Linux kernel是美国Linux基金会开源的一个操作系统内核。 Linux kernel存在安全漏洞,该漏洞源于drivers/char/tpm/tpm2-sessions.c中的tpm_buf_append_salt函数调用crypto_kpp_generate_public_key和crypto_kpp_compute_shared_secret时未安装完成回调即释放请求,导致异步KPP后端出现释放后重用,可能引发内核崩溃。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | 1085b8276bb4239daa7008f0dcd5c973e4bd690f< 111e520efbe82b324bc42b1999b723c0619eea6d |
affected |
1085b8276bb4239daa7008f0dcd5c973e4bd690f< 934d1cd40e2893bf7a041b54f6afd1c008d7a21c |
affected | ||
1085b8276bb4239daa7008f0dcd5c973e4bd690f< 493333f167926c7adab8e7563e21ad71d8af84fa |
affected | ||
1085b8276bb4239daa7008f0dcd5c973e4bd690f< 73851a7c43dfa52d2ed9415889b33daf85da0ed9 |
affected | ||
6.10 |
affected | ||
< 6.10 |
unaffected | ||
6.12.97≤ 6.12.* |
unaffected | ||
6.18.40≤ 6.18.* |
unaffected | ||
| … +2 more rows | |||
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-74475 | 10.0 CRITICAL | vxlan: use neigh_ha_snapshot() in route_shortcircuit() |
| CVE-2026-74280 | 10.0 CRITICAL | crypto: marvell/octeontx - fix DMA cleanup using wrong loop index |
| CVE-2026-72407 | 10.0 CRITICAL | geneve: validate inner network offset in geneve_gro_complete() |
| CVE-2026-72408 | 10.0 CRITICAL | geneve: gate GRO hint in geneve_gro_complete() on gs->gro_hint |
| CVE-2026-72421 | 10.0 CRITICAL | ipv4: fib: Don't ignore error route in local/main tables. |
| CVE-2026-74309 | 10.0 CRITICAL | vdpa/octeon_ep: fix IRQ-to-ring mapping in interrupt handler |
| CVE-2026-74279 | 10.0 CRITICAL | crypto: cavium/cpt - fix DMA cleanup using wrong loop index |
| CVE-2026-72493 | 9.9 CRITICAL | net: serialize netif_running() check in enqueue_to_backlog() |
| CVE-2026-72381 | 9.8 CRITICAL | ksmbd: fix use-after-free of fp->owner.name in durable handle owner check |
| CVE-2026-72393 | 9.8 CRITICAL | eth: fbnic: don't cache shinfo across skb realloc |
| CVE-2026-74401 | 9.8 CRITICAL | dlm: fix add msg handle in send_queue ordered |
| CVE-2026-74406 | 9.8 CRITICAL | vxlan: Fix potential null-ptr-deref in vxlan_gro_prepare_receive(). |
| CVE-2026-72355 | 9.8 CRITICAL | netfs: Fix barriering when walking subrequest list |
| CVE-2026-72339 | 9.8 CRITICAL | qede: fix off-by-one in BD ring consumption on build_skb failure |
| CVE-2026-72211 | 9.8 CRITICAL | ntfs: grow index root value before reparent header update |
| CVE-2026-72194 | 9.8 CRITICAL | fs/ntfs3: add depth limit to indx_find_buffer to prevent stack overflow |
| CVE-2026-72351 | 9.8 CRITICAL | gue: validate REMCSUM private option length |
| CVE-2026-72366 | 9.8 CRITICAL | netfs: Fix netfs_create_write_req() to handle async cache object creation |
| CVE-2026-72098 | 9.8 CRITICAL | dm-verity: fix buffer overflow in FEC calculation |
| CVE-2026-72083 | 9.8 CRITICAL | scsi: target: core: Fix iSCSI ISID use-after-free in REGISTER AND MOVE |
Showing top 20 of 845 CVEs. View all on vendor page → →
No comments yet