在 Linux 内核中,以下漏洞已修复: wifi: mac80211: 在驱动配置前验证单独的 TWT 参数 在将接收到的 802.11 单播 TWT 配置帧加入队列之前,仅对其进行了部分验证。 因此,单个 TWT 协议可能在 短于完整 所需长度时,到达 。 该单个路径会将 传递给 。无论是跟踪点(tracepoint)还是驱动回调,都会使用完整的参数字段块,而不仅仅是 。因此,不应将长度不足的单个协议传递给驱动。 广播协议的逻辑保持不变,因为在访问 后会在本地被拒绝。 [编辑提交信息,以准确表述:避免过度声称缺
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | f5a4c24e689f54e66201f04d343bdd2e8a1d7923< 92fcd0f30dc8e51f252589b082d46851d295cc1a |
affected |
f5a4c24e689f54e66201f04d343bdd2e8a1d7923< 09d60d1f72e6598241490eb6c4e97245af895c09 |
affected | ||
f5a4c24e689f54e66201f04d343bdd2e8a1d7923< ff558072d199c1d641d1561da622e67f780514de |
affected | ||
f5a4c24e689f54e66201f04d343bdd2e8a1d7923< ade9e2f0f7f4d3089600ac2af8ef0b91746f923b |
affected | ||
f5a4c24e689f54e66201f04d343bdd2e8a1d7923< b558e07708d886acfcf4b0391ed7a8546e81d326 |
affected | ||
f5a4c24e689f54e66201f04d343bdd2e8a1d7923< 47fb04c3826e1f90271d405523043d6708b9072a |
affected | ||
f5a4c24e689f54e66201f04d343bdd2e8a1d7923< 0502d5077e419427d80f4d46ba95d0067f5fb916 |
affected | ||
5.15 |
affected | ||
| … +8 more rows | |||
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-80694 | 9.8 CRITICAL | net: ethernet: mtk_eth_soc: pass eth to mtk_handle_irq_rx in poll_controller |
| CVE-2026-80681 | 9.8 CRITICAL | vxlan: re-fetch eth header after route_shortcircuit() |
| CVE-2026-80674 | 9.8 CRITICAL | ntfs: validate resident attribute lists and harden the validator |
| CVE-2026-80673 | 9.8 CRITICAL | ntfs: bound the look-ahead attribute-list entry in ntfs_external_attr_find() |
| CVE-2026-80600 | 9.8 CRITICAL | batman-adv: dat: acquire ARP hw source only after skb realloc |
| CVE-2026-80668 | 9.8 CRITICAL | netfilter: nf_conntrack_expect: use conntrack GC to reap expectations |
| CVE-2026-80714 | 9.8 CRITICAL | ipvs: do not propagate one-packet flag to synced conns |
| CVE-2026-80634 | 9.8 CRITICAL | netfilter: flowtable: avoid num_encaps underflow on bridge VLAN untag |
| CVE-2026-80630 | 9.8 CRITICAL | net/sched: sch_fq_codel: Do not call qdisc_tree_reduce_backlog during peek before restorin |
| CVE-2026-80609 | 9.8 CRITICAL | qede: fix out-of-bounds check for cqe->len_list[] |
| CVE-2026-80612 | 9.8 CRITICAL | net: lwtunnel: Drop skb metadata before LWT encapsulation |
| CVE-2026-80617 | 9.8 CRITICAL | net: airoha: fix foe_check_time allocation size |
| CVE-2026-80684 | 9.3 CRITICAL | KVM: s390: pci: Fix NULL dereference on AIBV allocation failure |
| CVE-2026-80693 | 9.3 CRITICAL | idpf: bound interrupt-vector register fill to the allocated array |
| CVE-2026-80671 | 9.3 CRITICAL | perf sched: Fix register_pid() overflow, strcpy, and BUG_ON |
| CVE-2026-80670 | 9.1 CRITICAL | perf tools: Use perf_env__get_cpu_topology() in machine__resolve() |
| CVE-2026-80603 | 9.1 CRITICAL | netfilter: nf_conntrack_irc: fix parse_dcc() off-by-one OOB read |
| CVE-2026-80721 | 8.8 HIGH | Bluetooth: ISO: ensure no dangling hcon references in iso_conn |
| CVE-2026-80672 | 8.8 HIGH | ntfs: fix u16 truncation of restart-area length check |
| CVE-2026-80692 | 8.8 HIGH | Bluetooth: hci_sync: hold conn in hci_connect_acl/le_sync() callbacks |
Showing top 20 of 135 CVEs. View all on vendor page → →
No comments yet