Linux kernel是美国Linux基金会开源的一款操作系统内核。 Linux kernel 6.12版本存在安全漏洞,该漏洞源于bpf模块在处理BTF重复字段计数时扩展字段计数计算使用u32整数导致回绕,绕过剩余容量检查,造成memcpy写入超出固定数组边界。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | 797d73ee232dd1833dec4824bc53a22032e97c1c< c5ff816d5f13900c3f1f3298cfcc61339e056e56 |
affected |
797d73ee232dd1833dec4824bc53a22032e97c1c< cd407de2ef5dc70f1970b343ffaa16186340fdfd |
affected | ||
797d73ee232dd1833dec4824bc53a22032e97c1c< ff77d013b737c0f77d925e2f2c59f0cf3d76bd35 |
affected | ||
797d73ee232dd1833dec4824bc53a22032e97c1c< b9452b594fd3aecbfd4aa0a6a1f741330a37dab7 |
affected | ||
6f957d972feee9b385ea3ae6530310a84e55ba71 |
affected | ||
6.11.6< 6.12 |
affected | ||
6.12 |
affected | ||
< 6.12 |
unaffected | ||
| … +4 more rows | |||
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-64355 | 9.8 CRITICAL | bpf: Reject fragmented frames in devmap |
| CVE-2026-64410 | 9.8 CRITICAL | netfilter: flowtable: IPIP tunnel hardware offload is not yet support |
| CVE-2026-64399 | 9.8 CRITICAL | ksmbd: add permission checks for FSCTL_DUPLICATE_EXTENTS_TO_FILE |
| CVE-2026-64397 | 9.8 CRITICAL | ksmbd: serialize QUERY_DIRECTORY requests per file |
| CVE-2026-64391 | 9.8 CRITICAL | ksmbd: use opener credentials for ADS I/O |
| CVE-2026-64387 | 9.8 CRITICAL | smb: client: fix query directory replay double-free |
| CVE-2026-64386 | 9.8 CRITICAL | smb: client: fix query_info() replay double-free |
| CVE-2026-64385 | 9.8 CRITICAL | smb: client: fix double-free in SMB2_ioctl() replay |
| CVE-2026-64383 | 9.8 CRITICAL | smb: client: fix double-free in SMB2_flush() replay |
| CVE-2026-64268 | 9.8 CRITICAL | RDMA/siw: bound Read Response placement to the RREAD length |
| CVE-2026-64384 | 9.8 CRITICAL | smb: client: fix change notify replay double-free |
| CVE-2026-64439 | 9.8 CRITICAL | crypto: krb5 - filter out async aead implementations at alloc |
| CVE-2026-64459 | 9.8 CRITICAL | tcp: restore RCU grace period in tcp_ao_destroy_sock |
| CVE-2026-64303 | 9.8 CRITICAL | spi: fsl-lpspi: terminate the RX channel on TX prepare failure path |
| CVE-2026-64523 | 9.8 CRITICAL | net/handshake: Take a long-lived file reference at submit |
| CVE-2026-64319 | 9.1 CRITICAL | nvmet-auth: validate reply message payload bounds against transfer length |
| CVE-2026-64393 | 9.1 CRITICAL | ksmbd: run set info with opener credentials |
| CVE-2026-64392 | 9.1 CRITICAL | ksmbd: use opener credentials for delete-on-close |
| CVE-2026-64269 | 9.1 CRITICAL | RDMA/rtrs-srv: Bound RDMA-Write length to chunk size in rdma_write_sg |
| CVE-2026-64450 | 9.1 CRITICAL | tipc: fix out-of-bounds read in broadcast Gap ACK blocks |
Showing top 20 of 274 CVEs. View all on vendor page → →
No comments yet