Linux kernel是美国Linux基金会开源的操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于__sctp_rcv_asconf_lookup()函数中未正确验证ASCONF地址参数边界,可能导致未经身份验证的对等端发送截断的ASCONF块,从而使from_addr_param()读取未初始化的内存。以下版本受到影响:2.6.25版本。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | df21857714398acb8b24a8bb5a6d2286dd9c59ef< 446e0ecd845abc394b24ae2030a883572bec9d16 |
affected |
df21857714398acb8b24a8bb5a6d2286dd9c59ef< 928dd94db23e8ba340f83d68f7f24d831b7a4426 |
affected | ||
df21857714398acb8b24a8bb5a6d2286dd9c59ef< d796cfd06074b579d265b28401306cadd30db945 |
affected | ||
df21857714398acb8b24a8bb5a6d2286dd9c59ef< 8ce96f1182644079249a24ac7e2ffc32e0301a46 |
affected | ||
df21857714398acb8b24a8bb5a6d2286dd9c59ef< d6bd0bb7697ea8c0387b0d9d973453f479017b23 |
affected | ||
df21857714398acb8b24a8bb5a6d2286dd9c59ef< f76a8b323e28e0951f979dbef20a7496383c47df |
affected | ||
df21857714398acb8b24a8bb5a6d2286dd9c59ef< 8e86817b8af4d552f3c6fe04ca52bb0c8c57411d |
affected | ||
df21857714398acb8b24a8bb5a6d2286dd9c59ef< f8373d7090b745728de66308deeecc67e8d319ce |
affected | ||
| … +10 more rows | |||
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-53175 | 9.8 CRITICAL | inet: frags: fix use-after-free caused by the fqdir_pre_exit() flush |
| CVE-2026-53221 | 9.8 CRITICAL | ip6_vti: fix incorrect tunnel matching in vti6_tnl_lookup() |
| CVE-2026-53176 | 9.8 CRITICAL | IB/isert: Reject login PDUs shorter than ISER_HEADERS_LEN |
| CVE-2026-53246 | 9.8 CRITICAL | sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing |
| CVE-2026-53247 | 9.8 CRITICAL | net: ethernet: mtk_eth_soc: Fix use-after-free in metadata dst teardown |
| CVE-2026-53228 | 9.8 CRITICAL | ipv6: sit: reload inner IPv6 header after GSO offloads |
| CVE-2026-53151 | 9.8 CRITICAL | rxrpc: Fix the ACK parser to extract the SACK table for parsing |
| CVE-2026-53216 | 9.8 CRITICAL | net: mvpp2: limit XDP frame size to the RX buffer |
| CVE-2026-53260 | 9.8 CRITICAL | tcp: Add preempt_{disable,enable}_nested() in reqsk_queue_hash_req(). |
| CVE-2026-53215 | 9.8 CRITICAL | net: mvpp2: refill RX buffers before XDP or skb use |
| CVE-2026-53131 | 9.4 CRITICAL | netfilter: require Ethernet MAC header before using eth_hdr() |
| CVE-2026-53186 | 9.1 CRITICAL | RDMA/srp: bound SRP_RSP sense copy by the received length |
| CVE-2026-53224 | 9.1 CRITICAL | sctp: validate embedded INIT chunk and address list lengths in cookie |
| CVE-2026-53232 | 8.8 HIGH | net: phy: clean the sfp upstream if phy probing fails |
| CVE-2026-53277 | 8.8 HIGH | KVM: arm64: Take the SRCU lock for page table walks in fault injection and AT emulation |
| CVE-2026-53198 | 8.8 HIGH | ksmbd: fix use-after-free of a deferred file_lock on double SMB2_CANCEL |
| CVE-2026-53248 | 8.8 HIGH | net: airoha: Fix use-after-free in metadata dst teardown |
| CVE-2026-53170 | 8.8 HIGH | accel/ethosu: reject DMA commands with uninitialized length |
| CVE-2026-53159 | 8.8 HIGH | misc: fastrpc: fix DMA address corruption due to find_vma misuse |
| CVE-2026-53275 | 8.8 HIGH | ipv6: mcast: Fix use-after-free when processing MLD queries |
Showing top 20 of 146 CVEs. View all on vendor page → →
No comments yet