Linux kernel是美国Linux基金会开源的操作系统Linux所使用的内核。 Linux kernel 6.15版本存在安全漏洞,该漏洞源于RDMA/core中ib_get_ucaps()函数对传入的fops验证不当,可能导致攻击者通过查找具有相同设备号的块设备来伪装成ucap cdev fd。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | 61e51682816d395307f78ae06d640089054c28ab< 96b6e98ff12d50ed5817230c6f1188e1150d225d |
affected |
61e51682816d395307f78ae06d640089054c28ab< aa181287ebdcc53ee0ba5c2f8243e2d541ebc19b |
affected | ||
61e51682816d395307f78ae06d640089054c28ab< 4a1b1ac2744694a2ecd66a84bdb1445f4ef24bee |
affected | ||
6.15 |
affected | ||
< 6.15 |
unaffected | ||
6.18.36≤ 6.18.* |
unaffected | ||
7.0.13≤ 7.0.* |
unaffected | ||
7.1≤ * |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-53176 | 9.8 CRITICAL | IB/isert: Reject login PDUs shorter than ISER_HEADERS_LEN |
| CVE-2026-53247 | 9.8 CRITICAL | net: ethernet: mtk_eth_soc: Fix use-after-free in metadata dst teardown |
| CVE-2026-53151 | 9.8 CRITICAL | rxrpc: Fix the ACK parser to extract the SACK table for parsing |
| CVE-2026-53246 | 9.8 CRITICAL | sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing |
| CVE-2026-53260 | 9.8 CRITICAL | tcp: Add preempt_{disable,enable}_nested() in reqsk_queue_hash_req(). |
| CVE-2026-53175 | 9.8 CRITICAL | inet: frags: fix use-after-free caused by the fqdir_pre_exit() flush |
| CVE-2026-53228 | 9.8 CRITICAL | ipv6: sit: reload inner IPv6 header after GSO offloads |
| CVE-2026-53215 | 9.8 CRITICAL | net: mvpp2: refill RX buffers before XDP or skb use |
| CVE-2026-53221 | 9.8 CRITICAL | ip6_vti: fix incorrect tunnel matching in vti6_tnl_lookup() |
| CVE-2026-53216 | 9.8 CRITICAL | net: mvpp2: limit XDP frame size to the RX buffer |
| CVE-2026-53131 | 9.4 CRITICAL | netfilter: require Ethernet MAC header before using eth_hdr() |
| CVE-2026-53225 | 9.1 CRITICAL | sctp: fix uninit-value in __sctp_rcv_asconf_lookup() |
| CVE-2026-53224 | 9.1 CRITICAL | sctp: validate embedded INIT chunk and address list lengths in cookie |
| CVE-2026-53186 | 9.1 CRITICAL | RDMA/srp: bound SRP_RSP sense copy by the received length |
| CVE-2026-53159 | 8.8 HIGH | misc: fastrpc: fix DMA address corruption due to find_vma misuse |
| CVE-2026-53248 | 8.8 HIGH | net: airoha: Fix use-after-free in metadata dst teardown |
| CVE-2026-53232 | 8.8 HIGH | net: phy: clean the sfp upstream if phy probing fails |
| CVE-2026-53200 | 8.8 HIGH | KVM: arm64: nv: Fix handling of XN[0] when !FEAT_XNX |
| CVE-2026-53171 | 8.8 HIGH | accel/ethosu: fix arithmetic issues in dma_length() |
| CVE-2026-53170 | 8.8 HIGH | accel/ethosu: reject DMA commands with uninitialized length |
Showing top 20 of 146 CVEs. View all on vendor page → →
No comments yet