<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 11:41:14 +0000</lastBuildDate>
    <item>
      <title>ALSA-2026:36018 — Important: kernel security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:36018</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: kernel, AlmaLinux:9: kernel-64k, AlmaLinux:9: kernel-64k-core, AlmaLinux:9: kernel-64k-debug, AlmaLinux:9: kernel-64k-debug-core, AlmaLinux:9: kernel-64k-debug-devel, AlmaLinux:9: kernel-64k-debug-devel-matched, AlmaLinux:9: kernel-64k-debug-modules, AlmaLinux:9: kernel-64k-debug-modules-core, AlmaLinux:9: kernel-64k-debug-modules-extra and 64 more&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: fs/smb/client: fix out-of-bounds read in cifs_sanitize_prepath (CVE-2026-43112)
  * kernel: net: mana: Fix double destroy_workqueue on service rescan PCI path (CVE-2026-43276)
  * kernel: Linux kernel: Use-After-Free in net/gro due to improper handling of zerocopy skbs (CVE-2026-46323)
  * kernel: xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete (CVE-2026-46116)
  * kernel: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (CVE-2026-46227)
  * kernel: drm/gem: Fix inconsistent plane dimension calculation in drm_gem_fb_init_with_funcs() (CVE-2026-46209)
  * kernel: smb/client: fix out-of-bounds read in smb2_compound_op() (CVE-2026-46155)
  * kernel: netfilter: nft_inner: Fix IPv6 inner_thoff desync (CVE-2026-46244)
  * kernel: procfs: fix missing RCU protection when reading real_parent in do_task_stat() (CVE-2026-46259)
  * kernel: Arm Processors: Privilege escalation or information disclosure via writes to higher exception level resources (CVE-2025-10263)
  * kernel: KVM: arm64: vgic-its: Drop the translation cache reference only for the erased entry (CVE-2026-46316)&lt;/p&gt;
&lt;p&gt;Bug Fix(es) and Enhancement(s):&lt;/p&gt;
&lt;p&gt;* WARNING at drivers/gpu/drm/nouveau/nvkm/subdev/gsp/r535.c:1585 r535_gsp_fini+0x2fb/0x310 [nouveau] [almalinux-9.8.z] (JIRA:AlmaLinux-160966)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: kernel, AlmaLinux:9: kernel-64k, AlmaLinux:9: kernel-64k-core, AlmaLinux:9: kernel-64k-debug, AlmaLinux:9: kernel-64k-debug-core, AlmaLinux:9: kernel-64k-debug-devel, AlmaLinux:9: kernel-64k-debug-devel-matched, AlmaLinux:9: kernel-64k-debug-modules, AlmaLinux:9: kernel-64k-debug-modules-core, AlmaLinux:9: kernel-64k-debug-modules-extra and 64 more&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: fs/smb/client: fix out-of-bounds read in cifs_sanitize_prepath (CVE-2026-43112)
  * kernel: net: mana: Fix double destroy_workqueue on service rescan PCI path (CVE-2026-43276)
  * kernel: Linux kernel: Use-After-Free in net/gro due to improper handling of zerocopy skbs (CVE-2026-46323)
  * kernel: xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete (CVE-2026-46116)
  * kernel: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (CVE-2026-46227)
  * kernel: drm/gem: Fix inconsistent plane dimension calculation in drm_gem_fb_init_with_funcs() (CVE-2026-46209)
  * kernel: smb/client: fix out-of-bounds read in smb2_compound_op() (CVE-2026-46155)
  * kernel: netfilter: nft_inner: Fix IPv6 inner_thoff desync (CVE-2026-46244)
  * kernel: procfs: fix missing RCU protection when reading real_parent in do_task_stat() (CVE-2026-46259)
  * kernel: Arm Processors: Privilege escalation or information disclosure via writes to higher exception level resources (CVE-2025-10263)
  * kernel: KVM: arm64: vgic-its: Drop the translation cache reference only for the erased entry (CVE-2026-46316)&lt;/p&gt;
&lt;p&gt;Bug Fix(es) and Enhancement(s):&lt;/p&gt;
&lt;p&gt;* WARNING at drivers/gpu/drm/nouveau/nvkm/subdev/gsp/r535.c:1585 r535_gsp_fini+0x2fb/0x310 [nouveau] [almalinux-9.8.z] (JIRA:AlmaLinux-160966)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:36018</guid>
    </item>
    <item>
      <title>bdu:2026-11328</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-11328</link>
      <description>bdu:2026-11328</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-11328</guid>
    </item>
    <item>
      <title>BELL-CVE-2026-46116</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-46116</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-46116</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0731 — De multiples vulnérabilités ont été découvertes dans les produits Microsoft. Certaines d'entre elles permettent à un at…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0731</link>
      <description>certfr-2026-avi-0731</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0731</guid>
    </item>
    <item>
      <title>ESSA-2026:0162 — Important: kernel security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/essa-2026:0162</link>
      <description>&lt;p&gt;Important: kernel security, bug fix, and enhancement update&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Important: kernel security, bug fix, and enhancement update&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/essa-2026:0162</guid>
    </item>
    <item>
      <title>EUVD-2026-368461</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-368461</link>
      <description>EUVD-2026-368461</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-368461</guid>
    </item>
    <item>
      <title>fkie_cve-2026-46116</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-46116</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete&lt;/p&gt;
&lt;p&gt;KASAN reproduces a slab-use-after-free in __xfrm_state_delete()&amp;#39;s
hlist_del_rcu calls under syzkaller load on linux-6.12.y stable
(reproduced on 6.12.47, also reachable via the same code path on
torvalds/master and on the ipsec tree). Nine unique signatures cluster
in the xfrm_state lifecycle, the load-bearing one being:&lt;/p&gt;
&lt;p&gt;BUG: KASAN: slab-use-after-free in __hlist_del include/linux/list.h:990 [inline]
  BUG: KASAN: slab-use-after-free in hlist_del_rcu include/linux/rculist.h:516 [inline]
  BUG: KASAN: slab-use-after-free in __xfrm_state_delete net/xfrm/xfrm_state.c
  Write of size 8 at addr ffff8881198bcb70 by task kworker/u8:9/435&lt;/p&gt;
&lt;p&gt;Workqueue: netns cleanup_net
  Call Trace:
   __hlist_del / hlist_del_rcu
   __xfrm_state_delete
   xfrm_state_delete
   xfrm_state_flush
   xfrm_state_fini
   ops_exit_list
   cleanup_net&lt;/p&gt;
&lt;p&gt;The other observed signatures hit the same slab object from
__xfrm_state_lookup, xfrm_alloc_spi, __xfrm_state_insert and an OOB
write variant of __xfrm_state_delete, all on the byseq/byspi
hash chains.&lt;/p&gt;
&lt;p&gt;__xfrm_state_delete() guards its byseq and byspi unhashes with
value-based predicates:&lt;/p&gt;
&lt;p&gt;if (x-&amp;gt;km.seq)
		hlist_del_rcu(&amp;amp;x-&amp;gt;byseq);
	if (x-&amp;gt;id.spi)
		hlist_del_rcu(&amp;amp;x-&amp;gt;byspi);&lt;/p&gt;
&lt;p&gt;while everywhere else in the file (e.g. state_cache, state_cache_input)
the safer hlist_unhashed() check is used. xfrm_alloc_spi() sets
x-&amp;gt;id.spi = n…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete&lt;/p&gt;
&lt;p&gt;KASAN reproduces a slab-use-after-free in __xfrm_state_delete()&amp;#39;s
hlist_del_rcu calls under syzkaller load on linux-6.12.y stable
(reproduced on 6.12.47, also reachable via the same code path on
torvalds/master and on the ipsec tree). Nine unique signatures cluster
in the xfrm_state lifecycle, the load-bearing one being:&lt;/p&gt;
&lt;p&gt;BUG: KASAN: slab-use-after-free in __hlist_del include/linux/list.h:990 [inline]
  BUG: KASAN: slab-use-after-free in hlist_del_rcu include/linux/rculist.h:516 [inline]
  BUG: KASAN: slab-use-after-free in __xfrm_state_delete net/xfrm/xfrm_state.c
  Write of size 8 at addr ffff8881198bcb70 by task kworker/u8:9/435&lt;/p&gt;
&lt;p&gt;Workqueue: netns cleanup_net
  Call Trace:
   __hlist_del / hlist_del_rcu
   __xfrm_state_delete
   xfrm_state_delete
   xfrm_state_flush
   xfrm_state_fini
   ops_exit_list
   cleanup_net&lt;/p&gt;
&lt;p&gt;The other observed signatures hit the same slab object from
__xfrm_state_lookup, xfrm_alloc_spi, __xfrm_state_insert and an OOB
write variant of __xfrm_state_delete, all on the byseq/byspi
hash chains.&lt;/p&gt;
&lt;p&gt;__xfrm_state_delete() guards its byseq and byspi unhashes with
value-based predicates:&lt;/p&gt;
&lt;p&gt;if (x-&amp;gt;km.seq)
		hlist_del_rcu(&amp;amp;x-&amp;gt;byseq);
	if (x-&amp;gt;id.spi)
		hlist_del_rcu(&amp;amp;x-&amp;gt;byspi);&lt;/p&gt;
&lt;p&gt;while everywhere else in the file (e.g. state_cache, state_cache_input)
the safer hlist_unhashed() check is used. xfrm_alloc_spi() sets
x-&amp;gt;id.spi = n…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-46116</guid>
    </item>
    <item>
      <title>GHSA-96hg-7p79-ggx2</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-96hg-7p79-ggx2</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete&lt;/p&gt;
&lt;p&gt;KASAN reproduces a slab-use-after-free in __xfrm_state_delete()&amp;#39;s
hlist_del_rcu calls under syzkaller load on linux-6.12.y stable
(reproduced on 6.12.47, also reachable via the same code path on
torvalds/master and on the ipsec tree). Nine unique signatures cluster
in the xfrm_state lifecycle, the load-bearing one being:&lt;/p&gt;
&lt;p&gt;BUG: KASAN: slab-use-after-free in __hlist_del include/linux/list.h:990 [inline]
  BUG: KASAN: slab-use-after-free in hlist_del_rcu include/linux/rculist.h:516 [inline]
  BUG: KASAN: slab-use-after-free in __xfrm_state_delete net/xfrm/xfrm_state.c
  Write of size 8 at addr ffff8881198bcb70 by task kworker/u8:9/435&lt;/p&gt;
&lt;p&gt;Workqueue: netns cleanup_net
  Call Trace:
   __hlist_del / hlist_del_rcu
   __xfrm_state_delete
   xfrm_state_delete
   xfrm_state_flush
   xfrm_state_fini
   ops_exit_list
   cleanup_net&lt;/p&gt;
&lt;p&gt;The other observed signatures hit the same slab object from
__xfrm_state_lookup, xfrm_alloc_spi, __xfrm_state_insert and an OOB
write variant of __xfrm_state_delete, all on the byseq/byspi
hash chains.&lt;/p&gt;
&lt;p&gt;__xfrm_state_delete() guards its byseq and byspi unhashes with
value-based predicates:&lt;/p&gt;
&lt;p&gt;if (x-&amp;gt;km.seq)
		hlist_del_rcu(&amp;amp;x-&amp;gt;byseq);
	if (x-&amp;gt;id.spi)
		hlist_del_rcu(&amp;amp;x-&amp;gt;byspi);&lt;/p&gt;
&lt;p&gt;while everywhere else in the file (e.g. state_cache, state_cache_input)
the safer hlist_unhashed() check is used. xfrm_alloc_spi() sets
x-&amp;gt;id.spi = n…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete&lt;/p&gt;
&lt;p&gt;KASAN reproduces a slab-use-after-free in __xfrm_state_delete()&amp;#39;s
hlist_del_rcu calls under syzkaller load on linux-6.12.y stable
(reproduced on 6.12.47, also reachable via the same code path on
torvalds/master and on the ipsec tree). Nine unique signatures cluster
in the xfrm_state lifecycle, the load-bearing one being:&lt;/p&gt;
&lt;p&gt;BUG: KASAN: slab-use-after-free in __hlist_del include/linux/list.h:990 [inline]
  BUG: KASAN: slab-use-after-free in hlist_del_rcu include/linux/rculist.h:516 [inline]
  BUG: KASAN: slab-use-after-free in __xfrm_state_delete net/xfrm/xfrm_state.c
  Write of size 8 at addr ffff8881198bcb70 by task kworker/u8:9/435&lt;/p&gt;
&lt;p&gt;Workqueue: netns cleanup_net
  Call Trace:
   __hlist_del / hlist_del_rcu
   __xfrm_state_delete
   xfrm_state_delete
   xfrm_state_flush
   xfrm_state_fini
   ops_exit_list
   cleanup_net&lt;/p&gt;
&lt;p&gt;The other observed signatures hit the same slab object from
__xfrm_state_lookup, xfrm_alloc_spi, __xfrm_state_insert and an OOB
write variant of __xfrm_state_delete, all on the byseq/byspi
hash chains.&lt;/p&gt;
&lt;p&gt;__xfrm_state_delete() guards its byseq and byspi unhashes with
value-based predicates:&lt;/p&gt;
&lt;p&gt;if (x-&amp;gt;km.seq)
		hlist_del_rcu(&amp;amp;x-&amp;gt;byseq);
	if (x-&amp;gt;id.spi)
		hlist_del_rcu(&amp;amp;x-&amp;gt;byspi);&lt;/p&gt;
&lt;p&gt;while everywhere else in the file (e.g. state_cache, state_cache_input)
the safer hlist_unhashed() check is used. xfrm_alloc_spi() sets
x-&amp;gt;id.spi = n…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-96hg-7p79-ggx2</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-46116 — xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-46116</link>
      <description>msrc_CVE-2026-46116</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-46116</guid>
    </item>
    <item>
      <title>OESA-2026-2674 — kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-2674</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP4: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;btrfs: qgroup: fix race between quota disable and quota rescan ioctl&lt;/p&gt;
&lt;p&gt;There&amp;amp;apos;s a race between a task disabling quotas and another running the
rescan ioctl that can result in a use-after-free of qgroup records from
the fs_info-&amp;amp;gt;qgroup_tree rbtree.&lt;/p&gt;
&lt;p&gt;This happens as follows:&lt;/p&gt;
&lt;p&gt;1) Task A enters btrfs_ioctl_quota_rescan() -&amp;amp;gt; btrfs_qgroup_rescan();&lt;/p&gt;
&lt;p&gt;2) Task B enters btrfs_quota_disable() and calls
   btrfs_qgroup_wait_for_completion(), which does nothing because at that
   point fs_info-&amp;amp;gt;qgroup_rescan_running is false (it wasn&amp;amp;apos;t set yet by
   task A);&lt;/p&gt;
&lt;p&gt;3) Task B calls btrfs_free_qgroup_config() which starts freeing qgroups
   from fs_info-&amp;amp;gt;qgroup_tree without taking the lock fs_info-&amp;amp;gt;qgroup_lock;&lt;/p&gt;
&lt;p&gt;4) Task A enters qgroup_rescan_zero_tracking() which starts iterating
   the fs_info-&amp;amp;gt;qgroup_tree tree while holding fs_info-&amp;amp;gt;qgroup_lock,
   but task B is freeing qgroup records from that tree without holding
   the lock, resulting in a use-after-free.&lt;/p&gt;
&lt;p&gt;Fix this by taking fs_info-&amp;amp;gt;qgroup_lock at btrfs_free_qgroup_config().
Also at btrfs_qgroup_rescan() don&amp;amp;apos;t start the rescan worker if quotas
were already disabled.(CVE-2025-39759)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;wifi: wilc1000: avoid buffer overflow in WID string configuration&lt;/p&gt;
&lt;p&gt;Fix the following copy overflow warning identi…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP4: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;btrfs: qgroup: fix race between quota disable and quota rescan ioctl&lt;/p&gt;
&lt;p&gt;There&amp;amp;apos;s a race between a task disabling quotas and another running the
rescan ioctl that can result in a use-after-free of qgroup records from
the fs_info-&amp;amp;gt;qgroup_tree rbtree.&lt;/p&gt;
&lt;p&gt;This happens as follows:&lt;/p&gt;
&lt;p&gt;1) Task A enters btrfs_ioctl_quota_rescan() -&amp;amp;gt; btrfs_qgroup_rescan();&lt;/p&gt;
&lt;p&gt;2) Task B enters btrfs_quota_disable() and calls
   btrfs_qgroup_wait_for_completion(), which does nothing because at that
   point fs_info-&amp;amp;gt;qgroup_rescan_running is false (it wasn&amp;amp;apos;t set yet by
   task A);&lt;/p&gt;
&lt;p&gt;3) Task B calls btrfs_free_qgroup_config() which starts freeing qgroups
   from fs_info-&amp;amp;gt;qgroup_tree without taking the lock fs_info-&amp;amp;gt;qgroup_lock;&lt;/p&gt;
&lt;p&gt;4) Task A enters qgroup_rescan_zero_tracking() which starts iterating
   the fs_info-&amp;amp;gt;qgroup_tree tree while holding fs_info-&amp;amp;gt;qgroup_lock,
   but task B is freeing qgroup records from that tree without holding
   the lock, resulting in a use-after-free.&lt;/p&gt;
&lt;p&gt;Fix this by taking fs_info-&amp;amp;gt;qgroup_lock at btrfs_free_qgroup_config().
Also at btrfs_qgroup_rescan() don&amp;amp;apos;t start the rescan worker if quotas
were already disabled.(CVE-2025-39759)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;wifi: wilc1000: avoid buffer overflow in WID string configuration&lt;/p&gt;
&lt;p&gt;Fix the following copy overflow warning identi…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-2674</guid>
    </item>
    <item>
      <title>RHSA-2026:39180 — Red Hat Security Advisory: kernel-rt security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:39180</link>
      <description>&lt;p&gt;kernel: net: bridge: use a stable FDB dst snapshot in RCU readers kernel: xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete kernel: XFS data corruption using reflink&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;kernel: net: bridge: use a stable FDB dst snapshot in RCU readers kernel: xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete kernel: XFS data corruption using reflink&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:39180</guid>
    </item>
    <item>
      <title>RLSA-2026:36018 — Important: kernel security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:36018</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:9: kernel&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: fs/smb/client: fix out-of-bounds read in cifs_sanitize_prepath (CVE-2026-43112)&lt;/p&gt;
&lt;p&gt;* kernel: net: mana: Fix double destroy_workqueue on service rescan PCI path (CVE-2026-43276)&lt;/p&gt;
&lt;p&gt;* kernel: Linux kernel: Use-After-Free in net/gro due to improper handling of zerocopy skbs (CVE-2026-46323)&lt;/p&gt;
&lt;p&gt;* kernel: xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete (CVE-2026-46116)&lt;/p&gt;
&lt;p&gt;* kernel: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (CVE-2026-46227)&lt;/p&gt;
&lt;p&gt;* kernel: drm/gem: Fix inconsistent plane dimension calculation in drm_gem_fb_init_with_funcs() (CVE-2026-46209)&lt;/p&gt;
&lt;p&gt;* kernel: smb/client: fix out-of-bounds read in smb2_compound_op() (CVE-2026-46155)&lt;/p&gt;
&lt;p&gt;* kernel: netfilter: nft_inner: Fix IPv6 inner_thoff desync (CVE-2026-46244)&lt;/p&gt;
&lt;p&gt;* kernel: procfs: fix missing RCU protection when reading real_parent in do_task_stat() (CVE-2026-46259)&lt;/p&gt;
&lt;p&gt;* kernel: Arm Processors: Privilege escalation or information disclosure via writes to higher exception level resources (CVE-2025-10263)&lt;/p&gt;
&lt;p&gt;* kernel: KVM: arm64: vgic-its: Drop the translation cache reference only for the erased entry (CVE-2026-46316)&lt;/p&gt;
&lt;p&gt;Bug Fix(es) and Enhancement(s):&lt;/p&gt;
&lt;p&gt;* WARNING at drivers/gpu/drm/nouveau/nvkm/subdev/gsp/r535.c:1585 r535_gsp_fini+0x2fb/0x310 [nouveau] [rhel-9.8.z] (JIRA:Rocky Linux-160966)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgme…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:9: kernel&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: fs/smb/client: fix out-of-bounds read in cifs_sanitize_prepath (CVE-2026-43112)&lt;/p&gt;
&lt;p&gt;* kernel: net: mana: Fix double destroy_workqueue on service rescan PCI path (CVE-2026-43276)&lt;/p&gt;
&lt;p&gt;* kernel: Linux kernel: Use-After-Free in net/gro due to improper handling of zerocopy skbs (CVE-2026-46323)&lt;/p&gt;
&lt;p&gt;* kernel: xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete (CVE-2026-46116)&lt;/p&gt;
&lt;p&gt;* kernel: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (CVE-2026-46227)&lt;/p&gt;
&lt;p&gt;* kernel: drm/gem: Fix inconsistent plane dimension calculation in drm_gem_fb_init_with_funcs() (CVE-2026-46209)&lt;/p&gt;
&lt;p&gt;* kernel: smb/client: fix out-of-bounds read in smb2_compound_op() (CVE-2026-46155)&lt;/p&gt;
&lt;p&gt;* kernel: netfilter: nft_inner: Fix IPv6 inner_thoff desync (CVE-2026-46244)&lt;/p&gt;
&lt;p&gt;* kernel: procfs: fix missing RCU protection when reading real_parent in do_task_stat() (CVE-2026-46259)&lt;/p&gt;
&lt;p&gt;* kernel: Arm Processors: Privilege escalation or information disclosure via writes to higher exception level resources (CVE-2025-10263)&lt;/p&gt;
&lt;p&gt;* kernel: KVM: arm64: vgic-its: Drop the translation cache reference only for the erased entry (CVE-2026-46316)&lt;/p&gt;
&lt;p&gt;Bug Fix(es) and Enhancement(s):&lt;/p&gt;
&lt;p&gt;* WARNING at drivers/gpu/drm/nouveau/nvkm/subdev/gsp/r535.c:1585 r535_gsp_fini+0x2fb/0x310 [nouveau] [rhel-9.8.z] (JIRA:Rocky Linux-160966)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgme…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:36018</guid>
    </item>
    <item>
      <title>SSA-019113 — SSA-019113: Vulnerabilities in the additional GNU/Linux subsystem of the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1.6</title>
      <link>https://cve.radiocsirt.org/vuln/ssa-019113</link>
      <description>&lt;p&gt;Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.6 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant).&lt;/p&gt;
&lt;p&gt;Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.6 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant).&lt;/p&gt;
&lt;p&gt;Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ssa-019113</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:22521-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:22521-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:22521-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-46116</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-46116</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux, Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe and 253 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete KASAN reproduces a slab-use-after-free in __xfrm_state_delete()&amp;#39;s hlist_del_rcu calls under syzkaller load on linux-6.12.y stable (reproduced on 6.12.47, also reachable via the same code path on torvalds/master and on the ipsec tree). Nine unique signatures cluster in the xfrm_state lifecycle, the load-bearing one being:   BUG: KASAN: slab-use-after-free in __hlist_del include/linux/list.h:990 [inline]   BUG: KASAN: slab-use-after-free in hlist_del_rcu include/linux/rculist.h:516 [inline]   BUG: KASAN: slab-use-after-free in __xfrm_state_delete net/xfrm/xfrm_state.c   Write of size 8 at addr ffff8881198bcb70 by task kworker/u8:9/435   Workqueue: netns cleanup_net   Call Trace:    __hlist_del / hlist_del_rcu    __xfrm_state_delete    xfrm_state_delete    xfrm_state_flush    xfrm_state_fini    ops_exit_list    cleanup_net The other observed signatures hit the same slab object from __xfrm_state_lookup, xfrm_alloc_spi, __xfrm_state_insert and an OOB write variant of __xfrm_state_delete, all on the byseq/byspi hash chains. __xfrm_state_delete() guards its byseq and byspi unhashes with value-based predicates: 	if (x-&amp;gt;km.seq) 		hlist_del_rcu(&amp;amp;x-&amp;gt;byseq); 	if (x-&amp;gt;id.spi) 		hlist_del_rcu(&amp;amp;x-&amp;gt;byspi); while everywhere else in the file (e.g. state_cache, state_cache_input) the safer hlist_unhashed() check is used. xfrm_alloc_spi() sets x-&amp;gt;id.spi = newspi in…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux, Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe and 253 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete KASAN reproduces a slab-use-after-free in __xfrm_state_delete()&amp;#39;s hlist_del_rcu calls under syzkaller load on linux-6.12.y stable (reproduced on 6.12.47, also reachable via the same code path on torvalds/master and on the ipsec tree). Nine unique signatures cluster in the xfrm_state lifecycle, the load-bearing one being:   BUG: KASAN: slab-use-after-free in __hlist_del include/linux/list.h:990 [inline]   BUG: KASAN: slab-use-after-free in hlist_del_rcu include/linux/rculist.h:516 [inline]   BUG: KASAN: slab-use-after-free in __xfrm_state_delete net/xfrm/xfrm_state.c   Write of size 8 at addr ffff8881198bcb70 by task kworker/u8:9/435   Workqueue: netns cleanup_net   Call Trace:    __hlist_del / hlist_del_rcu    __xfrm_state_delete    xfrm_state_delete    xfrm_state_flush    xfrm_state_fini    ops_exit_list    cleanup_net The other observed signatures hit the same slab object from __xfrm_state_lookup, xfrm_alloc_spi, __xfrm_state_insert and an OOB write variant of __xfrm_state_delete, all on the byseq/byspi hash chains. __xfrm_state_delete() guards its byseq and byspi unhashes with value-based predicates: 	if (x-&amp;gt;km.seq) 		hlist_del_rcu(&amp;amp;x-&amp;gt;byseq); 	if (x-&amp;gt;id.spi) 		hlist_del_rcu(&amp;amp;x-&amp;gt;byspi); while everywhere else in the file (e.g. state_cache, state_cache_input) the safer hlist_unhashed() check is used. xfrm_alloc_spi() sets x-&amp;gt;id.spi = newspi in…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-46116</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1700 — Linux Kernel: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1700</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen oder andere nicht näher spezifizierte Auswirkungen zu erzielen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen oder andere nicht näher spezifizierte Auswirkungen zu erzielen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1700</guid>
    </item>
  </channel>
</rss>
