Linux Distros 未修補弱點:CVE-2026-74289

critical Nessus Plugin ID 335521

概要

Linux/Unix 主機上安裝的一個或多個套件存有弱點,廠商表示將不會修補。

說明

Linux/Unix 主機上安裝了一個或多個受到弱點影響的套件,且廠商未提供可用的修補程式。

- ipv4: fib:不要在 fib_leaf_notify() 中轉儲垂死的fib_info。syzbot 在 nsim_fib4_prepare_event() 中報告釋放後使用。[0] 問題是,以下函數在RCU下轉儲fib_info時調用fib_info_hold() / refcount_inc(),這是不安全的。* mlxsw_sp_router_fib4_event() * rocker_router_fib_event() * 必須使用 nsim_fib4_prepare_event() refcount_inc_not_zero(),但為時已晚。讓我們保證 fib_leaf_notify() 中fib_info的生命週期。請注意,IPv6 不需要對應的變更,因為 fib6_table_dump() 保留 fib6_table.tb6_lock。[0]:refcount_t:0 上加法;釋放後使用。警告: lib/refcount.c:25 at refcount_warn_saturate+0x9f/0x110 lib/refcount.c:25, CPU#0: kworker/u8:15/3420 連結的模組: CPU: 0 UID: 0 PID: 3420 通訊: kworker/u8:15 未受污染的 syzkaller #0 PREEMPT_{RT,(full)} 硬體名稱:Google Google Compute Engine/Google Compute Engine, BIOS Google 04/18/2026 工作佇列:netns cleanup_net RIP:0010:refcount_warn_saturate+0x9f/0x110 lib/refcount.c:25 程式碼: EB 66 85 DB 74 3e 83 FB 01 75 4C E8 1B F1 22 FD 48 8D 3D 84 CB F1 0A 67 48 0F B9 3A EB 4A E8 08 F1 22 FD 48 8D 3D 81 CB F1 0A 48 0F <67> B9 3A EB 37 E8 F5 F0 22 FD 48 8D 3D 7E CB F1 0A 67 48 0f RSP: 0018:ffffc9000f2c7270 EFLAGS:00010293 RAX:ffffffff84a18858 RBX:0000000000000002 RCX:
ffff888032ff9ec0 RDX:00000000000000000000 RSI:000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 ffff888032ff9ec0 R09: 0000000000000005 : 0000000000000100 R10R11: 0000000000000004 R12:R08
ffff8880570cc000 R13: dffffc0000000000 R14: ffff88802b40563c R15: ffff8880570cc000 FS:
00000000000000000(0000) GS:ffff888126173000(0000) knlGS:000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
0000000080050033 CR2:00007fb1f4d5d000 CR3:000000006072a000 CR4:00000000003526f0 呼叫追蹤: <TASK>
__refcount_add include/linux/refcount.h:-1 [內聯] __refcount_inc include/linux/refcount.h:366 [內聯] refcount_inc include/linux/refcount.h:383 [內聯] fib_info_hold include/net/ip_fib.h:629 [內聯] nsim_fib4_prepare_event drivers/net/netdevsim/fib.c:930 [內聯] nsim_fib_event_schedule_work drivers/net/netdevsim/fib.c:1000 [內聯] nsim_fib_event_nb+0x1055/0x1240 drivers/net/netdevsim/fib.c:1043 call_fib_notifier+0x45/0x80 net/core/fib_notifier.c:25 call_fib_entry_notifier net/ipv4/fib_trie.c:90 [內嵌] fib_leaf_notify net/ipv4/fib_trie.c:2176 [內嵌] fib_table_notify net/ipv4/fib_trie.c:2194 [內嵌] fib_notify+0x36b/0x5e0 net/ipv4/fib_trie.c:2217 fib_net_dump net/core/fib_notifier.c:70 [內嵌] register_fib_notifier+0x184/0x360 net/core/fib_notifier.c:108 nsim_fib_create+0x85d/0x9f0 drivers/net/netdevsim/fib.c:1596 nsim_dev_reload_create drivers/net/netdevsim/dev.c:1604 [內嵌] nsim_dev_reload_up+0x374/0x7c0 drivers/net/netdevsim/dev.c:1058 devlink_reload+0x501/0x8d0 net/devlink/dev.c:475 devlink_pernet_pre_exit+0x1ff/0x420 net/devlink/core.c:558 ops_pre_exit_list net/core/net_namespace.c:161 [內嵌] ops_undo_list+0x187/0x940 net/core/net_namespace.c:234 cleanup_net+0x56e/0x800 net/core/net_namespace.c:702 process_one_work kernel/workqueue.c:3314 [內嵌] process_scheduled_works+0xb5d/0x1860 kernel/workqueue.c:3397 worker_thread+0xa53/0xfc0 kernel/workqueue.c:3478 kthread+0x388/0x470 kernel/kthread.c:436 ret_from_fork+0x514/0xb70 arch/x86/kernel/process.c:158 ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245 </TASK> (CVE-2026-74289)

請注意,Nessus 的判定取決於廠商所報告的套件是否存在。

解決方案

目前尚未有已知的解決方案。

另請參閱

https://security-tracker.debian.org/tracker/CVE-2026-74289

Plugin 詳細資訊

嚴重性: Critical

ID: 335521

檔案名稱: unpatched_CVE_2026_74289.nasl

版本: 1.1

類型: Local

代理程式: unix

系列: Misc.

已發布: 2026/8/15

已更新: 2026/8/15

支援的感應器: Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

風險資訊

VPR

風險因素: Medium

分數: 6.3

百分位數: 96.61

CVSS v2

風險因素: High

基本分數: 7.5

時間性分數: 6.4

媒介: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS 評分資料來源: CVE-2026-74289

CVSS v3

風險因素: Critical

基本分數: 9.8

時間性分數: 9

媒介: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

時間媒介: CVSS:3.0/E:U/RL:U/RC:C

弱點資訊

CPE: cpe:/o:debian:debian_linux:11.0, cpe:/o:debian:debian_linux:12.0, cpe:/o:debian:debian_linux:13.0, p-cpe:/a:debian:debian_linux:linux

必要的 KB 項目: Host/local_checks_enabled, Host/cpu, global_settings/vendor_unpatched, Host/OS/identifier

可輕鬆利用: No known exploits are available

弱點發布日期: 2026/8/15

參考資訊

CVE: CVE-2026-74289