目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2026-93206— PCI/proc 配置空间读取访问检查漏洞

一分钟漏洞结论

影响对象
Linux Linux
利用判断
尚无明确在野利用证据,仍需结合暴露面评估
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

在 Linux 内核中,已修复以下漏洞: PCI/proc:在检查配置空间读访问权限时使用 根据 的结果来决定可读取的配置空间范围。该检查验证的是调用 的系统任务(task)的凭据(credentials),而非打开该文件的进程的凭据。 而 sysfs 中的等效函数 自提交 (“pci:从 sysfs 文件打开时检查配置空间的权限,以读取设备相关的配置空间”)起,已开始检查打开文件的进程的凭据。因此,特权进程可以打开配置空间文件,并将文件描述符传递给非特权进程(例如,运行具有分配设备的 KVM 来宾的进程),从而使

AI 预测 5.5 利用难度: 中等 EPSS 0.19% · P8

可能的 ATT&CK 技术 1 AI

T1528 · Steal Application Access Token

影响版本矩阵 18

厂商产品 版本范围状态
Linux Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2< 8a3a54aa3e65ed76f8560a387243a7738ae0cb1c affected
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2< 5c7ab4ca66f0880cffc3735555ea719dd5253726 affected
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2< 53407535d49ec034e476121020b5c878f0d92e18 affected
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2< e7730acd6a01c5931a3afb83639810ff2fb9cc92 affected
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2< 77272b7fd0e472086fd626a1fcd11da625822cc2 affected
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2< c2d4174f492458ecdcdef309243624999612d526 affected
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2< 6351e94076329dab517ea94c115e15c4d8459381 affected
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2< f82f53e75eff382fc8f56b73279b54f7cf5a5c65 affected
… +10 条更多
获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2026-93206 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
PCI/proc: Use file_ns_capable() when checking config space read access
来源: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: PCI/proc: Use file_ns_capable() when checking config space read access proc_bus_pci_read() decides how much of the config space is readable based on capable(CAP_SYS_ADMIN), which checks the credentials of the task calling read(), not the credentials of the process that opened the file. The sysfs equivalent, pci_read_config(), has checked the credentials of the opening process since commit de139a339395 ("pci: check caps from sysfs file open to read device dependent config space"), so a privileged process can open the config space file and pass the file descriptor to an unprivileged process (for example, a process running a KVM guest with an assigned device), which can then read the entire config space. The check was subsequently routed through the LSM framework in commit 47970b1b2aa6 ("pci: use security_capable() when checking capablities during config space read") and converted to the dedicated helper in commit ab0fa82b2df9 ("pci-sysfs: use proper file capability helper function"). Thus, the two interfaces check the same capability against different credentials. Checking the credentials of the task calling read() makes the outcome depend on who reads rather than who opened, so the restriction is bypassed whenever a more privileged process reads through the descriptor. Checking the credentials recorded in file->f_cred settles the decision at open() time and ties it to the file, where it cannot change with the caller. Use file_ns_capable() to check CAP_SYS_ADMIN against the credentials in effect when the file was opened, bringing the procfs interface in line with the sysfs behaviour. As a result, a file descriptor opened by a privileged process and passed to an unprivileged one now allows the entire config space to be read through procfs, matching sysfs.
来源: CVE Program / CVE List V5
CVSS Information
N/A
来源: CVE Program / CVE List V5
Vulnerability Type
N/A
来源: CVE Program / CVE List V5

受影响产品

厂商 产品 影响版本 CPE 订阅
Linux Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 ~ 8a3a54aa3e65ed76f8560a387243a7738ae0cb1c -
Linux Linux 2.6.12 -

二、漏洞 CVE-2026-93206 的公开POC

# POC 描述 源链接 神龙链接
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2026-93206 的情报信息

请登录查看更多情报信息。

CVE-2026-93206 补丁与修复 (7)

CVE-2026-93206 其他参考 (1)

同批安全公告 · Linux · 2026-09-24 · 共 234 条

CVE-2026-93207 9.8 CRITICAL SUNRPC svcauth_gss_decode_credbody() 存在安全漏洞
CVE-2026-97413 9.8 CRITICAL Linux RDMA/rtrs-srv整数下溢漏洞
CVE-2026-93228 9.1 CRITICAL svcrdma 拒绝段计数为0的写入/回复块漏洞
CVE-2026-93793 8.8 HIGH iwlwifi 驱动 TX_CMD 响应布局验证漏洞
CVE-2026-93799 8.8 HIGH iwlwifi mvm BA窗口状态通知中sta_id验证漏洞
CVE-2026-93790 8.8 HIGH iwlwifi 驱动 BA 通知中 tid_data 越界访问漏洞
CVE-2026-93806 8.8 HIGH wifi: cfg80211 关联响应长度验证漏洞
CVE-2026-97442 8.8 HIGH ath11k无线驱动rx_h_undecap_nwifi无效数据访问漏洞
CVE-2026-97409 8.8 HIGH Linux NVMe-oF目标未初始化前取消请求漏洞
CVE-2026-97509 8.8 HIGH Thunderbolt 服务期间保持 XDomain 引用漏洞
CVE-2026-93280 8.8 HIGH Greybus 音频拓扑边界检查漏洞
CVE-2026-93284 8.8 HIGH drm/pagemap 迁移错误前未解除 dma 映射
CVE-2026-97451 8.4 HIGH ACPICA mid_op 整数溢出漏洞
CVE-2026-97452 8.4 HIGH ACPICA:防止添加无效引用
CVE-2026-97455 8.4 HIGH ACPICA acpi_ds_terminate_control_method 使用后释放漏洞
CVE-2026-97450 8.4 HIGH ACPICA 双重验证处理器对象类型漏洞
CVE-2026-93827 8.4 HIGH virtio-fs 队列设置失败时双重释放漏洞
CVE-2026-97433 8.2 HIGH NVMe 验证 FDP 配置描述符大小
CVE-2026-93787 8.1 HIGH CIFS cifs_filldir 中目录项名称越界访问漏洞
CVE-2026-93224 8.1 HIGH svcrdma 接受失败时未配对 rn_unregister 漏洞

显示前 20 条,共 234 条。 查看全部 &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-93206

暂无评论


发表评论