在 Linux 内核中,已修复以下漏洞: ovpn:将密钥槽位加密资源的释放延迟到工作队列中执行 密钥槽位通过 进行引用计数管理,现有的释放路径原本在 RCU 回调中释放 AEAD 变换对象。然而,这对某些加密实现而言并不安全:例如,当异步或硬件加速实现需要完成拆除(teardown)工作时, 可能会睡眠。 本补丁改用 来释放密钥槽位。这样做既保留了无锁密钥槽位读取者所需的 RCU 宽限期,又确保实际的加密资源拆除操作在工作队列(workqueue)上下文中执行,从而允许睡眠。一旦 回调被执行,预先存在的 RCU
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | 8534731dbf2d52a539b94defd06d2a8d3514aacb< 0f77ed5ee91946ea63e29f2e0ff9dc9e722d8da3 |
affected |
8534731dbf2d52a539b94defd06d2a8d3514aacb< 2da3dfa1ddfe55a065f484750c83660e3bd4ac00 |
affected | ||
6.16 |
affected | ||
< 6.16 |
unaffected | ||
7.1.10≤ 7.1.* |
unaffected | ||
7.2≤ * |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-80558 | 9.8 CRITICAL | libceph: Avoid using invalid osd indices from primary_temp |
| CVE-2026-74752 | 9.8 CRITICAL | sctp: validate cookie AUTH state before use |
| CVE-2026-74746 | 9.8 CRITICAL | netfilter: flowtable: publish GC-visible tuple last |
| CVE-2026-80586 | 9.8 CRITICAL | mptcp: options: reset DSS fields in case of unexpected size |
| CVE-2026-74744 | 9.8 CRITICAL | ipvlan: inherit needed_headroom and needed_tailroom from phy_dev |
| CVE-2026-74743 | 9.8 CRITICAL | macvlan: inherit needed_headroom and needed_tailroom from lowerdev |
| CVE-2026-80519 | 9.8 CRITICAL | ovpn: finish crypto callback cleanup before peer release |
| CVE-2026-80561 | 9.8 CRITICAL | libceph: fix multiple unsafe decodes in decode_locker() |
| CVE-2026-80587 | 9.8 CRITICAL | mptcp: avoid combining some incoming suboptions |
| CVE-2026-80528 | 9.8 CRITICAL | ceph: avoid fs reclaim while using current->journal_info |
| CVE-2026-74737 | 9.8 CRITICAL | net: ethernet: ti: am65-cpsw-nuss: Fix port_id extraction from SRC TAG |
| CVE-2026-80589 | 9.8 CRITICAL | block: stop the timeout timer when releasing a never added disk |
| CVE-2026-80557 | 9.8 CRITICAL | libceph: fix OOB read in decode_watchers() via missing bounds check |
| CVE-2026-74751 | 9.4 CRITICAL | riscv: lib: Fix ZBB strnlen reading past count boundary |
| CVE-2026-80585 | 9.4 CRITICAL | mptcp: fastopen: only mark MPTFO subflows with SYN data |
| CVE-2026-80554 | 9.3 CRITICAL | s390/vfio_ccw: Limit the number of channel program segments |
| CVE-2026-80551 | 9.3 CRITICAL | s390/vfio_ccw: Ensure first IDAW remains constant |
| CVE-2026-80576 | 8.8 HIGH | drm/amdgpu: reject oversized IBs with per-ring packet limits |
| CVE-2026-80552 | 8.8 HIGH | s390/vfio_ccw: Ensure index for read/write regions are within range |
| CVE-2026-80553 | 8.8 HIGH | s390/vfio_ccw: Cancel existing workqueues |
Showing top 20 of 92 CVEs. View all on vendor page → →
No comments yet