<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 19:32:29 +0000</lastBuildDate>
    <item>
      <title>ALSA-2026:42919 — Important: kernel security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:42919</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: kernel, AlmaLinux:10: kernel-64k, AlmaLinux:10: kernel-64k-core, AlmaLinux:10: kernel-64k-debug, AlmaLinux:10: kernel-64k-debug-core, AlmaLinux:10: kernel-64k-debug-devel, AlmaLinux:10: kernel-64k-debug-devel-matched, AlmaLinux:10: kernel-64k-debug-modules, AlmaLinux:10: kernel-64k-debug-modules-core, AlmaLinux:10: kernel-64k-debug-modules-extra and 65 more&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: crypto: af_alg - zero initialize memory allocated via sock_kmalloc (CVE-2025-71113)
  * kernel: Linux kernel: Denial of Service due to memory leak in tpm2_load_cmd (CVE-2025-71147)
  * kernel: flex_proportions: make fprop_new_period() hardirq safe (CVE-2026-23168)
  * kernel: cxl/port: Fix use after free of parent_port in cxl_detach_ep() (CVE-2026-31530)
  * kernel: xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete (CVE-2026-46116)
  * kernel: fanotify: fix false positive on permission events (CVE-2026-46150)
  * kernel: drm: Set old handle to NULL before prime swap in change_handle (CVE-2026-46215)
  * kernel: drm/xe: Fix error cleanup in xe_exec_queue_create_ioctl() (CVE-2026-52976)
  * kernel: drm/xe/dma-buf: fix UAF with retry loop (CVE-2026-52950)
  * kernel: ice: fix double-free of tx_buf skb (CVE-2026-53009)
  * kernel: Bluetooth: l2cap: Add missing chan lock in l2cap_ecred_reconf_rsp (CVE-2026-53071)
  * kernel: can: bcm: thrtimer use-after-free during RX operation teardown ()&lt;/p&gt;
&lt;p&gt;Bug Fix(es) and Enhancement(s):&lt;/p&gt;
&lt;p&gt;* nfsd_file slab cache objects remaining on kmem_cache_shutdown during nfsd teardown while running bz1477872 testcase (JIRA:AlmaLinux-173103)
  * tools/lib/perf/Makefile: libperf includes appended after CFLAGS causes parallel build race, breaking kernel builds [almalinux-10.2.z] (JIRA:AlmaLinux-183975)
  * [AlmaLinux10-de…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: kernel, AlmaLinux:10: kernel-64k, AlmaLinux:10: kernel-64k-core, AlmaLinux:10: kernel-64k-debug, AlmaLinux:10: kernel-64k-debug-core, AlmaLinux:10: kernel-64k-debug-devel, AlmaLinux:10: kernel-64k-debug-devel-matched, AlmaLinux:10: kernel-64k-debug-modules, AlmaLinux:10: kernel-64k-debug-modules-core, AlmaLinux:10: kernel-64k-debug-modules-extra and 65 more&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: crypto: af_alg - zero initialize memory allocated via sock_kmalloc (CVE-2025-71113)
  * kernel: Linux kernel: Denial of Service due to memory leak in tpm2_load_cmd (CVE-2025-71147)
  * kernel: flex_proportions: make fprop_new_period() hardirq safe (CVE-2026-23168)
  * kernel: cxl/port: Fix use after free of parent_port in cxl_detach_ep() (CVE-2026-31530)
  * kernel: xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete (CVE-2026-46116)
  * kernel: fanotify: fix false positive on permission events (CVE-2026-46150)
  * kernel: drm: Set old handle to NULL before prime swap in change_handle (CVE-2026-46215)
  * kernel: drm/xe: Fix error cleanup in xe_exec_queue_create_ioctl() (CVE-2026-52976)
  * kernel: drm/xe/dma-buf: fix UAF with retry loop (CVE-2026-52950)
  * kernel: ice: fix double-free of tx_buf skb (CVE-2026-53009)
  * kernel: Bluetooth: l2cap: Add missing chan lock in l2cap_ecred_reconf_rsp (CVE-2026-53071)
  * kernel: can: bcm: thrtimer use-after-free during RX operation teardown ()&lt;/p&gt;
&lt;p&gt;Bug Fix(es) and Enhancement(s):&lt;/p&gt;
&lt;p&gt;* nfsd_file slab cache objects remaining on kmem_cache_shutdown during nfsd teardown while running bz1477872 testcase (JIRA:AlmaLinux-173103)
  * tools/lib/perf/Makefile: libperf includes appended after CFLAGS causes parallel build race, breaking kernel builds [almalinux-10.2.z] (JIRA:AlmaLinux-183975)
  * [AlmaLinux10-de…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:42919</guid>
    </item>
    <item>
      <title>bdu:2026-13949</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-13949</link>
      <description>bdu:2026-13949</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-13949</guid>
    </item>
    <item>
      <title>BELL-CVE-2026-53009</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-53009</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-53009</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0926 — De multiples vulnérabilités ont été découvertes dans le noyau Linux d'Ubuntu. Certaines d'entre elles permettent à un a…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0926</link>
      <description>certfr-2026-avi-0926</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0926</guid>
    </item>
    <item>
      <title>EUVD-2026-365495</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-365495</link>
      <description>EUVD-2026-365495</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-365495</guid>
    </item>
    <item>
      <title>fkie_cve-2026-53009</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-53009</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;ice: fix double-free of tx_buf skb&lt;/p&gt;
&lt;p&gt;If ice_tso() or ice_tx_csum() fail, the error path in
ice_xmit_frame_ring() frees the skb, but the &amp;#39;first&amp;#39; tx_buf still points
to it and is marked as valid (ICE_TX_BUF_SKB).
&amp;#39;next_to_use&amp;#39; remains unchanged, so the potential problem will
likely fix itself when the next packet is transmitted and the tx_buf
gets overwritten. But if there is no next packet and the interface is
brought down instead, ice_clean_tx_ring() -&amp;gt; ice_unmap_and_free_tx_buf()
will find the tx_buf and free the skb for the second time.&lt;/p&gt;
&lt;p&gt;The fix is to reset the tx_buf type to ICE_TX_BUF_EMPTY in the error
path, so that ice_unmap_and_free_tx_buf().
Move the initialization of &amp;#39;first&amp;#39; up, to ensure it&amp;#39;s already valid in
case we hit the linearization error path.&lt;/p&gt;
&lt;p&gt;The bug was spotted by AI while I had it looking for something else.
It also proposed an initial version of the patch.&lt;/p&gt;
&lt;p&gt;I reproduced the bug and tested the fix by adding code to inject
failures, on a build with KASAN.&lt;/p&gt;
&lt;p&gt;I looked for similar bugs in related Intel drivers and did not find any.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;ice: fix double-free of tx_buf skb&lt;/p&gt;
&lt;p&gt;If ice_tso() or ice_tx_csum() fail, the error path in
ice_xmit_frame_ring() frees the skb, but the &amp;#39;first&amp;#39; tx_buf still points
to it and is marked as valid (ICE_TX_BUF_SKB).
&amp;#39;next_to_use&amp;#39; remains unchanged, so the potential problem will
likely fix itself when the next packet is transmitted and the tx_buf
gets overwritten. But if there is no next packet and the interface is
brought down instead, ice_clean_tx_ring() -&amp;gt; ice_unmap_and_free_tx_buf()
will find the tx_buf and free the skb for the second time.&lt;/p&gt;
&lt;p&gt;The fix is to reset the tx_buf type to ICE_TX_BUF_EMPTY in the error
path, so that ice_unmap_and_free_tx_buf().
Move the initialization of &amp;#39;first&amp;#39; up, to ensure it&amp;#39;s already valid in
case we hit the linearization error path.&lt;/p&gt;
&lt;p&gt;The bug was spotted by AI while I had it looking for something else.
It also proposed an initial version of the patch.&lt;/p&gt;
&lt;p&gt;I reproduced the bug and tested the fix by adding code to inject
failures, on a build with KASAN.&lt;/p&gt;
&lt;p&gt;I looked for similar bugs in related Intel drivers and did not find any.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-53009</guid>
    </item>
    <item>
      <title>GHSA-67p5-53x6-9j7q</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-67p5-53x6-9j7q</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;ice: fix double-free of tx_buf skb&lt;/p&gt;
&lt;p&gt;If ice_tso() or ice_tx_csum() fail, the error path in
ice_xmit_frame_ring() frees the skb, but the &amp;#39;first&amp;#39; tx_buf still points
to it and is marked as valid (ICE_TX_BUF_SKB).
&amp;#39;next_to_use&amp;#39; remains unchanged, so the potential problem will
likely fix itself when the next packet is transmitted and the tx_buf
gets overwritten. But if there is no next packet and the interface is
brought down instead, ice_clean_tx_ring() -&amp;gt; ice_unmap_and_free_tx_buf()
will find the tx_buf and free the skb for the second time.&lt;/p&gt;
&lt;p&gt;The fix is to reset the tx_buf type to ICE_TX_BUF_EMPTY in the error
path, so that ice_unmap_and_free_tx_buf().
Move the initialization of &amp;#39;first&amp;#39; up, to ensure it&amp;#39;s already valid in
case we hit the linearization error path.&lt;/p&gt;
&lt;p&gt;The bug was spotted by AI while I had it looking for something else.
It also proposed an initial version of the patch.&lt;/p&gt;
&lt;p&gt;I reproduced the bug and tested the fix by adding code to inject
failures, on a build with KASAN.&lt;/p&gt;
&lt;p&gt;I looked for similar bugs in related Intel drivers and did not find any.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;ice: fix double-free of tx_buf skb&lt;/p&gt;
&lt;p&gt;If ice_tso() or ice_tx_csum() fail, the error path in
ice_xmit_frame_ring() frees the skb, but the &amp;#39;first&amp;#39; tx_buf still points
to it and is marked as valid (ICE_TX_BUF_SKB).
&amp;#39;next_to_use&amp;#39; remains unchanged, so the potential problem will
likely fix itself when the next packet is transmitted and the tx_buf
gets overwritten. But if there is no next packet and the interface is
brought down instead, ice_clean_tx_ring() -&amp;gt; ice_unmap_and_free_tx_buf()
will find the tx_buf and free the skb for the second time.&lt;/p&gt;
&lt;p&gt;The fix is to reset the tx_buf type to ICE_TX_BUF_EMPTY in the error
path, so that ice_unmap_and_free_tx_buf().
Move the initialization of &amp;#39;first&amp;#39; up, to ensure it&amp;#39;s already valid in
case we hit the linearization error path.&lt;/p&gt;
&lt;p&gt;The bug was spotted by AI while I had it looking for something else.
It also proposed an initial version of the patch.&lt;/p&gt;
&lt;p&gt;I reproduced the bug and tested the fix by adding code to inject
failures, on a build with KASAN.&lt;/p&gt;
&lt;p&gt;I looked for similar bugs in related Intel drivers and did not find any.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-67p5-53x6-9j7q</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-53009 — ice: fix double-free of tx_buf skb</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-53009</link>
      <description>msrc_CVE-2026-53009</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-53009</guid>
    </item>
    <item>
      <title>OESA-2026-3156 — kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-3156</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP4: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;drbd: add missing kref_get in handle_write_conflicts&lt;/p&gt;
&lt;p&gt;With `two-primaries` enabled, DRBD tries to detect &amp;amp;quot;concurrent&amp;amp;quot; writes
and handle write conflicts, so that even if you write to the same sector
simultaneously on both nodes, they end up with the identical data once
the writes are completed.&lt;/p&gt;
&lt;p&gt;In handling &amp;amp;quot;superseeded&amp;amp;quot; writes, we forgot a kref_get,
resulting in a premature drbd_destroy_device and use after free,
and further to kernel crashes with symptoms.&lt;/p&gt;
&lt;p&gt;Relevance: No one should use DRBD as a random data generator, and apparently
all users of &amp;amp;quot;two-primaries&amp;amp;quot; handle concurrent writes correctly on layer up.
That is cluster file systems use some distributed lock manager,
and live migration in virtualization environments stops writes on one node
before starting writes on the other node.&lt;/p&gt;
&lt;p&gt;Which means that other than for &amp;amp;quot;test cases&amp;amp;quot;,
this code path is never taken in real life.&lt;/p&gt;
&lt;p&gt;FYI, in DRBD 9, things are handled differently nowadays.  We still detect
&amp;amp;quot;write conflicts&amp;amp;quot;, but no longer try to be smart about them.
We decided to disconnect hard instead: upper layers must not submit concurrent
writes. If they do, that&amp;amp;apos;s their fault.(CVE-2025-38708)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;wifi: mwifiex: Initialize the chan_stats array to zero&lt;/p&gt;
&lt;p&gt;The adapter-&amp;amp;gt…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP4: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;drbd: add missing kref_get in handle_write_conflicts&lt;/p&gt;
&lt;p&gt;With `two-primaries` enabled, DRBD tries to detect &amp;amp;quot;concurrent&amp;amp;quot; writes
and handle write conflicts, so that even if you write to the same sector
simultaneously on both nodes, they end up with the identical data once
the writes are completed.&lt;/p&gt;
&lt;p&gt;In handling &amp;amp;quot;superseeded&amp;amp;quot; writes, we forgot a kref_get,
resulting in a premature drbd_destroy_device and use after free,
and further to kernel crashes with symptoms.&lt;/p&gt;
&lt;p&gt;Relevance: No one should use DRBD as a random data generator, and apparently
all users of &amp;amp;quot;two-primaries&amp;amp;quot; handle concurrent writes correctly on layer up.
That is cluster file systems use some distributed lock manager,
and live migration in virtualization environments stops writes on one node
before starting writes on the other node.&lt;/p&gt;
&lt;p&gt;Which means that other than for &amp;amp;quot;test cases&amp;amp;quot;,
this code path is never taken in real life.&lt;/p&gt;
&lt;p&gt;FYI, in DRBD 9, things are handled differently nowadays.  We still detect
&amp;amp;quot;write conflicts&amp;amp;quot;, but no longer try to be smart about them.
We decided to disconnect hard instead: upper layers must not submit concurrent
writes. If they do, that&amp;amp;apos;s their fault.(CVE-2025-38708)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;wifi: mwifiex: Initialize the chan_stats array to zero&lt;/p&gt;
&lt;p&gt;The adapter-&amp;amp;gt…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-3156</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:21555-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:21555-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:21555-1</guid>
    </item>
    <item>
      <title>RHSA-2026:54246 — Red Hat Security Advisory: kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:54246</link>
      <description>&lt;p&gt;kernel: udf: fix partition descriptor append bookkeeping kernel: ice: fix double-free of tx_buf skb&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;kernel: udf: fix partition descriptor append bookkeeping kernel: ice: fix double-free of tx_buf skb&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:54246</guid>
    </item>
    <item>
      <title>RLSA-2026:42919 — Important: kernel security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:42919</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: kernel&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: crypto: af_alg - zero initialize memory allocated via sock_kmalloc (CVE-2025-71113)&lt;/p&gt;
&lt;p&gt;* kernel: Linux kernel: Denial of Service due to memory leak in tpm2_load_cmd (CVE-2025-71147)&lt;/p&gt;
&lt;p&gt;* kernel: flex_proportions: make fprop_new_period() hardirq safe (CVE-2026-23168)&lt;/p&gt;
&lt;p&gt;* kernel: cxl/port: Fix use after free of parent_port in cxl_detach_ep() (CVE-2026-31530)&lt;/p&gt;
&lt;p&gt;* kernel: xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete (CVE-2026-46116)&lt;/p&gt;
&lt;p&gt;* kernel: fanotify: fix false positive on permission events (CVE-2026-46150)&lt;/p&gt;
&lt;p&gt;* kernel: drm: Set old handle to NULL before prime swap in change_handle (CVE-2026-46215)&lt;/p&gt;
&lt;p&gt;* kernel: drm/xe: Fix error cleanup in xe_exec_queue_create_ioctl() (CVE-2026-52976)&lt;/p&gt;
&lt;p&gt;* kernel: drm/xe/dma-buf: fix UAF with retry loop (CVE-2026-52950)&lt;/p&gt;
&lt;p&gt;* kernel: ice: fix double-free of tx_buf skb (CVE-2026-53009)&lt;/p&gt;
&lt;p&gt;* kernel: Bluetooth: l2cap: Add missing chan lock in l2cap_ecred_reconf_rsp (CVE-2026-53071)&lt;/p&gt;
&lt;p&gt;* kernel: can: bcm: thrtimer use-after-free during RX operation teardown ()&lt;/p&gt;
&lt;p&gt;Bug Fix(es) and Enhancement(s):&lt;/p&gt;
&lt;p&gt;* nfsd_file slab cache objects remaining on kmem_cache_shutdown during nfsd teardown while running bz1477872 testcase (JIRA:Rocky Linux-173103)&lt;/p&gt;
&lt;p&gt;* tools/lib/perf/Makefile: libperf includes appended after CFLAGS causes parallel build race, breaking kernel builds [rhel-10.2.z] (JIRA:Rocky Linux-183975)&lt;/p&gt;
&lt;p&gt;* [Rocky Linux10-debug]: BUG: KASAN: slab-…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: kernel&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: crypto: af_alg - zero initialize memory allocated via sock_kmalloc (CVE-2025-71113)&lt;/p&gt;
&lt;p&gt;* kernel: Linux kernel: Denial of Service due to memory leak in tpm2_load_cmd (CVE-2025-71147)&lt;/p&gt;
&lt;p&gt;* kernel: flex_proportions: make fprop_new_period() hardirq safe (CVE-2026-23168)&lt;/p&gt;
&lt;p&gt;* kernel: cxl/port: Fix use after free of parent_port in cxl_detach_ep() (CVE-2026-31530)&lt;/p&gt;
&lt;p&gt;* kernel: xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete (CVE-2026-46116)&lt;/p&gt;
&lt;p&gt;* kernel: fanotify: fix false positive on permission events (CVE-2026-46150)&lt;/p&gt;
&lt;p&gt;* kernel: drm: Set old handle to NULL before prime swap in change_handle (CVE-2026-46215)&lt;/p&gt;
&lt;p&gt;* kernel: drm/xe: Fix error cleanup in xe_exec_queue_create_ioctl() (CVE-2026-52976)&lt;/p&gt;
&lt;p&gt;* kernel: drm/xe/dma-buf: fix UAF with retry loop (CVE-2026-52950)&lt;/p&gt;
&lt;p&gt;* kernel: ice: fix double-free of tx_buf skb (CVE-2026-53009)&lt;/p&gt;
&lt;p&gt;* kernel: Bluetooth: l2cap: Add missing chan lock in l2cap_ecred_reconf_rsp (CVE-2026-53071)&lt;/p&gt;
&lt;p&gt;* kernel: can: bcm: thrtimer use-after-free during RX operation teardown ()&lt;/p&gt;
&lt;p&gt;Bug Fix(es) and Enhancement(s):&lt;/p&gt;
&lt;p&gt;* nfsd_file slab cache objects remaining on kmem_cache_shutdown during nfsd teardown while running bz1477872 testcase (JIRA:Rocky Linux-173103)&lt;/p&gt;
&lt;p&gt;* tools/lib/perf/Makefile: libperf includes appended after CFLAGS causes parallel build race, breaking kernel builds [rhel-10.2.z] (JIRA:Rocky Linux-183975)&lt;/p&gt;
&lt;p&gt;* [Rocky Linux10-debug]: BUG: KASAN: slab-…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:42919</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:23066-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:23066-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:23066-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-53009</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-53009</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:Pro:18.04:LTS: linux-aws-5.4, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:Pro:18.04:LTS: linux-azure-5.4, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3 and 227 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: ice: fix double-free of tx_buf skb If ice_tso() or ice_tx_csum() fail, the error path in ice_xmit_frame_ring() frees the skb, but the &amp;#39;first&amp;#39; tx_buf still points to it and is marked as valid (ICE_TX_BUF_SKB). &amp;#39;next_to_use&amp;#39; remains unchanged, so the potential problem will likely fix itself when the next packet is transmitted and the tx_buf gets overwritten. But if there is no next packet and the interface is brought down instead, ice_clean_tx_ring() -&amp;gt; ice_unmap_and_free_tx_buf() will find the tx_buf and free the skb for the second time. The fix is to reset the tx_buf type to ICE_TX_BUF_EMPTY in the error path, so that ice_unmap_and_free_tx_buf(). Move the initialization of &amp;#39;first&amp;#39; up, to ensure it&amp;#39;s already valid in case we hit the linearization error path. The bug was spotted by AI while I had it looking for something else. It also proposed an initial version of the patch. I reproduced the bug and tested the fix by adding code to inject failures, on a build with KASAN. I looked for similar bugs in related Intel drivers and did not find any.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:Pro:18.04:LTS: linux-aws-5.4, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:Pro:18.04:LTS: linux-azure-5.4, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3 and 227 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: ice: fix double-free of tx_buf skb If ice_tso() or ice_tx_csum() fail, the error path in ice_xmit_frame_ring() frees the skb, but the &amp;#39;first&amp;#39; tx_buf still points to it and is marked as valid (ICE_TX_BUF_SKB). &amp;#39;next_to_use&amp;#39; remains unchanged, so the potential problem will likely fix itself when the next packet is transmitted and the tx_buf gets overwritten. But if there is no next packet and the interface is brought down instead, ice_clean_tx_ring() -&amp;gt; ice_unmap_and_free_tx_buf() will find the tx_buf and free the skb for the second time. The fix is to reset the tx_buf type to ICE_TX_BUF_EMPTY in the error path, so that ice_unmap_and_free_tx_buf(). Move the initialization of &amp;#39;first&amp;#39; up, to ensure it&amp;#39;s already valid in case we hit the linearization error path. The bug was spotted by AI while I had it looking for something else. It also proposed an initial version of the patch. I reproduced the bug and tested the fix by adding code to inject failures, on a build with KASAN. I looked for similar bugs in related Intel drivers and did not find any.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-53009</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2077 — Linux Kernel: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2077</link>
      <description>&lt;p&gt;Ein entfernter Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um Sicherheitsvorkehrungen zu umgehen, einen Denial-of-Service-Zustand herbeizuführen und weitere, nicht näher spezifizierte Auswirkungen zu erzielen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um Sicherheitsvorkehrungen zu umgehen, einen Denial-of-Service-Zustand herbeizuführen und weitere, nicht näher spezifizierte Auswirkungen zu erzielen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2077</guid>
    </item>
  </channel>
</rss>
