在 Linux 内核中,已修复以下漏洞: SCTP:若传输端点已被移除,则丢弃该数据块 会为每个数据包解析一次传输端点(transport),并将其保存在 中。查找时的引用计数,或者当套接字由用户空间拥有时 获取的引用计数,会在数据块被处理之前保持该传输端点有效。 在此期间,一个经过身份验证的 ASCONF DEL-IP 命令可以将其移除。 会将传输端点从关联(association)中移除,并调用 ,该函数会将其标记为失效(dead)并释放关联所持有的引用计数。两条路径上均存在时间窗口:数据包可能停留在套接字的
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2< c6c86a5e62a4fec36692ddd64b9144b660f71f96 |
affected |
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2< 1035bdef1efb9b1076d1a57b81e08c637ff08ecc |
affected | ||
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2< 3537961df2163258bddc230db0e18dc14e925ea6 |
affected | ||
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2< 03a9d10ecf71f54b2af8020935f2033d4a132be5 |
affected | ||
2.6.12 |
affected | ||
< 2.6.12 |
unaffected | ||
6.12.109≤ 6.12.* |
unaffected | ||
6.18.50≤ 6.18.* |
unaffected | ||
| … +2 more rows | |||
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-89490 | ocfs2: fix readdir position truncation on 32-bit kernels | |
| CVE-2026-89477 | sctp: fix NULL deref on untransmitted RECONF completion | |
| CVE-2026-89479 | sctp: stop processing a packet once its association is deleted | |
| CVE-2026-89480 | nvme-tcp: reject a read that transferred too few bytes | |
| CVE-2026-89482 | nvme-tcp: do not accept C2HData based on blk_rq_payload_bytes() alone | |
| CVE-2026-89481 | nvme-tcp: fix host memory disclosure on R2T for a read command | |
| CVE-2026-89483 | nvme: zero the discard fallback page | |
| CVE-2026-89484 | lockd: fix NULL dereference on lockowner allocation failure | |
| CVE-2026-89485 | lockd: pin next file across nlm_inspect_file lock-drop | |
| CVE-2026-89486 | ipmi: Fix use-after-free of cmd_rcvr in _ipmi_destroy_user() | |
| CVE-2026-89487 | openvswitch: only skb_tx_error() a packet we are about to drop | |
| CVE-2026-89488 | openvswitch: Fix CT limit teardown use-after-free | |
| CVE-2026-89489 | openrisc: fix arbitrary kernel memory access via or1k_atomic syscall | |
| CVE-2026-89491 | ocfs2: cluster: don't sleep while holding o2hb_live_lock in o2hb_region_pin() | |
| CVE-2026-89501 | ring-buffer: Hold cpu_buffer::lock when resizing a subbuf | |
| CVE-2026-89498 | orangefs: fix double-free of trailer_buf on readdir copy failure | |
| CVE-2026-89499 | ring-buffer: Stop remote reader update when page swap fails | |
| CVE-2026-89500 | ring-buffer: Make cpu_buffer::free_page a buffer_data_read_page | |
| CVE-2026-89497 | orangefs: skip leading spaces before parsing client debug masks | |
| CVE-2026-89502 | ring-buffer: Free cpu_buffer::free_page with subbuf_order |
Showing top 20 of 431 CVEs. View all on vendor page → →
No comments yet