在 Linux 内核中,已修复以下漏洞: ovpn:跳过对已从 by_id 表中移除的对等体的重新哈希操作 在获取 锁之前,通过调用 来解析目标对等体(peer)。在查找操作(仅增加引用计数)与后续获取 之间的时间窗口内,并发的 命令、保活超时或套接字断开连接可能会先获取 ,执行 将该对等体从所有四个哈希表中移除(按 ID、按 VPN 地址 IPv4/IPv6、按传输地址),然后释放锁。随后, 获取 并调用 ,从而将已移除的对等体重新插入到重新哈希表中。 同样的竞态条件也影响“浮动”(float)路径: 仅持有引用
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | 1d36a36f6d5347360ef9681a05f6166683bafd1d< d20c181088984b6eaa8d7fe7cb5ab3510988df59 |
affected |
1d36a36f6d5347360ef9681a05f6166683bafd1d< 66745480298775f188b2f5ad266643e85a90f73b |
affected | ||
1d36a36f6d5347360ef9681a05f6166683bafd1d< 33ec10567fe14456063daf549fdf1a4f53448e4c |
affected | ||
6.16 |
affected | ||
< 6.16 |
unaffected | ||
6.18.45≤ 6.18.* |
unaffected | ||
7.1.9≤ 7.1.* |
unaffected | ||
7.2≤ * |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-74638 | drm/v3d: Serialize the scheduler timeout handlers | |
| CVE-2026-74621 | net/sched: act_ct: fix sk_buff leak when the header checks reject a packet | |
| CVE-2026-74622 | net: atlantic: free RX pages of consumed but not refilled buffers | |
| CVE-2026-74623 | net: atlantic: free stranded TX buffers on ring deinit | |
| CVE-2026-74624 | netfilter: nf_conntrack: defer invalid log until after unlock | |
| CVE-2026-74625 | netfilter: bridge: release template ct on non-IP path | |
| CVE-2026-74627 | net: devmem: prevent net-iov / page mixing | |
| CVE-2026-74626 | NTB: ntb_netdev: Preserve RX queue depth on allocation failure | |
| CVE-2026-74628 | net/x25: fix use-after-free of the socket by its timers | |
| CVE-2026-74629 | net/dibs: Correct freeing of dmb_clientid_arr | |
| CVE-2026-74631 | net: smc: fix splice entry lifetime imbalance in smc_rx_splice | |
| CVE-2026-74630 | ipv6: prevent in6_dev_get() from resurrecting inet6_dev | |
| CVE-2026-74632 | mm/huge_memory: fix huge_zero_pfn race | |
| CVE-2026-74633 | tracing: Fix NULL pointer dereference in module event cache removal | |
| CVE-2026-74634 | ring-buffer: Prevent subbuf order change when resizing is disabled | |
| CVE-2026-74635 | fbdev: bitblit: bound-check glyph index in bit_cursor() | |
| CVE-2026-74636 | tracing: Fix race between update_event_fields and, event_define_fields | |
| CVE-2026-74637 | perf/core: Fix group leader use-after-free after sibling detach | |
| CVE-2026-74639 | ALSA: us144mkii: re-anchor capture URBs on resubmission | |
| CVE-2026-74650 | staging: rtl8723bs: fix OOB read in WMM_param_handler() |
Showing top 20 of 150 CVEs. View all on vendor page → →
No comments yet