Linux kernel是美国Linux基金会开源的一个操作系统内核。 Linux kernel存在安全漏洞,该漏洞源于nvmet_tcp_map_data()函数未对所有SGL描述符类型的sgl->length长度进行限制便分配命令缓冲区,可能导致远程未认证攻击者通过特制命令触发无界内核内存分配,造成拒绝服务。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | 872d26a391da92ed8f0c0f5cb5fef428067b7f30< f6e51b09cbaa5f6f6e6a3a9dafa666f76c37aab5 |
affected |
872d26a391da92ed8f0c0f5cb5fef428067b7f30< f63e89a0310264264923f84406dea05fe752de62 |
affected | ||
872d26a391da92ed8f0c0f5cb5fef428067b7f30< 0952541b153e258b99d39cdb03ea6919fdeb41d0 |
affected | ||
872d26a391da92ed8f0c0f5cb5fef428067b7f30< 25ad03d5c0e858c4b63f1e4b6d461d2af1b30b22 |
affected | ||
872d26a391da92ed8f0c0f5cb5fef428067b7f30< d2acc96c528d589f5827cfb90e8e9229dd9d8cb4 |
affected | ||
872d26a391da92ed8f0c0f5cb5fef428067b7f30< 6d27199ebe8cb223022150f74be13f154a964474 |
affected | ||
872d26a391da92ed8f0c0f5cb5fef428067b7f30< 14dbe37681a6a7e346fc147bb363ec7cca3180a0 |
affected | ||
872d26a391da92ed8f0c0f5cb5fef428067b7f30< d895e66628f939edbb98608f6e033d3d39e6e546 |
affected | ||
| … +12 more rows | |||
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-80865 | bpf: Add missing access_ok call to copy_user_syms | |
| CVE-2026-80856 | fuse: fix invalidate lock leak on setattr writeback failure | |
| CVE-2026-80857 | fuse: wait for FR_FINISHED on abort_on_kill to prevent use-after-free | |
| CVE-2026-80858 | fuse: publish io-uring queues with release semantics | |
| CVE-2026-80859 | fuse: fix missing barrier when checking io-uring readiness | |
| CVE-2026-80860 | fuse: fix race between interrupt and resend | |
| CVE-2026-80861 | usb: xhci: bail out of setup if the controller is inaccessible | |
| CVE-2026-80862 | nvme-tcp: fix usage of page_frag_cache | |
| CVE-2026-80863 | RDMA/rxe: Fix OOB in free_rd_atomic_resources() | |
| CVE-2026-80864 | RDMA/rxe: Fix responder UAF on IB_QP_MAX_DEST_RD_ATOMIC modify_qp | |
| CVE-2026-80870 | drm/amdkfd: Validate CRIU-restored IDs before idr_alloc | |
| CVE-2026-80874 | arm64: dts: renesas: ironhide: Describe inline ECC carveouts | |
| CVE-2026-80873 | KVM: arm64: nv: Write ESR_EL2 for injected nested SError exceptions | |
| CVE-2026-80872 | ALSA: hda/tas2781: Cancel async firmware request at unbind | |
| CVE-2026-80871 | crypto: xilinx-trng - Remove crypto_rng interface | |
| CVE-2026-80868 | ntfs3: Allocate iomap inline_data using alloc_page | |
| CVE-2026-80866 | tipc: avoid busy looping in tipc_exit_net() | |
| CVE-2026-80867 | alpha/PCI: Add security_locked_down() check to pci_mmap_resource() | |
| CVE-2026-80855 | fuse: fix invalidate lock leak on open O_TRUNC DAX failure | |
| CVE-2026-80869 | ntfs: bound the attribute-list entry in ntfs_read_inode_mount() |
Showing top 20 of 156 CVEs. View all on vendor page → →
No comments yet