Linux kernel是美国Linux基金会开源的操作系统Linux所使用的内核。 Linux kernel 6.0版本存在安全漏洞,该漏洞源于UDP接收路径上skb->dev被重用作dev_scratch(由udp_set_dev_scratch设置的大小/状态缓存),当UDP套接字位于sockmap中时,在运行sockmap判决程序前未清除skb->dev,导致bpf_skc_lookup通过dev_net(skb->dev)解引用时产生一般保护故障,可能导致内核崩溃。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | 965b57b469a589d64d81b1688b38dcb537011bb0< 263779a6beff03b8b06f6d25566cb0f45af361f2 |
affected |
965b57b469a589d64d81b1688b38dcb537011bb0< 1b585673a2249f13678e7ac443ac683ba767e0b6 |
affected | ||
965b57b469a589d64d81b1688b38dcb537011bb0< 90d35188aaa92b8f8b23f66335e0e91bf60103a3 |
affected | ||
965b57b469a589d64d81b1688b38dcb537011bb0< 6822eed69572000a181fa4e31fceacc60918c471 |
affected | ||
965b57b469a589d64d81b1688b38dcb537011bb0< 7d6d92d000ebe3a845a17c165c1d3a70c5d84fe1 |
affected | ||
965b57b469a589d64d81b1688b38dcb537011bb0< 3c94f241f776562c489876ff506f366224565c21 |
affected | ||
6.0 |
affected | ||
< 6.0 |
unaffected | ||
| … +6 more rows | |||
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-53228 | 9.8 CRITICAL | ipv6: sit: reload inner IPv6 header after GSO offloads |
| CVE-2026-53247 | 9.8 CRITICAL | net: ethernet: mtk_eth_soc: Fix use-after-free in metadata dst teardown |
| CVE-2026-53246 | 9.8 CRITICAL | sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing |
| CVE-2026-53151 | 9.8 CRITICAL | rxrpc: Fix the ACK parser to extract the SACK table for parsing |
| CVE-2026-53260 | 9.8 CRITICAL | tcp: Add preempt_{disable,enable}_nested() in reqsk_queue_hash_req(). |
| CVE-2026-53175 | 9.8 CRITICAL | inet: frags: fix use-after-free caused by the fqdir_pre_exit() flush |
| CVE-2026-53176 | 9.8 CRITICAL | IB/isert: Reject login PDUs shorter than ISER_HEADERS_LEN |
| CVE-2026-53221 | 9.8 CRITICAL | ip6_vti: fix incorrect tunnel matching in vti6_tnl_lookup() |
| CVE-2026-53215 | 9.8 CRITICAL | net: mvpp2: refill RX buffers before XDP or skb use |
| CVE-2026-53216 | 9.8 CRITICAL | net: mvpp2: limit XDP frame size to the RX buffer |
| CVE-2026-53131 | 9.4 CRITICAL | netfilter: require Ethernet MAC header before using eth_hdr() |
| CVE-2026-53225 | 9.1 CRITICAL | sctp: fix uninit-value in __sctp_rcv_asconf_lookup() |
| CVE-2026-53186 | 9.1 CRITICAL | RDMA/srp: bound SRP_RSP sense copy by the received length |
| CVE-2026-53224 | 9.1 CRITICAL | sctp: validate embedded INIT chunk and address list lengths in cookie |
| CVE-2026-53200 | 8.8 HIGH | KVM: arm64: nv: Fix handling of XN[0] when !FEAT_XNX |
| CVE-2026-53248 | 8.8 HIGH | net: airoha: Fix use-after-free in metadata dst teardown |
| CVE-2026-53159 | 8.8 HIGH | misc: fastrpc: fix DMA address corruption due to find_vma misuse |
| CVE-2026-53198 | 8.8 HIGH | ksmbd: fix use-after-free of a deferred file_lock on double SMB2_CANCEL |
| CVE-2026-53188 | 8.8 HIGH | RDMA/core: Validate the passed in fops for ib_get_ucaps() |
| CVE-2026-53232 | 8.8 HIGH | net: phy: clean the sfp upstream if phy probing fails |
Showing top 20 of 146 CVEs. View all on vendor page → →
No comments yet