Linux kernel是美国Linux基金会开源的一个操作系统内核。 Linux kernel 5.15及之后版本存在安全漏洞,该漏洞源于hdr_find_split()函数在遍历NTFS条目时未验证条目大小,导致split-point偏移超出缓冲区并发生整数下溢,可能造成越界内核写入和内核崩溃。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | 82cae269cfa953032fbb8980a7d554d60fb00b17< 8e4ba5a38c155bb3c1c11e63cd285b178cdb099e |
affected |
82cae269cfa953032fbb8980a7d554d60fb00b17< 4c2f648139a0a86f4486170f72e24fedd4fae74e |
affected | ||
82cae269cfa953032fbb8980a7d554d60fb00b17< b232eb5c9fe11ec2368e9b565db69c724c35fbd2 |
affected | ||
82cae269cfa953032fbb8980a7d554d60fb00b17< 7bf74e6baf810fe325f111996496c678fc6e244f |
affected | ||
82cae269cfa953032fbb8980a7d554d60fb00b17< f3624cc069195001c88df7a291af215f2133ff2c |
affected | ||
82cae269cfa953032fbb8980a7d554d60fb00b17< 1758a564b6ebe7f4a82f23c9851d1cae15549457 |
affected | ||
82cae269cfa953032fbb8980a7d554d60fb00b17< f1df9d771df47aa40de6d70949c28720ae1e430d |
affected | ||
5.15 |
affected | ||
| … +8 more rows | |||
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-74475 | 10.0 CRITICAL | vxlan: use neigh_ha_snapshot() in route_shortcircuit() |
| CVE-2026-74280 | 10.0 CRITICAL | crypto: marvell/octeontx - fix DMA cleanup using wrong loop index |
| CVE-2026-72407 | 10.0 CRITICAL | geneve: validate inner network offset in geneve_gro_complete() |
| CVE-2026-72408 | 10.0 CRITICAL | geneve: gate GRO hint in geneve_gro_complete() on gs->gro_hint |
| CVE-2026-72421 | 10.0 CRITICAL | ipv4: fib: Don't ignore error route in local/main tables. |
| CVE-2026-74309 | 10.0 CRITICAL | vdpa/octeon_ep: fix IRQ-to-ring mapping in interrupt handler |
| CVE-2026-74279 | 10.0 CRITICAL | crypto: cavium/cpt - fix DMA cleanup using wrong loop index |
| CVE-2026-72493 | 9.9 CRITICAL | net: serialize netif_running() check in enqueue_to_backlog() |
| CVE-2026-72381 | 9.8 CRITICAL | ksmbd: fix use-after-free of fp->owner.name in durable handle owner check |
| CVE-2026-72393 | 9.8 CRITICAL | eth: fbnic: don't cache shinfo across skb realloc |
| CVE-2026-74401 | 9.8 CRITICAL | dlm: fix add msg handle in send_queue ordered |
| CVE-2026-74406 | 9.8 CRITICAL | vxlan: Fix potential null-ptr-deref in vxlan_gro_prepare_receive(). |
| CVE-2026-72355 | 9.8 CRITICAL | netfs: Fix barriering when walking subrequest list |
| CVE-2026-72339 | 9.8 CRITICAL | qede: fix off-by-one in BD ring consumption on build_skb failure |
| CVE-2026-72192 | 9.8 CRITICAL | ntfs3: bound to_move in indx_insert_into_root before hdr_insert_head |
| CVE-2026-72209 | 9.8 CRITICAL | ntfs: validate attribute values on lookup |
| CVE-2026-72351 | 9.8 CRITICAL | gue: validate REMCSUM private option length |
| CVE-2026-72366 | 9.8 CRITICAL | netfs: Fix netfs_create_write_req() to handle async cache object creation |
| CVE-2026-72098 | 9.8 CRITICAL | dm-verity: fix buffer overflow in FEC calculation |
| CVE-2026-72084 | 9.8 CRITICAL | scsi: target: Bound PR-OUT TransportID parsing to the received buffer |
Showing top 20 of 845 CVEs. View all on vendor page → →
No comments yet