Linux kernel是美国Linux基金会开源的一个操作系统内核。 Linux kernel存在安全漏洞,该漏洞源于free_rd_atomic_resources()在释放旧数组前更新qp->attr.max_dest_rd_atomic,导致释放路径越过旧分配边界,可能触发slab越界写入。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | b6bbee0d2438a2c9c7525f5bd7047a8b2ce4f38f< 142c8165b7974b40fa62c393653edb5c00b8b5fe |
affected |
b6bbee0d2438a2c9c7525f5bd7047a8b2ce4f38f< 30b90b55201902b2b8edcdbe2315ccd4c7547002 |
affected | ||
b6bbee0d2438a2c9c7525f5bd7047a8b2ce4f38f< 9b7d66ea88ae9395e42766b94a5c717b158b940a |
affected | ||
b6bbee0d2438a2c9c7525f5bd7047a8b2ce4f38f< f5e6580a3a16a83c743ad5a7c16922854a0d8b71 |
affected | ||
b6bbee0d2438a2c9c7525f5bd7047a8b2ce4f38f< bc6e943794515d2a8417b02597a27bd377468d04 |
affected | ||
b6bbee0d2438a2c9c7525f5bd7047a8b2ce4f38f< bdf5deccfbf9f556a08d1d2ef52e9e48f969e53e |
affected | ||
b6bbee0d2438a2c9c7525f5bd7047a8b2ce4f38f< 4e5f753e8c280278c09f68fe728abf846e2bdfc1 |
affected | ||
b6bbee0d2438a2c9c7525f5bd7047a8b2ce4f38f< d219e7a8eed3802970c3e4d243d79c70ef0a31bf |
affected | ||
| … +12 more rows | |||
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-80865 | bpf: Add missing access_ok call to copy_user_syms | |
| CVE-2026-80855 | fuse: fix invalidate lock leak on open O_TRUNC DAX failure | |
| CVE-2026-80856 | fuse: fix invalidate lock leak on setattr writeback failure | |
| CVE-2026-80857 | fuse: wait for FR_FINISHED on abort_on_kill to prevent use-after-free | |
| CVE-2026-80858 | fuse: publish io-uring queues with release semantics | |
| CVE-2026-80859 | fuse: fix missing barrier when checking io-uring readiness | |
| CVE-2026-80860 | fuse: fix race between interrupt and resend | |
| CVE-2026-80861 | usb: xhci: bail out of setup if the controller is inaccessible | |
| CVE-2026-80862 | nvme-tcp: fix usage of page_frag_cache | |
| CVE-2026-80864 | RDMA/rxe: Fix responder UAF on IB_QP_MAX_DEST_RD_ATOMIC modify_qp | |
| CVE-2026-80870 | drm/amdkfd: Validate CRIU-restored IDs before idr_alloc | |
| CVE-2026-80874 | arm64: dts: renesas: ironhide: Describe inline ECC carveouts | |
| CVE-2026-80873 | KVM: arm64: nv: Write ESR_EL2 for injected nested SError exceptions | |
| CVE-2026-80872 | ALSA: hda/tas2781: Cancel async firmware request at unbind | |
| CVE-2026-80871 | crypto: xilinx-trng - Remove crypto_rng interface | |
| CVE-2026-80868 | ntfs3: Allocate iomap inline_data using alloc_page | |
| CVE-2026-80866 | tipc: avoid busy looping in tipc_exit_net() | |
| CVE-2026-80867 | alpha/PCI: Add security_locked_down() check to pci_mmap_resource() | |
| CVE-2026-80854 | usb: gadget: f_tcm: keep port count until LUN teardown completes | |
| CVE-2026-80869 | ntfs: bound the attribute-list entry in ntfs_read_inode_mount() |
Showing top 20 of 156 CVEs. View all on vendor page → →
No comments yet