TIOCSCTTY 的 ioctl 处理程序在获取进程树锁之前释放了 tty 锁。在重新获取 tty 锁后,处理程序未重新验证终端的状态,可能会将正在被并发销毁的终端链接到调用进程所在的会话中。 非特权本地用户可利用此竞态条件提升权限。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-58090 | Use-after-free in unix SOCK_STREAM message handling | |
| CVE-2026-58091 | Kernel use-after-free via the SNDCTL_DSP_SYNCSTART ioctl | |
| CVE-2026-58092 | Unauthorized credential switching | |
| CVE-2026-58089 | hwpmc fails to detach PMCs during exec credential transitions | |
| CVE-2026-58097 | ppp(8): missing length validation in mp_SetEnddisc() | |
| CVE-2026-58095 | ppp(8): incorrect length calculation in mp_Enddisc() | |
| CVE-2026-58096 | ppp(8): missing length validation in LcpDecodeConfig() | |
| CVE-2026-58094 | TOCTOU race in POSIX shared memory large page configuration |
No comments yet