在 Linux 内核中,已修复以下漏洞: ALSA: usb: 修复 MIDI2 端点延迟释放时的使用-after-free(UAF)漏洞 最近对 函数中 UAF 漏洞的修复引入了另一个 UAF 问题,因为该函数尝试解引用 UMP 端点对象,但这可能在延迟上下文中执行,而此时端点已被释放。 添加 回调以清除相关数据,从而避免在延迟释放时再次解引用。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | 49eccef6d6e1c00dac6fb2e7eb6f9206c33e1c37< d431941825d357be7d9ab0cb7505e3a1963bd89e |
affected |
8a7a33b846d6ba695891b8d0040027cdbad8cd52< 422d8a02de5ce6a29d616d55e5ead5dec69ac1d7 |
affected | ||
cc014ebf803174f0e5d15956dfc5a38413c945ae< d217d723c5e43881b952cdb978477f7f2dc0b6d7 |
affected | ||
ae388c0e1bf727972096f770f82d12e4f748d1b6< f9d492a39ebeb1a56f13ec6dd165a18a48dec812 |
affected | ||
4a05b2d1b4642df74f30b6f54843e825c4a2bfd3< f8a80cfb68613fb7e6452b66447dbc63f435d140 |
affected | ||
6.6.151< 6.6.152 |
affected | ||
6.12.103< 6.12.104 |
affected | ||
6.18.44< 6.18.45 |
affected | ||
| … +1 more rows | |||
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-74705 | 10.0 CRITICAL | udp: fix potential use-after-free in tunnel segmentation |
| CVE-2026-74612 | 10.0 CRITICAL | veth: fix skb length accounting after XDP frag adjustment |
| CVE-2026-74608 | 9.8 CRITICAL | smb: client: Fix use-after-free in cifs_try_adding_channels() |
| CVE-2026-74591 | 9.8 CRITICAL | mm/filemap: __filemap_add_folio() restore index before retrying |
| CVE-2026-74611 | 9.8 CRITICAL | tls: rx: restore msg_iter before TLS 1.3 optimistic retry |
| CVE-2026-74628 | 9.8 CRITICAL | net/x25: fix use-after-free of the socket by its timers |
| CVE-2026-74669 | 9.8 CRITICAL | ipvs: clear IPv4 options after rebasing tunnel ICMP errors |
| CVE-2026-74597 | 9.8 CRITICAL | ip6_tunnel: clear skb2->cb[] in ip6ip6_err() |
| CVE-2026-74662 | 9.8 CRITICAL | inet: frags: publish queues before arming timer |
| CVE-2026-74587 | 9.8 CRITICAL | sctp: fix use-after-free of cached ASCONF chunk |
| CVE-2026-74688 | 9.8 CRITICAL | sctp: clear control chunk transport if it is being removed |
| CVE-2026-74723 | 9.8 CRITICAL | btrfs: lzo: reject inline extents without valid headers |
| CVE-2026-74730 | 9.8 CRITICAL | NFS: Pin the 'struct nfs_server' during a FREE_STATEID call |
| CVE-2026-74617 | 9.8 CRITICAL | dibs: initialise dibs->lock in dibs_dev_alloc() |
| CVE-2026-74727 | 9.8 CRITICAL | ovpn: skip rehash for peers already removed from by_id |
| CVE-2026-74586 | 9.8 CRITICAL | sctp: clear new_transport when removing a peer |
| CVE-2026-74616 | 9.8 CRITICAL | xdp: reject clones that overrun skb_shared_info tailroom |
| CVE-2026-74588 | 9.8 CRITICAL | sctp: keep chunk->transport in step with the list it is queued on |
| CVE-2026-74712 | 9.3 CRITICAL | vdpa/mlx5: Fix buffer length in create_direct_keys() |
| CVE-2026-74665 | 9.1 CRITICAL | net: fix skb length accounting after generic XDP frag adjustment |
Showing top 20 of 150 CVEs. View all on vendor page → →
No comments yet