util-linux是util-linux组织开源的一个软件包。 util-linux存在资源管理错误漏洞,该漏洞源于在嵌套分区探测过程中,BSD、Minix、Solaris x86和UnixWare分区探测程序在动态分配的数组中缓存指向父分区条目的原始指针,当后续分区添加导致数组重新分配时,该指针失效,导致堆释放后重用读取。攻击者可以通过呈现特制块设备映像(如通过USB插入或循环挂载的磁盘映像)触发此漏洞,可能导致有限的信息泄露或拒绝服务。以下版本受到影响:Red Hat Enterprise Linu
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | any |
affected |
| Red Hat | Red Hat Enterprise Linux 7 | any |
affected |
| Red Hat | Red Hat Enterprise Linux 8 | any |
affected |
| Red Hat | Red Hat Enterprise Linux 9 | any |
affected |
| Red Hat | Red Hat Hardened Images | 2.42.2-1.hum1< * |
unaffected |
| Red Hat | Red Hat OpenShift Container Platform 4 | any |
affected |
any |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Hardened Images | 2.42.2-1.hum1 ~ * |
cpe:/a:redhat:hummingbird:1
|
|
| Red Hat | Red Hat Enterprise Linux 10 | - |
cpe:/o:redhat:enterprise_linux:10
|
|
| Red Hat | Red Hat Enterprise Linux 7 | - |
cpe:/o:redhat:enterprise_linux:7
|
|
| Red Hat | Red Hat Enterprise Linux 8 | - |
cpe:/o:redhat:enterprise_linux:8
|
|
| Red Hat | Red Hat Enterprise Linux 9 | - |
cpe:/o:redhat:enterprise_linux:9
|
|
| Red Hat | Red Hat OpenShift Container Platform 4 | - |
cpe:/a:redhat:openshift:4
|
|
| Red Hat | Red Hat OpenShift Container Platform 4 | - |
cpe:/a:redhat:openshift:4
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-12856 | 8.8 HIGH | Vscode-java: vscode: command injection vulnerability in the javadoc hover provider of the |
| CVE-2026-12912 | 7.3 HIGH | Libtiff: libtiff: heap-based buffer overflow via crafted pixarlog-compressed tiff image |
| CVE-2026-13601 | 7.1 HIGH | Yelp: yelp-xsl: overly permissive content security policy in yelp allows host file disclos |
| CVE-2026-13757 | 6.2 MEDIUM | P11-kit: stack exhaustion via unbounded recursion in rpc attribute parsing |
| CVE-2026-57965 | 5.1 MEDIUM | Spice-vdagent: integer overflow in udscs_write() leading to heap buffer overflow |
| CVE-2026-57966 | 4.4 MEDIUM | Spice-vdagent: path traversal in file transfer via unsanitized filename |
No comments yet