目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CVE-2026-64218— Linux kernel 安全漏洞

CVSS 7.8 · High EPSS 0.13% · P3

影响版本矩阵 18

厂商产品版本范围状态
LinuxLinux23721387c409087fd3b97e274f34d3ddc0970b74< ce2c0ee4d76d5ee4b391fe0e31334361e25030ecaffected
23721387c409087fd3b97e274f34d3ddc0970b74< 3423a45e5c3d3c5129f88143a9a969787d7d5a0aaffected
23721387c409087fd3b97e274f34d3ddc0970b74< f1303adb1e59582f76c22798a2e2e150e054a9e7affected
23721387c409087fd3b97e274f34d3ddc0970b74< 48663158222b3b7f6ee6791a67d512ede7fc94bbaffected
23721387c409087fd3b97e274f34d3ddc0970b74< eeddd7bab3d59c1e98642a204141f8c5d6194707affected
23721387c409087fd3b97e274f34d3ddc0970b74< c6de1a5a9c406e30b91f1515a6ce05cc84023baaaffected
23721387c409087fd3b97e274f34d3ddc0970b74< 95a7034661274cf5985708bd2f6d86ee46f88fa9affected
23721387c409087fd3b97e274f34d3ddc0970b74< 0459430add32ea41f3e2ef9351610e6d33627a6baffected
… +10 条更多
获取后续新漏洞提醒登录后订阅

一、 漏洞 CVE-2026-64218 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
batman-adv: bla: fix report_work leak on backbone_gw purge
来源: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: batman-adv: bla: fix report_work leak on backbone_gw purge batadv_bla_purge_backbone_gw() removes stale backbone gateway entries, but fails to properly handle their associated report_work: - If report_work is running, the purge must wait for it to finish before freeing the backbone_gw, otherwise the worker may access freed memory (e.g. bat_priv). - If report_work is pending, the purge must cancel it and release the reference held for that pending work item. The previous implementation called hlist_for_each_entry_safe() inside a spin_lock_bh() section, but cancel_work_sync() may sleep and therefore cannot be called from within a spinlock-protected region. Restructure the loop to handle one entry per spinlock critical section: acquire the lock, find the next entry to purge, remove it from the hash list, then release the lock before calling cancel_work_sync() and dropping the hash_entry reference. Repeat until no more entries require purging.
来源: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
来源: CVE Program / CVE List V5
Vulnerability Type
N/A
来源: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Description
Linux kernel是美国Linux基金会开源的一款操作系统内核。 Linux kernel 3.5版本存在安全漏洞,该漏洞源于batadv_bla_purge_backbone_gw()函数在清理骨干网关条目时未正确处理关联的report_work,可能导致释放后重用和内存泄漏。
来源: 中国国家信息安全漏洞库 CNNVD
CVSS Information
N/A
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Type
N/A
来源: 中国国家信息安全漏洞库 CNNVD

受影响产品

厂商产品影响版本CPE订阅
LinuxLinux 23721387c409087fd3b97e274f34d3ddc0970b74 ~ ce2c0ee4d76d5ee4b391fe0e31334361e25030ec -
LinuxLinux 3.5 -

二、漏洞 CVE-2026-64218 的公开POC

#POC 描述源链接神龙链接
AI 生成 POC高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2026-64218 的情报信息

登录查看更多情报信息。

CVE-2026-64218 补丁与修复 (7)

同批安全公告 · Linux · 2026-07-24 · 共 48 条

CVE-2026-642329.8 CRITICALLinux kernel 安全漏洞
CVE-2026-642169.8 CRITICALLinux kernel 安全漏洞
CVE-2026-642558.8 HIGHLinux kernel 安全漏洞
CVE-2026-642478.4 HIGHLinux kernel 安全漏洞
CVE-2026-642358.1 HIGHLinux kernel 安全漏洞
CVE-2026-642238.1 HIGHLinux kernel 安全漏洞
CVE-2026-642517.8 HIGHLinux kernel 安全漏洞
CVE-2026-642267.8 HIGHLinux kernel 安全漏洞
CVE-2026-642217.8 HIGHLinux kernel 安全漏洞
CVE-2026-642177.8 HIGHLinux kernel 安全漏洞
CVE-2026-642107.5 HIGHLinux kernel 安全漏洞
CVE-2026-642087.5 HIGHLinux kernel 安全漏洞
CVE-2026-642437.1 HIGHLinux kernel 安全漏洞
CVE-2026-642227.0 HIGHLinux kernel 安全漏洞
CVE-2026-642197.0 HIGHLinux kernel 安全漏洞
CVE-2026-64252Linux kernel 安全漏洞
CVE-2026-64224Linux kernel 安全漏洞
CVE-2026-64250Linux kernel 安全漏洞
CVE-2026-64248Linux kernel 安全漏洞
CVE-2026-64254Linux kernel 安全漏洞

显示前 20 条,共 48 条。 查看全部 &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-64218

暂无评论


发表评论