目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1336 CNY

100%

CVE-2026-22993— Linux kernel 安全漏洞

AI Predicted 7.8 Difficulty: Moderate EPSS 0.11% · P2

Possible ATT&CK Techniques 1AI

T1083 · File and Directory Discovery

Affected Version Matrix 8

ベンダープロダクトVersion Rangeステータス
LinuxLinux02cbfba1add5bd9088c7d14c6b93b77a6ea8f3bb< a09380354d2f14759b9dd45de1bc2f6bf49e651baffected
02cbfba1add5bd9088c7d14c6b93b77a6ea8f3bb< ab92fa4dd81beaaed4e93a851f7a37c9b2d9776faffected
02cbfba1add5bd9088c7d14c6b93b77a6ea8f3bb< ebecca5b093895da801b3eba1a55b4ec4027d196affected
6.7affected
< 6.7unaffected
6.12.80≤ 6.12.*unaffected
6.18.6≤ 6.18.*unaffected
6.19≤ *unaffected
新しい脆弱性情報の通知を購読するログインして購読

I. CVE-2026-22993の基本情報

脆弱性情報

脆弱性についてご質問がありますか?Shenlongの分析が参考になるかご確認ください!
Shenlongの10の質問を表示 ↗

高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。

脆弱性タイトル
idpf: Fix RSS LUT NULL ptr issue after soft reset
ソース: CVE Program / CVE List V5
脆弱性説明
In the Linux kernel, the following vulnerability has been resolved: idpf: Fix RSS LUT NULL ptr issue after soft reset During soft reset, the RSS LUT is freed and not restored unless the interface is up. If an ethtool command that accesses the rss lut is attempted immediately after reset, it will result in NULL ptr dereference. Also, there is no need to reset the rss lut if the soft reset does not involve queue count change. After soft reset, set the RSS LUT to default values based on the updated queue count only if the reset was a result of a queue count change and the LUT was not configured by the user. In all other cases, don't touch the LUT. Steps to reproduce: ** Bring the interface down (if up) ifconfig eth1 down ** update the queue count (eg., 27->20) ethtool -L eth1 combined 20 ** display the RSS LUT ethtool -x eth1 [82375.558338] BUG: kernel NULL pointer dereference, address: 0000000000000000 [82375.558373] #PF: supervisor read access in kernel mode [82375.558391] #PF: error_code(0x0000) - not-present page [82375.558408] PGD 0 P4D 0 [82375.558421] Oops: Oops: 0000 [#1] SMP NOPTI <snip> [82375.558516] RIP: 0010:idpf_get_rxfh+0x108/0x150 [idpf] [82375.558786] Call Trace: [82375.558793] <TASK> [82375.558804] rss_prepare.isra.0+0x187/0x2a0 [82375.558827] rss_prepare_data+0x3a/0x50 [82375.558845] ethnl_default_doit+0x13d/0x3e0 [82375.558863] genl_family_rcv_msg_doit+0x11f/0x180 [82375.558886] genl_rcv_msg+0x1ad/0x2b0 [82375.558902] ? __pfx_ethnl_default_doit+0x10/0x10 [82375.558920] ? __pfx_genl_rcv_msg+0x10/0x10 [82375.558937] netlink_rcv_skb+0x58/0x100 [82375.558957] genl_rcv+0x2c/0x50 [82375.558971] netlink_unicast+0x289/0x3e0 [82375.558988] netlink_sendmsg+0x215/0x440 [82375.559005] __sys_sendto+0x234/0x240 [82375.559555] __x64_sys_sendto+0x28/0x30 [82375.560068] x64_sys_call+0x1909/0x1da0 [82375.560576] do_syscall_64+0x7a/0xfa0 [82375.561076] ? clear_bhb_loop+0x60/0xb0 [82375.561567] entry_SYSCALL_64_after_hwframe+0x76/0x7e <snip>
ソース: CVE Program / CVE List V5
CVSS情報
N/A
ソース: CVE Program / CVE List V5
脆弱性タイプ
N/A
ソース: CVE Program / CVE List V5
脆弱性タイトル
Linux kernel 安全漏洞
ソース: CNNVD (China National Vulnerability Database)
脆弱性説明
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于RSS LUT空指针问题,可能导致空指针取消引用。
ソース: CNNVD (China National Vulnerability Database)
CVSS情報
N/A
ソース: CNNVD (China National Vulnerability Database)
脆弱性タイプ
N/A
ソース: CNNVD (China National Vulnerability Database)

影響を受ける製品

ベンダープロダクト影響を受けるバージョンCPE購読
LinuxLinux 02cbfba1add5bd9088c7d14c6b93b77a6ea8f3bb ~ a09380354d2f14759b9dd45de1bc2f6bf49e651b -
LinuxLinux 6.7 -

II. CVE-2026-22993の公開POC

#POC説明ソースリンクShenlongリンク
AI生成POCプレミアム

公開POCは見つかりませんでした。

ログインしてAI POCを生成

III. CVE-2026-22993のインテリジェンス情報

登录查看更多情报信息。

Same Patch Batch · Linux · 2026-01-23 · 34 CVEs total

CVE-2026-229849.8 CRITICALlibceph: prevent potential out-of-bounds reads in handle_auth_done()
CVE-2025-711599.8 CRITICALbtrfs: fix use-after-free warning in btrfs_get_or_create_delayed_node()
CVE-2026-229807.8 HIGHnfsd: provide locking for v4_end_grace
CVE-2025-711457.8 HIGHusb: phy: isp1301: fix non-OF device reference imbalance
CVE-2025-711587.8 HIGHgpio: mpsse: ensure worker is torn down
CVE-2026-229887.8 HIGHarp: do not assume dev_hard_header() does not change skb->head
CVE-2025-711557.8 HIGHKVM: s390: Fix gmap_helper_zap_one_page() again
CVE-2025-711467.5 HIGHnetfilter: nf_conncount: fix leaked ct in error paths
CVE-2025-711617.5 HIGHdm-verity: disable recursive forward error correction
CVE-2026-229907.5 HIGHlibceph: replace overzealous BUG_ON in osdmap_apply_incremental()
CVE-2026-229917.5 HIGHlibceph: make free_choose_arg_map() resilient to partial allocation
CVE-2026-229927.5 HIGHlibceph: return the handler error from mon_handle_auth_done()
CVE-2025-711507.5 HIGHksmbd: Fix refcount leak when invalid session is found on session lookup
CVE-2026-22989nfsd: check that server is running in unlock_filesystem
CVE-2026-22987net/sched: act_api: avoid dereferencing ERR_PTR in tcf_idrinfo_destroy
CVE-2026-22986gpiolib: fix race condition for gdev->srcu
CVE-2026-22985idpf: Fix RSS LUT NULL pointer crash on early ethtool operations
CVE-2026-22994bpf: Fix reference count leak in bpf_prog_test_run_xdp()
CVE-2026-22995ublk: fix use-after-free in ublk_partition_scan_work
CVE-2026-22983net: do not write to msg_get_inq in callee

Showing 20 of 34 CVEs. View all on vendor page →

IV. 関連脆弱性

V. CVE-2026-22993へのコメント

まだコメントはありません


コメントを残す