Linux kernel是美国Linux基金会开源的操作系统Linux所使用的内核。 Linux kernel 3.10版本存在安全漏洞,该漏洞源于在drivers/infiniband/ulp/isert/ib_isert.c中isert_login_recv_done()函数计算登录请求有效载荷长度时缺少下界检查,导致整数下溢,可能允许远程iSER发起者登录阶段发送少于ISER_HEADERS_LEN字节的请求造成越界复制并导致目标节点崩溃。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | b8d26b3be8b33682cf163274ed07479a70554633< 75ee6e4aa096aa9e7b2dd5c8ff98356e30aceefb |
affected |
b8d26b3be8b33682cf163274ed07479a70554633< e8a013c0c3ca2f6708341a56612a3f6d6921620a |
affected | ||
b8d26b3be8b33682cf163274ed07479a70554633< bd22740d7f14cb1c0289444cfd2c8d2938667c1d |
affected | ||
b8d26b3be8b33682cf163274ed07479a70554633< c1234229399f4af12c553b1b0ffd978eeba65548 |
affected | ||
b8d26b3be8b33682cf163274ed07479a70554633< c5584e089b5af7b3bf8bd5e8ca0560cbf32b0a47 |
affected | ||
b8d26b3be8b33682cf163274ed07479a70554633< df422fd273c96c2ee5beb80fc21adc8c70c29260 |
affected | ||
b8d26b3be8b33682cf163274ed07479a70554633< 1ca40b243277c9e88be5e00bd3e083f71aefb93e |
affected | ||
b8d26b3be8b33682cf163274ed07479a70554633< 29e7b925ae6df64894e82ab6419994dc25580a8a |
affected | ||
| … +10 more rows | |||
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-53228 | 9.8 CRITICAL | ipv6: sit: reload inner IPv6 header after GSO offloads |
| CVE-2026-53247 | 9.8 CRITICAL | net: ethernet: mtk_eth_soc: Fix use-after-free in metadata dst teardown |
| CVE-2026-53151 | 9.8 CRITICAL | rxrpc: Fix the ACK parser to extract the SACK table for parsing |
| CVE-2026-53246 | 9.8 CRITICAL | sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing |
| CVE-2026-53260 | 9.8 CRITICAL | tcp: Add preempt_{disable,enable}_nested() in reqsk_queue_hash_req(). |
| CVE-2026-53175 | 9.8 CRITICAL | inet: frags: fix use-after-free caused by the fqdir_pre_exit() flush |
| CVE-2026-53221 | 9.8 CRITICAL | ip6_vti: fix incorrect tunnel matching in vti6_tnl_lookup() |
| CVE-2026-53215 | 9.8 CRITICAL | net: mvpp2: refill RX buffers before XDP or skb use |
| CVE-2026-53216 | 9.8 CRITICAL | net: mvpp2: limit XDP frame size to the RX buffer |
| CVE-2026-53131 | 9.4 CRITICAL | netfilter: require Ethernet MAC header before using eth_hdr() |
| CVE-2026-53224 | 9.1 CRITICAL | sctp: validate embedded INIT chunk and address list lengths in cookie |
| CVE-2026-53225 | 9.1 CRITICAL | sctp: fix uninit-value in __sctp_rcv_asconf_lookup() |
| CVE-2026-53186 | 9.1 CRITICAL | RDMA/srp: bound SRP_RSP sense copy by the received length |
| CVE-2026-53240 | 8.8 HIGH | xfrm: iptfs: fix use-after-free on first_skb in __input_process_payload |
| CVE-2026-53188 | 8.8 HIGH | RDMA/core: Validate the passed in fops for ib_get_ucaps() |
| CVE-2026-53248 | 8.8 HIGH | net: airoha: Fix use-after-free in metadata dst teardown |
| CVE-2026-53159 | 8.8 HIGH | misc: fastrpc: fix DMA address corruption due to find_vma misuse |
| CVE-2026-53170 | 8.8 HIGH | accel/ethosu: reject DMA commands with uninitialized length |
| CVE-2026-53198 | 8.8 HIGH | ksmbd: fix use-after-free of a deferred file_lock on double SMB2_CANCEL |
| CVE-2026-53171 | 8.8 HIGH | accel/ethosu: fix arithmetic issues in dma_length() |
Showing top 20 of 146 CVEs. View all on vendor page → →
No comments yet