<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 08:49:27 +0000</lastBuildDate>
    <item>
      <title>BELL-CVE-2026-46299</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-46299</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-46299</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0783 — De multiples vulnérabilités ont été découvertes dans Microsoft Azure. Elles permettent à un attaquant de provoquer une…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0783</link>
      <description>certfr-2026-avi-0783</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0783</guid>
    </item>
    <item>
      <title>EUVD-2026-348068</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-348068</link>
      <description>EUVD-2026-348068</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-348068</guid>
    </item>
    <item>
      <title>fkie_cve-2026-46299</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-46299</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;hfsplus: fix held lock freed on hfsplus_fill_super()&lt;/p&gt;
&lt;p&gt;hfsplus_fill_super() calls hfs_find_init() to initialize a search
structure, which acquires tree-&amp;gt;tree_lock. If the subsequent call to
hfsplus_cat_build_key() fails, the function jumps to the out_put_root
error label without releasing the lock. The later cleanup path then
frees the tree data structure with the lock still held, triggering a
held lock freed warning.&lt;/p&gt;
&lt;p&gt;Fix this by adding the missing hfs_find_exit(&amp;amp;fd) call before jumping
to the out_put_root error label. This ensures that tree-&amp;gt;tree_lock is
properly released on the error path.&lt;/p&gt;
&lt;p&gt;The bug was originally detected on v6.13-rc1 using an experimental
static analysis tool we are developing, and we have verified that the
issue persists in the latest mainline kernel. The tool is specifically
designed to detect memory management issues. It is currently under active
development and not yet publicly available.&lt;/p&gt;
&lt;p&gt;We confirmed the bug by runtime testing under QEMU with x86_64 defconfig,
lockdep enabled, and CONFIG_HFSPLUS_FS=y. To trigger the error path, we
used GDB to dynamically shrink the max_unistr_len parameter to 1 before
hfsplus_asc2uni() is called. This forces hfsplus_asc2uni() to naturally
return -ENAMETOOLONG, which propagates to hfsplus_cat_build_key() and
exercises the faulty error path. The following warning was observed
during mount:&lt;/p&gt;
&lt;p&gt;=========================
	WARNING: held lock freed!
	7.0.0…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;hfsplus: fix held lock freed on hfsplus_fill_super()&lt;/p&gt;
&lt;p&gt;hfsplus_fill_super() calls hfs_find_init() to initialize a search
structure, which acquires tree-&amp;gt;tree_lock. If the subsequent call to
hfsplus_cat_build_key() fails, the function jumps to the out_put_root
error label without releasing the lock. The later cleanup path then
frees the tree data structure with the lock still held, triggering a
held lock freed warning.&lt;/p&gt;
&lt;p&gt;Fix this by adding the missing hfs_find_exit(&amp;amp;fd) call before jumping
to the out_put_root error label. This ensures that tree-&amp;gt;tree_lock is
properly released on the error path.&lt;/p&gt;
&lt;p&gt;The bug was originally detected on v6.13-rc1 using an experimental
static analysis tool we are developing, and we have verified that the
issue persists in the latest mainline kernel. The tool is specifically
designed to detect memory management issues. It is currently under active
development and not yet publicly available.&lt;/p&gt;
&lt;p&gt;We confirmed the bug by runtime testing under QEMU with x86_64 defconfig,
lockdep enabled, and CONFIG_HFSPLUS_FS=y. To trigger the error path, we
used GDB to dynamically shrink the max_unistr_len parameter to 1 before
hfsplus_asc2uni() is called. This forces hfsplus_asc2uni() to naturally
return -ENAMETOOLONG, which propagates to hfsplus_cat_build_key() and
exercises the faulty error path. The following warning was observed
during mount:&lt;/p&gt;
&lt;p&gt;=========================
	WARNING: held lock freed!
	7.0.0…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-46299</guid>
    </item>
    <item>
      <title>GHSA-r7xr-jh3w-26ww</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-r7xr-jh3w-26ww</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;hfsplus: fix held lock freed on hfsplus_fill_super()&lt;/p&gt;
&lt;p&gt;hfsplus_fill_super() calls hfs_find_init() to initialize a search
structure, which acquires tree-&amp;gt;tree_lock. If the subsequent call to
hfsplus_cat_build_key() fails, the function jumps to the out_put_root
error label without releasing the lock. The later cleanup path then
frees the tree data structure with the lock still held, triggering a
held lock freed warning.&lt;/p&gt;
&lt;p&gt;Fix this by adding the missing hfs_find_exit(&amp;amp;fd) call before jumping
to the out_put_root error label. This ensures that tree-&amp;gt;tree_lock is
properly released on the error path.&lt;/p&gt;
&lt;p&gt;The bug was originally detected on v6.13-rc1 using an experimental
static analysis tool we are developing, and we have verified that the
issue persists in the latest mainline kernel. The tool is specifically
designed to detect memory management issues. It is currently under active
development and not yet publicly available.&lt;/p&gt;
&lt;p&gt;We confirmed the bug by runtime testing under QEMU with x86_64 defconfig,
lockdep enabled, and CONFIG_HFSPLUS_FS=y. To trigger the error path, we
used GDB to dynamically shrink the max_unistr_len parameter to 1 before
hfsplus_asc2uni() is called. This forces hfsplus_asc2uni() to naturally
return -ENAMETOOLONG, which propagates to hfsplus_cat_build_key() and
exercises the faulty error path. The following warning was observed
during mount:&lt;/p&gt;
&lt;p&gt;=========================
	WARNING: held lock freed!
	7.0.0…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;hfsplus: fix held lock freed on hfsplus_fill_super()&lt;/p&gt;
&lt;p&gt;hfsplus_fill_super() calls hfs_find_init() to initialize a search
structure, which acquires tree-&amp;gt;tree_lock. If the subsequent call to
hfsplus_cat_build_key() fails, the function jumps to the out_put_root
error label without releasing the lock. The later cleanup path then
frees the tree data structure with the lock still held, triggering a
held lock freed warning.&lt;/p&gt;
&lt;p&gt;Fix this by adding the missing hfs_find_exit(&amp;amp;fd) call before jumping
to the out_put_root error label. This ensures that tree-&amp;gt;tree_lock is
properly released on the error path.&lt;/p&gt;
&lt;p&gt;The bug was originally detected on v6.13-rc1 using an experimental
static analysis tool we are developing, and we have verified that the
issue persists in the latest mainline kernel. The tool is specifically
designed to detect memory management issues. It is currently under active
development and not yet publicly available.&lt;/p&gt;
&lt;p&gt;We confirmed the bug by runtime testing under QEMU with x86_64 defconfig,
lockdep enabled, and CONFIG_HFSPLUS_FS=y. To trigger the error path, we
used GDB to dynamically shrink the max_unistr_len parameter to 1 before
hfsplus_asc2uni() is called. This forces hfsplus_asc2uni() to naturally
return -ENAMETOOLONG, which propagates to hfsplus_cat_build_key() and
exercises the faulty error path. The following warning was observed
during mount:&lt;/p&gt;
&lt;p&gt;=========================
	WARNING: held lock freed!
	7.0.0…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-r7xr-jh3w-26ww</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-46299 — hfsplus: fix held lock freed on hfsplus_fill_super()</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-46299</link>
      <description>msrc_CVE-2026-46299</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-46299</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:11014-1 — kernel-devel-7.0.12-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11014-1</link>
      <description>&lt;p&gt;kernel-devel-7.0.12-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;kernel-devel-7.0.12-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:11014-1</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:2914-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:2914-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:2914-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-46299</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-46299</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe, Ubuntu:16.04:LTS: linux-hwe-edge and 252 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: hfsplus: fix held lock freed on hfsplus_fill_super() hfsplus_fill_super() calls hfs_find_init() to initialize a search structure, which acquires tree-&amp;gt;tree_lock. If the subsequent call to hfsplus_cat_build_key() fails, the function jumps to the out_put_root error label without releasing the lock. The later cleanup path then frees the tree data structure with the lock still held, triggering a held lock freed warning. Fix this by adding the missing hfs_find_exit(&amp;amp;fd) call before jumping to the out_put_root error label. This ensures that tree-&amp;gt;tree_lock is properly released on the error path. The bug was originally detected on v6.13-rc1 using an experimental static analysis tool we are developing, and we have verified that the issue persists in the latest mainline kernel. The tool is specifically designed to detect memory management issues. It is currently under active development and not yet publicly available. We confirmed the bug by runtime testing under QEMU with x86_64 defconfig, lockdep enabled, and CONFIG_HFSPLUS_FS=y. To trigger the error path, we used GDB to dynamically shrink the max_unistr_len parameter to 1 before hfsplus_asc2uni() is called. This forces hfsplus_asc2uni() to naturally return -ENAMETOOLONG, which propagates to hfsplus_cat_build_key() and exercises the faulty error path. The following warning was observed during mount: 	========================= 	WARNING: held lock freed! 	7.0.0-rc3-0…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe, Ubuntu:16.04:LTS: linux-hwe-edge and 252 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: hfsplus: fix held lock freed on hfsplus_fill_super() hfsplus_fill_super() calls hfs_find_init() to initialize a search structure, which acquires tree-&amp;gt;tree_lock. If the subsequent call to hfsplus_cat_build_key() fails, the function jumps to the out_put_root error label without releasing the lock. The later cleanup path then frees the tree data structure with the lock still held, triggering a held lock freed warning. Fix this by adding the missing hfs_find_exit(&amp;amp;fd) call before jumping to the out_put_root error label. This ensures that tree-&amp;gt;tree_lock is properly released on the error path. The bug was originally detected on v6.13-rc1 using an experimental static analysis tool we are developing, and we have verified that the issue persists in the latest mainline kernel. The tool is specifically designed to detect memory management issues. It is currently under active development and not yet publicly available. We confirmed the bug by runtime testing under QEMU with x86_64 defconfig, lockdep enabled, and CONFIG_HFSPLUS_FS=y. To trigger the error path, we used GDB to dynamically shrink the max_unistr_len parameter to 1 before hfsplus_asc2uni() is called. This forces hfsplus_asc2uni() to naturally return -ENAMETOOLONG, which propagates to hfsplus_cat_build_key() and exercises the faulty error path. The following warning was observed during mount: 	========================= 	WARNING: held lock freed! 	7.0.0-rc3-0…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-46299</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1827 — Linux Kernel: Mehrere Schwachstellen ermöglichen Denial of Service</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1827</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen oder nicht bekannte Auswirkungen zu erzielen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen oder nicht bekannte Auswirkungen zu erzielen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1827</guid>
    </item>
  </channel>
</rss>
