在 Linux 内核中,以下漏洞已修复: vlan:要求在 中必须存在 MAC 头部 仅通过 保证有足够的头部预留空间(head room),但从未确保存在长度为 字节的完整 MAC 头部。因此,在其上方的 ETH_HLEN 封装函数——即在 下的 ,以及在通用发送路径 下的 ——会对 处的前 16 字节进行重写操作,具体包括一次 12 字节的 操作,以及在偏移 +12 和 +14 处的两次 2 字节写入。 目前没有任何调用者提供边界检查,而对应的弹出(pop)辅助函数则使用了 来确保数据可写。 对于 设备,其 ,
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-98384 | bpf: Fix out-of-bounds read of sk_protocol in bpf_sock_destroy() | |
| CVE-2026-98383 | bpf: Disallow bpf_skb_pull_data() for LWT_SEG6LOCAL | |
| CVE-2026-98382 | bpf: Reject dev-bound-only programs on other devices | |
| CVE-2026-98381 | veth: manage XDP program pointers during channel resize | |
| CVE-2026-98380 | net/sched: reject IDR error pointers when deleting actions | |
| CVE-2026-98378 | bpf: Skip unsettled links in link iterator | |
| CVE-2026-98379 | netfilter: ip6t_rpfilter: reject routes without inet6_dev | |
| CVE-2026-98376 | bpf: Use array_map_meta_equal for percpu array inner map replacement | |
| CVE-2026-98375 | xen/netfront: drop RX packets with a short Ethernet header |
No comments yet