目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CVE-2026-80891— Linux kernel 安全漏洞

一分钟漏洞结论

影响对象
Linux Linux
利用判断
尚无明确在野利用证据,仍需结合暴露面评估
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

Linux kernel是美国Linux基金会开源的一个操作系统内核。 Linux kernel存在安全漏洞,该漏洞源于KVM的s390 PCI实现在固定客户机页面之前未验证AIBV大小是否超过单个页面边界,且未验证AISB地址是否按8字节对齐,可能导致无法安全固定客户机AIBV。

AI 预测 5.5 利用难度: 中等 EPSS 0.17% · P7

可能的 ATT&CK 技术 1 AI

T1210 · Exploitation of Remote Services

影响版本矩阵 14

厂商产品 版本范围状态
Linux Linux 3c5a1b6f0a18520a0edd0600fef6f1a8553b8fdc< 3a1c64220ede4ac9ef9a3e76f008ff60a34f4c48 affected
3c5a1b6f0a18520a0edd0600fef6f1a8553b8fdc< f00ef8efd41440129ccd88f4a1ebebf8d61d297f affected
3c5a1b6f0a18520a0edd0600fef6f1a8553b8fdc< 15df7700dd99f8a37f5c6ed2dcf1e33009cdba47 affected
3c5a1b6f0a18520a0edd0600fef6f1a8553b8fdc< b878ba7e28144c9a857bc847d31f3c45413450ac affected
3c5a1b6f0a18520a0edd0600fef6f1a8553b8fdc< fbfe683f8b1ae7e40b56bdd6daf5bd671bc3a528 affected
3c5a1b6f0a18520a0edd0600fef6f1a8553b8fdc< 868d32ac72cba21c5c6d8a66a814b7c25a3a5c01 affected
6.0 affected
< 6.0 unaffected
… +6 条更多
获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2026-80891 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
KVM: s390: pci: Validate AIBV and AISB before pinning guest pages
来源: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: KVM: s390: pci: Validate AIBV and AISB before pinning guest pages The AIBV holds one bit per MSI-X vector for a given function. The size of the bit vector is derived from the NOI and the AIBVO. If the size of the AIBV exceeds a single page boundary, then reject the request as we cannot safely pin the guest AIBV. Similarly reject the request if the AISB address is not 8-byte aligned as the architecture requires doubleword alignment for the summary bit address. Since the AISBO can address up to 64 bits, the size of the AISB can only be 8 bytes for the function. This also ensures the AISB doesn't exceed a single page boundary.
来源: CVE Program / CVE List V5
CVSS Information
N/A
来源: CVE Program / CVE List V5
Vulnerability Type
N/A
来源: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Description
Linux kernel是美国Linux基金会开源的一个操作系统内核。 Linux kernel存在安全漏洞,该漏洞源于KVM的s390 PCI实现在固定客户机页面之前未验证AIBV大小是否超过单个页面边界,且未验证AISB地址是否按8字节对齐,可能导致无法安全固定客户机AIBV。
来源: 中国国家信息安全漏洞库 CNNVD
CVSS Information
N/A
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Type
N/A
来源: 中国国家信息安全漏洞库 CNNVD

受影响产品

厂商 产品 影响版本 CPE 订阅
Linux Linux 3c5a1b6f0a18520a0edd0600fef6f1a8553b8fdc ~ 3a1c64220ede4ac9ef9a3e76f008ff60a34f4c48 -
Linux Linux 6.0 -

二、漏洞 CVE-2026-80891 的公开POC

# POC 描述 源链接 神龙链接
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2026-80891 的情报信息

登录查看更多情报信息。

CVE-2026-80891 补丁与修复 (6)

同批安全公告 · Linux · 2026-09-04 · 共 156 条

CVE-2026-80864 Linux kernel 安全漏洞
CVE-2026-80855 Linux kernel 安全漏洞
CVE-2026-80856 Linux kernel 安全漏洞
CVE-2026-80857 Linux kernel 安全漏洞
CVE-2026-80858 Linux kernel 安全漏洞
CVE-2026-80859 Linux kernel 安全漏洞
CVE-2026-80860 Linux kernel 安全漏洞
CVE-2026-80861 Linux kernel 安全漏洞
CVE-2026-80862 Linux kernel 安全漏洞
CVE-2026-80863 Linux kernel 安全漏洞
CVE-2026-80869 Linux kernel 安全漏洞
CVE-2026-80873 Linux kernel 安全漏洞
CVE-2026-80872 Linux kernel 安全漏洞
CVE-2026-80871 Linux kernel 安全漏洞
CVE-2026-80870 Linux kernel 安全漏洞
CVE-2026-80867 Linux kernel 安全漏洞
CVE-2026-80865 Linux kernel 安全漏洞
CVE-2026-80866 Linux kernel 安全漏洞
CVE-2026-80854 Linux kernel 安全漏洞
CVE-2026-80868 Linux kernel 安全漏洞

显示前 20 条,共 156 条。 查看全部 &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-80891

暂无评论


发表评论