在 Linux 内核中,已修复以下漏洞: ksmbd:在解引用其字段之前,先验证 IPC 响应长度 通过从用户空间 ksmbd 守护进程提供的响应缓冲区中读取长度字段( 、 、 等)来计算预期消息大小。这些字段是在缓冲区被验证是否足够大以容纳其所属结构体之前就被读取的,因此,如果响应过短,读取操作会落在内存分配的末尾之外。 完全依据 netlink 属性长度( )来确定 的大小,并且仅对开头的 handle 读取进行了保护,因此守护进程可以安装一个小到如同下面看到的 对象一样的响应。当 为 调用 时,将响应强制转换
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | bf396208418371174869baba9434535cd3288e80< 17b7d1a2b4d5473df5dca8c9a07d65021806c23a |
affected |
7dd0c858e1909769a4c91842724315ee74f1a5f1< 398cba4b646a6c08ff3d79e6b1e70e5ddae8a065 |
affected | ||
299db777ea0cfa5c407e41b045c24a14c034c27b< 0aa8f94bfd4d818284c8a7ce0040d40ca1ec3595 |
affected | ||
d6a6aa81eac2c9bff66dc6e191179cb69a14426b< c494fcf8e89e3c970e13d78ebe62bf5d8f2b1c52 |
affected | ||
d6a6aa81eac2c9bff66dc6e191179cb69a14426b< e9b33376bd07bca4175f7bcc2d6034ef250f8181 |
affected | ||
99c631d0366c1eab8fb188fe66425f4581ebdde4 |
affected | ||
6.6.141< 6.6.157 |
affected | ||
6.12.84< 6.12.110 |
affected | ||
| … +9 more rows | |||
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-90235 | 9.8 CRITICAL | sunrpc: xprtsock: annotate shared socket callbacks with READ_ONCE/WRITE_ONCE |
| CVE-2026-90104 | 9.8 CRITICAL | NFSv4.1: zero referring call lists before decoding |
| CVE-2026-90173 | 9.8 CRITICAL | smb: smbdirect: free completion queues with ib_free_cq() |
| CVE-2026-92489 | 9.8 CRITICAL | xfrm: Fix skb double-free in xfrm_dev_direct_output() |
| CVE-2026-90151 | 9.8 CRITICAL | NFSv4: remove callback IDR entry on client allocation failure |
| CVE-2026-90110 | 9.4 CRITICAL | inetpeer: randomize RB-tree node comparison using SipHash |
| CVE-2026-90230 | 9.1 CRITICAL | nvmet: fix heap out-of-bounds read in nvmet_auth_negotiate() |
| CVE-2026-90414 | 9.1 CRITICAL | IB/isert: reject PDUs declaring more data than was received |
| CVE-2026-90413 | 9.1 CRITICAL | IB/isert: reject login PDUs declaring more data than was received |
| CVE-2026-90380 | 8.8 HIGH | wifi: mt76: mt792x: fix use-after-free in mt76_rx_poll_complete |
| CVE-2026-93042 | 8.8 HIGH | dmaengine: dw-edma: Terminate all descriptors without callbacks |
| CVE-2026-90425 | 8.8 HIGH | iommu/tegra241-cmdqv: Require exactly one Stream ID for a vSID |
| CVE-2026-90240 | 8.8 HIGH | iommu/vt-d: Flush context cache with correct SID when tearing down aliases |
| CVE-2026-90381 | 8.8 HIGH | wifi: mt76: fix handling channel context with different bands in mt76_switch_vif_chanctx() |
| CVE-2026-90329 | 8.8 HIGH | HID: synchronize input before cleaning up a failed probe |
| CVE-2026-90357 | 8.8 HIGH | wifi: mt76: mt7915: unlink TWT flow if the MCU rejects the agreement |
| CVE-2026-90379 | 8.8 HIGH | wifi: mt76: mt7921: Add PCIe AER handler support to prevent system crash |
| CVE-2026-90162 | 8.8 HIGH | ksmbd: defer publishing granted locks to prevent UAF/double-free race |
| CVE-2026-93189 | 8.8 HIGH | HID: core: quiesce input in hid_hw_stop() to prevent use-after-free |
| CVE-2026-90255 | 8.8 HIGH | Bluetooth: hci_conn: fix the SCO setup context lifetime |
Showing top 20 of 600 CVEs. View all on vendor page → →
No comments yet