在 Linux 内核中,以下漏洞已得到修复: ipv6: flowlabel: 限制每个套接字重复租约的数量 函数会对每次成功的 操作分配一个 条目。在兼容现有流标签的重检路径中,会链接另一个租约,而未进行任何租约准入检查。因此,对可共享标签重复发起 请求会导致套接字的租约列表无限增长。 一旦套接字已持有 数量的租约,则拒绝新的非特权租约。该检查应用于共享的重检路径,以确保全局内联标签的重用(包括 冲突路径)也得到覆盖。新标签的准入仍然遵循现有的 策略。 使用 而非 ,以与 保持一致。必须防止非特权用户通过创建具有
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2< 6d917992c22b6029fc2dc1bd464b7f6709357161 |
affected |
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2< 2f1a6dd5c80ceb902f50449efe899f29cd7918e3 |
affected | ||
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2< 467467bf4209f9f8add0c648bae763f92a0224c3 |
affected | ||
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2< 8d6cd188508513503805c156165de38e4e4a8615 |
affected | ||
2.6.12 |
affected | ||
< 2.6.12 |
unaffected | ||
6.12.112≤ 6.12.* |
unaffected | ||
6.18.53≤ 6.18.* |
unaffected | ||
| … +2 more rows | |||
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-100075 | 9.8 CRITICAL | RDMA/srpt: Fix srpt_alloc_rw_ctxs() unwind counters |
| CVE-2026-97957 | 8.8 HIGH | net: hinic: fix mailbox segment buffer overflow |
| CVE-2026-97527 | 8.8 HIGH | scsi: qla2xxx: Serialize NVMe unsol ctx list with a per-fcport lock |
| CVE-2026-97528 | 8.8 HIGH | scsi: qla2xxx: Unlink NVMe unsol ctx before freeing on LS reject error |
| CVE-2026-97555 | 8.8 HIGH | smb: client: fix heap overflow in DACL owner/group rewrite |
| CVE-2026-98115 | 8.8 HIGH | ksmbd: safely drain sessions during logoff |
| CVE-2026-97525 | 8.2 HIGH | x86/mm/pat: Allocate split page tables as kernel page tables |
| CVE-2026-97573 | 8.1 HIGH | bnxt_en: Handle buffer allocation failure in bnxt_rx_ring_reset() |
| CVE-2026-97570 | 8.1 HIGH | bnxt_en: Bound SW TPA IDs to prevent crashes |
| CVE-2026-98070 | 8.1 HIGH | net/rds: acquire RDS_IN_XMIT in rds_tcp_reset_callbacks() |
| CVE-2026-98069 | 8.1 HIGH | net/rds: acquire the fastpath locks in rds_conn_shutdown() |
| CVE-2026-98130 | 8.1 HIGH | sctp: fix a TOCTOU race in SCTP_CMD_TIMER_START |
| CVE-2026-98116 | 7.8 HIGH | ALSA: pcm: Serialize PCM mmap with buffer reallocation to fix page UAF |
| CVE-2026-97903 | 7.8 HIGH | exit: hold a reference to thread_pid across proc_flush_pid |
| CVE-2026-97548 | 7.8 HIGH | xfs: fix the rtrmap and rtrefcount _maxlevels_ondisk functions |
| CVE-2026-97611 | 7.8 HIGH | net: openvswitch: fix use-after-free of the flow table mask array |
| CVE-2026-97612 | 7.8 HIGH | net: mpls: clear inner_protocol when the last label is popped |
| CVE-2026-98073 | 7.8 HIGH | net: Remove conflicting altnames for dying netns in __dev_change_net_namespace(). |
| CVE-2026-97602 | 7.8 HIGH | inet: frags: invalidate queues before flushing them |
| CVE-2026-97577 | 7.8 HIGH | media: verisilicon: rockchip: reject AV1 frames exceeding the tile capacity |
Showing top 20 of 372 CVEs. View all on vendor page → →
No comments yet