SecLens 情报中心

网安资讯,一网打尽。汇集权威漏洞通告与行业要闻,结合分组浏览、智能过滤、RSS订阅 和 Webhook 推送,多通道拓展您的安全情报视野。

厂商发布

厂商对产品安全、配置或策略的更新说明。

  • CVE-2026-46331

    发布时间 2026-07-24 17:46 (UTC+08:00) 抓取时间 2026-07-24 18:10 (UTC+08:00)

    In the Linux kernel, the following vulnerability has been resolved:net/sched: fix pedit partial COW leading to page cache corruptiontcf_pedit_act() computes the COW range for skb_ensure_writable()once before the key loop using tcfp_off_max_hint, but the hint doesnot account for the runtime header offset added by typed keys. Thiscan leave part of the write re

    扩展字段
    {
      "cve_id": "CVE-2026-46331",
      "raw_pub_date": "Fri, 24 Jul 2026 17:46:41 +0800"
    }
    阿里云 Linux CVE 通知 cve:cve-2026-46331 type:cve vendor:alibaba cve vendor-update
  • CVE-2026-46242

    发布时间 2026-07-24 17:46 (UTC+08:00) 抓取时间 2026-07-24 18:10 (UTC+08:00)

    In the Linux kernel, the following vulnerability has been resolved:eventpoll: fix ep_remove struct eventpoll / struct file UAFep_remove() (via ep_remove_file()) cleared file->f_ep underfile->f_lock but then kept using @file inside the critical section(is_file_epoll(), hlist_del_rcu() through the head, spin_unlock).A concurrent __fput() taking the eventpoll_r

    扩展字段
    {
      "cve_id": "CVE-2026-46242",
      "raw_pub_date": "Fri, 24 Jul 2026 17:46:40 +0800"
    }
    阿里云 Linux CVE 通知 cve:cve-2026-46242 type:cve vendor:alibaba cve vendor-update
  • CVE-2026-53359

    发布时间 2026-07-24 17:46 (UTC+08:00) 抓取时间 2026-07-24 18:10 (UTC+08:00)

    In the Linux kernel, the following vulnerability has been resolved:KVM: x86: Fix shadow paging use-after-free due to unexpected roleCommit 0cb2af2ea66ad ("KVM: x86: Fix shadow paging use-after-free dueto unexpected GFN") fixed a shadow paging mismatch between stored andcomputed GFNs; the bug could be triggered by changing a PDE mapping fromoutside the guest,

    扩展字段
    {
      "cve_id": "CVE-2026-53359",
      "raw_pub_date": "Fri, 24 Jul 2026 17:46:35 +0800"
    }
    阿里云 Linux CVE 通知 cve:cve-2026-53359 type:cve vendor:alibaba cve vendor-update
  • CVE-2026-54369

    发布时间 2026-07-23 16:07 (UTC+08:00) 抓取时间 2026-07-23 16:10 (UTC+08:00)

    acl before version 2.4.0 contains a symlink traversal vulnerability in the libacl pathname-based functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() that allows local attackers to escalate privileges by replacing any pathname component with a symbolic link. Attackers who control any component of a pathname processed by a

    扩展字段
    {
      "cve_id": "CVE-2026-54369",
      "raw_pub_date": "Thu, 23 Jul 2026 16:07:59 +0800"
    }
    阿里云 Linux CVE 通知 cve:cve-2026-54369 type:cve vendor:alibaba cve vendor-update
  • CVE-2026-56211

    发布时间 2026-07-23 16:07 (UTC+08:00) 抓取时间 2026-07-24 00:10 (UTC+08:00)

    A remote code execution vulnerability was found in libaom, the reference AV1 codec implementation. Insufficient bounds validation in the AV1 encoder's SVC (Scalable Video Coding) layer ID control allows an attacker to supply crafted video frame pixels that overlap with internal encoder layer context structures. In fork-based video processing services, an att

    扩展字段
    {
      "cve_id": "CVE-2026-56211",
      "raw_pub_date": "Thu, 23 Jul 2026 16:07:47 +0800"
    }
    阿里云 Linux CVE 通知 cve:cve-2026-56211 type:cve vendor:alibaba cve vendor-update
  • CVE-2026-56210

    发布时间 2026-07-23 16:07 (UTC+08:00) 抓取时间 2026-07-23 16:10 (UTC+08:00)

    A heap-buffer-overflow read vulnerability was found in libaom, the reference AV1 codec implementation. A missing bounds check in the SVC (Scalable Video Coding) layer ID control function allows setting a spatial_layer_id exceeding the configured number of layers. This causes an out-of-bounds heap read of approximately 40,728 bytes when computing a layer cont

    扩展字段
    {
      "cve_id": "CVE-2026-56210",
      "raw_pub_date": "Thu, 23 Jul 2026 16:07:46 +0800"
    }
    阿里云 Linux CVE 通知 cve:cve-2026-56210 type:cve vendor:alibaba cve vendor-update
  • CVE-2026-56209

    发布时间 2026-07-23 16:07 (UTC+08:00) 抓取时间 2026-07-23 18:10 (UTC+08:00)

    An arbitrary address write vulnerability was found in libaom, the reference AV1 codec implementation. A missing bounds check in the SVC (Scalable Video Coding) layer ID control function allows an attacker to inject an arbitrary pointer into the cyclic refresh map field via crafted image pixel values. The encoder then writes approximately 1,200 bytes at the a

    扩展字段
    {
      "cve_id": "CVE-2026-56209",
      "raw_pub_date": "Thu, 23 Jul 2026 16:07:45 +0800"
    }
    阿里云 Linux CVE 通知 cve:cve-2026-56209 type:cve vendor:alibaba cve vendor-update
  • CVE-2026-56208

    发布时间 2026-07-23 16:07 (UTC+08:00) 抓取时间 2026-07-23 18:10 (UTC+08:00)

    A heap buffer overflow vulnerability was found in libaom, the reference AV1 codec implementation. A flaw in the AV1 encoder's Look-Ahead Processing (LAP) mode causes the first-pass stats ring buffer wrap-around guard to be bypassed when g_lag_in_frames is set to 1 or higher. This results in a 232-byte out-of-bounds write on every encoded frame after the seco

    扩展字段
    {
      "cve_id": "CVE-2026-56208",
      "raw_pub_date": "Thu, 23 Jul 2026 16:07:44 +0800"
    }
    阿里云 Linux CVE 通知 cve:cve-2026-56208 type:cve vendor:alibaba cve vendor-update