<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 13:04:40 +0000</lastBuildDate>
    <item>
      <title>ALSA-2026:71700 — Important: kernel security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:71700</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: kernel, AlmaLinux:9: kernel-64k, AlmaLinux:9: kernel-64k-core, AlmaLinux:9: kernel-64k-debug, AlmaLinux:9: kernel-64k-debug-core, AlmaLinux:9: kernel-64k-debug-devel, AlmaLinux:9: kernel-64k-debug-devel-matched, AlmaLinux:9: kernel-64k-debug-modules, AlmaLinux:9: kernel-64k-debug-modules-core, AlmaLinux:9: kernel-64k-debug-modules-extra and 64 more&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: fbcon: Set fb_display[i]-&amp;gt;mode to NULL when the mode is released (CVE-2025-40323)
  * kernel: smb: smbdirect: introduce smbdirect_socket.recv_io.credits.available (CVE-2026-31539)
  * kernel: drm/amdgpu/vcn3: Prevent OOB reads when parsing dec msg (CVE-2026-46230)
  * kernel: drm/amdgpu/vcn4: Prevent OOB reads when parsing IB (CVE-2026-46204)
  * kernel: drm/amdgpu/vcn4: Prevent OOB reads when parsing dec msg (CVE-2026-46199)
  * kernel: drm/amdgpu/userq: fix access to stale wptr mapping (CVE-2026-46311)
  * kernel: netfilter: nf_queue: hold bridge skb-&amp;gt;dev while queued (CVE-2026-52912)
  * kernel: accel/ivpu: Add buffer overflow check in MS get_info_ioctl (CVE-2026-53203)
  * kernel: drm/xe/eustall: Fix drm_dev_put called before stream disable in close (CVE-2026-53290)
  * kernel: drm/virtio: use uninterruptible resv lock for plane updates (CVE-2026-64098)
  * kernel: Linux kernel: PPPoE memory corruption via stale pointer (CVE-2026-68121)
  * kernel: drm/amdgpu/vce: fix integer overflow in image size (CVE-2026-68108)
  * kernel: drm/amdkfd: fix 32-bit overflow in CWSR total size calculation (CVE-2026-68257)
  * kernel: drm/xe/rtp: Add RING_FORCE_TO_NONPRIV_DENY to OA whitelists (CVE-2026-68267)
  * kernel: drm/xe: Hold a dma-buf reference for imported BOs (CVE-2026-68266)
  * kernel: drm/amdgpu: Fix context pstate override handling (CVE-2026-68273)
  *…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: kernel, AlmaLinux:9: kernel-64k, AlmaLinux:9: kernel-64k-core, AlmaLinux:9: kernel-64k-debug, AlmaLinux:9: kernel-64k-debug-core, AlmaLinux:9: kernel-64k-debug-devel, AlmaLinux:9: kernel-64k-debug-devel-matched, AlmaLinux:9: kernel-64k-debug-modules, AlmaLinux:9: kernel-64k-debug-modules-core, AlmaLinux:9: kernel-64k-debug-modules-extra and 64 more&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: fbcon: Set fb_display[i]-&amp;gt;mode to NULL when the mode is released (CVE-2025-40323)
  * kernel: smb: smbdirect: introduce smbdirect_socket.recv_io.credits.available (CVE-2026-31539)
  * kernel: drm/amdgpu/vcn3: Prevent OOB reads when parsing dec msg (CVE-2026-46230)
  * kernel: drm/amdgpu/vcn4: Prevent OOB reads when parsing IB (CVE-2026-46204)
  * kernel: drm/amdgpu/vcn4: Prevent OOB reads when parsing dec msg (CVE-2026-46199)
  * kernel: drm/amdgpu/userq: fix access to stale wptr mapping (CVE-2026-46311)
  * kernel: netfilter: nf_queue: hold bridge skb-&amp;gt;dev while queued (CVE-2026-52912)
  * kernel: accel/ivpu: Add buffer overflow check in MS get_info_ioctl (CVE-2026-53203)
  * kernel: drm/xe/eustall: Fix drm_dev_put called before stream disable in close (CVE-2026-53290)
  * kernel: drm/virtio: use uninterruptible resv lock for plane updates (CVE-2026-64098)
  * kernel: Linux kernel: PPPoE memory corruption via stale pointer (CVE-2026-68121)
  * kernel: drm/amdgpu/vce: fix integer overflow in image size (CVE-2026-68108)
  * kernel: drm/amdkfd: fix 32-bit overflow in CWSR total size calculation (CVE-2026-68257)
  * kernel: drm/xe/rtp: Add RING_FORCE_TO_NONPRIV_DENY to OA whitelists (CVE-2026-68267)
  * kernel: drm/xe: Hold a dma-buf reference for imported BOs (CVE-2026-68266)
  * kernel: drm/amdgpu: Fix context pstate override handling (CVE-2026-68273)
  *…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:71700</guid>
    </item>
    <item>
      <title>BELL-CVE-2026-68266</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-68266</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-68266</guid>
    </item>
    <item>
      <title>certfr-2026-avi-1090 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de Debian. Elles permettent à un attaquant de provo…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1090</link>
      <description>certfr-2026-avi-1090</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-1090</guid>
    </item>
    <item>
      <title>EUVD-2026-353527</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-353527</link>
      <description>EUVD-2026-353527</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-353527</guid>
    </item>
    <item>
      <title>fkie_cve-2026-68266</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-68266</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;drm/xe: Hold a dma-buf reference for imported BOs&lt;/p&gt;
&lt;p&gt;An imported dma-buf BO is created as a ttm_bo_type_sg BO whose
reservation object is the exporter&amp;#39;s dma_buf-&amp;gt;resv. The importer,
however, only takes a dma-buf reference after a successful
dma_buf_dynamic_attach(). Until then nothing keeps the exporter alive,
so if the exporter is freed while the BO still references its resv, a
later access to that resv is a use-after-free:&lt;/p&gt;
&lt;p&gt;Oops: general protection fault, probably for non-canonical address
        0x6b6b6b6b6b6b6b9c
  Workqueue: ttm ttm_bo_delayed_delete [ttm]
  RIP: 0010:mutex_can_spin_on_owner+0x3f/0xc0&lt;/p&gt;
&lt;p&gt;This can be reached on two paths:&lt;/p&gt;
&lt;p&gt;- dma_buf_dynamic_attach() fails, or
 - ttm_bo_init_reserved() fails during BO creation.&lt;/p&gt;
&lt;p&gt;In both cases the BO already has bo-&amp;gt;base.resv pointing at the exporter
resv, and sg BOs are always torn down via ttm_bo_delayed_delete(), which
locks bo-&amp;gt;base.resv asynchronously - potentially after the exporter has
been freed.&lt;/p&gt;
&lt;p&gt;Take the dma-buf reference in xe_bo_init_locked(), before
ttm_bo_init_reserved(), so it also covers a creation failure there, and
release it in xe_ttm_bo_destroy(). The reference is held for the whole
BO lifetime, keeping the shared resv alive on every path.&lt;/p&gt;
&lt;p&gt;v2:
  - Reworked the fix to avoid creating the imported sg BO before
    dma_buf_dynamic_attach() succeeds.
  - Attach with importer_priv == NULL and make invalidate_mappings ignore
    incomplete i…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;drm/xe: Hold a dma-buf reference for imported BOs&lt;/p&gt;
&lt;p&gt;An imported dma-buf BO is created as a ttm_bo_type_sg BO whose
reservation object is the exporter&amp;#39;s dma_buf-&amp;gt;resv. The importer,
however, only takes a dma-buf reference after a successful
dma_buf_dynamic_attach(). Until then nothing keeps the exporter alive,
so if the exporter is freed while the BO still references its resv, a
later access to that resv is a use-after-free:&lt;/p&gt;
&lt;p&gt;Oops: general protection fault, probably for non-canonical address
        0x6b6b6b6b6b6b6b9c
  Workqueue: ttm ttm_bo_delayed_delete [ttm]
  RIP: 0010:mutex_can_spin_on_owner+0x3f/0xc0&lt;/p&gt;
&lt;p&gt;This can be reached on two paths:&lt;/p&gt;
&lt;p&gt;- dma_buf_dynamic_attach() fails, or
 - ttm_bo_init_reserved() fails during BO creation.&lt;/p&gt;
&lt;p&gt;In both cases the BO already has bo-&amp;gt;base.resv pointing at the exporter
resv, and sg BOs are always torn down via ttm_bo_delayed_delete(), which
locks bo-&amp;gt;base.resv asynchronously - potentially after the exporter has
been freed.&lt;/p&gt;
&lt;p&gt;Take the dma-buf reference in xe_bo_init_locked(), before
ttm_bo_init_reserved(), so it also covers a creation failure there, and
release it in xe_ttm_bo_destroy(). The reference is held for the whole
BO lifetime, keeping the shared resv alive on every path.&lt;/p&gt;
&lt;p&gt;v2:
  - Reworked the fix to avoid creating the imported sg BO before
    dma_buf_dynamic_attach() succeeds.
  - Attach with importer_priv == NULL and make invalidate_mappings ignore
    incomplete i…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-68266</guid>
    </item>
    <item>
      <title>GHSA-9jm7-867x-hm4j</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-9jm7-867x-hm4j</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;drm/xe: Hold a dma-buf reference for imported BOs&lt;/p&gt;
&lt;p&gt;An imported dma-buf BO is created as a ttm_bo_type_sg BO whose
reservation object is the exporter&amp;#39;s dma_buf-&amp;gt;resv. The importer,
however, only takes a dma-buf reference after a successful
dma_buf_dynamic_attach(). Until then nothing keeps the exporter alive,
so if the exporter is freed while the BO still references its resv, a
later access to that resv is a use-after-free:&lt;/p&gt;
&lt;p&gt;Oops: general protection fault, probably for non-canonical address
        0x6b6b6b6b6b6b6b9c
  Workqueue: ttm ttm_bo_delayed_delete [ttm]
  RIP: 0010:mutex_can_spin_on_owner+0x3f/0xc0&lt;/p&gt;
&lt;p&gt;This can be reached on two paths:&lt;/p&gt;
&lt;p&gt;- dma_buf_dynamic_attach() fails, or
 - ttm_bo_init_reserved() fails during BO creation.&lt;/p&gt;
&lt;p&gt;In both cases the BO already has bo-&amp;gt;base.resv pointing at the exporter
resv, and sg BOs are always torn down via ttm_bo_delayed_delete(), which
locks bo-&amp;gt;base.resv asynchronously - potentially after the exporter has
been freed.&lt;/p&gt;
&lt;p&gt;Take the dma-buf reference in xe_bo_init_locked(), before
ttm_bo_init_reserved(), so it also covers a creation failure there, and
release it in xe_ttm_bo_destroy(). The reference is held for the whole
BO lifetime, keeping the shared resv alive on every path.&lt;/p&gt;
&lt;p&gt;v2:
  - Reworked the fix to avoid creating the imported sg BO before
    dma_buf_dynamic_attach() succeeds.
  - Attach with importer_priv == NULL and make invalidate_mappings ignore
    incomplete i…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;drm/xe: Hold a dma-buf reference for imported BOs&lt;/p&gt;
&lt;p&gt;An imported dma-buf BO is created as a ttm_bo_type_sg BO whose
reservation object is the exporter&amp;#39;s dma_buf-&amp;gt;resv. The importer,
however, only takes a dma-buf reference after a successful
dma_buf_dynamic_attach(). Until then nothing keeps the exporter alive,
so if the exporter is freed while the BO still references its resv, a
later access to that resv is a use-after-free:&lt;/p&gt;
&lt;p&gt;Oops: general protection fault, probably for non-canonical address
        0x6b6b6b6b6b6b6b9c
  Workqueue: ttm ttm_bo_delayed_delete [ttm]
  RIP: 0010:mutex_can_spin_on_owner+0x3f/0xc0&lt;/p&gt;
&lt;p&gt;This can be reached on two paths:&lt;/p&gt;
&lt;p&gt;- dma_buf_dynamic_attach() fails, or
 - ttm_bo_init_reserved() fails during BO creation.&lt;/p&gt;
&lt;p&gt;In both cases the BO already has bo-&amp;gt;base.resv pointing at the exporter
resv, and sg BOs are always torn down via ttm_bo_delayed_delete(), which
locks bo-&amp;gt;base.resv asynchronously - potentially after the exporter has
been freed.&lt;/p&gt;
&lt;p&gt;Take the dma-buf reference in xe_bo_init_locked(), before
ttm_bo_init_reserved(), so it also covers a creation failure there, and
release it in xe_ttm_bo_destroy(). The reference is held for the whole
BO lifetime, keeping the shared resv alive on every path.&lt;/p&gt;
&lt;p&gt;v2:
  - Reworked the fix to avoid creating the imported sg BO before
    dma_buf_dynamic_attach() succeeds.
  - Attach with importer_priv == NULL and make invalidate_mappings ignore
    incomplete i…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-9jm7-867x-hm4j</guid>
    </item>
    <item>
      <title>RHSA-2026:71602 — Red Hat Security Advisory: kernel security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:71602</link>
      <description>&lt;p&gt;kernel: fbcon: Set fb_display[i]-&amp;gt;mode to NULL when the mode is released kernel: libceph: fix potential use-after-free in have_mon_and_osd_map() kernel: libceph: make decode_pool() more resilient against corrupted osdmaps kernel: libceph: prevent potential out-of-bounds reads in handle_auth_done() kernel: libceph: replace overzealous BUG_ON in osdmap_apply_incremental() kernel: Linux kernel: Denial of Service in libceph OSD client due to unreset sparse-read state kernel: drm/amdgpu/vcn4: Prevent OOB reads when parsing dec msg kernel: drm/amdgpu/vcn4: Prevent OOB reads when parsing IB kernel: drm/amdgpu/vcn3: Prevent OOB reads when parsing dec msg kernel: drm/amdgpu/userq: fix access to stale wptr mapping kernel: af_unix: Drop all SCM attributes for SOCKMAP kernel: accel/ivpu: Add buffer overflow check in MS get_info_ioctl kernel: drm/xe/eustall: Fix drm_dev_put called before stream disable in close kernel: drm/virtio: use uninterruptible resv lock for plane updates kernel: drm/amdgpu/vce: fix integer overflow in image size kernel: pppoe: reload header pointer after dev_hard_header() kernel: drm/amdkfd: fix 32-bit overflow in CWSR total size calculation kernel: drm/xe: Hold a dma-buf reference for imported BOs kernel: drm/xe/rtp: Add RING_FORCE_TO_NONPRIV_DENY to OA whitelists kernel: drm/amdgpu: Fix context pstate override handling kernel: ipvs: do not propagate one-packet flag to synced conns kernel: nvme-tcp: fix host memory disclosure on R2T for a read command&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;kernel: fbcon: Set fb_display[i]-&amp;gt;mode to NULL when the mode is released kernel: libceph: fix potential use-after-free in have_mon_and_osd_map() kernel: libceph: make decode_pool() more resilient against corrupted osdmaps kernel: libceph: prevent potential out-of-bounds reads in handle_auth_done() kernel: libceph: replace overzealous BUG_ON in osdmap_apply_incremental() kernel: Linux kernel: Denial of Service in libceph OSD client due to unreset sparse-read state kernel: drm/amdgpu/vcn4: Prevent OOB reads when parsing dec msg kernel: drm/amdgpu/vcn4: Prevent OOB reads when parsing IB kernel: drm/amdgpu/vcn3: Prevent OOB reads when parsing dec msg kernel: drm/amdgpu/userq: fix access to stale wptr mapping kernel: af_unix: Drop all SCM attributes for SOCKMAP kernel: accel/ivpu: Add buffer overflow check in MS get_info_ioctl kernel: drm/xe/eustall: Fix drm_dev_put called before stream disable in close kernel: drm/virtio: use uninterruptible resv lock for plane updates kernel: drm/amdgpu/vce: fix integer overflow in image size kernel: pppoe: reload header pointer after dev_hard_header() kernel: drm/amdkfd: fix 32-bit overflow in CWSR total size calculation kernel: drm/xe: Hold a dma-buf reference for imported BOs kernel: drm/xe/rtp: Add RING_FORCE_TO_NONPRIV_DENY to OA whitelists kernel: drm/amdgpu: Fix context pstate override handling kernel: ipvs: do not propagate one-packet flag to synced conns kernel: nvme-tcp: fix host memory disclosure on R2T for a read command&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:71602</guid>
    </item>
    <item>
      <title>RHSA-2026:71700 — Red Hat Security Advisory: kernel security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:71700</link>
      <description>&lt;p&gt;kernel: fbcon: Set fb_display[i]-&amp;gt;mode to NULL when the mode is released kernel: smb: smbdirect: introduce smbdirect_socket.recv_io.credits.available kernel: drm/amdgpu/vcn4: Prevent OOB reads when parsing dec msg kernel: drm/amdgpu/vcn4: Prevent OOB reads when parsing IB kernel: drm/amdgpu/vcn3: Prevent OOB reads when parsing dec msg kernel: drm/amdgpu/userq: fix access to stale wptr mapping kernel: netfilter: nf_queue: hold bridge skb-&amp;gt;dev while queued kernel: accel/ivpu: Add buffer overflow check in MS get_info_ioctl kernel: drm/xe/eustall: Fix drm_dev_put called before stream disable in close kernel: drm/virtio: use uninterruptible resv lock for plane updates kernel: drm/amdgpu/vce: fix integer overflow in image size kernel: pppoe: reload header pointer after dev_hard_header() kernel: drm/amdkfd: fix 32-bit overflow in CWSR total size calculation kernel: drm/xe: Hold a dma-buf reference for imported BOs kernel: drm/xe/rtp: Add RING_FORCE_TO_NONPRIV_DENY to OA whitelists kernel: drm/amdgpu: Fix context pstate override handling kernel: ipvs: do not propagate one-packet flag to synced conns&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;kernel: fbcon: Set fb_display[i]-&amp;gt;mode to NULL when the mode is released kernel: smb: smbdirect: introduce smbdirect_socket.recv_io.credits.available kernel: drm/amdgpu/vcn4: Prevent OOB reads when parsing dec msg kernel: drm/amdgpu/vcn4: Prevent OOB reads when parsing IB kernel: drm/amdgpu/vcn3: Prevent OOB reads when parsing dec msg kernel: drm/amdgpu/userq: fix access to stale wptr mapping kernel: netfilter: nf_queue: hold bridge skb-&amp;gt;dev while queued kernel: accel/ivpu: Add buffer overflow check in MS get_info_ioctl kernel: drm/xe/eustall: Fix drm_dev_put called before stream disable in close kernel: drm/virtio: use uninterruptible resv lock for plane updates kernel: drm/amdgpu/vce: fix integer overflow in image size kernel: pppoe: reload header pointer after dev_hard_header() kernel: drm/amdkfd: fix 32-bit overflow in CWSR total size calculation kernel: drm/xe: Hold a dma-buf reference for imported BOs kernel: drm/xe/rtp: Add RING_FORCE_TO_NONPRIV_DENY to OA whitelists kernel: drm/amdgpu: Fix context pstate override handling kernel: ipvs: do not propagate one-packet flag to synced conns&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:71700</guid>
    </item>
    <item>
      <title>RLSA-2026:71602 — Important: kernel security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:71602</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: kernel&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: fbcon: Set fb_display[i]-&amp;gt;mode to NULL when the mode is released (CVE-2025-40323)&lt;/p&gt;
&lt;p&gt;* kernel: libceph: fix potential use-after-free in have_mon_and_osd_map() (CVE-2025-68285)&lt;/p&gt;
&lt;p&gt;* kernel: libceph: make decode_pool() more resilient against corrupted osdmaps (CVE-2025-71116)&lt;/p&gt;
&lt;p&gt;* kernel: libceph: prevent potential out-of-bounds reads in handle_auth_done() (CVE-2026-22984)&lt;/p&gt;
&lt;p&gt;* kernel: libceph: replace overzealous BUG_ON in osdmap_apply_incremental() (CVE-2026-22990)&lt;/p&gt;
&lt;p&gt;* kernel: Linux kernel: Denial of Service in libceph OSD client due to unreset sparse-read state (CVE-2026-23136)&lt;/p&gt;
&lt;p&gt;* kernel: drm/amdgpu/vcn3: Prevent OOB reads when parsing dec msg (CVE-2026-46230)&lt;/p&gt;
&lt;p&gt;* kernel: drm/amdgpu/vcn4: Prevent OOB reads when parsing IB (CVE-2026-46204)&lt;/p&gt;
&lt;p&gt;* kernel: drm/amdgpu/vcn4: Prevent OOB reads when parsing dec msg (CVE-2026-46199)&lt;/p&gt;
&lt;p&gt;* kernel: drm/amdgpu/userq: fix access to stale wptr mapping (CVE-2026-46311)&lt;/p&gt;
&lt;p&gt;* kernel: af_unix: Drop all SCM attributes for SOCKMAP (CVE-2026-53005)&lt;/p&gt;
&lt;p&gt;* kernel: accel/ivpu: Add buffer overflow check in MS get_info_ioctl (CVE-2026-53203)&lt;/p&gt;
&lt;p&gt;* kernel: drm/xe/eustall: Fix drm_dev_put called before stream disable in close (CVE-2026-53290)&lt;/p&gt;
&lt;p&gt;* kernel: drm/virtio: use uninterruptible resv lock for plane updates (CVE-2026-64098)&lt;/p&gt;
&lt;p&gt;* kernel: Linux kernel: PPPoE memory corruption via stale pointer (CVE-2026-68121)&lt;/p&gt;
&lt;p&gt;* kernel: drm/amdgpu/vce: fix integer overflow in…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: kernel&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: fbcon: Set fb_display[i]-&amp;gt;mode to NULL when the mode is released (CVE-2025-40323)&lt;/p&gt;
&lt;p&gt;* kernel: libceph: fix potential use-after-free in have_mon_and_osd_map() (CVE-2025-68285)&lt;/p&gt;
&lt;p&gt;* kernel: libceph: make decode_pool() more resilient against corrupted osdmaps (CVE-2025-71116)&lt;/p&gt;
&lt;p&gt;* kernel: libceph: prevent potential out-of-bounds reads in handle_auth_done() (CVE-2026-22984)&lt;/p&gt;
&lt;p&gt;* kernel: libceph: replace overzealous BUG_ON in osdmap_apply_incremental() (CVE-2026-22990)&lt;/p&gt;
&lt;p&gt;* kernel: Linux kernel: Denial of Service in libceph OSD client due to unreset sparse-read state (CVE-2026-23136)&lt;/p&gt;
&lt;p&gt;* kernel: drm/amdgpu/vcn3: Prevent OOB reads when parsing dec msg (CVE-2026-46230)&lt;/p&gt;
&lt;p&gt;* kernel: drm/amdgpu/vcn4: Prevent OOB reads when parsing IB (CVE-2026-46204)&lt;/p&gt;
&lt;p&gt;* kernel: drm/amdgpu/vcn4: Prevent OOB reads when parsing dec msg (CVE-2026-46199)&lt;/p&gt;
&lt;p&gt;* kernel: drm/amdgpu/userq: fix access to stale wptr mapping (CVE-2026-46311)&lt;/p&gt;
&lt;p&gt;* kernel: af_unix: Drop all SCM attributes for SOCKMAP (CVE-2026-53005)&lt;/p&gt;
&lt;p&gt;* kernel: accel/ivpu: Add buffer overflow check in MS get_info_ioctl (CVE-2026-53203)&lt;/p&gt;
&lt;p&gt;* kernel: drm/xe/eustall: Fix drm_dev_put called before stream disable in close (CVE-2026-53290)&lt;/p&gt;
&lt;p&gt;* kernel: drm/virtio: use uninterruptible resv lock for plane updates (CVE-2026-64098)&lt;/p&gt;
&lt;p&gt;* kernel: Linux kernel: PPPoE memory corruption via stale pointer (CVE-2026-68121)&lt;/p&gt;
&lt;p&gt;* kernel: drm/amdgpu/vce: fix integer overflow in…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:71602</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-68266</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-68266</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 154 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: drm/xe: Hold a dma-buf reference for imported BOs An imported dma-buf BO is created as a ttm_bo_type_sg BO whose reservation object is the exporter&amp;#39;s dma_buf-&amp;gt;resv. The importer, however, only takes a dma-buf reference after a successful dma_buf_dynamic_attach(). Until then nothing keeps the exporter alive, so if the exporter is freed while the BO still references its resv, a later access to that resv is a use-after-free:   Oops: general protection fault, probably for non-canonical address         0x6b6b6b6b6b6b6b9c   Workqueue: ttm ttm_bo_delayed_delete [ttm]   RIP: 0010:mutex_can_spin_on_owner+0x3f/0xc0 This can be reached on two paths:  - dma_buf_dynamic_attach() fails, or  - ttm_bo_init_reserved() fails during BO creation. In both cases the BO already has bo-&amp;gt;base.resv pointing at the exporter resv, and sg BOs are always torn down via ttm_bo_delayed_delete(), which locks bo-&amp;gt;base.resv asynchronously - potentially after the exporter has been freed. Take the dma-buf reference in xe_bo_init_locked(), before ttm_bo_init_reserved(), so it also covers a creation failure there, and release it in xe_ttm_bo_destroy(). The reference is held for the whole BO lifetime, keeping the shared resv alive on every path. v2:   - Reworked the fix to avoid creating the imported sg BO before     dma_buf_dynamic_attach() succeeds.   - Attach with importer_priv == NULL and make invalidate_mappings ignore     incomplete imports.…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 154 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: drm/xe: Hold a dma-buf reference for imported BOs An imported dma-buf BO is created as a ttm_bo_type_sg BO whose reservation object is the exporter&amp;#39;s dma_buf-&amp;gt;resv. The importer, however, only takes a dma-buf reference after a successful dma_buf_dynamic_attach(). Until then nothing keeps the exporter alive, so if the exporter is freed while the BO still references its resv, a later access to that resv is a use-after-free:   Oops: general protection fault, probably for non-canonical address         0x6b6b6b6b6b6b6b9c   Workqueue: ttm ttm_bo_delayed_delete [ttm]   RIP: 0010:mutex_can_spin_on_owner+0x3f/0xc0 This can be reached on two paths:  - dma_buf_dynamic_attach() fails, or  - ttm_bo_init_reserved() fails during BO creation. In both cases the BO already has bo-&amp;gt;base.resv pointing at the exporter resv, and sg BOs are always torn down via ttm_bo_delayed_delete(), which locks bo-&amp;gt;base.resv asynchronously - potentially after the exporter has been freed. Take the dma-buf reference in xe_bo_init_locked(), before ttm_bo_init_reserved(), so it also covers a creation failure there, and release it in xe_ttm_bo_destroy(). The reference is held for the whole BO lifetime, keeping the shared resv alive on every path. v2:   - Reworked the fix to avoid creating the imported sg BO before     dma_buf_dynamic_attach() succeeds.   - Attach with importer_priv == NULL and make invalidate_mappings ignore     incomplete imports.…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-68266</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2730 — Linux Kernel: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2730</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen, darunter möglicherweise die Ausführung von beliebigem Code, die Ausweitung von Berechtigungen, die Offenlegung von Informationen, die Manipulation von Daten oder Denial-of-Service-Zustände.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen, darunter möglicherweise die Ausführung von beliebigem Code, die Ausweitung von Berechtigungen, die Offenlegung von Informationen, die Manipulation von Daten oder Denial-of-Service-Zustände.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2730</guid>
    </item>
  </channel>
</rss>
