<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 18:56:46 +0000</lastBuildDate>
    <item>
      <title>BELL-CVE-2026-80528</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-80528</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-80528</guid>
    </item>
    <item>
      <title>certfr-2026-avi-1163 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de Debian LTS. Certaines d'entre elles permettent à…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1163</link>
      <description>certfr-2026-avi-1163</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-1163</guid>
    </item>
    <item>
      <title>EUVD-2026-359784</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-359784</link>
      <description>EUVD-2026-359784</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-359784</guid>
    </item>
    <item>
      <title>fkie_cve-2026-80528</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-80528</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;ceph: avoid fs reclaim while using current-&amp;gt;journal_info&lt;/p&gt;
&lt;p&gt;handle_reply() stores a `ceph_mds_request` pointer in
`current-&amp;gt;journal_info` while filling the inode and dentry cache from
an MDS reply.&lt;/p&gt;
&lt;p&gt;An allocation in this section can enter direct reclaim and prune
dentries from another filesystem.  If this dirties an ext4 inode, ext4
starts a JBD2 transaction.  JBD2 interprets the Ceph request in
`current-&amp;gt;journal_info` as a journal handle and dereferences the
request&amp;#39;s `r_tid` as `h_transaction`, causing a kernel crash, e.g.:&lt;/p&gt;
&lt;p&gt;Unable to handle kernel paging request at virtual address 00000000077b4818
 [...]
 Internal error: Oops: 0000000096000004 [#1]  SMP
 Modules linked in:
 CPU: 6 UID: 0 PID: 2699135 Comm: kworker/6:3 Tainted: G        W           6.18.38-i3 #1113 NONE
 [...]
 Workqueue: ceph-msgr ceph_con_workfn
 pstate: 80400009 (Nzcv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)
 pc : jbd2__journal_start+0x2c/0x208
 lr : __ext4_journal_start_sb+0x100/0x178
 [...]
 Call trace:
  jbd2__journal_start+0x2c/0x208 (P)
  __ext4_journal_start_sb+0x100/0x178
  ext4_dirty_inode+0x3c/0x90
  __mark_inode_dirty+0x58/0x400
  iput.part.0+0x2b0/0x370
  iput+0x18/0x30
  dentry_unlink_inode+0xc0/0x158
  __dentry_kill+0x80/0x250
  shrink_dentry_list+0x90/0x130
  prune_dcache_sb+0x60/0x98
  super_cache_scan+0xe8/0x190
  do_shrink_slab+0x174/0x388
  shrink_slab+0xd8/0x4c0
  shrink_node+0x31c/0x908
  do_try_to_free_pages+0xd0/0x…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;ceph: avoid fs reclaim while using current-&amp;gt;journal_info&lt;/p&gt;
&lt;p&gt;handle_reply() stores a `ceph_mds_request` pointer in
`current-&amp;gt;journal_info` while filling the inode and dentry cache from
an MDS reply.&lt;/p&gt;
&lt;p&gt;An allocation in this section can enter direct reclaim and prune
dentries from another filesystem.  If this dirties an ext4 inode, ext4
starts a JBD2 transaction.  JBD2 interprets the Ceph request in
`current-&amp;gt;journal_info` as a journal handle and dereferences the
request&amp;#39;s `r_tid` as `h_transaction`, causing a kernel crash, e.g.:&lt;/p&gt;
&lt;p&gt;Unable to handle kernel paging request at virtual address 00000000077b4818
 [...]
 Internal error: Oops: 0000000096000004 [#1]  SMP
 Modules linked in:
 CPU: 6 UID: 0 PID: 2699135 Comm: kworker/6:3 Tainted: G        W           6.18.38-i3 #1113 NONE
 [...]
 Workqueue: ceph-msgr ceph_con_workfn
 pstate: 80400009 (Nzcv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)
 pc : jbd2__journal_start+0x2c/0x208
 lr : __ext4_journal_start_sb+0x100/0x178
 [...]
 Call trace:
  jbd2__journal_start+0x2c/0x208 (P)
  __ext4_journal_start_sb+0x100/0x178
  ext4_dirty_inode+0x3c/0x90
  __mark_inode_dirty+0x58/0x400
  iput.part.0+0x2b0/0x370
  iput+0x18/0x30
  dentry_unlink_inode+0xc0/0x158
  __dentry_kill+0x80/0x250
  shrink_dentry_list+0x90/0x130
  prune_dcache_sb+0x60/0x98
  super_cache_scan+0xe8/0x190
  do_shrink_slab+0x174/0x388
  shrink_slab+0xd8/0x4c0
  shrink_node+0x31c/0x908
  do_try_to_free_pages+0xd0/0x…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-80528</guid>
    </item>
    <item>
      <title>GHSA-g3v4-jm6x-37fc</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-g3v4-jm6x-37fc</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;ceph: avoid fs reclaim while using current-&amp;gt;journal_info&lt;/p&gt;
&lt;p&gt;handle_reply() stores a `ceph_mds_request` pointer in
`current-&amp;gt;journal_info` while filling the inode and dentry cache from
an MDS reply.&lt;/p&gt;
&lt;p&gt;An allocation in this section can enter direct reclaim and prune
dentries from another filesystem.  If this dirties an ext4 inode, ext4
starts a JBD2 transaction.  JBD2 interprets the Ceph request in
`current-&amp;gt;journal_info` as a journal handle and dereferences the
request&amp;#39;s `r_tid` as `h_transaction`, causing a kernel crash, e.g.:&lt;/p&gt;
&lt;p&gt;Unable to handle kernel paging request at virtual address 00000000077b4818
 [...]
 Internal error: Oops: 0000000096000004 [#1]  SMP
 Modules linked in:
 CPU: 6 UID: 0 PID: 2699135 Comm: kworker/6:3 Tainted: G        W           6.18.38-i3 #1113 NONE
 [...]
 Workqueue: ceph-msgr ceph_con_workfn
 pstate: 80400009 (Nzcv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)
 pc : jbd2__journal_start+0x2c/0x208
 lr : __ext4_journal_start_sb+0x100/0x178
 [...]
 Call trace:
  jbd2__journal_start+0x2c/0x208 (P)
  __ext4_journal_start_sb+0x100/0x178
  ext4_dirty_inode+0x3c/0x90
  __mark_inode_dirty+0x58/0x400
  iput.part.0+0x2b0/0x370
  iput+0x18/0x30
  dentry_unlink_inode+0xc0/0x158
  __dentry_kill+0x80/0x250
  shrink_dentry_list+0x90/0x130
  prune_dcache_sb+0x60/0x98
  super_cache_scan+0xe8/0x190
  do_shrink_slab+0x174/0x388
  shrink_slab+0xd8/0x4c0
  shrink_node+0x31c/0x908
  do_try_to_free_pages+0xd0/0x…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;ceph: avoid fs reclaim while using current-&amp;gt;journal_info&lt;/p&gt;
&lt;p&gt;handle_reply() stores a `ceph_mds_request` pointer in
`current-&amp;gt;journal_info` while filling the inode and dentry cache from
an MDS reply.&lt;/p&gt;
&lt;p&gt;An allocation in this section can enter direct reclaim and prune
dentries from another filesystem.  If this dirties an ext4 inode, ext4
starts a JBD2 transaction.  JBD2 interprets the Ceph request in
`current-&amp;gt;journal_info` as a journal handle and dereferences the
request&amp;#39;s `r_tid` as `h_transaction`, causing a kernel crash, e.g.:&lt;/p&gt;
&lt;p&gt;Unable to handle kernel paging request at virtual address 00000000077b4818
 [...]
 Internal error: Oops: 0000000096000004 [#1]  SMP
 Modules linked in:
 CPU: 6 UID: 0 PID: 2699135 Comm: kworker/6:3 Tainted: G        W           6.18.38-i3 #1113 NONE
 [...]
 Workqueue: ceph-msgr ceph_con_workfn
 pstate: 80400009 (Nzcv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)
 pc : jbd2__journal_start+0x2c/0x208
 lr : __ext4_journal_start_sb+0x100/0x178
 [...]
 Call trace:
  jbd2__journal_start+0x2c/0x208 (P)
  __ext4_journal_start_sb+0x100/0x178
  ext4_dirty_inode+0x3c/0x90
  __mark_inode_dirty+0x58/0x400
  iput.part.0+0x2b0/0x370
  iput+0x18/0x30
  dentry_unlink_inode+0xc0/0x158
  __dentry_kill+0x80/0x250
  shrink_dentry_list+0x90/0x130
  prune_dcache_sb+0x60/0x98
  super_cache_scan+0xe8/0x190
  do_shrink_slab+0x174/0x388
  shrink_slab+0xd8/0x4c0
  shrink_node+0x31c/0x908
  do_try_to_free_pages+0xd0/0x…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-g3v4-jm6x-37fc</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-80528 — ceph: avoid fs reclaim while using current-&gt;journal_info</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-80528</link>
      <description>msrc_CVE-2026-80528</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-80528</guid>
    </item>
    <item>
      <title>OESA-2026-3707 — kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-3707</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP1: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;seg6: separate dst_cache for input and output paths in seg6 lwtunnel&lt;/p&gt;
&lt;p&gt;The seg6 lwtunnel uses a single dst_cache per encap route, shared
between seg6_input_core() and seg6_output_core(). These two paths
can perform the post-encap SID lookup in different routing contexts
(e.g., ip rules matching on the ingress interface, or VRF table
separation). Whichever path runs first populates the cache, and the
other reuses it blindly, bypassing its own lookup.&lt;/p&gt;
&lt;p&gt;Fix this by splitting the cache into cache_input and cache_output,
so each path maintains its own cached dst independently.(CVE-2026-31668)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;RDMA/rxe: Fix iova-to-va conversion for MR page sizes != PAGE_SIZE&lt;/p&gt;
&lt;p&gt;The current implementation incorrectly handles memory regions (MRs) with
page sizes different from the system PAGE_SIZE. The core issue is that
rxe_set_page() is called with mr-&amp;amp;gt;page_size step increments, but the
page_list stores individual struct page pointers, each representing
PAGE_SIZE of memory.&lt;/p&gt;
&lt;p&gt;ib_sg_to_page() has ensured that when i&amp;amp;gt;=1 either
a) SG[i-1].dma_end and SG[i].dma_addr are contiguous
or
b) SG[i-1].dma_end and SG[i].dma_addr are mr-&amp;amp;gt;page_size aligned.&lt;/p&gt;
&lt;p&gt;This leads to incorrect iova-to-va conversion in scenarios:&lt;/p&gt;
&lt;p&gt;1) page_size &amp;amp;lt; PAGE_SIZE (e.g., MR: 4K, system: 64K):
   ibmr-&amp;amp;gt;iova = 0x1…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP1: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;seg6: separate dst_cache for input and output paths in seg6 lwtunnel&lt;/p&gt;
&lt;p&gt;The seg6 lwtunnel uses a single dst_cache per encap route, shared
between seg6_input_core() and seg6_output_core(). These two paths
can perform the post-encap SID lookup in different routing contexts
(e.g., ip rules matching on the ingress interface, or VRF table
separation). Whichever path runs first populates the cache, and the
other reuses it blindly, bypassing its own lookup.&lt;/p&gt;
&lt;p&gt;Fix this by splitting the cache into cache_input and cache_output,
so each path maintains its own cached dst independently.(CVE-2026-31668)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;RDMA/rxe: Fix iova-to-va conversion for MR page sizes != PAGE_SIZE&lt;/p&gt;
&lt;p&gt;The current implementation incorrectly handles memory regions (MRs) with
page sizes different from the system PAGE_SIZE. The core issue is that
rxe_set_page() is called with mr-&amp;amp;gt;page_size step increments, but the
page_list stores individual struct page pointers, each representing
PAGE_SIZE of memory.&lt;/p&gt;
&lt;p&gt;ib_sg_to_page() has ensured that when i&amp;amp;gt;=1 either
a) SG[i-1].dma_end and SG[i].dma_addr are contiguous
or
b) SG[i-1].dma_end and SG[i].dma_addr are mr-&amp;amp;gt;page_size aligned.&lt;/p&gt;
&lt;p&gt;This leads to incorrect iova-to-va conversion in scenarios:&lt;/p&gt;
&lt;p&gt;1) page_size &amp;amp;lt; PAGE_SIZE (e.g., MR: 4K, system: 64K):
   ibmr-&amp;amp;gt;iova = 0x1…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-3707</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-80528</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-80528</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe, Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:Pro:16.04:LTS: linux-oracle, Ubuntu:Pro:18.04:LTS: linux, Ubuntu:Pro:18.04:LTS: linux-aws, Ubuntu:18.04:LTS: linux-aws-5.0 and 239 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: ceph: avoid fs reclaim while using current-&amp;gt;journal_info handle_reply() stores a `ceph_mds_request` pointer in `current-&amp;gt;journal_info` while filling the inode and dentry cache from an MDS reply. An allocation in this section can enter direct reclaim and prune dentries from another filesystem.  If this dirties an ext4 inode, ext4 starts a JBD2 transaction.  JBD2 interprets the Ceph request in `current-&amp;gt;journal_info` as a journal handle and dereferences the request&amp;#39;s `r_tid` as `h_transaction`, causing a kernel crash, e.g.:  Unable to handle kernel paging request at virtual address 00000000077b4818  [...]  Internal error: Oops: 0000000096000004 [#1]  SMP  Modules linked in:  CPU: 6 UID: 0 PID: 2699135 Comm: kworker/6:3 Tainted: G        W 6.18.38-i3 #1113 NONE  [...]  Workqueue: ceph-msgr ceph_con_workfn  pstate: 80400009 (Nzcv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)  pc : jbd2__journal_start+0x2c/0x208  lr : __ext4_journal_start_sb+0x100/0x178  [...]  Call trace:   jbd2__journal_start+0x2c/0x208 (P)   __ext4_journal_start_sb+0x100/0x178   ext4_dirty_inode+0x3c/0x90   __mark_inode_dirty+0x58/0x400   iput.part.0+0x2b0/0x370   iput+0x18/0x30   dentry_unlink_inode+0xc0/0x158   __dentry_kill+0x80/0x250   shrink_dentry_list+0x90/0x130   prune_dcache_sb+0x60/0x98   super_cache_scan+0xe8/0x190   do_shrink_slab+0x174/0x388   shrink_slab+0xd8/0x4c0   shrink_node+0x31c/0x908   do_try_to_free_pages+0xd0/0x508   try_to_f…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe, Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:Pro:16.04:LTS: linux-oracle, Ubuntu:Pro:18.04:LTS: linux, Ubuntu:Pro:18.04:LTS: linux-aws, Ubuntu:18.04:LTS: linux-aws-5.0 and 239 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: ceph: avoid fs reclaim while using current-&amp;gt;journal_info handle_reply() stores a `ceph_mds_request` pointer in `current-&amp;gt;journal_info` while filling the inode and dentry cache from an MDS reply. An allocation in this section can enter direct reclaim and prune dentries from another filesystem.  If this dirties an ext4 inode, ext4 starts a JBD2 transaction.  JBD2 interprets the Ceph request in `current-&amp;gt;journal_info` as a journal handle and dereferences the request&amp;#39;s `r_tid` as `h_transaction`, causing a kernel crash, e.g.:  Unable to handle kernel paging request at virtual address 00000000077b4818  [...]  Internal error: Oops: 0000000096000004 [#1]  SMP  Modules linked in:  CPU: 6 UID: 0 PID: 2699135 Comm: kworker/6:3 Tainted: G        W 6.18.38-i3 #1113 NONE  [...]  Workqueue: ceph-msgr ceph_con_workfn  pstate: 80400009 (Nzcv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)  pc : jbd2__journal_start+0x2c/0x208  lr : __ext4_journal_start_sb+0x100/0x178  [...]  Call trace:   jbd2__journal_start+0x2c/0x208 (P)   __ext4_journal_start_sb+0x100/0x178   ext4_dirty_inode+0x3c/0x90   __mark_inode_dirty+0x58/0x400   iput.part.0+0x2b0/0x370   iput+0x18/0x30   dentry_unlink_inode+0xc0/0x158   __dentry_kill+0x80/0x250   shrink_dentry_list+0x90/0x130   prune_dcache_sb+0x60/0x98   super_cache_scan+0xe8/0x190   do_shrink_slab+0x174/0x388   shrink_slab+0xd8/0x4c0   shrink_node+0x31c/0x908   do_try_to_free_pages+0xd0/0x508   try_to_f…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-80528</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-3042 — Linux Kernel: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3042</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen, darunter möglicherweise die Ausführung von beliebigem Code, die Ausweitung von Berechtigungen, die Offenlegung von Informationen, die Manipulation von Daten oder Denial-of-Service-Zustände.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen, darunter möglicherweise die Ausführung von beliebigem Code, die Ausweitung von Berechtigungen, die Offenlegung von Informationen, die Manipulation von Daten oder Denial-of-Service-Zustände.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3042</guid>
    </item>
  </channel>
</rss>
