Linux 内核中已修复了以下漏洞: usb: gadget: uac:在存储前校验速率列表长度 UAC1 和 UAC2 的 configfs 速率列表属性会解析以逗号分隔的采样率列表,并将每个解析出的值存储到固定大小的数组中。这些数组包含 个元素,但存储路径在通过 写入之前,并未检查输入中包含的令牌数量是否超过该上限。 因此,写入超过 10 个速率值时,就会在 或 中的 或 数组末尾之外发生越界写入。 当启用 时,向 UAC1 的 属性写入包含 11 个条目的速率列表会报告: 使用相同的复现步骤对 UAC2 的
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | a7339e4f5788bd088bb0be1f96a6cce459676ed0< 3819c6f255a37c4d085ce9f264f9f11bf3c2c6bb |
affected |
a7339e4f5788bd088bb0be1f96a6cce459676ed0< 844d83d5964b87919b958ff48405188c6ddae9cc |
affected | ||
5.18 |
affected | ||
< 5.18 |
unaffected | ||
7.2.6≤ 7.2.* |
unaffected | ||
7.3-rc1≤ * |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-92489 | 9.8 CRITICAL | xfrm: Fix skb double-free in xfrm_dev_direct_output() |
| CVE-2026-90151 | 9.8 CRITICAL | NFSv4: remove callback IDR entry on client allocation failure |
| CVE-2026-90104 | 9.8 CRITICAL | NFSv4.1: zero referring call lists before decoding |
| CVE-2026-90235 | 9.8 CRITICAL | sunrpc: xprtsock: annotate shared socket callbacks with READ_ONCE/WRITE_ONCE |
| CVE-2026-90173 | 9.8 CRITICAL | smb: smbdirect: free completion queues with ib_free_cq() |
| CVE-2026-90110 | 9.4 CRITICAL | inetpeer: randomize RB-tree node comparison using SipHash |
| CVE-2026-90413 | 9.1 CRITICAL | IB/isert: reject login PDUs declaring more data than was received |
| CVE-2026-90414 | 9.1 CRITICAL | IB/isert: reject PDUs declaring more data than was received |
| CVE-2026-90230 | 9.1 CRITICAL | nvmet: fix heap out-of-bounds read in nvmet_auth_negotiate() |
| CVE-2026-90329 | 8.8 HIGH | HID: synchronize input before cleaning up a failed probe |
| CVE-2026-93189 | 8.8 HIGH | HID: core: quiesce input in hid_hw_stop() to prevent use-after-free |
| CVE-2026-90357 | 8.8 HIGH | wifi: mt76: mt7915: unlink TWT flow if the MCU rejects the agreement |
| CVE-2026-90286 | 8.8 HIGH | drm/amdgpu/gfx6: Use PFP on the compute queues too |
| CVE-2026-90367 | 8.8 HIGH | wifi: mt76: mt7996: hold dev->mt76.mutex while disabling tx worker in SER |
| CVE-2026-93042 | 8.8 HIGH | dmaengine: dw-edma: Terminate all descriptors without callbacks |
| CVE-2026-90256 | 8.8 HIGH | Bluetooth: L2CAP: use proto_lock for l2cap_data to fix l2cap_disconn_ind |
| CVE-2026-90381 | 8.8 HIGH | wifi: mt76: fix handling channel context with different bands in mt76_switch_vif_chanctx() |
| CVE-2026-90371 | 8.8 HIGH | wifi: mt76: fix RXDMAD_C buffer recycling race |
| CVE-2026-90240 | 8.8 HIGH | iommu/vt-d: Flush context cache with correct SID when tearing down aliases |
| CVE-2026-90255 | 8.8 HIGH | Bluetooth: hci_conn: fix the SCO setup context lifetime |
Showing top 20 of 600 CVEs. View all on vendor page → →
No comments yet