目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CVE-2026-64535— Linux kernel 安全漏洞

AI 预测 7.8 利用难度: 中等 EPSS 0.17% · P7

影响版本矩阵 14

厂商产品版本范围状态
LinuxLinux1da177e4c3f41524e886b7f1b8a0c1fc7321cac2< 96fe2513df590e74b04253a45089cae75569570eaffected
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2< e091ff83d962f9ed00d9bd70443676de9fe98bdcaffected
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2< 6f9442983a3e4227afd1c83a5251ddbca585ea21affected
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2< 088ee46c18d99baef453afd74181dd40ade044adaffected
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2< dbbd07d0a7020b80f6a7028e561908f7b83b3d5aaffected
< 6.1.178affected
< 6.6.145affected
< 6.12.97affected
… +6 条更多
获取后续新漏洞提醒登录后订阅

一、 漏洞 CVE-2026-64535 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
nvmet-tcp: Fix potential UAF when ddgst mismatch
来源: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: Fix potential UAF when ddgst mismatch Shivam Kumar found via vulnerability testing: When data digest is enabled on an NVMe/TCP connection and a digest mismatch occurs on a non-final H2C_DATA PDU during an R2T-based data transfer, the digest error handler in nvmet_tcp_try_recv_ddgst() calls nvmet_req_uninit() — which performs percpu_ref_put() on the submission queue — but does NOT mark the command as completed. It does not set cqe->status, does not modify rbytes_done, and does not clear any flag. When the subsequent fatal error triggers queue teardown, nvmet_tcp_uninit_data_in_cmds() iterates all commands, checks nvmet_tcp_need_data_in() for each one, and finds that the already-uninited command still appears to need data (because rbytes_done < transfer_len and cqe->status == 0). It therefore calls nvmet_req_uninit() a second time on the same command — a double percpu_ref_put against a single percpu_ref_get.
来源: CVE Program / CVE List V5
CVSS Information
N/A
来源: CVE Program / CVE List V5
Vulnerability Type
N/A
来源: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Description
Linux kernel是美国Linux基金会开源的一款操作系统内核。 Linux kernel 存在安全漏洞,该漏洞源于数据摘要处理不当,导致在R2T数据传输中非最终H2C_DATA PDU摘要不匹配时,错误处理未标记命令完成,造成双重释放,从而引发释放后重用。
来源: 中国国家信息安全漏洞库 CNNVD
CVSS Information
N/A
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Type
N/A
来源: 中国国家信息安全漏洞库 CNNVD

受影响产品

厂商产品影响版本CPE订阅
LinuxLinux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 ~ 96fe2513df590e74b04253a45089cae75569570e -
LinuxLinux 6.1.178 ~ 6.1.* -

二、漏洞 CVE-2026-64535 的公开POC

#POC 描述源链接神龙链接
AI 生成 POC高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2026-64535 的情报信息

登录查看更多情报信息。

CVE-2026-64535 补丁与修复 (4)

同批安全公告 · Linux · 2026-07-27 · 共 25 条

CVE-2026-64543Linux kernel 安全漏洞
CVE-2026-64532Linux kernel 安全漏洞
CVE-2026-64531Linux kernel 安全漏洞
CVE-2026-64533Linux kernel 安全漏洞
CVE-2026-64534Linux kernel 安全漏洞
CVE-2026-64536Linux kernel 安全漏洞
CVE-2026-64537Linux kernel 安全漏洞
CVE-2026-64538Linux kernel 安全漏洞
CVE-2026-64539Linux kernel 安全漏洞
CVE-2026-64540Linux kernel 安全漏洞
CVE-2026-64541Linux kernel 安全漏洞
CVE-2026-64542Linux kernel 安全漏洞
CVE-2026-64554Linux kernel 安全漏洞
CVE-2026-64544Linux kernel 安全漏洞
CVE-2026-64546Linux kernel 安全漏洞
CVE-2026-64545Linux kernel 安全漏洞
CVE-2026-64547Linux kernel 安全漏洞
CVE-2026-64548Linux kernel 安全漏洞
CVE-2026-64550Linux kernel 安全漏洞
CVE-2026-64549Linux kernel 安全漏洞

显示前 20 条,共 25 条。 查看全部 &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-64535

暂无评论


发表评论