<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Thu, 08 Oct 2026 08:17:02 +0000</lastBuildDate>
    <item>
      <title>CVE-2026-23270 — net/sched: Only allow act_ct to bind to clsact/ingress qdiscs and shared blocks</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-23270</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Linux, Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, Siemens SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP, Siemens SIPLUS S7-1500 CPU 1518-4 PN/DP MFP&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;net/sched: Only allow act_ct to bind to clsact/ingress qdiscs and shared blocks&lt;/p&gt;
&lt;p&gt;As Paolo said earlier [1]:&lt;/p&gt;
&lt;p&gt;&amp;#34;Since the blamed commit below, classify can return TC_ACT_CONSUMED while
the current skb being held by the defragmentation engine. As reported by
GangMin Kim, if such packet is that may cause a UaF when the defrag engine
later on tries to tuch again such packet.&amp;#34;&lt;/p&gt;
&lt;p&gt;act_ct was never meant to be used in the egress path, however some users
are attaching it to egress today [2]. Attempting to reach a middle
ground, we noticed that, while most qdiscs are not handling
TC_ACT_CONSUMED, clsact/ingress qdiscs are. With that in mind, we
address the issue by only allowing act_ct to bind to clsact/ingress
qdiscs and shared blocks. That way it&amp;#39;s still possible to attach act_ct to
egress (albeit only with clsact).&lt;/p&gt;
&lt;p&gt;[1] https://lore.kernel.org/netdev/674b8cbfc385c6f37fb29a1de08d8fe5c2b0fbee.1771321118.git.pabeni@redhat.com/
[2] https://lore.kernel.org/netdev/cc6bfb4a-4a2b-42d8-b9ce-7ef6644fb22b@ovn.org/&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Linux, Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, Siemens SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP, Siemens SIPLUS S7-1500 CPU 1518-4 PN/DP MFP&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;net/sched: Only allow act_ct to bind to clsact/ingress qdiscs and shared blocks&lt;/p&gt;
&lt;p&gt;As Paolo said earlier [1]:&lt;/p&gt;
&lt;p&gt;&amp;#34;Since the blamed commit below, classify can return TC_ACT_CONSUMED while
the current skb being held by the defragmentation engine. As reported by
GangMin Kim, if such packet is that may cause a UaF when the defrag engine
later on tries to tuch again such packet.&amp;#34;&lt;/p&gt;
&lt;p&gt;act_ct was never meant to be used in the egress path, however some users
are attaching it to egress today [2]. Attempting to reach a middle
ground, we noticed that, while most qdiscs are not handling
TC_ACT_CONSUMED, clsact/ingress qdiscs are. With that in mind, we
address the issue by only allowing act_ct to bind to clsact/ingress
qdiscs and shared blocks. That way it&amp;#39;s still possible to attach act_ct to
egress (albeit only with clsact).&lt;/p&gt;
&lt;p&gt;[1] https://lore.kernel.org/netdev/674b8cbfc385c6f37fb29a1de08d8fe5c2b0fbee.1771321118.git.pabeni@redhat.com/
[2] https://lore.kernel.org/netdev/cc6bfb4a-4a2b-42d8-b9ce-7ef6644fb22b@ovn.org/&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-23270</guid>
    </item>
    <item>
      <title>RHSA-2026:13565 — Red Hat Security Advisory: kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:13565</link>
      <description>&lt;p&gt;kernel: Linux kernel: Denial of Service in libceph OSD client due to unreset sparse-read state kernel: Linux kernel: Use-after-free in traffic control (act_ct) may lead to denial of service or privilege escalation kernel: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache kernel: crypto: algif_aead - Revert to operating out-of-place kernel: crypto: algif_aead - Fix minimum RX size check for decryption&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;kernel: Linux kernel: Denial of Service in libceph OSD client due to unreset sparse-read state kernel: Linux kernel: Use-after-free in traffic control (act_ct) may lead to denial of service or privilege escalation kernel: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache kernel: crypto: algif_aead - Revert to operating out-of-place kernel: crypto: algif_aead - Fix minimum RX size check for decryption&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:13565</guid>
    </item>
    <item>
      <title>RHSA-2026:21209 — Red Hat Security Advisory: kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:21209</link>
      <description>&lt;p&gt;kernel: proc: fix UAF in proc_get_inode() kernel: proc: use the same treatment to check proc_lseek as ones for proc_read_iter et.al kernel: net/sched: Make cake_enqueue return NET_XMIT_CN when past buffer_limit kernel: nbd: defer config unlock in nbd_genl_connect kernel: scsi: qla2xxx: Fix improper freeing of purex item kernel: Linux kernel: Denial of service and memory corruption in RDMA umad kernel: Linux kernel: Use-after-free in traffic control (act_ct) may lead to denial of service or privilege escalation kernel: Linux kernel: Use-after-free in bonding driver leads to denial of service kernel: md/bitmap: fix GPF in write_page caused by resize race&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;kernel: proc: fix UAF in proc_get_inode() kernel: proc: use the same treatment to check proc_lseek as ones for proc_read_iter et.al kernel: net/sched: Make cake_enqueue return NET_XMIT_CN when past buffer_limit kernel: nbd: defer config unlock in nbd_genl_connect kernel: scsi: qla2xxx: Fix improper freeing of purex item kernel: Linux kernel: Denial of service and memory corruption in RDMA umad kernel: Linux kernel: Use-after-free in traffic control (act_ct) may lead to denial of service or privilege escalation kernel: Linux kernel: Use-after-free in bonding driver leads to denial of service kernel: md/bitmap: fix GPF in write_page caused by resize race&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:21209</guid>
    </item>
  </channel>
</rss>
