目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2026-97952— sunvdc 描述符发送失败未映射LDC cookies漏洞

一分钟漏洞结论

影响对象
Linux Linux
利用判断
尚无明确在野利用证据,仍需结合暴露面评估
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

在 Linux 内核中,已修复以下漏洞: sunvdc:在描述符发送失败时取消映射 LDC cookies 函数会将请求的页面映射到 LDC(逻辑域通道)通道的映射表(通过 ),填充描述符,并在通过 触发门铃之前将其标记为 。当触发失败时,错误处理路径仅打印一条消息,而描述符仍保持 状态,且 cookies 永远不会被取消映射。 通常情况下,当对端完成描述符时,映射会在 中释放——但从未发送门铃的描述符永远不会被完成;此外,由于失败时未推进 ,重置路径( ,遍历区间 )也不会访问该描述符。因此,映射表条目会永久泄漏

AI 预测 5.5 利用难度: 中等 EPSS 0.18% · P7

影响版本矩阵 28

厂商产品 版本范围状态
Linux Linux a11f6ca9aef989b56cd31ff4ee2af4fb31a172ec< eb9c5f6747fe98b83c78cb5476a914e91d50e8e8 affected
a11f6ca9aef989b56cd31ff4ee2af4fb31a172ec< 24564576be423f3b5d7e67cd7df848ac66646497 affected
a11f6ca9aef989b56cd31ff4ee2af4fb31a172ec< 9251573e7cf7d797ae4a30b2a236af8242237a61 affected
a11f6ca9aef989b56cd31ff4ee2af4fb31a172ec< b0de6463667e9bb9dc14a83a9c24c1b6b3f7b5f7 affected
a11f6ca9aef989b56cd31ff4ee2af4fb31a172ec< ab81a5c1014a38dab0fb402609fd866b0bcb4726 affected
a11f6ca9aef989b56cd31ff4ee2af4fb31a172ec< 57835952566f0be9b365a6eb3a70b397a9d5ef47 affected
a11f6ca9aef989b56cd31ff4ee2af4fb31a172ec< f3322baa3a8ac87730feae952c1146269d78e098 affected
a11f6ca9aef989b56cd31ff4ee2af4fb31a172ec< 0c6da21fa35e03fc74f09895433ccd6d4a9c3530 affected
… +20 条更多
获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2026-97952 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
sunvdc: unmap LDC cookies when the descriptor send fails
来源: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: sunvdc: unmap LDC cookies when the descriptor send fails __send_request() maps the request's pages into the LDC channel's map table (ldc_map_sg()), fills in the descriptor and marks it VIO_DESC_READY before ringing the doorbell via __vdc_tx_trigger(). When the trigger fails, the error path only prints a message: the descriptor stays READY and the cookies are never unmapped. The mapping is normally released in vdc_end_one() when the peer completes the descriptor - but a descriptor whose doorbell was never sent will never complete, and since dr->prod is not advanced on failure, the reset path (vdc_requeue_inflight(), which walks [cons, prod)) never visits it either. The map table entries are leaked permanently. Since commit a11f6ca9aef9 ("sunvdc: Do not spin in an infinite loop when vio_ldc_send() returns EAGAIN") trigger failures occur in practice under load, so every resulting I/O error also leaks one request's worth of entries from the fixed-size (8192 entries per channel) map table. Because the allocator hands out contiguous ranges, fragmentation makes large multi-segment requests fail first as the table drains, until ldc_map_sg() fails permanently and the disk is dead until reboot. It also makes any retry-based recovery unusable: requeuing the request on -EAGAIN remaps the pages on every attempt, overwriting desc->cookies and orphaning the previous mapping, so the table drains at the retry rate. This is the memory exhaustion observed when the requeue approach was first tested in October 2025. Roll back on failure: unmap the cookies, mark the descriptor FREE again and clear the request entry. If the trigger failed with -ENOTCONN, __vdc_tx_trigger() has already reset the port, which tears down and reallocates both the dring and the LDC channel including its map table - nothing to roll back, and the stale descriptor must not be touched.
来源: CVE Program / CVE List V5
CVSS Information
N/A
来源: CVE Program / CVE List V5
Vulnerability Type
N/A
来源: CVE Program / CVE List V5

受影响产品

厂商 产品 影响版本 CPE 订阅
Linux Linux a11f6ca9aef989b56cd31ff4ee2af4fb31a172ec ~ eb9c5f6747fe98b83c78cb5476a914e91d50e8e8 -
Linux Linux 5.0 -

二、漏洞 CVE-2026-97952 的公开POC

# POC 描述 源链接 神龙链接
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2026-97952 的情报信息

请登录查看更多情报信息。

CVE-2026-97952 补丁与修复 (8)

同批安全公告 · Linux · 2026-09-25 · 共 372 条

CVE-2026-100075 9.8 CRITICAL RDMA/srpt:srpt_alloc_rw_ctxs() 未释放计数器修复
CVE-2026-97555 8.8 HIGH smb客户端:修复DACL所有者/组重写中的堆溢出漏洞
CVE-2026-97957 8.8 HIGH hinic 邮箱段缓冲区溢出漏洞
CVE-2026-97527 8.8 HIGH qla2xxx SCSI驱动程序 NVMe未解决上下文列表竞争条件漏洞
CVE-2026-97528 8.8 HIGH QLogic qla2xxx驱动LS拒绝错误NVMe内存泄漏漏洞
CVE-2026-98115 8.8 HIGH ksmbd 注销期间会话安全排空漏洞
CVE-2026-97525 8.2 HIGH x86/mm/pat:内核页表分裂页表分配漏洞
CVE-2026-98069 8.1 HIGH Net/RDS rds_conn_shutdown() 快速路径锁获取漏洞
CVE-2026-97573 8.1 HIGH bnxt_en 驱动 bnxt_rx_ring_reset 缓冲区分配失败漏洞
CVE-2026-97570 8.1 HIGH bnxt_en: 修复因SW TPA ID绑定问题导致的崩溃漏洞
CVE-2026-98130 8.1 HIGH SCTP定时器启动竞争条件漏洞
CVE-2026-98070 8.1 HIGH Linux RDS 模块远程代码执行漏洞
CVE-2026-97941 7.8 HIGH Linux 内核 slab 内存分配器竞态条件漏洞
CVE-2026-97575 7.8 HIGH v4l2-ctrls AV1瓦片计数验证漏洞
CVE-2026-97576 7.8 HIGH V4L2-ctrls HEVC 瓦片计数验证漏洞
CVE-2026-98112 7.8 HIGH ksmbd 网络接口事件中监听器任务生命周期修复漏洞
CVE-2026-98002 7.8 HIGH AMD IOMMU 嵌套域分配中错误检查失效漏洞
CVE-2026-97937 7.8 HIGH Linux内核ftrace远程代码执行漏洞
CVE-2026-97580 7.8 HIGH rkvdec HEVC解析数组越界漏洞
CVE-2026-97940 7.8 HIGH IPv6 修复 fib6 遍历器在 seq 停止时存在 UAF 漏洞

显示前 20 条,共 372 条。 查看全部 &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-97952

暂无评论


发表评论