Amazon Linux 2:核心, --advisory ALAS2KERNEL-5。10-2026-124(ALASKERNEL-5。10-2026-124

high Nessus Plugin ID 325574

概要

遠端 Amazon Linux 2 主機缺少安全性更新。

說明

遠端主機上安裝的核心版本早於 5.10.259-258.1043。因此,會受到 ALAS2KERNEL-5.10-2026-124 公告中所提及的多個弱點影響。

在 Linux 核心中,下列弱點已解決:

net/sched: teql:修正 teql_master_xmit 中的雙重釋放 (CVE-2026-23449)

在 Linux 核心中,下列弱點已解決:

ext4:驗證 ext4_ext_correct_indexes (CVE-2026-31449) 中的p_idx邊界

在 Linux 核心中,下列弱點已解決:

net/tls:修正 -EBUSY 中的釋放後使用錯誤路徑 tls_do_encryption (CVE-2026-31533)

在 Linux 核心中,下列弱點已解決:

smb: client:修正smb2_ioctl_query_info QUERY_INFO路徑中的 OOB 讀取 (CVE-2026-31708)

在 Linux 核心中,下列弱點已解決:

smb: client:需要完整的 NFS 模式 SID,才能讀取模式位元 (CVE-2026-43350)

在 Linux 核心中,下列弱點已解決:

lib/crypto: mpi:修正 mpi_read_raw_from_sgl()CVE-2026-43492 () 中的整數反向溢位

在 Linux 核心中,下列弱點已解決:

ipvs:跳過 csum 檢查的 IPv6 延伸標頭 (CVE-2026-45850)

在 Linux 核心中,下列弱點已解決:

udf:修正分割區描述元附加簿記 (CVE-2026-45991)

在 Linux 核心中,下列弱點已解決:

thermal: core:修正熱區域調速器清理問題 (CVE-2026-46021)

在 Linux 核心中,下列弱點已解決:

ceph:僅當未雜湊時,僅 d_add() 負 dentry (CVE-2026-46052)

在 Linux 核心中,下列弱點已解決:

net: bridge:在 RCU 讀取器中使用穩定的 FDB dst 快照 (CVE-2026-46086)

在 Linux 核心中,下列弱點已解決:

dm-thin:修正中繼資料參照計數反向溢位 (CVE-2026-46107)

在 Linux 核心中,下列弱點已解決:

mptcp:pm:ADD_ADDR rtx:修正潛在的資料爭用 (CVE-2026-46137)

在 Linux 核心中,下列弱點已解決:

btrfs:修正 TOCTOU slot_count可能導致資訊洩露 (CVE-2026-46159) 的 btrfs_ioctl_space_info()

在 Linux 核心中,下列弱點已解決:

btrfs:修正移除目錄時遺失的 last_unlink_trans 更新 (CVE-2026-46160)

在 Linux 核心中,下列弱點已解決:

hfsplus:透過驗證目錄記錄大小 (CVE-2026-46169) 來修正 uninit-value

在 Linux 核心中,下列弱點已解決:

fbcon:如果主控台輪換失敗,則避免 OOB 字型存取 (CVE-2026-46191)

在 Linux 核心中,下列弱點已解決:

追蹤點:在 tracepoint_add_func()CVE-2026-46196 () 中的 func_add() 失敗時平衡 regfunc()

在 Linux 核心中,下列弱點已解決:

pmdomain: core:修正 genpd (CVE-2026-46292) 中虛擬裝置的分離程序

在 Linux 核心中,下列弱點已解決:

hfsplus:修正 hfsplus_fill_super() 上釋放的保留鎖定 (CVE-2026-46299)

在 Linux 核心中,下列弱點已解決:

點選:tap_get_user_xdp() 中錯誤路徑的空閒頁面 (CVE-2026-46320)

在 Linux 核心中,下列弱點已解決:

tun:關於 tun_xdp_one() 中短框架拒絕的免費頁面 (CVE-2026-46321)

在 Linux 核心中,下列弱點已解決:

tun:關於 tun_xdp_one() 中build_skb失敗的免費頁面 (CVE-2026-46322)

在 Linux 核心中,下列弱點已解決:

bpf:在 RCU 寬限期後釋放重用埠 cBPF 程序。(CVE-2026-52910)

在 Linux 核心中,下列弱點已解決:

netfilter: nf_queue:佇列時保留橋接器 skb->dev (CVE-2026-52912)

在 Linux 核心中,下列弱點已解決:

ipc:將next_id分配限制為有效 ID 範圍 (CVE-2026-52923)

在 Linux 核心中,下列弱點已解決:

sctp:在過時的 COOKIE-ECHO 處理上清除出佇列 (CVE-2026-52924)

在 Linux 核心中,下列弱點已解決:

netfilter: ebtables:修正 compat_mtw_from_user (CVE-2026-52927) 中的 OOB 讀取

在 Linux 核心中,下列弱點已解決:

sctp: stream:完全復原拒絕的新增串流狀態 (CVE-2026-52929)

在 Linux 核心中,下列弱點已解決:

ipc/shm:使用 shm_nattch 更新序列化孤立清除 (CVE-2026-52930)

在 Linux 核心中,下列弱點已解決:

net: skbuff:修正 pskb_carve 協助程式中缺少的 ZeroCopy 參照 (CVE-2026-52943)

在 Linux 核心中,下列弱點已解決:

fs/fcntl:修正 fasync 訊號中的 SOFTIRQ-unsafe 鎖定順序 (CVE-2026-52946)

在 Linux 核心中,下列弱點已解決:

i2c: dev:防止 ioctl I2C_TIMEOUT中的整數溢位 (CVE-2026-52948)

在 Linux 核心中,下列弱點已解決:

net/sched: cls_fw:修正 change()CVE-2026-53080 () 之前舊篩選器的 NULL 解除參照

在 Linux 核心中,下列弱點已解決:

RDMA/umem:修正區塊大小的截斷 >= 4G (CVE-2026-53133)

在 Linux 核心中,下列弱點已解決:

netfilter: nft_fib:透過 OIFNAME 暫存器 (CVE-2026-53134) 修正過時的堆疊洩漏

在 Linux 核心中,下列弱點已解決:

fuse:拒絕目錄上的 fuse_notify() 頁面快取操作 (CVE-2026-53168)

在 Linux 核心中,下列弱點已解決:

IB/isert:拒絕短於 ISER_HEADERS_LEN (CVE-2026-53176) 的登入 PDU

在 Linux 核心中,下列弱點已解決:

RDMA/srp:由接收到的長度 (CVE-2026-53186) 綁定SRP_RSP感應副本

在 Linux 核心中,下列弱點已解決:

mm/huge_memory:在 folio_put() 之前更新檔案 PMD 計數器 (CVE-2026-53189)

在 Linux 核心中,下列弱點已解決:

USB:serial:kl5kusb105:修正大量緩衝區溢位 (CVE-2026-53194)

在 Linux 核心中,下列弱點已解決:

USB: serial: io_ti:修正 build_i2c_fw_hdr() 中的堆積溢位 (CVE-2026-53195)

在 Linux 核心中,下列弱點已解決:

USB: serial: io_ti:修正 get_manuf_info() 中的堆積溢位 (CVE-2026-53196)

在 Linux 核心中,下列弱點已解決:

hv_netvsc:在netvsc_copy_to_send_buf中使用kmap_local_page (CVE-2026-53199)

在 Linux 核心中,下列弱點已解決:

netfilter: nft_tunnel:修正物件銷毀 (CVE-2026-53212) 上的釋放後使用

在 Linux 核心中,下列弱點已解決:

netfilter: nft_exthdr:修正 F_PRESENT 旗標的暫存器追蹤 (CVE-2026-53218)

在 Linux 核心中,下列弱點已解決:

netfilter: x_tables:避免洩漏 percpu 計數指標 (CVE-2026-53219)

在 Linux 核心中,下列弱點已解決:

ip6_vti:修正 vti6_tnl_lookup()CVE-2026-53221 () 中不正確的通道比對

在 Linux 核心中,下列弱點已解決:

net:將時間戳記 cmsgs 保護到實際錯誤佇列 skbs (CVE-2026-53223)

在 Linux 核心中,下列弱點已解決:

sctp:修正 __sctp_rcv_asconf_lookup() 中的 uninit-value (CVE-2026-53225)

在 Linux 核心中,下列弱點已解決:

net: openvswitch:修正可能的 ERR_PTR (CVE-2026-53227) kfree_skb

在 Linux 核心中,下列弱點已解決:

ipv6: sit:GSO 卸載後重新載入內部 IPv6 標頭 (CVE-2026-53228)

在 Linux 核心中,下列弱點已解決:

netlabel:驗證未標記的位址和遮罩屬性長度 (CVE-2026-53238)

在 Linux 核心中,下列弱點已解決:

xfrm: policy:修正 xfrm_policy_bysel_ctx() 中不精確 bin 的釋放後使用 (CVE-2026-53239)

在 Linux 核心中,下列弱點已解決:

net/802/mrp:修正 mrp_pdu_parse_vecattr (CVE-2026-53245) 中的向量屬性剖析

在 Linux 核心中,下列弱點已解決:

ipv4:限制IPOPT_SSRR和IPOPT_LSRR選項 (CVE-2026-53249)

在 Linux 核心中,下列弱點已解決:

net/sched: act_api:在動作生命週期使用具有延遲釋放功能的 RCU (CVE-2026-53264)

在 Linux 核心中,下列弱點已解決:

netfilter: bridge:使ebt_snat ARP 重寫可寫入 (CVE-2026-53266)

在 Linux 核心中,下列弱點已解決:

netfilter: conntrack_irc:修正可能的越界讀取 (CVE-2026-53268)

在 Linux 核心中,下列弱點已解決:

netfilter: synproxy:新增互斥以保護鉤子參照計數 (CVE-2026-53269)

在 Linux 核心中,下列弱點已解決:

ipvs:在編輯 (CVE-2026-53270) 時儘早清除 SVC 排程器 PTR

在 Linux 核心中,下列弱點已解決:

net: bonding:修正 bond_do_ioctl() 中的 NULL 指標解除參照

在 bond_do_ioctl() 中,slave_dev 是透過 __dev_get_by_name() 取得的,如果請求的介面名稱不存在,則可以傳回 NULL。不過,後續的 slave_dbg() 呼叫會放在 NULL 檢查之前:

slave_dev = __dev_get_by_name(net, ifr->ifr_slave);slave_dbg(bond_dev, slave_dev, slave_dev=%p:\n, slave_dev); //hereif (!slave_dev)return -ENODEV;

slave_dbg() 巨集會展開為 netdev_dbg(bond_dev, (slave %s): fmt,(slave_dev)->name, ...),在執行 NULL 檢查之前,會無條件地解除參照 slave_dev->name。當使用者呼叫具有不存在的 slaveinterface 名稱的綁定 ioctl (例如 SIOCBONDENSLAVE、SIOCBONDRELEASE 等) 時,這會導致 NULL 指標解除參照核心 oops。

這可以透過綁定 ioctl 介面withCAP_NET_ADMIN功能從使用者空間存取,使其成為潛在的本機拒絕服務向量。

透過在 NULL 檢查之後移動 slave_dbg() 呼叫來修正。(CVE-2026-53337)

在 Linux 核心中,下列弱點已解決:

signal:在 zap_other_threads() 中清除呼叫者的JOBCTL_PENDING_MASK

當多執行緒處理程序收到停止訊號(例如 SIGSTOP)時,do_signal_stop() 會在 allthreads 上設定 JOBCTL_STOP_PENDING 和 JOBCTL_STOP_CONSUME,並將訊號>group_stop_count設定為執行緒數。如果其中一個執行緒同時呼叫 execve()、de_thread() invokeszap_other_threads() 以終止所有其他執行緒。zap_other_threads()透過將 signal->group_stop_count 重設為 0 來中止擱置的群組停止,並清除所有其他執行緒的JOBCTL_PENDING_MASK。不過,它無法清除呼叫執行緒的作業控制旗標。

execve() 完成後,呼叫執行緒會返回使用者模式,並檢查擱置中的訊號。看到過時的 JOBCTL_STOP_PENDING 標誌,它調用 do_signal_stop(),調用 task_participate_group_stop()。由於 JOBCTL_STOP_CONSUME 仍處於設定狀態,因此它會嘗試遞減訊號>group_stop_count已經為零,從而觸發警告:

sig->group_stop_count == 0警告: CPU:1 PID:6475 at kernel/signal.c:373task_participate_group_stop+0x215/0x2d0呼叫追蹤:<TASK>do_signal_stop+0x3be/0x5c0 kernel/signal.c:2619get_signal+0xa8c/0x1330 kernel/signal.c:2884arch_do_signal_or_restart+0xbc/0x840 arch/x86/kernel/signal.c:337exit_to_user_mode_loop+0x8c/0x4d0 kernel/entry/common.c:98do_syscall_64+0x33e/0xf80 arch/x86/entry/syscall_64.c:100entry_SYSCALL_64_after_hwframe+0x77/0x7f</TASK>

清除 zap_other_threads() 中呼叫執行緒的JOBCTL_PENDING_MASK來修正此爭用情形,確保在執行緒群組遭到破壞後,它不會保留任何過時的工作控制狀態。這與拆卸執行緒群組並中止群組停止的其他函式保持一致,例如 zap_process() 和 complete_signal(),它們會正確清除所有執行緒的這些旗標,包括目前執行緒。
(CVE-2026-53352)

在 Linux 核心中,下列弱點已解決:

arm64: 勘誤表:緩解各種 Arm CPU 上的 TLBI 勘誤表

Arm 開發的許多 CPU 都存在勘誤,即 broadcastTLBI;DSB 序列可能會在全域觀察由受影響的 TLB 項目轉換的寫入之前完成。

這些勘誤僅影響已由無效 TLB 項目轉譯的記憶體存取的完成,而這些勘誤表不會影響 TLB 項目的實際失效。TLB 項目已正確移除。

已指派此問題 CVE ID CVE-2025-10263。

為了緩解此問題,Arm 建議軟體遵循任何受影響的 TLBI;DSB 序列,並加上額外的 TLBI;DSB,這將確保受第一個 TLBI 影響的所有記憶體寫入效果都已全域觀察。其他 TLBI 可以使用廣播至受影響 CPU 的任何作業,而其他 DSB 可以使用任何選項,足以完成額外的 TLBI。

ARM64_WORKAROUND_REPEAT_TLBI的因應措施足以緩解此問題。針對受影響的 CPU 啟用此因應措施,並據此更新晶片勘誤文件。

請注意,由於 Arm 開發 IP 和追蹤勘誤的方式,某些 CPU 共用一個共同的勘誤編號。(CVE-2026-53354)

在 Linux 核心中,下列弱點已解決:

drm/i915/gem: 修正具有位移 (CVE-2026-53356) 的 phys BO 前置詞/pwrite

在 Linux 核心中,下列弱點已解決:

net: garp:修正 garp_pdu_parse_attr 中的無符號整數反向溢位

接收端 GARP 屬性剖析器會以反向轉換器計算 dlen:

dlen = sizeof(*ga) - ga->len;

ga->len 是線上屬性長度,包括 GARP 屬性標頭。對於具有資料的一般屬性,ga->len 大於sizeof(*ga),因此減法在無符號算術中溢位。

結果值稍後會傳遞給 garp_attr_lookup(),其 length引數為 u8。截斷後,剖析的資料長度通常不再與為本機註冊的屬性儲存的長度相符,因此會忽略接收到的 Join/Leave 事件。這會中斷常見屬性(如GVRP VLAN註冊屬性)的GARP接收路徑。

將資料長度計算為屬性長度減去標頭長度。(CVE-2026-63868)

在 Linux 核心中,下列弱點已解決:

scsi: fcoe:拒絕 CVL walker 中fip_dlen為零的 FIP 描述元

drivers/scsi/fcoe/fcoe_ctlr.c::fcoe_ctlr_recv_clr_vlink() 由攻擊者提供的fip_dlen進階描述元游標,而不需要預設分支中的 dlen >= sizeof(struct fip_desc)。命名描述符案例 (FIP_DT_MAC、FIP_DT_NAME、FIP_DT_VN_ID) 檢查了它們每個類型的最小長度,但FIP_DT_NON_CRITICAL描述符 (fip_dtype >= 128,標準要求接收者無訊息地忽略) 完全跳過了該檢查。

FCoE 控制 VLAN 上未經身份驗證的 L2 對等體可以無限期地hangfcoe_ctlr_recv_work在 fcoe、qedf 或 bnx2fc 啟動器上,方法是發出一個 FIP CVL 幀,其單個描述符fip_dtype ==FIP_DT_NON_CRITICAL 且 fip_dlen == 0:游標進階零位元組重複,迴圈條件 rlen >= sizeof(*desc) 永遠保持 true, 封鎖該控制器上的每個後續 FIP 幀。

擰緊外部 dlen 保護以也拒絕 dlen< sizeof(structfip_desc),因此長度甚至無法覆蓋描述元標頭的格式錯誤的描述元在切換之前被拒絕。這與命名案例已套用的下限相同,也是閉環的最小範圍。(CVE-2026-63890)

在 Linux 核心中,下列弱點已解決:

USB:serial:mct_u232:修正缺少的中斷輸入傳輸健全性檢查

新增中斷傳入傳輸大小的缺失的健全性檢查,以避免剖析過時或未初始化的 slab 資料 (並將其洩漏給使用者空間)。(CVE-2026-63897)

在 Linux 核心中,下列弱點已解決:

USB:serial:mct_u232:使用小端點修正記憶體損毀 (CVE-2026-63898)

在 Linux 核心中,下列弱點已解決:

USB: serial: keyspan:修正缺少的 indat 傳輸健全性檢查

對 usa49wg indat 傳輸的大小新增缺少的健全性檢查,以避免剖析過時或未初始化的 slab 資料。(CVE-2026-63900)

在 Linux 核心中,下列弱點已解決:

USB:serial:digi_acceleport:修正小型端點的記憶體損毀

新增缺少的大量緩衝區大小健全性檢查,以避免在惡意裝置報告的緩衝區比預期小時發生越界記憶體存取或 slab 損毀。(CVE-2026-63901)

在 Linux 核心中,下列弱點已解決:

USB:serial:cypress_m8:驗證中斷封包標頭

cypress_read_int_callback() 會根據選取的 Cypress 封包格式剖析中斷輸入緩衝區。
格式 1 具有兩個位元組的狀態/計數標頭,而格式 2 具有一個位元組的結合狀態/計數標頭。
usb-serial 核心會從端點描述元的 wMaxPacketSize 調整中斷輸入緩衝區的大小,而未設定URB_SHORT_NOT_OK時,成功的中斷傳輸可以完成短。

在讀取之前,請檢查已完成的封包是否包含所選標頭。系統會忽略格式錯誤的短報表,並透過現有的重試路徑重新提交中斷 URB,以防止越界標頭位元組讀取。

KASAN 報告如下:大小為 1 的 cypress_read_int_callback+0x240/0x7f0 中的 KASAN 板越界讀取呼叫追蹤:cypress_read_int_callback() (drivers/usb/serial/cypress_m8.c:1009)__usb_hcd_giveback_urb()dummy_timer()

[ johan:在標頭長度健全性檢查中使用常數 ](CVE-2026-63902)

在 Linux 核心中,下列弱點已解決:

USB: serial: belkin_sa:驗證中斷狀態長度

Belkin 中斷回調將中斷資料視為四位元組狀態報告,並讀取位移 2 和 3 處的 LSR/MSR 欄位。中斷輸入緩衝區長度衍生自端點 wMaxPacketSize,而短中斷傳輸可能會以smalleractual_length成功完成。

在剖析 statusfields 之前,檢查已完成的中斷封包長度,以便忽略短中斷端點和短而成功的封包,而不是造成越界或過時的狀態位元組讀取。

KASAN 報告如下:

錯誤:KASAN:大小為 1 的 belkin_sa_read_int_callback() 讀取中的 slab-out-of-bound呼叫 trace:belkin_sa_read_int_callback() (drivers/usb/serial/belkin_sa.c:202)__usb_hcd_giveback_urb() (drivers/usb/core/hcd.c:1630)dummy_timer() (?:?)(CVE-2026-63903)

在 Linux 核心中,下列弱點已解決:

usb: usbtmc:檢查 URB actual_length是否有中斷 IN 通知

USBTMC 裝置可以使用選擇性的中斷端點來取得通知訊息。這些通常包含指示承載格式的兩位元組標頭,但驅動程式不會在存取資料緩衝區之前檢查這些標頭是否代表。如果URBactual_length不足以符合這些標頭,驅動程式會造成越界讀取,或取用先前通知的過時剩餘數據。

檢查標頭是否包含足夠的位元組actual_data以修正,否則將 URB 重新提交至中斷端點。(CVE-2026-63904)

在 Linux 核心中,下列弱點已解決:

xfrm: esp:還原組合的單片段長度閘門

ESP 就位快速路徑會在 esp_output_tail() 配置目的地頁面片段之前,在 esp_output_head() 中附加預告片。頭側閘門目前分別檢查 skb->data_len 和 tailen,但尾部代碼從組合後拖車 skb->data_len 中分配一個目的地片段。

當組合的對齊長度超過 apage 時,拒絕頁面片段快速路徑。否則,skb_page_frag_refill() 可能會回歸到單個頁面,而目標 sg 仍然跨越組合的 skb->data_len。

還原 IPv4 和 IPv6 的此組合長度分頁閘道。(CVE-2026-63912)

在 Linux 核心中,下列弱點已解決:

netfilter: conntrack: tcp:不要在沒有方向檢查的情況下對 invalid-seq RST 強制關閉 (CVE-2026-63913)

在 Linux 核心中,下列弱點已解決:

xfrm:將 MIGRATE 通知路由傳送至呼叫端的 netns (CVE-2026-63914)

在 Linux 核心中,下列弱點已解決:

HID: wacom:修正 wacom_hid_set_device_mode() 中的 OOB 寫入

wacom_hid_set_device_mode() 目前假設HID_DG_INPUTMODEusage一律位於功能報告的第一個欄位 (field[0]) 中。不過,裝置可以在不同的欄位中指定HID_DG_INPUTMODE。

如果HID_DG_INPUTMODE位於第一個欄位以外的欄位中,且第一個欄位的report_count小於HID_DG_INPUTMODE的usage_index,則會導致對 r->field[0]->value 的越界寫入。

透過在特徵映射期間將HID_DG_INPUTMODE的欄位索引儲存在「structhid_data」中來解決此問題。在wacom_hid_set_device_mode()中,使用這個儲存的欄位索引來存取正確的欄位,並新增邊界檢查以確保欄位索引和值索引都在寫入前的無效範圍內。(CVE-2026-63916)

在 Linux 核心中,下列弱點已解決:

ip6: vti:在 vti6_changelink() 中使用 ip6_tnl.net。(CVE-2026-63917)

在 Linux 核心中,下列弱點已解決:

xfrm: input:在延遲傳輸重新插入期間保留 netns (CVE-2026-63919)

在 Linux 核心中,下列弱點已解決:

ipv6:在複製到 CMSG (CVE-2026-63920) 之前驗證擴充功能標頭長度

在 Linux 核心中,下列弱點已解決:

ip6: vti:在 vti6_siocdevprivate() 中使用 ip6_tnl.net。

在本系列的修補程式 1/2 之後,vti6_update() 會透過 t->net 取消連結並重新連結通道。
vti6_siocdevprivate() 仍usesdev_net(dev) 進行衝突查詢。對於移動throughIFLA_NET_NS_FD的隧道,dev_net(dev) 是新的 netns,而不是 t->net。

SIOCCHGTUNNEL 接著在移轉的通道上執行:

net = dev_net(dev) /* 移轉的 netns */t = vti6_locate(net, &p1, false) /* 在 t->net 中遺漏目標 */...t = netdev_priv(dev)vti6_update(t, &p1, false) /* 改變 t->net 的雜湊
*/

移轉的 netns 中的呼叫端會挑選符合建立 netns 中通道的參數。dev_net(dev) 中的查詢會發現 nothing.vti6_update() 會在這些參數的建立 netns 雜湊儲存桶的前面加上移轉的通道。建立 netns 中稍後的查詢會解析為移轉的裝置。xfrm receive會透過呼叫端控制的裝置傳遞相符的封包。

可從無特權的使用者命名空間連線 (取消共用 --user--map-root-user --net)。容器主機上的跨租用戶範圍。

將非後援裝置上的 SIOCCHGTUNNEL 路徑切換為 uset->net 進行查詢。查詢現在與 netnsvti6_update() 操作的相符。

另外,在查詢之前新增 ns_capable(self->net->user_ns, CAP_NET_ADMIN)。案例頂端的檢查是 againstdev_net(dev)->user_ns,移轉後就是攻擊者的 snetns。那裡的調用者可以選擇 self->net 中不存在的參數,查找返回 NULL,t 變為 self,並且 vti6_update()將設備插入創建 netns 哈希中。新的檢查也需要在建立 netns user_ns中CAP_NET_ADMIN。

SIOCADDTUNNEL 和 SIOCCHGTUNNEL 在後援裝置 keepdev_net (dev) 上,這等於那裡的init_net。
(CVE-2026-63921)

在 Linux 核心中,下列弱點已解決:

ipv6: exthdrs:在 ipv6_hop_jumbo() 之後重新整理 NH 指標

ipv6_hop_jumbo() 呼叫 pskb_trim_rcsum(),可以更改 skb 指標。讓我們重新計算 nh 指標,以確保任何更改都不會把事情搞砸。(CVE-2026-63924)

在 Linux 核心中,下列弱點已解決:

macsec:修正 XPN lower-PN 換行 (CVE-2026-63925) 處的重播保護

在 Linux 核心中,下列弱點已解決:

bpf: sockmap:修正bpf_msg_push_data中的尾部片段偏移

當 bpf_msg_push_data() 在 scatterlistentry 中間插入資料時,它會將原始項目拆分為左側片段和右側片段。

正確的片段位移量是頁面本機,但程式碼會使用「start」來推進它,這是訊息全域插入點。對於插入到非第一個 SG 項目中,這會過度推進偏移並使分割佈局不一致。

將右側片段偏移量前推進片段局部增量「開始 - 偏移量」,該增量與從原始項目前面移除的長度相符。(CVE-2026-63926)

在 Linux 核心中,下列弱點已解決:

USB:serial:omninet:修正具有小型端點的記憶體損毀

請確定大量緩衝區至少與硬式編碼傳輸大小一樣大,以避免使用者控制的 slab 損毀,惡意裝置應該報告比預期更小的端點封包大小上限。(CVE-2026-63928)

在 Linux 核心中,下列弱點已解決:

USB:serial:cypress_m8:修正具有小型端點的記憶體損毀

請確定中斷端點封包大小上限至少為八個位元組,以避免使用者控制的 slab 損毀或惡意裝置報告較小大小時的 NULL 指標解除參照。
(CVE-2026-63956)

在 Linux 核心中,下列弱點已解決:

USB:serial:safe_serial:修正具有小型端點的記憶體損毀 (CVE-2026-63957)

在 Linux 核心中,下列弱點已解決:

sctp:修正 sctp_wait_for_connect 和 peeloff 之間的爭用

sctp_wait_for_connect() 在等待關聯達到 ESTABLISHED 狀態時刪除並重新取得通訊端鎖定。在此視窗期間,另一個執行緒可以剝離與新通訊端 viagetsockopt(SCTP_SOCKOPT_PEELOFF) 的關聯,以變更 asoc->base.sk。重新取得舊的通訊端鎖定後,sctp_wait_for_connect() 傳回成功而不註意到遷移 -- 然後調用方在 sctp_datamsg_from_user() 中錯誤的鎖定下存取關聯。

新增 sctp_wait_for_sndbuf() 已經進行的相同 sk != asoc->base.sk 檢查,如果關聯是在我們睡覺時遷移的,則傳回錯誤。(CVE-2026-63971)

在 Linux 核心中,下列弱點已解決:

ipv6: rpl:修正 ipv6_rpl_srh_decompress() 中的 hdrlen 溢位 (CVE-2026-63984)

在 Linux 核心中,下列弱點已解決:

隧道:不要假設 iptunnel_pmtud_check_icmp() 中的傳輸標頭 (CVE-2026-63992)

在 Linux 核心中,下列弱點已解決:

vxlan:不要在 skb_tunnel_check_pmtu() 之後重複使用快取的 ip_hdr() 值 (CVE-2026-63993)

在 Linux 核心中,下列弱點已解決:

隧道:在 IPT 中的 skb_cow() 之後載入網路標頭 ...

請注意,由於長度原因,描述已被截斷。如需完整說明,請參閱供應商公告。

Tenable 已直接從所測試產品的安全公告擷取前置描述區塊。

請注意,Nessus 並未測試這些問題,而是僅依據應用程式自我報告的版本號碼作出判斷。

解決方案

執行「yum update kernel」或「yum update --advisory ALAS2KERNEL-5.10-2026-124」以更新您的系統。

另請參閱

https://alas.aws.amazon.com//AL2/ALAS2KERNEL-5.10-2026-124.html

https://alas.aws.amazon.com/faqs.html

https://explore.alas.aws.amazon.com/CVE-2026-23449.html

https://explore.alas.aws.amazon.com/CVE-2026-31449.html

https://explore.alas.aws.amazon.com/CVE-2026-31533.html

https://explore.alas.aws.amazon.com/CVE-2026-31708.html

https://explore.alas.aws.amazon.com/CVE-2026-43350.html

https://explore.alas.aws.amazon.com/CVE-2026-43492.html

https://explore.alas.aws.amazon.com/CVE-2026-45850.html

https://explore.alas.aws.amazon.com/CVE-2026-45991.html

https://explore.alas.aws.amazon.com/CVE-2026-46021.html

https://explore.alas.aws.amazon.com/CVE-2026-46052.html

https://explore.alas.aws.amazon.com/CVE-2026-46086.html

https://explore.alas.aws.amazon.com/CVE-2026-46107.html

https://explore.alas.aws.amazon.com/CVE-2026-46137.html

https://explore.alas.aws.amazon.com/CVE-2026-46159.html

https://explore.alas.aws.amazon.com/CVE-2026-46160.html

https://explore.alas.aws.amazon.com/CVE-2026-46169.html

https://explore.alas.aws.amazon.com/CVE-2026-46191.html

https://explore.alas.aws.amazon.com/CVE-2026-46196.html

https://explore.alas.aws.amazon.com/CVE-2026-46292.html

https://explore.alas.aws.amazon.com/CVE-2026-46299.html

https://explore.alas.aws.amazon.com/CVE-2026-46320.html

https://explore.alas.aws.amazon.com/CVE-2026-46321.html

https://explore.alas.aws.amazon.com/CVE-2026-46322.html

https://explore.alas.aws.amazon.com/CVE-2026-52910.html

https://explore.alas.aws.amazon.com/CVE-2026-52912.html

https://explore.alas.aws.amazon.com/CVE-2026-52923.html

https://explore.alas.aws.amazon.com/CVE-2026-52924.html

https://explore.alas.aws.amazon.com/CVE-2026-52927.html

https://explore.alas.aws.amazon.com/CVE-2026-52929.html

https://explore.alas.aws.amazon.com/CVE-2026-52930.html

https://explore.alas.aws.amazon.com/CVE-2026-52943.html

https://explore.alas.aws.amazon.com/CVE-2026-52946.html

https://explore.alas.aws.amazon.com/CVE-2026-52948.html

https://explore.alas.aws.amazon.com/CVE-2026-53080.html

https://explore.alas.aws.amazon.com/CVE-2026-53133.html

https://explore.alas.aws.amazon.com/CVE-2026-53134.html

https://explore.alas.aws.amazon.com/CVE-2026-53168.html

https://explore.alas.aws.amazon.com/CVE-2026-53176.html

https://explore.alas.aws.amazon.com/CVE-2026-53186.html

https://explore.alas.aws.amazon.com/CVE-2026-53189.html

https://explore.alas.aws.amazon.com/CVE-2026-53194.html

https://explore.alas.aws.amazon.com/CVE-2026-53195.html

https://explore.alas.aws.amazon.com/CVE-2026-53196.html

https://explore.alas.aws.amazon.com/CVE-2026-53199.html

https://explore.alas.aws.amazon.com/CVE-2026-53212.html

https://explore.alas.aws.amazon.com/CVE-2026-53218.html

https://explore.alas.aws.amazon.com/CVE-2026-53219.html

https://explore.alas.aws.amazon.com/CVE-2026-53221.html

https://explore.alas.aws.amazon.com/CVE-2026-53223.html

https://explore.alas.aws.amazon.com/CVE-2026-53225.html

https://explore.alas.aws.amazon.com/CVE-2026-53227.html

https://explore.alas.aws.amazon.com/CVE-2026-53228.html

https://explore.alas.aws.amazon.com/CVE-2026-53238.html

https://explore.alas.aws.amazon.com/CVE-2026-53239.html

https://explore.alas.aws.amazon.com/CVE-2026-53245.html

https://explore.alas.aws.amazon.com/CVE-2026-53249.html

https://explore.alas.aws.amazon.com/CVE-2026-53264.html

https://explore.alas.aws.amazon.com/CVE-2026-53266.html

https://explore.alas.aws.amazon.com/CVE-2026-53268.html

https://explore.alas.aws.amazon.com/CVE-2026-53269.html

https://explore.alas.aws.amazon.com/CVE-2026-53270.html

https://explore.alas.aws.amazon.com/CVE-2026-53337.html

https://explore.alas.aws.amazon.com/CVE-2026-53352.html

https://explore.alas.aws.amazon.com/CVE-2026-53354.html

https://explore.alas.aws.amazon.com/CVE-2026-53356.html

https://explore.alas.aws.amazon.com/CVE-2026-63868.html

https://explore.alas.aws.amazon.com/CVE-2026-63890.html

https://explore.alas.aws.amazon.com/CVE-2026-63897.html

https://explore.alas.aws.amazon.com/CVE-2026-63898.html

https://explore.alas.aws.amazon.com/CVE-2026-63900.html

https://explore.alas.aws.amazon.com/CVE-2026-63901.html

https://explore.alas.aws.amazon.com/CVE-2026-63902.html

https://explore.alas.aws.amazon.com/CVE-2026-63903.html

https://explore.alas.aws.amazon.com/CVE-2026-63904.html

https://explore.alas.aws.amazon.com/CVE-2026-63912.html

https://explore.alas.aws.amazon.com/CVE-2026-63913.html

https://explore.alas.aws.amazon.com/CVE-2026-63914.html

https://explore.alas.aws.amazon.com/CVE-2026-63916.html

https://explore.alas.aws.amazon.com/CVE-2026-63917.html

https://explore.alas.aws.amazon.com/CVE-2026-63919.html

https://explore.alas.aws.amazon.com/CVE-2026-63920.html

https://explore.alas.aws.amazon.com/CVE-2026-63921.html

https://explore.alas.aws.amazon.com/CVE-2026-63924.html

https://explore.alas.aws.amazon.com/CVE-2026-63925.html

https://explore.alas.aws.amazon.com/CVE-2026-63926.html

https://explore.alas.aws.amazon.com/CVE-2026-63928.html

https://explore.alas.aws.amazon.com/CVE-2026-63956.html

https://explore.alas.aws.amazon.com/CVE-2026-63957.html

https://explore.alas.aws.amazon.com/CVE-2026-63971.html

https://explore.alas.aws.amazon.com/CVE-2026-63984.html

https://explore.alas.aws.amazon.com/CVE-2026-63992.html

https://explore.alas.aws.amazon.com/CVE-2026-63993.html

https://explore.alas.aws.amazon.com/CVE-2026-63994.html

https://explore.alas.aws.amazon.com/CVE-2026-64005.html

https://explore.alas.aws.amazon.com/CVE-2026-64007.html

https://explore.alas.aws.amazon.com/CVE-2026-64009.html

https://explore.alas.aws.amazon.com/CVE-2026-64012.html

https://explore.alas.aws.amazon.com/CVE-2026-64118.html

https://explore.alas.aws.amazon.com/CVE-2026-64170.html

Plugin 詳細資訊

嚴重性: High

ID: 325574

檔案名稱: al2_ALASKERNEL-5_10-2026-124.nasl

版本: 1.3

類型: Local

代理程式: unix

已發布: 2026/7/8

已更新: 2026/7/31

支援的感應器: Agentless Assessment, Continuous Assessment, Frictionless Assessment Agent, Frictionless Assessment AWS, Nessus Agent, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

風險資訊

VPR

風險因素: High

分數: 7.9

百分位數: 99.36

CVSS v2

風險因素: High

基本分數: 7.2

時間性分數: 5.6

媒介: CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C

CVSS 評分資料來源: CVE-2026-53196

CVSS v3

風險因素: High

基本分數: 7.8

時間性分數: 7

媒介: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

時間媒介: CVSS:3.0/E:P/RL:O/RC:C

CVSS 評分資料來源: CVE-2026-53195

弱點資訊

CPE: cpe:/o:amazon:linux:2, p-cpe:/a:amazon:linux:bpftool-debuginfo, p-cpe:/a:amazon:linux:bpftool, p-cpe:/a:amazon:linux:kernel-debuginfo-common-aarch64, p-cpe:/a:amazon:linux:kernel-debuginfo-common-x86_64, p-cpe:/a:amazon:linux:kernel-debuginfo, p-cpe:/a:amazon:linux:kernel-devel, p-cpe:/a:amazon:linux:kernel-headers, p-cpe:/a:amazon:linux:kernel-livepatch-5.10.259-258.1043, p-cpe:/a:amazon:linux:kernel-tools-debuginfo, p-cpe:/a:amazon:linux:kernel-tools-devel, p-cpe:/a:amazon:linux:kernel-tools, p-cpe:/a:amazon:linux:kernel, p-cpe:/a:amazon:linux:perf-debuginfo, p-cpe:/a:amazon:linux:perf, p-cpe:/a:amazon:linux:python-perf-debuginfo, p-cpe:/a:amazon:linux:python-perf

必要的 KB 項目: Host/local_checks_enabled, Host/AmazonLinux/release, Host/AmazonLinux/rpm-list

可被惡意程式利用: true

可輕鬆利用: Exploits are available

修補程式發佈日期: 2026/7/8

弱點發布日期: 2026/4/3

參考資訊

CVE: CVE-2026-23449, CVE-2026-31449, CVE-2026-31533, CVE-2026-31708, CVE-2026-43350, CVE-2026-43492, CVE-2026-45850, CVE-2026-45991, CVE-2026-46021, CVE-2026-46052, CVE-2026-46086, CVE-2026-46107, CVE-2026-46137, CVE-2026-46159, CVE-2026-46160, CVE-2026-46169, CVE-2026-46191, CVE-2026-46196, CVE-2026-46292, CVE-2026-46299, CVE-2026-46320, CVE-2026-46321, CVE-2026-46322, CVE-2026-52910, CVE-2026-52912, CVE-2026-52923, CVE-2026-52924, CVE-2026-52927, CVE-2026-52929, CVE-2026-52930, CVE-2026-52943, CVE-2026-52946, CVE-2026-52948, CVE-2026-53080, CVE-2026-53133, CVE-2026-53134, CVE-2026-53168, CVE-2026-53176, CVE-2026-53186, CVE-2026-53189, CVE-2026-53194, CVE-2026-53195, CVE-2026-53196, CVE-2026-53199, CVE-2026-53212, CVE-2026-53218, CVE-2026-53219, CVE-2026-53221, CVE-2026-53223, CVE-2026-53225, CVE-2026-53227, CVE-2026-53228, CVE-2026-53238, CVE-2026-53239, CVE-2026-53245, CVE-2026-53249, CVE-2026-53264, CVE-2026-53266, CVE-2026-53268, CVE-2026-53269, CVE-2026-53270, CVE-2026-53337, CVE-2026-53352, CVE-2026-53354, CVE-2026-53356, CVE-2026-63868, CVE-2026-63890, CVE-2026-63897, CVE-2026-63898, CVE-2026-63900, CVE-2026-63901, CVE-2026-63902, CVE-2026-63903, CVE-2026-63904, CVE-2026-63912, CVE-2026-63913, CVE-2026-63914, CVE-2026-63916, CVE-2026-63917, CVE-2026-63919, CVE-2026-63920, CVE-2026-63921, CVE-2026-63924, CVE-2026-63925, CVE-2026-63926, CVE-2026-63928, CVE-2026-63956, CVE-2026-63957, CVE-2026-63971, CVE-2026-63984, CVE-2026-63992, CVE-2026-63993, CVE-2026-63994, CVE-2026-64005, CVE-2026-64007, CVE-2026-64009, CVE-2026-64012, CVE-2026-64118, CVE-2026-64170