目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CVE-2026-64542— Linux kernel 安全漏洞

AI 预测 6.5 利用难度: 中等 EPSS 0.17% · P6

影响版本矩阵 12

厂商产品版本范围状态
LinuxLinuxaaa5f515b16b6b3e137779ffb4c9558bb58c1e75< 160d3f0d7a556ceae505dcab521a37057b4ce28faffected
aaa5f515b16b6b3e137779ffb4c9558bb58c1e75< 62c719203cb521b64fab74da94a81bdde5c18808affected
aaa5f515b16b6b3e137779ffb4c9558bb58c1e75< a6450f7cfae57b382cbaf66a577765c9a88b3c58affected
aaa5f515b16b6b3e137779ffb4c9558bb58c1e75< 63d1c23764de2309cedbb779c75188d257a09d9baffected
aaa5f515b16b6b3e137779ffb4c9558bb58c1e75< d186e942365acece7c56d39da05dd63bf95b280aaffected
6.0affected
< 6.0unaffected
6.6.148≤ 6.6.*unaffected
… +4 条更多
获取后续新漏洞提醒登录后订阅

一、 漏洞 CVE-2026-64542 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
ipv6: ndisc: fix NULL deref in accept_untracked_na()
来源: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: ipv6: ndisc: fix NULL deref in accept_untracked_na() accept_untracked_na() re-fetches the inet6_dev with __in6_dev_get(dev) and dereferences idev->cnf.accept_untracked_na without a NULL check, even though its only caller ndisc_recv_na() already fetched and NULL-checked idev for the same device. Both reads of dev->ip6_ptr run in the same RCU read-side critical section, but a concurrent addrconf_ifdown() can clear dev->ip6_ptr between them: lowering the MTU below IPV6_MIN_MTU calls addrconf_ifdown() without the synchronize_net() that orders the unregister path, so the re-fetch returns NULL and oopses: BUG: KASAN: null-ptr-deref in ndisc_recv_na (net/ipv6/ndisc.c:974) Read of size 4 at addr 0000000000000364 Call Trace: <IRQ> ndisc_recv_na (net/ipv6/ndisc.c:974) icmpv6_rcv (net/ipv6/icmp.c:1193) ip6_protocol_deliver_rcu (net/ipv6/ip6_input.c:479) ip6_input_finish (net/ipv6/ip6_input.c:534) ip6_input (net/ipv6/ip6_input.c:545) ip6_mc_input (net/ipv6/ip6_input.c:635) ipv6_rcv (net/ipv6/ip6_input.c:351) </IRQ> It is reachable by an unprivileged user via a network namespace. Pass the caller's already validated idev instead of re-fetching it; the idev stays alive for the whole RCU critical section, so it is safe even after dev->ip6_ptr has been cleared.
来源: CVE Program / CVE List V5
CVSS Information
N/A
来源: CVE Program / CVE List V5
Vulnerability Type
N/A
来源: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Description
Linux kernel是美国Linux基金会开源的一款操作系统内核。 Linux kernel存在安全漏洞,该漏洞源于accept_untracked_na()函数中重新获取inet6_dev时未进行空指针检查,可能导致空指针取消引用。
来源: 中国国家信息安全漏洞库 CNNVD
CVSS Information
N/A
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Type
N/A
来源: 中国国家信息安全漏洞库 CNNVD

受影响产品

厂商产品影响版本CPE订阅
LinuxLinux aaa5f515b16b6b3e137779ffb4c9558bb58c1e75 ~ 160d3f0d7a556ceae505dcab521a37057b4ce28f -
LinuxLinux 6.0 -

二、漏洞 CVE-2026-64542 的公开POC

#POC 描述源链接神龙链接
AI 生成 POC高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2026-64542 的情报信息

登录查看更多情报信息。

CVE-2026-64542 补丁与修复 (5)

同批安全公告 · Linux · 2026-07-27 · 共 25 条

CVE-2026-645349.8 CRITICALLinux kernel 安全漏洞
CVE-2026-645359.8 CRITICALLinux kernel 安全漏洞
CVE-2026-645419.8 CRITICALLinux kernel 安全漏洞
CVE-2026-645519.1 CRITICALLinux kernel 安全漏洞
CVE-2026-645558.8 HIGHLinux kernel 安全漏洞
CVE-2026-645548.8 HIGHLinux kernel 安全漏洞
CVE-2026-645528.4 HIGHLinux kernel 安全漏洞
CVE-2026-645488.4 HIGHLinux kernel 安全漏洞
CVE-2026-645368.1 HIGHLinux kernel 安全漏洞
CVE-2026-645478.1 HIGHLinux kernel 安全漏洞
CVE-2026-645408.1 HIGHLinux kernel 安全漏洞
CVE-2026-645437.8 HIGHLinux kernel 安全漏洞
CVE-2026-645317.8 HIGHLinux kernel 安全漏洞
CVE-2026-645397.8 HIGHLinux kernel 安全漏洞
CVE-2026-645337.8 HIGHLinux kernel 安全漏洞
CVE-2026-645327.8 HIGHLinux kernel 安全漏洞
CVE-2026-645457.5 HIGHLinux kernel 安全漏洞
CVE-2026-645507.3 HIGHLinux kernel 安全漏洞
CVE-2026-645467.1 HIGHLinux kernel 安全漏洞
CVE-2026-64544Linux kernel 安全漏洞

显示前 20 条,共 25 条。 查看全部 &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-64542

暂无评论


发表评论