SecLens 情报中心

网安资讯,一网打尽。汇集权威漏洞通告与行业要闻,结合分组浏览、智能过滤、RSS订阅 和 Webhook 推送,多通道拓展您的安全情报视野。

厂商发布

厂商对产品安全、配置或策略的更新说明。

  • ALINUX3-SA-2026:0140

    发布时间 2026-05-29 15:23 (UTC+08:00) 抓取时间 2026-05-29 16:00 (UTC+08:00)

    Package updates are available for Alibaba Cloud Linux 3 that fix the following vulnerabilities: CVE-2026-46333: In the Linux kernel, the following vulnerability has been resolved: ptrace: slightly saner 'get_dumpable()' logic The 'dumpability' of a task is fundamentally about the memory image of the task - the concept comes from whether it can core dump or

    扩展字段
    {
      "advisory_id": "ALINUX3-SA-2026:0140",
      "affected_products": [
        "Alinux 3.2104"
      ],
      "cve_ids": [
        "CVE-2026-46333"
      ],
      "raw_pub_date": "Fri, 29 May 2026 15:23:37 +0800",
      "solution": "请您尽快将升级到修复后的版本。修复命令如下:\nyum update --advisory ALINUX3-SA-2026:0140"
    }
    阿里云 Linux 安全公告 cve:cve-2026-46333 severity:important type:advisory vendor:alibaba cve official_advisory vendor-update
  • ALINUX3-SA-2026:0139

    发布时间 2026-05-29 15:15 (UTC+08:00) 抓取时间 2026-05-29 16:00 (UTC+08:00)

    Package updates are available for Alibaba Cloud Linux 3 that fix the following vulnerabilities: CVE-2023-54068: In the Linux kernel, the following vulnerability has been resolved: f2fs: compress: fix to call f2fs_wait_on_page_writeback() in f2fs_write_raw_pages() BUG_ON() will be triggered when writing files concurrently. CVE-2026-23038: In the Linux kerne

    扩展字段
    {
      "advisory_id": "ALINUX3-SA-2026:0139",
      "affected_products": [
        "Alinux 3.2104"
      ],
      "cve_ids": [
        "CVE-2023-54068",
        "CVE-2026-23038",
        "CVE-2026-23398",
        "CVE-2026-23420",
        "CVE-2026-23449",
        "CVE-2026-23450",
        "CVE-2026-23452",
        "CVE-2026-23455",
        "CVE-2026-23456",
        "CVE-2026-23457",
        "CVE-2026-31399",
        "CVE-2026-31402",
        "CVE-2026-31431",
        "CVE-2026-43284"
      ],
      "raw_pub_date": "Fri, 29 May 2026 15:15:17 +0800",
      "solution": "请您尽快将升级到修复后的版本。修复命令如下:\nyum update --advisory ALINUX3-SA-2026:0139"
    }
    阿里云 Linux 安全公告 cve:cve-2023-54068 cve:cve-2026-23038 cve:cve-2026-23398 cve:cve-2026-23420 cve:cve-2026-23449 cve:cve-2026-23450 cve:cve-2026-23452 cve:cve-2026-23455 cve:cve-2026-23456 cve:cve-2026-23457 cve:cve-2026-31399 cve:cve-2026-31402 cve:cve-2026-31431 cve:cve-2026-43284 severity:important type:advisory vendor:alibaba cve official_advisory vendor-update
  • ALINUX3-SA-2026:0138

    发布时间 2026-05-29 14:59 (UTC+08:00) 抓取时间 2026-05-29 16:00 (UTC+08:00)

    Package updates are available for Alibaba Cloud Linux 3 Pro that fix the following vulnerabilities: CVE-2026-46333: In the Linux kernel, the following vulnerability has been resolved: ptrace: slightly saner 'get_dumpable()' logic The 'dumpability' of a task is fundamentally about the memory image of the task - the concept comes from whether it can core dump

    扩展字段
    {
      "advisory_id": "ALINUX3-SA-2026:0138",
      "affected_products": [
        "Alinux 3 Pro"
      ],
      "cve_ids": [
        "CVE-2026-46333"
      ],
      "raw_pub_date": "Fri, 29 May 2026 14:59:38 +0800",
      "solution": "请您尽快将升级到修复后的版本。修复命令如下:\nyum update --advisory ALINUX3-SA-2026:0138"
    }
    阿里云 Linux 安全公告 cve:cve-2026-46333 severity:important type:advisory vendor:alibaba cve official_advisory vendor-update
  • ALINUX3-SA-2026:0137

    发布时间 2026-05-29 14:59 (UTC+08:00) 抓取时间 2026-05-29 16:00 (UTC+08:00)

    Package updates are available for Alibaba Cloud Linux 3 that fix the following vulnerabilities: CVE-2022-41741: NGINX Open Source before versions 1.23.2 and 1.22.1, NGINX Open Source Subscription before versions R2 P1 and R1 P1, and NGINX Plus before versions R27 P1 and R26 P1 have a vulnerability in the module ngx_http_mp4_module that might allow a local a

    扩展字段
    {
      "advisory_id": "ALINUX3-SA-2026:0137",
      "affected_products": [
        "Alinux 3.2104",
        "Alinux 3 Pro"
      ],
      "cve_ids": [
        "CVE-2022-41741",
        "CVE-2026-1642",
        "CVE-2026-27651",
        "CVE-2026-27654",
        "CVE-2026-27784",
        "CVE-2026-32647"
      ],
      "raw_pub_date": "Fri, 29 May 2026 14:59:12 +0800",
      "solution": "请您尽快将升级到修复后的版本。修复命令如下:\nyum update --advisory ALINUX3-SA-2026:0137"
    }
    阿里云 Linux 安全公告 cve:cve-2022-41741 cve:cve-2026-1642 cve:cve-2026-27651 cve:cve-2026-27654 cve:cve-2026-27784 cve:cve-2026-32647 severity:important type:advisory vendor:alibaba cve official_advisory vendor-update
  • ALINUX2-SA-2026:0003

    发布时间 2026-05-29 13:52 (UTC+08:00) 抓取时间 2026-05-29 14:00 (UTC+08:00)

    Package updates are available for Alibaba Cloud Linux 2.1903 that fix the following vulnerabilities: CVE-2026-46333: In the Linux kernel, the following vulnerability has been resolved: ptrace: slightly saner 'get_dumpable()' logic The 'dumpability' of a task is fundamentally about the memory image of the task - the concept comes from whether it can core dum

    扩展字段
    {
      "advisory_id": "ALINUX2-SA-2026:0003",
      "affected_products": [
        "Alinux 2.1903"
      ],
      "cve_ids": [
        "CVE-2026-46333"
      ],
      "raw_pub_date": "Fri, 29 May 2026 13:52:13 +0800",
      "solution": "请您尽快将升级到修复后的版本。修复命令如下:\nyum update --advisory ALINUX2-SA-2026:0003"
    }
    阿里云 Linux 安全公告 cve:cve-2026-46333 severity:important type:advisory vendor:alibaba cve official_advisory vendor-update
  • ALINUX4-SA-2026:0246

    发布时间 2026-05-28 18:27 (UTC+08:00) 抓取时间 2026-05-28 20:00 (UTC+08:00)

    Package updates are available for Alibaba Cloud Linux 4 that fix the following vulnerabilities: CVE-2026-46333: In the Linux kernel, the following vulnerability has been resolved: ptrace: slightly saner 'get_dumpable()' logic The 'dumpability' of a task is fundamentally about the memory image of the task - the concept comes from whether it can core dump or

    扩展字段
    {
      "advisory_id": "ALINUX4-SA-2026:0246",
      "affected_products": [
        "Alinux 4 Agentic OS"
      ],
      "cve_ids": [
        "CVE-2026-46333"
      ],
      "raw_pub_date": "Thu, 28 May 2026 18:27:44 +0800",
      "solution": "请您尽快将升级到修复后的版本。修复命令如下:\nyum update --advisory ALINUX4-SA-2026:0246"
    }
    阿里云 Linux 安全公告 cve:cve-2026-46333 severity:important type:advisory vendor:alibaba cve official_advisory vendor-update
  • ALINUX4-SA-2026:0240

    发布时间 2026-05-28 18:05 (UTC+08:00) 抓取时间 2026-05-28 20:00 (UTC+08:00)

    Package updates are available for Alibaba Cloud Linux 4 that fix the following vulnerabilities: CVE-2026-4802: A flaw was found in Cockpit. This vulnerability allows a remote attacker to achieve arbitrary command execution on the host by exploiting unsanitized user-controlled parameters within crafted links in the system logs user interface (UI). An attacke

    扩展字段
    {
      "advisory_id": "ALINUX4-SA-2026:0240",
      "affected_products": [
        "Alinux 4"
      ],
      "cve_ids": [
        "CVE-2026-4802"
      ],
      "raw_pub_date": "Thu, 28 May 2026 18:05:50 +0800",
      "solution": "请您尽快将升级到修复后的版本。修复命令如下:\nyum update --advisory ALINUX4-SA-2026:0240"
    }
    阿里云 Linux 安全公告 cve:cve-2026-4802 severity:important type:advisory vendor:alibaba cve official_advisory vendor-update
  • ALINUX4-SA-2026:0241

    发布时间 2026-05-28 18:05 (UTC+08:00) 抓取时间 2026-05-28 20:00 (UTC+08:00)

    Package updates are available for Alibaba Cloud Linux 4 that fix the following vulnerabilities: CVE-2026-45186: A flaw was found in libexpat. When processing a specially crafted XML input containing a specific pattern of attributes, the parsing time increases quadratically due to checks for attribute name collisions. This consumes excessive CPU resources an

    扩展字段
    {
      "advisory_id": "ALINUX4-SA-2026:0241",
      "affected_products": [
        "Alinux 4"
      ],
      "cve_ids": [
        "CVE-2026-45186"
      ],
      "raw_pub_date": "Thu, 28 May 2026 18:05:42 +0800",
      "solution": "请您尽快将升级到修复后的版本。修复命令如下:\nyum update --advisory ALINUX4-SA-2026:0241"
    }
    阿里云 Linux 安全公告 cve:cve-2026-45186 severity:important type:advisory vendor:alibaba cve official_advisory vendor-update