<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 12:35:42 +0000</lastBuildDate>
    <item>
      <title>ALSA-2026:57251 — Important: kernel security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:57251</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: kernel, AlmaLinux:10: kernel-64k, AlmaLinux:10: kernel-64k-core, AlmaLinux:10: kernel-64k-debug, AlmaLinux:10: kernel-64k-debug-core, AlmaLinux:10: kernel-64k-debug-devel, AlmaLinux:10: kernel-64k-debug-devel-matched, AlmaLinux:10: kernel-64k-debug-modules, AlmaLinux:10: kernel-64k-debug-modules-core, AlmaLinux:10: kernel-64k-debug-modules-extra and 65 more&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: drm/amdkfd: Fix out-of-bounds write in kfd_event_page_set() (CVE-2026-43206)
  * kernel: drm/amdgpu: Refactor amdgpu_gem_va_ioctl for Handling Last Fence Update and Timeline Management v4 (CVE-2026-43237)
  * kernel: crypto: pcrypt - Fix handling of MAY_BACKLOG requests (CVE-2026-43493)
  * kernel: udf: fix partition descriptor append bookkeeping (CVE-2026-45991)
  * kernel: drm/amdkfd: Fix watch_id bounds checking in debug address watch v2 (CVE-2026-45878)
  * kernel: smb/client: fix out-of-bounds read in symlink_data() (CVE-2026-46185)
  * kernel: sched/psi: fix race between file release and pressure write (CVE-2026-52991)
  * kernel: drm/amdkfd: Fix buffer overflow in SDMA queue checkpoint/restore on GFX11 (CVE-2026-53143)
  * kernel: drm/amd/display: Clamp VBIOS HDMI retimer register count to array size (CVE-2026-53136)
  * kernel: drm/amd/display: Use krealloc_array() in dal_vector_reserve() (CVE-2026-53329)
  * kernel: drm/i915/gem: Fix phys BO pread/pwrite with offset (CVE-2026-53356)
  * kernel: drm/amdgpu: zero-initialize GART table on allocation (CVE-2026-53374)
  * kernel: drm/i915: Fix potential UAF in TTM object purge (CVE-2026-63884)
  * kernel: scsi: target: iscsi: Validate CHAP_R length before base64 decode (CVE-2026-63886)
  * kernel: memfd: deny writeable mappings when implying SEAL_WRITE (CVE-2026-63952)
  * kernel: scsi: target: iscsi:…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: kernel, AlmaLinux:10: kernel-64k, AlmaLinux:10: kernel-64k-core, AlmaLinux:10: kernel-64k-debug, AlmaLinux:10: kernel-64k-debug-core, AlmaLinux:10: kernel-64k-debug-devel, AlmaLinux:10: kernel-64k-debug-devel-matched, AlmaLinux:10: kernel-64k-debug-modules, AlmaLinux:10: kernel-64k-debug-modules-core, AlmaLinux:10: kernel-64k-debug-modules-extra and 65 more&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: drm/amdkfd: Fix out-of-bounds write in kfd_event_page_set() (CVE-2026-43206)
  * kernel: drm/amdgpu: Refactor amdgpu_gem_va_ioctl for Handling Last Fence Update and Timeline Management v4 (CVE-2026-43237)
  * kernel: crypto: pcrypt - Fix handling of MAY_BACKLOG requests (CVE-2026-43493)
  * kernel: udf: fix partition descriptor append bookkeeping (CVE-2026-45991)
  * kernel: drm/amdkfd: Fix watch_id bounds checking in debug address watch v2 (CVE-2026-45878)
  * kernel: smb/client: fix out-of-bounds read in symlink_data() (CVE-2026-46185)
  * kernel: sched/psi: fix race between file release and pressure write (CVE-2026-52991)
  * kernel: drm/amdkfd: Fix buffer overflow in SDMA queue checkpoint/restore on GFX11 (CVE-2026-53143)
  * kernel: drm/amd/display: Clamp VBIOS HDMI retimer register count to array size (CVE-2026-53136)
  * kernel: drm/amd/display: Use krealloc_array() in dal_vector_reserve() (CVE-2026-53329)
  * kernel: drm/i915/gem: Fix phys BO pread/pwrite with offset (CVE-2026-53356)
  * kernel: drm/amdgpu: zero-initialize GART table on allocation (CVE-2026-53374)
  * kernel: drm/i915: Fix potential UAF in TTM object purge (CVE-2026-63884)
  * kernel: scsi: target: iscsi: Validate CHAP_R length before base64 decode (CVE-2026-63886)
  * kernel: memfd: deny writeable mappings when implying SEAL_WRITE (CVE-2026-63952)
  * kernel: scsi: target: iscsi:…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:57251</guid>
    </item>
    <item>
      <title>BELL-CVE-2026-68388</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-68388</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-68388</guid>
    </item>
    <item>
      <title>certfr-2026-avi-1065 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de Red Hat. Certaines d'entre elles permettent à un…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1065</link>
      <description>certfr-2026-avi-1065</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-1065</guid>
    </item>
    <item>
      <title>EUVD-2026-356322</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-356322</link>
      <description>EUVD-2026-356322</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-356322</guid>
    </item>
    <item>
      <title>fkie_cve-2026-68388</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-68388</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;smb/client: handle overlapping allocated ranges in fallocate&lt;/p&gt;
&lt;p&gt;smb3_simple_fallocate_range() can skip holes when an allocated range
returned by the server starts before the current fallocate offset. The
skipped hole is not zero-filled, but fallocate still returns success. A
later write to that hole may therefore fail with ENOSPC.&lt;/p&gt;
&lt;p&gt;The function queries allocated ranges so that it can preserve existing
contents and write zeroes only into holes. However, the server may return
a range that starts before the current fallocate offset.&lt;/p&gt;
&lt;p&gt;For example, assume the fallocate request is [100, 400) and the only
allocated range returned by the server is [0, 200):&lt;/p&gt;
&lt;p&gt;Request:      [100, 400)
        Server range: [  0, 200)  allocated&lt;/p&gt;
&lt;p&gt;Correct:
        [100, 200)    allocated data, skip
        [200, 400)    hole, zero-fill&lt;/p&gt;
&lt;p&gt;Current:
        [100, 300)    skipped
        [300, 400)    zero-filled afterwards&lt;/p&gt;
&lt;p&gt;The current code adds the full server range length, 200, to the current
offset 100 and moves to 300. As a result, the hole in [200, 300) is
skipped without being zero-filled.&lt;/p&gt;
&lt;p&gt;Fix this by advancing only over the part of the allocated range that
overlaps the current fallocate offset.  Ignore ranges that end before the
current offset and reject ranges whose end offset overflows.&lt;/p&gt;
&lt;p&gt;This also prevents a malformed range length from causing an out-of-bounds
zero-buffer read.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;smb/client: handle overlapping allocated ranges in fallocate&lt;/p&gt;
&lt;p&gt;smb3_simple_fallocate_range() can skip holes when an allocated range
returned by the server starts before the current fallocate offset. The
skipped hole is not zero-filled, but fallocate still returns success. A
later write to that hole may therefore fail with ENOSPC.&lt;/p&gt;
&lt;p&gt;The function queries allocated ranges so that it can preserve existing
contents and write zeroes only into holes. However, the server may return
a range that starts before the current fallocate offset.&lt;/p&gt;
&lt;p&gt;For example, assume the fallocate request is [100, 400) and the only
allocated range returned by the server is [0, 200):&lt;/p&gt;
&lt;p&gt;Request:      [100, 400)
        Server range: [  0, 200)  allocated&lt;/p&gt;
&lt;p&gt;Correct:
        [100, 200)    allocated data, skip
        [200, 400)    hole, zero-fill&lt;/p&gt;
&lt;p&gt;Current:
        [100, 300)    skipped
        [300, 400)    zero-filled afterwards&lt;/p&gt;
&lt;p&gt;The current code adds the full server range length, 200, to the current
offset 100 and moves to 300. As a result, the hole in [200, 300) is
skipped without being zero-filled.&lt;/p&gt;
&lt;p&gt;Fix this by advancing only over the part of the allocated range that
overlaps the current fallocate offset.  Ignore ranges that end before the
current offset and reject ranges whose end offset overflows.&lt;/p&gt;
&lt;p&gt;This also prevents a malformed range length from causing an out-of-bounds
zero-buffer read.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-68388</guid>
    </item>
    <item>
      <title>GHSA-h6fv-x4pg-r56c</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-h6fv-x4pg-r56c</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;smb/client: handle overlapping allocated ranges in fallocate&lt;/p&gt;
&lt;p&gt;smb3_simple_fallocate_range() can skip holes when an allocated range
returned by the server starts before the current fallocate offset. The
skipped hole is not zero-filled, but fallocate still returns success. A
later write to that hole may therefore fail with ENOSPC.&lt;/p&gt;
&lt;p&gt;The function queries allocated ranges so that it can preserve existing
contents and write zeroes only into holes. However, the server may return
a range that starts before the current fallocate offset.&lt;/p&gt;
&lt;p&gt;For example, assume the fallocate request is [100, 400) and the only
allocated range returned by the server is [0, 200):&lt;/p&gt;
&lt;p&gt;Request:      [100, 400)
        Server range: [  0, 200)  allocated&lt;/p&gt;
&lt;p&gt;Correct:
        [100, 200)    allocated data, skip
        [200, 400)    hole, zero-fill&lt;/p&gt;
&lt;p&gt;Current:
        [100, 300)    skipped
        [300, 400)    zero-filled afterwards&lt;/p&gt;
&lt;p&gt;The current code adds the full server range length, 200, to the current
offset 100 and moves to 300. As a result, the hole in [200, 300) is
skipped without being zero-filled.&lt;/p&gt;
&lt;p&gt;Fix this by advancing only over the part of the allocated range that
overlaps the current fallocate offset.  Ignore ranges that end before the
current offset and reject ranges whose end offset overflows.&lt;/p&gt;
&lt;p&gt;This also prevents a malformed range length from causing an out-of-bounds
zero-buffer read.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;smb/client: handle overlapping allocated ranges in fallocate&lt;/p&gt;
&lt;p&gt;smb3_simple_fallocate_range() can skip holes when an allocated range
returned by the server starts before the current fallocate offset. The
skipped hole is not zero-filled, but fallocate still returns success. A
later write to that hole may therefore fail with ENOSPC.&lt;/p&gt;
&lt;p&gt;The function queries allocated ranges so that it can preserve existing
contents and write zeroes only into holes. However, the server may return
a range that starts before the current fallocate offset.&lt;/p&gt;
&lt;p&gt;For example, assume the fallocate request is [100, 400) and the only
allocated range returned by the server is [0, 200):&lt;/p&gt;
&lt;p&gt;Request:      [100, 400)
        Server range: [  0, 200)  allocated&lt;/p&gt;
&lt;p&gt;Correct:
        [100, 200)    allocated data, skip
        [200, 400)    hole, zero-fill&lt;/p&gt;
&lt;p&gt;Current:
        [100, 300)    skipped
        [300, 400)    zero-filled afterwards&lt;/p&gt;
&lt;p&gt;The current code adds the full server range length, 200, to the current
offset 100 and moves to 300. As a result, the hole in [200, 300) is
skipped without being zero-filled.&lt;/p&gt;
&lt;p&gt;Fix this by advancing only over the part of the allocated range that
overlaps the current fallocate offset.  Ignore ranges that end before the
current offset and reject ranges whose end offset overflows.&lt;/p&gt;
&lt;p&gt;This also prevents a malformed range length from causing an out-of-bounds
zero-buffer read.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-h6fv-x4pg-r56c</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-68388 — smb/client: handle overlapping allocated ranges in fallocate</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-68388</link>
      <description>msrc_CVE-2026-68388</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-68388</guid>
    </item>
    <item>
      <title>OESA-2026-3706 — kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-3706</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP4: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:net: af_can: do not leave a dangling sk pointer in can_create()On error can_create() frees the allocated sk object, but sock_init_data()has already attached it to the provided sock object. This will leave adangling sk pointer in the sock object and may cause use-after-free later.(CVE-2024-56603)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;hdlc_ppp: sync per-proto timers before freeing hdlc state&lt;/p&gt;
&lt;p&gt;Each PPP control protocol (LCP/IPCP/IPV6CP) embedded in struct ppp
registers a timer via timer_setup(). That struct ppp is the
hdlc-&amp;amp;gt;state allocation, which detach_hdlc_protocol() frees with kfree()
in both teardown paths: unregister_hdlc_device() and the re-attach inside
attach_hdlc_protocol().&lt;/p&gt;
&lt;p&gt;The ppp proto never registered a .detach callback, so
detach_hdlc_protocol() performs no timer synchronization before the
kfree(). The only cancel, timer_delete(&amp;amp;amp;proto-&amp;amp;gt;timer) in ppp_cp_event(),
is partial (it does not wait for a running callback) and only runs on the
-&amp;amp;gt;CLOSED transition; ppp_stop()/ppp_close() do not sync either. A
ppp_timer callback already executing (blocked on ppp-&amp;amp;gt;lock) survives the
kfree and then dereferences proto-&amp;amp;gt;state / ppp-&amp;amp;gt;lock in freed memory,
leading to a use-after-free.&lt;/p&gt;
&lt;p&gt;Fix this by adding a .detach helper that calls timer_shutdown_sync() on
every per-proto timer. detach_hd…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP4: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:net: af_can: do not leave a dangling sk pointer in can_create()On error can_create() frees the allocated sk object, but sock_init_data()has already attached it to the provided sock object. This will leave adangling sk pointer in the sock object and may cause use-after-free later.(CVE-2024-56603)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;hdlc_ppp: sync per-proto timers before freeing hdlc state&lt;/p&gt;
&lt;p&gt;Each PPP control protocol (LCP/IPCP/IPV6CP) embedded in struct ppp
registers a timer via timer_setup(). That struct ppp is the
hdlc-&amp;amp;gt;state allocation, which detach_hdlc_protocol() frees with kfree()
in both teardown paths: unregister_hdlc_device() and the re-attach inside
attach_hdlc_protocol().&lt;/p&gt;
&lt;p&gt;The ppp proto never registered a .detach callback, so
detach_hdlc_protocol() performs no timer synchronization before the
kfree(). The only cancel, timer_delete(&amp;amp;amp;proto-&amp;amp;gt;timer) in ppp_cp_event(),
is partial (it does not wait for a running callback) and only runs on the
-&amp;amp;gt;CLOSED transition; ppp_stop()/ppp_close() do not sync either. A
ppp_timer callback already executing (blocked on ppp-&amp;amp;gt;lock) survives the
kfree and then dereferences proto-&amp;amp;gt;state / ppp-&amp;amp;gt;lock in freed memory,
leading to a use-after-free.&lt;/p&gt;
&lt;p&gt;Fix this by adding a .detach helper that calls timer_shutdown_sync() on
every per-proto timer. detach_hd…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-3706</guid>
    </item>
    <item>
      <title>RHSA-2026:57251 — Red Hat Security Advisory: kernel security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:57251</link>
      <description>&lt;p&gt;kernel: drm/amdkfd: Fix out-of-bounds write in kfd_event_page_set() kernel: drm/amdgpu: Refactor amdgpu_gem_va_ioctl for Handling Last Fence Update and Timeline Management v4 kernel: crypto: pcrypt - Fix handling of MAY_BACKLOG requests kernel: drm/amdkfd: Fix watch_id bounds checking in debug address watch v2 kernel: udf: fix partition descriptor append bookkeeping kernel: smb/client: fix out-of-bounds read in symlink_data() kernel: sched/psi: fix race between file release and pressure write kernel: drm/amd/display: Clamp VBIOS HDMI retimer register count to array size kernel: drm/amdkfd: Fix buffer overflow in SDMA queue checkpoint/restore on GFX11 kernel: drm/amd/display: Use krealloc_array() in dal_vector_reserve() kernel: drm/i915/gem: Fix phys BO pread/pwrite with offset kernel: drm/amdgpu: zero-initialize GART table on allocation kernel: drm/amdgpu: fix amdgpu_hmm_range_get_pages kernel: drm/i915: Fix potential UAF in TTM object purge kernel: scsi: target: iscsi: Validate CHAP_R length before base64 decode kernel: scsi: target: iscsi: Fix CRC overread and double-free in iscsit_handle_text_cmd() kernel: memfd: deny writeable mappings when implying SEAL_WRITE kernel: blk-mq: pop cached request if it is usable kernel: drm/amd/display: Validate payload length and link_index in dc_process_dmub_aux_transfer_async kernel: smb: client: mask server-provided mode to 07777 in modefromsid kernel: smb: client: fix double-free in SMB2_open() replay kernel: smb: client: fix query_in…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;kernel: drm/amdkfd: Fix out-of-bounds write in kfd_event_page_set() kernel: drm/amdgpu: Refactor amdgpu_gem_va_ioctl for Handling Last Fence Update and Timeline Management v4 kernel: crypto: pcrypt - Fix handling of MAY_BACKLOG requests kernel: drm/amdkfd: Fix watch_id bounds checking in debug address watch v2 kernel: udf: fix partition descriptor append bookkeeping kernel: smb/client: fix out-of-bounds read in symlink_data() kernel: sched/psi: fix race between file release and pressure write kernel: drm/amd/display: Clamp VBIOS HDMI retimer register count to array size kernel: drm/amdkfd: Fix buffer overflow in SDMA queue checkpoint/restore on GFX11 kernel: drm/amd/display: Use krealloc_array() in dal_vector_reserve() kernel: drm/i915/gem: Fix phys BO pread/pwrite with offset kernel: drm/amdgpu: zero-initialize GART table on allocation kernel: drm/amdgpu: fix amdgpu_hmm_range_get_pages kernel: drm/i915: Fix potential UAF in TTM object purge kernel: scsi: target: iscsi: Validate CHAP_R length before base64 decode kernel: scsi: target: iscsi: Fix CRC overread and double-free in iscsit_handle_text_cmd() kernel: memfd: deny writeable mappings when implying SEAL_WRITE kernel: blk-mq: pop cached request if it is usable kernel: drm/amd/display: Validate payload length and link_index in dc_process_dmub_aux_transfer_async kernel: smb: client: mask server-provided mode to 07777 in modefromsid kernel: smb: client: fix double-free in SMB2_open() replay kernel: smb: client: fix query_in…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:57251</guid>
    </item>
    <item>
      <title>RHSA-2026:57254 — Red Hat Security Advisory: kernel-rt security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:57254</link>
      <description>&lt;p&gt;kernel: net: ieee802154: do not leave a dangling sk pointer in ieee802154_create() kernel: ip6_gre: Use cached t-&amp;gt;net in ip6erspan_changelink() kernel: sched/psi: fix race between file release and pressure write kernel: mm/huge_memory: update file PMD counter before folio_put() kernel: scsi: target: iscsi: Bound iscsi_encode_text_output() appends to rsp_buf kernel: scsi: target: iscsi: Fix CRC overread and double-free in iscsit_handle_text_cmd() kernel: net/smc: reject CHID-0 ACCEPT that matches an empty ism_dev slot kernel: smb: client: mask server-provided mode to 07777 in modefromsid kernel: smb/client: handle overlapping allocated ranges in fallocate&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;kernel: net: ieee802154: do not leave a dangling sk pointer in ieee802154_create() kernel: ip6_gre: Use cached t-&amp;gt;net in ip6erspan_changelink() kernel: sched/psi: fix race between file release and pressure write kernel: mm/huge_memory: update file PMD counter before folio_put() kernel: scsi: target: iscsi: Bound iscsi_encode_text_output() appends to rsp_buf kernel: scsi: target: iscsi: Fix CRC overread and double-free in iscsit_handle_text_cmd() kernel: net/smc: reject CHID-0 ACCEPT that matches an empty ism_dev slot kernel: smb: client: mask server-provided mode to 07777 in modefromsid kernel: smb/client: handle overlapping allocated ranges in fallocate&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:57254</guid>
    </item>
    <item>
      <title>RLSA-2026:57251 — Important: kernel security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:57251</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: kernel&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: drm/amdkfd: Fix out-of-bounds write in kfd_event_page_set() (CVE-2026-43206)&lt;/p&gt;
&lt;p&gt;* kernel: drm/amdgpu: Refactor amdgpu_gem_va_ioctl for Handling Last Fence Update and Timeline Management v4 (CVE-2026-43237)&lt;/p&gt;
&lt;p&gt;* kernel: crypto: pcrypt - Fix handling of MAY_BACKLOG requests (CVE-2026-43493)&lt;/p&gt;
&lt;p&gt;* kernel: udf: fix partition descriptor append bookkeeping (CVE-2026-45991)&lt;/p&gt;
&lt;p&gt;* kernel: drm/amdkfd: Fix watch_id bounds checking in debug address watch v2 (CVE-2026-45878)&lt;/p&gt;
&lt;p&gt;* kernel: smb/client: fix out-of-bounds read in symlink_data() (CVE-2026-46185)&lt;/p&gt;
&lt;p&gt;* kernel: sched/psi: fix race between file release and pressure write (CVE-2026-52991)&lt;/p&gt;
&lt;p&gt;* kernel: drm/amdkfd: Fix buffer overflow in SDMA queue checkpoint/restore on GFX11 (CVE-2026-53143)&lt;/p&gt;
&lt;p&gt;* kernel: drm/amd/display: Clamp VBIOS HDMI retimer register count to array size (CVE-2026-53136)&lt;/p&gt;
&lt;p&gt;* kernel: drm/amd/display: Use krealloc_array() in dal_vector_reserve() (CVE-2026-53329)&lt;/p&gt;
&lt;p&gt;* kernel: drm/i915/gem: Fix phys BO pread/pwrite with offset (CVE-2026-53356)&lt;/p&gt;
&lt;p&gt;* kernel: drm/amdgpu: zero-initialize GART table on allocation (CVE-2026-53374)&lt;/p&gt;
&lt;p&gt;* kernel: drm/i915: Fix potential UAF in TTM object purge (CVE-2026-63884)&lt;/p&gt;
&lt;p&gt;* kernel: scsi: target: iscsi: Validate CHAP_R length before base64 decode (CVE-2026-63886)&lt;/p&gt;
&lt;p&gt;* kernel: memfd: deny writeable mappings when implying SEAL_WRITE (CVE-2026-63952)&lt;/p&gt;
&lt;p&gt;* kernel: scsi: target: iscsi: Fix CRC overread and…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: kernel&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: drm/amdkfd: Fix out-of-bounds write in kfd_event_page_set() (CVE-2026-43206)&lt;/p&gt;
&lt;p&gt;* kernel: drm/amdgpu: Refactor amdgpu_gem_va_ioctl for Handling Last Fence Update and Timeline Management v4 (CVE-2026-43237)&lt;/p&gt;
&lt;p&gt;* kernel: crypto: pcrypt - Fix handling of MAY_BACKLOG requests (CVE-2026-43493)&lt;/p&gt;
&lt;p&gt;* kernel: udf: fix partition descriptor append bookkeeping (CVE-2026-45991)&lt;/p&gt;
&lt;p&gt;* kernel: drm/amdkfd: Fix watch_id bounds checking in debug address watch v2 (CVE-2026-45878)&lt;/p&gt;
&lt;p&gt;* kernel: smb/client: fix out-of-bounds read in symlink_data() (CVE-2026-46185)&lt;/p&gt;
&lt;p&gt;* kernel: sched/psi: fix race between file release and pressure write (CVE-2026-52991)&lt;/p&gt;
&lt;p&gt;* kernel: drm/amdkfd: Fix buffer overflow in SDMA queue checkpoint/restore on GFX11 (CVE-2026-53143)&lt;/p&gt;
&lt;p&gt;* kernel: drm/amd/display: Clamp VBIOS HDMI retimer register count to array size (CVE-2026-53136)&lt;/p&gt;
&lt;p&gt;* kernel: drm/amd/display: Use krealloc_array() in dal_vector_reserve() (CVE-2026-53329)&lt;/p&gt;
&lt;p&gt;* kernel: drm/i915/gem: Fix phys BO pread/pwrite with offset (CVE-2026-53356)&lt;/p&gt;
&lt;p&gt;* kernel: drm/amdgpu: zero-initialize GART table on allocation (CVE-2026-53374)&lt;/p&gt;
&lt;p&gt;* kernel: drm/i915: Fix potential UAF in TTM object purge (CVE-2026-63884)&lt;/p&gt;
&lt;p&gt;* kernel: scsi: target: iscsi: Validate CHAP_R length before base64 decode (CVE-2026-63886)&lt;/p&gt;
&lt;p&gt;* kernel: memfd: deny writeable mappings when implying SEAL_WRITE (CVE-2026-63952)&lt;/p&gt;
&lt;p&gt;* kernel: scsi: target: iscsi: Fix CRC overread and…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:57251</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-68388</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-68388</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 193 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: smb/client: handle overlapping allocated ranges in fallocate smb3_simple_fallocate_range() can skip holes when an allocated range returned by the server starts before the current fallocate offset. The skipped hole is not zero-filled, but fallocate still returns success. A later write to that hole may therefore fail with ENOSPC. The function queries allocated ranges so that it can preserve existing contents and write zeroes only into holes. However, the server may return a range that starts before the current fallocate offset. For example, assume the fallocate request is [100, 400) and the only allocated range returned by the server is [0, 200):         Request:      [100, 400)         Server range: [  0, 200)  allocated         Correct:         [100, 200)    allocated data, skip         [200, 400)    hole, zero-fill         Current:         [100, 300)    skipped         [300, 400)    zero-filled afterwards The current code adds the full server range length, 200, to the current offset 100 and moves to 300. As a result, the hole in [200, 300) is skipped without being zero-filled. Fix this by advancing only over the part of the allocated range that overlaps the current fallocate offset.  Ignore ranges that end before the current offset and reject ranges whose end offset overflows. This also prevents a malformed range length from causing an out-of-bounds zero-buffer read.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 193 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: smb/client: handle overlapping allocated ranges in fallocate smb3_simple_fallocate_range() can skip holes when an allocated range returned by the server starts before the current fallocate offset. The skipped hole is not zero-filled, but fallocate still returns success. A later write to that hole may therefore fail with ENOSPC. The function queries allocated ranges so that it can preserve existing contents and write zeroes only into holes. However, the server may return a range that starts before the current fallocate offset. For example, assume the fallocate request is [100, 400) and the only allocated range returned by the server is [0, 200):         Request:      [100, 400)         Server range: [  0, 200)  allocated         Correct:         [100, 200)    allocated data, skip         [200, 400)    hole, zero-fill         Current:         [100, 300)    skipped         [300, 400)    zero-filled afterwards The current code adds the full server range length, 200, to the current offset 100 and moves to 300. As a result, the hole in [200, 300) is skipped without being zero-filled. Fix this by advancing only over the part of the allocated range that overlaps the current fallocate offset.  Ignore ranges that end before the current offset and reject ranges whose end offset overflows. This also prevents a malformed range length from causing an out-of-bounds zero-buffer read.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-68388</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2730 — Linux Kernel: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2730</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen, darunter möglicherweise die Ausführung von beliebigem Code, die Ausweitung von Berechtigungen, die Offenlegung von Informationen, die Manipulation von Daten oder Denial-of-Service-Zustände.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen, darunter möglicherweise die Ausführung von beliebigem Code, die Ausweitung von Berechtigungen, die Offenlegung von Informationen, die Manipulation von Daten oder Denial-of-Service-Zustände.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2730</guid>
    </item>
  </channel>
</rss>
