在 Linux 内核中,已修复以下漏洞: XDP:拒绝超出 skb_shared_info 尾部空间(tailroom)的克隆帧 函数将广播副本克隆到单个页面中,并将 设置为 。随后, 将该页面视为普通的 XDP 帧,并期望在缓冲区末尾存在常规的 尾部空间。 当前的检查仅拒绝那些线性部分的 XDP 帧头、头部预留空间(headroom)以及包数据总大小超过 的帧。然而,由更大分配 backing 的源帧仍可能通过此检查,但其数据会延伸到克隆帧所需的共享信息区域。当此类克隆帧被转换回 sk_buff(skb)结构时,
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | e624d4ed4aa8cc3c69d1359b0aaea539203ed266< 58408982fa39f9758124cec169f42854d6f98f35 |
affected |
e624d4ed4aa8cc3c69d1359b0aaea539203ed266< 685edea27ac68d08fe4dbd3de74b858d2ad8e830 |
affected | ||
e624d4ed4aa8cc3c69d1359b0aaea539203ed266< ba13763d667e008e185fedf592d53846a5b457d1 |
affected | ||
e624d4ed4aa8cc3c69d1359b0aaea539203ed266< ef4b7c7046d29a67090de15af0da0d1ae8d1b192 |
affected | ||
e624d4ed4aa8cc3c69d1359b0aaea539203ed266< fab820f1691a9e26d9031f18aae1e9ce09078f92 |
affected | ||
e624d4ed4aa8cc3c69d1359b0aaea539203ed266< f463b6f4957c9c3fd1c75f8d3e5af4879fa609c0 |
affected | ||
e624d4ed4aa8cc3c69d1359b0aaea539203ed266< e48e8edbef2eb824201495daa5234560f632b23c |
affected | ||
5.14 |
affected | ||
| … +8 more rows | |||
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-74612 | 10.0 CRITICAL | veth: fix skb length accounting after XDP frag adjustment |
| CVE-2026-74705 | 10.0 CRITICAL | udp: fix potential use-after-free in tunnel segmentation |
| CVE-2026-74730 | 9.8 CRITICAL | NFS: Pin the 'struct nfs_server' during a FREE_STATEID call |
| CVE-2026-74617 | 9.8 CRITICAL | dibs: initialise dibs->lock in dibs_dev_alloc() |
| CVE-2026-74727 | 9.8 CRITICAL | ovpn: skip rehash for peers already removed from by_id |
| CVE-2026-74586 | 9.8 CRITICAL | sctp: clear new_transport when removing a peer |
| CVE-2026-74597 | 9.8 CRITICAL | ip6_tunnel: clear skb2->cb[] in ip6ip6_err() |
| CVE-2026-74688 | 9.8 CRITICAL | sctp: clear control chunk transport if it is being removed |
| CVE-2026-74611 | 9.8 CRITICAL | tls: rx: restore msg_iter before TLS 1.3 optimistic retry |
| CVE-2026-74723 | 9.8 CRITICAL | btrfs: lzo: reject inline extents without valid headers |
| CVE-2026-74588 | 9.8 CRITICAL | sctp: keep chunk->transport in step with the list it is queued on |
| CVE-2026-74628 | 9.8 CRITICAL | net/x25: fix use-after-free of the socket by its timers |
| CVE-2026-74587 | 9.8 CRITICAL | sctp: fix use-after-free of cached ASCONF chunk |
| CVE-2026-74669 | 9.8 CRITICAL | ipvs: clear IPv4 options after rebasing tunnel ICMP errors |
| CVE-2026-74591 | 9.8 CRITICAL | mm/filemap: __filemap_add_folio() restore index before retrying |
| CVE-2026-74662 | 9.8 CRITICAL | inet: frags: publish queues before arming timer |
| CVE-2026-74608 | 9.8 CRITICAL | smb: client: Fix use-after-free in cifs_try_adding_channels() |
| CVE-2026-74712 | 9.3 CRITICAL | vdpa/mlx5: Fix buffer length in create_direct_keys() |
| CVE-2026-74665 | 9.1 CRITICAL | net: fix skb length accounting after generic XDP frag adjustment |
| CVE-2026-74615 | 8.8 HIGH | vxlan: do not arm the ageing timer on a device that is down |
Showing top 20 of 150 CVEs. View all on vendor page → →
No comments yet