在 Linux 内核中,已修复以下漏洞: mm/damon/ops-common:在迁移节点(nid)无效时将页(folios)放回 LRU 列表 和 函数会将页(folios)隔离到一个局部列表中,然后调用 。当目标节点 ID(target_nid)无效时(包括使用 scheme 默认的 / -1), 会提前返回,而没有将这些页重新放回 LRU(最近最少使用)链表。 调用方随后会丢弃列表头,但这些页仍保持隔离状态,且由于 已获取了额外的引用计数。这些页一直位于 LRU 之外,表现为匿名活跃和非活跃计数下降,而 R
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | 7c303fa1f311aadc17fa82b7bbf776412adf45de< 7001c0a1bc9018cd5b2b72ebebb216d738b2ec81 |
affected |
7e6c3130690a01076efdf45aa02ba5d5c16849a0< 460181e4bb47a57776c64f0832c2096de8878cb3 |
affected | ||
7e6c3130690a01076efdf45aa02ba5d5c16849a0< cfef454862b7d2776e0955b873dd59af6b47cfcb |
affected | ||
7e6c3130690a01076efdf45aa02ba5d5c16849a0< 5deb65c34e682e7c5f5df417a70e223e8fcc5f5a |
affected | ||
9d0c2d15aff96746f99a7c97221bb8ce5b62db19 |
affected | ||
6.12.44< 6.12.105 |
affected | ||
6.16.4< 6.17 |
affected | ||
6.17 |
affected | ||
| … +5 more rows | |||
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-74705 | 10.0 CRITICAL | udp: fix potential use-after-free in tunnel segmentation |
| CVE-2026-74612 | 10.0 CRITICAL | veth: fix skb length accounting after XDP frag adjustment |
| CVE-2026-74608 | 9.8 CRITICAL | smb: client: Fix use-after-free in cifs_try_adding_channels() |
| CVE-2026-74591 | 9.8 CRITICAL | mm/filemap: __filemap_add_folio() restore index before retrying |
| CVE-2026-74611 | 9.8 CRITICAL | tls: rx: restore msg_iter before TLS 1.3 optimistic retry |
| CVE-2026-74628 | 9.8 CRITICAL | net/x25: fix use-after-free of the socket by its timers |
| CVE-2026-74669 | 9.8 CRITICAL | ipvs: clear IPv4 options after rebasing tunnel ICMP errors |
| CVE-2026-74597 | 9.8 CRITICAL | ip6_tunnel: clear skb2->cb[] in ip6ip6_err() |
| CVE-2026-74662 | 9.8 CRITICAL | inet: frags: publish queues before arming timer |
| CVE-2026-74587 | 9.8 CRITICAL | sctp: fix use-after-free of cached ASCONF chunk |
| CVE-2026-74688 | 9.8 CRITICAL | sctp: clear control chunk transport if it is being removed |
| CVE-2026-74723 | 9.8 CRITICAL | btrfs: lzo: reject inline extents without valid headers |
| CVE-2026-74617 | 9.8 CRITICAL | dibs: initialise dibs->lock in dibs_dev_alloc() |
| CVE-2026-74730 | 9.8 CRITICAL | NFS: Pin the 'struct nfs_server' during a FREE_STATEID call |
| CVE-2026-74727 | 9.8 CRITICAL | ovpn: skip rehash for peers already removed from by_id |
| CVE-2026-74586 | 9.8 CRITICAL | sctp: clear new_transport when removing a peer |
| CVE-2026-74616 | 9.8 CRITICAL | xdp: reject clones that overrun skb_shared_info tailroom |
| CVE-2026-74588 | 9.8 CRITICAL | sctp: keep chunk->transport in step with the list it is queued on |
| CVE-2026-74712 | 9.3 CRITICAL | vdpa/mlx5: Fix buffer length in create_direct_keys() |
| CVE-2026-74665 | 9.1 CRITICAL | net: fix skb length accounting after generic XDP frag adjustment |
Showing top 20 of 150 CVEs. View all on vendor page → →
No comments yet