目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CVE-2026-63914— Linux kernel 安全漏洞

CVSS 7.3 · High EPSS 0.15% · P5

影响版本矩阵 18

厂商产品版本范围状态
LinuxLinux5c79de6e79cd8ecfbae28886be3ee49044f3a4d4< bafc7d0774b9bf52909c70ed990bc5ccf7ec4badaffected
5c79de6e79cd8ecfbae28886be3ee49044f3a4d4< 6df8157547347b5257bf640a0ae3dfc4411e06cdaffected
5c79de6e79cd8ecfbae28886be3ee49044f3a4d4< fe463798343382c8fe9416a95959f005a3c30aa5affected
5c79de6e79cd8ecfbae28886be3ee49044f3a4d4< 00f2c451e57df50b1151d9b2254878f106b7c892affected
5c79de6e79cd8ecfbae28886be3ee49044f3a4d4< a306cf2ac8849c487791369fad6f216399d000f6affected
5c79de6e79cd8ecfbae28886be3ee49044f3a4d4< 448bb92ca101dde8a6e88b4dc824044b4e341604affected
5c79de6e79cd8ecfbae28886be3ee49044f3a4d4< 26ce8dbf2e23fe4fcc3351d19ef6d3fb703ed126affected
5c79de6e79cd8ecfbae28886be3ee49044f3a4d4< 7e2a4f7ca0952820731ef7bdadfc9a9e9d3571b4affected
… +10 条更多
获取后续新漏洞提醒登录后订阅

一、 漏洞 CVE-2026-63914 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
xfrm: route MIGRATE notifications to caller's netns
来源: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: xfrm: route MIGRATE notifications to caller's netns xfrm_send_migrate() in net/xfrm/xfrm_user.c and pfkey_send_migrate() in net/key/af_key.c both hardcode &init_net for the multicast that announces a successful XFRM_MSG_MIGRATE / SADB_X_MIGRATE. XFRM_MSG_MIGRATE arrives on a per-netns NETLINK_XFRM socket, and the rest of the xfrm/af_key netlink path was made netns-aware in 2008. The other 14 multicast paths in xfrm_user.c route their event using xs_net(x), xp_net(xp) or sock_net(skb->sk); only the migrate path was missed. Two consequences of the init_net hardcoding: 1. The notification (selector, old/new endpoint addresses, and the km_address) is delivered to listeners on init_net's XFRMNLGRP_MIGRATE / pfkey BROADCAST_ALL groups rather than on the issuing netns. An IKE daemon running in init_net therefore receives migration notifications originating from any other netns on the host. 2. An IKE daemon running inside a non-init netns and subscribed to its own XFRMNLGRP_MIGRATE / pfkey groups never receives the notification of its own migration. IKEv2 MOBIKE / address-update handling inside a netns is silently broken. Thread struct net through km_migrate() and the xfrm_mgr.migrate function pointer, drop the &init_net override in xfrm_send_migrate() and pfkey_send_migrate(), and pass the caller's net (already in scope in xfrm_migrate() via sock_net(skb->sk)) all the way down. struct xfrm_mgr is in-tree only and not exported as a stable API, so the function-pointer signature change is internal. pfkey_broadcast() is already netns-aware via net_generic(net, pfkey_net_id) since the pernet conversion. The five other pfkey_broadcast() callers in af_key.c already pass xs_net(x), sock_net(sk) or a per-netns net, so this only removes the &init_net outlier.
来源: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L
来源: CVE Program / CVE List V5
Vulnerability Type
N/A
来源: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Description
Linux kernel是美国Linux基金会开源的一款操作系统内核。 Linux kernel存在安全漏洞,该漏洞源于xfrm_send_migrate和pfkey_send_migrate函数中硬编码&init_net,导致迁移通知未正确路由到调用者的网络命名空间,可能使IKE守护进程接收到来自其他网络命名空间的通知而非自身。
来源: 中国国家信息安全漏洞库 CNNVD
CVSS Information
N/A
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Type
N/A
来源: 中国国家信息安全漏洞库 CNNVD

受影响产品

厂商产品影响版本CPE订阅
LinuxLinux 5c79de6e79cd8ecfbae28886be3ee49044f3a4d4 ~ bafc7d0774b9bf52909c70ed990bc5ccf7ec4bad -
LinuxLinux 2.6.21 -

二、漏洞 CVE-2026-63914 的公开POC

#POC 描述源链接神龙链接
AI 生成 POC高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2026-63914 的情报信息

登录查看更多情报信息。

CVE-2026-63914 补丁与修复 (8)

同批安全公告 · Linux · 2026-07-19 · 共 431 条

CVE-2026-6379510.0 CRITICALLinux kernel 安全漏洞
CVE-2026-639849.8 CRITICALLinux kernel 安全漏洞
CVE-2026-640009.8 CRITICALLinux kernel 安全漏洞
CVE-2026-641509.8 CRITICALLinux kernel 安全漏洞
CVE-2026-639229.8 CRITICALLinux kernel 安全漏洞
CVE-2026-639249.8 CRITICALLinux kernel 安全漏洞
CVE-2026-640469.8 CRITICALLinux kernel 安全漏洞
CVE-2026-640479.8 CRITICALLinux kernel 安全漏洞
CVE-2026-639949.8 CRITICALLinux kernel 安全漏洞
CVE-2026-641429.8 CRITICALLinux kernel 安全漏洞
CVE-2026-639939.8 CRITICALLinux kernel 安全漏洞
CVE-2026-640559.8 CRITICALLinux kernel 安全漏洞
CVE-2026-533989.8 CRITICALLinux kernel 安全漏洞
CVE-2026-641329.8 CRITICALLinux kernel 安全漏洞
CVE-2026-533999.8 CRITICALLinux kernel 安全漏洞
CVE-2026-641259.8 CRITICALLinux kernel 安全漏洞
CVE-2026-640569.8 CRITICALLinux kernel 安全漏洞
CVE-2026-640699.8 CRITICALLinux kernel 安全漏洞
CVE-2026-638579.8 CRITICALLinux kernel 安全漏洞
CVE-2026-639789.8 CRITICALLinux kernel 安全漏洞

显示前 20 条,共 431 条。 查看全部 &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-63914

暂无评论


发表评论