<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 11:34:58 +0000</lastBuildDate>
    <item>
      <title>ALSA-2026:25191 — Critical: kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:25191</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: kernel, AlmaLinux:10: kernel-64k, AlmaLinux:10: kernel-64k-core, AlmaLinux:10: kernel-64k-debug, AlmaLinux:10: kernel-64k-debug-core, AlmaLinux:10: kernel-64k-debug-devel, AlmaLinux:10: kernel-64k-debug-devel-matched, AlmaLinux:10: kernel-64k-debug-modules, AlmaLinux:10: kernel-64k-debug-modules-core, AlmaLinux:10: kernel-64k-debug-modules-extra and 65 more&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: Linux kernel: Use-after-free in bonding driver leads to denial of service (CVE-2026-31419)
  * kernel: Linux kernel: Denial of Service in erofs filesystem (CVE-2026-31467)
  * kernel: can: raw: fix ro-&amp;gt;uniq use-after-free in raw_rcv() (CVE-2026-31532)
  * kernel: ALSA: 6fire: fix use-after-free on disconnect (CVE-2026-31581)
  * kernel: ip6_tunnel: clear skb2-&amp;gt;cb[] in ip4ip6_err() (CVE-2026-43037)
  * kernel: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (CVE-2026-43501)
  * kernel: selinux: fix overlayfs mmap() and mprotect() access checks (CVE-2026-46054)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: kernel, AlmaLinux:10: kernel-64k, AlmaLinux:10: kernel-64k-core, AlmaLinux:10: kernel-64k-debug, AlmaLinux:10: kernel-64k-debug-core, AlmaLinux:10: kernel-64k-debug-devel, AlmaLinux:10: kernel-64k-debug-devel-matched, AlmaLinux:10: kernel-64k-debug-modules, AlmaLinux:10: kernel-64k-debug-modules-core, AlmaLinux:10: kernel-64k-debug-modules-extra and 65 more&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: Linux kernel: Use-after-free in bonding driver leads to denial of service (CVE-2026-31419)
  * kernel: Linux kernel: Denial of Service in erofs filesystem (CVE-2026-31467)
  * kernel: can: raw: fix ro-&amp;gt;uniq use-after-free in raw_rcv() (CVE-2026-31532)
  * kernel: ALSA: 6fire: fix use-after-free on disconnect (CVE-2026-31581)
  * kernel: ip6_tunnel: clear skb2-&amp;gt;cb[] in ip4ip6_err() (CVE-2026-43037)
  * kernel: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (CVE-2026-43501)
  * kernel: selinux: fix overlayfs mmap() and mprotect() access checks (CVE-2026-46054)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:25191</guid>
    </item>
    <item>
      <title>bdu:2026-09229</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-09229</link>
      <description>bdu:2026-09229</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-09229</guid>
    </item>
    <item>
      <title>BELL-CVE-2026-43501</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-43501</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-43501</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0745 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de SUSE. Certaines d'entre elles permettent à un at…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0745</link>
      <description>certfr-2026-avi-0745</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0745</guid>
    </item>
    <item>
      <title>ESSA-2026:0153 — Important: kernel security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/essa-2026:0153</link>
      <description>&lt;p&gt;Important: kernel security, bug fix, and enhancement update&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Important: kernel security, bug fix, and enhancement update&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/essa-2026:0153</guid>
    </item>
    <item>
      <title>EUVD-2026-364805</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-364805</link>
      <description>EUVD-2026-364805</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-364805</guid>
    </item>
    <item>
      <title>fkie_cve-2026-43501</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-43501</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;ipv6: rpl: reserve mac_len headroom when recompressed SRH grows&lt;/p&gt;
&lt;p&gt;ipv6_rpl_srh_rcv() decompresses an RFC 6554 Source Routing Header, swaps
the next segment into ipv6_hdr-&amp;gt;daddr, recompresses, then pulls the old
header and pushes the new one plus the IPv6 header back.  The
recompressed header can be larger than the received one when the swap
reduces the common-prefix length the segments share with daddr (CmprI=0,
CmprE&amp;gt;0, seg[0][0] != daddr[0] gives the maximum +8 bytes).&lt;/p&gt;
&lt;p&gt;pskb_expand_head() was gated on segments_left == 0, so on earlier
segments the push consumed unchecked headroom.  Once skb_push() leaves
fewer than skb-&amp;gt;mac_len bytes in front of data,
skb_mac_header_rebuild()&amp;#39;s call to:&lt;/p&gt;
&lt;p&gt;skb_set_mac_header(skb, -skb-&amp;gt;mac_len);&lt;/p&gt;
&lt;p&gt;will store (data - head) - mac_len into the u16 mac_header field, which
wraps to ~65530, and the following memmove() writes mac_len bytes ~64KiB
past skb-&amp;gt;head.&lt;/p&gt;
&lt;p&gt;A single AF_INET6/SOCK_RAW/IPV6_HDRINCL packet over lo with a two
segment type-3 SRH (CmprI=0, CmprE=15) reaches headroom 8 after one
pass; KASAN reports a 14-byte OOB write in ipv6_rthdr_rcv.&lt;/p&gt;
&lt;p&gt;Fix this by expanding the head whenever the remaining room is less than
the push size plus mac_len, and request that much extra so the rebuilt
MAC header fits afterwards.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;ipv6: rpl: reserve mac_len headroom when recompressed SRH grows&lt;/p&gt;
&lt;p&gt;ipv6_rpl_srh_rcv() decompresses an RFC 6554 Source Routing Header, swaps
the next segment into ipv6_hdr-&amp;gt;daddr, recompresses, then pulls the old
header and pushes the new one plus the IPv6 header back.  The
recompressed header can be larger than the received one when the swap
reduces the common-prefix length the segments share with daddr (CmprI=0,
CmprE&amp;gt;0, seg[0][0] != daddr[0] gives the maximum +8 bytes).&lt;/p&gt;
&lt;p&gt;pskb_expand_head() was gated on segments_left == 0, so on earlier
segments the push consumed unchecked headroom.  Once skb_push() leaves
fewer than skb-&amp;gt;mac_len bytes in front of data,
skb_mac_header_rebuild()&amp;#39;s call to:&lt;/p&gt;
&lt;p&gt;skb_set_mac_header(skb, -skb-&amp;gt;mac_len);&lt;/p&gt;
&lt;p&gt;will store (data - head) - mac_len into the u16 mac_header field, which
wraps to ~65530, and the following memmove() writes mac_len bytes ~64KiB
past skb-&amp;gt;head.&lt;/p&gt;
&lt;p&gt;A single AF_INET6/SOCK_RAW/IPV6_HDRINCL packet over lo with a two
segment type-3 SRH (CmprI=0, CmprE=15) reaches headroom 8 after one
pass; KASAN reports a 14-byte OOB write in ipv6_rthdr_rcv.&lt;/p&gt;
&lt;p&gt;Fix this by expanding the head whenever the remaining room is less than
the push size plus mac_len, and request that much extra so the rebuilt
MAC header fits afterwards.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-43501</guid>
    </item>
    <item>
      <title>GHSA-fqx3-r8j8-73qq</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-fqx3-r8j8-73qq</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;ipv6: rpl: reserve mac_len headroom when recompressed SRH grows&lt;/p&gt;
&lt;p&gt;ipv6_rpl_srh_rcv() decompresses an RFC 6554 Source Routing Header, swaps
the next segment into ipv6_hdr-&amp;gt;daddr, recompresses, then pulls the old
header and pushes the new one plus the IPv6 header back.  The
recompressed header can be larger than the received one when the swap
reduces the common-prefix length the segments share with daddr (CmprI=0,
CmprE&amp;gt;0, seg[0][0] != daddr[0] gives the maximum +8 bytes).&lt;/p&gt;
&lt;p&gt;pskb_expand_head() was gated on segments_left == 0, so on earlier
segments the push consumed unchecked headroom.  Once skb_push() leaves
fewer than skb-&amp;gt;mac_len bytes in front of data,
skb_mac_header_rebuild()&amp;#39;s call to:&lt;/p&gt;
&lt;p&gt;skb_set_mac_header(skb, -skb-&amp;gt;mac_len);&lt;/p&gt;
&lt;p&gt;will store (data - head) - mac_len into the u16 mac_header field, which
wraps to ~65530, and the following memmove() writes mac_len bytes ~64KiB
past skb-&amp;gt;head.&lt;/p&gt;
&lt;p&gt;A single AF_INET6/SOCK_RAW/IPV6_HDRINCL packet over lo with a two
segment type-3 SRH (CmprI=0, CmprE=15) reaches headroom 8 after one
pass; KASAN reports a 14-byte OOB write in ipv6_rthdr_rcv.&lt;/p&gt;
&lt;p&gt;Fix this by expanding the head whenever the remaining room is less than
the push size plus mac_len, and request that much extra so the rebuilt
MAC header fits afterwards.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;ipv6: rpl: reserve mac_len headroom when recompressed SRH grows&lt;/p&gt;
&lt;p&gt;ipv6_rpl_srh_rcv() decompresses an RFC 6554 Source Routing Header, swaps
the next segment into ipv6_hdr-&amp;gt;daddr, recompresses, then pulls the old
header and pushes the new one plus the IPv6 header back.  The
recompressed header can be larger than the received one when the swap
reduces the common-prefix length the segments share with daddr (CmprI=0,
CmprE&amp;gt;0, seg[0][0] != daddr[0] gives the maximum +8 bytes).&lt;/p&gt;
&lt;p&gt;pskb_expand_head() was gated on segments_left == 0, so on earlier
segments the push consumed unchecked headroom.  Once skb_push() leaves
fewer than skb-&amp;gt;mac_len bytes in front of data,
skb_mac_header_rebuild()&amp;#39;s call to:&lt;/p&gt;
&lt;p&gt;skb_set_mac_header(skb, -skb-&amp;gt;mac_len);&lt;/p&gt;
&lt;p&gt;will store (data - head) - mac_len into the u16 mac_header field, which
wraps to ~65530, and the following memmove() writes mac_len bytes ~64KiB
past skb-&amp;gt;head.&lt;/p&gt;
&lt;p&gt;A single AF_INET6/SOCK_RAW/IPV6_HDRINCL packet over lo with a two
segment type-3 SRH (CmprI=0, CmprE=15) reaches headroom 8 after one
pass; KASAN reports a 14-byte OOB write in ipv6_rthdr_rcv.&lt;/p&gt;
&lt;p&gt;Fix this by expanding the head whenever the remaining room is less than
the push size plus mac_len, and request that much extra so the rebuilt
MAC header fits afterwards.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-fqx3-r8j8-73qq</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-43501 — ipv6: rpl: reserve mac_len headroom when recompressed SRH grows</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-43501</link>
      <description>msrc_CVE-2026-43501</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-43501</guid>
    </item>
    <item>
      <title>RHSA-2026:27713 — Red Hat Security Advisory: kernel security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:27713</link>
      <description>&lt;p&gt;kernel: netfilter: nf_conntrack_h323: check for zero length in DecodeQ931() kernel: mptcp: fix slab-use-after-free in __inet_lookup_established kernel: RDMA/umem: Fix double dma_buf_unpin in failure path kernel: netfilter: flowtable: strictly check for maximum number of actions kernel: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows kernel: RDMA/rxe: Fix double free in rxe_srq_from_init kernel: exit: prevent preemption of oopsing TASK_DEAD task kernel: net/sched: act_pedit: extend the writable skb range per key&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;kernel: netfilter: nf_conntrack_h323: check for zero length in DecodeQ931() kernel: mptcp: fix slab-use-after-free in __inet_lookup_established kernel: RDMA/umem: Fix double dma_buf_unpin in failure path kernel: netfilter: flowtable: strictly check for maximum number of actions kernel: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows kernel: RDMA/rxe: Fix double free in rxe_srq_from_init kernel: exit: prevent preemption of oopsing TASK_DEAD task kernel: net/sched: act_pedit: extend the writable skb range per key&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:27713</guid>
    </item>
    <item>
      <title>RLSA-2026:25191 — Critical: kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:25191</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: kernel&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: Linux kernel: Use-after-free in bonding driver leads to denial of service (CVE-2026-31419)&lt;/p&gt;
&lt;p&gt;* kernel: Linux kernel: Denial of Service in erofs filesystem (CVE-2026-31467)&lt;/p&gt;
&lt;p&gt;* kernel: can: raw: fix ro-&amp;gt;uniq use-after-free in raw_rcv() (CVE-2026-31532)&lt;/p&gt;
&lt;p&gt;* kernel: ALSA: 6fire: fix use-after-free on disconnect (CVE-2026-31581)&lt;/p&gt;
&lt;p&gt;* kernel: ip6_tunnel: clear skb2-&amp;gt;cb[] in ip4ip6_err() (CVE-2026-43037)&lt;/p&gt;
&lt;p&gt;* kernel: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (CVE-2026-43501)&lt;/p&gt;
&lt;p&gt;* kernel: selinux: fix overlayfs mmap() and mprotect() access checks (CVE-2026-46054)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: kernel&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: Linux kernel: Use-after-free in bonding driver leads to denial of service (CVE-2026-31419)&lt;/p&gt;
&lt;p&gt;* kernel: Linux kernel: Denial of Service in erofs filesystem (CVE-2026-31467)&lt;/p&gt;
&lt;p&gt;* kernel: can: raw: fix ro-&amp;gt;uniq use-after-free in raw_rcv() (CVE-2026-31532)&lt;/p&gt;
&lt;p&gt;* kernel: ALSA: 6fire: fix use-after-free on disconnect (CVE-2026-31581)&lt;/p&gt;
&lt;p&gt;* kernel: ip6_tunnel: clear skb2-&amp;gt;cb[] in ip4ip6_err() (CVE-2026-43037)&lt;/p&gt;
&lt;p&gt;* kernel: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (CVE-2026-43501)&lt;/p&gt;
&lt;p&gt;* kernel: selinux: fix overlayfs mmap() and mprotect() access checks (CVE-2026-46054)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:25191</guid>
    </item>
    <item>
      <title>SSA-019113 — SSA-019113: Vulnerabilities in the additional GNU/Linux subsystem of the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1.6</title>
      <link>https://cve.radiocsirt.org/vuln/ssa-019113</link>
      <description>&lt;p&gt;Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.6 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant).&lt;/p&gt;
&lt;p&gt;Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.6 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant).&lt;/p&gt;
&lt;p&gt;Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ssa-019113</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:22108-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:22108-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:22108-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-43501</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-43501</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 192 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows ipv6_rpl_srh_rcv() decompresses an RFC 6554 Source Routing Header, swaps the next segment into ipv6_hdr-&amp;gt;daddr, recompresses, then pulls the old header and pushes the new one plus the IPv6 header back.  The recompressed header can be larger than the received one when the swap reduces the common-prefix length the segments share with daddr (CmprI=0, CmprE&amp;gt;0, seg[0][0] != daddr[0] gives the maximum +8 bytes). pskb_expand_head() was gated on segments_left == 0, so on earlier segments the push consumed unchecked headroom.  Once skb_push() leaves fewer than skb-&amp;gt;mac_len bytes in front of data, skb_mac_header_rebuild()&amp;#39;s call to: 	skb_set_mac_header(skb, -skb-&amp;gt;mac_len); will store (data - head) - mac_len into the u16 mac_header field, which wraps to ~65530, and the following memmove() writes mac_len bytes ~64KiB past skb-&amp;gt;head. A single AF_INET6/SOCK_RAW/IPV6_HDRINCL packet over lo with a two segment type-3 SRH (CmprI=0, CmprE=15) reaches headroom 8 after one pass; KASAN reports a 14-byte OOB write in ipv6_rthdr_rcv. Fix this by expanding the head whenever the remaining room is less than the push size plus mac_len, and request that much extra so the rebuilt MAC header fits afterwards.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 192 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows ipv6_rpl_srh_rcv() decompresses an RFC 6554 Source Routing Header, swaps the next segment into ipv6_hdr-&amp;gt;daddr, recompresses, then pulls the old header and pushes the new one plus the IPv6 header back.  The recompressed header can be larger than the received one when the swap reduces the common-prefix length the segments share with daddr (CmprI=0, CmprE&amp;gt;0, seg[0][0] != daddr[0] gives the maximum +8 bytes). pskb_expand_head() was gated on segments_left == 0, so on earlier segments the push consumed unchecked headroom.  Once skb_push() leaves fewer than skb-&amp;gt;mac_len bytes in front of data, skb_mac_header_rebuild()&amp;#39;s call to: 	skb_set_mac_header(skb, -skb-&amp;gt;mac_len); will store (data - head) - mac_len into the u16 mac_header field, which wraps to ~65530, and the following memmove() writes mac_len bytes ~64KiB past skb-&amp;gt;head. A single AF_INET6/SOCK_RAW/IPV6_HDRINCL packet over lo with a two segment type-3 SRH (CmprI=0, CmprE=15) reaches headroom 8 after one pass; KASAN reports a 14-byte OOB write in ipv6_rthdr_rcv. Fix this by expanding the head whenever the remaining room is less than the push size plus mac_len, and request that much extra so the rebuilt MAC header fits afterwards.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-43501</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1656 — Linux Kernel: Mehrere Schwachstellen ermöglichen nicht spezifizierten Angriff</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1656</link>
      <description>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um seine Privilegien zu eskalieren oder nicht näher spezifizierte Angriffe durchzuführen, darunter möglicherweise Denial-of-Service-Angriffe, Speicherbeschädigungen oder die Offenlegung von Informationen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um seine Privilegien zu eskalieren oder nicht näher spezifizierte Angriffe durchzuführen, darunter möglicherweise Denial-of-Service-Angriffe, Speicherbeschädigungen oder die Offenlegung von Informationen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1656</guid>
    </item>
  </channel>
</rss>
