在 Linux 内核中,已修复以下漏洞: scsi: qla2xxx:对 rsp_info_len 进行边界限制,以避免越界读取 sense 数据 在 函数中,FWI2 状态处理路径会推进 指针,并通过 缩减 : 其中, 是一个直接从目标设备的 FCP 响应中获取的 32 位值(即 ),而 是 IOCB 数据区域的大小(24xx 为 28 字节,29xx 为 60 字节)。如果目标设备存在恶意行为或存在缺陷,报告了一个大于 的 ,无符号减法会发生下溢,导致其变为一个极大的值,并使 指针越界。 下溢后的 会在 中削弱
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | 5544213be7b4fb693730106a6d70a8cc1aa7cdf6< 125b12861c726e58448bb95d55b04851fb131d1f |
affected |
5544213be7b4fb693730106a6d70a8cc1aa7cdf6< e57ace988bda5693f7b3645f652ea4b4220870ee |
affected | ||
5544213be7b4fb693730106a6d70a8cc1aa7cdf6< 6b08c0cb110a1fba92f99d655020198489699815 |
affected | ||
5544213be7b4fb693730106a6d70a8cc1aa7cdf6< be75ab791c9b3baca66c70ce03443afebc83acda |
affected | ||
5544213be7b4fb693730106a6d70a8cc1aa7cdf6< ebc41dfc59d190956e0113e8bd90c28f6f21e8b9 |
affected | ||
5544213be7b4fb693730106a6d70a8cc1aa7cdf6< d7f7746ff031ae45724881261804f4bf5317c985 |
affected | ||
5544213be7b4fb693730106a6d70a8cc1aa7cdf6< f6e8977bce887481b2b2b0e2e14a791270741cfb |
affected | ||
5544213be7b4fb693730106a6d70a8cc1aa7cdf6< ca6d880d6c70cb7946e7b3e05d7285f271b6d99e |
affected | ||
| … +10 more rows | |||
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-90048 | 9.8 CRITICAL | fs/ntfs3: fix slab-out-of-bounds write in ni_create_attr_list() |
| CVE-2026-90012 | 9.8 CRITICAL | spi: Fix DMA mapping ownership on partial map failure |
| CVE-2026-89970 | 9.8 CRITICAL | nvmet-auth: Synchronize timeout work during SQ teardown |
| CVE-2026-89857 | 9.8 CRITICAL | scsi: qla2xxx: Hold qpair lock when sending NVMe LS reject |
| CVE-2026-89969 | 9.8 CRITICAL | nvmet-tcp: fix out-of-bounds write when receiving an over-long PDU |
| CVE-2026-89847 | 9.8 CRITICAL | scsi: qla2xxx: Avoid double completion in async IOCB timeout |
| CVE-2026-89972 | 9.8 CRITICAL | nvme: add missing SRCU grace period in error path |
| CVE-2026-89990 | 9.8 CRITICAL | ceph: lock mutex in ceph_mds_check_access() |
| CVE-2026-90036 | 9.8 CRITICAL | NFSD: Prevent client use-after-free during blocked-lock reaping |
| CVE-2026-90038 | 9.8 CRITICAL | NFSD: Prevent client use-after-free during export state revocation |
| CVE-2026-90037 | 9.8 CRITICAL | NFSD: Prevent client use-after-free during close_lru reaping |
| CVE-2026-89783 | 9.8 CRITICAL | xfrm6: fix out-of-bounds write in xfrm6_input_addr() when secpath is full |
| CVE-2026-89788 | 9.8 CRITICAL | ksmbd: fix tree connection use-after-free in smb2_tree_connect() |
| CVE-2026-90042 | 9.8 CRITICAL | ceph: properly decrypt filenames in vmalloc() buffers |
| CVE-2026-89778 | 9.8 CRITICAL | isofs: fix out-of-bounds page array access on empty zisofs block |
| CVE-2026-89914 | 9.3 CRITICAL | KVM: arm64: Sign-extend VA for range-based TLBI invalidation |
| CVE-2026-89915 | 9.3 CRITICAL | KVM: arm64: Remove VM-wide VNCR mapping counter |
| CVE-2026-90049 | 9.3 CRITICAL | net: skbuff: don't skb_tx_error() the source skb in skb_zerocopy() |
| CVE-2026-89775 | 9.3 CRITICAL | KVM: arm64: Handle negative S1 walk levels in VNCR TLB size evaluation |
| CVE-2026-89918 | 9.3 CRITICAL | KVM: arm64: Correctly handle end of VA space TLBI invalidation |
Showing top 20 of 276 CVEs. View all on vendor page → →
No comments yet