<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 15:26:58 +0000</lastBuildDate>
    <item>
      <title>BELL-CVE-2026-68189</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-68189</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-68189</guid>
    </item>
    <item>
      <title>certfr-2026-avi-1069 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de Debian LTS. Elles permettent à un attaquant de p…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1069</link>
      <description>certfr-2026-avi-1069</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-1069</guid>
    </item>
    <item>
      <title>EUVD-2026-356123</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-356123</link>
      <description>EUVD-2026-356123</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-356123</guid>
    </item>
    <item>
      <title>fkie_cve-2026-68189</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-68189</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;Bluetooth: hci_sync: Protect UUID list traversal&lt;/p&gt;
&lt;p&gt;The hci_sync conversion moved class-of-device and EIR generation from an
HCI request built under hdev-&amp;gt;lock to asynchronous command sync work.
The worker holds hdev-&amp;gt;req_lock, but that lock does not serialize access
to hdev-&amp;gt;uuids against add_uuid() and remove_uuid(), which update the
list under hdev-&amp;gt;lock.&lt;/p&gt;
&lt;p&gt;The following interleaving can therefore occur:&lt;/p&gt;
&lt;p&gt;CPU0 (command sync work)       CPU1 (management socket)
  fetch uuid from the list
                                list_del(&amp;amp;uuid-&amp;gt;list)
                                kfree(uuid)
  read uuid-&amp;gt;size&lt;/p&gt;
&lt;p&gt;KASAN reports the resulting use-after-free:&lt;/p&gt;
&lt;p&gt;BUG: KASAN: slab-use-after-free in eir_create+0xb8f/0xee0
  Read of size 1 at addr ffff88810dbd8620 by task kworker/u17:0/87
  Workqueue: hci0 hci_cmd_sync_work
  Call Trace:
   eir_create+0xb8f/0xee0
   hci_update_eir_sync+0x1c0/0x330
   hci_cmd_sync_work+0x13c/0x290
   process_one_work+0x63a/0x1070
   worker_thread+0x45b/0xd10&lt;/p&gt;
&lt;p&gt;Allocated by task 86:
   __kasan_kmalloc+0x8f/0xa0
   add_uuid+0x18a/0x4b0
   hci_sock_sendmsg+0x1033/0x1ea0&lt;/p&gt;
&lt;p&gt;Freed by task 92:
   __kasan_slab_free+0x43/0x70
   kfree+0x131/0x3c0
   remove_uuid+0x25e/0x560
   hci_sock_sendmsg+0x1033/0x1ea0&lt;/p&gt;
&lt;p&gt;Hold hdev-&amp;gt;lock while generating and committing the class-of-device and
EIR snapshots.  Release it before sending an HCI command, so controller
waits do not happen under the device lock.  This p…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;Bluetooth: hci_sync: Protect UUID list traversal&lt;/p&gt;
&lt;p&gt;The hci_sync conversion moved class-of-device and EIR generation from an
HCI request built under hdev-&amp;gt;lock to asynchronous command sync work.
The worker holds hdev-&amp;gt;req_lock, but that lock does not serialize access
to hdev-&amp;gt;uuids against add_uuid() and remove_uuid(), which update the
list under hdev-&amp;gt;lock.&lt;/p&gt;
&lt;p&gt;The following interleaving can therefore occur:&lt;/p&gt;
&lt;p&gt;CPU0 (command sync work)       CPU1 (management socket)
  fetch uuid from the list
                                list_del(&amp;amp;uuid-&amp;gt;list)
                                kfree(uuid)
  read uuid-&amp;gt;size&lt;/p&gt;
&lt;p&gt;KASAN reports the resulting use-after-free:&lt;/p&gt;
&lt;p&gt;BUG: KASAN: slab-use-after-free in eir_create+0xb8f/0xee0
  Read of size 1 at addr ffff88810dbd8620 by task kworker/u17:0/87
  Workqueue: hci0 hci_cmd_sync_work
  Call Trace:
   eir_create+0xb8f/0xee0
   hci_update_eir_sync+0x1c0/0x330
   hci_cmd_sync_work+0x13c/0x290
   process_one_work+0x63a/0x1070
   worker_thread+0x45b/0xd10&lt;/p&gt;
&lt;p&gt;Allocated by task 86:
   __kasan_kmalloc+0x8f/0xa0
   add_uuid+0x18a/0x4b0
   hci_sock_sendmsg+0x1033/0x1ea0&lt;/p&gt;
&lt;p&gt;Freed by task 92:
   __kasan_slab_free+0x43/0x70
   kfree+0x131/0x3c0
   remove_uuid+0x25e/0x560
   hci_sock_sendmsg+0x1033/0x1ea0&lt;/p&gt;
&lt;p&gt;Hold hdev-&amp;gt;lock while generating and committing the class-of-device and
EIR snapshots.  Release it before sending an HCI command, so controller
waits do not happen under the device lock.  This p…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-68189</guid>
    </item>
    <item>
      <title>GHSA-jprq-4ghp-p3f9</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-jprq-4ghp-p3f9</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;Bluetooth: hci_sync: Protect UUID list traversal&lt;/p&gt;
&lt;p&gt;The hci_sync conversion moved class-of-device and EIR generation from an
HCI request built under hdev-&amp;gt;lock to asynchronous command sync work.
The worker holds hdev-&amp;gt;req_lock, but that lock does not serialize access
to hdev-&amp;gt;uuids against add_uuid() and remove_uuid(), which update the
list under hdev-&amp;gt;lock.&lt;/p&gt;
&lt;p&gt;The following interleaving can therefore occur:&lt;/p&gt;
&lt;p&gt;CPU0 (command sync work)       CPU1 (management socket)
  fetch uuid from the list
                                list_del(&amp;amp;uuid-&amp;gt;list)
                                kfree(uuid)
  read uuid-&amp;gt;size&lt;/p&gt;
&lt;p&gt;KASAN reports the resulting use-after-free:&lt;/p&gt;
&lt;p&gt;BUG: KASAN: slab-use-after-free in eir_create+0xb8f/0xee0
  Read of size 1 at addr ffff88810dbd8620 by task kworker/u17:0/87
  Workqueue: hci0 hci_cmd_sync_work
  Call Trace:
   eir_create+0xb8f/0xee0
   hci_update_eir_sync+0x1c0/0x330
   hci_cmd_sync_work+0x13c/0x290
   process_one_work+0x63a/0x1070
   worker_thread+0x45b/0xd10&lt;/p&gt;
&lt;p&gt;Allocated by task 86:
   __kasan_kmalloc+0x8f/0xa0
   add_uuid+0x18a/0x4b0
   hci_sock_sendmsg+0x1033/0x1ea0&lt;/p&gt;
&lt;p&gt;Freed by task 92:
   __kasan_slab_free+0x43/0x70
   kfree+0x131/0x3c0
   remove_uuid+0x25e/0x560
   hci_sock_sendmsg+0x1033/0x1ea0&lt;/p&gt;
&lt;p&gt;Hold hdev-&amp;gt;lock while generating and committing the class-of-device and
EIR snapshots.  Release it before sending an HCI command, so controller
waits do not happen under the device lock.  This p…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;Bluetooth: hci_sync: Protect UUID list traversal&lt;/p&gt;
&lt;p&gt;The hci_sync conversion moved class-of-device and EIR generation from an
HCI request built under hdev-&amp;gt;lock to asynchronous command sync work.
The worker holds hdev-&amp;gt;req_lock, but that lock does not serialize access
to hdev-&amp;gt;uuids against add_uuid() and remove_uuid(), which update the
list under hdev-&amp;gt;lock.&lt;/p&gt;
&lt;p&gt;The following interleaving can therefore occur:&lt;/p&gt;
&lt;p&gt;CPU0 (command sync work)       CPU1 (management socket)
  fetch uuid from the list
                                list_del(&amp;amp;uuid-&amp;gt;list)
                                kfree(uuid)
  read uuid-&amp;gt;size&lt;/p&gt;
&lt;p&gt;KASAN reports the resulting use-after-free:&lt;/p&gt;
&lt;p&gt;BUG: KASAN: slab-use-after-free in eir_create+0xb8f/0xee0
  Read of size 1 at addr ffff88810dbd8620 by task kworker/u17:0/87
  Workqueue: hci0 hci_cmd_sync_work
  Call Trace:
   eir_create+0xb8f/0xee0
   hci_update_eir_sync+0x1c0/0x330
   hci_cmd_sync_work+0x13c/0x290
   process_one_work+0x63a/0x1070
   worker_thread+0x45b/0xd10&lt;/p&gt;
&lt;p&gt;Allocated by task 86:
   __kasan_kmalloc+0x8f/0xa0
   add_uuid+0x18a/0x4b0
   hci_sock_sendmsg+0x1033/0x1ea0&lt;/p&gt;
&lt;p&gt;Freed by task 92:
   __kasan_slab_free+0x43/0x70
   kfree+0x131/0x3c0
   remove_uuid+0x25e/0x560
   hci_sock_sendmsg+0x1033/0x1ea0&lt;/p&gt;
&lt;p&gt;Hold hdev-&amp;gt;lock while generating and committing the class-of-device and
EIR snapshots.  Release it before sending an HCI command, so controller
waits do not happen under the device lock.  This p…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-jprq-4ghp-p3f9</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-68189 — Bluetooth: hci_sync: Protect UUID list traversal</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-68189</link>
      <description>msrc_CVE-2026-68189</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-68189</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:21910-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:21910-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:21910-1</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:23477-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:23477-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:23477-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-68189</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-68189</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 154 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sync: Protect UUID list traversal The hci_sync conversion moved class-of-device and EIR generation from an HCI request built under hdev-&amp;gt;lock to asynchronous command sync work. The worker holds hdev-&amp;gt;req_lock, but that lock does not serialize access to hdev-&amp;gt;uuids against add_uuid() and remove_uuid(), which update the list under hdev-&amp;gt;lock. The following interleaving can therefore occur:   CPU0 (command sync work)       CPU1 (management socket)   fetch uuid from the list                                 list_del(&amp;amp;uuid-&amp;gt;list)                                 kfree(uuid)   read uuid-&amp;gt;size KASAN reports the resulting use-after-free:   BUG: KASAN: slab-use-after-free in eir_create+0xb8f/0xee0   Read of size 1 at addr ffff88810dbd8620 by task kworker/u17:0/87   Workqueue: hci0 hci_cmd_sync_work   Call Trace:    eir_create+0xb8f/0xee0    hci_update_eir_sync+0x1c0/0x330    hci_cmd_sync_work+0x13c/0x290    process_one_work+0x63a/0x1070    worker_thread+0x45b/0xd10   Allocated by task 86:    __kasan_kmalloc+0x8f/0xa0    add_uuid+0x18a/0x4b0    hci_sock_sendmsg+0x1033/0x1ea0   Freed by task 92:    __kasan_slab_free+0x43/0x70    kfree+0x131/0x3c0    remove_uuid+0x25e/0x560    hci_sock_sendmsg+0x1033/0x1ea0 Hold hdev-&amp;gt;lock while generating and committing the class-of-device and EIR snapshots.  Release it before sending an HCI command, so controller waits do not happen under the device lock.  This protects a…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 154 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sync: Protect UUID list traversal The hci_sync conversion moved class-of-device and EIR generation from an HCI request built under hdev-&amp;gt;lock to asynchronous command sync work. The worker holds hdev-&amp;gt;req_lock, but that lock does not serialize access to hdev-&amp;gt;uuids against add_uuid() and remove_uuid(), which update the list under hdev-&amp;gt;lock. The following interleaving can therefore occur:   CPU0 (command sync work)       CPU1 (management socket)   fetch uuid from the list                                 list_del(&amp;amp;uuid-&amp;gt;list)                                 kfree(uuid)   read uuid-&amp;gt;size KASAN reports the resulting use-after-free:   BUG: KASAN: slab-use-after-free in eir_create+0xb8f/0xee0   Read of size 1 at addr ffff88810dbd8620 by task kworker/u17:0/87   Workqueue: hci0 hci_cmd_sync_work   Call Trace:    eir_create+0xb8f/0xee0    hci_update_eir_sync+0x1c0/0x330    hci_cmd_sync_work+0x13c/0x290    process_one_work+0x63a/0x1070    worker_thread+0x45b/0xd10   Allocated by task 86:    __kasan_kmalloc+0x8f/0xa0    add_uuid+0x18a/0x4b0    hci_sock_sendmsg+0x1033/0x1ea0   Freed by task 92:    __kasan_slab_free+0x43/0x70    kfree+0x131/0x3c0    remove_uuid+0x25e/0x560    hci_sock_sendmsg+0x1033/0x1ea0 Hold hdev-&amp;gt;lock while generating and committing the class-of-device and EIR snapshots.  Release it before sending an HCI command, so controller waits do not happen under the device lock.  This protects a…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-68189</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2730 — Linux Kernel: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2730</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen, darunter möglicherweise die Ausführung von beliebigem Code, die Ausweitung von Berechtigungen, die Offenlegung von Informationen, die Manipulation von Daten oder Denial-of-Service-Zustände.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen, darunter möglicherweise die Ausführung von beliebigem Code, die Ausweitung von Berechtigungen, die Offenlegung von Informationen, die Manipulation von Daten oder Denial-of-Service-Zustände.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2730</guid>
    </item>
  </channel>
</rss>
