该 ioctl 的实现尝试在同步组中对所有通道获取锁。如果锁定某个通道会导致阻塞,它会释放同步组列表锁并进入睡眠状态。当重新被唤醒时,同步组结构可能已被释放,但该实现未对此情况进行处理。 在多音频设备的系统上,本地未授权用户可利用此使用后释放(use-after-free)漏洞实现权限提升。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-58090 | Use-after-free in unix SOCK_STREAM message handling | |
| CVE-2026-58092 | Unauthorized credential switching | |
| CVE-2026-58089 | hwpmc fails to detach PMCs during exec credential transitions | |
| CVE-2026-58097 | ppp(8): missing length validation in mp_SetEnddisc() | |
| CVE-2026-58095 | ppp(8): incorrect length calculation in mp_Enddisc() | |
| CVE-2026-58093 | Kernel use-after-free via tty ioctls | |
| CVE-2026-58096 | ppp(8): missing length validation in LcpDecodeConfig() | |
| CVE-2026-58094 | TOCTOU race in POSIX shared memory large page configuration |
No comments yet