Linux kernel是美国Linux基金会开源的一个操作系统内核。 Linux kernel存在安全漏洞,该漏洞源于drm/amdgpu驱动中devres teardown机制的后进先出顺序问题,aperture devres节点注册晚于DRM设备节点,导致devres_release_all()在DRM设备释放回调触发amdgpu_device_fini_sw()前将aperture映射解除,使IP sw_fini回调(如vcn_v4_0_sw_fini)在探测失败或回滚时通过aper_base_k
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2< 7380f1bfe9d7ed3a4ca9d99a5c4df840fff9af2a |
affected |
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2< 96d26143882f9cb47dcc1f3dd4e26d047e53ab9b |
affected | ||
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2< a2e326c52c4bcecc033cd3ca2733fdbe30fbf55d |
affected | ||
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2< 496846a9411136eb9e86ad4f4e62d751bd1e1db5 |
affected | ||
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2< b96c529cd2551b78316a4afa3237b2ed96ba03c8 |
affected | ||
< 6.6.152 |
affected | ||
< 6.12.104 |
affected | ||
< 6.18.45 |
affected | ||
| … +6 more rows | |||
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-80726 | 9.3 CRITICAL | KVM: x86/mmu: WARN and clear role.invalid when creating a child shadow page |
| CVE-2026-80734 | 8.8 HIGH | btrfs: initialize inode mapping flags for cached inodes |
| CVE-2026-80745 | 8.4 HIGH | regulator: fp9931: Fix VPOS/VNEG voltage selector table |
| CVE-2026-80750 | 8.4 HIGH | pmdomain: mediatek: fix remaining %pOF after of_node_put() |
| CVE-2026-80752 | 8.4 HIGH | Input: psxpad-spi - set driver data before use |
| CVE-2026-80753 | 8.4 HIGH | ovpn: run deferred work on a module-owned workqueue |
| CVE-2026-80747 | 8.0 HIGH | drm/amdkfd: Add bounds check for CRAT subtype length |
| CVE-2026-80751 | 7.8 HIGH | pmdomain: mediatek: mfg: initialize prev_o in mtk_mfg_attach_dev() |
| CVE-2026-80736 | 7.8 HIGH | thunderbolt: Fix bandwidth group reservation indexing |
| CVE-2026-80737 | 7.8 HIGH | serial: amba-pl011: synchronize DMA teardown |
| CVE-2026-80732 | 7.8 HIGH | ata: pata_sl82c105: fix bridge revision use-after-free |
| CVE-2026-80731 | 7.8 HIGH | net: remove CAP_SYS_RAWIO zero-padding in dev_validate_header |
| CVE-2026-80748 | 7.8 HIGH | mmc: loongson2: Fix sg iteration in data reorder functions |
| CVE-2026-80754 | 7.8 HIGH | Input: synaptics-rmi4 - fix F55 transmitter electrode count typo |
| CVE-2026-80738 | 7.3 HIGH | bpf: Check sk_state before sk_protocol in bpf_tcp_*_syncookie |
| CVE-2026-80735 | 7.3 HIGH | ovpn: ensure socket is owned by ovpn before deref sk_user_data |
| CVE-2026-80749 | 7.1 HIGH | drm/connector/hdmi: Fix out of bounds memory read |
| CVE-2026-80741 | 7.1 HIGH | drm/log: Fix out-of-bounds read on empty message length |
| CVE-2026-80729 | mm/huge_memory: initialise workingset state before folio split | |
| CVE-2026-80730 | ring-buffer: Fix crash passing ERR_PTR to kthread_stop() |
Showing top 20 of 32 CVEs. View all on vendor page → →
No comments yet