GNOME Shell 中存在一个缺陷。在通过 D-Bus 处理来自远程搜索提供程序的图标时,系统未能验证图标声明的尺寸与实际数据缓冲区大小是否匹配。恶意或已失陷的远程搜索提供程序可以通过提供尺寸过大的图标尺寸来利用此漏洞,从而导致越界读取。这可能引发 GNOME Shell 进程崩溃,中断用户的会话,并可能泄露相邻内存中的敏感信息。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | - |
cpe:/o:redhat:enterprise_linux:10
|
|
| Red Hat | Red Hat Enterprise Linux 7 | - |
cpe:/o:redhat:enterprise_linux:7
|
|
| Red Hat | Red Hat Enterprise Linux 8 | - |
cpe:/o:redhat:enterprise_linux:8
|
|
| Red Hat | Red Hat Enterprise Linux 9 | - |
cpe:/o:redhat:enterprise_linux:9
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-75092 | 7.3 HIGH | Leapp-repository: leapp-upgrade-el9toel10: leapp-upgrade-el9toel10: scan_mysql runs mysqld |
| CVE-2026-81303 | 6.3 MEDIUM | Hawtio-operator: hawtio-operator: routes/custom-host confused-deputy via spec.routehostnam |
| CVE-2026-81320 | 5.5 MEDIUM | Hawtio-operator: hawtio-operator: tls private key written to operator log at debug level |
| CVE-2026-91926 | 3.7 LOW | Gss-ntlmssp: gss-ntlmssp: memory leak in ntlm_decode_target_info via duplicated av_pair en |
No comments yet