Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于未检查add_sidecar回调是否为空,可能导致空指针取消引用。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | da5244180281a18c4c7859674fec308514aaf629< aea038062edfca9c6e5ddcecd4611d5a80113b4e |
affected |
da5244180281a18c4c7859674fec308514aaf629< a5416c0fc9e77b69f853dfb1e78bc05a7c06a789 |
affected | ||
da5244180281a18c4c7859674fec308514aaf629< 87cab86925b7fa4c1c977bc191ac549a3b23f0ea |
affected | ||
6.10 |
affected | ||
< 6.10 |
unaffected | ||
6.12.53≤ 6.12.* |
unaffected | ||
6.17.3≤ 6.17.* |
unaffected | ||
6.18≤ * |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-40176 | 9.8 CRITICAL | tls: wait for pending async decryptions if tls_strp_msg_hold fails |
| CVE-2025-40140 | 8.8 HIGH | net: usb: Remove disruptive netif_wake_queue in rtl8150_set_multicast |
| CVE-2025-40133 | 8.1 HIGH | mptcp: Use __sk_dst_get() and dst_dev_rcu() in mptcp_active_enable(). |
| CVE-2025-40186 | 8.1 HIGH | tcp: Don't call reqsk_fastopen_remove() in tcp_conn_request(). |
| CVE-2025-40158 | 8.1 HIGH | ipv6: use RCU in ip6_output() |
| CVE-2025-40204 | 8.1 HIGH | sctp: Fix MAC comparison to be constant-time |
| CVE-2025-40135 | 8.1 HIGH | ipv6: use RCU in ip6_xmit() |
| CVE-2025-40168 | 8.1 HIGH | smc: Use __sk_dst_get() and dst_dev_rcu() in smc_clc_prfx_match(). |
| CVE-2025-40141 | 8.0 HIGH | Bluetooth: ISO: Fix possible UAF on iso_conn_free |
| CVE-2025-40166 | 7.8 HIGH | drm/xe/guc: Check GuC running state before deregistering exec queue |
| CVE-2025-40159 | 7.8 HIGH | xsk: Harden userspace-supplied xdp_desc validation |
| CVE-2025-40173 | 7.8 HIGH | net/ip6_tunnel: Prevent perpetual tunnel growth |
| CVE-2025-40167 | 7.8 HIGH | ext4: detect invalid INLINE_DATA + EXTENTS flag combination |
| CVE-2025-40170 | 7.8 HIGH | net: use dst_dev_rcu() in sk_setup_caps() |
| CVE-2025-40149 | 7.8 HIGH | tls: Use __sk_dst_get() and dst_dev_rcu() in get_netdev_for_sock(). |
| CVE-2025-40172 | 7.8 HIGH | accel/qaic: Treat remaining == 0 as error in find_and_map_user_pages() |
| CVE-2025-40174 | 7.8 HIGH | x86/mm: Fix SMP ordering in switch_mm_irqs_off() |
| CVE-2025-40139 | 7.8 HIGH | smc: Use __sk_dst_get() and dst_dev_rcu() in in smc_clc_prfx_set(). |
| CVE-2025-40190 | 7.8 HIGH | ext4: guard against EA inode refcount underflow in xattr update |
| CVE-2025-40151 | 7.8 HIGH | LoongArch: BPF: No support of struct argument in trampoline programs |
Showing top 20 of 96 CVEs. View all on vendor page → →
No comments yet