在构建用于接收 TLS 1.2 CBC 记录的 iovec 数组时, 函数会对链中的每个 mbuf(内存缓冲区)递增 iovec 索引,即使某些 mbuf 因仅包含 TLS 头部字节而被跳过,仍会被计入索引。这导致 iovec 数组中存在未初始化的条目。由于该 iovec 数组在分配时并未清零,因此其内容未初始化。 远程 TLS 对等方可以通过控制 TCP 分段,使得一个 CBC 记录对应的第一个 mbuf 仅包含 5 字节的 TLS 记录头部,从而诱导内核在计算 HMAC 时读取未初始化的 iovec 条目,最终
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-49426 | Incorrect audit records for ptrace(2) syscall requests | |
| CVE-2026-58087 | Heap out-of-bounds access in semctl(2) | |
| CVE-2026-58088 | Race condition in ELF core dump segment counting | |
| CVE-2026-58083 | Use-after-free in kqueue copy-on-fork | |
| CVE-2026-58084 | Kernel stack disclosure via timer_settime(2) | |
| CVE-2026-58085 | Missing MAC validation in wg(4) packet decryption | |
| CVE-2026-58086 | ktrace(2) privilege incorrectly validated in jails | |
| CVE-2026-49425 | Kernel stack disclosure in 32-bit compatibility support | |
| CVE-2026-49424 | Kernel stack disclosure in Linux compatibility layer | |
| CVE-2026-58081 | Heap based buffer overflow in iconv(3) | |
| CVE-2026-58082 | Stack based buffer overflow in iconv(3) | |
| CVE-2026-49418 | Use-after-free in device pager page list | |
| CVE-2026-49427 | posixshm: largepage shared memory objects not explicitly wired | |
| CVE-2026-49428 | posixshm: system calls can incorrectly free memory of largepage objects | |
| CVE-2026-49420 | Buffer overflow in libalias RTSP handler | |
| CVE-2026-49422 | Use-after-free in TCP RACK stack option handler | |
| CVE-2026-49421 | unlinkat(2) ignores AT_RESOLVE_BENEATH flag | |
| CVE-2026-49430 | Kernel heap overflow in ZFS_IOC_RECV_NEW ioctl | |
| CVE-2026-49429 | Kernel heap overflow in ZFS_IOC_USERSPACE_MANY ioctl | |
| CVE-2026-49431 | Incorrect user validation in ZFS_IOC_SET_PROP ioctl |
Showing top 20 of 23 CVEs. View all on vendor page → →
No comments yet