<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 10:06:09 +0000</lastBuildDate>
    <item>
      <title>ALSA-2026:75746 — Important: kernel-rt security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:75746</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: kernel-rt, AlmaLinux:8: kernel-rt-core, AlmaLinux:8: kernel-rt-debug, AlmaLinux:8: kernel-rt-debug-core, AlmaLinux:8: kernel-rt-debug-devel, AlmaLinux:8: kernel-rt-debug-modules, AlmaLinux:8: kernel-rt-debug-modules-extra, AlmaLinux:8: kernel-rt-devel, AlmaLinux:8: kernel-rt-modules, AlmaLinux:8: kernel-rt-modules-extra&lt;/p&gt;
&lt;p&gt;The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: Linux kernel: Use-after-free in xc5000 tuner driver due to race condition (CVE-2025-39994)
  * kernel: gfs2: Fix unlikely race in gdlm_put_lock (CVE-2025-40242)
  * kernel: Linux kernel: Denial of Service in RDMA/bnxt_re driver due to race condition during QP destruction (CVE-2023-54048)
  * kernel: nvme-pci: fix mempool alloc size (CVE-2022-50756)
  * kernel: Linux kernel: Denial of Service in QFQ scheduler via child qlen manipulation (CVE-2026-23105)
  * kernel: RDMA/uverbs: Validate wqe_size before using it in ib_uverbs_post_send (CVE-2026-45856)
  * kernel: gfs2: Fix slab-use-after-free in qd_put (CVE-2026-45861)
  * kernel: net/sched: act_ct: Only release RCU read lock after ct_ft (CVE-2026-46319)
  * kernel: gfs2: add some missing log locking (CVE-2026-53049)
  * kernel: crypto: af_alg - Cap AEAD AD length to 0x80000000 (CVE-2026-52972)
  * kernel: net/mlx5: Fix slab-out-of-bounds in mlx5_query_nic_vport_mac_list (CVE-2026-53230)
  * kernel: ipvs: clear the svc scheduler ptr early on edit (CVE-2026-53270)
  * kernel: net: ip_gre: require CAP_NET_ADMIN in the device netns for changelink (CVE-2026-63829)
  * kernel: KVM: SVM: Fix page overflow in sev_dbg_crypt() for ENCRYPT path (CVE-2026-63794)
  * kernel: tunnels: do not assume transport header in iptunnel_pmtud_check_icmp() (CVE-2026-63992)…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: kernel-rt, AlmaLinux:8: kernel-rt-core, AlmaLinux:8: kernel-rt-debug, AlmaLinux:8: kernel-rt-debug-core, AlmaLinux:8: kernel-rt-debug-devel, AlmaLinux:8: kernel-rt-debug-modules, AlmaLinux:8: kernel-rt-debug-modules-extra, AlmaLinux:8: kernel-rt-devel, AlmaLinux:8: kernel-rt-modules, AlmaLinux:8: kernel-rt-modules-extra&lt;/p&gt;
&lt;p&gt;The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: Linux kernel: Use-after-free in xc5000 tuner driver due to race condition (CVE-2025-39994)
  * kernel: gfs2: Fix unlikely race in gdlm_put_lock (CVE-2025-40242)
  * kernel: Linux kernel: Denial of Service in RDMA/bnxt_re driver due to race condition during QP destruction (CVE-2023-54048)
  * kernel: nvme-pci: fix mempool alloc size (CVE-2022-50756)
  * kernel: Linux kernel: Denial of Service in QFQ scheduler via child qlen manipulation (CVE-2026-23105)
  * kernel: RDMA/uverbs: Validate wqe_size before using it in ib_uverbs_post_send (CVE-2026-45856)
  * kernel: gfs2: Fix slab-use-after-free in qd_put (CVE-2026-45861)
  * kernel: net/sched: act_ct: Only release RCU read lock after ct_ft (CVE-2026-46319)
  * kernel: gfs2: add some missing log locking (CVE-2026-53049)
  * kernel: crypto: af_alg - Cap AEAD AD length to 0x80000000 (CVE-2026-52972)
  * kernel: net/mlx5: Fix slab-out-of-bounds in mlx5_query_nic_vport_mac_list (CVE-2026-53230)
  * kernel: ipvs: clear the svc scheduler ptr early on edit (CVE-2026-53270)
  * kernel: net: ip_gre: require CAP_NET_ADMIN in the device netns for changelink (CVE-2026-63829)
  * kernel: KVM: SVM: Fix page overflow in sev_dbg_crypt() for ENCRYPT path (CVE-2026-63794)
  * kernel: tunnels: do not assume transport header in iptunnel_pmtud_check_icmp() (CVE-2026-63992)…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:75746</guid>
    </item>
    <item>
      <title>BELL-CVE-2026-74516</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-74516</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-74516</guid>
    </item>
    <item>
      <title>certfr-2026-avi-1090 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de Debian. Elles permettent à un attaquant de provo…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1090</link>
      <description>certfr-2026-avi-1090</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-1090</guid>
    </item>
    <item>
      <title>EUVD-2026-356408</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-356408</link>
      <description>EUVD-2026-356408</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-356408</guid>
    </item>
    <item>
      <title>fkie_cve-2026-74516</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-74516</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;KVM: SVM: Update x2APIC MSR intercepts if AVIC is inhibited while L2 is active&lt;/p&gt;
&lt;p&gt;Always update x2APIC MSR intercepts for L1 when AVIC is deactivated, even
if L2 is active and KVM is using a separate MSR bitmap to run L2.  If AVIC
is fully enabled prior to running L2, and is then inhibited while L2 is
active (for a VM-scoped inhibit), then KVM will run L1 with AVIC disabled,
but with x2APIC MSR intercepts disabled, i.e. will allow L1 to read most of
the host&amp;#39;s APIC state, send arbitrary interrupts, change task priority, and
ultimately trivially DoS the host.&lt;/p&gt;
&lt;p&gt;E.g. sending a self-IPI in L1 on HYPERV_REENLIGHTENMENT_VECTOR, 0xee, with
CONFIG_HYPERV=n in the host kernel as a &amp;#34;safe&amp;#34; PoC, yields:&lt;/p&gt;
&lt;p&gt;Spurious interrupt (vector 0xee) on CPU#425. Acked&lt;/p&gt;
&lt;p&gt;And hacking KVM to abuse kvm_set_posted_intr_wakeup_handler() to register a
handler and WARN on POSTED_INTR_WAKEUP_VECTOR yields:&lt;/p&gt;
&lt;p&gt;------------[ cut here ]------------
  WARNING: arch/x86/kvm/svm/svm.c:5594 at pi_wakeup_handler+0x9/0x10 [kvm_amd], CPU#156: nested_x2apic_t/316940
  CPU: 156 UID: 0 PID: 316940 Comm: nested_x2apic_t Tainted: G S   U
  Tainted: [S]=CPU_OUT_OF_SPEC, [U]=USER
  Hardware name: Google Astoria-Turin/astoria, BIOS 0.20260209.0-0 02/09/2026
  RIP: 0010:pi_wakeup_handler+0x9/0x10 [kvm_amd]
  Call Trace:
   &amp;lt;IRQ&amp;gt;
   sysvec_kvm_posted_intr_wakeup_ipi+0x64/0x80
   &amp;lt;/IRQ&amp;gt;
   &amp;lt;TASK&amp;gt;
   asm_sysvec_kvm_posted_intr_wakeup_ipi+0x1a/0x20
  RIP: 0010:vcpu…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;KVM: SVM: Update x2APIC MSR intercepts if AVIC is inhibited while L2 is active&lt;/p&gt;
&lt;p&gt;Always update x2APIC MSR intercepts for L1 when AVIC is deactivated, even
if L2 is active and KVM is using a separate MSR bitmap to run L2.  If AVIC
is fully enabled prior to running L2, and is then inhibited while L2 is
active (for a VM-scoped inhibit), then KVM will run L1 with AVIC disabled,
but with x2APIC MSR intercepts disabled, i.e. will allow L1 to read most of
the host&amp;#39;s APIC state, send arbitrary interrupts, change task priority, and
ultimately trivially DoS the host.&lt;/p&gt;
&lt;p&gt;E.g. sending a self-IPI in L1 on HYPERV_REENLIGHTENMENT_VECTOR, 0xee, with
CONFIG_HYPERV=n in the host kernel as a &amp;#34;safe&amp;#34; PoC, yields:&lt;/p&gt;
&lt;p&gt;Spurious interrupt (vector 0xee) on CPU#425. Acked&lt;/p&gt;
&lt;p&gt;And hacking KVM to abuse kvm_set_posted_intr_wakeup_handler() to register a
handler and WARN on POSTED_INTR_WAKEUP_VECTOR yields:&lt;/p&gt;
&lt;p&gt;------------[ cut here ]------------
  WARNING: arch/x86/kvm/svm/svm.c:5594 at pi_wakeup_handler+0x9/0x10 [kvm_amd], CPU#156: nested_x2apic_t/316940
  CPU: 156 UID: 0 PID: 316940 Comm: nested_x2apic_t Tainted: G S   U
  Tainted: [S]=CPU_OUT_OF_SPEC, [U]=USER
  Hardware name: Google Astoria-Turin/astoria, BIOS 0.20260209.0-0 02/09/2026
  RIP: 0010:pi_wakeup_handler+0x9/0x10 [kvm_amd]
  Call Trace:
   &amp;lt;IRQ&amp;gt;
   sysvec_kvm_posted_intr_wakeup_ipi+0x64/0x80
   &amp;lt;/IRQ&amp;gt;
   &amp;lt;TASK&amp;gt;
   asm_sysvec_kvm_posted_intr_wakeup_ipi+0x1a/0x20
  RIP: 0010:vcpu…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-74516</guid>
    </item>
    <item>
      <title>GHSA-p473-wqx8-95rq</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-p473-wqx8-95rq</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;KVM: SVM: Update x2APIC MSR intercepts if AVIC is inhibited while L2 is active&lt;/p&gt;
&lt;p&gt;Always update x2APIC MSR intercepts for L1 when AVIC is deactivated, even
if L2 is active and KVM is using a separate MSR bitmap to run L2.  If AVIC
is fully enabled prior to running L2, and is then inhibited while L2 is
active (for a VM-scoped inhibit), then KVM will run L1 with AVIC disabled,
but with x2APIC MSR intercepts disabled, i.e. will allow L1 to read most of
the host&amp;#39;s APIC state, send arbitrary interrupts, change task priority, and
ultimately trivially DoS the host.&lt;/p&gt;
&lt;p&gt;E.g. sending a self-IPI in L1 on HYPERV_REENLIGHTENMENT_VECTOR, 0xee, with
CONFIG_HYPERV=n in the host kernel as a &amp;#34;safe&amp;#34; PoC, yields:&lt;/p&gt;
&lt;p&gt;Spurious interrupt (vector 0xee) on CPU#425. Acked&lt;/p&gt;
&lt;p&gt;And hacking KVM to abuse kvm_set_posted_intr_wakeup_handler() to register a
handler and WARN on POSTED_INTR_WAKEUP_VECTOR yields:&lt;/p&gt;
&lt;p&gt;------------[ cut here ]------------
  WARNING: arch/x86/kvm/svm/svm.c:5594 at pi_wakeup_handler+0x9/0x10 [kvm_amd], CPU#156: nested_x2apic_t/316940
  CPU: 156 UID: 0 PID: 316940 Comm: nested_x2apic_t Tainted: G S   U
  Tainted: [S]=CPU_OUT_OF_SPEC, [U]=USER
  Hardware name: Google Astoria-Turin/astoria, BIOS 0.20260209.0-0 02/09/2026
  RIP: 0010:pi_wakeup_handler+0x9/0x10 [kvm_amd]
  Call Trace:
   &amp;lt;IRQ&amp;gt;
   sysvec_kvm_posted_intr_wakeup_ipi+0x64/0x80
   &amp;lt;/IRQ&amp;gt;
   &amp;lt;TASK&amp;gt;
   asm_sysvec_kvm_posted_intr_wakeup_ipi+0x1a/0x20
  RIP: 0010:vcpu…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;KVM: SVM: Update x2APIC MSR intercepts if AVIC is inhibited while L2 is active&lt;/p&gt;
&lt;p&gt;Always update x2APIC MSR intercepts for L1 when AVIC is deactivated, even
if L2 is active and KVM is using a separate MSR bitmap to run L2.  If AVIC
is fully enabled prior to running L2, and is then inhibited while L2 is
active (for a VM-scoped inhibit), then KVM will run L1 with AVIC disabled,
but with x2APIC MSR intercepts disabled, i.e. will allow L1 to read most of
the host&amp;#39;s APIC state, send arbitrary interrupts, change task priority, and
ultimately trivially DoS the host.&lt;/p&gt;
&lt;p&gt;E.g. sending a self-IPI in L1 on HYPERV_REENLIGHTENMENT_VECTOR, 0xee, with
CONFIG_HYPERV=n in the host kernel as a &amp;#34;safe&amp;#34; PoC, yields:&lt;/p&gt;
&lt;p&gt;Spurious interrupt (vector 0xee) on CPU#425. Acked&lt;/p&gt;
&lt;p&gt;And hacking KVM to abuse kvm_set_posted_intr_wakeup_handler() to register a
handler and WARN on POSTED_INTR_WAKEUP_VECTOR yields:&lt;/p&gt;
&lt;p&gt;------------[ cut here ]------------
  WARNING: arch/x86/kvm/svm/svm.c:5594 at pi_wakeup_handler+0x9/0x10 [kvm_amd], CPU#156: nested_x2apic_t/316940
  CPU: 156 UID: 0 PID: 316940 Comm: nested_x2apic_t Tainted: G S   U
  Tainted: [S]=CPU_OUT_OF_SPEC, [U]=USER
  Hardware name: Google Astoria-Turin/astoria, BIOS 0.20260209.0-0 02/09/2026
  RIP: 0010:pi_wakeup_handler+0x9/0x10 [kvm_amd]
  Call Trace:
   &amp;lt;IRQ&amp;gt;
   sysvec_kvm_posted_intr_wakeup_ipi+0x64/0x80
   &amp;lt;/IRQ&amp;gt;
   &amp;lt;TASK&amp;gt;
   asm_sysvec_kvm_posted_intr_wakeup_ipi+0x1a/0x20
  RIP: 0010:vcpu…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-p473-wqx8-95rq</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-74516 — KVM: SVM: Update x2APIC MSR intercepts if AVIC is inhibited while L2 is active</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-74516</link>
      <description>msrc_CVE-2026-74516</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-74516</guid>
    </item>
    <item>
      <title>RHSA-2026:75746 — Red Hat Security Advisory: kernel-rt security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:75746</link>
      <description>&lt;p&gt;kernel: nvme-pci: fix mempool alloc size kernel: Linux kernel: Denial of Service in RDMA/bnxt_re driver due to race condition during QP destruction kernel: Linux kernel: Use-after-free in xc5000 tuner driver due to race condition kernel: gfs2: Fix unlikely race in gdlm_put_lock kernel: Linux kernel: Denial of Service in QFQ scheduler via child qlen manipulation kernel: RDMA/uverbs: Validate wqe_size before using it in ib_uverbs_post_send kernel: gfs2: Fix slab-use-after-free in qd_put kernel: net/sched: act_ct: Only release RCU read lock after ct_ft kernel: crypto: af_alg - Cap AEAD AD length to 0x80000000 kernel: gfs2: add some missing log locking kernel: net/mlx5: Fix slab-out-of-bounds in mlx5_query_nic_vport_mac_list kernel: ipvs: clear the svc scheduler ptr early on edit kernel: KVM: SVM: Fix page overflow in sev_dbg_crypt() for ENCRYPT path kernel: net: ip_gre: require CAP_NET_ADMIN in the device netns for changelink kernel: tunnels: do not assume transport header in iptunnel_pmtud_check_icmp() kernel: tunnels: load network headers after skb_cow() in iptunnel_pmtud_build_icmp[v6]() kernel: vxlan: require CAP_NET_ADMIN in the device netns for changelink kernel: net: ip6_gre: require CAP_NET_ADMIN in the device netns for changelink kernel: netfilter: nf_queue: pin bridge device while NFQUEUE holds fake dst kernel: KVM: SVM: Update x2APIC MSR intercepts if AVIC is inhibited while L2 is active kernel: netfilter: nf_conntrack_sip: widen NAT rewrite delta to s32 in sip_help_…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;kernel: nvme-pci: fix mempool alloc size kernel: Linux kernel: Denial of Service in RDMA/bnxt_re driver due to race condition during QP destruction kernel: Linux kernel: Use-after-free in xc5000 tuner driver due to race condition kernel: gfs2: Fix unlikely race in gdlm_put_lock kernel: Linux kernel: Denial of Service in QFQ scheduler via child qlen manipulation kernel: RDMA/uverbs: Validate wqe_size before using it in ib_uverbs_post_send kernel: gfs2: Fix slab-use-after-free in qd_put kernel: net/sched: act_ct: Only release RCU read lock after ct_ft kernel: crypto: af_alg - Cap AEAD AD length to 0x80000000 kernel: gfs2: add some missing log locking kernel: net/mlx5: Fix slab-out-of-bounds in mlx5_query_nic_vport_mac_list kernel: ipvs: clear the svc scheduler ptr early on edit kernel: KVM: SVM: Fix page overflow in sev_dbg_crypt() for ENCRYPT path kernel: net: ip_gre: require CAP_NET_ADMIN in the device netns for changelink kernel: tunnels: do not assume transport header in iptunnel_pmtud_check_icmp() kernel: tunnels: load network headers after skb_cow() in iptunnel_pmtud_build_icmp[v6]() kernel: vxlan: require CAP_NET_ADMIN in the device netns for changelink kernel: net: ip6_gre: require CAP_NET_ADMIN in the device netns for changelink kernel: netfilter: nf_queue: pin bridge device while NFQUEUE holds fake dst kernel: KVM: SVM: Update x2APIC MSR intercepts if AVIC is inhibited while L2 is active kernel: netfilter: nf_conntrack_sip: widen NAT rewrite delta to s32 in sip_help_…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:75746</guid>
    </item>
    <item>
      <title>RHSA-2026:75747 — security update for kernel</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:75747</link>
      <description>&lt;p&gt;security update for kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;security update for kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:75747</guid>
    </item>
    <item>
      <title>RLSA-2026:75746 — Important: kernel-rt security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:75746</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:8: kernel-rt&lt;/p&gt;
&lt;p&gt;The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: Linux kernel: Use-after-free in xc5000 tuner driver due to race condition (CVE-2025-39994)&lt;/p&gt;
&lt;p&gt;* kernel: gfs2: Fix unlikely race in gdlm_put_lock (CVE-2025-40242)&lt;/p&gt;
&lt;p&gt;* kernel: Linux kernel: Denial of Service in RDMA/bnxt_re driver due to race condition during QP destruction (CVE-2023-54048)&lt;/p&gt;
&lt;p&gt;* kernel: nvme-pci: fix mempool alloc size (CVE-2022-50756)&lt;/p&gt;
&lt;p&gt;* kernel: Linux kernel: Denial of Service in QFQ scheduler via child qlen manipulation (CVE-2026-23105)&lt;/p&gt;
&lt;p&gt;* kernel: RDMA/uverbs: Validate wqe_size before using it in ib_uverbs_post_send (CVE-2026-45856)&lt;/p&gt;
&lt;p&gt;* kernel: gfs2: Fix slab-use-after-free in qd_put (CVE-2026-45861)&lt;/p&gt;
&lt;p&gt;* kernel: net/sched: act_ct: Only release RCU read lock after ct_ft (CVE-2026-46319)&lt;/p&gt;
&lt;p&gt;* kernel: gfs2: add some missing log locking (CVE-2026-53049)&lt;/p&gt;
&lt;p&gt;* kernel: crypto: af_alg - Cap AEAD AD length to 0x80000000 (CVE-2026-52972)&lt;/p&gt;
&lt;p&gt;* kernel: net/mlx5: Fix slab-out-of-bounds in mlx5_query_nic_vport_mac_list (CVE-2026-53230)&lt;/p&gt;
&lt;p&gt;* kernel: ipvs: clear the svc scheduler ptr early on edit (CVE-2026-53270)&lt;/p&gt;
&lt;p&gt;* kernel: net: ip_gre: require CAP_NET_ADMIN in the device netns for changelink (CVE-2026-63829)&lt;/p&gt;
&lt;p&gt;* kernel: KVM: SVM: Fix page overflow in sev_dbg_crypt() for ENCRYPT path (CVE-2026-63794)&lt;/p&gt;
&lt;p&gt;* kernel: tunnels: do not assume transport header in iptunnel_pmtud_check_icmp() (CVE-2026-63992)&lt;/p&gt;
&lt;p&gt;* kernel: tunnels: l…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:8: kernel-rt&lt;/p&gt;
&lt;p&gt;The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: Linux kernel: Use-after-free in xc5000 tuner driver due to race condition (CVE-2025-39994)&lt;/p&gt;
&lt;p&gt;* kernel: gfs2: Fix unlikely race in gdlm_put_lock (CVE-2025-40242)&lt;/p&gt;
&lt;p&gt;* kernel: Linux kernel: Denial of Service in RDMA/bnxt_re driver due to race condition during QP destruction (CVE-2023-54048)&lt;/p&gt;
&lt;p&gt;* kernel: nvme-pci: fix mempool alloc size (CVE-2022-50756)&lt;/p&gt;
&lt;p&gt;* kernel: Linux kernel: Denial of Service in QFQ scheduler via child qlen manipulation (CVE-2026-23105)&lt;/p&gt;
&lt;p&gt;* kernel: RDMA/uverbs: Validate wqe_size before using it in ib_uverbs_post_send (CVE-2026-45856)&lt;/p&gt;
&lt;p&gt;* kernel: gfs2: Fix slab-use-after-free in qd_put (CVE-2026-45861)&lt;/p&gt;
&lt;p&gt;* kernel: net/sched: act_ct: Only release RCU read lock after ct_ft (CVE-2026-46319)&lt;/p&gt;
&lt;p&gt;* kernel: gfs2: add some missing log locking (CVE-2026-53049)&lt;/p&gt;
&lt;p&gt;* kernel: crypto: af_alg - Cap AEAD AD length to 0x80000000 (CVE-2026-52972)&lt;/p&gt;
&lt;p&gt;* kernel: net/mlx5: Fix slab-out-of-bounds in mlx5_query_nic_vport_mac_list (CVE-2026-53230)&lt;/p&gt;
&lt;p&gt;* kernel: ipvs: clear the svc scheduler ptr early on edit (CVE-2026-53270)&lt;/p&gt;
&lt;p&gt;* kernel: net: ip_gre: require CAP_NET_ADMIN in the device netns for changelink (CVE-2026-63829)&lt;/p&gt;
&lt;p&gt;* kernel: KVM: SVM: Fix page overflow in sev_dbg_crypt() for ENCRYPT path (CVE-2026-63794)&lt;/p&gt;
&lt;p&gt;* kernel: tunnels: do not assume transport header in iptunnel_pmtud_check_icmp() (CVE-2026-63992)&lt;/p&gt;
&lt;p&gt;* kernel: tunnels: l…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:75746</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:23477-1 — Security update for the Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:23477-1</link>
      <description>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for the Linux Kernel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:23477-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-74516</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-74516</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 154 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: KVM: SVM: Update x2APIC MSR intercepts if AVIC is inhibited while L2 is active Always update x2APIC MSR intercepts for L1 when AVIC is deactivated, even if L2 is active and KVM is using a separate MSR bitmap to run L2.  If AVIC is fully enabled prior to running L2, and is then inhibited while L2 is active (for a VM-scoped inhibit), then KVM will run L1 with AVIC disabled, but with x2APIC MSR intercepts disabled, i.e. will allow L1 to read most of the host&amp;#39;s APIC state, send arbitrary interrupts, change task priority, and ultimately trivially DoS the host. E.g. sending a self-IPI in L1 on HYPERV_REENLIGHTENMENT_VECTOR, 0xee, with CONFIG_HYPERV=n in the host kernel as a &amp;#34;safe&amp;#34; PoC, yields:   Spurious interrupt (vector 0xee) on CPU#425. Acked And hacking KVM to abuse kvm_set_posted_intr_wakeup_handler() to register a handler and WARN on POSTED_INTR_WAKEUP_VECTOR yields:   ------------[ cut here ]------------   WARNING: arch/x86/kvm/svm/svm.c:5594 at pi_wakeup_handler+0x9/0x10 [kvm_amd], CPU#156: nested_x2apic_t/316940   CPU: 156 UID: 0 PID: 316940 Comm: nested_x2apic_t Tainted: G S   U   Tainted: [S]=CPU_OUT_OF_SPEC, [U]=USER   Hardware name: Google Astoria-Turin/astoria, BIOS 0.20260209.0-0 02/09/2026   RIP: 0010:pi_wakeup_handler+0x9/0x10 [kvm_amd]   Call Trace:    &amp;lt;IRQ&amp;gt;    sysvec_kvm_posted_intr_wakeup_ipi+0x64/0x80    &amp;lt;/IRQ&amp;gt;    &amp;lt;TASK&amp;gt;    asm_sysvec_kvm_posted_intr_wakeup_ipi+0x1a/0x20   RIP: 0010:vcpu_run+0…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 154 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: KVM: SVM: Update x2APIC MSR intercepts if AVIC is inhibited while L2 is active Always update x2APIC MSR intercepts for L1 when AVIC is deactivated, even if L2 is active and KVM is using a separate MSR bitmap to run L2.  If AVIC is fully enabled prior to running L2, and is then inhibited while L2 is active (for a VM-scoped inhibit), then KVM will run L1 with AVIC disabled, but with x2APIC MSR intercepts disabled, i.e. will allow L1 to read most of the host&amp;#39;s APIC state, send arbitrary interrupts, change task priority, and ultimately trivially DoS the host. E.g. sending a self-IPI in L1 on HYPERV_REENLIGHTENMENT_VECTOR, 0xee, with CONFIG_HYPERV=n in the host kernel as a &amp;#34;safe&amp;#34; PoC, yields:   Spurious interrupt (vector 0xee) on CPU#425. Acked And hacking KVM to abuse kvm_set_posted_intr_wakeup_handler() to register a handler and WARN on POSTED_INTR_WAKEUP_VECTOR yields:   ------------[ cut here ]------------   WARNING: arch/x86/kvm/svm/svm.c:5594 at pi_wakeup_handler+0x9/0x10 [kvm_amd], CPU#156: nested_x2apic_t/316940   CPU: 156 UID: 0 PID: 316940 Comm: nested_x2apic_t Tainted: G S   U   Tainted: [S]=CPU_OUT_OF_SPEC, [U]=USER   Hardware name: Google Astoria-Turin/astoria, BIOS 0.20260209.0-0 02/09/2026   RIP: 0010:pi_wakeup_handler+0x9/0x10 [kvm_amd]   Call Trace:    &amp;lt;IRQ&amp;gt;    sysvec_kvm_posted_intr_wakeup_ipi+0x64/0x80    &amp;lt;/IRQ&amp;gt;    &amp;lt;TASK&amp;gt;    asm_sysvec_kvm_posted_intr_wakeup_ipi+0x1a/0x20   RIP: 0010:vcpu_run+0…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-74516</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2852 — Linux Kernel: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2852</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Linux Kernel ausnutzen, um root Rechte zu erlangen, um einen Denial of Service herbeizuführen oder einen nicht näher spezifizierten Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Linux Kernel ausnutzen, um root Rechte zu erlangen, um einen Denial of Service herbeizuführen oder einen nicht näher spezifizierten Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2852</guid>
    </item>
  </channel>
</rss>
