<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 17:16:14 +0000</lastBuildDate>
    <item>
      <title>ALSA-2026:74132 — Moderate: kernel-rt security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:74132</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: kernel-rt, AlmaLinux:8: kernel-rt-core, AlmaLinux:8: kernel-rt-debug, AlmaLinux:8: kernel-rt-debug-core, AlmaLinux:8: kernel-rt-debug-devel, AlmaLinux:8: kernel-rt-debug-modules, AlmaLinux:8: kernel-rt-debug-modules-extra, AlmaLinux:8: kernel-rt-devel, AlmaLinux:8: kernel-rt-modules, AlmaLinux:8: kernel-rt-modules-extra&lt;/p&gt;
&lt;p&gt;The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: RDMA/siw: Reject MPA FPDU length underflow before signed receive math (CVE-2026-64102)
  * kernel: vmxnet3: fix BUG_ON in vmxnet3_get_hdr_len() for Geneve packets (CVE-2026-68299)
  * kernel: net/liquidio: drop cached VF pci_dev LUT (CVE-2026-72329)
  * kernel: dm-integrity: don&amp;#39;t increment hash_offset twice (CVE-2026-72099)&lt;/p&gt;
&lt;p&gt;Bug Fix(es) and Enhancement(s):&lt;/p&gt;
&lt;p&gt;* [AlmaLinux 8.10] &amp;#34;kernel BUG at lib/list_debug.c:28!&amp;#34;: list_add corruption in register_trace_event AlmaLinux 8.10 (JIRA:AlmaLinux-214136)
  * request_key_auth use-after-free on every request-key upcall since 4.18.0-553.165.1 (regression from CVE-2026-63823 backport) (JIRA:AlmaLinux-270349)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: kernel-rt, AlmaLinux:8: kernel-rt-core, AlmaLinux:8: kernel-rt-debug, AlmaLinux:8: kernel-rt-debug-core, AlmaLinux:8: kernel-rt-debug-devel, AlmaLinux:8: kernel-rt-debug-modules, AlmaLinux:8: kernel-rt-debug-modules-extra, AlmaLinux:8: kernel-rt-devel, AlmaLinux:8: kernel-rt-modules, AlmaLinux:8: kernel-rt-modules-extra&lt;/p&gt;
&lt;p&gt;The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: RDMA/siw: Reject MPA FPDU length underflow before signed receive math (CVE-2026-64102)
  * kernel: vmxnet3: fix BUG_ON in vmxnet3_get_hdr_len() for Geneve packets (CVE-2026-68299)
  * kernel: net/liquidio: drop cached VF pci_dev LUT (CVE-2026-72329)
  * kernel: dm-integrity: don&amp;#39;t increment hash_offset twice (CVE-2026-72099)&lt;/p&gt;
&lt;p&gt;Bug Fix(es) and Enhancement(s):&lt;/p&gt;
&lt;p&gt;* [AlmaLinux 8.10] &amp;#34;kernel BUG at lib/list_debug.c:28!&amp;#34;: list_add corruption in register_trace_event AlmaLinux 8.10 (JIRA:AlmaLinux-214136)
  * request_key_auth use-after-free on every request-key upcall since 4.18.0-553.165.1 (regression from CVE-2026-63823 backport) (JIRA:AlmaLinux-270349)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:74132</guid>
    </item>
    <item>
      <title>BELL-CVE-2026-68299</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-68299</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-68299</guid>
    </item>
    <item>
      <title>certfr-2026-avi-1069 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de Debian LTS. Elles permettent à un attaquant de p…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1069</link>
      <description>certfr-2026-avi-1069</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-1069</guid>
    </item>
    <item>
      <title>EUVD-2026-356162</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-356162</link>
      <description>EUVD-2026-356162</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-356162</guid>
    </item>
    <item>
      <title>fkie_cve-2026-68299</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-68299</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;vmxnet3: fix BUG_ON in vmxnet3_get_hdr_len() for Geneve packets&lt;/p&gt;
&lt;p&gt;vmxnet3_get_hdr_len() assumes gdesc-&amp;gt;rcd.v4/v6/tcp always describe the
outer header, but for a Geneve-encapsulated packet the device can set
them based on the inner header instead, signalled by the
VMXNET3_RCD_HDR_INNER_SHIFT bit in the completion descriptor. Since the
function never skips the outer encapsulation, this mismatch triggers:&lt;/p&gt;
&lt;p&gt;- BUG_ON(hdr.ipv4-&amp;gt;protocol != IPPROTO_TCP), because the outer
  protocol is UDP (Geneve), not TCP.
- BUG_ON(hdr.eth-&amp;gt;h_proto != ...), when the tunnel&amp;#39;s outer and inner
  IP versions differ (e.g. outer IPv6/inner IPv4 or vice versa).&lt;/p&gt;
&lt;p&gt;Check VMXNET3_RCD_HDR_INNER_SHIFT up front and bail out, since the
function cannot locate the inner header it would need to parse. Also
convert the remaining BUG_ON()s in this function to return 0
defensively.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;vmxnet3: fix BUG_ON in vmxnet3_get_hdr_len() for Geneve packets&lt;/p&gt;
&lt;p&gt;vmxnet3_get_hdr_len() assumes gdesc-&amp;gt;rcd.v4/v6/tcp always describe the
outer header, but for a Geneve-encapsulated packet the device can set
them based on the inner header instead, signalled by the
VMXNET3_RCD_HDR_INNER_SHIFT bit in the completion descriptor. Since the
function never skips the outer encapsulation, this mismatch triggers:&lt;/p&gt;
&lt;p&gt;- BUG_ON(hdr.ipv4-&amp;gt;protocol != IPPROTO_TCP), because the outer
  protocol is UDP (Geneve), not TCP.
- BUG_ON(hdr.eth-&amp;gt;h_proto != ...), when the tunnel&amp;#39;s outer and inner
  IP versions differ (e.g. outer IPv6/inner IPv4 or vice versa).&lt;/p&gt;
&lt;p&gt;Check VMXNET3_RCD_HDR_INNER_SHIFT up front and bail out, since the
function cannot locate the inner header it would need to parse. Also
convert the remaining BUG_ON()s in this function to return 0
defensively.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-68299</guid>
    </item>
    <item>
      <title>GHSA-m243-8cm2-374c</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-m243-8cm2-374c</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;vmxnet3: fix BUG_ON in vmxnet3_get_hdr_len() for Geneve packets&lt;/p&gt;
&lt;p&gt;vmxnet3_get_hdr_len() assumes gdesc-&amp;gt;rcd.v4/v6/tcp always describe the
outer header, but for a Geneve-encapsulated packet the device can set
them based on the inner header instead, signalled by the
VMXNET3_RCD_HDR_INNER_SHIFT bit in the completion descriptor. Since the
function never skips the outer encapsulation, this mismatch triggers:&lt;/p&gt;
&lt;p&gt;- BUG_ON(hdr.ipv4-&amp;gt;protocol != IPPROTO_TCP), because the outer
  protocol is UDP (Geneve), not TCP.
- BUG_ON(hdr.eth-&amp;gt;h_proto != ...), when the tunnel&amp;#39;s outer and inner
  IP versions differ (e.g. outer IPv6/inner IPv4 or vice versa).&lt;/p&gt;
&lt;p&gt;Check VMXNET3_RCD_HDR_INNER_SHIFT up front and bail out, since the
function cannot locate the inner header it would need to parse. Also
convert the remaining BUG_ON()s in this function to return 0
defensively.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;vmxnet3: fix BUG_ON in vmxnet3_get_hdr_len() for Geneve packets&lt;/p&gt;
&lt;p&gt;vmxnet3_get_hdr_len() assumes gdesc-&amp;gt;rcd.v4/v6/tcp always describe the
outer header, but for a Geneve-encapsulated packet the device can set
them based on the inner header instead, signalled by the
VMXNET3_RCD_HDR_INNER_SHIFT bit in the completion descriptor. Since the
function never skips the outer encapsulation, this mismatch triggers:&lt;/p&gt;
&lt;p&gt;- BUG_ON(hdr.ipv4-&amp;gt;protocol != IPPROTO_TCP), because the outer
  protocol is UDP (Geneve), not TCP.
- BUG_ON(hdr.eth-&amp;gt;h_proto != ...), when the tunnel&amp;#39;s outer and inner
  IP versions differ (e.g. outer IPv6/inner IPv4 or vice versa).&lt;/p&gt;
&lt;p&gt;Check VMXNET3_RCD_HDR_INNER_SHIFT up front and bail out, since the
function cannot locate the inner header it would need to parse. Also
convert the remaining BUG_ON()s in this function to return 0
defensively.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-m243-8cm2-374c</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-68299 — vmxnet3: fix BUG_ON in vmxnet3_get_hdr_len() for Geneve packets</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-68299</link>
      <description>msrc_CVE-2026-68299</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-68299</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:21910-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:21910-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:21910-1</guid>
    </item>
    <item>
      <title>RHSA-2026:72624 — Red Hat Security Advisory: kernel security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:72624</link>
      <description>&lt;p&gt;kernel: ext4: fix e4b bitmap inconsistency reports kernel: KVM: nSVM: Raise #UD if unhandled VMMCALL isn&amp;#39;t intercepted by L1 kernel: KVM: arm64: Reassign nested_mmus array behind mmu_lock kernel: fhandle: fix UAF due to unlocked -&amp;gt;mnt_ns read in may_decode_fh() kernel: perf/core: Detach event groups during remove_on_exec kernel: vmxnet3: fix BUG_ON in vmxnet3_get_hdr_len() for Geneve packets kernel: perf: Reject exited events as group leaders kernel: crypto: tegra - fix rctx-&amp;gt;cryptlen calculation in tegra_gcm_do_one_req() kernel: nvme-tcp: reject a read that transferred too few bytes kernel: KVM: arm64: Handle negative S1 walk levels in VNCR TLB size evaluation&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;kernel: ext4: fix e4b bitmap inconsistency reports kernel: KVM: nSVM: Raise #UD if unhandled VMMCALL isn&amp;#39;t intercepted by L1 kernel: KVM: arm64: Reassign nested_mmus array behind mmu_lock kernel: fhandle: fix UAF due to unlocked -&amp;gt;mnt_ns read in may_decode_fh() kernel: perf/core: Detach event groups during remove_on_exec kernel: vmxnet3: fix BUG_ON in vmxnet3_get_hdr_len() for Geneve packets kernel: perf: Reject exited events as group leaders kernel: crypto: tegra - fix rctx-&amp;gt;cryptlen calculation in tegra_gcm_do_one_req() kernel: nvme-tcp: reject a read that transferred too few bytes kernel: KVM: arm64: Handle negative S1 walk levels in VNCR TLB size evaluation&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:72624</guid>
    </item>
    <item>
      <title>RLSA-2026:72624 — Important: kernel security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:72624</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: kernel&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: KVM: nSVM: Raise #UD if unhandled VMMCALL isn&amp;#39;t intercepted by L1 (CVE-2026-46076)&lt;/p&gt;
&lt;p&gt;* kernel: ext4: fix e4b bitmap inconsistency reports (CVE-2026-45942)&lt;/p&gt;
&lt;p&gt;* kernel: KVM: arm64: Reassign nested_mmus array behind mmu_lock (CVE-2026-46317)&lt;/p&gt;
&lt;p&gt;* kernel: fhandle: fix UAF due to unlocked -&amp;gt;mnt_ns read in may_decode_fh() (CVE-2026-53341)&lt;/p&gt;
&lt;p&gt;* kernel: perf/core: Detach event groups during remove_on_exec (CVE-2026-64556)&lt;/p&gt;
&lt;p&gt;* kernel: vmxnet3: fix BUG_ON in vmxnet3_get_hdr_len() for Geneve packets (CVE-2026-68299)&lt;/p&gt;
&lt;p&gt;* kernel: crypto: tegra - fix rctx-&amp;gt;cryptlen calculation in tegra_gcm_do_one_req() (CVE-2026-80522)&lt;/p&gt;
&lt;p&gt;* kernel: perf: Reject exited events as group leaders (CVE-2026-74753)&lt;/p&gt;
&lt;p&gt;* kernel: nvme-tcp: reject a read that transferred too few bytes (CVE-2026-89480)&lt;/p&gt;
&lt;p&gt;* kernel: KVM: arm64: Handle negative S1 walk levels in VNCR TLB size evaluation (CVE-2026-89775)&lt;/p&gt;
&lt;p&gt;Bug Fix(es) and Enhancement(s):&lt;/p&gt;
&lt;p&gt;* KVM: s390: Limit adapter indicator access to mapped page [rhel-10.2.z] (JIRA:Rocky Linux-188661)&lt;/p&gt;
&lt;p&gt;* crypto: xxhash64 should not be fips approved [rhel-10.2.z] (JIRA:Rocky Linux-254943)&lt;/p&gt;
&lt;p&gt;* kata-tdx TD vCPU stuck at reset vector (EIP=0xFFF0) on Intel Xeon 6 (Granite Rapids / Sierra Forest) ? guest never executes. (10.2.z) (JIRA:Rocky Linux-260402)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: kernel&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: KVM: nSVM: Raise #UD if unhandled VMMCALL isn&amp;#39;t intercepted by L1 (CVE-2026-46076)&lt;/p&gt;
&lt;p&gt;* kernel: ext4: fix e4b bitmap inconsistency reports (CVE-2026-45942)&lt;/p&gt;
&lt;p&gt;* kernel: KVM: arm64: Reassign nested_mmus array behind mmu_lock (CVE-2026-46317)&lt;/p&gt;
&lt;p&gt;* kernel: fhandle: fix UAF due to unlocked -&amp;gt;mnt_ns read in may_decode_fh() (CVE-2026-53341)&lt;/p&gt;
&lt;p&gt;* kernel: perf/core: Detach event groups during remove_on_exec (CVE-2026-64556)&lt;/p&gt;
&lt;p&gt;* kernel: vmxnet3: fix BUG_ON in vmxnet3_get_hdr_len() for Geneve packets (CVE-2026-68299)&lt;/p&gt;
&lt;p&gt;* kernel: crypto: tegra - fix rctx-&amp;gt;cryptlen calculation in tegra_gcm_do_one_req() (CVE-2026-80522)&lt;/p&gt;
&lt;p&gt;* kernel: perf: Reject exited events as group leaders (CVE-2026-74753)&lt;/p&gt;
&lt;p&gt;* kernel: nvme-tcp: reject a read that transferred too few bytes (CVE-2026-89480)&lt;/p&gt;
&lt;p&gt;* kernel: KVM: arm64: Handle negative S1 walk levels in VNCR TLB size evaluation (CVE-2026-89775)&lt;/p&gt;
&lt;p&gt;Bug Fix(es) and Enhancement(s):&lt;/p&gt;
&lt;p&gt;* KVM: s390: Limit adapter indicator access to mapped page [rhel-10.2.z] (JIRA:Rocky Linux-188661)&lt;/p&gt;
&lt;p&gt;* crypto: xxhash64 should not be fips approved [rhel-10.2.z] (JIRA:Rocky Linux-254943)&lt;/p&gt;
&lt;p&gt;* kata-tdx TD vCPU stuck at reset vector (EIP=0xFFF0) on Intel Xeon 6 (Granite Rapids / Sierra Forest) ? guest never executes. (10.2.z) (JIRA:Rocky Linux-260402)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:72624</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:23477-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:23477-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:23477-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-68299</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-68299</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe, Ubuntu:16.04:LTS: linux-hwe-edge and 245 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: vmxnet3: fix BUG_ON in vmxnet3_get_hdr_len() for Geneve packets vmxnet3_get_hdr_len() assumes gdesc-&amp;gt;rcd.v4/v6/tcp always describe the outer header, but for a Geneve-encapsulated packet the device can set them based on the inner header instead, signalled by the VMXNET3_RCD_HDR_INNER_SHIFT bit in the completion descriptor. Since the function never skips the outer encapsulation, this mismatch triggers: - BUG_ON(hdr.ipv4-&amp;gt;protocol != IPPROTO_TCP), because the outer   protocol is UDP (Geneve), not TCP. - BUG_ON(hdr.eth-&amp;gt;h_proto != ...), when the tunnel&amp;#39;s outer and inner   IP versions differ (e.g. outer IPv6/inner IPv4 or vice versa). Check VMXNET3_RCD_HDR_INNER_SHIFT up front and bail out, since the function cannot locate the inner header it would need to parse. Also convert the remaining BUG_ON()s in this function to return 0 defensively.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe, Ubuntu:16.04:LTS: linux-hwe-edge and 245 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: vmxnet3: fix BUG_ON in vmxnet3_get_hdr_len() for Geneve packets vmxnet3_get_hdr_len() assumes gdesc-&amp;gt;rcd.v4/v6/tcp always describe the outer header, but for a Geneve-encapsulated packet the device can set them based on the inner header instead, signalled by the VMXNET3_RCD_HDR_INNER_SHIFT bit in the completion descriptor. Since the function never skips the outer encapsulation, this mismatch triggers: - BUG_ON(hdr.ipv4-&amp;gt;protocol != IPPROTO_TCP), because the outer   protocol is UDP (Geneve), not TCP. - BUG_ON(hdr.eth-&amp;gt;h_proto != ...), when the tunnel&amp;#39;s outer and inner   IP versions differ (e.g. outer IPv6/inner IPv4 or vice versa). Check VMXNET3_RCD_HDR_INNER_SHIFT up front and bail out, since the function cannot locate the inner header it would need to parse. Also convert the remaining BUG_ON()s in this function to return 0 defensively.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-68299</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2730 — Linux Kernel: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2730</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen, darunter möglicherweise die Ausführung von beliebigem Code, die Ausweitung von Berechtigungen, die Offenlegung von Informationen, die Manipulation von Daten oder Denial-of-Service-Zustände.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen, darunter möglicherweise die Ausführung von beliebigem Code, die Ausweitung von Berechtigungen, die Offenlegung von Informationen, die Manipulation von Daten oder Denial-of-Service-Zustände.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2730</guid>
    </item>
  </channel>
</rss>
