<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 19:28:47 +0000</lastBuildDate>
    <item>
      <title>ALSA-2026:71016 — Important: kernel-rt security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:71016</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: kernel-rt, AlmaLinux:8: kernel-rt-core, AlmaLinux:8: kernel-rt-debug, AlmaLinux:8: kernel-rt-debug-core, AlmaLinux:8: kernel-rt-debug-devel, AlmaLinux:8: kernel-rt-debug-modules, AlmaLinux:8: kernel-rt-debug-modules-extra, AlmaLinux:8: kernel-rt-devel, AlmaLinux:8: kernel-rt-modules, AlmaLinux:8: kernel-rt-modules-extra&lt;/p&gt;
&lt;p&gt;The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: drm/amdgpu: Fix use-after-free race in VM acquire (CVE-2026-43370)
  * kernel: mac802154: llsec: add skb_cow_data() before in-place crypto (CVE-2026-63831)
  * kernel: sctp: don&amp;#39;t free the ASCONF&amp;#39;s own transport in DEL-IP processing (CVE-2026-64564)
  * kernel: ASoC: SOF: ipc3-control: Validate size in snd_sof_update_control (CVE-2026-72261)
  * kernel: xfrm: ah6: validate routing header segments_left (CVE-2026-80844)
  * kernel: net: tun: bound receive headroom (CVE-2026-81000)
  * kernel: scsi: qla2xxx: Bound rsp_info_len to avoid OOB sense-data read (CVE-2026-89846)&lt;/p&gt;
&lt;p&gt;Bug Fix(es) and Enhancement(s):&lt;/p&gt;
&lt;p&gt;* sctp: prevent peer transport count overflow [almalinux-8.10.z] (JIRA:AlmaLinux-216297)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: kernel-rt, AlmaLinux:8: kernel-rt-core, AlmaLinux:8: kernel-rt-debug, AlmaLinux:8: kernel-rt-debug-core, AlmaLinux:8: kernel-rt-debug-devel, AlmaLinux:8: kernel-rt-debug-modules, AlmaLinux:8: kernel-rt-debug-modules-extra, AlmaLinux:8: kernel-rt-devel, AlmaLinux:8: kernel-rt-modules, AlmaLinux:8: kernel-rt-modules-extra&lt;/p&gt;
&lt;p&gt;The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: drm/amdgpu: Fix use-after-free race in VM acquire (CVE-2026-43370)
  * kernel: mac802154: llsec: add skb_cow_data() before in-place crypto (CVE-2026-63831)
  * kernel: sctp: don&amp;#39;t free the ASCONF&amp;#39;s own transport in DEL-IP processing (CVE-2026-64564)
  * kernel: ASoC: SOF: ipc3-control: Validate size in snd_sof_update_control (CVE-2026-72261)
  * kernel: xfrm: ah6: validate routing header segments_left (CVE-2026-80844)
  * kernel: net: tun: bound receive headroom (CVE-2026-81000)
  * kernel: scsi: qla2xxx: Bound rsp_info_len to avoid OOB sense-data read (CVE-2026-89846)&lt;/p&gt;
&lt;p&gt;Bug Fix(es) and Enhancement(s):&lt;/p&gt;
&lt;p&gt;* sctp: prevent peer transport count overflow [almalinux-8.10.z] (JIRA:AlmaLinux-216297)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:71016</guid>
    </item>
    <item>
      <title>BELL-CVE-2026-89846</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-89846</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-89846</guid>
    </item>
    <item>
      <title>certfr-2026-avi-1230 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de Red Hat. Certaines d'entre elles permettent à un…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1230</link>
      <description>certfr-2026-avi-1230</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-1230</guid>
    </item>
    <item>
      <title>EUVD-2026-369435</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-369435</link>
      <description>EUVD-2026-369435</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-369435</guid>
    </item>
    <item>
      <title>fkie_cve-2026-89846</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-89846</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;scsi: qla2xxx: Bound rsp_info_len to avoid OOB sense-data read&lt;/p&gt;
&lt;p&gt;In qla2x00_status_entry(), the FWI2 status path advances sense_data and
shrinks par_sense_len by rsp_info_len:&lt;/p&gt;
&lt;p&gt;if (IS_FWI2_CAPABLE(ha)) {
		sense_data += rsp_info_len;
		par_sense_len -= rsp_info_len;
	}&lt;/p&gt;
&lt;p&gt;rsp_info_len is a 32-bit value taken directly from the target&amp;#39;s FCP
response (sf.rsp_data_len), while par_sense_len is the IOCB data area
size (28 bytes for 24xx, 60 bytes for 29xx). A hostile or buggy target
reporting an rsp_info_len larger than par_sense_len makes the unsigned
subtraction underflow to a huge value and advances sense_data out of
bounds.&lt;/p&gt;
&lt;p&gt;The underflowed par_sense_len then defeats the cap in
qla2x00_handle_sense():&lt;/p&gt;
&lt;p&gt;if (sense_len &amp;gt; par_sense_len)
		sense_len = par_sense_len;
	memcpy(cp-&amp;gt;sense_buffer, sense_data, sense_len);&lt;/p&gt;
&lt;p&gt;so the memcpy reads up to SCSI_SENSE_BUFFERSIZE bytes from the
out-of-bounds sense_data pointer, leaking adjacent response-ring/heap
memory into the command&amp;#39;s sense buffer.&lt;/p&gt;
&lt;p&gt;Clamp rsp_info_len to par_sense_len before the subtraction so
par_sense_len can never underflow and sense_data stays within the IOCB
data area. The fix sits before the comp_status switch, covering both
qla2x00_handle_sense() call sites.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;scsi: qla2xxx: Bound rsp_info_len to avoid OOB sense-data read&lt;/p&gt;
&lt;p&gt;In qla2x00_status_entry(), the FWI2 status path advances sense_data and
shrinks par_sense_len by rsp_info_len:&lt;/p&gt;
&lt;p&gt;if (IS_FWI2_CAPABLE(ha)) {
		sense_data += rsp_info_len;
		par_sense_len -= rsp_info_len;
	}&lt;/p&gt;
&lt;p&gt;rsp_info_len is a 32-bit value taken directly from the target&amp;#39;s FCP
response (sf.rsp_data_len), while par_sense_len is the IOCB data area
size (28 bytes for 24xx, 60 bytes for 29xx). A hostile or buggy target
reporting an rsp_info_len larger than par_sense_len makes the unsigned
subtraction underflow to a huge value and advances sense_data out of
bounds.&lt;/p&gt;
&lt;p&gt;The underflowed par_sense_len then defeats the cap in
qla2x00_handle_sense():&lt;/p&gt;
&lt;p&gt;if (sense_len &amp;gt; par_sense_len)
		sense_len = par_sense_len;
	memcpy(cp-&amp;gt;sense_buffer, sense_data, sense_len);&lt;/p&gt;
&lt;p&gt;so the memcpy reads up to SCSI_SENSE_BUFFERSIZE bytes from the
out-of-bounds sense_data pointer, leaking adjacent response-ring/heap
memory into the command&amp;#39;s sense buffer.&lt;/p&gt;
&lt;p&gt;Clamp rsp_info_len to par_sense_len before the subtraction so
par_sense_len can never underflow and sense_data stays within the IOCB
data area. The fix sits before the comp_status switch, covering both
qla2x00_handle_sense() call sites.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-89846</guid>
    </item>
    <item>
      <title>GHSA-w8mp-89wx-m5rw</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-w8mp-89wx-m5rw</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;scsi: qla2xxx: Bound rsp_info_len to avoid OOB sense-data read&lt;/p&gt;
&lt;p&gt;In qla2x00_status_entry(), the FWI2 status path advances sense_data and
shrinks par_sense_len by rsp_info_len:&lt;/p&gt;
&lt;p&gt;if (IS_FWI2_CAPABLE(ha)) {
		sense_data += rsp_info_len;
		par_sense_len -= rsp_info_len;
	}&lt;/p&gt;
&lt;p&gt;rsp_info_len is a 32-bit value taken directly from the target&amp;#39;s FCP
response (sf.rsp_data_len), while par_sense_len is the IOCB data area
size (28 bytes for 24xx, 60 bytes for 29xx). A hostile or buggy target
reporting an rsp_info_len larger than par_sense_len makes the unsigned
subtraction underflow to a huge value and advances sense_data out of
bounds.&lt;/p&gt;
&lt;p&gt;The underflowed par_sense_len then defeats the cap in
qla2x00_handle_sense():&lt;/p&gt;
&lt;p&gt;if (sense_len &amp;gt; par_sense_len)
		sense_len = par_sense_len;
	memcpy(cp-&amp;gt;sense_buffer, sense_data, sense_len);&lt;/p&gt;
&lt;p&gt;so the memcpy reads up to SCSI_SENSE_BUFFERSIZE bytes from the
out-of-bounds sense_data pointer, leaking adjacent response-ring/heap
memory into the command&amp;#39;s sense buffer.&lt;/p&gt;
&lt;p&gt;Clamp rsp_info_len to par_sense_len before the subtraction so
par_sense_len can never underflow and sense_data stays within the IOCB
data area. The fix sits before the comp_status switch, covering both
qla2x00_handle_sense() call sites.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;scsi: qla2xxx: Bound rsp_info_len to avoid OOB sense-data read&lt;/p&gt;
&lt;p&gt;In qla2x00_status_entry(), the FWI2 status path advances sense_data and
shrinks par_sense_len by rsp_info_len:&lt;/p&gt;
&lt;p&gt;if (IS_FWI2_CAPABLE(ha)) {
		sense_data += rsp_info_len;
		par_sense_len -= rsp_info_len;
	}&lt;/p&gt;
&lt;p&gt;rsp_info_len is a 32-bit value taken directly from the target&amp;#39;s FCP
response (sf.rsp_data_len), while par_sense_len is the IOCB data area
size (28 bytes for 24xx, 60 bytes for 29xx). A hostile or buggy target
reporting an rsp_info_len larger than par_sense_len makes the unsigned
subtraction underflow to a huge value and advances sense_data out of
bounds.&lt;/p&gt;
&lt;p&gt;The underflowed par_sense_len then defeats the cap in
qla2x00_handle_sense():&lt;/p&gt;
&lt;p&gt;if (sense_len &amp;gt; par_sense_len)
		sense_len = par_sense_len;
	memcpy(cp-&amp;gt;sense_buffer, sense_data, sense_len);&lt;/p&gt;
&lt;p&gt;so the memcpy reads up to SCSI_SENSE_BUFFERSIZE bytes from the
out-of-bounds sense_data pointer, leaking adjacent response-ring/heap
memory into the command&amp;#39;s sense buffer.&lt;/p&gt;
&lt;p&gt;Clamp rsp_info_len to par_sense_len before the subtraction so
par_sense_len can never underflow and sense_data stays within the IOCB
data area. The fix sits before the comp_status switch, covering both
qla2x00_handle_sense() call sites.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-w8mp-89wx-m5rw</guid>
    </item>
    <item>
      <title>OESA-2026-4039 — kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-4039</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP4: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:ALSA: caiaq: Use snd_card_free_when_closed() at disconnectionThe USB disconnect callback is supposed to be short and not too-longwaiting.  OTOH, the current code uses snd_card_free() atdisconnection, but this waits for the close of all used fds, hence itcan take long.  It eventually blocks the upper layer USB ioctls, whichmay trigger a soft lockup.An easy workaround is to replace snd_card_free() withsnd_card_free_when_closed().  This variant returns immediately whilethe release of resources is done asynchronously by the card devicerelease at the last close.This patch also splits the code to the disconnect and the free phases;the former is called immediately at the USB disconnect callback whilethe latter is called from the card destructor.(CVE-2024-56531)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:xsk: fix OOB map writes when deleting elementsJordy says: In the xsk_map_delete_elem function an unsigned integer(map-&amp;amp;gt;max_entries) is compared with a user-controlled signed integer(k). Due to implicit type conversion, a large unsigned value formap-&amp;amp;gt;max_entries can bypass the intended bounds check: if (k &amp;amp;gt;= map-&amp;amp;gt;max_entries)  return -EINVAL;This allows k to hold a negative value (between -2147483648 and -2),which is then used as an array index in m-&amp;amp;gt;xsk_map[k], which resultsin an out-of-bounds access. spi…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP4: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:ALSA: caiaq: Use snd_card_free_when_closed() at disconnectionThe USB disconnect callback is supposed to be short and not too-longwaiting.  OTOH, the current code uses snd_card_free() atdisconnection, but this waits for the close of all used fds, hence itcan take long.  It eventually blocks the upper layer USB ioctls, whichmay trigger a soft lockup.An easy workaround is to replace snd_card_free() withsnd_card_free_when_closed().  This variant returns immediately whilethe release of resources is done asynchronously by the card devicerelease at the last close.This patch also splits the code to the disconnect and the free phases;the former is called immediately at the USB disconnect callback whilethe latter is called from the card destructor.(CVE-2024-56531)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:xsk: fix OOB map writes when deleting elementsJordy says: In the xsk_map_delete_elem function an unsigned integer(map-&amp;amp;gt;max_entries) is compared with a user-controlled signed integer(k). Due to implicit type conversion, a large unsigned value formap-&amp;amp;gt;max_entries can bypass the intended bounds check: if (k &amp;amp;gt;= map-&amp;amp;gt;max_entries)  return -EINVAL;This allows k to hold a negative value (between -2147483648 and -2),which is then used as an array index in m-&amp;amp;gt;xsk_map[k], which resultsin an out-of-bounds access. spi…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-4039</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:11880-1 — kernel-devel-7.2.7-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11880-1</link>
      <description>&lt;p&gt;kernel-devel-7.2.7-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;kernel-devel-7.2.7-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:11880-1</guid>
    </item>
    <item>
      <title>RHSA-2026:71016 — Red Hat Security Advisory: kernel-rt security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:71016</link>
      <description>&lt;p&gt;kernel: drm/amdgpu: Fix use-after-free race in VM acquire kernel: mac802154: llsec: add skb_cow_data() before in-place crypto kernel: sctp: don&amp;#39;t free the ASCONF&amp;#39;s own transport in DEL-IP processing kernel: ASoC: SOF: ipc3-control: Validate size in snd_sof_update_control kernel: xfrm: ah6: validate routing header segments_left kernel: net: tun: bound receive headroom kernel: scsi: qla2xxx: Bound rsp_info_len to avoid OOB sense-data read&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;kernel: drm/amdgpu: Fix use-after-free race in VM acquire kernel: mac802154: llsec: add skb_cow_data() before in-place crypto kernel: sctp: don&amp;#39;t free the ASCONF&amp;#39;s own transport in DEL-IP processing kernel: ASoC: SOF: ipc3-control: Validate size in snd_sof_update_control kernel: xfrm: ah6: validate routing header segments_left kernel: net: tun: bound receive headroom kernel: scsi: qla2xxx: Bound rsp_info_len to avoid OOB sense-data read&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:71016</guid>
    </item>
    <item>
      <title>RLSA-2026:71232 — Important: kernel security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:71232</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:9: kernel&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: block: zero non-PI portion of auto integrity buffer (CVE-2026-23007)&lt;/p&gt;
&lt;p&gt;* kernel: af_unix: Drop all SCM attributes for SOCKMAP (CVE-2026-53005)&lt;/p&gt;
&lt;p&gt;* kernel: mac802154: llsec: add skb_cow_data() before in-place crypto (CVE-2026-63831)&lt;/p&gt;
&lt;p&gt;* kernel: blk-cgroup: fix UAF in __blkcg_rstat_flush() (CVE-2026-63802)&lt;/p&gt;
&lt;p&gt;* kernel: block: don&amp;#39;t overwrite bip_vcnt in bio_integrity_copy_user() (CVE-2026-64053)&lt;/p&gt;
&lt;p&gt;* kernel: smb: client: fix double-free in SMB2_flush() replay (CVE-2026-64383)&lt;/p&gt;
&lt;p&gt;* kernel: nvmet-tcp: check INIT_FAILED before nvmet_req_uninit in digest error path (CVE-2026-64534)&lt;/p&gt;
&lt;p&gt;* kernel: sctp: don&amp;#39;t free the ASCONF&amp;#39;s own transport in DEL-IP processing (CVE-2026-64564)&lt;/p&gt;
&lt;p&gt;* kernel: ALSA: timer: drain a slave&amp;#39;s callback before its master detaches it (CVE-2026-68201)&lt;/p&gt;
&lt;p&gt;* kernel: ASoC: SOF: ipc3-control: Validate size in snd_sof_update_control (CVE-2026-72261)&lt;/p&gt;
&lt;p&gt;* kernel: xfrm: ah6: validate routing header segments_left (CVE-2026-80844)&lt;/p&gt;
&lt;p&gt;* kernel: net: tun: bound receive headroom (CVE-2026-81000)&lt;/p&gt;
&lt;p&gt;* kernel: scsi: qla2xxx: Bound rsp_info_len to avoid OOB sense-data read (CVE-2026-89846)&lt;/p&gt;
&lt;p&gt;Bug Fix(es) and Enhancement(s):&lt;/p&gt;
&lt;p&gt;* sctp: prevent peer transport count overflow [rhel-9.8.z] (JIRA:Rocky Linux-216251)&lt;/p&gt;
&lt;p&gt;* netfilter: nftables CVE and memory safety backports for 9.8 (JIRA:Rocky Linux-236634)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowl…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:9: kernel&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: block: zero non-PI portion of auto integrity buffer (CVE-2026-23007)&lt;/p&gt;
&lt;p&gt;* kernel: af_unix: Drop all SCM attributes for SOCKMAP (CVE-2026-53005)&lt;/p&gt;
&lt;p&gt;* kernel: mac802154: llsec: add skb_cow_data() before in-place crypto (CVE-2026-63831)&lt;/p&gt;
&lt;p&gt;* kernel: blk-cgroup: fix UAF in __blkcg_rstat_flush() (CVE-2026-63802)&lt;/p&gt;
&lt;p&gt;* kernel: block: don&amp;#39;t overwrite bip_vcnt in bio_integrity_copy_user() (CVE-2026-64053)&lt;/p&gt;
&lt;p&gt;* kernel: smb: client: fix double-free in SMB2_flush() replay (CVE-2026-64383)&lt;/p&gt;
&lt;p&gt;* kernel: nvmet-tcp: check INIT_FAILED before nvmet_req_uninit in digest error path (CVE-2026-64534)&lt;/p&gt;
&lt;p&gt;* kernel: sctp: don&amp;#39;t free the ASCONF&amp;#39;s own transport in DEL-IP processing (CVE-2026-64564)&lt;/p&gt;
&lt;p&gt;* kernel: ALSA: timer: drain a slave&amp;#39;s callback before its master detaches it (CVE-2026-68201)&lt;/p&gt;
&lt;p&gt;* kernel: ASoC: SOF: ipc3-control: Validate size in snd_sof_update_control (CVE-2026-72261)&lt;/p&gt;
&lt;p&gt;* kernel: xfrm: ah6: validate routing header segments_left (CVE-2026-80844)&lt;/p&gt;
&lt;p&gt;* kernel: net: tun: bound receive headroom (CVE-2026-81000)&lt;/p&gt;
&lt;p&gt;* kernel: scsi: qla2xxx: Bound rsp_info_len to avoid OOB sense-data read (CVE-2026-89846)&lt;/p&gt;
&lt;p&gt;Bug Fix(es) and Enhancement(s):&lt;/p&gt;
&lt;p&gt;* sctp: prevent peer transport count overflow [rhel-9.8.z] (JIRA:Rocky Linux-216251)&lt;/p&gt;
&lt;p&gt;* netfilter: nftables CVE and memory safety backports for 9.8 (JIRA:Rocky Linux-236634)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowl…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:71232</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-89846</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-89846</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux, Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe and 246 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Bound rsp_info_len to avoid OOB sense-data read In qla2x00_status_entry(), the FWI2 status path advances sense_data and shrinks par_sense_len by rsp_info_len: 	if (IS_FWI2_CAPABLE(ha)) { 		sense_data += rsp_info_len; 		par_sense_len -= rsp_info_len; 	} rsp_info_len is a 32-bit value taken directly from the target&amp;#39;s FCP response (sf.rsp_data_len), while par_sense_len is the IOCB data area size (28 bytes for 24xx, 60 bytes for 29xx). A hostile or buggy target reporting an rsp_info_len larger than par_sense_len makes the unsigned subtraction underflow to a huge value and advances sense_data out of bounds. The underflowed par_sense_len then defeats the cap in qla2x00_handle_sense(): 	if (sense_len &amp;gt; par_sense_len) 		sense_len = par_sense_len; 	memcpy(cp-&amp;gt;sense_buffer, sense_data, sense_len); so the memcpy reads up to SCSI_SENSE_BUFFERSIZE bytes from the out-of-bounds sense_data pointer, leaking adjacent response-ring/heap memory into the command&amp;#39;s sense buffer. Clamp rsp_info_len to par_sense_len before the subtraction so par_sense_len can never underflow and sense_data stays within the IOCB data area. The fix sits before the comp_status switch, covering both qla2x00_handle_sense() call sites.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux, Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe and 246 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Bound rsp_info_len to avoid OOB sense-data read In qla2x00_status_entry(), the FWI2 status path advances sense_data and shrinks par_sense_len by rsp_info_len: 	if (IS_FWI2_CAPABLE(ha)) { 		sense_data += rsp_info_len; 		par_sense_len -= rsp_info_len; 	} rsp_info_len is a 32-bit value taken directly from the target&amp;#39;s FCP response (sf.rsp_data_len), while par_sense_len is the IOCB data area size (28 bytes for 24xx, 60 bytes for 29xx). A hostile or buggy target reporting an rsp_info_len larger than par_sense_len makes the unsigned subtraction underflow to a huge value and advances sense_data out of bounds. The underflowed par_sense_len then defeats the cap in qla2x00_handle_sense(): 	if (sense_len &amp;gt; par_sense_len) 		sense_len = par_sense_len; 	memcpy(cp-&amp;gt;sense_buffer, sense_data, sense_len); so the memcpy reads up to SCSI_SENSE_BUFFERSIZE bytes from the out-of-bounds sense_data pointer, leaking adjacent response-ring/heap memory into the command&amp;#39;s sense buffer. Clamp rsp_info_len to par_sense_len before the subtraction so par_sense_len can never underflow and sense_data stays within the IOCB data area. The fix sits before the comp_status switch, covering both qla2x00_handle_sense() call sites.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-89846</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-3438 — Linux Kernel: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3438</link>
      <description>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen Denial of Service zu verursachen oder eine nicht näher spezifizierte Auswirkung zu erzielen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen Denial of Service zu verursachen oder eine nicht näher spezifizierte Auswirkung zu erzielen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3438</guid>
    </item>
  </channel>
</rss>
