在 Linux 内核中,已修复以下漏洞: vsock/virtio:在工作器锁的保护下读取 virtqueues 提交 bd50c5dc182b(“vsock/virtio:添加对设备挂起/恢复的支持”)导致在恢复过程中安装新的 virtqueues 时,*_run 标志从 false 变为 true。RX、TX 和事件工作器在未加锁的情况下先读取其 virtqueue,再检查对应的标志。因此,若在挂起和恢复之间被延迟的工作器可能会观察到新 virtqueue 的运行状态,但仍保留对已删除旧 virtqueue 的
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | 762c251c7f5c4ee5bef71460c6e822ed293fd69f< 941329ce14c5f481223a10d1d4c8b57ea7f3048a |
affected |
bd50c5dc182b0a52599f87b429f9a5a9cbfc9b1c< 29dd10583bf9d2744cd84b862e4257c0a5699570 |
affected | ||
bd50c5dc182b0a52599f87b429f9a5a9cbfc9b1c< a1fb0c5b8a7c2753758aeced40971f99449dde0c |
affected | ||
bd50c5dc182b0a52599f87b429f9a5a9cbfc9b1c< eae099c764c7ebdb842eb1f638913e310bdd6513 |
affected | ||
bd50c5dc182b0a52599f87b429f9a5a9cbfc9b1c< bd43a7ec668be428265b3209eb43647aedcf720a |
affected | ||
bd50c5dc182b0a52599f87b429f9a5a9cbfc9b1c< 1cecb4202afdbeddcf29d59baf596ac6ab753f7f |
affected | ||
bd50c5dc182b0a52599f87b429f9a5a9cbfc9b1c< ebac8f6b1ef0e9278afe204b8692a7479988dace |
affected | ||
5.15.138< 5.15.216 |
affected | ||
| … +9 more rows | |||
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-74705 | 10.0 CRITICAL | udp: fix potential use-after-free in tunnel segmentation |
| CVE-2026-74612 | 10.0 CRITICAL | veth: fix skb length accounting after XDP frag adjustment |
| CVE-2026-74669 | 9.8 CRITICAL | ipvs: clear IPv4 options after rebasing tunnel ICMP errors |
| CVE-2026-74628 | 9.8 CRITICAL | net/x25: fix use-after-free of the socket by its timers |
| CVE-2026-74608 | 9.8 CRITICAL | smb: client: Fix use-after-free in cifs_try_adding_channels() |
| CVE-2026-74662 | 9.8 CRITICAL | inet: frags: publish queues before arming timer |
| CVE-2026-74688 | 9.8 CRITICAL | sctp: clear control chunk transport if it is being removed |
| CVE-2026-74587 | 9.8 CRITICAL | sctp: fix use-after-free of cached ASCONF chunk |
| CVE-2026-74591 | 9.8 CRITICAL | mm/filemap: __filemap_add_folio() restore index before retrying |
| CVE-2026-74588 | 9.8 CRITICAL | sctp: keep chunk->transport in step with the list it is queued on |
| CVE-2026-74727 | 9.8 CRITICAL | ovpn: skip rehash for peers already removed from by_id |
| CVE-2026-74616 | 9.8 CRITICAL | xdp: reject clones that overrun skb_shared_info tailroom |
| CVE-2026-74730 | 9.8 CRITICAL | NFS: Pin the 'struct nfs_server' during a FREE_STATEID call |
| CVE-2026-74723 | 9.8 CRITICAL | btrfs: lzo: reject inline extents without valid headers |
| CVE-2026-74586 | 9.8 CRITICAL | sctp: clear new_transport when removing a peer |
| CVE-2026-74597 | 9.8 CRITICAL | ip6_tunnel: clear skb2->cb[] in ip6ip6_err() |
| CVE-2026-74611 | 9.8 CRITICAL | tls: rx: restore msg_iter before TLS 1.3 optimistic retry |
| CVE-2026-74617 | 9.8 CRITICAL | dibs: initialise dibs->lock in dibs_dev_alloc() |
| CVE-2026-74712 | 9.3 CRITICAL | vdpa/mlx5: Fix buffer length in create_direct_keys() |
| CVE-2026-74665 | 9.1 CRITICAL | net: fix skb length accounting after generic XDP frag adjustment |
Showing top 20 of 150 CVEs. View all on vendor page → →
No comments yet