在 Linux 内核中,已修复以下漏洞: ksmbd:修复网络接口事件监听器任务的生命周期问题 当监听套接字被关闭时,监听线程会退出。然而,网络设备通知机制(netdevice notifier)在调用 之前会先关闭该套接字,导致 可能在 获取其引用之前就被释放。 为解决此问题,创建监听器时应将其设置为已停止状态,并额外持有对 的引用,直到 执行完毕。此外,在 TCP 断开连接并释放接口记录之前,应先停止并释放监听器。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | 3316a8fc840d82fad5efcf76ad0ea3f76fdca209< 40581f10c1e56238b157af5f260b8f9518a0cbc1 |
affected |
3316a8fc840d82fad5efcf76ad0ea3f76fdca209< a506290f59e1c6ce9ac0a13158640bb8fee93471 |
affected | ||
6.19 |
affected | ||
< 6.19 |
unaffected | ||
7.2.7≤ 7.2.* |
unaffected | ||
7.3-rc2≤ * |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-100075 | 9.8 CRITICAL | RDMA/srpt: Fix srpt_alloc_rw_ctxs() unwind counters |
| CVE-2026-98115 | 8.8 HIGH | ksmbd: safely drain sessions during logoff |
| CVE-2026-97555 | 8.8 HIGH | smb: client: fix heap overflow in DACL owner/group rewrite |
| CVE-2026-97527 | 8.8 HIGH | scsi: qla2xxx: Serialize NVMe unsol ctx list with a per-fcport lock |
| CVE-2026-97528 | 8.8 HIGH | scsi: qla2xxx: Unlink NVMe unsol ctx before freeing on LS reject error |
| CVE-2026-97957 | 8.8 HIGH | net: hinic: fix mailbox segment buffer overflow |
| CVE-2026-97525 | 8.2 HIGH | x86/mm/pat: Allocate split page tables as kernel page tables |
| CVE-2026-98130 | 8.1 HIGH | sctp: fix a TOCTOU race in SCTP_CMD_TIMER_START |
| CVE-2026-98070 | 8.1 HIGH | net/rds: acquire RDS_IN_XMIT in rds_tcp_reset_callbacks() |
| CVE-2026-98069 | 8.1 HIGH | net/rds: acquire the fastpath locks in rds_conn_shutdown() |
| CVE-2026-97570 | 8.1 HIGH | bnxt_en: Bound SW TPA IDs to prevent crashes |
| CVE-2026-97573 | 8.1 HIGH | bnxt_en: Handle buffer allocation failure in bnxt_rx_ring_reset() |
| CVE-2026-97941 | 7.8 HIGH | mm/slab: take n->list_lock in __slab_try_return_freelist() to avoid race |
| CVE-2026-97991 | 7.8 HIGH | vdpa_sim_blk: reject out-of-range sector starts |
| CVE-2026-98122 | 7.8 HIGH | vxlan: mdb: Fix use-after-free in vxlan_mdb_remote_src_del() |
| CVE-2026-97612 | 7.8 HIGH | net: mpls: clear inner_protocol when the last label is popped |
| CVE-2026-97594 | 7.8 HIGH | landlock: Fix use-after-free of the source's parent directory |
| CVE-2026-97611 | 7.8 HIGH | net: openvswitch: fix use-after-free of the flow table mask array |
| CVE-2026-98002 | 7.8 HIGH | iommu/amd: Fix ineffective error check in nested domain allocation |
| CVE-2026-98073 | 7.8 HIGH | net: Remove conflicting altnames for dying netns in __dev_change_net_namespace(). |
Showing top 20 of 372 CVEs. View all on vendor page → →
No comments yet