在 Linux 内核中,以下漏洞已被修复: ASoC: meson:在内存重新分配(realloc)失败时保持链接指针有效 meson_card_reallocate_links() 函数通过两次连续的 krealloc() 调用来扩展 DAI 链接数组和私有数据数组,并且仅在两次调用均成功之后才更新所有者指针。 成功的 krealloc() 调用可能会移动数据:它会释放旧内存块并返回一个新内存块。当这种情况发生在链接数组上,且随后的第二次 krealloc() 调用失败时,card->dai_link 仍指向已被
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | 7864a79f37b55769b817d5e6c5ae0ca4bfdba93b< de33afc57f24538186bccf4c4f6c65dd38634fd8 |
affected |
7864a79f37b55769b817d5e6c5ae0ca4bfdba93b< 1c1485343b7c1c39dab7ecb9cd16ba49fd0ce642 |
affected | ||
7864a79f37b55769b817d5e6c5ae0ca4bfdba93b< 8db0a0fc84e80aa9924e0833aef6cc95df94e5a7 |
affected | ||
7864a79f37b55769b817d5e6c5ae0ca4bfdba93b< 41e92e0caa1fe3df2efaca346bfcaeb7fb9826ab |
affected | ||
7864a79f37b55769b817d5e6c5ae0ca4bfdba93b< 0b30fbe6bf7cf6499b19dd886f466e7c9e820089 |
affected | ||
7864a79f37b55769b817d5e6c5ae0ca4bfdba93b< 8fec16898f184e5f8f8fdd09ff1ced2bd7ffc13d |
affected | ||
7864a79f37b55769b817d5e6c5ae0ca4bfdba93b< 5ed1b048527bebe4529eb6e01c34dcc5d97ba5fe |
affected | ||
7864a79f37b55769b817d5e6c5ae0ca4bfdba93b< 2aaa41cf974f83a6fb105422bac4e2f107150774 |
affected | ||
| … +10 more rows | |||
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-92489 | 9.8 CRITICAL | xfrm: Fix skb double-free in xfrm_dev_direct_output() |
| CVE-2026-90235 | 9.8 CRITICAL | sunrpc: xprtsock: annotate shared socket callbacks with READ_ONCE/WRITE_ONCE |
| CVE-2026-90173 | 9.8 CRITICAL | smb: smbdirect: free completion queues with ib_free_cq() |
| CVE-2026-90104 | 9.8 CRITICAL | NFSv4.1: zero referring call lists before decoding |
| CVE-2026-90151 | 9.8 CRITICAL | NFSv4: remove callback IDR entry on client allocation failure |
| CVE-2026-90110 | 9.4 CRITICAL | inetpeer: randomize RB-tree node comparison using SipHash |
| CVE-2026-90230 | 9.1 CRITICAL | nvmet: fix heap out-of-bounds read in nvmet_auth_negotiate() |
| CVE-2026-90414 | 9.1 CRITICAL | IB/isert: reject PDUs declaring more data than was received |
| CVE-2026-90413 | 9.1 CRITICAL | IB/isert: reject login PDUs declaring more data than was received |
| CVE-2026-90367 | 8.8 HIGH | wifi: mt76: mt7996: hold dev->mt76.mutex while disabling tx worker in SER |
| CVE-2026-90329 | 8.8 HIGH | HID: synchronize input before cleaning up a failed probe |
| CVE-2026-93189 | 8.8 HIGH | HID: core: quiesce input in hid_hw_stop() to prevent use-after-free |
| CVE-2026-90240 | 8.8 HIGH | iommu/vt-d: Flush context cache with correct SID when tearing down aliases |
| CVE-2026-90357 | 8.8 HIGH | wifi: mt76: mt7915: unlink TWT flow if the MCU rejects the agreement |
| CVE-2026-90286 | 8.8 HIGH | drm/amdgpu/gfx6: Use PFP on the compute queues too |
| CVE-2026-93042 | 8.8 HIGH | dmaengine: dw-edma: Terminate all descriptors without callbacks |
| CVE-2026-90256 | 8.8 HIGH | Bluetooth: L2CAP: use proto_lock for l2cap_data to fix l2cap_disconn_ind |
| CVE-2026-90380 | 8.8 HIGH | wifi: mt76: mt792x: fix use-after-free in mt76_rx_poll_complete |
| CVE-2026-90381 | 8.8 HIGH | wifi: mt76: fix handling channel context with different bands in mt76_switch_vif_chanctx() |
| CVE-2026-90425 | 8.8 HIGH | iommu/tegra241-cmdqv: Require exactly one Stream ID for a vSID |
Showing top 20 of 600 CVEs. View all on vendor page → →
No comments yet