🔴 严重 | CVE-2026-53002 — In the Linux kernel, the following vulnerability h...
🔴 《严重安全漏洞:CVE-2026-53002》
CVSS 评分: 严重(9.8) 状态: Received 发布时间: 2026-06-24
英文原文描述
In the Linux kernel, the following vulnerability has been resolved:
netfilter: conntrack: remove sprintf usage
Replace it with scnprintf, the buffer sizes are expected to be large enough
to hold the result, no need for snprintf+overflow check.
Increase buffer size in mangle_content_len() while at it.
BUG: KASAN: stack-out-of-bounds in vsnprintf+0xea5/0x1270
Write of size 1 at addr [..]
vsnprintf+0xea5/0x1270
sprintf+0xb1/0xe0
mangle_content_len+0x1ac/0x280
nf_nat_sdp_session+0x1cc/0x240
process_sdp+0x8f8/0xb80
process_invite_request+0x108/0x2b0
process_sip_msg+0x5da/0xf50
sip_help_tcp+0x45e/0x780
nf_confirm+0x34d/0x990
[..]
🔍 技术细节
| 字段 | 值 |
|---|---|
| CVE ID | CVE-2026-53002 |
| CVSS 评分 | 9.8 🔴 |
| 严重程度 | 严重 |
| CVSS 向量 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| 发布时间 | 2026-06-24 |
| 最后更新 | 2026-06-28 |
| 状态 | Received |
| 数据来源 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
🔗 参考链接
https://git.kernel.org/stable/c/1c9fb8aeed06790d42cdcd00f6c3ce0b9e926c1e
https://git.kernel.org/stable/c/2f793ba78470a99f40389b7dc60a81d9f5ad3956
https://git.kernel.org/stable/c/6bbf829b4c1b44c941c47dd0d710f1393258f3d5
https://git.kernel.org/stable/c/6e7066bdb481a87fe88c4fa563e348c03b2d373d
https://git.kernel.org/stable/c/8e3be0d12615a173fe260cd42753ca7a001acbf2
https://git.kernel.org/stable/c/a8e0a32a23d3f34862af3b4da792ecb3a891a9a3
https://git.kernel.org/stable/c/ab64e61c9323fa6de21bd20da1ddb29a0fb65d34
https://git.kernel.org/stable/c/c08ff52e44945e6ef4ce0790f49ea761b060c45b
🤖 本文由 CVE 安全快讯机器人自动生成
英文描述已由 AI 自动翻译为中文,仅供参考,请以原文为准
数据来源: NVD (National Vulnerability Database) | 获取时间: 2026-06-28 18:14