以下是该漏洞描述信息的中文翻译: 在 Linux 内核中,已解决以下漏洞: wifi: cfg80211: 不要释放由驱动程序拥有的扫描请求 当接口在扫描运行时关闭,cfg80211 会向用户空间完成扫描并释放扫描请求。然而,由于取消操作是(旨在)异步进行的,驱动程序可能仍然认为自己拥有该请求。 netdev 通知链中的 原本用于检测这种情况,但实际上这种情况无法避免,因此该警告会被触发,导致在 中发生使用-after-free(UAF)漏洞。 似乎没有完美的解决办法,因此只需跟踪驱动程序是否仍认为自己拥有该请求;
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | 4a58e7c38443154fce1b47910e1a9184f65c5d72< e8c75736cfd0c6c87562cda2312e3fe5e2227955 |
affected |
4a58e7c38443154fce1b47910e1a9184f65c5d72< cf6da29d17994865f73ca70976495ea856909c63 |
affected | ||
4a58e7c38443154fce1b47910e1a9184f65c5d72< dab68a74e90b8e07f08ed9deaa5884857a3cfe89 |
affected | ||
3.14 |
affected | ||
< 3.14 |
unaffected | ||
6.18.54≤ 6.18.* |
unaffected | ||
7.2.8≤ 7.2.* |
unaffected | ||
7.3-rc4≤ * |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-98323 | 9.8 CRITICAL | RDMA/siw: Bound fragmented header copies by the remaining length |
| CVE-2026-98365 | 9.8 CRITICAL | RDMA/rxe: Fix integer overflow in mr_check_range() leading to OOB access |
| CVE-2026-98282 | 8.8 HIGH | powerpc/iommu: Fix the overflow validation in iommu_tce_check_ioba |
| CVE-2026-98339 | 8.8 HIGH | wifi: cfg80211: don't filter by BSS type when removing stale entries |
| CVE-2026-98171 | 8.8 HIGH | smb: client: fix next_buffer UAF and NextCommand bounds in compound PDUs |
| CVE-2026-98283 | 8.8 HIGH | KVM: PPC: Book3S HV: fix use-after-free in kvmhv_emulate_tlbie_all_lpid() |
| CVE-2026-98261 | 8.1 HIGH | cifs: Fix server use-after-free in cifs_chan_skip_or_disable() |
| CVE-2026-98357 | 8.1 HIGH | IB/isert: wait for deferred control PDU completions before releasing the connection |
| CVE-2026-98239 | 8.1 HIGH | net: lan743x: fix RX checksum use-after-free |
| CVE-2026-98315 | 7.8 HIGH | ntfs: protect runlist updates with the runlist lock |
| CVE-2026-98281 | 7.8 HIGH | futex: Also allocate private hash on vfork() |
| CVE-2026-98324 | 7.8 HIGH | dmaengine: pxa: fix double counting of the hw descriptors |
| CVE-2026-98260 | 7.8 HIGH | exec: Cleanup POSIX timers right after de_thread() |
| CVE-2026-98258 | 7.8 HIGH | posix-cpu-timers: Prevent freeing a timer which is queued on the expiry list |
| CVE-2026-98320 | 7.8 HIGH | netfilter: flowtable: hold reference on ct until flow is released |
| CVE-2026-98228 | 7.8 HIGH | mips: select CONFIG_WEAK_REORDERING_BEYOND_LLSC from CONFIG_EYEQ |
| CVE-2026-98229 | 7.8 HIGH | xfrm: save input state data before secpath resets |
| CVE-2026-98318 | 7.8 HIGH | smb: client: validate absolute native symlink targets before NT fixups |
| CVE-2026-98251 | 7.8 HIGH | openvswitch: avoid reallocating confirmed conntrack labels |
| CVE-2026-98305 | 7.8 HIGH | net: dsa: mxl862xx: disable the stats poll on teardown |
Showing top 20 of 208 CVEs. View all on vendor page → →
No comments yet