernel-64k-debug-core, AlmaLinux:9: kernel-64k-debug-devel, AlmaLinux:9: kernel-64k-debug-devel-matched, AlmaLinux:9: kernel-64k-debug-modules, AlmaLinux:9: kernel-64k-debug-modules-core, AlmaLinux:9: kernel-64k-debug-modules-extra and 64 more&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: Linux kernel: Memory leak in networking due to incorrect GRO packet handling (CVE-2026-22979)
  * kernel: rtmutex: Use waiter::task instead of current in remove_waiter() (CVE-2026-43499)
  * kernel: net: bridge: use a stable FDB dst snapshot in RCU readers (CVE-2026-46086)
  * kernel: crypto: ccp - copy IV using skcipher ivsize (CVE-2026-53016)
  * kernel: futex/requeue: Prevent NULL pointer dereference in remove_waiter() on self-deadlock (CVE-2026-53166)&lt;/p&gt;
&lt;p&gt;Bug Fix(es) and Enhancement(s):&lt;/p&gt;
&lt;p&gt;* Kernel panic very early during boot while reading a tracefs file (available_filter_functions) due to invalid module name pointer [9.8.z] (JIRA:AlmaLinux-183236)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: kernel, AlmaLinux:9: kernel-64k, AlmaLinux:9: kernel-64k-core, AlmaLinux:9: kernel-64k-debug, AlmaLinux:9: kernel-64k-debug-core, AlmaLinux:9: kernel-64k-debug-devel, AlmaLinux:9: kernel-64k-debug-devel-matched, AlmaLinux:9: kernel-64k-debug-modules, AlmaLinux:9: kernel-64k-debug-modules-core, AlmaLinux:9: kernel-64k-debug-modules-extra and 64 more&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: Linux kernel: Memory leak in networking due to incorrect GRO packet handling (CVE-2026-22979)
  * kernel: rtmutex: Use waiter::task instead of current in remove_waiter() (CVE-2026-43499)
  * kernel: net: bridge: use a stable FDB dst snapshot in RCU readers (CVE-2026-46086)
  * kernel: crypto: ccp - copy IV using skcipher ivsize (CVE-2026-53016)
  * kernel: futex/requeue: Prevent NULL pointer dereference in remove_waiter() on self-deadlock (CVE-2026-53166)&lt;/p&gt;
&lt;p&gt;Bug Fix(es) and Enhancement(s):&lt;/p&gt;
&lt;p&gt;* Kernel panic very early during boot while reading a tracefs file (available_filter_functions) due to invalid module name pointer [9.8.z] (JIRA:AlmaLinux-183236)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:38491</guid>
    </item>
    <item>
      <title>bdu:2026-08889</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-08889</link>
      <description>bdu:2026-08889</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-08889</guid>
    </item>
    <item>
      <title>BELL-CVE-2026-43499</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-43499</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-43499</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0745 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de SUSE. Certaines d'entre elles permettent à un at…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0745</link>
      <description>certfr-2026-avi-0745</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0745</guid>
    </item>
    <item>
      <title>ESSA-2026:0154 — Important: kernel update</title>
      <link>https://cve.radiocsirt.org/vuln/essa-2026:0154</link>
      <description>&lt;p&gt;Important: kernel update&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Important: kernel update&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/essa-2026:0154</guid>
    </item>
    <item>
      <title>EUVD-2026-364804</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-364804</link>
      <description>EUVD-2026-364804</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-364804</guid>
    </item>
    <item>
      <title>fkie_cve-2026-43499</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-43499</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;rtmutex: Use waiter::task instead of current in remove_waiter()&lt;/p&gt;
&lt;p&gt;remove_waiter() is used by the slowlock paths, but it is also used for
proxy-lock rollback in rt_mutex_start_proxy_lock() when invoked from
futex_requeue().&lt;/p&gt;
&lt;p&gt;In the latter case waiter::task is not current, but remove_waiter()
operates on current for the dequeue operation. That results in several
problems:&lt;/p&gt;
&lt;p&gt;1) the rbtree dequeue happens without waiter::task::pi_lock being held&lt;/p&gt;
&lt;p&gt;2) the waiter task&amp;#39;s pi_blocked_on state is not cleared, which leaves a
     dangling pointer primed for UAF around.&lt;/p&gt;
&lt;p&gt;3) rt_mutex_adjust_prio_chain() operates on the wrong top priority waiter
     task&lt;/p&gt;
&lt;p&gt;Use waiter::task instead of current in all related operations in
remove_waiter() to cure those problems.&lt;/p&gt;
&lt;p&gt;[ tglx: Fixup rt_mutex_adjust_prio_chain(), add a comment and amend the
  	changelog ]&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;rtmutex: Use waiter::task instead of current in remove_waiter()&lt;/p&gt;
&lt;p&gt;remove_waiter() is used by the slowlock paths, but it is also used for
proxy-lock rollback in rt_mutex_start_proxy_lock() when invoked from
futex_requeue().&lt;/p&gt;
&lt;p&gt;In the latter case waiter::task is not current, but remove_waiter()
operates on current for the dequeue operation. That results in several
problems:&lt;/p&gt;
&lt;p&gt;1) the rbtree dequeue happens without waiter::task::pi_lock being held&lt;/p&gt;
&lt;p&gt;2) the waiter task&amp;#39;s pi_blocked_on state is not cleared, which leaves a
     dangling pointer primed for UAF around.&lt;/p&gt;
&lt;p&gt;3) rt_mutex_adjust_prio_chain() operates on the wrong top priority waiter
     task&lt;/p&gt;
&lt;p&gt;Use waiter::task instead of current in all related operations in
remove_waiter() to cure those problems.&lt;/p&gt;
&lt;p&gt;[ tglx: Fixup rt_mutex_adjust_prio_chain(), add a comment and amend the
  	changelog ]&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-43499</guid>
    </item>
    <item>
      <title>GHSA-cqc6-9f34-295v</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-cqc6-9f34-295v</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;rtmutex: Use waiter::task instead of current in remove_waiter()&lt;/p&gt;
&lt;p&gt;remove_waiter() is used by the slowlock paths, but it is also used for
proxy-lock rollback in rt_mutex_start_proxy_lock() when invoked from
futex_requeue().&lt;/p&gt;
&lt;p&gt;In the latter case waiter::task is not current, but remove_waiter()
operates on current for the dequeue operation. That results in several
problems:&lt;/p&gt;
&lt;p&gt;1) the rbtree dequeue happens without waiter::task::pi_lock being held&lt;/p&gt;
&lt;p&gt;2) the waiter task&amp;#39;s pi_blocked_on state is not cleared, which leaves a
     dangling pointer primed for UAF around.&lt;/p&gt;
&lt;p&gt;3) rt_mutex_adjust_prio_chain() operates on the wrong top priority waiter
     task&lt;/p&gt;
&lt;p&gt;Use waiter::task instead of current in all related operations in
remove_waiter() to cure those problems.&lt;/p&gt;
&lt;p&gt;[ tglx: Fixup rt_mutex_adjust_prio_chain(), add a comment and amend the
  	changelog ]&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;rtmutex: Use waiter::task instead of current in remove_waiter()&lt;/p&gt;
&lt;p&gt;remove_waiter() is used by the slowlock paths, but it is also used for
proxy-lock rollback in rt_mutex_start_proxy_lock() when invoked from
futex_requeue().&lt;/p&gt;
&lt;p&gt;In the latter case waiter::task is not current, but remove_waiter()
operates on current for the dequeue operation. That results in several
problems:&lt;/p&gt;
&lt;p&gt;1) the rbtree dequeue happens without waiter::task::pi_lock being held&lt;/p&gt;
&lt;p&gt;2) the waiter task&amp;#39;s pi_blocked_on state is not cleared, which leaves a
     dangling pointer primed for UAF around.&lt;/p&gt;
&lt;p&gt;3) rt_mutex_adjust_prio_chain() operates on the wrong top priority waiter
     task&lt;/p&gt;
&lt;p&gt;Use waiter::task instead of current in all related operations in
remove_waiter() to cure those problems.&lt;/p&gt;
&lt;p&gt;[ tglx: Fixup rt_mutex_adjust_prio_chain(), add a comment and amend the
  	changelog ]&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-cqc6-9f34-295v</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-43499 — rtmutex: Use waiter::task instead of current in remove_waiter()</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-43499</link>
      <description>msrc_CVE-2026-43499</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-43499</guid>
    </item>
    <item>
      <title>OESA-2026-2674 — kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-2674</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP4: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;btrfs: qgroup: fix race between quota disable and quota rescan ioctl&lt;/p&gt;
&lt;p&gt;There&amp;amp;apos;s a race between a task disabling quotas and another running the
rescan ioctl that can result in a use-after-free of qgroup records from
the fs_info-&amp;amp;gt;qgroup_tree rbtree.&lt;/p&gt;
&lt;p&gt;This happens as follows:&lt;/p&gt;
&lt;p&gt;1) Task A enters btrfs_ioctl_quota_rescan() -&amp;amp;gt; btrfs_qgroup_rescan();&lt;/p&gt;
&lt;p&gt;2) Task B enters btrfs_quota_disable() and calls
   btrfs_qgroup_wait_for_completion(), which does nothing because at that
   point fs_info-&amp;amp;gt;qgroup_rescan_running is false (it wasn&amp;amp;apos;t set yet by
   task A);&lt;/p&gt;
&lt;p&gt;3) Task B calls btrfs_free_qgroup_config() which starts freeing qgroups
   from fs_info-&amp;amp;gt;qgroup_tree without taking the lock fs_info-&amp;amp;gt;qgroup_lock;&lt;/p&gt;
&lt;p&gt;4) Task A enters qgroup_rescan_zero_tracking() which starts iterating
   the fs_info-&amp;amp;gt;qgroup_tree tree while holding fs_info-&amp;amp;gt;qgroup_lock,
   but task B is freeing qgroup records from that tree without holding
   the lock, resulting in a use-after-free.&lt;/p&gt;
&lt;p&gt;Fix this by taking fs_info-&amp;amp;gt;qgroup_lock at btrfs_free_qgroup_config().
Also at btrfs_qgroup_rescan() don&amp;amp;apos;t start the rescan worker if quotas
were already disabled.(CVE-2025-39759)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;wifi: wilc1000: avoid buffer overflow in WID string configuration&lt;/p&gt;
&lt;p&gt;Fix the following copy overflow warning identi…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP4: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;btrfs: qgroup: fix race between quota disable and quota rescan ioctl&lt;/p&gt;
&lt;p&gt;There&amp;amp;apos;s a race between a task disabling quotas and another running the
rescan ioctl that can result in a use-after-free of qgroup records from
the fs_info-&amp;amp;gt;qgroup_tree rbtree.&lt;/p&gt;
&lt;p&gt;This happens as follows:&lt;/p&gt;
&lt;p&gt;1) Task A enters btrfs_ioctl_quota_rescan() -&amp;amp;gt; btrfs_qgroup_rescan();&lt;/p&gt;
&lt;p&gt;2) Task B enters btrfs_quota_disable() and calls
   btrfs_qgroup_wait_for_completion(), which does nothing because at that
   point fs_info-&amp;amp;gt;qgroup_rescan_running is false (it wasn&amp;amp;apos;t set yet by
   task A);&lt;/p&gt;
&lt;p&gt;3) Task B calls btrfs_free_qgroup_config() which starts freeing qgroups
   from fs_info-&amp;amp;gt;qgroup_tree without taking the lock fs_info-&amp;amp;gt;qgroup_lock;&lt;/p&gt;
&lt;p&gt;4) Task A enters qgroup_rescan_zero_tracking() which starts iterating
   the fs_info-&amp;amp;gt;qgroup_tree tree while holding fs_info-&amp;amp;gt;qgroup_lock,
   but task B is freeing qgroup records from that tree without holding
   the lock, resulting in a use-after-free.&lt;/p&gt;
&lt;p&gt;Fix this by taking fs_info-&amp;amp;gt;qgroup_lock at btrfs_free_qgroup_config().
Also at btrfs_qgroup_rescan() don&amp;amp;apos;t start the rescan worker if quotas
were already disabled.(CVE-2025-39759)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;wifi: wilc1000: avoid buffer overflow in WID string configuration&lt;/p&gt;
&lt;p&gt;Fix the following copy overflow warning identi…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-2674</guid>
    </item>
    <item>
      <title>RHSA-2026:37728 — Red Hat Security Advisory: kernel security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:37728</link>
      <description>&lt;p&gt;kernel: rtmutex: Use waiter::task instead of current in remove_waiter() kernel: futex/requeue: Prevent NULL pointer dereference in remove_waiter() on self-deadlock&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;kernel: rtmutex: Use waiter::task instead of current in remove_waiter() kernel: futex/requeue: Prevent NULL pointer dereference in remove_waiter() on self-deadlock&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:37728</guid>
    </item>
    <item>
      <title>RLSA-2026:38491 — Important: kernel security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:38491</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:9: kernel&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: Linux kernel: Memory leak in networking due to incorrect GRO packet handling (CVE-2026-22979)&lt;/p&gt;
&lt;p&gt;* kernel: rtmutex: Use waiter::task instead of current in remove_waiter() (CVE-2026-43499)&lt;/p&gt;
&lt;p&gt;* kernel: net: bridge: use a stable FDB dst snapshot in RCU readers (CVE-2026-46086)&lt;/p&gt;
&lt;p&gt;* kernel: crypto: ccp - copy IV using skcipher ivsize (CVE-2026-53016)&lt;/p&gt;
&lt;p&gt;* kernel: futex/requeue: Prevent NULL pointer dereference in remove_waiter() on self-deadlock (CVE-2026-53166)&lt;/p&gt;
&lt;p&gt;Bug Fix(es) and Enhancement(s):&lt;/p&gt;
&lt;p&gt;* Kernel panic very early during boot while reading a tracefs file (available_filter_functions) due to invalid module name pointer [9.8.z] (JIRA:Rocky Linux-183236)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:9: kernel&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: Linux kernel: Memory leak in networking due to incorrect GRO packet handling (CVE-2026-22979)&lt;/p&gt;
&lt;p&gt;* kernel: rtmutex: Use waiter::task instead of current in remove_waiter() (CVE-2026-43499)&lt;/p&gt;
&lt;p&gt;* kernel: net: bridge: use a stable FDB dst snapshot in RCU readers (CVE-2026-46086)&lt;/p&gt;
&lt;p&gt;* kernel: crypto: ccp - copy IV using skcipher ivsize (CVE-2026-53016)&lt;/p&gt;
&lt;p&gt;* kernel: futex/requeue: Prevent NULL pointer dereference in remove_waiter() on self-deadlock (CVE-2026-53166)&lt;/p&gt;
&lt;p&gt;Bug Fix(es) and Enhancement(s):&lt;/p&gt;
&lt;p&gt;* Kernel panic very early during boot while reading a tracefs file (available_filter_functions) due to invalid module name pointer [9.8.z] (JIRA:Rocky Linux-183236)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:38491</guid>
    </item>
    <item>
      <title>SSA-019113 — SSA-019113: Vulnerabilities in the additional GNU/Linux subsystem of the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1.6</title>
      <link>https://cve.radiocsirt.org/vuln/ssa-019113</link>
      <description>&lt;p&gt;Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.6 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant).&lt;/p&gt;
&lt;p&gt;Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.6 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant).&lt;/p&gt;
&lt;p&gt;Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ssa-019113</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:22043-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:22043-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:22043-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-43499</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-43499</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux, Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe and 245 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: rtmutex: Use waiter::task instead of current in remove_waiter() remove_waiter() is used by the slowlock paths, but it is also used for proxy-lock rollback in rt_mutex_start_proxy_lock() when invoked from futex_requeue(). In the latter case waiter::task is not current, but remove_waiter() operates on current for the dequeue operation. That results in several problems:   1) the rbtree dequeue happens without waiter::task::pi_lock being held   2) the waiter task&amp;#39;s pi_blocked_on state is not cleared, which leaves a      dangling pointer primed for UAF around.   3) rt_mutex_adjust_prio_chain() operates on the wrong top priority waiter      task Use waiter::task instead of current in all related operations in remove_waiter() to cure those problems. [ tglx: Fixup rt_mutex_adjust_prio_chain(), add a comment and amend the   	changelog ]&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux, Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe and 245 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: rtmutex: Use waiter::task instead of current in remove_waiter() remove_waiter() is used by the slowlock paths, but it is also used for proxy-lock rollback in rt_mutex_start_proxy_lock() when invoked from futex_requeue(). In the latter case waiter::task is not current, but remove_waiter() operates on current for the dequeue operation. That results in several problems:   1) the rbtree dequeue happens without waiter::task::pi_lock being held   2) the waiter task&amp;#39;s pi_blocked_on state is not cleared, which leaves a      dangling pointer primed for UAF around.   3) rt_mutex_adjust_prio_chain() operates on the wrong top priority waiter      task Use waiter::task instead of current in all related operations in remove_waiter() to cure those problems. [ tglx: Fixup rt_mutex_adjust_prio_chain(), add a comment and amend the   	changelog ]&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-43499</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1656 — Linux Kernel: Mehrere Schwachstellen ermöglichen nicht spezifizierten Angriff</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1656</link>
      <description>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um seine Privilegien zu eskalieren oder nicht näher spezifizierte Angriffe durchzuführen, darunter möglicherweise Denial-of-Service-Angriffe, Speicherbeschädigungen oder die Offenlegung von Informationen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um seine Privilegien zu eskalieren oder nicht näher spezifizierte Angriffe durchzuführen, darunter möglicherweise Denial-of-Service-Angriffe, Speicherbeschädigungen oder die Offenlegung von Informationen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1656</guid>
    </item>
  </channel>
</rss>
