Linux kernel是美国Linux基金会开源的一款操作系统内核。 Linux kernel存在安全漏洞,该漏洞源于iptfs_clone_state()函数使用kmemdup()克隆SA时复制了运行时对象(包括sk_buff_head、hrtimers、spinlock和重组/重排序状态),导致这些对象与原SA共享。当xfrm_state_migrate()在clone_state()之后、init_state()重新初始化这些字段之前失败时,克隆状态会被xfrm_state_gc_task()销毁
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | 0e4fbf013fa566f274ce9b4ce698c75b1f998c52< 9327252e04626d4bb02ca8c0c108fbe8eabf0c5a |
affected |
0e4fbf013fa566f274ce9b4ce698c75b1f998c52< dfb9f6cbfa9826655a49698cf90eb800fce2178e |
affected | ||
0e4fbf013fa566f274ce9b4ce698c75b1f998c52< 7f83d174073234839aea176f265e517e0d50a1d2 |
affected | ||
6.14 |
affected | ||
< 6.14 |
unaffected | ||
6.18.35≤ 6.18.* |
unaffected | ||
7.0.12≤ 7.0.* |
unaffected | ||
7.1≤ * |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-63795 | 10.0 CRITICAL | 9p: avoid putting oldfid in p9_client_walk() error path |
| CVE-2026-64089 | 9.8 CRITICAL | batman-adv: tt: fix negative last_changeset_len |
| CVE-2026-53398 | 9.8 CRITICAL | NFSD: Fix SECINFO_NO_NAME decode error cleanup |
| CVE-2026-63984 | 9.8 CRITICAL | ipv6: rpl: fix hdrlen overflow in ipv6_rpl_srh_decompress() |
| CVE-2026-64025 | 9.8 CRITICAL | bpf, skmsg: fix verdict sk_data_ready racing with ktls rx |
| CVE-2026-63979 | 9.8 CRITICAL | net/handshake: hand off the pinned file reference to accept_doit |
| CVE-2026-64033 | 9.8 CRITICAL | RDMA/rtrs: Fix use-after-free in path file creation cleanup |
| CVE-2026-64056 | 9.8 CRITICAL | net: ethernet: cortina: Make RX SKB per-port |
| CVE-2026-63800 | 9.8 CRITICAL | pNFS: Fix use-after-free in pnfs_update_layout() |
| CVE-2026-63978 | 9.8 CRITICAL | net/handshake: Drain pending requests at net namespace exit |
| CVE-2026-64055 | 9.8 CRITICAL | net: ethernet: cortina: Carry over frag counter |
| CVE-2026-63808 | 9.8 CRITICAL | exfat: fix potential use-after-free in exfat_find_dir_entry() |
| CVE-2026-63888 | 9.8 CRITICAL | scsi: target: iscsi: Fix CRC overread and double-free in iscsit_handle_text_cmd() |
| CVE-2026-63887 | 9.8 CRITICAL | scsi: target: iscsi: Bound iscsi_encode_text_output() appends to rsp_buf |
| CVE-2026-64113 | 9.8 CRITICAL | ixgbevf: fix use-after-free in VEPA multicast source pruning |
| CVE-2026-63886 | 9.8 CRITICAL | scsi: target: iscsi: Validate CHAP_R length before base64 decode |
| CVE-2026-64162 | 9.8 CRITICAL | idpf: fix read_dev_clk_lock spinlock init in idpf_ptp_init() |
| CVE-2026-64035 | 9.8 CRITICAL | igc: set tx buffer type for SMD frames |
| CVE-2026-64150 | 9.8 CRITICAL | netfilter: nft_inner: release local_lock before re-enabling softirqs |
| CVE-2026-63922 | 9.8 CRITICAL | ipv6: exthdrs: refresh nh after handling HAO option |
Showing top 20 of 429 CVEs. View all on vendor page → →
No comments yet