目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CVE-2026-80893— Linux kernel 安全漏洞

一分钟漏洞结论

影响对象
Linux Linux
利用判断
尚无明确在野利用证据,仍需结合暴露面评估
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

Linux kernel是美国Linux基金会开源的一个操作系统内核。 Linux kernel存在安全漏洞,该漏洞源于mm/hugetlb中copy_hugetlb_page_range()函数在fork()时使用huge_pte_clear_uffd_wp()清除迁移条目和hwpoison条目的uffd-wp位,该操作作用于普通PTE位位置,导致交换条目中编码的PFN偏移两个页面,可能破坏复制到子进程的页表条目。

AI 预测 5.5 利用难度: 中等 EPSS 0.17% · P7

可能的 ATT&CK 技术 1 AI

T1069 · Permission Groups Discovery

影响版本矩阵 14

厂商产品 版本范围状态
Linux Linux bc70fbf269fdff410b0b6d75c3770b9f59117b90< f1b1311c0352873137768bac5a126e491271a747 affected
bc70fbf269fdff410b0b6d75c3770b9f59117b90< 69cb5825d9988c7944bc9f1dc08cb233655405a7 affected
bc70fbf269fdff410b0b6d75c3770b9f59117b90< 8b0de7005b148738d79d6c45594d566489948a68 affected
bc70fbf269fdff410b0b6d75c3770b9f59117b90< 2b9a07002c2f296aa6a9c591213933d3492e3089 affected
bc70fbf269fdff410b0b6d75c3770b9f59117b90< 2fa11c60c9c06bafc19cf4d9efdaa36a38079e87 affected
bc70fbf269fdff410b0b6d75c3770b9f59117b90< 83abe2fd5b3aeb3123b5408a5a91709c5538fb23 affected
5.19 affected
< 5.19 unaffected
… +6 条更多
获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2026-80893 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
mm/hugetlb: fix swap entry corruption when clearing uffd-wp at fork()
来源: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: mm/hugetlb: fix swap entry corruption when clearing uffd-wp at fork() copy_hugetlb_page_range() clears the uffd-wp bit of migration and hwpoison entries with huge_pte_clear_uffd_wp(), which operates on the present-PTE bit position. Swap entries keep the uffd-wp state elsewhere -- the migration branch reads and sets it with pte_swp_uffd_wp() and pte_swp_mkuffd_wp() -- and the present-PTE position falls into the swap payload. On x86-64 it lands in the inverted swap offset, where a naturally-aligned hugetlb PFN always has the affected bit set, so the clear advances the encoded PFN by two pages. No userfaultfd needs to be involved: the clear is guarded only by the child VMA not being uffd-wp registered, so a plain fork() with an in-flight hugetlb migration entry (or a poisoned hugetlb page) corrupts the entry copied into the child. Instrumenting the clear and forking after MADV_HWPOISON on a 2MB anon hugetlb page shows: offset before=120e00 offset after =120e02 The fallout is mostly latent: rmap walks match migration entries by folio range and remove_migration_pte() rebuilds the PTE from the folio, so a within-folio PFN skew heals once migration completes. But any path that re-encodes the corrupted offset -- e.g. hugetlb_change_protection() rewriting a writable migration entry via make_readable_migration_entry(swp_offset(entry)) -- propagates it. Migration entries legitimately carry uffd-wp, so clear it with pte_swp_clear_uffd_wp(), matching copy_nonpresent_pte() and move_huge_pte(). A hwpoison entry, on the other hand, never carries the uffd-wp bit: it is installed fresh by make_hwpoison_entry() (try_to_unmap_one() does not preserve uffd-wp on the hwpoison path) and hugetlb_change_protection() leaves hwpoison entries untouched. There was nothing to clear there, only the corruption, so drop the clear entirely.
来源: CVE Program / CVE List V5
CVSS Information
N/A
来源: CVE Program / CVE List V5
Vulnerability Type
N/A
来源: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Description
Linux kernel是美国Linux基金会开源的一个操作系统内核。 Linux kernel存在安全漏洞,该漏洞源于mm/hugetlb中copy_hugetlb_page_range()函数在fork()时使用huge_pte_clear_uffd_wp()清除迁移条目和hwpoison条目的uffd-wp位,该操作作用于普通PTE位位置,导致交换条目中编码的PFN偏移两个页面,可能破坏复制到子进程的页表条目。
来源: 中国国家信息安全漏洞库 CNNVD
CVSS Information
N/A
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Type
N/A
来源: 中国国家信息安全漏洞库 CNNVD

受影响产品

厂商 产品 影响版本 CPE 订阅
Linux Linux bc70fbf269fdff410b0b6d75c3770b9f59117b90 ~ f1b1311c0352873137768bac5a126e491271a747 -
Linux Linux 5.19 -

二、漏洞 CVE-2026-80893 的公开POC

# POC 描述 源链接 神龙链接
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2026-80893 的情报信息

登录查看更多情报信息。

CVE-2026-80893 补丁与修复 (5)

CVE-2026-80893 其他参考 (1)

同批安全公告 · Linux · 2026-09-04 · 共 156 条

CVE-2026-80864 Linux kernel 安全漏洞
CVE-2026-80855 Linux kernel 安全漏洞
CVE-2026-80856 Linux kernel 安全漏洞
CVE-2026-80857 Linux kernel 安全漏洞
CVE-2026-80858 Linux kernel 安全漏洞
CVE-2026-80859 Linux kernel 安全漏洞
CVE-2026-80860 Linux kernel 安全漏洞
CVE-2026-80861 Linux kernel 安全漏洞
CVE-2026-80862 Linux kernel 安全漏洞
CVE-2026-80863 Linux kernel 安全漏洞
CVE-2026-80869 Linux kernel 安全漏洞
CVE-2026-80873 Linux kernel 安全漏洞
CVE-2026-80872 Linux kernel 安全漏洞
CVE-2026-80871 Linux kernel 安全漏洞
CVE-2026-80870 Linux kernel 安全漏洞
CVE-2026-80867 Linux kernel 安全漏洞
CVE-2026-80865 Linux kernel 安全漏洞
CVE-2026-80866 Linux kernel 安全漏洞
CVE-2026-80854 Linux kernel 安全漏洞
CVE-2026-80868 Linux kernel 安全漏洞

显示前 20 条,共 156 条。 查看全部 &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-80893

暂无评论


发表评论