🔴 Linux 内核 sctp 模块本地提权漏洞 SCTPhantom。
- 腾讯朱雀实验室利用 AI 辅助发现了一个于 2008 年引入的 sctp 模块的漏洞。
- Kernel 上游和 Debian Sid 已经发布修复版本。
CVE: CVE-2026-64564
CVSS: 8.5 (作者自评)
Fixed-In: 6.6.148, 6.12.101, 6.18.42, 7.1.6, 7.2-rc5
matrix.tencent.com/~
[感谢一位匿名订户提供信息。]
#SCTPhantom #Kernel
- 腾讯朱雀实验室利用 AI 辅助发现了一个于 2008 年引入的 sctp 模块的漏洞。
- Kernel 上游和 Debian Sid 已经发布修复版本。
CVE: CVE-2026-64564
CVSS: 8.5 (作者自评)
Fixed-In: 6.6.148, 6.12.101, 6.18.42, 7.1.6, 7.2-rc5
matrix.tencent.com/~
[感谢一位匿名订户提供信息。]
#SCTPhantom #Kernel
Debian 用户请暂停更新系统:新版本 Linux 内核 ext4 数据损坏问题*。
- 也请注意停止自动更新。
- Linux 6.1.64-1、5.15.140-1、5.10.202-1 等版本存在 ext4 数据损坏问题。此问题于 6.1.66 修复。另外,6.5-1 及更高的版本接收了一个 fix,所以不受影响 [1]。
- 截至发稿时,bookworm 的 linux-image-amd64 依然在 6.1.64-1 版本 [2]。
- https://micronews.debian.org/2023/1702150551.html
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1057843
1. lore.kernel.org/~
2. https://packages.debian.org/bookworm/linux-image-amd64
* 不仅限于 Debian,其它发行版的对应内核版本也可能存在此问题。
linksrc: https://t.me/bupt_moe/2008
EDIT 12/10: 添加了更详细的关于影响版本及发行版的描述。感谢一位匿名订户指出。
#PSA #Kernel #Debian
- 也请注意停止自动更新。
- Linux 6.1.64-1、5.15.140-1、5.10.202-1 等版本存在 ext4 数据损坏问题。此问题于 6.1.66 修复。另外,6.5-1 及更高的版本接收了一个 fix,所以不受影响 [1]。
- 截至发稿时,bookworm 的 linux-image-amd64 依然在 6.1.64-1 版本 [2]。
- https://micronews.debian.org/2023/1702150551.html
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1057843
1. lore.kernel.org/~
2. https://packages.debian.org/bookworm/linux-image-amd64
* 不仅限于 Debian,其它发行版的对应内核版本也可能存在此问题。
linksrc: https://t.me/bupt_moe/2008
EDIT 12/10: 添加了更详细的关于影响版本及发行版的描述。感谢一位匿名订户指出。
#PSA #Kernel #Debian