Amazon Linux 2:核心, --advisory ALAS2KERNEL-5。15-2026-107(ALASKERNEL-5。15-2026-107

high Nessus Plugin ID 322048

概要

遠端 Amazon Linux 2 主機缺少安全性更新。

說明

遠端主機上安裝的核心版本早於 5.15.209-147.245。因此,會受到 ALAS2KERNEL-5.15-2026-107 公告中所提及的多個弱點影響。

在 Linux 核心中,下列弱點已解決:

blk-mq:重新初始化佇列時使用靜止的電梯開關 (CVE-2022-50552)

在 Linux 核心中,下列弱點已解決:

net:變更 skb 通訊協定時清除 dst (CVE-2025-38192)

在 Linux 核心中,下列弱點已解決:

binfmt_misc:在關閉 open_exec()CVE-2025-68239 () 開啟的檔案之前還原寫入存取權

在 Linux 核心中,下列弱點已解決:

btrfs:不嚴格要求中繼資料寫入頁面的中繼資料閾值 (CVE-2026-23157)

在 Linux 核心中,下列弱點已解決:

net/sched: cls_u32:使用 skb_header_pointer_careful() (CVE-2026-23204)

在 Linux 核心中,下列弱點已解決:

netfilter: nf_tables:在插入 (CVE-2026-23272) 之前無條件地碰撞 set->nelems

在 Linux 核心中,下列弱點已解決:

nf_tables: nft_dynset:修正錯誤路徑 (CVE-2026-23399) 中可能的有狀態運算式 memleak

在 Linux 核心中,下列弱點已解決:

ipv6:在 SRv6 路徑中新增 idev 的 NULL 檢查 (CVE-2026-23442)

在 Linux 核心中,下列弱點已解決:

netfilter: conntrack:新增缺少的網路連結原則驗證 (CVE-2026-31407)

在 Linux 核心中,下列弱點已解決:

spi: meson-spicc:修正移除路徑 (CVE-2026-31489) 中的雙重放置

在 Linux 核心中,下列弱點已解決:

can:raw:修正 raw_rcv() 中的 ro->uniq 釋放後使用 (CVE-2026-31532)

在 Linux 核心中,下列弱點已解決:

nilfs2:修正 nilfs_mdt_save_to_shadow_map 中的 NULL i_assoc_inode取消參照 (CVE-2026-31577)

在 Linux 核心中,下列弱點已解決:

bcache:修正 cached_dev.sb_bio 釋放後使用和損毀 (CVE-2026-31580)

在 Linux 核心中,下列弱點已解決:

mm: blk-cgroup:修正 cgwb_release_workfn() 中的釋放後使用 (CVE-2026-31586)

在 Linux 核心中,下列弱點已解決:

KVM:x86:在 MMIO 片段中使用暫存欄位來保存小的寫入值 (CVE-2026-31588)

在 Linux 核心中,下列弱點已解決:

KVM:SEV:刪除 KVM_MEMORY_ENCRYPT_REG_REGION 大尺寸的 WARN (CVE-2026-31590)

在 Linux 核心中,下列弱點已解決:

media:vidtv:修正 vidtv_channel_pmt_match_sections 中的 NULL 指標解除參照 (CVE-2026-31599)

在 Linux 核心中,下列弱點已解決:

usbip:驗證 usbip_pack_ret_submit() 中的number_of_packets (CVE-2026-31607)

在 Linux 核心中,下列弱點已解決:

HID: core:在 s32ton() 中夾report_size以避免未定義的移位 (CVE-2026-31624)

在 Linux 核心中,下列弱點已解決:

xfrm:清除 build_polexpire() 中的尾端填充 (CVE-2026-31664)

在 Linux 核心中,下列弱點已解決:

af_unix:讀取 unix_state_lock (CVE-2026-31673) 下的UNIX_DIAG_VFS資料

在 Linux 核心中,下列弱點已解決:

netfilter: xt_multiport:驗證 checkentry (CVE-2026-31681) 中的範圍編碼

在 Linux 核心中,下列弱點已解決:

net: sched: act_csum:驗證巢狀 VLAN 標頭 (CVE-2026-31684)

在 Linux 核心中,下列弱點已解決:

netfilter: ip6t_eui64:拒絕所有封包的無效 MAC 標頭 (CVE-2026-31685)

在 Linux 核心中,下列弱點已解決:

rtnetlink:新增對等 netn 的遺漏 netlink_ns_capable() 檢查 (CVE-2026-31692)

在 Linux 核心中,下列弱點已解決:

fuse:拒絕頁面快取中過大的 dirents (CVE-2026-31694)

在 Linux 核心中,下列弱點已解決:

fs/ntfs3:驗證 rec->用於日誌重播檔案記錄檢查 (CVE-2026-31716)

在 Linux 核心中,下列弱點已解決:

perf/x86/intel/uncore:跳過離線晶片的探索表 (CVE-2026-43079)

在 Linux 核心中,下列弱點已解決:

netfilter: nfnetlink_log:初始化 NLMSG_DONE 終止符中的 nfgenmsg (CVE-2026-43085)

在 Linux 核心中,下列弱點已解決:

xfrm_user:修正 build_mapping()CVE-2026-43089 () 中的資訊洩露

在 Linux 核心中,下列弱點已解決:

xsk:加強 UMEM 餘量驗證,以考慮尾部空間和最小框架 (CVE-2026-43093)

在 Linux 核心中,下列弱點已解決:

ipv4: icmp:修正 icmp_build_probe() 中的 null-ptr-deref (CVE-2026-43099)

在 Linux 核心中,下列弱點已解決:

fs/smb/client:修正 cifs_sanitize_prepath (CVE-2026-43112) 中的越界讀取

在 Linux 核心中,下列弱點已解決:

netfilter: nft_set_pipapo_avx2:到期時不傳回不相符的項目 (CVE-2026-43114)

在 Linux 核心中,下列弱點已解決:

btrfs: tracepoints:在事件 btrfs_sync_file() (CVE-2026-43117) 中從 dentry 取得正確的超級區塊

在 Linux 核心中,下列弱點已解決:

信箱:防止 fw_mbox_index_xlate() 中的越界存取 (CVE-2026-43281)

在 Linux 核心中,下列弱點已解決:

cpufreq: governor:修正 cpufreq_dbs_governor_init() 錯誤路徑中的雙重釋放 (CVE-2026-43328)

在 Linux 核心中,下列弱點已解決:

crypto: pcrypt - 修正MAY_BACKLOG要求的處理 (CVE-2026-43493)

在 Linux 核心中,下列弱點已解決:

net/sched: sch_red:將直接出列呼叫替換為 peek 和 qdisc_dequeue_peeked (CVE-2026-43496)

在 Linux 核心中,下列弱點已解決:

net/rds:在訊息排入佇列之前處理 Zerocopy 傳送清理 (CVE-2026-43502)

在 Linux 核心中,下列弱點已解決:

bpf:修正 cgroup_storage_get_next_key() 中的清單結尾偵測 (CVE-2026-45838)

在 Linux 核心中,下列弱點已解決:

bpf:拒絕 bpf_core_parse_spec() 中的負 CO-RE 存取子索引 (CVE-2026-45839)

在 Linux 核心中,下列弱點已解決:

openvswitch:上限 upcall PID 陣列大小和預先大小 vport 回覆 (CVE-2026-45840)

在 Linux 核心中,下列弱點已解決:

netfilter: nfnetlink_osf:修正 OSF_WSS_MODULO 中的除以零 (CVE-2026-45841)

在 Linux 核心中,下列弱點已解決:

KVM: nSVM:在 L2 的 VMRUN 之後,將中斷影子同步至快取的 vmcb12 (CVE-2026-45987)

在 Linux 核心中,下列弱點已解決:

tcp:接聽程式移轉CVE-2026-46015後呼叫 sk_data_ready() ()

在 Linux 核心中,下列弱點已解決:

dm mirror:修正 create_dirty_log() 中的整數溢位 (CVE-2026-46023)

在 Linux 核心中,下列弱點已解決:

libceph:防止 ceph_handle_auth_reply() 中潛在的 null-ptr-deref (CVE-2026-46024)

在 Linux 核心中,下列弱點已解決:

crypto: authencesn - 在執行個體建立期間拒絕短 ahash 摘要 (CVE-2026-46033)

在 Linux 核心中,下列弱點已解決:

ipv4: icmp:使用 icmp_pointers (CVE-2026-46037) 之前先驗證回覆類型

在 Linux 核心中,下列弱點已解決:

inotify:修正 fsnotify_add_inode_mark_locked() 失敗時的監視計數洩漏 (CVE-2026-46040)

在 Linux 核心中,下列弱點已解決:

ext4:修正 ext4_xattr_inode_dec_ref_all()CVE-2026-46046 () 中缺少的 brelse()

在 Linux 核心中,下列弱點已解決:

md/raid10:修正 check operation 和 nowait 要求 (CVE-2026-46050) 的鎖死

在 Linux 核心中,下列弱點已解決:

md/raid5:修正 retry_aligned_read() 中的軟鎖定 (CVE-2026-46051)

在 Linux 核心中,下列弱點已解決:

net:rds:修正複製錯誤 (CVE-2026-46053) 上的 MR 清除

在 Linux 核心中,下列弱點已解決:

ntfs3:修正 run_unpack() 磁碟區邊界檢查 () 中的整數溢位 (CVE-2026-46062)

在 Linux 核心中,下列弱點已解決:

md/raid5:在存取日誌中繼資料之前驗證承載大小 (CVE-2026-46070)

在 Linux 核心中,下列弱點已解決:

ntfs3:將緩衝區邊界檢查新增至 run_unpack() (CVE-2026-46072)

在 Linux 核心中,下列弱點已解決:

KVM: SVM:如果是 EFER,則為 INVLPGA 注入 #UD。SVME=0 (CVE-2026-46082)

在 Linux 核心中,下列弱點已解決:

net: ipv6:修正 seg6 和 rpl lwtunnels 中的 NOREF dst 使用 (CVE-2026-46099)

在 Linux 核心中,下列弱點已解決:

netfilter:拒絕 nft_bitwise (CVE-2026-46101) 中的零移位

在 Linux 核心中,下列弱點已解決:

net: strparser:修正 strp_abort_strp() 中的skb_head洩露 (CVE-2026-46102)

在 Linux 核心中,下列弱點已解決:

dm-thin:修正中繼資料參照計數反向溢位 (CVE-2026-46107)

在 Linux 核心中,下列弱點已解決:

KVM: x86:修正由於意外的 GFN 而導致的影子分頁釋放後使用 (CVE-2026-46113)

在 Linux 核心中,下列弱點已解決:

libceph:修正驗證訊息處理中的 slab-out-of-bounds 存取 (CVE-2026-46119)

在 Linux 核心中,下列弱點已解決:

ip6_gre:在 ip6erspan_changelink() 中使用快取的 t->net。(CVE-2026-46120)

在 Linux 核心中,下列弱點已解決:

isofs:驗證 isofs_export_iget (CVE-2026-46124) 中 NFS 檔案控點的區塊編號

在 Linux 核心中,下列弱點已解決:

net:rtnetlink:零ifla_vf_broadcast以避免rtnl_fill_vfinfo中的堆疊資訊洩露 (CVE-2026-46132)

在 Linux 核心中,下列弱點已解決:

scsi:target:configfs:在 tg_pt_gp_members_show() 中傳回綁定 snprintf() (CVE-2026-46149)

在 Linux 核心中,下列弱點已解決:

fanotify:修正權限事件的誤報 (CVE-2026-46150)

在 Linux 核心中,下列弱點已解決:

md/raid10:修正 setup_geo() 中零far_copies除以零 (CVE-2026-46161)

在 Linux 核心中,下列弱點已解決:

mptcp:修正時間戳記 sockopt (CVE-2026-46168) 中不可部分完成的排程

在 Linux 核心中,下列弱點已解決:

ipv6: xfrm6:在 xfrm6_rcv_encap()CVE-2026-46172 () 中出錯時釋放 DST

在 Linux 核心中,下列弱點已解決:

drm/gem:修正 drm_gem_fb_init_with_funcs()CVE-2026-46209 () 中不一致的平面尺寸計算

在 Linux 核心中,下列弱點已解決:

vsock/virtio:修正傳輸不相符時的接受佇列計數洩漏 (CVE-2026-46214)

在 Linux 核心中,下列弱點已解決:

sctp:在 SCTP_SENDALL (CVE-2026-46227) 中 sctp_sendmsg_to_asoc() 之後重新驗證清單游標

在 Linux 核心中,下列弱點已解決:

VSOCK:修正緩衝區大小限制順序 (CVE-2026-46234)

在 Linux 核心中,下列弱點已解決:

io-wq:檢查前置任務是否在 io_wq_remove_pending() (CVE-2026-46274) 中雜湊處理

在 Linux 核心中,下列弱點已解決:

dm:修正 ioctl 處理中的緩衝區溢位 (CVE-2026-46294)

在 Linux 核心中,下列弱點已解決:

netfilter: nf_queue:佇列時保留橋接器 skb->dev (CVE-2026-52912)

在 Linux 核心中,下列弱點已解決:

netfilter: ip6t_hbh:拒絕過大的選項清單 (CVE-2026-52915)

在 Linux 核心中,下列弱點已解決:

netfilter: xt_policy:修正嚴格模式傳入原則比對 (CVE-2026-52920)

在 Linux 核心中,下列弱點已解決:

netfilter: ipset:停止雜湊:* 結束時的範圍反覆運算 (CVE-2026-52921)

在 Linux 核心中,下列弱點已解決:

vrf:修正從 VRF 移除連接埠時的潛在 NPD (CVE-2026-52925)

在 Linux 核心中,下列弱點已解決:

libceph:處理 decode_choose_args() 中的 rbtree 插入錯誤 (CVE-2026-52954)

在 Linux 核心中,下列弱點已解決:

libceph:修正 crush_decode() 中潛在的越界存取 (CVE-2026-52955)

在 Linux 核心中,下列弱點已解決:

libceph:修正 decode_choose_args() 中潛在的 null-ptr-deref (CVE-2026-52957)

在 Linux 核心中,下列弱點已解決:

libceph:修正 osdmap_decode() 中潛在的越界存取 (CVE-2026-52958)

在 Linux 核心中,下列弱點已解決:

Ceph:修正 __ceph_setxattr()CVE-2026-52962 () 中的緩衝區洩漏

在 Linux 核心中,下列弱點已解決:

KVM:拒絕 kvm_reset_dirty_gfn() 中的包裝偏移 (CVE-2026-52969)

在 Linux 核心中,下列弱點已解決:

netfilter: nft_ct:修正 obj eval (CVE-2026-52970) 中缺少的預期 put

在 Linux 核心中,下列弱點已解決:

crypto: af_alg - 將 AEAD AD 長度限制為 0x80000000 (CVE-2026-52972)

在 Linux 核心中,下列弱點已解決:

net/sched: netem:修正佇列限制檢查以包含重新排序的封包

netem_enqueue() 中的佇列限制檢查使用 q->t_len,它僅計算內部 tfifo 中的封包。
透過重新排序路徑 (__qdisc_enqueue_head) 放置在 sch->q 中的封包不會被計算在內,因此重新排序時允許總佇列佔用率超過 sch->limit。

在限制檢查中包括 sch->q.qlen。(CVE-2026-52984)

在 Linux 核心中,下列弱點已解決:

netdevsim:在虛擬sk_buff中初始化結構 iphdr 的零 (CVE-2026-52985)

在 Linux 核心中,下列弱點已解決:

netfilter: nf_conntrack_sip:不要使用 simple_strtoul (CVE-2026-52986)

在 Linux 核心中,下列弱點已解決:

net/rds:在將項目資訊交給訪客之前,每個項目的資訊緩衝區為零 (CVE-2026-52995)

在 Linux 核心中,下列弱點已解決:

netfilter: nfnetlink_osf:修正 ttl 檢查 () 中潛在的空取消參照 (CVE-2026-52998)

在 Linux 核心中,下列弱點已解決:

netfilter: nfnetlink_osf:修正選項比對 (CVE-2026-52999) 的越界讀取

在 Linux 核心中,下列弱點已解決:

netfilter: xtables:將多個比對項限制為 inet 系列 (CVE-2026-53001)

在 Linux 核心中,下列弱點已解決:

netfilter: conntrack:移除 sprintf 用法 (CVE-2026-53002)

在 Linux 核心中,下列弱點已解決:

sctp:修正 sctp_getsockopt_peer_auth_chunks (CVE-2026-53004) 中對使用者空間的 OOB 寫入

在 Linux 核心中,下列弱點已解決:

ipv6:修正 icmpv6_rcv()CVE-2026-53006 () 中可能的 UAF

在 Linux 核心中,下列弱點已解決:

nexthop:修正參照 IPv4 nexthop (CVE-2026-53012) 的 IPv6 路由

在 Linux 核心中,下列弱點已解決:

scsi: target: core:修正 UNMAP 邊界檢查中的整數溢位 (CVE-2026-53021)

在 Linux 核心中,下列弱點已解決:

fs/ntfs3:在 UTF-8 轉換後終止快取的磁碟區標籤 (CVE-2026-53023)

在 Linux 核心中,下列弱點已解決:

HID: usbhid:修正 hid_post_reset() 中的鎖死 (CVE-2026-53037)

在 Linux 核心中,下列弱點已解決:

quota:透過停用配額修正 dquot_scan_active() 的爭用 (CVE-2026-53050)

在 Linux 核心中,下列弱點已解決:

dm log:修正由於 region_count 溢位而導致的越界寫入 (CVE-2026-53059)

在 Linux 核心中,下列弱點已解決:

dm 快取中繼資料:修正中繼資料中止重試時的記憶體洩漏 (CVE-2026-53060)

在 Linux 核心中,下列弱點已解決:

dm 快取:修正直通模式切換中的髒映射檢查 (CVE-2026-53061)

在 Linux 核心中,下列弱點已解決:

dm 快取原則 smq:修正快取區塊無效時遺失的鎖定 (CVE-2026-53062)

在 Linux 核心中,下列弱點已解決:

dm 快取:在直通模式下修正並發寫入的 null-deref (CVE-2026-53064)

在 Linux 核心中,下列弱點已解決:

net, bpf:修正 xdp_master_redirect() 中對關閉主機 (CVE-2026-53069) 的 null-ptr-deref

在 Linux 核心中,下列弱點已解決:

bpf:拒絕 bpf_prog_test_run_skb (CVE-2026-53074) 中的短 IPv4/IPv6 輸入

在 Linux 核心中,下列弱點已解決:

net/rds:將 RDS/IB 的使用限制在初始網路命名空間 (CVE-2026-53077)

在 Linux 核心中,下列弱點已解決:

bpf:在 dev_map_redirect_multi() SKB 路徑中使用 RCU 安全反覆運算 (CVE-2026-53096)

在 Linux 核心中,下列弱點已解決:

drbd:平衡 drbd_adm_dump_devices() 中的 RCU 呼叫 (CVE-2026-53128)

在 Linux 核心中,下列弱點已解決:

audit:修正 CAPSET 記錄中不正確的可繼承功能

__audit_log_capset() 會記錄由於複製貼上錯誤而設定到可繼承欄位中的有效功能。因此,每個 CAPSET auditrecord 都會以 cap_effective 而不是 cap_inheritable 的值報告cap_pi(進程可繼承)。

這會無訊息地損毀用於合規性和鑑識分析的稽核資料:修改可繼承功能以準備特權提升執行人員的攻擊者,會在稽核追蹤中遮罩變更。

自 2008 年首次引入 CAPSETaudit 記錄以來,該錯誤就一直存在。(CVE-2026-53287)

在 Linux 核心中,下列弱點已解決:

mailbox:新增通道陣列的健全性檢查

如果沒有連結至 mailboxcontroller 的通道陣列,則正常失敗。否則,稍後的取消參照會導致可能看不到的 OOPS,因為信箱控制器可能會每年實例化。刪除解釋顯而易見的事情的評論。(CVE-2026-53295)

在 Linux 核心中,下列弱點已解決:

scsi:sg:解決開啟 /dev/sgX 時的軟鎖定問題 (CVE-2026-53304)

在 Linux 核心中,下列弱點已解決:

udf:拒絕具有過大 CRC 長度的描述元

當 descCRCLength +sizeof(struct tag) 超過區塊大小時,udf_read_tagged() 會跳過 CRC 驗證。特製的 UDF 映像檔可以將 descCRCLength 設定為超大的值,以完全繞過 CRC 驗證;然後,僅根據 8 位元標籤總和檢查碼來接受描述元,該總和檢查碼是可重新計算的。

拒絕這樣的描述,而不是默默地接受它們。合法的單塊描述項不應具有超過塊的 CRC 長度。(CVE-2026-53369)

在 Linux 核心中,下列弱點已解決:

RDMA/core:首選 NLA_NUL_STRING

這些屬性會評估為 c-string (傳遞至 strcmp),butNLA_STRING不會檢查是否存在 \0 終止字元。

這需要切換到 nla_strcmp() 並需要調整 printf fmtspecifier 以不使用純 %s,或者這需要使用 NLA_NUL_STRING。

由於代碼已經這樣很長時間了,在我看來,用戶空間確實包含終止 nul,甚至到目前為止還沒有強制執行,因此NLA_NUL_STRING使用是更簡單的解決方案。
(CVE-2026-63860)

在 Linux 核心中,下列弱點已解決:

bpf:從 lsm 可休眠掛鉤中刪除 task_to_inode 和inet_conn_established (CVE-2026-63865)

在 Linux 核心中,下列弱點已解決:

bridge: mcast:修正移除橋接器連接埠時可能的釋放後使用 (CVE-2026-64032)

在 Linux 核心中,下列弱點已解決:

net: tls:防止純文字中的鏈結後鏈結 SG (CVE-2026-64046)

在 Linux 核心中,下列弱點已解決:

net: tls:修正包裝 sk_msg 環的sg_chain項目計數中的差一錯誤

當sk_msg散佈清單環環換行 (sg.end < sg.start) 時,tls_push_record() 使用 sg_chain() 將環的尾部鏈結到頭部。sg 陣列中的額外項目會為此保留:

struct sk_msg_sg {[...]/* 額外的兩個元素:* 1) 用於在清單變得*分割時鏈結前面和部分(例如結束<開始)。加密 API 需要* 鏈結;* 2) 在訊息之後鏈結尾 SG 項目。*/struct 散點清單資料[MAX_MSG_FRAGS + 2];

目前程式碼使用 MAX_SKB_FRAGS + 1 作為戒指大小:

sg_chain(&msg_pl->sg.data[msg_pl->sg.start],MAX_SKB_FRAGS - msg_pl->sg.start + 1,msg_pl->sg.data);

這會將鏈結指標置於

sg_chain(data[start], (MAX_SKB_FRAGS - msg_start + 1) .. =&data[start] + (MAX_SKB_FRAGS - msg_start + 1) - 1 =data[start + (MAX_SKB_FRAGS - start + 1) - 1] =data[MAX_SKB_FRAGS]

而不是真正的最後一個項目。這可能是因為「修正」下的提交爭用接近提交 031097d9e079 (bpf:sk_msg,psock down 時出現 zap 輸入佇列)

轉換為 ARRAY_SIZE 並刪除 data[start] / - start(按照 Sabrina 的建議)。(CVE-2026-64047)

在 Linux 核心中,下列弱點已解決:

ixgbevf:修正 VEPA 多點傳播來源修剪中的釋放後使用

ixgbevf_clean_rx_irq() 會透過釋放 skb 並繼續執行下一個描述元,來修剪來源 MAC 符合 VF 自有位址的框架 (VEPA 多點傳播變通方案):

dev_kfree_skb_irq(skb);繼續;

skb 指標是在 while 迴圈外部宣告,並保留 acrossiterations。因為繼續跳過迴圈底部的 skb = NULL 重設,所以下一次迭代會進入 else if (skb) 路徑,並在釋放的 skb 上調用 ixgbevf_add_rx_frag(),dereferencingskb_shinfo(skb)->nr_frags - NAPI softirq 上下文中的釋放後使用。

同級驅動程式 iavf 已在繼續之前將指標設為 null,以正確處理此問題。在這裡套用相同的模式。

我沒有 ixgbevf 硬體;該錯誤是通過靜態分析發現的(scan_drop_continue_loops.py + semgrep drop_continue_in_loop,多工具佐證,掃描得分最高)。UAF 是在 KASAN 下通過加載一個重現確切代碼模式的測試模塊來確認的(alloc skb, kfree_skb,然後讀取 skb_shinfo(skb)->nr_frags):

錯誤:KASAN:在 ixgbevf_uaf_test_init+0x100/0x1000 中,由任務 insmod/30freed 208 位元組區域在 addr 000000006163ae78 讀取大小 8 的 slab-use-after-free [000000006163adc0, 000000006163ae90)

QEMU 模擬 igb (82576),但不模擬 ixgbe (82599),而且 igbvf VFdriver 不包含 VEPA 來源修剪路徑,因此無法使用模擬硬體進行完整的端到端重現。(CVE-2026-64113)

在 Linux 核心中,下列弱點已解決:

ipv4: raw:拒絕具有 IHL < 5 的IP_HDRINCL封包

raw_send_hdrinc() 會驗證呼叫端提供的 IPv4 標頭是否符合訊息長度:

iphlen = iph->IHL * 4;錯誤 = -EINVAL;if (iphlen > length)goto error_free;

if (iphlen >= sizeof(*iph)) {/* 修正 saddr, tot_len, id, csum, transport_header */}

然而,它並不拒絕 ihl < 5。對於此類封包,會跳過 theif (iphlen >= sizeof(*iph)) 分支,保留特製的 iphdr,但封包仍會傳遞 to__ip_local_out() 及以後。
readiph->ihl 的下游消費者假設一個合理的值:net/ipv4/ah4.c:ah_output() 特別會從 top_iph->ihl * 4 減去 sizeof(struct iphdr),並將 (signed-int-negative,然後轉換為 size_t)結果傳遞給 memcpy(),從而產生長度接近toSIZE_MAX的 OOB 存取和主機核心錯誤。

根據定義,具有 ihl < 5 的 IPv4 標頭格式錯誤 (RFC 791:Internet 標頭長度是網際網路標頭的長度,以 32 位元字表示... 請注意,正確標頭的最小值為 5。核心不應該願意將這樣的封包注入自己的輸出路徑。

拒絕 iphlen < sizeof(*iph) 以及 existingiphlen >長度檢查。這符合重新進入 IP 堆疊的本地建構封包必須通過外部封包將要接受的相同基本健全性測試的原則。

一旦它落地,fixup 分支周圍的 if (iphlen >= sizeof(*iph)) 包裝器就變得多餘;留在原處以保持補丁最小且適合向後移植。後續行動可以解開它。

請注意,提交 86f4c90a1c5c (ipv4、ipv6:確保原始通訊端訊息足夠大以容納 IP 標頭) 可確保訊息緩衝區足夠大以容納 iphdr,但不會限制自我報告的 iph->ihl。

可連線性:格式錯誤的封包來源是任何呼叫端withCAP_NET_RAW,包括 CONFIG_USER_NS=y 的核心上 user+netnamespace 中的無權限處理程序。重現的 AHcrash 也需要在傳出路由上具有相符的 xfrm AH 原則;授予CAP_NET_ADMIN的容器可以在其 netns 中安裝該 stateand 原則。回送會繞過xfrm_output,因此觸發程式會使用真正的 netdev。

在 UML + KASAN 上重現:當機站點的 addr 0x0 withmemcpy_orig 發生核心模式錯誤。相同的形狀在 arootless Docker 容器 --cap-add 內重現,並在 stockdistro 核心上進行NET_ADMIN。
(CVE-2026-64114)

在 Linux 核心中,下列弱點已解決:

vsock/vmci:修正對等體在交握期間重設連線時的 UAF (CVE-2026-64115)

在 Linux 核心中,下列弱點已解決:

drm/msm:修正 iommu_map_sgtable() 傳回值檢查並避免 WARN (CVE-2026-64153)

在 Linux 核心中,下列弱點已解決:

sysfs:更新失敗時不要移除現有目錄

當為具名群組呼叫 sysfs_update_group() 並且 create_files() 失敗 (例如 -ENOMEM) 時,internal_create_group() 會呼叫群組目錄上的 kernfs_remove(kn)。在更新路徑中,kn 是viakernfs_find_and_get() 取得的,它指的是在此呼叫之前已經存在的目錄。
移除它會以無訊息方式銷毀呼叫端未建立的 sysfs 群組。

...

請注意,由於長度原因,描述已被截斷。如需完整說明,請參閱供應商公告。

Tenable 已直接從所測試產品的安全公告擷取前置描述區塊。

請注意,Nessus 並未測試這些問題,而是僅依據應用程式自我報告的版本號碼作出判斷。

解決方案

執行「yum update kernel」或「yum update --advisory ALAS2KERNEL-5.15-2026-107」以更新您的系統。

另請參閱

https://alas.aws.amazon.com//AL2/ALAS2KERNEL-5.15-2026-107.html

https://alas.aws.amazon.com/faqs.html

https://explore.alas.aws.amazon.com/CVE-2022-50552.html

https://explore.alas.aws.amazon.com/CVE-2025-38192.html

https://explore.alas.aws.amazon.com/CVE-2025-68239.html

https://explore.alas.aws.amazon.com/CVE-2026-23157.html

https://explore.alas.aws.amazon.com/CVE-2026-23204.html

https://explore.alas.aws.amazon.com/CVE-2026-23272.html

https://explore.alas.aws.amazon.com/CVE-2026-23399.html

https://explore.alas.aws.amazon.com/CVE-2026-23442.html

https://explore.alas.aws.amazon.com/CVE-2026-31407.html

https://explore.alas.aws.amazon.com/CVE-2026-31489.html

https://explore.alas.aws.amazon.com/CVE-2026-31532.html

https://explore.alas.aws.amazon.com/CVE-2026-31577.html

https://explore.alas.aws.amazon.com/CVE-2026-31580.html

https://explore.alas.aws.amazon.com/CVE-2026-31586.html

https://explore.alas.aws.amazon.com/CVE-2026-31588.html

https://explore.alas.aws.amazon.com/CVE-2026-31590.html

https://explore.alas.aws.amazon.com/CVE-2026-31599.html

https://explore.alas.aws.amazon.com/CVE-2026-31607.html

https://explore.alas.aws.amazon.com/CVE-2026-31624.html

https://explore.alas.aws.amazon.com/CVE-2026-31664.html

https://explore.alas.aws.amazon.com/CVE-2026-31673.html

https://explore.alas.aws.amazon.com/CVE-2026-31681.html

https://explore.alas.aws.amazon.com/CVE-2026-31684.html

https://explore.alas.aws.amazon.com/CVE-2026-31685.html

https://explore.alas.aws.amazon.com/CVE-2026-31692.html

https://explore.alas.aws.amazon.com/CVE-2026-31694.html

https://explore.alas.aws.amazon.com/CVE-2026-31716.html

https://explore.alas.aws.amazon.com/CVE-2026-43079.html

https://explore.alas.aws.amazon.com/CVE-2026-43085.html

https://explore.alas.aws.amazon.com/CVE-2026-43089.html

https://explore.alas.aws.amazon.com/CVE-2026-43093.html

https://explore.alas.aws.amazon.com/CVE-2026-43099.html

https://explore.alas.aws.amazon.com/CVE-2026-43112.html

https://explore.alas.aws.amazon.com/CVE-2026-43114.html

https://explore.alas.aws.amazon.com/CVE-2026-43117.html

https://explore.alas.aws.amazon.com/CVE-2026-43281.html

https://explore.alas.aws.amazon.com/CVE-2026-43328.html

https://explore.alas.aws.amazon.com/CVE-2026-43493.html

https://explore.alas.aws.amazon.com/CVE-2026-43496.html

https://explore.alas.aws.amazon.com/CVE-2026-43502.html

https://explore.alas.aws.amazon.com/CVE-2026-45838.html

https://explore.alas.aws.amazon.com/CVE-2026-45839.html

https://explore.alas.aws.amazon.com/CVE-2026-45840.html

https://explore.alas.aws.amazon.com/CVE-2026-45841.html

https://explore.alas.aws.amazon.com/CVE-2026-45987.html

https://explore.alas.aws.amazon.com/CVE-2026-46015.html

https://explore.alas.aws.amazon.com/CVE-2026-46023.html

https://explore.alas.aws.amazon.com/CVE-2026-46024.html

https://explore.alas.aws.amazon.com/CVE-2026-46033.html

https://explore.alas.aws.amazon.com/CVE-2026-46037.html

https://explore.alas.aws.amazon.com/CVE-2026-46040.html

https://explore.alas.aws.amazon.com/CVE-2026-46046.html

https://explore.alas.aws.amazon.com/CVE-2026-46050.html

https://explore.alas.aws.amazon.com/CVE-2026-46051.html

https://explore.alas.aws.amazon.com/CVE-2026-46053.html

https://explore.alas.aws.amazon.com/CVE-2026-46062.html

https://explore.alas.aws.amazon.com/CVE-2026-46070.html

https://explore.alas.aws.amazon.com/CVE-2026-46072.html

https://explore.alas.aws.amazon.com/CVE-2026-46082.html

https://explore.alas.aws.amazon.com/CVE-2026-46099.html

https://explore.alas.aws.amazon.com/CVE-2026-46101.html

https://explore.alas.aws.amazon.com/CVE-2026-46102.html

https://explore.alas.aws.amazon.com/CVE-2026-46107.html

https://explore.alas.aws.amazon.com/CVE-2026-46113.html

https://explore.alas.aws.amazon.com/CVE-2026-46119.html

https://explore.alas.aws.amazon.com/CVE-2026-46120.html

https://explore.alas.aws.amazon.com/CVE-2026-46124.html

https://explore.alas.aws.amazon.com/CVE-2026-46132.html

https://explore.alas.aws.amazon.com/CVE-2026-46149.html

https://explore.alas.aws.amazon.com/CVE-2026-46150.html

https://explore.alas.aws.amazon.com/CVE-2026-46161.html

https://explore.alas.aws.amazon.com/CVE-2026-46168.html

https://explore.alas.aws.amazon.com/CVE-2026-46172.html

https://explore.alas.aws.amazon.com/CVE-2026-46209.html

https://explore.alas.aws.amazon.com/CVE-2026-46214.html

https://explore.alas.aws.amazon.com/CVE-2026-46227.html

https://explore.alas.aws.amazon.com/CVE-2026-46234.html

https://explore.alas.aws.amazon.com/CVE-2026-46274.html

https://explore.alas.aws.amazon.com/CVE-2026-46294.html

https://explore.alas.aws.amazon.com/CVE-2026-52912.html

https://explore.alas.aws.amazon.com/CVE-2026-52915.html

https://explore.alas.aws.amazon.com/CVE-2026-52920.html

https://explore.alas.aws.amazon.com/CVE-2026-52921.html

https://explore.alas.aws.amazon.com/CVE-2026-52925.html

https://explore.alas.aws.amazon.com/CVE-2026-52954.html

https://explore.alas.aws.amazon.com/CVE-2026-52955.html

https://explore.alas.aws.amazon.com/CVE-2026-52957.html

https://explore.alas.aws.amazon.com/CVE-2026-52958.html

https://explore.alas.aws.amazon.com/CVE-2026-52962.html

https://explore.alas.aws.amazon.com/CVE-2026-52969.html

https://explore.alas.aws.amazon.com/CVE-2026-52970.html

https://explore.alas.aws.amazon.com/CVE-2026-52972.html

https://explore.alas.aws.amazon.com/CVE-2026-52984.html

https://explore.alas.aws.amazon.com/CVE-2026-52985.html

https://explore.alas.aws.amazon.com/CVE-2026-52986.html

https://explore.alas.aws.amazon.com/CVE-2026-52995.html

https://explore.alas.aws.amazon.com/CVE-2026-52998.html

https://explore.alas.aws.amazon.com/CVE-2026-52999.html

https://explore.alas.aws.amazon.com/CVE-2026-53001.html

https://explore.alas.aws.amazon.com/CVE-2026-53002.html

https://explore.alas.aws.amazon.com/CVE-2026-53004.html

https://explore.alas.aws.amazon.com/CVE-2026-53006.html

https://explore.alas.aws.amazon.com/CVE-2026-53012.html

https://explore.alas.aws.amazon.com/CVE-2026-53021.html

https://explore.alas.aws.amazon.com/CVE-2026-53023.html

https://explore.alas.aws.amazon.com/CVE-2026-53037.html

https://explore.alas.aws.amazon.com/CVE-2026-53050.html

https://explore.alas.aws.amazon.com/CVE-2026-53059.html

https://explore.alas.aws.amazon.com/CVE-2026-53060.html

https://explore.alas.aws.amazon.com/CVE-2026-53061.html

https://explore.alas.aws.amazon.com/CVE-2026-53062.html

https://explore.alas.aws.amazon.com/CVE-2026-53064.html

https://explore.alas.aws.amazon.com/CVE-2026-53069.html

https://explore.alas.aws.amazon.com/CVE-2026-53074.html

https://explore.alas.aws.amazon.com/CVE-2026-53077.html

https://explore.alas.aws.amazon.com/CVE-2026-53096.html

https://explore.alas.aws.amazon.com/CVE-2026-53128.html

https://explore.alas.aws.amazon.com/CVE-2026-53287.html

https://explore.alas.aws.amazon.com/CVE-2026-53295.html

https://explore.alas.aws.amazon.com/CVE-2026-53304.html

https://explore.alas.aws.amazon.com/CVE-2026-53369.html

https://explore.alas.aws.amazon.com/CVE-2026-63860.html

https://explore.alas.aws.amazon.com/CVE-2026-63865.html

https://explore.alas.aws.amazon.com/CVE-2026-64032.html

https://explore.alas.aws.amazon.com/CVE-2026-64046.html

https://explore.alas.aws.amazon.com/CVE-2026-64047.html

https://explore.alas.aws.amazon.com/CVE-2026-64113.html

https://explore.alas.aws.amazon.com/CVE-2026-64114.html

https://explore.alas.aws.amazon.com/CVE-2026-64115.html

https://explore.alas.aws.amazon.com/CVE-2026-64153.html

https://explore.alas.aws.amazon.com/CVE-2026-64185.html

https://explore.alas.aws.amazon.com/CVE-2026-64220.html

Plugin 詳細資訊

嚴重性: High

ID: 322048

檔案名稱: al2_ALASKERNEL-5_15-2026-107.nasl

版本: 1.7

類型: Local

代理程式: unix

已發布: 2026/6/22

已更新: 2026/8/3

支援的感應器: Agentless Assessment, Continuous Assessment, Frictionless Assessment Agent, Frictionless Assessment AWS, Nessus Agent, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

風險資訊

VPR

風險因素: High

分數: 7.7

百分位數: 99.03

CVSS v2

風險因素: Medium

基本分數: 6.8

時間性分數: 5.3

媒介: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS 評分資料來源: CVE-2026-53059

CVSS v3

風險因素: High

基本分數: 7.8

時間性分數: 7

媒介: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

時間媒介: CVSS:3.0/E:P/RL:O/RC:C

弱點資訊

CPE: cpe:/o:amazon:linux:2, p-cpe:/a:amazon:linux:bpftool-debuginfo, p-cpe:/a:amazon:linux:bpftool, p-cpe:/a:amazon:linux:kernel-debuginfo-common-aarch64, p-cpe:/a:amazon:linux:kernel-debuginfo-common-x86_64, p-cpe:/a:amazon:linux:kernel-debuginfo, p-cpe:/a:amazon:linux:kernel-devel, p-cpe:/a:amazon:linux:kernel-headers, p-cpe:/a:amazon:linux:kernel-livepatch-5.15.209-147.245, p-cpe:/a:amazon:linux:kernel-tools-debuginfo, p-cpe:/a:amazon:linux:kernel-tools-devel, p-cpe:/a:amazon:linux:kernel-tools, p-cpe:/a:amazon:linux:kernel, p-cpe:/a:amazon:linux:perf-debuginfo, p-cpe:/a:amazon:linux:perf, p-cpe:/a:amazon:linux:python-perf-debuginfo, p-cpe:/a:amazon:linux:python-perf

必要的 KB 項目: Host/local_checks_enabled, Host/AmazonLinux/release, Host/AmazonLinux/rpm-list

可被惡意程式利用: true

可輕鬆利用: Exploits are available

修補程式發佈日期: 2026/6/22

弱點發布日期: 2025/7/4

參考資訊

CVE: CVE-2022-50552, CVE-2025-38192, CVE-2025-68239, CVE-2026-23157, CVE-2026-23204, CVE-2026-23272, CVE-2026-23399, CVE-2026-23442, CVE-2026-31407, CVE-2026-31489, CVE-2026-31532, CVE-2026-31577, CVE-2026-31580, CVE-2026-31586, CVE-2026-31588, CVE-2026-31590, CVE-2026-31599, CVE-2026-31607, CVE-2026-31624, CVE-2026-31664, CVE-2026-31673, CVE-2026-31681, CVE-2026-31684, CVE-2026-31685, CVE-2026-31692, CVE-2026-31694, CVE-2026-31716, CVE-2026-43079, CVE-2026-43085, CVE-2026-43089, CVE-2026-43093, CVE-2026-43099, CVE-2026-43112, CVE-2026-43114, CVE-2026-43117, CVE-2026-43281, CVE-2026-43328, CVE-2026-43493, CVE-2026-43496, CVE-2026-43502, CVE-2026-45838, CVE-2026-45839, CVE-2026-45840, CVE-2026-45841, CVE-2026-45987, CVE-2026-46015, CVE-2026-46023, CVE-2026-46024, CVE-2026-46033, CVE-2026-46037, CVE-2026-46040, CVE-2026-46046, CVE-2026-46050, CVE-2026-46051, CVE-2026-46053, CVE-2026-46062, CVE-2026-46070, CVE-2026-46072, CVE-2026-46082, CVE-2026-46099, CVE-2026-46101, CVE-2026-46102, CVE-2026-46107, CVE-2026-46113, CVE-2026-46119, CVE-2026-46120, CVE-2026-46124, CVE-2026-46132, CVE-2026-46149, CVE-2026-46150, CVE-2026-46161, CVE-2026-46168, CVE-2026-46172, CVE-2026-46209, CVE-2026-46214, CVE-2026-46227, CVE-2026-46234, CVE-2026-46274, CVE-2026-46294, CVE-2026-52912, CVE-2026-52915, CVE-2026-52920, CVE-2026-52921, CVE-2026-52925, CVE-2026-52954, CVE-2026-52955, CVE-2026-52957, CVE-2026-52958, CVE-2026-52962, CVE-2026-52969, CVE-2026-52970, CVE-2026-52972, CVE-2026-52984, CVE-2026-52985, CVE-2026-52986, CVE-2026-52995, CVE-2026-52998, CVE-2026-52999, CVE-2026-53001, CVE-2026-53002, CVE-2026-53004, CVE-2026-53006, CVE-2026-53012, CVE-2026-53021, CVE-2026-53023, CVE-2026-53037, CVE-2026-53050, CVE-2026-53059, CVE-2026-53060, CVE-2026-53061, CVE-2026-53062, CVE-2026-53064, CVE-2026-53069, CVE-2026-53074, CVE-2026-53077, CVE-2026-53096, CVE-2026-53128, CVE-2026-53287, CVE-2026-53295, CVE-2026-53304, CVE-2026-53369, CVE-2026-63860, CVE-2026-63865, CVE-2026-64032, CVE-2026-64046, CVE-2026-64047, CVE-2026-64113, CVE-2026-64114, CVE-2026-64115, CVE-2026-64153, CVE-2026-64185, CVE-2026-64220