<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 12:06:25 +0000</lastBuildDate>
    <item>
      <title>BELL-CVE-2026-72073</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-72073</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-72073</guid>
    </item>
    <item>
      <title>EUVD-2026-353652</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-353652</link>
      <description>EUVD-2026-353652</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-353652</guid>
    </item>
    <item>
      <title>fkie_cve-2026-72073</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-72073</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;mmc: vub300: fix use-after-free on probe failure&lt;/p&gt;
&lt;p&gt;The vub300 driver lifetime-manages its controller state using
vub300-&amp;gt;kref, with vub300_delete() freeing the mmc host when the last
reference is dropped. The probe error path after the inactivity timer has
been armed still bypasses that lifetime rule, however, and falls through
to mmc_free_host() directly if mmc_add_host() fails.&lt;/p&gt;
&lt;p&gt;The race window is between arming the inactivity timer and reaching the
probe error unwind after mmc_add_host() fails:&lt;/p&gt;
&lt;p&gt;probe thread                     timer/workqueue
        ------------                     ---------------
        kref_init(&amp;amp;vub300-&amp;gt;kref)         ref = 1
        kref_get(&amp;amp;vub300-&amp;gt;kref)          ref = 2, timer ref
        add_timer(inactivity_timer)      fires after one second
        |
        |   race window
        |&amp;lt;----------------------------------------------------&amp;gt;
        |
        mmc_add_host(mmc)
                                         inactivity timer fires
                                         vub300_queue_dead_work()
                                           kref_get()          ref = 3
                                           queue_work(deadwork)
        mmc_add_host() fails
        timer_delete_sync()
        mmc_free_host(mmc)
          frees vub300
                                         deadwork runs
                                           use-after-free&lt;/p&gt;
&lt;p&gt;The inactivity timeo…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;mmc: vub300: fix use-after-free on probe failure&lt;/p&gt;
&lt;p&gt;The vub300 driver lifetime-manages its controller state using
vub300-&amp;gt;kref, with vub300_delete() freeing the mmc host when the last
reference is dropped. The probe error path after the inactivity timer has
been armed still bypasses that lifetime rule, however, and falls through
to mmc_free_host() directly if mmc_add_host() fails.&lt;/p&gt;
&lt;p&gt;The race window is between arming the inactivity timer and reaching the
probe error unwind after mmc_add_host() fails:&lt;/p&gt;
&lt;p&gt;probe thread                     timer/workqueue
        ------------                     ---------------
        kref_init(&amp;amp;vub300-&amp;gt;kref)         ref = 1
        kref_get(&amp;amp;vub300-&amp;gt;kref)          ref = 2, timer ref
        add_timer(inactivity_timer)      fires after one second
        |
        |   race window
        |&amp;lt;----------------------------------------------------&amp;gt;
        |
        mmc_add_host(mmc)
                                         inactivity timer fires
                                         vub300_queue_dead_work()
                                           kref_get()          ref = 3
                                           queue_work(deadwork)
        mmc_add_host() fails
        timer_delete_sync()
        mmc_free_host(mmc)
          frees vub300
                                         deadwork runs
                                           use-after-free&lt;/p&gt;
&lt;p&gt;The inactivity timeo…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-72073</guid>
    </item>
    <item>
      <title>GHSA-2w4f-22fv-v9w4</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-2w4f-22fv-v9w4</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;mmc: vub300: fix use-after-free on probe failure&lt;/p&gt;
&lt;p&gt;The vub300 driver lifetime-manages its controller state using
vub300-&amp;gt;kref, with vub300_delete() freeing the mmc host when the last
reference is dropped. The probe error path after the inactivity timer has
been armed still bypasses that lifetime rule, however, and falls through
to mmc_free_host() directly if mmc_add_host() fails.&lt;/p&gt;
&lt;p&gt;The race window is between arming the inactivity timer and reaching the
probe error unwind after mmc_add_host() fails:&lt;/p&gt;
&lt;p&gt;probe thread                     timer/workqueue
        ------------                     ---------------
        kref_init(&amp;amp;vub300-&amp;gt;kref)         ref = 1
        kref_get(&amp;amp;vub300-&amp;gt;kref)          ref = 2, timer ref
        add_timer(inactivity_timer)      fires after one second
        |
        |   race window
        |&amp;lt;----------------------------------------------------&amp;gt;
        |
        mmc_add_host(mmc)
                                         inactivity timer fires
                                         vub300_queue_dead_work()
                                           kref_get()          ref = 3
                                           queue_work(deadwork)
        mmc_add_host() fails
        timer_delete_sync()
        mmc_free_host(mmc)
          frees vub300
                                         deadwork runs
                                           use-after-free&lt;/p&gt;
&lt;p&gt;The inactivity timeo…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;mmc: vub300: fix use-after-free on probe failure&lt;/p&gt;
&lt;p&gt;The vub300 driver lifetime-manages its controller state using
vub300-&amp;gt;kref, with vub300_delete() freeing the mmc host when the last
reference is dropped. The probe error path after the inactivity timer has
been armed still bypasses that lifetime rule, however, and falls through
to mmc_free_host() directly if mmc_add_host() fails.&lt;/p&gt;
&lt;p&gt;The race window is between arming the inactivity timer and reaching the
probe error unwind after mmc_add_host() fails:&lt;/p&gt;
&lt;p&gt;probe thread                     timer/workqueue
        ------------                     ---------------
        kref_init(&amp;amp;vub300-&amp;gt;kref)         ref = 1
        kref_get(&amp;amp;vub300-&amp;gt;kref)          ref = 2, timer ref
        add_timer(inactivity_timer)      fires after one second
        |
        |   race window
        |&amp;lt;----------------------------------------------------&amp;gt;
        |
        mmc_add_host(mmc)
                                         inactivity timer fires
                                         vub300_queue_dead_work()
                                           kref_get()          ref = 3
                                           queue_work(deadwork)
        mmc_add_host() fails
        timer_delete_sync()
        mmc_free_host(mmc)
          frees vub300
                                         deadwork runs
                                           use-after-free&lt;/p&gt;
&lt;p&gt;The inactivity timeo…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-2w4f-22fv-v9w4</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-72073 — mmc: vub300: fix use-after-free on probe failure</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-72073</link>
      <description>msrc_CVE-2026-72073</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-72073</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-72073</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-72073</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe, Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:Pro:16.04:LTS: linux-oracle, Ubuntu:Pro:18.04:LTS: linux, Ubuntu:Pro:18.04:LTS: linux-aws, Ubuntu:18.04:LTS: linux-aws-5.0 and 231 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: mmc: vub300: fix use-after-free on probe failure The vub300 driver lifetime-manages its controller state using vub300-&amp;gt;kref, with vub300_delete() freeing the mmc host when the last reference is dropped. The probe error path after the inactivity timer has been armed still bypasses that lifetime rule, however, and falls through to mmc_free_host() directly if mmc_add_host() fails. The race window is between arming the inactivity timer and reaching the probe error unwind after mmc_add_host() fails:         probe thread                     timer/workqueue         ------------                     ---------------         kref_init(&amp;amp;vub300-&amp;gt;kref)         ref = 1         kref_get(&amp;amp;vub300-&amp;gt;kref)          ref = 2, timer ref         add_timer(inactivity_timer)      fires after one second         |         |   race window         |&amp;lt;----------------------------------------------------&amp;gt;         |         mmc_add_host(mmc)                                          inactivity timer fires                                          vub300_queue_dead_work()                                            kref_get()          ref = 3                                            queue_work(deadwork)         mmc_add_host() fails         timer_delete_sync()         mmc_free_host(mmc)           frees vub300                                          deadwork runs                                            use-after-free The inactivity timeout is…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe, Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:Pro:16.04:LTS: linux-oracle, Ubuntu:Pro:18.04:LTS: linux, Ubuntu:Pro:18.04:LTS: linux-aws, Ubuntu:18.04:LTS: linux-aws-5.0 and 231 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: mmc: vub300: fix use-after-free on probe failure The vub300 driver lifetime-manages its controller state using vub300-&amp;gt;kref, with vub300_delete() freeing the mmc host when the last reference is dropped. The probe error path after the inactivity timer has been armed still bypasses that lifetime rule, however, and falls through to mmc_free_host() directly if mmc_add_host() fails. The race window is between arming the inactivity timer and reaching the probe error unwind after mmc_add_host() fails:         probe thread                     timer/workqueue         ------------                     ---------------         kref_init(&amp;amp;vub300-&amp;gt;kref)         ref = 1         kref_get(&amp;amp;vub300-&amp;gt;kref)          ref = 2, timer ref         add_timer(inactivity_timer)      fires after one second         |         |   race window         |&amp;lt;----------------------------------------------------&amp;gt;         |         mmc_add_host(mmc)                                          inactivity timer fires                                          vub300_queue_dead_work()                                            kref_get()          ref = 3                                            queue_work(deadwork)         mmc_add_host() fails         timer_delete_sync()         mmc_free_host(mmc)           frees vub300                                          deadwork runs                                            use-after-free The inactivity timeout is…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-72073</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2852 — Linux Kernel: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2852</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Linux Kernel ausnutzen, um root Rechte zu erlangen, um einen Denial of Service herbeizuführen oder einen nicht näher spezifizierten Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Linux Kernel ausnutzen, um root Rechte zu erlangen, um einen Denial of Service herbeizuführen oder einen nicht näher spezifizierten Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2852</guid>
    </item>
  </channel>
</rss>
