<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 19:32:52 +0000</lastBuildDate>
    <item>
      <title>BELL-CVE-2026-80789</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-80789</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-80789</guid>
    </item>
    <item>
      <title>certfr-2026-avi-1163 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de Debian LTS. Certaines d'entre elles permettent à…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1163</link>
      <description>certfr-2026-avi-1163</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-1163</guid>
    </item>
    <item>
      <title>EUVD-2026-363807</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-363807</link>
      <description>EUVD-2026-363807</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-363807</guid>
    </item>
    <item>
      <title>fkie_cve-2026-80789</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-80789</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;nvmet-tcp: bound SGL data length before allocating command buffers&lt;/p&gt;
&lt;p&gt;nvmet_tcp_map_data() reads the host-controlled 32-bit sgl-&amp;gt;length
and, for the in-capsule offset descriptor (type 0x01), checks it
against port-&amp;gt;inline_data_size before use. Any other SGL descriptor
type -- including the non-inline transport SGL data-block descriptor
(type (NVME_TRANSPORT_SGL_DATA_DESC &amp;lt;&amp;lt; 4) | NVME_SGL_FMT_TRANSPORT_A,
the type a real host uses for out-of-capsule writes) skips that check
entirely and falls straight through to:&lt;/p&gt;
&lt;p&gt;cmd-&amp;gt;req.sg = sgl_alloc(len, GFP_KERNEL, &amp;amp;cmd-&amp;gt;req.sg_cnt);&lt;/p&gt;
&lt;p&gt;with len taken directly from the wire, unbounded up to 4 GiB.&lt;/p&gt;
&lt;p&gt;nvmet_req_init() only parses the command and never inspects
sgl-&amp;gt;length, and nvmet_check_transfer_len() -- the only other place
transfer_len is validated -- runs later, from req-&amp;gt;execute(), after
the allocation has already happened. For a write command the target
responds with an R2T and parks the command waiting for the host to
send the data; if the host (or an unauthenticated peer that simply
never follows up) never does, the sgl_alloc() buffer stays resident
for the life of the command. NVMe/TCP has no mandatory authentication
in the default configuration, so any peer able to reach the target
portal and complete a Fabrics connect can drive this with a single
crafted command, repeatable across queues and connections for
amplification. This is unbounded kernel memory allocatio…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;nvmet-tcp: bound SGL data length before allocating command buffers&lt;/p&gt;
&lt;p&gt;nvmet_tcp_map_data() reads the host-controlled 32-bit sgl-&amp;gt;length
and, for the in-capsule offset descriptor (type 0x01), checks it
against port-&amp;gt;inline_data_size before use. Any other SGL descriptor
type -- including the non-inline transport SGL data-block descriptor
(type (NVME_TRANSPORT_SGL_DATA_DESC &amp;lt;&amp;lt; 4) | NVME_SGL_FMT_TRANSPORT_A,
the type a real host uses for out-of-capsule writes) skips that check
entirely and falls straight through to:&lt;/p&gt;
&lt;p&gt;cmd-&amp;gt;req.sg = sgl_alloc(len, GFP_KERNEL, &amp;amp;cmd-&amp;gt;req.sg_cnt);&lt;/p&gt;
&lt;p&gt;with len taken directly from the wire, unbounded up to 4 GiB.&lt;/p&gt;
&lt;p&gt;nvmet_req_init() only parses the command and never inspects
sgl-&amp;gt;length, and nvmet_check_transfer_len() -- the only other place
transfer_len is validated -- runs later, from req-&amp;gt;execute(), after
the allocation has already happened. For a write command the target
responds with an R2T and parks the command waiting for the host to
send the data; if the host (or an unauthenticated peer that simply
never follows up) never does, the sgl_alloc() buffer stays resident
for the life of the command. NVMe/TCP has no mandatory authentication
in the default configuration, so any peer able to reach the target
portal and complete a Fabrics connect can drive this with a single
crafted command, repeatable across queues and connections for
amplification. This is unbounded kernel memory allocatio…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-80789</guid>
    </item>
    <item>
      <title>GHSA-jx2c-6h88-85vx</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-jx2c-6h88-85vx</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;nvmet-tcp: bound SGL data length before allocating command buffers&lt;/p&gt;
&lt;p&gt;nvmet_tcp_map_data() reads the host-controlled 32-bit sgl-&amp;gt;length
and, for the in-capsule offset descriptor (type 0x01), checks it
against port-&amp;gt;inline_data_size before use. Any other SGL descriptor
type -- including the non-inline transport SGL data-block descriptor
(type (NVME_TRANSPORT_SGL_DATA_DESC &amp;lt;&amp;lt; 4) | NVME_SGL_FMT_TRANSPORT_A,
the type a real host uses for out-of-capsule writes) skips that check
entirely and falls straight through to:&lt;/p&gt;
&lt;p&gt;cmd-&amp;gt;req.sg = sgl_alloc(len, GFP_KERNEL, &amp;amp;cmd-&amp;gt;req.sg_cnt);&lt;/p&gt;
&lt;p&gt;with len taken directly from the wire, unbounded up to 4 GiB.&lt;/p&gt;
&lt;p&gt;nvmet_req_init() only parses the command and never inspects
sgl-&amp;gt;length, and nvmet_check_transfer_len() -- the only other place
transfer_len is validated -- runs later, from req-&amp;gt;execute(), after
the allocation has already happened. For a write command the target
responds with an R2T and parks the command waiting for the host to
send the data; if the host (or an unauthenticated peer that simply
never follows up) never does, the sgl_alloc() buffer stays resident
for the life of the command. NVMe/TCP has no mandatory authentication
in the default configuration, so any peer able to reach the target
portal and complete a Fabrics connect can drive this with a single
crafted command, repeatable across queues and connections for
amplification. This is unbounded kernel memory allocatio…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;nvmet-tcp: bound SGL data length before allocating command buffers&lt;/p&gt;
&lt;p&gt;nvmet_tcp_map_data() reads the host-controlled 32-bit sgl-&amp;gt;length
and, for the in-capsule offset descriptor (type 0x01), checks it
against port-&amp;gt;inline_data_size before use. Any other SGL descriptor
type -- including the non-inline transport SGL data-block descriptor
(type (NVME_TRANSPORT_SGL_DATA_DESC &amp;lt;&amp;lt; 4) | NVME_SGL_FMT_TRANSPORT_A,
the type a real host uses for out-of-capsule writes) skips that check
entirely and falls straight through to:&lt;/p&gt;
&lt;p&gt;cmd-&amp;gt;req.sg = sgl_alloc(len, GFP_KERNEL, &amp;amp;cmd-&amp;gt;req.sg_cnt);&lt;/p&gt;
&lt;p&gt;with len taken directly from the wire, unbounded up to 4 GiB.&lt;/p&gt;
&lt;p&gt;nvmet_req_init() only parses the command and never inspects
sgl-&amp;gt;length, and nvmet_check_transfer_len() -- the only other place
transfer_len is validated -- runs later, from req-&amp;gt;execute(), after
the allocation has already happened. For a write command the target
responds with an R2T and parks the command waiting for the host to
send the data; if the host (or an unauthenticated peer that simply
never follows up) never does, the sgl_alloc() buffer stays resident
for the life of the command. NVMe/TCP has no mandatory authentication
in the default configuration, so any peer able to reach the target
portal and complete a Fabrics connect can drive this with a single
crafted command, repeatable across queues and connections for
amplification. This is unbounded kernel memory allocatio…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-jx2c-6h88-85vx</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-80789 — nvmet-tcp: bound SGL data length before allocating command buffers</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-80789</link>
      <description>msrc_CVE-2026-80789</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-80789</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:11773-1 — kernel-devel-7.2.5-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11773-1</link>
      <description>&lt;p&gt;kernel-devel-7.2.5-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;kernel-devel-7.2.5-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:11773-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-80789</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-80789</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:Pro:18.04:LTS: linux-aws-5.4, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:Pro:18.04:LTS: linux-azure-5.4, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3 and 219 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: bound SGL data length before allocating command buffers nvmet_tcp_map_data() reads the host-controlled 32-bit sgl-&amp;gt;length and, for the in-capsule offset descriptor (type 0x01), checks it against port-&amp;gt;inline_data_size before use. Any other SGL descriptor type -- including the non-inline transport SGL data-block descriptor (type (NVME_TRANSPORT_SGL_DATA_DESC &amp;lt;&amp;lt; 4) | NVME_SGL_FMT_TRANSPORT_A, the type a real host uses for out-of-capsule writes) skips that check entirely and falls straight through to: 	cmd-&amp;gt;req.sg = sgl_alloc(len, GFP_KERNEL, &amp;amp;cmd-&amp;gt;req.sg_cnt); with len taken directly from the wire, unbounded up to 4 GiB. nvmet_req_init() only parses the command and never inspects sgl-&amp;gt;length, and nvmet_check_transfer_len() -- the only other place transfer_len is validated -- runs later, from req-&amp;gt;execute(), after the allocation has already happened. For a write command the target responds with an R2T and parks the command waiting for the host to send the data; if the host (or an unauthenticated peer that simply never follows up) never does, the sgl_alloc() buffer stays resident for the life of the command. NVMe/TCP has no mandatory authentication in the default configuration, so any peer able to reach the target portal and complete a Fabrics connect can drive this with a single crafted command, repeatable across queues and connections for amplification. This is unbounded kernel memory allocation tri…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:Pro:18.04:LTS: linux-aws-5.4, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:Pro:18.04:LTS: linux-azure-5.4, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3 and 219 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: bound SGL data length before allocating command buffers nvmet_tcp_map_data() reads the host-controlled 32-bit sgl-&amp;gt;length and, for the in-capsule offset descriptor (type 0x01), checks it against port-&amp;gt;inline_data_size before use. Any other SGL descriptor type -- including the non-inline transport SGL data-block descriptor (type (NVME_TRANSPORT_SGL_DATA_DESC &amp;lt;&amp;lt; 4) | NVME_SGL_FMT_TRANSPORT_A, the type a real host uses for out-of-capsule writes) skips that check entirely and falls straight through to: 	cmd-&amp;gt;req.sg = sgl_alloc(len, GFP_KERNEL, &amp;amp;cmd-&amp;gt;req.sg_cnt); with len taken directly from the wire, unbounded up to 4 GiB. nvmet_req_init() only parses the command and never inspects sgl-&amp;gt;length, and nvmet_check_transfer_len() -- the only other place transfer_len is validated -- runs later, from req-&amp;gt;execute(), after the allocation has already happened. For a write command the target responds with an R2T and parks the command waiting for the host to send the data; if the host (or an unauthenticated peer that simply never follows up) never does, the sgl_alloc() buffer stays resident for the life of the command. NVMe/TCP has no mandatory authentication in the default configuration, so any peer able to reach the target portal and complete a Fabrics connect can drive this with a single crafted command, repeatable across queues and connections for amplification. This is unbounded kernel memory allocation tri…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-80789</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-3211 — Linux Kernel: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3211</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Linux Kernel ausnutzen, um Speicherfehler und Kernel-Abstürze beziehungsweise Denial-of-Service-Zustände auszulösen, Speicher außerhalb vorgesehener Grenzen auszulesen sowie in einzelnen Fällen weitere Sicherheitsauswirkungen zu verursachen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Linux Kernel ausnutzen, um Speicherfehler und Kernel-Abstürze beziehungsweise Denial-of-Service-Zustände auszulösen, Speicher außerhalb vorgesehener Grenzen auszulesen sowie in einzelnen Fällen weitere Sicherheitsauswirkungen zu verursachen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3211</guid>
    </item>
  </channel>
</rss>
