Amazon Linux 2023:bpftool6.18、kernel6.18、kernel6.18-devel (ALAS2023-2026-1881)

medium Nessus Plugin ID 322087

概要

遠端 Amazon Linux 2023 主機缺少一個安全性更新。

說明

因此,會受到 ALAS2023-2026-1881 公告中所提及的多個弱點影響。

在 Linux 核心中,下列弱點已解決:

fs/ntfs3:處理截斷檔案 (CVE-2025-71289) 時的 attr_set_size() 錯誤

在 Linux 核心中,下列弱點已解決:

smb:client:在 cifsacl 中重寫 DACL 之前先驗證整個 DACL (CVE-2026-31709)

在 Linux 核心中,下列弱點已解決:

netfilter: nft_inner:修正 IPv6 inner_thoff不同步 (CVE-2026-46244)

在 Linux 核心中,下列弱點已解決:

io_uring/waitid:在將 waitid 資訊複製到使用者空間 (CVE-2026-46315) 之前,先清除 waitid 資訊

在 Linux 核心中,下列弱點已解決:

KVM: arm64: vgic-its: 僅刪除已刪除項目 (CVE-2026-46316) 的轉換快取參照

在 Linux 核心中,下列弱點已解決:

KVM: arm64:重新指派mmu_lock後面nested_mmus陣列 (CVE-2026-46317)

在 Linux 核心中,下列弱點已解決:

tun:關於 tun_xdp_one() 中短框架拒絕的免費頁面 (CVE-2026-46321)

在 Linux 核心中,下列弱點已解決:

tun:關於 tun_xdp_one() 中build_skb失敗的免費頁面 (CVE-2026-46322)

在 Linux 核心中,下列弱點已解決:

netfilter: nf_queue:佇列時保留橋接器 skb->dev (CVE-2026-52912)

在 Linux 核心中,下列弱點已解決:

netfilter: ip6t_hbh:拒絕過大的選項清單 (CVE-2026-52915)

在 Linux 核心中,下列弱點已解決:

netfilter: ipset:停止雜湊:* 結束時的範圍反覆運算 (CVE-2026-52921)

在 Linux 核心中,下列弱點已解決:

ipc:將next_id分配限制為有效 ID 範圍 (CVE-2026-52923)

在 Linux 核心中,下列弱點已解決:

xfrm: ipcomp:acomp 錯誤 (CVE-2026-52932) 上的釋放目的地頁面

在 Linux 核心中,下列弱點已解決:

tap:修正 tap_ioctl() 中的堆疊資訊洩露 () SIOCGIFHWADDR (CVE-2026-52937)

在 Linux 核心中,下列弱點已解決:

net: skbuff:修正 pskb_carve 協助程式中缺少的 ZeroCopy 參照 (CVE-2026-52943)

在 Linux 核心中,下列弱點已解決:

KVM:arm64:在錯誤插入和 AT 模擬 () 中進行頁面表格遍歷的 SRCU 鎖定 (CVE-2026-53277)

在 Linux 核心中,下列弱點已解決:

fuse:修正 fuse_dentry_revalidate() 中的 uninit-value (CVE-2026-53311)

在 Linux 核心中,下列弱點已解決:

KVM:SEV:如果 GHCB v2+ 處於使用中狀態,則需要 GHCB 內暫存區域 (CVE-2026-53360)

Tenable 已直接從所測試產品的安全公告擷取前置描述區塊。

請注意,Nessus 並未測試這些問題,而是僅依據應用程式自我報告的版本號碼作出判斷。

解決方案

執行「dnf update kernel6.18 --releasever 2023.12.20260622」或「dnf update --advisory ALAS2023-2026-1881 --releasever 2023.12.20260622」以更新系統。

另請參閱

https://alas.aws.amazon.com//AL2023/ALAS2023-2026-1881.html

https://alas.aws.amazon.com/faqs.html

https://explore.alas.aws.amazon.com/CVE-2025-71289.html

https://explore.alas.aws.amazon.com/CVE-2026-31709.html

https://explore.alas.aws.amazon.com/CVE-2026-46244.html

https://explore.alas.aws.amazon.com/CVE-2026-46315.html

https://explore.alas.aws.amazon.com/CVE-2026-46316.html

https://explore.alas.aws.amazon.com/CVE-2026-46317.html

https://explore.alas.aws.amazon.com/CVE-2026-46321.html

https://explore.alas.aws.amazon.com/CVE-2026-46322.html

https://explore.alas.aws.amazon.com/CVE-2026-52912.html

https://explore.alas.aws.amazon.com/CVE-2026-52915.html

https://explore.alas.aws.amazon.com/CVE-2026-52921.html

https://explore.alas.aws.amazon.com/CVE-2026-52923.html

https://explore.alas.aws.amazon.com/CVE-2026-52932.html

https://explore.alas.aws.amazon.com/CVE-2026-52937.html

https://explore.alas.aws.amazon.com/CVE-2026-52943.html

https://explore.alas.aws.amazon.com/CVE-2026-53277.html

https://explore.alas.aws.amazon.com/CVE-2026-53311.html

https://explore.alas.aws.amazon.com/CVE-2026-53360.html

Plugin 詳細資訊

嚴重性: Medium

ID: 322087

檔案名稱: al2023_ALAS2023-2026-1881.nasl

版本: 1.4

類型: Local

代理程式: unix

已發布: 2026/6/22

已更新: 2026/7/16

支援的感應器: Frictionless Assessment AWS, Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Continuous Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

風險資訊

VPR

風險因素: High

分數: 7.9

百分位: 99.35

CVSS v2

風險因素: Medium

基本分數: 4.6

時間性分數: 3.6

媒介: CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:C

CVSS 評分資料來源: CVE-2026-53311

CVSS v3

風險因素: Medium

基本分數: 5.5

時間性分數: 5

媒介: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

時間媒介: CVSS:3.0/E:P/RL:O/RC:C

弱點資訊

CPE: cpe:/o:amazon:linux:2023, p-cpe:/a:amazon:linux:bpftool6.18-debuginfo, p-cpe:/a:amazon:linux:bpftool6.18, p-cpe:/a:amazon:linux:kernel-livepatch-6.18.35-68.127, p-cpe:/a:amazon:linux:kernel6.18-debuginfo-common-aarch64, p-cpe:/a:amazon:linux:kernel6.18-debuginfo-common-x86_64, p-cpe:/a:amazon:linux:kernel6.18-debuginfo, p-cpe:/a:amazon:linux:kernel6.18-devel, p-cpe:/a:amazon:linux:kernel6.18-headers, p-cpe:/a:amazon:linux:kernel6.18-modules-extra-common, p-cpe:/a:amazon:linux:kernel6.18-modules-extra, p-cpe:/a:amazon:linux:kernel6.18-tools-debuginfo, p-cpe:/a:amazon:linux:kernel6.18-tools-devel, p-cpe:/a:amazon:linux:kernel6.18-tools, p-cpe:/a:amazon:linux:kernel6.18, p-cpe:/a:amazon:linux:microvm-kernel6.18, p-cpe:/a:amazon:linux:perf6.18-debuginfo, p-cpe:/a:amazon:linux:perf6.18, p-cpe:/a:amazon:linux:python3-perf6.18-debuginfo, p-cpe:/a:amazon:linux:python3-perf6.18

必要的 KB 項目: Host/local_checks_enabled, Host/AmazonLinux/release, Host/AmazonLinux/rpm-list

可被惡意程式利用: true

可輕鬆利用: Exploits are available

修補程式發佈日期: 2026/6/22

弱點發布日期: 2026/5/1

參考資訊

CVE: CVE-2025-71289, CVE-2026-31709, CVE-2026-46244, CVE-2026-46315, CVE-2026-46316, CVE-2026-46317, CVE-2026-46321, CVE-2026-46322, CVE-2026-52912, CVE-2026-52915, CVE-2026-52921, CVE-2026-52923, CVE-2026-52932, CVE-2026-52937, CVE-2026-52943, CVE-2026-53277, CVE-2026-53311, CVE-2026-53360