目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CVE-2026-64248— Linux kernel 安全漏洞

一分钟漏洞结论

影响对象
Linux Linux
利用判断
尚无明确在野利用证据,仍需结合暴露面评估
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

Linux kernel是美国Linux基金会开源的一款操作系统内核。 Linux kernel存在安全漏洞,该漏洞源于stop_this_cpu()函数在标记CPU离线时未通知RCU,导致重启时挂起。

AI 预测 4.3 利用难度: 中等 EPSS 0.11% · P2

可能的 ATT&CK 技术 1 AI

T1499 · Endpoint Denial of Service

影响版本矩阵 20

厂商产品 版本范围状态
Linux Linux 2dc79362302922cb18f35e262712b5e58de65442< f8a1ef884013dc99f712d3eb75624c7cd3fd94f6 affected
eef4f71b46a9929ac33e968538c9dd5d96a02460< e1919d026706544cb6e7251ec06e908edd6f34ee affected
684a78183c54c23e70d1cba320f7fc184604210b< 6eda71977ee11c222f8ad4cae4d18d50448e56f4 affected
18c0456ea2615b1a743a6db739c74411c3b42bc6< f9b57a0015c241274651f4b36627f56b1b5a8651 affected
91840be8f710370607f949a627e070896faeddb8< 9fef09df42df55ab819b285ea892e0fc1b95a9c4 affected
91840be8f710370607f949a627e070896faeddb8< 9f3f3bdc6d9dac1a5a8262ee7ad0f2ff1527a7e7 affected
81b582784518196eff1050212a046bc29d3a05dd affected
6.1.175< 6.1.178 affected
… +12 条更多
获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2026-64248 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
MIPS: smp: report dying CPU to RCU in stop_this_cpu()
来源: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: MIPS: smp: report dying CPU to RCU in stop_this_cpu() smp_send_stop() parks all secondary CPUs in stop_this_cpu(). The function marks the CPU offline for the scheduler via set_cpu_online(false) but never informs RCU, so RCU keeps expecting a quiescent state from CPUs that are now spinning forever with interrupts disabled. As long as nothing waits for an RCU grace period after smp_send_stop() this is harmless, which is why it went unnoticed. Since commit 91840be8f710 ("irq_work: Fix use-after-free in irq_work_single() on PREEMPT_RT") however, irq_work_sync() calls synchronize_rcu() on architectures without an irq_work self-IPI, i.e. where arch_irq_work_has_interrupt() returns false. That is the asm-generic default used by MIPS. Any irq_work_sync() issued in the reboot/shutdown path after smp_send_stop() then blocks on a grace period that can never complete, hanging the reboot: WARNING: CPU: 0 PID: 15 at kernel/irq_work.c:144 irq_work_queue_on ... rcu: INFO: rcu_sched detected stalls on CPUs/tasks: rcu: Offline CPU 1 blocking current GP. rcu: Offline CPU 2 blocking current GP. rcu: Offline CPU 3 blocking current GP. This issue was noticed on several Realtek MIPS switch SoCs (MIPS interAptiv) and came up during kernel bump downstream in OpenWrt from 6.18.33 to 6.18.34, after the backport of the patch to the 6.18 stable branch. The patch also has been backported all the way back to 6.1. Call rcutree_report_cpu_dead() once interrupts are disabled, mirroring the generic CPU-hotplug offline path, so RCU stops waiting on the parked CPUs and grace periods can still complete. MIPS shuts down all CPUs here without going through the CPU-hotplug mechanism, so this report is not otherwise issued. Reporting a dying CPU to RCU outside the regular hotplug offline path is not unprecedented: arm64 does the same in cpu_die_early(). There it is an exception for a CPU that was coming online and is aborting bringup, rather than the default shutdown action as on MIPS.
来源: CVE Program / CVE List V5
CVSS Information
N/A
来源: CVE Program / CVE List V5
Vulnerability Type
N/A
来源: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Description
Linux kernel是美国Linux基金会开源的一款操作系统内核。 Linux kernel存在安全漏洞,该漏洞源于stop_this_cpu()函数在标记CPU离线时未通知RCU,导致重启时挂起。
来源: 中国国家信息安全漏洞库 CNNVD
CVSS Information
N/A
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Type
N/A
来源: 中国国家信息安全漏洞库 CNNVD

受影响产品

厂商 产品 影响版本 CPE 订阅
Linux Linux 2dc79362302922cb18f35e262712b5e58de65442 ~ f8a1ef884013dc99f712d3eb75624c7cd3fd94f6 -
Linux Linux 7.1 -

二、漏洞 CVE-2026-64248 的公开POC

# POC 描述 源链接 神龙链接
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2026-64248 的情报信息

登录查看更多情报信息。

CVE-2026-64248 补丁与修复 (5)

同批安全公告 · Linux · 2026-07-24 · 共 48 条

CVE-2026-64232 9.8 CRITICAL Linux kernel 安全漏洞
CVE-2026-64216 9.8 CRITICAL Linux kernel 安全漏洞
CVE-2026-64255 8.8 HIGH Linux kernel 安全漏洞
CVE-2026-64247 8.4 HIGH Linux kernel 安全漏洞
CVE-2026-64223 8.1 HIGH Linux kernel 安全漏洞
CVE-2026-64235 8.1 HIGH Linux kernel 安全漏洞
CVE-2026-64226 7.8 HIGH Linux kernel 安全漏洞
CVE-2026-64217 7.8 HIGH Linux kernel 安全漏洞
CVE-2026-64218 7.8 HIGH Linux kernel 安全漏洞
CVE-2026-64221 7.8 HIGH Linux kernel 安全漏洞
CVE-2026-64251 7.8 HIGH Linux kernel 安全漏洞
CVE-2026-64208 7.5 HIGH Linux kernel 安全漏洞
CVE-2026-64210 7.5 HIGH Linux kernel 安全漏洞
CVE-2026-64243 7.1 HIGH Linux kernel 安全漏洞
CVE-2026-64219 7.0 HIGH Linux kernel 安全漏洞
CVE-2026-64222 7.0 HIGH Linux kernel 安全漏洞
CVE-2026-64224 Linux kernel 安全漏洞
CVE-2026-64227 Linux kernel 安全漏洞
CVE-2026-64209 Linux kernel 安全漏洞
CVE-2026-64225 Linux kernel 安全漏洞

显示前 20 条,共 48 条。 查看全部 &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-64248

暂无评论


发表评论