<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 23:54:56 +0000</lastBuildDate>
    <item>
      <title>ALSA-2026:54343 — Important: kernel security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:54343</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: kernel, AlmaLinux:10: kernel-64k, AlmaLinux:10: kernel-64k-core, AlmaLinux:10: kernel-64k-debug, AlmaLinux:10: kernel-64k-debug-core, AlmaLinux:10: kernel-64k-debug-devel, AlmaLinux:10: kernel-64k-debug-devel-matched, AlmaLinux:10: kernel-64k-debug-modules, AlmaLinux:10: kernel-64k-debug-modules-core, AlmaLinux:10: kernel-64k-debug-modules-extra and 65 more&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: accel/ivpu: Fix signed integer truncation in IPC receive (CVE-2026-53202)
  * kernel: net/sched: act_api: use RCU with deferred freeing for action lifecycle (CVE-2026-53264)
  * kernel: scsi: target: iscsi: Bound iscsi_encode_text_output() appends to rsp_buf (CVE-2026-63887)
  * kernel: perf/aux: Fix page UAF in map_range() (CVE-2026-64300)
  * kernel: af_unix: set gc_in_progress to true in unix_gc() (CVE-2026-53361)&lt;/p&gt;
&lt;p&gt;Bug Fix(es) and Enhancement(s):&lt;/p&gt;
&lt;p&gt;* netfilter: CVE backports for AlmaLinux 10.2.z (JIRA:AlmaLinux-185311)
  * tlbflush - Windows Driver Verifier catches FLTMGR/Ntfs crashes during KVM 42-VM soak test on AMD EPYC Turin [almalinux-10.2.z] (JIRA:AlmaLinux-214436)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: kernel, AlmaLinux:10: kernel-64k, AlmaLinux:10: kernel-64k-core, AlmaLinux:10: kernel-64k-debug, AlmaLinux:10: kernel-64k-debug-core, AlmaLinux:10: kernel-64k-debug-devel, AlmaLinux:10: kernel-64k-debug-devel-matched, AlmaLinux:10: kernel-64k-debug-modules, AlmaLinux:10: kernel-64k-debug-modules-core, AlmaLinux:10: kernel-64k-debug-modules-extra and 65 more&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: accel/ivpu: Fix signed integer truncation in IPC receive (CVE-2026-53202)
  * kernel: net/sched: act_api: use RCU with deferred freeing for action lifecycle (CVE-2026-53264)
  * kernel: scsi: target: iscsi: Bound iscsi_encode_text_output() appends to rsp_buf (CVE-2026-63887)
  * kernel: perf/aux: Fix page UAF in map_range() (CVE-2026-64300)
  * kernel: af_unix: set gc_in_progress to true in unix_gc() (CVE-2026-53361)&lt;/p&gt;
&lt;p&gt;Bug Fix(es) and Enhancement(s):&lt;/p&gt;
&lt;p&gt;* netfilter: CVE backports for AlmaLinux 10.2.z (JIRA:AlmaLinux-185311)
  * tlbflush - Windows Driver Verifier catches FLTMGR/Ntfs crashes during KVM 42-VM soak test on AMD EPYC Turin [almalinux-10.2.z] (JIRA:AlmaLinux-214436)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:54343</guid>
    </item>
    <item>
      <title>bdu:2026-14230</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-14230</link>
      <description>bdu:2026-14230</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-14230</guid>
    </item>
    <item>
      <title>BELL-CVE-2026-53264</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-53264</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-53264</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0812 — De multiples vulnérabilités ont été découvertes dans Microsoft Azure Linux. Elles permettent à un attaquant de provoque…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0812</link>
      <description>certfr-2026-avi-0812</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0812</guid>
    </item>
    <item>
      <title>EUVD-2026-348222</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-348222</link>
      <description>EUVD-2026-348222</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-348222</guid>
    </item>
    <item>
      <title>fkie_cve-2026-53264</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-53264</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;net/sched: act_api: use RCU with deferred freeing for action lifecycle&lt;/p&gt;
&lt;p&gt;When NEWTFILTER and DELFILTER are run concurrently it is possible to create a
race with an associated action.&lt;/p&gt;
&lt;p&gt;Let&amp;#39;s illustrate with CPU0 running NEWTFILTER and CPU1 running DELFILTER:&lt;/p&gt;
&lt;p&gt;0: mutex_lock() &amp;lt;-- holds the idr lock
 0: rcu_read_lock()
 0: p = idr_find(idr, index) &amp;lt;-- action p is valid (RCU protects IDR)
 0: mutex_unlock() &amp;lt;-- releases the idr lock
 1: refcount_dec_and_mutex_lock() &amp;lt;-- refcnt 1-&amp;gt;0, mutex held
 1: idr_remove(idr, index) &amp;lt;-- Action removed from IDR
 1: mutex_unlock() &amp;lt;-- mutex released allowing us to delete the action
 1: tcf_action_cleanup(p); kfree(p) &amp;lt;-- Kfrees p immediately, no deferral
 0: refcount_inc_not_zero(&amp;amp;p-&amp;gt;tcfa_refcnt) &amp;lt;-- ouch, UAF p points to freed memory&lt;/p&gt;
&lt;p&gt;This patch fixes the race condition between NEWTFILTER and DELFILTER by
adding struct rcu_head to tc_action used in the deferral and introducing a
call_rcu() in the delete path to defer the final kfree().&lt;/p&gt;
&lt;p&gt;Note: this is a revert of commit d7fb60b9cafb (&amp;#34;net_sched: get rid of tcfa_rcu&amp;#34;)
but also modernization/simplification to directly use kfree_rcu().&lt;/p&gt;
&lt;p&gt;Let&amp;#39;s illustrate the new restored code path:&lt;/p&gt;
&lt;p&gt;0: rcu_read_lock()
 1: refcount_dec_and_mutex_lock() &amp;lt;-- refcnt 1-&amp;gt;0, mutex held
 1: idr_remove(idr, index)
 1: mutex_unlock()
 1: call_rcu(&amp;amp;p-&amp;gt;tcfa_rcu, tcf_action_rcu_free) &amp;lt;-- defer kfree after grace period
 0: p = idr_find(idr, index)
 0: refcoun…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;net/sched: act_api: use RCU with deferred freeing for action lifecycle&lt;/p&gt;
&lt;p&gt;When NEWTFILTER and DELFILTER are run concurrently it is possible to create a
race with an associated action.&lt;/p&gt;
&lt;p&gt;Let&amp;#39;s illustrate with CPU0 running NEWTFILTER and CPU1 running DELFILTER:&lt;/p&gt;
&lt;p&gt;0: mutex_lock() &amp;lt;-- holds the idr lock
 0: rcu_read_lock()
 0: p = idr_find(idr, index) &amp;lt;-- action p is valid (RCU protects IDR)
 0: mutex_unlock() &amp;lt;-- releases the idr lock
 1: refcount_dec_and_mutex_lock() &amp;lt;-- refcnt 1-&amp;gt;0, mutex held
 1: idr_remove(idr, index) &amp;lt;-- Action removed from IDR
 1: mutex_unlock() &amp;lt;-- mutex released allowing us to delete the action
 1: tcf_action_cleanup(p); kfree(p) &amp;lt;-- Kfrees p immediately, no deferral
 0: refcount_inc_not_zero(&amp;amp;p-&amp;gt;tcfa_refcnt) &amp;lt;-- ouch, UAF p points to freed memory&lt;/p&gt;
&lt;p&gt;This patch fixes the race condition between NEWTFILTER and DELFILTER by
adding struct rcu_head to tc_action used in the deferral and introducing a
call_rcu() in the delete path to defer the final kfree().&lt;/p&gt;
&lt;p&gt;Note: this is a revert of commit d7fb60b9cafb (&amp;#34;net_sched: get rid of tcfa_rcu&amp;#34;)
but also modernization/simplification to directly use kfree_rcu().&lt;/p&gt;
&lt;p&gt;Let&amp;#39;s illustrate the new restored code path:&lt;/p&gt;
&lt;p&gt;0: rcu_read_lock()
 1: refcount_dec_and_mutex_lock() &amp;lt;-- refcnt 1-&amp;gt;0, mutex held
 1: idr_remove(idr, index)
 1: mutex_unlock()
 1: call_rcu(&amp;amp;p-&amp;gt;tcfa_rcu, tcf_action_rcu_free) &amp;lt;-- defer kfree after grace period
 0: p = idr_find(idr, index)
 0: refcoun…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-53264</guid>
    </item>
    <item>
      <title>GHSA-vq3g-6qwh-5wj2</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-vq3g-6qwh-5wj2</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;net/sched: act_api: use RCU with deferred freeing for action lifecycle&lt;/p&gt;
&lt;p&gt;When NEWTFILTER and DELFILTER are run concurrently it is possible to create a
race with an associated action.&lt;/p&gt;
&lt;p&gt;Let&amp;#39;s illustrate with CPU0 running NEWTFILTER and CPU1 running DELFILTER:&lt;/p&gt;
&lt;p&gt;0: mutex_lock() &amp;lt;-- holds the idr lock
 0: rcu_read_lock()
 0: p = idr_find(idr, index) &amp;lt;-- action p is valid (RCU protects IDR)
 0: mutex_unlock() &amp;lt;-- releases the idr lock
 1: refcount_dec_and_mutex_lock() &amp;lt;-- refcnt 1-&amp;gt;0, mutex held
 1: idr_remove(idr, index) &amp;lt;-- Action removed from IDR
 1: mutex_unlock() &amp;lt;-- mutex released allowing us to delete the action
 1: tcf_action_cleanup(p); kfree(p) &amp;lt;-- Kfrees p immediately, no deferral
 0: refcount_inc_not_zero(&amp;amp;p-&amp;gt;tcfa_refcnt) &amp;lt;-- ouch, UAF p points to freed memory&lt;/p&gt;
&lt;p&gt;This patch fixes the race condition between NEWTFILTER and DELFILTER by
adding struct rcu_head to tc_action used in the deferral and introducing a
call_rcu() in the delete path to defer the final kfree().&lt;/p&gt;
&lt;p&gt;Note: this is a revert of commit d7fb60b9cafb (&amp;#34;net_sched: get rid of tcfa_rcu&amp;#34;)
but also modernization/simplification to directly use kfree_rcu().&lt;/p&gt;
&lt;p&gt;Let&amp;#39;s illustrate the new restored code path:&lt;/p&gt;
&lt;p&gt;0: rcu_read_lock()
 1: refcount_dec_and_mutex_lock() &amp;lt;-- refcnt 1-&amp;gt;0, mutex held
 1: idr_remove(idr, index)
 1: mutex_unlock()
 1: call_rcu(&amp;amp;p-&amp;gt;tcfa_rcu, tcf_action_rcu_free) &amp;lt;-- defer kfree after grace period
 0: p = idr_find(idr, index)
 0: refcoun…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;net/sched: act_api: use RCU with deferred freeing for action lifecycle&lt;/p&gt;
&lt;p&gt;When NEWTFILTER and DELFILTER are run concurrently it is possible to create a
race with an associated action.&lt;/p&gt;
&lt;p&gt;Let&amp;#39;s illustrate with CPU0 running NEWTFILTER and CPU1 running DELFILTER:&lt;/p&gt;
&lt;p&gt;0: mutex_lock() &amp;lt;-- holds the idr lock
 0: rcu_read_lock()
 0: p = idr_find(idr, index) &amp;lt;-- action p is valid (RCU protects IDR)
 0: mutex_unlock() &amp;lt;-- releases the idr lock
 1: refcount_dec_and_mutex_lock() &amp;lt;-- refcnt 1-&amp;gt;0, mutex held
 1: idr_remove(idr, index) &amp;lt;-- Action removed from IDR
 1: mutex_unlock() &amp;lt;-- mutex released allowing us to delete the action
 1: tcf_action_cleanup(p); kfree(p) &amp;lt;-- Kfrees p immediately, no deferral
 0: refcount_inc_not_zero(&amp;amp;p-&amp;gt;tcfa_refcnt) &amp;lt;-- ouch, UAF p points to freed memory&lt;/p&gt;
&lt;p&gt;This patch fixes the race condition between NEWTFILTER and DELFILTER by
adding struct rcu_head to tc_action used in the deferral and introducing a
call_rcu() in the delete path to defer the final kfree().&lt;/p&gt;
&lt;p&gt;Note: this is a revert of commit d7fb60b9cafb (&amp;#34;net_sched: get rid of tcfa_rcu&amp;#34;)
but also modernization/simplification to directly use kfree_rcu().&lt;/p&gt;
&lt;p&gt;Let&amp;#39;s illustrate the new restored code path:&lt;/p&gt;
&lt;p&gt;0: rcu_read_lock()
 1: refcount_dec_and_mutex_lock() &amp;lt;-- refcnt 1-&amp;gt;0, mutex held
 1: idr_remove(idr, index)
 1: mutex_unlock()
 1: call_rcu(&amp;amp;p-&amp;gt;tcfa_rcu, tcf_action_rcu_free) &amp;lt;-- defer kfree after grace period
 0: p = idr_find(idr, index)
 0: refcoun…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-vq3g-6qwh-5wj2</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-53264 — net/sched: act_api: use RCU with deferred freeing for action lifecycle</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-53264</link>
      <description>msrc_CVE-2026-53264</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-53264</guid>
    </item>
    <item>
      <title>OESA-2026-3204 — kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-3204</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP1: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;wifi: rtw88: Use devm_kmemdup() in rtw_set_supported_band()&lt;/p&gt;
&lt;p&gt;Simplify the code by using device managed memory allocations.&lt;/p&gt;
&lt;p&gt;This also fixes a memory leak in rtw_register_hw(). The supported bands
were not freed in the error path.&lt;/p&gt;
&lt;p&gt;Copied from commit 145df52a8671 (&amp;amp;quot;wifi: rtw89: Convert
rtw89_core_set_supported_band to use devm_*&amp;amp;quot;).(CVE-2025-71273)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;xfrm: hold dev ref until after transport_finish NF_HOOK&lt;/p&gt;
&lt;p&gt;After async crypto completes, xfrm_input_resume() calls dev_put()
immediately on re-entry before the skb reaches transport_finish.
The skb-&amp;amp;gt;dev pointer is then used inside NF_HOOK and its okfn,
which can race with device teardown.&lt;/p&gt;
&lt;p&gt;Remove the dev_put from the async resumption entry and instead
drop the reference after the NF_HOOK call in transport_finish,
using a saved device pointer since NF_HOOK may consume the skb.
This covers NF_DROP, NF_QUEUE and NF_STOLEN paths that skip
the okfn.&lt;/p&gt;
&lt;p&gt;For non-transport exits (decaps, gro, drop) and secondary
async return points, release the reference inline when
async is set.(CVE-2026-31663)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;x86: shadow stacks: proper error handling for mmap lock&lt;/p&gt;
&lt;p&gt;김영민 reports that shstk_pop_sigframe() doesn&amp;amp;apos;t check for errors from
mmap_read_lock_killable(), whic…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP1: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;wifi: rtw88: Use devm_kmemdup() in rtw_set_supported_band()&lt;/p&gt;
&lt;p&gt;Simplify the code by using device managed memory allocations.&lt;/p&gt;
&lt;p&gt;This also fixes a memory leak in rtw_register_hw(). The supported bands
were not freed in the error path.&lt;/p&gt;
&lt;p&gt;Copied from commit 145df52a8671 (&amp;amp;quot;wifi: rtw89: Convert
rtw89_core_set_supported_band to use devm_*&amp;amp;quot;).(CVE-2025-71273)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;xfrm: hold dev ref until after transport_finish NF_HOOK&lt;/p&gt;
&lt;p&gt;After async crypto completes, xfrm_input_resume() calls dev_put()
immediately on re-entry before the skb reaches transport_finish.
The skb-&amp;amp;gt;dev pointer is then used inside NF_HOOK and its okfn,
which can race with device teardown.&lt;/p&gt;
&lt;p&gt;Remove the dev_put from the async resumption entry and instead
drop the reference after the NF_HOOK call in transport_finish,
using a saved device pointer since NF_HOOK may consume the skb.
This covers NF_DROP, NF_QUEUE and NF_STOLEN paths that skip
the okfn.&lt;/p&gt;
&lt;p&gt;For non-transport exits (decaps, gro, drop) and secondary
async return points, release the reference inline when
async is set.(CVE-2026-31663)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;x86: shadow stacks: proper error handling for mmap lock&lt;/p&gt;
&lt;p&gt;김영민 reports that shstk_pop_sigframe() doesn&amp;amp;apos;t check for errors from
mmap_read_lock_killable(), whic…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-3204</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:21910-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:21910-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:21910-1</guid>
    </item>
    <item>
      <title>RHSA-2026:53990 — Red Hat Security Advisory: kernel security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:53990</link>
      <description>&lt;p&gt;kernel: fs/smb/client: fix out-of-bounds read in cifs_sanitize_prepath kernel: net/sched: act_api: use RCU with deferred freeing for action lifecycle&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;kernel: fs/smb/client: fix out-of-bounds read in cifs_sanitize_prepath kernel: net/sched: act_api: use RCU with deferred freeing for action lifecycle&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:53990</guid>
    </item>
    <item>
      <title>RLSA-2026:54343 — Important: kernel security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:54343</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: kernel&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: accel/ivpu: Fix signed integer truncation in IPC receive (CVE-2026-53202)&lt;/p&gt;
&lt;p&gt;* kernel: net/sched: act_api: use RCU with deferred freeing for action lifecycle (CVE-2026-53264)&lt;/p&gt;
&lt;p&gt;* kernel: scsi: target: iscsi: Bound iscsi_encode_text_output() appends to rsp_buf (CVE-2026-63887)&lt;/p&gt;
&lt;p&gt;* kernel: perf/aux: Fix page UAF in map_range() (CVE-2026-64300)&lt;/p&gt;
&lt;p&gt;Bug Fix(es) and Enhancement(s):&lt;/p&gt;
&lt;p&gt;* netfilter: CVE backports for Rocky Linux 10.2.z (JIRA:Rocky Linux-185311)&lt;/p&gt;
&lt;p&gt;* tlbflush - Windows Driver Verifier catches FLTMGR/Ntfs crashes during KVM 42-VM soak test on AMD EPYC Turin [rhel-10.2.z] (JIRA:Rocky Linux-214436)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: kernel&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: accel/ivpu: Fix signed integer truncation in IPC receive (CVE-2026-53202)&lt;/p&gt;
&lt;p&gt;* kernel: net/sched: act_api: use RCU with deferred freeing for action lifecycle (CVE-2026-53264)&lt;/p&gt;
&lt;p&gt;* kernel: scsi: target: iscsi: Bound iscsi_encode_text_output() appends to rsp_buf (CVE-2026-63887)&lt;/p&gt;
&lt;p&gt;* kernel: perf/aux: Fix page UAF in map_range() (CVE-2026-64300)&lt;/p&gt;
&lt;p&gt;Bug Fix(es) and Enhancement(s):&lt;/p&gt;
&lt;p&gt;* netfilter: CVE backports for Rocky Linux 10.2.z (JIRA:Rocky Linux-185311)&lt;/p&gt;
&lt;p&gt;* tlbflush - Windows Driver Verifier catches FLTMGR/Ntfs crashes during KVM 42-VM soak test on AMD EPYC Turin [rhel-10.2.z] (JIRA:Rocky Linux-214436)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:54343</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:23477-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:23477-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:23477-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-53264</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-53264</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe, Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:Pro:16.04:LTS: linux-oracle, Ubuntu:Pro:18.04:LTS: linux, Ubuntu:Pro:18.04:LTS: linux-aws, Ubuntu:18.04:LTS: linux-aws-5.0 and 248 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: net/sched: act_api: use RCU with deferred freeing for action lifecycle When NEWTFILTER and DELFILTER are run concurrently it is possible to create a race with an associated action. Let&amp;#39;s illustrate with CPU0 running NEWTFILTER and CPU1 running DELFILTER:  0: mutex_lock() &amp;lt;-- holds the idr lock  0: rcu_read_lock()  0: p = idr_find(idr, index) &amp;lt;-- action p is valid (RCU protects IDR)  0: mutex_unlock() &amp;lt;-- releases the idr lock  1: refcount_dec_and_mutex_lock() &amp;lt;-- refcnt 1-&amp;gt;0, mutex held  1: idr_remove(idr, index) &amp;lt;-- Action removed from IDR  1: mutex_unlock() &amp;lt;-- mutex released allowing us to delete the action  1: tcf_action_cleanup(p); kfree(p) &amp;lt;-- Kfrees p immediately, no deferral  0: refcount_inc_not_zero(&amp;amp;p-&amp;gt;tcfa_refcnt) &amp;lt;-- ouch, UAF p points to freed memory This patch fixes the race condition between NEWTFILTER and DELFILTER by adding struct rcu_head to tc_action used in the deferral and introducing a call_rcu() in the delete path to defer the final kfree(). Note: this is a revert of commit d7fb60b9cafb (&amp;#34;net_sched: get rid of tcfa_rcu&amp;#34;) but also modernization/simplification to directly use kfree_rcu(). Let&amp;#39;s illustrate the new restored code path:  0: rcu_read_lock()  1: refcount_dec_and_mutex_lock() &amp;lt;-- refcnt 1-&amp;gt;0, mutex held  1: idr_remove(idr, index)  1: mutex_unlock()  1: call_rcu(&amp;amp;p-&amp;gt;tcfa_rcu, tcf_action_rcu_free) &amp;lt;-- defer kfree after grace period  0: p = idr_find(idr, index)  0: refcount_inc_no…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe, Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:Pro:16.04:LTS: linux-oracle, Ubuntu:Pro:18.04:LTS: linux, Ubuntu:Pro:18.04:LTS: linux-aws, Ubuntu:18.04:LTS: linux-aws-5.0 and 248 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: net/sched: act_api: use RCU with deferred freeing for action lifecycle When NEWTFILTER and DELFILTER are run concurrently it is possible to create a race with an associated action. Let&amp;#39;s illustrate with CPU0 running NEWTFILTER and CPU1 running DELFILTER:  0: mutex_lock() &amp;lt;-- holds the idr lock  0: rcu_read_lock()  0: p = idr_find(idr, index) &amp;lt;-- action p is valid (RCU protects IDR)  0: mutex_unlock() &amp;lt;-- releases the idr lock  1: refcount_dec_and_mutex_lock() &amp;lt;-- refcnt 1-&amp;gt;0, mutex held  1: idr_remove(idr, index) &amp;lt;-- Action removed from IDR  1: mutex_unlock() &amp;lt;-- mutex released allowing us to delete the action  1: tcf_action_cleanup(p); kfree(p) &amp;lt;-- Kfrees p immediately, no deferral  0: refcount_inc_not_zero(&amp;amp;p-&amp;gt;tcfa_refcnt) &amp;lt;-- ouch, UAF p points to freed memory This patch fixes the race condition between NEWTFILTER and DELFILTER by adding struct rcu_head to tc_action used in the deferral and introducing a call_rcu() in the delete path to defer the final kfree(). Note: this is a revert of commit d7fb60b9cafb (&amp;#34;net_sched: get rid of tcfa_rcu&amp;#34;) but also modernization/simplification to directly use kfree_rcu(). Let&amp;#39;s illustrate the new restored code path:  0: rcu_read_lock()  1: refcount_dec_and_mutex_lock() &amp;lt;-- refcnt 1-&amp;gt;0, mutex held  1: idr_remove(idr, index)  1: mutex_unlock()  1: call_rcu(&amp;amp;p-&amp;gt;tcfa_rcu, tcf_action_rcu_free) &amp;lt;-- defer kfree after grace period  0: p = idr_find(idr, index)  0: refcount_inc_no…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-53264</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2077 — Linux Kernel: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2077</link>
      <description>&lt;p&gt;Ein entfernter Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um Sicherheitsvorkehrungen zu umgehen, einen Denial-of-Service-Zustand herbeizuführen und weitere, nicht näher spezifizierte Auswirkungen zu erzielen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um Sicherheitsvorkehrungen zu umgehen, einen Denial-of-Service-Zustand herbeizuführen und weitere, nicht näher spezifizierte Auswirkungen zu erzielen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2077</guid>
    </item>
  </channel>
</rss>
