目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2026-53175— Linux kernel 安全漏洞

一分钟漏洞结论

影响对象
Linux Linux
利用判断
尚无明确在野利用证据,仍需结合暴露面评估
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

Linux kernel是美国Linux基金会开源的操作系统Linux所使用的内核。 Linux kernel 6.19版本存在安全漏洞,该漏洞源于网络命名空间拆除过程中fqdir_pre_exit()函数在刷新片段队列时,未正确释放后重用(UAF),可能导致攻击者利用释放的skbs指针触发slab释放后重用,影响包括IPv6、nf_conntrack_reasm6和6lowpan重组。

CVSS 9.8 · Critical EPSS 0.45% · P37

影响版本矩阵 13

厂商产品 版本范围状态
Linux Linux 22ee4010866da81aeee08e1ea3fddbe418feb212< 0e823ca0e7391630784ae7dd0981b7ad170a93d9 affected
543555954b1ee8d1903a7020324efb41b0c97428< c22599cc90e1cd5f8129c8670bd68a02ff7177b4 affected
c70df25214ac9b32b53e18e6ae3b8f073ffa6903< 89b909e9704587bfecc1aab1d37e98faee03b9f9 affected
006a5035b495dec008805df249f92c22c89c3d2e< 010c3313a4d178dc2d3ce958d2e5cb055e2864c1 affected
006a5035b495dec008805df249f92c22c89c3d2e< 32594b09854970d7ba83eb2dc8c69a2edd158c8e affected
6.12.93< 6.12.94 affected
6.18.3< 6.18.36 affected
6.19 affected
… +5 条更多
获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2026-53175 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
inet: frags: fix use-after-free caused by the fqdir_pre_exit() flush
来源: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: inet: frags: fix use-after-free caused by the fqdir_pre_exit() flush On netns teardown, fqdir_pre_exit() walks the fqdir rhashtable and flushes every fragment queue that is not yet complete using inet_frag_queue_flush(). That helper frees all the skbs queued on the fragment queue but does not set INET_FRAG_COMPLETE, and leaves q->fragments_tail and q->last_run_head pointing at the freed skbs. The queue itself stays in the rhashtable. fqdir_pre_exit() first lowers high_thresh to 0 to stop new queue lookups, but it cannot stop a fragment that already obtained the queue through inet_frag_find() earlier and stalled just before taking the queue lock. Once that fragment resumes after the flush and takes the queue lock, it passes the INET_FRAG_COMPLETE check and then dereferences the freed fragments_tail. inet_frag_queue_insert() reads FRAG_CB() and ->len of that pointer and, on the append path, writes ->next_frag, causing a slab use-after-free. IPv6, nf_conntrack_reasm6 and 6lowpan reassembly share the same flush path and are affected as well. Reset rb_fragments, fragments_tail and last_run_head in inet_frag_queue_flush() so a flushed queue no longer points at the freed skbs. A fragment that resumes after the flush and takes the queue lock then finds an empty queue and starts a new run instead of dereferencing the freed fragments_tail. ip_frag_reinit() already performed this reset after its own flush, so drop the now duplicate code there.
来源: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
来源: CVE Program / CVE List V5
Vulnerability Type
N/A
来源: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Description
Linux kernel是美国Linux基金会开源的操作系统Linux所使用的内核。 Linux kernel 6.19版本存在安全漏洞,该漏洞源于网络命名空间拆除过程中fqdir_pre_exit()函数在刷新片段队列时,未正确释放后重用(UAF),可能导致攻击者利用释放的skbs指针触发slab释放后重用,影响包括IPv6、nf_conntrack_reasm6和6lowpan重组。
来源: 中国国家信息安全漏洞库 CNNVD
CVSS Information
N/A
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Type
N/A
来源: 中国国家信息安全漏洞库 CNNVD

受影响产品

厂商 产品 影响版本 CPE 订阅
Linux Linux 22ee4010866da81aeee08e1ea3fddbe418feb212 ~ 0e823ca0e7391630784ae7dd0981b7ad170a93d9 -
Linux Linux 6.19 -

二、漏洞 CVE-2026-53175 的公开POC

# POC 描述 源链接 神龙链接
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2026-53175 的情报信息

请登录查看更多情报信息。

CVE-2026-53175 补丁与修复 (5)

同批安全公告 · Linux · 2026-06-25 · 共 146 条

CVE-2026-53228 9.8 CRITICAL Linux kernel 安全漏洞
CVE-2026-53247 9.8 CRITICAL Linux kernel 安全漏洞
CVE-2026-53151 9.8 CRITICAL Linux kernel 安全漏洞
CVE-2026-53246 9.8 CRITICAL Linux kernel 安全漏洞
CVE-2026-53260 9.8 CRITICAL Linux kernel 安全漏洞
CVE-2026-53176 9.8 CRITICAL Linux kernel 安全漏洞
CVE-2026-53221 9.8 CRITICAL Linux kernel 安全漏洞
CVE-2026-53215 9.8 CRITICAL Linux kernel 安全漏洞
CVE-2026-53216 9.8 CRITICAL Linux kernel 安全漏洞
CVE-2026-53131 9.4 CRITICAL Linux kernel 安全漏洞
CVE-2026-53224 9.1 CRITICAL Linux kernel 安全漏洞
CVE-2026-53225 9.1 CRITICAL Linux kernel 安全漏洞
CVE-2026-53186 9.1 CRITICAL Linux kernel 安全漏洞
CVE-2026-53240 8.8 HIGH Linux kernel 安全漏洞
CVE-2026-53188 8.8 HIGH Linux kernel 安全漏洞
CVE-2026-53248 8.8 HIGH Linux kernel 安全漏洞
CVE-2026-53159 8.8 HIGH Linux kernel 安全漏洞
CVE-2026-53170 8.8 HIGH Linux kernel 安全漏洞
CVE-2026-53198 8.8 HIGH Linux kernel 安全漏洞
CVE-2026-53171 8.8 HIGH Linux kernel 安全漏洞

显示前 20 条,共 146 条。 查看全部 &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-53175

暂无评论


发表评论