<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 03:39:20 +0000</lastBuildDate>
    <item>
      <title>BELL-CVE-2026-68302</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-68302</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-68302</guid>
    </item>
    <item>
      <title>certfr-2026-avi-1069 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de Debian LTS. Elles permettent à un attaquant de p…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1069</link>
      <description>certfr-2026-avi-1069</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-1069</guid>
    </item>
    <item>
      <title>EUVD-2026-356165</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-356165</link>
      <description>EUVD-2026-356165</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-356165</guid>
    </item>
    <item>
      <title>fkie_cve-2026-68302</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-68302</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;amt: re-read skb header pointers after every pull&lt;/p&gt;
&lt;p&gt;Several AMT receive and transmit paths cache a pointer into the skb head
(ip_hdr(), ipv6_hdr(), eth_hdr() or the AMT message header) and then call
a helper that can reallocate that head before the cached pointer is used
again.  pskb_may_pull(), ip_mc_may_pull(), ipv6_mc_may_pull(),
iptunnel_pull_header(), ip_mc_check_igmp() and ipv6_mc_check_mld() can all
free the old head and move the data, so a pointer taken before the call
dangles afterwards and the later access is a use-after-free of the freed
head.&lt;/p&gt;
&lt;p&gt;The affected sites are:&lt;/p&gt;
&lt;p&gt;amt_rcv() caches ip_hdr() before amt_parse_type() pulls, then reads
  iph-&amp;gt;saddr.&lt;/p&gt;
&lt;p&gt;amt_dev_xmit() caches ip_hdr()/ipv6_hdr() before ip_mc_check_igmp()/
  ipv6_mc_check_mld() and pskb_may_pull(), then reads the group address.&lt;/p&gt;
&lt;p&gt;amt_multicast_data_handler() caches eth_hdr() before pskb_may_pull(),
  then writes the L2 header.&lt;/p&gt;
&lt;p&gt;amt_membership_query_handler() caches the AMT header, the outer and
  inner eth_hdr() and ip_hdr() before iptunnel_pull_header() and several
  pulls, then reads and writes them.&lt;/p&gt;
&lt;p&gt;amt_igmpv3_report_handler() and amt_mldv2_report_handler() cache
  ip_hdr()/ipv6_hdr() and the current group record and read the record
  count from the report header inside the record loop, across the
  *_mc_may_pull() calls.&lt;/p&gt;
&lt;p&gt;amt_update_handler() caches ip_hdr() and the AMT membership-update
  header before pskb_may_pull(),…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;amt: re-read skb header pointers after every pull&lt;/p&gt;
&lt;p&gt;Several AMT receive and transmit paths cache a pointer into the skb head
(ip_hdr(), ipv6_hdr(), eth_hdr() or the AMT message header) and then call
a helper that can reallocate that head before the cached pointer is used
again.  pskb_may_pull(), ip_mc_may_pull(), ipv6_mc_may_pull(),
iptunnel_pull_header(), ip_mc_check_igmp() and ipv6_mc_check_mld() can all
free the old head and move the data, so a pointer taken before the call
dangles afterwards and the later access is a use-after-free of the freed
head.&lt;/p&gt;
&lt;p&gt;The affected sites are:&lt;/p&gt;
&lt;p&gt;amt_rcv() caches ip_hdr() before amt_parse_type() pulls, then reads
  iph-&amp;gt;saddr.&lt;/p&gt;
&lt;p&gt;amt_dev_xmit() caches ip_hdr()/ipv6_hdr() before ip_mc_check_igmp()/
  ipv6_mc_check_mld() and pskb_may_pull(), then reads the group address.&lt;/p&gt;
&lt;p&gt;amt_multicast_data_handler() caches eth_hdr() before pskb_may_pull(),
  then writes the L2 header.&lt;/p&gt;
&lt;p&gt;amt_membership_query_handler() caches the AMT header, the outer and
  inner eth_hdr() and ip_hdr() before iptunnel_pull_header() and several
  pulls, then reads and writes them.&lt;/p&gt;
&lt;p&gt;amt_igmpv3_report_handler() and amt_mldv2_report_handler() cache
  ip_hdr()/ipv6_hdr() and the current group record and read the record
  count from the report header inside the record loop, across the
  *_mc_may_pull() calls.&lt;/p&gt;
&lt;p&gt;amt_update_handler() caches ip_hdr() and the AMT membership-update
  header before pskb_may_pull(),…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-68302</guid>
    </item>
    <item>
      <title>GHSA-9gq3-j787-cjhr</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-9gq3-j787-cjhr</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;amt: re-read skb header pointers after every pull&lt;/p&gt;
&lt;p&gt;Several AMT receive and transmit paths cache a pointer into the skb head
(ip_hdr(), ipv6_hdr(), eth_hdr() or the AMT message header) and then call
a helper that can reallocate that head before the cached pointer is used
again.  pskb_may_pull(), ip_mc_may_pull(), ipv6_mc_may_pull(),
iptunnel_pull_header(), ip_mc_check_igmp() and ipv6_mc_check_mld() can all
free the old head and move the data, so a pointer taken before the call
dangles afterwards and the later access is a use-after-free of the freed
head.&lt;/p&gt;
&lt;p&gt;The affected sites are:&lt;/p&gt;
&lt;p&gt;amt_rcv() caches ip_hdr() before amt_parse_type() pulls, then reads
  iph-&amp;gt;saddr.&lt;/p&gt;
&lt;p&gt;amt_dev_xmit() caches ip_hdr()/ipv6_hdr() before ip_mc_check_igmp()/
  ipv6_mc_check_mld() and pskb_may_pull(), then reads the group address.&lt;/p&gt;
&lt;p&gt;amt_multicast_data_handler() caches eth_hdr() before pskb_may_pull(),
  then writes the L2 header.&lt;/p&gt;
&lt;p&gt;amt_membership_query_handler() caches the AMT header, the outer and
  inner eth_hdr() and ip_hdr() before iptunnel_pull_header() and several
  pulls, then reads and writes them.&lt;/p&gt;
&lt;p&gt;amt_igmpv3_report_handler() and amt_mldv2_report_handler() cache
  ip_hdr()/ipv6_hdr() and the current group record and read the record
  count from the report header inside the record loop, across the
  *_mc_may_pull() calls.&lt;/p&gt;
&lt;p&gt;amt_update_handler() caches ip_hdr() and the AMT membership-update
  header before pskb_may_pull(),…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;amt: re-read skb header pointers after every pull&lt;/p&gt;
&lt;p&gt;Several AMT receive and transmit paths cache a pointer into the skb head
(ip_hdr(), ipv6_hdr(), eth_hdr() or the AMT message header) and then call
a helper that can reallocate that head before the cached pointer is used
again.  pskb_may_pull(), ip_mc_may_pull(), ipv6_mc_may_pull(),
iptunnel_pull_header(), ip_mc_check_igmp() and ipv6_mc_check_mld() can all
free the old head and move the data, so a pointer taken before the call
dangles afterwards and the later access is a use-after-free of the freed
head.&lt;/p&gt;
&lt;p&gt;The affected sites are:&lt;/p&gt;
&lt;p&gt;amt_rcv() caches ip_hdr() before amt_parse_type() pulls, then reads
  iph-&amp;gt;saddr.&lt;/p&gt;
&lt;p&gt;amt_dev_xmit() caches ip_hdr()/ipv6_hdr() before ip_mc_check_igmp()/
  ipv6_mc_check_mld() and pskb_may_pull(), then reads the group address.&lt;/p&gt;
&lt;p&gt;amt_multicast_data_handler() caches eth_hdr() before pskb_may_pull(),
  then writes the L2 header.&lt;/p&gt;
&lt;p&gt;amt_membership_query_handler() caches the AMT header, the outer and
  inner eth_hdr() and ip_hdr() before iptunnel_pull_header() and several
  pulls, then reads and writes them.&lt;/p&gt;
&lt;p&gt;amt_igmpv3_report_handler() and amt_mldv2_report_handler() cache
  ip_hdr()/ipv6_hdr() and the current group record and read the record
  count from the report header inside the record loop, across the
  *_mc_may_pull() calls.&lt;/p&gt;
&lt;p&gt;amt_update_handler() caches ip_hdr() and the AMT membership-update
  header before pskb_may_pull(),…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-9gq3-j787-cjhr</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-68302 — amt: re-read skb header pointers after every pull</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-68302</link>
      <description>msrc_CVE-2026-68302</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-68302</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:21910-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:21910-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:21910-1</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:23881-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:23881-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:23881-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-68302</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-68302</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 154 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: amt: re-read skb header pointers after every pull Several AMT receive and transmit paths cache a pointer into the skb head (ip_hdr(), ipv6_hdr(), eth_hdr() or the AMT message header) and then call a helper that can reallocate that head before the cached pointer is used again.  pskb_may_pull(), ip_mc_may_pull(), ipv6_mc_may_pull(), iptunnel_pull_header(), ip_mc_check_igmp() and ipv6_mc_check_mld() can all free the old head and move the data, so a pointer taken before the call dangles afterwards and the later access is a use-after-free of the freed head. The affected sites are:   amt_rcv() caches ip_hdr() before amt_parse_type() pulls, then reads   iph-&amp;gt;saddr.   amt_dev_xmit() caches ip_hdr()/ipv6_hdr() before ip_mc_check_igmp()/   ipv6_mc_check_mld() and pskb_may_pull(), then reads the group address.   amt_multicast_data_handler() caches eth_hdr() before pskb_may_pull(),   then writes the L2 header.   amt_membership_query_handler() caches the AMT header, the outer and   inner eth_hdr() and ip_hdr() before iptunnel_pull_header() and several   pulls, then reads and writes them.   amt_igmpv3_report_handler() and amt_mldv2_report_handler() cache   ip_hdr()/ipv6_hdr() and the current group record and read the record   count from the report header inside the record loop, across the   *_mc_may_pull() calls.   amt_update_handler() caches ip_hdr() and the AMT membership-update   header before pskb_may_pull(), iptunnel…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 154 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: amt: re-read skb header pointers after every pull Several AMT receive and transmit paths cache a pointer into the skb head (ip_hdr(), ipv6_hdr(), eth_hdr() or the AMT message header) and then call a helper that can reallocate that head before the cached pointer is used again.  pskb_may_pull(), ip_mc_may_pull(), ipv6_mc_may_pull(), iptunnel_pull_header(), ip_mc_check_igmp() and ipv6_mc_check_mld() can all free the old head and move the data, so a pointer taken before the call dangles afterwards and the later access is a use-after-free of the freed head. The affected sites are:   amt_rcv() caches ip_hdr() before amt_parse_type() pulls, then reads   iph-&amp;gt;saddr.   amt_dev_xmit() caches ip_hdr()/ipv6_hdr() before ip_mc_check_igmp()/   ipv6_mc_check_mld() and pskb_may_pull(), then reads the group address.   amt_multicast_data_handler() caches eth_hdr() before pskb_may_pull(),   then writes the L2 header.   amt_membership_query_handler() caches the AMT header, the outer and   inner eth_hdr() and ip_hdr() before iptunnel_pull_header() and several   pulls, then reads and writes them.   amt_igmpv3_report_handler() and amt_mldv2_report_handler() cache   ip_hdr()/ipv6_hdr() and the current group record and read the record   count from the report header inside the record loop, across the   *_mc_may_pull() calls.   amt_update_handler() caches ip_hdr() and the AMT membership-update   header before pskb_may_pull(), iptunnel…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-68302</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2730 — Linux Kernel: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2730</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen, darunter möglicherweise die Ausführung von beliebigem Code, die Ausweitung von Berechtigungen, die Offenlegung von Informationen, die Manipulation von Daten oder Denial-of-Service-Zustände.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen, darunter möglicherweise die Ausführung von beliebigem Code, die Ausweitung von Berechtigungen, die Offenlegung von Informationen, die Manipulation von Daten oder Denial-of-Service-Zustände.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2730</guid>
    </item>
  </channel>
</rss>
