在 Linux 内核中,已解决以下漏洞: s390/crypto:修复异步回调中向加密引擎返回错误代码的问题 当 或 显式完成请求时, 回调必须返回 0,以表示请求已成功处理。如果返回负值错误代码,加密引擎会误认为驱动程序未能取得请求的所有权,从而通过 触发第二次完成操作,导致双重完成(double completion)。该问题模式在 中出现 4 次,在 中出现 1 次。 修复方式:在 以及全部四个 的 回调(ecb、cbc、ctr、xts)中,在完成请求后返回 0,而非传递错误代码。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | 6cd87cb5ef6ca50ae17c371482ceaab1d635e232< 972e0d9b7d1d112240ccde1f1be85bf9ffaa1720 |
affected |
6cd87cb5ef6ca50ae17c371482ceaab1d635e232< 5480291aa848e19e61175abfd457933516db70c6 |
affected | ||
6cd87cb5ef6ca50ae17c371482ceaab1d635e232< ac1481320110b803ab9b79ab4d2ca11a74fc05f2 |
affected | ||
6.16 |
affected | ||
< 6.16 |
unaffected | ||
6.18.53≤ 6.18.* |
unaffected | ||
7.2.7≤ 7.2.* |
unaffected | ||
7.3-rc3≤ * |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-100075 | 9.8 CRITICAL | RDMA/srpt: Fix srpt_alloc_rw_ctxs() unwind counters |
| CVE-2026-97957 | 8.8 HIGH | net: hinic: fix mailbox segment buffer overflow |
| CVE-2026-97527 | 8.8 HIGH | scsi: qla2xxx: Serialize NVMe unsol ctx list with a per-fcport lock |
| CVE-2026-97528 | 8.8 HIGH | scsi: qla2xxx: Unlink NVMe unsol ctx before freeing on LS reject error |
| CVE-2026-97555 | 8.8 HIGH | smb: client: fix heap overflow in DACL owner/group rewrite |
| CVE-2026-98115 | 8.8 HIGH | ksmbd: safely drain sessions during logoff |
| CVE-2026-97525 | 8.2 HIGH | x86/mm/pat: Allocate split page tables as kernel page tables |
| CVE-2026-97573 | 8.1 HIGH | bnxt_en: Handle buffer allocation failure in bnxt_rx_ring_reset() |
| CVE-2026-98130 | 8.1 HIGH | sctp: fix a TOCTOU race in SCTP_CMD_TIMER_START |
| CVE-2026-98069 | 8.1 HIGH | net/rds: acquire the fastpath locks in rds_conn_shutdown() |
| CVE-2026-98070 | 8.1 HIGH | net/rds: acquire RDS_IN_XMIT in rds_tcp_reset_callbacks() |
| CVE-2026-97570 | 8.1 HIGH | bnxt_en: Bound SW TPA IDs to prevent crashes |
| CVE-2026-97911 | 7.8 HIGH | accel: ethosu: Ensure SRAM region size matches job |
| CVE-2026-98116 | 7.8 HIGH | ALSA: pcm: Serialize PCM mmap with buffer reallocation to fix page UAF |
| CVE-2026-97910 | 7.8 HIGH | ASoC: sprd: validate compress buffer sizes against fixed allocations |
| CVE-2026-98143 | 7.8 HIGH | accel: ethosu: Don't read the U65 rounding mode as a storage mode |
| CVE-2026-97903 | 7.8 HIGH | exit: hold a reference to thread_pid across proc_flush_pid |
| CVE-2026-97548 | 7.8 HIGH | xfs: fix the rtrmap and rtrefcount _maxlevels_ondisk functions |
| CVE-2026-97584 | 7.8 HIGH | afs: Fix incorrect free in candidate cleanup in afs_lookup_server() |
| CVE-2026-97602 | 7.8 HIGH | inet: frags: invalidate queues before flushing them |
Showing top 20 of 372 CVEs. View all on vendor page → →
No comments yet