当对未管理的设备对象映射调用 msync(MS_INVALIDATE) 时,映射范围内的物理页被标记为无效,但仍保留在分页器(pager)的页面列表中。随后发生的页面错误(page fault)会导致故障处理程序将该页重新插入到该对象的列表中。这种操作会破坏列表结构,并在对象销毁时导致页面被双重释放(double free)。 拥有设备访问权限且无需特权的本地用户,若能访问提供内存映射 I/O(MMIO)的设备,即可在内核中触发释放后使用(use-after-free)漏洞。不过,该漏洞的影响范围仅限于一组对象(即
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-49423 | Remote DOS via uninitialized memory access in KTLS receive | |
| CVE-2026-58087 | Heap out-of-bounds access in semctl(2) | |
| CVE-2026-58088 | Race condition in ELF core dump segment counting | |
| CVE-2026-58083 | Use-after-free in kqueue copy-on-fork | |
| CVE-2026-58084 | Kernel stack disclosure via timer_settime(2) | |
| CVE-2026-58085 | Missing MAC validation in wg(4) packet decryption | |
| CVE-2026-58086 | ktrace(2) privilege incorrectly validated in jails | |
| CVE-2026-49425 | Kernel stack disclosure in 32-bit compatibility support | |
| CVE-2026-49424 | Kernel stack disclosure in Linux compatibility layer | |
| CVE-2026-58081 | Heap based buffer overflow in iconv(3) | |
| CVE-2026-58082 | Stack based buffer overflow in iconv(3) | |
| CVE-2026-49419 | Jail reference count underflow | |
| CVE-2026-49426 | Incorrect audit records for ptrace(2) syscall requests | |
| CVE-2026-49427 | posixshm: largepage shared memory objects not explicitly wired | |
| CVE-2026-49428 | posixshm: system calls can incorrectly free memory of largepage objects | |
| CVE-2026-49420 | Buffer overflow in libalias RTSP handler | |
| CVE-2026-49422 | Use-after-free in TCP RACK stack option handler | |
| CVE-2026-49421 | unlinkat(2) ignores AT_RESOLVE_BENEATH flag | |
| CVE-2026-49430 | Kernel heap overflow in ZFS_IOC_RECV_NEW ioctl | |
| CVE-2026-49429 | Kernel heap overflow in ZFS_IOC_USERSPACE_MANY ioctl |
Showing top 20 of 23 CVEs. View all on vendor page → →
No comments yet