Linux kernel是美国Linux基金会开源的一个操作系统内核。 Linux kernel存在安全漏洞,该漏洞源于mm/hugetlb中copy_hugetlb_page_range()函数在fork()时使用huge_pte_clear_uffd_wp()清除迁移条目和hwpoison条目的uffd-wp位,该操作作用于普通PTE位位置,导致交换条目中编码的PFN偏移两个页面,可能破坏复制到子进程的页表条目。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | bc70fbf269fdff410b0b6d75c3770b9f59117b90< f1b1311c0352873137768bac5a126e491271a747 |
affected |
bc70fbf269fdff410b0b6d75c3770b9f59117b90< 69cb5825d9988c7944bc9f1dc08cb233655405a7 |
affected | ||
bc70fbf269fdff410b0b6d75c3770b9f59117b90< 8b0de7005b148738d79d6c45594d566489948a68 |
affected | ||
bc70fbf269fdff410b0b6d75c3770b9f59117b90< 2b9a07002c2f296aa6a9c591213933d3492e3089 |
affected | ||
bc70fbf269fdff410b0b6d75c3770b9f59117b90< 2fa11c60c9c06bafc19cf4d9efdaa36a38079e87 |
affected | ||
bc70fbf269fdff410b0b6d75c3770b9f59117b90< 83abe2fd5b3aeb3123b5408a5a91709c5538fb23 |
affected | ||
5.19 |
affected | ||
< 5.19 |
unaffected | ||
| … +6 more rows | |||
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-80864 | RDMA/rxe: Fix responder UAF on IB_QP_MAX_DEST_RD_ATOMIC modify_qp | |
| CVE-2026-80855 | fuse: fix invalidate lock leak on open O_TRUNC DAX failure | |
| CVE-2026-80856 | fuse: fix invalidate lock leak on setattr writeback failure | |
| CVE-2026-80857 | fuse: wait for FR_FINISHED on abort_on_kill to prevent use-after-free | |
| CVE-2026-80858 | fuse: publish io-uring queues with release semantics | |
| CVE-2026-80859 | fuse: fix missing barrier when checking io-uring readiness | |
| CVE-2026-80860 | fuse: fix race between interrupt and resend | |
| CVE-2026-80861 | usb: xhci: bail out of setup if the controller is inaccessible | |
| CVE-2026-80862 | nvme-tcp: fix usage of page_frag_cache | |
| CVE-2026-80863 | RDMA/rxe: Fix OOB in free_rd_atomic_resources() | |
| CVE-2026-80869 | ntfs: bound the attribute-list entry in ntfs_read_inode_mount() | |
| CVE-2026-80873 | KVM: arm64: nv: Write ESR_EL2 for injected nested SError exceptions | |
| CVE-2026-80872 | ALSA: hda/tas2781: Cancel async firmware request at unbind | |
| CVE-2026-80871 | crypto: xilinx-trng - Remove crypto_rng interface | |
| CVE-2026-80870 | drm/amdkfd: Validate CRIU-restored IDs before idr_alloc | |
| CVE-2026-80867 | alpha/PCI: Add security_locked_down() check to pci_mmap_resource() | |
| CVE-2026-80865 | bpf: Add missing access_ok call to copy_user_syms | |
| CVE-2026-80866 | tipc: avoid busy looping in tipc_exit_net() | |
| CVE-2026-80854 | usb: gadget: f_tcm: keep port count until LUN teardown completes | |
| CVE-2026-80868 | ntfs3: Allocate iomap inline_data using alloc_page |
Showing top 20 of 156 CVEs. View all on vendor page → →
No comments yet