目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2026-97927— ufs 文件系统在加载柱面元数据前创建根目录项

一分钟漏洞结论

影响对象
Linux Linux
利用判断
尚无明确在野利用证据,仍需结合暴露面评估
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

在 Linux 内核中,已修复以下漏洞: ufs:在加载柱面元数据之后再创建根目录项(dentry) 在加载用于可写挂载的柱面组结构之前,就已安装了 : 当 失败时,错误处理路径会释放内核中的超级块信息,并将 设置为 NULL,但此时 仍被安装。随后, 会调用 。由于 存在, 会调用 和 操作。这两个操作都会解引用 ,而此时该指针已为 NULL。因此,仅因读取柱面组失败而导致的挂载错误,在清理阶段会导致 oops(内核崩溃)。一个精心构造的镜像,其第一个柱面组无法被读取,会触发此路径。 先加载柱面组元数据,最后再创

AI 预测 5.9 利用难度: 中等 EPSS 0.21% · P10

影响版本矩阵 18

厂商产品 版本范围状态
Linux Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2< e58db6c2dce6e453dca26c3a4953002425201880 affected
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2< 05360c6eb8388bb5adac3c439ffb1512de39550a affected
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2< 5cc48633fb76196b596a449ba1f4f642ad6125ce affected
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2< cd21f1ff74b1c15077fa3b98e80da3b41055aae4 affected
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2< a9804121d55aaa4319c1cac00b99794aa177dd6a affected
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2< 785e523b6c1931d802cab9f85912f3e6c7028af1 affected
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2< 8173e051a8acbb4ae6547be0436727944119e0b5 affected
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2< 55a4c98abb9694b067c6a031d11501f06b6b523c affected
… +10 条更多
获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2026-97927 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
ufs: create the root dentry after loading cylinder metadata
来源: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: ufs: create the root dentry after loading cylinder metadata ufs_fill_super() installed sb->s_root before it loaded the cylinder group structures for a writable mount: sb->s_root = d_make_root(inode); ... if (!sb_rdonly(sb)) if (!ufs_read_cylinder_structures(sb)) goto failed; When ufs_read_cylinder_structures() failed, the error path freed the in-core superblock information and set sb->s_fs_info to NULL while sb->s_root stayed installed. get_tree_bdev() then reached deactivate_locked_super(), and because s_root was present, generic_shutdown_super() called sync_filesystem() and the put_super operation. Both dereference UFS_SB(sb), which is now NULL, so a mount that fails only while reading the cylinder groups oopses during teardown. A crafted image whose first cylinder group cannot be read reaches this path. Load the cylinder group metadata first and create the root dentry last, so the superblock is published to the VFS only once it is fully set up. ufs_setup_cstotal() and ufs_read_cylinder_structures() take only the super_block and do not use the root inode, so the reordering is safe.
来源: CVE Program / CVE List V5
CVSS Information
N/A
来源: CVE Program / CVE List V5
Vulnerability Type
N/A
来源: CVE Program / CVE List V5

受影响产品

厂商 产品 影响版本 CPE 订阅
Linux Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 ~ e58db6c2dce6e453dca26c3a4953002425201880 -
Linux Linux 2.6.12 -

二、漏洞 CVE-2026-97927 的公开POC

# POC 描述 源链接 神龙链接
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2026-97927 的情报信息

请登录查看更多情报信息。

CVE-2026-97927 补丁与修复 (8)

同批安全公告 · Linux · 2026-09-25 · 共 372 条

CVE-2026-100075 9.8 CRITICAL RDMA/srpt:srpt_alloc_rw_ctxs() 未释放计数器修复
CVE-2026-97555 8.8 HIGH smb客户端:修复DACL所有者/组重写中的堆溢出漏洞
CVE-2026-97957 8.8 HIGH hinic 邮箱段缓冲区溢出漏洞
CVE-2026-97527 8.8 HIGH qla2xxx SCSI驱动程序 NVMe未解决上下文列表竞争条件漏洞
CVE-2026-97528 8.8 HIGH QLogic qla2xxx驱动LS拒绝错误NVMe内存泄漏漏洞
CVE-2026-98115 8.8 HIGH ksmbd 注销期间会话安全排空漏洞
CVE-2026-97525 8.2 HIGH x86/mm/pat:内核页表分裂页表分配漏洞
CVE-2026-98069 8.1 HIGH Net/RDS rds_conn_shutdown() 快速路径锁获取漏洞
CVE-2026-97573 8.1 HIGH bnxt_en 驱动 bnxt_rx_ring_reset 缓冲区分配失败漏洞
CVE-2026-97570 8.1 HIGH bnxt_en: 修复因SW TPA ID绑定问题导致的崩溃漏洞
CVE-2026-98130 8.1 HIGH SCTP定时器启动竞争条件漏洞
CVE-2026-98070 8.1 HIGH Linux RDS 模块远程代码执行漏洞
CVE-2026-98122 7.8 HIGH Linux内核vxlan mdb远程源删除后使用漏洞
CVE-2026-97575 7.8 HIGH v4l2-ctrls AV1瓦片计数验证漏洞
CVE-2026-97576 7.8 HIGH V4L2-ctrls HEVC 瓦片计数验证漏洞
CVE-2026-98112 7.8 HIGH ksmbd 网络接口事件中监听器任务生命周期修复漏洞
CVE-2026-98002 7.8 HIGH AMD IOMMU 嵌套域分配中错误检查失效漏洞
CVE-2026-98116 7.8 HIGH ALSA: PCM内存映射与缓冲区重新分配序列化以修复页面UAF漏洞
CVE-2026-97580 7.8 HIGH rkvdec HEVC解析数组越界漏洞
CVE-2026-97940 7.8 HIGH IPv6 修复 fib6 遍历器在 seq 停止时存在 UAF 漏洞

显示前 20 条,共 372 条。 查看全部 &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-97927

暂无评论


发表评论