<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 20:53:32 +0000</lastBuildDate>
    <item>
      <title>ALSA-2026:27288 — Important: kernel security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:27288</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: kernel, AlmaLinux:10: kernel-64k, AlmaLinux:10: kernel-64k-core, AlmaLinux:10: kernel-64k-debug, AlmaLinux:10: kernel-64k-debug-core, AlmaLinux:10: kernel-64k-debug-devel, AlmaLinux:10: kernel-64k-debug-devel-matched, AlmaLinux:10: kernel-64k-debug-modules, AlmaLinux:10: kernel-64k-debug-modules-core, AlmaLinux:10: kernel-64k-debug-modules-extra and 65 more&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: can: isotp: fix tx.buf use-after-free in isotp_sendmsg() (CVE-2026-31474)
  * kernel: mptcp: fix slab-use-after-free in __inet_lookup_established (CVE-2026-31669)
  * kernel: rxrpc: Fix RxGK token loading to check bounds (CVE-2026-31641)
  * kernel: xen/privcmd: fix double free via VMA splitting (CVE-2026-31787)
  * kernel: Buffer overflow in drivers/xen/sys-hypervisor.c (CVE-2026-31786)
  * kernel: net: mana: fix use-after-free in add_adev() error path (CVE-2026-43056)
  * kernel: Bluetooth: hci_sync: fix stack buffer overflow in hci_le_big_create_sync (CVE-2026-31772)
  * kernel: bnxt_en: Fix RSS context delete logic (CVE-2026-43260)
  * kernel: crypto: caam - fix overflow on long hmac keys (CVE-2026-43330)
  * kernel: net/sched: act_pedit: extend the writable skb range per key (CVE-2026-46331)
  * kernel: Bluetooth: hci_event: fix potential UAF in SSP passkey handlers (CVE-2026-46056)
  * kernel: wifi: mac80211: drop stray &amp;#39;static&amp;#39; from fast-RX rx_result (CVE-2026-46152)
  * kernel: wifi: mac80211: remove station if connection prep fails (CVE-2026-46125)
  * kernel: exit: prevent preemption of oopsing TASK_DEAD task (CVE-2026-46173)
  * kernel: wifi: mac80211: use safe list iteration in radar detect work (CVE-2026-46166)&lt;/p&gt;
&lt;p&gt;Bug Fix(es) and Enhancement(s):&lt;/p&gt;
&lt;p&gt;* AlmaLinux10.0 - s390/ap: Expose ap_bindings_complete_count counter via sysfs [almalinux-10.2…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: kernel, AlmaLinux:10: kernel-64k, AlmaLinux:10: kernel-64k-core, AlmaLinux:10: kernel-64k-debug, AlmaLinux:10: kernel-64k-debug-core, AlmaLinux:10: kernel-64k-debug-devel, AlmaLinux:10: kernel-64k-debug-devel-matched, AlmaLinux:10: kernel-64k-debug-modules, AlmaLinux:10: kernel-64k-debug-modules-core, AlmaLinux:10: kernel-64k-debug-modules-extra and 65 more&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: can: isotp: fix tx.buf use-after-free in isotp_sendmsg() (CVE-2026-31474)
  * kernel: mptcp: fix slab-use-after-free in __inet_lookup_established (CVE-2026-31669)
  * kernel: rxrpc: Fix RxGK token loading to check bounds (CVE-2026-31641)
  * kernel: xen/privcmd: fix double free via VMA splitting (CVE-2026-31787)
  * kernel: Buffer overflow in drivers/xen/sys-hypervisor.c (CVE-2026-31786)
  * kernel: net: mana: fix use-after-free in add_adev() error path (CVE-2026-43056)
  * kernel: Bluetooth: hci_sync: fix stack buffer overflow in hci_le_big_create_sync (CVE-2026-31772)
  * kernel: bnxt_en: Fix RSS context delete logic (CVE-2026-43260)
  * kernel: crypto: caam - fix overflow on long hmac keys (CVE-2026-43330)
  * kernel: net/sched: act_pedit: extend the writable skb range per key (CVE-2026-46331)
  * kernel: Bluetooth: hci_event: fix potential UAF in SSP passkey handlers (CVE-2026-46056)
  * kernel: wifi: mac80211: drop stray &amp;#39;static&amp;#39; from fast-RX rx_result (CVE-2026-46152)
  * kernel: wifi: mac80211: remove station if connection prep fails (CVE-2026-46125)
  * kernel: exit: prevent preemption of oopsing TASK_DEAD task (CVE-2026-46173)
  * kernel: wifi: mac80211: use safe list iteration in radar detect work (CVE-2026-46166)&lt;/p&gt;
&lt;p&gt;Bug Fix(es) and Enhancement(s):&lt;/p&gt;
&lt;p&gt;* AlmaLinux10.0 - s390/ap: Expose ap_bindings_complete_count counter via sysfs [almalinux-10.2…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:27288</guid>
    </item>
    <item>
      <title>bdu:2026-14226</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-14226</link>
      <description>bdu:2026-14226</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-14226</guid>
    </item>
    <item>
      <title>BELL-CVE-2026-46173</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-46173</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-46173</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0731 — De multiples vulnérabilités ont été découvertes dans les produits Microsoft. Certaines d'entre elles permettent à un at…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0731</link>
      <description>certfr-2026-avi-0731</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0731</guid>
    </item>
    <item>
      <title>ESSA-2026:0153 — Important: kernel security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/essa-2026:0153</link>
      <description>&lt;p&gt;Important: kernel security, bug fix, and enhancement update&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Important: kernel security, bug fix, and enhancement update&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/essa-2026:0153</guid>
    </item>
    <item>
      <title>EUVD-2026-364817</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-364817</link>
      <description>EUVD-2026-364817</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-364817</guid>
    </item>
    <item>
      <title>fkie_cve-2026-46173</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-46173</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;exit: prevent preemption of oopsing TASK_DEAD task&lt;/p&gt;
&lt;p&gt;When an already-exiting task oopses, make_task_dead() currently calls
do_task_dead() with preemption enabled.  That is forbidden:
do_task_dead() calls __schedule(), which has a comment saying &amp;#34;WARNING:
must be called with preemption disabled!&amp;#34;.&lt;/p&gt;
&lt;p&gt;If an oopsing task is preempted in do_task_dead(), between becoming
TASK_DEAD and entering the scheduler explicitly, bad things happen:
finish_task_switch() assumes that once the scheduler has switched away
from a TASK_DEAD task, the task can never run again and its stack is no
longer needed; but that assumption apparently doesn&amp;#39;t hold if the dead
task was preempted (the SM_PREEMPT case).&lt;/p&gt;
&lt;p&gt;This means that the scheduler ends up repeatedly dropping references on
the dead task&amp;#39;s stack, which can lead to use-after-free or double-free
of the entire task stack; in other words, two tasks can end up running
on the same stack, resulting in various kinds of memory corruption.&lt;/p&gt;
&lt;p&gt;(This does not just affect &amp;#34;recursively oopsing&amp;#34; tasks; it is enough to
oops once during task exit, for example in a file_operations::release
handler)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;exit: prevent preemption of oopsing TASK_DEAD task&lt;/p&gt;
&lt;p&gt;When an already-exiting task oopses, make_task_dead() currently calls
do_task_dead() with preemption enabled.  That is forbidden:
do_task_dead() calls __schedule(), which has a comment saying &amp;#34;WARNING:
must be called with preemption disabled!&amp;#34;.&lt;/p&gt;
&lt;p&gt;If an oopsing task is preempted in do_task_dead(), between becoming
TASK_DEAD and entering the scheduler explicitly, bad things happen:
finish_task_switch() assumes that once the scheduler has switched away
from a TASK_DEAD task, the task can never run again and its stack is no
longer needed; but that assumption apparently doesn&amp;#39;t hold if the dead
task was preempted (the SM_PREEMPT case).&lt;/p&gt;
&lt;p&gt;This means that the scheduler ends up repeatedly dropping references on
the dead task&amp;#39;s stack, which can lead to use-after-free or double-free
of the entire task stack; in other words, two tasks can end up running
on the same stack, resulting in various kinds of memory corruption.&lt;/p&gt;
&lt;p&gt;(This does not just affect &amp;#34;recursively oopsing&amp;#34; tasks; it is enough to
oops once during task exit, for example in a file_operations::release
handler)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-46173</guid>
    </item>
    <item>
      <title>GHSA-mpr4-2mm3-rwm6</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-mpr4-2mm3-rwm6</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;exit: prevent preemption of oopsing TASK_DEAD task&lt;/p&gt;
&lt;p&gt;When an already-exiting task oopses, make_task_dead() currently calls
do_task_dead() with preemption enabled.  That is forbidden:
do_task_dead() calls __schedule(), which has a comment saying &amp;#34;WARNING:
must be called with preemption disabled!&amp;#34;.&lt;/p&gt;
&lt;p&gt;If an oopsing task is preempted in do_task_dead(), between becoming
TASK_DEAD and entering the scheduler explicitly, bad things happen:
finish_task_switch() assumes that once the scheduler has switched away
from a TASK_DEAD task, the task can never run again and its stack is no
longer needed; but that assumption apparently doesn&amp;#39;t hold if the dead
task was preempted (the SM_PREEMPT case).&lt;/p&gt;
&lt;p&gt;This means that the scheduler ends up repeatedly dropping references on
the dead task&amp;#39;s stack, which can lead to use-after-free or double-free
of the entire task stack; in other words, two tasks can end up running
on the same stack, resulting in various kinds of memory corruption.&lt;/p&gt;
&lt;p&gt;(This does not just affect &amp;#34;recursively oopsing&amp;#34; tasks; it is enough to
oops once during task exit, for example in a file_operations::release
handler)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;exit: prevent preemption of oopsing TASK_DEAD task&lt;/p&gt;
&lt;p&gt;When an already-exiting task oopses, make_task_dead() currently calls
do_task_dead() with preemption enabled.  That is forbidden:
do_task_dead() calls __schedule(), which has a comment saying &amp;#34;WARNING:
must be called with preemption disabled!&amp;#34;.&lt;/p&gt;
&lt;p&gt;If an oopsing task is preempted in do_task_dead(), between becoming
TASK_DEAD and entering the scheduler explicitly, bad things happen:
finish_task_switch() assumes that once the scheduler has switched away
from a TASK_DEAD task, the task can never run again and its stack is no
longer needed; but that assumption apparently doesn&amp;#39;t hold if the dead
task was preempted (the SM_PREEMPT case).&lt;/p&gt;
&lt;p&gt;This means that the scheduler ends up repeatedly dropping references on
the dead task&amp;#39;s stack, which can lead to use-after-free or double-free
of the entire task stack; in other words, two tasks can end up running
on the same stack, resulting in various kinds of memory corruption.&lt;/p&gt;
&lt;p&gt;(This does not just affect &amp;#34;recursively oopsing&amp;#34; tasks; it is enough to
oops once during task exit, for example in a file_operations::release
handler)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-mpr4-2mm3-rwm6</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-46173 — exit: prevent preemption of oopsing TASK_DEAD task</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-46173</link>
      <description>msrc_CVE-2026-46173</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-46173</guid>
    </item>
    <item>
      <title>RHSA-2026:27713 — Red Hat Security Advisory: kernel security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:27713</link>
      <description>&lt;p&gt;kernel: netfilter: nf_conntrack_h323: check for zero length in DecodeQ931() kernel: mptcp: fix slab-use-after-free in __inet_lookup_established kernel: RDMA/umem: Fix double dma_buf_unpin in failure path kernel: netfilter: flowtable: strictly check for maximum number of actions kernel: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows kernel: RDMA/rxe: Fix double free in rxe_srq_from_init kernel: exit: prevent preemption of oopsing TASK_DEAD task kernel: net/sched: act_pedit: extend the writable skb range per key&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;kernel: netfilter: nf_conntrack_h323: check for zero length in DecodeQ931() kernel: mptcp: fix slab-use-after-free in __inet_lookup_established kernel: RDMA/umem: Fix double dma_buf_unpin in failure path kernel: netfilter: flowtable: strictly check for maximum number of actions kernel: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows kernel: RDMA/rxe: Fix double free in rxe_srq_from_init kernel: exit: prevent preemption of oopsing TASK_DEAD task kernel: net/sched: act_pedit: extend the writable skb range per key&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:27713</guid>
    </item>
    <item>
      <title>RLSA-2026:27288 — Important: kernel security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:27288</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: kernel&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: can: isotp: fix tx.buf use-after-free in isotp_sendmsg() (CVE-2026-31474)&lt;/p&gt;
&lt;p&gt;* kernel: mptcp: fix slab-use-after-free in __inet_lookup_established (CVE-2026-31669)&lt;/p&gt;
&lt;p&gt;* kernel: rxrpc: Fix RxGK token loading to check bounds (CVE-2026-31641)&lt;/p&gt;
&lt;p&gt;* kernel: xen/privcmd: fix double free via VMA splitting (CVE-2026-31787)&lt;/p&gt;
&lt;p&gt;* kernel: Buffer overflow in drivers/xen/sys-hypervisor.c (CVE-2026-31786)&lt;/p&gt;
&lt;p&gt;* kernel: net: mana: fix use-after-free in add_adev() error path (CVE-2026-43056)&lt;/p&gt;
&lt;p&gt;* kernel: Bluetooth: hci_sync: fix stack buffer overflow in hci_le_big_create_sync (CVE-2026-31772)&lt;/p&gt;
&lt;p&gt;* kernel: bnxt_en: Fix RSS context delete logic (CVE-2026-43260)&lt;/p&gt;
&lt;p&gt;* kernel: crypto: caam - fix overflow on long hmac keys (CVE-2026-43330)&lt;/p&gt;
&lt;p&gt;* kernel: net/sched: act_pedit: extend the writable skb range per key (CVE-2026-46331)&lt;/p&gt;
&lt;p&gt;* kernel: Bluetooth: hci_event: fix potential UAF in SSP passkey handlers (CVE-2026-46056)&lt;/p&gt;
&lt;p&gt;* kernel: wifi: mac80211: drop stray &amp;#39;static&amp;#39; from fast-RX rx_result (CVE-2026-46152)&lt;/p&gt;
&lt;p&gt;* kernel: wifi: mac80211: remove station if connection prep fails (CVE-2026-46125)&lt;/p&gt;
&lt;p&gt;* kernel: exit: prevent preemption of oopsing TASK_DEAD task (CVE-2026-46173)&lt;/p&gt;
&lt;p&gt;* kernel: wifi: mac80211: use safe list iteration in radar detect work (CVE-2026-46166)&lt;/p&gt;
&lt;p&gt;Bug Fix(es) and Enhancement(s):&lt;/p&gt;
&lt;p&gt;* Rocky Linux10.0 - s390/ap: Expose ap_bindings_complete_count counter via sysfs [rhel-10.2.z] (JIRA:Rocky Linux-166047…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: kernel&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: can: isotp: fix tx.buf use-after-free in isotp_sendmsg() (CVE-2026-31474)&lt;/p&gt;
&lt;p&gt;* kernel: mptcp: fix slab-use-after-free in __inet_lookup_established (CVE-2026-31669)&lt;/p&gt;
&lt;p&gt;* kernel: rxrpc: Fix RxGK token loading to check bounds (CVE-2026-31641)&lt;/p&gt;
&lt;p&gt;* kernel: xen/privcmd: fix double free via VMA splitting (CVE-2026-31787)&lt;/p&gt;
&lt;p&gt;* kernel: Buffer overflow in drivers/xen/sys-hypervisor.c (CVE-2026-31786)&lt;/p&gt;
&lt;p&gt;* kernel: net: mana: fix use-after-free in add_adev() error path (CVE-2026-43056)&lt;/p&gt;
&lt;p&gt;* kernel: Bluetooth: hci_sync: fix stack buffer overflow in hci_le_big_create_sync (CVE-2026-31772)&lt;/p&gt;
&lt;p&gt;* kernel: bnxt_en: Fix RSS context delete logic (CVE-2026-43260)&lt;/p&gt;
&lt;p&gt;* kernel: crypto: caam - fix overflow on long hmac keys (CVE-2026-43330)&lt;/p&gt;
&lt;p&gt;* kernel: net/sched: act_pedit: extend the writable skb range per key (CVE-2026-46331)&lt;/p&gt;
&lt;p&gt;* kernel: Bluetooth: hci_event: fix potential UAF in SSP passkey handlers (CVE-2026-46056)&lt;/p&gt;
&lt;p&gt;* kernel: wifi: mac80211: drop stray &amp;#39;static&amp;#39; from fast-RX rx_result (CVE-2026-46152)&lt;/p&gt;
&lt;p&gt;* kernel: wifi: mac80211: remove station if connection prep fails (CVE-2026-46125)&lt;/p&gt;
&lt;p&gt;* kernel: exit: prevent preemption of oopsing TASK_DEAD task (CVE-2026-46173)&lt;/p&gt;
&lt;p&gt;* kernel: wifi: mac80211: use safe list iteration in radar detect work (CVE-2026-46166)&lt;/p&gt;
&lt;p&gt;Bug Fix(es) and Enhancement(s):&lt;/p&gt;
&lt;p&gt;* Rocky Linux10.0 - s390/ap: Expose ap_bindings_complete_count counter via sysfs [rhel-10.2.z] (JIRA:Rocky Linux-166047…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:27288</guid>
    </item>
    <item>
      <title>SSA-019113 — SSA-019113: Vulnerabilities in the additional GNU/Linux subsystem of the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1.6</title>
      <link>https://cve.radiocsirt.org/vuln/ssa-019113</link>
      <description>&lt;p&gt;Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.6 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant).&lt;/p&gt;
&lt;p&gt;Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.6 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant).&lt;/p&gt;
&lt;p&gt;Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ssa-019113</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:22521-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:22521-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:22521-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-46173</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-46173</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 161 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: exit: prevent preemption of oopsing TASK_DEAD task When an already-exiting task oopses, make_task_dead() currently calls do_task_dead() with preemption enabled.  That is forbidden: do_task_dead() calls __schedule(), which has a comment saying &amp;#34;WARNING: must be called with preemption disabled!&amp;#34;. If an oopsing task is preempted in do_task_dead(), between becoming TASK_DEAD and entering the scheduler explicitly, bad things happen: finish_task_switch() assumes that once the scheduler has switched away from a TASK_DEAD task, the task can never run again and its stack is no longer needed; but that assumption apparently doesn&amp;#39;t hold if the dead task was preempted (the SM_PREEMPT case). This means that the scheduler ends up repeatedly dropping references on the dead task&amp;#39;s stack, which can lead to use-after-free or double-free of the entire task stack; in other words, two tasks can end up running on the same stack, resulting in various kinds of memory corruption. (This does not just affect &amp;#34;recursively oopsing&amp;#34; tasks; it is enough to oops once during task exit, for example in a file_operations::release handler)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 161 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: exit: prevent preemption of oopsing TASK_DEAD task When an already-exiting task oopses, make_task_dead() currently calls do_task_dead() with preemption enabled.  That is forbidden: do_task_dead() calls __schedule(), which has a comment saying &amp;#34;WARNING: must be called with preemption disabled!&amp;#34;. If an oopsing task is preempted in do_task_dead(), between becoming TASK_DEAD and entering the scheduler explicitly, bad things happen: finish_task_switch() assumes that once the scheduler has switched away from a TASK_DEAD task, the task can never run again and its stack is no longer needed; but that assumption apparently doesn&amp;#39;t hold if the dead task was preempted (the SM_PREEMPT case). This means that the scheduler ends up repeatedly dropping references on the dead task&amp;#39;s stack, which can lead to use-after-free or double-free of the entire task stack; in other words, two tasks can end up running on the same stack, resulting in various kinds of memory corruption. (This does not just affect &amp;#34;recursively oopsing&amp;#34; tasks; it is enough to oops once during task exit, for example in a file_operations::release handler)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-46173</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1700 — Linux Kernel: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1700</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen oder andere nicht näher spezifizierte Auswirkungen zu erzielen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen oder andere nicht näher spezifizierte Auswirkungen zu erzielen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1700</guid>
    </item>
  </channel>
</rss>
