<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 21:41:48 +0000</lastBuildDate>
    <item>
      <title>BELL-CVE-2026-52982</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-52982</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-52982</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0862 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de Debian LTS. Certaines d'entre elles permettent à…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0862</link>
      <description>certfr-2026-avi-0862</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0862</guid>
    </item>
    <item>
      <title>EUVD-2026-348121</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-348121</link>
      <description>EUVD-2026-348121</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-348121</guid>
    </item>
    <item>
      <title>fkie_cve-2026-52982</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-52982</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;net: usb: rtl8150: fix use-after-free in rtl8150_start_xmit()&lt;/p&gt;
&lt;p&gt;syzbot reported a KASAN slab-use-after-free read in rtl8150_start_xmit()
when accessing skb-&amp;gt;len for tx statistics after usb_submit_urb() has
been called:&lt;/p&gt;
&lt;p&gt;BUG: KASAN: slab-use-after-free in rtl8150_start_xmit+0x71f/0x760
    drivers/net/usb/rtl8150.c:712
  Read of size 4 at addr ffff88810eb7a930 by task kworker/0:4/5226&lt;/p&gt;
&lt;p&gt;The URB completion handler write_bulk_callback() frees the skb via
dev_kfree_skb_irq(dev-&amp;gt;tx_skb). The URB may complete on another CPU
in softirq context before usb_submit_urb() returns in the submitter,
so by the time the submitter reads skb-&amp;gt;len the skb has already been
queued to the per-CPU completion_queue and freed by net_tx_action():&lt;/p&gt;
&lt;p&gt;CPU A (xmit)                      CPU B (USB completion softirq)
  ------------                      ------------------------------
  dev-&amp;gt;tx_skb = skb;
  usb_submit_urb()      --+
                          |-------&amp;gt; write_bulk_callback()
                          |           dev_kfree_skb_irq(dev-&amp;gt;tx_skb)
                          |         net_tx_action()
                          |           napi_skb_cache_put()   &amp;lt;-- free
  netdev-&amp;gt;stats.tx_bytes  |
    += skb-&amp;gt;len;          &amp;lt;-- UAF read&lt;/p&gt;
&lt;p&gt;Fix it by caching skb-&amp;gt;len before submitting the URB and using the
cached value when updating the tx_bytes counter.&lt;/p&gt;
&lt;p&gt;The pre-existing tx_bytes semantics are preserved: the counter tracks
the origina…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;net: usb: rtl8150: fix use-after-free in rtl8150_start_xmit()&lt;/p&gt;
&lt;p&gt;syzbot reported a KASAN slab-use-after-free read in rtl8150_start_xmit()
when accessing skb-&amp;gt;len for tx statistics after usb_submit_urb() has
been called:&lt;/p&gt;
&lt;p&gt;BUG: KASAN: slab-use-after-free in rtl8150_start_xmit+0x71f/0x760
    drivers/net/usb/rtl8150.c:712
  Read of size 4 at addr ffff88810eb7a930 by task kworker/0:4/5226&lt;/p&gt;
&lt;p&gt;The URB completion handler write_bulk_callback() frees the skb via
dev_kfree_skb_irq(dev-&amp;gt;tx_skb). The URB may complete on another CPU
in softirq context before usb_submit_urb() returns in the submitter,
so by the time the submitter reads skb-&amp;gt;len the skb has already been
queued to the per-CPU completion_queue and freed by net_tx_action():&lt;/p&gt;
&lt;p&gt;CPU A (xmit)                      CPU B (USB completion softirq)
  ------------                      ------------------------------
  dev-&amp;gt;tx_skb = skb;
  usb_submit_urb()      --+
                          |-------&amp;gt; write_bulk_callback()
                          |           dev_kfree_skb_irq(dev-&amp;gt;tx_skb)
                          |         net_tx_action()
                          |           napi_skb_cache_put()   &amp;lt;-- free
  netdev-&amp;gt;stats.tx_bytes  |
    += skb-&amp;gt;len;          &amp;lt;-- UAF read&lt;/p&gt;
&lt;p&gt;Fix it by caching skb-&amp;gt;len before submitting the URB and using the
cached value when updating the tx_bytes counter.&lt;/p&gt;
&lt;p&gt;The pre-existing tx_bytes semantics are preserved: the counter tracks
the origina…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-52982</guid>
    </item>
    <item>
      <title>GHSA-pjm2-h6fg-mfw7</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-pjm2-h6fg-mfw7</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;net: usb: rtl8150: fix use-after-free in rtl8150_start_xmit()&lt;/p&gt;
&lt;p&gt;syzbot reported a KASAN slab-use-after-free read in rtl8150_start_xmit()
when accessing skb-&amp;gt;len for tx statistics after usb_submit_urb() has
been called:&lt;/p&gt;
&lt;p&gt;BUG: KASAN: slab-use-after-free in rtl8150_start_xmit+0x71f/0x760
    drivers/net/usb/rtl8150.c:712
  Read of size 4 at addr ffff88810eb7a930 by task kworker/0:4/5226&lt;/p&gt;
&lt;p&gt;The URB completion handler write_bulk_callback() frees the skb via
dev_kfree_skb_irq(dev-&amp;gt;tx_skb). The URB may complete on another CPU
in softirq context before usb_submit_urb() returns in the submitter,
so by the time the submitter reads skb-&amp;gt;len the skb has already been
queued to the per-CPU completion_queue and freed by net_tx_action():&lt;/p&gt;
&lt;p&gt;CPU A (xmit)                      CPU B (USB completion softirq)
  ------------                      ------------------------------
  dev-&amp;gt;tx_skb = skb;
  usb_submit_urb()      --+
                          |-------&amp;gt; write_bulk_callback()
                          |           dev_kfree_skb_irq(dev-&amp;gt;tx_skb)
                          |         net_tx_action()
                          |           napi_skb_cache_put()   &amp;lt;-- free
  netdev-&amp;gt;stats.tx_bytes  |
    += skb-&amp;gt;len;          &amp;lt;-- UAF read&lt;/p&gt;
&lt;p&gt;Fix it by caching skb-&amp;gt;len before submitting the URB and using the
cached value when updating the tx_bytes counter.&lt;/p&gt;
&lt;p&gt;The pre-existing tx_bytes semantics are preserved: the counter tracks
the origina…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;net: usb: rtl8150: fix use-after-free in rtl8150_start_xmit()&lt;/p&gt;
&lt;p&gt;syzbot reported a KASAN slab-use-after-free read in rtl8150_start_xmit()
when accessing skb-&amp;gt;len for tx statistics after usb_submit_urb() has
been called:&lt;/p&gt;
&lt;p&gt;BUG: KASAN: slab-use-after-free in rtl8150_start_xmit+0x71f/0x760
    drivers/net/usb/rtl8150.c:712
  Read of size 4 at addr ffff88810eb7a930 by task kworker/0:4/5226&lt;/p&gt;
&lt;p&gt;The URB completion handler write_bulk_callback() frees the skb via
dev_kfree_skb_irq(dev-&amp;gt;tx_skb). The URB may complete on another CPU
in softirq context before usb_submit_urb() returns in the submitter,
so by the time the submitter reads skb-&amp;gt;len the skb has already been
queued to the per-CPU completion_queue and freed by net_tx_action():&lt;/p&gt;
&lt;p&gt;CPU A (xmit)                      CPU B (USB completion softirq)
  ------------                      ------------------------------
  dev-&amp;gt;tx_skb = skb;
  usb_submit_urb()      --+
                          |-------&amp;gt; write_bulk_callback()
                          |           dev_kfree_skb_irq(dev-&amp;gt;tx_skb)
                          |         net_tx_action()
                          |           napi_skb_cache_put()   &amp;lt;-- free
  netdev-&amp;gt;stats.tx_bytes  |
    += skb-&amp;gt;len;          &amp;lt;-- UAF read&lt;/p&gt;
&lt;p&gt;Fix it by caching skb-&amp;gt;len before submitting the URB and using the
cached value when updating the tx_bytes counter.&lt;/p&gt;
&lt;p&gt;The pre-existing tx_bytes semantics are preserved: the counter tracks
the origina…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-pjm2-h6fg-mfw7</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-52982 — net: usb: rtl8150: fix use-after-free in rtl8150_start_xmit()</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-52982</link>
      <description>msrc_CVE-2026-52982</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-52982</guid>
    </item>
    <item>
      <title>OESA-2026-4039 — kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-4039</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP4: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:ALSA: caiaq: Use snd_card_free_when_closed() at disconnectionThe USB disconnect callback is supposed to be short and not too-longwaiting.  OTOH, the current code uses snd_card_free() atdisconnection, but this waits for the close of all used fds, hence itcan take long.  It eventually blocks the upper layer USB ioctls, whichmay trigger a soft lockup.An easy workaround is to replace snd_card_free() withsnd_card_free_when_closed().  This variant returns immediately whilethe release of resources is done asynchronously by the card devicerelease at the last close.This patch also splits the code to the disconnect and the free phases;the former is called immediately at the USB disconnect callback whilethe latter is called from the card destructor.(CVE-2024-56531)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:xsk: fix OOB map writes when deleting elementsJordy says: In the xsk_map_delete_elem function an unsigned integer(map-&amp;amp;gt;max_entries) is compared with a user-controlled signed integer(k). Due to implicit type conversion, a large unsigned value formap-&amp;amp;gt;max_entries can bypass the intended bounds check: if (k &amp;amp;gt;= map-&amp;amp;gt;max_entries)  return -EINVAL;This allows k to hold a negative value (between -2147483648 and -2),which is then used as an array index in m-&amp;amp;gt;xsk_map[k], which resultsin an out-of-bounds access. spi…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP4: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:ALSA: caiaq: Use snd_card_free_when_closed() at disconnectionThe USB disconnect callback is supposed to be short and not too-longwaiting.  OTOH, the current code uses snd_card_free() atdisconnection, but this waits for the close of all used fds, hence itcan take long.  It eventually blocks the upper layer USB ioctls, whichmay trigger a soft lockup.An easy workaround is to replace snd_card_free() withsnd_card_free_when_closed().  This variant returns immediately whilethe release of resources is done asynchronously by the card devicerelease at the last close.This patch also splits the code to the disconnect and the free phases;the former is called immediately at the USB disconnect callback whilethe latter is called from the card destructor.(CVE-2024-56531)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:xsk: fix OOB map writes when deleting elementsJordy says: In the xsk_map_delete_elem function an unsigned integer(map-&amp;amp;gt;max_entries) is compared with a user-controlled signed integer(k). Due to implicit type conversion, a large unsigned value formap-&amp;amp;gt;max_entries can bypass the intended bounds check: if (k &amp;amp;gt;= map-&amp;amp;gt;max_entries)  return -EINVAL;This allows k to hold a negative value (between -2147483648 and -2),which is then used as an array index in m-&amp;amp;gt;xsk_map[k], which resultsin an out-of-bounds access. spi…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-4039</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:21555-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:21555-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:21555-1</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:23066-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:23066-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:23066-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-52982</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-52982</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux, Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe and 253 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: net: usb: rtl8150: fix use-after-free in rtl8150_start_xmit() syzbot reported a KASAN slab-use-after-free read in rtl8150_start_xmit() when accessing skb-&amp;gt;len for tx statistics after usb_submit_urb() has been called:   BUG: KASAN: slab-use-after-free in rtl8150_start_xmit+0x71f/0x760     drivers/net/usb/rtl8150.c:712   Read of size 4 at addr ffff88810eb7a930 by task kworker/0:4/5226 The URB completion handler write_bulk_callback() frees the skb via dev_kfree_skb_irq(dev-&amp;gt;tx_skb). The URB may complete on another CPU in softirq context before usb_submit_urb() returns in the submitter, so by the time the submitter reads skb-&amp;gt;len the skb has already been queued to the per-CPU completion_queue and freed by net_tx_action():   CPU A (xmit)                      CPU B (USB completion softirq)   ------------                      ------------------------------   dev-&amp;gt;tx_skb = skb;   usb_submit_urb()      --+                           |-------&amp;gt; write_bulk_callback()                           |           dev_kfree_skb_irq(dev-&amp;gt;tx_skb)                           |         net_tx_action()                           |           napi_skb_cache_put()   &amp;lt;-- free   netdev-&amp;gt;stats.tx_bytes  |     += skb-&amp;gt;len;          &amp;lt;-- UAF read Fix it by caching skb-&amp;gt;len before submitting the URB and using the cached value when updating the tx_bytes counter. The pre-existing tx_bytes semantics are preserved: the counter tracks the original frame…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux, Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe and 253 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: net: usb: rtl8150: fix use-after-free in rtl8150_start_xmit() syzbot reported a KASAN slab-use-after-free read in rtl8150_start_xmit() when accessing skb-&amp;gt;len for tx statistics after usb_submit_urb() has been called:   BUG: KASAN: slab-use-after-free in rtl8150_start_xmit+0x71f/0x760     drivers/net/usb/rtl8150.c:712   Read of size 4 at addr ffff88810eb7a930 by task kworker/0:4/5226 The URB completion handler write_bulk_callback() frees the skb via dev_kfree_skb_irq(dev-&amp;gt;tx_skb). The URB may complete on another CPU in softirq context before usb_submit_urb() returns in the submitter, so by the time the submitter reads skb-&amp;gt;len the skb has already been queued to the per-CPU completion_queue and freed by net_tx_action():   CPU A (xmit)                      CPU B (USB completion softirq)   ------------                      ------------------------------   dev-&amp;gt;tx_skb = skb;   usb_submit_urb()      --+                           |-------&amp;gt; write_bulk_callback()                           |           dev_kfree_skb_irq(dev-&amp;gt;tx_skb)                           |         net_tx_action()                           |           napi_skb_cache_put()   &amp;lt;-- free   netdev-&amp;gt;stats.tx_bytes  |     += skb-&amp;gt;len;          &amp;lt;-- UAF read Fix it by caching skb-&amp;gt;len before submitting the URB and using the cached value when updating the tx_bytes counter. The pre-existing tx_bytes semantics are preserved: the counter tracks the original frame…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-52982</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2077 — Linux Kernel: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2077</link>
      <description>&lt;p&gt;Ein entfernter Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um Sicherheitsvorkehrungen zu umgehen, einen Denial-of-Service-Zustand herbeizuführen und weitere, nicht näher spezifizierte Auswirkungen zu erzielen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um Sicherheitsvorkehrungen zu umgehen, einen Denial-of-Service-Zustand herbeizuführen und weitere, nicht näher spezifizierte Auswirkungen zu erzielen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2077</guid>
    </item>
  </channel>
</rss>
