在 Linux 内核中,已修复以下漏洞: 串口:amba-pl011:在释放 IRQ 后取消 RS485 高精度实时定时器(hrtimers) RS485 触发用的高精度实时定时器(hrtimers)嵌入在由 devm 管理的端口结构中,可能在端口被释放后仍会被触发。由于 IRQ 处理程序可能会启动定时器,因此应先释放 IRQ,再取消这两个定时器。 在 RS485 停止操作时不再启动定时器,并在 remove() 函数中取消定时器,以处理 suspend-then-unbind(挂起后解除绑定)路径,在此路径中不会
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | 2c1fd53af21b8cb13878b054894d33d3383eb1f3< 759ead98a39fb625be302f9aa66290985dcaa325 |
affected |
2c1fd53af21b8cb13878b054894d33d3383eb1f3< e57f0aa5c35be37218ba0e4887b241584dd4b2d2 |
affected | ||
2c1fd53af21b8cb13878b054894d33d3383eb1f3< 36672c8d7d14e9c43287528455d2c97b526ea6ad |
affected | ||
6.14 |
affected | ||
< 6.14 |
unaffected | ||
6.18.45≤ 6.18.* |
unaffected | ||
7.1.9≤ 7.1.* |
unaffected | ||
7.2≤ * |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-74705 | 10.0 CRITICAL | udp: fix potential use-after-free in tunnel segmentation |
| CVE-2026-74612 | 10.0 CRITICAL | veth: fix skb length accounting after XDP frag adjustment |
| CVE-2026-74597 | 9.8 CRITICAL | ip6_tunnel: clear skb2->cb[] in ip6ip6_err() |
| CVE-2026-74591 | 9.8 CRITICAL | mm/filemap: __filemap_add_folio() restore index before retrying |
| CVE-2026-74662 | 9.8 CRITICAL | inet: frags: publish queues before arming timer |
| CVE-2026-74669 | 9.8 CRITICAL | ipvs: clear IPv4 options after rebasing tunnel ICMP errors |
| CVE-2026-74608 | 9.8 CRITICAL | smb: client: Fix use-after-free in cifs_try_adding_channels() |
| CVE-2026-74628 | 9.8 CRITICAL | net/x25: fix use-after-free of the socket by its timers |
| CVE-2026-74688 | 9.8 CRITICAL | sctp: clear control chunk transport if it is being removed |
| CVE-2026-74587 | 9.8 CRITICAL | sctp: fix use-after-free of cached ASCONF chunk |
| CVE-2026-74588 | 9.8 CRITICAL | sctp: keep chunk->transport in step with the list it is queued on |
| CVE-2026-74727 | 9.8 CRITICAL | ovpn: skip rehash for peers already removed from by_id |
| CVE-2026-74611 | 9.8 CRITICAL | tls: rx: restore msg_iter before TLS 1.3 optimistic retry |
| CVE-2026-74723 | 9.8 CRITICAL | btrfs: lzo: reject inline extents without valid headers |
| CVE-2026-74617 | 9.8 CRITICAL | dibs: initialise dibs->lock in dibs_dev_alloc() |
| CVE-2026-74586 | 9.8 CRITICAL | sctp: clear new_transport when removing a peer |
| CVE-2026-74616 | 9.8 CRITICAL | xdp: reject clones that overrun skb_shared_info tailroom |
| CVE-2026-74730 | 9.8 CRITICAL | NFS: Pin the 'struct nfs_server' during a FREE_STATEID call |
| CVE-2026-74712 | 9.3 CRITICAL | vdpa/mlx5: Fix buffer length in create_direct_keys() |
| CVE-2026-74665 | 9.1 CRITICAL | net: fix skb length accounting after generic XDP frag adjustment |
Showing top 20 of 150 CVEs. View all on vendor page → →
No comments yet