现在我也不知道这频道发了啥了,各位慢慢吃瓜,将就着看

联系我请去 @abc1763613206

友链儿
@cyberElaina
@rvalue_daily
@billchenla
🔴 Linux 内核 sctp 模块本地提权漏洞 SCTPhantom。

- 腾讯朱雀实验室利用 AI 辅助发现了一个于 2008 年引入的 sctp 模块的漏洞。
- Kernel 上游和 Debian Sid 已经发布修复版本。

CVE: CVE-2026-64564
CVSS: 8.5 (作者自评)
Fixed-In: 6.6.148, 6.12.101, 6.18.42, 7.1.6, 7.2-rc5

matrix.tencent.com/~

[感谢一位匿名订户提供信息。]

#SCTPhantom #Kernel SCTPhantom: 潜伏18年的Linux内核提权与容器逃逸漏洞 · 腾讯朱雀实验室
Debian 用户请暂停更新系统:新版本 Linux 内核 ext4 数据损坏问题*。

- 也请注意停止自动更新。
- Linux 6.1.64-1、5.15.140-1、5.10.202-1 等版本存在 ext4 数据损坏问题。此问题于 6.1.66 修复。另外,6.5-1 及更高的版本接收了一个 fix,所以不受影响 [1]。
- 截至发稿时,bookworm 的 linux-image-amd64 依然在 6.1.64-1 版本 [2]。

- https://micronews.debian.org/2023/1702150551.html
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1057843

1. lore.kernel.org/~
2. https://packages.debian.org/bookworm/linux-image-amd64

* 不仅限于 Debian,其它发行版的对应内核版本也可能存在此问题。

linksrc: https://t.me/bupt_moe/2008

EDIT 12/10: 添加了更详细的关于影响版本及发行版的描述。感谢一位匿名订户指出。

#PSA #Kernel #Debian
 
 
Back to Top