Linux kernel是美国Linux基金会开源的一款操作系统内核。 Linux kernel 6.14版本存在安全漏洞,该漏洞源于fuse_uring_commit函数中copy_from_user返回值处理不当,导致EFAULT错误被正数残留覆盖,可能使调用者使用未初始化或部分数据。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | c090c8abae4b6b77a1bee116aa6c385456ebef96< 0483fffdeeb363f320e6bf5fc0f0306007507306 |
affected |
c090c8abae4b6b77a1bee116aa6c385456ebef96< fe604c08d874648a69187f6380e5c7858627dc04 |
affected | ||
c090c8abae4b6b77a1bee116aa6c385456ebef96< 3a0a8bc51a13951c5141262bf770eeea3e0b6228 |
affected | ||
6.14 |
affected | ||
< 6.14 |
unaffected | ||
6.18.39≤ 6.18.* |
unaffected | ||
7.1.4≤ 7.1.* |
unaffected | ||
7.2≤ * |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-64355 | 9.8 CRITICAL | bpf: Reject fragmented frames in devmap |
| CVE-2026-64459 | 9.8 CRITICAL | tcp: restore RCU grace period in tcp_ao_destroy_sock |
| CVE-2026-64303 | 9.8 CRITICAL | spi: fsl-lpspi: terminate the RX channel on TX prepare failure path |
| CVE-2026-64439 | 9.8 CRITICAL | crypto: krb5 - filter out async aead implementations at alloc |
| CVE-2026-64410 | 9.8 CRITICAL | netfilter: flowtable: IPIP tunnel hardware offload is not yet support |
| CVE-2026-64399 | 9.8 CRITICAL | ksmbd: add permission checks for FSCTL_DUPLICATE_EXTENTS_TO_FILE |
| CVE-2026-64397 | 9.8 CRITICAL | ksmbd: serialize QUERY_DIRECTORY requests per file |
| CVE-2026-64391 | 9.8 CRITICAL | ksmbd: use opener credentials for ADS I/O |
| CVE-2026-64387 | 9.8 CRITICAL | smb: client: fix query directory replay double-free |
| CVE-2026-64386 | 9.8 CRITICAL | smb: client: fix query_info() replay double-free |
| CVE-2026-64385 | 9.8 CRITICAL | smb: client: fix double-free in SMB2_ioctl() replay |
| CVE-2026-64383 | 9.8 CRITICAL | smb: client: fix double-free in SMB2_flush() replay |
| CVE-2026-64384 | 9.8 CRITICAL | smb: client: fix change notify replay double-free |
| CVE-2026-64268 | 9.8 CRITICAL | RDMA/siw: bound Read Response placement to the RREAD length |
| CVE-2026-64523 | 9.8 CRITICAL | net/handshake: Take a long-lived file reference at submit |
| CVE-2026-64257 | 9.1 CRITICAL | smb: client: reject overlapping data areas in SMB2 responses |
| CVE-2026-64392 | 9.1 CRITICAL | ksmbd: use opener credentials for delete-on-close |
| CVE-2026-64393 | 9.1 CRITICAL | ksmbd: run set info with opener credentials |
| CVE-2026-64269 | 9.1 CRITICAL | RDMA/rtrs-srv: Bound RDMA-Write length to chunk size in rdma_write_sg |
| CVE-2026-64319 | 9.1 CRITICAL | nvmet-auth: validate reply message payload bounds against transfer length |
Showing top 20 of 274 CVEs. View all on vendor page → →
No comments yet