在 Linux 内核中,以下漏洞已被修复: mptcp: 选项:在遇到意外大小时重置 DSS 字段 远程对端可能发送一个大小错误的格式错误的 DSS(Data Segmentation Size)子选项,随后紧接着是另一个 DSS 或 MPC + 数据。在这种情况下,第一个子选项将被忽略,但其中部分字段仍会被写入,这可能导致状态不一致或访问未初始化的数据。 修复方式为:当检测到意外的大小时,显式重置那些可能被修改过的字段。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | 648ef4b88673dadb8463bf0d4b10fbf33d55def8< 15e35fdad7a5576bf3f1c8d688877aeb5d1b506b |
affected |
648ef4b88673dadb8463bf0d4b10fbf33d55def8< b1256090816ec46011601e084be580731df58fc7 |
affected | ||
648ef4b88673dadb8463bf0d4b10fbf33d55def8< 192878df582c51d440bf7b91a15f297f29f2b596 |
affected | ||
648ef4b88673dadb8463bf0d4b10fbf33d55def8< 26dac5c9ffb20812b475fdf253eb04fab99cff3b |
affected | ||
648ef4b88673dadb8463bf0d4b10fbf33d55def8< 4e80eff5c1c893aca2ac1d202f0b256d2e52ecde |
affected | ||
648ef4b88673dadb8463bf0d4b10fbf33d55def8< 1fade1b2ac5b1a4948e538fae7313bea57b5ac36 |
affected | ||
648ef4b88673dadb8463bf0d4b10fbf33d55def8< 27ed642a4e7e4b5df4b8522c72c457a67e052493 |
affected | ||
648ef4b88673dadb8463bf0d4b10fbf33d55def8< 35772b4981f38ba8059372cde8753e8e477e98ec |
affected | ||
| … +10 more rows | |||
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-80557 | libceph: fix OOB read in decode_watchers() via missing bounds check | |
| CVE-2026-80553 | s390/vfio_ccw: Cancel existing workqueues | |
| CVE-2026-80552 | s390/vfio_ccw: Ensure index for read/write regions are within range | |
| CVE-2026-80549 | s390/vfio_ccw: Move cp cleanup out of not operational | |
| CVE-2026-80546 | s390/zcrypt: Improve CCA CPRB length and overflow checks | |
| CVE-2026-80547 | s390/vfio_ccw: Implement a crw lock | |
| CVE-2026-80545 | s390/zcrypt: Improve EP11 CPRB length and overflow checks | |
| CVE-2026-80543 | s390/zcrypt: Pad trailing CCA or EP11 message with zeros | |
| CVE-2026-80548 | s390/vfio_ccw: Selectively expand io_mutex | |
| CVE-2026-80555 | s390/vfio_ccw: Free all memory if cp_init() fails | |
| CVE-2026-80554 | s390/vfio_ccw: Limit the number of channel program segments | |
| CVE-2026-80556 | mmc: atmel-mci: Fix use-after-free in atmci_remove due to race condition | |
| CVE-2026-80559 | Input: sur40 - fix input device registration ordering | |
| CVE-2026-80558 | libceph: Avoid using invalid osd indices from primary_temp | |
| CVE-2026-80560 | openrisc: signal: do not restore privileged SR bits on sigreturn | |
| CVE-2026-80561 | libceph: fix multiple unsafe decodes in decode_locker() | |
| CVE-2026-80562 | gpio: ml-ioh: use raw_spinlock_t for the register lock | |
| CVE-2026-80563 | gpio: sloppy-logic-analyzer: fix use-after-free via debugfs trigger on unbind | |
| CVE-2026-80564 | gve: fix NULL dereference due to missing ptp adjfine | |
| CVE-2026-80565 | crypto: qce - fix error path in devm_qce_register_algs |
Showing top 20 of 92 CVEs. View all on vendor page → →
No comments yet