在 Linux 内核中,以下漏洞已得到修复: BPF:禁止 LWT_SEG6LOCAL 程序调用 bpf_skb_pull_data() LWT_SEG6LOCAL 程序可以通过调用 bpf_lwt_seg6_adjust_srh() 使其缓存的 SRH(Seg6 Route Header)失效,随后再调用 bpf_skb_pull_data()。后者可能会重新分配 skb->head,导致每 CPU 变量的 SRH 指针变为悬空指针(dangling pointer)。在程序执行结束后进行 SRH 验证时,会通过
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-98384 | bpf: Fix out-of-bounds read of sk_protocol in bpf_sock_destroy() | |
| CVE-2026-98382 | bpf: Reject dev-bound-only programs on other devices | |
| CVE-2026-98381 | veth: manage XDP program pointers during channel resize | |
| CVE-2026-98380 | net/sched: reject IDR error pointers when deleting actions | |
| CVE-2026-98378 | bpf: Skip unsettled links in link iterator | |
| CVE-2026-98379 | netfilter: ip6t_rpfilter: reject routes without inet6_dev | |
| CVE-2026-98377 | vlan: require the MAC header to be present in __vlan_insert_inner_tag() | |
| CVE-2026-98376 | bpf: Use array_map_meta_equal for percpu array inner map replacement | |
| CVE-2026-98375 | xen/netfront: drop RX packets with a short Ethernet header |
No comments yet