<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 06:52:46 +0000</lastBuildDate>
    <item>
      <title>BELL-CVE-2026-68370</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-68370</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-68370</guid>
    </item>
    <item>
      <title>certfr-2026-avi-1069 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de Debian LTS. Elles permettent à un attaquant de p…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1069</link>
      <description>certfr-2026-avi-1069</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-1069</guid>
    </item>
    <item>
      <title>EUVD-2026-356316</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-356316</link>
      <description>EUVD-2026-356316</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-356316</guid>
    </item>
    <item>
      <title>fkie_cve-2026-68370</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-68370</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;usb: gadget: dummy_hcd: prevent fifo_req reuse during giveback&lt;/p&gt;
&lt;p&gt;dummy_hcd embeds a single shared usb_request (dum-&amp;gt;fifo_req) that the
&amp;#34;emulated single-request FIFO&amp;#34; fast-path in dummy_queue() reuses for
small IN transfers: it copies the caller&amp;#39;s request into it
(req-&amp;gt;req = *_req) and queues it, treating list_empty(&amp;amp;fifo_req.queue)
as &amp;#34;the slot is free&amp;#34;.&lt;/p&gt;
&lt;p&gt;The completion side (dummy_timer/transfer/nuke/dummy_dequeue) follows
the standard pattern: list_del_init(&amp;amp;req-&amp;gt;queue) unlinks the request,
then the lock is dropped and usb_gadget_giveback_request() invokes
req-&amp;gt;complete().  But list_del_init() makes fifo_req.queue look empty
*before* the completion callback returns, so a concurrent dummy_queue()
on another CPU sees the slot as free, reuses fifo_req and runs
req-&amp;gt;req = *_req -- overwriting req-&amp;gt;complete while dummy_timer is
mid-calling it.  The indirect call then jumps to a clobbered pointer,
causing a general protection fault / page fault in dummy_timer
(syzkaller extid faf3a6cf579fc65591ca).  The clobbering write is an
in-bounds memcpy on a live shared object, so KASAN cannot flag it.&lt;/p&gt;
&lt;p&gt;Add a fifo_req_busy bit covering the shared request&amp;#39;s whole lifetime:
set it in dummy_queue() when the FIFO fast-path takes fifo_req (making
it the fast-path guard, replacing the list_empty(&amp;amp;fifo_req.queue)
test), and clear it after the completion callback has returned, via a
dummy_giveback() helper used at all four gadget-…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;usb: gadget: dummy_hcd: prevent fifo_req reuse during giveback&lt;/p&gt;
&lt;p&gt;dummy_hcd embeds a single shared usb_request (dum-&amp;gt;fifo_req) that the
&amp;#34;emulated single-request FIFO&amp;#34; fast-path in dummy_queue() reuses for
small IN transfers: it copies the caller&amp;#39;s request into it
(req-&amp;gt;req = *_req) and queues it, treating list_empty(&amp;amp;fifo_req.queue)
as &amp;#34;the slot is free&amp;#34;.&lt;/p&gt;
&lt;p&gt;The completion side (dummy_timer/transfer/nuke/dummy_dequeue) follows
the standard pattern: list_del_init(&amp;amp;req-&amp;gt;queue) unlinks the request,
then the lock is dropped and usb_gadget_giveback_request() invokes
req-&amp;gt;complete().  But list_del_init() makes fifo_req.queue look empty
*before* the completion callback returns, so a concurrent dummy_queue()
on another CPU sees the slot as free, reuses fifo_req and runs
req-&amp;gt;req = *_req -- overwriting req-&amp;gt;complete while dummy_timer is
mid-calling it.  The indirect call then jumps to a clobbered pointer,
causing a general protection fault / page fault in dummy_timer
(syzkaller extid faf3a6cf579fc65591ca).  The clobbering write is an
in-bounds memcpy on a live shared object, so KASAN cannot flag it.&lt;/p&gt;
&lt;p&gt;Add a fifo_req_busy bit covering the shared request&amp;#39;s whole lifetime:
set it in dummy_queue() when the FIFO fast-path takes fifo_req (making
it the fast-path guard, replacing the list_empty(&amp;amp;fifo_req.queue)
test), and clear it after the completion callback has returned, via a
dummy_giveback() helper used at all four gadget-…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-68370</guid>
    </item>
    <item>
      <title>GHSA-c79g-9hcr-cr2x</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-c79g-9hcr-cr2x</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;usb: gadget: dummy_hcd: prevent fifo_req reuse during giveback&lt;/p&gt;
&lt;p&gt;dummy_hcd embeds a single shared usb_request (dum-&amp;gt;fifo_req) that the
&amp;#34;emulated single-request FIFO&amp;#34; fast-path in dummy_queue() reuses for
small IN transfers: it copies the caller&amp;#39;s request into it
(req-&amp;gt;req = *_req) and queues it, treating list_empty(&amp;amp;fifo_req.queue)
as &amp;#34;the slot is free&amp;#34;.&lt;/p&gt;
&lt;p&gt;The completion side (dummy_timer/transfer/nuke/dummy_dequeue) follows
the standard pattern: list_del_init(&amp;amp;req-&amp;gt;queue) unlinks the request,
then the lock is dropped and usb_gadget_giveback_request() invokes
req-&amp;gt;complete().  But list_del_init() makes fifo_req.queue look empty
*before* the completion callback returns, so a concurrent dummy_queue()
on another CPU sees the slot as free, reuses fifo_req and runs
req-&amp;gt;req = *_req -- overwriting req-&amp;gt;complete while dummy_timer is
mid-calling it.  The indirect call then jumps to a clobbered pointer,
causing a general protection fault / page fault in dummy_timer
(syzkaller extid faf3a6cf579fc65591ca).  The clobbering write is an
in-bounds memcpy on a live shared object, so KASAN cannot flag it.&lt;/p&gt;
&lt;p&gt;Add a fifo_req_busy bit covering the shared request&amp;#39;s whole lifetime:
set it in dummy_queue() when the FIFO fast-path takes fifo_req (making
it the fast-path guard, replacing the list_empty(&amp;amp;fifo_req.queue)
test), and clear it after the completion callback has returned, via a
dummy_giveback() helper used at all four gadget-…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;usb: gadget: dummy_hcd: prevent fifo_req reuse during giveback&lt;/p&gt;
&lt;p&gt;dummy_hcd embeds a single shared usb_request (dum-&amp;gt;fifo_req) that the
&amp;#34;emulated single-request FIFO&amp;#34; fast-path in dummy_queue() reuses for
small IN transfers: it copies the caller&amp;#39;s request into it
(req-&amp;gt;req = *_req) and queues it, treating list_empty(&amp;amp;fifo_req.queue)
as &amp;#34;the slot is free&amp;#34;.&lt;/p&gt;
&lt;p&gt;The completion side (dummy_timer/transfer/nuke/dummy_dequeue) follows
the standard pattern: list_del_init(&amp;amp;req-&amp;gt;queue) unlinks the request,
then the lock is dropped and usb_gadget_giveback_request() invokes
req-&amp;gt;complete().  But list_del_init() makes fifo_req.queue look empty
*before* the completion callback returns, so a concurrent dummy_queue()
on another CPU sees the slot as free, reuses fifo_req and runs
req-&amp;gt;req = *_req -- overwriting req-&amp;gt;complete while dummy_timer is
mid-calling it.  The indirect call then jumps to a clobbered pointer,
causing a general protection fault / page fault in dummy_timer
(syzkaller extid faf3a6cf579fc65591ca).  The clobbering write is an
in-bounds memcpy on a live shared object, so KASAN cannot flag it.&lt;/p&gt;
&lt;p&gt;Add a fifo_req_busy bit covering the shared request&amp;#39;s whole lifetime:
set it in dummy_queue() when the FIFO fast-path takes fifo_req (making
it the fast-path guard, replacing the list_empty(&amp;amp;fifo_req.queue)
test), and clear it after the completion callback has returned, via a
dummy_giveback() helper used at all four gadget-…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-c79g-9hcr-cr2x</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-68370 — usb: gadget: dummy_hcd: prevent fifo_req reuse during giveback</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-68370</link>
      <description>msrc_CVE-2026-68370</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-68370</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:21910-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:21910-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:21910-1</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:23477-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:23477-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:23477-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-68370</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-68370</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux, Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe and 246 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: usb: gadget: dummy_hcd: prevent fifo_req reuse during giveback dummy_hcd embeds a single shared usb_request (dum-&amp;gt;fifo_req) that the &amp;#34;emulated single-request FIFO&amp;#34; fast-path in dummy_queue() reuses for small IN transfers: it copies the caller&amp;#39;s request into it (req-&amp;gt;req = *_req) and queues it, treating list_empty(&amp;amp;fifo_req.queue) as &amp;#34;the slot is free&amp;#34;. The completion side (dummy_timer/transfer/nuke/dummy_dequeue) follows the standard pattern: list_del_init(&amp;amp;req-&amp;gt;queue) unlinks the request, then the lock is dropped and usb_gadget_giveback_request() invokes req-&amp;gt;complete().  But list_del_init() makes fifo_req.queue look empty *before* the completion callback returns, so a concurrent dummy_queue() on another CPU sees the slot as free, reuses fifo_req and runs req-&amp;gt;req = *_req -- overwriting req-&amp;gt;complete while dummy_timer is mid-calling it.  The indirect call then jumps to a clobbered pointer, causing a general protection fault / page fault in dummy_timer (syzkaller extid faf3a6cf579fc65591ca).  The clobbering write is an in-bounds memcpy on a live shared object, so KASAN cannot flag it. Add a fifo_req_busy bit covering the shared request&amp;#39;s whole lifetime: set it in dummy_queue() when the FIFO fast-path takes fifo_req (making it the fast-path guard, replacing the list_empty(&amp;amp;fifo_req.queue) test), and clear it after the completion callback has returned, via a dummy_giveback() helper used at all four gadget-requ…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux, Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe and 246 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: usb: gadget: dummy_hcd: prevent fifo_req reuse during giveback dummy_hcd embeds a single shared usb_request (dum-&amp;gt;fifo_req) that the &amp;#34;emulated single-request FIFO&amp;#34; fast-path in dummy_queue() reuses for small IN transfers: it copies the caller&amp;#39;s request into it (req-&amp;gt;req = *_req) and queues it, treating list_empty(&amp;amp;fifo_req.queue) as &amp;#34;the slot is free&amp;#34;. The completion side (dummy_timer/transfer/nuke/dummy_dequeue) follows the standard pattern: list_del_init(&amp;amp;req-&amp;gt;queue) unlinks the request, then the lock is dropped and usb_gadget_giveback_request() invokes req-&amp;gt;complete().  But list_del_init() makes fifo_req.queue look empty *before* the completion callback returns, so a concurrent dummy_queue() on another CPU sees the slot as free, reuses fifo_req and runs req-&amp;gt;req = *_req -- overwriting req-&amp;gt;complete while dummy_timer is mid-calling it.  The indirect call then jumps to a clobbered pointer, causing a general protection fault / page fault in dummy_timer (syzkaller extid faf3a6cf579fc65591ca).  The clobbering write is an in-bounds memcpy on a live shared object, so KASAN cannot flag it. Add a fifo_req_busy bit covering the shared request&amp;#39;s whole lifetime: set it in dummy_queue() when the FIFO fast-path takes fifo_req (making it the fast-path guard, replacing the list_empty(&amp;amp;fifo_req.queue) test), and clear it after the completion callback has returned, via a dummy_giveback() helper used at all four gadget-requ…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-68370</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2730 — Linux Kernel: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2730</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen, darunter möglicherweise die Ausführung von beliebigem Code, die Ausweitung von Berechtigungen, die Offenlegung von Informationen, die Manipulation von Daten oder Denial-of-Service-Zustände.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen, darunter möglicherweise die Ausführung von beliebigem Code, die Ausweitung von Berechtigungen, die Offenlegung von Informationen, die Manipulation von Daten oder Denial-of-Service-Zustände.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2730</guid>
    </item>
  </channel>
</rss>
