以下是该 Linux 内核漏洞描述的中文翻译: 在 Linux 内核中,已修复以下漏洞: NFSD:防止 close_lru 收割过程中的客户端 use-after-free(释放后使用)问题 在 中残留的 ,在其最终执行 CLOSE 操作后,会将其最后关闭的 保存在 中,该结构体仅通过裸指针指向 。当“洗涤槽”(laundromat)机制收割超时条目时,它会释放 锁,并调用 ,该函数会通过 对 client 进行解引用。然而,在此窗口期内没有任何机制固定(pin)该 client 实例,因此并发执行的 可能将其释
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | 217526e7ecc9f6f243e976772e81eab7ab986a4c< 0763482227822f7343557f086afc382086d56c4c |
affected |
217526e7ecc9f6f243e976772e81eab7ab986a4c< 83dd59ac1c3455c2c7d8ddb582d980a13199b9b3 |
affected | ||
217526e7ecc9f6f243e976772e81eab7ab986a4c< e57a9ed34ea8c17e831de59b8f1a6b2d80d347a1 |
affected | ||
217526e7ecc9f6f243e976772e81eab7ab986a4c< 2330b788d732f43668b965b3105b37ceb276dfea |
affected | ||
3.17 |
affected | ||
< 3.17 |
unaffected | ||
6.12.111≤ 6.12.* |
unaffected | ||
6.18.51≤ 6.18.* |
unaffected | ||
| … +2 more rows | |||
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-90048 | 9.8 CRITICAL | fs/ntfs3: fix slab-out-of-bounds write in ni_create_attr_list() |
| CVE-2026-89778 | 9.8 CRITICAL | isofs: fix out-of-bounds page array access on empty zisofs block |
| CVE-2026-90042 | 9.8 CRITICAL | ceph: properly decrypt filenames in vmalloc() buffers |
| CVE-2026-89783 | 9.8 CRITICAL | xfrm6: fix out-of-bounds write in xfrm6_input_addr() when secpath is full |
| CVE-2026-90012 | 9.8 CRITICAL | spi: Fix DMA mapping ownership on partial map failure |
| CVE-2026-89788 | 9.8 CRITICAL | ksmbd: fix tree connection use-after-free in smb2_tree_connect() |
| CVE-2026-90038 | 9.8 CRITICAL | NFSD: Prevent client use-after-free during export state revocation |
| CVE-2026-90036 | 9.8 CRITICAL | NFSD: Prevent client use-after-free during blocked-lock reaping |
| CVE-2026-89970 | 9.8 CRITICAL | nvmet-auth: Synchronize timeout work during SQ teardown |
| CVE-2026-89990 | 9.8 CRITICAL | ceph: lock mutex in ceph_mds_check_access() |
| CVE-2026-89972 | 9.8 CRITICAL | nvme: add missing SRCU grace period in error path |
| CVE-2026-89857 | 9.8 CRITICAL | scsi: qla2xxx: Hold qpair lock when sending NVMe LS reject |
| CVE-2026-89847 | 9.8 CRITICAL | scsi: qla2xxx: Avoid double completion in async IOCB timeout |
| CVE-2026-89969 | 9.8 CRITICAL | nvmet-tcp: fix out-of-bounds write when receiving an over-long PDU |
| CVE-2026-89930 | 9.3 CRITICAL | KVM: nVMX: Service local TLB flushes on failed nested VM-Enter |
| CVE-2026-89918 | 9.3 CRITICAL | KVM: arm64: Correctly handle end of VA space TLBI invalidation |
| CVE-2026-89916 | 9.3 CRITICAL | KVM: arm64: Make VNCR invalidation participate in MMU invalidation retry |
| CVE-2026-89914 | 9.3 CRITICAL | KVM: arm64: Sign-extend VA for range-based TLBI invalidation |
| CVE-2026-89915 | 9.3 CRITICAL | KVM: arm64: Remove VM-wide VNCR mapping counter |
| CVE-2026-89775 | 9.3 CRITICAL | KVM: arm64: Handle negative S1 walk levels in VNCR TLB size evaluation |
Showing top 20 of 276 CVEs. View all on vendor page → →
No comments yet