<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 14:57:45 +0000</lastBuildDate>
    <item>
      <title>ALSA-2026:70402 — Important: kernel security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:70402</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: bpftool, AlmaLinux:8: kernel, AlmaLinux:8: kernel-abi-stablelists, AlmaLinux:8: kernel-core, AlmaLinux:8: kernel-cross-headers, AlmaLinux:8: kernel-debug, AlmaLinux:8: kernel-debug-core, AlmaLinux:8: kernel-debug-devel, AlmaLinux:8: kernel-debug-modules, AlmaLinux:8: kernel-debug-modules-extra and 15 more&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg (CVE-2025-39964)
  * kernel: Linux kernel Bluetooth: Denial of Service via race condition in hidp_session_thread (CVE-2023-54120)
  * kernel: Bluetooth: L2CAP: Fix potential user-after-free (CVE-2023-54214)
  * kernel: Bluetooth: btusb: revert use of devm_kzalloc in btusb (CVE-2025-71082)
  * kernel: Bluetooth: SMP: force responder MITM requirements before building the pairing response (CVE-2026-43334)
  * kernel: iommu/vt-d: Clear Present bit before tearing down PASID entry (CVE-2026-45894)
  * kernel: RDMA/rxe: Validate pad and ICRC before payload_size() in rxe_rcv (CVE-2026-46043)
  * kernel: RDMA/rxe: Reject unknown opcodes before ICRC processing (CVE-2026-46133)
  * kernel: Bluetooth: serialize accept_q access (CVE-2026-52918)
  * kernel: dm cache policy smq: fix missing locks in invalidating cache blocks (CVE-2026-53062)
  * kernel: iommu/amd: Fix clone_alias() to use the original device&amp;#39;s devid (CVE-2026-53053)
  * kernel: Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind() (CVE-2026-53256)
  * kernel: Bluetooth: RFCOMM: validate skb length in MCC handlers (CVE-2026-53254)
  * kernel: keys: Pin request_key_auth payload in instantiate paths (CVE-2026-63823)
  * kernel: Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp (CVE-2026-63975)
  * kernel: Bluetooth: HIDP: fi…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: bpftool, AlmaLinux:8: kernel, AlmaLinux:8: kernel-abi-stablelists, AlmaLinux:8: kernel-core, AlmaLinux:8: kernel-cross-headers, AlmaLinux:8: kernel-debug, AlmaLinux:8: kernel-debug-core, AlmaLinux:8: kernel-debug-devel, AlmaLinux:8: kernel-debug-modules, AlmaLinux:8: kernel-debug-modules-extra and 15 more&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg (CVE-2025-39964)
  * kernel: Linux kernel Bluetooth: Denial of Service via race condition in hidp_session_thread (CVE-2023-54120)
  * kernel: Bluetooth: L2CAP: Fix potential user-after-free (CVE-2023-54214)
  * kernel: Bluetooth: btusb: revert use of devm_kzalloc in btusb (CVE-2025-71082)
  * kernel: Bluetooth: SMP: force responder MITM requirements before building the pairing response (CVE-2026-43334)
  * kernel: iommu/vt-d: Clear Present bit before tearing down PASID entry (CVE-2026-45894)
  * kernel: RDMA/rxe: Validate pad and ICRC before payload_size() in rxe_rcv (CVE-2026-46043)
  * kernel: RDMA/rxe: Reject unknown opcodes before ICRC processing (CVE-2026-46133)
  * kernel: Bluetooth: serialize accept_q access (CVE-2026-52918)
  * kernel: dm cache policy smq: fix missing locks in invalidating cache blocks (CVE-2026-53062)
  * kernel: iommu/amd: Fix clone_alias() to use the original device&amp;#39;s devid (CVE-2026-53053)
  * kernel: Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind() (CVE-2026-53256)
  * kernel: Bluetooth: RFCOMM: validate skb length in MCC handlers (CVE-2026-53254)
  * kernel: keys: Pin request_key_auth payload in instantiate paths (CVE-2026-63823)
  * kernel: Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp (CVE-2026-63975)
  * kernel: Bluetooth: HIDP: fi…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:70402</guid>
    </item>
    <item>
      <title>BELL-CVE-2026-63823</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-63823</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-63823</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0957 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de Debian LTS. Certaines d'entre elles permettent à…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0957</link>
      <description>certfr-2026-avi-0957</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0957</guid>
    </item>
    <item>
      <title>EUVD-2026-353144</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-353144</link>
      <description>EUVD-2026-353144</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-353144</guid>
    </item>
    <item>
      <title>fkie_cve-2026-63823</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-63823</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;keys: Pin request_key_auth payload in instantiate paths&lt;/p&gt;
&lt;p&gt;A: request_key()       B: KEYCTL_INSTANTIATE_IOV
================       =========================&lt;/p&gt;
&lt;p&gt;create auth key
store rka in auth key
wait for helper
                       get auth key
                       load rka from auth key
                       copy user payload
                       sleep on #PF&lt;/p&gt;
&lt;p&gt;helper completed
detach and free rka
destroy auth key
                       wake up
                       use rka-&amp;gt;target_key
                       **USE-AFTER-FREE**&lt;/p&gt;
&lt;p&gt;Give request_key_auth payloads a refcount.  Take a payload reference while
authkey-&amp;gt;sem stabilizes the payload and revocation state.  Hold that
reference across the instantiate and reject paths.  Drop the auth key
owning reference from revoke and destroy.&lt;/p&gt;
&lt;p&gt;[jarkko: Replaced the first two paragraphs of text with an actual
 concurrency scenario.]&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;keys: Pin request_key_auth payload in instantiate paths&lt;/p&gt;
&lt;p&gt;A: request_key()       B: KEYCTL_INSTANTIATE_IOV
================       =========================&lt;/p&gt;
&lt;p&gt;create auth key
store rka in auth key
wait for helper
                       get auth key
                       load rka from auth key
                       copy user payload
                       sleep on #PF&lt;/p&gt;
&lt;p&gt;helper completed
detach and free rka
destroy auth key
                       wake up
                       use rka-&amp;gt;target_key
                       **USE-AFTER-FREE**&lt;/p&gt;
&lt;p&gt;Give request_key_auth payloads a refcount.  Take a payload reference while
authkey-&amp;gt;sem stabilizes the payload and revocation state.  Hold that
reference across the instantiate and reject paths.  Drop the auth key
owning reference from revoke and destroy.&lt;/p&gt;
&lt;p&gt;[jarkko: Replaced the first two paragraphs of text with an actual
 concurrency scenario.]&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-63823</guid>
    </item>
    <item>
      <title>GHSA-hhf9-cxvj-3mv7</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-hhf9-cxvj-3mv7</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;keys: Pin request_key_auth payload in instantiate paths&lt;/p&gt;
&lt;p&gt;A: request_key()       B: KEYCTL_INSTANTIATE_IOV
================       =========================&lt;/p&gt;
&lt;p&gt;create auth key
store rka in auth key
wait for helper
                       get auth key
                       load rka from auth key
                       copy user payload
                       sleep on #PF&lt;/p&gt;
&lt;p&gt;helper completed
detach and free rka
destroy auth key
                       wake up
                       use rka-&amp;gt;target_key
                       **USE-AFTER-FREE**&lt;/p&gt;
&lt;p&gt;Give request_key_auth payloads a refcount.  Take a payload reference while
authkey-&amp;gt;sem stabilizes the payload and revocation state.  Hold that
reference across the instantiate and reject paths.  Drop the auth key
owning reference from revoke and destroy.&lt;/p&gt;
&lt;p&gt;[jarkko: Replaced the first two paragraphs of text with an actual
 concurrency scenario.]&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;keys: Pin request_key_auth payload in instantiate paths&lt;/p&gt;
&lt;p&gt;A: request_key()       B: KEYCTL_INSTANTIATE_IOV
================       =========================&lt;/p&gt;
&lt;p&gt;create auth key
store rka in auth key
wait for helper
                       get auth key
                       load rka from auth key
                       copy user payload
                       sleep on #PF&lt;/p&gt;
&lt;p&gt;helper completed
detach and free rka
destroy auth key
                       wake up
                       use rka-&amp;gt;target_key
                       **USE-AFTER-FREE**&lt;/p&gt;
&lt;p&gt;Give request_key_auth payloads a refcount.  Take a payload reference while
authkey-&amp;gt;sem stabilizes the payload and revocation state.  Hold that
reference across the instantiate and reject paths.  Drop the auth key
owning reference from revoke and destroy.&lt;/p&gt;
&lt;p&gt;[jarkko: Replaced the first two paragraphs of text with an actual
 concurrency scenario.]&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-hhf9-cxvj-3mv7</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-63823 — keys: Pin request_key_auth payload in instantiate paths</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-63823</link>
      <description>msrc_CVE-2026-63823</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-63823</guid>
    </item>
    <item>
      <title>OESA-2026-3317 — kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-3317</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP4: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;drm/amdgpu: prevent immediate PASID reuse case&lt;/p&gt;
&lt;p&gt;PASID resue could cause interrupt issue when process
immediately runs into hw state left by previous
process exited with the same PASID, it&amp;amp;apos;s possible that
page faults are still pending in the IH ring buffer when
the process exits and frees up its PASID. To prevent the
case, it uses idr cyclic allocator same as kernel pid&amp;amp;apos;s.&lt;/p&gt;
&lt;p&gt;(cherry picked from commit 8f1de51f49be692de137c8525106e0fce2d1912d)(CVE-2026-31462)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;media: hackrf: fix to not free memory after the device is registered in hackrf_probe()&lt;/p&gt;
&lt;p&gt;In hackrf driver, the following race condition occurs:
```
		CPU0						CPU1
hackrf_probe()
  kzalloc(); // alloc hackrf_dev
  ....
  v4l2_device_register();
  ....
						fd = sys_open(&amp;amp;quot;/path/to/dev&amp;amp;quot;); // open hackrf fd
						....
  v4l2_device_unregister();
  ....
  kfree(); // free hackrf_dev
  ....
						sys_ioctl(fd, ...);
						  v4l2_ioctl();
						    video_is_registered() // UAF!!
						....
						sys_close(fd);
						  v4l2_release() // UAF!!
						    hackrf_video_release()
						      kfree(); // DFB!!
```&lt;/p&gt;
&lt;p&gt;When a V4L2 or video device is unregistered, the device node is removed so
new open() calls are blocked.&lt;/p&gt;
&lt;p&gt;However, file descriptors that are already open-and any in-flight I/O-do
not terminate i…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP4: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;drm/amdgpu: prevent immediate PASID reuse case&lt;/p&gt;
&lt;p&gt;PASID resue could cause interrupt issue when process
immediately runs into hw state left by previous
process exited with the same PASID, it&amp;amp;apos;s possible that
page faults are still pending in the IH ring buffer when
the process exits and frees up its PASID. To prevent the
case, it uses idr cyclic allocator same as kernel pid&amp;amp;apos;s.&lt;/p&gt;
&lt;p&gt;(cherry picked from commit 8f1de51f49be692de137c8525106e0fce2d1912d)(CVE-2026-31462)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;media: hackrf: fix to not free memory after the device is registered in hackrf_probe()&lt;/p&gt;
&lt;p&gt;In hackrf driver, the following race condition occurs:
```
		CPU0						CPU1
hackrf_probe()
  kzalloc(); // alloc hackrf_dev
  ....
  v4l2_device_register();
  ....
						fd = sys_open(&amp;amp;quot;/path/to/dev&amp;amp;quot;); // open hackrf fd
						....
  v4l2_device_unregister();
  ....
  kfree(); // free hackrf_dev
  ....
						sys_ioctl(fd, ...);
						  v4l2_ioctl();
						    video_is_registered() // UAF!!
						....
						sys_close(fd);
						  v4l2_release() // UAF!!
						    hackrf_video_release()
						      kfree(); // DFB!!
```&lt;/p&gt;
&lt;p&gt;When a V4L2 or video device is unregistered, the device node is removed so
new open() calls are blocked.&lt;/p&gt;
&lt;p&gt;However, file descriptors that are already open-and any in-flight I/O-do
not terminate i…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-3317</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:11339-1 — kernel-devel-7.1.4-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11339-1</link>
      <description>&lt;p&gt;kernel-devel-7.1.4-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;kernel-devel-7.1.4-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:11339-1</guid>
    </item>
    <item>
      <title>RHSA-2026:70402 — Red Hat Security Advisory: kernel security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:70402</link>
      <description>&lt;p&gt;kernel: Linux kernel Bluetooth: Denial of Service via race condition in hidp_session_thread kernel: Bluetooth: L2CAP: Fix potential user-after-free kernel: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg kernel: Bluetooth: btusb: revert use of devm_kzalloc in btusb kernel: Bluetooth: SMP: force responder MITM requirements before building the pairing response kernel: iommu/vt-d: Clear Present bit before tearing down PASID entry kernel: RDMA/rxe: Validate pad and ICRC before payload_size() in rxe_rcv kernel: RDMA/rxe: Reject unknown opcodes before ICRC processing kernel: Bluetooth: serialize accept_q access kernel: iommu/amd: Fix clone_alias() to use the original device&amp;#39;s devid kernel: dm cache policy smq: fix missing locks in invalidating cache blocks kernel: Bluetooth: RFCOMM: validate skb length in MCC handlers kernel: Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind() kernel: keys: Pin request_key_auth payload in instantiate paths kernel: Bluetooth: HIDP: fix missing length checks in hidp_input_report() kernel: Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp kernel: nvmet-tcp: check INIT_FAILED before nvmet_req_uninit in digest error path kernel: RDMA/rxe: Fix a use-after-free problem in rxe_mmap kernel: Linux kernel Bluetooth RFCOMM: Denial of Service via use-after-free in set_termios kernel: net/mlx5: Fix MCIA register buffer overflow on 32 dword reads&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;kernel: Linux kernel Bluetooth: Denial of Service via race condition in hidp_session_thread kernel: Bluetooth: L2CAP: Fix potential user-after-free kernel: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg kernel: Bluetooth: btusb: revert use of devm_kzalloc in btusb kernel: Bluetooth: SMP: force responder MITM requirements before building the pairing response kernel: iommu/vt-d: Clear Present bit before tearing down PASID entry kernel: RDMA/rxe: Validate pad and ICRC before payload_size() in rxe_rcv kernel: RDMA/rxe: Reject unknown opcodes before ICRC processing kernel: Bluetooth: serialize accept_q access kernel: iommu/amd: Fix clone_alias() to use the original device&amp;#39;s devid kernel: dm cache policy smq: fix missing locks in invalidating cache blocks kernel: Bluetooth: RFCOMM: validate skb length in MCC handlers kernel: Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind() kernel: keys: Pin request_key_auth payload in instantiate paths kernel: Bluetooth: HIDP: fix missing length checks in hidp_input_report() kernel: Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp kernel: nvmet-tcp: check INIT_FAILED before nvmet_req_uninit in digest error path kernel: RDMA/rxe: Fix a use-after-free problem in rxe_mmap kernel: Linux kernel Bluetooth RFCOMM: Denial of Service via use-after-free in set_termios kernel: net/mlx5: Fix MCIA register buffer overflow on 32 dword reads&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:70402</guid>
    </item>
    <item>
      <title>RLSA-2026:70402 — Important: kernel security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:70402</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:8: kernel&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg (CVE-2025-39964)&lt;/p&gt;
&lt;p&gt;* kernel: Linux kernel Bluetooth: Denial of Service via race condition in hidp_session_thread (CVE-2023-54120)&lt;/p&gt;
&lt;p&gt;* kernel: Bluetooth: L2CAP: Fix potential user-after-free (CVE-2023-54214)&lt;/p&gt;
&lt;p&gt;* kernel: Bluetooth: btusb: revert use of devm_kzalloc in btusb (CVE-2025-71082)&lt;/p&gt;
&lt;p&gt;* kernel: Bluetooth: SMP: force responder MITM requirements before building the pairing response (CVE-2026-43334)&lt;/p&gt;
&lt;p&gt;* kernel: iommu/vt-d: Clear Present bit before tearing down PASID entry (CVE-2026-45894)&lt;/p&gt;
&lt;p&gt;* kernel: RDMA/rxe: Validate pad and ICRC before payload_size() in rxe_rcv (CVE-2026-46043)&lt;/p&gt;
&lt;p&gt;* kernel: RDMA/rxe: Reject unknown opcodes before ICRC processing (CVE-2026-46133)&lt;/p&gt;
&lt;p&gt;* kernel: Bluetooth: serialize accept_q access (CVE-2026-52918)&lt;/p&gt;
&lt;p&gt;* kernel: dm cache policy smq: fix missing locks in invalidating cache blocks (CVE-2026-53062)&lt;/p&gt;
&lt;p&gt;* kernel: iommu/amd: Fix clone_alias() to use the original device&amp;#39;s devid (CVE-2026-53053)&lt;/p&gt;
&lt;p&gt;* kernel: Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind() (CVE-2026-53256)&lt;/p&gt;
&lt;p&gt;* kernel: Bluetooth: RFCOMM: validate skb length in MCC handlers (CVE-2026-53254)&lt;/p&gt;
&lt;p&gt;* kernel: keys: Pin request_key_auth payload in instantiate paths (CVE-2026-63823)&lt;/p&gt;
&lt;p&gt;* kernel: Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp (CVE-2026-63975)&lt;/p&gt;
&lt;p&gt;* kernel: Bluetooth: HIDP: fix missing length chec…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:8: kernel&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg (CVE-2025-39964)&lt;/p&gt;
&lt;p&gt;* kernel: Linux kernel Bluetooth: Denial of Service via race condition in hidp_session_thread (CVE-2023-54120)&lt;/p&gt;
&lt;p&gt;* kernel: Bluetooth: L2CAP: Fix potential user-after-free (CVE-2023-54214)&lt;/p&gt;
&lt;p&gt;* kernel: Bluetooth: btusb: revert use of devm_kzalloc in btusb (CVE-2025-71082)&lt;/p&gt;
&lt;p&gt;* kernel: Bluetooth: SMP: force responder MITM requirements before building the pairing response (CVE-2026-43334)&lt;/p&gt;
&lt;p&gt;* kernel: iommu/vt-d: Clear Present bit before tearing down PASID entry (CVE-2026-45894)&lt;/p&gt;
&lt;p&gt;* kernel: RDMA/rxe: Validate pad and ICRC before payload_size() in rxe_rcv (CVE-2026-46043)&lt;/p&gt;
&lt;p&gt;* kernel: RDMA/rxe: Reject unknown opcodes before ICRC processing (CVE-2026-46133)&lt;/p&gt;
&lt;p&gt;* kernel: Bluetooth: serialize accept_q access (CVE-2026-52918)&lt;/p&gt;
&lt;p&gt;* kernel: dm cache policy smq: fix missing locks in invalidating cache blocks (CVE-2026-53062)&lt;/p&gt;
&lt;p&gt;* kernel: iommu/amd: Fix clone_alias() to use the original device&amp;#39;s devid (CVE-2026-53053)&lt;/p&gt;
&lt;p&gt;* kernel: Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind() (CVE-2026-53256)&lt;/p&gt;
&lt;p&gt;* kernel: Bluetooth: RFCOMM: validate skb length in MCC handlers (CVE-2026-53254)&lt;/p&gt;
&lt;p&gt;* kernel: keys: Pin request_key_auth payload in instantiate paths (CVE-2026-63823)&lt;/p&gt;
&lt;p&gt;* kernel: Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp (CVE-2026-63975)&lt;/p&gt;
&lt;p&gt;* kernel: Bluetooth: HIDP: fix missing length chec…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:70402</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:23477-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:23477-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:23477-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-63823</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-63823</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux, Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe and 246 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: keys: Pin request_key_auth payload in instantiate paths A: request_key()       B: KEYCTL_INSTANTIATE_IOV ================       ========================= create auth key store rka in auth key wait for helper                        get auth key                        load rka from auth key                        copy user payload                        sleep on #PF helper completed detach and free rka destroy auth key                        wake up                        use rka-&amp;gt;target_key                        **USE-AFTER-FREE** Give request_key_auth payloads a refcount.  Take a payload reference while authkey-&amp;gt;sem stabilizes the payload and revocation state.  Hold that reference across the instantiate and reject paths.  Drop the auth key owning reference from revoke and destroy. [jarkko: Replaced the first two paragraphs of text with an actual  concurrency scenario.]&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux, Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe and 246 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: keys: Pin request_key_auth payload in instantiate paths A: request_key()       B: KEYCTL_INSTANTIATE_IOV ================       ========================= create auth key store rka in auth key wait for helper                        get auth key                        load rka from auth key                        copy user payload                        sleep on #PF helper completed detach and free rka destroy auth key                        wake up                        use rka-&amp;gt;target_key                        **USE-AFTER-FREE** Give request_key_auth payloads a refcount.  Take a payload reference while authkey-&amp;gt;sem stabilizes the payload and revocation state.  Hold that reference across the instantiate and reject paths.  Drop the auth key owning reference from revoke and destroy. [jarkko: Replaced the first two paragraphs of text with an actual  concurrency scenario.]&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-63823</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2403 — Linux Kernel: Mehrere Schwachstellen ermöglichen nicht spezifizierten Angriff</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2403</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen, möglicherweise Sicherheitsmaßnahmen zu umgehen, einen Denial-of-Service-Zustand herbeizuführen oder vertrauliche Informationen offenzulegen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen, möglicherweise Sicherheitsmaßnahmen zu umgehen, einen Denial-of-Service-Zustand herbeizuführen oder vertrauliche Informationen offenzulegen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2403</guid>
    </item>
  </channel>
</rss>
