在将解密操作分发到 OCF(Open Crypto Framework,开放加密框架)并接收结果后,wg(4) 驱动程序未能检查 MAC(消息认证码)验证步骤是否成功。因此,该驱动程序默许了携带无效 Poly1305 认证标签的数据包。 若远程攻击者能够向 WireGuard 端点发送 UDP 数据包,并且能够推测出接收方重放窗口(replay window)的边界,则可以向隧道中注入伪造或篡改的传输数据数据包。 若远程攻击者能够拦截发往 FreeBSD 主机的 WireGuard 数据包,则可以在不被接收方检测到
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-49426 | Incorrect audit records for ptrace(2) syscall requests | |
| CVE-2026-58087 | Heap out-of-bounds access in semctl(2) | |
| CVE-2026-58088 | Race condition in ELF core dump segment counting | |
| CVE-2026-58083 | Use-after-free in kqueue copy-on-fork | |
| CVE-2026-58084 | Kernel stack disclosure via timer_settime(2) | |
| CVE-2026-58086 | ktrace(2) privilege incorrectly validated in jails | |
| CVE-2026-49425 | Kernel stack disclosure in 32-bit compatibility support | |
| CVE-2026-49424 | Kernel stack disclosure in Linux compatibility layer | |
| CVE-2026-58081 | Heap based buffer overflow in iconv(3) | |
| CVE-2026-58082 | Stack based buffer overflow in iconv(3) | |
| CVE-2026-49423 | Remote DOS via uninitialized memory access in KTLS receive | |
| CVE-2026-49418 | Use-after-free in device pager page list | |
| CVE-2026-49427 | posixshm: largepage shared memory objects not explicitly wired | |
| CVE-2026-49428 | posixshm: system calls can incorrectly free memory of largepage objects | |
| CVE-2026-49420 | Buffer overflow in libalias RTSP handler | |
| CVE-2026-49422 | Use-after-free in TCP RACK stack option handler | |
| CVE-2026-49421 | unlinkat(2) ignores AT_RESOLVE_BENEATH flag | |
| CVE-2026-49430 | Kernel heap overflow in ZFS_IOC_RECV_NEW ioctl | |
| CVE-2026-49429 | Kernel heap overflow in ZFS_IOC_USERSPACE_MANY ioctl | |
| CVE-2026-49431 | Incorrect user validation in ZFS_IOC_SET_PROP ioctl |
Showing top 20 of 23 CVEs. View all on vendor page → →
No comments yet