在 cockpit-files 中发现了缺陷。低权限的本地用户可以通过构造一个包含符号链接(symlink)的目录,并利用具有权限的“以所有者身份粘贴”功能来利用此漏洞。这可能导致在目标粘贴目录之外发生任意文件所有权的变更,从而导致数据完整性受到破坏。在某些情况下,如果新的所有权授予了未经授权的读取权限,还可能导致机密性降低。利用该漏洞需要在粘贴操作期间由用户交互选择非原始所有者。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | any |
affected |
| Red Hat | Red Hat Enterprise Linux 9 | any |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | - |
cpe:/o:redhat:enterprise_linux:10
|
|
| Red Hat | Red Hat Enterprise Linux 9 | - |
cpe:/o:redhat:enterprise_linux:9
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-93569 | 8.2 HIGH | Io.netty/netty-codec-http2: http/1 absolute-form host mismatch is translated to http/2 :au |
| CVE-2026-91149 | 7.5 HIGH | Cockpit: cockpit: denial of service via unbounded connection thread spawning |
| CVE-2026-93565 | 7.5 HIGH | Io.netty/netty-codec-http: netty rtspdecoder method-token smuggling via trailing control b |
| CVE-2026-93564 | 7.5 HIGH | Io.netty/netty-codec-haproxy: netty: haproxy proxy-v2 nested-tlv grandchild bytebuf refere |
| CVE-2026-93567 | 7.5 HIGH | Io.netty/netty-codec-http2: http/1 authority-form connect is translated to malformed http/ |
| CVE-2026-93558 | 7.5 HIGH | Io.netty/netty-codec-http: netty: unbounded per-connection queue growth in websocketserver |
| CVE-2026-93576 | 7.5 HIGH | Io.netty/netty-codec-smtp: netty netty-codec-smtp — smtp command-name field is not crlf-va |
| CVE-2026-93568 | 7.5 HIGH | Io.netty/netty-codec-http2: io.netty/netty-codec-http3: netty: http/2 and http/3 extended |
| CVE-2026-93560 | 7.5 HIGH | Io.netty/netty-codec-stomp: netty: stomp codec content-length long-to-int truncation cause |
| CVE-2026-93491 | 7.5 HIGH | Io.netty/netty-codec-http: netty: denial of service via unbounded httpservercodec http/1.1 |
| CVE-2026-93488 | 7.5 HIGH | Io.netty/netty-codec-http: netty: denial of service via unbounded concurrent spdy streams |
| CVE-2026-93563 | 7.5 HIGH | Io.netty/netty-codec-smtp: netty: unbounded multi-line response accumulation in smtprespon |
| CVE-2026-93572 | 7.5 HIGH | Io.netty/netty-codec-redis: netty: redisarrayaggregator nested resp headers multiply patch |
| CVE-2026-93575 | 7.5 HIGH | Io.netty/netty-codec-mqtt: netty: resource exhaustion in mqttdecoder |
| CVE-2026-87743 | 7.5 HIGH | Quarkus-vertx-http: authorization bypass via path normalization discrepancy in quarkus htt |
| CVE-2026-93494 | 7.5 HIGH | Io.netty/netty-codec-stomp: netty: bytebuf leak in stompsubframedecoder when a frame body |
| CVE-2026-89059 | 7.5 HIGH | Resteasy-core: resteasy: iioimageprovider unbounded image decode (decompression-bomb dos) |
| CVE-2026-89058 | 7.4 HIGH | Resteasy-core: resteasy: corsfilter reflects arbitrary origin with credentials under wildc |
| CVE-2026-81627 | 6.7 MEDIUM | Qemu-kvm: vapic writable rom alias can escape the option-rom window and expose locked smra |
| CVE-2026-93566 | 6.5 MEDIUM | Io.netty/netty-codec-http: netty: http request smuggling due to control characters in the |
Showing top 20 of 42 CVEs. View all on vendor page → →
No comments yet