在 Linux 内核中,已解决以下漏洞: KVM: SVM:使用独立锁对所有者(owner)和镜像(mirror)列表的访问进行序列化 与 之间的交互可能导致两个独立的问题: 在 中,当目标 KVM 是镜像时,镜像条目会从源列表移动到所有者的 列表中,但与其他所有者的镜像列表写入函数(如 、 )不同,此操作未持有所有者的锁。因此,并发的 COPY 或 DESTROY 操作可能与 产生竞态,从而导致列表损坏。 在 中,所有者仍处于活跃状态,可能同时接收一个 请求,导致 发生变化。在这种情况下,错误的 VM 会被调用
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | b2125513dfc0dd0ec5a9605138a3c356592cfb73< 7943ec3a6d0e7e0a2eb4943300bce089ac3e8c3e |
affected |
b2125513dfc0dd0ec5a9605138a3c356592cfb73< 28afde1edbd8b20058cbf4d75fb57876471ec334 |
affected | ||
b2125513dfc0dd0ec5a9605138a3c356592cfb73< 328ab4fabe05af004d886659f8744076e320ddce |
affected | ||
b2125513dfc0dd0ec5a9605138a3c356592cfb73< 47976eaaf0a4eb46dade48b3246779090db9e3ec |
affected | ||
b2125513dfc0dd0ec5a9605138a3c356592cfb73< d728baba0f20e49439fc7831bf3e4e7dee82161a |
affected | ||
b2125513dfc0dd0ec5a9605138a3c356592cfb73< 1d78d33275ef2a16c6d080910b291d0a97a0e613 |
affected | ||
5.18 |
affected | ||
< 5.18 |
unaffected | ||
| … +6 more rows | |||
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-74705 | 10.0 CRITICAL | udp: fix potential use-after-free in tunnel segmentation |
| CVE-2026-74612 | 10.0 CRITICAL | veth: fix skb length accounting after XDP frag adjustment |
| CVE-2026-74611 | 9.8 CRITICAL | tls: rx: restore msg_iter before TLS 1.3 optimistic retry |
| CVE-2026-74591 | 9.8 CRITICAL | mm/filemap: __filemap_add_folio() restore index before retrying |
| CVE-2026-74662 | 9.8 CRITICAL | inet: frags: publish queues before arming timer |
| CVE-2026-74628 | 9.8 CRITICAL | net/x25: fix use-after-free of the socket by its timers |
| CVE-2026-74669 | 9.8 CRITICAL | ipvs: clear IPv4 options after rebasing tunnel ICMP errors |
| CVE-2026-74608 | 9.8 CRITICAL | smb: client: Fix use-after-free in cifs_try_adding_channels() |
| CVE-2026-74587 | 9.8 CRITICAL | sctp: fix use-after-free of cached ASCONF chunk |
| CVE-2026-74588 | 9.8 CRITICAL | sctp: keep chunk->transport in step with the list it is queued on |
| CVE-2026-74688 | 9.8 CRITICAL | sctp: clear control chunk transport if it is being removed |
| CVE-2026-74616 | 9.8 CRITICAL | xdp: reject clones that overrun skb_shared_info tailroom |
| CVE-2026-74730 | 9.8 CRITICAL | NFS: Pin the 'struct nfs_server' during a FREE_STATEID call |
| CVE-2026-74727 | 9.8 CRITICAL | ovpn: skip rehash for peers already removed from by_id |
| CVE-2026-74586 | 9.8 CRITICAL | sctp: clear new_transport when removing a peer |
| CVE-2026-74617 | 9.8 CRITICAL | dibs: initialise dibs->lock in dibs_dev_alloc() |
| CVE-2026-74597 | 9.8 CRITICAL | ip6_tunnel: clear skb2->cb[] in ip6ip6_err() |
| CVE-2026-74723 | 9.8 CRITICAL | btrfs: lzo: reject inline extents without valid headers |
| CVE-2026-74712 | 9.3 CRITICAL | vdpa/mlx5: Fix buffer length in create_direct_keys() |
| CVE-2026-74665 | 9.1 CRITICAL | net: fix skb length accounting after generic XDP frag adjustment |
Showing top 20 of 150 CVEs. View all on vendor page → →
No comments yet