在 Linux 内核中,已修复以下漏洞: xen/netfront:丢弃以太网头过短的 RX(接收)数据包 在处理入队数据时, 函数会先将 字节的数据拷贝到缓冲区头部,然后再调用 函数。其中, 的值等于第一个 RX 槽位(slot)的长度,并受 上限限制,该长度来自后端(backend)提供。然而,代码中并未将此长度与 (以太网头最小长度)进行比较验证。 如果第一个槽位短于 且后续还有更多槽位,则缓冲区头部长度将不足一个以太网头的长度,而 (套接字缓冲区总长度)却更长,从而导致 在调用 时触发 BUG(内核断言失败
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-98384 | bpf: Fix out-of-bounds read of sk_protocol in bpf_sock_destroy() | |
| CVE-2026-98383 | bpf: Disallow bpf_skb_pull_data() for LWT_SEG6LOCAL | |
| CVE-2026-98382 | bpf: Reject dev-bound-only programs on other devices | |
| CVE-2026-98381 | veth: manage XDP program pointers during channel resize | |
| CVE-2026-98380 | net/sched: reject IDR error pointers when deleting actions | |
| CVE-2026-98378 | bpf: Skip unsettled links in link iterator | |
| CVE-2026-98379 | netfilter: ip6t_rpfilter: reject routes without inet6_dev | |
| CVE-2026-98377 | vlan: require the MAC header to be present in __vlan_insert_inner_tag() | |
| CVE-2026-98376 | bpf: Use array_map_meta_equal for percpu array inner map replacement |
No comments yet