<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 18:37:46 +0000</lastBuildDate>
    <item>
      <title>ALSA-2026:71700 — Important: kernel security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:71700</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: kernel, AlmaLinux:9: kernel-64k, AlmaLinux:9: kernel-64k-core, AlmaLinux:9: kernel-64k-debug, AlmaLinux:9: kernel-64k-debug-core, AlmaLinux:9: kernel-64k-debug-devel, AlmaLinux:9: kernel-64k-debug-devel-matched, AlmaLinux:9: kernel-64k-debug-modules, AlmaLinux:9: kernel-64k-debug-modules-core, AlmaLinux:9: kernel-64k-debug-modules-extra and 64 more&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: fbcon: Set fb_display[i]-&amp;gt;mode to NULL when the mode is released (CVE-2025-40323)
  * kernel: smb: smbdirect: introduce smbdirect_socket.recv_io.credits.available (CVE-2026-31539)
  * kernel: drm/amdgpu/vcn3: Prevent OOB reads when parsing dec msg (CVE-2026-46230)
  * kernel: drm/amdgpu/vcn4: Prevent OOB reads when parsing IB (CVE-2026-46204)
  * kernel: drm/amdgpu/vcn4: Prevent OOB reads when parsing dec msg (CVE-2026-46199)
  * kernel: drm/amdgpu/userq: fix access to stale wptr mapping (CVE-2026-46311)
  * kernel: netfilter: nf_queue: hold bridge skb-&amp;gt;dev while queued (CVE-2026-52912)
  * kernel: accel/ivpu: Add buffer overflow check in MS get_info_ioctl (CVE-2026-53203)
  * kernel: drm/xe/eustall: Fix drm_dev_put called before stream disable in close (CVE-2026-53290)
  * kernel: drm/virtio: use uninterruptible resv lock for plane updates (CVE-2026-64098)
  * kernel: Linux kernel: PPPoE memory corruption via stale pointer (CVE-2026-68121)
  * kernel: drm/amdgpu/vce: fix integer overflow in image size (CVE-2026-68108)
  * kernel: drm/amdkfd: fix 32-bit overflow in CWSR total size calculation (CVE-2026-68257)
  * kernel: drm/xe/rtp: Add RING_FORCE_TO_NONPRIV_DENY to OA whitelists (CVE-2026-68267)
  * kernel: drm/xe: Hold a dma-buf reference for imported BOs (CVE-2026-68266)
  * kernel: drm/amdgpu: Fix context pstate override handling (CVE-2026-68273)
  *…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: kernel, AlmaLinux:9: kernel-64k, AlmaLinux:9: kernel-64k-core, AlmaLinux:9: kernel-64k-debug, AlmaLinux:9: kernel-64k-debug-core, AlmaLinux:9: kernel-64k-debug-devel, AlmaLinux:9: kernel-64k-debug-devel-matched, AlmaLinux:9: kernel-64k-debug-modules, AlmaLinux:9: kernel-64k-debug-modules-core, AlmaLinux:9: kernel-64k-debug-modules-extra and 64 more&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: fbcon: Set fb_display[i]-&amp;gt;mode to NULL when the mode is released (CVE-2025-40323)
  * kernel: smb: smbdirect: introduce smbdirect_socket.recv_io.credits.available (CVE-2026-31539)
  * kernel: drm/amdgpu/vcn3: Prevent OOB reads when parsing dec msg (CVE-2026-46230)
  * kernel: drm/amdgpu/vcn4: Prevent OOB reads when parsing IB (CVE-2026-46204)
  * kernel: drm/amdgpu/vcn4: Prevent OOB reads when parsing dec msg (CVE-2026-46199)
  * kernel: drm/amdgpu/userq: fix access to stale wptr mapping (CVE-2026-46311)
  * kernel: netfilter: nf_queue: hold bridge skb-&amp;gt;dev while queued (CVE-2026-52912)
  * kernel: accel/ivpu: Add buffer overflow check in MS get_info_ioctl (CVE-2026-53203)
  * kernel: drm/xe/eustall: Fix drm_dev_put called before stream disable in close (CVE-2026-53290)
  * kernel: drm/virtio: use uninterruptible resv lock for plane updates (CVE-2026-64098)
  * kernel: Linux kernel: PPPoE memory corruption via stale pointer (CVE-2026-68121)
  * kernel: drm/amdgpu/vce: fix integer overflow in image size (CVE-2026-68108)
  * kernel: drm/amdkfd: fix 32-bit overflow in CWSR total size calculation (CVE-2026-68257)
  * kernel: drm/xe/rtp: Add RING_FORCE_TO_NONPRIV_DENY to OA whitelists (CVE-2026-68267)
  * kernel: drm/xe: Hold a dma-buf reference for imported BOs (CVE-2026-68266)
  * kernel: drm/amdgpu: Fix context pstate override handling (CVE-2026-68273)
  *…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:71700</guid>
    </item>
    <item>
      <title>BELL-CVE-2026-64098</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-64098</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-64098</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0926 — De multiples vulnérabilités ont été découvertes dans le noyau Linux d'Ubuntu. Certaines d'entre elles permettent à un a…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0926</link>
      <description>certfr-2026-avi-0926</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0926</guid>
    </item>
    <item>
      <title>EUVD-2026-348401</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-348401</link>
      <description>EUVD-2026-348401</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-348401</guid>
    </item>
    <item>
      <title>fkie_cve-2026-64098</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-64098</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;drm/virtio: use uninterruptible resv lock for plane updates&lt;/p&gt;
&lt;p&gt;virtio_gpu_cursor_plane_update() and virtio_gpu_resource_flush() lock
the framebuffer BO&amp;#39;s dma_resv via virtio_gpu_array_lock_resv() and
ignore its return value. The function can fail with -EINTR from
dma_resv_lock_interruptible() (signal during lock wait) or with
-ENOMEM from dma_resv_reserve_fences() (fence slot allocation),
leaving the resv lock not held. The queue path then walks the object
array and calls dma_resv_add_fence(), which requires the lock held;
with lockdep enabled this trips dma_resv_assert_held():&lt;/p&gt;
&lt;p&gt;WARNING: drivers/dma-buf/dma-resv.c:296 at dma_resv_add_fence+0x71e/0x840
  Call Trace:
   virtio_gpu_array_add_fence
   virtio_gpu_queue_ctrl_sgs
   virtio_gpu_queue_fenced_ctrl_buffer
   virtio_gpu_cursor_plane_update
   drm_atomic_helper_commit_planes
   drm_atomic_helper_commit_tail
   commit_tail
   drm_atomic_helper_commit
   drm_atomic_commit
   drm_atomic_helper_update_plane
   __setplane_atomic
   drm_mode_cursor_universal
   drm_mode_cursor_common
   drm_mode_cursor_ioctl
   drm_ioctl
   __x64_sys_ioctl&lt;/p&gt;
&lt;p&gt;Beyond the WARN, mutating the dma_resv fence list without the lock
races with concurrent readers/writers and can corrupt the list.&lt;/p&gt;
&lt;p&gt;Both call sites run inside the .atomic_update plane callback, which
DRM atomic helpers do not allow to fail (by the time it runs, the
commit has been signed off to userspace and there is no cl…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;drm/virtio: use uninterruptible resv lock for plane updates&lt;/p&gt;
&lt;p&gt;virtio_gpu_cursor_plane_update() and virtio_gpu_resource_flush() lock
the framebuffer BO&amp;#39;s dma_resv via virtio_gpu_array_lock_resv() and
ignore its return value. The function can fail with -EINTR from
dma_resv_lock_interruptible() (signal during lock wait) or with
-ENOMEM from dma_resv_reserve_fences() (fence slot allocation),
leaving the resv lock not held. The queue path then walks the object
array and calls dma_resv_add_fence(), which requires the lock held;
with lockdep enabled this trips dma_resv_assert_held():&lt;/p&gt;
&lt;p&gt;WARNING: drivers/dma-buf/dma-resv.c:296 at dma_resv_add_fence+0x71e/0x840
  Call Trace:
   virtio_gpu_array_add_fence
   virtio_gpu_queue_ctrl_sgs
   virtio_gpu_queue_fenced_ctrl_buffer
   virtio_gpu_cursor_plane_update
   drm_atomic_helper_commit_planes
   drm_atomic_helper_commit_tail
   commit_tail
   drm_atomic_helper_commit
   drm_atomic_commit
   drm_atomic_helper_update_plane
   __setplane_atomic
   drm_mode_cursor_universal
   drm_mode_cursor_common
   drm_mode_cursor_ioctl
   drm_ioctl
   __x64_sys_ioctl&lt;/p&gt;
&lt;p&gt;Beyond the WARN, mutating the dma_resv fence list without the lock
races with concurrent readers/writers and can corrupt the list.&lt;/p&gt;
&lt;p&gt;Both call sites run inside the .atomic_update plane callback, which
DRM atomic helpers do not allow to fail (by the time it runs, the
commit has been signed off to userspace and there is no cl…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-64098</guid>
    </item>
    <item>
      <title>GHSA-9phf-m556-w4xg</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-9phf-m556-w4xg</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;drm/virtio: use uninterruptible resv lock for plane updates&lt;/p&gt;
&lt;p&gt;virtio_gpu_cursor_plane_update() and virtio_gpu_resource_flush() lock
the framebuffer BO&amp;#39;s dma_resv via virtio_gpu_array_lock_resv() and
ignore its return value. The function can fail with -EINTR from
dma_resv_lock_interruptible() (signal during lock wait) or with
-ENOMEM from dma_resv_reserve_fences() (fence slot allocation),
leaving the resv lock not held. The queue path then walks the object
array and calls dma_resv_add_fence(), which requires the lock held;
with lockdep enabled this trips dma_resv_assert_held():&lt;/p&gt;
&lt;p&gt;WARNING: drivers/dma-buf/dma-resv.c:296 at dma_resv_add_fence+0x71e/0x840
  Call Trace:
   virtio_gpu_array_add_fence
   virtio_gpu_queue_ctrl_sgs
   virtio_gpu_queue_fenced_ctrl_buffer
   virtio_gpu_cursor_plane_update
   drm_atomic_helper_commit_planes
   drm_atomic_helper_commit_tail
   commit_tail
   drm_atomic_helper_commit
   drm_atomic_commit
   drm_atomic_helper_update_plane
   __setplane_atomic
   drm_mode_cursor_universal
   drm_mode_cursor_common
   drm_mode_cursor_ioctl
   drm_ioctl
   __x64_sys_ioctl&lt;/p&gt;
&lt;p&gt;Beyond the WARN, mutating the dma_resv fence list without the lock
races with concurrent readers/writers and can corrupt the list.&lt;/p&gt;
&lt;p&gt;Both call sites run inside the .atomic_update plane callback, which
DRM atomic helpers do not allow to fail (by the time it runs, the
commit has been signed off to userspace and there is no cl…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;drm/virtio: use uninterruptible resv lock for plane updates&lt;/p&gt;
&lt;p&gt;virtio_gpu_cursor_plane_update() and virtio_gpu_resource_flush() lock
the framebuffer BO&amp;#39;s dma_resv via virtio_gpu_array_lock_resv() and
ignore its return value. The function can fail with -EINTR from
dma_resv_lock_interruptible() (signal during lock wait) or with
-ENOMEM from dma_resv_reserve_fences() (fence slot allocation),
leaving the resv lock not held. The queue path then walks the object
array and calls dma_resv_add_fence(), which requires the lock held;
with lockdep enabled this trips dma_resv_assert_held():&lt;/p&gt;
&lt;p&gt;WARNING: drivers/dma-buf/dma-resv.c:296 at dma_resv_add_fence+0x71e/0x840
  Call Trace:
   virtio_gpu_array_add_fence
   virtio_gpu_queue_ctrl_sgs
   virtio_gpu_queue_fenced_ctrl_buffer
   virtio_gpu_cursor_plane_update
   drm_atomic_helper_commit_planes
   drm_atomic_helper_commit_tail
   commit_tail
   drm_atomic_helper_commit
   drm_atomic_commit
   drm_atomic_helper_update_plane
   __setplane_atomic
   drm_mode_cursor_universal
   drm_mode_cursor_common
   drm_mode_cursor_ioctl
   drm_ioctl
   __x64_sys_ioctl&lt;/p&gt;
&lt;p&gt;Beyond the WARN, mutating the dma_resv fence list without the lock
races with concurrent readers/writers and can corrupt the list.&lt;/p&gt;
&lt;p&gt;Both call sites run inside the .atomic_update plane callback, which
DRM atomic helpers do not allow to fail (by the time it runs, the
commit has been signed off to userspace and there is no cl…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-9phf-m556-w4xg</guid>
    </item>
    <item>
      <title>OESA-2026-3704 — kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-3704</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP3: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;net: hns3: add VLAN id validation before using&lt;/p&gt;
&lt;p&gt;Currently, the VLAN id may be used without validation when
receive a VLAN configuration mailbox from VF. The length of
vlan_del_fail_bmap is BITS_TO_LONGS(VLAN_N_VID). It may cause
out-of-bounds memory access once the VLAN id is bigger than
or equal to VLAN_N_VID.&lt;/p&gt;
&lt;p&gt;Therefore, VLAN id needs to be checked to ensure it is within
the range of VLAN_N_VID.(CVE-2025-71112)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;ext4: fix string copying in parse_apply_sb_mount_options()&lt;/p&gt;
&lt;p&gt;strscpy_pad() can&amp;amp;apos;t be used to copy a non-NUL-term string into a NUL-term
string of possibly bigger size.  Commit 0efc5990bca5 (&amp;amp;quot;string.h: Introduce
memtostr() and memtostr_pad()&amp;amp;quot;) provides additional information in that
regard.  So if this happens, the following warning is observed:&lt;/p&gt;
&lt;p&gt;strnlen: detected buffer overflow: 65 byte read of buffer size 64
WARNING: CPU: 0 PID: 28655 at lib/string_helpers.c:1032 __fortify_report+0x96/0xc0 lib/string_helpers.c:1032
Modules linked in:
CPU: 0 UID: 0 PID: 28655 Comm: syz-executor.3 Not tainted 6.12.54-syzkaller-00144-g5f0270f1ba00 #0
Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
RIP: 0010:__fortify_report+0x96/0xc0 lib/string_helpers.c:1032
Call Trace:
 &amp;amp;lt;TASK&amp;amp;gt;
 __fortify_panic+0x1f/0x30 lib/s…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP3: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;net: hns3: add VLAN id validation before using&lt;/p&gt;
&lt;p&gt;Currently, the VLAN id may be used without validation when
receive a VLAN configuration mailbox from VF. The length of
vlan_del_fail_bmap is BITS_TO_LONGS(VLAN_N_VID). It may cause
out-of-bounds memory access once the VLAN id is bigger than
or equal to VLAN_N_VID.&lt;/p&gt;
&lt;p&gt;Therefore, VLAN id needs to be checked to ensure it is within
the range of VLAN_N_VID.(CVE-2025-71112)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;ext4: fix string copying in parse_apply_sb_mount_options()&lt;/p&gt;
&lt;p&gt;strscpy_pad() can&amp;amp;apos;t be used to copy a non-NUL-term string into a NUL-term
string of possibly bigger size.  Commit 0efc5990bca5 (&amp;amp;quot;string.h: Introduce
memtostr() and memtostr_pad()&amp;amp;quot;) provides additional information in that
regard.  So if this happens, the following warning is observed:&lt;/p&gt;
&lt;p&gt;strnlen: detected buffer overflow: 65 byte read of buffer size 64
WARNING: CPU: 0 PID: 28655 at lib/string_helpers.c:1032 __fortify_report+0x96/0xc0 lib/string_helpers.c:1032
Modules linked in:
CPU: 0 UID: 0 PID: 28655 Comm: syz-executor.3 Not tainted 6.12.54-syzkaller-00144-g5f0270f1ba00 #0
Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
RIP: 0010:__fortify_report+0x96/0xc0 lib/string_helpers.c:1032
Call Trace:
 &amp;amp;lt;TASK&amp;amp;gt;
 __fortify_panic+0x1f/0x30 lib/s…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-3704</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:21910-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:21910-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:21910-1</guid>
    </item>
    <item>
      <title>RHSA-2026:71602 — Red Hat Security Advisory: kernel security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:71602</link>
      <description>&lt;p&gt;kernel: fbcon: Set fb_display[i]-&amp;gt;mode to NULL when the mode is released kernel: libceph: fix potential use-after-free in have_mon_and_osd_map() kernel: libceph: make decode_pool() more resilient against corrupted osdmaps kernel: libceph: prevent potential out-of-bounds reads in handle_auth_done() kernel: libceph: replace overzealous BUG_ON in osdmap_apply_incremental() kernel: Linux kernel: Denial of Service in libceph OSD client due to unreset sparse-read state kernel: drm/amdgpu/vcn4: Prevent OOB reads when parsing dec msg kernel: drm/amdgpu/vcn4: Prevent OOB reads when parsing IB kernel: drm/amdgpu/vcn3: Prevent OOB reads when parsing dec msg kernel: drm/amdgpu/userq: fix access to stale wptr mapping kernel: af_unix: Drop all SCM attributes for SOCKMAP kernel: accel/ivpu: Add buffer overflow check in MS get_info_ioctl kernel: drm/xe/eustall: Fix drm_dev_put called before stream disable in close kernel: drm/virtio: use uninterruptible resv lock for plane updates kernel: drm/amdgpu/vce: fix integer overflow in image size kernel: pppoe: reload header pointer after dev_hard_header() kernel: drm/amdkfd: fix 32-bit overflow in CWSR total size calculation kernel: drm/xe: Hold a dma-buf reference for imported BOs kernel: drm/xe/rtp: Add RING_FORCE_TO_NONPRIV_DENY to OA whitelists kernel: drm/amdgpu: Fix context pstate override handling kernel: ipvs: do not propagate one-packet flag to synced conns kernel: nvme-tcp: fix host memory disclosure on R2T for a read command&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;kernel: fbcon: Set fb_display[i]-&amp;gt;mode to NULL when the mode is released kernel: libceph: fix potential use-after-free in have_mon_and_osd_map() kernel: libceph: make decode_pool() more resilient against corrupted osdmaps kernel: libceph: prevent potential out-of-bounds reads in handle_auth_done() kernel: libceph: replace overzealous BUG_ON in osdmap_apply_incremental() kernel: Linux kernel: Denial of Service in libceph OSD client due to unreset sparse-read state kernel: drm/amdgpu/vcn4: Prevent OOB reads when parsing dec msg kernel: drm/amdgpu/vcn4: Prevent OOB reads when parsing IB kernel: drm/amdgpu/vcn3: Prevent OOB reads when parsing dec msg kernel: drm/amdgpu/userq: fix access to stale wptr mapping kernel: af_unix: Drop all SCM attributes for SOCKMAP kernel: accel/ivpu: Add buffer overflow check in MS get_info_ioctl kernel: drm/xe/eustall: Fix drm_dev_put called before stream disable in close kernel: drm/virtio: use uninterruptible resv lock for plane updates kernel: drm/amdgpu/vce: fix integer overflow in image size kernel: pppoe: reload header pointer after dev_hard_header() kernel: drm/amdkfd: fix 32-bit overflow in CWSR total size calculation kernel: drm/xe: Hold a dma-buf reference for imported BOs kernel: drm/xe/rtp: Add RING_FORCE_TO_NONPRIV_DENY to OA whitelists kernel: drm/amdgpu: Fix context pstate override handling kernel: ipvs: do not propagate one-packet flag to synced conns kernel: nvme-tcp: fix host memory disclosure on R2T for a read command&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:71602</guid>
    </item>
    <item>
      <title>RLSA-2026:71602 — Important: kernel security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:71602</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: kernel&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: fbcon: Set fb_display[i]-&amp;gt;mode to NULL when the mode is released (CVE-2025-40323)&lt;/p&gt;
&lt;p&gt;* kernel: libceph: fix potential use-after-free in have_mon_and_osd_map() (CVE-2025-68285)&lt;/p&gt;
&lt;p&gt;* kernel: libceph: make decode_pool() more resilient against corrupted osdmaps (CVE-2025-71116)&lt;/p&gt;
&lt;p&gt;* kernel: libceph: prevent potential out-of-bounds reads in handle_auth_done() (CVE-2026-22984)&lt;/p&gt;
&lt;p&gt;* kernel: libceph: replace overzealous BUG_ON in osdmap_apply_incremental() (CVE-2026-22990)&lt;/p&gt;
&lt;p&gt;* kernel: Linux kernel: Denial of Service in libceph OSD client due to unreset sparse-read state (CVE-2026-23136)&lt;/p&gt;
&lt;p&gt;* kernel: drm/amdgpu/vcn3: Prevent OOB reads when parsing dec msg (CVE-2026-46230)&lt;/p&gt;
&lt;p&gt;* kernel: drm/amdgpu/vcn4: Prevent OOB reads when parsing IB (CVE-2026-46204)&lt;/p&gt;
&lt;p&gt;* kernel: drm/amdgpu/vcn4: Prevent OOB reads when parsing dec msg (CVE-2026-46199)&lt;/p&gt;
&lt;p&gt;* kernel: drm/amdgpu/userq: fix access to stale wptr mapping (CVE-2026-46311)&lt;/p&gt;
&lt;p&gt;* kernel: af_unix: Drop all SCM attributes for SOCKMAP (CVE-2026-53005)&lt;/p&gt;
&lt;p&gt;* kernel: accel/ivpu: Add buffer overflow check in MS get_info_ioctl (CVE-2026-53203)&lt;/p&gt;
&lt;p&gt;* kernel: drm/xe/eustall: Fix drm_dev_put called before stream disable in close (CVE-2026-53290)&lt;/p&gt;
&lt;p&gt;* kernel: drm/virtio: use uninterruptible resv lock for plane updates (CVE-2026-64098)&lt;/p&gt;
&lt;p&gt;* kernel: Linux kernel: PPPoE memory corruption via stale pointer (CVE-2026-68121)&lt;/p&gt;
&lt;p&gt;* kernel: drm/amdgpu/vce: fix integer overflow in…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: kernel&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: fbcon: Set fb_display[i]-&amp;gt;mode to NULL when the mode is released (CVE-2025-40323)&lt;/p&gt;
&lt;p&gt;* kernel: libceph: fix potential use-after-free in have_mon_and_osd_map() (CVE-2025-68285)&lt;/p&gt;
&lt;p&gt;* kernel: libceph: make decode_pool() more resilient against corrupted osdmaps (CVE-2025-71116)&lt;/p&gt;
&lt;p&gt;* kernel: libceph: prevent potential out-of-bounds reads in handle_auth_done() (CVE-2026-22984)&lt;/p&gt;
&lt;p&gt;* kernel: libceph: replace overzealous BUG_ON in osdmap_apply_incremental() (CVE-2026-22990)&lt;/p&gt;
&lt;p&gt;* kernel: Linux kernel: Denial of Service in libceph OSD client due to unreset sparse-read state (CVE-2026-23136)&lt;/p&gt;
&lt;p&gt;* kernel: drm/amdgpu/vcn3: Prevent OOB reads when parsing dec msg (CVE-2026-46230)&lt;/p&gt;
&lt;p&gt;* kernel: drm/amdgpu/vcn4: Prevent OOB reads when parsing IB (CVE-2026-46204)&lt;/p&gt;
&lt;p&gt;* kernel: drm/amdgpu/vcn4: Prevent OOB reads when parsing dec msg (CVE-2026-46199)&lt;/p&gt;
&lt;p&gt;* kernel: drm/amdgpu/userq: fix access to stale wptr mapping (CVE-2026-46311)&lt;/p&gt;
&lt;p&gt;* kernel: af_unix: Drop all SCM attributes for SOCKMAP (CVE-2026-53005)&lt;/p&gt;
&lt;p&gt;* kernel: accel/ivpu: Add buffer overflow check in MS get_info_ioctl (CVE-2026-53203)&lt;/p&gt;
&lt;p&gt;* kernel: drm/xe/eustall: Fix drm_dev_put called before stream disable in close (CVE-2026-53290)&lt;/p&gt;
&lt;p&gt;* kernel: drm/virtio: use uninterruptible resv lock for plane updates (CVE-2026-64098)&lt;/p&gt;
&lt;p&gt;* kernel: Linux kernel: PPPoE memory corruption via stale pointer (CVE-2026-68121)&lt;/p&gt;
&lt;p&gt;* kernel: drm/amdgpu/vce: fix integer overflow in…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:71602</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:23477-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:23477-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:23477-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-64098</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-64098</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 192 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: drm/virtio: use uninterruptible resv lock for plane updates virtio_gpu_cursor_plane_update() and virtio_gpu_resource_flush() lock the framebuffer BO&amp;#39;s dma_resv via virtio_gpu_array_lock_resv() and ignore its return value. The function can fail with -EINTR from dma_resv_lock_interruptible() (signal during lock wait) or with -ENOMEM from dma_resv_reserve_fences() (fence slot allocation), leaving the resv lock not held. The queue path then walks the object array and calls dma_resv_add_fence(), which requires the lock held; with lockdep enabled this trips dma_resv_assert_held():   WARNING: drivers/dma-buf/dma-resv.c:296 at dma_resv_add_fence+0x71e/0x840   Call Trace:    virtio_gpu_array_add_fence    virtio_gpu_queue_ctrl_sgs    virtio_gpu_queue_fenced_ctrl_buffer    virtio_gpu_cursor_plane_update    drm_atomic_helper_commit_planes    drm_atomic_helper_commit_tail    commit_tail    drm_atomic_helper_commit    drm_atomic_commit    drm_atomic_helper_update_plane    __setplane_atomic    drm_mode_cursor_universal    drm_mode_cursor_common    drm_mode_cursor_ioctl    drm_ioctl    __x64_sys_ioctl Beyond the WARN, mutating the dma_resv fence list without the lock races with concurrent readers/writers and can corrupt the list. Both call sites run inside the .atomic_update plane callback, which DRM atomic helpers do not allow to fail (by the time it runs, the commit has been signed off to userspace and there is no clean r…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 192 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: drm/virtio: use uninterruptible resv lock for plane updates virtio_gpu_cursor_plane_update() and virtio_gpu_resource_flush() lock the framebuffer BO&amp;#39;s dma_resv via virtio_gpu_array_lock_resv() and ignore its return value. The function can fail with -EINTR from dma_resv_lock_interruptible() (signal during lock wait) or with -ENOMEM from dma_resv_reserve_fences() (fence slot allocation), leaving the resv lock not held. The queue path then walks the object array and calls dma_resv_add_fence(), which requires the lock held; with lockdep enabled this trips dma_resv_assert_held():   WARNING: drivers/dma-buf/dma-resv.c:296 at dma_resv_add_fence+0x71e/0x840   Call Trace:    virtio_gpu_array_add_fence    virtio_gpu_queue_ctrl_sgs    virtio_gpu_queue_fenced_ctrl_buffer    virtio_gpu_cursor_plane_update    drm_atomic_helper_commit_planes    drm_atomic_helper_commit_tail    commit_tail    drm_atomic_helper_commit    drm_atomic_commit    drm_atomic_helper_update_plane    __setplane_atomic    drm_mode_cursor_universal    drm_mode_cursor_common    drm_mode_cursor_ioctl    drm_ioctl    __x64_sys_ioctl Beyond the WARN, mutating the dma_resv fence list without the lock races with concurrent readers/writers and can corrupt the list. Both call sites run inside the .atomic_update plane callback, which DRM atomic helpers do not allow to fail (by the time it runs, the commit has been signed off to userspace and there is no clean r…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-64098</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2403 — Linux Kernel: Mehrere Schwachstellen ermöglichen nicht spezifizierten Angriff</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2403</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen, möglicherweise Sicherheitsmaßnahmen zu umgehen, einen Denial-of-Service-Zustand herbeizuführen oder vertrauliche Informationen offenzulegen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen, möglicherweise Sicherheitsmaßnahmen zu umgehen, einen Denial-of-Service-Zustand herbeizuführen oder vertrauliche Informationen offenzulegen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2403</guid>
    </item>
  </channel>
</rss>
