在 Linux 内核中,已修复以下漏洞: landlock:修复源目录父级的 Use-After-Free(释放后使用)问题 在未持有引用(reference)也未加锁的情况下读取 ,随后在 和审计记录中解引用该指针。 子项(dentry)的引用并不会固定(pin)其父项: 会重新分配 ,并释放子项对其原父项持有的引用。 不受此影响,因为 rename 路径在调用钩子之前会调用 ,因此源项在该钩子执行期间不会被重新绑定(reparented)。然而, 缺乏此类保护: 虽然对源 dentry 持有引用,但既未对其父项
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | b91c3e4ea756b12b7d992529226edce1cfd854d7< 379efd2ce8b26fd35feb13ccc2f671ff105a5052 |
affected |
b91c3e4ea756b12b7d992529226edce1cfd854d7< ba29c46ccfe3ebadfb8aa18149186c49f84b14f8 |
affected | ||
b91c3e4ea756b12b7d992529226edce1cfd854d7< 2c6dc792538260a8087ac5b22c31b3b8e47c85d6 |
affected | ||
5.19 |
affected | ||
< 5.19 |
unaffected | ||
6.18.53≤ 6.18.* |
unaffected | ||
7.2.7≤ 7.2.* |
unaffected | ||
7.3-rc3≤ * |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-100075 | 9.8 CRITICAL | RDMA/srpt: Fix srpt_alloc_rw_ctxs() unwind counters |
| CVE-2026-97957 | 8.8 HIGH | net: hinic: fix mailbox segment buffer overflow |
| CVE-2026-97527 | 8.8 HIGH | scsi: qla2xxx: Serialize NVMe unsol ctx list with a per-fcport lock |
| CVE-2026-97528 | 8.8 HIGH | scsi: qla2xxx: Unlink NVMe unsol ctx before freeing on LS reject error |
| CVE-2026-97555 | 8.8 HIGH | smb: client: fix heap overflow in DACL owner/group rewrite |
| CVE-2026-98115 | 8.8 HIGH | ksmbd: safely drain sessions during logoff |
| CVE-2026-97525 | 8.2 HIGH | x86/mm/pat: Allocate split page tables as kernel page tables |
| CVE-2026-98130 | 8.1 HIGH | sctp: fix a TOCTOU race in SCTP_CMD_TIMER_START |
| CVE-2026-97573 | 8.1 HIGH | bnxt_en: Handle buffer allocation failure in bnxt_rx_ring_reset() |
| CVE-2026-98069 | 8.1 HIGH | net/rds: acquire the fastpath locks in rds_conn_shutdown() |
| CVE-2026-98070 | 8.1 HIGH | net/rds: acquire RDS_IN_XMIT in rds_tcp_reset_callbacks() |
| CVE-2026-97570 | 8.1 HIGH | bnxt_en: Bound SW TPA IDs to prevent crashes |
| CVE-2026-97911 | 7.8 HIGH | accel: ethosu: Ensure SRAM region size matches job |
| CVE-2026-98023 | 7.8 HIGH | vxlan: reject dynamic fdb entries that reference a nexthop id |
| CVE-2026-97910 | 7.8 HIGH | ASoC: sprd: validate compress buffer sizes against fixed allocations |
| CVE-2026-98143 | 7.8 HIGH | accel: ethosu: Don't read the U65 rounding mode as a storage mode |
| CVE-2026-97903 | 7.8 HIGH | exit: hold a reference to thread_pid across proc_flush_pid |
| CVE-2026-97548 | 7.8 HIGH | xfs: fix the rtrmap and rtrefcount _maxlevels_ondisk functions |
| CVE-2026-98073 | 7.8 HIGH | net: Remove conflicting altnames for dying netns in __dev_change_net_namespace(). |
| CVE-2026-97612 | 7.8 HIGH | net: mpls: clear inner_protocol when the last label is popped |
Showing top 20 of 372 CVEs. View all on vendor page → →
No comments yet