<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 17:33:11 +0000</lastBuildDate>
    <item>
      <title>ALSA-2026:64808 — Important: kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:64808</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: kernel, AlmaLinux:9: kernel-64k, AlmaLinux:9: kernel-64k-core, AlmaLinux:9: kernel-64k-debug, AlmaLinux:9: kernel-64k-debug-core, AlmaLinux:9: kernel-64k-debug-devel, AlmaLinux:9: kernel-64k-debug-devel-matched, AlmaLinux:9: kernel-64k-debug-modules, AlmaLinux:9: kernel-64k-debug-modules-core, AlmaLinux:9: kernel-64k-debug-modules-extra and 64 more&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: can: bcm: add locking for bcm_op runtime updates (CVE-2025-38004)
  * kernel: io_uring/poll: fix signed comparison in io_poll_get_ownership() (CVE-2026-52933)
  * kernel: netfilter: nat: use kfree_rcu to release ops (CVE-2026-53000)
  * kernel: smb: client: protect tc_count increment in smb2_find_smb_sess_tcon_unlocked() (CVE-2026-64136)
  * kernel: nvmet: fix pre-auth out-of-bounds heap read in Discovery Get Log Page (CVE-2026-64320)
  * kernel: nvmet-auth: validate reply message payload bounds against transfer length (CVE-2026-64319)
  * kernel: KVM: arm64: Bound used_lrs when flushing the pKVM hyp vCPU (CVE-2026-64287)
  * kernel: smb: client: fix change notify replay double-free (CVE-2026-64384)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: kernel, AlmaLinux:9: kernel-64k, AlmaLinux:9: kernel-64k-core, AlmaLinux:9: kernel-64k-debug, AlmaLinux:9: kernel-64k-debug-core, AlmaLinux:9: kernel-64k-debug-devel, AlmaLinux:9: kernel-64k-debug-devel-matched, AlmaLinux:9: kernel-64k-debug-modules, AlmaLinux:9: kernel-64k-debug-modules-core, AlmaLinux:9: kernel-64k-debug-modules-extra and 64 more&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: can: bcm: add locking for bcm_op runtime updates (CVE-2025-38004)
  * kernel: io_uring/poll: fix signed comparison in io_poll_get_ownership() (CVE-2026-52933)
  * kernel: netfilter: nat: use kfree_rcu to release ops (CVE-2026-53000)
  * kernel: smb: client: protect tc_count increment in smb2_find_smb_sess_tcon_unlocked() (CVE-2026-64136)
  * kernel: nvmet: fix pre-auth out-of-bounds heap read in Discovery Get Log Page (CVE-2026-64320)
  * kernel: nvmet-auth: validate reply message payload bounds against transfer length (CVE-2026-64319)
  * kernel: KVM: arm64: Bound used_lrs when flushing the pKVM hyp vCPU (CVE-2026-64287)
  * kernel: smb: client: fix change notify replay double-free (CVE-2026-64384)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:64808</guid>
    </item>
    <item>
      <title>bdu:2026-14797</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-14797</link>
      <description>bdu:2026-14797</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-14797</guid>
    </item>
    <item>
      <title>BELL-CVE-2026-52933</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-52933</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-52933</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0831 — De multiples vulnérabilités ont été découvertes dans le noyau Linux d'Ubuntu. Certaines d'entre elles permettent à un a…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0831</link>
      <description>certfr-2026-avi-0831</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0831</guid>
    </item>
    <item>
      <title>EUVD-2026-364828</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-364828</link>
      <description>EUVD-2026-364828</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-364828</guid>
    </item>
    <item>
      <title>fkie_cve-2026-52933</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-52933</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;io_uring/poll: fix signed comparison in io_poll_get_ownership()&lt;/p&gt;
&lt;p&gt;io_poll_get_ownership() uses a signed comparison to check whether
poll_refs has reached the threshold for the slowpath:&lt;/p&gt;
&lt;p&gt;if (unlikely(atomic_read(&amp;amp;req-&amp;gt;poll_refs) &amp;gt;= IO_POLL_REF_BIAS))&lt;/p&gt;
&lt;p&gt;atomic_read() returns int (signed). When IO_POLL_CANCEL_FLAG
(BIT(31)) is set in poll_refs, the value becomes negative in
signed arithmetic, so the &amp;gt;= 128 comparison always evaluates to
false and the slowpath is never taken.&lt;/p&gt;
&lt;p&gt;Fix this by casting the atomic_read() result to unsigned int
before the comparison, so that the cancel flag is treated as a
large positive value and correctly triggers the slowpath.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;io_uring/poll: fix signed comparison in io_poll_get_ownership()&lt;/p&gt;
&lt;p&gt;io_poll_get_ownership() uses a signed comparison to check whether
poll_refs has reached the threshold for the slowpath:&lt;/p&gt;
&lt;p&gt;if (unlikely(atomic_read(&amp;amp;req-&amp;gt;poll_refs) &amp;gt;= IO_POLL_REF_BIAS))&lt;/p&gt;
&lt;p&gt;atomic_read() returns int (signed). When IO_POLL_CANCEL_FLAG
(BIT(31)) is set in poll_refs, the value becomes negative in
signed arithmetic, so the &amp;gt;= 128 comparison always evaluates to
false and the slowpath is never taken.&lt;/p&gt;
&lt;p&gt;Fix this by casting the atomic_read() result to unsigned int
before the comparison, so that the cancel flag is treated as a
large positive value and correctly triggers the slowpath.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-52933</guid>
    </item>
    <item>
      <title>GHSA-37vf-c5qj-3jr7</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-37vf-c5qj-3jr7</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;io_uring/poll: fix signed comparison in io_poll_get_ownership()&lt;/p&gt;
&lt;p&gt;io_poll_get_ownership() uses a signed comparison to check whether
poll_refs has reached the threshold for the slowpath:&lt;/p&gt;
&lt;p&gt;if (unlikely(atomic_read(&amp;amp;req-&amp;gt;poll_refs) &amp;gt;= IO_POLL_REF_BIAS))&lt;/p&gt;
&lt;p&gt;atomic_read() returns int (signed). When IO_POLL_CANCEL_FLAG
(BIT(31)) is set in poll_refs, the value becomes negative in
signed arithmetic, so the &amp;gt;= 128 comparison always evaluates to
false and the slowpath is never taken.&lt;/p&gt;
&lt;p&gt;Fix this by casting the atomic_read() result to unsigned int
before the comparison, so that the cancel flag is treated as a
large positive value and correctly triggers the slowpath.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;io_uring/poll: fix signed comparison in io_poll_get_ownership()&lt;/p&gt;
&lt;p&gt;io_poll_get_ownership() uses a signed comparison to check whether
poll_refs has reached the threshold for the slowpath:&lt;/p&gt;
&lt;p&gt;if (unlikely(atomic_read(&amp;amp;req-&amp;gt;poll_refs) &amp;gt;= IO_POLL_REF_BIAS))&lt;/p&gt;
&lt;p&gt;atomic_read() returns int (signed). When IO_POLL_CANCEL_FLAG
(BIT(31)) is set in poll_refs, the value becomes negative in
signed arithmetic, so the &amp;gt;= 128 comparison always evaluates to
false and the slowpath is never taken.&lt;/p&gt;
&lt;p&gt;Fix this by casting the atomic_read() result to unsigned int
before the comparison, so that the cancel flag is treated as a
large positive value and correctly triggers the slowpath.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-37vf-c5qj-3jr7</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-52933 — io_uring/poll: fix signed comparison in io_poll_get_ownership()</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-52933</link>
      <description>msrc_CVE-2026-52933</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-52933</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:21388-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:21388-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:21388-1</guid>
    </item>
    <item>
      <title>RHSA-2026:65708 — Red Hat Security Advisory: kernel security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:65708</link>
      <description>&lt;p&gt;kernel: rxrpc: Fix potential UAF after skb_unshare() failure kernel: smb/client: fix out-of-bounds read in smb2_compound_op() kernel: io_uring/poll: fix signed comparison in io_poll_get_ownership() kernel: zram: fix use-after-free in zram_bvec_write_partial() kernel: USB: serial: io_ti: fix heap overflow in get_manuf_info() kernel: scsi: target: iscsi: Validate CHAP_R length before base64 decode kernel: i2c: stub: Reject I2C block transfers with invalid length kernel: posix-cpu-timers: Prevent UAF caused by non-leader exec() race&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;kernel: rxrpc: Fix potential UAF after skb_unshare() failure kernel: smb/client: fix out-of-bounds read in smb2_compound_op() kernel: io_uring/poll: fix signed comparison in io_poll_get_ownership() kernel: zram: fix use-after-free in zram_bvec_write_partial() kernel: USB: serial: io_ti: fix heap overflow in get_manuf_info() kernel: scsi: target: iscsi: Validate CHAP_R length before base64 decode kernel: i2c: stub: Reject I2C block transfers with invalid length kernel: posix-cpu-timers: Prevent UAF caused by non-leader exec() race&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:65708</guid>
    </item>
    <item>
      <title>RLSA-2026:64775 — Important: kernel security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:64775</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: kernel&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: can: bcm: add locking for bcm_op runtime updates (CVE-2025-38004)&lt;/p&gt;
&lt;p&gt;* kernel: ipv6: add NULL checks for idev in SRv6 paths (CVE-2026-23442)&lt;/p&gt;
&lt;p&gt;* kernel: udp: Fix wildcard bind conflict check when using hash2 (CVE-2026-31503)&lt;/p&gt;
&lt;p&gt;* kernel: ipv6: prevent possible UaF in addrconf_permanent_addr() (CVE-2026-43339)&lt;/p&gt;
&lt;p&gt;* kernel: tcp: call sk_data_ready() after listener migration (CVE-2026-46015)&lt;/p&gt;
&lt;p&gt;* kernel: inet: RAW sockets using IPPROTO_RAW MUST drop incoming ICMP (CVE-2026-46266)&lt;/p&gt;
&lt;p&gt;* kernel: flow_dissector: do not dissect PPPoE PFC frames (CVE-2026-46306)&lt;/p&gt;
&lt;p&gt;* kernel: io_uring/poll: fix signed comparison in io_poll_get_ownership() (CVE-2026-52933)&lt;/p&gt;
&lt;p&gt;* kernel: ppp: require CAP_NET_ADMIN in target netns for unattached ioctls (CVE-2026-53075)&lt;/p&gt;
&lt;p&gt;* kernel: KVM: arm64: Take the SRCU lock for page table walks in fault injection and AT emulation (CVE-2026-53277)&lt;/p&gt;
&lt;p&gt;* kernel: ipv6: sit: reload inner IPv6 header after GSO offloads (CVE-2026-53228)&lt;/p&gt;
&lt;p&gt;* kernel: net: add pskb_may_pull() to skb_gro_receive_list() (CVE-2026-53235)&lt;/p&gt;
&lt;p&gt;* kernel: net: guard timestamp cmsgs to real error queue skbs (CVE-2026-53223)&lt;/p&gt;
&lt;p&gt;* kernel: ipv6: mcast: Fix use-after-free when processing MLD queries (CVE-2026-53275)&lt;/p&gt;
&lt;p&gt;* kernel: ipv6: anycast: insert aca into global hash under idev-&amp;gt;lock (CVE-2026-53259)&lt;/p&gt;
&lt;p&gt;* kernel: ipv4: free net-&amp;gt;ipv4.sysctl_local_reserved_ports after unregister_net_sysctl_table() (CVE-2026-64002)&lt;/p&gt;
&lt;p&gt;*…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: kernel&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: can: bcm: add locking for bcm_op runtime updates (CVE-2025-38004)&lt;/p&gt;
&lt;p&gt;* kernel: ipv6: add NULL checks for idev in SRv6 paths (CVE-2026-23442)&lt;/p&gt;
&lt;p&gt;* kernel: udp: Fix wildcard bind conflict check when using hash2 (CVE-2026-31503)&lt;/p&gt;
&lt;p&gt;* kernel: ipv6: prevent possible UaF in addrconf_permanent_addr() (CVE-2026-43339)&lt;/p&gt;
&lt;p&gt;* kernel: tcp: call sk_data_ready() after listener migration (CVE-2026-46015)&lt;/p&gt;
&lt;p&gt;* kernel: inet: RAW sockets using IPPROTO_RAW MUST drop incoming ICMP (CVE-2026-46266)&lt;/p&gt;
&lt;p&gt;* kernel: flow_dissector: do not dissect PPPoE PFC frames (CVE-2026-46306)&lt;/p&gt;
&lt;p&gt;* kernel: io_uring/poll: fix signed comparison in io_poll_get_ownership() (CVE-2026-52933)&lt;/p&gt;
&lt;p&gt;* kernel: ppp: require CAP_NET_ADMIN in target netns for unattached ioctls (CVE-2026-53075)&lt;/p&gt;
&lt;p&gt;* kernel: KVM: arm64: Take the SRCU lock for page table walks in fault injection and AT emulation (CVE-2026-53277)&lt;/p&gt;
&lt;p&gt;* kernel: ipv6: sit: reload inner IPv6 header after GSO offloads (CVE-2026-53228)&lt;/p&gt;
&lt;p&gt;* kernel: net: add pskb_may_pull() to skb_gro_receive_list() (CVE-2026-53235)&lt;/p&gt;
&lt;p&gt;* kernel: net: guard timestamp cmsgs to real error queue skbs (CVE-2026-53223)&lt;/p&gt;
&lt;p&gt;* kernel: ipv6: mcast: Fix use-after-free when processing MLD queries (CVE-2026-53275)&lt;/p&gt;
&lt;p&gt;* kernel: ipv6: anycast: insert aca into global hash under idev-&amp;gt;lock (CVE-2026-53259)&lt;/p&gt;
&lt;p&gt;* kernel: ipv4: free net-&amp;gt;ipv4.sysctl_local_reserved_ports after unregister_net_sysctl_table() (CVE-2026-64002)&lt;/p&gt;
&lt;p&gt;*…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:64775</guid>
    </item>
    <item>
      <title>SSA-019113 — SSA-019113: Vulnerabilities in the additional GNU/Linux subsystem of the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1.6</title>
      <link>https://cve.radiocsirt.org/vuln/ssa-019113</link>
      <description>&lt;p&gt;Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.6 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant).&lt;/p&gt;
&lt;p&gt;Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.6 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant).&lt;/p&gt;
&lt;p&gt;Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ssa-019113</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:22742-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:22742-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:22742-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-52933</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-52933</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 192 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: io_uring/poll: fix signed comparison in io_poll_get_ownership() io_poll_get_ownership() uses a signed comparison to check whether poll_refs has reached the threshold for the slowpath:     if (unlikely(atomic_read(&amp;amp;req-&amp;gt;poll_refs) &amp;gt;= IO_POLL_REF_BIAS)) atomic_read() returns int (signed). When IO_POLL_CANCEL_FLAG (BIT(31)) is set in poll_refs, the value becomes negative in signed arithmetic, so the &amp;gt;= 128 comparison always evaluates to false and the slowpath is never taken. Fix this by casting the atomic_read() result to unsigned int before the comparison, so that the cancel flag is treated as a large positive value and correctly triggers the slowpath.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 192 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: io_uring/poll: fix signed comparison in io_poll_get_ownership() io_poll_get_ownership() uses a signed comparison to check whether poll_refs has reached the threshold for the slowpath:     if (unlikely(atomic_read(&amp;amp;req-&amp;gt;poll_refs) &amp;gt;= IO_POLL_REF_BIAS)) atomic_read() returns int (signed). When IO_POLL_CANCEL_FLAG (BIT(31)) is set in poll_refs, the value becomes negative in signed arithmetic, so the &amp;gt;= 128 comparison always evaluates to false and the slowpath is never taken. Fix this by casting the atomic_read() result to unsigned int before the comparison, so that the cancel flag is treated as a large positive value and correctly triggers the slowpath.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-52933</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2056 — Linux Kernel: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2056</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen Denial-of-Service-Angriff  auszulösen oder andere, nicht näher spezifizierte Angriffe durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen Denial-of-Service-Angriff  auszulösen oder andere, nicht näher spezifizierte Angriffe durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2056</guid>
    </item>
  </channel>
</rss>
