在 Linux 内核中,已修复以下漏洞: bnxt_en:在所有芯片上禁用 TPA 相关的 EOP,以防止数据损坏 在 AGG(聚合)环上启用 EOP(帧尾填充,End of frame padding)可能导致前一片段的尾部零填充与下一个片段的数据发生重叠。如果启用了宽松排序(Relaxed Ordering,RO),这些零填充可能会覆盖下一片段中的有效数据,从而导致数据损坏。较老的芯片(P5 及更早版本)在启用 EOP 时不会自动禁用 RO。在部分 ARM 系统上,已报告在使用启用 RO 的 57508(P5)
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | bfcd8d791ec18496772d117774398e336917f56e< 68c181af7cd1ca9cbf29acd95911073bfd3c6397 |
affected |
bfcd8d791ec18496772d117774398e336917f56e< 7aee22a35978b44784612c156e358e375ddf5d16 |
affected | ||
bfcd8d791ec18496772d117774398e336917f56e< 410da4428b1f47bf9a84bdc0bcaa089d73ba2048 |
affected | ||
bfcd8d791ec18496772d117774398e336917f56e< b61c4911204a0a2f900e538d64ceb608f6c9614d |
affected | ||
bfcd8d791ec18496772d117774398e336917f56e< aab3b5f4d8ec8598606ee011e219ef824ae25ca0 |
affected | ||
bfcd8d791ec18496772d117774398e336917f56e< c1962ab4645a914a91ff492735881150ddc8a79e |
affected | ||
bfcd8d791ec18496772d117774398e336917f56e< c3faf548a00f4c17100cc9204746975fa46a73b9 |
affected | ||
5.4 |
affected | ||
| … +8 more rows | |||
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-74705 | 10.0 CRITICAL | udp: fix potential use-after-free in tunnel segmentation |
| CVE-2026-74612 | 10.0 CRITICAL | veth: fix skb length accounting after XDP frag adjustment |
| CVE-2026-74611 | 9.8 CRITICAL | tls: rx: restore msg_iter before TLS 1.3 optimistic retry |
| CVE-2026-74591 | 9.8 CRITICAL | mm/filemap: __filemap_add_folio() restore index before retrying |
| CVE-2026-74688 | 9.8 CRITICAL | sctp: clear control chunk transport if it is being removed |
| CVE-2026-74597 | 9.8 CRITICAL | ip6_tunnel: clear skb2->cb[] in ip6ip6_err() |
| CVE-2026-74617 | 9.8 CRITICAL | dibs: initialise dibs->lock in dibs_dev_alloc() |
| CVE-2026-74628 | 9.8 CRITICAL | net/x25: fix use-after-free of the socket by its timers |
| CVE-2026-74616 | 9.8 CRITICAL | xdp: reject clones that overrun skb_shared_info tailroom |
| CVE-2026-74587 | 9.8 CRITICAL | sctp: fix use-after-free of cached ASCONF chunk |
| CVE-2026-74608 | 9.8 CRITICAL | smb: client: Fix use-after-free in cifs_try_adding_channels() |
| CVE-2026-74723 | 9.8 CRITICAL | btrfs: lzo: reject inline extents without valid headers |
| CVE-2026-74730 | 9.8 CRITICAL | NFS: Pin the 'struct nfs_server' during a FREE_STATEID call |
| CVE-2026-74727 | 9.8 CRITICAL | ovpn: skip rehash for peers already removed from by_id |
| CVE-2026-74586 | 9.8 CRITICAL | sctp: clear new_transport when removing a peer |
| CVE-2026-74662 | 9.8 CRITICAL | inet: frags: publish queues before arming timer |
| CVE-2026-74588 | 9.8 CRITICAL | sctp: keep chunk->transport in step with the list it is queued on |
| CVE-2026-74669 | 9.8 CRITICAL | ipvs: clear IPv4 options after rebasing tunnel ICMP errors |
| CVE-2026-74712 | 9.3 CRITICAL | vdpa/mlx5: Fix buffer length in create_direct_keys() |
| CVE-2026-74665 | 9.1 CRITICAL | net: fix skb length accounting after generic XDP frag adjustment |
Showing top 20 of 150 CVEs. View all on vendor page → →
No comments yet