Linux kernel是美国Linux基金会开源的一款操作系统内核。 Linux kernel 6.12版本存在释放后重用漏洞,该漏洞源于l2tp_session_get_by_ifname()函数中未使用refcount_inc_not_zero(),导致引用计数为零的会话指针可能被返回,进而引发释放后重用。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | abe7a1a7d0b69e63b1bca5f9531023a52336784f< ee80455feffb9cb62b5b58715cabeff495e666b2 |
affected |
abe7a1a7d0b69e63b1bca5f9531023a52336784f< 947013fd7c8c35dd5856557b215840098a3f67f8 |
affected | ||
abe7a1a7d0b69e63b1bca5f9531023a52336784f< 782d60a6596aee9b29c2eecfa70033899278bf65 |
affected | ||
abe7a1a7d0b69e63b1bca5f9531023a52336784f< 05f95729ca844704d15e49ce14868af4b403b32b |
affected | ||
6.12 |
affected | ||
< 6.12 |
unaffected | ||
6.12.93≤ 6.12.* |
unaffected | ||
6.18.35≤ 6.18.* |
unaffected | ||
| … +2 more rows | |||
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-63795 | 10.0 CRITICAL | 9p: avoid putting oldfid in p9_client_walk() error path |
| CVE-2026-64016 | 9.8 CRITICAL | ksmbd: fix durable reconnect error path file lifetime |
| CVE-2026-53398 | 9.8 CRITICAL | NFSD: Fix SECINFO_NO_NAME decode error cleanup |
| CVE-2026-64136 | 9.8 CRITICAL | smb: client: protect tc_count increment in smb2_find_smb_sess_tcon_unlocked() |
| CVE-2026-64037 | 9.8 CRITICAL | wifi: iwlwifi: mld: fix TSO segmentation explosion when AMSDU is disabled |
| CVE-2026-64035 | 9.8 CRITICAL | igc: set tx buffer type for SMD frames |
| CVE-2026-63800 | 9.8 CRITICAL | pNFS: Fix use-after-free in pnfs_update_layout() |
| CVE-2026-64033 | 9.8 CRITICAL | RDMA/rtrs: Fix use-after-free in path file creation cleanup |
| CVE-2026-64142 | 9.8 CRITICAL | ksmbd: close durable scavenger races against m_fp_list lookups |
| CVE-2026-63808 | 9.8 CRITICAL | exfat: fix potential use-after-free in exfat_find_dir_entry() |
| CVE-2026-63888 | 9.8 CRITICAL | scsi: target: iscsi: Fix CRC overread and double-free in iscsit_handle_text_cmd() |
| CVE-2026-64025 | 9.8 CRITICAL | bpf, skmsg: fix verdict sk_data_ready racing with ktls rx |
| CVE-2026-63887 | 9.8 CRITICAL | scsi: target: iscsi: Bound iscsi_encode_text_output() appends to rsp_buf |
| CVE-2026-64089 | 9.8 CRITICAL | batman-adv: tt: fix negative last_changeset_len |
| CVE-2026-63886 | 9.8 CRITICAL | scsi: target: iscsi: Validate CHAP_R length before base64 decode |
| CVE-2026-64122 | 9.8 CRITICAL | net/mlx5e: Fix use-after-free in mlx5e_tx_reporter_timeout_recover |
| CVE-2026-64102 | 9.8 CRITICAL | RDMA/siw: Reject MPA FPDU length underflow before signed receive math |
| CVE-2026-63984 | 9.8 CRITICAL | ipv6: rpl: fix hdrlen overflow in ipv6_rpl_srh_decompress() |
| CVE-2026-63979 | 9.8 CRITICAL | net/handshake: hand off the pinned file reference to accept_doit |
| CVE-2026-63993 | 9.8 CRITICAL | vxlan: do not reuse cached ip_hdr() value after skb_tunnel_check_pmtu() |
Showing top 20 of 429 CVEs. View all on vendor page → →
No comments yet