<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 14:27:54 +0000</lastBuildDate>
    <item>
      <title>BELL-CVE-2026-74672</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-74672</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-74672</guid>
    </item>
    <item>
      <title>certfr-2026-avi-1090 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de Debian. Elles permettent à un attaquant de provo…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1090</link>
      <description>certfr-2026-avi-1090</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-1090</guid>
    </item>
    <item>
      <title>EUVD-2026-357930</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-357930</link>
      <description>EUVD-2026-357930</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-357930</guid>
    </item>
    <item>
      <title>fkie_cve-2026-74672</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-74672</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;mm/vmalloc: acquire init_mm lock on huge vmap to avoid ptdump UAF&lt;/p&gt;
&lt;p&gt;Patch series &amp;#34;mm: fix UAF caused by race between ptdump and vmap pgtable
freeing&amp;#34;, v6.&lt;/p&gt;
&lt;p&gt;Kernel page table walkers fall into two broad categories - those ranges
where no exclusion is required via walk_kernel_page_table_range_lockless()
and those where exclusion is required via walk_kernel_page_table_range()
or walk_page_range_debug().&lt;/p&gt;
&lt;p&gt;The former category is used only by arm64 arch code operating on ranges it
both wholly owns and does not concurrently write.&lt;/p&gt;
&lt;p&gt;The latter category consists of kernel page table walkers operating on
ranges that are wholly owned (but which need exclusion against concurrent
writers).&lt;/p&gt;
&lt;p&gt;The lock used for exclusion is the mmap lock, and for kernel ranges this
is the mmap lock on init_mm.&lt;/p&gt;
&lt;p&gt;ptdump is a special case being both the only user of
walk_page_range_debug(), and the only case in which it walks ranges it
does not own.&lt;/p&gt;
&lt;p&gt;This presents a problem, as page tables may be freed under ptdump.  And
indeed there is a use-after-free bug in the kernel as a result, which this
series addresses.&lt;/p&gt;
&lt;p&gt;vmap promotes page tables to huge leaf entries where possible, freeing the
lower page table when it does.  It does this with no meaningful locks held
against concurrent ptdump walks.&lt;/p&gt;
&lt;p&gt;As a result, use-after-free can currently occur.  This series addresses
the issue by having the vmap huge promotion logic acquire the mmap read
lock whi…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;mm/vmalloc: acquire init_mm lock on huge vmap to avoid ptdump UAF&lt;/p&gt;
&lt;p&gt;Patch series &amp;#34;mm: fix UAF caused by race between ptdump and vmap pgtable
freeing&amp;#34;, v6.&lt;/p&gt;
&lt;p&gt;Kernel page table walkers fall into two broad categories - those ranges
where no exclusion is required via walk_kernel_page_table_range_lockless()
and those where exclusion is required via walk_kernel_page_table_range()
or walk_page_range_debug().&lt;/p&gt;
&lt;p&gt;The former category is used only by arm64 arch code operating on ranges it
both wholly owns and does not concurrently write.&lt;/p&gt;
&lt;p&gt;The latter category consists of kernel page table walkers operating on
ranges that are wholly owned (but which need exclusion against concurrent
writers).&lt;/p&gt;
&lt;p&gt;The lock used for exclusion is the mmap lock, and for kernel ranges this
is the mmap lock on init_mm.&lt;/p&gt;
&lt;p&gt;ptdump is a special case being both the only user of
walk_page_range_debug(), and the only case in which it walks ranges it
does not own.&lt;/p&gt;
&lt;p&gt;This presents a problem, as page tables may be freed under ptdump.  And
indeed there is a use-after-free bug in the kernel as a result, which this
series addresses.&lt;/p&gt;
&lt;p&gt;vmap promotes page tables to huge leaf entries where possible, freeing the
lower page table when it does.  It does this with no meaningful locks held
against concurrent ptdump walks.&lt;/p&gt;
&lt;p&gt;As a result, use-after-free can currently occur.  This series addresses
the issue by having the vmap huge promotion logic acquire the mmap read
lock whi…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-74672</guid>
    </item>
    <item>
      <title>GHSA-h3pq-52v7-99m6</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-h3pq-52v7-99m6</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;mm/vmalloc: acquire init_mm lock on huge vmap to avoid ptdump UAF&lt;/p&gt;
&lt;p&gt;Patch series &amp;#34;mm: fix UAF caused by race between ptdump and vmap pgtable
freeing&amp;#34;, v6.&lt;/p&gt;
&lt;p&gt;Kernel page table walkers fall into two broad categories - those ranges
where no exclusion is required via walk_kernel_page_table_range_lockless()
and those where exclusion is required via walk_kernel_page_table_range()
or walk_page_range_debug().&lt;/p&gt;
&lt;p&gt;The former category is used only by arm64 arch code operating on ranges it
both wholly owns and does not concurrently write.&lt;/p&gt;
&lt;p&gt;The latter category consists of kernel page table walkers operating on
ranges that are wholly owned (but which need exclusion against concurrent
writers).&lt;/p&gt;
&lt;p&gt;The lock used for exclusion is the mmap lock, and for kernel ranges this
is the mmap lock on init_mm.&lt;/p&gt;
&lt;p&gt;ptdump is a special case being both the only user of
walk_page_range_debug(), and the only case in which it walks ranges it
does not own.&lt;/p&gt;
&lt;p&gt;This presents a problem, as page tables may be freed under ptdump.  And
indeed there is a use-after-free bug in the kernel as a result, which this
series addresses.&lt;/p&gt;
&lt;p&gt;vmap promotes page tables to huge leaf entries where possible, freeing the
lower page table when it does.  It does this with no meaningful locks held
against concurrent ptdump walks.&lt;/p&gt;
&lt;p&gt;As a result, use-after-free can currently occur.  This series addresses
the issue by having the vmap huge promotion logic acquire the mmap read
lock whi…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;mm/vmalloc: acquire init_mm lock on huge vmap to avoid ptdump UAF&lt;/p&gt;
&lt;p&gt;Patch series &amp;#34;mm: fix UAF caused by race between ptdump and vmap pgtable
freeing&amp;#34;, v6.&lt;/p&gt;
&lt;p&gt;Kernel page table walkers fall into two broad categories - those ranges
where no exclusion is required via walk_kernel_page_table_range_lockless()
and those where exclusion is required via walk_kernel_page_table_range()
or walk_page_range_debug().&lt;/p&gt;
&lt;p&gt;The former category is used only by arm64 arch code operating on ranges it
both wholly owns and does not concurrently write.&lt;/p&gt;
&lt;p&gt;The latter category consists of kernel page table walkers operating on
ranges that are wholly owned (but which need exclusion against concurrent
writers).&lt;/p&gt;
&lt;p&gt;The lock used for exclusion is the mmap lock, and for kernel ranges this
is the mmap lock on init_mm.&lt;/p&gt;
&lt;p&gt;ptdump is a special case being both the only user of
walk_page_range_debug(), and the only case in which it walks ranges it
does not own.&lt;/p&gt;
&lt;p&gt;This presents a problem, as page tables may be freed under ptdump.  And
indeed there is a use-after-free bug in the kernel as a result, which this
series addresses.&lt;/p&gt;
&lt;p&gt;vmap promotes page tables to huge leaf entries where possible, freeing the
lower page table when it does.  It does this with no meaningful locks held
against concurrent ptdump walks.&lt;/p&gt;
&lt;p&gt;As a result, use-after-free can currently occur.  This series addresses
the issue by having the vmap huge promotion logic acquire the mmap read
lock whi…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-h3pq-52v7-99m6</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-74672 — mm/vmalloc: acquire init_mm lock on huge vmap to avoid ptdump UAF</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-74672</link>
      <description>msrc_CVE-2026-74672</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-74672</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-74672</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-74672</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe, Ubuntu:16.04:LTS: linux-hwe-edge and 245 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: mm/vmalloc: acquire init_mm lock on huge vmap to avoid ptdump UAF Patch series &amp;#34;mm: fix UAF caused by race between ptdump and vmap pgtable freeing&amp;#34;, v6. Kernel page table walkers fall into two broad categories - those ranges where no exclusion is required via walk_kernel_page_table_range_lockless() and those where exclusion is required via walk_kernel_page_table_range() or walk_page_range_debug(). The former category is used only by arm64 arch code operating on ranges it both wholly owns and does not concurrently write. The latter category consists of kernel page table walkers operating on ranges that are wholly owned (but which need exclusion against concurrent writers). The lock used for exclusion is the mmap lock, and for kernel ranges this is the mmap lock on init_mm. ptdump is a special case being both the only user of walk_page_range_debug(), and the only case in which it walks ranges it does not own. This presents a problem, as page tables may be freed under ptdump.  And indeed there is a use-after-free bug in the kernel as a result, which this series addresses. vmap promotes page tables to huge leaf entries where possible, freeing the lower page table when it does.  It does this with no meaningful locks held against concurrent ptdump walks. As a result, use-after-free can currently occur.  This series addresses the issue by having the vmap huge promotion logic acquire the mmap read lock while both se…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe, Ubuntu:16.04:LTS: linux-hwe-edge and 245 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: mm/vmalloc: acquire init_mm lock on huge vmap to avoid ptdump UAF Patch series &amp;#34;mm: fix UAF caused by race between ptdump and vmap pgtable freeing&amp;#34;, v6. Kernel page table walkers fall into two broad categories - those ranges where no exclusion is required via walk_kernel_page_table_range_lockless() and those where exclusion is required via walk_kernel_page_table_range() or walk_page_range_debug(). The former category is used only by arm64 arch code operating on ranges it both wholly owns and does not concurrently write. The latter category consists of kernel page table walkers operating on ranges that are wholly owned (but which need exclusion against concurrent writers). The lock used for exclusion is the mmap lock, and for kernel ranges this is the mmap lock on init_mm. ptdump is a special case being both the only user of walk_page_range_debug(), and the only case in which it walks ranges it does not own. This presents a problem, as page tables may be freed under ptdump.  And indeed there is a use-after-free bug in the kernel as a result, which this series addresses. vmap promotes page tables to huge leaf entries where possible, freeing the lower page table when it does.  It does this with no meaningful locks held against concurrent ptdump walks. As a result, use-after-free can currently occur.  This series addresses the issue by having the vmap huge promotion logic acquire the mmap read lock while both se…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-74672</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2970 — Linux Kernel: Mehrere Schwachstellen ermöglichen nicht spezifizierten Angriff</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2970</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen, möglicherweise Sicherheitsmaßnahmen zu umgehen, einen Denial-of-Service-Zustand herbeizuführen oder vertrauliche Informationen offenzulegen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen, möglicherweise Sicherheitsmaßnahmen zu umgehen, einen Denial-of-Service-Zustand herbeizuführen oder vertrauliche Informationen offenzulegen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2970</guid>
    </item>
  </channel>
</rss>
