发现了一个在 luksmeta 中的漏洞。具有管理员权限的本地攻击者可以在将元数据保存到 Linux 统一密钥设置(LUKS)设备时导致数据损坏。由于边界计算不正确以及重叠检测存在缺陷,新的元数据条目可能会被写入到可用空闲空间之外,或覆盖现有记录。该问题可能导致已存储的加密有效载荷数据或现有元数据损坏,进而使相关数据无法访问。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | - |
cpe:/o:redhat:enterprise_linux:10
|
|
| Red Hat | Red Hat Enterprise Linux 7 | - |
cpe:/o:redhat:enterprise_linux:7
|
|
| Red Hat | Red Hat Enterprise Linux 8 | - |
cpe:/o:redhat:enterprise_linux:8
|
|
| Red Hat | Red Hat Enterprise Linux 9 | - |
cpe:/o:redhat:enterprise_linux:9
|
|
| Red Hat | Red Hat OpenShift Container Platform 4 | - |
cpe:/a:redhat:openshift:4
|
|
| Red Hat | Red Hat OpenShift Container Platform 4 | - |
cpe:/a:redhat:openshift:4
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-93017 | 7.7 HIGH | Insights-operator: gather serviceaccount has cluster-wide secret read plus nodes/proxy and |
| CVE-2026-107466 | 6.1 MEDIUM | Flatpak-builder: local file exfiltration via `file |
| CVE-2026-107445 | 5.4 MEDIUM | Rubygem-katello: katello flatpak remote repositories api cross-organization authorization |
| CVE-2026-107604 | 4.9 MEDIUM | Keycloak-services: keycloak-services: view-clients role allows retrieval of active client |
| CVE-2026-107623 | 4.3 MEDIUM | Keycloak-services: keycloak-services: oidc dcr read-modify-write silently disables offline |
| CVE-2026-107444 | 4.3 MEDIUM | Rubygem-katello: katello docker tags repositories api cross-organization authorization byp |
No comments yet