在 Linux 内核中,已修复以下漏洞: inetpeer:使用 SipHash 随机化红黑树节点比较逻辑 inetpeer 限流系统以前端 IP 地址作为确定性键值,将 peer 条目存储在一棵红黑树(Red-Black tree)中。由于树的查找过程使用标准的字典序比较( )来遍历红黑树,非路径对手(off-path adversary)可以预测树的精确拓扑结构以及在查找过程中遍历的节点序列(即 候选列表)。 通过将确定性的树遍历与激进的垃圾回收机制(当树的大小超过 时触发)相结合,攻击者可以有选择地强制驱逐特
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | b145425f269a17ed344d737f746b844dfac60c82< b20e98f0bb668a59abaf7bcf85d75c073e90d352 |
affected |
b145425f269a17ed344d737f746b844dfac60c82< 5f127e3cc9647a8a70db12c65dbd0de473545380 |
affected | ||
b145425f269a17ed344d737f746b844dfac60c82< 199fcf285e498111e029137d088949bc6c26d578 |
affected | ||
b145425f269a17ed344d737f746b844dfac60c82< 857681f6835d5b0a7bc4a34a026baeaaf5215623 |
affected | ||
b145425f269a17ed344d737f746b844dfac60c82< 7109bb63667a53e4542ad845476f97d0c8b28a61 |
affected | ||
b145425f269a17ed344d737f746b844dfac60c82< 2ee66e9487172fcd189bc52a767c30dad7141c09 |
affected | ||
4.14 |
affected | ||
< 4.14 |
unaffected | ||
| … +6 more rows | |||
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-92489 | 9.8 CRITICAL | xfrm: Fix skb double-free in xfrm_dev_direct_output() |
| CVE-2026-90151 | 9.8 CRITICAL | NFSv4: remove callback IDR entry on client allocation failure |
| CVE-2026-90173 | 9.8 CRITICAL | smb: smbdirect: free completion queues with ib_free_cq() |
| CVE-2026-90104 | 9.8 CRITICAL | NFSv4.1: zero referring call lists before decoding |
| CVE-2026-90235 | 9.8 CRITICAL | sunrpc: xprtsock: annotate shared socket callbacks with READ_ONCE/WRITE_ONCE |
| CVE-2026-90413 | 9.1 CRITICAL | IB/isert: reject login PDUs declaring more data than was received |
| CVE-2026-90414 | 9.1 CRITICAL | IB/isert: reject PDUs declaring more data than was received |
| CVE-2026-90230 | 9.1 CRITICAL | nvmet: fix heap out-of-bounds read in nvmet_auth_negotiate() |
| CVE-2026-90379 | 8.8 HIGH | wifi: mt76: mt7921: Add PCIe AER handler support to prevent system crash |
| CVE-2026-90286 | 8.8 HIGH | drm/amdgpu/gfx6: Use PFP on the compute queues too |
| CVE-2026-90381 | 8.8 HIGH | wifi: mt76: fix handling channel context with different bands in mt76_switch_vif_chanctx() |
| CVE-2026-90256 | 8.8 HIGH | Bluetooth: L2CAP: use proto_lock for l2cap_data to fix l2cap_disconn_ind |
| CVE-2026-90255 | 8.8 HIGH | Bluetooth: hci_conn: fix the SCO setup context lifetime |
| CVE-2026-90380 | 8.8 HIGH | wifi: mt76: mt792x: fix use-after-free in mt76_rx_poll_complete |
| CVE-2026-90357 | 8.8 HIGH | wifi: mt76: mt7915: unlink TWT flow if the MCU rejects the agreement |
| CVE-2026-90240 | 8.8 HIGH | iommu/vt-d: Flush context cache with correct SID when tearing down aliases |
| CVE-2026-90425 | 8.8 HIGH | iommu/tegra241-cmdqv: Require exactly one Stream ID for a vSID |
| CVE-2026-90371 | 8.8 HIGH | wifi: mt76: fix RXDMAD_C buffer recycling race |
| CVE-2026-93189 | 8.8 HIGH | HID: core: quiesce input in hid_hw_stop() to prevent use-after-free |
| CVE-2026-90329 | 8.8 HIGH | HID: synchronize input before cleaning up a failed probe |
Showing top 20 of 600 CVEs. View all on vendor page → →
No comments yet