在 Linux 内核中,以下漏洞已被修复: bpf:在使用 percpu 数组内部地图替换时,使用 指向的是通用的 函数,该函数未比较 字段。当 percpu 数组作为内部地图(inner map)使用时,若用具有更小 值的地图进行替换,可绕过该检查。由于 会将原始模板的 内联为 JIT 立即数,对替换后的地图进行查找操作可能导致越界访问 数组。 将 指向 ,后者已强制执行 相等性检查。 新增一项自测(selftest)用例,验证当尝试将 percpu 数组内部地图替换为不同大小的地图时,系统会正确拒绝该操作。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-98384 | bpf: Fix out-of-bounds read of sk_protocol in bpf_sock_destroy() | |
| CVE-2026-98383 | bpf: Disallow bpf_skb_pull_data() for LWT_SEG6LOCAL | |
| CVE-2026-98382 | bpf: Reject dev-bound-only programs on other devices | |
| CVE-2026-98381 | veth: manage XDP program pointers during channel resize | |
| CVE-2026-98380 | net/sched: reject IDR error pointers when deleting actions | |
| CVE-2026-98378 | bpf: Skip unsettled links in link iterator | |
| CVE-2026-98379 | netfilter: ip6t_rpfilter: reject routes without inet6_dev | |
| CVE-2026-98377 | vlan: require the MAC header to be present in __vlan_insert_inner_tag() | |
| CVE-2026-98375 | xen/netfront: drop RX packets with a short Ethernet header |
No comments yet