<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 19:47:09 +0000</lastBuildDate>
    <item>
      <title>BELL-CVE-2026-80563</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-80563</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-80563</guid>
    </item>
    <item>
      <title>certfr-2026-avi-1232 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de Debian LTS. Certaines d'entre elles permettent à…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1232</link>
      <description>certfr-2026-avi-1232</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-1232</guid>
    </item>
    <item>
      <title>EUVD-2026-359162</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-359162</link>
      <description>EUVD-2026-359162</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-359162</guid>
    </item>
    <item>
      <title>fkie_cve-2026-80563</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-80563</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;gpio: sloppy-logic-analyzer: fix use-after-free via debugfs trigger on unbind&lt;/p&gt;
&lt;p&gt;The &amp;#34;trigger&amp;#34; debugfs file has a hand-rolled -&amp;gt;write handler
(trigger_write()) that dereferences the per-device gpio_la_poll_priv. The
file is created with debugfs_create_file_unsafe(), and the handler never
takes a debugfs reference. Nothing keeps the object alive while the
handler runs.&lt;/p&gt;
&lt;p&gt;priv is allocated with devm_kzalloc(). devres frees it when the platform
device is unbound. debugfs_create_file_unsafe() installs no full_proxy
wrapper, so debugfs_remove_recursive() in gpio_la_poll_remove() does not
wait for an in-flight trigger_write(). The blob_lock taken there does not
help, because trigger_write() never takes it. A write that races an unbind
therefore writes into freed memory:&lt;/p&gt;
&lt;p&gt;trigger_write()                  gpio_la_poll_remove()
    priv = m-&amp;gt;private
    buf = memdup_user()  [may sleep]
                                     mutex_lock(&amp;amp;priv-&amp;gt;blob_lock)
                                     debugfs_remove_recursive()  [no wait]
                                     mutex_unlock(&amp;amp;priv-&amp;gt;blob_lock)
                                   (remove returns; devres frees priv)
    priv-&amp;gt;trig_data = buf   &amp;lt;-- use-after-free write
    priv-&amp;gt;trig_len  = count&lt;/p&gt;
&lt;p&gt;The race is reachable by root via
/sys/bus/platform/drivers/gpio-sloppy-logic-analyzer/unbind.&lt;/p&gt;
&lt;p&gt;Create &amp;#34;trigger&amp;#34; with debugfs_create_file() instead. Its full_proxy
wrapper makes d…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;gpio: sloppy-logic-analyzer: fix use-after-free via debugfs trigger on unbind&lt;/p&gt;
&lt;p&gt;The &amp;#34;trigger&amp;#34; debugfs file has a hand-rolled -&amp;gt;write handler
(trigger_write()) that dereferences the per-device gpio_la_poll_priv. The
file is created with debugfs_create_file_unsafe(), and the handler never
takes a debugfs reference. Nothing keeps the object alive while the
handler runs.&lt;/p&gt;
&lt;p&gt;priv is allocated with devm_kzalloc(). devres frees it when the platform
device is unbound. debugfs_create_file_unsafe() installs no full_proxy
wrapper, so debugfs_remove_recursive() in gpio_la_poll_remove() does not
wait for an in-flight trigger_write(). The blob_lock taken there does not
help, because trigger_write() never takes it. A write that races an unbind
therefore writes into freed memory:&lt;/p&gt;
&lt;p&gt;trigger_write()                  gpio_la_poll_remove()
    priv = m-&amp;gt;private
    buf = memdup_user()  [may sleep]
                                     mutex_lock(&amp;amp;priv-&amp;gt;blob_lock)
                                     debugfs_remove_recursive()  [no wait]
                                     mutex_unlock(&amp;amp;priv-&amp;gt;blob_lock)
                                   (remove returns; devres frees priv)
    priv-&amp;gt;trig_data = buf   &amp;lt;-- use-after-free write
    priv-&amp;gt;trig_len  = count&lt;/p&gt;
&lt;p&gt;The race is reachable by root via
/sys/bus/platform/drivers/gpio-sloppy-logic-analyzer/unbind.&lt;/p&gt;
&lt;p&gt;Create &amp;#34;trigger&amp;#34; with debugfs_create_file() instead. Its full_proxy
wrapper makes d…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-80563</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-80563</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-80563</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 120 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: gpio: sloppy-logic-analyzer: fix use-after-free via debugfs trigger on unbind The &amp;#34;trigger&amp;#34; debugfs file has a hand-rolled -&amp;gt;write handler (trigger_write()) that dereferences the per-device gpio_la_poll_priv. The file is created with debugfs_create_file_unsafe(), and the handler never takes a debugfs reference. Nothing keeps the object alive while the handler runs. priv is allocated with devm_kzalloc(). devres frees it when the platform device is unbound. debugfs_create_file_unsafe() installs no full_proxy wrapper, so debugfs_remove_recursive() in gpio_la_poll_remove() does not wait for an in-flight trigger_write(). The blob_lock taken there does not help, because trigger_write() never takes it. A write that races an unbind therefore writes into freed memory:   trigger_write()                  gpio_la_poll_remove()     priv = m-&amp;gt;private     buf = memdup_user()  [may sleep]                                      mutex_lock(&amp;amp;priv-&amp;gt;blob_lock)                                      debugfs_remove_recursive()  [no wait]                                      mutex_unlock(&amp;amp;priv-&amp;gt;blob_lock)                                    (remove returns; devres frees priv)     priv-&amp;gt;trig_data = buf   &amp;lt;-- use-after-free write     priv-&amp;gt;trig_len  = count The race is reachable by root via /sys/bus/platform/drivers/gpio-sloppy-logic-analyzer/unbind. Create &amp;#34;trigger&amp;#34; with debugfs_create_file() instead. Its full_proxy wrapper makes debugfs…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 120 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: gpio: sloppy-logic-analyzer: fix use-after-free via debugfs trigger on unbind The &amp;#34;trigger&amp;#34; debugfs file has a hand-rolled -&amp;gt;write handler (trigger_write()) that dereferences the per-device gpio_la_poll_priv. The file is created with debugfs_create_file_unsafe(), and the handler never takes a debugfs reference. Nothing keeps the object alive while the handler runs. priv is allocated with devm_kzalloc(). devres frees it when the platform device is unbound. debugfs_create_file_unsafe() installs no full_proxy wrapper, so debugfs_remove_recursive() in gpio_la_poll_remove() does not wait for an in-flight trigger_write(). The blob_lock taken there does not help, because trigger_write() never takes it. A write that races an unbind therefore writes into freed memory:   trigger_write()                  gpio_la_poll_remove()     priv = m-&amp;gt;private     buf = memdup_user()  [may sleep]                                      mutex_lock(&amp;amp;priv-&amp;gt;blob_lock)                                      debugfs_remove_recursive()  [no wait]                                      mutex_unlock(&amp;amp;priv-&amp;gt;blob_lock)                                    (remove returns; devres frees priv)     priv-&amp;gt;trig_data = buf   &amp;lt;-- use-after-free write     priv-&amp;gt;trig_len  = count The race is reachable by root via /sys/bus/platform/drivers/gpio-sloppy-logic-analyzer/unbind. Create &amp;#34;trigger&amp;#34; with debugfs_create_file() instead. Its full_proxy wrapper makes debugfs…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-80563</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-3042 — Linux Kernel: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3042</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen, darunter möglicherweise die Ausführung von beliebigem Code, die Ausweitung von Berechtigungen, die Offenlegung von Informationen, die Manipulation von Daten oder Denial-of-Service-Zustände.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen, darunter möglicherweise die Ausführung von beliebigem Code, die Ausweitung von Berechtigungen, die Offenlegung von Informationen, die Manipulation von Daten oder Denial-of-Service-Zustände.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3042</guid>
    </item>
  </channel>
</rss>
