<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 19:35:42 +0000</lastBuildDate>
    <item>
      <title>BELL-CVE-2026-46076</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-46076</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-46076</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0831 — De multiples vulnérabilités ont été découvertes dans le noyau Linux d'Ubuntu. Certaines d'entre elles permettent à un a…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0831</link>
      <description>certfr-2026-avi-0831</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0831</guid>
    </item>
    <item>
      <title>EUVD-2026-347997</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-347997</link>
      <description>EUVD-2026-347997</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-347997</guid>
    </item>
    <item>
      <title>fkie_cve-2026-46076</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-46076</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;KVM: nSVM: Raise #UD if unhandled VMMCALL isn&amp;#39;t intercepted by L1&lt;/p&gt;
&lt;p&gt;Explicitly synthesize a #UD for VMMCALL if L2 is active, L1 does NOT want
to intercept VMMCALL, nested_svm_l2_tlb_flush_enabled() is true, and the
hypercall is something other than one of the supported Hyper-V hypercalls.
When all of the above conditions are met, KVM will intercept VMMCALL but
never forward it to L1, i.e. will let L2 make hypercalls as if it were L1.&lt;/p&gt;
&lt;p&gt;The TLFS says a whole lot of nothing about this scenario, so go with the
architectural behavior, which says that VMMCALL #UDs if it&amp;#39;s not
intercepted.&lt;/p&gt;
&lt;p&gt;Opportunistically do a 2-for-1 stub trade by stub-ifying the new API
instead of the helpers it uses.  The last remaining &amp;#34;single&amp;#34; stub will
soon be dropped as well.&lt;/p&gt;
&lt;p&gt;[sean: rewrite changelog and comment, tag for stable, remove defunct stubs]&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;KVM: nSVM: Raise #UD if unhandled VMMCALL isn&amp;#39;t intercepted by L1&lt;/p&gt;
&lt;p&gt;Explicitly synthesize a #UD for VMMCALL if L2 is active, L1 does NOT want
to intercept VMMCALL, nested_svm_l2_tlb_flush_enabled() is true, and the
hypercall is something other than one of the supported Hyper-V hypercalls.
When all of the above conditions are met, KVM will intercept VMMCALL but
never forward it to L1, i.e. will let L2 make hypercalls as if it were L1.&lt;/p&gt;
&lt;p&gt;The TLFS says a whole lot of nothing about this scenario, so go with the
architectural behavior, which says that VMMCALL #UDs if it&amp;#39;s not
intercepted.&lt;/p&gt;
&lt;p&gt;Opportunistically do a 2-for-1 stub trade by stub-ifying the new API
instead of the helpers it uses.  The last remaining &amp;#34;single&amp;#34; stub will
soon be dropped as well.&lt;/p&gt;
&lt;p&gt;[sean: rewrite changelog and comment, tag for stable, remove defunct stubs]&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-46076</guid>
    </item>
    <item>
      <title>GHSA-gj33-hwgc-v3v8</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-gj33-hwgc-v3v8</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;KVM: nSVM: Raise #UD if unhandled VMMCALL isn&amp;#39;t intercepted by L1&lt;/p&gt;
&lt;p&gt;Explicitly synthesize a #UD for VMMCALL if L2 is active, L1 does NOT want
to intercept VMMCALL, nested_svm_l2_tlb_flush_enabled() is true, and the
hypercall is something other than one of the supported Hyper-V hypercalls.
When all of the above conditions are met, KVM will intercept VMMCALL but
never forward it to L1, i.e. will let L2 make hypercalls as if it were L1.&lt;/p&gt;
&lt;p&gt;The TLFS says a whole lot of nothing about this scenario, so go with the
architectural behavior, which says that VMMCALL #UDs if it&amp;#39;s not
intercepted.&lt;/p&gt;
&lt;p&gt;Opportunistically do a 2-for-1 stub trade by stub-ifying the new API
instead of the helpers it uses.  The last remaining &amp;#34;single&amp;#34; stub will
soon be dropped as well.&lt;/p&gt;
&lt;p&gt;[sean: rewrite changelog and comment, tag for stable, remove defunct stubs]&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;KVM: nSVM: Raise #UD if unhandled VMMCALL isn&amp;#39;t intercepted by L1&lt;/p&gt;
&lt;p&gt;Explicitly synthesize a #UD for VMMCALL if L2 is active, L1 does NOT want
to intercept VMMCALL, nested_svm_l2_tlb_flush_enabled() is true, and the
hypercall is something other than one of the supported Hyper-V hypercalls.
When all of the above conditions are met, KVM will intercept VMMCALL but
never forward it to L1, i.e. will let L2 make hypercalls as if it were L1.&lt;/p&gt;
&lt;p&gt;The TLFS says a whole lot of nothing about this scenario, so go with the
architectural behavior, which says that VMMCALL #UDs if it&amp;#39;s not
intercepted.&lt;/p&gt;
&lt;p&gt;Opportunistically do a 2-for-1 stub trade by stub-ifying the new API
instead of the helpers it uses.  The last remaining &amp;#34;single&amp;#34; stub will
soon be dropped as well.&lt;/p&gt;
&lt;p&gt;[sean: rewrite changelog and comment, tag for stable, remove defunct stubs]&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-gj33-hwgc-v3v8</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-46076 — KVM: nSVM: Raise #UD if unhandled VMMCALL isn't intercepted by L1</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-46076</link>
      <description>msrc_CVE-2026-46076</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-46076</guid>
    </item>
    <item>
      <title>OESA-2026-2582 — kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-2582</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP3: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;mISDN: hfcpci: Fix warning when deleting uninitialized timer&lt;/p&gt;
&lt;p&gt;With CONFIG_DEBUG_OBJECTS_TIMERS unloading hfcpci module leads
to the following splat:&lt;/p&gt;
&lt;p&gt;[  250.215892] ODEBUG: assert_init not available (active state 0) object: ffffffffc01a3dc0 object type: timer_list hint: 0x0
[  250.217520] WARNING: CPU: 0 PID: 233 at lib/debugobjects.c:612 debug_print_object+0x1b6/0x2c0
[  250.218775] Modules linked in: hfcpci(-) mISDN_core
[  250.219537] CPU: 0 UID: 0 PID: 233 Comm: rmmod Not tainted 6.17.0-rc2-g6f713187ac98 #2 PREEMPT(voluntary)
[  250.220940] Hardware name: QEMU Ubuntu 24.04 PC (i440FX + PIIX, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
[  250.222377] RIP: 0010:debug_print_object+0x1b6/0x2c0
[  250.223131] Code: fc ff df 48 89 fa 48 c1 ea 03 80 3c 02 00 75 4f 41 56 48 8b 14 dd a0 4e 01 9f 48 89 ee 48 c7 c7 20 46 01 9f e8 cb 84d
[  250.225805] RSP: 0018:ffff888015ea7c08 EFLAGS: 00010286
[  250.226608] RAX: 0000000000000000 RBX: 0000000000000005 RCX: ffffffff9be93a95
[  250.227708] RDX: 1ffff1100d945138 RSI: 0000000000000008 RDI: ffff88806ca289c0
[  250.228993] RBP: ffffffff9f014a00 R08: 0000000000000001 R09: ffffed1002bd4f39
[  250.230043] R10: ffff888015ea79cf R11: 0000000000000001 R12: 0000000000000001
[  250.231185] R13: ffffffff9eea0520 R14: 0000000000000000 R15: ffff888015ea7cc8
[  250.232454] FS:  00007f3208f01540(0000) GS:ff…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP3: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;mISDN: hfcpci: Fix warning when deleting uninitialized timer&lt;/p&gt;
&lt;p&gt;With CONFIG_DEBUG_OBJECTS_TIMERS unloading hfcpci module leads
to the following splat:&lt;/p&gt;
&lt;p&gt;[  250.215892] ODEBUG: assert_init not available (active state 0) object: ffffffffc01a3dc0 object type: timer_list hint: 0x0
[  250.217520] WARNING: CPU: 0 PID: 233 at lib/debugobjects.c:612 debug_print_object+0x1b6/0x2c0
[  250.218775] Modules linked in: hfcpci(-) mISDN_core
[  250.219537] CPU: 0 UID: 0 PID: 233 Comm: rmmod Not tainted 6.17.0-rc2-g6f713187ac98 #2 PREEMPT(voluntary)
[  250.220940] Hardware name: QEMU Ubuntu 24.04 PC (i440FX + PIIX, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
[  250.222377] RIP: 0010:debug_print_object+0x1b6/0x2c0
[  250.223131] Code: fc ff df 48 89 fa 48 c1 ea 03 80 3c 02 00 75 4f 41 56 48 8b 14 dd a0 4e 01 9f 48 89 ee 48 c7 c7 20 46 01 9f e8 cb 84d
[  250.225805] RSP: 0018:ffff888015ea7c08 EFLAGS: 00010286
[  250.226608] RAX: 0000000000000000 RBX: 0000000000000005 RCX: ffffffff9be93a95
[  250.227708] RDX: 1ffff1100d945138 RSI: 0000000000000008 RDI: ffff88806ca289c0
[  250.228993] RBP: ffffffff9f014a00 R08: 0000000000000001 R09: ffffed1002bd4f39
[  250.230043] R10: ffff888015ea79cf R11: 0000000000000001 R12: 0000000000000001
[  250.231185] R13: ffffffff9eea0520 R14: 0000000000000000 R15: ffff888015ea7cc8
[  250.232454] FS:  00007f3208f01540(0000) GS:ff…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-2582</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:10954-1 — kernel-devel-7.0.11-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10954-1</link>
      <description>&lt;p&gt;kernel-devel-7.0.11-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;kernel-devel-7.0.11-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:10954-1</guid>
    </item>
    <item>
      <title>RHSA-2026:72624 — Red Hat Security Advisory: kernel security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:72624</link>
      <description>&lt;p&gt;kernel: ext4: fix e4b bitmap inconsistency reports kernel: KVM: nSVM: Raise #UD if unhandled VMMCALL isn&amp;#39;t intercepted by L1 kernel: KVM: arm64: Reassign nested_mmus array behind mmu_lock kernel: fhandle: fix UAF due to unlocked -&amp;gt;mnt_ns read in may_decode_fh() kernel: perf/core: Detach event groups during remove_on_exec kernel: vmxnet3: fix BUG_ON in vmxnet3_get_hdr_len() for Geneve packets kernel: perf: Reject exited events as group leaders kernel: crypto: tegra - fix rctx-&amp;gt;cryptlen calculation in tegra_gcm_do_one_req() kernel: nvme-tcp: reject a read that transferred too few bytes kernel: KVM: arm64: Handle negative S1 walk levels in VNCR TLB size evaluation&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;kernel: ext4: fix e4b bitmap inconsistency reports kernel: KVM: nSVM: Raise #UD if unhandled VMMCALL isn&amp;#39;t intercepted by L1 kernel: KVM: arm64: Reassign nested_mmus array behind mmu_lock kernel: fhandle: fix UAF due to unlocked -&amp;gt;mnt_ns read in may_decode_fh() kernel: perf/core: Detach event groups during remove_on_exec kernel: vmxnet3: fix BUG_ON in vmxnet3_get_hdr_len() for Geneve packets kernel: perf: Reject exited events as group leaders kernel: crypto: tegra - fix rctx-&amp;gt;cryptlen calculation in tegra_gcm_do_one_req() kernel: nvme-tcp: reject a read that transferred too few bytes kernel: KVM: arm64: Handle negative S1 walk levels in VNCR TLB size evaluation&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:72624</guid>
    </item>
    <item>
      <title>RLSA-2026:72624 — Important: kernel security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:72624</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: kernel&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: KVM: nSVM: Raise #UD if unhandled VMMCALL isn&amp;#39;t intercepted by L1 (CVE-2026-46076)&lt;/p&gt;
&lt;p&gt;* kernel: ext4: fix e4b bitmap inconsistency reports (CVE-2026-45942)&lt;/p&gt;
&lt;p&gt;* kernel: KVM: arm64: Reassign nested_mmus array behind mmu_lock (CVE-2026-46317)&lt;/p&gt;
&lt;p&gt;* kernel: fhandle: fix UAF due to unlocked -&amp;gt;mnt_ns read in may_decode_fh() (CVE-2026-53341)&lt;/p&gt;
&lt;p&gt;* kernel: perf/core: Detach event groups during remove_on_exec (CVE-2026-64556)&lt;/p&gt;
&lt;p&gt;* kernel: vmxnet3: fix BUG_ON in vmxnet3_get_hdr_len() for Geneve packets (CVE-2026-68299)&lt;/p&gt;
&lt;p&gt;* kernel: crypto: tegra - fix rctx-&amp;gt;cryptlen calculation in tegra_gcm_do_one_req() (CVE-2026-80522)&lt;/p&gt;
&lt;p&gt;* kernel: perf: Reject exited events as group leaders (CVE-2026-74753)&lt;/p&gt;
&lt;p&gt;* kernel: nvme-tcp: reject a read that transferred too few bytes (CVE-2026-89480)&lt;/p&gt;
&lt;p&gt;* kernel: KVM: arm64: Handle negative S1 walk levels in VNCR TLB size evaluation (CVE-2026-89775)&lt;/p&gt;
&lt;p&gt;Bug Fix(es) and Enhancement(s):&lt;/p&gt;
&lt;p&gt;* KVM: s390: Limit adapter indicator access to mapped page [rhel-10.2.z] (JIRA:Rocky Linux-188661)&lt;/p&gt;
&lt;p&gt;* crypto: xxhash64 should not be fips approved [rhel-10.2.z] (JIRA:Rocky Linux-254943)&lt;/p&gt;
&lt;p&gt;* kata-tdx TD vCPU stuck at reset vector (EIP=0xFFF0) on Intel Xeon 6 (Granite Rapids / Sierra Forest) ? guest never executes. (10.2.z) (JIRA:Rocky Linux-260402)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: kernel&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: KVM: nSVM: Raise #UD if unhandled VMMCALL isn&amp;#39;t intercepted by L1 (CVE-2026-46076)&lt;/p&gt;
&lt;p&gt;* kernel: ext4: fix e4b bitmap inconsistency reports (CVE-2026-45942)&lt;/p&gt;
&lt;p&gt;* kernel: KVM: arm64: Reassign nested_mmus array behind mmu_lock (CVE-2026-46317)&lt;/p&gt;
&lt;p&gt;* kernel: fhandle: fix UAF due to unlocked -&amp;gt;mnt_ns read in may_decode_fh() (CVE-2026-53341)&lt;/p&gt;
&lt;p&gt;* kernel: perf/core: Detach event groups during remove_on_exec (CVE-2026-64556)&lt;/p&gt;
&lt;p&gt;* kernel: vmxnet3: fix BUG_ON in vmxnet3_get_hdr_len() for Geneve packets (CVE-2026-68299)&lt;/p&gt;
&lt;p&gt;* kernel: crypto: tegra - fix rctx-&amp;gt;cryptlen calculation in tegra_gcm_do_one_req() (CVE-2026-80522)&lt;/p&gt;
&lt;p&gt;* kernel: perf: Reject exited events as group leaders (CVE-2026-74753)&lt;/p&gt;
&lt;p&gt;* kernel: nvme-tcp: reject a read that transferred too few bytes (CVE-2026-89480)&lt;/p&gt;
&lt;p&gt;* kernel: KVM: arm64: Handle negative S1 walk levels in VNCR TLB size evaluation (CVE-2026-89775)&lt;/p&gt;
&lt;p&gt;Bug Fix(es) and Enhancement(s):&lt;/p&gt;
&lt;p&gt;* KVM: s390: Limit adapter indicator access to mapped page [rhel-10.2.z] (JIRA:Rocky Linux-188661)&lt;/p&gt;
&lt;p&gt;* crypto: xxhash64 should not be fips approved [rhel-10.2.z] (JIRA:Rocky Linux-254943)&lt;/p&gt;
&lt;p&gt;* kata-tdx TD vCPU stuck at reset vector (EIP=0xFFF0) on Intel Xeon 6 (Granite Rapids / Sierra Forest) ? guest never executes. (10.2.z) (JIRA:Rocky Linux-260402)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:72624</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:22521-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:22521-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:22521-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-46076</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-46076</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 153 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: KVM: nSVM: Raise #UD if unhandled VMMCALL isn&amp;#39;t intercepted by L1 Explicitly synthesize a #UD for VMMCALL if L2 is active, L1 does NOT want to intercept VMMCALL, nested_svm_l2_tlb_flush_enabled() is true, and the hypercall is something other than one of the supported Hyper-V hypercalls. When all of the above conditions are met, KVM will intercept VMMCALL but never forward it to L1, i.e. will let L2 make hypercalls as if it were L1. The TLFS says a whole lot of nothing about this scenario, so go with the architectural behavior, which says that VMMCALL #UDs if it&amp;#39;s not intercepted. Opportunistically do a 2-for-1 stub trade by stub-ifying the new API instead of the helpers it uses.  The last remaining &amp;#34;single&amp;#34; stub will soon be dropped as well. [sean: rewrite changelog and comment, tag for stable, remove defunct stubs]&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 153 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: KVM: nSVM: Raise #UD if unhandled VMMCALL isn&amp;#39;t intercepted by L1 Explicitly synthesize a #UD for VMMCALL if L2 is active, L1 does NOT want to intercept VMMCALL, nested_svm_l2_tlb_flush_enabled() is true, and the hypercall is something other than one of the supported Hyper-V hypercalls. When all of the above conditions are met, KVM will intercept VMMCALL but never forward it to L1, i.e. will let L2 make hypercalls as if it were L1. The TLFS says a whole lot of nothing about this scenario, so go with the architectural behavior, which says that VMMCALL #UDs if it&amp;#39;s not intercepted. Opportunistically do a 2-for-1 stub trade by stub-ifying the new API instead of the helpers it uses.  The last remaining &amp;#34;single&amp;#34; stub will soon be dropped as well. [sean: rewrite changelog and comment, tag for stable, remove defunct stubs]&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-46076</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1700 — Linux Kernel: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1700</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen oder andere nicht näher spezifizierte Auswirkungen zu erzielen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen oder andere nicht näher spezifizierte Auswirkungen zu erzielen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1700</guid>
    </item>
  </channel>
</rss>
