<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 09 Oct 2026 04:58:59 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-14088</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-14088</link>
      <description>bdu:2026-14088</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-14088</guid>
    </item>
    <item>
      <title>BELL-CVE-2026-53308</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-53308</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-53308</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0926 — De multiples vulnérabilités ont été découvertes dans le noyau Linux d'Ubuntu. Certaines d'entre elles permettent à un a…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0926</link>
      <description>certfr-2026-avi-0926</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0926</guid>
    </item>
    <item>
      <title>EUVD-2026-330799</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-330799</link>
      <description>EUVD-2026-330799</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-330799</guid>
    </item>
    <item>
      <title>fkie_cve-2026-53308</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-53308</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;power: supply: max77705: Free allocated workqueue and fix removal order&lt;/p&gt;
&lt;p&gt;Use devm interface for allocating workqueue to fix two bugs at the same
time:&lt;/p&gt;
&lt;p&gt;1. Driver leaks the memory on remove(), because the workqueue is not
   destroyed.&lt;/p&gt;
&lt;p&gt;2. Driver allocates workqueue and then registers interrupt handlers
   with devm interface.  This means that probe error paths will not use a
   reversed order, but first destroy the workqueue and then, via devm
   release handlers, free the interrupt.&lt;/p&gt;
&lt;p&gt;The interrupt handler schedules work on this exact workqueue, thus if
   interrupt is hit in this short time window - after destroying
   workqueue, but before devm() frees the interrupt - the schedulled
   work will lead to use of freed memory.&lt;/p&gt;
&lt;p&gt;Change is not equivalent in the workqueue itself: use non-legacy API
which does not set (__WQ_LEGACY | WQ_MEM_RECLAIM).  The workqueue is
used to update power supply (power_supply_changed()) status, thus there
is no point to run it for memory reclaim.  Note that dev_name() is not
directly used in second argument to prevent possible unlikely parsing
any &amp;#34;%&amp;#34; character in device name as format.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;power: supply: max77705: Free allocated workqueue and fix removal order&lt;/p&gt;
&lt;p&gt;Use devm interface for allocating workqueue to fix two bugs at the same
time:&lt;/p&gt;
&lt;p&gt;1. Driver leaks the memory on remove(), because the workqueue is not
   destroyed.&lt;/p&gt;
&lt;p&gt;2. Driver allocates workqueue and then registers interrupt handlers
   with devm interface.  This means that probe error paths will not use a
   reversed order, but first destroy the workqueue and then, via devm
   release handlers, free the interrupt.&lt;/p&gt;
&lt;p&gt;The interrupt handler schedules work on this exact workqueue, thus if
   interrupt is hit in this short time window - after destroying
   workqueue, but before devm() frees the interrupt - the schedulled
   work will lead to use of freed memory.&lt;/p&gt;
&lt;p&gt;Change is not equivalent in the workqueue itself: use non-legacy API
which does not set (__WQ_LEGACY | WQ_MEM_RECLAIM).  The workqueue is
used to update power supply (power_supply_changed()) status, thus there
is no point to run it for memory reclaim.  Note that dev_name() is not
directly used in second argument to prevent possible unlikely parsing
any &amp;#34;%&amp;#34; character in device name as format.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-53308</guid>
    </item>
    <item>
      <title>GHSA-2vjf-7vmh-8jpp</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-2vjf-7vmh-8jpp</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;power: supply: max77705: Free allocated workqueue and fix removal order&lt;/p&gt;
&lt;p&gt;Use devm interface for allocating workqueue to fix two bugs at the same
time:&lt;/p&gt;
&lt;p&gt;1. Driver leaks the memory on remove(), because the workqueue is not
   destroyed.&lt;/p&gt;
&lt;p&gt;2. Driver allocates workqueue and then registers interrupt handlers
   with devm interface.  This means that probe error paths will not use a
   reversed order, but first destroy the workqueue and then, via devm
   release handlers, free the interrupt.&lt;/p&gt;
&lt;p&gt;The interrupt handler schedules work on this exact workqueue, thus if
   interrupt is hit in this short time window - after destroying
   workqueue, but before devm() frees the interrupt - the schedulled
   work will lead to use of freed memory.&lt;/p&gt;
&lt;p&gt;Change is not equivalent in the workqueue itself: use non-legacy API
which does not set (__WQ_LEGACY | WQ_MEM_RECLAIM).  The workqueue is
used to update power supply (power_supply_changed()) status, thus there
is no point to run it for memory reclaim.  Note that dev_name() is not
directly used in second argument to prevent possible unlikely parsing
any &amp;#34;%&amp;#34; character in device name as format.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;power: supply: max77705: Free allocated workqueue and fix removal order&lt;/p&gt;
&lt;p&gt;Use devm interface for allocating workqueue to fix two bugs at the same
time:&lt;/p&gt;
&lt;p&gt;1. Driver leaks the memory on remove(), because the workqueue is not
   destroyed.&lt;/p&gt;
&lt;p&gt;2. Driver allocates workqueue and then registers interrupt handlers
   with devm interface.  This means that probe error paths will not use a
   reversed order, but first destroy the workqueue and then, via devm
   release handlers, free the interrupt.&lt;/p&gt;
&lt;p&gt;The interrupt handler schedules work on this exact workqueue, thus if
   interrupt is hit in this short time window - after destroying
   workqueue, but before devm() frees the interrupt - the schedulled
   work will lead to use of freed memory.&lt;/p&gt;
&lt;p&gt;Change is not equivalent in the workqueue itself: use non-legacy API
which does not set (__WQ_LEGACY | WQ_MEM_RECLAIM).  The workqueue is
used to update power supply (power_supply_changed()) status, thus there
is no point to run it for memory reclaim.  Note that dev_name() is not
directly used in second argument to prevent possible unlikely parsing
any &amp;#34;%&amp;#34; character in device name as format.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-2vjf-7vmh-8jpp</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-53308</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-53308</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 127 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: power: supply: max77705: Free allocated workqueue and fix removal order Use devm interface for allocating workqueue to fix two bugs at the same time: 1. Driver leaks the memory on remove(), because the workqueue is not    destroyed. 2. Driver allocates workqueue and then registers interrupt handlers    with devm interface.  This means that probe error paths will not use a    reversed order, but first destroy the workqueue and then, via devm    release handlers, free the interrupt.    The interrupt handler schedules work on this exact workqueue, thus if    interrupt is hit in this short time window - after destroying    workqueue, but before devm() frees the interrupt - the schedulled    work will lead to use of freed memory. Change is not equivalent in the workqueue itself: use non-legacy API which does not set (__WQ_LEGACY | WQ_MEM_RECLAIM).  The workqueue is used to update power supply (power_supply_changed()) status, thus there is no point to run it for memory reclaim.  Note that dev_name() is not directly used in second argument to prevent possible unlikely parsing any &amp;#34;%&amp;#34; character in device name as format.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 127 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: power: supply: max77705: Free allocated workqueue and fix removal order Use devm interface for allocating workqueue to fix two bugs at the same time: 1. Driver leaks the memory on remove(), because the workqueue is not    destroyed. 2. Driver allocates workqueue and then registers interrupt handlers    with devm interface.  This means that probe error paths will not use a    reversed order, but first destroy the workqueue and then, via devm    release handlers, free the interrupt.    The interrupt handler schedules work on this exact workqueue, thus if    interrupt is hit in this short time window - after destroying    workqueue, but before devm() frees the interrupt - the schedulled    work will lead to use of freed memory. Change is not equivalent in the workqueue itself: use non-legacy API which does not set (__WQ_LEGACY | WQ_MEM_RECLAIM).  The workqueue is used to update power supply (power_supply_changed()) status, thus there is no point to run it for memory reclaim.  Note that dev_name() is not directly used in second argument to prevent possible unlikely parsing any &amp;#34;%&amp;#34; character in device name as format.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-53308</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2119 — Linux Kernel: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2119</link>
      <description>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um Sicherheitsmaßnahmen zu umgehen, einen Denial of Service zu verursachen und potentiell Code auszuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um Sicherheitsmaßnahmen zu umgehen, einen Denial of Service zu verursachen und potentiell Code auszuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2119</guid>
    </item>
  </channel>
</rss>
