在 Linux 内核中,已修复以下漏洞: RDMA/rxe:仅在 成功后才将多播组(mcg)插入 在通过 配置底层以太网多播地址之前,就将新分配的多播组发布到了 中,而 的执行过程不在 保护之下。当本地用户态 RDMA 客户端在 UD 类型队列对(QP)上调用 并命中此代码路径时,如果 随后返回错误(例如,当底层网络设备已被移除时返回 ,或传播自 的错误),清理逻辑会释放该已发布的组,但并未将其从树中移除。随后,对同一 MGID(多组标识符)的查找会通过 解引用已释放的 结构体,导致使用后释放(use-after-
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | a926a903b7dc39a8a949150258c09290998dd812< ddb43ac0926d4a931bc9b7744b93627f627457e5 |
affected |
a926a903b7dc39a8a949150258c09290998dd812< c79a789aa15180a1543b5db49c343d12e3ec214d |
affected | ||
a926a903b7dc39a8a949150258c09290998dd812< faae1fb4ccf8205806a8802c008798dabeb0205b |
affected | ||
a926a903b7dc39a8a949150258c09290998dd812< 02c0a2fa69c16248a7432af8a6d64ab2a73a5283 |
affected | ||
a926a903b7dc39a8a949150258c09290998dd812< d4fc4e37f8a143b0fe83b42c8fb48cf542154fee |
affected | ||
a926a903b7dc39a8a949150258c09290998dd812< 1caceeb2d74bbe88223aea55eb8626b4c5f076fd |
affected | ||
5.18 |
affected | ||
< 5.18 |
unaffected | ||
| … +6 more rows | |||
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-98323 | 9.8 CRITICAL | RDMA/siw: Bound fragmented header copies by the remaining length |
| CVE-2026-98365 | 9.8 CRITICAL | RDMA/rxe: Fix integer overflow in mr_check_range() leading to OOB access |
| CVE-2026-98282 | 8.8 HIGH | powerpc/iommu: Fix the overflow validation in iommu_tce_check_ioba |
| CVE-2026-98283 | 8.8 HIGH | KVM: PPC: Book3S HV: fix use-after-free in kvmhv_emulate_tlbie_all_lpid() |
| CVE-2026-98339 | 8.8 HIGH | wifi: cfg80211: don't filter by BSS type when removing stale entries |
| CVE-2026-98171 | 8.8 HIGH | smb: client: fix next_buffer UAF and NextCommand bounds in compound PDUs |
| CVE-2026-98261 | 8.1 HIGH | cifs: Fix server use-after-free in cifs_chan_skip_or_disable() |
| CVE-2026-98357 | 8.1 HIGH | IB/isert: wait for deferred control PDU completions before releasing the connection |
| CVE-2026-98239 | 8.1 HIGH | net: lan743x: fix RX checksum use-after-free |
| CVE-2026-98341 | 7.8 HIGH | wifi: cfg80211: don't free driver-owned scan requests |
| CVE-2026-98281 | 7.8 HIGH | futex: Also allocate private hash on vfork() |
| CVE-2026-98324 | 7.8 HIGH | dmaengine: pxa: fix double counting of the hw descriptors |
| CVE-2026-98320 | 7.8 HIGH | netfilter: flowtable: hold reference on ct until flow is released |
| CVE-2026-98228 | 7.8 HIGH | mips: select CONFIG_WEAK_REORDERING_BEYOND_LLSC from CONFIG_EYEQ |
| CVE-2026-98229 | 7.8 HIGH | xfrm: save input state data before secpath resets |
| CVE-2026-98318 | 7.8 HIGH | smb: client: validate absolute native symlink targets before NT fixups |
| CVE-2026-98315 | 7.8 HIGH | ntfs: protect runlist updates with the runlist lock |
| CVE-2026-98260 | 7.8 HIGH | exec: Cleanup POSIX timers right after de_thread() |
| CVE-2026-98256 | 7.8 HIGH | signal: Prevent exec() race |
| CVE-2026-98258 | 7.8 HIGH | posix-cpu-timers: Prevent freeing a timer which is queued on the expiry list |
Showing top 20 of 208 CVEs. View all on vendor page → →
No comments yet