Linux Distros 未修補弱點:CVE-2026-74660

critical Nessus Plugin ID 338879

概要

Linux/Unix 主機上安裝的一個或多個套件存有弱點,廠商表示將不會修補。

說明

Linux/Unix 主機上安裝了一個或多個受到弱點影響的套件,且廠商未提供可用的修補程式。

- netfilter: ebt_nflog:釘選 NFLOG 後端 nf_log_unregister() 在每網拆解後執行,因此其最終的 RCU 寬限期也會耗盡從每網綁定取得記錄器的讀取器。但是,與 xt_NFLOG 和 nft_log 前端不同,ebt_nflog 將明確的 ULOG 日誌類型傳遞給 nf_log_packet(),而不保留所選記錄器模組上的引用。因此,當卸載 nfnetlink_log 時,ebtables nflog 規則可以保持可呼叫狀態。產生的交錯為: CPU 0 CPU 1 nfnetlink_log_fini() unregister_pernet_subsys() kfree(nfnl_log_pernet(net)) ebt_nflog_tg() nf_log_packet() nfulnl_log_packet() instance_lookup_get_rcu() 全域 ULOG 記錄器此時仍處於註冊狀態狀態,因此 CPU 0 釋放 per-net 狀態後,CPU 1 會取消參照它。KASAN 報告: 錯誤:KASAN:在 instance_lookup_get_rcu 中釋放後使用 slab-use-after-free 透過任務 poc/92 在 addr ff110001052e6210 讀取大小 8 呼叫追蹤:
instance_lookup_get_rcu+0x1ce/0x1f0 [nfnetlink_log] nfulnl_log_packet+0x248/0x2fb0 [nfnetlink_log] nf_log_packet+0x204/0x300 ebt_nflog_tg+0x351/0x550 ebt_do_table+0xedf/0x22b0 由工作 90 分配:
__kmalloc_noprof+0x186/0x470 ops_init+0x6d/0x420 register_pernet_operations+0x2f6/0x670 register_pernet_subsys+0x23/0x40 由工作 93 釋放:kfree+0x131/0x3c0 ops_undo_list+0x3e3/0x700 unregister_pernet_operations+0x232/0x490 unregister_pernet_subsys+0x1c/0x30 nfnetlink_log_fini+0x34/0x450 [nfnetlink_log] 驗證 ebt_nflog 規則時取得 ULOG 記錄器模組參照,並在規則被銷毀時釋放它。需要時,為舊版呼叫者請求 NFLOG 後端,與xt_NFLOG相符。這可防止模組拆卸,直到所有ebt_nflog規則都停止使用記錄器。
(CVE-2026-74660)

請注意,Nessus 依賴供應商報告的套件存在。

解決方案

目前尚未有已知的解決方案。

另請參閱

https://security-tracker.debian.org/tracker/CVE-2026-74660

Plugin 詳細資訊

嚴重性: Critical

ID: 338879

檔案名稱: unpatched_CVE_2026_74660.nasl

版本: 1.1

類型: Local

代理程式: unix

系列: Misc.

已發布: 2026/8/22

已更新: 2026/8/22

支援的感應器: Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

風險資訊

VPR

風險因素: Medium

分數: 4.3

百分位數: 53.51

CVSS v2

風險因素: High

基本分數: 7.5

時間性分數: 6.4

媒介: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS 評分資料來源: CVE-2026-74660

CVSS v3

風險因素: Critical

基本分數: 9.8

時間性分數: 9

媒介: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

時間媒介: CVSS:3.0/E:U/RL:U/RC:C

弱點資訊

CPE: cpe:/o:debian:debian_linux:11.0, cpe:/o:debian:debian_linux:12.0, cpe:/o:debian:debian_linux:13.0, cpe:/o:debian:debian_linux:14.0, p-cpe:/a:debian:debian_linux:linux

必要的 KB 項目: Host/local_checks_enabled, Host/cpu, global_settings/vendor_unpatched, Host/OS/identifier

可輕鬆利用: No known exploits are available

弱點發布日期: 2026/8/22

參考資訊

CVE: CVE-2026-74660