在 Linux 内核中,以下漏洞已被修复: perf sched:修复 register_pid() 中的整数溢出、strcpy 以及 BUG_ON 问题 当处理不可信的 perf.data 文件时, 函数存在以下几个问题: 1. 整数溢出:在 32 位系统上,当 值较大时(例如 ),表达式 可能会发生回绕(wrap),导致 返回一个极小的缓冲区,进而在初始化循环中引发越界写入。 2. 堆缓冲区溢出: 将不可信的 字符串拷贝到一个固定长度为 20 字节( )的缓冲区中,且未进行长度检查。 3. 分配失败时触发 BU
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | ec156764d424dd67283c2cd5e9f6f1b8388364ac< 652cea73b7b7b7c622a2be670e44e3c499c6d49f |
affected |
ec156764d424dd67283c2cd5e9f6f1b8388364ac< 5ea1dcc9418c4e06ce29ed5170596f497ba86872 |
affected | ||
ec156764d424dd67283c2cd5e9f6f1b8388364ac< 5949d339f5ec98752d56dcd4e36f619a59d513a5 |
affected | ||
2.6.32 |
affected | ||
< 2.6.32 |
unaffected | ||
6.18.40≤ 6.18.* |
unaffected | ||
7.1.5≤ 7.1.* |
unaffected | ||
7.2≤ * |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-80694 | 9.8 CRITICAL | net: ethernet: mtk_eth_soc: pass eth to mtk_handle_irq_rx in poll_controller |
| CVE-2026-80668 | 9.8 CRITICAL | netfilter: nf_conntrack_expect: use conntrack GC to reap expectations |
| CVE-2026-80673 | 9.8 CRITICAL | ntfs: bound the look-ahead attribute-list entry in ntfs_external_attr_find() |
| CVE-2026-80634 | 9.8 CRITICAL | netfilter: flowtable: avoid num_encaps underflow on bridge VLAN untag |
| CVE-2026-80674 | 9.8 CRITICAL | ntfs: validate resident attribute lists and harden the validator |
| CVE-2026-80630 | 9.8 CRITICAL | net/sched: sch_fq_codel: Do not call qdisc_tree_reduce_backlog during peek before restorin |
| CVE-2026-80617 | 9.8 CRITICAL | net: airoha: fix foe_check_time allocation size |
| CVE-2026-80612 | 9.8 CRITICAL | net: lwtunnel: Drop skb metadata before LWT encapsulation |
| CVE-2026-80714 | 9.8 CRITICAL | ipvs: do not propagate one-packet flag to synced conns |
| CVE-2026-80681 | 9.8 CRITICAL | vxlan: re-fetch eth header after route_shortcircuit() |
| CVE-2026-80609 | 9.8 CRITICAL | qede: fix out-of-bounds check for cqe->len_list[] |
| CVE-2026-80600 | 9.8 CRITICAL | batman-adv: dat: acquire ARP hw source only after skb realloc |
| CVE-2026-80693 | 9.3 CRITICAL | idpf: bound interrupt-vector register fill to the allocated array |
| CVE-2026-80684 | 9.3 CRITICAL | KVM: s390: pci: Fix NULL dereference on AIBV allocation failure |
| CVE-2026-80670 | 9.1 CRITICAL | perf tools: Use perf_env__get_cpu_topology() in machine__resolve() |
| CVE-2026-80603 | 9.1 CRITICAL | netfilter: nf_conntrack_irc: fix parse_dcc() off-by-one OOB read |
| CVE-2026-80683 | 8.8 HIGH | Bluetooth: SCO: give the socket its own sco_conn reference |
| CVE-2026-80692 | 8.8 HIGH | Bluetooth: hci_sync: hold conn in hci_connect_acl/le_sync() callbacks |
| CVE-2026-80633 | 8.8 HIGH | iommufd: Take dma_resv lock before dma_buf_unpin() in release path |
| CVE-2026-80672 | 8.8 HIGH | ntfs: fix u16 truncation of restart-area length check |
Showing top 20 of 135 CVEs. View all on vendor page → →
No comments yet