<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 11:32:12 +0000</lastBuildDate>
    <item>
      <title>ALSA-2026:70459 — Important: kernel security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:70459</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: kernel, AlmaLinux:9: kernel-64k, AlmaLinux:9: kernel-64k-core, AlmaLinux:9: kernel-64k-debug, AlmaLinux:9: kernel-64k-debug-core, AlmaLinux:9: kernel-64k-debug-devel, AlmaLinux:9: kernel-64k-debug-devel-matched, AlmaLinux:9: kernel-64k-debug-modules, AlmaLinux:9: kernel-64k-debug-modules-core, AlmaLinux:9: kernel-64k-debug-modules-extra and 64 more&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg (CVE-2025-39964)
  * kernel: iommu/vt-d: Clear Present bit before tearing down PASID entry (CVE-2026-45894)
  * kernel: crypto: ccp - Fix a crash due to incorrect cleanup usage of kfree (CVE-2026-45959)
  * kernel: dm cache policy smq: fix missing locks in invalidating cache blocks (CVE-2026-53062)
  * kernel: keys: Pin request_key_auth payload in instantiate paths (CVE-2026-63823)
  * kernel: net/mlx5: Fix MCIA register buffer overflow on 32 dword reads (CVE-2026-68293)
  * kernel: Linux kernel: libceph null pointer dereference leads to denial of service (CVE-2026-68157)
  * kernel: Linux kernel Bluetooth RFCOMM: Denial of Service via use-after-free in set_termios (CVE-2026-68188)
  * kernel: libceph: refresh auth-&amp;gt;authorizer_buf{,_len} after authorizer update (CVE-2026-68156)
  * kernel: Linux kernel (libceph): Denial of Service due to malformed monitor maps (CVE-2026-68155)
  * kernel: Bluetooth: mgmt: hold reference for hci_conn in mgmt_pending_cmds (CVE-2026-68391)
  * kernel: net/mlx5e: macsec: fix use-after-free of metadata_dst on RX SC delete (CVE-2026-72072)
  * kernel: mm/hugetlb: fix list corruption in allocate_file_region_entries() (CVE-2026-74518)&lt;/p&gt;
&lt;p&gt;Bug Fix(es) and Enhancement(s):&lt;/p&gt;
&lt;p&gt;* [Intel 9.8 FEAT] ice: Driver Update [almalinux-9.8.z] (JIRA:AlmaLinux-213003)
  * AlmaLinux 9.8…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: kernel, AlmaLinux:9: kernel-64k, AlmaLinux:9: kernel-64k-core, AlmaLinux:9: kernel-64k-debug, AlmaLinux:9: kernel-64k-debug-core, AlmaLinux:9: kernel-64k-debug-devel, AlmaLinux:9: kernel-64k-debug-devel-matched, AlmaLinux:9: kernel-64k-debug-modules, AlmaLinux:9: kernel-64k-debug-modules-core, AlmaLinux:9: kernel-64k-debug-modules-extra and 64 more&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg (CVE-2025-39964)
  * kernel: iommu/vt-d: Clear Present bit before tearing down PASID entry (CVE-2026-45894)
  * kernel: crypto: ccp - Fix a crash due to incorrect cleanup usage of kfree (CVE-2026-45959)
  * kernel: dm cache policy smq: fix missing locks in invalidating cache blocks (CVE-2026-53062)
  * kernel: keys: Pin request_key_auth payload in instantiate paths (CVE-2026-63823)
  * kernel: net/mlx5: Fix MCIA register buffer overflow on 32 dword reads (CVE-2026-68293)
  * kernel: Linux kernel: libceph null pointer dereference leads to denial of service (CVE-2026-68157)
  * kernel: Linux kernel Bluetooth RFCOMM: Denial of Service via use-after-free in set_termios (CVE-2026-68188)
  * kernel: libceph: refresh auth-&amp;gt;authorizer_buf{,_len} after authorizer update (CVE-2026-68156)
  * kernel: Linux kernel (libceph): Denial of Service due to malformed monitor maps (CVE-2026-68155)
  * kernel: Bluetooth: mgmt: hold reference for hci_conn in mgmt_pending_cmds (CVE-2026-68391)
  * kernel: net/mlx5e: macsec: fix use-after-free of metadata_dst on RX SC delete (CVE-2026-72072)
  * kernel: mm/hugetlb: fix list corruption in allocate_file_region_entries() (CVE-2026-74518)&lt;/p&gt;
&lt;p&gt;Bug Fix(es) and Enhancement(s):&lt;/p&gt;
&lt;p&gt;* [Intel 9.8 FEAT] ice: Driver Update [almalinux-9.8.z] (JIRA:AlmaLinux-213003)
  * AlmaLinux 9.8…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:70459</guid>
    </item>
    <item>
      <title>BELL-CVE-2026-68156</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-68156</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-68156</guid>
    </item>
    <item>
      <title>certfr-2026-avi-1069 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de Debian LTS. Elles permettent à un attaquant de p…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1069</link>
      <description>certfr-2026-avi-1069</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-1069</guid>
    </item>
    <item>
      <title>EUVD-2026-356060</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-356060</link>
      <description>EUVD-2026-356060</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-356060</guid>
    </item>
    <item>
      <title>fkie_cve-2026-68156</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-68156</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;libceph: refresh auth-&amp;gt;authorizer_buf{,_len} after authorizer update&lt;/p&gt;
&lt;p&gt;ceph_x_create_authorizer() caches au-&amp;gt;buf-&amp;gt;vec.iov_base and
au-&amp;gt;buf-&amp;gt;vec.iov_len in struct ceph_auth_handshake.  These
cached values are then used by the messenger connect code when
sending the authorizer.&lt;/p&gt;
&lt;p&gt;ceph_x_update_authorizer() can rebuild the authorizer when a newer
service ticket is available.  If the rebuilt authorizer no longer
fits in the existing buffer, ceph_x_build_authorizer() drops its
reference to au-&amp;gt;buf and allocates a new one.  If this is the final
reference, ceph_buffer_put() frees the old ceph_buffer and its
vec.iov_base, but auth-&amp;gt;authorizer_buf still points at that freed
memory.&lt;/p&gt;
&lt;p&gt;A subsequent msgr1 reconnect can therefore queue the stale pointer
and trigger a KASAN slab-use-after-free in _copy_from_iter() while
tcp_sendmsg() copies the authorizer.&lt;/p&gt;
&lt;p&gt;Refresh auth-&amp;gt;authorizer_buf and auth-&amp;gt;authorizer_buf_len after a
successful authorizer rebuild so the messenger sends the current
buffer.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;libceph: refresh auth-&amp;gt;authorizer_buf{,_len} after authorizer update&lt;/p&gt;
&lt;p&gt;ceph_x_create_authorizer() caches au-&amp;gt;buf-&amp;gt;vec.iov_base and
au-&amp;gt;buf-&amp;gt;vec.iov_len in struct ceph_auth_handshake.  These
cached values are then used by the messenger connect code when
sending the authorizer.&lt;/p&gt;
&lt;p&gt;ceph_x_update_authorizer() can rebuild the authorizer when a newer
service ticket is available.  If the rebuilt authorizer no longer
fits in the existing buffer, ceph_x_build_authorizer() drops its
reference to au-&amp;gt;buf and allocates a new one.  If this is the final
reference, ceph_buffer_put() frees the old ceph_buffer and its
vec.iov_base, but auth-&amp;gt;authorizer_buf still points at that freed
memory.&lt;/p&gt;
&lt;p&gt;A subsequent msgr1 reconnect can therefore queue the stale pointer
and trigger a KASAN slab-use-after-free in _copy_from_iter() while
tcp_sendmsg() copies the authorizer.&lt;/p&gt;
&lt;p&gt;Refresh auth-&amp;gt;authorizer_buf and auth-&amp;gt;authorizer_buf_len after a
successful authorizer rebuild so the messenger sends the current
buffer.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-68156</guid>
    </item>
    <item>
      <title>GHSA-rf74-56p2-8jqj</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-rf74-56p2-8jqj</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;libceph: refresh auth-&amp;gt;authorizer_buf{,_len} after authorizer update&lt;/p&gt;
&lt;p&gt;ceph_x_create_authorizer() caches au-&amp;gt;buf-&amp;gt;vec.iov_base and
au-&amp;gt;buf-&amp;gt;vec.iov_len in struct ceph_auth_handshake.  These
cached values are then used by the messenger connect code when
sending the authorizer.&lt;/p&gt;
&lt;p&gt;ceph_x_update_authorizer() can rebuild the authorizer when a newer
service ticket is available.  If the rebuilt authorizer no longer
fits in the existing buffer, ceph_x_build_authorizer() drops its
reference to au-&amp;gt;buf and allocates a new one.  If this is the final
reference, ceph_buffer_put() frees the old ceph_buffer and its
vec.iov_base, but auth-&amp;gt;authorizer_buf still points at that freed
memory.&lt;/p&gt;
&lt;p&gt;A subsequent msgr1 reconnect can therefore queue the stale pointer
and trigger a KASAN slab-use-after-free in _copy_from_iter() while
tcp_sendmsg() copies the authorizer.&lt;/p&gt;
&lt;p&gt;Refresh auth-&amp;gt;authorizer_buf and auth-&amp;gt;authorizer_buf_len after a
successful authorizer rebuild so the messenger sends the current
buffer.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;libceph: refresh auth-&amp;gt;authorizer_buf{,_len} after authorizer update&lt;/p&gt;
&lt;p&gt;ceph_x_create_authorizer() caches au-&amp;gt;buf-&amp;gt;vec.iov_base and
au-&amp;gt;buf-&amp;gt;vec.iov_len in struct ceph_auth_handshake.  These
cached values are then used by the messenger connect code when
sending the authorizer.&lt;/p&gt;
&lt;p&gt;ceph_x_update_authorizer() can rebuild the authorizer when a newer
service ticket is available.  If the rebuilt authorizer no longer
fits in the existing buffer, ceph_x_build_authorizer() drops its
reference to au-&amp;gt;buf and allocates a new one.  If this is the final
reference, ceph_buffer_put() frees the old ceph_buffer and its
vec.iov_base, but auth-&amp;gt;authorizer_buf still points at that freed
memory.&lt;/p&gt;
&lt;p&gt;A subsequent msgr1 reconnect can therefore queue the stale pointer
and trigger a KASAN slab-use-after-free in _copy_from_iter() while
tcp_sendmsg() copies the authorizer.&lt;/p&gt;
&lt;p&gt;Refresh auth-&amp;gt;authorizer_buf and auth-&amp;gt;authorizer_buf_len after a
successful authorizer rebuild so the messenger sends the current
buffer.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-rf74-56p2-8jqj</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-68156 — libceph: refresh auth-&gt;authorizer_buf{,_len} after authorizer update</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-68156</link>
      <description>msrc_CVE-2026-68156</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-68156</guid>
    </item>
    <item>
      <title>OESA-2026-3701 — kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-3701</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP4: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;staging: greybus: uart: fix tty use after free&lt;/p&gt;
&lt;p&gt;User space can hold a tty open indefinitely and tty drivers must not
release the underlying structures until the last user is gone.&lt;/p&gt;
&lt;p&gt;Switch to using the tty-port reference counter to manage the life time
of the greybus tty state to avoid use after free after a disconnect.(CVE-2021-47358)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;net: sched: avoid qdisc_reset_all_tx_gt() vs dequeue race for lockless qdiscs&lt;/p&gt;
&lt;p&gt;When shrinking the number of real tx queues,
netif_set_real_num_tx_queues() calls qdisc_reset_all_tx_gt() to flush
qdiscs for queues which will no longer be used.&lt;/p&gt;
&lt;p&gt;qdisc_reset_all_tx_gt() currently serializes qdisc_reset() with
qdisc_lock(). However, for lockless qdiscs, the dequeue path is
serialized by qdisc_run_begin/end() using qdisc-&amp;amp;gt;seqlock instead, so
qdisc_reset() can run concurrently with __qdisc_run() and free skbs
while they are still being dequeued, leading to UAF.&lt;/p&gt;
&lt;p&gt;This can easily be reproduced on e.g. virtio-net by imposing heavy
traffic while frequently changing the number of queue pairs:&lt;/p&gt;
&lt;p&gt;iperf3 -ub0 -c $peer -t 0 &amp;amp;amp;
  while :; do
    ethtool -L eth0 combined 1
    ethtool -L eth0 combined 2
  done&lt;/p&gt;
&lt;p&gt;With KASAN enabled, this leads to reports like:&lt;/p&gt;
&lt;p&gt;BUG: KASAN: slab-use-after-free in __qdisc_run+0x133f/0x1760
  ...
  Call Trace:
   &amp;amp;l…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP4: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;staging: greybus: uart: fix tty use after free&lt;/p&gt;
&lt;p&gt;User space can hold a tty open indefinitely and tty drivers must not
release the underlying structures until the last user is gone.&lt;/p&gt;
&lt;p&gt;Switch to using the tty-port reference counter to manage the life time
of the greybus tty state to avoid use after free after a disconnect.(CVE-2021-47358)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;net: sched: avoid qdisc_reset_all_tx_gt() vs dequeue race for lockless qdiscs&lt;/p&gt;
&lt;p&gt;When shrinking the number of real tx queues,
netif_set_real_num_tx_queues() calls qdisc_reset_all_tx_gt() to flush
qdiscs for queues which will no longer be used.&lt;/p&gt;
&lt;p&gt;qdisc_reset_all_tx_gt() currently serializes qdisc_reset() with
qdisc_lock(). However, for lockless qdiscs, the dequeue path is
serialized by qdisc_run_begin/end() using qdisc-&amp;amp;gt;seqlock instead, so
qdisc_reset() can run concurrently with __qdisc_run() and free skbs
while they are still being dequeued, leading to UAF.&lt;/p&gt;
&lt;p&gt;This can easily be reproduced on e.g. virtio-net by imposing heavy
traffic while frequently changing the number of queue pairs:&lt;/p&gt;
&lt;p&gt;iperf3 -ub0 -c $peer -t 0 &amp;amp;amp;
  while :; do
    ethtool -L eth0 combined 1
    ethtool -L eth0 combined 2
  done&lt;/p&gt;
&lt;p&gt;With KASAN enabled, this leads to reports like:&lt;/p&gt;
&lt;p&gt;BUG: KASAN: slab-use-after-free in __qdisc_run+0x133f/0x1760
  ...
  Call Trace:
   &amp;amp;l…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-3701</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:21910-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:21910-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:21910-1</guid>
    </item>
    <item>
      <title>RHSA-2026:72467 — Red Hat Security Advisory: kernel-rt security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:72467</link>
      <description>&lt;p&gt;kernel: fbcon: Set fb_display[i]-&amp;gt;mode to NULL when the mode is released kernel: ext4: fix e4b bitmap inconsistency reports kernel: drm/amdgpu/vcn4: Prevent OOB reads when parsing dec msg kernel: drm/amdgpu/vcn4: Prevent OOB reads when parsing IB kernel: drm/amdgpu/vcn3: Prevent OOB reads when parsing dec msg kernel: arm64: tlb: Flush walk cache when unsharing PMD tables kernel: net: mana: Fix TOCTOU double-fetch of hwc_msg_id from DMA buffer kernel: perf/core: Detach event groups during remove_on_exec kernel: Linux kernel (libceph): Denial of Service due to malformed monitor maps kernel: libceph: refresh auth-&amp;gt;authorizer_buf{,_len} after authorizer update kernel: Linux kernel: libceph stack out-of-bounds write via crafted OSDMap kernel: drm/amdgpu: Fix context pstate override handling kernel: perf: Reject exited events as group leaders&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;kernel: fbcon: Set fb_display[i]-&amp;gt;mode to NULL when the mode is released kernel: ext4: fix e4b bitmap inconsistency reports kernel: drm/amdgpu/vcn4: Prevent OOB reads when parsing dec msg kernel: drm/amdgpu/vcn4: Prevent OOB reads when parsing IB kernel: drm/amdgpu/vcn3: Prevent OOB reads when parsing dec msg kernel: arm64: tlb: Flush walk cache when unsharing PMD tables kernel: net: mana: Fix TOCTOU double-fetch of hwc_msg_id from DMA buffer kernel: perf/core: Detach event groups during remove_on_exec kernel: Linux kernel (libceph): Denial of Service due to malformed monitor maps kernel: libceph: refresh auth-&amp;gt;authorizer_buf{,_len} after authorizer update kernel: Linux kernel: libceph stack out-of-bounds write via crafted OSDMap kernel: drm/amdgpu: Fix context pstate override handling kernel: perf: Reject exited events as group leaders&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:72467</guid>
    </item>
    <item>
      <title>RLSA-2026:70459 — Important: kernel security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:70459</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:9: kernel&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg (CVE-2025-39964)&lt;/p&gt;
&lt;p&gt;* kernel: iommu/vt-d: Clear Present bit before tearing down PASID entry (CVE-2026-45894)&lt;/p&gt;
&lt;p&gt;* kernel: crypto: ccp - Fix a crash due to incorrect cleanup usage of kfree (CVE-2026-45959)&lt;/p&gt;
&lt;p&gt;* kernel: dm cache policy smq: fix missing locks in invalidating cache blocks (CVE-2026-53062)&lt;/p&gt;
&lt;p&gt;* kernel: keys: Pin request_key_auth payload in instantiate paths (CVE-2026-63823)&lt;/p&gt;
&lt;p&gt;* kernel: net/mlx5: Fix MCIA register buffer overflow on 32 dword reads (CVE-2026-68293)&lt;/p&gt;
&lt;p&gt;* kernel: Linux kernel: libceph null pointer dereference leads to denial of service (CVE-2026-68157)&lt;/p&gt;
&lt;p&gt;* kernel: Linux kernel Bluetooth RFCOMM: Denial of Service via use-after-free in set_termios (CVE-2026-68188)&lt;/p&gt;
&lt;p&gt;* kernel: libceph: refresh auth-&amp;gt;authorizer_buf{,_len} after authorizer update (CVE-2026-68156)&lt;/p&gt;
&lt;p&gt;* kernel: Linux kernel (libceph): Denial of Service due to malformed monitor maps (CVE-2026-68155)&lt;/p&gt;
&lt;p&gt;* kernel: Bluetooth: mgmt: hold reference for hci_conn in mgmt_pending_cmds (CVE-2026-68391)&lt;/p&gt;
&lt;p&gt;* kernel: net/mlx5e: macsec: fix use-after-free of metadata_dst on RX SC delete (CVE-2026-72072)&lt;/p&gt;
&lt;p&gt;* kernel: mm/hugetlb: fix list corruption in allocate_file_region_entries() (CVE-2026-74518)&lt;/p&gt;
&lt;p&gt;Bug Fix(es) and Enhancement(s):&lt;/p&gt;
&lt;p&gt;* [Intel 9.8 FEAT] ice: Driver Update [rhel-9.8.z] (JIRA:Rocky Linux-213003)&lt;/p&gt;
&lt;p&gt;* Rocky Linux 9.8: Multiuser Kerberized DF…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:9: kernel&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg (CVE-2025-39964)&lt;/p&gt;
&lt;p&gt;* kernel: iommu/vt-d: Clear Present bit before tearing down PASID entry (CVE-2026-45894)&lt;/p&gt;
&lt;p&gt;* kernel: crypto: ccp - Fix a crash due to incorrect cleanup usage of kfree (CVE-2026-45959)&lt;/p&gt;
&lt;p&gt;* kernel: dm cache policy smq: fix missing locks in invalidating cache blocks (CVE-2026-53062)&lt;/p&gt;
&lt;p&gt;* kernel: keys: Pin request_key_auth payload in instantiate paths (CVE-2026-63823)&lt;/p&gt;
&lt;p&gt;* kernel: net/mlx5: Fix MCIA register buffer overflow on 32 dword reads (CVE-2026-68293)&lt;/p&gt;
&lt;p&gt;* kernel: Linux kernel: libceph null pointer dereference leads to denial of service (CVE-2026-68157)&lt;/p&gt;
&lt;p&gt;* kernel: Linux kernel Bluetooth RFCOMM: Denial of Service via use-after-free in set_termios (CVE-2026-68188)&lt;/p&gt;
&lt;p&gt;* kernel: libceph: refresh auth-&amp;gt;authorizer_buf{,_len} after authorizer update (CVE-2026-68156)&lt;/p&gt;
&lt;p&gt;* kernel: Linux kernel (libceph): Denial of Service due to malformed monitor maps (CVE-2026-68155)&lt;/p&gt;
&lt;p&gt;* kernel: Bluetooth: mgmt: hold reference for hci_conn in mgmt_pending_cmds (CVE-2026-68391)&lt;/p&gt;
&lt;p&gt;* kernel: net/mlx5e: macsec: fix use-after-free of metadata_dst on RX SC delete (CVE-2026-72072)&lt;/p&gt;
&lt;p&gt;* kernel: mm/hugetlb: fix list corruption in allocate_file_region_entries() (CVE-2026-74518)&lt;/p&gt;
&lt;p&gt;Bug Fix(es) and Enhancement(s):&lt;/p&gt;
&lt;p&gt;* [Intel 9.8 FEAT] ice: Driver Update [rhel-9.8.z] (JIRA:Rocky Linux-213003)&lt;/p&gt;
&lt;p&gt;* Rocky Linux 9.8: Multiuser Kerberized DF…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:70459</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:23477-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:23477-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:23477-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-68156</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-68156</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux, Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe and 246 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: libceph: refresh auth-&amp;gt;authorizer_buf{,_len} after authorizer update ceph_x_create_authorizer() caches au-&amp;gt;buf-&amp;gt;vec.iov_base and au-&amp;gt;buf-&amp;gt;vec.iov_len in struct ceph_auth_handshake.  These cached values are then used by the messenger connect code when sending the authorizer. ceph_x_update_authorizer() can rebuild the authorizer when a newer service ticket is available.  If the rebuilt authorizer no longer fits in the existing buffer, ceph_x_build_authorizer() drops its reference to au-&amp;gt;buf and allocates a new one.  If this is the final reference, ceph_buffer_put() frees the old ceph_buffer and its vec.iov_base, but auth-&amp;gt;authorizer_buf still points at that freed memory. A subsequent msgr1 reconnect can therefore queue the stale pointer and trigger a KASAN slab-use-after-free in _copy_from_iter() while tcp_sendmsg() copies the authorizer. Refresh auth-&amp;gt;authorizer_buf and auth-&amp;gt;authorizer_buf_len after a successful authorizer rebuild so the messenger sends the current buffer.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux, Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe and 246 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: libceph: refresh auth-&amp;gt;authorizer_buf{,_len} after authorizer update ceph_x_create_authorizer() caches au-&amp;gt;buf-&amp;gt;vec.iov_base and au-&amp;gt;buf-&amp;gt;vec.iov_len in struct ceph_auth_handshake.  These cached values are then used by the messenger connect code when sending the authorizer. ceph_x_update_authorizer() can rebuild the authorizer when a newer service ticket is available.  If the rebuilt authorizer no longer fits in the existing buffer, ceph_x_build_authorizer() drops its reference to au-&amp;gt;buf and allocates a new one.  If this is the final reference, ceph_buffer_put() frees the old ceph_buffer and its vec.iov_base, but auth-&amp;gt;authorizer_buf still points at that freed memory. A subsequent msgr1 reconnect can therefore queue the stale pointer and trigger a KASAN slab-use-after-free in _copy_from_iter() while tcp_sendmsg() copies the authorizer. Refresh auth-&amp;gt;authorizer_buf and auth-&amp;gt;authorizer_buf_len after a successful authorizer rebuild so the messenger sends the current buffer.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-68156</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2730 — Linux Kernel: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2730</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen, darunter möglicherweise die Ausführung von beliebigem Code, die Ausweitung von Berechtigungen, die Offenlegung von Informationen, die Manipulation von Daten oder Denial-of-Service-Zustände.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen, darunter möglicherweise die Ausführung von beliebigem Code, die Ausweitung von Berechtigungen, die Offenlegung von Informationen, die Manipulation von Daten oder Denial-of-Service-Zustände.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2730</guid>
    </item>
  </channel>
</rss>
