<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from osv_rocky</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 08:00:37 +0000</lastBuildDate>
    <item>
      <title>RLSA-2026:71658 — Important: python-cryptography security update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:71658</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: python-cryptography&lt;/p&gt;
&lt;p&gt;Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* python-cryptography: python-cryptography: Duplicate self-signed intermediates can cause exponential path-building (CVE-2026-69249)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: python-cryptography&lt;/p&gt;
&lt;p&gt;Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* python-cryptography: python-cryptography: Duplicate self-signed intermediates can cause exponential path-building (CVE-2026-69249)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:71658</guid>
      <pubDate>Sat, 26 Sep 2026 12:12:16 +0000</pubDate>
    </item>
    <item>
      <title>RLSA-2026:73998 — Important: gvfs security update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:73998</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: gvfs&lt;/p&gt;
&lt;p&gt;GVFS is the GNOME Desktop Virtual File System layer that allows users to easily access local and remote data using File Transfer Protocol (FTP), Secure Shell File Transfer Protocol (SFTP), Web Distributed Authoring and Versioning (WebDAV), Common Internet File System (CIFS), Server Message Block (SMB), and other protocols. GVFS integrates with the GNOME I/O (GIO) abstraction layer.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* gvfs: SFTP: heap-based buffer overflow in read_reply() (CVE-2026-84268)&lt;/p&gt;
&lt;p&gt;* gvfs: gvfs-admin socket ownership race permits local root (CVE-2026-88924)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: gvfs&lt;/p&gt;
&lt;p&gt;GVFS is the GNOME Desktop Virtual File System layer that allows users to easily access local and remote data using File Transfer Protocol (FTP), Secure Shell File Transfer Protocol (SFTP), Web Distributed Authoring and Versioning (WebDAV), Common Internet File System (CIFS), Server Message Block (SMB), and other protocols. GVFS integrates with the GNOME I/O (GIO) abstraction layer.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* gvfs: SFTP: heap-based buffer overflow in read_reply() (CVE-2026-84268)&lt;/p&gt;
&lt;p&gt;* gvfs: gvfs-admin socket ownership race permits local root (CVE-2026-88924)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:73998</guid>
      <pubDate>Thu, 01 Oct 2026 12:08:49 +0000</pubDate>
    </item>
    <item>
      <title>RLSA-2026:74001 — Important: expat security update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:74001</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: expat&lt;/p&gt;
&lt;p&gt;Expat is a C library for parsing XML documents.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* expat: Expat: Denial of Service via quadratic complexity in attribute processing (CVE-2026-66046)&lt;/p&gt;
&lt;p&gt;* expat: Expat: XML Injection via Malformed UTF-16 Input (CVE-2026-93990)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: expat&lt;/p&gt;
&lt;p&gt;Expat is a C library for parsing XML documents.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* expat: Expat: Denial of Service via quadratic complexity in attribute processing (CVE-2026-66046)&lt;/p&gt;
&lt;p&gt;* expat: Expat: XML Injection via Malformed UTF-16 Input (CVE-2026-93990)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:74001</guid>
      <pubDate>Thu, 01 Oct 2026 12:08:49 +0000</pubDate>
    </item>
    <item>
      <title>RLSA-2026:73954 — Moderate: openssh security update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:73954</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: openssh&lt;/p&gt;
&lt;p&gt;OpenSSH is an SSH protocol implementation supported by a number of Linux, UNIX, and similar operating systems. It includes the core files necessary for both the OpenSSH client and server.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* openssh: OpenSSH: Brute-force attacks facilitated due to insufficient authentication delay (CVE-2026-60001)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: openssh&lt;/p&gt;
&lt;p&gt;OpenSSH is an SSH protocol implementation supported by a number of Linux, UNIX, and similar operating systems. It includes the core files necessary for both the OpenSSH client and server.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* openssh: OpenSSH: Brute-force attacks facilitated due to insufficient authentication delay (CVE-2026-60001)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:73954</guid>
      <pubDate>Thu, 01 Oct 2026 12:08:49 +0000</pubDate>
    </item>
    <item>
      <title>RLSA-2026:73765 — Important: dogtag-pki security update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:73765</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: dogtag-pki&lt;/p&gt;
&lt;p&gt;IdM PKI is an enterprise software system designed to manage enterprise Public Key Infrastructure deployments.  IdM PKI consists of the following components: 
  * Certificate Authority (CA)
  * Key Recovery Authority (KRA)
  * Online Certificate Status Protocol (OCSP) Manager
  * Token Key Service (TKS)
  * Token Processing Service (TPS)
  * Automatic Certificate Management Environment (ACME) Responder
  * Enrollment over Secure Transport (EST) Responder&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* pki-core: Dogtag/PKI: certprofile-import allows code execution via unsanitized profile content (ExternalProcessConstraint) (CVE-2026-76561)&lt;/p&gt;
&lt;p&gt;* pki-core: Dogtag PKI v2 REST ACL filter&amp;#39;s reverse-lexicographic tie-break lets a CA Agent invoke the admin-only raw profile creation endpoint (CVE-2026-80110)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: dogtag-pki&lt;/p&gt;
&lt;p&gt;IdM PKI is an enterprise software system designed to manage enterprise Public Key Infrastructure deployments.  IdM PKI consists of the following components: 
  * Certificate Authority (CA)
  * Key Recovery Authority (KRA)
  * Online Certificate Status Protocol (OCSP) Manager
  * Token Key Service (TKS)
  * Token Processing Service (TPS)
  * Automatic Certificate Management Environment (ACME) Responder
  * Enrollment over Secure Transport (EST) Responder&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* pki-core: Dogtag/PKI: certprofile-import allows code execution via unsanitized profile content (ExternalProcessConstraint) (CVE-2026-76561)&lt;/p&gt;
&lt;p&gt;* pki-core: Dogtag PKI v2 REST ACL filter&amp;#39;s reverse-lexicographic tie-break lets a CA Agent invoke the admin-only raw profile creation endpoint (CVE-2026-80110)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:73765</guid>
      <pubDate>Thu, 01 Oct 2026 12:08:49 +0000</pubDate>
    </item>
    <item>
      <title>RLSA-2026:73429 — Moderate: gawk security update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:73429</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: gawk&lt;/p&gt;
&lt;p&gt;The gawk packages contain the GNU version of awk, a text processing utility. Awk interprets a special-purpose programming language to do quick and easy text pattern matching and reformatting jobs.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* gawk: gawk: Memory corruption via integer overflow (CVE-2026-40468)&lt;/p&gt;
&lt;p&gt;* gawk: Gawk: Buffer overflow in ftype() routine may lead to code execution or denial of service (CVE-2026-40553)&lt;/p&gt;
&lt;p&gt;* gawk: gawk: Denial of Service due to Use After Free vulnerability in io.c (CVE-2026-40467)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: gawk&lt;/p&gt;
&lt;p&gt;The gawk packages contain the GNU version of awk, a text processing utility. Awk interprets a special-purpose programming language to do quick and easy text pattern matching and reformatting jobs.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* gawk: gawk: Memory corruption via integer overflow (CVE-2026-40468)&lt;/p&gt;
&lt;p&gt;* gawk: Gawk: Buffer overflow in ftype() routine may lead to code execution or denial of service (CVE-2026-40553)&lt;/p&gt;
&lt;p&gt;* gawk: gawk: Denial of Service due to Use After Free vulnerability in io.c (CVE-2026-40467)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:73429</guid>
      <pubDate>Wed, 30 Sep 2026 12:10:38 +0000</pubDate>
    </item>
    <item>
      <title>RLSA-2026:73428 — Important: nodejs24 security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:73428</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: nodejs24&lt;/p&gt;
&lt;p&gt;Node.js is a platform built on Chrome&amp;#39;s JavaScript runtime for easily building fast, scalable network applications. Node.js uses an event-driven, non-blocking I/O model that makes it lightweight and efficient, perfect for data-intensive real-time applications that run across distributed devices.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* undici: undici: Authentication bypass via cross-origin cache poisoning due to missing origin isolation (CVE-2026-85152)&lt;/p&gt;
&lt;p&gt;* undici: undici: TLS certificate validation bypass in BalancedPool via dropped connect options (CVE-2026-84961)&lt;/p&gt;
&lt;p&gt;* undici: undici: Denial of Service via unrequested WebSocket subprotocol (CVE-2026-19534)&lt;/p&gt;
&lt;p&gt;Bug Fix(es) and Enhancement(s):&lt;/p&gt;
&lt;p&gt;* nodejs24: Rebase to the latest Node.js 24 release [rhel-10] (JIRA:Rocky Linux-249187)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: nodejs24&lt;/p&gt;
&lt;p&gt;Node.js is a platform built on Chrome&amp;#39;s JavaScript runtime for easily building fast, scalable network applications. Node.js uses an event-driven, non-blocking I/O model that makes it lightweight and efficient, perfect for data-intensive real-time applications that run across distributed devices.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* undici: undici: Authentication bypass via cross-origin cache poisoning due to missing origin isolation (CVE-2026-85152)&lt;/p&gt;
&lt;p&gt;* undici: undici: TLS certificate validation bypass in BalancedPool via dropped connect options (CVE-2026-84961)&lt;/p&gt;
&lt;p&gt;* undici: undici: Denial of Service via unrequested WebSocket subprotocol (CVE-2026-19534)&lt;/p&gt;
&lt;p&gt;Bug Fix(es) and Enhancement(s):&lt;/p&gt;
&lt;p&gt;* nodejs24: Rebase to the latest Node.js 24 release [rhel-10] (JIRA:Rocky Linux-249187)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:73428</guid>
      <pubDate>Thu, 01 Oct 2026 12:08:49 +0000</pubDate>
    </item>
    <item>
      <title>RLSA-2026:73427 — Important: gdb security update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:73427</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: gdb&lt;/p&gt;
&lt;p&gt;The GNU Debugger (GDB) allows debugging of programs written in C, C++, and
other languages by executing them in a controlled fashion and printing their
data.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* gdb: Out-of-bounds write in STABS parser read_member_functions() via crafted ELF (CVE-2026-13732)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: gdb&lt;/p&gt;
&lt;p&gt;The GNU Debugger (GDB) allows debugging of programs written in C, C++, and
other languages by executing them in a controlled fashion and printing their
data.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* gdb: Out-of-bounds write in STABS parser read_member_functions() via crafted ELF (CVE-2026-13732)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:73427</guid>
      <pubDate>Wed, 30 Sep 2026 12:10:38 +0000</pubDate>
    </item>
    <item>
      <title>RLSA-2026:73130 — Important: thunderbird security update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:73130</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: thunderbird&lt;/p&gt;
&lt;p&gt;Mozilla Thunderbird is a standalone mail and newsgroup client.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* firefox: thunderbird: Privilege escalation in the DOM: Workers component (CVE-2026-16365)&lt;/p&gt;
&lt;p&gt;* firefox: thunderbird: Sandbox escape in the Remote Settings Client component (CVE-2026-75874)&lt;/p&gt;
&lt;p&gt;* firefox: Sandbox escape due to use-after-free in the DOM: Security component (CVE-2026-84121)&lt;/p&gt;
&lt;p&gt;* firefox: Internally found bugs fixed in Firefox 155, Firefox ESR 153.2, Firefox ESR 140.15 and Firefox ESR 115.40 (CVE-2026-84145)&lt;/p&gt;
&lt;p&gt;* firefox: Sandbox escape due to use-after-free in the DOM: Navigation component (CVE-2026-84119)&lt;/p&gt;
&lt;p&gt;* firefox: Use-after-free in the Audio/Video component (CVE-2026-84120)&lt;/p&gt;
&lt;p&gt;* firefox: Privilege escalation due to invalid pointer in the Graphics component (CVE-2026-84131)&lt;/p&gt;
&lt;p&gt;* firefox: Use-after-free in the DOM: Core &amp;amp; HTML component (CVE-2026-84124)&lt;/p&gt;
&lt;p&gt;* firefox: Use-after-free in the Audio/Video component (CVE-2026-84122)&lt;/p&gt;
&lt;p&gt;* firefox: Internally found bugs fixed in Firefox 155, Firefox ESR 153.2 and Firefox ESR 140.15 (CVE-2026-84143)&lt;/p&gt;
&lt;p&gt;* thunderbird: Uninitialized memory in MIME parsing (CVE-2026-84639)&lt;/p&gt;
&lt;p&gt;* thunderbird: Information disclosure due to malicious IMAP server response (CVE-2026-84641)&lt;/p&gt;
&lt;p&gt;* thunderbird: One byte overflow read in mail parser (CVE-2026-84640)&lt;/p&gt;
&lt;p&gt;* firefox: thunderbird: Use-after-free in the SVG component (CVE-2026-92024)&lt;/p&gt;
&lt;p&gt;* firefox: thunderbird: Mitigation bypass in the Remote Settings Client component (CVE-2026-92019)&lt;/p&gt;
&lt;p&gt;* firefox: thunderbird: Use-after-free in the…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: thunderbird&lt;/p&gt;
&lt;p&gt;Mozilla Thunderbird is a standalone mail and newsgroup client.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* firefox: thunderbird: Privilege escalation in the DOM: Workers component (CVE-2026-16365)&lt;/p&gt;
&lt;p&gt;* firefox: thunderbird: Sandbox escape in the Remote Settings Client component (CVE-2026-75874)&lt;/p&gt;
&lt;p&gt;* firefox: Sandbox escape due to use-after-free in the DOM: Security component (CVE-2026-84121)&lt;/p&gt;
&lt;p&gt;* firefox: Internally found bugs fixed in Firefox 155, Firefox ESR 153.2, Firefox ESR 140.15 and Firefox ESR 115.40 (CVE-2026-84145)&lt;/p&gt;
&lt;p&gt;* firefox: Sandbox escape due to use-after-free in the DOM: Navigation component (CVE-2026-84119)&lt;/p&gt;
&lt;p&gt;* firefox: Use-after-free in the Audio/Video component (CVE-2026-84120)&lt;/p&gt;
&lt;p&gt;* firefox: Privilege escalation due to invalid pointer in the Graphics component (CVE-2026-84131)&lt;/p&gt;
&lt;p&gt;* firefox: Use-after-free in the DOM: Core &amp;amp; HTML component (CVE-2026-84124)&lt;/p&gt;
&lt;p&gt;* firefox: Use-after-free in the Audio/Video component (CVE-2026-84122)&lt;/p&gt;
&lt;p&gt;* firefox: Internally found bugs fixed in Firefox 155, Firefox ESR 153.2 and Firefox ESR 140.15 (CVE-2026-84143)&lt;/p&gt;
&lt;p&gt;* thunderbird: Uninitialized memory in MIME parsing (CVE-2026-84639)&lt;/p&gt;
&lt;p&gt;* thunderbird: Information disclosure due to malicious IMAP server response (CVE-2026-84641)&lt;/p&gt;
&lt;p&gt;* thunderbird: One byte overflow read in mail parser (CVE-2026-84640)&lt;/p&gt;
&lt;p&gt;* firefox: thunderbird: Use-after-free in the SVG component (CVE-2026-92024)&lt;/p&gt;
&lt;p&gt;* firefox: thunderbird: Mitigation bypass in the Remote Settings Client component (CVE-2026-92019)&lt;/p&gt;
&lt;p&gt;* firefox: thunderbird: Use-after-free in the…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:73130</guid>
      <pubDate>Wed, 30 Sep 2026 12:10:38 +0000</pubDate>
    </item>
    <item>
      <title>RLSA-2026:72624 — Important: kernel security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:72624</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: kernel&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: KVM: nSVM: Raise #UD if unhandled VMMCALL isn&amp;#39;t intercepted by L1 (CVE-2026-46076)&lt;/p&gt;
&lt;p&gt;* kernel: ext4: fix e4b bitmap inconsistency reports (CVE-2026-45942)&lt;/p&gt;
&lt;p&gt;* kernel: KVM: arm64: Reassign nested_mmus array behind mmu_lock (CVE-2026-46317)&lt;/p&gt;
&lt;p&gt;* kernel: fhandle: fix UAF due to unlocked -&amp;gt;mnt_ns read in may_decode_fh() (CVE-2026-53341)&lt;/p&gt;
&lt;p&gt;* kernel: perf/core: Detach event groups during remove_on_exec (CVE-2026-64556)&lt;/p&gt;
&lt;p&gt;* kernel: vmxnet3: fix BUG_ON in vmxnet3_get_hdr_len() for Geneve packets (CVE-2026-68299)&lt;/p&gt;
&lt;p&gt;* kernel: crypto: tegra - fix rctx-&amp;gt;cryptlen calculation in tegra_gcm_do_one_req() (CVE-2026-80522)&lt;/p&gt;
&lt;p&gt;* kernel: perf: Reject exited events as group leaders (CVE-2026-74753)&lt;/p&gt;
&lt;p&gt;* kernel: nvme-tcp: reject a read that transferred too few bytes (CVE-2026-89480)&lt;/p&gt;
&lt;p&gt;* kernel: KVM: arm64: Handle negative S1 walk levels in VNCR TLB size evaluation (CVE-2026-89775)&lt;/p&gt;
&lt;p&gt;Bug Fix(es) and Enhancement(s):&lt;/p&gt;
&lt;p&gt;* KVM: s390: Limit adapter indicator access to mapped page [rhel-10.2.z] (JIRA:Rocky Linux-188661)&lt;/p&gt;
&lt;p&gt;* crypto: xxhash64 should not be fips approved [rhel-10.2.z] (JIRA:Rocky Linux-254943)&lt;/p&gt;
&lt;p&gt;* kata-tdx TD vCPU stuck at reset vector (EIP=0xFFF0) on Intel Xeon 6 (Granite Rapids / Sierra Forest) ? guest never executes. (10.2.z) (JIRA:Rocky Linux-260402)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: kernel&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: KVM: nSVM: Raise #UD if unhandled VMMCALL isn&amp;#39;t intercepted by L1 (CVE-2026-46076)&lt;/p&gt;
&lt;p&gt;* kernel: ext4: fix e4b bitmap inconsistency reports (CVE-2026-45942)&lt;/p&gt;
&lt;p&gt;* kernel: KVM: arm64: Reassign nested_mmus array behind mmu_lock (CVE-2026-46317)&lt;/p&gt;
&lt;p&gt;* kernel: fhandle: fix UAF due to unlocked -&amp;gt;mnt_ns read in may_decode_fh() (CVE-2026-53341)&lt;/p&gt;
&lt;p&gt;* kernel: perf/core: Detach event groups during remove_on_exec (CVE-2026-64556)&lt;/p&gt;
&lt;p&gt;* kernel: vmxnet3: fix BUG_ON in vmxnet3_get_hdr_len() for Geneve packets (CVE-2026-68299)&lt;/p&gt;
&lt;p&gt;* kernel: crypto: tegra - fix rctx-&amp;gt;cryptlen calculation in tegra_gcm_do_one_req() (CVE-2026-80522)&lt;/p&gt;
&lt;p&gt;* kernel: perf: Reject exited events as group leaders (CVE-2026-74753)&lt;/p&gt;
&lt;p&gt;* kernel: nvme-tcp: reject a read that transferred too few bytes (CVE-2026-89480)&lt;/p&gt;
&lt;p&gt;* kernel: KVM: arm64: Handle negative S1 walk levels in VNCR TLB size evaluation (CVE-2026-89775)&lt;/p&gt;
&lt;p&gt;Bug Fix(es) and Enhancement(s):&lt;/p&gt;
&lt;p&gt;* KVM: s390: Limit adapter indicator access to mapped page [rhel-10.2.z] (JIRA:Rocky Linux-188661)&lt;/p&gt;
&lt;p&gt;* crypto: xxhash64 should not be fips approved [rhel-10.2.z] (JIRA:Rocky Linux-254943)&lt;/p&gt;
&lt;p&gt;* kata-tdx TD vCPU stuck at reset vector (EIP=0xFFF0) on Intel Xeon 6 (Granite Rapids / Sierra Forest) ? guest never executes. (10.2.z) (JIRA:Rocky Linux-260402)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:72624</guid>
      <pubDate>Wed, 30 Sep 2026 12:10:38 +0000</pubDate>
    </item>
  </channel>
</rss>
