Linux kernel是美国Linux基金会开源的操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于IPv6 SIT隧道函数ipip6_tunnel_xmit()在处理GSO分片时未重新加载内部IPv6头部指针,可能导致从已释放的skb头部读取数据。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | 14909664e4e192f4c6f6fcdccd9919af7cf783ab< fddd41445a0537b093e6b3f6232c9933cad1e48b |
affected |
14909664e4e192f4c6f6fcdccd9919af7cf783ab< 1132e5edc2866c3530be17622153a597095f0e43 |
affected | ||
14909664e4e192f4c6f6fcdccd9919af7cf783ab< 9c67b44edb3598d234efae6e44649eb993c03da5 |
affected | ||
14909664e4e192f4c6f6fcdccd9919af7cf783ab< 0bfa7bba1f41aaf5f0604dc712bb4701493e3aa0 |
affected | ||
14909664e4e192f4c6f6fcdccd9919af7cf783ab< 59f80c919713250fe5d25a4d9aea4e49580fa1d4 |
affected | ||
14909664e4e192f4c6f6fcdccd9919af7cf783ab< 2fa49b2715e1bad12ce3b0fa64e234d9582c8193 |
affected | ||
14909664e4e192f4c6f6fcdccd9919af7cf783ab< cb658c2f5f7977c2a1c77c9f239f4bc8196edb5c |
affected | ||
14909664e4e192f4c6f6fcdccd9919af7cf783ab< f0e42f0c4337b1f220de1ddd63f47197c7dee4de |
affected | ||
| … +10 more rows | |||
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-53175 | 9.8 CRITICAL | inet: frags: fix use-after-free caused by the fqdir_pre_exit() flush |
| CVE-2026-53221 | 9.8 CRITICAL | ip6_vti: fix incorrect tunnel matching in vti6_tnl_lookup() |
| CVE-2026-53176 | 9.8 CRITICAL | IB/isert: Reject login PDUs shorter than ISER_HEADERS_LEN |
| CVE-2026-53246 | 9.8 CRITICAL | sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing |
| CVE-2026-53247 | 9.8 CRITICAL | net: ethernet: mtk_eth_soc: Fix use-after-free in metadata dst teardown |
| CVE-2026-53151 | 9.8 CRITICAL | rxrpc: Fix the ACK parser to extract the SACK table for parsing |
| CVE-2026-53216 | 9.8 CRITICAL | net: mvpp2: limit XDP frame size to the RX buffer |
| CVE-2026-53260 | 9.8 CRITICAL | tcp: Add preempt_{disable,enable}_nested() in reqsk_queue_hash_req(). |
| CVE-2026-53215 | 9.8 CRITICAL | net: mvpp2: refill RX buffers before XDP or skb use |
| CVE-2026-53131 | 9.4 CRITICAL | netfilter: require Ethernet MAC header before using eth_hdr() |
| CVE-2026-53186 | 9.1 CRITICAL | RDMA/srp: bound SRP_RSP sense copy by the received length |
| CVE-2026-53224 | 9.1 CRITICAL | sctp: validate embedded INIT chunk and address list lengths in cookie |
| CVE-2026-53225 | 9.1 CRITICAL | sctp: fix uninit-value in __sctp_rcv_asconf_lookup() |
| CVE-2026-53232 | 8.8 HIGH | net: phy: clean the sfp upstream if phy probing fails |
| CVE-2026-53277 | 8.8 HIGH | KVM: arm64: Take the SRCU lock for page table walks in fault injection and AT emulation |
| CVE-2026-53198 | 8.8 HIGH | ksmbd: fix use-after-free of a deferred file_lock on double SMB2_CANCEL |
| CVE-2026-53248 | 8.8 HIGH | net: airoha: Fix use-after-free in metadata dst teardown |
| CVE-2026-53170 | 8.8 HIGH | accel/ethosu: reject DMA commands with uninitialized length |
| CVE-2026-53159 | 8.8 HIGH | misc: fastrpc: fix DMA address corruption due to find_vma misuse |
| CVE-2026-53275 | 8.8 HIGH | ipv6: mcast: Fix use-after-free when processing MLD queries |
Showing top 20 of 146 CVEs. View all on vendor page → →
No comments yet