在 Linux 内核中,已修复以下漏洞: libceph:修复 decode_locker() 中的多处不安全解码操作 中的 包含三处不安全的解码操作,使得恶意或已受控的 OSD 能够触发 slab 越界读取: 1. 在 的 字段处调用 时,前面缺少边界检查。当 接受 后,若 ,则会读取超出已验证缓冲区边界 9 字节(即 )。 2. 在读取 头部之后执行的 是一个未检查的指针推进。恶意 OSD 可以将指针 移动到 之后,导致后续所有 检查相对于错误的边界通过。 3. 前面同样缺少边界检查,而紧随其后的 也没有上限控
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | d4ed4a530562881cc5225050e42d96034f405aae< 1ed45c8d96498725eb54f740172f9068d8673906 |
affected |
d4ed4a530562881cc5225050e42d96034f405aae< 6265103e78f0ee7e2518de9cf938b94bee9700a0 |
affected | ||
d4ed4a530562881cc5225050e42d96034f405aae< 3c3716dc06a34e4ca7f743f5fcfa07fbc5a11070 |
affected | ||
d4ed4a530562881cc5225050e42d96034f405aae< fa4aa86fff0c56799c2e3f51a88879053285f4a9 |
affected | ||
d4ed4a530562881cc5225050e42d96034f405aae< dbfd83f722a78446ec18a476ef7a38e52240b50a |
affected | ||
d4ed4a530562881cc5225050e42d96034f405aae< d1bba38574d095f191557d397d9633f08cd966b1 |
affected | ||
d4ed4a530562881cc5225050e42d96034f405aae< 51c8d238fe7236de627ab1a1433694552a904136 |
affected | ||
d4ed4a530562881cc5225050e42d96034f405aae< 437b6551cfcc235eea1d735a874f9d421f555e17 |
affected | ||
| … +10 more rows | |||
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-80557 | libceph: fix OOB read in decode_watchers() via missing bounds check | |
| CVE-2026-80553 | s390/vfio_ccw: Cancel existing workqueues | |
| CVE-2026-80552 | s390/vfio_ccw: Ensure index for read/write regions are within range | |
| CVE-2026-80549 | s390/vfio_ccw: Move cp cleanup out of not operational | |
| CVE-2026-80546 | s390/zcrypt: Improve CCA CPRB length and overflow checks | |
| CVE-2026-80547 | s390/vfio_ccw: Implement a crw lock | |
| CVE-2026-80545 | s390/zcrypt: Improve EP11 CPRB length and overflow checks | |
| CVE-2026-80543 | s390/zcrypt: Pad trailing CCA or EP11 message with zeros | |
| CVE-2026-80548 | s390/vfio_ccw: Selectively expand io_mutex | |
| CVE-2026-80555 | s390/vfio_ccw: Free all memory if cp_init() fails | |
| CVE-2026-80554 | s390/vfio_ccw: Limit the number of channel program segments | |
| CVE-2026-80556 | mmc: atmel-mci: Fix use-after-free in atmci_remove due to race condition | |
| CVE-2026-80559 | Input: sur40 - fix input device registration ordering | |
| CVE-2026-80558 | libceph: Avoid using invalid osd indices from primary_temp | |
| CVE-2026-80560 | openrisc: signal: do not restore privileged SR bits on sigreturn | |
| CVE-2026-80562 | gpio: ml-ioh: use raw_spinlock_t for the register lock | |
| CVE-2026-80563 | gpio: sloppy-logic-analyzer: fix use-after-free via debugfs trigger on unbind | |
| CVE-2026-80564 | gve: fix NULL dereference due to missing ptp adjfine | |
| CVE-2026-80565 | crypto: qce - fix error path in devm_qce_register_algs | |
| CVE-2026-80566 | Input: hynitron_cstxxx - validate touch count and finger IDs |
Showing top 20 of 92 CVEs. View all on vendor page → →
No comments yet