Linux kernel是美国Linux基金会开源的一款操作系统内核。 Linux kernel 6.8之前版本存在释放后重用漏洞,该漏洞源于drm/v3d驱动中CPU任务错误路径上查询数组释放后重用,可能导致空指针取消引用和syncobj引用泄漏的用户交互问题。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | 9ba0ff3e083f6a4a0b6698f06bfff74805fefa5f< acd55ea40d03e06f20a9986363019e0e5173990e |
affected |
9ba0ff3e083f6a4a0b6698f06bfff74805fefa5f< 0f8efc45740b0628a787d1b0be8a0ddabd700625 |
affected | ||
9ba0ff3e083f6a4a0b6698f06bfff74805fefa5f< 69c2a1fec2e7ca25598180816f3bc56e1842eb41 |
affected | ||
9ba0ff3e083f6a4a0b6698f06bfff74805fefa5f< b0fe80c0b9250b35e2211bf3117e7aca814a21b0 |
affected | ||
6.8 |
affected | ||
< 6.8 |
unaffected | ||
6.12.93≤ 6.12.* |
unaffected | ||
6.18.34≤ 6.18.* |
unaffected | ||
| … +2 more rows | |||
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-63795 | 10.0 CRITICAL | 9p: avoid putting oldfid in p9_client_walk() error path |
| CVE-2026-64091 | 9.8 CRITICAL | batman-adv: tt: fix TOCTOU race for reported vlans |
| CVE-2026-53399 | 9.8 CRITICAL | nfsd: release layout stid on setlease failure |
| CVE-2026-53398 | 9.8 CRITICAL | NFSD: Fix SECINFO_NO_NAME decode error cleanup |
| CVE-2026-64047 | 9.8 CRITICAL | net: tls: fix off-by-one in sg_chain entry count for wrapped sk_msg ring |
| CVE-2026-64102 | 9.8 CRITICAL | RDMA/siw: Reject MPA FPDU length underflow before signed receive math |
| CVE-2026-64056 | 9.8 CRITICAL | net: ethernet: cortina: Make RX SKB per-port |
| CVE-2026-64046 | 9.8 CRITICAL | net: tls: prevent chain-after-chain in plain text SG |
| CVE-2026-63984 | 9.8 CRITICAL | ipv6: rpl: fix hdrlen overflow in ipv6_rpl_srh_decompress() |
| CVE-2026-63800 | 9.8 CRITICAL | pNFS: Fix use-after-free in pnfs_update_layout() |
| CVE-2026-64061 | 9.8 CRITICAL | netfs: Fix early put of sink folio in netfs_read_gaps() |
| CVE-2026-63924 | 9.8 CRITICAL | ipv6: exthdrs: refresh nh pointer after ipv6_hop_jumbo() |
| CVE-2026-64089 | 9.8 CRITICAL | batman-adv: tt: fix negative last_changeset_len |
| CVE-2026-64136 | 9.8 CRITICAL | smb: client: protect tc_count increment in smb2_find_smb_sess_tcon_unlocked() |
| CVE-2026-63979 | 9.8 CRITICAL | net/handshake: hand off the pinned file reference to accept_doit |
| CVE-2026-63886 | 9.8 CRITICAL | scsi: target: iscsi: Validate CHAP_R length before base64 decode |
| CVE-2026-63887 | 9.8 CRITICAL | scsi: target: iscsi: Bound iscsi_encode_text_output() appends to rsp_buf |
| CVE-2026-64122 | 9.8 CRITICAL | net/mlx5e: Fix use-after-free in mlx5e_tx_reporter_timeout_recover |
| CVE-2026-64125 | 9.8 CRITICAL | net: bcmgenet: keep RBUF EEE/PM disabled |
| CVE-2026-63825 | 9.8 CRITICAL | gcov: use atomic counter updates to fix concurrent access crashes |
Showing top 20 of 429 CVEs. View all on vendor page → →
No comments yet