在 Linux 内核中,已修复以下漏洞: usb: gadget: f_fs: 防止 ep0 读取循环中的死锁 当前, 在准备进入睡眠状态等待事件时,仍持有 互斥锁。当没有待处理的 setup 事件时,它在仍持有互斥锁的情况下调用了 。该 wait 宏在进入睡眠前会主动释放等待队列的自旋锁,但不会释放互斥锁。 如果用户空间守护进程通过 轮询 ep0,而 gadget 设备通过 configfs 被异步解绑(例如执行 ),则可能发生死锁: 1. configfs 的解绑流程调用 ,该函数会入队一个 事件。 2. 守护
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | ddf8abd2599491cbad959c700b90ba72a5dce8d0< fd20cc68bbdb5620696ac108e8f2efd180fe2c1a |
affected |
ddf8abd2599491cbad959c700b90ba72a5dce8d0< 34e88f53614640b59039a46717fb6142e9871022 |
affected | ||
ddf8abd2599491cbad959c700b90ba72a5dce8d0< eac233e63f9db82ba874e3cccafaafab162999e0 |
affected | ||
ddf8abd2599491cbad959c700b90ba72a5dce8d0< 569dd7e5dcffe1e1c6b26ca2cd3be57eb433e082 |
affected | ||
2.6.35 |
affected | ||
< 2.6.35 |
unaffected | ||
6.12.109≤ 6.12.* |
unaffected | ||
6.18.50≤ 6.18.* |
unaffected | ||
| … +2 more rows | |||
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-89491 | ocfs2: cluster: don't sleep while holding o2hb_live_lock in o2hb_region_pin() | |
| CVE-2026-89477 | sctp: fix NULL deref on untransmitted RECONF completion | |
| CVE-2026-89478 | sctp: drop a chunk if its transport was removed | |
| CVE-2026-89479 | sctp: stop processing a packet once its association is deleted | |
| CVE-2026-89480 | nvme-tcp: reject a read that transferred too few bytes | |
| CVE-2026-89482 | nvme-tcp: do not accept C2HData based on blk_rq_payload_bytes() alone | |
| CVE-2026-89481 | nvme-tcp: fix host memory disclosure on R2T for a read command | |
| CVE-2026-89483 | nvme: zero the discard fallback page | |
| CVE-2026-89484 | lockd: fix NULL dereference on lockowner allocation failure | |
| CVE-2026-89485 | lockd: pin next file across nlm_inspect_file lock-drop | |
| CVE-2026-89486 | ipmi: Fix use-after-free of cmd_rcvr in _ipmi_destroy_user() | |
| CVE-2026-89487 | openvswitch: only skb_tx_error() a packet we are about to drop | |
| CVE-2026-89488 | openvswitch: Fix CT limit teardown use-after-free | |
| CVE-2026-89489 | openrisc: fix arbitrary kernel memory access via or1k_atomic syscall | |
| CVE-2026-89500 | ring-buffer: Make cpu_buffer::free_page a buffer_data_read_page | |
| CVE-2026-89497 | orangefs: skip leading spaces before parsing client debug masks | |
| CVE-2026-89498 | orangefs: fix double-free of trailer_buf on readdir copy failure | |
| CVE-2026-89499 | ring-buffer: Stop remote reader update when page swap fails | |
| CVE-2026-89496 | ocfs2: always run deallocs on copy-on-write completion | |
| CVE-2026-89501 | ring-buffer: Hold cpu_buffer::lock when resizing a subbuf |
Showing top 20 of 431 CVEs. View all on vendor page → →
No comments yet