<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 16:24:45 +0000</lastBuildDate>
    <item>
      <title>BELL-CVE-2026-89633</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-89633</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-89633</guid>
    </item>
    <item>
      <title>EUVD-2026-367316</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-367316</link>
      <description>EUVD-2026-367316</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-367316</guid>
    </item>
    <item>
      <title>fkie_cve-2026-89633</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-89633</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;smb: client: fix OOB read/write from unvalidated DataOffset in coalesce_t2()&lt;/p&gt;
&lt;p&gt;coalesce_t2() computes data pointers directly from server-supplied
DataOffset fields with no validation against buffer bounds:&lt;/p&gt;
&lt;p&gt;data_area_of_tgt = (char *)&amp;amp;pSMBt-&amp;gt;hdr.Protocol +
                     get_unaligned_le16(&amp;amp;pSMBt-&amp;gt;t2_rsp.DataOffset);
  data_area_of_src = (char *)&amp;amp;pSMBs-&amp;gt;hdr.Protocol +
                     get_unaligned_le16(&amp;amp;pSMBs-&amp;gt;t2_rsp.DataOffset);
  data_area_of_tgt += total_in_tgt;
  ...
  memcpy(data_area_of_tgt, data_area_of_src, total_in_src);&lt;/p&gt;
&lt;p&gt;A small DataOffset can push a pointer below the actual byte area,
overwriting header fields; a large one can push it past the buffer
end, causing out-of-bounds heap reads (source) or writes (target).
The BCC overflow guard does not prevent this: BCC reflects how much
data is present, while DataOffset controls where in the buffer it
starts.&lt;/p&gt;
&lt;p&gt;The &amp;#34;validate target area&amp;#34; comment present since the function was
first written in 2005 was a placeholder that was never implemented.&lt;/p&gt;
&lt;p&gt;Add lower- and upper-bound checks for both data pointers before the
memcpy, and before any target header fields are modified.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;smb: client: fix OOB read/write from unvalidated DataOffset in coalesce_t2()&lt;/p&gt;
&lt;p&gt;coalesce_t2() computes data pointers directly from server-supplied
DataOffset fields with no validation against buffer bounds:&lt;/p&gt;
&lt;p&gt;data_area_of_tgt = (char *)&amp;amp;pSMBt-&amp;gt;hdr.Protocol +
                     get_unaligned_le16(&amp;amp;pSMBt-&amp;gt;t2_rsp.DataOffset);
  data_area_of_src = (char *)&amp;amp;pSMBs-&amp;gt;hdr.Protocol +
                     get_unaligned_le16(&amp;amp;pSMBs-&amp;gt;t2_rsp.DataOffset);
  data_area_of_tgt += total_in_tgt;
  ...
  memcpy(data_area_of_tgt, data_area_of_src, total_in_src);&lt;/p&gt;
&lt;p&gt;A small DataOffset can push a pointer below the actual byte area,
overwriting header fields; a large one can push it past the buffer
end, causing out-of-bounds heap reads (source) or writes (target).
The BCC overflow guard does not prevent this: BCC reflects how much
data is present, while DataOffset controls where in the buffer it
starts.&lt;/p&gt;
&lt;p&gt;The &amp;#34;validate target area&amp;#34; comment present since the function was
first written in 2005 was a placeholder that was never implemented.&lt;/p&gt;
&lt;p&gt;Add lower- and upper-bound checks for both data pointers before the
memcpy, and before any target header fields are modified.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-89633</guid>
    </item>
    <item>
      <title>GHSA-6jcv-m8xc-577h</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-6jcv-m8xc-577h</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;smb: client: fix OOB read/write from unvalidated DataOffset in coalesce_t2()&lt;/p&gt;
&lt;p&gt;coalesce_t2() computes data pointers directly from server-supplied
DataOffset fields with no validation against buffer bounds:&lt;/p&gt;
&lt;p&gt;data_area_of_tgt = (char *)&amp;amp;pSMBt-&amp;gt;hdr.Protocol +
                     get_unaligned_le16(&amp;amp;pSMBt-&amp;gt;t2_rsp.DataOffset);
  data_area_of_src = (char *)&amp;amp;pSMBs-&amp;gt;hdr.Protocol +
                     get_unaligned_le16(&amp;amp;pSMBs-&amp;gt;t2_rsp.DataOffset);
  data_area_of_tgt += total_in_tgt;
  ...
  memcpy(data_area_of_tgt, data_area_of_src, total_in_src);&lt;/p&gt;
&lt;p&gt;A small DataOffset can push a pointer below the actual byte area,
overwriting header fields; a large one can push it past the buffer
end, causing out-of-bounds heap reads (source) or writes (target).
The BCC overflow guard does not prevent this: BCC reflects how much
data is present, while DataOffset controls where in the buffer it
starts.&lt;/p&gt;
&lt;p&gt;The &amp;#34;validate target area&amp;#34; comment present since the function was
first written in 2005 was a placeholder that was never implemented.&lt;/p&gt;
&lt;p&gt;Add lower- and upper-bound checks for both data pointers before the
memcpy, and before any target header fields are modified.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;smb: client: fix OOB read/write from unvalidated DataOffset in coalesce_t2()&lt;/p&gt;
&lt;p&gt;coalesce_t2() computes data pointers directly from server-supplied
DataOffset fields with no validation against buffer bounds:&lt;/p&gt;
&lt;p&gt;data_area_of_tgt = (char *)&amp;amp;pSMBt-&amp;gt;hdr.Protocol +
                     get_unaligned_le16(&amp;amp;pSMBt-&amp;gt;t2_rsp.DataOffset);
  data_area_of_src = (char *)&amp;amp;pSMBs-&amp;gt;hdr.Protocol +
                     get_unaligned_le16(&amp;amp;pSMBs-&amp;gt;t2_rsp.DataOffset);
  data_area_of_tgt += total_in_tgt;
  ...
  memcpy(data_area_of_tgt, data_area_of_src, total_in_src);&lt;/p&gt;
&lt;p&gt;A small DataOffset can push a pointer below the actual byte area,
overwriting header fields; a large one can push it past the buffer
end, causing out-of-bounds heap reads (source) or writes (target).
The BCC overflow guard does not prevent this: BCC reflects how much
data is present, while DataOffset controls where in the buffer it
starts.&lt;/p&gt;
&lt;p&gt;The &amp;#34;validate target area&amp;#34; comment present since the function was
first written in 2005 was a placeholder that was never implemented.&lt;/p&gt;
&lt;p&gt;Add lower- and upper-bound checks for both data pointers before the
memcpy, and before any target header fields are modified.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-6jcv-m8xc-577h</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-89633 — smb: client: fix OOB read/write from unvalidated DataOffset in coalesce_t2()</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-89633</link>
      <description>msrc_CVE-2026-89633</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-89633</guid>
    </item>
    <item>
      <title>OESA-2026-4039 — kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-4039</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP4: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:ALSA: caiaq: Use snd_card_free_when_closed() at disconnectionThe USB disconnect callback is supposed to be short and not too-longwaiting.  OTOH, the current code uses snd_card_free() atdisconnection, but this waits for the close of all used fds, hence itcan take long.  It eventually blocks the upper layer USB ioctls, whichmay trigger a soft lockup.An easy workaround is to replace snd_card_free() withsnd_card_free_when_closed().  This variant returns immediately whilethe release of resources is done asynchronously by the card devicerelease at the last close.This patch also splits the code to the disconnect and the free phases;the former is called immediately at the USB disconnect callback whilethe latter is called from the card destructor.(CVE-2024-56531)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:xsk: fix OOB map writes when deleting elementsJordy says: In the xsk_map_delete_elem function an unsigned integer(map-&amp;amp;gt;max_entries) is compared with a user-controlled signed integer(k). Due to implicit type conversion, a large unsigned value formap-&amp;amp;gt;max_entries can bypass the intended bounds check: if (k &amp;amp;gt;= map-&amp;amp;gt;max_entries)  return -EINVAL;This allows k to hold a negative value (between -2147483648 and -2),which is then used as an array index in m-&amp;amp;gt;xsk_map[k], which resultsin an out-of-bounds access. spi…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP4: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:ALSA: caiaq: Use snd_card_free_when_closed() at disconnectionThe USB disconnect callback is supposed to be short and not too-longwaiting.  OTOH, the current code uses snd_card_free() atdisconnection, but this waits for the close of all used fds, hence itcan take long.  It eventually blocks the upper layer USB ioctls, whichmay trigger a soft lockup.An easy workaround is to replace snd_card_free() withsnd_card_free_when_closed().  This variant returns immediately whilethe release of resources is done asynchronously by the card devicerelease at the last close.This patch also splits the code to the disconnect and the free phases;the former is called immediately at the USB disconnect callback whilethe latter is called from the card destructor.(CVE-2024-56531)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:xsk: fix OOB map writes when deleting elementsJordy says: In the xsk_map_delete_elem function an unsigned integer(map-&amp;amp;gt;max_entries) is compared with a user-controlled signed integer(k). Due to implicit type conversion, a large unsigned value formap-&amp;amp;gt;max_entries can bypass the intended bounds check: if (k &amp;amp;gt;= map-&amp;amp;gt;max_entries)  return -EINVAL;This allows k to hold a negative value (between -2147483648 and -2),which is then used as an array index in m-&amp;amp;gt;xsk_map[k], which resultsin an out-of-bounds access. spi…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-4039</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:11880-1 — kernel-devel-7.2.7-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11880-1</link>
      <description>&lt;p&gt;kernel-devel-7.2.7-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;kernel-devel-7.2.7-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:11880-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-89633</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-89633</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux, Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe and 246 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: smb: client: fix OOB read/write from unvalidated DataOffset in coalesce_t2() coalesce_t2() computes data pointers directly from server-supplied DataOffset fields with no validation against buffer bounds:   data_area_of_tgt = (char *)&amp;amp;pSMBt-&amp;gt;hdr.Protocol +                      get_unaligned_le16(&amp;amp;pSMBt-&amp;gt;t2_rsp.DataOffset);   data_area_of_src = (char *)&amp;amp;pSMBs-&amp;gt;hdr.Protocol +                      get_unaligned_le16(&amp;amp;pSMBs-&amp;gt;t2_rsp.DataOffset);   data_area_of_tgt += total_in_tgt;   ...   memcpy(data_area_of_tgt, data_area_of_src, total_in_src); A small DataOffset can push a pointer below the actual byte area, overwriting header fields; a large one can push it past the buffer end, causing out-of-bounds heap reads (source) or writes (target). The BCC overflow guard does not prevent this: BCC reflects how much data is present, while DataOffset controls where in the buffer it starts. The &amp;#34;validate target area&amp;#34; comment present since the function was first written in 2005 was a placeholder that was never implemented. Add lower- and upper-bound checks for both data pointers before the memcpy, and before any target header fields are modified.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux, Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe and 246 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: smb: client: fix OOB read/write from unvalidated DataOffset in coalesce_t2() coalesce_t2() computes data pointers directly from server-supplied DataOffset fields with no validation against buffer bounds:   data_area_of_tgt = (char *)&amp;amp;pSMBt-&amp;gt;hdr.Protocol +                      get_unaligned_le16(&amp;amp;pSMBt-&amp;gt;t2_rsp.DataOffset);   data_area_of_src = (char *)&amp;amp;pSMBs-&amp;gt;hdr.Protocol +                      get_unaligned_le16(&amp;amp;pSMBs-&amp;gt;t2_rsp.DataOffset);   data_area_of_tgt += total_in_tgt;   ...   memcpy(data_area_of_tgt, data_area_of_src, total_in_src); A small DataOffset can push a pointer below the actual byte area, overwriting header fields; a large one can push it past the buffer end, causing out-of-bounds heap reads (source) or writes (target). The BCC overflow guard does not prevent this: BCC reflects how much data is present, while DataOffset controls where in the buffer it starts. The &amp;#34;validate target area&amp;#34; comment present since the function was first written in 2005 was a placeholder that was never implemented. Add lower- and upper-bound checks for both data pointers before the memcpy, and before any target header fields are modified.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-89633</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-3321 — Linux Kernel: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3321</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um Sicherheitsmaßnahmen zu umgehen, Daten oder den Systemzustand zu manipulieren, Denial-of-Service-Zustände herbeizuführen oder andere, nicht näher spezifizierte Angriffe durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um Sicherheitsmaßnahmen zu umgehen, Daten oder den Systemzustand zu manipulieren, Denial-of-Service-Zustände herbeizuführen oder andere, nicht näher spezifizierte Angriffe durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3321</guid>
    </item>
  </channel>
</rss>
