在 Linux 内核中,以下漏洞已得到修复: ublk:在获取 uring_cmd 之前校验自动缓冲区注册 当使用 时,在 已设置 标志后,无效的 可能导致校验失败。此时 已标记为完成,但对应的 tag 仍处于 active 状态,可能导致设备卸载(teardown)过程中发生挂起。 修复方式: 将校验逻辑与缓冲区应用(apply)分离,使校验过程不产生任何副作用;随后再获取 ,并保存已校验通过的缓冲区。在 路径中也采用相同的处理顺序,确保在 进行状态检查之前,不会写入 ,从而避免状态不一致的问题。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | 52460dda3a775a73f226312b43c0a0211e8665ea< 653d22269a8b83b491f7f186a5d7872f14e6ddca |
affected |
52460dda3a775a73f226312b43c0a0211e8665ea< ca5a01eee34c7cbe0f531a613b0292a3ad1a419b |
affected | ||
6.17 |
affected | ||
< 6.17 |
unaffected | ||
7.2.6≤ 7.2.* |
unaffected | ||
7.3-rc1≤ * |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-90255 | Bluetooth: hci_conn: fix the SCO setup context lifetime | |
| CVE-2026-90238 | media: amd: isp4: fix self-deadlock in isp4sd_pwron_and_init() error path | |
| CVE-2026-90240 | iommu/vt-d: Flush context cache with correct SID when tearing down aliases | |
| CVE-2026-90239 | media: amd: isp4: release partial allocations in isp4if_alloc_fw_gpumem() | |
| CVE-2026-90241 | iommu/vt-d: Tear down scalable-mode context on probe failure | |
| CVE-2026-90243 | iommu/vt-d: Clear Present bit before tearing down copied context entry | |
| CVE-2026-90242 | iommu/vt-d: Fix iopf_refcount leak on RID domain replacement | |
| CVE-2026-90244 | iommu/dma: Restore locking around msi_page_list | |
| CVE-2026-90245 | fbdev: kyro: Validate overlay viewport coordinates | |
| CVE-2026-90246 | apparmor: fix integer overflow in verify_tags() bounds check | |
| CVE-2026-90247 | bpf: Fix mmap_lock leak in irq_work path | |
| CVE-2026-90248 | net/sched: cls_api: fix teardown of an adopted proto on insert-race loss | |
| CVE-2026-90249 | iio: light: gp2ap002: Fix unbalanced runtime PM on repeated event writes | |
| CVE-2026-90250 | bpf, cgroup: Fix storage null-ptr-deref after replacing prog | |
| CVE-2026-90251 | Bluetooth: MSFT: validate evt_prefix_len against the response length | |
| CVE-2026-90253 | Bluetooth: MGMT: free the mesh send cancel command when it is cancelled | |
| CVE-2026-90252 | Bluetooth: MGMT: free the HCI command when it is cancelled | |
| CVE-2026-90254 | Bluetooth: hci_sync: free the advertising instance on the failure and cancel paths | |
| CVE-2026-90256 | Bluetooth: L2CAP: use proto_lock for l2cap_data to fix l2cap_disconn_ind | |
| CVE-2026-90268 | scsi: sd: Fix error handling in sd_probe() after large pool creation failure |
Showing top 20 of 602 CVEs. View all on vendor page → →
No comments yet