Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于bpf_core_parse_spec使用sscanf解析CO-RE访问器索引时接受负值且边界检查仅保护上限,可能导致负值到达btf_member_bit_offset时转换为u32 0xffffffff产生越界读取导致内核崩溃。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | ddc7c3042614e273044f698d2beab25cc3842d45< c8e49b79c4b48bd687706ff6e9c82638dc81ef80 |
affected |
ddc7c3042614e273044f698d2beab25cc3842d45< a9e777f856cd2f1efc106afc7bf21aef868509d5 |
affected | ||
ddc7c3042614e273044f698d2beab25cc3842d45< 669349b4612c26b3d7aacfa99d7174681bd19223 |
affected | ||
ddc7c3042614e273044f698d2beab25cc3842d45< 3ff85ae79e1a74baeb916b78a63d821f6d19a994 |
affected | ||
ddc7c3042614e273044f698d2beab25cc3842d45< 36a9012f76ba8d9189ae56a1f8bb7c87c07a1f3a |
affected | ||
ddc7c3042614e273044f698d2beab25cc3842d45< 76f2ebaf79a9ae6d0737b87f045fe769e425d78f |
affected | ||
ddc7c3042614e273044f698d2beab25cc3842d45< 99dbab7b5a12d8f58d5b0aa2f7a1fe656a70f4b2 |
affected | ||
ddc7c3042614e273044f698d2beab25cc3842d45< 1c22483a2c4bbf747787f328392ca3e68619c4dc |
affected | ||
| … +10 more rows | |||
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-46039 | 9.8 CRITICAL | rxgk: Fix potential integer overflow in length check |
| CVE-2026-45898 | 9.8 CRITICAL | RDMA/iwcm: Fix workqueue list corruption by removing work_list |
| CVE-2026-45972 | 9.8 CRITICAL | smb: client: fix potential UAF and double free in smb2_open_file() |
| CVE-2026-45988 | 9.8 CRITICAL | rxrpc: Fix re-decryption of RESPONSE packets |
| CVE-2026-46043 | 9.1 CRITICAL | RDMA/rxe: Validate pad and ICRC before payload_size() in rxe_rcv |
| CVE-2026-45945 | 8.8 HIGH | iommu/vt-d: Fix race condition during PASID entry replacement |
| CVE-2026-46056 | 8.8 HIGH | Bluetooth: hci_event: fix potential UAF in SSP passkey handlers |
| CVE-2025-71311 | 8.2 HIGH | fs/ntfs3: Initialize new folios before use |
| CVE-2026-46037 | 8.2 HIGH | ipv4: icmp: validate reply type before using icmp_pointers |
| CVE-2026-45843 | 8.2 HIGH | slip: bound decode() reads against the compressed packet length |
| CVE-2026-46099 | 8.1 HIGH | net: ipv6: fix NOREF dst use in seg6 and rpl lwtunnels |
| CVE-2026-46010 | 8.1 HIGH | rxrpc: Fix error handling in rxgk_extract_token() |
| CVE-2026-46076 | 7.9 HIGH | KVM: nSVM: Raise #UD if unhandled VMMCALL isn't intercepted by L1 |
| CVE-2026-45910 | 7.8 HIGH | RDMA/rxe: Fix race condition in QP timer handlers |
| CVE-2026-45931 | 7.8 HIGH | accel/amdxdna: Hold mm structure across iommu_sva_unbind_device() |
| CVE-2026-45956 | 7.8 HIGH | drm/exynos: vidi: use priv->vidi_dev for ctx lookup in vidi_connection_ioctl() |
| CVE-2026-46036 | 7.8 HIGH | vfio/cdx: Serialize VFIO_DEVICE_SET_IRQS with a per-device mutex |
| CVE-2026-46100 | 7.8 HIGH | fs: afs: revert mmap_prepare() change |
| CVE-2026-45894 | 7.8 HIGH | iommu/vt-d: Clear Present bit before tearing down PASID entry |
| CVE-2026-45933 | 7.8 HIGH | bpf: Preserve id of register in sync_linked_regs() |
Showing top 20 of 275 CVEs. View all on vendor page → →
No comments yet