Amazon Linux 2023:bpftool6.18、kernel6.18、kernel6.18-devel (ALAS2023-2026-1881)

high Nessus Plugin ID 322087

概要

遠端 Amazon Linux 2023 主機缺少一個安全性更新。

說明

因此,會受到 ALAS2023-2026-1881 公告中所提及的多個弱點影響。

在 Linux 核心中,下列弱點已解決:

fs/ntfs3:處理截斷檔案 (CVE-2025-71289) 時的 attr_set_size() 錯誤

在 Linux 核心中,下列弱點已解決:

smb:client:在 cifsacl 中重寫 DACL 之前先驗證整個 DACL (CVE-2026-31709)

在 Linux 核心中,下列弱點已解決:

netfilter: nft_inner:修正 IPv6 inner_thoff不同步 (CVE-2026-46244)

在 Linux 核心中,下列弱點已解決:

io_uring/waitid:在將 waitid 資訊複製到使用者空間 (CVE-2026-46315) 之前,先清除 waitid 資訊

在 Linux 核心中,下列弱點已解決:

KVM: arm64: vgic-its: 僅刪除已刪除項目 (CVE-2026-46316) 的轉換快取參照

在 Linux 核心中,下列弱點已解決:

KVM: arm64:重新指派mmu_lock後面nested_mmus陣列 (CVE-2026-46317)

在 Linux 核心中,下列弱點已解決:

tun:關於 tun_xdp_one() 中短框架拒絕的免費頁面 (CVE-2026-46321)

在 Linux 核心中,下列弱點已解決:

tun:關於 tun_xdp_one() 中build_skb失敗的免費頁面 (CVE-2026-46322)

在 Linux 核心中,下列弱點已解決:

netfilter: nf_queue:佇列時保留橋接器 skb->dev (CVE-2026-52912)

在 Linux 核心中,下列弱點已解決:

netfilter: ip6t_hbh:拒絕過大的選項清單 (CVE-2026-52915)

在 Linux 核心中,下列弱點已解決:

netfilter: ipset:停止雜湊:* 結束時的範圍反覆運算 (CVE-2026-52921)

在 Linux 核心中,下列弱點已解決:

ipc:將next_id分配限制為有效 ID 範圍 (CVE-2026-52923)

在 Linux 核心中,下列弱點已解決:

xfrm: ipcomp:acomp 錯誤 (CVE-2026-52932) 上的釋放目的地頁面

在 Linux 核心中,下列弱點已解決:

tap:修正 tap_ioctl() 中的堆疊資訊洩露 () SIOCGIFHWADDR (CVE-2026-52937)

在 Linux 核心中,下列弱點已解決:

net: skbuff:修正 pskb_carve 協助程式中缺少的 ZeroCopy 參照 (CVE-2026-52943)

在 Linux 核心中,下列弱點已解決:

KVM:arm64:在錯誤插入和 AT 模擬 () 中進行頁面表格遍歷的 SRCU 鎖定 (CVE-2026-53277)

在 Linux 核心中,下列弱點已解決:

fuse:修正 fuse_dentry_revalidate() 中的 uninit-value (CVE-2026-53311)

在 Linux 核心中,下列弱點已解決:

KVM:SEV:如果 GHCB v2+ 處於使用中狀態,則需要 GHCB 內暫存區域 (CVE-2026-53360)

在 Linux 核心中,下列弱點已解決:

vsock/virtio:修正多重 skb 傳送的零複製完成 (CVE-2026-53365)

在 Linux 核心中,下列弱點已解決:

arm64: tlb:取消共用 PMD 表格時排清遍歷快取 (CVE-2026-63875)

在 Linux 核心中,下列弱點已解決:

serial: zs: 轉換為使用平台裝置 (CVE-2026-63876)

在 Linux 核心中,下列弱點已解決:

serial: dz: 轉換為使用平台裝置 (CVE-2026-63877)

在 Linux 核心中,下列弱點已解決:

drm/i915:修正 TTM 物件清除中潛在的 UAF (CVE-2026-63884)

在 Linux 核心中,下列弱點已解決:

drm/gem:修正 change_handle 和 handle_delete 之間的爭用 (CVE-2026-63885)

在 Linux 核心中,下列弱點已解決:

scsi: target: iscsi: 在 base64 解碼 (CVE-2026-63886) 之前驗證CHAP_R長度

在 Linux 核心中,下列弱點已解決:

scsi:target:iscsi:綁定的 iscsi_encode_text_output() 附加到 rsp_buf (CVE-2026-63887)

在 Linux 核心中,下列弱點已解決:

scsi:target:iscsi:修正 iscsit_handle_text_cmd() 中的 CRC 過度讀取和雙重釋放 (CVE-2026-63888)

在 Linux 核心中,下列弱點已解決:

scsi: scsi_transport_fc:將 FPIN pname 步行計數器擴大到 u32 (CVE-2026-63889)

在 Linux 核心中,下列弱點已解決:

usb: gadget: composite:修正 WebUSB GET_URL處理中的整數反向溢位 (CVE-2026-63896)

在 Linux 核心中,下列弱點已解決:

xfrm: esp:還原組合的單片段長度閘門

ESP 就位快速路徑會在 esp_output_tail() 配置目的地頁面片段之前,在 esp_output_head() 中附加預告片。頭側閘門目前分別檢查 skb->data_len 和 tailen,但尾部代碼從組合後拖車 skb->data_len 中分配一個目的地片段。

當組合的對齊長度超過 apage 時,拒絕頁面片段快速路徑。否則,skb_page_frag_refill() 可能會回歸到單個頁面,而目標 sg 仍然跨越組合的 skb->data_len。

還原 IPv4 和 IPv6 的此組合長度分頁閘道。(CVE-2026-63912)

在 Linux 核心中,下列弱點已解決:

netfilter: conntrack: tcp:不要在沒有方向檢查的情況下對 invalid-seq RST 強制關閉 (CVE-2026-63913)

在 Linux 核心中,下列弱點已解決:

xfrm:將 MIGRATE 通知路由傳送至呼叫端的 netns (CVE-2026-63914)

在 Linux 核心中,下列弱點已解決:

ip6: vti:在 vti6_changelink() 中使用 ip6_tnl.net。(CVE-2026-63917)

在 Linux 核心中,下列弱點已解決:

xfrm: input:在延遲傳輸重新插入期間保留 netns (CVE-2026-63919)

在 Linux 核心中,下列弱點已解決:

ipv6:在複製到 CMSG (CVE-2026-63920) 之前驗證擴充功能標頭長度

在 Linux 核心中,下列弱點已解決:

ip6: vti:在 vti6_siocdevprivate() 中使用 ip6_tnl.net。

在本系列的修補程式 1/2 之後,vti6_update() 會透過 t->net 取消連結並重新連結通道。
vti6_siocdevprivate() 仍usesdev_net(dev) 進行衝突查詢。對於移動throughIFLA_NET_NS_FD的隧道,dev_net(dev) 是新的 netns,而不是 t->net。

SIOCCHGTUNNEL 接著在移轉的通道上執行:

net = dev_net(dev) /* 移轉的 netns */t = vti6_locate(net, &p1, false) /* 在 t->net 中遺漏目標 */...t = netdev_priv(dev)vti6_update(t, &p1, false) /* 改變 t->net 的雜湊
*/

移轉的 netns 中的呼叫端會挑選符合建立 netns 中通道的參數。dev_net(dev) 中的查詢會發現 nothing.vti6_update() 會在這些參數的建立 netns 雜湊儲存桶的前面加上移轉的通道。建立 netns 中稍後的查詢會解析為移轉的裝置。xfrm receive會透過呼叫端控制的裝置傳遞相符的封包。

可從無特權的使用者命名空間連線 (取消共用 --user--map-root-user --net)。容器主機上的跨租用戶範圍。

將非後援裝置上的 SIOCCHGTUNNEL 路徑切換為 uset->net 進行查詢。查詢現在與 netnsvti6_update() 操作的相符。

另外,在查詢之前新增 ns_capable(self->net->user_ns, CAP_NET_ADMIN)。案例頂端的檢查是 againstdev_net(dev)->user_ns,移轉後就是攻擊者的 snetns。那裡的調用者可以選擇 self->net 中不存在的參數,查找返回 NULL,t 變為 self,並且 vti6_update()將設備插入創建 netns 哈希中。新的檢查也需要在建立 netns user_ns中CAP_NET_ADMIN。

SIOCADDTUNNEL 和 SIOCCHGTUNNEL 在後援裝置 keepdev_net (dev) 上,這等於那裡的init_net。
(CVE-2026-63921)

在 Linux 核心中,下列弱點已解決:

ipv6: exthdrs:處理 HAO 選項 (CVE-2026-63922) 後重新整理 nh

在 Linux 核心中,下列弱點已解決:

ipv6: exthdrs:在 ipv6_hop_jumbo() 之後重新整理 NH 指標

ipv6_hop_jumbo() 呼叫 pskb_trim_rcsum(),可以更改 skb 指標。讓我們重新計算 nh 指標,以確保任何更改都不會把事情搞砸。(CVE-2026-63924)

在 Linux 核心中,下列弱點已解決:

macsec:修正 XPN lower-PN 換行 (CVE-2026-63925) 處的重播保護

在 Linux 核心中,下列弱點已解決:

bpf: sockmap:修正bpf_msg_push_data中的尾部片段偏移

當 bpf_msg_push_data() 在 scatterlistentry 中間插入資料時,它會將原始項目拆分為左側片段和右側片段。

正確的片段位移量是頁面本機,但程式碼會使用「start」來推進它,這是訊息全域插入點。對於插入到非第一個 SG 項目中,這會過度推進偏移並使分割佈局不一致。

將右側片段偏移量前推進片段局部增量「開始 - 偏移量」,該增量與從原始項目前面移除的長度相符。(CVE-2026-63926)

在 Linux 核心中,下列弱點已解決:

KVM:SEV:從 PSC 緩衝區 (CVE-2026-63937) 讀取項目/索引時,請使用 READ_ONCE()

在 Linux 核心中,下列弱點已解決:

KVM: SEV:根據緩衝區的實際大小檢查 PSC 要求指數 (CVE-2026-63938)

在 Linux 核心中,下列弱點已解決:

KVM: SEV:計算 GHCB 內暫存區域的正確最大長度 (CVE-2026-63939)

在 Linux 核心中,下列弱點已解決:

KVM: SEV:略過長度為「0」的連接埠 I/O 要求

明確忽略長度為 '0' (或計數 '0') 的埠 I/O 要求,這樣設定軟體暫存區域 (和其他程式碼) 就不必擔心長度下溢,並允許在嘗試以 len==0 配置暫存區域時發出警告。(CVE-2026-63940)

在 Linux 核心中,下列弱點已解決:

mm/rmap:在 try_to_unmap_one (CVE-2026-63950) 中迴圈啟動時將 nr_pages 初始化為 1

在 Linux 核心中,下列弱點已解決:

memfd:當暗示 SEAL_WRITE (CVE-2026-63952) 時,拒絕可寫入的對應

在 Linux 核心中,下列弱點已解決:

USB:typec:tcpm:在 svdm_consume_modes() (CVE-2026-63962) 中按迭代綁定altmode_desc[]

在 Linux 核心中,下列弱點已解決:

ipv6:修正 fib6_select_path() 中可能的無限迴圈 (CVE-2026-63968)

在 Linux 核心中,下列弱點已解決:

ipv6:修正 rt6_fill_node() 中可能的無限迴圈 (CVE-2026-63969)

在 Linux 核心中,下列弱點已解決:

vsock/virtio:在填入 Zerocopy skb (CVE-2026-63970) 之前綁定 UARG

在 Linux 核心中,下列弱點已解決:

sctp:修正 sctp_wait_for_connect 和 peeloff 之間的爭用

sctp_wait_for_connect() 在等待關聯達到 ESTABLISHED 狀態時刪除並重新取得通訊端鎖定。在此視窗期間,另一個執行緒可以剝離與新通訊端 viagetsockopt(SCTP_SOCKOPT_PEELOFF) 的關聯,以變更 asoc->base.sk。重新取得舊的通訊端鎖定後,sctp_wait_for_connect() 傳回成功而不註意到遷移 -- 然後調用方在 sctp_datamsg_from_user() 中錯誤的鎖定下存取關聯。

新增 sctp_wait_for_sndbuf() 已經進行的相同 sk != asoc->base.sk 檢查,如果關聯是在我們睡覺時遷移的,則傳回錯誤。(CVE-2026-63971)

在 Linux 核心中,下列弱點已解決:

net/handshake:對hn_lock使用spin_lock_bh (CVE-2026-63980)

在 Linux 核心中,下列弱點已解決:

ipv6: rpl:修正 ipv6_rpl_srh_decompress() 中的 hdrlen 溢位 (CVE-2026-63984)

在 Linux 核心中,下列弱點已解決:

ethtool: eeprom:為 EEPROM 網路連結後援新增更多安全性 (CVE-2026-63985)

在 Linux 核心中,下列弱點已解決:

ethtool: tsinfo:不要在準備失敗時將ERR_PTR傳遞給genlmsg_cancel (CVE-2026-63986)

在 Linux 核心中,下列弱點已解決:

ethtool:coalesce:NET_DIM_PARAMS_NUM_PROFILESCVE-2026-63987 () 時的 CAP 設定檔更新

在 Linux 核心中,下列弱點已解決:

bridge:修正 sysfs 路徑中不可部分完成上下文中的睡眠 (CVE-2026-63988)

在 Linux 核心中,下列弱點已解決:

bridge:修正網路連結路徑 (CVE-2026-63989) 中原子上下文中的睡眠

在 Linux 核心中,下列弱點已解決:

bonding:拒絕從屬 CAN 設備 (CVE-2026-63990)

在 Linux 核心中,下列弱點已解決:

隧道:不要假設 iptunnel_pmtud_check_icmp() 中的傳輸標頭 (CVE-2026-63992)

在 Linux 核心中,下列弱點已解決:

vxlan:不要在 skb_tunnel_check_pmtu() 之後重複使用快取的 ip_hdr() 值 (CVE-2026-63993)

在 Linux 核心中,下列弱點已解決:

隧道:在 iptunnel_pmtud_build_icmp[v6]()CVE-2026-63994 () 中 skb_cow() 之後載入網路標頭

在 Linux 核心中,下列弱點已解決:

ethtool: cmis:驗證模組 (CVE-2026-63995) 中的start_cmd_payload_size

在 Linux 核心中,下列弱點已解決:

ethtool: cmis:需要確切的 CDB 回覆長度 (CVE-2026-63996)

在 Linux 核心中,下列弱點已解決:

ethtool: module:避免在模組快閃錯誤上洩露 netdev ref (CVE-2026-63997)

在 Linux 核心中,下列弱點已解決:

ethtool: module:在模組快閃記憶體錯誤時呼叫 ethnl_ops_complete() (CVE-2026-63998)

在 Linux 核心中,下列弱點已解決:

ethtool: rss:修正 get_rxfh 失敗時的 indir_table 和 hkey 洩漏 (CVE-2026-63999)

在 Linux 核心中,下列弱點已解決:

ipv4:unregister_net_sysctl_table() 後釋放網路>ipv4.sysctl_local_reserved_ports (CVE-2026-64002)

在 Linux 核心中,下列弱點已解決:

scsi: core:從 scsi_run_host_queues (CVE-2026-64003) 為所有非SDEV_DEL裝置執行佇列

在 Linux 核心中,下列弱點已解決:

net/smc:不要重新初始化 smc 雜湊表 (CVE-2026-64005)

在 Linux 核心中,下列弱點已解決:

netfilter: nf_tables:修正相同暫存器作業中的 dst 損毀

對於 lshift 和 rshift,移位操作是在 32 位字的循環中執行的。迴圈計算移位值並將其寫入 dst,然後立即從 src 讀取以計算下一次迭代的進位。因為 src 和 dst 可能指向相同的記憶體位置,所以使用新修改的 dst 值而不是原始 src 值來正確計算進位。

在寫入 dst 並將其用於進位計算之前添加一個臨時本地變量以緩存原始值可以解決問題。此外,控制平面會拒絕包括位元組順序在內的所有作業的部分重疊。這是使用以下字節碼測試的:

表 test_table IP 旗標 0 使用 1 處理 1ip test_table test_chain 使用 3 類型 篩選器勾點 輸入 prio 0 原則 接受封包 0 位元組 0 旗標 1ip test_table test_chain 2[ immediate reg 1 0x44332211 0x88776655][ bitwise reg 1 = ( reg 1 << 0x08000000 ) ][ cmp eq reg 1 0x66443322 0x00887766 ][ counter pkts 0 bytes 0]ip test_table test_chain 4 3[ immediate reg 1 0x44332211 0x88776655 ][ bitwise reg 1 = ( reg1 << 0x08000000 ) ][ cmp eq reg 1 0x55443322 0x00887766 ][ 計數器 pkts 21794 位元組 1917798 ] (CVE-2026-64006)

在 Linux 核心中,下列弱點已解決:

netfilter: synproxy:skb_ensure_writable後重新整理 tcphdr

synproxy_tstamp_adjust() 會就地重寫 TCP 時間戳記選項,然後透過呼叫端提供的 tcphdr 指標上的 inet_proto_csum_replace4() 修補 TCP 總和檢查碼。ipv4_synproxy_hook() andipv6_synproxy_hook() 在調用之前使用 skb_header_pointer() 獲取該指標,因此它可以直接別名 skb->head,或者指向調用方的堆棧上_tcph緩衝區。

在取得指標和使用它之間,函數 callsskb_ensure_writable(skb, optend) 在複製或非線性 skb 上呼叫 pskb_expand_head() 並釋放舊的 skb->head。在那之後,緩存的 th 就過時了:

呼叫者 (ipv[46]_synproxy_hook)th = skb_header_pointer(skb, ..., &_tcph)synproxy_tstamp_adjust(skb, protoff, th, ...)skb_ensure_writable(skb, optend)pskb_expand_head() /* kfree(舊 skb->head)
*/...inet_proto_csum_replace4(&th->check,.../* 寫入釋放的磁頭,或寫入調用方的堆疊複製中,留下線上總和檢查碼 */

選項位元組是透過 skb->data 寫入的,並且沒問題;只有總和檢查碼更新會經過 th,因此會出現在錯誤的位置。結果是寫入已釋放的 slab 記憶體,或封包留下的總和檢查碼與其承載不符。

透過立即從 skb->data + protoff 重新派生 th 來修正 afterskb_ensure_writable() 成功,因此後續總和檢查碼更新會以線性、可寫入的標頭為目標。(CVE-2026-64007)

在 Linux 核心中,下列弱點已解決:

xfrm:檢查xfrm_state_mtu中的反向溢位 (CVE-2026-64009)

在 Linux 核心中,下列弱點已解決:

net/sched: sch_sfb:將直接出列呼叫替換為 peek 和 qdisc_dequeue_peeked (CVE-2026-64012)

在 Linux 核心中,下列弱點已解決:

security/keys:修正查詢時遺漏的 RCU 讀取部分

Nicholas Carlini 報告說,金鑰環程式碼在 find_key_to_update() 中呼叫 assoc_array_find(),而不持有 RCU 讀取鎖定,而 theassoc_array_gc() 程式碼實際上是圍繞從樹中刪除節點,然後在 RCU 寬限期後釋放它而設計的。

一般金鑰處理不會看到此問題,因為持有金鑰環信號量會隱藏任何存留期問題,但持續性金鑰處理會使用不同的模型。

無需延長鑰匙圈鎖定,只需進行簡單的 RCU 鎖定assoc_array的設計目的。(CVE-2026-64015)

在 Linux 核心中,下列弱點已解決:

tcp:修正過時的 per-CPU tcp_tw_isn洩漏,啟用 ISN 預測

Blamed commit 將 TIME_WAIT 派生的 ISN 從 skb 控制區塊移至 per-CPU 變數,假設寫入該值的同一封包的 tcp_conn_request() 一律會耗用該值。tcp_v{4,6}_rcv()) 中的生產者 (__this_cpu_write(tcp_tw_isn, isn) 和消費者 (tcp_conn_request()) 之間的多個刪除路徑違反了該假設:

- min_ttl / min_hopcount檢查 - xfrm 策略檢查 - tcp_inbound_hash() MD5/AO 不相符 - tcp_filter() eBPF/SO_ATTACH_FILTER 刪除 tcp_rcv_state_process() 中的 th->syn & th->fin 捨棄 tcp_v{4,6}_do_rcv() 中的 TCP_LISTEN-psp_sk_rx_policy_check() - tcp_v{4,6}_do_rcv() 中的 tcp_checksum_complete() - tcp_v{4,6}_cookie_check() 傳回 NULL

當封包丟棄在任何這些路徑上時,tcp_tw_isn會保持設定狀態。

然後,在相同 CPU 上處理的下一個 SYN 會耗用非零值 intcp_conn_request(),並接收可能可預測的 ISN。

此修補程式tcp_tw_isn移回 skb->cb[],刪除了 per-cpu 變數。

請注意,tcp_v{4,6}_fill_cb() 不會設定它。

對整體程式碼大小/複雜性的影響非常小:

$ scripts/bloat-o-meter -t vmlinux.old vmlinux.newadd/remove: 0/0 增長/縮小: 2/1 上/下: 8/-15 (-7)功能 舊的 new deltatcp_v6_rcv 3038 3042 +4tcp_v4_rcv 3035 3039 +4tcp_conn_request 2938 2923 -15總計: 之前=24436060, 之後=24436053, chg -0.00% (CVE-2026-64024)

在 Linux 核心中,下列弱點已解決:

bpf, skmsg:修正使用 KTLS RX sk_data_ready比賽的判定

sk_psock_strp_data_ready() 已經檢查 tls_sw_has_ctx_rx(),並在存在 TLS RX 上下文時延遲執行 psock->saved_data_ready,從而避免與TLS strparser 對 receivequeue 的所有權發生衝突(提交 e91de6afa81c,bpf:使用 ktls 修正正在運行的sk_skb程式類型)。

sk_psock_verdict_data_ready() 沒有對等的防護。當在配置 RX 之前將通訊端插入 sockmap (BPF_SK_SKB_VERDICT) TLS,tls_sw_strparser_arm() 會儲存 sk_psock_verdict_data_readyas rx_ctx->saved_data_ready。資料到達時:

tls_data_ready -> tls_strp_data_ready -> tls_rx_msg_ready-> saved_data_ready() = sk_psock_verdict_data_ready()-> tcp_read_skb() 透過 __skb_unlink() sk_receive_queue,而不呼叫 tcp_eat_skb(),因此copied_seq不會進階。

然後,tls_strp_msg_load() 會在現在為空的佇列上找到 tcp_inq() >= full_len (過時)、callstcp_recv_skb(),點擊 WARN_ON_ONCE(!first),然後返回指向 psock 擁有(可能釋放)skb 的 rx_ctx->strp.anchor.frag_list。tls_decrypt_sg() 隨後thatfrag_list:釋放後使用。

套用與 sk_psock_strp_data_ready() 相同的修正:如果存在 TLS RX 上下文,則呼叫 psock->saved_data_ready (sock_def_readable) 以 wakerecv() 等候者並立即返回,讓接收佇列保持不變。TLS保留佇列的唯一所有權,並透過 tls_sw_recvmsg() 正常解密記錄。(CVE-2026-64025)

在 Linux 核心中,下列弱點已解決:

net: shaper:重做 VALID 標記 (再次) (CVE-2026-64027)

在 Linux 核心中,下列弱點已解決:

erofs:修正未對齊範圍的受管理快取爭用 (CVE-2026-64031)

在 Linux 核心中,下列弱點已解決:

bridge: mcast:修正移除橋接器連接埠時可能的釋放後使用 (CVE-2026-64032)

在 Linux 核心中,下列弱點已解決:

igc:設定 SMD 框架的 tx 緩衝區類型 (CVE-2026-64035)

在 Linux 核心中,下列弱點已解決:

cgroup/rstat:在 css_rstat_cpu() 存取之前驗證 CPU

css_rstat_updated() 會公開為 BPF kfunc,並接受呼叫者提供的 cpu 引數。此函式會使用 cpu 進行 per-cpu rstatlookups,而不檢查它是否參照有效的可能 CPU。

具有 CAP_BPF 和 CAP_PERFMON 的 BPF iter/cgroup 程式可以傳遞無效的 cpu 值。在未修正的 UBSCAN_BOUNDS 測試核心上,cpu ==0x7fffffff 觸發:

UBSAN: array-index-out-of-bounds 在 kernel/cgroup/rstat.c:31:9index 中,2147483647超出類型「long unsigned int [64]」的範圍,呼叫追蹤:css_rstat_updatedbpf_iter_run_progcgroup_iter_seq_showbpf_seq_read

將 cpu 驗證新增至面向 BPF 的 css_rstat_updated() kfunc,並將通用實作移至
__css_rstat_updated() 用於 in-kernelcallers。(CVE-2026-64036)

在 Linux 核心中,下列弱點已解決:

ovpn:遵守錯誤路徑中的對等參照計數CMD_NEW_PEER (CVE-2026-64044)

在 Linux 核心中,下列弱點已解決:

ovpn: tcp - 在 ovpn_tcp_close() 中使用快取的對等指標 (CVE-2026-64045)

在 Linux 核心中,下列弱點已解決:

net: tls:防止純文字中的鏈結後鏈結 SG (CVE-2026-64046)

在 Linux 核心中,下列弱點已解決:

net: tls:修正包裝 sk_msg 環的sg_chain項目計數中的差一錯誤

當sk_msg散佈清單環環換行 (sg.end < sg.start) 時,tls_push_record() 使用 sg_chain() 將環的尾部鏈結到頭部。sg 陣列中的額外項目會為此保留:

struct sk_msg_sg {[...]/* 額外的兩個元素:* 1) 用於在清單變得*分割時鏈結前面和部分(例如結束<開始)。加密 API 需要* 鏈結;* 2) 在訊息之後鏈結尾 SG 項目。*/struct 散點清單資料[MAX_MSG_FRAGS + 2];

目前程式碼使用 MAX_SKB_FRAGS + 1 作為戒指大小:

sg_chain(&msg_pl->sg.data[msg_pl->sg.start],MAX_SKB_FRAGS - msg_pl->sg.start + 1,msg_pl->sg.data);

這會將鏈結指標置於

sg_chain(data[start], (MAX_SKB_FRAGS - msg_start + 1) .. =&data[start] + (MAX_SKB_FRAGS - msg_start + 1) - 1 =data[start + (MAX_SKB_FRAGS - start + 1) - 1] =data[MAX_SKB_FRAGS]

而不是真正的最後一個項目。這可能是因為「修正」下的提交爭用接近提交 031097d9e079 (bpf:sk_msg,psock down 時出現 zap 輸入佇列)

轉換為 ARRAY_SIZE 並刪除 data[start] / - start(按照 Sabrina 的建議)。(CVE-2026-64047)

在 Linux 核心中,下列弱點已解決:

block: bio-integrity:修正 bio_integrity_map_user() 中的 null-ptr-deref (CVE-2026-64052)

在 Linux 核心中,下列弱點已解決:

block:不要覆寫 bio_integrity_copy_user() 中的 bip_vcnt (CVE-2026-64053)

在 Linux 核心中,下列弱點已解決:

net: shaper:拒絕 GROUP request () 中的重複離開 (CVE-2026-64054)

在 Linux 核心中,下列弱點已解決:

netfs:修正 netfs_read_folio() 以等候回寫 (CVE-2026-64058)

在 Linux 核心中,下列弱點已解決:

netfs:修正 netfs_perform_write()CVE-2026-64059 () 中的 folio->private 處理

在 Linux 核心中,下列弱點已解決:

netfs:修正 netfs_write_begin() 錯誤處理中要求洩露的問題

修正 netfs_write_begin(),以便在我們收到來自 netfs_wait_for_read() 的錯誤時不會洩露請求上的引用。(CVE-2026-64060)

在 Linux 核心中,下列弱點已解決:

netfs:修正 netfs_read_gaps() 中接收對開的提前放置 (CVE-2026-64061)

在 Linux 核心中,下列弱點已解決:

netfs:修正直寫模式下的潛在鎖死 (CVE-2026-64062)

在 Linux 核心中,下列弱點已解決:

netfs:修正被覆寫的串流寫入 (CVE-2026-64063)

在 Linux 核心中,下列弱點已解決:

netfs:修正 netfs_invalidate_folio() 以在所有變更都消失時清除髒位元 (CVE-2026-64064)

在 Linux 核心中,下列弱點已解決:

netfs:修正 netfs_write_begin() 調用 (CVE-2026-64065) 中的 VM_BUG_ON_FOLIO() 問題

在 Linux 核心中,下列弱點已解決:

netfs:修正 netfs_read_to_pagecache() 以在 subreq 失敗時暫停 (CVE-2026-64066)

在 Linux 核心中,下列弱點已解決:

netfs:修正 DIO 和單一讀取子要求的取消 (CVE-2026-64069)

在 Linux 核心中,下列弱點已解決:

nvme-pci:修正 nvme_free_host_mem() 中的釋放後使用 (CVE-2026-64071)

在 Linux 核心中,下列弱點已解決:

NVMe:修正映射失敗時的生物洩漏 (CVE-2026-64072)

在 Linux 核心中,下列弱點已解決:

irq_work:修正 PREEMPT_RT 上 irq_work_single() 中的釋放後使用 ...

請注意,由於長度原因,描述已被截斷。如需完整說明,請參閱供應商公告。

Tenable 已直接從所測試產品的安全公告擷取前置描述區塊。

請注意,Nessus 並未測試這些問題,而是僅依據應用程式自我報告的版本號碼作出判斷。

解決方案

執行「dnf update kernel6.18 --releasever 2023.12.20260622」或「dnf update --advisory ALAS2023-2026-1881 --releasever 2023.12.20260622」以更新系統。

另請參閱

https://alas.aws.amazon.com//AL2023/ALAS2023-2026-1881.html

https://alas.aws.amazon.com/faqs.html

https://explore.alas.aws.amazon.com/CVE-2025-71289.html

https://explore.alas.aws.amazon.com/CVE-2026-31709.html

https://explore.alas.aws.amazon.com/CVE-2026-46244.html

https://explore.alas.aws.amazon.com/CVE-2026-46315.html

https://explore.alas.aws.amazon.com/CVE-2026-46316.html

https://explore.alas.aws.amazon.com/CVE-2026-46317.html

https://explore.alas.aws.amazon.com/CVE-2026-46321.html

https://explore.alas.aws.amazon.com/CVE-2026-46322.html

https://explore.alas.aws.amazon.com/CVE-2026-52912.html

https://explore.alas.aws.amazon.com/CVE-2026-52915.html

https://explore.alas.aws.amazon.com/CVE-2026-52921.html

https://explore.alas.aws.amazon.com/CVE-2026-52923.html

https://explore.alas.aws.amazon.com/CVE-2026-52932.html

https://explore.alas.aws.amazon.com/CVE-2026-52937.html

https://explore.alas.aws.amazon.com/CVE-2026-52943.html

https://explore.alas.aws.amazon.com/CVE-2026-53277.html

https://explore.alas.aws.amazon.com/CVE-2026-53311.html

https://explore.alas.aws.amazon.com/CVE-2026-53360.html

https://explore.alas.aws.amazon.com/CVE-2026-53365.html

https://explore.alas.aws.amazon.com/CVE-2026-63875.html

https://explore.alas.aws.amazon.com/CVE-2026-63876.html

https://explore.alas.aws.amazon.com/CVE-2026-63877.html

https://explore.alas.aws.amazon.com/CVE-2026-63884.html

https://explore.alas.aws.amazon.com/CVE-2026-63885.html

https://explore.alas.aws.amazon.com/CVE-2026-63886.html

https://explore.alas.aws.amazon.com/CVE-2026-63887.html

https://explore.alas.aws.amazon.com/CVE-2026-63888.html

https://explore.alas.aws.amazon.com/CVE-2026-63889.html

https://explore.alas.aws.amazon.com/CVE-2026-63896.html

https://explore.alas.aws.amazon.com/CVE-2026-63912.html

https://explore.alas.aws.amazon.com/CVE-2026-63913.html

https://explore.alas.aws.amazon.com/CVE-2026-63914.html

https://explore.alas.aws.amazon.com/CVE-2026-63917.html

https://explore.alas.aws.amazon.com/CVE-2026-63919.html

https://explore.alas.aws.amazon.com/CVE-2026-63920.html

https://explore.alas.aws.amazon.com/CVE-2026-63921.html

https://explore.alas.aws.amazon.com/CVE-2026-63922.html

https://explore.alas.aws.amazon.com/CVE-2026-63924.html

https://explore.alas.aws.amazon.com/CVE-2026-63925.html

https://explore.alas.aws.amazon.com/CVE-2026-63926.html

https://explore.alas.aws.amazon.com/CVE-2026-63937.html

https://explore.alas.aws.amazon.com/CVE-2026-63938.html

https://explore.alas.aws.amazon.com/CVE-2026-63939.html

https://explore.alas.aws.amazon.com/CVE-2026-63940.html

https://explore.alas.aws.amazon.com/CVE-2026-63950.html

https://explore.alas.aws.amazon.com/CVE-2026-63952.html

https://explore.alas.aws.amazon.com/CVE-2026-63962.html

https://explore.alas.aws.amazon.com/CVE-2026-63968.html

https://explore.alas.aws.amazon.com/CVE-2026-63969.html

https://explore.alas.aws.amazon.com/CVE-2026-63970.html

https://explore.alas.aws.amazon.com/CVE-2026-63971.html

https://explore.alas.aws.amazon.com/CVE-2026-63980.html

https://explore.alas.aws.amazon.com/CVE-2026-63984.html

https://explore.alas.aws.amazon.com/CVE-2026-63985.html

https://explore.alas.aws.amazon.com/CVE-2026-63986.html

https://explore.alas.aws.amazon.com/CVE-2026-63987.html

https://explore.alas.aws.amazon.com/CVE-2026-63988.html

https://explore.alas.aws.amazon.com/CVE-2026-63989.html

https://explore.alas.aws.amazon.com/CVE-2026-63990.html

https://explore.alas.aws.amazon.com/CVE-2026-63992.html

https://explore.alas.aws.amazon.com/CVE-2026-63993.html

https://explore.alas.aws.amazon.com/CVE-2026-63994.html

https://explore.alas.aws.amazon.com/CVE-2026-63995.html

https://explore.alas.aws.amazon.com/CVE-2026-63996.html

https://explore.alas.aws.amazon.com/CVE-2026-63997.html

https://explore.alas.aws.amazon.com/CVE-2026-63998.html

https://explore.alas.aws.amazon.com/CVE-2026-63999.html

https://explore.alas.aws.amazon.com/CVE-2026-64002.html

https://explore.alas.aws.amazon.com/CVE-2026-64003.html

https://explore.alas.aws.amazon.com/CVE-2026-64005.html

https://explore.alas.aws.amazon.com/CVE-2026-64006.html

https://explore.alas.aws.amazon.com/CVE-2026-64007.html

https://explore.alas.aws.amazon.com/CVE-2026-64009.html

https://explore.alas.aws.amazon.com/CVE-2026-64012.html

https://explore.alas.aws.amazon.com/CVE-2026-64015.html

https://explore.alas.aws.amazon.com/CVE-2026-64024.html

https://explore.alas.aws.amazon.com/CVE-2026-64025.html

https://explore.alas.aws.amazon.com/CVE-2026-64027.html

https://explore.alas.aws.amazon.com/CVE-2026-64031.html

https://explore.alas.aws.amazon.com/CVE-2026-64032.html

https://explore.alas.aws.amazon.com/CVE-2026-64035.html

https://explore.alas.aws.amazon.com/CVE-2026-64036.html

https://explore.alas.aws.amazon.com/CVE-2026-64044.html

https://explore.alas.aws.amazon.com/CVE-2026-64045.html

https://explore.alas.aws.amazon.com/CVE-2026-64046.html

https://explore.alas.aws.amazon.com/CVE-2026-64047.html

https://explore.alas.aws.amazon.com/CVE-2026-64052.html

https://explore.alas.aws.amazon.com/CVE-2026-64053.html

https://explore.alas.aws.amazon.com/CVE-2026-64054.html

https://explore.alas.aws.amazon.com/CVE-2026-64058.html

https://explore.alas.aws.amazon.com/CVE-2026-64059.html

https://explore.alas.aws.amazon.com/CVE-2026-64060.html

https://explore.alas.aws.amazon.com/CVE-2026-64061.html

https://explore.alas.aws.amazon.com/CVE-2026-64062.html

https://explore.alas.aws.amazon.com/CVE-2026-64063.html

https://explore.alas.aws.amazon.com/CVE-2026-64064.html

https://explore.alas.aws.amazon.com/CVE-2026-64065.html

https://explore.alas.aws.amazon.com/CVE-2026-64066.html

https://explore.alas.aws.amazon.com/CVE-2026-64069.html

https://explore.alas.aws.amazon.com/CVE-2026-64071.html

https://explore.alas.aws.amazon.com/CVE-2026-64072.html

https://explore.alas.aws.amazon.com/CVE-2026-64073.html

https://explore.alas.aws.amazon.com/CVE-2026-64074.html

https://explore.alas.aws.amazon.com/CVE-2026-64075.html

https://explore.alas.aws.amazon.com/CVE-2026-64076.html

https://explore.alas.aws.amazon.com/CVE-2026-64077.html

https://explore.alas.aws.amazon.com/CVE-2026-64078.html

https://explore.alas.aws.amazon.com/CVE-2026-64080.html

https://explore.alas.aws.amazon.com/CVE-2026-64081.html

https://explore.alas.aws.amazon.com/CVE-2026-64098.html

https://explore.alas.aws.amazon.com/CVE-2026-64104.html

https://explore.alas.aws.amazon.com/CVE-2026-64105.html

https://explore.alas.aws.amazon.com/CVE-2026-64106.html

https://explore.alas.aws.amazon.com/CVE-2026-64108.html

https://explore.alas.aws.amazon.com/CVE-2026-64109.html

https://explore.alas.aws.amazon.com/CVE-2026-64110.html

https://explore.alas.aws.amazon.com/CVE-2026-64111.html

https://explore.alas.aws.amazon.com/CVE-2026-64112.html

https://explore.alas.aws.amazon.com/CVE-2026-64113.html

https://explore.alas.aws.amazon.com/CVE-2026-64114.html

https://explore.alas.aws.amazon.com/CVE-2026-64115.html

https://explore.alas.aws.amazon.com/CVE-2026-64116.html

https://explore.alas.aws.amazon.com/CVE-2026-64120.html

https://explore.alas.aws.amazon.com/CVE-2026-64121.html

https://explore.alas.aws.amazon.com/CVE-2026-64122.html

https://explore.alas.aws.amazon.com/CVE-2026-64124.html

https://explore.alas.aws.amazon.com/CVE-2026-64130.html

https://explore.alas.aws.amazon.com/CVE-2026-64131.html

https://explore.alas.aws.amazon.com/CVE-2026-64132.html

https://explore.alas.aws.amazon.com/CVE-2026-64136.html

https://explore.alas.aws.amazon.com/CVE-2026-64149.html

https://explore.alas.aws.amazon.com/CVE-2026-64150.html

https://explore.alas.aws.amazon.com/CVE-2026-64153.html

https://explore.alas.aws.amazon.com/CVE-2026-64156.html

https://explore.alas.aws.amazon.com/CVE-2026-64157.html

https://explore.alas.aws.amazon.com/CVE-2026-64158.html

https://explore.alas.aws.amazon.com/CVE-2026-64163.html

https://explore.alas.aws.amazon.com/CVE-2026-64164.html

https://explore.alas.aws.amazon.com/CVE-2026-64166.html

https://explore.alas.aws.amazon.com/CVE-2026-64172.html

https://explore.alas.aws.amazon.com/CVE-2026-64180.html

https://explore.alas.aws.amazon.com/CVE-2026-64181.html

https://explore.alas.aws.amazon.com/CVE-2026-64182.html

https://explore.alas.aws.amazon.com/CVE-2026-64183.html

https://explore.alas.aws.amazon.com/CVE-2026-64184.html

https://explore.alas.aws.amazon.com/CVE-2026-64185.html

https://explore.alas.aws.amazon.com/CVE-2026-64186.html

https://explore.alas.aws.amazon.com/CVE-2026-64190.html

https://explore.alas.aws.amazon.com/CVE-2026-64216.html

https://explore.alas.aws.amazon.com/CVE-2026-64217.html

https://explore.alas.aws.amazon.com/CVE-2026-64220.html

https://explore.alas.aws.amazon.com/CVE-2026-64226.html

https://explore.alas.aws.amazon.com/CVE-2026-64228.html

https://explore.alas.aws.amazon.com/CVE-2026-64229.html

https://explore.alas.aws.amazon.com/CVE-2026-64232.html

https://explore.alas.aws.amazon.com/CVE-2026-64235.html

https://explore.alas.aws.amazon.com/CVE-2026-64239.html

https://explore.alas.aws.amazon.com/CVE-2026-64302.html

https://explore.alas.aws.amazon.com/CVE-2026-64518.html

https://explore.alas.aws.amazon.com/CVE-2026-64519.html

https://explore.alas.aws.amazon.com/CVE-2026-64520.html

https://explore.alas.aws.amazon.com/CVE-2026-64522.html

https://explore.alas.aws.amazon.com/CVE-2026-64525.html

https://explore.alas.aws.amazon.com/CVE-2026-64526.html

Plugin 詳細資訊

嚴重性: High

ID: 322087

檔案名稱: al2023_ALAS2023-2026-1881.nasl

版本: 1.10

類型: Local

代理程式: unix

已發布: 2026/6/22

已更新: 2026/8/13

支援的感應器: Frictionless Assessment AWS, Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Continuous Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

風險資訊

VPR

風險因素: High

分數: 7.9

百分位數: 99.36

CVSS v2

風險因素: Medium

基本分數: 6.8

時間性分數: 5.3

媒介: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS 評分資料來源: CVE-2026-64239

CVSS v3

風險因素: High

基本分數: 7.8

時間性分數: 7

媒介: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

時間媒介: CVSS:3.0/E:P/RL:O/RC:C

弱點資訊

CPE: cpe:/o:amazon:linux:2023, p-cpe:/a:amazon:linux:bpftool6.18-debuginfo, p-cpe:/a:amazon:linux:bpftool6.18, p-cpe:/a:amazon:linux:kernel-livepatch-6.18.35-68.127, p-cpe:/a:amazon:linux:kernel6.18-debuginfo-common-aarch64, p-cpe:/a:amazon:linux:kernel6.18-debuginfo-common-x86_64, p-cpe:/a:amazon:linux:kernel6.18-debuginfo, p-cpe:/a:amazon:linux:kernel6.18-devel, p-cpe:/a:amazon:linux:kernel6.18-headers, p-cpe:/a:amazon:linux:kernel6.18-modules-extra-common, p-cpe:/a:amazon:linux:kernel6.18-modules-extra, p-cpe:/a:amazon:linux:kernel6.18-tools-debuginfo, p-cpe:/a:amazon:linux:kernel6.18-tools-devel, p-cpe:/a:amazon:linux:kernel6.18-tools, p-cpe:/a:amazon:linux:kernel6.18, p-cpe:/a:amazon:linux:microvm-kernel6.18, p-cpe:/a:amazon:linux:perf6.18-debuginfo, p-cpe:/a:amazon:linux:perf6.18, p-cpe:/a:amazon:linux:python3-perf6.18-debuginfo, p-cpe:/a:amazon:linux:python3-perf6.18

必要的 KB 項目: Host/local_checks_enabled, Host/AmazonLinux/release, Host/AmazonLinux/rpm-list

可被惡意程式利用: true

可輕鬆利用: Exploits are available

修補程式發佈日期: 2026/6/22

弱點發布日期: 2026/5/1

參考資訊

CVE: CVE-2025-71289, CVE-2026-31709, CVE-2026-46244, CVE-2026-46315, CVE-2026-46316, CVE-2026-46317, CVE-2026-46321, CVE-2026-46322, CVE-2026-52912, CVE-2026-52915, CVE-2026-52921, CVE-2026-52923, CVE-2026-52932, CVE-2026-52937, CVE-2026-52943, CVE-2026-53277, CVE-2026-53311, CVE-2026-53360, CVE-2026-53365, CVE-2026-63875, CVE-2026-63876, CVE-2026-63877, CVE-2026-63884, CVE-2026-63885, CVE-2026-63886, CVE-2026-63887, CVE-2026-63888, CVE-2026-63889, CVE-2026-63896, CVE-2026-63912, CVE-2026-63913, CVE-2026-63914, CVE-2026-63917, CVE-2026-63919, CVE-2026-63920, CVE-2026-63921, CVE-2026-63922, CVE-2026-63924, CVE-2026-63925, CVE-2026-63926, CVE-2026-63937, CVE-2026-63938, CVE-2026-63939, CVE-2026-63940, CVE-2026-63950, CVE-2026-63952, CVE-2026-63962, CVE-2026-63968, CVE-2026-63969, CVE-2026-63970, CVE-2026-63971, CVE-2026-63980, CVE-2026-63984, CVE-2026-63985, CVE-2026-63986, CVE-2026-63987, CVE-2026-63988, CVE-2026-63989, CVE-2026-63990, CVE-2026-63992, CVE-2026-63993, CVE-2026-63994, CVE-2026-63995, CVE-2026-63996, CVE-2026-63997, CVE-2026-63998, CVE-2026-63999, CVE-2026-64002, CVE-2026-64003, CVE-2026-64005, CVE-2026-64006, CVE-2026-64007, CVE-2026-64009, CVE-2026-64012, CVE-2026-64015, CVE-2026-64024, CVE-2026-64025, CVE-2026-64027, CVE-2026-64031, CVE-2026-64032, CVE-2026-64035, CVE-2026-64036, CVE-2026-64044, CVE-2026-64045, CVE-2026-64046, CVE-2026-64047, CVE-2026-64052, CVE-2026-64053, CVE-2026-64054, CVE-2026-64058, CVE-2026-64059, CVE-2026-64060, CVE-2026-64061, CVE-2026-64062, CVE-2026-64063, CVE-2026-64064, CVE-2026-64065, CVE-2026-64066, CVE-2026-64069, CVE-2026-64071, CVE-2026-64072, CVE-2026-64073, CVE-2026-64074, CVE-2026-64075, CVE-2026-64076, CVE-2026-64077, CVE-2026-64078, CVE-2026-64080, CVE-2026-64081, CVE-2026-64098, CVE-2026-64104, CVE-2026-64105, CVE-2026-64106, CVE-2026-64108, CVE-2026-64109, CVE-2026-64110, CVE-2026-64111, CVE-2026-64112, CVE-2026-64113, CVE-2026-64114, CVE-2026-64115, CVE-2026-64116, CVE-2026-64120, CVE-2026-64121, CVE-2026-64122, CVE-2026-64124, CVE-2026-64130, CVE-2026-64131, CVE-2026-64132, CVE-2026-64136, CVE-2026-64149, CVE-2026-64150, CVE-2026-64153, CVE-2026-64156, CVE-2026-64157, CVE-2026-64158, CVE-2026-64163, CVE-2026-64164, CVE-2026-64166, CVE-2026-64172, CVE-2026-64180, CVE-2026-64181, CVE-2026-64182, CVE-2026-64183, CVE-2026-64184, CVE-2026-64185, CVE-2026-64186, CVE-2026-64190, CVE-2026-64216, CVE-2026-64217, CVE-2026-64220, CVE-2026-64226, CVE-2026-64228, CVE-2026-64229, CVE-2026-64232, CVE-2026-64235, CVE-2026-64239, CVE-2026-64302, CVE-2026-64518, CVE-2026-64519, CVE-2026-64520, CVE-2026-64522, CVE-2026-64525, CVE-2026-64526