<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from osv_rocky</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 13:08:24 +0000</lastBuildDate>
    <item>
      <title>RLSA-2026:74442 — Important: libpcap security update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:74442</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: libpcap&lt;/p&gt;
&lt;p&gt;The libpcap packages provide a portable framework for low-level network monitoring. The libpcap library provides network statistics collection, security monitoring, and network debugging.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* libpcap: libpcap: Out-of-bounds read and write vulnerability allows arbitrary memory access (CVE-2026-0799)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: libpcap&lt;/p&gt;
&lt;p&gt;The libpcap packages provide a portable framework for low-level network monitoring. The libpcap library provides network statistics collection, security monitoring, and network debugging.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* libpcap: libpcap: Out-of-bounds read and write vulnerability allows arbitrary memory access (CVE-2026-0799)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:74442</guid>
      <pubDate>Fri, 02 Oct 2026 12:09:30 +0000</pubDate>
    </item>
    <item>
      <title>RLSA-2026:74464 — Moderate: ghostscript security update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:74464</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: ghostscript&lt;/p&gt;
&lt;p&gt;The Ghostscript suite contains utilities for rendering PostScript and PDF documents. Ghostscript translates PostScript code to common bitmap formats so that the code can be displayed or printed.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* ghostscript: ghostscript: Heap buffer overflow via JPEG 2000 output adapter (CVE-2026-39919)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: ghostscript&lt;/p&gt;
&lt;p&gt;The Ghostscript suite contains utilities for rendering PostScript and PDF documents. Ghostscript translates PostScript code to common bitmap formats so that the code can be displayed or printed.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* ghostscript: ghostscript: Heap buffer overflow via JPEG 2000 output adapter (CVE-2026-39919)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:74464</guid>
      <pubDate>Fri, 02 Oct 2026 12:08:50 +0000</pubDate>
    </item>
    <item>
      <title>RLSA-2026:72785 — Important: ruby security update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:72785</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: ruby&lt;/p&gt;
&lt;p&gt;Ruby is an extensible, interpreted, object-oriented, scripting language. It has features to process text files and to perform system management tasks.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* resolv: resolv gem: Denial of Service via uncontrolled memory growth from crafted DNS responses (CVE-2026-80212)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: ruby&lt;/p&gt;
&lt;p&gt;Ruby is an extensible, interpreted, object-oriented, scripting language. It has features to process text files and to perform system management tasks.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* resolv: resolv gem: Denial of Service via uncontrolled memory growth from crafted DNS responses (CVE-2026-80212)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:72785</guid>
      <pubDate>Fri, 02 Oct 2026 12:08:50 +0000</pubDate>
    </item>
    <item>
      <title>RLSA-2026:73511 — Moderate: gawk security update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:73511</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:8: gawk&lt;/p&gt;
&lt;p&gt;The gawk packages contain the GNU version of awk, a text processing utility. Awk interprets a special-purpose programming language to do quick and easy text pattern matching and reformatting jobs.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* gawk: gawk: Memory corruption via integer overflow (CVE-2026-40468)&lt;/p&gt;
&lt;p&gt;* gawk: gawk: Denial of Service due to Use After Free vulnerability in io.c (CVE-2026-40467)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:8: gawk&lt;/p&gt;
&lt;p&gt;The gawk packages contain the GNU version of awk, a text processing utility. Awk interprets a special-purpose programming language to do quick and easy text pattern matching and reformatting jobs.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* gawk: gawk: Memory corruption via integer overflow (CVE-2026-40468)&lt;/p&gt;
&lt;p&gt;* gawk: gawk: Denial of Service due to Use After Free vulnerability in io.c (CVE-2026-40467)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:73511</guid>
      <pubDate>Fri, 02 Oct 2026 12:00:58 +0000</pubDate>
    </item>
    <item>
      <title>RLSA-2026:74370 — Important: gvfs security update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:74370</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:9: gvfs&lt;/p&gt;
&lt;p&gt;GVFS is the GNOME Desktop Virtual File System layer that allows users to easily access local and remote data using File Transfer Protocol (FTP), Secure Shell File Transfer Protocol (SFTP), Web Distributed Authoring and Versioning (WebDAV), Common Internet File System (CIFS), Server Message Block (SMB), and other protocols. GVFS integrates with the GNOME I/O (GIO) abstraction layer.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* gvfs: SFTP: heap-based buffer overflow in read_reply() (CVE-2026-84268)&lt;/p&gt;
&lt;p&gt;* gvfs: gvfs-admin socket ownership race permits local root (CVE-2026-88924)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:9: gvfs&lt;/p&gt;
&lt;p&gt;GVFS is the GNOME Desktop Virtual File System layer that allows users to easily access local and remote data using File Transfer Protocol (FTP), Secure Shell File Transfer Protocol (SFTP), Web Distributed Authoring and Versioning (WebDAV), Common Internet File System (CIFS), Server Message Block (SMB), and other protocols. GVFS integrates with the GNOME I/O (GIO) abstraction layer.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* gvfs: SFTP: heap-based buffer overflow in read_reply() (CVE-2026-84268)&lt;/p&gt;
&lt;p&gt;* gvfs: gvfs-admin socket ownership race permits local root (CVE-2026-88924)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:74370</guid>
      <pubDate>Fri, 02 Oct 2026 06:07:33 +0000</pubDate>
    </item>
    <item>
      <title>RLSA-2026:74441 — Important: libpcap security update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:74441</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:9: libpcap&lt;/p&gt;
&lt;p&gt;The libpcap packages provide a portable framework for low-level network monitoring. The libpcap library provides network statistics collection, security monitoring, and network debugging.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* libpcap: libpcap: Out-of-bounds read and write vulnerability allows arbitrary memory access (CVE-2026-0799)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:9: libpcap&lt;/p&gt;
&lt;p&gt;The libpcap packages provide a portable framework for low-level network monitoring. The libpcap library provides network statistics collection, security monitoring, and network debugging.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* libpcap: libpcap: Out-of-bounds read and write vulnerability allows arbitrary memory access (CVE-2026-0799)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:74441</guid>
      <pubDate>Fri, 02 Oct 2026 06:06:44 +0000</pubDate>
    </item>
    <item>
      <title>RLSA-2026:74132 — Moderate: kernel-rt security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:74132</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:8: kernel-rt&lt;/p&gt;
&lt;p&gt;The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: RDMA/siw: Reject MPA FPDU length underflow before signed receive math (CVE-2026-64102)&lt;/p&gt;
&lt;p&gt;* kernel: vmxnet3: fix BUG_ON in vmxnet3_get_hdr_len() for Geneve packets (CVE-2026-68299)&lt;/p&gt;
&lt;p&gt;* kernel: net/liquidio: drop cached VF pci_dev LUT (CVE-2026-72329)&lt;/p&gt;
&lt;p&gt;* kernel: dm-integrity: don&amp;#39;t increment hash_offset twice (CVE-2026-72099)&lt;/p&gt;
&lt;p&gt;Bug Fix(es) and Enhancement(s):&lt;/p&gt;
&lt;p&gt;* [Rocky Linux 8.10] &amp;#34;kernel BUG at lib/list_debug.c:28!&amp;#34;: list_add corruption in register_trace_event Rocky Linux 8.10 (JIRA:Rocky Linux-214136)&lt;/p&gt;
&lt;p&gt;* request_key_auth use-after-free on every request-key upcall since 4.18.0-553.165.1 (regression from CVE-2026-63823 backport) (JIRA:Rocky Linux-270349)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:8: kernel-rt&lt;/p&gt;
&lt;p&gt;The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: RDMA/siw: Reject MPA FPDU length underflow before signed receive math (CVE-2026-64102)&lt;/p&gt;
&lt;p&gt;* kernel: vmxnet3: fix BUG_ON in vmxnet3_get_hdr_len() for Geneve packets (CVE-2026-68299)&lt;/p&gt;
&lt;p&gt;* kernel: net/liquidio: drop cached VF pci_dev LUT (CVE-2026-72329)&lt;/p&gt;
&lt;p&gt;* kernel: dm-integrity: don&amp;#39;t increment hash_offset twice (CVE-2026-72099)&lt;/p&gt;
&lt;p&gt;Bug Fix(es) and Enhancement(s):&lt;/p&gt;
&lt;p&gt;* [Rocky Linux 8.10] &amp;#34;kernel BUG at lib/list_debug.c:28!&amp;#34;: list_add corruption in register_trace_event Rocky Linux 8.10 (JIRA:Rocky Linux-214136)&lt;/p&gt;
&lt;p&gt;* request_key_auth use-after-free on every request-key upcall since 4.18.0-553.165.1 (regression from CVE-2026-63823 backport) (JIRA:Rocky Linux-270349)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:74132</guid>
      <pubDate>Thu, 01 Oct 2026 18:02:02 +0000</pubDate>
    </item>
    <item>
      <title>RLSA-2026:73971 — Important: thunderbird security update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:73971</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:8: thunderbird&lt;/p&gt;
&lt;p&gt;Mozilla Thunderbird is a standalone mail and newsgroup client.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* firefox: thunderbird: Privilege escalation in the DOM: Workers component (CVE-2026-16365)&lt;/p&gt;
&lt;p&gt;* firefox: thunderbird: Sandbox escape in the Remote Settings Client component (CVE-2026-75874)&lt;/p&gt;
&lt;p&gt;* firefox: Sandbox escape due to use-after-free in the DOM: Security component (CVE-2026-84121)&lt;/p&gt;
&lt;p&gt;* firefox: Internally found bugs fixed in Firefox 155, Firefox ESR 153.2, Firefox ESR 140.15 and Firefox ESR 115.40 (CVE-2026-84145)&lt;/p&gt;
&lt;p&gt;* firefox: Sandbox escape due to use-after-free in the DOM: Navigation component (CVE-2026-84119)&lt;/p&gt;
&lt;p&gt;* firefox: Use-after-free in the Audio/Video component (CVE-2026-84120)&lt;/p&gt;
&lt;p&gt;* firefox: Privilege escalation due to invalid pointer in the Graphics component (CVE-2026-84131)&lt;/p&gt;
&lt;p&gt;* firefox: Use-after-free in the DOM: Core &amp;amp; HTML component (CVE-2026-84124)&lt;/p&gt;
&lt;p&gt;* firefox: Use-after-free in the Audio/Video component (CVE-2026-84122)&lt;/p&gt;
&lt;p&gt;* firefox: Internally found bugs fixed in Firefox 155, Firefox ESR 153.2 and Firefox ESR 140.15 (CVE-2026-84143)&lt;/p&gt;
&lt;p&gt;* thunderbird: Uninitialized memory in MIME parsing (CVE-2026-84639)&lt;/p&gt;
&lt;p&gt;* thunderbird: Information disclosure due to malicious IMAP server response (CVE-2026-84641)&lt;/p&gt;
&lt;p&gt;* thunderbird: One byte overflow read in mail parser (CVE-2026-84640)&lt;/p&gt;
&lt;p&gt;* firefox: thunderbird: Use-after-free in the SVG component (CVE-2026-92024)&lt;/p&gt;
&lt;p&gt;* firefox: thunderbird: Mitigation bypass in the Remote Settings Client component (CVE-2026-92019)&lt;/p&gt;
&lt;p&gt;* firefox: thunderbird: Use-after-free in the…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:8: thunderbird&lt;/p&gt;
&lt;p&gt;Mozilla Thunderbird is a standalone mail and newsgroup client.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* firefox: thunderbird: Privilege escalation in the DOM: Workers component (CVE-2026-16365)&lt;/p&gt;
&lt;p&gt;* firefox: thunderbird: Sandbox escape in the Remote Settings Client component (CVE-2026-75874)&lt;/p&gt;
&lt;p&gt;* firefox: Sandbox escape due to use-after-free in the DOM: Security component (CVE-2026-84121)&lt;/p&gt;
&lt;p&gt;* firefox: Internally found bugs fixed in Firefox 155, Firefox ESR 153.2, Firefox ESR 140.15 and Firefox ESR 115.40 (CVE-2026-84145)&lt;/p&gt;
&lt;p&gt;* firefox: Sandbox escape due to use-after-free in the DOM: Navigation component (CVE-2026-84119)&lt;/p&gt;
&lt;p&gt;* firefox: Use-after-free in the Audio/Video component (CVE-2026-84120)&lt;/p&gt;
&lt;p&gt;* firefox: Privilege escalation due to invalid pointer in the Graphics component (CVE-2026-84131)&lt;/p&gt;
&lt;p&gt;* firefox: Use-after-free in the DOM: Core &amp;amp; HTML component (CVE-2026-84124)&lt;/p&gt;
&lt;p&gt;* firefox: Use-after-free in the Audio/Video component (CVE-2026-84122)&lt;/p&gt;
&lt;p&gt;* firefox: Internally found bugs fixed in Firefox 155, Firefox ESR 153.2 and Firefox ESR 140.15 (CVE-2026-84143)&lt;/p&gt;
&lt;p&gt;* thunderbird: Uninitialized memory in MIME parsing (CVE-2026-84639)&lt;/p&gt;
&lt;p&gt;* thunderbird: Information disclosure due to malicious IMAP server response (CVE-2026-84641)&lt;/p&gt;
&lt;p&gt;* thunderbird: One byte overflow read in mail parser (CVE-2026-84640)&lt;/p&gt;
&lt;p&gt;* firefox: thunderbird: Use-after-free in the SVG component (CVE-2026-92024)&lt;/p&gt;
&lt;p&gt;* firefox: thunderbird: Mitigation bypass in the Remote Settings Client component (CVE-2026-92019)&lt;/p&gt;
&lt;p&gt;* firefox: thunderbird: Use-after-free in the…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:73971</guid>
      <pubDate>Thu, 01 Oct 2026 18:01:23 +0000</pubDate>
    </item>
    <item>
      <title>RLSA-2026:74133 — Moderate: kernel security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:74133</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:8: kernel&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: RDMA/siw: Reject MPA FPDU length underflow before signed receive math (CVE-2026-64102)&lt;/p&gt;
&lt;p&gt;* kernel: vmxnet3: fix BUG_ON in vmxnet3_get_hdr_len() for Geneve packets (CVE-2026-68299)&lt;/p&gt;
&lt;p&gt;* kernel: net/liquidio: drop cached VF pci_dev LUT (CVE-2026-72329)&lt;/p&gt;
&lt;p&gt;* kernel: dm-integrity: don&amp;#39;t increment hash_offset twice (CVE-2026-72099)&lt;/p&gt;
&lt;p&gt;Bug Fix(es) and Enhancement(s):&lt;/p&gt;
&lt;p&gt;* [Rocky Linux 8.10] &amp;#34;kernel BUG at lib/list_debug.c:28!&amp;#34;: list_add corruption in register_trace_event Rocky Linux 8.10 (JIRA:Rocky Linux-214136)&lt;/p&gt;
&lt;p&gt;* request_key_auth use-after-free on every request-key upcall since 4.18.0-553.165.1 (regression from CVE-2026-63823 backport) (JIRA:Rocky Linux-270349)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:8: kernel&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: RDMA/siw: Reject MPA FPDU length underflow before signed receive math (CVE-2026-64102)&lt;/p&gt;
&lt;p&gt;* kernel: vmxnet3: fix BUG_ON in vmxnet3_get_hdr_len() for Geneve packets (CVE-2026-68299)&lt;/p&gt;
&lt;p&gt;* kernel: net/liquidio: drop cached VF pci_dev LUT (CVE-2026-72329)&lt;/p&gt;
&lt;p&gt;* kernel: dm-integrity: don&amp;#39;t increment hash_offset twice (CVE-2026-72099)&lt;/p&gt;
&lt;p&gt;Bug Fix(es) and Enhancement(s):&lt;/p&gt;
&lt;p&gt;* [Rocky Linux 8.10] &amp;#34;kernel BUG at lib/list_debug.c:28!&amp;#34;: list_add corruption in register_trace_event Rocky Linux 8.10 (JIRA:Rocky Linux-214136)&lt;/p&gt;
&lt;p&gt;* request_key_auth use-after-free on every request-key upcall since 4.18.0-553.165.1 (regression from CVE-2026-63823 backport) (JIRA:Rocky Linux-270349)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:74133</guid>
      <pubDate>Thu, 01 Oct 2026 18:00:58 +0000</pubDate>
    </item>
    <item>
      <title>RLSA-2026:74095 — Important: rsync security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:74095</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:8: rsync&lt;/p&gt;
&lt;p&gt;The rsync utility enables the users to copy and synchronize files locally or across a network. Synchronization with rsync is fast because rsync only sends the differences in files over the network instead of sending whole files. The rsync utility is also used as a mirroring tool.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* rsync: rsync 2.3.3 &amp;lt; 3.5.0 Path Traversal via --partial-dir/--backup-dir Symlink (CVE-2026-70460)&lt;/p&gt;
&lt;p&gt;* rsync: rsync: Arbitrary file deletion via malicious file list (CVE-2026-53789)&lt;/p&gt;
&lt;p&gt;* rsync: rsync &amp;lt; 3.5.0 Command Injection via Multiple Code Paths (CVE-2026-53790)&lt;/p&gt;
&lt;p&gt;* rsync: rsync: Memory corruption via crafted file entries (CVE-2026-70458)&lt;/p&gt;
&lt;p&gt;* rsync: rsync: Denial of Service via handshake stall (CVE-2026-70464)&lt;/p&gt;
&lt;p&gt;* rsync: rsync: Local Privilege Escalation via Symlink Following (CVE-2026-53803)&lt;/p&gt;
&lt;p&gt;* rsync: rsync: Unauthorized File Access via Symlink Module Root (CVE-2026-53784)&lt;/p&gt;
&lt;p&gt;* rsync: rsync: Authorization bypass via `auth users` directive parsing (CVE-2026-70463)&lt;/p&gt;
&lt;p&gt;* rsync: rsync 3.1.0 &amp;lt; 3.5.0 Access Control Bypass via DNS Resolution Failure (CVE-2026-70452)&lt;/p&gt;
&lt;p&gt;* rsync: rsync: Arbitrary file write via --temp-dir or --link-dest options (CVE-2026-53795)&lt;/p&gt;
&lt;p&gt;* rsync: rsync: Heap Out-of-Bounds Write via crafted argument list (CVE-2026-70456)&lt;/p&gt;
&lt;p&gt;* rsync: rsync &amp;lt; 3.5.0 Path Confinement Bypass via /./ Boundary Marker in Chroot Mode (CVE-2026-53793)&lt;/p&gt;
&lt;p&gt;* rsync: rsync: Denial of Service via Algorithmic Complexity (CVE-2026-70453)&lt;/p&gt;
&lt;p&gt;* rsync: rsync: Information disclosure and denial of service via craft…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:8: rsync&lt;/p&gt;
&lt;p&gt;The rsync utility enables the users to copy and synchronize files locally or across a network. Synchronization with rsync is fast because rsync only sends the differences in files over the network instead of sending whole files. The rsync utility is also used as a mirroring tool.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* rsync: rsync 2.3.3 &amp;lt; 3.5.0 Path Traversal via --partial-dir/--backup-dir Symlink (CVE-2026-70460)&lt;/p&gt;
&lt;p&gt;* rsync: rsync: Arbitrary file deletion via malicious file list (CVE-2026-53789)&lt;/p&gt;
&lt;p&gt;* rsync: rsync &amp;lt; 3.5.0 Command Injection via Multiple Code Paths (CVE-2026-53790)&lt;/p&gt;
&lt;p&gt;* rsync: rsync: Memory corruption via crafted file entries (CVE-2026-70458)&lt;/p&gt;
&lt;p&gt;* rsync: rsync: Denial of Service via handshake stall (CVE-2026-70464)&lt;/p&gt;
&lt;p&gt;* rsync: rsync: Local Privilege Escalation via Symlink Following (CVE-2026-53803)&lt;/p&gt;
&lt;p&gt;* rsync: rsync: Unauthorized File Access via Symlink Module Root (CVE-2026-53784)&lt;/p&gt;
&lt;p&gt;* rsync: rsync: Authorization bypass via `auth users` directive parsing (CVE-2026-70463)&lt;/p&gt;
&lt;p&gt;* rsync: rsync 3.1.0 &amp;lt; 3.5.0 Access Control Bypass via DNS Resolution Failure (CVE-2026-70452)&lt;/p&gt;
&lt;p&gt;* rsync: rsync: Arbitrary file write via --temp-dir or --link-dest options (CVE-2026-53795)&lt;/p&gt;
&lt;p&gt;* rsync: rsync: Heap Out-of-Bounds Write via crafted argument list (CVE-2026-70456)&lt;/p&gt;
&lt;p&gt;* rsync: rsync &amp;lt; 3.5.0 Path Confinement Bypass via /./ Boundary Marker in Chroot Mode (CVE-2026-53793)&lt;/p&gt;
&lt;p&gt;* rsync: rsync: Denial of Service via Algorithmic Complexity (CVE-2026-70453)&lt;/p&gt;
&lt;p&gt;* rsync: rsync: Information disclosure and denial of service via craft…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:74095</guid>
      <pubDate>Thu, 01 Oct 2026 18:00:58 +0000</pubDate>
    </item>
  </channel>
</rss>
