在 Linux 内核中,以下漏洞已得到解决: bpf: 在链接迭代器中跳过未稳定的链接 在 成功之前,以及在 将 ID 发布到 之前,就将一个链接插入到了 中。 将此类 ID 为零的链接视为未稳定状态,但链接迭代器在未进行此检查的情况下获取了引用。 如果随后 失败,创建者会移除该 ID 并直接释放仍处于私有状态的链接。此时迭代器仍持有一个悬空引用,其随后的 调用将访问已释放的内存。 在 中,应将 ID 为零的条目视为瞬态条目,就像 所做的那样。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | 9f88361273082825d9f0d13a543d49f9fa0d44a8< 68930f8d40ab4c10ca3b019f076136758fd100a8 |
affected |
9f88361273082825d9f0d13a543d49f9fa0d44a8< c251ed48bd9063cf7de6049421e78b6de989060f |
affected | ||
9f88361273082825d9f0d13a543d49f9fa0d44a8< 798a61edbc436cacdb659927d067368eeb1e30e2 |
affected | ||
9f88361273082825d9f0d13a543d49f9fa0d44a8< 6e271f093d15d323f42de26f66556af53fa8e19f |
affected | ||
9f88361273082825d9f0d13a543d49f9fa0d44a8< 87ce4b53b7436b50fc984f0a6afaf77f68ac5573 |
affected | ||
9f88361273082825d9f0d13a543d49f9fa0d44a8< 50e80e2bb5e2be8515205b9c496b9640ddefa434 |
affected | ||
5.19 |
affected | ||
< 5.19 |
unaffected | ||
| … +6 more rows | |||
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-98384 | bpf: Fix out-of-bounds read of sk_protocol in bpf_sock_destroy() | |
| CVE-2026-98383 | bpf: Disallow bpf_skb_pull_data() for LWT_SEG6LOCAL | |
| CVE-2026-98382 | bpf: Reject dev-bound-only programs on other devices | |
| CVE-2026-98381 | veth: manage XDP program pointers during channel resize | |
| CVE-2026-98380 | net/sched: reject IDR error pointers when deleting actions | |
| CVE-2026-98379 | netfilter: ip6t_rpfilter: reject routes without inet6_dev | |
| CVE-2026-98377 | vlan: require the MAC header to be present in __vlan_insert_inner_tag() | |
| CVE-2026-98376 | bpf: Use array_map_meta_equal for percpu array inner map replacement | |
| CVE-2026-98375 | xen/netfront: drop RX packets with a short Ethernet header |
No comments yet