目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1336 CNY

100%

CVE-2026-53398— Linux kernel 安全漏洞

CVSS 9.8 · Critical EPSS 0.51% · P41

Possible ATT&CK Techniques 1AI

T1190 · Exploit Public-Facing Application

Affected Version Matrix 20

ベンダープロダクトVersion Rangeステータス
LinuxLinux5e76b25d7cc82c148d391c0c43b884e6427cb302< 8836405abdc53ca3dd5fc68b2cf6f8f012fad011affected
07b68ff5c71cf4ed5443016d8eb116863c0a4d88< 49de5d31dd8fdebf78bdeaf196b0ca5cd5c75439affected
3fdc546462348b8a497c72bc894e0cde9f10fc40< 5ec37edcb534f3fc92304be236d37f08e6545585affected
3fdc546462348b8a497c72bc894e0cde9f10fc40< 1e04be34cafae119e82bcaccd6d28a20f72a3647affected
3fdc546462348b8a497c72bc894e0cde9f10fc40< 161d1aaeb04d620d3692639700512bb5038c1e10affected
3fdc546462348b8a497c72bc894e0cde9f10fc40< c8a24effd96d4779e2ad779654682304491c55a5affected
3fdc546462348b8a497c72bc894e0cde9f10fc40< 46eb17d45be69d28c7a23ea03283b207426a8232affected
3fdc546462348b8a497c72bc894e0cde9f10fc40< 9e18e83b8846a5c3fe13fc8a464b4865d33996c6affected
… +12 more rows
新しい脆弱性情報の通知を購読するログインして購読

I. CVE-2026-53398の基本情報

脆弱性情報

脆弱性についてご質問がありますか?Shenlongの分析が参考になるかご確認ください!
Shenlongの10の質問を表示 ↗

高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。

脆弱性タイトル
NFSD: Fix SECINFO_NO_NAME decode error cleanup
ソース: CVE Program / CVE List V5
脆弱性説明
In the Linux kernel, the following vulnerability has been resolved: NFSD: Fix SECINFO_NO_NAME decode error cleanup nfsd4_decode_secinfo_no_name() currently initializes sin_exp after decoding sin_style. If the XDR stream is truncated, the decoder returns nfserr_bad_xdr before sin_exp is initialized. Since commit 3fdc54646234 ("NFSD: Reduce amount of struct nfsd4_compoundargs that needs clearing"), the inline iops array is not cleared between RPC calls. A failed SECINFO_NO_NAME decode can therefore leave sin_exp holding stale union contents from a previous operation. The error response path still invokes nfsd4_secinfo_no_name_release(), which calls exp_put() on a non-NULL sin_exp. Initialize sin_exp before the first failable decode step, matching nfsd4_decode_secinfo().
ソース: CVE Program / CVE List V5
CVSS情報
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
ソース: CVE Program / CVE List V5
脆弱性タイプ
N/A
ソース: CVE Program / CVE List V5
脆弱性タイトル
Linux kernel 安全漏洞
ソース: CNNVD (China National Vulnerability Database)
脆弱性説明
Linux kernel是美国Linux基金会开源的一款操作系统内核。 Linux kernel存在安全漏洞,该漏洞源于解码步骤中sin_exp初始化不当,可能导致sin_exp持有先前操作的旧联合体内容。以下受影响版本:6.1版本。
ソース: CNNVD (China National Vulnerability Database)
CVSS情報
N/A
ソース: CNNVD (China National Vulnerability Database)
脆弱性タイプ
N/A
ソース: CNNVD (China National Vulnerability Database)

影響を受ける製品

ベンダープロダクト影響を受けるバージョンCPE購読
LinuxLinux 5e76b25d7cc82c148d391c0c43b884e6427cb302 ~ 8836405abdc53ca3dd5fc68b2cf6f8f012fad011 -
LinuxLinux 6.1 -

II. CVE-2026-53398の公開POC

#POC説明ソースリンクShenlongリンク
AI生成POCプレミアム

公開POCは見つかりませんでした。

ログインしてAI POCを生成

III. CVE-2026-53398のインテリジェンス情報

登录查看更多情报信息。

CVE-2026-53398 补丁与修复 (7)

Same Patch Batch · Linux · 2026-07-19 · 431 CVEs total

CVE-2026-6379510.0 CRITICAL9p: avoid putting oldfid in p9_client_walk() error path
CVE-2026-641429.8 CRITICALksmbd: close durable scavenger races against m_fp_list lookups
CVE-2026-640559.8 CRITICALnet: ethernet: cortina: Carry over frag counter
CVE-2026-640569.8 CRITICALnet: ethernet: cortina: Make RX SKB per-port
CVE-2026-640619.8 CRITICALnetfs: Fix early put of sink folio in netfs_read_gaps()
CVE-2026-639849.8 CRITICALipv6: rpl: fix hdrlen overflow in ipv6_rpl_srh_decompress()
CVE-2026-640669.8 CRITICALnetfs: Fix netfs_read_to_pagecache() to pause on subreq failure
CVE-2026-640679.8 CRITICALnetfs: Fix missing barriers when accessing stream->subrequests locklessly
CVE-2026-641509.8 CRITICALnetfilter: nft_inner: release local_lock before re-enabling softirqs
CVE-2026-639229.8 CRITICALipv6: exthdrs: refresh nh after handling HAO option
CVE-2026-640689.8 CRITICALnetfs: Fix missing locking around retry adding new subreqs
CVE-2026-639249.8 CRITICALipv6: exthdrs: refresh nh pointer after ipv6_hop_jumbo()
CVE-2026-640699.8 CRITICALnetfs: Fix cancellation of a DIO and single read subrequests
CVE-2026-639799.8 CRITICALnet/handshake: hand off the pinned file reference to accept_doit
CVE-2026-639789.8 CRITICALnet/handshake: Drain pending requests at net namespace exit
CVE-2026-641229.8 CRITICALnet/mlx5e: Fix use-after-free in mlx5e_tx_reporter_timeout_recover
CVE-2026-641259.8 CRITICALnet: bcmgenet: keep RBUF EEE/PM disabled
CVE-2026-638579.8 CRITICALnet: airoha: Do not read uninitialized fragment address in airoha_dev_xmit()
CVE-2026-638009.8 CRITICALpNFS: Fix use-after-free in pnfs_update_layout()
CVE-2026-640919.8 CRITICALbatman-adv: tt: fix TOCTOU race for reported vlans

Showing 20 of 431 CVEs. View all on vendor page →

IV. 関連脆弱性

V. CVE-2026-53398へのコメント

まだコメントはありません


コメントを残す