<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 07:02:58 +0000</lastBuildDate>
    <item>
      <title>BELL-CVE-2026-74754</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-74754</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-74754</guid>
    </item>
    <item>
      <title>EUVD-2026-359153</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-359153</link>
      <description>EUVD-2026-359153</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-359153</guid>
    </item>
    <item>
      <title>fkie_cve-2026-74754</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-74754</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;scsi: core: pair EH runtime PM get and put&lt;/p&gt;
&lt;p&gt;shost-&amp;gt;eh_noresume is currently consulted twice in one error handling
iteration: once before scsi_autopm_get_host() and once again before
scsi_autopm_put_host().&lt;/p&gt;
&lt;p&gt;That is racy when a PM-triggered error path flips shost-&amp;gt;eh_noresume
while the SCSI EH thread is still running.&lt;/p&gt;
&lt;p&gt;The problem flow looks like this:
PM path
  ufshcd_set_dev_pwr_mode()
    shost-&amp;gt;eh_noresume = 1
    ufshcd_execute_start_stop  &amp;lt;-- trigger EH
    ...
    shost-&amp;gt;eh_noresume = 0&lt;/p&gt;
&lt;p&gt;EH path
  scsi_error_handler()
    if (!shost-&amp;gt;eh_noresume)
      scsi_autopm_get_host()  &amp;lt;-- skipped
    ...
    if (!shost-&amp;gt;eh_noresume)
       scsi_autopm_put_host()  &amp;lt;-- executed later&lt;/p&gt;
&lt;p&gt;In that case one EH iteration can skip autoresume on entry and still
drop a runtime PM reference on exit. That leaves an unmatched runtime PM
put and can trigger a runtime PM usage count underflow.&lt;/p&gt;
&lt;p&gt;Fix this by making eh_noresume a regular bool so it can be accessed with
READ_ONCE() and WRITE_ONCE(). Snapshot it once per EH iteration and use
that snapshot for both runtime PM get and put decisions.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;scsi: core: pair EH runtime PM get and put&lt;/p&gt;
&lt;p&gt;shost-&amp;gt;eh_noresume is currently consulted twice in one error handling
iteration: once before scsi_autopm_get_host() and once again before
scsi_autopm_put_host().&lt;/p&gt;
&lt;p&gt;That is racy when a PM-triggered error path flips shost-&amp;gt;eh_noresume
while the SCSI EH thread is still running.&lt;/p&gt;
&lt;p&gt;The problem flow looks like this:
PM path
  ufshcd_set_dev_pwr_mode()
    shost-&amp;gt;eh_noresume = 1
    ufshcd_execute_start_stop  &amp;lt;-- trigger EH
    ...
    shost-&amp;gt;eh_noresume = 0&lt;/p&gt;
&lt;p&gt;EH path
  scsi_error_handler()
    if (!shost-&amp;gt;eh_noresume)
      scsi_autopm_get_host()  &amp;lt;-- skipped
    ...
    if (!shost-&amp;gt;eh_noresume)
       scsi_autopm_put_host()  &amp;lt;-- executed later&lt;/p&gt;
&lt;p&gt;In that case one EH iteration can skip autoresume on entry and still
drop a runtime PM reference on exit. That leaves an unmatched runtime PM
put and can trigger a runtime PM usage count underflow.&lt;/p&gt;
&lt;p&gt;Fix this by making eh_noresume a regular bool so it can be accessed with
READ_ONCE() and WRITE_ONCE(). Snapshot it once per EH iteration and use
that snapshot for both runtime PM get and put decisions.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-74754</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-74754 — scsi: core: pair EH runtime PM get and put</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-74754</link>
      <description>msrc_CVE-2026-74754</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-74754</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-74754</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-74754</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux, Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe and 247 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: scsi: core: pair EH runtime PM get and put shost-&amp;gt;eh_noresume is currently consulted twice in one error handling iteration: once before scsi_autopm_get_host() and once again before scsi_autopm_put_host(). That is racy when a PM-triggered error path flips shost-&amp;gt;eh_noresume while the SCSI EH thread is still running. The problem flow looks like this: PM path   ufshcd_set_dev_pwr_mode()     shost-&amp;gt;eh_noresume = 1     ufshcd_execute_start_stop  &amp;lt;-- trigger EH     ...     shost-&amp;gt;eh_noresume = 0 EH path   scsi_error_handler()     if (!shost-&amp;gt;eh_noresume)       scsi_autopm_get_host()  &amp;lt;-- skipped     ...     if (!shost-&amp;gt;eh_noresume)        scsi_autopm_put_host()  &amp;lt;-- executed later In that case one EH iteration can skip autoresume on entry and still drop a runtime PM reference on exit. That leaves an unmatched runtime PM put and can trigger a runtime PM usage count underflow. Fix this by making eh_noresume a regular bool so it can be accessed with READ_ONCE() and WRITE_ONCE(). Snapshot it once per EH iteration and use that snapshot for both runtime PM get and put decisions.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux, Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe and 247 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: scsi: core: pair EH runtime PM get and put shost-&amp;gt;eh_noresume is currently consulted twice in one error handling iteration: once before scsi_autopm_get_host() and once again before scsi_autopm_put_host(). That is racy when a PM-triggered error path flips shost-&amp;gt;eh_noresume while the SCSI EH thread is still running. The problem flow looks like this: PM path   ufshcd_set_dev_pwr_mode()     shost-&amp;gt;eh_noresume = 1     ufshcd_execute_start_stop  &amp;lt;-- trigger EH     ...     shost-&amp;gt;eh_noresume = 0 EH path   scsi_error_handler()     if (!shost-&amp;gt;eh_noresume)       scsi_autopm_get_host()  &amp;lt;-- skipped     ...     if (!shost-&amp;gt;eh_noresume)        scsi_autopm_put_host()  &amp;lt;-- executed later In that case one EH iteration can skip autoresume on entry and still drop a runtime PM reference on exit. That leaves an unmatched runtime PM put and can trigger a runtime PM usage count underflow. Fix this by making eh_noresume a regular bool so it can be accessed with READ_ONCE() and WRITE_ONCE(). Snapshot it once per EH iteration and use that snapshot for both runtime PM get and put decisions.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-74754</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-3042 — Linux Kernel: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3042</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen, darunter möglicherweise die Ausführung von beliebigem Code, die Ausweitung von Berechtigungen, die Offenlegung von Informationen, die Manipulation von Daten oder Denial-of-Service-Zustände.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen, darunter möglicherweise die Ausführung von beliebigem Code, die Ausweitung von Berechtigungen, die Offenlegung von Informationen, die Manipulation von Daten oder Denial-of-Service-Zustände.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3042</guid>
    </item>
  </channel>
</rss>
