在 Linux 内核中,以下漏洞已得到修复: 蓝牙:ISO:确保 iso_conn 中不存在悬空的 hcon 引用 在 调用之后,ISO socket 不应再解引用 。目前,清除 的逻辑依赖于 释放对 的最后一个引用。 为简化这一逻辑,我们在 中显式地清除 ,从而避免因“谁持有最后引用”而产生的复杂竞态条件推理。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2< e941799c31f68e67ce0976efb38a79101f921b64 |
affected |
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2< cdce8af9291d8a1f8916c271de029bf558d9e8ec |
affected | ||
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2< aa9f7cb2bd3a2be998ceb739fc9a2f986eba43eb |
affected | ||
< 6.18.44 |
affected | ||
< 7.1.8 |
affected | ||
6.18.44≤ 6.18.* |
unaffected | ||
7.1.8≤ 7.1.* |
unaffected | ||
7.2≤ * |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-80634 | 9.8 CRITICAL | netfilter: flowtable: avoid num_encaps underflow on bridge VLAN untag |
| CVE-2026-80694 | 9.8 CRITICAL | net: ethernet: mtk_eth_soc: pass eth to mtk_handle_irq_rx in poll_controller |
| CVE-2026-80681 | 9.8 CRITICAL | vxlan: re-fetch eth header after route_shortcircuit() |
| CVE-2026-80674 | 9.8 CRITICAL | ntfs: validate resident attribute lists and harden the validator |
| CVE-2026-80673 | 9.8 CRITICAL | ntfs: bound the look-ahead attribute-list entry in ntfs_external_attr_find() |
| CVE-2026-80668 | 9.8 CRITICAL | netfilter: nf_conntrack_expect: use conntrack GC to reap expectations |
| CVE-2026-80630 | 9.8 CRITICAL | net/sched: sch_fq_codel: Do not call qdisc_tree_reduce_backlog during peek before restorin |
| CVE-2026-80617 | 9.8 CRITICAL | net: airoha: fix foe_check_time allocation size |
| CVE-2026-80612 | 9.8 CRITICAL | net: lwtunnel: Drop skb metadata before LWT encapsulation |
| CVE-2026-80609 | 9.8 CRITICAL | qede: fix out-of-bounds check for cqe->len_list[] |
| CVE-2026-80600 | 9.8 CRITICAL | batman-adv: dat: acquire ARP hw source only after skb realloc |
| CVE-2026-80714 | 9.8 CRITICAL | ipvs: do not propagate one-packet flag to synced conns |
| CVE-2026-80671 | 9.3 CRITICAL | perf sched: Fix register_pid() overflow, strcpy, and BUG_ON |
| CVE-2026-80693 | 9.3 CRITICAL | idpf: bound interrupt-vector register fill to the allocated array |
| CVE-2026-80684 | 9.3 CRITICAL | KVM: s390: pci: Fix NULL dereference on AIBV allocation failure |
| CVE-2026-80603 | 9.1 CRITICAL | netfilter: nf_conntrack_irc: fix parse_dcc() off-by-one OOB read |
| CVE-2026-80670 | 9.1 CRITICAL | perf tools: Use perf_env__get_cpu_topology() in machine__resolve() |
| CVE-2026-80604 | 8.8 HIGH | HID: core: Fix OOB read in hid_get_report for numbered reports |
| CVE-2026-80608 | 8.8 HIGH | accel/amdxdna: Fix iommu domain lifetime race during device removal |
| CVE-2026-80683 | 8.8 HIGH | Bluetooth: SCO: give the socket its own sco_conn reference |
Showing top 20 of 135 CVEs. View all on vendor page → →
No comments yet