<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 10:01:56 +0000</lastBuildDate>
    <item>
      <title>ALSA-2026:65334 — Important: kernel security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:65334</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: kernel, AlmaLinux:10: kernel-64k, AlmaLinux:10: kernel-64k-core, AlmaLinux:10: kernel-64k-debug, AlmaLinux:10: kernel-64k-debug-core, AlmaLinux:10: kernel-64k-debug-devel, AlmaLinux:10: kernel-64k-debug-devel-matched, AlmaLinux:10: kernel-64k-debug-modules, AlmaLinux:10: kernel-64k-debug-modules-core, AlmaLinux:10: kernel-64k-debug-modules-extra and 65 more&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: KVM: nSVM: Always use vmcb01 in VMLOAD/VMSAVE emulation (CVE-2026-43133)
  * kernel: Bluetooth: SMP: force responder MITM requirements before building the pairing response (CVE-2026-43334)
  * kernel: Bluetooth: virtio_bt: clamp rx length before skb_put (CVE-2026-46123)
  * kernel: Bluetooth: serialize accept_q access (CVE-2026-52918)
  * kernel: net: pull headers in qdisc_pkt_len_segs_init() (CVE-2026-53091)
  * kernel: Bluetooth: fix locking in hci_conn_request_evt() with HCI_PROTO_DEFER (CVE-2026-53072)
  * kernel: net: qrtr: fix refcount saturation and potential UAF in qrtr_port_remove (CVE-2026-52947)
  * kernel: Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind() (CVE-2026-53256)
  * kernel: wifi: nl80211: reject oversized EMA RNR lists (CVE-2026-53182)
  * kernel: Bluetooth: hci_sync: reject oversized Broadcast Announcement prepend (CVE-2026-53209)
  * kernel: Bluetooth: RFCOMM: validate skb length in MCC handlers (CVE-2026-53254)
  * kernel: vfio/pci: Clean up DMABUFs before disabling function (CVE-2026-53322)
  * kernel: Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp (CVE-2026-63975)
  * kernel: security/keys: fix missed RCU read section on lookup (CVE-2026-64015)
  * kernel: Bluetooth: HIDP: fix missing length checks in hidp_input_report() (CVE-2026-63947)
  * kernel: Bluetooth: hci_sync: fix UAF in hci_le_create_cis_sy…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: kernel, AlmaLinux:10: kernel-64k, AlmaLinux:10: kernel-64k-core, AlmaLinux:10: kernel-64k-debug, AlmaLinux:10: kernel-64k-debug-core, AlmaLinux:10: kernel-64k-debug-devel, AlmaLinux:10: kernel-64k-debug-devel-matched, AlmaLinux:10: kernel-64k-debug-modules, AlmaLinux:10: kernel-64k-debug-modules-core, AlmaLinux:10: kernel-64k-debug-modules-extra and 65 more&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: KVM: nSVM: Always use vmcb01 in VMLOAD/VMSAVE emulation (CVE-2026-43133)
  * kernel: Bluetooth: SMP: force responder MITM requirements before building the pairing response (CVE-2026-43334)
  * kernel: Bluetooth: virtio_bt: clamp rx length before skb_put (CVE-2026-46123)
  * kernel: Bluetooth: serialize accept_q access (CVE-2026-52918)
  * kernel: net: pull headers in qdisc_pkt_len_segs_init() (CVE-2026-53091)
  * kernel: Bluetooth: fix locking in hci_conn_request_evt() with HCI_PROTO_DEFER (CVE-2026-53072)
  * kernel: net: qrtr: fix refcount saturation and potential UAF in qrtr_port_remove (CVE-2026-52947)
  * kernel: Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind() (CVE-2026-53256)
  * kernel: wifi: nl80211: reject oversized EMA RNR lists (CVE-2026-53182)
  * kernel: Bluetooth: hci_sync: reject oversized Broadcast Announcement prepend (CVE-2026-53209)
  * kernel: Bluetooth: RFCOMM: validate skb length in MCC handlers (CVE-2026-53254)
  * kernel: vfio/pci: Clean up DMABUFs before disabling function (CVE-2026-53322)
  * kernel: Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp (CVE-2026-63975)
  * kernel: security/keys: fix missed RCU read section on lookup (CVE-2026-64015)
  * kernel: Bluetooth: HIDP: fix missing length checks in hidp_input_report() (CVE-2026-63947)
  * kernel: Bluetooth: hci_sync: fix UAF in hci_le_create_cis_sy…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:65334</guid>
    </item>
    <item>
      <title>BELL-CVE-2026-64113</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-64113</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-64113</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0926 — De multiples vulnérabilités ont été découvertes dans le noyau Linux d'Ubuntu. Certaines d'entre elles permettent à un a…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0926</link>
      <description>certfr-2026-avi-0926</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0926</guid>
    </item>
    <item>
      <title>EUVD-2026-348410</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-348410</link>
      <description>EUVD-2026-348410</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-348410</guid>
    </item>
    <item>
      <title>fkie_cve-2026-64113</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-64113</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;ixgbevf: fix use-after-free in VEPA multicast source pruning&lt;/p&gt;
&lt;p&gt;ixgbevf_clean_rx_irq() prunes frames whose source MAC matches the VF&amp;#39;s
own address (VEPA multicast workaround) by freeing the skb and
continuing to the next descriptor:&lt;/p&gt;
&lt;p&gt;dev_kfree_skb_irq(skb);
    continue;&lt;/p&gt;
&lt;p&gt;The skb pointer is declared outside the while loop and persists across
iterations.  Because the continue skips the &amp;#34;skb = NULL&amp;#34; reset at the
bottom of the loop, the next iteration enters the &amp;#34;else if (skb)&amp;#34; path
and calls ixgbevf_add_rx_frag() on the freed skb, dereferencing
skb_shinfo(skb)-&amp;gt;nr_frags - a use-after-free in NAPI softirq context.&lt;/p&gt;
&lt;p&gt;The sibling driver iavf already handles this correctly by nulling the
pointer before continuing.  Apply the same pattern here.&lt;/p&gt;
&lt;p&gt;I do not have ixgbevf hardware; the bug was found by static analysis
(scan_drop_continue_loops.py + semgrep drop_continue_in_loop, multi-tool
corroboration with the highest score in the scan).  The UAF was confirmed
under KASAN by loading a test module that reproduces the exact code
pattern (alloc skb, kfree_skb, then read skb_shinfo(skb)-&amp;gt;nr_frags):&lt;/p&gt;
&lt;p&gt;BUG: KASAN: slab-use-after-free in ixgbevf_uaf_test_init+0x100/0x1000
  Read of size 8 at addr 000000006163ae78 by task insmod/30
  freed 208-byte region [000000006163adc0, 000000006163ae90)&lt;/p&gt;
&lt;p&gt;QEMU emulates igb (82576) but not ixgbe (82599), and the igbvf VF
driver does not include the VEPA source pruning path, so a full
en…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;ixgbevf: fix use-after-free in VEPA multicast source pruning&lt;/p&gt;
&lt;p&gt;ixgbevf_clean_rx_irq() prunes frames whose source MAC matches the VF&amp;#39;s
own address (VEPA multicast workaround) by freeing the skb and
continuing to the next descriptor:&lt;/p&gt;
&lt;p&gt;dev_kfree_skb_irq(skb);
    continue;&lt;/p&gt;
&lt;p&gt;The skb pointer is declared outside the while loop and persists across
iterations.  Because the continue skips the &amp;#34;skb = NULL&amp;#34; reset at the
bottom of the loop, the next iteration enters the &amp;#34;else if (skb)&amp;#34; path
and calls ixgbevf_add_rx_frag() on the freed skb, dereferencing
skb_shinfo(skb)-&amp;gt;nr_frags - a use-after-free in NAPI softirq context.&lt;/p&gt;
&lt;p&gt;The sibling driver iavf already handles this correctly by nulling the
pointer before continuing.  Apply the same pattern here.&lt;/p&gt;
&lt;p&gt;I do not have ixgbevf hardware; the bug was found by static analysis
(scan_drop_continue_loops.py + semgrep drop_continue_in_loop, multi-tool
corroboration with the highest score in the scan).  The UAF was confirmed
under KASAN by loading a test module that reproduces the exact code
pattern (alloc skb, kfree_skb, then read skb_shinfo(skb)-&amp;gt;nr_frags):&lt;/p&gt;
&lt;p&gt;BUG: KASAN: slab-use-after-free in ixgbevf_uaf_test_init+0x100/0x1000
  Read of size 8 at addr 000000006163ae78 by task insmod/30
  freed 208-byte region [000000006163adc0, 000000006163ae90)&lt;/p&gt;
&lt;p&gt;QEMU emulates igb (82576) but not ixgbe (82599), and the igbvf VF
driver does not include the VEPA source pruning path, so a full
en…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-64113</guid>
    </item>
    <item>
      <title>GHSA-gwhj-73cj-phr2</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-gwhj-73cj-phr2</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;ixgbevf: fix use-after-free in VEPA multicast source pruning&lt;/p&gt;
&lt;p&gt;ixgbevf_clean_rx_irq() prunes frames whose source MAC matches the VF&amp;#39;s
own address (VEPA multicast workaround) by freeing the skb and
continuing to the next descriptor:&lt;/p&gt;
&lt;p&gt;dev_kfree_skb_irq(skb);
    continue;&lt;/p&gt;
&lt;p&gt;The skb pointer is declared outside the while loop and persists across
iterations.  Because the continue skips the &amp;#34;skb = NULL&amp;#34; reset at the
bottom of the loop, the next iteration enters the &amp;#34;else if (skb)&amp;#34; path
and calls ixgbevf_add_rx_frag() on the freed skb, dereferencing
skb_shinfo(skb)-&amp;gt;nr_frags - a use-after-free in NAPI softirq context.&lt;/p&gt;
&lt;p&gt;The sibling driver iavf already handles this correctly by nulling the
pointer before continuing.  Apply the same pattern here.&lt;/p&gt;
&lt;p&gt;I do not have ixgbevf hardware; the bug was found by static analysis
(scan_drop_continue_loops.py + semgrep drop_continue_in_loop, multi-tool
corroboration with the highest score in the scan).  The UAF was confirmed
under KASAN by loading a test module that reproduces the exact code
pattern (alloc skb, kfree_skb, then read skb_shinfo(skb)-&amp;gt;nr_frags):&lt;/p&gt;
&lt;p&gt;BUG: KASAN: slab-use-after-free in ixgbevf_uaf_test_init+0x100/0x1000
  Read of size 8 at addr 000000006163ae78 by task insmod/30
  freed 208-byte region [000000006163adc0, 000000006163ae90)&lt;/p&gt;
&lt;p&gt;QEMU emulates igb (82576) but not ixgbe (82599), and the igbvf VF
driver does not include the VEPA source pruning path, so a full
en…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;ixgbevf: fix use-after-free in VEPA multicast source pruning&lt;/p&gt;
&lt;p&gt;ixgbevf_clean_rx_irq() prunes frames whose source MAC matches the VF&amp;#39;s
own address (VEPA multicast workaround) by freeing the skb and
continuing to the next descriptor:&lt;/p&gt;
&lt;p&gt;dev_kfree_skb_irq(skb);
    continue;&lt;/p&gt;
&lt;p&gt;The skb pointer is declared outside the while loop and persists across
iterations.  Because the continue skips the &amp;#34;skb = NULL&amp;#34; reset at the
bottom of the loop, the next iteration enters the &amp;#34;else if (skb)&amp;#34; path
and calls ixgbevf_add_rx_frag() on the freed skb, dereferencing
skb_shinfo(skb)-&amp;gt;nr_frags - a use-after-free in NAPI softirq context.&lt;/p&gt;
&lt;p&gt;The sibling driver iavf already handles this correctly by nulling the
pointer before continuing.  Apply the same pattern here.&lt;/p&gt;
&lt;p&gt;I do not have ixgbevf hardware; the bug was found by static analysis
(scan_drop_continue_loops.py + semgrep drop_continue_in_loop, multi-tool
corroboration with the highest score in the scan).  The UAF was confirmed
under KASAN by loading a test module that reproduces the exact code
pattern (alloc skb, kfree_skb, then read skb_shinfo(skb)-&amp;gt;nr_frags):&lt;/p&gt;
&lt;p&gt;BUG: KASAN: slab-use-after-free in ixgbevf_uaf_test_init+0x100/0x1000
  Read of size 8 at addr 000000006163ae78 by task insmod/30
  freed 208-byte region [000000006163adc0, 000000006163ae90)&lt;/p&gt;
&lt;p&gt;QEMU emulates igb (82576) but not ixgbe (82599), and the igbvf VF
driver does not include the VEPA source pruning path, so a full
en…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-gwhj-73cj-phr2</guid>
    </item>
    <item>
      <title>OESA-2026-3317 — kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-3317</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP4: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;drm/amdgpu: prevent immediate PASID reuse case&lt;/p&gt;
&lt;p&gt;PASID resue could cause interrupt issue when process
immediately runs into hw state left by previous
process exited with the same PASID, it&amp;amp;apos;s possible that
page faults are still pending in the IH ring buffer when
the process exits and frees up its PASID. To prevent the
case, it uses idr cyclic allocator same as kernel pid&amp;amp;apos;s.&lt;/p&gt;
&lt;p&gt;(cherry picked from commit 8f1de51f49be692de137c8525106e0fce2d1912d)(CVE-2026-31462)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;media: hackrf: fix to not free memory after the device is registered in hackrf_probe()&lt;/p&gt;
&lt;p&gt;In hackrf driver, the following race condition occurs:
```
		CPU0						CPU1
hackrf_probe()
  kzalloc(); // alloc hackrf_dev
  ....
  v4l2_device_register();
  ....
						fd = sys_open(&amp;amp;quot;/path/to/dev&amp;amp;quot;); // open hackrf fd
						....
  v4l2_device_unregister();
  ....
  kfree(); // free hackrf_dev
  ....
						sys_ioctl(fd, ...);
						  v4l2_ioctl();
						    video_is_registered() // UAF!!
						....
						sys_close(fd);
						  v4l2_release() // UAF!!
						    hackrf_video_release()
						      kfree(); // DFB!!
```&lt;/p&gt;
&lt;p&gt;When a V4L2 or video device is unregistered, the device node is removed so
new open() calls are blocked.&lt;/p&gt;
&lt;p&gt;However, file descriptors that are already open-and any in-flight I/O-do
not terminate i…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP4: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;drm/amdgpu: prevent immediate PASID reuse case&lt;/p&gt;
&lt;p&gt;PASID resue could cause interrupt issue when process
immediately runs into hw state left by previous
process exited with the same PASID, it&amp;amp;apos;s possible that
page faults are still pending in the IH ring buffer when
the process exits and frees up its PASID. To prevent the
case, it uses idr cyclic allocator same as kernel pid&amp;amp;apos;s.&lt;/p&gt;
&lt;p&gt;(cherry picked from commit 8f1de51f49be692de137c8525106e0fce2d1912d)(CVE-2026-31462)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;media: hackrf: fix to not free memory after the device is registered in hackrf_probe()&lt;/p&gt;
&lt;p&gt;In hackrf driver, the following race condition occurs:
```
		CPU0						CPU1
hackrf_probe()
  kzalloc(); // alloc hackrf_dev
  ....
  v4l2_device_register();
  ....
						fd = sys_open(&amp;amp;quot;/path/to/dev&amp;amp;quot;); // open hackrf fd
						....
  v4l2_device_unregister();
  ....
  kfree(); // free hackrf_dev
  ....
						sys_ioctl(fd, ...);
						  v4l2_ioctl();
						    video_is_registered() // UAF!!
						....
						sys_close(fd);
						  v4l2_release() // UAF!!
						    hackrf_video_release()
						      kfree(); // DFB!!
```&lt;/p&gt;
&lt;p&gt;When a V4L2 or video device is unregistered, the device node is removed so
new open() calls are blocked.&lt;/p&gt;
&lt;p&gt;However, file descriptors that are already open-and any in-flight I/O-do
not terminate i…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-3317</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:21910-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:21910-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:21910-1</guid>
    </item>
    <item>
      <title>RHSA-2026:66324 — Red Hat Security Advisory: kernel-rt security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:66324</link>
      <description>&lt;p&gt;kernel: Linux kernel: Denial of Service in qla2xxx SCSI driver due to improper command handling after chip reset kernel: scsi: target: configfs: Bound snprintf() return in tg_pt_gp_members_show() kernel: sctp: diag: reject stale associations in dump_one path kernel: netfilter: nf_log: validate MAC header was set before dumping it kernel: netfilter: nf_conntrack_sip: don&amp;#39;t use simple_strtoul kernel: net: pull headers in qdisc_pkt_len_segs_init() kernel: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing kernel: tipc: fix slab-use-after-free Read in tipc_aead_decrypt_done kernel: sctp: fix race between sctp_wait_for_connect and peeloff kernel: security/keys: fix missed RCU read section on lookup kernel: ixgbevf: fix use-after-free in VEPA multicast source pruning kernel: tipc: clear sock-&amp;gt;sk on the failed-insert path in tipc_sk_create() kernel: sctp: auth: verify auth requirement when auth_chunk is NULL kernel: sctp: validate stream count in sctp_process_strreset_inreq() kernel: sctp: fix auth_hmacs array size in struct sctp_cookie&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;kernel: Linux kernel: Denial of Service in qla2xxx SCSI driver due to improper command handling after chip reset kernel: scsi: target: configfs: Bound snprintf() return in tg_pt_gp_members_show() kernel: sctp: diag: reject stale associations in dump_one path kernel: netfilter: nf_log: validate MAC header was set before dumping it kernel: netfilter: nf_conntrack_sip: don&amp;#39;t use simple_strtoul kernel: net: pull headers in qdisc_pkt_len_segs_init() kernel: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing kernel: tipc: fix slab-use-after-free Read in tipc_aead_decrypt_done kernel: sctp: fix race between sctp_wait_for_connect and peeloff kernel: security/keys: fix missed RCU read section on lookup kernel: ixgbevf: fix use-after-free in VEPA multicast source pruning kernel: tipc: clear sock-&amp;gt;sk on the failed-insert path in tipc_sk_create() kernel: sctp: auth: verify auth requirement when auth_chunk is NULL kernel: sctp: validate stream count in sctp_process_strreset_inreq() kernel: sctp: fix auth_hmacs array size in struct sctp_cookie&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:66324</guid>
    </item>
    <item>
      <title>RLSA-2026:65334 — Important: kernel security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:65334</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: kernel&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: KVM: nSVM: Always use vmcb01 in VMLOAD/VMSAVE emulation (CVE-2026-43133)&lt;/p&gt;
&lt;p&gt;* kernel: Bluetooth: SMP: force responder MITM requirements before building the pairing response (CVE-2026-43334)&lt;/p&gt;
&lt;p&gt;* kernel: Bluetooth: virtio_bt: clamp rx length before skb_put (CVE-2026-46123)&lt;/p&gt;
&lt;p&gt;* kernel: Bluetooth: serialize accept_q access (CVE-2026-52918)&lt;/p&gt;
&lt;p&gt;* kernel: net: pull headers in qdisc_pkt_len_segs_init() (CVE-2026-53091)&lt;/p&gt;
&lt;p&gt;* kernel: Bluetooth: fix locking in hci_conn_request_evt() with HCI_PROTO_DEFER (CVE-2026-53072)&lt;/p&gt;
&lt;p&gt;* kernel: net: qrtr: fix refcount saturation and potential UAF in qrtr_port_remove (CVE-2026-52947)&lt;/p&gt;
&lt;p&gt;* kernel: Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind() (CVE-2026-53256)&lt;/p&gt;
&lt;p&gt;* kernel: wifi: nl80211: reject oversized EMA RNR lists (CVE-2026-53182)&lt;/p&gt;
&lt;p&gt;* kernel: Bluetooth: hci_sync: reject oversized Broadcast Announcement prepend (CVE-2026-53209)&lt;/p&gt;
&lt;p&gt;* kernel: Bluetooth: RFCOMM: validate skb length in MCC handlers (CVE-2026-53254)&lt;/p&gt;
&lt;p&gt;* kernel: vfio/pci: Clean up DMABUFs before disabling function (CVE-2026-53322)&lt;/p&gt;
&lt;p&gt;* kernel: Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp (CVE-2026-63975)&lt;/p&gt;
&lt;p&gt;* kernel: security/keys: fix missed RCU read section on lookup (CVE-2026-64015)&lt;/p&gt;
&lt;p&gt;* kernel: Bluetooth: HIDP: fix missing length checks in hidp_input_report() (CVE-2026-63947)&lt;/p&gt;
&lt;p&gt;* kernel: Bluetooth: hci_sync: fix UAF in hci_le_create_cis_sync (CVE-2026-63944)…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: kernel&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: KVM: nSVM: Always use vmcb01 in VMLOAD/VMSAVE emulation (CVE-2026-43133)&lt;/p&gt;
&lt;p&gt;* kernel: Bluetooth: SMP: force responder MITM requirements before building the pairing response (CVE-2026-43334)&lt;/p&gt;
&lt;p&gt;* kernel: Bluetooth: virtio_bt: clamp rx length before skb_put (CVE-2026-46123)&lt;/p&gt;
&lt;p&gt;* kernel: Bluetooth: serialize accept_q access (CVE-2026-52918)&lt;/p&gt;
&lt;p&gt;* kernel: net: pull headers in qdisc_pkt_len_segs_init() (CVE-2026-53091)&lt;/p&gt;
&lt;p&gt;* kernel: Bluetooth: fix locking in hci_conn_request_evt() with HCI_PROTO_DEFER (CVE-2026-53072)&lt;/p&gt;
&lt;p&gt;* kernel: net: qrtr: fix refcount saturation and potential UAF in qrtr_port_remove (CVE-2026-52947)&lt;/p&gt;
&lt;p&gt;* kernel: Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind() (CVE-2026-53256)&lt;/p&gt;
&lt;p&gt;* kernel: wifi: nl80211: reject oversized EMA RNR lists (CVE-2026-53182)&lt;/p&gt;
&lt;p&gt;* kernel: Bluetooth: hci_sync: reject oversized Broadcast Announcement prepend (CVE-2026-53209)&lt;/p&gt;
&lt;p&gt;* kernel: Bluetooth: RFCOMM: validate skb length in MCC handlers (CVE-2026-53254)&lt;/p&gt;
&lt;p&gt;* kernel: vfio/pci: Clean up DMABUFs before disabling function (CVE-2026-53322)&lt;/p&gt;
&lt;p&gt;* kernel: Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp (CVE-2026-63975)&lt;/p&gt;
&lt;p&gt;* kernel: security/keys: fix missed RCU read section on lookup (CVE-2026-64015)&lt;/p&gt;
&lt;p&gt;* kernel: Bluetooth: HIDP: fix missing length checks in hidp_input_report() (CVE-2026-63947)&lt;/p&gt;
&lt;p&gt;* kernel: Bluetooth: hci_sync: fix UAF in hci_le_create_cis_sync (CVE-2026-63944)…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:65334</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:23477-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:23477-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:23477-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-64113</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-64113</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe, Ubuntu:16.04:LTS: linux-hwe-edge and 244 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: ixgbevf: fix use-after-free in VEPA multicast source pruning ixgbevf_clean_rx_irq() prunes frames whose source MAC matches the VF&amp;#39;s own address (VEPA multicast workaround) by freeing the skb and continuing to the next descriptor:     dev_kfree_skb_irq(skb);     continue; The skb pointer is declared outside the while loop and persists across iterations.  Because the continue skips the &amp;#34;skb = NULL&amp;#34; reset at the bottom of the loop, the next iteration enters the &amp;#34;else if (skb)&amp;#34; path and calls ixgbevf_add_rx_frag() on the freed skb, dereferencing skb_shinfo(skb)-&amp;gt;nr_frags - a use-after-free in NAPI softirq context. The sibling driver iavf already handles this correctly by nulling the pointer before continuing.  Apply the same pattern here. I do not have ixgbevf hardware; the bug was found by static analysis (scan_drop_continue_loops.py + semgrep drop_continue_in_loop, multi-tool corroboration with the highest score in the scan).  The UAF was confirmed under KASAN by loading a test module that reproduces the exact code pattern (alloc skb, kfree_skb, then read skb_shinfo(skb)-&amp;gt;nr_frags):   BUG: KASAN: slab-use-after-free in ixgbevf_uaf_test_init+0x100/0x1000   Read of size 8 at addr 000000006163ae78 by task insmod/30   freed 208-byte region [000000006163adc0, 000000006163ae90) QEMU emulates igb (82576) but not ixgbe (82599), and the igbvf VF driver does not include the VEPA source pruning path, so a full end-to-end…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe, Ubuntu:16.04:LTS: linux-hwe-edge and 244 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: ixgbevf: fix use-after-free in VEPA multicast source pruning ixgbevf_clean_rx_irq() prunes frames whose source MAC matches the VF&amp;#39;s own address (VEPA multicast workaround) by freeing the skb and continuing to the next descriptor:     dev_kfree_skb_irq(skb);     continue; The skb pointer is declared outside the while loop and persists across iterations.  Because the continue skips the &amp;#34;skb = NULL&amp;#34; reset at the bottom of the loop, the next iteration enters the &amp;#34;else if (skb)&amp;#34; path and calls ixgbevf_add_rx_frag() on the freed skb, dereferencing skb_shinfo(skb)-&amp;gt;nr_frags - a use-after-free in NAPI softirq context. The sibling driver iavf already handles this correctly by nulling the pointer before continuing.  Apply the same pattern here. I do not have ixgbevf hardware; the bug was found by static analysis (scan_drop_continue_loops.py + semgrep drop_continue_in_loop, multi-tool corroboration with the highest score in the scan).  The UAF was confirmed under KASAN by loading a test module that reproduces the exact code pattern (alloc skb, kfree_skb, then read skb_shinfo(skb)-&amp;gt;nr_frags):   BUG: KASAN: slab-use-after-free in ixgbevf_uaf_test_init+0x100/0x1000   Read of size 8 at addr 000000006163ae78 by task insmod/30   freed 208-byte region [000000006163adc0, 000000006163ae90) QEMU emulates igb (82576) but not ixgbe (82599), and the igbvf VF driver does not include the VEPA source pruning path, so a full end-to-end…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-64113</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2403 — Linux Kernel: Mehrere Schwachstellen ermöglichen nicht spezifizierten Angriff</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2403</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen, möglicherweise Sicherheitsmaßnahmen zu umgehen, einen Denial-of-Service-Zustand herbeizuführen oder vertrauliche Informationen offenzulegen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen, möglicherweise Sicherheitsmaßnahmen zu umgehen, einen Denial-of-Service-Zustand herbeizuführen oder vertrauliche Informationen offenzulegen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2403</guid>
    </item>
  </channel>
</rss>
