SecLens 情报中心

网安资讯,一网打尽。汇集权威漏洞通告与行业要闻,结合分组浏览、智能过滤、RSS订阅 和 Webhook 推送,多通道拓展您的安全情报视野。

厂商发布

厂商对产品安全、配置或策略的更新说明。

  • ALINUX4-SA-2026:0333

    发布时间 2026-07-24 17:48 (UTC+08:00) 抓取时间 2026-07-24 18:00 (UTC+08:00)

    Package updates are available for Alibaba Cloud Linux 4 that fix the following vulnerabilities: CVE-2023-52590: In the Linux kernel, the following vulnerability has been resolved:ocfs2: Avoid touching renamed directory if parent does not changeThe VFS will not be locking moved directory if its parent does notchange. Change ocfs2 rename code to avoid touchin

    扩展字段
    {
      "advisory_id": "ALINUX4-SA-2026:0333",
      "affected_products": [
        "Alinux 4"
      ],
      "cve_ids": [
        "CVE-2023-52590",
        "CVE-2024-39478",
        "CVE-2024-41082",
        "CVE-2024-58094",
        "CVE-2024-58095",
        "CVE-2025-21722",
        "CVE-2025-21927",
        "CVE-2025-22070",
        "CVE-2025-22104",
        "CVE-2025-22113",
        "CVE-2025-22127",
        "CVE-2025-23131",
        "CVE-2025-23132",
        "CVE-2025-37833",
        "CVE-2025-38203",
        "CVE-2025-38204",
        "CVE-2025-38206",
        "CVE-2025-38237",
        "CVE-2025-38248",
        "CVE-2025-38264",
        "CVE-2025-38502",
        "CVE-2025-38678",
        "CVE-2025-39682",
        "CVE-2025-39702",
        "CVE-2025-39711",
        "CVE-2025-39746",
        "CVE-2025-39790",
        "CVE-2025-39833",
        "CVE-2025-39866",
        "CVE-2025-39946",
        "CVE-2025-39964",
        "CVE-2025-40018",
        "CVE-2025-40019",
        "CVE-2025-40020",
        "CVE-2025-40106",
        "CVE-2025-40214",
        "CVE-2025-40215",
        "CVE-2025-40297",
        "CVE-2025-40307",
        "CVE-2025-40325",
        "CVE-2025-40355",
        "CVE-2025-68745",
        "CVE-2026-23112",
        "CVE-2026-23361",
        "CVE-2026-31402",
        "CVE-2026-31449",
        "CVE-2026-31450",
        "CVE-2026-31523",
        "CVE-2026-31530",
        "CVE-2026-31693",
        "CVE-2026-31705",
        "CVE-2026-31708",
        "CVE-2026-31711",
        "CVE-2026-31714",
        "CVE-2026-31716",
        "CVE-2026-43046",
        "CVE-2026-43053",
        "CVE-2026-43066",
        "CVE-2026-43068",
        "CVE-2026-43074",
        "CVE-2026-43125",
        "CVE-2026-43153",
        "CVE-2026-43168",
        "CVE-2026-43200",
        "CVE-2026-43211",
        "CVE-2026-43262",
        "CVE-2026-43288",
        "CVE-2026-43299",
        "CVE-2026-43338",
        "CVE-2026-43350",
        "CVE-2026-43359",
        "CVE-2026-43360",
        "CVE-2026-43361",
        "CVE-2026-43362",
        "CVE-2026-43366",
        "CVE-2026-43376",
        "CVE-2026-43377",
        "CVE-2026-43379",
        "CVE-2026-43414",
        "CVE-2026-43419",
        "CVE-2026-43420",
        "CVE-2026-43448",
        "CVE-2026-43449",
        "CVE-2026-46333"
      ],
      "raw_pub_date": "Fri, 24 Jul 2026 17:48:00 +0800",
      "solution": "请您尽快将升级到修复后的版本。修复命令如下:\nyum update --advisory ALINUX4-SA-2026:0333"
    }
    阿里云 Linux 安全公告 cve:cve-2023-52590 cve:cve-2024-39478 cve:cve-2024-41082 cve:cve-2024-58094 cve:cve-2024-58095 cve:cve-2025-21722 cve:cve-2025-21927 cve:cve-2025-22070 cve:cve-2025-22104 cve:cve-2025-22113 cve:cve-2025-22127 cve:cve-2025-23131 cve:cve-2025-23132 cve:cve-2025-37833 cve:cve-2025-38203 cve:cve-2025-38204 cve:cve-2025-38206 cve:cve-2025-38237 cve:cve-2025-38248 cve:cve-2025-38264 cve:cve-2025-38502 cve:cve-2025-38678 cve:cve-2025-39682 cve:cve-2025-39702 cve:cve-2025-39711 cve:cve-2025-39746 cve:cve-2025-39790 cve:cve-2025-39833 cve:cve-2025-39866 cve:cve-2025-39946 cve:cve-2025-39964 cve:cve-2025-40018 cve:cve-2025-40019 cve:cve-2025-40020 cve:cve-2025-40106 cve:cve-2025-40214 cve:cve-2025-40215 cve:cve-2025-40297 cve:cve-2025-40307 cve:cve-2025-40325 cve:cve-2025-40355 cve:cve-2025-68745 cve:cve-2026-23112 cve:cve-2026-23361 cve:cve-2026-31402 cve:cve-2026-31449 cve:cve-2026-31450 cve:cve-2026-31523 cve:cve-2026-31530 cve:cve-2026-31693 cve:cve-2026-31705 cve:cve-2026-31708 cve:cve-2026-31711 cve:cve-2026-31714 cve:cve-2026-31716 cve:cve-2026-43046 cve:cve-2026-43053 cve:cve-2026-43066 cve:cve-2026-43068 cve:cve-2026-43074 cve:cve-2026-43125 cve:cve-2026-43153 cve:cve-2026-43168 cve:cve-2026-43200 cve:cve-2026-43211 cve:cve-2026-43262 cve:cve-2026-43288 cve:cve-2026-43299 cve:cve-2026-43338 cve:cve-2026-43350 cve:cve-2026-43359 cve:cve-2026-43360 cve:cve-2026-43361 cve:cve-2026-43362 cve:cve-2026-43366 cve:cve-2026-43376 cve:cve-2026-43377 cve:cve-2026-43379 cve:cve-2026-43414 cve:cve-2026-43419 cve:cve-2026-43420 cve:cve-2026-43448 cve:cve-2026-43449 cve:cve-2026-46333 severity:important type:advisory vendor:alibaba cve official_advisory vendor-update
  • ALINUX4-SA-2026:0334

    发布时间 2026-07-24 17:46 (UTC+08:00) 抓取时间 2026-07-24 18:00 (UTC+08:00)

    Package updates are available for Alibaba Cloud Linux 4 that fix the following vulnerabilities: CVE-2026-43499: In the Linux kernel, the following vulnerability has been resolved:rtmutex: Use waiter::task instead of current in remove_waiter()remove_waiter() is used by the slowlock paths, but it is also used forproxy-lock rollback in rt_mutex_start_proxy_loc

    扩展字段
    {
      "advisory_id": "ALINUX4-SA-2026:0334",
      "affected_products": [
        "Alinux 4"
      ],
      "cve_ids": [
        "CVE-2026-43499",
        "CVE-2026-43503",
        "CVE-2026-46242",
        "CVE-2026-46331",
        "CVE-2026-53166"
      ],
      "raw_pub_date": "Fri, 24 Jul 2026 17:46:42 +0800",
      "solution": "请您尽快将升级到修复后的版本。修复命令如下:\nyum update --advisory ALINUX4-SA-2026:0334"
    }
    阿里云 Linux 安全公告 cve:cve-2026-43499 cve:cve-2026-43503 cve:cve-2026-46242 cve:cve-2026-46331 cve:cve-2026-53166 severity:important type:advisory vendor:alibaba cve official_advisory vendor-update
  • ALINUX4-SA-2026:0335

    发布时间 2026-07-24 17:46 (UTC+08:00) 抓取时间 2026-07-24 18:00 (UTC+08:00)

    Package updates are available for Alibaba Cloud Linux 4 that fix the following vulnerabilities: CVE-2026-53359: In the Linux kernel, the following vulnerability has been resolved:KVM: x86: Fix shadow paging use-after-free due to unexpected roleCommit 0cb2af2ea66ad ("KVM: x86: Fix shadow paging use-after-free dueto unexpected GFN") fixed a shadow paging mism

    扩展字段
    {
      "advisory_id": "ALINUX4-SA-2026:0335",
      "affected_products": [
        "Alinux 4"
      ],
      "cve_ids": [
        "CVE-2026-53359"
      ],
      "raw_pub_date": "Fri, 24 Jul 2026 17:46:35 +0800",
      "solution": "请您尽快将升级到修复后的版本。修复命令如下:\nyum update --advisory ALINUX4-SA-2026:0335"
    }
    阿里云 Linux 安全公告 cve:cve-2026-53359 severity:important type:advisory vendor:alibaba cve official_advisory vendor-update
  • ALINUX4-SA-2026:0307

    发布时间 2026-07-23 16:08 (UTC+08:00) 抓取时间 2026-07-23 18:00 (UTC+08:00)

    Package updates are available for Alibaba Cloud Linux 4 that fix the following vulnerabilities: CVE-2026-54369: acl before version 2.4.0 contains a symlink traversal vulnerability in the libacl pathname-based functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() that allows local attackers to escalate privileges by replaci

    扩展字段
    {
      "advisory_id": "ALINUX4-SA-2026:0307",
      "affected_products": [
        "Alinux 4"
      ],
      "cve_ids": [
        "CVE-2026-54369"
      ],
      "raw_pub_date": "Thu, 23 Jul 2026 16:08:00 +0800",
      "solution": "请您尽快将升级到修复后的版本。修复命令如下:\nyum update --advisory ALINUX4-SA-2026:0307"
    }
    阿里云 Linux 安全公告 cve:cve-2026-54369 severity:important type:advisory vendor:alibaba cve official_advisory vendor-update
  • ALINUX4-SA-2026:0308

    发布时间 2026-07-23 16:07 (UTC+08:00) 抓取时间 2026-07-23 18:00 (UTC+08:00)

    Package updates are available for Alibaba Cloud Linux 4 that fix the following vulnerabilities: CVE-2026-56208: A heap buffer overflow vulnerability was found in libaom, the reference AV1 codec implementation. A flaw in the AV1 encoder's Look-Ahead Processing (LAP) mode causes the first-pass stats ring buffer wrap-around guard to be bypassed when g_lag_in_f

    扩展字段
    {
      "advisory_id": "ALINUX4-SA-2026:0308",
      "affected_products": [
        "Alinux 4"
      ],
      "cve_ids": [
        "CVE-2026-56208",
        "CVE-2026-56209",
        "CVE-2026-56210",
        "CVE-2026-56211"
      ],
      "raw_pub_date": "Thu, 23 Jul 2026 16:07:48 +0800",
      "solution": "请您尽快将升级到修复后的版本。修复命令如下:\nyum update --advisory ALINUX4-SA-2026:0308"
    }
    阿里云 Linux 安全公告 cve:cve-2026-56208 cve:cve-2026-56209 cve:cve-2026-56210 cve:cve-2026-56211 severity:important type:advisory vendor:alibaba cve official_advisory vendor-update
  • ALINUX4-SA-2026:0309

    发布时间 2026-07-23 16:07 (UTC+08:00) 抓取时间 2026-07-23 18:00 (UTC+08:00)

    Package updates are available for Alibaba Cloud Linux 4 that fix the following vulnerabilities: CVE-2025-61729: Within HostnameError.Error(), when constructing an error string, there is no limit to the number of hosts that will be printed out. Furthermore, the error string is constructed by repeated string concatenation, leading to quadratic runtime. Theref

    扩展字段
    {
      "advisory_id": "ALINUX4-SA-2026:0309",
      "affected_products": [
        "Alinux 4"
      ],
      "cve_ids": [
        "CVE-2025-61729"
      ],
      "raw_pub_date": "Thu, 23 Jul 2026 16:07:28 +0800",
      "solution": "请您尽快将升级到修复后的版本。修复命令如下:\nyum update --advisory ALINUX4-SA-2026:0309"
    }
    阿里云 Linux 安全公告 cve:cve-2025-61729 severity:important type:advisory vendor:alibaba cve official_advisory vendor-update
  • ALINUX4-SA-2026:0310

    发布时间 2026-07-23 16:07 (UTC+08:00) 抓取时间 2026-07-23 18:00 (UTC+08:00)

    Package updates are available for Alibaba Cloud Linux 4 that fix the following vulnerabilities: CVE-2025-2296: EDK2 contains a vulnerability in BIOS where an attacker may cause “ Improper Input Validation” by local access. Successful exploitation of this vulnerability could alter control flow in unexpected ways, potentially allowing arbitrary command execut

    扩展字段
    {
      "advisory_id": "ALINUX4-SA-2026:0310",
      "affected_products": [
        "Alinux 4"
      ],
      "cve_ids": [
        "CVE-2025-2296"
      ],
      "raw_pub_date": "Thu, 23 Jul 2026 16:07:24 +0800",
      "solution": "请您尽快将升级到修复后的版本。修复命令如下:\nyum update --advisory ALINUX4-SA-2026:0310"
    }
    阿里云 Linux 安全公告 cve:cve-2025-2296 severity:important type:advisory vendor:alibaba cve official_advisory vendor-update
  • ALINUX4-SA-2026:0311

    发布时间 2026-07-23 16:07 (UTC+08:00) 抓取时间 2026-07-23 20:00 (UTC+08:00)

    Package updates are available for Alibaba Cloud Linux 4 that fix the following vulnerabilities: CVE-2026-50219: libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_ParserFree, or XML_ParserReset from within handlers in cases of a policy violation. Thus, a use-after-free can occur, CVE-2026-561

    扩展字段
    {
      "advisory_id": "ALINUX4-SA-2026:0311",
      "affected_products": [
        "Alinux 4"
      ],
      "cve_ids": [
        "CVE-2026-50219",
        "CVE-2026-56131",
        "CVE-2026-56406"
      ],
      "raw_pub_date": "Thu, 23 Jul 2026 16:07:13 +0800",
      "solution": "请您尽快将升级到修复后的版本。修复命令如下:\nyum update --advisory ALINUX4-SA-2026:0311"
    }
    阿里云 Linux 安全公告 cve:cve-2026-50219 cve:cve-2026-56131 cve:cve-2026-56406 severity:moderate type:advisory vendor:alibaba cve official_advisory vendor-update