在 Linux 内核中,已修复以下漏洞: drm/v3d:序列化调度器超时处理程序 V3D 暴露了多个独立的硬件队列(BIN、RENDER、TFU 和 CSD),但仅有一个全局重置机制。因此,任何单个队列的超时都必須停止、重置并重新启动所有其他队列的调度器。这使得并发执行的超时处理程序变得不安全。 此前始终无法确保安全,因为驱动程序侧的锁只能覆盖驱动程序的 回调函数。调度器在该回调函数之外处理超时作业及其待处理列表,超出了驱动程序的直接控制范围。因此,由一个队列触发的全局重置仍可能与另一个正在处理自身超时的队列发生
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | 35e4079bf1a2570abffce6ababa631afcf8ea0e5< 5884851a096d8afcdf91f0e542bac193035183a6 |
affected |
35e4079bf1a2570abffce6ababa631afcf8ea0e5< c22a45817b9c92aa0391db60e2ed467c7e6027d7 |
affected | ||
35e4079bf1a2570abffce6ababa631afcf8ea0e5< 4da94744707b27a3ae1197bdd7127da4505dc5b1 |
affected | ||
5235b56b7e5449d990d21d78723b1a5e7bb5738e |
affected | ||
12125f7d9c15e6d8ac91d10373b2db2f17dcf767 |
affected | ||
a5f162727b91e480656da1876247a91f651f76de |
affected | ||
422a8b10ba42097a704d6909ada2956f880246f2 |
affected | ||
6.1.139< 6.2 |
affected | ||
| … +8 more rows | |||
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-74705 | 10.0 CRITICAL | udp: fix potential use-after-free in tunnel segmentation |
| CVE-2026-74612 | 10.0 CRITICAL | veth: fix skb length accounting after XDP frag adjustment |
| CVE-2026-74608 | 9.8 CRITICAL | smb: client: Fix use-after-free in cifs_try_adding_channels() |
| CVE-2026-74591 | 9.8 CRITICAL | mm/filemap: __filemap_add_folio() restore index before retrying |
| CVE-2026-74611 | 9.8 CRITICAL | tls: rx: restore msg_iter before TLS 1.3 optimistic retry |
| CVE-2026-74628 | 9.8 CRITICAL | net/x25: fix use-after-free of the socket by its timers |
| CVE-2026-74669 | 9.8 CRITICAL | ipvs: clear IPv4 options after rebasing tunnel ICMP errors |
| CVE-2026-74597 | 9.8 CRITICAL | ip6_tunnel: clear skb2->cb[] in ip6ip6_err() |
| CVE-2026-74662 | 9.8 CRITICAL | inet: frags: publish queues before arming timer |
| CVE-2026-74587 | 9.8 CRITICAL | sctp: fix use-after-free of cached ASCONF chunk |
| CVE-2026-74688 | 9.8 CRITICAL | sctp: clear control chunk transport if it is being removed |
| CVE-2026-74723 | 9.8 CRITICAL | btrfs: lzo: reject inline extents without valid headers |
| CVE-2026-74730 | 9.8 CRITICAL | NFS: Pin the 'struct nfs_server' during a FREE_STATEID call |
| CVE-2026-74617 | 9.8 CRITICAL | dibs: initialise dibs->lock in dibs_dev_alloc() |
| CVE-2026-74727 | 9.8 CRITICAL | ovpn: skip rehash for peers already removed from by_id |
| CVE-2026-74586 | 9.8 CRITICAL | sctp: clear new_transport when removing a peer |
| CVE-2026-74616 | 9.8 CRITICAL | xdp: reject clones that overrun skb_shared_info tailroom |
| CVE-2026-74588 | 9.8 CRITICAL | sctp: keep chunk->transport in step with the list it is queued on |
| CVE-2026-74712 | 9.3 CRITICAL | vdpa/mlx5: Fix buffer length in create_direct_keys() |
| CVE-2026-74665 | 9.1 CRITICAL | net: fix skb length accounting after generic XDP frag adjustment |
Showing top 20 of 150 CVEs. View all on vendor page → →
No comments yet