Linux kernel是美国Linux基金会开源的操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于sctp_cookie中INIT块和地址列表长度验证不足,可能导致越界读取。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2< 7560afb8cddafd829e709d7ea09230e45a825557 |
affected |
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2< 512a9bb77c04ac9927648ea58af617e472be96e6 |
affected | ||
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2< 6f4c80a2a7e6d06753b89a578b710a2499a5e62b |
affected | ||
2.6.12 |
affected | ||
< 2.6.12 |
unaffected | ||
6.18.36≤ 6.18.* |
unaffected | ||
7.0.13≤ 7.0.* |
unaffected | ||
7.1≤ * |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-53175 | 9.8 CRITICAL | inet: frags: fix use-after-free caused by the fqdir_pre_exit() flush |
| CVE-2026-53221 | 9.8 CRITICAL | ip6_vti: fix incorrect tunnel matching in vti6_tnl_lookup() |
| CVE-2026-53176 | 9.8 CRITICAL | IB/isert: Reject login PDUs shorter than ISER_HEADERS_LEN |
| CVE-2026-53246 | 9.8 CRITICAL | sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing |
| CVE-2026-53247 | 9.8 CRITICAL | net: ethernet: mtk_eth_soc: Fix use-after-free in metadata dst teardown |
| CVE-2026-53228 | 9.8 CRITICAL | ipv6: sit: reload inner IPv6 header after GSO offloads |
| CVE-2026-53151 | 9.8 CRITICAL | rxrpc: Fix the ACK parser to extract the SACK table for parsing |
| CVE-2026-53216 | 9.8 CRITICAL | net: mvpp2: limit XDP frame size to the RX buffer |
| CVE-2026-53260 | 9.8 CRITICAL | tcp: Add preempt_{disable,enable}_nested() in reqsk_queue_hash_req(). |
| CVE-2026-53215 | 9.8 CRITICAL | net: mvpp2: refill RX buffers before XDP or skb use |
| CVE-2026-53131 | 9.4 CRITICAL | netfilter: require Ethernet MAC header before using eth_hdr() |
| CVE-2026-53186 | 9.1 CRITICAL | RDMA/srp: bound SRP_RSP sense copy by the received length |
| CVE-2026-53225 | 9.1 CRITICAL | sctp: fix uninit-value in __sctp_rcv_asconf_lookup() |
| CVE-2026-53232 | 8.8 HIGH | net: phy: clean the sfp upstream if phy probing fails |
| CVE-2026-53277 | 8.8 HIGH | KVM: arm64: Take the SRCU lock for page table walks in fault injection and AT emulation |
| CVE-2026-53198 | 8.8 HIGH | ksmbd: fix use-after-free of a deferred file_lock on double SMB2_CANCEL |
| CVE-2026-53248 | 8.8 HIGH | net: airoha: Fix use-after-free in metadata dst teardown |
| CVE-2026-53170 | 8.8 HIGH | accel/ethosu: reject DMA commands with uninitialized length |
| CVE-2026-53159 | 8.8 HIGH | misc: fastrpc: fix DMA address corruption due to find_vma misuse |
| CVE-2026-53275 | 8.8 HIGH | ipv6: mcast: Fix use-after-free when processing MLD queries |
Showing top 20 of 146 CVEs. View all on vendor page → →
No comments yet