目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1336 CNY

100%

CVE-2026-68435— Linux kernel 安全漏洞

AI Predicted 7.8 Difficulty: Moderate EPSS 0.15% · P5

Affected Version Matrix 8

ベンダープロダクトVersion Rangeステータス
LinuxLinux4a03b2ac06a5bcae29371866d9d11f5bfd4c9188< a94d6726ec8680a2b0c453fc782a543f68a1ea06affected
4a03b2ac06a5bcae29371866d9d11f5bfd4c9188< 7a54e0cbaad4a5a09e7cc7a4f05d181048e98ca7affected
4a03b2ac06a5bcae29371866d9d11f5bfd4c9188< 485ed44db5694d8d2e5027f63ad608e705286f30affected
6.1affected
< 6.1unaffected
6.18.42≤ 6.18.*unaffected
7.1.6≤ 7.1.*unaffected
7.2-rc5≤ *unaffected
新しい脆弱性情報の通知を購読するログインして購読

I. CVE-2026-68435の基本情報

脆弱性情報

脆弱性についてご質問がありますか?Shenlongの分析が参考になるかご確認ください!
Shenlongの10の質問を表示 ↗

高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。

脆弱性タイトル
LoongArch: Fix address space mismatch in kexec command line lookup
ソース: CVE Program / CVE List V5
脆弱性説明
In the Linux kernel, the following vulnerability has been resolved: LoongArch: Fix address space mismatch in kexec command line lookup When searching the loaded segments for the "kexec" command line marker, the kexec_load(2) path (file_mode == 0) passes the user-space segment buffer straight to strncmp() through a bogus (char __user *) cast. This dereferences a user pointer in kernel context, which is wrong and is flagged by sparse: arch/loongarch/kernel/machine_kexec.c:84:51: sparse: incorrect type in argument 2 (different address spaces) @@ expected char const * @@ got char [noderef] __user * Here copy the marker-sized prefix of each segment into a small on-stack buffer with copy_from_user() before comparing, and skip segments that fault. The subsequent copy_from_user() that stages the full command line into the safe area is left unchanged.
ソース: CVE Program / CVE List V5
CVSS情報
N/A
ソース: CVE Program / CVE List V5
脆弱性タイプ
N/A
ソース: CVE Program / CVE List V5
脆弱性タイトル
Linux kernel 安全漏洞
ソース: CNNVD (China National Vulnerability Database)
脆弱性説明
Linux kernel是美国Linux基金会开源的一个操作系统内核。 Linux kernel存在安全漏洞,该漏洞源于kexec命令行查找时存在地址空间不匹配,导致在内核上下文中错误解引用用户指针。
ソース: CNNVD (China National Vulnerability Database)
CVSS情報
N/A
ソース: CNNVD (China National Vulnerability Database)
脆弱性タイプ
N/A
ソース: CNNVD (China National Vulnerability Database)

影響を受ける製品

ベンダープロダクト影響を受けるバージョンCPE購読
LinuxLinux 4a03b2ac06a5bcae29371866d9d11f5bfd4c9188 ~ a94d6726ec8680a2b0c453fc782a543f68a1ea06 -
LinuxLinux 6.1 -

II. CVE-2026-68435の公開POC

#POC説明ソースリンクShenlongリンク
AI生成POCプレミアム

公開POCは見つかりませんでした。

ログインしてAI POCを生成

III. CVE-2026-68435のインテリジェンス情報

登录查看更多情报信息。

CVE-2026-68435 补丁与修复 (3)

Same Patch Batch · Linux · 2026-08-12 · 22 CVEs total

CVE-2026-684319.1 CRITICALksmbd: validate minimum PDU size for transform requests
CVE-2026-684328.8 HIGHvxlan: require CAP_NET_ADMIN in the device netns for changelink
CVE-2026-684338.6 HIGHlibceph: bound get_version reply decode to front len
CVE-2026-684467.8 HIGHdrm/vmwgfx: Validate vmw_surface_metadata::array_size
CVE-2026-684457.8 HIGHdrm/vc4: Prevent shader BO mappings from becoming writable
CVE-2026-684427.8 HIGHbtrfs: don't propagate EXTENT_FLAG_LOGGING to split extent maps
CVE-2026-684407.8 HIGHnet: txgbe: fix heap overflow when reading module EEPROM
CVE-2026-684477.1 HIGHdrm/amdkfd: clamp v9 CRIU control stack checkpoint copy to BO size
CVE-2026-68429drm/dp_mst: Handle torn-down topology gracefully in drm_dp_mst_topology_queue_probe()
CVE-2026-68450btrfs: free mapping node on duplicate reloc root insert
CVE-2026-68430drm/amdgpu/gfx8: drop unecessary BUG_ON()
CVE-2026-68434serial: 8250_mid: Fix NULL function pointer dereference on DNV/ICX-D/SNR platforms
CVE-2026-68436drm/amd/display: use kvzalloc to allocate struct dc
CVE-2026-68437drm/imagination: Fit paired fragment job in the correct CCCB
CVE-2026-68438smp: Make CSD lock acquisition atomic for debug mode
CVE-2026-68439wifi: mt76: mt7925: fix possible NULL-pointer deref in mt7925_mcu_bss_he_tlv()
CVE-2026-68441net/sched: Handle TC_ACT_REDIRECT from qdisc filter chains
CVE-2026-68443hwmon: (gigabyte_waterforce) Stop device IO before calling hid_hw_stop
CVE-2026-68444firmware: arm_ffa: Fix NULL dereference in ffa_partition_info_get()
CVE-2026-68448ovl: check access to copy_file_range source with src mounter creds

Showing 20 of 22 CVEs. View all on vendor page →

IV. 関連脆弱性

V. CVE-2026-68435へのコメント

まだコメントはありません


コメントを残す