目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1336 CNY

100%

CVE-2026-74352— 保留内存:alloc_reserved_mem_array() 失败时避免使用后释放漏洞

AI Predicted 4.4 Difficulty: Hard EPSS 0.17% · P6

Affected Version Matrix 9

ベンダープロダクトVersion Rangeステータス
LinuxLinuxb6ae53301eb41f0f59f83c161248b186bca7da70< 6d28e6ad3c5c9248577f21057baa9bf16fa9ef3baffected
00c9a452a235c61f099504783badd9a7675ff5a5< 9af58d10d0d8c08b822de5fc99e61f31a87ede8daffected
00c9a452a235c61f099504783badd9a7675ff5a5< cbd3102fe27bc87da244bf4c3ba670ea4698b0a8affected
00c9a452a235c61f099504783badd9a7675ff5a5< e1686ca81dbf3edbde589b7daf312b45cbf76e03affected
6.13affected
< 6.13unaffected
6.18.40≤ 6.18.*unaffected
7.1.5≤ 7.1.*unaffected
… +1 more rows
新しい脆弱性情報の通知を購読するログインして購読

I. CVE-2026-74352の基本情報

脆弱性情報

脆弱性についてご質問がありますか?Shenlongの分析が参考になるかご確認ください!
Shenlongの10の質問を表示 ↗

高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。

脆弱性タイトル
of: reserved_mem: avoid post-init UAF when alloc_reserved_mem_array() fails
ソース: CVE Program / CVE List V5
脆弱性説明
In the Linux kernel, the following vulnerability has been resolved: of: reserved_mem: avoid post-init UAF when alloc_reserved_mem_array() fails The global pointer 'reserved_mem' continues to reference the reserved_mem_array which lives in __initdata if alloc_reserved_mem_array() fails. of_reserved_mem_lookup() is exported for post-init use, that would dereference freed memory and trigger a use-after-free. So reset reserved_mem_count to 0 when alloc_reserved_mem_array() fails.
ソース: CVE Program / CVE List V5
CVSS情報
N/A
ソース: CVE Program / CVE List V5
脆弱性タイプ
N/A
ソース: CVE Program / CVE List V5

影響を受ける製品

ベンダープロダクト影響を受けるバージョンCPE購読
LinuxLinux b6ae53301eb41f0f59f83c161248b186bca7da70 ~ 6d28e6ad3c5c9248577f21057baa9bf16fa9ef3b -
LinuxLinux 6.13 -

II. CVE-2026-74352の公開POC

#POC説明ソースリンクShenlongリンク
AI生成POCプレミアム

公開POCは見つかりませんでした。

ログインしてAI POCを生成

III. CVE-2026-74352のインテリジェンス情報

登录查看更多情报信息。

CVE-2026-74352 补丁与修复 (4)

Same Patch Batch · Linux · 2026-08-15 · 848 CVEs total

CVE-2026-72255netfilter: nf_queue: pin bridge device while NFQUEUE holds fake dst
CVE-2026-72268fbdev: tdfxfb: fix potential memory leak in tdfxfb_probe()
CVE-2026-72267fbdev: carminefb: fix potential memory leak in alloc_carmine_fb()
CVE-2026-72266fbdev: vesafb: fix memory leak in vesafb_probe()
CVE-2026-72265fbdev: nvidia: fix potential memory leak in nvidiafb_probe()
CVE-2026-72264fbdev: tridentfb: fix potential memory leak in trident_pci_probe()
CVE-2026-72262ASoC: SOF: ipc3-control: Fix heap overflow in bytes_ext put/get
CVE-2026-72263ASoC: SOF: topology: fix memory leak in snd_sof_load_topology
CVE-2026-72261ASoC: SOF: ipc3-control: Validate size in snd_sof_update_control
CVE-2026-72260ASoC: mediatek: mt8192: Check runtime resume during probe
CVE-2026-72259ASoC: mediatek: mt8192: Release reserved memory on cleanup
CVE-2026-72258ASoC: mediatek: mt8183: Release reserved memory on cleanup
CVE-2026-72256netfilter: xt_cluster: reject template conntracks in hash match
CVE-2026-72257ASoC: qcom: q6apm: fix NULL pointer dereference in graph_callback
CVE-2026-72245gpu: host1x: Fix device reference leak in host1x_device_parse_dt() error path
CVE-2026-72248netfilter: flowtable: support IPIP tunnel with direct xmit
CVE-2026-72247netfilter: nf_conncount: fix zone comparison in tuple dedup
CVE-2026-72246netfilter: flowtable: use correct direction to set up tunnel route
CVE-2026-72249netfilter: flowtable: use dst in this direction when pushing IPIP header
CVE-2026-72244gpu/buddy: bail out of try_harder when alignment cannot be honoured

Showing 20 of 848 CVEs. View all on vendor page →

IV. 関連脆弱性

V. CVE-2026-74352へのコメント

まだコメントはありません


コメントを残す