以下是该漏洞描述信息的中文翻译: 在 Linux 内核中,已解决以下漏洞: crypto: ccp - 将零长度证书链视为查询 blob 长度的请求 在处理 PDH(平台设备句柄)导出时,将来自用户空间的零长度证书链缓冲区视为一个查询相关 blob 长度的请求。 由于未正确考虑零长度缓冲区,当启用 运行内核时,会触发 断言失败。这是因为系统尝试获取 的物理地址(该指针由 在处理非法分配时返回),导致内核崩溃。 内核崩溃日志(Kernel OOPS 信息): 补充说明: 幸运的是,在没有启用 的情况下,该缺陷影响较小
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | 76a2b524a4b1d6dc0f2421f9854a01d55d5e5436< 1c587f30c6242cc37b3d6ee6d91daef84e51633f |
affected |
76a2b524a4b1d6dc0f2421f9854a01d55d5e5436< 13b4d5e055d344e34b864bced0a591ceaac7ad81 |
affected | ||
76a2b524a4b1d6dc0f2421f9854a01d55d5e5436< 94344bc7c9d70b04be718d841b92873aa3ea8191 |
affected | ||
76a2b524a4b1d6dc0f2421f9854a01d55d5e5436< 50c3c7df4f26d36b30bc950a7d780f7029fd52f8 |
affected | ||
76a2b524a4b1d6dc0f2421f9854a01d55d5e5436< ee717e73ab47253c82c134c342e32fcdfcfccd87 |
affected | ||
76a2b524a4b1d6dc0f2421f9854a01d55d5e5436< 21650fe221ea9b72809140b691589dde8bff3eab |
affected | ||
76a2b524a4b1d6dc0f2421f9854a01d55d5e5436< d88071a6ce091272726bedda26c105b85b23705f |
affected | ||
76a2b524a4b1d6dc0f2421f9854a01d55d5e5436< ef8c9dacda2871accd64e3eda951fef6b788b1ea |
affected | ||
| … +10 more rows | |||
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-80634 | 9.8 CRITICAL | netfilter: flowtable: avoid num_encaps underflow on bridge VLAN untag |
| CVE-2026-80694 | 9.8 CRITICAL | net: ethernet: mtk_eth_soc: pass eth to mtk_handle_irq_rx in poll_controller |
| CVE-2026-80681 | 9.8 CRITICAL | vxlan: re-fetch eth header after route_shortcircuit() |
| CVE-2026-80674 | 9.8 CRITICAL | ntfs: validate resident attribute lists and harden the validator |
| CVE-2026-80673 | 9.8 CRITICAL | ntfs: bound the look-ahead attribute-list entry in ntfs_external_attr_find() |
| CVE-2026-80668 | 9.8 CRITICAL | netfilter: nf_conntrack_expect: use conntrack GC to reap expectations |
| CVE-2026-80630 | 9.8 CRITICAL | net/sched: sch_fq_codel: Do not call qdisc_tree_reduce_backlog during peek before restorin |
| CVE-2026-80617 | 9.8 CRITICAL | net: airoha: fix foe_check_time allocation size |
| CVE-2026-80612 | 9.8 CRITICAL | net: lwtunnel: Drop skb metadata before LWT encapsulation |
| CVE-2026-80714 | 9.8 CRITICAL | ipvs: do not propagate one-packet flag to synced conns |
| CVE-2026-80609 | 9.8 CRITICAL | qede: fix out-of-bounds check for cqe->len_list[] |
| CVE-2026-80600 | 9.8 CRITICAL | batman-adv: dat: acquire ARP hw source only after skb realloc |
| CVE-2026-80693 | 9.3 CRITICAL | idpf: bound interrupt-vector register fill to the allocated array |
| CVE-2026-80684 | 9.3 CRITICAL | KVM: s390: pci: Fix NULL dereference on AIBV allocation failure |
| CVE-2026-80671 | 9.3 CRITICAL | perf sched: Fix register_pid() overflow, strcpy, and BUG_ON |
| CVE-2026-80603 | 9.1 CRITICAL | netfilter: nf_conntrack_irc: fix parse_dcc() off-by-one OOB read |
| CVE-2026-80670 | 9.1 CRITICAL | perf tools: Use perf_env__get_cpu_topology() in machine__resolve() |
| CVE-2026-80721 | 8.8 HIGH | Bluetooth: ISO: ensure no dangling hcon references in iso_conn |
| CVE-2026-80722 | 8.8 HIGH | wifi: mac80211: validate individual TWT params before driver setup |
| CVE-2026-80724 | 8.8 HIGH | ptp: vmclock: prevent read-only mappings from becoming writable |
Showing top 20 of 135 CVEs. View all on vendor page → →
No comments yet