Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在资源管理错误漏洞,该漏洞源于cifs_put_tcp_session函数在关闭服务器时,cifsd线程可能仍在尝试重新连接DFS目标,导致server->hostname被重复释放,引发空指针引用。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | 7be3248f313930ff3d3436d4e9ddbe9fccc1f541< 1ea68070338518a1d31ce71e6abfe1b30001b27a |
affected |
7be3248f313930ff3d3436d4e9ddbe9fccc1f541< a2be5f2ba34d0c6d5ef2624b24e3d852561fcd6a |
affected | ||
7be3248f313930ff3d3436d4e9ddbe9fccc1f541< fa2f9906a7b333ba757a7dbae0713d8a5396186e |
affected | ||
49f933bb3016269dc50074eac5f6033d127644f1 |
affected | ||
1c35a216ef77db708178ca225d796271f2f60a7a |
affected | ||
5.14.19< 5.15 |
affected | ||
5.15.3< 5.16 |
affected | ||
5.16 |
affected | ||
| … +4 more rows | |||
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-21680 | 7.8 HIGH | pktgen: Avoid out-of-bounds access in get_imix_entries |
| CVE-2025-21678 | 7.8 HIGH | gtp: Destroy device along with udp socket's netns dismantle. |
| CVE-2025-21677 | 7.8 HIGH | pfcp: Destroy device along with udp socket's netns dismantle. |
| CVE-2025-21669 | 7.8 HIGH | vsock/virtio: discard packets if the transport changes |
| CVE-2025-21676 | 7.5 HIGH | net: fec: handle page_pool_dev_alloc_pages error |
| CVE-2025-21682 | 7.3 HIGH | eth: bnxt: always recalculate features after XDP clearing, fix null-deref |
| CVE-2024-57948 | mac802154: check local interfaces before deleting sdata list | |
| CVE-2025-21683 | bpf: Fix bpf_sk_select_reuseport() memory leak | |
| CVE-2025-21665 | filemap: avoid truncating 64-bit offset to 32 bits | |
| CVE-2025-21666 | vsock: prevent null-ptr-deref in vsock_*[has_data|has_space] | |
| CVE-2025-21667 | iomap: avoid avoid truncating 64-bit offset to 32 bits | |
| CVE-2025-21668 | pmdomain: imx8mp-blk-ctrl: add missing loop break condition | |
| CVE-2025-21670 | vsock/bpf: return early if transport is not assigned | |
| CVE-2025-21671 | zram: fix potential UAF of zram table | |
| CVE-2025-21672 | afs: Fix merge preference rule failure condition | |
| CVE-2025-21674 | net/mlx5e: Fix inversion dependency warning while enabling IPsec tunnel | |
| CVE-2025-21675 | net/mlx5: Clear port select structure when fail to create | |
| CVE-2025-21679 | btrfs: add the missing error handling inside get_canonical_dev_path | |
| CVE-2025-21681 | openvswitch: fix lockup on tx to unregistering netdev with carrier |
No comments yet