<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 08:43:14 +0000</lastBuildDate>
    <item>
      <title>ALSA-2026:67468 — Important: kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:67468</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: bpftool, AlmaLinux:8: kernel, AlmaLinux:8: kernel-abi-stablelists, AlmaLinux:8: kernel-core, AlmaLinux:8: kernel-cross-headers, AlmaLinux:8: kernel-debug, AlmaLinux:8: kernel-debug-core, AlmaLinux:8: kernel-debug-devel, AlmaLinux:8: kernel-debug-modules, AlmaLinux:8: kernel-debug-modules-extra and 15 more&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: EDAC/bluefield: Fix potential integer overflow (CVE-2024-53161)
  * kernel: wifi: mac80211: Discard Beacon frames to non-broadcast address (CVE-2025-71127)
  * kernel: KVM: nSVM: Always use vmcb01 in VMLOAD/VMSAVE emulation (CVE-2026-43133)
  * kernel: net: qrtr: fix refcount saturation and potential UAF in qrtr_port_remove (CVE-2026-52947)
  * kernel: wifi: nl80211: reject oversized EMA RNR lists (CVE-2026-53182)
  * kernel: blk-cgroup: fix UAF in __blkcg_rstat_flush() (CVE-2026-63802)
  * kernel: scsi: scsi_transport_fc: Widen FPIN pname walker counter to u32 (CVE-2026-63889)
  * kernel: wifi: mac80211: capture fast-RX rate before mesh reuses skb-&amp;gt;cb (CVE-2026-64117)
  * kernel: Linux kernel: ath9k Wi-Fi driver use-after-free vulnerability leading to system crash (CVE-2026-68363)
  * kernel: dm-verity: fix buffer overflow in FEC calculation (CVE-2026-72098)
  * kernel: scsi: libiscsi_tcp: Bound SCSI Response data segment to the connection buffer (CVE-2026-74556)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: bpftool, AlmaLinux:8: kernel, AlmaLinux:8: kernel-abi-stablelists, AlmaLinux:8: kernel-core, AlmaLinux:8: kernel-cross-headers, AlmaLinux:8: kernel-debug, AlmaLinux:8: kernel-debug-core, AlmaLinux:8: kernel-debug-devel, AlmaLinux:8: kernel-debug-modules, AlmaLinux:8: kernel-debug-modules-extra and 15 more&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: EDAC/bluefield: Fix potential integer overflow (CVE-2024-53161)
  * kernel: wifi: mac80211: Discard Beacon frames to non-broadcast address (CVE-2025-71127)
  * kernel: KVM: nSVM: Always use vmcb01 in VMLOAD/VMSAVE emulation (CVE-2026-43133)
  * kernel: net: qrtr: fix refcount saturation and potential UAF in qrtr_port_remove (CVE-2026-52947)
  * kernel: wifi: nl80211: reject oversized EMA RNR lists (CVE-2026-53182)
  * kernel: blk-cgroup: fix UAF in __blkcg_rstat_flush() (CVE-2026-63802)
  * kernel: scsi: scsi_transport_fc: Widen FPIN pname walker counter to u32 (CVE-2026-63889)
  * kernel: wifi: mac80211: capture fast-RX rate before mesh reuses skb-&amp;gt;cb (CVE-2026-64117)
  * kernel: Linux kernel: ath9k Wi-Fi driver use-after-free vulnerability leading to system crash (CVE-2026-68363)
  * kernel: dm-verity: fix buffer overflow in FEC calculation (CVE-2026-72098)
  * kernel: scsi: libiscsi_tcp: Bound SCSI Response data segment to the connection buffer (CVE-2026-74556)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:67468</guid>
    </item>
    <item>
      <title>BELL-CVE-2026-68363</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-68363</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-68363</guid>
    </item>
    <item>
      <title>certfr-2026-avi-1069 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de Debian LTS. Elles permettent à un attaquant de p…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1069</link>
      <description>certfr-2026-avi-1069</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-1069</guid>
    </item>
    <item>
      <title>EUVD-2026-356309</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-356309</link>
      <description>EUVD-2026-356309</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-356309</guid>
    </item>
    <item>
      <title>fkie_cve-2026-68363</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-68363</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;wifi: ath9k: hif_usb: don&amp;#39;t dereference hif_dev after re-arming firmware request&lt;/p&gt;
&lt;p&gt;ath9k_hif_request_firmware() re-arms an asynchronous firmware load via
request_firmware_nowait(), passing hif_dev as the completion context, and
then still dereferences hif_dev:&lt;/p&gt;
&lt;p&gt;dev_info(&amp;amp;hif_dev-&amp;gt;udev-&amp;gt;dev, &amp;#34;ath9k_htc: Firmware %s requested\n&amp;#34;,
		 hif_dev-&amp;gt;fw_name);&lt;/p&gt;
&lt;p&gt;The re-armed callback ath9k_hif_usb_firmware_cb() runs on the &amp;#34;events&amp;#34;
workqueue and, when the firmware is missing, walks the retry chain into
ath9k_hif_usb_firmware_fail() -&amp;gt; complete_all(&amp;amp;hif_dev-&amp;gt;fw_done). That
releases the wait_for_completion(&amp;amp;hif_dev-&amp;gt;fw_done) in a concurrent
ath9k_hif_usb_disconnect(), which then kfree()s hif_dev. The trailing
dev_info() in the frame that re-armed the request can therefore read freed
memory (hif_dev-&amp;gt;udev, the first field of struct hif_device_usb):&lt;/p&gt;
&lt;p&gt;BUG: KASAN: slab-use-after-free in ath9k_hif_request_firmware
  Read of size 8 ... by task kworker/...
   ath9k_hif_request_firmware
   ath9k_hif_usb_firmware_cb           drivers/net/wireless/ath/ath9k/hif_usb.c:1247
   request_firmware_work_func
  Allocated by ...:
   ath9k_hif_usb_probe                 drivers/net/wireless/ath/ath9k/hif_usb.c
  Freed by ...:
   ath9k_hif_usb_disconnect -&amp;gt; kfree   drivers/net/wireless/ath/ath9k/hif_usb.c&lt;/p&gt;
&lt;p&gt;The fw_done barrier only makes disconnect wait for the firmware chain to
*terminate*; it does not protect the outer ath9k_hif_request_fi…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;wifi: ath9k: hif_usb: don&amp;#39;t dereference hif_dev after re-arming firmware request&lt;/p&gt;
&lt;p&gt;ath9k_hif_request_firmware() re-arms an asynchronous firmware load via
request_firmware_nowait(), passing hif_dev as the completion context, and
then still dereferences hif_dev:&lt;/p&gt;
&lt;p&gt;dev_info(&amp;amp;hif_dev-&amp;gt;udev-&amp;gt;dev, &amp;#34;ath9k_htc: Firmware %s requested\n&amp;#34;,
		 hif_dev-&amp;gt;fw_name);&lt;/p&gt;
&lt;p&gt;The re-armed callback ath9k_hif_usb_firmware_cb() runs on the &amp;#34;events&amp;#34;
workqueue and, when the firmware is missing, walks the retry chain into
ath9k_hif_usb_firmware_fail() -&amp;gt; complete_all(&amp;amp;hif_dev-&amp;gt;fw_done). That
releases the wait_for_completion(&amp;amp;hif_dev-&amp;gt;fw_done) in a concurrent
ath9k_hif_usb_disconnect(), which then kfree()s hif_dev. The trailing
dev_info() in the frame that re-armed the request can therefore read freed
memory (hif_dev-&amp;gt;udev, the first field of struct hif_device_usb):&lt;/p&gt;
&lt;p&gt;BUG: KASAN: slab-use-after-free in ath9k_hif_request_firmware
  Read of size 8 ... by task kworker/...
   ath9k_hif_request_firmware
   ath9k_hif_usb_firmware_cb           drivers/net/wireless/ath/ath9k/hif_usb.c:1247
   request_firmware_work_func
  Allocated by ...:
   ath9k_hif_usb_probe                 drivers/net/wireless/ath/ath9k/hif_usb.c
  Freed by ...:
   ath9k_hif_usb_disconnect -&amp;gt; kfree   drivers/net/wireless/ath/ath9k/hif_usb.c&lt;/p&gt;
&lt;p&gt;The fw_done barrier only makes disconnect wait for the firmware chain to
*terminate*; it does not protect the outer ath9k_hif_request_fi…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-68363</guid>
    </item>
    <item>
      <title>GHSA-x3fw-jwr8-ppm9</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-x3fw-jwr8-ppm9</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;wifi: ath9k: hif_usb: don&amp;#39;t dereference hif_dev after re-arming firmware request&lt;/p&gt;
&lt;p&gt;ath9k_hif_request_firmware() re-arms an asynchronous firmware load via
request_firmware_nowait(), passing hif_dev as the completion context, and
then still dereferences hif_dev:&lt;/p&gt;
&lt;p&gt;dev_info(&amp;amp;hif_dev-&amp;gt;udev-&amp;gt;dev, &amp;#34;ath9k_htc: Firmware %s requested\n&amp;#34;,
		 hif_dev-&amp;gt;fw_name);&lt;/p&gt;
&lt;p&gt;The re-armed callback ath9k_hif_usb_firmware_cb() runs on the &amp;#34;events&amp;#34;
workqueue and, when the firmware is missing, walks the retry chain into
ath9k_hif_usb_firmware_fail() -&amp;gt; complete_all(&amp;amp;hif_dev-&amp;gt;fw_done). That
releases the wait_for_completion(&amp;amp;hif_dev-&amp;gt;fw_done) in a concurrent
ath9k_hif_usb_disconnect(), which then kfree()s hif_dev. The trailing
dev_info() in the frame that re-armed the request can therefore read freed
memory (hif_dev-&amp;gt;udev, the first field of struct hif_device_usb):&lt;/p&gt;
&lt;p&gt;BUG: KASAN: slab-use-after-free in ath9k_hif_request_firmware
  Read of size 8 ... by task kworker/...
   ath9k_hif_request_firmware
   ath9k_hif_usb_firmware_cb           drivers/net/wireless/ath/ath9k/hif_usb.c:1247
   request_firmware_work_func
  Allocated by ...:
   ath9k_hif_usb_probe                 drivers/net/wireless/ath/ath9k/hif_usb.c
  Freed by ...:
   ath9k_hif_usb_disconnect -&amp;gt; kfree   drivers/net/wireless/ath/ath9k/hif_usb.c&lt;/p&gt;
&lt;p&gt;The fw_done barrier only makes disconnect wait for the firmware chain to
*terminate*; it does not protect the outer ath9k_hif_request_fi…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;wifi: ath9k: hif_usb: don&amp;#39;t dereference hif_dev after re-arming firmware request&lt;/p&gt;
&lt;p&gt;ath9k_hif_request_firmware() re-arms an asynchronous firmware load via
request_firmware_nowait(), passing hif_dev as the completion context, and
then still dereferences hif_dev:&lt;/p&gt;
&lt;p&gt;dev_info(&amp;amp;hif_dev-&amp;gt;udev-&amp;gt;dev, &amp;#34;ath9k_htc: Firmware %s requested\n&amp;#34;,
		 hif_dev-&amp;gt;fw_name);&lt;/p&gt;
&lt;p&gt;The re-armed callback ath9k_hif_usb_firmware_cb() runs on the &amp;#34;events&amp;#34;
workqueue and, when the firmware is missing, walks the retry chain into
ath9k_hif_usb_firmware_fail() -&amp;gt; complete_all(&amp;amp;hif_dev-&amp;gt;fw_done). That
releases the wait_for_completion(&amp;amp;hif_dev-&amp;gt;fw_done) in a concurrent
ath9k_hif_usb_disconnect(), which then kfree()s hif_dev. The trailing
dev_info() in the frame that re-armed the request can therefore read freed
memory (hif_dev-&amp;gt;udev, the first field of struct hif_device_usb):&lt;/p&gt;
&lt;p&gt;BUG: KASAN: slab-use-after-free in ath9k_hif_request_firmware
  Read of size 8 ... by task kworker/...
   ath9k_hif_request_firmware
   ath9k_hif_usb_firmware_cb           drivers/net/wireless/ath/ath9k/hif_usb.c:1247
   request_firmware_work_func
  Allocated by ...:
   ath9k_hif_usb_probe                 drivers/net/wireless/ath/ath9k/hif_usb.c
  Freed by ...:
   ath9k_hif_usb_disconnect -&amp;gt; kfree   drivers/net/wireless/ath/ath9k/hif_usb.c&lt;/p&gt;
&lt;p&gt;The fw_done barrier only makes disconnect wait for the firmware chain to
*terminate*; it does not protect the outer ath9k_hif_request_fi…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-x3fw-jwr8-ppm9</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-68363 — wifi: ath9k: hif_usb: don't dereference hif_dev after re-arming firmware request</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-68363</link>
      <description>msrc_CVE-2026-68363</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-68363</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:21910-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:21910-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:21910-1</guid>
    </item>
    <item>
      <title>RHSA-2026:67469 — Red Hat Security Advisory: kernel-rt security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:67469</link>
      <description>&lt;p&gt;kernel: EDAC/bluefield: Fix potential integer overflow kernel: wifi: mac80211: Discard Beacon frames to non-broadcast address kernel: KVM: nSVM: Always use vmcb01 in VMLOAD/VMSAVE emulation kernel: net: qrtr: fix refcount saturation and potential UAF in qrtr_port_remove kernel: wifi: nl80211: reject oversized EMA RNR lists kernel: blk-cgroup: fix UAF in __blkcg_rstat_flush() kernel: scsi: scsi_transport_fc: Widen FPIN pname walker counter to u32 kernel: wifi: mac80211: capture fast-RX rate before mesh reuses skb-&amp;gt;cb kernel: net: qrtr: restrict socket creation to the initial network namespace kernel: Linux kernel: ath9k Wi-Fi driver use-after-free vulnerability leading to system crash kernel: dm-verity: fix buffer overflow in FEC calculation kernel: scsi: libiscsi_tcp: Bound SCSI Response data segment to the connection buffer&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;kernel: EDAC/bluefield: Fix potential integer overflow kernel: wifi: mac80211: Discard Beacon frames to non-broadcast address kernel: KVM: nSVM: Always use vmcb01 in VMLOAD/VMSAVE emulation kernel: net: qrtr: fix refcount saturation and potential UAF in qrtr_port_remove kernel: wifi: nl80211: reject oversized EMA RNR lists kernel: blk-cgroup: fix UAF in __blkcg_rstat_flush() kernel: scsi: scsi_transport_fc: Widen FPIN pname walker counter to u32 kernel: wifi: mac80211: capture fast-RX rate before mesh reuses skb-&amp;gt;cb kernel: net: qrtr: restrict socket creation to the initial network namespace kernel: Linux kernel: ath9k Wi-Fi driver use-after-free vulnerability leading to system crash kernel: dm-verity: fix buffer overflow in FEC calculation kernel: scsi: libiscsi_tcp: Bound SCSI Response data segment to the connection buffer&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:67469</guid>
    </item>
    <item>
      <title>RLSA-2026:67468 — Important: kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:67468</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:8: kernel&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: EDAC/bluefield: Fix potential integer overflow (CVE-2024-53161)&lt;/p&gt;
&lt;p&gt;* kernel: wifi: mac80211: Discard Beacon frames to non-broadcast address (CVE-2025-71127)&lt;/p&gt;
&lt;p&gt;* kernel: KVM: nSVM: Always use vmcb01 in VMLOAD/VMSAVE emulation (CVE-2026-43133)&lt;/p&gt;
&lt;p&gt;* kernel: net: qrtr: fix refcount saturation and potential UAF in qrtr_port_remove (CVE-2026-52947)&lt;/p&gt;
&lt;p&gt;* kernel: wifi: nl80211: reject oversized EMA RNR lists (CVE-2026-53182)&lt;/p&gt;
&lt;p&gt;* kernel: blk-cgroup: fix UAF in __blkcg_rstat_flush() (CVE-2026-63802)&lt;/p&gt;
&lt;p&gt;* kernel: scsi: scsi_transport_fc: Widen FPIN pname walker counter to u32 (CVE-2026-63889)&lt;/p&gt;
&lt;p&gt;* kernel: wifi: mac80211: capture fast-RX rate before mesh reuses skb-&amp;gt;cb (CVE-2026-64117)&lt;/p&gt;
&lt;p&gt;* kernel: Linux kernel: ath9k Wi-Fi driver use-after-free vulnerability leading to system crash (CVE-2026-68363)&lt;/p&gt;
&lt;p&gt;* kernel: dm-verity: fix buffer overflow in FEC calculation (CVE-2026-72098)&lt;/p&gt;
&lt;p&gt;* kernel: scsi: libiscsi_tcp: Bound SCSI Response data segment to the connection buffer (CVE-2026-74556)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:8: kernel&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: EDAC/bluefield: Fix potential integer overflow (CVE-2024-53161)&lt;/p&gt;
&lt;p&gt;* kernel: wifi: mac80211: Discard Beacon frames to non-broadcast address (CVE-2025-71127)&lt;/p&gt;
&lt;p&gt;* kernel: KVM: nSVM: Always use vmcb01 in VMLOAD/VMSAVE emulation (CVE-2026-43133)&lt;/p&gt;
&lt;p&gt;* kernel: net: qrtr: fix refcount saturation and potential UAF in qrtr_port_remove (CVE-2026-52947)&lt;/p&gt;
&lt;p&gt;* kernel: wifi: nl80211: reject oversized EMA RNR lists (CVE-2026-53182)&lt;/p&gt;
&lt;p&gt;* kernel: blk-cgroup: fix UAF in __blkcg_rstat_flush() (CVE-2026-63802)&lt;/p&gt;
&lt;p&gt;* kernel: scsi: scsi_transport_fc: Widen FPIN pname walker counter to u32 (CVE-2026-63889)&lt;/p&gt;
&lt;p&gt;* kernel: wifi: mac80211: capture fast-RX rate before mesh reuses skb-&amp;gt;cb (CVE-2026-64117)&lt;/p&gt;
&lt;p&gt;* kernel: Linux kernel: ath9k Wi-Fi driver use-after-free vulnerability leading to system crash (CVE-2026-68363)&lt;/p&gt;
&lt;p&gt;* kernel: dm-verity: fix buffer overflow in FEC calculation (CVE-2026-72098)&lt;/p&gt;
&lt;p&gt;* kernel: scsi: libiscsi_tcp: Bound SCSI Response data segment to the connection buffer (CVE-2026-74556)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:67468</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:23477-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:23477-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:23477-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-68363</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-68363</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe, Ubuntu:16.04:LTS: linux-hwe-edge and 245 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: wifi: ath9k: hif_usb: don&amp;#39;t dereference hif_dev after re-arming firmware request ath9k_hif_request_firmware() re-arms an asynchronous firmware load via request_firmware_nowait(), passing hif_dev as the completion context, and then still dereferences hif_dev: 	dev_info(&amp;amp;hif_dev-&amp;gt;udev-&amp;gt;dev, &amp;#34;ath9k_htc: Firmware %s requested\n&amp;#34;, 		 hif_dev-&amp;gt;fw_name); The re-armed callback ath9k_hif_usb_firmware_cb() runs on the &amp;#34;events&amp;#34; workqueue and, when the firmware is missing, walks the retry chain into ath9k_hif_usb_firmware_fail() -&amp;gt; complete_all(&amp;amp;hif_dev-&amp;gt;fw_done). That releases the wait_for_completion(&amp;amp;hif_dev-&amp;gt;fw_done) in a concurrent ath9k_hif_usb_disconnect(), which then kfree()s hif_dev. The trailing dev_info() in the frame that re-armed the request can therefore read freed memory (hif_dev-&amp;gt;udev, the first field of struct hif_device_usb):   BUG: KASAN: slab-use-after-free in ath9k_hif_request_firmware   Read of size 8 ... by task kworker/...    ath9k_hif_request_firmware    ath9k_hif_usb_firmware_cb drivers/net/wireless/ath/ath9k/hif_usb.c:1247    request_firmware_work_func   Allocated by ...:    ath9k_hif_usb_probe drivers/net/wireless/ath/ath9k/hif_usb.c   Freed by ...:    ath9k_hif_usb_disconnect -&amp;gt; kfree drivers/net/wireless/ath/ath9k/hif_usb.c The fw_done barrier only makes disconnect wait for the firmware chain to *terminate*; it does not protect the outer ath9k_hif_request_firmware() frame that re-armed the r…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe, Ubuntu:16.04:LTS: linux-hwe-edge and 245 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: wifi: ath9k: hif_usb: don&amp;#39;t dereference hif_dev after re-arming firmware request ath9k_hif_request_firmware() re-arms an asynchronous firmware load via request_firmware_nowait(), passing hif_dev as the completion context, and then still dereferences hif_dev: 	dev_info(&amp;amp;hif_dev-&amp;gt;udev-&amp;gt;dev, &amp;#34;ath9k_htc: Firmware %s requested\n&amp;#34;, 		 hif_dev-&amp;gt;fw_name); The re-armed callback ath9k_hif_usb_firmware_cb() runs on the &amp;#34;events&amp;#34; workqueue and, when the firmware is missing, walks the retry chain into ath9k_hif_usb_firmware_fail() -&amp;gt; complete_all(&amp;amp;hif_dev-&amp;gt;fw_done). That releases the wait_for_completion(&amp;amp;hif_dev-&amp;gt;fw_done) in a concurrent ath9k_hif_usb_disconnect(), which then kfree()s hif_dev. The trailing dev_info() in the frame that re-armed the request can therefore read freed memory (hif_dev-&amp;gt;udev, the first field of struct hif_device_usb):   BUG: KASAN: slab-use-after-free in ath9k_hif_request_firmware   Read of size 8 ... by task kworker/...    ath9k_hif_request_firmware    ath9k_hif_usb_firmware_cb drivers/net/wireless/ath/ath9k/hif_usb.c:1247    request_firmware_work_func   Allocated by ...:    ath9k_hif_usb_probe drivers/net/wireless/ath/ath9k/hif_usb.c   Freed by ...:    ath9k_hif_usb_disconnect -&amp;gt; kfree drivers/net/wireless/ath/ath9k/hif_usb.c The fw_done barrier only makes disconnect wait for the firmware chain to *terminate*; it does not protect the outer ath9k_hif_request_firmware() frame that re-armed the r…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-68363</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2730 — Linux Kernel: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2730</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen, darunter möglicherweise die Ausführung von beliebigem Code, die Ausweitung von Berechtigungen, die Offenlegung von Informationen, die Manipulation von Daten oder Denial-of-Service-Zustände.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen, darunter möglicherweise die Ausführung von beliebigem Code, die Ausweitung von Berechtigungen, die Offenlegung von Informationen, die Manipulation von Daten oder Denial-of-Service-Zustände.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2730</guid>
    </item>
  </channel>
</rss>
