<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 01:24:22 +0000</lastBuildDate>
    <item>
      <title>BELL-CVE-2026-68382</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-68382</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-68382</guid>
    </item>
    <item>
      <title>EUVD-2026-353580</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-353580</link>
      <description>EUVD-2026-353580</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-353580</guid>
    </item>
    <item>
      <title>fkie_cve-2026-68382</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-68382</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;drm/xe/guc: Hold device ref until queue teardown completes&lt;/p&gt;
&lt;p&gt;GuC exec queue destruction can run asynchronously. If the final device
put happens from a destroy worker, drmm cleanup can end up draining
the same workqueue and deadlock.&lt;/p&gt;
&lt;p&gt;Hold a drm_device reference for the queue lifetime and drop it after
queue teardown completes. This keeps drmm cleanup from running while
async destroy work is still pending.&lt;/p&gt;
&lt;p&gt;Move GuC destroy work to a module-lifetime Xe workqueue and flush it
on PCI remove so hot-unbind/rebind still waits for pending destroy work.&lt;/p&gt;
&lt;p&gt;With queue-held device refs, guc_submit_sw_fini() cannot run with live
GuC IDs. Replace the fini wait with an assertion and remove the unused
fini_wq.&lt;/p&gt;
&lt;p&gt;v2:
  - Rebase&lt;/p&gt;
&lt;p&gt;v3:
  - Switch to queue-lifetime drm_dev_get()/drm_dev_put() model. (Matt)
  - Queue async teardown on system_dfl_wq instead of xe-&amp;gt;destroy_wq. (Matt)
  - Drop separate deferred drm_dev_put worker.
  - Remove stale drain_workqueue(xe-&amp;gt;destroy_wq) from guc_submit_sw_fini().&lt;/p&gt;
&lt;p&gt;v4:
  - Replace the guc_submit_sw_fini() wait with an assertion and remove
    the now-unused fini_wq. (sashiko)&lt;/p&gt;
&lt;p&gt;v5:
  - Move destroy work to a module-lifetime Xe workqueue instead of
    system_dfl_wq. (Matt)
  - Flush the module-lifetime destroy workqueue during PCI remove to
    preserve the old device-remove wait semantics.&lt;/p&gt;
&lt;p&gt;v6:
  - Keep SVM pagemap destroy work on the per-device destroy_wq to avoid
    letting it outlive the…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;drm/xe/guc: Hold device ref until queue teardown completes&lt;/p&gt;
&lt;p&gt;GuC exec queue destruction can run asynchronously. If the final device
put happens from a destroy worker, drmm cleanup can end up draining
the same workqueue and deadlock.&lt;/p&gt;
&lt;p&gt;Hold a drm_device reference for the queue lifetime and drop it after
queue teardown completes. This keeps drmm cleanup from running while
async destroy work is still pending.&lt;/p&gt;
&lt;p&gt;Move GuC destroy work to a module-lifetime Xe workqueue and flush it
on PCI remove so hot-unbind/rebind still waits for pending destroy work.&lt;/p&gt;
&lt;p&gt;With queue-held device refs, guc_submit_sw_fini() cannot run with live
GuC IDs. Replace the fini wait with an assertion and remove the unused
fini_wq.&lt;/p&gt;
&lt;p&gt;v2:
  - Rebase&lt;/p&gt;
&lt;p&gt;v3:
  - Switch to queue-lifetime drm_dev_get()/drm_dev_put() model. (Matt)
  - Queue async teardown on system_dfl_wq instead of xe-&amp;gt;destroy_wq. (Matt)
  - Drop separate deferred drm_dev_put worker.
  - Remove stale drain_workqueue(xe-&amp;gt;destroy_wq) from guc_submit_sw_fini().&lt;/p&gt;
&lt;p&gt;v4:
  - Replace the guc_submit_sw_fini() wait with an assertion and remove
    the now-unused fini_wq. (sashiko)&lt;/p&gt;
&lt;p&gt;v5:
  - Move destroy work to a module-lifetime Xe workqueue instead of
    system_dfl_wq. (Matt)
  - Flush the module-lifetime destroy workqueue during PCI remove to
    preserve the old device-remove wait semantics.&lt;/p&gt;
&lt;p&gt;v6:
  - Keep SVM pagemap destroy work on the per-device destroy_wq to avoid
    letting it outlive the…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-68382</guid>
    </item>
    <item>
      <title>GHSA-j3x5-5jxr-fgc6</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-j3x5-5jxr-fgc6</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;drm/xe/guc: Hold device ref until queue teardown completes&lt;/p&gt;
&lt;p&gt;GuC exec queue destruction can run asynchronously. If the final device
put happens from a destroy worker, drmm cleanup can end up draining
the same workqueue and deadlock.&lt;/p&gt;
&lt;p&gt;Hold a drm_device reference for the queue lifetime and drop it after
queue teardown completes. This keeps drmm cleanup from running while
async destroy work is still pending.&lt;/p&gt;
&lt;p&gt;Move GuC destroy work to a module-lifetime Xe workqueue and flush it
on PCI remove so hot-unbind/rebind still waits for pending destroy work.&lt;/p&gt;
&lt;p&gt;With queue-held device refs, guc_submit_sw_fini() cannot run with live
GuC IDs. Replace the fini wait with an assertion and remove the unused
fini_wq.&lt;/p&gt;
&lt;p&gt;v2:
  - Rebase&lt;/p&gt;
&lt;p&gt;v3:
  - Switch to queue-lifetime drm_dev_get()/drm_dev_put() model. (Matt)
  - Queue async teardown on system_dfl_wq instead of xe-&amp;gt;destroy_wq. (Matt)
  - Drop separate deferred drm_dev_put worker.
  - Remove stale drain_workqueue(xe-&amp;gt;destroy_wq) from guc_submit_sw_fini().&lt;/p&gt;
&lt;p&gt;v4:
  - Replace the guc_submit_sw_fini() wait with an assertion and remove
    the now-unused fini_wq. (sashiko)&lt;/p&gt;
&lt;p&gt;v5:
  - Move destroy work to a module-lifetime Xe workqueue instead of
    system_dfl_wq. (Matt)
  - Flush the module-lifetime destroy workqueue during PCI remove to
    preserve the old device-remove wait semantics.&lt;/p&gt;
&lt;p&gt;v6:
  - Keep SVM pagemap destroy work on the per-device destroy_wq to avoid
    letting it outlive the…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;drm/xe/guc: Hold device ref until queue teardown completes&lt;/p&gt;
&lt;p&gt;GuC exec queue destruction can run asynchronously. If the final device
put happens from a destroy worker, drmm cleanup can end up draining
the same workqueue and deadlock.&lt;/p&gt;
&lt;p&gt;Hold a drm_device reference for the queue lifetime and drop it after
queue teardown completes. This keeps drmm cleanup from running while
async destroy work is still pending.&lt;/p&gt;
&lt;p&gt;Move GuC destroy work to a module-lifetime Xe workqueue and flush it
on PCI remove so hot-unbind/rebind still waits for pending destroy work.&lt;/p&gt;
&lt;p&gt;With queue-held device refs, guc_submit_sw_fini() cannot run with live
GuC IDs. Replace the fini wait with an assertion and remove the unused
fini_wq.&lt;/p&gt;
&lt;p&gt;v2:
  - Rebase&lt;/p&gt;
&lt;p&gt;v3:
  - Switch to queue-lifetime drm_dev_get()/drm_dev_put() model. (Matt)
  - Queue async teardown on system_dfl_wq instead of xe-&amp;gt;destroy_wq. (Matt)
  - Drop separate deferred drm_dev_put worker.
  - Remove stale drain_workqueue(xe-&amp;gt;destroy_wq) from guc_submit_sw_fini().&lt;/p&gt;
&lt;p&gt;v4:
  - Replace the guc_submit_sw_fini() wait with an assertion and remove
    the now-unused fini_wq. (sashiko)&lt;/p&gt;
&lt;p&gt;v5:
  - Move destroy work to a module-lifetime Xe workqueue instead of
    system_dfl_wq. (Matt)
  - Flush the module-lifetime destroy workqueue during PCI remove to
    preserve the old device-remove wait semantics.&lt;/p&gt;
&lt;p&gt;v6:
  - Keep SVM pagemap destroy work on the per-device destroy_wq to avoid
    letting it outlive the…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-j3x5-5jxr-fgc6</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-68382</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-68382</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 154 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: drm/xe/guc: Hold device ref until queue teardown completes GuC exec queue destruction can run asynchronously. If the final device put happens from a destroy worker, drmm cleanup can end up draining the same workqueue and deadlock. Hold a drm_device reference for the queue lifetime and drop it after queue teardown completes. This keeps drmm cleanup from running while async destroy work is still pending. Move GuC destroy work to a module-lifetime Xe workqueue and flush it on PCI remove so hot-unbind/rebind still waits for pending destroy work. With queue-held device refs, guc_submit_sw_fini() cannot run with live GuC IDs. Replace the fini wait with an assertion and remove the unused fini_wq. v2:   - Rebase v3:   - Switch to queue-lifetime drm_dev_get()/drm_dev_put() model. (Matt)   - Queue async teardown on system_dfl_wq instead of xe-&amp;gt;destroy_wq. (Matt)   - Drop separate deferred drm_dev_put worker.   - Remove stale drain_workqueue(xe-&amp;gt;destroy_wq) from guc_submit_sw_fini(). v4:   - Replace the guc_submit_sw_fini() wait with an assertion and remove     the now-unused fini_wq. (sashiko) v5:   - Move destroy work to a module-lifetime Xe workqueue instead of     system_dfl_wq. (Matt)   - Flush the module-lifetime destroy workqueue during PCI remove to     preserve the old device-remove wait semantics. v6:   - Keep SVM pagemap destroy work on the per-device destroy_wq to avoid     letting it outlive the xe_device/…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 154 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: drm/xe/guc: Hold device ref until queue teardown completes GuC exec queue destruction can run asynchronously. If the final device put happens from a destroy worker, drmm cleanup can end up draining the same workqueue and deadlock. Hold a drm_device reference for the queue lifetime and drop it after queue teardown completes. This keeps drmm cleanup from running while async destroy work is still pending. Move GuC destroy work to a module-lifetime Xe workqueue and flush it on PCI remove so hot-unbind/rebind still waits for pending destroy work. With queue-held device refs, guc_submit_sw_fini() cannot run with live GuC IDs. Replace the fini wait with an assertion and remove the unused fini_wq. v2:   - Rebase v3:   - Switch to queue-lifetime drm_dev_get()/drm_dev_put() model. (Matt)   - Queue async teardown on system_dfl_wq instead of xe-&amp;gt;destroy_wq. (Matt)   - Drop separate deferred drm_dev_put worker.   - Remove stale drain_workqueue(xe-&amp;gt;destroy_wq) from guc_submit_sw_fini(). v4:   - Replace the guc_submit_sw_fini() wait with an assertion and remove     the now-unused fini_wq. (sashiko) v5:   - Move destroy work to a module-lifetime Xe workqueue instead of     system_dfl_wq. (Matt)   - Flush the module-lifetime destroy workqueue during PCI remove to     preserve the old device-remove wait semantics. v6:   - Keep SVM pagemap destroy work on the per-device destroy_wq to avoid     letting it outlive the xe_device/…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-68382</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2730 — Linux Kernel: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2730</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen, darunter möglicherweise die Ausführung von beliebigem Code, die Ausweitung von Berechtigungen, die Offenlegung von Informationen, die Manipulation von Daten oder Denial-of-Service-Zustände.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen, darunter möglicherweise die Ausführung von beliebigem Code, die Ausweitung von Berechtigungen, die Offenlegung von Informationen, die Manipulation von Daten oder Denial-of-Service-Zustände.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2730</guid>
    </item>
  </channel>
</rss>
