在 Linux 内核中,已修复以下漏洞: bpf:在其他设备上拒绝仅绑定到特定设备(dev-bound-only)的 BPF 程序 在精确的网络设备(netdev)不匹配后,会回退到比较 offload 设备(offdev)指针。仅绑定程序(bound-only programs)通常具有 NULL 的 offdev 指针,因此不相关的网络设备会被错误地视为相等。如果某个仅绑定程序绑定到一个已注册 offload 的网络设备,它可能会继承一个真实的 offload 设备(offdev),从而错误地匹配到同源端口(s
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-98384 | bpf: Fix out-of-bounds read of sk_protocol in bpf_sock_destroy() | |
| CVE-2026-98383 | bpf: Disallow bpf_skb_pull_data() for LWT_SEG6LOCAL | |
| CVE-2026-98381 | veth: manage XDP program pointers during channel resize | |
| CVE-2026-98380 | net/sched: reject IDR error pointers when deleting actions | |
| CVE-2026-98378 | bpf: Skip unsettled links in link iterator | |
| CVE-2026-98379 | netfilter: ip6t_rpfilter: reject routes without inet6_dev | |
| CVE-2026-98377 | vlan: require the MAC header to be present in __vlan_insert_inner_tag() | |
| CVE-2026-98376 | bpf: Use array_map_meta_equal for percpu array inner map replacement | |
| CVE-2026-98375 | xen/netfront: drop RX packets with a short Ethernet header |
No comments yet