Microsoft Security Response Center 中文 关注 微软网络安全和合规博客:了解微软网络安全专家的最佳实践、更新和见解。微软安全响应中心(MSRC)为保护微软用户提供了最新和有价值的安全更新和漏洞信息。通过最新的博客文章,提高您的网络安全技能,并获取保护微软产品的最好建议。 RSS blogs.technet.microsoft.com Microsoft Security Response Center msrc.microsoft.com
CVE-2026-56434 NGINX ngx_http_ssi_module漏洞 CVE-2026-56434 NGINX ngx_http_ssi_module vulnerability msrc.microsoft.com
CVE-2026-42533 NGINX Map 指令和正则匹配漏洞” CVE-2026-42533 NGINX Map directive and Regex matching vulnerability msrc.microsoft.com
CVE-2026-39879 syslog-ng SQL 目的地驱动程序中的 SQL 注入漏洞 CVE-2026-39879 SQL injection in syslog-ng SQL destionation driver msrc.microsoft.com
CVE-2026-64191 i2c: stub: 拒绝具有无效长度的 I2C 块传输” CVE-2026-64191 i2c: stub: Reject I2C block transfers with invalid length msrc.microsoft.com
CVE-2026-64188 net: qualcomm: rmnet: 修复 rmnet_dellink() 中的端点释放后使用问题 CVE-2026-64188 net: qualcomm: rmnet: fix endpoint use-after-free in rmnet_dellink() msrc.microsoft.com
CVE-2026-64189 netfilter: ipset: 修复 dump 与 ip_set_list 调整大小之间的竞态条件” CVE-2026-64189 netfilter: ipset: fix race between dump and ip_set_list resize msrc.microsoft.com
CVE-2026-64206 Bluetooth: L2CAP: 在获取 conn->lock 之前取消 pending_rx_work CVE-2026-64206 Bluetooth: L2CAP: cancel pending_rx_work before taking conn->lock msrc.microsoft.com
CVE-2026-64190 net: team: 修复 team_xmit 在模式切换期间发生的空指针解引用” CVE-2026-64190 net: team: fix NULL pointer dereference in team_xmit during mode change msrc.microsoft.com
CVE-2026-64205 i2c: i801: 修复错误路径中的硬件状态机损坏问题” CVE-2026-64205 i2c: i801: fix hardware state machine corruption in error path msrc.microsoft.com
CVE-2026-64192 bpf:若 BPF LSM 未初始化,则拒绝创建 BPF_MAP_TYPE_INODE_STORAGE CVE-2026-64192 bpf: Reject BPF_MAP_TYPE_INODE_STORAGE creation if BPF LSM is uninitialized msrc.microsoft.com
CVE-2026-64187 xfs:在具有无区域的已提交日志项上失败恢复” CVE-2026-64187 xfs: fail recovery on a committed log item with no regions msrc.microsoft.com
CVE-2026-26199:当 size 为零时,H5Iget_name/H5G_get_name 中的缓冲区下溢 CVE-2026-26199 Buffer underflow in `H5Iget_name `/`H5G_get_name` if size is zero msrc.microsoft.com
CVE-2026-26197 在 H5Odtype.c 中未检查数组的全尺寸、元素计数和元素大小是否匹配” CVE-2026-26197 Array full size, element count, and element size are not checked to make sure they match in H5Odtype.c msrc.microsoft.com
CVE-2026-3842 Qemu-kvm: hyperv/syndbg: cpu_physical_memory_map 之后缺少映射长度保护,导致主机越界写入 CVE-2026-3842 Qemu-kvm: hyperv/syndbg: missing mapped-length guard after cpu_physical_memory_map causes host oob write msrc.microsoft.com
CVE-2026-38755 Busybox v1.38.0 中 shell/ash.c 的 evalcommand() 函数存在堆溢出漏洞,攻击者可通过提供精心构造的输入引发拒绝服务(DoS)。 CVE-2026-38755 A heap overflow in the evalcommand() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input. msrc.microsoft.com
CVE-2026-38754 Busybox v1.38.0 中 ifsbreakup() 函数(shell/ash.c)存在堆溢出漏洞,攻击者可通过提供精心构造的输入引发拒绝服务(DoS)。” CVE-2026-38754 A heap overflow in the ifsbreakup() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input. msrc.microsoft.com
CVE-2026-42770 FFC-DH 对等体验证使用攻击者提供的 q CVE-2026-42770 FFC-DH Peer Validation Uses Attacker-Supplied q msrc.microsoft.com
CVE-2026-38752 BusyBox 提交 371fe9 中 editors/awk.c 的 evaluate() 函数存在栈溢出漏洞,攻击者可通过提供精心构造的 AWK 脚本引发拒绝服务(DoS)。 CVE-2026-38752 A stack overflow in the evaluate() function (editors/awk.c) of BusyBox commit 371fe9 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AWK script. msrc.microsoft.com
CVE-2026-38753 Busybox v1.38.0 中 awk_sub() 函数(位于 editors/awk.c)存在释放后使用漏洞,攻击者可通过提供精心构造的 AWK 脚本引发拒绝服务(DoS)。 CVE-2026-38753 A use-after-free in the awk_sub() function (editors/awk.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AWK script. msrc.microsoft.com
CVE-2026-64082 riscv:修复因错误时未初始化的 cregs 导致的寄存器损坏” CVE-2026-64082 riscv: Fix register corruption from uninitialized cregs on error msrc.microsoft.com
CVE-2026-64146 erofs:修复 inode 扩展属性初始化中的 metabuf 泄漏 CVE-2026-64146 erofs: fix metabuf leak in inode xattr initialization msrc.microsoft.com
CVE-2026-63974 Bluetooth: hci_sync:在设备关闭期间设置 HCI_CMD_DRAIN_WORKQUEUE CVE-2026-63974 Bluetooth: hci_sync: Set HCI_CMD_DRAIN_WORKQUEUE during device close msrc.microsoft.com
CVE-2026-63978 net/handshake:在 net 命名空间退出时排空待处理请求” CVE-2026-63978 net/handshake: Drain pending requests at net namespace exit msrc.microsoft.com
CVE-2026-63999 ethtool: rss:修复 get_rxfh 失败时 indir_table 和 hkey 的泄漏问题 CVE-2026-63999 ethtool: rss: fix indir_table and hkey leak on get_rxfh failure msrc.microsoft.com
CVE-2026-64017 blk-mq:若缓存请求可用则弹出” CVE-2026-64017 blk-mq: pop cached request if it is usable msrc.microsoft.com
CVE-2026-63979 net/handshake: 将已固定的文件引用移交至 accept_doit CVE-2026-63979 net/handshake: hand off the pinned file reference to accept_doit msrc.microsoft.com
CVE-2026-64060 netfs:修复 netfs_write_begin() 错误处理中的请求泄漏问题” CVE-2026-64060 netfs: Fix leak of request in netfs_write_begin() error handling msrc.microsoft.com
CVE-2026-64076 netfilter: bridge: eb_tables: 关闭模块初始化竞态 CVE-2026-64076 netfilter: bridge: eb_tables: close module init race msrc.microsoft.com
CVE-2026-64112 rbd:消除 unmap 时 lock_dwork 排空中的竞态条件” CVE-2026-64112 rbd: eliminate a race in lock_dwork draining on unmap msrc.microsoft.com
CVE-2026-63882 drm/amdkfd:修复 svm_range_set_attr 中的空指针错误” CVE-2026-63882 drm/amdkfd: fix NULL pointer bug in svm_range_set_attr msrc.microsoft.com
CVE-2026-64154 drm/msm/adreno:修复 a6xx_gpu_init() 中的引用泄漏” CVE-2026-64154 drm/msm/adreno: Fix a reference leak in a6xx_gpu_init() msrc.microsoft.com
CVE-2026-64111 lsm:在 lsm_set_self_attr() 期间持有 cred_guard_mutex CVE-2026-64111 lsm: hold cred_guard_mutex for lsm_set_self_attr() msrc.microsoft.com
CVE-2026-63879 drm/amdgpu:修复amdgpu_hmm_range_get_pages CVE-2026-63879 drm/amdgpu: fix amdgpu_hmm_range_get_pages msrc.microsoft.com
CVE-2026-63963 usb: typec: tcpm: 在 Discover Identity ACK 处理器中验证 VDO 计数” CVE-2026-63963 usb: typec: tcpm: validate VDO count in Discover Identity ACK handlers msrc.microsoft.com
CVE-2026-63961 usb: typec: altmodes/displayport: 读取状态更新 VDO 前验证计数 CVE-2026-63961 usb: typec: altmodes/displayport: validate count before reading Status Update VDO msrc.microsoft.com
CVE-2026-63881 drm/amdkfd:修复 kfd 调试器中的整数溢出漏洞” CVE-2026-63881 drm/amdkfd: fix a vulnerability of integer overflow in kfd debugger msrc.microsoft.com
CVE-2026-63960 usb: typec: wcove: 在 wcove_read_rx_buffer() 中不要向 struct pd_message 结构体之外写入数据” CVE-2026-63960 usb: typec: wcove: don't write past struct pd_message in wcove_read_rx_buffer() msrc.microsoft.com
CVE-2026-63964 usb: typec: ucsi: ccg:拒绝缺少':'记录头的固件镜像 CVE-2026-63964 usb: typec: ucsi: ccg: reject firmware images without a ':' record header msrc.microsoft.com
CVE-2026-63983 net/sched: 修复 netem 在启用 duplicate 时的数据包循环问题” CVE-2026-63983 net/sched: fix packet loop on netem when duplicate is on msrc.microsoft.com
CVE-2026-64077 netfilter: ebtables: 移至两阶段移除方案” CVE-2026-64077 netfilter: ebtables: move to two-stage removal scheme msrc.microsoft.com
CVE-2026-63940 KVM: SEV:忽略长度为"0"的端口 I/O 请求 CVE-2026-63940 KVM: SEV: Ignore Port I/O requests of length '0' msrc.microsoft.com
CVE-2026-64078 netfilter: x_tables: 添加并使用 xtables_unregister_table_exit CVE-2026-64078 netfilter: x_tables: add and use xtables_unregister_table_exit msrc.microsoft.com
CVE-2026-64097 drm/amd/display:在迭代前验证 GPIO 引脚 LUT 表大小” CVE-2026-64097 drm/amd/display: Validate GPIO pin LUT table size before iterating msrc.microsoft.com
CVE-2026-63954 hpfs:修复 hpfs_map_dnode_bitmap 失败时导致的崩溃” CVE-2026-63954 hpfs: fix a crash if hpfs_map_dnode_bitmap fails msrc.microsoft.com
CVE-2026-64117 wifi: mac80211: 在 mesh 重用 skb->cb 之前捕获 fast-RX 速率 CVE-2026-64117 wifi: mac80211: capture fast-RX rate before mesh reuses skb->cb msrc.microsoft.com
CVE-2026-63958 usb: typec: ucsi: 在 ucsi_connector_change() 中验证连接器编号” CVE-2026-63958 usb: typec: ucsi: validate connector number in ucsi_connector_change() msrc.microsoft.com
CVE-2026-63962 usb: typec: tcpm: 在 svdm_consume_modes() 中每次迭代绑定 altmode_desc[] CVE-2026-63962 usb: typec: tcpm: bound altmode_desc[] per iteration in svdm_consume_modes() msrc.microsoft.com
CVE-2026-64015 security/keys:修复查找时遗漏的 RCU 读区段” CVE-2026-64015 security/keys: fix missed RCU read section on lookup msrc.microsoft.com
CVE-2026-64070 powerpc/hv-gpci:修复 sysfs 显示路径中的抢占计数泄漏” CVE-2026-64070 powerpc/hv-gpci: fix preempt count leak in sysfs show paths msrc.microsoft.com
CVE-2026-63959 usb: typec: tcpm/tcpci_maxim:验证 NDO 头部与 RX_BYTE_CNT CVE-2026-63959 usb: typec: tcpm/tcpci_maxim: validate header NDO against RX_BYTE_CNT msrc.microsoft.com