在 Linux 内核中,已修复如下漏洞: IB/isert:拒绝声明接收数据量超过实际接收量的 PDU 在处理每个接收到的 PDU 时,直接将其交给操作码(opcode)处理器,却从未检查 ——即主机通道适配器(HCA)实际放入接收描述符中的字节数。随后,这些处理器会从固定大小的描述符中复制相应数量的字节,其长度依据的是发起方在基头段(BHS)中声明的数据段长度(通过 派生出的 或 ): 由于声明的长度从未与实际接收的 进行比对,发起方可以声明一个比其实际发送的字节数更大(且大于描述符容量)的数据段,从而导致接收缓
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | b8d26b3be8b33682cf163274ed07479a70554633< b4706722ed3ea72882b3c986a19b4a1ba66384c4 |
affected |
b8d26b3be8b33682cf163274ed07479a70554633< bc58e9d3dc560220c57b8bdfc12af0cff1c8a43d |
affected | ||
b8d26b3be8b33682cf163274ed07479a70554633< 274b1ad7e78338710864c4b4235bb1ce7e7107f9 |
affected | ||
b8d26b3be8b33682cf163274ed07479a70554633< 2a6b8f88fb7ee51714a1922a039225bdcaf12855 |
affected | ||
b8d26b3be8b33682cf163274ed07479a70554633< 39da0b7e1f530347d284cebcfc5b5afa90a173bf |
affected | ||
b8d26b3be8b33682cf163274ed07479a70554633< cf36fa5357a2fb25776a568d13a3653da7d99bcb |
affected | ||
b8d26b3be8b33682cf163274ed07479a70554633< 352dc85324b29f5c85876f2666f3158b645e3f18 |
affected | ||
b8d26b3be8b33682cf163274ed07479a70554633< 957f92ea4022fb6af4618271615a2a21a7b5bef9 |
affected | ||
| … +10 more rows | |||
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-92489 | 9.8 CRITICAL | xfrm: Fix skb double-free in xfrm_dev_direct_output() |
| CVE-2026-90104 | 9.8 CRITICAL | NFSv4.1: zero referring call lists before decoding |
| CVE-2026-90173 | 9.8 CRITICAL | smb: smbdirect: free completion queues with ib_free_cq() |
| CVE-2026-90151 | 9.8 CRITICAL | NFSv4: remove callback IDR entry on client allocation failure |
| CVE-2026-90235 | 9.8 CRITICAL | sunrpc: xprtsock: annotate shared socket callbacks with READ_ONCE/WRITE_ONCE |
| CVE-2026-90110 | 9.4 CRITICAL | inetpeer: randomize RB-tree node comparison using SipHash |
| CVE-2026-90230 | 9.1 CRITICAL | nvmet: fix heap out-of-bounds read in nvmet_auth_negotiate() |
| CVE-2026-90413 | 9.1 CRITICAL | IB/isert: reject login PDUs declaring more data than was received |
| CVE-2026-90381 | 8.8 HIGH | wifi: mt76: fix handling channel context with different bands in mt76_switch_vif_chanctx() |
| CVE-2026-93189 | 8.8 HIGH | HID: core: quiesce input in hid_hw_stop() to prevent use-after-free |
| CVE-2026-90329 | 8.8 HIGH | HID: synchronize input before cleaning up a failed probe |
| CVE-2026-90256 | 8.8 HIGH | Bluetooth: L2CAP: use proto_lock for l2cap_data to fix l2cap_disconn_ind |
| CVE-2026-90357 | 8.8 HIGH | wifi: mt76: mt7915: unlink TWT flow if the MCU rejects the agreement |
| CVE-2026-90255 | 8.8 HIGH | Bluetooth: hci_conn: fix the SCO setup context lifetime |
| CVE-2026-90367 | 8.8 HIGH | wifi: mt76: mt7996: hold dev->mt76.mutex while disabling tx worker in SER |
| CVE-2026-90286 | 8.8 HIGH | drm/amdgpu/gfx6: Use PFP on the compute queues too |
| CVE-2026-90240 | 8.8 HIGH | iommu/vt-d: Flush context cache with correct SID when tearing down aliases |
| CVE-2026-90380 | 8.8 HIGH | wifi: mt76: mt792x: fix use-after-free in mt76_rx_poll_complete |
| CVE-2026-90379 | 8.8 HIGH | wifi: mt76: mt7921: Add PCIe AER handler support to prevent system crash |
| CVE-2026-90162 | 8.8 HIGH | ksmbd: defer publishing granted locks to prevent UAF/double-free race |
Showing top 20 of 600 CVEs. View all on vendor page → →
No comments yet