<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 13:37:34 +0000</lastBuildDate>
    <item>
      <title>ALSA-2026:70402 — Important: kernel security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:70402</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: bpftool, AlmaLinux:8: kernel, AlmaLinux:8: kernel-abi-stablelists, AlmaLinux:8: kernel-core, AlmaLinux:8: kernel-cross-headers, AlmaLinux:8: kernel-debug, AlmaLinux:8: kernel-debug-core, AlmaLinux:8: kernel-debug-devel, AlmaLinux:8: kernel-debug-modules, AlmaLinux:8: kernel-debug-modules-extra and 15 more&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg (CVE-2025-39964)
  * kernel: Linux kernel Bluetooth: Denial of Service via race condition in hidp_session_thread (CVE-2023-54120)
  * kernel: Bluetooth: L2CAP: Fix potential user-after-free (CVE-2023-54214)
  * kernel: Bluetooth: btusb: revert use of devm_kzalloc in btusb (CVE-2025-71082)
  * kernel: Bluetooth: SMP: force responder MITM requirements before building the pairing response (CVE-2026-43334)
  * kernel: iommu/vt-d: Clear Present bit before tearing down PASID entry (CVE-2026-45894)
  * kernel: RDMA/rxe: Validate pad and ICRC before payload_size() in rxe_rcv (CVE-2026-46043)
  * kernel: RDMA/rxe: Reject unknown opcodes before ICRC processing (CVE-2026-46133)
  * kernel: Bluetooth: serialize accept_q access (CVE-2026-52918)
  * kernel: dm cache policy smq: fix missing locks in invalidating cache blocks (CVE-2026-53062)
  * kernel: iommu/amd: Fix clone_alias() to use the original device&amp;#39;s devid (CVE-2026-53053)
  * kernel: Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind() (CVE-2026-53256)
  * kernel: Bluetooth: RFCOMM: validate skb length in MCC handlers (CVE-2026-53254)
  * kernel: keys: Pin request_key_auth payload in instantiate paths (CVE-2026-63823)
  * kernel: Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp (CVE-2026-63975)
  * kernel: Bluetooth: HIDP: fi…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: bpftool, AlmaLinux:8: kernel, AlmaLinux:8: kernel-abi-stablelists, AlmaLinux:8: kernel-core, AlmaLinux:8: kernel-cross-headers, AlmaLinux:8: kernel-debug, AlmaLinux:8: kernel-debug-core, AlmaLinux:8: kernel-debug-devel, AlmaLinux:8: kernel-debug-modules, AlmaLinux:8: kernel-debug-modules-extra and 15 more&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg (CVE-2025-39964)
  * kernel: Linux kernel Bluetooth: Denial of Service via race condition in hidp_session_thread (CVE-2023-54120)
  * kernel: Bluetooth: L2CAP: Fix potential user-after-free (CVE-2023-54214)
  * kernel: Bluetooth: btusb: revert use of devm_kzalloc in btusb (CVE-2025-71082)
  * kernel: Bluetooth: SMP: force responder MITM requirements before building the pairing response (CVE-2026-43334)
  * kernel: iommu/vt-d: Clear Present bit before tearing down PASID entry (CVE-2026-45894)
  * kernel: RDMA/rxe: Validate pad and ICRC before payload_size() in rxe_rcv (CVE-2026-46043)
  * kernel: RDMA/rxe: Reject unknown opcodes before ICRC processing (CVE-2026-46133)
  * kernel: Bluetooth: serialize accept_q access (CVE-2026-52918)
  * kernel: dm cache policy smq: fix missing locks in invalidating cache blocks (CVE-2026-53062)
  * kernel: iommu/amd: Fix clone_alias() to use the original device&amp;#39;s devid (CVE-2026-53053)
  * kernel: Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind() (CVE-2026-53256)
  * kernel: Bluetooth: RFCOMM: validate skb length in MCC handlers (CVE-2026-53254)
  * kernel: keys: Pin request_key_auth payload in instantiate paths (CVE-2026-63823)
  * kernel: Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp (CVE-2026-63975)
  * kernel: Bluetooth: HIDP: fi…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:70402</guid>
    </item>
    <item>
      <title>BELL-CVE-2026-68293</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-68293</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-68293</guid>
    </item>
    <item>
      <title>certfr-2026-avi-1069 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de Debian LTS. Elles permettent à un attaquant de p…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1069</link>
      <description>certfr-2026-avi-1069</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-1069</guid>
    </item>
    <item>
      <title>EUVD-2026-353544</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-353544</link>
      <description>EUVD-2026-353544</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-353544</guid>
    </item>
    <item>
      <title>fkie_cve-2026-68293</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-68293</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;net/mlx5: Fix MCIA register buffer overflow on 32 dword reads&lt;/p&gt;
&lt;p&gt;The MCIA register can return up to 32 dwords (128 bytes) when the device
advertises the mcia_32dwords capability, but struct
mlx5_ifc_mcia_reg_bits only defines dword_0..11, leaving room for just
12 dwords (48 bytes) of data.&lt;/p&gt;
&lt;p&gt;mlx5_query_mcia() clamps the read size to mlx5_mcia_max_bytes() and then
memcpy()s that many bytes out of the register, potentially reading past
the end of the &amp;#39;out&amp;#39; buffer. On kernels built with FORTIFY_SOURCE this
is caught as a buffer overflow while reading the module EEPROM via
ethtool:&lt;/p&gt;
&lt;p&gt;detected buffer overflow in memcpy
  kernel BUG at lib/string_helpers.c:1048!
  RIP: 0010:fortify_panic+0x13/0x20
  Call Trace:
   mlx5_query_mcia.isra.0+0x200/0x210 [mlx5_core]
   mlx5_query_module_eeprom_by_page+0x4a/0xa0 [mlx5_core]
   mlx5e_get_module_eeprom_by_page+0xbb/0x120 [mlx5_core]
   eeprom_prepare_data+0xf3/0x170
   ethnl_default_doit+0xf1/0x3b0&lt;/p&gt;
&lt;p&gt;Extend the mcia_reg layout to 32 dwords.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;net/mlx5: Fix MCIA register buffer overflow on 32 dword reads&lt;/p&gt;
&lt;p&gt;The MCIA register can return up to 32 dwords (128 bytes) when the device
advertises the mcia_32dwords capability, but struct
mlx5_ifc_mcia_reg_bits only defines dword_0..11, leaving room for just
12 dwords (48 bytes) of data.&lt;/p&gt;
&lt;p&gt;mlx5_query_mcia() clamps the read size to mlx5_mcia_max_bytes() and then
memcpy()s that many bytes out of the register, potentially reading past
the end of the &amp;#39;out&amp;#39; buffer. On kernels built with FORTIFY_SOURCE this
is caught as a buffer overflow while reading the module EEPROM via
ethtool:&lt;/p&gt;
&lt;p&gt;detected buffer overflow in memcpy
  kernel BUG at lib/string_helpers.c:1048!
  RIP: 0010:fortify_panic+0x13/0x20
  Call Trace:
   mlx5_query_mcia.isra.0+0x200/0x210 [mlx5_core]
   mlx5_query_module_eeprom_by_page+0x4a/0xa0 [mlx5_core]
   mlx5e_get_module_eeprom_by_page+0xbb/0x120 [mlx5_core]
   eeprom_prepare_data+0xf3/0x170
   ethnl_default_doit+0xf1/0x3b0&lt;/p&gt;
&lt;p&gt;Extend the mcia_reg layout to 32 dwords.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-68293</guid>
    </item>
    <item>
      <title>GHSA-7555-mcj4-25r2</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-7555-mcj4-25r2</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;net/mlx5: Fix MCIA register buffer overflow on 32 dword reads&lt;/p&gt;
&lt;p&gt;The MCIA register can return up to 32 dwords (128 bytes) when the device
advertises the mcia_32dwords capability, but struct
mlx5_ifc_mcia_reg_bits only defines dword_0..11, leaving room for just
12 dwords (48 bytes) of data.&lt;/p&gt;
&lt;p&gt;mlx5_query_mcia() clamps the read size to mlx5_mcia_max_bytes() and then
memcpy()s that many bytes out of the register, potentially reading past
the end of the &amp;#39;out&amp;#39; buffer. On kernels built with FORTIFY_SOURCE this
is caught as a buffer overflow while reading the module EEPROM via
ethtool:&lt;/p&gt;
&lt;p&gt;detected buffer overflow in memcpy
  kernel BUG at lib/string_helpers.c:1048!
  RIP: 0010:fortify_panic+0x13/0x20
  Call Trace:
   mlx5_query_mcia.isra.0+0x200/0x210 [mlx5_core]
   mlx5_query_module_eeprom_by_page+0x4a/0xa0 [mlx5_core]
   mlx5e_get_module_eeprom_by_page+0xbb/0x120 [mlx5_core]
   eeprom_prepare_data+0xf3/0x170
   ethnl_default_doit+0xf1/0x3b0&lt;/p&gt;
&lt;p&gt;Extend the mcia_reg layout to 32 dwords.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;net/mlx5: Fix MCIA register buffer overflow on 32 dword reads&lt;/p&gt;
&lt;p&gt;The MCIA register can return up to 32 dwords (128 bytes) when the device
advertises the mcia_32dwords capability, but struct
mlx5_ifc_mcia_reg_bits only defines dword_0..11, leaving room for just
12 dwords (48 bytes) of data.&lt;/p&gt;
&lt;p&gt;mlx5_query_mcia() clamps the read size to mlx5_mcia_max_bytes() and then
memcpy()s that many bytes out of the register, potentially reading past
the end of the &amp;#39;out&amp;#39; buffer. On kernels built with FORTIFY_SOURCE this
is caught as a buffer overflow while reading the module EEPROM via
ethtool:&lt;/p&gt;
&lt;p&gt;detected buffer overflow in memcpy
  kernel BUG at lib/string_helpers.c:1048!
  RIP: 0010:fortify_panic+0x13/0x20
  Call Trace:
   mlx5_query_mcia.isra.0+0x200/0x210 [mlx5_core]
   mlx5_query_module_eeprom_by_page+0x4a/0xa0 [mlx5_core]
   mlx5e_get_module_eeprom_by_page+0xbb/0x120 [mlx5_core]
   eeprom_prepare_data+0xf3/0x170
   ethnl_default_doit+0xf1/0x3b0&lt;/p&gt;
&lt;p&gt;Extend the mcia_reg layout to 32 dwords.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-7555-mcj4-25r2</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-68293 — net/mlx5: Fix MCIA register buffer overflow on 32 dword reads</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-68293</link>
      <description>msrc_CVE-2026-68293</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-68293</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:21910-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:21910-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:21910-1</guid>
    </item>
    <item>
      <title>RHSA-2026:70402 — Red Hat Security Advisory: kernel security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:70402</link>
      <description>&lt;p&gt;kernel: Linux kernel Bluetooth: Denial of Service via race condition in hidp_session_thread kernel: Bluetooth: L2CAP: Fix potential user-after-free kernel: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg kernel: Bluetooth: btusb: revert use of devm_kzalloc in btusb kernel: Bluetooth: SMP: force responder MITM requirements before building the pairing response kernel: iommu/vt-d: Clear Present bit before tearing down PASID entry kernel: RDMA/rxe: Validate pad and ICRC before payload_size() in rxe_rcv kernel: RDMA/rxe: Reject unknown opcodes before ICRC processing kernel: Bluetooth: serialize accept_q access kernel: iommu/amd: Fix clone_alias() to use the original device&amp;#39;s devid kernel: dm cache policy smq: fix missing locks in invalidating cache blocks kernel: Bluetooth: RFCOMM: validate skb length in MCC handlers kernel: Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind() kernel: keys: Pin request_key_auth payload in instantiate paths kernel: Bluetooth: HIDP: fix missing length checks in hidp_input_report() kernel: Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp kernel: nvmet-tcp: check INIT_FAILED before nvmet_req_uninit in digest error path kernel: RDMA/rxe: Fix a use-after-free problem in rxe_mmap kernel: Linux kernel Bluetooth RFCOMM: Denial of Service via use-after-free in set_termios kernel: net/mlx5: Fix MCIA register buffer overflow on 32 dword reads&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;kernel: Linux kernel Bluetooth: Denial of Service via race condition in hidp_session_thread kernel: Bluetooth: L2CAP: Fix potential user-after-free kernel: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg kernel: Bluetooth: btusb: revert use of devm_kzalloc in btusb kernel: Bluetooth: SMP: force responder MITM requirements before building the pairing response kernel: iommu/vt-d: Clear Present bit before tearing down PASID entry kernel: RDMA/rxe: Validate pad and ICRC before payload_size() in rxe_rcv kernel: RDMA/rxe: Reject unknown opcodes before ICRC processing kernel: Bluetooth: serialize accept_q access kernel: iommu/amd: Fix clone_alias() to use the original device&amp;#39;s devid kernel: dm cache policy smq: fix missing locks in invalidating cache blocks kernel: Bluetooth: RFCOMM: validate skb length in MCC handlers kernel: Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind() kernel: keys: Pin request_key_auth payload in instantiate paths kernel: Bluetooth: HIDP: fix missing length checks in hidp_input_report() kernel: Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp kernel: nvmet-tcp: check INIT_FAILED before nvmet_req_uninit in digest error path kernel: RDMA/rxe: Fix a use-after-free problem in rxe_mmap kernel: Linux kernel Bluetooth RFCOMM: Denial of Service via use-after-free in set_termios kernel: net/mlx5: Fix MCIA register buffer overflow on 32 dword reads&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:70402</guid>
    </item>
    <item>
      <title>RLSA-2026:70402 — Important: kernel security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:70402</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:8: kernel&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg (CVE-2025-39964)&lt;/p&gt;
&lt;p&gt;* kernel: Linux kernel Bluetooth: Denial of Service via race condition in hidp_session_thread (CVE-2023-54120)&lt;/p&gt;
&lt;p&gt;* kernel: Bluetooth: L2CAP: Fix potential user-after-free (CVE-2023-54214)&lt;/p&gt;
&lt;p&gt;* kernel: Bluetooth: btusb: revert use of devm_kzalloc in btusb (CVE-2025-71082)&lt;/p&gt;
&lt;p&gt;* kernel: Bluetooth: SMP: force responder MITM requirements before building the pairing response (CVE-2026-43334)&lt;/p&gt;
&lt;p&gt;* kernel: iommu/vt-d: Clear Present bit before tearing down PASID entry (CVE-2026-45894)&lt;/p&gt;
&lt;p&gt;* kernel: RDMA/rxe: Validate pad and ICRC before payload_size() in rxe_rcv (CVE-2026-46043)&lt;/p&gt;
&lt;p&gt;* kernel: RDMA/rxe: Reject unknown opcodes before ICRC processing (CVE-2026-46133)&lt;/p&gt;
&lt;p&gt;* kernel: Bluetooth: serialize accept_q access (CVE-2026-52918)&lt;/p&gt;
&lt;p&gt;* kernel: dm cache policy smq: fix missing locks in invalidating cache blocks (CVE-2026-53062)&lt;/p&gt;
&lt;p&gt;* kernel: iommu/amd: Fix clone_alias() to use the original device&amp;#39;s devid (CVE-2026-53053)&lt;/p&gt;
&lt;p&gt;* kernel: Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind() (CVE-2026-53256)&lt;/p&gt;
&lt;p&gt;* kernel: Bluetooth: RFCOMM: validate skb length in MCC handlers (CVE-2026-53254)&lt;/p&gt;
&lt;p&gt;* kernel: keys: Pin request_key_auth payload in instantiate paths (CVE-2026-63823)&lt;/p&gt;
&lt;p&gt;* kernel: Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp (CVE-2026-63975)&lt;/p&gt;
&lt;p&gt;* kernel: Bluetooth: HIDP: fix missing length chec…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:8: kernel&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg (CVE-2025-39964)&lt;/p&gt;
&lt;p&gt;* kernel: Linux kernel Bluetooth: Denial of Service via race condition in hidp_session_thread (CVE-2023-54120)&lt;/p&gt;
&lt;p&gt;* kernel: Bluetooth: L2CAP: Fix potential user-after-free (CVE-2023-54214)&lt;/p&gt;
&lt;p&gt;* kernel: Bluetooth: btusb: revert use of devm_kzalloc in btusb (CVE-2025-71082)&lt;/p&gt;
&lt;p&gt;* kernel: Bluetooth: SMP: force responder MITM requirements before building the pairing response (CVE-2026-43334)&lt;/p&gt;
&lt;p&gt;* kernel: iommu/vt-d: Clear Present bit before tearing down PASID entry (CVE-2026-45894)&lt;/p&gt;
&lt;p&gt;* kernel: RDMA/rxe: Validate pad and ICRC before payload_size() in rxe_rcv (CVE-2026-46043)&lt;/p&gt;
&lt;p&gt;* kernel: RDMA/rxe: Reject unknown opcodes before ICRC processing (CVE-2026-46133)&lt;/p&gt;
&lt;p&gt;* kernel: Bluetooth: serialize accept_q access (CVE-2026-52918)&lt;/p&gt;
&lt;p&gt;* kernel: dm cache policy smq: fix missing locks in invalidating cache blocks (CVE-2026-53062)&lt;/p&gt;
&lt;p&gt;* kernel: iommu/amd: Fix clone_alias() to use the original device&amp;#39;s devid (CVE-2026-53053)&lt;/p&gt;
&lt;p&gt;* kernel: Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind() (CVE-2026-53256)&lt;/p&gt;
&lt;p&gt;* kernel: Bluetooth: RFCOMM: validate skb length in MCC handlers (CVE-2026-53254)&lt;/p&gt;
&lt;p&gt;* kernel: keys: Pin request_key_auth payload in instantiate paths (CVE-2026-63823)&lt;/p&gt;
&lt;p&gt;* kernel: Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp (CVE-2026-63975)&lt;/p&gt;
&lt;p&gt;* kernel: Bluetooth: HIDP: fix missing length chec…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:70402</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:23477-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:23477-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:23477-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-68293</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-68293</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 154 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Fix MCIA register buffer overflow on 32 dword reads The MCIA register can return up to 32 dwords (128 bytes) when the device advertises the mcia_32dwords capability, but struct mlx5_ifc_mcia_reg_bits only defines dword_0..11, leaving room for just 12 dwords (48 bytes) of data. mlx5_query_mcia() clamps the read size to mlx5_mcia_max_bytes() and then memcpy()s that many bytes out of the register, potentially reading past the end of the &amp;#39;out&amp;#39; buffer. On kernels built with FORTIFY_SOURCE this is caught as a buffer overflow while reading the module EEPROM via ethtool:   detected buffer overflow in memcpy   kernel BUG at lib/string_helpers.c:1048!   RIP: 0010:fortify_panic+0x13/0x20   Call Trace:    mlx5_query_mcia.isra.0+0x200/0x210 [mlx5_core]    mlx5_query_module_eeprom_by_page+0x4a/0xa0 [mlx5_core]    mlx5e_get_module_eeprom_by_page+0xbb/0x120 [mlx5_core]    eeprom_prepare_data+0xf3/0x170    ethnl_default_doit+0xf1/0x3b0 Extend the mcia_reg layout to 32 dwords.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 154 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Fix MCIA register buffer overflow on 32 dword reads The MCIA register can return up to 32 dwords (128 bytes) when the device advertises the mcia_32dwords capability, but struct mlx5_ifc_mcia_reg_bits only defines dword_0..11, leaving room for just 12 dwords (48 bytes) of data. mlx5_query_mcia() clamps the read size to mlx5_mcia_max_bytes() and then memcpy()s that many bytes out of the register, potentially reading past the end of the &amp;#39;out&amp;#39; buffer. On kernels built with FORTIFY_SOURCE this is caught as a buffer overflow while reading the module EEPROM via ethtool:   detected buffer overflow in memcpy   kernel BUG at lib/string_helpers.c:1048!   RIP: 0010:fortify_panic+0x13/0x20   Call Trace:    mlx5_query_mcia.isra.0+0x200/0x210 [mlx5_core]    mlx5_query_module_eeprom_by_page+0x4a/0xa0 [mlx5_core]    mlx5e_get_module_eeprom_by_page+0xbb/0x120 [mlx5_core]    eeprom_prepare_data+0xf3/0x170    ethnl_default_doit+0xf1/0x3b0 Extend the mcia_reg layout to 32 dwords.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-68293</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2730 — Linux Kernel: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2730</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen, darunter möglicherweise die Ausführung von beliebigem Code, die Ausweitung von Berechtigungen, die Offenlegung von Informationen, die Manipulation von Daten oder Denial-of-Service-Zustände.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen, darunter möglicherweise die Ausführung von beliebigem Code, die Ausweitung von Berechtigungen, die Offenlegung von Informationen, die Manipulation von Daten oder Denial-of-Service-Zustände.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2730</guid>
    </item>
  </channel>
</rss>
