Linux kernel是美国Linux基金会开源的一款操作系统内核。 Linux kernel 5.18版本存在安全漏洞,该漏洞源于rpmsg字符设备在探测错误路径上的释放后重用(use-after-free)问题,可能导致默认端点分发回调时使用已释放的priv指针。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | bc69d10665690492421d926b1cd9a7a36bffd691< 1306fc4f76f765727a6d5aefbf08ef0c8f32996f |
affected |
bc69d10665690492421d926b1cd9a7a36bffd691< ddf13f91ca82c94ef7ad9c41a434a03313f8eb1b |
affected | ||
bc69d10665690492421d926b1cd9a7a36bffd691< c5ebb06c7e24d531b68707168e04698859d642bc |
affected | ||
bc69d10665690492421d926b1cd9a7a36bffd691< 104d100212396801f1d9d388282f746e23e2bfd6 |
affected | ||
bc69d10665690492421d926b1cd9a7a36bffd691< ff268cd9ccbce6472a0658791b417bf11c31ee39 |
affected | ||
bc69d10665690492421d926b1cd9a7a36bffd691< 1ff3f528e67d20e2b1483dcaba899dc7832b2e6b |
affected | ||
5.18 |
affected | ||
< 5.18 |
unaffected | ||
| … +6 more rows | |||
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-63795 | 10.0 CRITICAL | 9p: avoid putting oldfid in p9_client_walk() error path |
| CVE-2026-63887 | 9.8 CRITICAL | scsi: target: iscsi: Bound iscsi_encode_text_output() appends to rsp_buf |
| CVE-2026-64102 | 9.8 CRITICAL | RDMA/siw: Reject MPA FPDU length underflow before signed receive math |
| CVE-2026-64142 | 9.8 CRITICAL | ksmbd: close durable scavenger races against m_fp_list lookups |
| CVE-2026-64125 | 9.8 CRITICAL | net: bcmgenet: keep RBUF EEE/PM disabled |
| CVE-2026-63924 | 9.8 CRITICAL | ipv6: exthdrs: refresh nh pointer after ipv6_hop_jumbo() |
| CVE-2026-63922 | 9.8 CRITICAL | ipv6: exthdrs: refresh nh after handling HAO option |
| CVE-2026-63857 | 9.8 CRITICAL | net: airoha: Do not read uninitialized fragment address in airoha_dev_xmit() |
| CVE-2026-53399 | 9.8 CRITICAL | nfsd: release layout stid on setlease failure |
| CVE-2026-53398 | 9.8 CRITICAL | NFSD: Fix SECINFO_NO_NAME decode error cleanup |
| CVE-2026-63984 | 9.8 CRITICAL | ipv6: rpl: fix hdrlen overflow in ipv6_rpl_srh_decompress() |
| CVE-2026-64162 | 9.8 CRITICAL | idpf: fix read_dev_clk_lock spinlock init in idpf_ptp_init() |
| CVE-2026-64025 | 9.8 CRITICAL | bpf, skmsg: fix verdict sk_data_ready racing with ktls rx |
| CVE-2026-64056 | 9.8 CRITICAL | net: ethernet: cortina: Make RX SKB per-port |
| CVE-2026-64055 | 9.8 CRITICAL | net: ethernet: cortina: Carry over frag counter |
| CVE-2026-63808 | 9.8 CRITICAL | exfat: fix potential use-after-free in exfat_find_dir_entry() |
| CVE-2026-63978 | 9.8 CRITICAL | net/handshake: Drain pending requests at net namespace exit |
| CVE-2026-64150 | 9.8 CRITICAL | netfilter: nft_inner: release local_lock before re-enabling softirqs |
| CVE-2026-63800 | 9.8 CRITICAL | pNFS: Fix use-after-free in pnfs_update_layout() |
| CVE-2026-63888 | 9.8 CRITICAL | scsi: target: iscsi: Fix CRC overread and double-free in iscsit_handle_text_cmd() |
Showing top 20 of 429 CVEs. View all on vendor page → →
No comments yet