以下是该 Linux 内核漏洞描述信息的中文翻译: 在 Linux 内核中,以下漏洞已得到修复: inet: frags: 在重组前从 IP 分片中剥离 GSO 状态 问题描述: (用于 tun/tap 或带有 的 )可以将 IPv4 或 IPv6 分片标记为 GSO(通用分段卸载);然而没有任何机制将 与 (分片偏移量)关联起来。 / 会保留第一个分片的 skb 作为重组后数据报的头部(包括其 / / ),并将其余分片按照其到达时的线性/分页布局链接到 中。 在 (如 、 等)之后,重组后的 skb 仍然声称自己
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | f43798c27684ab925adde7d8acc34c78c6e50df8< cfdbc8c2e6f9ef5d8b8e54859da03dfe682b0bee |
affected |
f43798c27684ab925adde7d8acc34c78c6e50df8< 29dda278a5ed272f2230ff4eaa23cf403107bba0 |
affected | ||
f43798c27684ab925adde7d8acc34c78c6e50df8< 14a8f3e10fa9a5abd6cedcdaa0c0b7ea9a09f234 |
affected | ||
f43798c27684ab925adde7d8acc34c78c6e50df8< 3edf721bb4b99d272c336631b44e3d8ff9a4f31b |
affected | ||
f43798c27684ab925adde7d8acc34c78c6e50df8< dec2edb7aaf12a8878b3a03172ea8fc277b8eaad |
affected | ||
f43798c27684ab925adde7d8acc34c78c6e50df8< c49f04e8d2b94dbb8d9fd99731dd3f00589c8ace |
affected | ||
f43798c27684ab925adde7d8acc34c78c6e50df8< 69b73b74d9eb45f5560a8fe4fa406ada580e1340 |
affected | ||
f43798c27684ab925adde7d8acc34c78c6e50df8< da857e448322a2e871ce3ecc2900027041160d43 |
affected | ||
| … +12 more rows | |||
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-80674 | 9.8 CRITICAL | ntfs: validate resident attribute lists and harden the validator |
| CVE-2026-80630 | 9.8 CRITICAL | net/sched: sch_fq_codel: Do not call qdisc_tree_reduce_backlog during peek before restorin |
| CVE-2026-80617 | 9.8 CRITICAL | net: airoha: fix foe_check_time allocation size |
| CVE-2026-80612 | 9.8 CRITICAL | net: lwtunnel: Drop skb metadata before LWT encapsulation |
| CVE-2026-80634 | 9.8 CRITICAL | netfilter: flowtable: avoid num_encaps underflow on bridge VLAN untag |
| CVE-2026-80609 | 9.8 CRITICAL | qede: fix out-of-bounds check for cqe->len_list[] |
| CVE-2026-80694 | 9.8 CRITICAL | net: ethernet: mtk_eth_soc: pass eth to mtk_handle_irq_rx in poll_controller |
| CVE-2026-80668 | 9.8 CRITICAL | netfilter: nf_conntrack_expect: use conntrack GC to reap expectations |
| CVE-2026-80714 | 9.8 CRITICAL | ipvs: do not propagate one-packet flag to synced conns |
| CVE-2026-80600 | 9.8 CRITICAL | batman-adv: dat: acquire ARP hw source only after skb realloc |
| CVE-2026-80673 | 9.8 CRITICAL | ntfs: bound the look-ahead attribute-list entry in ntfs_external_attr_find() |
| CVE-2026-80681 | 9.8 CRITICAL | vxlan: re-fetch eth header after route_shortcircuit() |
| CVE-2026-80684 | 9.3 CRITICAL | KVM: s390: pci: Fix NULL dereference on AIBV allocation failure |
| CVE-2026-80671 | 9.3 CRITICAL | perf sched: Fix register_pid() overflow, strcpy, and BUG_ON |
| CVE-2026-80693 | 9.3 CRITICAL | idpf: bound interrupt-vector register fill to the allocated array |
| CVE-2026-80603 | 9.1 CRITICAL | netfilter: nf_conntrack_irc: fix parse_dcc() off-by-one OOB read |
| CVE-2026-80670 | 9.1 CRITICAL | perf tools: Use perf_env__get_cpu_topology() in machine__resolve() |
| CVE-2026-80633 | 8.8 HIGH | iommufd: Take dma_resv lock before dma_buf_unpin() in release path |
| CVE-2026-80638 | 8.8 HIGH | ocfs2: fix out-of-bounds write in ocfs2_remove_refcount_extent |
| CVE-2026-80722 | 8.8 HIGH | wifi: mac80211: validate individual TWT params before driver setup |
Showing top 20 of 135 CVEs. View all on vendor page → →
No comments yet