在 Linux 内核中,已修复以下漏洞: fs/ntfs3:修复 MFT 簇验证中的整数溢出问题 在 函数中,启动扇区的 MFT 簇编号会与卷大小进行验证,代码如下: 其中 和 是从启动扇区直接读取的 u64 字段。 的上限为 4096(由 及其下方的 检查所限定)。然而,乘法运算在 u64 下进行,当 (或 )的值足够大时(例如 接近 2^62 且 ),乘法结果会发生回绕(wrap around)——例如回绕为 0,这将小于任何非零的 ,从而绕过了检查,导致格式错误的记录被接受。 被接受的 随后未经验证地用于以下
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | 82cae269cfa953032fbb8980a7d554d60fb00b17< f77a8d9fdf58e298b36564a44c27fadc617bdd28 |
affected |
82cae269cfa953032fbb8980a7d554d60fb00b17< 805cc5554b13d045dce9b03c13eaf015418739fd |
affected | ||
82cae269cfa953032fbb8980a7d554d60fb00b17< dc6d85de7e2656e56e10ff5ba514f2583a4f612b |
affected | ||
82cae269cfa953032fbb8980a7d554d60fb00b17< 169383d8914b8fe03464a83540b5b6de3e7831af |
affected | ||
82cae269cfa953032fbb8980a7d554d60fb00b17< c510c63873103a5da6a498fe537bdb5d6f8d03a2 |
affected | ||
5.15 |
affected | ||
< 5.15 |
unaffected | ||
6.6.157≤ 6.6.* |
unaffected | ||
| … +4 more rows | |||
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-90235 | 9.8 CRITICAL | sunrpc: xprtsock: annotate shared socket callbacks with READ_ONCE/WRITE_ONCE |
| CVE-2026-90104 | 9.8 CRITICAL | NFSv4.1: zero referring call lists before decoding |
| CVE-2026-90173 | 9.8 CRITICAL | smb: smbdirect: free completion queues with ib_free_cq() |
| CVE-2026-92489 | 9.8 CRITICAL | xfrm: Fix skb double-free in xfrm_dev_direct_output() |
| CVE-2026-90151 | 9.8 CRITICAL | NFSv4: remove callback IDR entry on client allocation failure |
| CVE-2026-90110 | 9.4 CRITICAL | inetpeer: randomize RB-tree node comparison using SipHash |
| CVE-2026-90230 | 9.1 CRITICAL | nvmet: fix heap out-of-bounds read in nvmet_auth_negotiate() |
| CVE-2026-90414 | 9.1 CRITICAL | IB/isert: reject PDUs declaring more data than was received |
| CVE-2026-90413 | 9.1 CRITICAL | IB/isert: reject login PDUs declaring more data than was received |
| CVE-2026-90380 | 8.8 HIGH | wifi: mt76: mt792x: fix use-after-free in mt76_rx_poll_complete |
| CVE-2026-93042 | 8.8 HIGH | dmaengine: dw-edma: Terminate all descriptors without callbacks |
| CVE-2026-90425 | 8.8 HIGH | iommu/tegra241-cmdqv: Require exactly one Stream ID for a vSID |
| CVE-2026-90240 | 8.8 HIGH | iommu/vt-d: Flush context cache with correct SID when tearing down aliases |
| CVE-2026-90381 | 8.8 HIGH | wifi: mt76: fix handling channel context with different bands in mt76_switch_vif_chanctx() |
| CVE-2026-90329 | 8.8 HIGH | HID: synchronize input before cleaning up a failed probe |
| CVE-2026-90357 | 8.8 HIGH | wifi: mt76: mt7915: unlink TWT flow if the MCU rejects the agreement |
| CVE-2026-90379 | 8.8 HIGH | wifi: mt76: mt7921: Add PCIe AER handler support to prevent system crash |
| CVE-2026-90162 | 8.8 HIGH | ksmbd: defer publishing granted locks to prevent UAF/double-free race |
| CVE-2026-93189 | 8.8 HIGH | HID: core: quiesce input in hid_hw_stop() to prevent use-after-free |
| CVE-2026-90255 | 8.8 HIGH | Bluetooth: hci_conn: fix the SCO setup context lifetime |
Showing top 20 of 600 CVEs. View all on vendor page → →
No comments yet