<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 15:34:04 +0000</lastBuildDate>
    <item>
      <title>ALSA-2026:53329 — Important: kernel security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:53329</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: kernel, AlmaLinux:9: kernel-64k, AlmaLinux:9: kernel-64k-core, AlmaLinux:9: kernel-64k-debug, AlmaLinux:9: kernel-64k-debug-core, AlmaLinux:9: kernel-64k-debug-devel, AlmaLinux:9: kernel-64k-debug-devel-matched, AlmaLinux:9: kernel-64k-debug-modules, AlmaLinux:9: kernel-64k-debug-modules-core, AlmaLinux:9: kernel-64k-debug-modules-extra and 64 more&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: cxl/port: Fix use after free of parent_port in cxl_detach_ep() (CVE-2026-31530)
  * kernel: xen: AMD Zen 2 Processors: Privilege escalation via improper CPU cache isolation (CVE-2025-54518)
  * kernel: mm/slab: do not limit zeroing to orig_size when only red zoning is enabled (CVE-2026-64368)
  * kernel: net: openvswitch: reject oversized nested action attrs (CVE-2026-64531)&lt;/p&gt;
&lt;p&gt;Bug Fix(es) and Enhancement(s):&lt;/p&gt;
&lt;p&gt;* Kernel oops after increasing max number of mac addresses of a mlx5 VF [almalinux-9.8.z] (JIRA:AlmaLinux-213036)
  * AlmaLinux9.4 - s390/pkey: Check length in pkey_pckmo handler implementation [almalinux-9.8.z] (JIRA:AlmaLinux-215578)
  * AlmaLinux9.4 - s390/pkey: Check length in PKEY_VERIFYPROTK ioctl [almalinux-9.8.z] (JIRA:AlmaLinux-215580)
  * cifs: periodic IO errors when rename races with lease break (JIRA:AlmaLinux-192999)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: kernel, AlmaLinux:9: kernel-64k, AlmaLinux:9: kernel-64k-core, AlmaLinux:9: kernel-64k-debug, AlmaLinux:9: kernel-64k-debug-core, AlmaLinux:9: kernel-64k-debug-devel, AlmaLinux:9: kernel-64k-debug-devel-matched, AlmaLinux:9: kernel-64k-debug-modules, AlmaLinux:9: kernel-64k-debug-modules-core, AlmaLinux:9: kernel-64k-debug-modules-extra and 64 more&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: cxl/port: Fix use after free of parent_port in cxl_detach_ep() (CVE-2026-31530)
  * kernel: xen: AMD Zen 2 Processors: Privilege escalation via improper CPU cache isolation (CVE-2025-54518)
  * kernel: mm/slab: do not limit zeroing to orig_size when only red zoning is enabled (CVE-2026-64368)
  * kernel: net: openvswitch: reject oversized nested action attrs (CVE-2026-64531)&lt;/p&gt;
&lt;p&gt;Bug Fix(es) and Enhancement(s):&lt;/p&gt;
&lt;p&gt;* Kernel oops after increasing max number of mac addresses of a mlx5 VF [almalinux-9.8.z] (JIRA:AlmaLinux-213036)
  * AlmaLinux9.4 - s390/pkey: Check length in pkey_pckmo handler implementation [almalinux-9.8.z] (JIRA:AlmaLinux-215578)
  * AlmaLinux9.4 - s390/pkey: Check length in PKEY_VERIFYPROTK ioctl [almalinux-9.8.z] (JIRA:AlmaLinux-215580)
  * cifs: periodic IO errors when rename races with lease break (JIRA:AlmaLinux-192999)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:53329</guid>
    </item>
    <item>
      <title>bdu:2026-13774</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-13774</link>
      <description>bdu:2026-13774</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-13774</guid>
    </item>
    <item>
      <title>BELL-CVE-2026-64531</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-64531</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-64531</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0981 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de Debian. Elles permettent à un attaquant de provo…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0981</link>
      <description>certfr-2026-avi-0981</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0981</guid>
    </item>
    <item>
      <title>EUVD-2026-357764</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-357764</link>
      <description>EUVD-2026-357764</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-357764</guid>
    </item>
    <item>
      <title>fkie_cve-2026-64531</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-64531</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;net: openvswitch: reject oversized nested action attrs&lt;/p&gt;
&lt;p&gt;Open vSwitch stores generated flow actions as nlattrs, whose nla_len
field is u16. Commit a1e64addf3ff (&amp;#34;net: openvswitch: remove
misbehaving actions length check&amp;#34;) allowed the total sw_flow_actions
stream to grow beyond 64 KiB, which is valid, but also removed the last
guard preventing a generated nested action attribute from exceeding
U16_MAX.&lt;/p&gt;
&lt;p&gt;An oversized generated container can thus be closed with a truncated
nla_len. A later dump or teardown then walks a structurally different
stream than the one that was validated. In particular, an oversized
nested CLONE/CT action may cause subsequent bytes in the generated
stream to be interpreted as independent actions.&lt;/p&gt;
&lt;p&gt;Keep the larger total-action-stream behavior, but make nested action
close reject generated containers that do not fit in nla_len, and return
the error through all callers. For recursive SAMPLE, CLONE, DEC_TTL, and
CHECK_PKT_LEN builders, trim resource-owning action-list tails in reverse
construction order before discarding failed wrappers, so resources copied
into the rejected tails are released before the wrappers are removed.&lt;/p&gt;
&lt;p&gt;Most failed outer wrappers are discarded by truncating actions_len after
child resources have been released. CHECK_PKT_LEN also trims its parent
after branch resources are gone. SET/TUNNEL close failures unwind their
known tun_dst ownership directly, and SET_TO_MASKE…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;net: openvswitch: reject oversized nested action attrs&lt;/p&gt;
&lt;p&gt;Open vSwitch stores generated flow actions as nlattrs, whose nla_len
field is u16. Commit a1e64addf3ff (&amp;#34;net: openvswitch: remove
misbehaving actions length check&amp;#34;) allowed the total sw_flow_actions
stream to grow beyond 64 KiB, which is valid, but also removed the last
guard preventing a generated nested action attribute from exceeding
U16_MAX.&lt;/p&gt;
&lt;p&gt;An oversized generated container can thus be closed with a truncated
nla_len. A later dump or teardown then walks a structurally different
stream than the one that was validated. In particular, an oversized
nested CLONE/CT action may cause subsequent bytes in the generated
stream to be interpreted as independent actions.&lt;/p&gt;
&lt;p&gt;Keep the larger total-action-stream behavior, but make nested action
close reject generated containers that do not fit in nla_len, and return
the error through all callers. For recursive SAMPLE, CLONE, DEC_TTL, and
CHECK_PKT_LEN builders, trim resource-owning action-list tails in reverse
construction order before discarding failed wrappers, so resources copied
into the rejected tails are released before the wrappers are removed.&lt;/p&gt;
&lt;p&gt;Most failed outer wrappers are discarded by truncating actions_len after
child resources have been released. CHECK_PKT_LEN also trims its parent
after branch resources are gone. SET/TUNNEL close failures unwind their
known tun_dst ownership directly, and SET_TO_MASKE…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-64531</guid>
    </item>
    <item>
      <title>GHSA-4pwv-pmm4-fw4r</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-4pwv-pmm4-fw4r</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;net: openvswitch: reject oversized nested action attrs&lt;/p&gt;
&lt;p&gt;Open vSwitch stores generated flow actions as nlattrs, whose nla_len
field is u16. Commit a1e64addf3ff (&amp;#34;net: openvswitch: remove
misbehaving actions length check&amp;#34;) allowed the total sw_flow_actions
stream to grow beyond 64 KiB, which is valid, but also removed the last
guard preventing a generated nested action attribute from exceeding
U16_MAX.&lt;/p&gt;
&lt;p&gt;An oversized generated container can thus be closed with a truncated
nla_len. A later dump or teardown then walks a structurally different
stream than the one that was validated. In particular, an oversized
nested CLONE/CT action may cause subsequent bytes in the generated
stream to be interpreted as independent actions.&lt;/p&gt;
&lt;p&gt;Keep the larger total-action-stream behavior, but make nested action
close reject generated containers that do not fit in nla_len, and return
the error through all callers. For recursive SAMPLE, CLONE, DEC_TTL, and
CHECK_PKT_LEN builders, trim resource-owning action-list tails in reverse
construction order before discarding failed wrappers, so resources copied
into the rejected tails are released before the wrappers are removed.&lt;/p&gt;
&lt;p&gt;Most failed outer wrappers are discarded by truncating actions_len after
child resources have been released. CHECK_PKT_LEN also trims its parent
after branch resources are gone. SET/TUNNEL close failures unwind their
known tun_dst ownership directly, and SET_TO_MASKE…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;net: openvswitch: reject oversized nested action attrs&lt;/p&gt;
&lt;p&gt;Open vSwitch stores generated flow actions as nlattrs, whose nla_len
field is u16. Commit a1e64addf3ff (&amp;#34;net: openvswitch: remove
misbehaving actions length check&amp;#34;) allowed the total sw_flow_actions
stream to grow beyond 64 KiB, which is valid, but also removed the last
guard preventing a generated nested action attribute from exceeding
U16_MAX.&lt;/p&gt;
&lt;p&gt;An oversized generated container can thus be closed with a truncated
nla_len. A later dump or teardown then walks a structurally different
stream than the one that was validated. In particular, an oversized
nested CLONE/CT action may cause subsequent bytes in the generated
stream to be interpreted as independent actions.&lt;/p&gt;
&lt;p&gt;Keep the larger total-action-stream behavior, but make nested action
close reject generated containers that do not fit in nla_len, and return
the error through all callers. For recursive SAMPLE, CLONE, DEC_TTL, and
CHECK_PKT_LEN builders, trim resource-owning action-list tails in reverse
construction order before discarding failed wrappers, so resources copied
into the rejected tails are released before the wrappers are removed.&lt;/p&gt;
&lt;p&gt;Most failed outer wrappers are discarded by truncating actions_len after
child resources have been released. CHECK_PKT_LEN also trims its parent
after branch resources are gone. SET/TUNNEL close failures unwind their
known tun_dst ownership directly, and SET_TO_MASKE…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-4pwv-pmm4-fw4r</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-64531 — net: openvswitch: reject oversized nested action attrs</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-64531</link>
      <description>msrc_CVE-2026-64531</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-64531</guid>
    </item>
    <item>
      <title>OESA-2026-3704 — kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-3704</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP3: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;net: hns3: add VLAN id validation before using&lt;/p&gt;
&lt;p&gt;Currently, the VLAN id may be used without validation when
receive a VLAN configuration mailbox from VF. The length of
vlan_del_fail_bmap is BITS_TO_LONGS(VLAN_N_VID). It may cause
out-of-bounds memory access once the VLAN id is bigger than
or equal to VLAN_N_VID.&lt;/p&gt;
&lt;p&gt;Therefore, VLAN id needs to be checked to ensure it is within
the range of VLAN_N_VID.(CVE-2025-71112)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;ext4: fix string copying in parse_apply_sb_mount_options()&lt;/p&gt;
&lt;p&gt;strscpy_pad() can&amp;amp;apos;t be used to copy a non-NUL-term string into a NUL-term
string of possibly bigger size.  Commit 0efc5990bca5 (&amp;amp;quot;string.h: Introduce
memtostr() and memtostr_pad()&amp;amp;quot;) provides additional information in that
regard.  So if this happens, the following warning is observed:&lt;/p&gt;
&lt;p&gt;strnlen: detected buffer overflow: 65 byte read of buffer size 64
WARNING: CPU: 0 PID: 28655 at lib/string_helpers.c:1032 __fortify_report+0x96/0xc0 lib/string_helpers.c:1032
Modules linked in:
CPU: 0 UID: 0 PID: 28655 Comm: syz-executor.3 Not tainted 6.12.54-syzkaller-00144-g5f0270f1ba00 #0
Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
RIP: 0010:__fortify_report+0x96/0xc0 lib/string_helpers.c:1032
Call Trace:
 &amp;amp;lt;TASK&amp;amp;gt;
 __fortify_panic+0x1f/0x30 lib/s…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP3: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;net: hns3: add VLAN id validation before using&lt;/p&gt;
&lt;p&gt;Currently, the VLAN id may be used without validation when
receive a VLAN configuration mailbox from VF. The length of
vlan_del_fail_bmap is BITS_TO_LONGS(VLAN_N_VID). It may cause
out-of-bounds memory access once the VLAN id is bigger than
or equal to VLAN_N_VID.&lt;/p&gt;
&lt;p&gt;Therefore, VLAN id needs to be checked to ensure it is within
the range of VLAN_N_VID.(CVE-2025-71112)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;ext4: fix string copying in parse_apply_sb_mount_options()&lt;/p&gt;
&lt;p&gt;strscpy_pad() can&amp;amp;apos;t be used to copy a non-NUL-term string into a NUL-term
string of possibly bigger size.  Commit 0efc5990bca5 (&amp;amp;quot;string.h: Introduce
memtostr() and memtostr_pad()&amp;amp;quot;) provides additional information in that
regard.  So if this happens, the following warning is observed:&lt;/p&gt;
&lt;p&gt;strnlen: detected buffer overflow: 65 byte read of buffer size 64
WARNING: CPU: 0 PID: 28655 at lib/string_helpers.c:1032 __fortify_report+0x96/0xc0 lib/string_helpers.c:1032
Modules linked in:
CPU: 0 UID: 0 PID: 28655 Comm: syz-executor.3 Not tainted 6.12.54-syzkaller-00144-g5f0270f1ba00 #0
Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
RIP: 0010:__fortify_report+0x96/0xc0 lib/string_helpers.c:1032
Call Trace:
 &amp;amp;lt;TASK&amp;amp;gt;
 __fortify_panic+0x1f/0x30 lib/s…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-3704</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:11476-1 — kernel-devel-7.1.7-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11476-1</link>
      <description>&lt;p&gt;kernel-devel-7.1.7-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;kernel-devel-7.1.7-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:11476-1</guid>
    </item>
    <item>
      <title>RHSA-2026:51603 — Red Hat Security Advisory: kernel security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:51603</link>
      <description>&lt;p&gt;kernel: Arm Processors: Privilege escalation or information disclosure via writes to higher exception level resources kernel: KVM: x86: Don&amp;#39;t (re)check L1 intercepts when completing userspace I/O kernel: xen/privcmd: fix double free via VMA splitting kernel: gfs2: Fix use-after-free in iomap inline data write path kernel: ipc: limit next_id allocation to the valid ID range kernel: net: openvswitch: reject oversized nested action attrs&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;kernel: Arm Processors: Privilege escalation or information disclosure via writes to higher exception level resources kernel: KVM: x86: Don&amp;#39;t (re)check L1 intercepts when completing userspace I/O kernel: xen/privcmd: fix double free via VMA splitting kernel: gfs2: Fix use-after-free in iomap inline data write path kernel: ipc: limit next_id allocation to the valid ID range kernel: net: openvswitch: reject oversized nested action attrs&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:51603</guid>
    </item>
    <item>
      <title>RLSA-2026:53329 — Important: kernel security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:53329</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:9: kernel&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: cxl/port: Fix use after free of parent_port in cxl_detach_ep() (CVE-2026-31530)&lt;/p&gt;
&lt;p&gt;* kernel: xen: AMD Zen 2 Processors: Privilege escalation via improper CPU cache isolation (CVE-2025-54518)&lt;/p&gt;
&lt;p&gt;* kernel: mm/slab: do not limit zeroing to orig_size when only red zoning is enabled (CVE-2026-64368)&lt;/p&gt;
&lt;p&gt;* kernel: net: openvswitch: reject oversized nested action attrs (CVE-2026-64531)&lt;/p&gt;
&lt;p&gt;Bug Fix(es) and Enhancement(s):&lt;/p&gt;
&lt;p&gt;* Kernel oops after increasing max number of mac addresses of a mlx5 VF [rhel-9.8.z] (JIRA:Rocky Linux-213036)&lt;/p&gt;
&lt;p&gt;* Rocky Linux9.4 - s390/pkey: Check length in pkey_pckmo handler implementation [rhel-9.8.z] (JIRA:Rocky Linux-215578)&lt;/p&gt;
&lt;p&gt;* Rocky Linux9.4 - s390/pkey: Check length in PKEY_VERIFYPROTK ioctl [rhel-9.8.z] (JIRA:Rocky Linux-215580)&lt;/p&gt;
&lt;p&gt;* cifs: periodic IO errors when rename races with lease break (JIRA:Rocky Linux-192999)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:9: kernel&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: cxl/port: Fix use after free of parent_port in cxl_detach_ep() (CVE-2026-31530)&lt;/p&gt;
&lt;p&gt;* kernel: xen: AMD Zen 2 Processors: Privilege escalation via improper CPU cache isolation (CVE-2025-54518)&lt;/p&gt;
&lt;p&gt;* kernel: mm/slab: do not limit zeroing to orig_size when only red zoning is enabled (CVE-2026-64368)&lt;/p&gt;
&lt;p&gt;* kernel: net: openvswitch: reject oversized nested action attrs (CVE-2026-64531)&lt;/p&gt;
&lt;p&gt;Bug Fix(es) and Enhancement(s):&lt;/p&gt;
&lt;p&gt;* Kernel oops after increasing max number of mac addresses of a mlx5 VF [rhel-9.8.z] (JIRA:Rocky Linux-213036)&lt;/p&gt;
&lt;p&gt;* Rocky Linux9.4 - s390/pkey: Check length in pkey_pckmo handler implementation [rhel-9.8.z] (JIRA:Rocky Linux-215578)&lt;/p&gt;
&lt;p&gt;* Rocky Linux9.4 - s390/pkey: Check length in PKEY_VERIFYPROTK ioctl [rhel-9.8.z] (JIRA:Rocky Linux-215580)&lt;/p&gt;
&lt;p&gt;* cifs: periodic IO errors when rename races with lease break (JIRA:Rocky Linux-192999)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:53329</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-64531</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-64531</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 189 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: net: openvswitch: reject oversized nested action attrs Open vSwitch stores generated flow actions as nlattrs, whose nla_len field is u16. Commit a1e64addf3ff (&amp;#34;net: openvswitch: remove misbehaving actions length check&amp;#34;) allowed the total sw_flow_actions stream to grow beyond 64 KiB, which is valid, but also removed the last guard preventing a generated nested action attribute from exceeding U16_MAX. An oversized generated container can thus be closed with a truncated nla_len. A later dump or teardown then walks a structurally different stream than the one that was validated. In particular, an oversized nested CLONE/CT action may cause subsequent bytes in the generated stream to be interpreted as independent actions. Keep the larger total-action-stream behavior, but make nested action close reject generated containers that do not fit in nla_len, and return the error through all callers. For recursive SAMPLE, CLONE, DEC_TTL, and CHECK_PKT_LEN builders, trim resource-owning action-list tails in reverse construction order before discarding failed wrappers, so resources copied into the rejected tails are released before the wrappers are removed. Most failed outer wrappers are discarded by truncating actions_len after child resources have been released. CHECK_PKT_LEN also trims its parent after branch resources are gone. SET/TUNNEL close failures unwind their known tun_dst ownership directly, and SET_TO_MASKED has…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 189 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: net: openvswitch: reject oversized nested action attrs Open vSwitch stores generated flow actions as nlattrs, whose nla_len field is u16. Commit a1e64addf3ff (&amp;#34;net: openvswitch: remove misbehaving actions length check&amp;#34;) allowed the total sw_flow_actions stream to grow beyond 64 KiB, which is valid, but also removed the last guard preventing a generated nested action attribute from exceeding U16_MAX. An oversized generated container can thus be closed with a truncated nla_len. A later dump or teardown then walks a structurally different stream than the one that was validated. In particular, an oversized nested CLONE/CT action may cause subsequent bytes in the generated stream to be interpreted as independent actions. Keep the larger total-action-stream behavior, but make nested action close reject generated containers that do not fit in nla_len, and return the error through all callers. For recursive SAMPLE, CLONE, DEC_TTL, and CHECK_PKT_LEN builders, trim resource-owning action-list tails in reverse construction order before discarding failed wrappers, so resources copied into the rejected tails are released before the wrappers are removed. Most failed outer wrappers are discarded by truncating actions_len after child resources have been released. CHECK_PKT_LEN also trims its parent after branch resources are gone. SET/TUNNEL close failures unwind their known tun_dst ownership directly, and SET_TO_MASKED has…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-64531</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2527 — Linux Kernel: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2527</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um nicht näher spezifizierte Angriffe durchzuführen, dazu können DoS-Angriffe, die Offenlegung von Informationen, die Beschädigung des Speichers oder die Umgehung von Sicherheitsmaßnahmen gehören.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um nicht näher spezifizierte Angriffe durchzuführen, dazu können DoS-Angriffe, die Offenlegung von Informationen, die Beschädigung des Speichers oder die Umgehung von Sicherheitsmaßnahmen gehören.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2527</guid>
    </item>
  </channel>
</rss>
