<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Thu, 08 Oct 2026 07:58:06 +0000</lastBuildDate>
    <item>
      <title>CVE-2026-31431 — crypto: algif_aead - Revert to operating out-of-place</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-31431</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Linux, Siemens SIMATIC AX Runtime Core Linux Common Debian, Siemens SIMATIC AX Runtime Core Linux Common Debian arm64, Siemens SIMATIC AX Runtime Core Linux Platform Container Common Debian Development, Siemens SIMATIC AX Runtime Core Linux VMWare Development, Siemens SIMATIC CN 4100, Siemens SIMATIC HMI MTP1000 Unified Basic, Siemens SIMATIC HMI MTP1000 Unified Comfort Panel, Siemens SIMATIC HMI MTP1000 Unified Comfort Panel hygienic, Siemens SIMATIC HMI MTP1000 Unified Comfort Panel hygienic neutral design and 89 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;crypto: algif_aead - Revert to operating out-of-place&lt;/p&gt;
&lt;p&gt;This mostly reverts commit 72548b093ee3 except for the copying of
the associated data.&lt;/p&gt;
&lt;p&gt;There is no benefit in operating in-place in algif_aead since the
source and destination come from different mappings.  Get rid of
all the complexity added for in-place operation and just copy the
AD directly.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Linux, Siemens SIMATIC AX Runtime Core Linux Common Debian, Siemens SIMATIC AX Runtime Core Linux Common Debian arm64, Siemens SIMATIC AX Runtime Core Linux Platform Container Common Debian Development, Siemens SIMATIC AX Runtime Core Linux VMWare Development, Siemens SIMATIC CN 4100, Siemens SIMATIC HMI MTP1000 Unified Basic, Siemens SIMATIC HMI MTP1000 Unified Comfort Panel, Siemens SIMATIC HMI MTP1000 Unified Comfort Panel hygienic, Siemens SIMATIC HMI MTP1000 Unified Comfort Panel hygienic neutral design and 89 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;crypto: algif_aead - Revert to operating out-of-place&lt;/p&gt;
&lt;p&gt;This mostly reverts commit 72548b093ee3 except for the copying of
the associated data.&lt;/p&gt;
&lt;p&gt;There is no benefit in operating in-place in algif_aead since the
source and destination come from different mappings.  Get rid of
all the complexity added for in-place operation and just copy the
AD directly.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-31431</guid>
    </item>
    <item>
      <title>LSN-0121-1 — Kernel Live Patch Security Notice</title>
      <link>https://cve.radiocsirt.org/vuln/lsn-0121-1</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:18.04:LTS: linux-aws, Ubuntu:Pro:18.04:LTS: linux-azure-4.15, Ubuntu:Pro:18.04:LTS: linux-gcp-4.15, Ubuntu:Pro:18.04:LTS: linux and 24 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been
resolved: ksmbd: ipc: fix use-after-free in ipc_msg_send_request
ipc_msg_send_request() waits for a generic netlink reply using an
ipc_msg_table_entry on the stack.&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been
resolved: ksmbd: fix use-after-free of share_conf in compound request
smb2_get_ksmbd_tcon() reuses work-&amp;gt;tcon in compound requests without
validating tcon-&amp;gt;t_state.&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been
resolved: netfilter: nf_conntrack_h323: check for zero length in
DecodeQ931() In DecodeQ931(), the UserUserIE code path reads a 16-bit
length from the packet, then decrements it by 1 to skip the protocol
discriminator byte before passing it to DecodeH323_UserInformation().&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been
resolved: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache The NFSv4.0
replay cache uses a fixed 112-byte inline buffer
(rp_ibuf.&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been
resolved: media: dvb-net: fix OOB access in ULE extension header tables The
ule_mandatory_ext_handlers.&lt;/p&gt;
&lt;p&gt;It was discovered that the Linux kernel algif_aead module did not properly
handle in-place cryptographic operations. This flaw is known as Copy Fail.
A local attacker could use this to escalate privileges, or possibly escape
a container.)(CVE-2026-31431)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been
resolved: ksmbd: replace hardcoded hdr2_len with…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:18.04:LTS: linux-aws, Ubuntu:Pro:18.04:LTS: linux-azure-4.15, Ubuntu:Pro:18.04:LTS: linux-gcp-4.15, Ubuntu:Pro:18.04:LTS: linux and 24 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been
resolved: ksmbd: ipc: fix use-after-free in ipc_msg_send_request
ipc_msg_send_request() waits for a generic netlink reply using an
ipc_msg_table_entry on the stack.&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been
resolved: ksmbd: fix use-after-free of share_conf in compound request
smb2_get_ksmbd_tcon() reuses work-&amp;gt;tcon in compound requests without
validating tcon-&amp;gt;t_state.&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been
resolved: netfilter: nf_conntrack_h323: check for zero length in
DecodeQ931() In DecodeQ931(), the UserUserIE code path reads a 16-bit
length from the packet, then decrements it by 1 to skip the protocol
discriminator byte before passing it to DecodeH323_UserInformation().&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been
resolved: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache The NFSv4.0
replay cache uses a fixed 112-byte inline buffer
(rp_ibuf.&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been
resolved: media: dvb-net: fix OOB access in ULE extension header tables The
ule_mandatory_ext_handlers.&lt;/p&gt;
&lt;p&gt;It was discovered that the Linux kernel algif_aead module did not properly
handle in-place cryptographic operations. This flaw is known as Copy Fail.
A local attacker could use this to escalate privileges, or possibly escape
a container.)(CVE-2026-31431)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been
resolved: ksmbd: replace hardcoded hdr2_len with…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/lsn-0121-1</guid>
    </item>
  </channel>
</rss>
