ELF 核心转储(core dump)代码首先计算可转储的虚拟内存映射条目数量,为对应的程序头分配缓冲区,然后第二次遍历该映射以填充这些程序头。由于通过 共享地址空间的进程可以在两次遍历之间修改映射内容,导致第二次遍历时将程序头写入缓冲区末尾之外。 一个本地非特权用户,若与发生核心转储的进程共享地址空间,则可触发内核堆上的越界写入漏洞,可能导致权限提升(privilege escalation)。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-49426 | Incorrect audit records for ptrace(2) syscall requests | |
| CVE-2026-58087 | Heap out-of-bounds access in semctl(2) | |
| CVE-2026-58083 | Use-after-free in kqueue copy-on-fork | |
| CVE-2026-58084 | Kernel stack disclosure via timer_settime(2) | |
| CVE-2026-58085 | Missing MAC validation in wg(4) packet decryption | |
| CVE-2026-58086 | ktrace(2) privilege incorrectly validated in jails | |
| CVE-2026-49425 | Kernel stack disclosure in 32-bit compatibility support | |
| CVE-2026-49424 | Kernel stack disclosure in Linux compatibility layer | |
| CVE-2026-58081 | Heap based buffer overflow in iconv(3) | |
| CVE-2026-58082 | Stack based buffer overflow in iconv(3) | |
| CVE-2026-49423 | Remote DOS via uninitialized memory access in KTLS receive | |
| CVE-2026-49418 | Use-after-free in device pager page list | |
| CVE-2026-49427 | posixshm: largepage shared memory objects not explicitly wired | |
| CVE-2026-49428 | posixshm: system calls can incorrectly free memory of largepage objects | |
| CVE-2026-49420 | Buffer overflow in libalias RTSP handler | |
| CVE-2026-49422 | Use-after-free in TCP RACK stack option handler | |
| CVE-2026-49421 | unlinkat(2) ignores AT_RESOLVE_BENEATH flag | |
| CVE-2026-49430 | Kernel heap overflow in ZFS_IOC_RECV_NEW ioctl | |
| CVE-2026-49429 | Kernel heap overflow in ZFS_IOC_USERSPACE_MANY ioctl | |
| CVE-2026-49431 | Incorrect user validation in ZFS_IOC_SET_PROP ioctl |
Showing top 20 of 23 CVEs. View all on vendor page → →
No comments yet