目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CVE-2026-68425— IB/mad 重组前丢弃未匹配 RMPP 响应漏洞

AI 预测 4.3 利用难度: 中等

影响版本矩阵 12

厂商产品版本范围状态
LinuxLinuxfa619a77046bef30478697aba0553991033afb8e< dfa535c94406c03d3f0c869ef3ba5528e395737caffected
fa619a77046bef30478697aba0553991033afb8e< 6e1bd7f590b0ccfee07f7fe1d48b92059bd37d72affected
fa619a77046bef30478697aba0553991033afb8e< 98d2d468b4faa1fdc68c0c6c238389906ee3490caffected
fa619a77046bef30478697aba0553991033afb8e< ad9c9ad3204f63a46f0f7de29687a8e512f05e29affected
fa619a77046bef30478697aba0553991033afb8e< d2e52d610b9b09694261632340b801a421e0b0c5affected
2.6.13affected
< 2.6.13unaffected
6.6.148≤ 6.6.*unaffected
… +4 条更多
获取后续新漏洞提醒登录后订阅

一、 漏洞 CVE-2026-68425 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
IB/mad: Drop unmatched RMPP responses before reassembly
来源: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: IB/mad: Drop unmatched RMPP responses before reassembly Kernel-handled RMPP receive processing starts reassembly for active DATA responses before the response is matched to an outstanding send. The normal match happens later, after ib_process_rmpp_recv_wc() has either assembled a complete message or consumed the segment. That ordering lets an unsolicited response that routes to a kernel RMPP agent by the high TID bits allocate or extend RMPP receive state before the full TID and source address are checked against a real request. A reordered burst can therefore reach the receive-side insertion path even though the response would not match any send. For kernel-handled RMPP DATA responses, require the existing ib_find_send_mad() match before entering RMPP reassembly. The matcher already checks the full TID, management class and source address/GID against the agent wait, backlog and in-flight send lists. If there is no match, drop the response without creating RMPP state. This leaves the RMPP window behavior unchanged and only rejects responses that have no corresponding request.
来源: CVE Program / CVE List V5
CVSS Information
N/A
来源: CVE Program / CVE List V5
Vulnerability Type
N/A
来源: CVE Program / CVE List V5

受影响产品

厂商产品影响版本CPE订阅
LinuxLinux fa619a77046bef30478697aba0553991033afb8e ~ dfa535c94406c03d3f0c869ef3ba5528e395737c -
LinuxLinux 2.6.13 -

二、漏洞 CVE-2026-68425 的公开POC

#POC 描述源链接神龙链接
AI 生成 POC高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2026-68425 的情报信息

登录查看更多情报信息。

CVE-2026-68425 补丁与修复 (5)

同批安全公告 · Linux · 2026-08-10 · 共 345 条

CVE-2026-68310mt76: mt7915驱动HE能力查询保护
CVE-2026-68320Linux内核SCTP协议栈认证列表容量检查漏洞
CVE-2026-68319pds_core 重置与移除死锁漏洞
CVE-2026-68318pds_core 工作队列移除时存在释放后使用漏洞
CVE-2026-68317pds_core 辅助设备添加/删除竞态漏洞
CVE-2026-68316加速驱动 Ethos-U 命令流校验元素大小处理漏洞
CVE-2026-68315SCTP协议栈在sctp_process_strreset_inreq()中验证流数
CVE-2026-68314Linux内核mctp i3c驱动注册失败处理漏洞
CVE-2026-68313TIPC __tipc_nl_compat_dumpit无限循环漏洞
CVE-2026-68312CIFS:kmalloc失败时cifsFileInfo泄漏
CVE-2026-68311mt7925无线网卡解封装卸载时STA链路保护缺陷
CVE-2026-68305drm/xe/vf CCS读写缓冲区分离时添加设备守卫
CVE-2026-68300Linux SCTP 认证模块空指针检查漏洞
CVE-2026-68301HSR 从节点注销内存泄漏漏洞
CVE-2026-68302amt: 拉取后重新读取skb头指针
CVE-2026-68303Linux内核 DRM VC4 HVS/V3D 解除绑定空指针解引用漏洞
CVE-2026-68304brcmfmac Wi-Fi驱动 802.1X-SHA256调用跟踪警告漏洞
CVE-2026-68307mt7925 WiFi驱动重置链路重播崩溃漏洞
CVE-2026-68309mt76驱动BSS HE TLV处理空指针解引用漏洞
CVE-2026-68308mt76_connac_get_he_phy_cap()返回值未检查

显示前 20 条,共 345 条。 查看全部 &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-68425

暂无评论


发表评论