在 Linux 内核中,已解决以下漏洞: sctp:在移除对等端时清除 new_transport 会将新添加的对等端传输地址存储在 中。在处理完 ASCONF 块中的所有参数后, 会使用此指针向新传输地址发送 HEARTBEAT(心跳)消息。 来自远程 SCTP 对等端经认证的 ASCONF 消息可以在同一个块中添加一个传输地址,并使用通配符 DEL-IP 参数立即将其移除。通配符删除会保留接收该 ASCONF 消息的传输地址,但通过 移除新添加的传输地址。然而,移除操作并未清空 ,导致该指针仍指向已被移除的传输
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | 6af29ccc223b0feb6fc6112281c3fa3cdb1afddf< c0f973bb5118dd1b146cda3fcc8af6f6057befec |
affected |
6af29ccc223b0feb6fc6112281c3fa3cdb1afddf< 3b539b317cd052236fed0350364ff1268996ba46 |
affected | ||
6af29ccc223b0feb6fc6112281c3fa3cdb1afddf< db9d8e3b670f841755bc2018f178472dc6064d27 |
affected | ||
6af29ccc223b0feb6fc6112281c3fa3cdb1afddf< 31efa656cf6aface26e88f038c14f22ee6ca1500 |
affected | ||
6af29ccc223b0feb6fc6112281c3fa3cdb1afddf< 291accf36febce751021888de5f15090f4875b56 |
affected | ||
6af29ccc223b0feb6fc6112281c3fa3cdb1afddf< ca33df36aa0143a1d04f57d2086020c12e7eddb7 |
affected | ||
6af29ccc223b0feb6fc6112281c3fa3cdb1afddf< 163847552a571bd55094291f4ffcdc1de0f14a7b |
affected | ||
6af29ccc223b0feb6fc6112281c3fa3cdb1afddf< beb33f8ee1ca83acddb2a5ae80f3d22ec550b4c3 |
affected | ||
| … +10 more rows | |||
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-74705 | 10.0 CRITICAL | udp: fix potential use-after-free in tunnel segmentation |
| CVE-2026-74612 | 10.0 CRITICAL | veth: fix skb length accounting after XDP frag adjustment |
| CVE-2026-74723 | 9.8 CRITICAL | btrfs: lzo: reject inline extents without valid headers |
| CVE-2026-74628 | 9.8 CRITICAL | net/x25: fix use-after-free of the socket by its timers |
| CVE-2026-74669 | 9.8 CRITICAL | ipvs: clear IPv4 options after rebasing tunnel ICMP errors |
| CVE-2026-74611 | 9.8 CRITICAL | tls: rx: restore msg_iter before TLS 1.3 optimistic retry |
| CVE-2026-74597 | 9.8 CRITICAL | ip6_tunnel: clear skb2->cb[] in ip6ip6_err() |
| CVE-2026-74587 | 9.8 CRITICAL | sctp: fix use-after-free of cached ASCONF chunk |
| CVE-2026-74608 | 9.8 CRITICAL | smb: client: Fix use-after-free in cifs_try_adding_channels() |
| CVE-2026-74617 | 9.8 CRITICAL | dibs: initialise dibs->lock in dibs_dev_alloc() |
| CVE-2026-74662 | 9.8 CRITICAL | inet: frags: publish queues before arming timer |
| CVE-2026-74616 | 9.8 CRITICAL | xdp: reject clones that overrun skb_shared_info tailroom |
| CVE-2026-74730 | 9.8 CRITICAL | NFS: Pin the 'struct nfs_server' during a FREE_STATEID call |
| CVE-2026-74688 | 9.8 CRITICAL | sctp: clear control chunk transport if it is being removed |
| CVE-2026-74588 | 9.8 CRITICAL | sctp: keep chunk->transport in step with the list it is queued on |
| CVE-2026-74727 | 9.8 CRITICAL | ovpn: skip rehash for peers already removed from by_id |
| CVE-2026-74591 | 9.8 CRITICAL | mm/filemap: __filemap_add_folio() restore index before retrying |
| CVE-2026-74712 | 9.3 CRITICAL | vdpa/mlx5: Fix buffer length in create_direct_keys() |
| CVE-2026-74665 | 9.1 CRITICAL | net: fix skb length accounting after generic XDP frag adjustment |
| CVE-2026-74629 | 8.8 HIGH | net/dibs: Correct freeing of dmb_clientid_arr |
Showing top 20 of 150 CVEs. View all on vendor page → →
No comments yet