Linux kernel是美国Linux基金会开源的一款操作系统内核。 Linux kernel 6.18版本存在安全漏洞,该漏洞源于多点触控驱动在访问mt_io_flags时未正确限制槽位索引边界,导致越界位访问,可能造成空指针解引用和内核崩溃。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | fc488f675344931ffab6a51c43691065ec006567< 12e90656e330ff8bbaf2f29c535fdb8a11cc6f55 |
affected |
77711d850bed75ae7142c3d1f22c1a8b4d049c33< 152983d87387f6a8ae72b73474cfa55fbcf1ec75 |
affected | ||
6acfe25968913788d30ec0eedd80178c4ea3f1d0< b5c037d6b807017e74a115288f81bc9cd5a5aab8 |
affected | ||
d280c138e66be87d1fccfed42593f02fdb893905< a6d5ce2e1a2d7bf189bde8a659d04b65f0b0725d |
affected | ||
f32fea4c0234c971c12e46d76612cdc2dd4bb046< e24918ee67c4dc3d20d4670750e46e9b160365f4 |
affected | ||
46f781e0d151844589dc2125c8cce3300546f92a< 37daa8c96bd563d03150e23f094cb60703594a6d |
affected | ||
46f781e0d151844589dc2125c8cce3300546f92a< 6493ebf9489efef0105078377b973ab33d51af22 |
affected | ||
46f781e0d151844589dc2125c8cce3300546f92a< 8813b0612275cc61fe9e6603d0ee019247ade6be |
affected | ||
| … +17 more rows | |||
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-64355 | 9.8 CRITICAL | bpf: Reject fragmented frames in devmap |
| CVE-2026-64410 | 9.8 CRITICAL | netfilter: flowtable: IPIP tunnel hardware offload is not yet support |
| CVE-2026-64399 | 9.8 CRITICAL | ksmbd: add permission checks for FSCTL_DUPLICATE_EXTENTS_TO_FILE |
| CVE-2026-64397 | 9.8 CRITICAL | ksmbd: serialize QUERY_DIRECTORY requests per file |
| CVE-2026-64391 | 9.8 CRITICAL | ksmbd: use opener credentials for ADS I/O |
| CVE-2026-64387 | 9.8 CRITICAL | smb: client: fix query directory replay double-free |
| CVE-2026-64386 | 9.8 CRITICAL | smb: client: fix query_info() replay double-free |
| CVE-2026-64385 | 9.8 CRITICAL | smb: client: fix double-free in SMB2_ioctl() replay |
| CVE-2026-64383 | 9.8 CRITICAL | smb: client: fix double-free in SMB2_flush() replay |
| CVE-2026-64268 | 9.8 CRITICAL | RDMA/siw: bound Read Response placement to the RREAD length |
| CVE-2026-64384 | 9.8 CRITICAL | smb: client: fix change notify replay double-free |
| CVE-2026-64439 | 9.8 CRITICAL | crypto: krb5 - filter out async aead implementations at alloc |
| CVE-2026-64523 | 9.8 CRITICAL | net/handshake: Take a long-lived file reference at submit |
| CVE-2026-64459 | 9.8 CRITICAL | tcp: restore RCU grace period in tcp_ao_destroy_sock |
| CVE-2026-64303 | 9.8 CRITICAL | spi: fsl-lpspi: terminate the RX channel on TX prepare failure path |
| CVE-2026-64257 | 9.1 CRITICAL | smb: client: reject overlapping data areas in SMB2 responses |
| CVE-2026-64269 | 9.1 CRITICAL | RDMA/rtrs-srv: Bound RDMA-Write length to chunk size in rdma_write_sg |
| CVE-2026-64393 | 9.1 CRITICAL | ksmbd: run set info with opener credentials |
| CVE-2026-64320 | 9.1 CRITICAL | nvmet: fix pre-auth out-of-bounds heap read in Discovery Get Log Page |
| CVE-2026-64319 | 9.1 CRITICAL | nvmet-auth: validate reply message payload bounds against transfer length |
Showing top 20 of 274 CVEs. View all on vendor page → →
No comments yet