<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 06:22:29 +0000</lastBuildDate>
    <item>
      <title>ALSA-2026:36018 — Important: kernel security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:36018</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: kernel, AlmaLinux:9: kernel-64k, AlmaLinux:9: kernel-64k-core, AlmaLinux:9: kernel-64k-debug, AlmaLinux:9: kernel-64k-debug-core, AlmaLinux:9: kernel-64k-debug-devel, AlmaLinux:9: kernel-64k-debug-devel-matched, AlmaLinux:9: kernel-64k-debug-modules, AlmaLinux:9: kernel-64k-debug-modules-core, AlmaLinux:9: kernel-64k-debug-modules-extra and 64 more&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: fs/smb/client: fix out-of-bounds read in cifs_sanitize_prepath (CVE-2026-43112)
  * kernel: net: mana: Fix double destroy_workqueue on service rescan PCI path (CVE-2026-43276)
  * kernel: Linux kernel: Use-After-Free in net/gro due to improper handling of zerocopy skbs (CVE-2026-46323)
  * kernel: xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete (CVE-2026-46116)
  * kernel: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (CVE-2026-46227)
  * kernel: drm/gem: Fix inconsistent plane dimension calculation in drm_gem_fb_init_with_funcs() (CVE-2026-46209)
  * kernel: smb/client: fix out-of-bounds read in smb2_compound_op() (CVE-2026-46155)
  * kernel: netfilter: nft_inner: Fix IPv6 inner_thoff desync (CVE-2026-46244)
  * kernel: procfs: fix missing RCU protection when reading real_parent in do_task_stat() (CVE-2026-46259)
  * kernel: Arm Processors: Privilege escalation or information disclosure via writes to higher exception level resources (CVE-2025-10263)
  * kernel: KVM: arm64: vgic-its: Drop the translation cache reference only for the erased entry (CVE-2026-46316)&lt;/p&gt;
&lt;p&gt;Bug Fix(es) and Enhancement(s):&lt;/p&gt;
&lt;p&gt;* WARNING at drivers/gpu/drm/nouveau/nvkm/subdev/gsp/r535.c:1585 r535_gsp_fini+0x2fb/0x310 [nouveau] [almalinux-9.8.z] (JIRA:AlmaLinux-160966)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: kernel, AlmaLinux:9: kernel-64k, AlmaLinux:9: kernel-64k-core, AlmaLinux:9: kernel-64k-debug, AlmaLinux:9: kernel-64k-debug-core, AlmaLinux:9: kernel-64k-debug-devel, AlmaLinux:9: kernel-64k-debug-devel-matched, AlmaLinux:9: kernel-64k-debug-modules, AlmaLinux:9: kernel-64k-debug-modules-core, AlmaLinux:9: kernel-64k-debug-modules-extra and 64 more&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: fs/smb/client: fix out-of-bounds read in cifs_sanitize_prepath (CVE-2026-43112)
  * kernel: net: mana: Fix double destroy_workqueue on service rescan PCI path (CVE-2026-43276)
  * kernel: Linux kernel: Use-After-Free in net/gro due to improper handling of zerocopy skbs (CVE-2026-46323)
  * kernel: xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete (CVE-2026-46116)
  * kernel: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (CVE-2026-46227)
  * kernel: drm/gem: Fix inconsistent plane dimension calculation in drm_gem_fb_init_with_funcs() (CVE-2026-46209)
  * kernel: smb/client: fix out-of-bounds read in smb2_compound_op() (CVE-2026-46155)
  * kernel: netfilter: nft_inner: Fix IPv6 inner_thoff desync (CVE-2026-46244)
  * kernel: procfs: fix missing RCU protection when reading real_parent in do_task_stat() (CVE-2026-46259)
  * kernel: Arm Processors: Privilege escalation or information disclosure via writes to higher exception level resources (CVE-2025-10263)
  * kernel: KVM: arm64: vgic-its: Drop the translation cache reference only for the erased entry (CVE-2026-46316)&lt;/p&gt;
&lt;p&gt;Bug Fix(es) and Enhancement(s):&lt;/p&gt;
&lt;p&gt;* WARNING at drivers/gpu/drm/nouveau/nvkm/subdev/gsp/r535.c:1585 r535_gsp_fini+0x2fb/0x310 [nouveau] [almalinux-9.8.z] (JIRA:AlmaLinux-160966)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:36018</guid>
    </item>
    <item>
      <title>bdu:2026-11810</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-11810</link>
      <description>bdu:2026-11810</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-11810</guid>
    </item>
    <item>
      <title>BELL-CVE-2026-46323</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-46323</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-46323</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0787 — De multiples vulnérabilités ont été découvertes dans le noyau Linux d'Ubuntu. Certaines d'entre elles permettent à un a…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0787</link>
      <description>certfr-2026-avi-0787</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0787</guid>
    </item>
    <item>
      <title>ESSA-2026:0155 — Important: kernel security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/essa-2026:0155</link>
      <description>&lt;p&gt;Important: kernel security, bug fix, and enhancement update&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Important: kernel security, bug fix, and enhancement update&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/essa-2026:0155</guid>
    </item>
    <item>
      <title>EUVD-2026-364823</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-364823</link>
      <description>EUVD-2026-364823</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-364823</guid>
    </item>
    <item>
      <title>fkie_cve-2026-46323</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-46323</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;net: gro: don&amp;#39;t merge zcopy skbs&lt;/p&gt;
&lt;p&gt;skb_gro_receive() can currently copy frags between the source and GRO
skb, without checking the zerocopy status, and in particular the
SKBFL_MANAGED_FRAG_REFS flag.&lt;/p&gt;
&lt;p&gt;When SKBFL_MANAGED_FRAG_REFS is set, the skb doesn&amp;#39;t hold a reference
on the pages in shinfo-&amp;gt;frags. Appending those frags to another skb&amp;#39;s
frags without fixing up the page refcount can lead to UAF.&lt;/p&gt;
&lt;p&gt;When either the last skb in the GRO chain (the one we would append
frags to) or the source skb is zerocopy, don&amp;#39;t merge the skbs.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;net: gro: don&amp;#39;t merge zcopy skbs&lt;/p&gt;
&lt;p&gt;skb_gro_receive() can currently copy frags between the source and GRO
skb, without checking the zerocopy status, and in particular the
SKBFL_MANAGED_FRAG_REFS flag.&lt;/p&gt;
&lt;p&gt;When SKBFL_MANAGED_FRAG_REFS is set, the skb doesn&amp;#39;t hold a reference
on the pages in shinfo-&amp;gt;frags. Appending those frags to another skb&amp;#39;s
frags without fixing up the page refcount can lead to UAF.&lt;/p&gt;
&lt;p&gt;When either the last skb in the GRO chain (the one we would append
frags to) or the source skb is zerocopy, don&amp;#39;t merge the skbs.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-46323</guid>
    </item>
    <item>
      <title>GHSA-hf4r-hm8m-w52j</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-hf4r-hm8m-w52j</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;net: gro: don&amp;#39;t merge zcopy skbs&lt;/p&gt;
&lt;p&gt;skb_gro_receive() can currently copy frags between the source and GRO
skb, without checking the zerocopy status, and in particular the
SKBFL_MANAGED_FRAG_REFS flag.&lt;/p&gt;
&lt;p&gt;When SKBFL_MANAGED_FRAG_REFS is set, the skb doesn&amp;#39;t hold a reference
on the pages in shinfo-&amp;gt;frags. Appending those frags to another skb&amp;#39;s
frags without fixing up the page refcount can lead to UAF.&lt;/p&gt;
&lt;p&gt;When either the last skb in the GRO chain (the one we would append
frags to) or the source skb is zerocopy, don&amp;#39;t merge the skbs.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;net: gro: don&amp;#39;t merge zcopy skbs&lt;/p&gt;
&lt;p&gt;skb_gro_receive() can currently copy frags between the source and GRO
skb, without checking the zerocopy status, and in particular the
SKBFL_MANAGED_FRAG_REFS flag.&lt;/p&gt;
&lt;p&gt;When SKBFL_MANAGED_FRAG_REFS is set, the skb doesn&amp;#39;t hold a reference
on the pages in shinfo-&amp;gt;frags. Appending those frags to another skb&amp;#39;s
frags without fixing up the page refcount can lead to UAF.&lt;/p&gt;
&lt;p&gt;When either the last skb in the GRO chain (the one we would append
frags to) or the source skb is zerocopy, don&amp;#39;t merge the skbs.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-hf4r-hm8m-w52j</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-46323 — net: gro: don't merge zcopy skbs</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-46323</link>
      <description>msrc_CVE-2026-46323</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-46323</guid>
    </item>
    <item>
      <title>OESA-2026-2869 — kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-2869</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP3: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;Arm C1-Ultra, C1-Premium, Neoverse V3 &amp;amp;amp; V3AE, Neoverse V2, Neoverse V1, Neoverse-N2, Neoverse-N1, Cortex-X925, Cortex-X4, Cortex-X3, Cortex-X2, Cortex-X1 &amp;amp;amp; X1C, Cortex-A710, Cortex-A78, A78AE &amp;amp;amp; A78C, Cortex-A77, Cortex-A76 &amp;amp;amp; A76A may allow writes to resources owned by a higher exception level.(CVE-2025-10263)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;smb: client: let smbd_destroy() call disable_work_sync(&amp;amp;amp;info-&amp;amp;gt;post_send_credits_work)&lt;/p&gt;
&lt;p&gt;In smbd_destroy() we may destroy the memory so we better
wait until post_send_credits_work is no longer pending
and will never be started again.&lt;/p&gt;
&lt;p&gt;I actually just hit the case using rxe:&lt;/p&gt;
&lt;p&gt;WARNING: CPU: 0 PID: 138 at drivers/infiniband/sw/rxe/rxe_verbs.c:1032 rxe_post_recv+0x1ee/0x480 [rdma_rxe]
...
[ 5305.686979] [    T138]  smbd_post_recv+0x445/0xc10 [cifs]
[ 5305.687135] [    T138]  ? srso_alias_return_thunk+0x5/0xfbef5
[ 5305.687149] [    T138]  ? __kasan_check_write+0x14/0x30
[ 5305.687185] [    T138]  ? __pfx_smbd_post_recv+0x10/0x10 [cifs]
[ 5305.687329] [    T138]  ? __pfx__raw_spin_lock_irqsave+0x10/0x10
[ 5305.687356] [    T138]  ? srso_alias_return_thunk+0x5/0xfbef5
[ 5305.687368] [    T138]  ? srso_alias_return_thunk+0x5/0xfbef5
[ 5305.687378] [    T138]  ? _raw_spin_unlock_irqrestore+0x11/0x60
[ 5305.687389] [    T138]  ? srso_alias_return_thunk+0x5/0xfbef5
[ 5305.687399] [    T138]  ? get_receive_buffer+0x168…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP3: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;Arm C1-Ultra, C1-Premium, Neoverse V3 &amp;amp;amp; V3AE, Neoverse V2, Neoverse V1, Neoverse-N2, Neoverse-N1, Cortex-X925, Cortex-X4, Cortex-X3, Cortex-X2, Cortex-X1 &amp;amp;amp; X1C, Cortex-A710, Cortex-A78, A78AE &amp;amp;amp; A78C, Cortex-A77, Cortex-A76 &amp;amp;amp; A76A may allow writes to resources owned by a higher exception level.(CVE-2025-10263)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;smb: client: let smbd_destroy() call disable_work_sync(&amp;amp;amp;info-&amp;amp;gt;post_send_credits_work)&lt;/p&gt;
&lt;p&gt;In smbd_destroy() we may destroy the memory so we better
wait until post_send_credits_work is no longer pending
and will never be started again.&lt;/p&gt;
&lt;p&gt;I actually just hit the case using rxe:&lt;/p&gt;
&lt;p&gt;WARNING: CPU: 0 PID: 138 at drivers/infiniband/sw/rxe/rxe_verbs.c:1032 rxe_post_recv+0x1ee/0x480 [rdma_rxe]
...
[ 5305.686979] [    T138]  smbd_post_recv+0x445/0xc10 [cifs]
[ 5305.687135] [    T138]  ? srso_alias_return_thunk+0x5/0xfbef5
[ 5305.687149] [    T138]  ? __kasan_check_write+0x14/0x30
[ 5305.687185] [    T138]  ? __pfx_smbd_post_recv+0x10/0x10 [cifs]
[ 5305.687329] [    T138]  ? __pfx__raw_spin_lock_irqsave+0x10/0x10
[ 5305.687356] [    T138]  ? srso_alias_return_thunk+0x5/0xfbef5
[ 5305.687368] [    T138]  ? srso_alias_return_thunk+0x5/0xfbef5
[ 5305.687378] [    T138]  ? _raw_spin_unlock_irqrestore+0x11/0x60
[ 5305.687389] [    T138]  ? srso_alias_return_thunk+0x5/0xfbef5
[ 5305.687399] [    T138]  ? get_receive_buffer+0x168…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-2869</guid>
    </item>
    <item>
      <title>RHSA-2026:27708 — Red Hat Security Advisory: kernel security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:27708</link>
      <description>&lt;p&gt;kernel: ceph: kernel: Ceph: exploit of hardcoded IVECs, in a misuse of AES, resulting in authentication bypass kernel: smc: Fix use-after-free in __pnet_find_base_ndev() kernel: smc: Use __sk_dst_get() and dst_dev_rcu() in smc_clc_prfx_match() kernel: Linux kernel: Denial of Service in libceph OSD client due to unreset sparse-read state kernel: netfilter: ctnetlink: ensure safe access to master conntrack kernel: xfs: fix freemap adjustments when adding xattrs to leaf blocks kernel: mm/page_alloc: clear page-&amp;gt;private in free_pages_prepare() kernel: RDMA/iwcm: Fix workqueue list corruption by removing work_list kernel: wifi: mac80211: remove station if connection prep fails kernel: wifi: mac80211: use safe list iteration in radar detect work kernel: Linux kernel: smb: client: reject userspace cifs.spnego descriptions kernel: Linux kernel: Use-After-Free in net/gro due to improper handling of zerocopy skbs kernel: net/sched: act_pedit: extend the writable skb range per key&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;kernel: ceph: kernel: Ceph: exploit of hardcoded IVECs, in a misuse of AES, resulting in authentication bypass kernel: smc: Fix use-after-free in __pnet_find_base_ndev() kernel: smc: Use __sk_dst_get() and dst_dev_rcu() in smc_clc_prfx_match() kernel: Linux kernel: Denial of Service in libceph OSD client due to unreset sparse-read state kernel: netfilter: ctnetlink: ensure safe access to master conntrack kernel: xfs: fix freemap adjustments when adding xattrs to leaf blocks kernel: mm/page_alloc: clear page-&amp;gt;private in free_pages_prepare() kernel: RDMA/iwcm: Fix workqueue list corruption by removing work_list kernel: wifi: mac80211: remove station if connection prep fails kernel: wifi: mac80211: use safe list iteration in radar detect work kernel: Linux kernel: smb: client: reject userspace cifs.spnego descriptions kernel: Linux kernel: Use-After-Free in net/gro due to improper handling of zerocopy skbs kernel: net/sched: act_pedit: extend the writable skb range per key&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:27708</guid>
    </item>
    <item>
      <title>RLSA-2026:36018 — Important: kernel security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:36018</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:9: kernel&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: fs/smb/client: fix out-of-bounds read in cifs_sanitize_prepath (CVE-2026-43112)&lt;/p&gt;
&lt;p&gt;* kernel: net: mana: Fix double destroy_workqueue on service rescan PCI path (CVE-2026-43276)&lt;/p&gt;
&lt;p&gt;* kernel: Linux kernel: Use-After-Free in net/gro due to improper handling of zerocopy skbs (CVE-2026-46323)&lt;/p&gt;
&lt;p&gt;* kernel: xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete (CVE-2026-46116)&lt;/p&gt;
&lt;p&gt;* kernel: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (CVE-2026-46227)&lt;/p&gt;
&lt;p&gt;* kernel: drm/gem: Fix inconsistent plane dimension calculation in drm_gem_fb_init_with_funcs() (CVE-2026-46209)&lt;/p&gt;
&lt;p&gt;* kernel: smb/client: fix out-of-bounds read in smb2_compound_op() (CVE-2026-46155)&lt;/p&gt;
&lt;p&gt;* kernel: netfilter: nft_inner: Fix IPv6 inner_thoff desync (CVE-2026-46244)&lt;/p&gt;
&lt;p&gt;* kernel: procfs: fix missing RCU protection when reading real_parent in do_task_stat() (CVE-2026-46259)&lt;/p&gt;
&lt;p&gt;* kernel: Arm Processors: Privilege escalation or information disclosure via writes to higher exception level resources (CVE-2025-10263)&lt;/p&gt;
&lt;p&gt;* kernel: KVM: arm64: vgic-its: Drop the translation cache reference only for the erased entry (CVE-2026-46316)&lt;/p&gt;
&lt;p&gt;Bug Fix(es) and Enhancement(s):&lt;/p&gt;
&lt;p&gt;* WARNING at drivers/gpu/drm/nouveau/nvkm/subdev/gsp/r535.c:1585 r535_gsp_fini+0x2fb/0x310 [nouveau] [rhel-9.8.z] (JIRA:Rocky Linux-160966)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgme…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:9: kernel&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: fs/smb/client: fix out-of-bounds read in cifs_sanitize_prepath (CVE-2026-43112)&lt;/p&gt;
&lt;p&gt;* kernel: net: mana: Fix double destroy_workqueue on service rescan PCI path (CVE-2026-43276)&lt;/p&gt;
&lt;p&gt;* kernel: Linux kernel: Use-After-Free in net/gro due to improper handling of zerocopy skbs (CVE-2026-46323)&lt;/p&gt;
&lt;p&gt;* kernel: xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete (CVE-2026-46116)&lt;/p&gt;
&lt;p&gt;* kernel: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (CVE-2026-46227)&lt;/p&gt;
&lt;p&gt;* kernel: drm/gem: Fix inconsistent plane dimension calculation in drm_gem_fb_init_with_funcs() (CVE-2026-46209)&lt;/p&gt;
&lt;p&gt;* kernel: smb/client: fix out-of-bounds read in smb2_compound_op() (CVE-2026-46155)&lt;/p&gt;
&lt;p&gt;* kernel: netfilter: nft_inner: Fix IPv6 inner_thoff desync (CVE-2026-46244)&lt;/p&gt;
&lt;p&gt;* kernel: procfs: fix missing RCU protection when reading real_parent in do_task_stat() (CVE-2026-46259)&lt;/p&gt;
&lt;p&gt;* kernel: Arm Processors: Privilege escalation or information disclosure via writes to higher exception level resources (CVE-2025-10263)&lt;/p&gt;
&lt;p&gt;* kernel: KVM: arm64: vgic-its: Drop the translation cache reference only for the erased entry (CVE-2026-46316)&lt;/p&gt;
&lt;p&gt;Bug Fix(es) and Enhancement(s):&lt;/p&gt;
&lt;p&gt;* WARNING at drivers/gpu/drm/nouveau/nvkm/subdev/gsp/r535.c:1585 r535_gsp_fini+0x2fb/0x310 [nouveau] [rhel-9.8.z] (JIRA:Rocky Linux-160966)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgme…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:36018</guid>
    </item>
    <item>
      <title>SSA-019113 — SSA-019113: Vulnerabilities in the additional GNU/Linux subsystem of the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1.6</title>
      <link>https://cve.radiocsirt.org/vuln/ssa-019113</link>
      <description>&lt;p&gt;Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.6 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant).&lt;/p&gt;
&lt;p&gt;Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.6 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant).&lt;/p&gt;
&lt;p&gt;Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ssa-019113</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:22276-1 — Security update for the Linux Kernel (Live Patch 0 for SUSE Linux Enterprise 16)</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:22276-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel (Live Patch 0 for SUSE Linux Enterprise 16)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel (Live Patch 0 for SUSE Linux Enterprise 16)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:22276-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-46323</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-46323</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 153 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: net: gro: don&amp;#39;t merge zcopy skbs skb_gro_receive() can currently copy frags between the source and GRO skb, without checking the zerocopy status, and in particular the SKBFL_MANAGED_FRAG_REFS flag. When SKBFL_MANAGED_FRAG_REFS is set, the skb doesn&amp;#39;t hold a reference on the pages in shinfo-&amp;gt;frags. Appending those frags to another skb&amp;#39;s frags without fixing up the page refcount can lead to UAF. When either the last skb in the GRO chain (the one we would append frags to) or the source skb is zerocopy, don&amp;#39;t merge the skbs.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 153 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: net: gro: don&amp;#39;t merge zcopy skbs skb_gro_receive() can currently copy frags between the source and GRO skb, without checking the zerocopy status, and in particular the SKBFL_MANAGED_FRAG_REFS flag. When SKBFL_MANAGED_FRAG_REFS is set, the skb doesn&amp;#39;t hold a reference on the pages in shinfo-&amp;gt;frags. Appending those frags to another skb&amp;#39;s frags without fixing up the page refcount can lead to UAF. When either the last skb in the GRO chain (the one we would append frags to) or the source skb is zerocopy, don&amp;#39;t merge the skbs.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-46323</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1870 — Linux Kernel: Mehrere Schwachstellen ermöglichen Denial of Service</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1870</link>
      <description>&lt;p&gt;Eiin Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen Denial-of-Service-Zustand zu erzeugen oder andere, nicht näher bezeichnete Angriffe durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Eiin Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen Denial-of-Service-Zustand zu erzeugen oder andere, nicht näher bezeichnete Angriffe durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1870</guid>
    </item>
  </channel>
</rss>
