Linux 内核中,以下漏洞已得到修复: s390/zcrypt:改进 EP11 CPRB 的域处理,采用 ASN.1 解析 函数此前使用脆弱的结构体重叠(struct overlay)方式访问和修改 EP11 CPRB 载荷中的 domain 字段,带来了可维护性和安全性方面的问题: 1. 结构体重叠方式(pld_hdr) 假设载荷具有固定结构,且未对实际的 ASN.1 编码进行验证。 2. 复杂的长度格式检测逻辑 容易出错,且在解析过程的每一步都未正确进行边界检查。 3. 直接访问结构体成员 绕过了应有的 AS
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | e2c6d91eb8b1533753755f07803e47eceed263d0< db21b2cf6dd0af5ffd08931e0a9fcda5a0473220 |
affected |
e2c6d91eb8b1533753755f07803e47eceed263d0< 0864a163783bff109b548266921829ea794edc93 |
affected | ||
7.1 |
affected | ||
< 7.1 |
unaffected | ||
7.1.10≤ 7.1.* |
unaffected | ||
7.2≤ * |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-80557 | 9.8 CRITICAL | libceph: fix OOB read in decode_watchers() via missing bounds check |
| CVE-2026-74737 | 9.8 CRITICAL | net: ethernet: ti: am65-cpsw-nuss: Fix port_id extraction from SRC TAG |
| CVE-2026-80589 | 9.8 CRITICAL | block: stop the timeout timer when releasing a never added disk |
| CVE-2026-80587 | 9.8 CRITICAL | mptcp: avoid combining some incoming suboptions |
| CVE-2026-74743 | 9.8 CRITICAL | macvlan: inherit needed_headroom and needed_tailroom from lowerdev |
| CVE-2026-74744 | 9.8 CRITICAL | ipvlan: inherit needed_headroom and needed_tailroom from phy_dev |
| CVE-2026-74746 | 9.8 CRITICAL | netfilter: flowtable: publish GC-visible tuple last |
| CVE-2026-80561 | 9.8 CRITICAL | libceph: fix multiple unsafe decodes in decode_locker() |
| CVE-2026-80558 | 9.8 CRITICAL | libceph: Avoid using invalid osd indices from primary_temp |
| CVE-2026-74752 | 9.8 CRITICAL | sctp: validate cookie AUTH state before use |
| CVE-2026-80586 | 9.8 CRITICAL | mptcp: options: reset DSS fields in case of unexpected size |
| CVE-2026-80519 | 9.8 CRITICAL | ovpn: finish crypto callback cleanup before peer release |
| CVE-2026-80528 | 9.8 CRITICAL | ceph: avoid fs reclaim while using current->journal_info |
| CVE-2026-80585 | 9.4 CRITICAL | mptcp: fastopen: only mark MPTFO subflows with SYN data |
| CVE-2026-74751 | 9.4 CRITICAL | riscv: lib: Fix ZBB strnlen reading past count boundary |
| CVE-2026-80554 | 9.3 CRITICAL | s390/vfio_ccw: Limit the number of channel program segments |
| CVE-2026-80551 | 9.3 CRITICAL | s390/vfio_ccw: Ensure first IDAW remains constant |
| CVE-2026-80553 | 8.8 HIGH | s390/vfio_ccw: Cancel existing workqueues |
| CVE-2026-80548 | 8.8 HIGH | s390/vfio_ccw: Selectively expand io_mutex |
| CVE-2026-80576 | 8.8 HIGH | drm/amdgpu: reject oversized IBs with per-ring packet limits |
Showing top 20 of 92 CVEs. View all on vendor page → →
No comments yet