在 Linux 内核中,已修复以下漏洞: dmaengine: pxa:修复硬件描述符的双重计数问题 函数已从以下形式: 转换为 。该函数会自动设置 计数器 ,但这一功能仅在编译器支持 时才生效(即从 GCC 15.1 或 Clang 22.1 开始)。然而,其下方的循环仍然会对 进行递增操作,导致该值在内部被双倍增加,而在其他使用场景中保持正确。 是 迭代时所依赖的变量,也是 进行索引的依据。因此,应显式设置 ,并移除循环中的递增操作。此外,在错误处理路径中,必须将 降低至当前已分配的描述符数量,否则 可能会释放
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | 69050f8d6d075dc01af7a5f2f550a8067510366f< 1de93785f32b450e9eae1e4fcfb7d03eb49eb27e |
affected |
69050f8d6d075dc01af7a5f2f550a8067510366f< f6504be006aa4bb4bd26285f410a885c17920d65 |
affected | ||
7.0 |
affected | ||
< 7.0 |
unaffected | ||
7.2.8≤ 7.2.* |
unaffected | ||
7.3-rc4≤ * |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-98323 | 9.8 CRITICAL | RDMA/siw: Bound fragmented header copies by the remaining length |
| CVE-2026-98365 | 9.8 CRITICAL | RDMA/rxe: Fix integer overflow in mr_check_range() leading to OOB access |
| CVE-2026-98282 | 8.8 HIGH | powerpc/iommu: Fix the overflow validation in iommu_tce_check_ioba |
| CVE-2026-98283 | 8.8 HIGH | KVM: PPC: Book3S HV: fix use-after-free in kvmhv_emulate_tlbie_all_lpid() |
| CVE-2026-98339 | 8.8 HIGH | wifi: cfg80211: don't filter by BSS type when removing stale entries |
| CVE-2026-98171 | 8.8 HIGH | smb: client: fix next_buffer UAF and NextCommand bounds in compound PDUs |
| CVE-2026-98261 | 8.1 HIGH | cifs: Fix server use-after-free in cifs_chan_skip_or_disable() |
| CVE-2026-98357 | 8.1 HIGH | IB/isert: wait for deferred control PDU completions before releasing the connection |
| CVE-2026-98239 | 8.1 HIGH | net: lan743x: fix RX checksum use-after-free |
| CVE-2026-98341 | 7.8 HIGH | wifi: cfg80211: don't free driver-owned scan requests |
| CVE-2026-98281 | 7.8 HIGH | futex: Also allocate private hash on vfork() |
| CVE-2026-98320 | 7.8 HIGH | netfilter: flowtable: hold reference on ct until flow is released |
| CVE-2026-98228 | 7.8 HIGH | mips: select CONFIG_WEAK_REORDERING_BEYOND_LLSC from CONFIG_EYEQ |
| CVE-2026-98229 | 7.8 HIGH | xfrm: save input state data before secpath resets |
| CVE-2026-98318 | 7.8 HIGH | smb: client: validate absolute native symlink targets before NT fixups |
| CVE-2026-98315 | 7.8 HIGH | ntfs: protect runlist updates with the runlist lock |
| CVE-2026-98260 | 7.8 HIGH | exec: Cleanup POSIX timers right after de_thread() |
| CVE-2026-98256 | 7.8 HIGH | signal: Prevent exec() race |
| CVE-2026-98258 | 7.8 HIGH | posix-cpu-timers: Prevent freeing a timer which is queued on the expiry list |
| CVE-2026-98254 | 7.8 HIGH | swiotlb: use the adjusted address for the highmem page lookup |
Showing top 20 of 208 CVEs. View all on vendor page → →
No comments yet