<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 15:09:11 +0000</lastBuildDate>
    <item>
      <title>BELL-CVE-2026-68197</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-68197</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-68197</guid>
    </item>
    <item>
      <title>certfr-2026-avi-1069 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de Debian LTS. Elles permettent à un attaquant de p…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1069</link>
      <description>certfr-2026-avi-1069</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-1069</guid>
    </item>
    <item>
      <title>EUVD-2026-356129</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-356129</link>
      <description>EUVD-2026-356129</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-356129</guid>
    </item>
    <item>
      <title>fkie_cve-2026-68197</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-68197</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;wifi: mwifiex: fix NULL dereference when the AP has HT-cap but no HT-oper&lt;/p&gt;
&lt;p&gt;mwifiex_tdls_add_ht_oper() gates its follow-the-AP-bandwidth path on
bss_desc-&amp;gt;bcn_ht_cap being present, but then dereferences a different
pointer, bss_desc-&amp;gt;bcn_ht_oper:&lt;/p&gt;
&lt;p&gt;if (ISSUPP_CHANWIDTH40(priv-&amp;gt;adapter-&amp;gt;hw_dot_11n_dev_cap) &amp;amp;&amp;amp;
	    bss_desc-&amp;gt;bcn_ht_cap &amp;amp;&amp;amp;
	    ISALLOWED_CHANWIDTH40(bss_desc-&amp;gt;bcn_ht_oper-&amp;gt;ht_param))&lt;/p&gt;
&lt;p&gt;bcn_ht_cap and bcn_ht_oper are populated independently while parsing the
associated AP&amp;#39;s beacon in mwifiex_update_bss_desc_with_ie(): an AP that
advertises an HT Capabilities element but no HT Operation element leaves
bcn_ht_cap non-NULL and bcn_ht_oper NULL. Setting up a TDLS link to a
peer while associated to such an AP then dereferences the NULL
bcn_ht_oper and crashes the kernel. Every other bcn_ht_oper user in the
driver NULL-checks it first.&lt;/p&gt;
&lt;p&gt;Guard on the pointer that is actually dereferenced.&lt;/p&gt;
&lt;p&gt;Found by 0sec automated security-research tooling (https://0sec.ai).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;wifi: mwifiex: fix NULL dereference when the AP has HT-cap but no HT-oper&lt;/p&gt;
&lt;p&gt;mwifiex_tdls_add_ht_oper() gates its follow-the-AP-bandwidth path on
bss_desc-&amp;gt;bcn_ht_cap being present, but then dereferences a different
pointer, bss_desc-&amp;gt;bcn_ht_oper:&lt;/p&gt;
&lt;p&gt;if (ISSUPP_CHANWIDTH40(priv-&amp;gt;adapter-&amp;gt;hw_dot_11n_dev_cap) &amp;amp;&amp;amp;
	    bss_desc-&amp;gt;bcn_ht_cap &amp;amp;&amp;amp;
	    ISALLOWED_CHANWIDTH40(bss_desc-&amp;gt;bcn_ht_oper-&amp;gt;ht_param))&lt;/p&gt;
&lt;p&gt;bcn_ht_cap and bcn_ht_oper are populated independently while parsing the
associated AP&amp;#39;s beacon in mwifiex_update_bss_desc_with_ie(): an AP that
advertises an HT Capabilities element but no HT Operation element leaves
bcn_ht_cap non-NULL and bcn_ht_oper NULL. Setting up a TDLS link to a
peer while associated to such an AP then dereferences the NULL
bcn_ht_oper and crashes the kernel. Every other bcn_ht_oper user in the
driver NULL-checks it first.&lt;/p&gt;
&lt;p&gt;Guard on the pointer that is actually dereferenced.&lt;/p&gt;
&lt;p&gt;Found by 0sec automated security-research tooling (https://0sec.ai).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-68197</guid>
    </item>
    <item>
      <title>GHSA-fw9r-2mhq-c5mq</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-fw9r-2mhq-c5mq</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;wifi: mwifiex: fix NULL dereference when the AP has HT-cap but no HT-oper&lt;/p&gt;
&lt;p&gt;mwifiex_tdls_add_ht_oper() gates its follow-the-AP-bandwidth path on
bss_desc-&amp;gt;bcn_ht_cap being present, but then dereferences a different
pointer, bss_desc-&amp;gt;bcn_ht_oper:&lt;/p&gt;
&lt;p&gt;if (ISSUPP_CHANWIDTH40(priv-&amp;gt;adapter-&amp;gt;hw_dot_11n_dev_cap) &amp;amp;&amp;amp;
	    bss_desc-&amp;gt;bcn_ht_cap &amp;amp;&amp;amp;
	    ISALLOWED_CHANWIDTH40(bss_desc-&amp;gt;bcn_ht_oper-&amp;gt;ht_param))&lt;/p&gt;
&lt;p&gt;bcn_ht_cap and bcn_ht_oper are populated independently while parsing the
associated AP&amp;#39;s beacon in mwifiex_update_bss_desc_with_ie(): an AP that
advertises an HT Capabilities element but no HT Operation element leaves
bcn_ht_cap non-NULL and bcn_ht_oper NULL. Setting up a TDLS link to a
peer while associated to such an AP then dereferences the NULL
bcn_ht_oper and crashes the kernel. Every other bcn_ht_oper user in the
driver NULL-checks it first.&lt;/p&gt;
&lt;p&gt;Guard on the pointer that is actually dereferenced.&lt;/p&gt;
&lt;p&gt;Found by 0sec automated security-research tooling (https://0sec.ai).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;wifi: mwifiex: fix NULL dereference when the AP has HT-cap but no HT-oper&lt;/p&gt;
&lt;p&gt;mwifiex_tdls_add_ht_oper() gates its follow-the-AP-bandwidth path on
bss_desc-&amp;gt;bcn_ht_cap being present, but then dereferences a different
pointer, bss_desc-&amp;gt;bcn_ht_oper:&lt;/p&gt;
&lt;p&gt;if (ISSUPP_CHANWIDTH40(priv-&amp;gt;adapter-&amp;gt;hw_dot_11n_dev_cap) &amp;amp;&amp;amp;
	    bss_desc-&amp;gt;bcn_ht_cap &amp;amp;&amp;amp;
	    ISALLOWED_CHANWIDTH40(bss_desc-&amp;gt;bcn_ht_oper-&amp;gt;ht_param))&lt;/p&gt;
&lt;p&gt;bcn_ht_cap and bcn_ht_oper are populated independently while parsing the
associated AP&amp;#39;s beacon in mwifiex_update_bss_desc_with_ie(): an AP that
advertises an HT Capabilities element but no HT Operation element leaves
bcn_ht_cap non-NULL and bcn_ht_oper NULL. Setting up a TDLS link to a
peer while associated to such an AP then dereferences the NULL
bcn_ht_oper and crashes the kernel. Every other bcn_ht_oper user in the
driver NULL-checks it first.&lt;/p&gt;
&lt;p&gt;Guard on the pointer that is actually dereferenced.&lt;/p&gt;
&lt;p&gt;Found by 0sec automated security-research tooling (https://0sec.ai).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-fw9r-2mhq-c5mq</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-68197 — wifi: mwifiex: fix NULL dereference when the AP has HT-cap but no HT-oper</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-68197</link>
      <description>msrc_CVE-2026-68197</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-68197</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:21910-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:21910-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:21910-1</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:23477-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:23477-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:23477-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-68197</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-68197</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe, Ubuntu:16.04:LTS: linux-hwe-edge and 245 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: wifi: mwifiex: fix NULL dereference when the AP has HT-cap but no HT-oper mwifiex_tdls_add_ht_oper() gates its follow-the-AP-bandwidth path on bss_desc-&amp;gt;bcn_ht_cap being present, but then dereferences a different pointer, bss_desc-&amp;gt;bcn_ht_oper: 	if (ISSUPP_CHANWIDTH40(priv-&amp;gt;adapter-&amp;gt;hw_dot_11n_dev_cap) &amp;amp;&amp;amp; 	    bss_desc-&amp;gt;bcn_ht_cap &amp;amp;&amp;amp; 	    ISALLOWED_CHANWIDTH40(bss_desc-&amp;gt;bcn_ht_oper-&amp;gt;ht_param)) bcn_ht_cap and bcn_ht_oper are populated independently while parsing the associated AP&amp;#39;s beacon in mwifiex_update_bss_desc_with_ie(): an AP that advertises an HT Capabilities element but no HT Operation element leaves bcn_ht_cap non-NULL and bcn_ht_oper NULL. Setting up a TDLS link to a peer while associated to such an AP then dereferences the NULL bcn_ht_oper and crashes the kernel. Every other bcn_ht_oper user in the driver NULL-checks it first. Guard on the pointer that is actually dereferenced. Found by 0sec automated security-research tooling (https://0sec.ai).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe, Ubuntu:16.04:LTS: linux-hwe-edge and 245 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: wifi: mwifiex: fix NULL dereference when the AP has HT-cap but no HT-oper mwifiex_tdls_add_ht_oper() gates its follow-the-AP-bandwidth path on bss_desc-&amp;gt;bcn_ht_cap being present, but then dereferences a different pointer, bss_desc-&amp;gt;bcn_ht_oper: 	if (ISSUPP_CHANWIDTH40(priv-&amp;gt;adapter-&amp;gt;hw_dot_11n_dev_cap) &amp;amp;&amp;amp; 	    bss_desc-&amp;gt;bcn_ht_cap &amp;amp;&amp;amp; 	    ISALLOWED_CHANWIDTH40(bss_desc-&amp;gt;bcn_ht_oper-&amp;gt;ht_param)) bcn_ht_cap and bcn_ht_oper are populated independently while parsing the associated AP&amp;#39;s beacon in mwifiex_update_bss_desc_with_ie(): an AP that advertises an HT Capabilities element but no HT Operation element leaves bcn_ht_cap non-NULL and bcn_ht_oper NULL. Setting up a TDLS link to a peer while associated to such an AP then dereferences the NULL bcn_ht_oper and crashes the kernel. Every other bcn_ht_oper user in the driver NULL-checks it first. Guard on the pointer that is actually dereferenced. Found by 0sec automated security-research tooling (https://0sec.ai).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-68197</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2730 — Linux Kernel: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2730</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen, darunter möglicherweise die Ausführung von beliebigem Code, die Ausweitung von Berechtigungen, die Offenlegung von Informationen, die Manipulation von Daten oder Denial-of-Service-Zustände.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen, darunter möglicherweise die Ausführung von beliebigem Code, die Ausweitung von Berechtigungen, die Offenlegung von Informationen, die Manipulation von Daten oder Denial-of-Service-Zustände.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2730</guid>
    </item>
  </channel>
</rss>
