<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 05:46:01 +0000</lastBuildDate>
    <item>
      <title>BELL-CVE-2026-68401</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-68401</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-68401</guid>
    </item>
    <item>
      <title>EUVD-2026-353593</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-353593</link>
      <description>EUVD-2026-353593</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-353593</guid>
    </item>
    <item>
      <title>fkie_cve-2026-68401</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-68401</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;firmware: arm_ffa: Fix out-of-bound writes in ffa_setup_and_transmit()&lt;/p&gt;
&lt;p&gt;Sashiko (locally) reports multiple out-of-bound issues in
ffa_setup_and_transmit:
1) Writing ep_mem_access-&amp;gt;reserved can write out of bounds for FFA
   versions &amp;lt; 1.2 as ffa_emad_size_get() returns 16 bytes in that case
   while reserved has an offset of 24.
   Instead of zeroing fields, memset the struct to zero first based on
   the FFA version.&lt;/p&gt;
&lt;p&gt;2) Make sure there is enough size to write constituents.&lt;/p&gt;
&lt;p&gt;While at it, convert the only sizeof() in the driver that uses a
type instead of variable.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;firmware: arm_ffa: Fix out-of-bound writes in ffa_setup_and_transmit()&lt;/p&gt;
&lt;p&gt;Sashiko (locally) reports multiple out-of-bound issues in
ffa_setup_and_transmit:
1) Writing ep_mem_access-&amp;gt;reserved can write out of bounds for FFA
   versions &amp;lt; 1.2 as ffa_emad_size_get() returns 16 bytes in that case
   while reserved has an offset of 24.
   Instead of zeroing fields, memset the struct to zero first based on
   the FFA version.&lt;/p&gt;
&lt;p&gt;2) Make sure there is enough size to write constituents.&lt;/p&gt;
&lt;p&gt;While at it, convert the only sizeof() in the driver that uses a
type instead of variable.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-68401</guid>
    </item>
    <item>
      <title>GHSA-hvgp-9g43-gqqw</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-hvgp-9g43-gqqw</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;firmware: arm_ffa: Fix out-of-bound writes in ffa_setup_and_transmit()&lt;/p&gt;
&lt;p&gt;Sashiko (locally) reports multiple out-of-bound issues in
ffa_setup_and_transmit:
1) Writing ep_mem_access-&amp;gt;reserved can write out of bounds for FFA
   versions &amp;lt; 1.2 as ffa_emad_size_get() returns 16 bytes in that case
   while reserved has an offset of 24.
   Instead of zeroing fields, memset the struct to zero first based on
   the FFA version.&lt;/p&gt;
&lt;p&gt;2) Make sure there is enough size to write constituents.&lt;/p&gt;
&lt;p&gt;While at it, convert the only sizeof() in the driver that uses a
type instead of variable.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;firmware: arm_ffa: Fix out-of-bound writes in ffa_setup_and_transmit()&lt;/p&gt;
&lt;p&gt;Sashiko (locally) reports multiple out-of-bound issues in
ffa_setup_and_transmit:
1) Writing ep_mem_access-&amp;gt;reserved can write out of bounds for FFA
   versions &amp;lt; 1.2 as ffa_emad_size_get() returns 16 bytes in that case
   while reserved has an offset of 24.
   Instead of zeroing fields, memset the struct to zero first based on
   the FFA version.&lt;/p&gt;
&lt;p&gt;2) Make sure there is enough size to write constituents.&lt;/p&gt;
&lt;p&gt;While at it, convert the only sizeof() in the driver that uses a
type instead of variable.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-hvgp-9g43-gqqw</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-68401 — firmware: arm_ffa: Fix out-of-bound writes in ffa_setup_and_transmit()</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-68401</link>
      <description>msrc_CVE-2026-68401</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-68401</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-68401</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-68401</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 192 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: firmware: arm_ffa: Fix out-of-bound writes in ffa_setup_and_transmit() Sashiko (locally) reports multiple out-of-bound issues in ffa_setup_and_transmit: 1) Writing ep_mem_access-&amp;gt;reserved can write out of bounds for FFA    versions &amp;lt; 1.2 as ffa_emad_size_get() returns 16 bytes in that case    while reserved has an offset of 24.    Instead of zeroing fields, memset the struct to zero first based on    the FFA version. 2) Make sure there is enough size to write constituents. While at it, convert the only sizeof() in the driver that uses a type instead of variable.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 192 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: firmware: arm_ffa: Fix out-of-bound writes in ffa_setup_and_transmit() Sashiko (locally) reports multiple out-of-bound issues in ffa_setup_and_transmit: 1) Writing ep_mem_access-&amp;gt;reserved can write out of bounds for FFA    versions &amp;lt; 1.2 as ffa_emad_size_get() returns 16 bytes in that case    while reserved has an offset of 24.    Instead of zeroing fields, memset the struct to zero first based on    the FFA version. 2) Make sure there is enough size to write constituents. While at it, convert the only sizeof() in the driver that uses a type instead of variable.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-68401</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2730 — Linux Kernel: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2730</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen, darunter möglicherweise die Ausführung von beliebigem Code, die Ausweitung von Berechtigungen, die Offenlegung von Informationen, die Manipulation von Daten oder Denial-of-Service-Zustände.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen, darunter möglicherweise die Ausführung von beliebigem Code, die Ausweitung von Berechtigungen, die Offenlegung von Informationen, die Manipulation von Daten oder Denial-of-Service-Zustände.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2730</guid>
    </item>
  </channel>
</rss>
