在 Linux 内核中,已解决以下漏洞: net/sched: 在删除动作(actions)时,拒绝无效的 IDR 错误指针 在调用 并传入保存的动作索引之前,会释放其查找引用所持有的引用计数。在此期间,一个未加锁的分类器(classifier)可能会移除该动作,并保留相同的 IDR 槽位,同时将其标记为 。 仅检查查找结果是否为 。因此,它将这种保留状态视为一个正常的 对象,并解引用 字段。我们使用硬件执行断点来调度这种并发交错场景,而无需修改内核源代码。KASAN(内核地址 sanitizer)报告了以下解码后
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-98384 | bpf: Fix out-of-bounds read of sk_protocol in bpf_sock_destroy() | |
| CVE-2026-98383 | bpf: Disallow bpf_skb_pull_data() for LWT_SEG6LOCAL | |
| CVE-2026-98382 | bpf: Reject dev-bound-only programs on other devices | |
| CVE-2026-98381 | veth: manage XDP program pointers during channel resize | |
| CVE-2026-98378 | bpf: Skip unsettled links in link iterator | |
| CVE-2026-98379 | netfilter: ip6t_rpfilter: reject routes without inet6_dev | |
| CVE-2026-98377 | vlan: require the MAC header to be present in __vlan_insert_inner_tag() | |
| CVE-2026-98376 | bpf: Use array_map_meta_equal for percpu array inner map replacement | |
| CVE-2026-98375 | xen/netfront: drop RX packets with a short Ethernet header |
No comments yet