目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1336 CNY

100%

CVE-2026-23230— Linux kernel 安全漏洞

CVSS 8.8 · High EPSS 0.22% · P12

Possible ATT&CK Techniques 1AI

T1059 · Command and Scripting Interpreter

Affected Version Matrix 14

ベンダープロダクトVersion Rangeステータス
LinuxLinuxebe98f1447bbccf8228335c62d86af02a0ed23f7< 569fecc56bfe4df66f05734d67daef887746656baffected
ebe98f1447bbccf8228335c62d86af02a0ed23f7< 4386f6af8aaedd0c5ad6f659b40cadcc8f423828affected
ebe98f1447bbccf8228335c62d86af02a0ed23f7< 3eaa22d688311c708b73f3c68bc6d0c8e3f0f77aaffected
ebe98f1447bbccf8228335c62d86af02a0ed23f7< c4b9edd55987384a1f201d3d07ff71e448d79c1baffected
ebe98f1447bbccf8228335c62d86af02a0ed23f7< 4cfa4c37dcbcfd70866e856200ed8a2894cac578affected
ebe98f1447bbccf8228335c62d86af02a0ed23f7< ec306600d5ba7148c9dbf8f5a8f1f5c1a044a241affected
6.1affected
< 6.1unaffected
… +6 more rows
新しい脆弱性情報の通知を購読するログインして購読

I. CVE-2026-23230の基本情報

脆弱性情報

脆弱性についてご質問がありますか?Shenlongの分析が参考になるかご確認ください!
Shenlongの10の質問を表示 ↗

高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。

脆弱性タイトル
smb: client: split cached_fid bitfields to avoid shared-byte RMW races
ソース: NVD (National Vulnerability Database)
脆弱性説明
In the Linux kernel, the following vulnerability has been resolved: smb: client: split cached_fid bitfields to avoid shared-byte RMW races is_open, has_lease and on_list are stored in the same bitfield byte in struct cached_fid but are updated in different code paths that may run concurrently. Bitfield assignments generate byte read–modify–write operations (e.g. `orb $mask, addr` on x86_64), so updating one flag can restore stale values of the others. A possible interleaving is: CPU1: load old byte (has_lease=1, on_list=1) CPU2: clear both flags (store 0) CPU1: RMW store (old | IS_OPEN) -> reintroduces cleared bits To avoid this class of races, convert these flags to separate bool fields.
ソース: NVD (National Vulnerability Database)
CVSS情報
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
ソース: NVD (National Vulnerability Database)
脆弱性タイプ
N/A
ソース: NVD (National Vulnerability Database)
脆弱性タイトル
Linux kernel 安全漏洞
ソース: CNNVD (China National Vulnerability Database)
脆弱性説明
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于位字段共享字节,可能导致读-修改-写竞争。
ソース: CNNVD (China National Vulnerability Database)
CVSS情報
N/A
ソース: CNNVD (China National Vulnerability Database)
脆弱性タイプ
N/A
ソース: CNNVD (China National Vulnerability Database)

影響を受ける製品

ベンダープロダクト影響を受けるバージョンCPE購読
LinuxLinux ebe98f1447bbccf8228335c62d86af02a0ed23f7 ~ 569fecc56bfe4df66f05734d67daef887746656b -
LinuxLinux 6.1 -

II. CVE-2026-23230の公開POC

#POC説明ソースリンクShenlongリンク
AI生成POCプレミアム

公開POCは見つかりませんでした。

ログインしてAI POCを生成

III. CVE-2026-23230のインテリジェンス情報

登录查看更多情报信息。

Same Patch Batch · Linux · 2026-02-18 · 31 CVEs total

CVE-2026-232268.8 HIGHksmbd: add chann_lock to protect ksmbd_chann_list xarray
CVE-2026-232277.8 HIGHdrm/exynos: vidi: use ctx->lock to protect struct vidi_context member variables related to
CVE-2026-232257.8 HIGHsched/mmcid: Don't assume CID is CPU owned on mode switch
CVE-2026-232247.8 HIGHerofs: fix UAF issue for file-backed mounts w/ directio option
CVE-2026-232227.8 HIGHcrypto: omap - Allocate OMAP_CRYPTO_FORCE_COPY scatterlists correctly
CVE-2025-71233PCI: endpoint: Avoid creating sub-groups asynchronously
CVE-2026-23229crypto: virtio - Add spinlock protection with virtqueue notification
CVE-2026-23228smb: server: fix leak of active_num_conn in ksmbd_tcp_new_connection()
CVE-2026-23223xfs: fix UAF in xchk_btree_check_block_owner
CVE-2026-23221bus: fsl-mc: fix use-after-free in driver_override_show()
CVE-2026-23220ksmbd: fix infinite loop caused by next_smb2_rcv_hdr_off reset in error paths
CVE-2025-71237nilfs2: Fix potential block overflow that cause system hang
CVE-2025-71236scsi: qla2xxx: Validate sp before freeing associated memory
CVE-2025-71235scsi: qla2xxx: Delay module unload while fabric scan in progress
CVE-2025-71234wifi: rtl8xxxu: fix slab-out-of-bounds in rtl8xxxu_sta_add
CVE-2026-23211mm, swap: restore swap_space attr aviod kernel panic
CVE-2025-71232scsi: qla2xxx: Free sp in error path to fix system crash
CVE-2025-71231crypto: iaa - Fix out-of-bounds index in find_empty_iaa_compression_mode
CVE-2025-71230hfs: ensure sb->s_fs_info is always cleaned up
CVE-2025-71229wifi: rtw88: Fix alignment fault in rtw_core_enable_beacon()

Showing 20 of 31 CVEs. View all on vendor page →

IV. 関連脆弱性

V. CVE-2026-23230へのコメント

まだコメントはありません


コメントを残す