Linux kernel是美国Linux基金会开源的一款操作系统内核。 Linux kernel存在安全漏洞,该漏洞源于函数check_and_correct_requested_length存在u32整数溢出,导致边界检查失败,可能使memmove读取超出节点缓冲区。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | 67ecc81f6492275c9c54280532f558483c99c90e< c8dd112173c02adf539fe2ad34a45f5e0068780d |
affected |
a1a60e79502279f996e55052f50cc14919020475< fc9d1447ca3cdc78d2e4ace1ce1f3a7c77ca08b1 |
affected | ||
fe2891a9c43ab87d1a210d61e6438ca6936e2f62< 671c3fcc2ad31c1311ea6414382a2d95104ae1b9 |
affected | ||
384a66b89f9540a9a8cb0f48807697dfabaece4c< b6a481642ea1977be2f84dc08c5affd742c177e7 |
affected | ||
efc095b35b23297e419c2ab4fc1ed1a8f0781a29< 7399c3baee7bb622a92f0b895cd4d3009a693f2b |
affected | ||
a431930c9bac518bf99d6b1da526a7f37ddee8d8< 607217f7ad419b53926f71e3f75001813bbc08ad |
affected | ||
a431930c9bac518bf99d6b1da526a7f37ddee8d8< c25d3c931a63e762fcaa9cb125b901c53b62403f |
affected | ||
a431930c9bac518bf99d6b1da526a7f37ddee8d8< 966cb76fb2857a4242cab6ea2ea17acf818a3da7 |
affected | ||
| … +21 more rows | |||
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-64355 | 9.8 CRITICAL | bpf: Reject fragmented frames in devmap |
| CVE-2026-64410 | 9.8 CRITICAL | netfilter: flowtable: IPIP tunnel hardware offload is not yet support |
| CVE-2026-64399 | 9.8 CRITICAL | ksmbd: add permission checks for FSCTL_DUPLICATE_EXTENTS_TO_FILE |
| CVE-2026-64397 | 9.8 CRITICAL | ksmbd: serialize QUERY_DIRECTORY requests per file |
| CVE-2026-64391 | 9.8 CRITICAL | ksmbd: use opener credentials for ADS I/O |
| CVE-2026-64387 | 9.8 CRITICAL | smb: client: fix query directory replay double-free |
| CVE-2026-64386 | 9.8 CRITICAL | smb: client: fix query_info() replay double-free |
| CVE-2026-64385 | 9.8 CRITICAL | smb: client: fix double-free in SMB2_ioctl() replay |
| CVE-2026-64383 | 9.8 CRITICAL | smb: client: fix double-free in SMB2_flush() replay |
| CVE-2026-64268 | 9.8 CRITICAL | RDMA/siw: bound Read Response placement to the RREAD length |
| CVE-2026-64384 | 9.8 CRITICAL | smb: client: fix change notify replay double-free |
| CVE-2026-64439 | 9.8 CRITICAL | crypto: krb5 - filter out async aead implementations at alloc |
| CVE-2026-64459 | 9.8 CRITICAL | tcp: restore RCU grace period in tcp_ao_destroy_sock |
| CVE-2026-64303 | 9.8 CRITICAL | spi: fsl-lpspi: terminate the RX channel on TX prepare failure path |
| CVE-2026-64523 | 9.8 CRITICAL | net/handshake: Take a long-lived file reference at submit |
| CVE-2026-64319 | 9.1 CRITICAL | nvmet-auth: validate reply message payload bounds against transfer length |
| CVE-2026-64393 | 9.1 CRITICAL | ksmbd: run set info with opener credentials |
| CVE-2026-64392 | 9.1 CRITICAL | ksmbd: use opener credentials for delete-on-close |
| CVE-2026-64269 | 9.1 CRITICAL | RDMA/rtrs-srv: Bound RDMA-Write length to chunk size in rdma_write_sg |
| CVE-2026-64450 | 9.1 CRITICAL | tipc: fix out-of-bounds read in broadcast Gap ACK blocks |
Showing top 20 of 274 CVEs. View all on vendor page → →
No comments yet