Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于mtd spi-nor debugfs中spi_nor_params_show函数使用sizeof(snor_f_names)传递数组大小,但sizeof返回的是指针数组的总字节数而非元素个数,可能导致越界读取。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | 0257be79fc4a16a3252ce80aa13b3640f728c425< 231b8e1f604f6e0a7e100536f506cdf482e2c5f5 |
affected |
0257be79fc4a16a3252ce80aa13b3640f728c425< 9a80c458320e0514e11945402dd6e48fcee05524 |
affected | ||
0257be79fc4a16a3252ce80aa13b3640f728c425< ca18c180b053f6ce80394322b314ac721c316af7 |
affected | ||
0257be79fc4a16a3252ce80aa13b3640f728c425< 34bdcfb496b29f9a52431194f94473b37fb8c162 |
affected | ||
0257be79fc4a16a3252ce80aa13b3640f728c425< c0b654bc0b76a1da102d9138be1ed1223bd99310 |
affected | ||
0257be79fc4a16a3252ce80aa13b3640f728c425< e47029b977e747cb3a9174308fd55762cce70147 |
affected | ||
5.19 |
affected | ||
< 5.19 |
unaffected | ||
| … +6 more rows | |||
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-46135 | 9.8 CRITICAL | nvmet-tcp: fix race between ICReq handling and queue teardown |
| CVE-2026-46137 | 9.8 CRITICAL | mptcp: pm: ADD_ADDR rtx: fix potential data-race |
| CVE-2026-46195 | 9.8 CRITICAL | smb: client: validate dacloffset before building DACL pointers |
| CVE-2026-46115 | 9.8 CRITICAL | block: add pgmap check to biovec_phys_mergeable |
| CVE-2026-46185 | 9.1 CRITICAL | smb/client: fix out-of-bounds read in symlink_data() |
| CVE-2026-46119 | 9.1 CRITICAL | libceph: Fix slab-out-of-bounds access in auth message processing |
| CVE-2026-46155 | 9.1 CRITICAL | smb/client: fix out-of-bounds read in smb2_compound_op() |
| CVE-2026-46166 | 8.8 HIGH | wifi: mac80211: use safe list iteration in radar detect work |
| CVE-2026-46198 | 8.8 HIGH | batman-adv: fix integer overflow on buff_pos |
| CVE-2026-46125 | 8.8 HIGH | wifi: mac80211: remove station if connection prep fails |
| CVE-2026-46174 | 8.8 HIGH | x86/CPU/AMD: Prevent improper isolation of shared resources in Zen2's op cache |
| CVE-2026-46238 | 8.8 HIGH | batman-adv: stop caching unowned originator pointers in BAT IV |
| CVE-2026-46152 | 8.8 HIGH | wifi: mac80211: drop stray 'static' from fast-RX rx_result |
| CVE-2026-46113 | 8.8 HIGH | KVM: x86: Fix shadow paging use-after-free due to unexpected GFN |
| CVE-2026-46212 | 8.8 HIGH | batman-adv: bla: prevent use-after-free when deleting claims |
| CVE-2026-46138 | 8.1 HIGH | Bluetooth: hci_event: Fix OOB read and infinite loop in hci_le_create_big_complete_evt |
| CVE-2026-46232 | 8.1 HIGH | HID: playstation: Clamp num_touch_reports |
| CVE-2026-46178 | 7.8 HIGH | RDMA/mlx4: Fix resource leak on error in mlx4_ib_create_srq() |
| CVE-2026-46205 | 7.8 HIGH | staging: media: atomisp: Disallow all private IOCTLs |
| CVE-2026-46176 | 7.8 HIGH | RDMA/mlx5: Fix error path fall-through in mlx5_ib_dev_res_srq_init() |
Showing top 20 of 135 CVEs. View all on vendor page → →
No comments yet