目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CVE-2026-80789— Linux kernel 安全漏洞

一分钟漏洞结论

影响对象
Linux Linux
利用判断
尚无明确在野利用证据,仍需结合暴露面评估
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

Linux kernel是美国Linux基金会开源的一个操作系统内核。 Linux kernel存在安全漏洞,该漏洞源于nvmet_tcp_map_data()函数未对所有SGL描述符类型的sgl->length长度进行限制便分配命令缓冲区,可能导致远程未认证攻击者通过特制命令触发无界内核内存分配,造成拒绝服务。

AI 预测 7.5 利用难度: 中等 EPSS 0.23% · P15

影响版本矩阵 20

厂商产品 版本范围状态
Linux Linux 872d26a391da92ed8f0c0f5cb5fef428067b7f30< f6e51b09cbaa5f6f6e6a3a9dafa666f76c37aab5 affected
872d26a391da92ed8f0c0f5cb5fef428067b7f30< f63e89a0310264264923f84406dea05fe752de62 affected
872d26a391da92ed8f0c0f5cb5fef428067b7f30< 0952541b153e258b99d39cdb03ea6919fdeb41d0 affected
872d26a391da92ed8f0c0f5cb5fef428067b7f30< 25ad03d5c0e858c4b63f1e4b6d461d2af1b30b22 affected
872d26a391da92ed8f0c0f5cb5fef428067b7f30< d2acc96c528d589f5827cfb90e8e9229dd9d8cb4 affected
872d26a391da92ed8f0c0f5cb5fef428067b7f30< 6d27199ebe8cb223022150f74be13f154a964474 affected
872d26a391da92ed8f0c0f5cb5fef428067b7f30< 14dbe37681a6a7e346fc147bb363ec7cca3180a0 affected
872d26a391da92ed8f0c0f5cb5fef428067b7f30< d895e66628f939edbb98608f6e033d3d39e6e546 affected
… +12 条更多
获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2026-80789 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
nvmet-tcp: bound SGL data length before allocating command buffers
来源: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: bound SGL data length before allocating command buffers nvmet_tcp_map_data() reads the host-controlled 32-bit sgl->length and, for the in-capsule offset descriptor (type 0x01), checks it against port->inline_data_size before use. Any other SGL descriptor type -- including the non-inline transport SGL data-block descriptor (type (NVME_TRANSPORT_SGL_DATA_DESC << 4) | NVME_SGL_FMT_TRANSPORT_A, the type a real host uses for out-of-capsule writes) skips that check entirely and falls straight through to: cmd->req.sg = sgl_alloc(len, GFP_KERNEL, &cmd->req.sg_cnt); with len taken directly from the wire, unbounded up to 4 GiB. nvmet_req_init() only parses the command and never inspects sgl->length, and nvmet_check_transfer_len() -- the only other place transfer_len is validated -- runs later, from req->execute(), after the allocation has already happened. For a write command the target responds with an R2T and parks the command waiting for the host to send the data; if the host (or an unauthenticated peer that simply never follows up) never does, the sgl_alloc() buffer stays resident for the life of the command. NVMe/TCP has no mandatory authentication in the default configuration, so any peer able to reach the target portal and complete a Fabrics connect can drive this with a single crafted command, repeatable across queues and connections for amplification. This is unbounded kernel memory allocation triggered by a remote, effectively unauthenticated peer. Validate len against the same NVMET_TCP_MAXH2CDATA ceiling this file already uses to bound per-PDU H2C data, for every SGL descriptor type, before doing any allocation. This closes the gap for the non-inline descriptor while leaving the existing, tighter inline_data_size check in place for the in-capsule case. Runtime-verified on a v6.19 KASAN stand: with this bound in place, a crafted write command carrying an oversized non-inline SGL length is rejected before sgl_alloc() runs, where the same request previously drove an unbounded ~256 MiB kernel allocation (up to 4 GiB) that stayed resident pending an R2T the host never satisfies.
来源: CVE Program / CVE List V5
CVSS Information
N/A
来源: CVE Program / CVE List V5
Vulnerability Type
N/A
来源: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Description
Linux kernel是美国Linux基金会开源的一个操作系统内核。 Linux kernel存在安全漏洞,该漏洞源于nvmet_tcp_map_data()函数未对所有SGL描述符类型的sgl->length长度进行限制便分配命令缓冲区,可能导致远程未认证攻击者通过特制命令触发无界内核内存分配,造成拒绝服务。
来源: 中国国家信息安全漏洞库 CNNVD
CVSS Information
N/A
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Type
N/A
来源: 中国国家信息安全漏洞库 CNNVD

受影响产品

厂商 产品 影响版本 CPE 订阅
Linux Linux 872d26a391da92ed8f0c0f5cb5fef428067b7f30 ~ f6e51b09cbaa5f6f6e6a3a9dafa666f76c37aab5 -
Linux Linux 5.0 -

二、漏洞 CVE-2026-80789 的公开POC

# POC 描述 源链接 神龙链接
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2026-80789 的情报信息

登录查看更多情报信息。

CVE-2026-80789 补丁与修复 (8)

同批安全公告 · Linux · 2026-09-04 · 共 156 条

CVE-2026-80865 Linux kernel 安全漏洞
CVE-2026-80856 Linux kernel 安全漏洞
CVE-2026-80857 Linux kernel 安全漏洞
CVE-2026-80858 Linux kernel 安全漏洞
CVE-2026-80859 Linux kernel 安全漏洞
CVE-2026-80860 Linux kernel 安全漏洞
CVE-2026-80861 Linux kernel 安全漏洞
CVE-2026-80862 Linux kernel 安全漏洞
CVE-2026-80863 Linux kernel 安全漏洞
CVE-2026-80864 Linux kernel 安全漏洞
CVE-2026-80870 Linux kernel 安全漏洞
CVE-2026-80874 Linux kernel 安全漏洞
CVE-2026-80873 Linux kernel 安全漏洞
CVE-2026-80872 Linux kernel 安全漏洞
CVE-2026-80871 Linux kernel 安全漏洞
CVE-2026-80868 Linux kernel 安全漏洞
CVE-2026-80866 Linux kernel 安全漏洞
CVE-2026-80867 Linux kernel 安全漏洞
CVE-2026-80855 Linux kernel 安全漏洞
CVE-2026-80869 Linux kernel 安全漏洞

显示前 20 条,共 156 条。 查看全部 &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-80789

暂无评论


发表评论