<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 13:04:06 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-14029</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-14029</link>
      <description>bdu:2026-14029</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-14029</guid>
    </item>
    <item>
      <title>BELL-CVE-2026-53194</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-53194</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-53194</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0812 — De multiples vulnérabilités ont été découvertes dans Microsoft Azure Linux. Elles permettent à un attaquant de provoque…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0812</link>
      <description>certfr-2026-avi-0812</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0812</guid>
    </item>
    <item>
      <title>EUVD-2026-348191</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-348191</link>
      <description>EUVD-2026-348191</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-348191</guid>
    </item>
    <item>
      <title>fkie_cve-2026-53194</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-53194</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;USB: serial: kl5kusb105: fix bulk-out buffer overflow&lt;/p&gt;
&lt;p&gt;klsi_105_prepare_write_buffer() is called by the generic write path
with the bulk-out buffer and its size (bulk_out_size, 64 bytes). It
stores a two-byte length header at the start of the buffer and copies
the payload from the write fifo starting at buf + KLSI_HDR_LEN, but
passes the full buffer size as the number of bytes to copy:&lt;/p&gt;
&lt;p&gt;count = kfifo_out_locked(&amp;amp;port-&amp;gt;write_fifo, buf + KLSI_HDR_LEN,
                           size, &amp;amp;port-&amp;gt;lock);&lt;/p&gt;
&lt;p&gt;When the fifo holds at least size bytes, size bytes are copied starting
two bytes into the size-byte buffer, writing KLSI_HDR_LEN bytes past its
end. Copy at most size - KLSI_HDR_LEN bytes instead, leaving room for
the header as safe_serial already does.&lt;/p&gt;
&lt;p&gt;Writing bulk_out_size or more bytes to the tty triggers a slab
out-of-bounds write, observed with KASAN by emulating the device with
dummy_hcd and raw-gadget:&lt;/p&gt;
&lt;p&gt;BUG: KASAN: slab-out-of-bounds in kfifo_copy_out+0x83/0xc0
  Write of size 64 at addr ffff888112c62202 by task python3
   kfifo_copy_out
   klsi_105_prepare_write_buffer [kl5kusb105]
   usb_serial_generic_write_start [usbserial]
  Allocated by task 139:
   usb_serial_probe [usbserial]
  The buggy address is located 2 bytes inside of allocated 64-byte region&lt;/p&gt;
&lt;p&gt;The out-of-bounds write no longer occurs with this change applied.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;USB: serial: kl5kusb105: fix bulk-out buffer overflow&lt;/p&gt;
&lt;p&gt;klsi_105_prepare_write_buffer() is called by the generic write path
with the bulk-out buffer and its size (bulk_out_size, 64 bytes). It
stores a two-byte length header at the start of the buffer and copies
the payload from the write fifo starting at buf + KLSI_HDR_LEN, but
passes the full buffer size as the number of bytes to copy:&lt;/p&gt;
&lt;p&gt;count = kfifo_out_locked(&amp;amp;port-&amp;gt;write_fifo, buf + KLSI_HDR_LEN,
                           size, &amp;amp;port-&amp;gt;lock);&lt;/p&gt;
&lt;p&gt;When the fifo holds at least size bytes, size bytes are copied starting
two bytes into the size-byte buffer, writing KLSI_HDR_LEN bytes past its
end. Copy at most size - KLSI_HDR_LEN bytes instead, leaving room for
the header as safe_serial already does.&lt;/p&gt;
&lt;p&gt;Writing bulk_out_size or more bytes to the tty triggers a slab
out-of-bounds write, observed with KASAN by emulating the device with
dummy_hcd and raw-gadget:&lt;/p&gt;
&lt;p&gt;BUG: KASAN: slab-out-of-bounds in kfifo_copy_out+0x83/0xc0
  Write of size 64 at addr ffff888112c62202 by task python3
   kfifo_copy_out
   klsi_105_prepare_write_buffer [kl5kusb105]
   usb_serial_generic_write_start [usbserial]
  Allocated by task 139:
   usb_serial_probe [usbserial]
  The buggy address is located 2 bytes inside of allocated 64-byte region&lt;/p&gt;
&lt;p&gt;The out-of-bounds write no longer occurs with this change applied.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-53194</guid>
    </item>
    <item>
      <title>GHSA-wwc5-7r8x-52gg</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-wwc5-7r8x-52gg</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;USB: serial: kl5kusb105: fix bulk-out buffer overflow&lt;/p&gt;
&lt;p&gt;klsi_105_prepare_write_buffer() is called by the generic write path
with the bulk-out buffer and its size (bulk_out_size, 64 bytes). It
stores a two-byte length header at the start of the buffer and copies
the payload from the write fifo starting at buf + KLSI_HDR_LEN, but
passes the full buffer size as the number of bytes to copy:&lt;/p&gt;
&lt;p&gt;count = kfifo_out_locked(&amp;amp;port-&amp;gt;write_fifo, buf + KLSI_HDR_LEN,
                           size, &amp;amp;port-&amp;gt;lock);&lt;/p&gt;
&lt;p&gt;When the fifo holds at least size bytes, size bytes are copied starting
two bytes into the size-byte buffer, writing KLSI_HDR_LEN bytes past its
end. Copy at most size - KLSI_HDR_LEN bytes instead, leaving room for
the header as safe_serial already does.&lt;/p&gt;
&lt;p&gt;Writing bulk_out_size or more bytes to the tty triggers a slab
out-of-bounds write, observed with KASAN by emulating the device with
dummy_hcd and raw-gadget:&lt;/p&gt;
&lt;p&gt;BUG: KASAN: slab-out-of-bounds in kfifo_copy_out+0x83/0xc0
  Write of size 64 at addr ffff888112c62202 by task python3
   kfifo_copy_out
   klsi_105_prepare_write_buffer [kl5kusb105]
   usb_serial_generic_write_start [usbserial]
  Allocated by task 139:
   usb_serial_probe [usbserial]
  The buggy address is located 2 bytes inside of allocated 64-byte region&lt;/p&gt;
&lt;p&gt;The out-of-bounds write no longer occurs with this change applied.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;USB: serial: kl5kusb105: fix bulk-out buffer overflow&lt;/p&gt;
&lt;p&gt;klsi_105_prepare_write_buffer() is called by the generic write path
with the bulk-out buffer and its size (bulk_out_size, 64 bytes). It
stores a two-byte length header at the start of the buffer and copies
the payload from the write fifo starting at buf + KLSI_HDR_LEN, but
passes the full buffer size as the number of bytes to copy:&lt;/p&gt;
&lt;p&gt;count = kfifo_out_locked(&amp;amp;port-&amp;gt;write_fifo, buf + KLSI_HDR_LEN,
                           size, &amp;amp;port-&amp;gt;lock);&lt;/p&gt;
&lt;p&gt;When the fifo holds at least size bytes, size bytes are copied starting
two bytes into the size-byte buffer, writing KLSI_HDR_LEN bytes past its
end. Copy at most size - KLSI_HDR_LEN bytes instead, leaving room for
the header as safe_serial already does.&lt;/p&gt;
&lt;p&gt;Writing bulk_out_size or more bytes to the tty triggers a slab
out-of-bounds write, observed with KASAN by emulating the device with
dummy_hcd and raw-gadget:&lt;/p&gt;
&lt;p&gt;BUG: KASAN: slab-out-of-bounds in kfifo_copy_out+0x83/0xc0
  Write of size 64 at addr ffff888112c62202 by task python3
   kfifo_copy_out
   klsi_105_prepare_write_buffer [kl5kusb105]
   usb_serial_generic_write_start [usbserial]
  Allocated by task 139:
   usb_serial_probe [usbserial]
  The buggy address is located 2 bytes inside of allocated 64-byte region&lt;/p&gt;
&lt;p&gt;The out-of-bounds write no longer occurs with this change applied.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-wwc5-7r8x-52gg</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-53194 — USB: serial: kl5kusb105: fix bulk-out buffer overflow</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-53194</link>
      <description>msrc_CVE-2026-53194</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-53194</guid>
    </item>
    <item>
      <title>OESA-2026-2929 — kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-2929</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP4: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;ipc: limit next_id allocation to the valid ID range&lt;/p&gt;
&lt;p&gt;The checkpoint/restore sysctl path can request the next SysV IPC id
through ids-&amp;amp;gt;next_id.  ipc_idr_alloc() currently forwards that request to
idr_alloc() with an open-ended upper bound.&lt;/p&gt;
&lt;p&gt;If the valid tail of the SysV IPC id space is full, the allocation can
spill beyond ipc_mni.  The returned SysV IPC id still uses the normal
index encoding, so later lookup and removal can target the wrong slot. 
This leaves the real IDR entry behind and breaks the IDR state for the
object.&lt;/p&gt;
&lt;p&gt;The bug is in ipc_idr_alloc() in the checkpoint/restore path.&lt;/p&gt;
&lt;p&gt;1. ids-&amp;amp;gt;next_id is passed to:&lt;/p&gt;
&lt;p&gt;idr_alloc(&amp;amp;amp;ids-&amp;amp;gt;ipcs_idr, new, ipcid_to_idx(next_id), 0, ...)&lt;/p&gt;
&lt;p&gt;2. The zero upper bound makes the allocation effectively open-ended.
   Once the valid SysV IPC tail is occupied, idr_alloc() can spill past
   ipc_mni and allocate an entry beyond the valid IPC id range.&lt;/p&gt;
&lt;p&gt;3. The new object id is still encoded with the narrower SysV IPC index
   width:&lt;/p&gt;
&lt;p&gt;new-&amp;amp;gt;id = (new-&amp;amp;gt;seq &amp;amp;lt;&amp;amp;lt; ipcmni_seq_shift()) + idx&lt;/p&gt;
&lt;p&gt;4. Later removal goes through ipc_rmid(), which uses:&lt;/p&gt;
&lt;p&gt;ipcid_to_idx(ipcp-&amp;amp;gt;id)&lt;/p&gt;
&lt;p&gt;That truncates the real IDR index. An object actually stored at a
   high index can then be removed as if it lived at a low in-range
   index.&lt;/p&gt;
&lt;p&gt;5. For shared memory, shm_destroy() frees the current…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP4: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;ipc: limit next_id allocation to the valid ID range&lt;/p&gt;
&lt;p&gt;The checkpoint/restore sysctl path can request the next SysV IPC id
through ids-&amp;amp;gt;next_id.  ipc_idr_alloc() currently forwards that request to
idr_alloc() with an open-ended upper bound.&lt;/p&gt;
&lt;p&gt;If the valid tail of the SysV IPC id space is full, the allocation can
spill beyond ipc_mni.  The returned SysV IPC id still uses the normal
index encoding, so later lookup and removal can target the wrong slot. 
This leaves the real IDR entry behind and breaks the IDR state for the
object.&lt;/p&gt;
&lt;p&gt;The bug is in ipc_idr_alloc() in the checkpoint/restore path.&lt;/p&gt;
&lt;p&gt;1. ids-&amp;amp;gt;next_id is passed to:&lt;/p&gt;
&lt;p&gt;idr_alloc(&amp;amp;amp;ids-&amp;amp;gt;ipcs_idr, new, ipcid_to_idx(next_id), 0, ...)&lt;/p&gt;
&lt;p&gt;2. The zero upper bound makes the allocation effectively open-ended.
   Once the valid SysV IPC tail is occupied, idr_alloc() can spill past
   ipc_mni and allocate an entry beyond the valid IPC id range.&lt;/p&gt;
&lt;p&gt;3. The new object id is still encoded with the narrower SysV IPC index
   width:&lt;/p&gt;
&lt;p&gt;new-&amp;amp;gt;id = (new-&amp;amp;gt;seq &amp;amp;lt;&amp;amp;lt; ipcmni_seq_shift()) + idx&lt;/p&gt;
&lt;p&gt;4. Later removal goes through ipc_rmid(), which uses:&lt;/p&gt;
&lt;p&gt;ipcid_to_idx(ipcp-&amp;amp;gt;id)&lt;/p&gt;
&lt;p&gt;That truncates the real IDR index. An object actually stored at a
   high index can then be removed as if it lived at a low in-range
   index.&lt;/p&gt;
&lt;p&gt;5. For shared memory, shm_destroy() frees the current…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-2929</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:21388-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:21388-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:21388-1</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:22742-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:22742-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:22742-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-53194</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-53194</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux, Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe and 255 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: USB: serial: kl5kusb105: fix bulk-out buffer overflow klsi_105_prepare_write_buffer() is called by the generic write path with the bulk-out buffer and its size (bulk_out_size, 64 bytes). It stores a two-byte length header at the start of the buffer and copies the payload from the write fifo starting at buf + KLSI_HDR_LEN, but passes the full buffer size as the number of bytes to copy:   count = kfifo_out_locked(&amp;amp;port-&amp;gt;write_fifo, buf + KLSI_HDR_LEN,                            size, &amp;amp;port-&amp;gt;lock); When the fifo holds at least size bytes, size bytes are copied starting two bytes into the size-byte buffer, writing KLSI_HDR_LEN bytes past its end. Copy at most size - KLSI_HDR_LEN bytes instead, leaving room for the header as safe_serial already does. Writing bulk_out_size or more bytes to the tty triggers a slab out-of-bounds write, observed with KASAN by emulating the device with dummy_hcd and raw-gadget:   BUG: KASAN: slab-out-of-bounds in kfifo_copy_out+0x83/0xc0   Write of size 64 at addr ffff888112c62202 by task python3    kfifo_copy_out    klsi_105_prepare_write_buffer [kl5kusb105]    usb_serial_generic_write_start [usbserial]   Allocated by task 139:    usb_serial_probe [usbserial]   The buggy address is located 2 bytes inside of allocated 64-byte region The out-of-bounds write no longer occurs with this change applied.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux, Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe and 255 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: USB: serial: kl5kusb105: fix bulk-out buffer overflow klsi_105_prepare_write_buffer() is called by the generic write path with the bulk-out buffer and its size (bulk_out_size, 64 bytes). It stores a two-byte length header at the start of the buffer and copies the payload from the write fifo starting at buf + KLSI_HDR_LEN, but passes the full buffer size as the number of bytes to copy:   count = kfifo_out_locked(&amp;amp;port-&amp;gt;write_fifo, buf + KLSI_HDR_LEN,                            size, &amp;amp;port-&amp;gt;lock); When the fifo holds at least size bytes, size bytes are copied starting two bytes into the size-byte buffer, writing KLSI_HDR_LEN bytes past its end. Copy at most size - KLSI_HDR_LEN bytes instead, leaving room for the header as safe_serial already does. Writing bulk_out_size or more bytes to the tty triggers a slab out-of-bounds write, observed with KASAN by emulating the device with dummy_hcd and raw-gadget:   BUG: KASAN: slab-out-of-bounds in kfifo_copy_out+0x83/0xc0   Write of size 64 at addr ffff888112c62202 by task python3    kfifo_copy_out    klsi_105_prepare_write_buffer [kl5kusb105]    usb_serial_generic_write_start [usbserial]   Allocated by task 139:    usb_serial_probe [usbserial]   The buggy address is located 2 bytes inside of allocated 64-byte region The out-of-bounds write no longer occurs with this change applied.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-53194</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2077 — Linux Kernel: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2077</link>
      <description>&lt;p&gt;Ein entfernter Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um Sicherheitsvorkehrungen zu umgehen, einen Denial-of-Service-Zustand herbeizuführen und weitere, nicht näher spezifizierte Auswirkungen zu erzielen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um Sicherheitsvorkehrungen zu umgehen, einen Denial-of-Service-Zustand herbeizuführen und weitere, nicht näher spezifizierte Auswirkungen zu erzielen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2077</guid>
    </item>
  </channel>
</rss>
