<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 10:06:57 +0000</lastBuildDate>
    <item>
      <title>ALSA-2026:16195 — Important: kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:16195</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: bpftool, AlmaLinux:8: kernel, AlmaLinux:8: kernel-abi-stablelists, AlmaLinux:8: kernel-core, AlmaLinux:8: kernel-cross-headers, AlmaLinux:8: kernel-debug, AlmaLinux:8: kernel-debug-core, AlmaLinux:8: kernel-debug-devel, AlmaLinux:8: kernel-debug-modules, AlmaLinux:8: kernel-debug-modules-extra and 15 more&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: &amp;#34;Dirty Frag&amp;#34; is a new universal Local Privilege Escalation (LPE) vulnerability in the Linux kernel (CVE-2026-43284)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: bpftool, AlmaLinux:8: kernel, AlmaLinux:8: kernel-abi-stablelists, AlmaLinux:8: kernel-core, AlmaLinux:8: kernel-cross-headers, AlmaLinux:8: kernel-debug, AlmaLinux:8: kernel-debug-core, AlmaLinux:8: kernel-debug-devel, AlmaLinux:8: kernel-debug-modules, AlmaLinux:8: kernel-debug-modules-extra and 15 more&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: &amp;#34;Dirty Frag&amp;#34; is a new universal Local Privilege Escalation (LPE) vulnerability in the Linux kernel (CVE-2026-43284)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:16195</guid>
    </item>
    <item>
      <title>bdu:2026-06439</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-06439</link>
      <description>bdu:2026-06439</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-06439</guid>
    </item>
    <item>
      <title>BELL-CVE-2026-43284</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-43284</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-43284</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0558 — De multiples vulnérabilités ont été découvertes dans Microsoft Azure Linux. Elles permettent à un attaquant de provoque…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0558</link>
      <description>certfr-2026-avi-0558</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0558</guid>
    </item>
    <item>
      <title>cnvd-2026-21358</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2026-21358</link>
      <description>cnvd-2026-21358</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2026-21358</guid>
    </item>
    <item>
      <title>ESBA-2026:0090 — security update for kernel</title>
      <link>https://cve.radiocsirt.org/vuln/esba-2026:0090</link>
      <description>&lt;p&gt;security update for kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;security update for kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/esba-2026:0090</guid>
    </item>
    <item>
      <title>EUVD-2026-364801</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-364801</link>
      <description>EUVD-2026-364801</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-364801</guid>
    </item>
    <item>
      <title>fkie_cve-2026-43284</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-43284</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;xfrm: esp: avoid in-place decrypt on shared skb frags&lt;/p&gt;
&lt;p&gt;MSG_SPLICE_PAGES can attach pages from a pipe directly to an skb. TCP
marks such skbs with SKBFL_SHARED_FRAG after skb_splice_from_iter(),
so later paths that may modify packet data can first make a private
copy. The IPv4/IPv6 datagram append paths did not set this flag when
splicing pages into UDP skbs.&lt;/p&gt;
&lt;p&gt;That leaves an ESP-in-UDP packet made from shared pipe pages looking
like an ordinary uncloned nonlinear skb. ESP input then takes the no-COW
fast path for uncloned skbs without a frag_list and decrypts in place
over data that is not owned privately by the skb.&lt;/p&gt;
&lt;p&gt;Mark IPv4/IPv6 datagram splice frags with SKBFL_SHARED_FRAG, matching
TCP. Also make ESP input fall back to skb_cow_data() when the flag is
present, so ESP does not decrypt externally backed frags in place.
Private nonlinear skb frags still use the existing fast path.&lt;/p&gt;
&lt;p&gt;This intentionally does not change ESP output. In esp_output_head(),
the path that appends the ESP trailer to existing skb tailroom without
calling skb_cow_data() is not reachable for nonlinear skbs:
skb_tailroom() returns zero when skb-&amp;gt;data_len is nonzero, while ESP
tailen is positive. Thus ESP output will either use the separate
destination-frag path or fall back to skb_cow_data().&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;xfrm: esp: avoid in-place decrypt on shared skb frags&lt;/p&gt;
&lt;p&gt;MSG_SPLICE_PAGES can attach pages from a pipe directly to an skb. TCP
marks such skbs with SKBFL_SHARED_FRAG after skb_splice_from_iter(),
so later paths that may modify packet data can first make a private
copy. The IPv4/IPv6 datagram append paths did not set this flag when
splicing pages into UDP skbs.&lt;/p&gt;
&lt;p&gt;That leaves an ESP-in-UDP packet made from shared pipe pages looking
like an ordinary uncloned nonlinear skb. ESP input then takes the no-COW
fast path for uncloned skbs without a frag_list and decrypts in place
over data that is not owned privately by the skb.&lt;/p&gt;
&lt;p&gt;Mark IPv4/IPv6 datagram splice frags with SKBFL_SHARED_FRAG, matching
TCP. Also make ESP input fall back to skb_cow_data() when the flag is
present, so ESP does not decrypt externally backed frags in place.
Private nonlinear skb frags still use the existing fast path.&lt;/p&gt;
&lt;p&gt;This intentionally does not change ESP output. In esp_output_head(),
the path that appends the ESP trailer to existing skb tailroom without
calling skb_cow_data() is not reachable for nonlinear skbs:
skb_tailroom() returns zero when skb-&amp;gt;data_len is nonzero, while ESP
tailen is positive. Thus ESP output will either use the separate
destination-frag path or fall back to skb_cow_data().&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-43284</guid>
    </item>
    <item>
      <title>GHSA-mmw8-mxmc-8w2r</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-mmw8-mxmc-8w2r</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;xfrm: esp: avoid in-place decrypt on shared skb frags&lt;/p&gt;
&lt;p&gt;MSG_SPLICE_PAGES can attach pages from a pipe directly to an skb. TCP
marks such skbs with SKBFL_SHARED_FRAG after skb_splice_from_iter(),
so later paths that may modify packet data can first make a private
copy. The IPv4/IPv6 datagram append paths did not set this flag when
splicing pages into UDP skbs.&lt;/p&gt;
&lt;p&gt;That leaves an ESP-in-UDP packet made from shared pipe pages looking
like an ordinary uncloned nonlinear skb. ESP input then takes the no-COW
fast path for uncloned skbs without a frag_list and decrypts in place
over data that is not owned privately by the skb.&lt;/p&gt;
&lt;p&gt;Mark IPv4/IPv6 datagram splice frags with SKBFL_SHARED_FRAG, matching
TCP. Also make ESP input fall back to skb_cow_data() when the flag is
present, so ESP does not decrypt externally backed frags in place.
Private nonlinear skb frags still use the existing fast path.&lt;/p&gt;
&lt;p&gt;This intentionally does not change ESP output. In esp_output_head(),
the path that appends the ESP trailer to existing skb tailroom without
calling skb_cow_data() is not reachable for nonlinear skbs:
skb_tailroom() returns zero when skb-&amp;gt;data_len is nonzero, while ESP
tailen is positive. Thus ESP output will either use the separate
destination-frag path or fall back to skb_cow_data().&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;xfrm: esp: avoid in-place decrypt on shared skb frags&lt;/p&gt;
&lt;p&gt;MSG_SPLICE_PAGES can attach pages from a pipe directly to an skb. TCP
marks such skbs with SKBFL_SHARED_FRAG after skb_splice_from_iter(),
so later paths that may modify packet data can first make a private
copy. The IPv4/IPv6 datagram append paths did not set this flag when
splicing pages into UDP skbs.&lt;/p&gt;
&lt;p&gt;That leaves an ESP-in-UDP packet made from shared pipe pages looking
like an ordinary uncloned nonlinear skb. ESP input then takes the no-COW
fast path for uncloned skbs without a frag_list and decrypts in place
over data that is not owned privately by the skb.&lt;/p&gt;
&lt;p&gt;Mark IPv4/IPv6 datagram splice frags with SKBFL_SHARED_FRAG, matching
TCP. Also make ESP input fall back to skb_cow_data() when the flag is
present, so ESP does not decrypt externally backed frags in place.
Private nonlinear skb frags still use the existing fast path.&lt;/p&gt;
&lt;p&gt;This intentionally does not change ESP output. In esp_output_head(),
the path that appends the ESP trailer to existing skb tailroom without
calling skb_cow_data() is not reachable for nonlinear skbs:
skb_tailroom() returns zero when skb-&amp;gt;data_len is nonzero, while ESP
tailen is positive. Thus ESP output will either use the separate
destination-frag path or fall back to skb_cow_data().&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-mmw8-mxmc-8w2r</guid>
    </item>
    <item>
      <title>ICSA-26-174-06 — Impact of Linux Kernel vulnerabilities on B&amp;R products</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-26-174-06</link>
      <description>&lt;p&gt;B&amp;amp;R is aware of publicly reported vulnerabilities affecting the Linux kernel versions shipped with the products listed as affected in the advisory.&lt;/p&gt;
&lt;p&gt;Successful local exploitation of these vulnerabilities could allow an attacker to escalate privileges on the affected system. Public proof-of-concept exploits are available for the vulnerabilities described herein. At the time of publication of this advisory, B&amp;amp;R had no evidence of active exploitation targeting B&amp;amp;R products.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;B&amp;amp;R is aware of publicly reported vulnerabilities affecting the Linux kernel versions shipped with the products listed as affected in the advisory.&lt;/p&gt;
&lt;p&gt;Successful local exploitation of these vulnerabilities could allow an attacker to escalate privileges on the affected system. Public proof-of-concept exploits are available for the vulnerabilities described herein. At the time of publication of this advisory, B&amp;amp;R had no evidence of active exploitation targeting B&amp;amp;R products.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-26-174-06</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-43284 — xfrm: esp: avoid in-place decrypt on shared skb frags</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-43284</link>
      <description>msrc_CVE-2026-43284</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-43284</guid>
    </item>
    <item>
      <title>OESA-2026-2310 — kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-2310</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP4: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;net: fix fanout UAF in packet_release() via NETDEV_UP race&lt;/p&gt;
&lt;p&gt;`packet_release()` has a race window where `NETDEV_UP` can re-register a
socket into a fanout group&amp;amp;apos;s `arr[]` array. The re-registration is not
cleaned up by `fanout_release()`, leaving a dangling pointer in the fanout
array.
`packet_release()` does NOT zero `po-&amp;amp;gt;num` in its `bind_lock` section.
After releasing `bind_lock`, `po-&amp;amp;gt;num` is still non-zero and `po-&amp;amp;gt;ifindex`
still matches the bound device. A concurrent `packet_notifier(NETDEV_UP)`
that already found the socket in `sklist` can re-register the hook.
For fanout sockets, this re-registration calls `__fanout_link(sk, po)`
which adds the socket back into `f-&amp;amp;gt;arr[]` and increments `f-&amp;amp;gt;num_members`,
but does NOT increment `f-&amp;amp;gt;sk_ref`.&lt;/p&gt;
&lt;p&gt;The fix sets `po-&amp;amp;gt;num` to zero in `packet_release` while `bind_lock` is
held to prevent NETDEV_UP from linking, preventing the race window.&lt;/p&gt;
&lt;p&gt;This bug was found following an additional audit with Claude Code based
on CVE-2025-38617.(CVE-2026-31504)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;af_key: validate families in pfkey_send_migrate()&lt;/p&gt;
&lt;p&gt;syzbot was able to trigger a crash in skb_put() [1]&lt;/p&gt;
&lt;p&gt;Issue is that pfkey_send_migrate() does not check old/new families,
and that set_ipsecrequest() @family argument was truncated,
thus possibly overfill…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP4: kernel&lt;/p&gt;
&lt;p&gt;The Linux Kernel, the operating system core itself.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;net: fix fanout UAF in packet_release() via NETDEV_UP race&lt;/p&gt;
&lt;p&gt;`packet_release()` has a race window where `NETDEV_UP` can re-register a
socket into a fanout group&amp;amp;apos;s `arr[]` array. The re-registration is not
cleaned up by `fanout_release()`, leaving a dangling pointer in the fanout
array.
`packet_release()` does NOT zero `po-&amp;amp;gt;num` in its `bind_lock` section.
After releasing `bind_lock`, `po-&amp;amp;gt;num` is still non-zero and `po-&amp;amp;gt;ifindex`
still matches the bound device. A concurrent `packet_notifier(NETDEV_UP)`
that already found the socket in `sklist` can re-register the hook.
For fanout sockets, this re-registration calls `__fanout_link(sk, po)`
which adds the socket back into `f-&amp;amp;gt;arr[]` and increments `f-&amp;amp;gt;num_members`,
but does NOT increment `f-&amp;amp;gt;sk_ref`.&lt;/p&gt;
&lt;p&gt;The fix sets `po-&amp;amp;gt;num` to zero in `packet_release` while `bind_lock` is
held to prevent NETDEV_UP from linking, preventing the race window.&lt;/p&gt;
&lt;p&gt;This bug was found following an additional audit with Claude Code based
on CVE-2025-38617.(CVE-2026-31504)&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;af_key: validate families in pfkey_send_migrate()&lt;/p&gt;
&lt;p&gt;syzbot was able to trigger a crash in skb_put() [1]&lt;/p&gt;
&lt;p&gt;Issue is that pfkey_send_migrate() does not check old/new families,
and that set_ipsecrequest() @family argument was truncated,
thus possibly overfill…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-2310</guid>
    </item>
    <item>
      <title>PPSA-2026-003 — Pilz: Multiple Vulnerabilities affecting industrial PC IndustrialPI</title>
      <link>https://cve.radiocsirt.org/vuln/ppsa-2026-003</link>
      <description>&lt;p&gt;The Linux kernel used in the IndustrialPI, &amp;#39;linux-image-revpi-v8&amp;#39;, prior to version 6.12.91-revpi0-rpi-v8 contains multiple vulnerabilities. Successful exploitation of these vulnerabilities can give an attacker full control over the device.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The Linux kernel used in the IndustrialPI, &amp;#39;linux-image-revpi-v8&amp;#39;, prior to version 6.12.91-revpi0-rpi-v8 contains multiple vulnerabilities. Successful exploitation of these vulnerabilities can give an attacker full control over the device.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ppsa-2026-003</guid>
    </item>
    <item>
      <title>RHSA-2026:16061 — Red Hat Security Advisory: kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:16061</link>
      <description>&lt;p&gt;kernel: &amp;#34;Dirty Frag&amp;#34; ESP XFRM variant is a new universal Local Privilege Escalation (LPE) vulnerability in the Linux kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;kernel: &amp;#34;Dirty Frag&amp;#34; ESP XFRM variant is a new universal Local Privilege Escalation (LPE) vulnerability in the Linux kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:16061</guid>
    </item>
    <item>
      <title>RLSA-2026:19569 — Important: kernel security update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:19569</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: kernel&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: net: af_can: do not leave a dangling sk pointer in can_create() (CVE-2024-56603)&lt;/p&gt;
&lt;p&gt;* kernel: net/sched: Make cake_enqueue return NET_XMIT_CN when past buffer_limit (CVE-2025-39766)&lt;/p&gt;
&lt;p&gt;* kernel: crypto: asymmetric_keys - prevent overflow in asymmetric_key_generate_id (CVE-2025-68724)&lt;/p&gt;
&lt;p&gt;* kernel: scsi: qla2xxx: Fix improper freeing of purex item (CVE-2025-68741)&lt;/p&gt;
&lt;p&gt;* kernel: Linux kernel: Use-after-free in traffic control (act_ct) may lead to denial of service or privilege escalation (CVE-2026-23270)&lt;/p&gt;
&lt;p&gt;* kernel: Linux kernel KVM: Privilege escalation or denial of service due to improper shadow page table entry handling (CVE-2026-23401)&lt;/p&gt;
&lt;p&gt;* kernel: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (CVE-2026-31402)&lt;/p&gt;
&lt;p&gt;* kernel: Bluetooth: SCO: Fix use-after-free in sco_recv_frame() due to missing sock_hold (CVE-2026-31408)&lt;/p&gt;
&lt;p&gt;* kernel: usbip: validate number_of_packets in usbip_pack_ret_submit() (CVE-2026-31607)&lt;/p&gt;
&lt;p&gt;* kernel: RDMA/umem: Fix double dma_buf_unpin in failure path (CVE-2026-43128)&lt;/p&gt;
&lt;p&gt;* kernel: &amp;#34;Dirty Frag&amp;#34; is a new universal Local Privilege Escalation (LPE) vulnerability in the Linux kernel (CVE-2026-43284)&lt;/p&gt;
&lt;p&gt;* kernel: &amp;#34;Fragnesia&amp;#34; is a variant of Dirty Frag vulnerability in the ESP/XFRM leading to Local Privilege Escalation (LPE) vulnerability in the Linux kernel (CVE-2026-46300)&lt;/p&gt;
&lt;p&gt;* kernel: Read root-owned files as an unprivileged user (CVE-2026-46333)&lt;/p&gt;
&lt;p&gt;For more deta…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: kernel&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: net: af_can: do not leave a dangling sk pointer in can_create() (CVE-2024-56603)&lt;/p&gt;
&lt;p&gt;* kernel: net/sched: Make cake_enqueue return NET_XMIT_CN when past buffer_limit (CVE-2025-39766)&lt;/p&gt;
&lt;p&gt;* kernel: crypto: asymmetric_keys - prevent overflow in asymmetric_key_generate_id (CVE-2025-68724)&lt;/p&gt;
&lt;p&gt;* kernel: scsi: qla2xxx: Fix improper freeing of purex item (CVE-2025-68741)&lt;/p&gt;
&lt;p&gt;* kernel: Linux kernel: Use-after-free in traffic control (act_ct) may lead to denial of service or privilege escalation (CVE-2026-23270)&lt;/p&gt;
&lt;p&gt;* kernel: Linux kernel KVM: Privilege escalation or denial of service due to improper shadow page table entry handling (CVE-2026-23401)&lt;/p&gt;
&lt;p&gt;* kernel: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (CVE-2026-31402)&lt;/p&gt;
&lt;p&gt;* kernel: Bluetooth: SCO: Fix use-after-free in sco_recv_frame() due to missing sock_hold (CVE-2026-31408)&lt;/p&gt;
&lt;p&gt;* kernel: usbip: validate number_of_packets in usbip_pack_ret_submit() (CVE-2026-31607)&lt;/p&gt;
&lt;p&gt;* kernel: RDMA/umem: Fix double dma_buf_unpin in failure path (CVE-2026-43128)&lt;/p&gt;
&lt;p&gt;* kernel: &amp;#34;Dirty Frag&amp;#34; is a new universal Local Privilege Escalation (LPE) vulnerability in the Linux kernel (CVE-2026-43284)&lt;/p&gt;
&lt;p&gt;* kernel: &amp;#34;Fragnesia&amp;#34; is a variant of Dirty Frag vulnerability in the ESP/XFRM leading to Local Privilege Escalation (LPE) vulnerability in the Linux kernel (CVE-2026-46300)&lt;/p&gt;
&lt;p&gt;* kernel: Read root-owned files as an unprivileged user (CVE-2026-46333)&lt;/p&gt;
&lt;p&gt;For more deta…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:19569</guid>
    </item>
    <item>
      <title>SA26P010 — Impact of Linux Kernel vulnerabilities on B&amp;R products</title>
      <link>https://cve.radiocsirt.org/vuln/sa26p010</link>
      <description>&lt;p&gt;B&amp;amp;R is aware of publicly reported vulnerabilities affecting the Linux kernel versions shipped with the products listed as affected in the advisory.&lt;/p&gt;
&lt;p&gt;Successful local exploitation of these vulnerabilities could allow an attacker to escalate privileges on the affected system. Public proof-of-concept exploits are available for the vulnerabilities described herein. At the time of publication of this advisory, B&amp;amp;R had no evidence of active exploitation targeting B&amp;amp;R products.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;B&amp;amp;R is aware of publicly reported vulnerabilities affecting the Linux kernel versions shipped with the products listed as affected in the advisory.&lt;/p&gt;
&lt;p&gt;Successful local exploitation of these vulnerabilities could allow an attacker to escalate privileges on the affected system. Public proof-of-concept exploits are available for the vulnerabilities described herein. At the time of publication of this advisory, B&amp;amp;R had no evidence of active exploitation targeting B&amp;amp;R products.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/sa26p010</guid>
    </item>
    <item>
      <title>SSA-019113 — SSA-019113: Vulnerabilities in the additional GNU/Linux subsystem of the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1.6</title>
      <link>https://cve.radiocsirt.org/vuln/ssa-019113</link>
      <description>&lt;p&gt;Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.6 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant).&lt;/p&gt;
&lt;p&gt;Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.6 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant).&lt;/p&gt;
&lt;p&gt;Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ssa-019113</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:1778-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:1778-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:1778-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-43284</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-43284</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:Pro:18.04:LTS: linux, Ubuntu:Pro:18.04:LTS: linux-aws, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:Pro:18.04:LTS: linux-aws-5.4, Ubuntu:18.04:LTS: linux-azure, Ubuntu:Pro:18.04:LTS: linux-azure-4.15 and 233 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: xfrm: esp: avoid in-place decrypt on shared skb frags MSG_SPLICE_PAGES can attach pages from a pipe directly to an skb. TCP marks such skbs with SKBFL_SHARED_FRAG after skb_splice_from_iter(), so later paths that may modify packet data can first make a private copy. The IPv4/IPv6 datagram append paths did not set this flag when splicing pages into UDP skbs. That leaves an ESP-in-UDP packet made from shared pipe pages looking like an ordinary uncloned nonlinear skb. ESP input then takes the no-COW fast path for uncloned skbs without a frag_list and decrypts in place over data that is not owned privately by the skb. Mark IPv4/IPv6 datagram splice frags with SKBFL_SHARED_FRAG, matching TCP. Also make ESP input fall back to skb_cow_data() when the flag is present, so ESP does not decrypt externally backed frags in place. Private nonlinear skb frags still use the existing fast path. This intentionally does not change ESP output. In esp_output_head(), the path that appends the ESP trailer to existing skb tailroom without calling skb_cow_data() is not reachable for nonlinear skbs: skb_tailroom() returns zero when skb-&amp;gt;data_len is nonzero, while ESP tailen is positive. Thus ESP output will either use the separate destination-frag path or fall back to skb_cow_data().&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:Pro:18.04:LTS: linux, Ubuntu:Pro:18.04:LTS: linux-aws, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:Pro:18.04:LTS: linux-aws-5.4, Ubuntu:18.04:LTS: linux-azure, Ubuntu:Pro:18.04:LTS: linux-azure-4.15 and 233 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: xfrm: esp: avoid in-place decrypt on shared skb frags MSG_SPLICE_PAGES can attach pages from a pipe directly to an skb. TCP marks such skbs with SKBFL_SHARED_FRAG after skb_splice_from_iter(), so later paths that may modify packet data can first make a private copy. The IPv4/IPv6 datagram append paths did not set this flag when splicing pages into UDP skbs. That leaves an ESP-in-UDP packet made from shared pipe pages looking like an ordinary uncloned nonlinear skb. ESP input then takes the no-COW fast path for uncloned skbs without a frag_list and decrypts in place over data that is not owned privately by the skb. Mark IPv4/IPv6 datagram splice frags with SKBFL_SHARED_FRAG, matching TCP. Also make ESP input fall back to skb_cow_data() when the flag is present, so ESP does not decrypt externally backed frags in place. Private nonlinear skb frags still use the existing fast path. This intentionally does not change ESP output. In esp_output_head(), the path that appends the ESP trailer to existing skb tailroom without calling skb_cow_data() is not reachable for nonlinear skbs: skb_tailroom() returns zero when skb-&amp;gt;data_len is nonzero, while ESP tailen is positive. Thus ESP output will either use the separate destination-frag path or fall back to skb_cow_data().&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-43284</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1430 — Linux Kernel (Dirty Frag): Mehrere Schwachstellen ermöglichen Erlangen von Administratorrechten</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1430</link>
      <description>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um Administratorrechte zu erlangen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um Administratorrechte zu erlangen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1430</guid>
    </item>
  </channel>
</rss>
