在 Linux 内核中,已修复以下漏洞: nvme: 在错误路径中添加缺失的 SRCU 宽限期(grace period) 的错误路径在 标签处通过 将命名空间 从其命名空间头(namespace head)的兄弟列表(siblings list)中移除,但在释放命名空间结构体之前,并未等待 SRCU 读者。多路径代码在 和 中在 保护下遍历 ,因此当执行 时,并发读者仍可能持有对 的引用。 正常移除路径 在 之后正确调用了 ,以等待正在进行的读者。需要在错误路径中添加相同的宽限期。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | ed754e5deeb17f4e675c84e4b6c640cc7344e498< d663944dbad81bb0e3635d7090db4713e6300858 |
affected |
ed754e5deeb17f4e675c84e4b6c640cc7344e498< 76023560d60f10b4f808941163aa2975f1631683 |
affected | ||
ed754e5deeb17f4e675c84e4b6c640cc7344e498< ef248d5de4469fb6bbaf8dbe0c4c47800080d648 |
affected | ||
4.15 |
affected | ||
< 4.15 |
unaffected | ||
6.18.51≤ 6.18.* |
unaffected | ||
7.2.5≤ 7.2.* |
unaffected | ||
7.3-rc2≤ * |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-90048 | 9.8 CRITICAL | fs/ntfs3: fix slab-out-of-bounds write in ni_create_attr_list() |
| CVE-2026-90012 | 9.8 CRITICAL | spi: Fix DMA mapping ownership on partial map failure |
| CVE-2026-89857 | 9.8 CRITICAL | scsi: qla2xxx: Hold qpair lock when sending NVMe LS reject |
| CVE-2026-89970 | 9.8 CRITICAL | nvmet-auth: Synchronize timeout work during SQ teardown |
| CVE-2026-89847 | 9.8 CRITICAL | scsi: qla2xxx: Avoid double completion in async IOCB timeout |
| CVE-2026-89969 | 9.8 CRITICAL | nvmet-tcp: fix out-of-bounds write when receiving an over-long PDU |
| CVE-2026-89990 | 9.8 CRITICAL | ceph: lock mutex in ceph_mds_check_access() |
| CVE-2026-90036 | 9.8 CRITICAL | NFSD: Prevent client use-after-free during blocked-lock reaping |
| CVE-2026-90038 | 9.8 CRITICAL | NFSD: Prevent client use-after-free during export state revocation |
| CVE-2026-90037 | 9.8 CRITICAL | NFSD: Prevent client use-after-free during close_lru reaping |
| CVE-2026-89788 | 9.8 CRITICAL | ksmbd: fix tree connection use-after-free in smb2_tree_connect() |
| CVE-2026-89783 | 9.8 CRITICAL | xfrm6: fix out-of-bounds write in xfrm6_input_addr() when secpath is full |
| CVE-2026-90042 | 9.8 CRITICAL | ceph: properly decrypt filenames in vmalloc() buffers |
| CVE-2026-89778 | 9.8 CRITICAL | isofs: fix out-of-bounds page array access on empty zisofs block |
| CVE-2026-89915 | 9.3 CRITICAL | KVM: arm64: Remove VM-wide VNCR mapping counter |
| CVE-2026-90049 | 9.3 CRITICAL | net: skbuff: don't skb_tx_error() the source skb in skb_zerocopy() |
| CVE-2026-89775 | 9.3 CRITICAL | KVM: arm64: Handle negative S1 walk levels in VNCR TLB size evaluation |
| CVE-2026-89916 | 9.3 CRITICAL | KVM: arm64: Make VNCR invalidation participate in MMU invalidation retry |
| CVE-2026-89930 | 9.3 CRITICAL | KVM: nVMX: Service local TLB flushes on failed nested VM-Enter |
| CVE-2026-89918 | 9.3 CRITICAL | KVM: arm64: Correctly handle end of VA space TLBI invalidation |
Showing top 20 of 276 CVEs. View all on vendor page → →
No comments yet