<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 04:10:16 +0000</lastBuildDate>
    <item>
      <title>ALSA-2026:66324 — Important: kernel-rt security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:66324</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: kernel-rt, AlmaLinux:8: kernel-rt-core, AlmaLinux:8: kernel-rt-debug, AlmaLinux:8: kernel-rt-debug-core, AlmaLinux:8: kernel-rt-debug-devel, AlmaLinux:8: kernel-rt-debug-modules, AlmaLinux:8: kernel-rt-debug-modules-extra, AlmaLinux:8: kernel-rt-devel, AlmaLinux:8: kernel-rt-modules, AlmaLinux:8: kernel-rt-modules-extra&lt;/p&gt;
&lt;p&gt;The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: Linux kernel: Denial of Service in qla2xxx SCSI driver due to improper command handling after chip reset (CVE-2025-68745)
  * kernel: scsi: target: configfs: Bound snprintf() return in tg_pt_gp_members_show() (CVE-2026-46149)
  * kernel: netfilter: nf_log: validate MAC header was set before dumping it (CVE-2026-52942)
  * kernel: sctp: diag: reject stale associations in dump_one path (CVE-2026-52917)
  * kernel: net: pull headers in qdisc_pkt_len_segs_init() (CVE-2026-53091)
  * kernel: netfilter: nf_conntrack_sip: don&amp;#39;t use simple_strtoul (CVE-2026-52986)
  * kernel: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing (CVE-2026-53246)
  * kernel: tipc: fix slab-use-after-free Read in tipc_aead_decrypt_done (CVE-2026-63801)
  * kernel: sctp: fix race between sctp_wait_for_connect and peeloff (CVE-2026-63971)
  * kernel: security/keys: fix missed RCU read section on lookup (CVE-2026-64015)
  * kernel: ixgbevf: fix use-after-free in VEPA multicast source pruning (CVE-2026-64113)
  * kernel: sctp: fix auth_hmacs array size in struct sctp_cookie (CVE-2026-68376)
  * kernel: tipc: clear sock-&amp;gt;sk on the failed-insert path in tipc_sk_create() (CVE-2026-68117)
  * kernel: sctp: auth: verify auth requirement when auth_chunk is NULL (CVE-2026-68300)
  * kernel: sctp: validate stream count i…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: kernel-rt, AlmaLinux:8: kernel-rt-core, AlmaLinux:8: kernel-rt-debug, AlmaLinux:8: kernel-rt-debug-core, AlmaLinux:8: kernel-rt-debug-devel, AlmaLinux:8: kernel-rt-debug-modules, AlmaLinux:8: kernel-rt-debug-modules-extra, AlmaLinux:8: kernel-rt-devel, AlmaLinux:8: kernel-rt-modules, AlmaLinux:8: kernel-rt-modules-extra&lt;/p&gt;
&lt;p&gt;The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: Linux kernel: Denial of Service in qla2xxx SCSI driver due to improper command handling after chip reset (CVE-2025-68745)
  * kernel: scsi: target: configfs: Bound snprintf() return in tg_pt_gp_members_show() (CVE-2026-46149)
  * kernel: netfilter: nf_log: validate MAC header was set before dumping it (CVE-2026-52942)
  * kernel: sctp: diag: reject stale associations in dump_one path (CVE-2026-52917)
  * kernel: net: pull headers in qdisc_pkt_len_segs_init() (CVE-2026-53091)
  * kernel: netfilter: nf_conntrack_sip: don&amp;#39;t use simple_strtoul (CVE-2026-52986)
  * kernel: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing (CVE-2026-53246)
  * kernel: tipc: fix slab-use-after-free Read in tipc_aead_decrypt_done (CVE-2026-63801)
  * kernel: sctp: fix race between sctp_wait_for_connect and peeloff (CVE-2026-63971)
  * kernel: security/keys: fix missed RCU read section on lookup (CVE-2026-64015)
  * kernel: ixgbevf: fix use-after-free in VEPA multicast source pruning (CVE-2026-64113)
  * kernel: sctp: fix auth_hmacs array size in struct sctp_cookie (CVE-2026-68376)
  * kernel: tipc: clear sock-&amp;gt;sk on the failed-insert path in tipc_sk_create() (CVE-2026-68117)
  * kernel: sctp: auth: verify auth requirement when auth_chunk is NULL (CVE-2026-68300)
  * kernel: sctp: validate stream count i…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:66324</guid>
    </item>
    <item>
      <title>BELL-CVE-2026-68315</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-68315</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-68315</guid>
    </item>
    <item>
      <title>certfr-2026-avi-1069 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de Debian LTS. Elles permettent à un attaquant de p…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1069</link>
      <description>certfr-2026-avi-1069</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-1069</guid>
    </item>
    <item>
      <title>EUVD-2026-356170</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-356170</link>
      <description>EUVD-2026-356170</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-356170</guid>
    </item>
    <item>
      <title>fkie_cve-2026-68315</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-68315</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;sctp: validate stream count in sctp_process_strreset_inreq()&lt;/p&gt;
&lt;p&gt;When processing a RESET_IN_REQUEST from a peer,
sctp_process_strreset_inreq() derives the stream count from the
parameter length but does not check whether the resulting
RESET_OUT_REQUEST would exceed SCTP_MAX_CHUNK_LEN.&lt;/p&gt;
&lt;p&gt;The OUT request header (sctp_strreset_outreq, 16 bytes) is 8 bytes
larger than the IN request header (sctp_strreset_inreq, 8 bytes).
Generally, the IP payload is bounded to 65535 bytes, so the stream
list cannot be large enough to trigger the overflow. However, on
interfaces with MTU &amp;gt; 65535 (e.g., loopback with IPv6 jumbograms), a
stream list that fits within the incoming IN parameter can cause a
__u16 overflow in sctp_make_strreset_req() when computing the OUT
request size, leading to an undersized skb allocation and a kernel
BUG:&lt;/p&gt;
&lt;p&gt;net/core/skbuff.c:207         skb_panic
  net/core/skbuff.c:2625        skb_put
  net/sctp/sm_make_chunk.c:1535 sctp_addto_chunk
  net/sctp/sm_make_chunk.c:3695 sctp_make_strreset_req
  net/sctp/stream.c:655         sctp_process_strreset_inreq&lt;/p&gt;
&lt;p&gt;The local setsockopt path validates the generated reset request size.
However, for an incoming-only reset, it accounts for the smaller IN
request even though the peer must generate an OUT request with the same
stream list. Such a request cannot be completed successfully by the
peer.&lt;/p&gt;
&lt;p&gt;Reject peer IN requests whose corresponding OUT request would exceed
SCTP_…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;sctp: validate stream count in sctp_process_strreset_inreq()&lt;/p&gt;
&lt;p&gt;When processing a RESET_IN_REQUEST from a peer,
sctp_process_strreset_inreq() derives the stream count from the
parameter length but does not check whether the resulting
RESET_OUT_REQUEST would exceed SCTP_MAX_CHUNK_LEN.&lt;/p&gt;
&lt;p&gt;The OUT request header (sctp_strreset_outreq, 16 bytes) is 8 bytes
larger than the IN request header (sctp_strreset_inreq, 8 bytes).
Generally, the IP payload is bounded to 65535 bytes, so the stream
list cannot be large enough to trigger the overflow. However, on
interfaces with MTU &amp;gt; 65535 (e.g., loopback with IPv6 jumbograms), a
stream list that fits within the incoming IN parameter can cause a
__u16 overflow in sctp_make_strreset_req() when computing the OUT
request size, leading to an undersized skb allocation and a kernel
BUG:&lt;/p&gt;
&lt;p&gt;net/core/skbuff.c:207         skb_panic
  net/core/skbuff.c:2625        skb_put
  net/sctp/sm_make_chunk.c:1535 sctp_addto_chunk
  net/sctp/sm_make_chunk.c:3695 sctp_make_strreset_req
  net/sctp/stream.c:655         sctp_process_strreset_inreq&lt;/p&gt;
&lt;p&gt;The local setsockopt path validates the generated reset request size.
However, for an incoming-only reset, it accounts for the smaller IN
request even though the peer must generate an OUT request with the same
stream list. Such a request cannot be completed successfully by the
peer.&lt;/p&gt;
&lt;p&gt;Reject peer IN requests whose corresponding OUT request would exceed
SCTP_…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-68315</guid>
    </item>
    <item>
      <title>GHSA-xm4m-qj4q-fpc2</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-xm4m-qj4q-fpc2</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;sctp: validate stream count in sctp_process_strreset_inreq()&lt;/p&gt;
&lt;p&gt;When processing a RESET_IN_REQUEST from a peer,
sctp_process_strreset_inreq() derives the stream count from the
parameter length but does not check whether the resulting
RESET_OUT_REQUEST would exceed SCTP_MAX_CHUNK_LEN.&lt;/p&gt;
&lt;p&gt;The OUT request header (sctp_strreset_outreq, 16 bytes) is 8 bytes
larger than the IN request header (sctp_strreset_inreq, 8 bytes).
Generally, the IP payload is bounded to 65535 bytes, so the stream
list cannot be large enough to trigger the overflow. However, on
interfaces with MTU &amp;gt; 65535 (e.g., loopback with IPv6 jumbograms), a
stream list that fits within the incoming IN parameter can cause a
__u16 overflow in sctp_make_strreset_req() when computing the OUT
request size, leading to an undersized skb allocation and a kernel
BUG:&lt;/p&gt;
&lt;p&gt;net/core/skbuff.c:207         skb_panic
  net/core/skbuff.c:2625        skb_put
  net/sctp/sm_make_chunk.c:1535 sctp_addto_chunk
  net/sctp/sm_make_chunk.c:3695 sctp_make_strreset_req
  net/sctp/stream.c:655         sctp_process_strreset_inreq&lt;/p&gt;
&lt;p&gt;The local setsockopt path validates the generated reset request size.
However, for an incoming-only reset, it accounts for the smaller IN
request even though the peer must generate an OUT request with the same
stream list. Such a request cannot be completed successfully by the
peer.&lt;/p&gt;
&lt;p&gt;Reject peer IN requests whose corresponding OUT request would exceed
SCTP_…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;sctp: validate stream count in sctp_process_strreset_inreq()&lt;/p&gt;
&lt;p&gt;When processing a RESET_IN_REQUEST from a peer,
sctp_process_strreset_inreq() derives the stream count from the
parameter length but does not check whether the resulting
RESET_OUT_REQUEST would exceed SCTP_MAX_CHUNK_LEN.&lt;/p&gt;
&lt;p&gt;The OUT request header (sctp_strreset_outreq, 16 bytes) is 8 bytes
larger than the IN request header (sctp_strreset_inreq, 8 bytes).
Generally, the IP payload is bounded to 65535 bytes, so the stream
list cannot be large enough to trigger the overflow. However, on
interfaces with MTU &amp;gt; 65535 (e.g., loopback with IPv6 jumbograms), a
stream list that fits within the incoming IN parameter can cause a
__u16 overflow in sctp_make_strreset_req() when computing the OUT
request size, leading to an undersized skb allocation and a kernel
BUG:&lt;/p&gt;
&lt;p&gt;net/core/skbuff.c:207         skb_panic
  net/core/skbuff.c:2625        skb_put
  net/sctp/sm_make_chunk.c:1535 sctp_addto_chunk
  net/sctp/sm_make_chunk.c:3695 sctp_make_strreset_req
  net/sctp/stream.c:655         sctp_process_strreset_inreq&lt;/p&gt;
&lt;p&gt;The local setsockopt path validates the generated reset request size.
However, for an incoming-only reset, it accounts for the smaller IN
request even though the peer must generate an OUT request with the same
stream list. Such a request cannot be completed successfully by the
peer.&lt;/p&gt;
&lt;p&gt;Reject peer IN requests whose corresponding OUT request would exceed
SCTP_…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-xm4m-qj4q-fpc2</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-68315 — sctp: validate stream count in sctp_process_strreset_inreq()</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-68315</link>
      <description>msrc_CVE-2026-68315</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-68315</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:21910-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:21910-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:21910-1</guid>
    </item>
    <item>
      <title>RHSA-2026:66324 — Red Hat Security Advisory: kernel-rt security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:66324</link>
      <description>&lt;p&gt;kernel: Linux kernel: Denial of Service in qla2xxx SCSI driver due to improper command handling after chip reset kernel: scsi: target: configfs: Bound snprintf() return in tg_pt_gp_members_show() kernel: sctp: diag: reject stale associations in dump_one path kernel: netfilter: nf_log: validate MAC header was set before dumping it kernel: netfilter: nf_conntrack_sip: don&amp;#39;t use simple_strtoul kernel: net: pull headers in qdisc_pkt_len_segs_init() kernel: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing kernel: tipc: fix slab-use-after-free Read in tipc_aead_decrypt_done kernel: sctp: fix race between sctp_wait_for_connect and peeloff kernel: security/keys: fix missed RCU read section on lookup kernel: ixgbevf: fix use-after-free in VEPA multicast source pruning kernel: tipc: clear sock-&amp;gt;sk on the failed-insert path in tipc_sk_create() kernel: sctp: auth: verify auth requirement when auth_chunk is NULL kernel: sctp: validate stream count in sctp_process_strreset_inreq() kernel: sctp: fix auth_hmacs array size in struct sctp_cookie&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;kernel: Linux kernel: Denial of Service in qla2xxx SCSI driver due to improper command handling after chip reset kernel: scsi: target: configfs: Bound snprintf() return in tg_pt_gp_members_show() kernel: sctp: diag: reject stale associations in dump_one path kernel: netfilter: nf_log: validate MAC header was set before dumping it kernel: netfilter: nf_conntrack_sip: don&amp;#39;t use simple_strtoul kernel: net: pull headers in qdisc_pkt_len_segs_init() kernel: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing kernel: tipc: fix slab-use-after-free Read in tipc_aead_decrypt_done kernel: sctp: fix race between sctp_wait_for_connect and peeloff kernel: security/keys: fix missed RCU read section on lookup kernel: ixgbevf: fix use-after-free in VEPA multicast source pruning kernel: tipc: clear sock-&amp;gt;sk on the failed-insert path in tipc_sk_create() kernel: sctp: auth: verify auth requirement when auth_chunk is NULL kernel: sctp: validate stream count in sctp_process_strreset_inreq() kernel: sctp: fix auth_hmacs array size in struct sctp_cookie&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:66324</guid>
    </item>
    <item>
      <title>RLSA-2026:66324 — Important: kernel-rt security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:66324</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:8: kernel-rt&lt;/p&gt;
&lt;p&gt;The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: Linux kernel: Denial of Service in qla2xxx SCSI driver due to improper command handling after chip reset (CVE-2025-68745)&lt;/p&gt;
&lt;p&gt;* kernel: scsi: target: configfs: Bound snprintf() return in tg_pt_gp_members_show() (CVE-2026-46149)&lt;/p&gt;
&lt;p&gt;* kernel: netfilter: nf_log: validate MAC header was set before dumping it (CVE-2026-52942)&lt;/p&gt;
&lt;p&gt;* kernel: sctp: diag: reject stale associations in dump_one path (CVE-2026-52917)&lt;/p&gt;
&lt;p&gt;* kernel: net: pull headers in qdisc_pkt_len_segs_init() (CVE-2026-53091)&lt;/p&gt;
&lt;p&gt;* kernel: netfilter: nf_conntrack_sip: don&amp;#39;t use simple_strtoul (CVE-2026-52986)&lt;/p&gt;
&lt;p&gt;* kernel: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing (CVE-2026-53246)&lt;/p&gt;
&lt;p&gt;* kernel: tipc: fix slab-use-after-free Read in tipc_aead_decrypt_done (CVE-2026-63801)&lt;/p&gt;
&lt;p&gt;* kernel: sctp: fix race between sctp_wait_for_connect and peeloff (CVE-2026-63971)&lt;/p&gt;
&lt;p&gt;* kernel: security/keys: fix missed RCU read section on lookup (CVE-2026-64015)&lt;/p&gt;
&lt;p&gt;* kernel: ixgbevf: fix use-after-free in VEPA multicast source pruning (CVE-2026-64113)&lt;/p&gt;
&lt;p&gt;* kernel: sctp: fix auth_hmacs array size in struct sctp_cookie (CVE-2026-68376)&lt;/p&gt;
&lt;p&gt;* kernel: tipc: clear sock-&amp;gt;sk on the failed-insert path in tipc_sk_create() (CVE-2026-68117)&lt;/p&gt;
&lt;p&gt;* kernel: sctp: auth: verify auth requirement when auth_chunk is NULL (CVE-2026-68300)&lt;/p&gt;
&lt;p&gt;* kernel: sctp: validate stream count in sctp_process_strre…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:8: kernel-rt&lt;/p&gt;
&lt;p&gt;The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: Linux kernel: Denial of Service in qla2xxx SCSI driver due to improper command handling after chip reset (CVE-2025-68745)&lt;/p&gt;
&lt;p&gt;* kernel: scsi: target: configfs: Bound snprintf() return in tg_pt_gp_members_show() (CVE-2026-46149)&lt;/p&gt;
&lt;p&gt;* kernel: netfilter: nf_log: validate MAC header was set before dumping it (CVE-2026-52942)&lt;/p&gt;
&lt;p&gt;* kernel: sctp: diag: reject stale associations in dump_one path (CVE-2026-52917)&lt;/p&gt;
&lt;p&gt;* kernel: net: pull headers in qdisc_pkt_len_segs_init() (CVE-2026-53091)&lt;/p&gt;
&lt;p&gt;* kernel: netfilter: nf_conntrack_sip: don&amp;#39;t use simple_strtoul (CVE-2026-52986)&lt;/p&gt;
&lt;p&gt;* kernel: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing (CVE-2026-53246)&lt;/p&gt;
&lt;p&gt;* kernel: tipc: fix slab-use-after-free Read in tipc_aead_decrypt_done (CVE-2026-63801)&lt;/p&gt;
&lt;p&gt;* kernel: sctp: fix race between sctp_wait_for_connect and peeloff (CVE-2026-63971)&lt;/p&gt;
&lt;p&gt;* kernel: security/keys: fix missed RCU read section on lookup (CVE-2026-64015)&lt;/p&gt;
&lt;p&gt;* kernel: ixgbevf: fix use-after-free in VEPA multicast source pruning (CVE-2026-64113)&lt;/p&gt;
&lt;p&gt;* kernel: sctp: fix auth_hmacs array size in struct sctp_cookie (CVE-2026-68376)&lt;/p&gt;
&lt;p&gt;* kernel: tipc: clear sock-&amp;gt;sk on the failed-insert path in tipc_sk_create() (CVE-2026-68117)&lt;/p&gt;
&lt;p&gt;* kernel: sctp: auth: verify auth requirement when auth_chunk is NULL (CVE-2026-68300)&lt;/p&gt;
&lt;p&gt;* kernel: sctp: validate stream count in sctp_process_strre…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:66324</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:23477-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:23477-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:23477-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-68315</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-68315</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe, Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:Pro:16.04:LTS: linux-oracle, Ubuntu:Pro:18.04:LTS: linux, Ubuntu:Pro:18.04:LTS: linux-aws, Ubuntu:18.04:LTS: linux-aws-5.0 and 239 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: sctp: validate stream count in sctp_process_strreset_inreq() When processing a RESET_IN_REQUEST from a peer, sctp_process_strreset_inreq() derives the stream count from the parameter length but does not check whether the resulting RESET_OUT_REQUEST would exceed SCTP_MAX_CHUNK_LEN. The OUT request header (sctp_strreset_outreq, 16 bytes) is 8 bytes larger than the IN request header (sctp_strreset_inreq, 8 bytes). Generally, the IP payload is bounded to 65535 bytes, so the stream list cannot be large enough to trigger the overflow. However, on interfaces with MTU &amp;gt; 65535 (e.g., loopback with IPv6 jumbograms), a stream list that fits within the incoming IN parameter can cause a __u16 overflow in sctp_make_strreset_req() when computing the OUT request size, leading to an undersized skb allocation and a kernel BUG:   net/core/skbuff.c:207         skb_panic   net/core/skbuff.c:2625        skb_put   net/sctp/sm_make_chunk.c:1535 sctp_addto_chunk   net/sctp/sm_make_chunk.c:3695 sctp_make_strreset_req   net/sctp/stream.c:655         sctp_process_strreset_inreq The local setsockopt path validates the generated reset request size. However, for an incoming-only reset, it accounts for the smaller IN request even though the peer must generate an OUT request with the same stream list. Such a request cannot be completed successfully by the peer. Reject peer IN requests whose corresponding OUT request would exceed SCTP_MAX_CH…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe, Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:Pro:16.04:LTS: linux-oracle, Ubuntu:Pro:18.04:LTS: linux, Ubuntu:Pro:18.04:LTS: linux-aws, Ubuntu:18.04:LTS: linux-aws-5.0 and 239 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: sctp: validate stream count in sctp_process_strreset_inreq() When processing a RESET_IN_REQUEST from a peer, sctp_process_strreset_inreq() derives the stream count from the parameter length but does not check whether the resulting RESET_OUT_REQUEST would exceed SCTP_MAX_CHUNK_LEN. The OUT request header (sctp_strreset_outreq, 16 bytes) is 8 bytes larger than the IN request header (sctp_strreset_inreq, 8 bytes). Generally, the IP payload is bounded to 65535 bytes, so the stream list cannot be large enough to trigger the overflow. However, on interfaces with MTU &amp;gt; 65535 (e.g., loopback with IPv6 jumbograms), a stream list that fits within the incoming IN parameter can cause a __u16 overflow in sctp_make_strreset_req() when computing the OUT request size, leading to an undersized skb allocation and a kernel BUG:   net/core/skbuff.c:207         skb_panic   net/core/skbuff.c:2625        skb_put   net/sctp/sm_make_chunk.c:1535 sctp_addto_chunk   net/sctp/sm_make_chunk.c:3695 sctp_make_strreset_req   net/sctp/stream.c:655         sctp_process_strreset_inreq The local setsockopt path validates the generated reset request size. However, for an incoming-only reset, it accounts for the smaller IN request even though the peer must generate an OUT request with the same stream list. Such a request cannot be completed successfully by the peer. Reject peer IN requests whose corresponding OUT request would exceed SCTP_MAX_CH…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-68315</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2730 — Linux Kernel: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2730</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen, darunter möglicherweise die Ausführung von beliebigem Code, die Ausweitung von Berechtigungen, die Offenlegung von Informationen, die Manipulation von Daten oder Denial-of-Service-Zustände.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen, darunter möglicherweise die Ausführung von beliebigem Code, die Ausweitung von Berechtigungen, die Offenlegung von Informationen, die Manipulation von Daten oder Denial-of-Service-Zustände.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2730</guid>
    </item>
  </channel>
</rss>
