<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 22:49:16 +0000</lastBuildDate>
    <item>
      <title>ALSA-2026:57251 — Important: kernel security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:57251</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: kernel, AlmaLinux:10: kernel-64k, AlmaLinux:10: kernel-64k-core, AlmaLinux:10: kernel-64k-debug, AlmaLinux:10: kernel-64k-debug-core, AlmaLinux:10: kernel-64k-debug-devel, AlmaLinux:10: kernel-64k-debug-devel-matched, AlmaLinux:10: kernel-64k-debug-modules, AlmaLinux:10: kernel-64k-debug-modules-core, AlmaLinux:10: kernel-64k-debug-modules-extra and 65 more&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: drm/amdkfd: Fix out-of-bounds write in kfd_event_page_set() (CVE-2026-43206)
  * kernel: drm/amdgpu: Refactor amdgpu_gem_va_ioctl for Handling Last Fence Update and Timeline Management v4 (CVE-2026-43237)
  * kernel: crypto: pcrypt - Fix handling of MAY_BACKLOG requests (CVE-2026-43493)
  * kernel: udf: fix partition descriptor append bookkeeping (CVE-2026-45991)
  * kernel: drm/amdkfd: Fix watch_id bounds checking in debug address watch v2 (CVE-2026-45878)
  * kernel: smb/client: fix out-of-bounds read in symlink_data() (CVE-2026-46185)
  * kernel: sched/psi: fix race between file release and pressure write (CVE-2026-52991)
  * kernel: drm/amdkfd: Fix buffer overflow in SDMA queue checkpoint/restore on GFX11 (CVE-2026-53143)
  * kernel: drm/amd/display: Clamp VBIOS HDMI retimer register count to array size (CVE-2026-53136)
  * kernel: drm/amd/display: Use krealloc_array() in dal_vector_reserve() (CVE-2026-53329)
  * kernel: drm/i915/gem: Fix phys BO pread/pwrite with offset (CVE-2026-53356)
  * kernel: drm/amdgpu: zero-initialize GART table on allocation (CVE-2026-53374)
  * kernel: drm/i915: Fix potential UAF in TTM object purge (CVE-2026-63884)
  * kernel: scsi: target: iscsi: Validate CHAP_R length before base64 decode (CVE-2026-63886)
  * kernel: memfd: deny writeable mappings when implying SEAL_WRITE (CVE-2026-63952)
  * kernel: scsi: target: iscsi:…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: kernel, AlmaLinux:10: kernel-64k, AlmaLinux:10: kernel-64k-core, AlmaLinux:10: kernel-64k-debug, AlmaLinux:10: kernel-64k-debug-core, AlmaLinux:10: kernel-64k-debug-devel, AlmaLinux:10: kernel-64k-debug-devel-matched, AlmaLinux:10: kernel-64k-debug-modules, AlmaLinux:10: kernel-64k-debug-modules-core, AlmaLinux:10: kernel-64k-debug-modules-extra and 65 more&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: drm/amdkfd: Fix out-of-bounds write in kfd_event_page_set() (CVE-2026-43206)
  * kernel: drm/amdgpu: Refactor amdgpu_gem_va_ioctl for Handling Last Fence Update and Timeline Management v4 (CVE-2026-43237)
  * kernel: crypto: pcrypt - Fix handling of MAY_BACKLOG requests (CVE-2026-43493)
  * kernel: udf: fix partition descriptor append bookkeeping (CVE-2026-45991)
  * kernel: drm/amdkfd: Fix watch_id bounds checking in debug address watch v2 (CVE-2026-45878)
  * kernel: smb/client: fix out-of-bounds read in symlink_data() (CVE-2026-46185)
  * kernel: sched/psi: fix race between file release and pressure write (CVE-2026-52991)
  * kernel: drm/amdkfd: Fix buffer overflow in SDMA queue checkpoint/restore on GFX11 (CVE-2026-53143)
  * kernel: drm/amd/display: Clamp VBIOS HDMI retimer register count to array size (CVE-2026-53136)
  * kernel: drm/amd/display: Use krealloc_array() in dal_vector_reserve() (CVE-2026-53329)
  * kernel: drm/i915/gem: Fix phys BO pread/pwrite with offset (CVE-2026-53356)
  * kernel: drm/amdgpu: zero-initialize GART table on allocation (CVE-2026-53374)
  * kernel: drm/i915: Fix potential UAF in TTM object purge (CVE-2026-63884)
  * kernel: scsi: target: iscsi: Validate CHAP_R length before base64 decode (CVE-2026-63886)
  * kernel: memfd: deny writeable mappings when implying SEAL_WRITE (CVE-2026-63952)
  * kernel: scsi: target: iscsi:…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:57251</guid>
    </item>
    <item>
      <title>bdu:2026-14399</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-14399</link>
      <description>bdu:2026-14399</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-14399</guid>
    </item>
    <item>
      <title>BELL-CVE-2026-63886</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-63886</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-63886</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0926 — De multiples vulnérabilités ont été découvertes dans le noyau Linux d'Ubuntu. Certaines d'entre elles permettent à un a…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0926</link>
      <description>certfr-2026-avi-0926</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0926</guid>
    </item>
    <item>
      <title>EUVD-2026-348282</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-348282</link>
      <description>EUVD-2026-348282</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-348282</guid>
    </item>
    <item>
      <title>fkie_cve-2026-63886</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-63886</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;scsi: target: iscsi: Validate CHAP_R length before base64 decode&lt;/p&gt;
&lt;p&gt;chap_server_compute_hash() allocates client_digest as
kzalloc(chap-&amp;gt;digest_size) and then, for BASE64-encoded responses,
passes chap_r directly to chap_base64_decode() without checking whether
the input length could produce more than digest_size bytes of output.&lt;/p&gt;
&lt;p&gt;chap_base64_decode() writes to the destination unconditionally as long
as there is input to consume. With MAX_RESPONSE_LENGTH set to 128 and
the &amp;#34;0b&amp;#34; prefix stripped by extract_param(), up to 127 base64 characters
can reach the decoder. 127 characters decode to 95 bytes. For SHA-256
(digest_size=32) this overflows client_digest by 63 bytes; for MD5
(digest_size=16) the overflow is 79 bytes.&lt;/p&gt;
&lt;p&gt;The length check at line 344 fires after the write has already happened.&lt;/p&gt;
&lt;p&gt;The HEX branch in the same switch statement already validates the length
up front. Apply the same approach to the BASE64 branch: strip trailing
base64 padding characters, then reject any input whose data length
exceeds DIV_ROUND_UP(digest_size * 4, 3) before calling the decoder.&lt;/p&gt;
&lt;p&gt;Stripping trailing &amp;#39;=&amp;#39; before the comparison handles both padded and
unpadded encodings. chap_base64_decode() already returns early on &amp;#39;=&amp;#39;,
so the full original string is still passed to the decoder unchanged.&lt;/p&gt;
&lt;p&gt;The mutual CHAP path decodes CHAP_C into initiatorchg_binhex, which is
kzalloc(CHAP_CHALLENGE_STR_LEN). extract_param() caps initiatorchg a…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;scsi: target: iscsi: Validate CHAP_R length before base64 decode&lt;/p&gt;
&lt;p&gt;chap_server_compute_hash() allocates client_digest as
kzalloc(chap-&amp;gt;digest_size) and then, for BASE64-encoded responses,
passes chap_r directly to chap_base64_decode() without checking whether
the input length could produce more than digest_size bytes of output.&lt;/p&gt;
&lt;p&gt;chap_base64_decode() writes to the destination unconditionally as long
as there is input to consume. With MAX_RESPONSE_LENGTH set to 128 and
the &amp;#34;0b&amp;#34; prefix stripped by extract_param(), up to 127 base64 characters
can reach the decoder. 127 characters decode to 95 bytes. For SHA-256
(digest_size=32) this overflows client_digest by 63 bytes; for MD5
(digest_size=16) the overflow is 79 bytes.&lt;/p&gt;
&lt;p&gt;The length check at line 344 fires after the write has already happened.&lt;/p&gt;
&lt;p&gt;The HEX branch in the same switch statement already validates the length
up front. Apply the same approach to the BASE64 branch: strip trailing
base64 padding characters, then reject any input whose data length
exceeds DIV_ROUND_UP(digest_size * 4, 3) before calling the decoder.&lt;/p&gt;
&lt;p&gt;Stripping trailing &amp;#39;=&amp;#39; before the comparison handles both padded and
unpadded encodings. chap_base64_decode() already returns early on &amp;#39;=&amp;#39;,
so the full original string is still passed to the decoder unchanged.&lt;/p&gt;
&lt;p&gt;The mutual CHAP path decodes CHAP_C into initiatorchg_binhex, which is
kzalloc(CHAP_CHALLENGE_STR_LEN). extract_param() caps initiatorchg a…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-63886</guid>
    </item>
    <item>
      <title>GHSA-f9cg-2c9v-xhmh</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-f9cg-2c9v-xhmh</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;scsi: target: iscsi: Validate CHAP_R length before base64 decode&lt;/p&gt;
&lt;p&gt;chap_server_compute_hash() allocates client_digest as
kzalloc(chap-&amp;gt;digest_size) and then, for BASE64-encoded responses,
passes chap_r directly to chap_base64_decode() without checking whether
the input length could produce more than digest_size bytes of output.&lt;/p&gt;
&lt;p&gt;chap_base64_decode() writes to the destination unconditionally as long
as there is input to consume. With MAX_RESPONSE_LENGTH set to 128 and
the &amp;#34;0b&amp;#34; prefix stripped by extract_param(), up to 127 base64 characters
can reach the decoder. 127 characters decode to 95 bytes. For SHA-256
(digest_size=32) this overflows client_digest by 63 bytes; for MD5
(digest_size=16) the overflow is 79 bytes.&lt;/p&gt;
&lt;p&gt;The length check at line 344 fires after the write has already happened.&lt;/p&gt;
&lt;p&gt;The HEX branch in the same switch statement already validates the length
up front. Apply the same approach to the BASE64 branch: strip trailing
base64 padding characters, then reject any input whose data length
exceeds DIV_ROUND_UP(digest_size * 4, 3) before calling the decoder.&lt;/p&gt;
&lt;p&gt;Stripping trailing &amp;#39;=&amp;#39; before the comparison handles both padded and
unpadded encodings. chap_base64_decode() already returns early on &amp;#39;=&amp;#39;,
so the full original string is still passed to the decoder unchanged.&lt;/p&gt;
&lt;p&gt;The mutual CHAP path decodes CHAP_C into initiatorchg_binhex, which is
kzalloc(CHAP_CHALLENGE_STR_LEN). extract_param() caps initiatorchg a…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;scsi: target: iscsi: Validate CHAP_R length before base64 decode&lt;/p&gt;
&lt;p&gt;chap_server_compute_hash() allocates client_digest as
kzalloc(chap-&amp;gt;digest_size) and then, for BASE64-encoded responses,
passes chap_r directly to chap_base64_decode() without checking whether
the input length could produce more than digest_size bytes of output.&lt;/p&gt;
&lt;p&gt;chap_base64_decode() writes to the destination unconditionally as long
as there is input to consume. With MAX_RESPONSE_LENGTH set to 128 and
the &amp;#34;0b&amp;#34; prefix stripped by extract_param(), up to 127 base64 characters
can reach the decoder. 127 characters decode to 95 bytes. For SHA-256
(digest_size=32) this overflows client_digest by 63 bytes; for MD5
(digest_size=16) the overflow is 79 bytes.&lt;/p&gt;
&lt;p&gt;The length check at line 344 fires after the write has already happened.&lt;/p&gt;
&lt;p&gt;The HEX branch in the same switch statement already validates the length
up front. Apply the same approach to the BASE64 branch: strip trailing
base64 padding characters, then reject any input whose data length
exceeds DIV_ROUND_UP(digest_size * 4, 3) before calling the decoder.&lt;/p&gt;
&lt;p&gt;Stripping trailing &amp;#39;=&amp;#39; before the comparison handles both padded and
unpadded encodings. chap_base64_decode() already returns early on &amp;#39;=&amp;#39;,
so the full original string is still passed to the decoder unchanged.&lt;/p&gt;
&lt;p&gt;The mutual CHAP path decodes CHAP_C into initiatorchg_binhex, which is
kzalloc(CHAP_CHALLENGE_STR_LEN). extract_param() caps initiatorchg a…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-f9cg-2c9v-xhmh</guid>
    </item>
    <item>
      <title>OESA-2026-3704 — kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-3704</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP3: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;net: hns3: add VLAN id validation before using&lt;/p&gt;
&lt;p&gt;Currently, the VLAN id may be used without validation when
receive a VLAN configuration mailbox from VF. The length of
vlan_del_fail_bmap is BITS_TO_LONGS(VLAN_N_VID). It may cause
out-of-bounds memory access once the VLAN id is bigger than
or equal to VLAN_N_VID.&lt;/p&gt;
&lt;p&gt;Therefore, VLAN id needs to be checked to ensure it is within
the range of VLAN_N_VID.(CVE-2025-71112)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;ext4: fix string copying in parse_apply_sb_mount_options()&lt;/p&gt;
&lt;p&gt;strscpy_pad() can&amp;amp;apos;t be used to copy a non-NUL-term string into a NUL-term
string of possibly bigger size.  Commit 0efc5990bca5 (&amp;amp;quot;string.h: Introduce
memtostr() and memtostr_pad()&amp;amp;quot;) provides additional information in that
regard.  So if this happens, the following warning is observed:&lt;/p&gt;
&lt;p&gt;strnlen: detected buffer overflow: 65 byte read of buffer size 64
WARNING: CPU: 0 PID: 28655 at lib/string_helpers.c:1032 __fortify_report+0x96/0xc0 lib/string_helpers.c:1032
Modules linked in:
CPU: 0 UID: 0 PID: 28655 Comm: syz-executor.3 Not tainted 6.12.54-syzkaller-00144-g5f0270f1ba00 #0
Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
RIP: 0010:__fortify_report+0x96/0xc0 lib/string_helpers.c:1032
Call Trace:
 &amp;amp;lt;TASK&amp;amp;gt;
 __fortify_panic+0x1f/0x30 lib/s…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP3: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;net: hns3: add VLAN id validation before using&lt;/p&gt;
&lt;p&gt;Currently, the VLAN id may be used without validation when
receive a VLAN configuration mailbox from VF. The length of
vlan_del_fail_bmap is BITS_TO_LONGS(VLAN_N_VID). It may cause
out-of-bounds memory access once the VLAN id is bigger than
or equal to VLAN_N_VID.&lt;/p&gt;
&lt;p&gt;Therefore, VLAN id needs to be checked to ensure it is within
the range of VLAN_N_VID.(CVE-2025-71112)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;ext4: fix string copying in parse_apply_sb_mount_options()&lt;/p&gt;
&lt;p&gt;strscpy_pad() can&amp;amp;apos;t be used to copy a non-NUL-term string into a NUL-term
string of possibly bigger size.  Commit 0efc5990bca5 (&amp;amp;quot;string.h: Introduce
memtostr() and memtostr_pad()&amp;amp;quot;) provides additional information in that
regard.  So if this happens, the following warning is observed:&lt;/p&gt;
&lt;p&gt;strnlen: detected buffer overflow: 65 byte read of buffer size 64
WARNING: CPU: 0 PID: 28655 at lib/string_helpers.c:1032 __fortify_report+0x96/0xc0 lib/string_helpers.c:1032
Modules linked in:
CPU: 0 UID: 0 PID: 28655 Comm: syz-executor.3 Not tainted 6.12.54-syzkaller-00144-g5f0270f1ba00 #0
Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
RIP: 0010:__fortify_report+0x96/0xc0 lib/string_helpers.c:1032
Call Trace:
 &amp;amp;lt;TASK&amp;amp;gt;
 __fortify_panic+0x1f/0x30 lib/s…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-3704</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:21555-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:21555-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:21555-1</guid>
    </item>
    <item>
      <title>RHSA-2026:59737 — Red Hat Security Advisory: kernel-rt security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:59737</link>
      <description>&lt;p&gt;kernel: sctp: purge outqueue on stale COOKIE-ECHO handling kernel: scsi: target: iscsi: Validate CHAP_R length before base64 decode kernel: netfilter: conntrack: tcp: do not force CLOSE on invalid-seq RST without direction check kernel: netfilter: ipset: fix race between dump and ip_set_list resize kernel: i2c: stub: Reject I2C block transfers with invalid length kernel: Input: synaptics-rmi4 - bound the F30 keymap to the GPIO/LED count kernel: Input: synaptics-rmi4 - bound the F3A keymap to the GPIO count kernel: nvmet: fix pre-auth out-of-bounds heap read in Discovery Get Log Page&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;kernel: sctp: purge outqueue on stale COOKIE-ECHO handling kernel: scsi: target: iscsi: Validate CHAP_R length before base64 decode kernel: netfilter: conntrack: tcp: do not force CLOSE on invalid-seq RST without direction check kernel: netfilter: ipset: fix race between dump and ip_set_list resize kernel: i2c: stub: Reject I2C block transfers with invalid length kernel: Input: synaptics-rmi4 - bound the F30 keymap to the GPIO/LED count kernel: Input: synaptics-rmi4 - bound the F3A keymap to the GPIO count kernel: nvmet: fix pre-auth out-of-bounds heap read in Discovery Get Log Page&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:59737</guid>
    </item>
    <item>
      <title>RLSA-2026:57251 — Important: kernel security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:57251</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: kernel&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: drm/amdkfd: Fix out-of-bounds write in kfd_event_page_set() (CVE-2026-43206)&lt;/p&gt;
&lt;p&gt;* kernel: drm/amdgpu: Refactor amdgpu_gem_va_ioctl for Handling Last Fence Update and Timeline Management v4 (CVE-2026-43237)&lt;/p&gt;
&lt;p&gt;* kernel: crypto: pcrypt - Fix handling of MAY_BACKLOG requests (CVE-2026-43493)&lt;/p&gt;
&lt;p&gt;* kernel: udf: fix partition descriptor append bookkeeping (CVE-2026-45991)&lt;/p&gt;
&lt;p&gt;* kernel: drm/amdkfd: Fix watch_id bounds checking in debug address watch v2 (CVE-2026-45878)&lt;/p&gt;
&lt;p&gt;* kernel: smb/client: fix out-of-bounds read in symlink_data() (CVE-2026-46185)&lt;/p&gt;
&lt;p&gt;* kernel: sched/psi: fix race between file release and pressure write (CVE-2026-52991)&lt;/p&gt;
&lt;p&gt;* kernel: drm/amdkfd: Fix buffer overflow in SDMA queue checkpoint/restore on GFX11 (CVE-2026-53143)&lt;/p&gt;
&lt;p&gt;* kernel: drm/amd/display: Clamp VBIOS HDMI retimer register count to array size (CVE-2026-53136)&lt;/p&gt;
&lt;p&gt;* kernel: drm/amd/display: Use krealloc_array() in dal_vector_reserve() (CVE-2026-53329)&lt;/p&gt;
&lt;p&gt;* kernel: drm/i915/gem: Fix phys BO pread/pwrite with offset (CVE-2026-53356)&lt;/p&gt;
&lt;p&gt;* kernel: drm/amdgpu: zero-initialize GART table on allocation (CVE-2026-53374)&lt;/p&gt;
&lt;p&gt;* kernel: drm/i915: Fix potential UAF in TTM object purge (CVE-2026-63884)&lt;/p&gt;
&lt;p&gt;* kernel: scsi: target: iscsi: Validate CHAP_R length before base64 decode (CVE-2026-63886)&lt;/p&gt;
&lt;p&gt;* kernel: memfd: deny writeable mappings when implying SEAL_WRITE (CVE-2026-63952)&lt;/p&gt;
&lt;p&gt;* kernel: scsi: target: iscsi: Fix CRC overread and…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: kernel&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: drm/amdkfd: Fix out-of-bounds write in kfd_event_page_set() (CVE-2026-43206)&lt;/p&gt;
&lt;p&gt;* kernel: drm/amdgpu: Refactor amdgpu_gem_va_ioctl for Handling Last Fence Update and Timeline Management v4 (CVE-2026-43237)&lt;/p&gt;
&lt;p&gt;* kernel: crypto: pcrypt - Fix handling of MAY_BACKLOG requests (CVE-2026-43493)&lt;/p&gt;
&lt;p&gt;* kernel: udf: fix partition descriptor append bookkeeping (CVE-2026-45991)&lt;/p&gt;
&lt;p&gt;* kernel: drm/amdkfd: Fix watch_id bounds checking in debug address watch v2 (CVE-2026-45878)&lt;/p&gt;
&lt;p&gt;* kernel: smb/client: fix out-of-bounds read in symlink_data() (CVE-2026-46185)&lt;/p&gt;
&lt;p&gt;* kernel: sched/psi: fix race between file release and pressure write (CVE-2026-52991)&lt;/p&gt;
&lt;p&gt;* kernel: drm/amdkfd: Fix buffer overflow in SDMA queue checkpoint/restore on GFX11 (CVE-2026-53143)&lt;/p&gt;
&lt;p&gt;* kernel: drm/amd/display: Clamp VBIOS HDMI retimer register count to array size (CVE-2026-53136)&lt;/p&gt;
&lt;p&gt;* kernel: drm/amd/display: Use krealloc_array() in dal_vector_reserve() (CVE-2026-53329)&lt;/p&gt;
&lt;p&gt;* kernel: drm/i915/gem: Fix phys BO pread/pwrite with offset (CVE-2026-53356)&lt;/p&gt;
&lt;p&gt;* kernel: drm/amdgpu: zero-initialize GART table on allocation (CVE-2026-53374)&lt;/p&gt;
&lt;p&gt;* kernel: drm/i915: Fix potential UAF in TTM object purge (CVE-2026-63884)&lt;/p&gt;
&lt;p&gt;* kernel: scsi: target: iscsi: Validate CHAP_R length before base64 decode (CVE-2026-63886)&lt;/p&gt;
&lt;p&gt;* kernel: memfd: deny writeable mappings when implying SEAL_WRITE (CVE-2026-63952)&lt;/p&gt;
&lt;p&gt;* kernel: scsi: target: iscsi: Fix CRC overread and…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:57251</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:23066-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:23066-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:23066-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-63886</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-63886</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 153 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: scsi: target: iscsi: Validate CHAP_R length before base64 decode chap_server_compute_hash() allocates client_digest as kzalloc(chap-&amp;gt;digest_size) and then, for BASE64-encoded responses, passes chap_r directly to chap_base64_decode() without checking whether the input length could produce more than digest_size bytes of output. chap_base64_decode() writes to the destination unconditionally as long as there is input to consume. With MAX_RESPONSE_LENGTH set to 128 and the &amp;#34;0b&amp;#34; prefix stripped by extract_param(), up to 127 base64 characters can reach the decoder. 127 characters decode to 95 bytes. For SHA-256 (digest_size=32) this overflows client_digest by 63 bytes; for MD5 (digest_size=16) the overflow is 79 bytes. The length check at line 344 fires after the write has already happened. The HEX branch in the same switch statement already validates the length up front. Apply the same approach to the BASE64 branch: strip trailing base64 padding characters, then reject any input whose data length exceeds DIV_ROUND_UP(digest_size * 4, 3) before calling the decoder. Stripping trailing &amp;#39;=&amp;#39; before the comparison handles both padded and unpadded encodings. chap_base64_decode() already returns early on &amp;#39;=&amp;#39;, so the full original string is still passed to the decoder unchanged. The mutual CHAP path decodes CHAP_C into initiatorchg_binhex, which is kzalloc(CHAP_CHALLENGE_STR_LEN). extract_param() caps initiatorchg at CHAP_…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 153 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: scsi: target: iscsi: Validate CHAP_R length before base64 decode chap_server_compute_hash() allocates client_digest as kzalloc(chap-&amp;gt;digest_size) and then, for BASE64-encoded responses, passes chap_r directly to chap_base64_decode() without checking whether the input length could produce more than digest_size bytes of output. chap_base64_decode() writes to the destination unconditionally as long as there is input to consume. With MAX_RESPONSE_LENGTH set to 128 and the &amp;#34;0b&amp;#34; prefix stripped by extract_param(), up to 127 base64 characters can reach the decoder. 127 characters decode to 95 bytes. For SHA-256 (digest_size=32) this overflows client_digest by 63 bytes; for MD5 (digest_size=16) the overflow is 79 bytes. The length check at line 344 fires after the write has already happened. The HEX branch in the same switch statement already validates the length up front. Apply the same approach to the BASE64 branch: strip trailing base64 padding characters, then reject any input whose data length exceeds DIV_ROUND_UP(digest_size * 4, 3) before calling the decoder. Stripping trailing &amp;#39;=&amp;#39; before the comparison handles both padded and unpadded encodings. chap_base64_decode() already returns early on &amp;#39;=&amp;#39;, so the full original string is still passed to the decoder unchanged. The mutual CHAP path decodes CHAP_C into initiatorchg_binhex, which is kzalloc(CHAP_CHALLENGE_STR_LEN). extract_param() caps initiatorchg at CHAP_…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-63886</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2403 — Linux Kernel: Mehrere Schwachstellen ermöglichen nicht spezifizierten Angriff</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2403</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen, möglicherweise Sicherheitsmaßnahmen zu umgehen, einen Denial-of-Service-Zustand herbeizuführen oder vertrauliche Informationen offenzulegen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen, möglicherweise Sicherheitsmaßnahmen zu umgehen, einen Denial-of-Service-Zustand herbeizuführen oder vertrauliche Informationen offenzulegen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2403</guid>
    </item>
  </channel>
</rss>
