<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 15:30:40 +0000</lastBuildDate>
    <item>
      <title>BELL-CVE-2026-45956</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-45956</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-45956</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0696 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de Debian LTS. Certaines d'entre elles permettent à…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0696</link>
      <description>certfr-2026-avi-0696</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0696</guid>
    </item>
    <item>
      <title>EUVD-2026-347970</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-347970</link>
      <description>EUVD-2026-347970</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-347970</guid>
    </item>
    <item>
      <title>fkie_cve-2026-45956</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-45956</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;drm/exynos: vidi: use priv-&amp;gt;vidi_dev for ctx lookup in vidi_connection_ioctl()&lt;/p&gt;
&lt;p&gt;vidi_connection_ioctl() retrieves the driver_data from drm_dev-&amp;gt;dev to
obtain a struct vidi_context pointer. However, drm_dev-&amp;gt;dev is the
exynos-drm master device, and the driver_data contained therein is not
the vidi component device, but a completely different device.&lt;/p&gt;
&lt;p&gt;This can lead to various bugs, ranging from null pointer dereferences and
garbage value accesses to, in unlucky cases, out-of-bounds errors,
use-after-free errors, and more.&lt;/p&gt;
&lt;p&gt;To resolve this issue, we need to store/delete the vidi device pointer in
exynos_drm_private-&amp;gt;vidi_dev during bind/unbind, and then read this
exynos_drm_private-&amp;gt;vidi_dev within ioctl() to obtain the correct
struct vidi_context pointer.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;drm/exynos: vidi: use priv-&amp;gt;vidi_dev for ctx lookup in vidi_connection_ioctl()&lt;/p&gt;
&lt;p&gt;vidi_connection_ioctl() retrieves the driver_data from drm_dev-&amp;gt;dev to
obtain a struct vidi_context pointer. However, drm_dev-&amp;gt;dev is the
exynos-drm master device, and the driver_data contained therein is not
the vidi component device, but a completely different device.&lt;/p&gt;
&lt;p&gt;This can lead to various bugs, ranging from null pointer dereferences and
garbage value accesses to, in unlucky cases, out-of-bounds errors,
use-after-free errors, and more.&lt;/p&gt;
&lt;p&gt;To resolve this issue, we need to store/delete the vidi device pointer in
exynos_drm_private-&amp;gt;vidi_dev during bind/unbind, and then read this
exynos_drm_private-&amp;gt;vidi_dev within ioctl() to obtain the correct
struct vidi_context pointer.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-45956</guid>
    </item>
    <item>
      <title>GHSA-pwfh-32f2-c83x</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-pwfh-32f2-c83x</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;drm/exynos: vidi: use priv-&amp;gt;vidi_dev for ctx lookup in vidi_connection_ioctl()&lt;/p&gt;
&lt;p&gt;vidi_connection_ioctl() retrieves the driver_data from drm_dev-&amp;gt;dev to
obtain a struct vidi_context pointer. However, drm_dev-&amp;gt;dev is the
exynos-drm master device, and the driver_data contained therein is not
the vidi component device, but a completely different device.&lt;/p&gt;
&lt;p&gt;This can lead to various bugs, ranging from null pointer dereferences and
garbage value accesses to, in unlucky cases, out-of-bounds errors,
use-after-free errors, and more.&lt;/p&gt;
&lt;p&gt;To resolve this issue, we need to store/delete the vidi device pointer in
exynos_drm_private-&amp;gt;vidi_dev during bind/unbind, and then read this
exynos_drm_private-&amp;gt;vidi_dev within ioctl() to obtain the correct
struct vidi_context pointer.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;drm/exynos: vidi: use priv-&amp;gt;vidi_dev for ctx lookup in vidi_connection_ioctl()&lt;/p&gt;
&lt;p&gt;vidi_connection_ioctl() retrieves the driver_data from drm_dev-&amp;gt;dev to
obtain a struct vidi_context pointer. However, drm_dev-&amp;gt;dev is the
exynos-drm master device, and the driver_data contained therein is not
the vidi component device, but a completely different device.&lt;/p&gt;
&lt;p&gt;This can lead to various bugs, ranging from null pointer dereferences and
garbage value accesses to, in unlucky cases, out-of-bounds errors,
use-after-free errors, and more.&lt;/p&gt;
&lt;p&gt;To resolve this issue, we need to store/delete the vidi device pointer in
exynos_drm_private-&amp;gt;vidi_dev during bind/unbind, and then read this
exynos_drm_private-&amp;gt;vidi_dev within ioctl() to obtain the correct
struct vidi_context pointer.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-pwfh-32f2-c83x</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-45956 — drm/exynos: vidi: use priv-&gt;vidi_dev for ctx lookup in vidi_connection_ioctl()</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-45956</link>
      <description>msrc_CVE-2026-45956</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-45956</guid>
    </item>
    <item>
      <title>OESA-2026-3156 — kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-3156</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP4: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;drbd: add missing kref_get in handle_write_conflicts&lt;/p&gt;
&lt;p&gt;With `two-primaries` enabled, DRBD tries to detect &amp;amp;quot;concurrent&amp;amp;quot; writes
and handle write conflicts, so that even if you write to the same sector
simultaneously on both nodes, they end up with the identical data once
the writes are completed.&lt;/p&gt;
&lt;p&gt;In handling &amp;amp;quot;superseeded&amp;amp;quot; writes, we forgot a kref_get,
resulting in a premature drbd_destroy_device and use after free,
and further to kernel crashes with symptoms.&lt;/p&gt;
&lt;p&gt;Relevance: No one should use DRBD as a random data generator, and apparently
all users of &amp;amp;quot;two-primaries&amp;amp;quot; handle concurrent writes correctly on layer up.
That is cluster file systems use some distributed lock manager,
and live migration in virtualization environments stops writes on one node
before starting writes on the other node.&lt;/p&gt;
&lt;p&gt;Which means that other than for &amp;amp;quot;test cases&amp;amp;quot;,
this code path is never taken in real life.&lt;/p&gt;
&lt;p&gt;FYI, in DRBD 9, things are handled differently nowadays.  We still detect
&amp;amp;quot;write conflicts&amp;amp;quot;, but no longer try to be smart about them.
We decided to disconnect hard instead: upper layers must not submit concurrent
writes. If they do, that&amp;amp;apos;s their fault.(CVE-2025-38708)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;wifi: mwifiex: Initialize the chan_stats array to zero&lt;/p&gt;
&lt;p&gt;The adapter-&amp;amp;gt…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP4: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;drbd: add missing kref_get in handle_write_conflicts&lt;/p&gt;
&lt;p&gt;With `two-primaries` enabled, DRBD tries to detect &amp;amp;quot;concurrent&amp;amp;quot; writes
and handle write conflicts, so that even if you write to the same sector
simultaneously on both nodes, they end up with the identical data once
the writes are completed.&lt;/p&gt;
&lt;p&gt;In handling &amp;amp;quot;superseeded&amp;amp;quot; writes, we forgot a kref_get,
resulting in a premature drbd_destroy_device and use after free,
and further to kernel crashes with symptoms.&lt;/p&gt;
&lt;p&gt;Relevance: No one should use DRBD as a random data generator, and apparently
all users of &amp;amp;quot;two-primaries&amp;amp;quot; handle concurrent writes correctly on layer up.
That is cluster file systems use some distributed lock manager,
and live migration in virtualization environments stops writes on one node
before starting writes on the other node.&lt;/p&gt;
&lt;p&gt;Which means that other than for &amp;amp;quot;test cases&amp;amp;quot;,
this code path is never taken in real life.&lt;/p&gt;
&lt;p&gt;FYI, in DRBD 9, things are handled differently nowadays.  We still detect
&amp;amp;quot;write conflicts&amp;amp;quot;, but no longer try to be smart about them.
We decided to disconnect hard instead: upper layers must not submit concurrent
writes. If they do, that&amp;amp;apos;s their fault.(CVE-2025-38708)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;wifi: mwifiex: Initialize the chan_stats array to zero&lt;/p&gt;
&lt;p&gt;The adapter-&amp;amp;gt…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-3156</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-45956</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-45956</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe, Ubuntu:16.04:LTS: linux-hwe-edge and 231 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: drm/exynos: vidi: use priv-&amp;gt;vidi_dev for ctx lookup in vidi_connection_ioctl() vidi_connection_ioctl() retrieves the driver_data from drm_dev-&amp;gt;dev to obtain a struct vidi_context pointer. However, drm_dev-&amp;gt;dev is the exynos-drm master device, and the driver_data contained therein is not the vidi component device, but a completely different device. This can lead to various bugs, ranging from null pointer dereferences and garbage value accesses to, in unlucky cases, out-of-bounds errors, use-after-free errors, and more. To resolve this issue, we need to store/delete the vidi device pointer in exynos_drm_private-&amp;gt;vidi_dev during bind/unbind, and then read this exynos_drm_private-&amp;gt;vidi_dev within ioctl() to obtain the correct struct vidi_context pointer.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe, Ubuntu:16.04:LTS: linux-hwe-edge and 231 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: drm/exynos: vidi: use priv-&amp;gt;vidi_dev for ctx lookup in vidi_connection_ioctl() vidi_connection_ioctl() retrieves the driver_data from drm_dev-&amp;gt;dev to obtain a struct vidi_context pointer. However, drm_dev-&amp;gt;dev is the exynos-drm master device, and the driver_data contained therein is not the vidi component device, but a completely different device. This can lead to various bugs, ranging from null pointer dereferences and garbage value accesses to, in unlucky cases, out-of-bounds errors, use-after-free errors, and more. To resolve this issue, we need to store/delete the vidi device pointer in exynos_drm_private-&amp;gt;vidi_dev during bind/unbind, and then read this exynos_drm_private-&amp;gt;vidi_dev within ioctl() to obtain the correct struct vidi_context pointer.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-45956</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1700 — Linux Kernel: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1700</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen oder andere nicht näher spezifizierte Auswirkungen zu erzielen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen oder andere nicht näher spezifizierte Auswirkungen zu erzielen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1700</guid>
    </item>
  </channel>
</rss>
