目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2026-97436— dpaa2-switch网桥离开路径FDB管理漏洞

一分钟漏洞结论

影响对象
Linux Linux
利用判断
尚无明确在野利用证据,仍需结合暴露面评估
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

在 Linux 内核中,以下漏洞已得到修复: dpaa2-switch:重构桥接退出路径上的 FDB(转发数据库)管理逻辑 当端口离开桥接(bridge)时, 函数总是为该变为独立端口的端口分配一个新的 FDB。如果未找到可用的 FDB,则该离开桥接的端口将继续使用当前的 FDB。 上述逻辑未能涵盖一种情况:即存在多个桥接,且这些桥接共享来自同一 DPSW 实例的端口。在这种情况下,当最后一个端口离开桥接 #1 时,它会找到一个未使用的 FDB 并切换过去,但旧的 FDB 并未被标记为“未使用”。由于 FDB 的数

AI 预测 5.3 利用难度: 中等 EPSS 0.17% · P6

可能的 ATT&CK 技术 1 AI

T1610 · Deploy Container

影响版本矩阵 14

厂商产品 版本范围状态
Linux Linux 539dda3c5d190c5088b5e57944b1b482fcb464de< ec41bfd281a8bc8027a42d2674eac5b74947ff7a affected
539dda3c5d190c5088b5e57944b1b482fcb464de< e07ff2338f45adbf572850335d761c2f97545935 affected
539dda3c5d190c5088b5e57944b1b482fcb464de< dc626f2abb3052881911b6166a9425739ce80085 affected
539dda3c5d190c5088b5e57944b1b482fcb464de< abea361a11e4e48695ea149652ef5d3f308b6a49 affected
539dda3c5d190c5088b5e57944b1b482fcb464de< 5adbc4d02d7df8bd7aa02c21874f7a582a576b55 affected
539dda3c5d190c5088b5e57944b1b482fcb464de< efc1d92eacf03afa6f4d53bf7120e059b6f961f2 affected
5.13 affected
< 5.13 unaffected
… +6 条更多
获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2026-97436 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
dpaa2-switch: rework FDB management on the bridge leave path
来源: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: dpaa2-switch: rework FDB management on the bridge leave path On bridge leave, the dpaa2_switch_port_set_fdb() function always allocates a new FDB for the port which is becoming standalone. In case no FDB is found, then the port leaving a bridge will continue to use the current one. The above logic does not cover the case in which there are multiple bridges which have ports from the same DPSW instance. In this case, when the last port leaves bridge #1, it finds an unused FDB to switch to, but the old FDB is not marked as unused. Since the number of FDBs is equal to the number of DPSW interfaces, this will eventually lead to multiple ports sharing the same FDB. Fix this by changing how we are managing the FDBs on the leave path. Instead of directly allocating a new FDB, first verify if the current port is the last one to leave a bridge. If this is the case, then continue to use the current FDB and only allocate another FDB if there are other ports remaining in the bridge.
来源: CVE Program / CVE List V5
CVSS Information
N/A
来源: CVE Program / CVE List V5
Vulnerability Type
N/A
来源: CVE Program / CVE List V5

受影响产品

厂商 产品 影响版本 CPE 订阅
Linux Linux 539dda3c5d190c5088b5e57944b1b482fcb464de ~ ec41bfd281a8bc8027a42d2674eac5b74947ff7a -
Linux Linux 5.13 -

二、漏洞 CVE-2026-97436 的公开POC

# POC 描述 源链接 神龙链接
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2026-97436 的情报信息

请登录查看更多情报信息。

CVE-2026-97436 补丁与修复 (6)

同批安全公告 · Linux · 2026-09-24 · 共 234 条

CVE-2026-93207 9.8 CRITICAL SUNRPC svcauth_gss_decode_credbody() 存在安全漏洞
CVE-2026-97413 9.8 CRITICAL Linux RDMA/rtrs-srv整数下溢漏洞
CVE-2026-93228 9.1 CRITICAL svcrdma 拒绝段计数为0的写入/回复块漏洞
CVE-2026-93799 8.8 HIGH iwlwifi mvm BA窗口状态通知中sta_id验证漏洞
CVE-2026-97442 8.8 HIGH ath11k无线驱动rx_h_undecap_nwifi无效数据访问漏洞
CVE-2026-97409 8.8 HIGH Linux NVMe-oF目标未初始化前取消请求漏洞
CVE-2026-93806 8.8 HIGH wifi: cfg80211 关联响应长度验证漏洞
CVE-2026-93793 8.8 HIGH iwlwifi 驱动 TX_CMD 响应布局验证漏洞
CVE-2026-93790 8.8 HIGH iwlwifi 驱动 BA 通知中 tid_data 越界访问漏洞
CVE-2026-93284 8.8 HIGH drm/pagemap 迁移错误前未解除 dma 映射
CVE-2026-93280 8.8 HIGH Greybus 音频拓扑边界检查漏洞
CVE-2026-97509 8.8 HIGH Thunderbolt 服务期间保持 XDomain 引用漏洞
CVE-2026-93827 8.4 HIGH virtio-fs 队列设置失败时双重释放漏洞
CVE-2026-97450 8.4 HIGH ACPICA 双重验证处理器对象类型漏洞
CVE-2026-97452 8.4 HIGH ACPICA:防止添加无效引用
CVE-2026-97451 8.4 HIGH ACPICA mid_op 整数溢出漏洞
CVE-2026-97455 8.4 HIGH ACPICA acpi_ds_terminate_control_method 使用后释放漏洞
CVE-2026-97433 8.2 HIGH NVMe 验证 FDP 配置描述符大小
CVE-2026-93787 8.1 HIGH CIFS cifs_filldir 中目录项名称越界访问漏洞
CVE-2026-93786 8.1 HIGH ksmbd 保持 VFS 继承 POSIX ACL 掩码漏洞

显示前 20 条,共 234 条。 查看全部 &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-97436

暂无评论


发表评论