<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 04:36:13 +0000</lastBuildDate>
    <item>
      <title>ALSA-2026:66324 — Important: kernel-rt security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:66324</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: kernel-rt, AlmaLinux:8: kernel-rt-core, AlmaLinux:8: kernel-rt-debug, AlmaLinux:8: kernel-rt-debug-core, AlmaLinux:8: kernel-rt-debug-devel, AlmaLinux:8: kernel-rt-debug-modules, AlmaLinux:8: kernel-rt-debug-modules-extra, AlmaLinux:8: kernel-rt-devel, AlmaLinux:8: kernel-rt-modules, AlmaLinux:8: kernel-rt-modules-extra&lt;/p&gt;
&lt;p&gt;The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: Linux kernel: Denial of Service in qla2xxx SCSI driver due to improper command handling after chip reset (CVE-2025-68745)
  * kernel: scsi: target: configfs: Bound snprintf() return in tg_pt_gp_members_show() (CVE-2026-46149)
  * kernel: netfilter: nf_log: validate MAC header was set before dumping it (CVE-2026-52942)
  * kernel: sctp: diag: reject stale associations in dump_one path (CVE-2026-52917)
  * kernel: net: pull headers in qdisc_pkt_len_segs_init() (CVE-2026-53091)
  * kernel: netfilter: nf_conntrack_sip: don&amp;#39;t use simple_strtoul (CVE-2026-52986)
  * kernel: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing (CVE-2026-53246)
  * kernel: tipc: fix slab-use-after-free Read in tipc_aead_decrypt_done (CVE-2026-63801)
  * kernel: sctp: fix race between sctp_wait_for_connect and peeloff (CVE-2026-63971)
  * kernel: security/keys: fix missed RCU read section on lookup (CVE-2026-64015)
  * kernel: ixgbevf: fix use-after-free in VEPA multicast source pruning (CVE-2026-64113)
  * kernel: sctp: fix auth_hmacs array size in struct sctp_cookie (CVE-2026-68376)
  * kernel: tipc: clear sock-&amp;gt;sk on the failed-insert path in tipc_sk_create() (CVE-2026-68117)
  * kernel: sctp: auth: verify auth requirement when auth_chunk is NULL (CVE-2026-68300)
  * kernel: sctp: validate stream count i…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: kernel-rt, AlmaLinux:8: kernel-rt-core, AlmaLinux:8: kernel-rt-debug, AlmaLinux:8: kernel-rt-debug-core, AlmaLinux:8: kernel-rt-debug-devel, AlmaLinux:8: kernel-rt-debug-modules, AlmaLinux:8: kernel-rt-debug-modules-extra, AlmaLinux:8: kernel-rt-devel, AlmaLinux:8: kernel-rt-modules, AlmaLinux:8: kernel-rt-modules-extra&lt;/p&gt;
&lt;p&gt;The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: Linux kernel: Denial of Service in qla2xxx SCSI driver due to improper command handling after chip reset (CVE-2025-68745)
  * kernel: scsi: target: configfs: Bound snprintf() return in tg_pt_gp_members_show() (CVE-2026-46149)
  * kernel: netfilter: nf_log: validate MAC header was set before dumping it (CVE-2026-52942)
  * kernel: sctp: diag: reject stale associations in dump_one path (CVE-2026-52917)
  * kernel: net: pull headers in qdisc_pkt_len_segs_init() (CVE-2026-53091)
  * kernel: netfilter: nf_conntrack_sip: don&amp;#39;t use simple_strtoul (CVE-2026-52986)
  * kernel: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing (CVE-2026-53246)
  * kernel: tipc: fix slab-use-after-free Read in tipc_aead_decrypt_done (CVE-2026-63801)
  * kernel: sctp: fix race between sctp_wait_for_connect and peeloff (CVE-2026-63971)
  * kernel: security/keys: fix missed RCU read section on lookup (CVE-2026-64015)
  * kernel: ixgbevf: fix use-after-free in VEPA multicast source pruning (CVE-2026-64113)
  * kernel: sctp: fix auth_hmacs array size in struct sctp_cookie (CVE-2026-68376)
  * kernel: tipc: clear sock-&amp;gt;sk on the failed-insert path in tipc_sk_create() (CVE-2026-68117)
  * kernel: sctp: auth: verify auth requirement when auth_chunk is NULL (CVE-2026-68300)
  * kernel: sctp: validate stream count i…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:66324</guid>
    </item>
    <item>
      <title>bdu:2026-13913</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-13913</link>
      <description>bdu:2026-13913</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-13913</guid>
    </item>
    <item>
      <title>BELL-CVE-2026-52942</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-52942</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-52942</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0812 — De multiples vulnérabilités ont été découvertes dans Microsoft Azure Linux. Elles permettent à un attaquant de provoque…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0812</link>
      <description>certfr-2026-avi-0812</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0812</guid>
    </item>
    <item>
      <title>EUVD-2026-364829</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-364829</link>
      <description>EUVD-2026-364829</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-364829</guid>
    </item>
    <item>
      <title>fkie_cve-2026-52942</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-52942</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;netfilter: nf_log: validate MAC header was set before dumping it&lt;/p&gt;
&lt;p&gt;The fallback path of dump_mac_header() guards the MAC header access
only with &amp;#34;skb-&amp;gt;mac_header != skb-&amp;gt;network_header&amp;#34;, without checking
skb_mac_header_was_set(). When the MAC header is unset, mac_header is
0xffff, so the test passes and skb_mac_header(skb) returns
skb-&amp;gt;head + 0xffff, ~64 KiB past the buffer; the loop then reads
dev-&amp;gt;hard_header_len bytes out of bounds into the kernel log.&lt;/p&gt;
&lt;p&gt;This is reachable via the netdev logger: nf_log_unknown_packet() calls
dump_mac_header() unconditionally, and an skb sent through AF_PACKET
with PACKET_QDISC_BYPASS reaches the egress hook with mac_header still
unset (__dev_queue_xmit(), which would reset it, is bypassed).&lt;/p&gt;
&lt;p&gt;Add the skb_mac_header_was_set() check the ARPHRD_ETHER path already
uses, and replace the open-coded MAC header length test with
skb_mac_header_len(). Only skbs with an unset MAC header are affected;
valid ones are dumped as before.&lt;/p&gt;
&lt;p&gt;BUG: KASAN: slab-out-of-bounds in dump_mac_header (net/netfilter/nf_log_syslog.c:831)
 Read of size 1 at addr ffff88800ea49d3f by task exploit/148
 Call Trace:
  kasan_report (mm/kasan/report.c:595)
  dump_mac_header (net/netfilter/nf_log_syslog.c:831)
  nf_log_netdev_packet (net/netfilter/nf_log_syslog.c:938 net/netfilter/nf_log_syslog.c:963)
  nf_log_packet (net/netfilter/nf_log.c:260)
  nft_log_eval (net/netfilter/nft_log.c:60)
  nft_do_chain (net/netf…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;netfilter: nf_log: validate MAC header was set before dumping it&lt;/p&gt;
&lt;p&gt;The fallback path of dump_mac_header() guards the MAC header access
only with &amp;#34;skb-&amp;gt;mac_header != skb-&amp;gt;network_header&amp;#34;, without checking
skb_mac_header_was_set(). When the MAC header is unset, mac_header is
0xffff, so the test passes and skb_mac_header(skb) returns
skb-&amp;gt;head + 0xffff, ~64 KiB past the buffer; the loop then reads
dev-&amp;gt;hard_header_len bytes out of bounds into the kernel log.&lt;/p&gt;
&lt;p&gt;This is reachable via the netdev logger: nf_log_unknown_packet() calls
dump_mac_header() unconditionally, and an skb sent through AF_PACKET
with PACKET_QDISC_BYPASS reaches the egress hook with mac_header still
unset (__dev_queue_xmit(), which would reset it, is bypassed).&lt;/p&gt;
&lt;p&gt;Add the skb_mac_header_was_set() check the ARPHRD_ETHER path already
uses, and replace the open-coded MAC header length test with
skb_mac_header_len(). Only skbs with an unset MAC header are affected;
valid ones are dumped as before.&lt;/p&gt;
&lt;p&gt;BUG: KASAN: slab-out-of-bounds in dump_mac_header (net/netfilter/nf_log_syslog.c:831)
 Read of size 1 at addr ffff88800ea49d3f by task exploit/148
 Call Trace:
  kasan_report (mm/kasan/report.c:595)
  dump_mac_header (net/netfilter/nf_log_syslog.c:831)
  nf_log_netdev_packet (net/netfilter/nf_log_syslog.c:938 net/netfilter/nf_log_syslog.c:963)
  nf_log_packet (net/netfilter/nf_log.c:260)
  nft_log_eval (net/netfilter/nft_log.c:60)
  nft_do_chain (net/netf…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-52942</guid>
    </item>
    <item>
      <title>GHSA-3p98-fq5j-wx55</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-3p98-fq5j-wx55</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;netfilter: nf_log: validate MAC header was set before dumping it&lt;/p&gt;
&lt;p&gt;The fallback path of dump_mac_header() guards the MAC header access
only with &amp;#34;skb-&amp;gt;mac_header != skb-&amp;gt;network_header&amp;#34;, without checking
skb_mac_header_was_set(). When the MAC header is unset, mac_header is
0xffff, so the test passes and skb_mac_header(skb) returns
skb-&amp;gt;head + 0xffff, ~64 KiB past the buffer; the loop then reads
dev-&amp;gt;hard_header_len bytes out of bounds into the kernel log.&lt;/p&gt;
&lt;p&gt;This is reachable via the netdev logger: nf_log_unknown_packet() calls
dump_mac_header() unconditionally, and an skb sent through AF_PACKET
with PACKET_QDISC_BYPASS reaches the egress hook with mac_header still
unset (__dev_queue_xmit(), which would reset it, is bypassed).&lt;/p&gt;
&lt;p&gt;Add the skb_mac_header_was_set() check the ARPHRD_ETHER path already
uses, and replace the open-coded MAC header length test with
skb_mac_header_len(). Only skbs with an unset MAC header are affected;
valid ones are dumped as before.&lt;/p&gt;
&lt;p&gt;BUG: KASAN: slab-out-of-bounds in dump_mac_header (net/netfilter/nf_log_syslog.c:831)
 Read of size 1 at addr ffff88800ea49d3f by task exploit/148
 Call Trace:
  kasan_report (mm/kasan/report.c:595)
  dump_mac_header (net/netfilter/nf_log_syslog.c:831)
  nf_log_netdev_packet (net/netfilter/nf_log_syslog.c:938 net/netfilter/nf_log_syslog.c:963)
  nf_log_packet (net/netfilter/nf_log.c:260)
  nft_log_eval (net/netfilter/nft_log.c:60)
  nft_do_chain (net/netf…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;netfilter: nf_log: validate MAC header was set before dumping it&lt;/p&gt;
&lt;p&gt;The fallback path of dump_mac_header() guards the MAC header access
only with &amp;#34;skb-&amp;gt;mac_header != skb-&amp;gt;network_header&amp;#34;, without checking
skb_mac_header_was_set(). When the MAC header is unset, mac_header is
0xffff, so the test passes and skb_mac_header(skb) returns
skb-&amp;gt;head + 0xffff, ~64 KiB past the buffer; the loop then reads
dev-&amp;gt;hard_header_len bytes out of bounds into the kernel log.&lt;/p&gt;
&lt;p&gt;This is reachable via the netdev logger: nf_log_unknown_packet() calls
dump_mac_header() unconditionally, and an skb sent through AF_PACKET
with PACKET_QDISC_BYPASS reaches the egress hook with mac_header still
unset (__dev_queue_xmit(), which would reset it, is bypassed).&lt;/p&gt;
&lt;p&gt;Add the skb_mac_header_was_set() check the ARPHRD_ETHER path already
uses, and replace the open-coded MAC header length test with
skb_mac_header_len(). Only skbs with an unset MAC header are affected;
valid ones are dumped as before.&lt;/p&gt;
&lt;p&gt;BUG: KASAN: slab-out-of-bounds in dump_mac_header (net/netfilter/nf_log_syslog.c:831)
 Read of size 1 at addr ffff88800ea49d3f by task exploit/148
 Call Trace:
  kasan_report (mm/kasan/report.c:595)
  dump_mac_header (net/netfilter/nf_log_syslog.c:831)
  nf_log_netdev_packet (net/netfilter/nf_log_syslog.c:938 net/netfilter/nf_log_syslog.c:963)
  nf_log_packet (net/netfilter/nf_log.c:260)
  nft_log_eval (net/netfilter/nft_log.c:60)
  nft_do_chain (net/netf…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-3p98-fq5j-wx55</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-52942 — netfilter: nf_log: validate MAC header was set before dumping it</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-52942</link>
      <description>msrc_CVE-2026-52942</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-52942</guid>
    </item>
    <item>
      <title>OESA-2026-3206 — kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-3206</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP4: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;Arm C1-Ultra, C1-Premium, Neoverse V3 &amp;amp;amp; V3AE, Neoverse V2, Neoverse V1, Neoverse-N2, Neoverse-N1, Cortex-X925, Cortex-X4, Cortex-X3, Cortex-X2, Cortex-X1 &amp;amp;amp; X1C, Cortex-A710, Cortex-A78, A78AE &amp;amp;amp; A78C, Cortex-A77, Cortex-A76 &amp;amp;amp; A76A may allow writes to resources owned by a higher exception level.(CVE-2025-10263)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;inet: RAW sockets using IPPROTO_RAW MUST drop incoming ICMP&lt;/p&gt;
&lt;p&gt;Yizhou Zhao reported that simply having one RAW socket on protocol
IPPROTO_RAW (255) was dangerous.&lt;/p&gt;
&lt;p&gt;socket(AF_INET, SOCK_RAW, 255);&lt;/p&gt;
&lt;p&gt;A malicious incoming ICMP packet can set the protocol field to 255
and match this socket, leading to FNHE cache changes.&lt;/p&gt;
&lt;p&gt;inner = IP(src=&amp;amp;quot;192.168.2.1&amp;amp;quot;, dst=&amp;amp;quot;8.8.8.8&amp;amp;quot;, proto=255)/Raw(&amp;amp;quot;TEST&amp;amp;quot;)
pkt = IP(src=&amp;amp;quot;192.168.1.1&amp;amp;quot;, dst=&amp;amp;quot;192.168.2.1&amp;amp;quot;)/ICMP(type=3, code=4, nexthopmtu=576)/inner&lt;/p&gt;
&lt;p&gt;&amp;amp;quot;man 7 raw&amp;amp;quot; states:&lt;/p&gt;
&lt;p&gt;A protocol of IPPROTO_RAW implies enabled IP_HDRINCL and is able
  to send any IP protocol that is specified in the passed header.
  Receiving of all IP protocols via IPPROTO_RAW is not possible
  using raw sockets.&lt;/p&gt;
&lt;p&gt;Make sure we drop these malicious packets.(CVE-2026-46266)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;tun: free page on build_skb failure in tun_xdp_one()&lt;/p&gt;
&lt;p&gt;When build_skb() fails in tun_xdp_one(), the function sets ret to
-…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP4: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;Arm C1-Ultra, C1-Premium, Neoverse V3 &amp;amp;amp; V3AE, Neoverse V2, Neoverse V1, Neoverse-N2, Neoverse-N1, Cortex-X925, Cortex-X4, Cortex-X3, Cortex-X2, Cortex-X1 &amp;amp;amp; X1C, Cortex-A710, Cortex-A78, A78AE &amp;amp;amp; A78C, Cortex-A77, Cortex-A76 &amp;amp;amp; A76A may allow writes to resources owned by a higher exception level.(CVE-2025-10263)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;inet: RAW sockets using IPPROTO_RAW MUST drop incoming ICMP&lt;/p&gt;
&lt;p&gt;Yizhou Zhao reported that simply having one RAW socket on protocol
IPPROTO_RAW (255) was dangerous.&lt;/p&gt;
&lt;p&gt;socket(AF_INET, SOCK_RAW, 255);&lt;/p&gt;
&lt;p&gt;A malicious incoming ICMP packet can set the protocol field to 255
and match this socket, leading to FNHE cache changes.&lt;/p&gt;
&lt;p&gt;inner = IP(src=&amp;amp;quot;192.168.2.1&amp;amp;quot;, dst=&amp;amp;quot;8.8.8.8&amp;amp;quot;, proto=255)/Raw(&amp;amp;quot;TEST&amp;amp;quot;)
pkt = IP(src=&amp;amp;quot;192.168.1.1&amp;amp;quot;, dst=&amp;amp;quot;192.168.2.1&amp;amp;quot;)/ICMP(type=3, code=4, nexthopmtu=576)/inner&lt;/p&gt;
&lt;p&gt;&amp;amp;quot;man 7 raw&amp;amp;quot; states:&lt;/p&gt;
&lt;p&gt;A protocol of IPPROTO_RAW implies enabled IP_HDRINCL and is able
  to send any IP protocol that is specified in the passed header.
  Receiving of all IP protocols via IPPROTO_RAW is not possible
  using raw sockets.&lt;/p&gt;
&lt;p&gt;Make sure we drop these malicious packets.(CVE-2026-46266)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;tun: free page on build_skb failure in tun_xdp_one()&lt;/p&gt;
&lt;p&gt;When build_skb() fails in tun_xdp_one(), the function sets ret to
-…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-3206</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:21555-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:21555-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:21555-1</guid>
    </item>
    <item>
      <title>RHSA-2026:66324 — Red Hat Security Advisory: kernel-rt security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:66324</link>
      <description>&lt;p&gt;kernel: Linux kernel: Denial of Service in qla2xxx SCSI driver due to improper command handling after chip reset kernel: scsi: target: configfs: Bound snprintf() return in tg_pt_gp_members_show() kernel: sctp: diag: reject stale associations in dump_one path kernel: netfilter: nf_log: validate MAC header was set before dumping it kernel: netfilter: nf_conntrack_sip: don&amp;#39;t use simple_strtoul kernel: net: pull headers in qdisc_pkt_len_segs_init() kernel: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing kernel: tipc: fix slab-use-after-free Read in tipc_aead_decrypt_done kernel: sctp: fix race between sctp_wait_for_connect and peeloff kernel: security/keys: fix missed RCU read section on lookup kernel: ixgbevf: fix use-after-free in VEPA multicast source pruning kernel: tipc: clear sock-&amp;gt;sk on the failed-insert path in tipc_sk_create() kernel: sctp: auth: verify auth requirement when auth_chunk is NULL kernel: sctp: validate stream count in sctp_process_strreset_inreq() kernel: sctp: fix auth_hmacs array size in struct sctp_cookie&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;kernel: Linux kernel: Denial of Service in qla2xxx SCSI driver due to improper command handling after chip reset kernel: scsi: target: configfs: Bound snprintf() return in tg_pt_gp_members_show() kernel: sctp: diag: reject stale associations in dump_one path kernel: netfilter: nf_log: validate MAC header was set before dumping it kernel: netfilter: nf_conntrack_sip: don&amp;#39;t use simple_strtoul kernel: net: pull headers in qdisc_pkt_len_segs_init() kernel: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing kernel: tipc: fix slab-use-after-free Read in tipc_aead_decrypt_done kernel: sctp: fix race between sctp_wait_for_connect and peeloff kernel: security/keys: fix missed RCU read section on lookup kernel: ixgbevf: fix use-after-free in VEPA multicast source pruning kernel: tipc: clear sock-&amp;gt;sk on the failed-insert path in tipc_sk_create() kernel: sctp: auth: verify auth requirement when auth_chunk is NULL kernel: sctp: validate stream count in sctp_process_strreset_inreq() kernel: sctp: fix auth_hmacs array size in struct sctp_cookie&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:66324</guid>
    </item>
    <item>
      <title>RLSA-2026:66324 — Important: kernel-rt security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:66324</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:8: kernel-rt&lt;/p&gt;
&lt;p&gt;The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: Linux kernel: Denial of Service in qla2xxx SCSI driver due to improper command handling after chip reset (CVE-2025-68745)&lt;/p&gt;
&lt;p&gt;* kernel: scsi: target: configfs: Bound snprintf() return in tg_pt_gp_members_show() (CVE-2026-46149)&lt;/p&gt;
&lt;p&gt;* kernel: netfilter: nf_log: validate MAC header was set before dumping it (CVE-2026-52942)&lt;/p&gt;
&lt;p&gt;* kernel: sctp: diag: reject stale associations in dump_one path (CVE-2026-52917)&lt;/p&gt;
&lt;p&gt;* kernel: net: pull headers in qdisc_pkt_len_segs_init() (CVE-2026-53091)&lt;/p&gt;
&lt;p&gt;* kernel: netfilter: nf_conntrack_sip: don&amp;#39;t use simple_strtoul (CVE-2026-52986)&lt;/p&gt;
&lt;p&gt;* kernel: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing (CVE-2026-53246)&lt;/p&gt;
&lt;p&gt;* kernel: tipc: fix slab-use-after-free Read in tipc_aead_decrypt_done (CVE-2026-63801)&lt;/p&gt;
&lt;p&gt;* kernel: sctp: fix race between sctp_wait_for_connect and peeloff (CVE-2026-63971)&lt;/p&gt;
&lt;p&gt;* kernel: security/keys: fix missed RCU read section on lookup (CVE-2026-64015)&lt;/p&gt;
&lt;p&gt;* kernel: ixgbevf: fix use-after-free in VEPA multicast source pruning (CVE-2026-64113)&lt;/p&gt;
&lt;p&gt;* kernel: sctp: fix auth_hmacs array size in struct sctp_cookie (CVE-2026-68376)&lt;/p&gt;
&lt;p&gt;* kernel: tipc: clear sock-&amp;gt;sk on the failed-insert path in tipc_sk_create() (CVE-2026-68117)&lt;/p&gt;
&lt;p&gt;* kernel: sctp: auth: verify auth requirement when auth_chunk is NULL (CVE-2026-68300)&lt;/p&gt;
&lt;p&gt;* kernel: sctp: validate stream count in sctp_process_strre…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:8: kernel-rt&lt;/p&gt;
&lt;p&gt;The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: Linux kernel: Denial of Service in qla2xxx SCSI driver due to improper command handling after chip reset (CVE-2025-68745)&lt;/p&gt;
&lt;p&gt;* kernel: scsi: target: configfs: Bound snprintf() return in tg_pt_gp_members_show() (CVE-2026-46149)&lt;/p&gt;
&lt;p&gt;* kernel: netfilter: nf_log: validate MAC header was set before dumping it (CVE-2026-52942)&lt;/p&gt;
&lt;p&gt;* kernel: sctp: diag: reject stale associations in dump_one path (CVE-2026-52917)&lt;/p&gt;
&lt;p&gt;* kernel: net: pull headers in qdisc_pkt_len_segs_init() (CVE-2026-53091)&lt;/p&gt;
&lt;p&gt;* kernel: netfilter: nf_conntrack_sip: don&amp;#39;t use simple_strtoul (CVE-2026-52986)&lt;/p&gt;
&lt;p&gt;* kernel: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing (CVE-2026-53246)&lt;/p&gt;
&lt;p&gt;* kernel: tipc: fix slab-use-after-free Read in tipc_aead_decrypt_done (CVE-2026-63801)&lt;/p&gt;
&lt;p&gt;* kernel: sctp: fix race between sctp_wait_for_connect and peeloff (CVE-2026-63971)&lt;/p&gt;
&lt;p&gt;* kernel: security/keys: fix missed RCU read section on lookup (CVE-2026-64015)&lt;/p&gt;
&lt;p&gt;* kernel: ixgbevf: fix use-after-free in VEPA multicast source pruning (CVE-2026-64113)&lt;/p&gt;
&lt;p&gt;* kernel: sctp: fix auth_hmacs array size in struct sctp_cookie (CVE-2026-68376)&lt;/p&gt;
&lt;p&gt;* kernel: tipc: clear sock-&amp;gt;sk on the failed-insert path in tipc_sk_create() (CVE-2026-68117)&lt;/p&gt;
&lt;p&gt;* kernel: sctp: auth: verify auth requirement when auth_chunk is NULL (CVE-2026-68300)&lt;/p&gt;
&lt;p&gt;* kernel: sctp: validate stream count in sctp_process_strre…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:66324</guid>
    </item>
    <item>
      <title>SSA-019113 — SSA-019113: Vulnerabilities in the additional GNU/Linux subsystem of the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1.6</title>
      <link>https://cve.radiocsirt.org/vuln/ssa-019113</link>
      <description>&lt;p&gt;Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.6 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant).&lt;/p&gt;
&lt;p&gt;Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.6 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant).&lt;/p&gt;
&lt;p&gt;Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ssa-019113</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:23066-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:23066-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:23066-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-52942</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-52942</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux, Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe and 255 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_log: validate MAC header was set before dumping it The fallback path of dump_mac_header() guards the MAC header access only with &amp;#34;skb-&amp;gt;mac_header != skb-&amp;gt;network_header&amp;#34;, without checking skb_mac_header_was_set(). When the MAC header is unset, mac_header is 0xffff, so the test passes and skb_mac_header(skb) returns skb-&amp;gt;head + 0xffff, ~64 KiB past the buffer; the loop then reads dev-&amp;gt;hard_header_len bytes out of bounds into the kernel log. This is reachable via the netdev logger: nf_log_unknown_packet() calls dump_mac_header() unconditionally, and an skb sent through AF_PACKET with PACKET_QDISC_BYPASS reaches the egress hook with mac_header still unset (__dev_queue_xmit(), which would reset it, is bypassed). Add the skb_mac_header_was_set() check the ARPHRD_ETHER path already uses, and replace the open-coded MAC header length test with skb_mac_header_len(). Only skbs with an unset MAC header are affected; valid ones are dumped as before.  BUG: KASAN: slab-out-of-bounds in dump_mac_header (net/netfilter/nf_log_syslog.c:831)  Read of size 1 at addr ffff88800ea49d3f by task exploit/148  Call Trace:   kasan_report (mm/kasan/report.c:595)   dump_mac_header (net/netfilter/nf_log_syslog.c:831)   nf_log_netdev_packet (net/netfilter/nf_log_syslog.c:938 net/netfilter/nf_log_syslog.c:963)   nf_log_packet (net/netfilter/nf_log.c:260)   nft_log_eval (net/netfilter/nft_log.c:60)   nft_do_chain (net/netfilter…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux, Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe and 255 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_log: validate MAC header was set before dumping it The fallback path of dump_mac_header() guards the MAC header access only with &amp;#34;skb-&amp;gt;mac_header != skb-&amp;gt;network_header&amp;#34;, without checking skb_mac_header_was_set(). When the MAC header is unset, mac_header is 0xffff, so the test passes and skb_mac_header(skb) returns skb-&amp;gt;head + 0xffff, ~64 KiB past the buffer; the loop then reads dev-&amp;gt;hard_header_len bytes out of bounds into the kernel log. This is reachable via the netdev logger: nf_log_unknown_packet() calls dump_mac_header() unconditionally, and an skb sent through AF_PACKET with PACKET_QDISC_BYPASS reaches the egress hook with mac_header still unset (__dev_queue_xmit(), which would reset it, is bypassed). Add the skb_mac_header_was_set() check the ARPHRD_ETHER path already uses, and replace the open-coded MAC header length test with skb_mac_header_len(). Only skbs with an unset MAC header are affected; valid ones are dumped as before.  BUG: KASAN: slab-out-of-bounds in dump_mac_header (net/netfilter/nf_log_syslog.c:831)  Read of size 1 at addr ffff88800ea49d3f by task exploit/148  Call Trace:   kasan_report (mm/kasan/report.c:595)   dump_mac_header (net/netfilter/nf_log_syslog.c:831)   nf_log_netdev_packet (net/netfilter/nf_log_syslog.c:938 net/netfilter/nf_log_syslog.c:963)   nf_log_packet (net/netfilter/nf_log.c:260)   nft_log_eval (net/netfilter/nft_log.c:60)   nft_do_chain (net/netfilter…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-52942</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2056 — Linux Kernel: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2056</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen Denial-of-Service-Angriff  auszulösen oder andere, nicht näher spezifizierte Angriffe durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen Denial-of-Service-Angriff  auszulösen oder andere, nicht näher spezifizierte Angriffe durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2056</guid>
    </item>
  </channel>
</rss>
