Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于vport netlink回复辅助函数分配固定大小skb但序列化完整upcall PID数组无上限,可能导致CAP_NET_ADMIN用户安装足够大的PID数组溢出回复缓冲区导致nla_put失败触发BUG_ON。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | 5cd667b0a4567048bb555927d6ee564f4e5620a9< 8d59b80e69dddb665eb2de36e62859ab2073470e |
affected |
5cd667b0a4567048bb555927d6ee564f4e5620a9< d9e47e29aacb9f8a9d59feb6ab5b128a9bbb40b0 |
affected | ||
5cd667b0a4567048bb555927d6ee564f4e5620a9< b39f763d720d623218bc1d95ace6855d7b474e81 |
affected | ||
5cd667b0a4567048bb555927d6ee564f4e5620a9< f9ef3db77a383d66847fd082c2b437d8ae4d9c63 |
affected | ||
5cd667b0a4567048bb555927d6ee564f4e5620a9< f99ac36b5d7c719d08a69fcdecce40f78a874e15 |
affected | ||
5cd667b0a4567048bb555927d6ee564f4e5620a9< fa6e90bc443bed8dc0d55bc5ea5b27ffdfe37704 |
affected | ||
5cd667b0a4567048bb555927d6ee564f4e5620a9< 1d6c02b86329883aa467a3a61f8d34369db73a2f |
affected | ||
5cd667b0a4567048bb555927d6ee564f4e5620a9< 2091c6aa0df6aba47deb5c8ab232b1cb60af3519 |
affected | ||
| … +10 more rows | |||
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-46039 | 9.8 CRITICAL | rxgk: Fix potential integer overflow in length check |
| CVE-2026-45898 | 9.8 CRITICAL | RDMA/iwcm: Fix workqueue list corruption by removing work_list |
| CVE-2026-45972 | 9.8 CRITICAL | smb: client: fix potential UAF and double free in smb2_open_file() |
| CVE-2026-45988 | 9.8 CRITICAL | rxrpc: Fix re-decryption of RESPONSE packets |
| CVE-2026-46043 | 9.1 CRITICAL | RDMA/rxe: Validate pad and ICRC before payload_size() in rxe_rcv |
| CVE-2026-45945 | 8.8 HIGH | iommu/vt-d: Fix race condition during PASID entry replacement |
| CVE-2026-46056 | 8.8 HIGH | Bluetooth: hci_event: fix potential UAF in SSP passkey handlers |
| CVE-2025-71311 | 8.2 HIGH | fs/ntfs3: Initialize new folios before use |
| CVE-2026-46037 | 8.2 HIGH | ipv4: icmp: validate reply type before using icmp_pointers |
| CVE-2026-45843 | 8.2 HIGH | slip: bound decode() reads against the compressed packet length |
| CVE-2026-46099 | 8.1 HIGH | net: ipv6: fix NOREF dst use in seg6 and rpl lwtunnels |
| CVE-2026-46010 | 8.1 HIGH | rxrpc: Fix error handling in rxgk_extract_token() |
| CVE-2026-46076 | 7.9 HIGH | KVM: nSVM: Raise #UD if unhandled VMMCALL isn't intercepted by L1 |
| CVE-2026-45910 | 7.8 HIGH | RDMA/rxe: Fix race condition in QP timer handlers |
| CVE-2026-45931 | 7.8 HIGH | accel/amdxdna: Hold mm structure across iommu_sva_unbind_device() |
| CVE-2026-45956 | 7.8 HIGH | drm/exynos: vidi: use priv->vidi_dev for ctx lookup in vidi_connection_ioctl() |
| CVE-2026-46036 | 7.8 HIGH | vfio/cdx: Serialize VFIO_DEVICE_SET_IRQS with a per-device mutex |
| CVE-2026-46100 | 7.8 HIGH | fs: afs: revert mmap_prepare() change |
| CVE-2026-45894 | 7.8 HIGH | iommu/vt-d: Clear Present bit before tearing down PASID entry |
| CVE-2026-45933 | 7.8 HIGH | bpf: Preserve id of register in sync_linked_regs() |
Showing top 20 of 275 CVEs. View all on vendor page → →
No comments yet