在 Linux 内核中,已修复以下漏洞: tcp: 修复 tcp_send_synack() 中对 retransmit_skb_hint 的释放后使用(use-after-free)问题 当 用其副本替换重传队列头部克隆的 SYN 报文(skb)时,它会通过 释放原始 skb,但仅修复了 。此时, 仍然指向已释放的 对象。 该悬空指针(dangling hint)会在 中被读取,并作为 中红黑树遍历的起点。非特权的 TCP 快速打开(TFO)客户端(通过 )可以利用攻击者提供的 ICMP “需要分片”(fragm
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | c31b70c9968fe9c4194d1b5d06d07596a3b680de< fad6d429651e748365e93ca54645accc212f0018 |
affected |
c31b70c9968fe9c4194d1b5d06d07596a3b680de< c5b4da1f403a658c1c19766be2b426003ada419f |
affected | ||
c31b70c9968fe9c4194d1b5d06d07596a3b680de< 71d45049b0d631dfdbf3c65305f7fca676de023b |
affected | ||
c31b70c9968fe9c4194d1b5d06d07596a3b680de< e3ea71cb1408a013ed4e8a757b815f1a919324bd |
affected | ||
c31b70c9968fe9c4194d1b5d06d07596a3b680de< 631aa4cb45099f09e9385dd786bd291c6270bfc4 |
affected | ||
c31b70c9968fe9c4194d1b5d06d07596a3b680de< 0f87720c7e4bcab07c24888b3cf12bfe857bb90e |
affected | ||
c31b70c9968fe9c4194d1b5d06d07596a3b680de< fe99bbeee5c5dbd3abc30721a8079ced59649d97 |
affected | ||
5.11 |
affected | ||
| … +8 more rows | |||
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet