在通过 fork 系统调用复制 knote(kevent 通知)期间,带有基于定时器的过滤器的 knote 可能在复制完成之前触发并被入队到 kqueue 的活动列表中。复制例程未考虑到这种情况,可能导致新的 knote 被重复入队,从而损坏活动列表。此外,复制例程在读取 knote 状态时未持有适当的锁,进一步引发了竞态条件。 未经特权的本地用户可以利用此漏洞在内核中触发 use-after-free 漏洞,可能导致权限提升。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-49426 | Incorrect audit records for ptrace(2) syscall requests | |
| CVE-2026-58087 | Heap out-of-bounds access in semctl(2) | |
| CVE-2026-58088 | Race condition in ELF core dump segment counting | |
| CVE-2026-58084 | Kernel stack disclosure via timer_settime(2) | |
| CVE-2026-58085 | Missing MAC validation in wg(4) packet decryption | |
| CVE-2026-58086 | ktrace(2) privilege incorrectly validated in jails | |
| CVE-2026-49425 | Kernel stack disclosure in 32-bit compatibility support | |
| CVE-2026-49424 | Kernel stack disclosure in Linux compatibility layer | |
| CVE-2026-58081 | Heap based buffer overflow in iconv(3) | |
| CVE-2026-58082 | Stack based buffer overflow in iconv(3) | |
| CVE-2026-49423 | Remote DOS via uninitialized memory access in KTLS receive | |
| CVE-2026-49418 | Use-after-free in device pager page list | |
| CVE-2026-49427 | posixshm: largepage shared memory objects not explicitly wired | |
| CVE-2026-49428 | posixshm: system calls can incorrectly free memory of largepage objects | |
| CVE-2026-49420 | Buffer overflow in libalias RTSP handler | |
| CVE-2026-49422 | Use-after-free in TCP RACK stack option handler | |
| CVE-2026-49421 | unlinkat(2) ignores AT_RESOLVE_BENEATH flag | |
| CVE-2026-49430 | Kernel heap overflow in ZFS_IOC_RECV_NEW ioctl | |
| CVE-2026-49429 | Kernel heap overflow in ZFS_IOC_USERSPACE_MANY ioctl | |
| CVE-2026-49431 | Incorrect user validation in ZFS_IOC_SET_PROP ioctl |
Showing top 20 of 23 CVEs. View all on vendor page → →
No comments yet