在 Linux 内核中,已修复以下漏洞: mm: 修复直接页面表回收中错误的刷新地址 当 回收页表时,它执行以下操作: 这一做法绝对错误:如果执行到此代码, 总是指向该页表覆盖范围末尾之后的位置。 参数用于刷新 TLB(实际上是分页结构缓存),以释放对该待回收页表的引用,而任何关注该参数的架构都会刷新错误的地址。(尽管它们仍会正确释放该页。) 值得深入探讨的是:为何内核在此情况下仍能正常运行? 如果我们命中这段问题代码,流程如下: 1. 首先清除 PMD 项(第 1954 行, ); 2. 若设置了 ,则发出待处理
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | 4c640eb4181cf8de74c8b9e7c9cf16bf8d26b73e< 0b8ff21cbda8808c86b18f1b0ca2d0025af9a80a |
affected |
4c640eb4181cf8de74c8b9e7c9cf16bf8d26b73e< 478a1c3abebfc717db0d1281a9cdd7befafee542 |
affected | ||
7.0 |
affected | ||
< 7.0 |
unaffected | ||
7.1.9≤ 7.1.* |
unaffected | ||
7.2≤ * |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-74705 | 10.0 CRITICAL | udp: fix potential use-after-free in tunnel segmentation |
| CVE-2026-74612 | 10.0 CRITICAL | veth: fix skb length accounting after XDP frag adjustment |
| CVE-2026-74616 | 9.8 CRITICAL | xdp: reject clones that overrun skb_shared_info tailroom |
| CVE-2026-74591 | 9.8 CRITICAL | mm/filemap: __filemap_add_folio() restore index before retrying |
| CVE-2026-74662 | 9.8 CRITICAL | inet: frags: publish queues before arming timer |
| CVE-2026-74669 | 9.8 CRITICAL | ipvs: clear IPv4 options after rebasing tunnel ICMP errors |
| CVE-2026-74608 | 9.8 CRITICAL | smb: client: Fix use-after-free in cifs_try_adding_channels() |
| CVE-2026-74628 | 9.8 CRITICAL | net/x25: fix use-after-free of the socket by its timers |
| CVE-2026-74587 | 9.8 CRITICAL | sctp: fix use-after-free of cached ASCONF chunk |
| CVE-2026-74588 | 9.8 CRITICAL | sctp: keep chunk->transport in step with the list it is queued on |
| CVE-2026-74611 | 9.8 CRITICAL | tls: rx: restore msg_iter before TLS 1.3 optimistic retry |
| CVE-2026-74730 | 9.8 CRITICAL | NFS: Pin the 'struct nfs_server' during a FREE_STATEID call |
| CVE-2026-74617 | 9.8 CRITICAL | dibs: initialise dibs->lock in dibs_dev_alloc() |
| CVE-2026-74727 | 9.8 CRITICAL | ovpn: skip rehash for peers already removed from by_id |
| CVE-2026-74586 | 9.8 CRITICAL | sctp: clear new_transport when removing a peer |
| CVE-2026-74597 | 9.8 CRITICAL | ip6_tunnel: clear skb2->cb[] in ip6ip6_err() |
| CVE-2026-74688 | 9.8 CRITICAL | sctp: clear control chunk transport if it is being removed |
| CVE-2026-74723 | 9.8 CRITICAL | btrfs: lzo: reject inline extents without valid headers |
| CVE-2026-74712 | 9.3 CRITICAL | vdpa/mlx5: Fix buffer length in create_direct_keys() |
| CVE-2026-74665 | 9.1 CRITICAL | net: fix skb length accounting after generic XDP frag adjustment |
Showing top 20 of 150 CVEs. View all on vendor page → →
No comments yet