<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 17:33:07 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-08879</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-08879</link>
      <description>bdu:2026-08879</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-08879</guid>
    </item>
    <item>
      <title>BELL-CVE-2026-43503</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-43503</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-43503</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0666 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de Debian. Certaines d'entre elles permettent à un…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0666</link>
      <description>certfr-2026-avi-0666</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0666</guid>
    </item>
    <item>
      <title>EUVD-2026-357978</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-357978</link>
      <description>EUVD-2026-357978</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-357978</guid>
    </item>
    <item>
      <title>fkie_cve-2026-43503</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-43503</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;net: skbuff: propagate shared-frag marker through frag-transfer helpers&lt;/p&gt;
&lt;p&gt;Two frag-transfer helpers (__pskb_copy_fclone() and skb_shift()) fail
to propagate the SKBFL_SHARED_FRAG bit in skb_shinfo()-&amp;gt;flags when
moving frags from source to destination.  __pskb_copy_fclone() defers
the rest of the shinfo metadata to skb_copy_header() after copying
frag descriptors, but that helper only carries over gso_{size,segs,
type} and never touches skb_shinfo()-&amp;gt;flags; skb_shift() moves frag
descriptors directly and leaves flags untouched.  As a result, the
destination skb keeps a reference to the same externally-owned or
page-cache-backed pages while reporting skb_has_shared_frag() as
false.&lt;/p&gt;
&lt;p&gt;The mismatch is harmful in any in-place writer that uses
skb_has_shared_frag() to decide whether shared pages must be detoured
through skb_cow_data().  ESP input is one such writer (esp4.c,
esp6.c), and a single nft &amp;#39;dup to &amp;lt;local&amp;gt;&amp;#39; rule -- or any other
nf_dup_ipv4() / xt_TEE caller -- is enough to land a pskb_copy()&amp;#39;d
skb in esp_input() with the marker stripped, letting an unprivileged
user write into the page cache of a root-owned read-only file via
authencesn-ESN stray writes.&lt;/p&gt;
&lt;p&gt;Set SKBFL_SHARED_FRAG on the destination whenever frag descriptors
were actually moved from the source.  skb_copy() and skb_copy_expand()
share skb_copy_header() too but linearize all paged data into freshly
allocated head storage and emerge with nr_frags…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;net: skbuff: propagate shared-frag marker through frag-transfer helpers&lt;/p&gt;
&lt;p&gt;Two frag-transfer helpers (__pskb_copy_fclone() and skb_shift()) fail
to propagate the SKBFL_SHARED_FRAG bit in skb_shinfo()-&amp;gt;flags when
moving frags from source to destination.  __pskb_copy_fclone() defers
the rest of the shinfo metadata to skb_copy_header() after copying
frag descriptors, but that helper only carries over gso_{size,segs,
type} and never touches skb_shinfo()-&amp;gt;flags; skb_shift() moves frag
descriptors directly and leaves flags untouched.  As a result, the
destination skb keeps a reference to the same externally-owned or
page-cache-backed pages while reporting skb_has_shared_frag() as
false.&lt;/p&gt;
&lt;p&gt;The mismatch is harmful in any in-place writer that uses
skb_has_shared_frag() to decide whether shared pages must be detoured
through skb_cow_data().  ESP input is one such writer (esp4.c,
esp6.c), and a single nft &amp;#39;dup to &amp;lt;local&amp;gt;&amp;#39; rule -- or any other
nf_dup_ipv4() / xt_TEE caller -- is enough to land a pskb_copy()&amp;#39;d
skb in esp_input() with the marker stripped, letting an unprivileged
user write into the page cache of a root-owned read-only file via
authencesn-ESN stray writes.&lt;/p&gt;
&lt;p&gt;Set SKBFL_SHARED_FRAG on the destination whenever frag descriptors
were actually moved from the source.  skb_copy() and skb_copy_expand()
share skb_copy_header() too but linearize all paged data into freshly
allocated head storage and emerge with nr_frags…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-43503</guid>
    </item>
    <item>
      <title>GHSA-494p-q444-9xf7</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-494p-q444-9xf7</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;net: skbuff: propagate shared-frag marker through frag-transfer helpers&lt;/p&gt;
&lt;p&gt;Two frag-transfer helpers (__pskb_copy_fclone() and skb_shift()) fail
to propagate the SKBFL_SHARED_FRAG bit in skb_shinfo()-&amp;gt;flags when
moving frags from source to destination.  __pskb_copy_fclone() defers
the rest of the shinfo metadata to skb_copy_header() after copying
frag descriptors, but that helper only carries over gso_{size,segs,
type} and never touches skb_shinfo()-&amp;gt;flags; skb_shift() moves frag
descriptors directly and leaves flags untouched.  As a result, the
destination skb keeps a reference to the same externally-owned or
page-cache-backed pages while reporting skb_has_shared_frag() as
false.&lt;/p&gt;
&lt;p&gt;The mismatch is harmful in any in-place writer that uses
skb_has_shared_frag() to decide whether shared pages must be detoured
through skb_cow_data().  ESP input is one such writer (esp4.c,
esp6.c), and a single nft &amp;#39;dup to &amp;lt;local&amp;gt;&amp;#39; rule -- or any other
nf_dup_ipv4() / xt_TEE caller -- is enough to land a pskb_copy()&amp;#39;d
skb in esp_input() with the marker stripped, letting an unprivileged
user write into the page cache of a root-owned read-only file via
authencesn-ESN stray writes.&lt;/p&gt;
&lt;p&gt;Set SKBFL_SHARED_FRAG on the destination whenever frag descriptors
were actually moved from the source.  skb_copy() and skb_copy_expand()
share skb_copy_header() too but linearize all paged data into freshly
allocated head storage and emerge with nr_frags…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;net: skbuff: propagate shared-frag marker through frag-transfer helpers&lt;/p&gt;
&lt;p&gt;Two frag-transfer helpers (__pskb_copy_fclone() and skb_shift()) fail
to propagate the SKBFL_SHARED_FRAG bit in skb_shinfo()-&amp;gt;flags when
moving frags from source to destination.  __pskb_copy_fclone() defers
the rest of the shinfo metadata to skb_copy_header() after copying
frag descriptors, but that helper only carries over gso_{size,segs,
type} and never touches skb_shinfo()-&amp;gt;flags; skb_shift() moves frag
descriptors directly and leaves flags untouched.  As a result, the
destination skb keeps a reference to the same externally-owned or
page-cache-backed pages while reporting skb_has_shared_frag() as
false.&lt;/p&gt;
&lt;p&gt;The mismatch is harmful in any in-place writer that uses
skb_has_shared_frag() to decide whether shared pages must be detoured
through skb_cow_data().  ESP input is one such writer (esp4.c,
esp6.c), and a single nft &amp;#39;dup to &amp;lt;local&amp;gt;&amp;#39; rule -- or any other
nf_dup_ipv4() / xt_TEE caller -- is enough to land a pskb_copy()&amp;#39;d
skb in esp_input() with the marker stripped, letting an unprivileged
user write into the page cache of a root-owned read-only file via
authencesn-ESN stray writes.&lt;/p&gt;
&lt;p&gt;Set SKBFL_SHARED_FRAG on the destination whenever frag descriptors
were actually moved from the source.  skb_copy() and skb_copy_expand()
share skb_copy_header() too but linearize all paged data into freshly
allocated head storage and emerge with nr_frags…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-494p-q444-9xf7</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-43503 — net: skbuff: propagate shared-frag marker through frag-transfer helpers</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-43503</link>
      <description>msrc_CVE-2026-43503</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-43503</guid>
    </item>
    <item>
      <title>OESA-2026-2496 — kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-2496</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP4: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;Revert &amp;amp;quot;smb: client: fix TCP timers deadlock after rmmod&amp;amp;quot;&lt;/p&gt;
&lt;p&gt;This reverts commit e9f2517a3e18a54a3943c098d2226b245d488801.&lt;/p&gt;
&lt;p&gt;Commit e9f2517a3e18 (&amp;amp;quot;smb: client: fix TCP timers deadlock after
rmmod&amp;amp;quot;) is intended to fix a null-ptr-deref in LOCKDEP, which is
mentioned as CVE-2024-54680, but is actually did not fix anything;
The issue can be reproduced on top of it. [0]&lt;/p&gt;
&lt;p&gt;Also, it reverted the change by commit ef7134c7fc48 (&amp;amp;quot;smb: client:
Fix use-after-free of network namespace.&amp;amp;quot;) and introduced a real
issue by reviving the kernel TCP socket.&lt;/p&gt;
&lt;p&gt;When a reconnect happens for a CIFS connection, the socket state
transitions to FIN_WAIT_1.  Then, inet_csk_clear_xmit_timers_sync()
in tcp_close() stops all timers for the socket.&lt;/p&gt;
&lt;p&gt;If an incoming FIN packet is lost, the socket will stay at FIN_WAIT_1
forever, and such sockets could be leaked up to net.ipv4.tcp_max_orphans.&lt;/p&gt;
&lt;p&gt;Usually, FIN can be retransmitted by the peer, but if the peer aborts
the connection, the issue comes into reality.&lt;/p&gt;
&lt;p&gt;I warned about this privately by pointing out the exact report [1],
but the bogus fix was finally merged.&lt;/p&gt;
&lt;p&gt;So, we should not stop the timers to finally kill the connection on
our side in that case, meaning we must not use a kernel socket for
TCP whose sk-&amp;amp;gt;sk_net_refcnt is 0.&lt;/p&gt;
&lt;p&gt;The kernel socket does not have a reference to its netns to ma…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP4: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;Revert &amp;amp;quot;smb: client: fix TCP timers deadlock after rmmod&amp;amp;quot;&lt;/p&gt;
&lt;p&gt;This reverts commit e9f2517a3e18a54a3943c098d2226b245d488801.&lt;/p&gt;
&lt;p&gt;Commit e9f2517a3e18 (&amp;amp;quot;smb: client: fix TCP timers deadlock after
rmmod&amp;amp;quot;) is intended to fix a null-ptr-deref in LOCKDEP, which is
mentioned as CVE-2024-54680, but is actually did not fix anything;
The issue can be reproduced on top of it. [0]&lt;/p&gt;
&lt;p&gt;Also, it reverted the change by commit ef7134c7fc48 (&amp;amp;quot;smb: client:
Fix use-after-free of network namespace.&amp;amp;quot;) and introduced a real
issue by reviving the kernel TCP socket.&lt;/p&gt;
&lt;p&gt;When a reconnect happens for a CIFS connection, the socket state
transitions to FIN_WAIT_1.  Then, inet_csk_clear_xmit_timers_sync()
in tcp_close() stops all timers for the socket.&lt;/p&gt;
&lt;p&gt;If an incoming FIN packet is lost, the socket will stay at FIN_WAIT_1
forever, and such sockets could be leaked up to net.ipv4.tcp_max_orphans.&lt;/p&gt;
&lt;p&gt;Usually, FIN can be retransmitted by the peer, but if the peer aborts
the connection, the issue comes into reality.&lt;/p&gt;
&lt;p&gt;I warned about this privately by pointing out the exact report [1],
but the bogus fix was finally merged.&lt;/p&gt;
&lt;p&gt;So, we should not stop the timers to finally kill the connection on
our side in that case, meaning we must not use a kernel socket for
TCP whose sk-&amp;amp;gt;sk_net_refcnt is 0.&lt;/p&gt;
&lt;p&gt;The kernel socket does not have a reference to its netns to ma…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-2496</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:10954-1 — kernel-devel-7.0.11-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10954-1</link>
      <description>&lt;p&gt;kernel-devel-7.0.11-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;kernel-devel-7.0.11-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:10954-1</guid>
    </item>
    <item>
      <title>RHSA-2026:19521 — Red Hat Security Advisory: kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:19521</link>
      <description>&lt;p&gt;kernel: Linux kernel: RDMA/rxe use-after-free vulnerability leading to potential arbitrary code execution kernel: ALSA: aloop: Fix racy access at PCM trigger kernel: Linux kernel: Denial of service and memory corruption in RDMA umad kernel: Linux kernel KVM: Privilege escalation or denial of service due to improper shadow page table entry handling kernel: Linux kernel: Use-after-free in bonding driver leads to denial of service kernel: can: raw: fix ro-&amp;gt;uniq use-after-free in raw_rcv() kernel: net: skbuff: propagate shared-frag marker through frag-transfer helpers kernel: &amp;#34;Fragnesia&amp;#34; is a variant of Dirty Frag vulnerability in the ESP/XFRM leading to Local Privilege Escalation (LPE) vulnerability in the Linux kernel kernel: Read root-owned files as an unprivileged user&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;kernel: Linux kernel: RDMA/rxe use-after-free vulnerability leading to potential arbitrary code execution kernel: ALSA: aloop: Fix racy access at PCM trigger kernel: Linux kernel: Denial of service and memory corruption in RDMA umad kernel: Linux kernel KVM: Privilege escalation or denial of service due to improper shadow page table entry handling kernel: Linux kernel: Use-after-free in bonding driver leads to denial of service kernel: can: raw: fix ro-&amp;gt;uniq use-after-free in raw_rcv() kernel: net: skbuff: propagate shared-frag marker through frag-transfer helpers kernel: &amp;#34;Fragnesia&amp;#34; is a variant of Dirty Frag vulnerability in the ESP/XFRM leading to Local Privilege Escalation (LPE) vulnerability in the Linux kernel kernel: Read root-owned files as an unprivileged user&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:19521</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:2111-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:2111-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:2111-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-43503</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-43503</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux, Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe and 244 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: net: skbuff: propagate shared-frag marker through frag-transfer helpers Two frag-transfer helpers (__pskb_copy_fclone() and skb_shift()) fail to propagate the SKBFL_SHARED_FRAG bit in skb_shinfo()-&amp;gt;flags when moving frags from source to destination.  __pskb_copy_fclone() defers the rest of the shinfo metadata to skb_copy_header() after copying frag descriptors, but that helper only carries over gso_{size,segs, type} and never touches skb_shinfo()-&amp;gt;flags; skb_shift() moves frag descriptors directly and leaves flags untouched.  As a result, the destination skb keeps a reference to the same externally-owned or page-cache-backed pages while reporting skb_has_shared_frag() as false. The mismatch is harmful in any in-place writer that uses skb_has_shared_frag() to decide whether shared pages must be detoured through skb_cow_data().  ESP input is one such writer (esp4.c, esp6.c), and a single nft &amp;#39;dup to &amp;lt;local&amp;gt;&amp;#39; rule -- or any other nf_dup_ipv4() / xt_TEE caller -- is enough to land a pskb_copy()&amp;#39;d skb in esp_input() with the marker stripped, letting an unprivileged user write into the page cache of a root-owned read-only file via authencesn-ESN stray writes. Set SKBFL_SHARED_FRAG on the destination whenever frag descriptors were actually moved from the source.  skb_copy() and skb_copy_expand() share skb_copy_header() too but linearize all paged data into freshly allocated head storage and emerge with nr_frags ==…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux, Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe and 244 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: net: skbuff: propagate shared-frag marker through frag-transfer helpers Two frag-transfer helpers (__pskb_copy_fclone() and skb_shift()) fail to propagate the SKBFL_SHARED_FRAG bit in skb_shinfo()-&amp;gt;flags when moving frags from source to destination.  __pskb_copy_fclone() defers the rest of the shinfo metadata to skb_copy_header() after copying frag descriptors, but that helper only carries over gso_{size,segs, type} and never touches skb_shinfo()-&amp;gt;flags; skb_shift() moves frag descriptors directly and leaves flags untouched.  As a result, the destination skb keeps a reference to the same externally-owned or page-cache-backed pages while reporting skb_has_shared_frag() as false. The mismatch is harmful in any in-place writer that uses skb_has_shared_frag() to decide whether shared pages must be detoured through skb_cow_data().  ESP input is one such writer (esp4.c, esp6.c), and a single nft &amp;#39;dup to &amp;lt;local&amp;gt;&amp;#39; rule -- or any other nf_dup_ipv4() / xt_TEE caller -- is enough to land a pskb_copy()&amp;#39;d skb in esp_input() with the marker stripped, letting an unprivileged user write into the page cache of a root-owned read-only file via authencesn-ESN stray writes. Set SKBFL_SHARED_FRAG on the destination whenever frag descriptors were actually moved from the source.  skb_copy() and skb_copy_expand() share skb_copy_header() too but linearize all paged data into freshly allocated head storage and emerge with nr_frags ==…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-43503</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2102 — Linux Kernel: Schwachstelle ermöglicht Erlangen von Administratorrechten</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2102</link>
      <description>&lt;p&gt;Ein lokaler Angreifer kann eine Schwachstelle in Linux Kernel ausnutzen, um Administratorrechte zu erlangen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein lokaler Angreifer kann eine Schwachstelle in Linux Kernel ausnutzen, um Administratorrechte zu erlangen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2102</guid>
    </item>
  </channel>
</rss>
