Linux 内核中已修复以下漏洞: libceph:修复 decode_watchers() 中因缺少边界检查导致的越界读取(OOB read) 会验证在编码头之后缓冲区中剩余 字节,但允许 作为有效值: 始终通过。当恶意或失陷的 OSD 发送一个 的 响应时, 会在 的情况下返回成功,导致后续读取没有保证任何可用字节。 紧随其后的 中的 前面没有进行边界检查。当 时,这将导致在已验证的缓冲区边界之外进行 4 字节的读取。这个垃圾值随后被直接传递给 作为观察者数量。 其姊妹函数 在自身的 调用之后,已经使用了安全变
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | a4ed38d7a180f184a6e7aedd09db9ca4b1e6a71c< 7130d94846dadbb97b6b7f4d78a3a7bba6e3daa1 |
affected |
a4ed38d7a180f184a6e7aedd09db9ca4b1e6a71c< 00ead17c7de137a692edee59f2772e6af687e8eb |
affected | ||
4.9 |
affected | ||
< 4.9 |
unaffected | ||
7.1.10≤ 7.1.* |
unaffected | ||
7.2≤ * |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-80556 | mmc: atmel-mci: Fix use-after-free in atmci_remove due to race condition | |
| CVE-2026-80553 | s390/vfio_ccw: Cancel existing workqueues | |
| CVE-2026-80552 | s390/vfio_ccw: Ensure index for read/write regions are within range | |
| CVE-2026-80549 | s390/vfio_ccw: Move cp cleanup out of not operational | |
| CVE-2026-80546 | s390/zcrypt: Improve CCA CPRB length and overflow checks | |
| CVE-2026-80547 | s390/vfio_ccw: Implement a crw lock | |
| CVE-2026-80545 | s390/zcrypt: Improve EP11 CPRB length and overflow checks | |
| CVE-2026-80543 | s390/zcrypt: Pad trailing CCA or EP11 message with zeros | |
| CVE-2026-80548 | s390/vfio_ccw: Selectively expand io_mutex | |
| CVE-2026-80555 | s390/vfio_ccw: Free all memory if cp_init() fails | |
| CVE-2026-80554 | s390/vfio_ccw: Limit the number of channel program segments | |
| CVE-2026-80559 | Input: sur40 - fix input device registration ordering | |
| CVE-2026-80558 | libceph: Avoid using invalid osd indices from primary_temp | |
| CVE-2026-80560 | openrisc: signal: do not restore privileged SR bits on sigreturn | |
| CVE-2026-80561 | libceph: fix multiple unsafe decodes in decode_locker() | |
| CVE-2026-80562 | gpio: ml-ioh: use raw_spinlock_t for the register lock | |
| CVE-2026-80563 | gpio: sloppy-logic-analyzer: fix use-after-free via debugfs trigger on unbind | |
| CVE-2026-80564 | gve: fix NULL dereference due to missing ptp adjfine | |
| CVE-2026-80565 | crypto: qce - fix error path in devm_qce_register_algs | |
| CVE-2026-80566 | Input: hynitron_cstxxx - validate touch count and finger IDs |
Showing top 20 of 92 CVEs. View all on vendor page → →
No comments yet