Amazon Linux 2023:bpftool6.12、kernel6.12、kernel6.12-devel (ALAS2023-2026-2110)

medium Nessus Plugin ID 341899

概要

遠端 Amazon Linux 2023 主機缺少一個安全性更新。

說明

因此,會受到 ALAS2023-2026-2110 公告中所提及的多個弱點影響。

在 Linux 核心中,下列弱點已解決:

netfilter: nft_counter:使用微調鎖 (CVE-2026-45897) 序列化重設

在 Linux 核心中,下列弱點已解決:

netfilter: nf_tables:還原重設路徑 (CVE-2026-45901) 中的commit_mutex用法

在 Linux 核心中,下列弱點已解決:

bpf:修正子程序 (CVE-2026-53090) 中的 ld_{abs,ind} 故障路徑分析

在 Linux 核心中,下列弱點已解決:

blk-mq:如果快取的要求可用,則彈出 (CVE-2026-64017)

在 Linux 核心中,下列弱點已解決:

i2c: i801:修正錯誤路徑 (CVE-2026-64205) 中的硬體狀態機器損毀

在 Linux 核心中,下列弱點已解決:

iommufd:在 iommufd_fault_fops_read()CVE-2026-64290 () 中失敗時中斷迴圈

在 Linux 核心中,下列弱點已解決:

KVM: nVMX:在 VMCLEAR 之後立即隱藏影子 VMCS (CVE-2026-64562)

在 Linux 核心中,下列弱點已解決:

rhashtable:在表格重新啟動時清除過時的 iter->p (CVE-2026-64563)

在 Linux 核心中,下列弱點已解決:

sctp:不要在 DEL-IP 處理中釋放 ASCONF 自己的傳輸 (CVE-2026-64564)

在 Linux 核心中,下列弱點已解決:

btrfs:拒絕項目多於頁面的可用空間快取 (CVE-2026-64567)

在 Linux 核心中,下列弱點已解決:

ipv4: fib:在插入錯誤路徑上釋放帶有 kfree_rcu() 的fib_alias (CVE-2026-64572)

在 Linux 核心中,下列弱點已解決:

nexthop:在 nh_res_bucket_migrate() 中初始化 extack (CVE-2026-64576)

在 Linux 核心中,下列弱點已解決:

xfrm: policy:在xfrm_hash_rebuild重新插入之前預先配置不精確的 bin (CVE-2026-64579)

在 Linux 核心中,下列弱點已解決:

xfrm6:錯誤時清除 dst.dev 以避免 xfrm6_fill_dst()CVE-2026-64580 () 中的重複netdev_put

在 Linux 核心中,下列弱點已解決:

xfrm:修正 xfrm_user_policy() 中的雙重釋放sk_dst_cache (CVE-2026-64581)

在 Linux 核心中,下列弱點已解決:

KVM: SVM:CPU 上的凸起asid_generation線上,以避免熱插拔後發生 ASID 衝突 (CVE-2026-68093)

在 Linux 核心中,下列弱點已解決:

audit:修正 audit_dupe_exe() 中的遞迴鎖定鎖死 (CVE-2026-68096)

在 Linux 核心中,下列弱點已解決:

vxlan: mdb:修正替換失敗時的來源清單損毀 (CVE-2026-68116)

在 Linux 核心中,下列弱點已解決:

提示:清除 tipc_sk_create() 中失敗插入路徑上的 sock->sk (CVE-2026-68117)

在 Linux 核心中,下列弱點已解決:

pppoe:在 dev_hard_header() (CVE-2026-68121) 之後重新載入標頭指標

在 Linux 核心中,下列弱點已解決:

openvswitch:修正 GSO 使用者空間截斷反向溢位 (CVE-2026-68123)

在 Linux 核心中,下列弱點已解決:

ila:在總和檢查碼 adjust (CVE-2026-68127) 中pskb_may_pull後重新載入 IPv6 標頭

在 Linux 核心中,下列弱點已解決:

ice:拒絕 ice_parser_profile_init (CVE-2026-68128) 中超出範圍的 ptype

在 Linux 核心中,下列弱點已解決:

rbd:將物件對應更新路徑中的正結果代碼重設為零 (CVE-2026-68131)

在 Linux 核心中,下列弱點已解決:

ice:修正 PTP 發佈期間的 PTP 呼叫跟蹤 (CVE-2026-68133)

在 Linux 核心中,下列弱點已解決:

net: gro:修正齊清標記的 skb 的雙重彙總 (CVE-2026-68136)

在 Linux 核心中,下列弱點已解決:

net/sched:針對並行 get/put (CVE-2026-68138) 序列化 qdisc_rtab_list

在 Linux 核心中,下列弱點已解決:

net/mlx5e:使用 sender devcom 進行 MPV 主控 (CVE-2026-68139)

在 Linux 核心中,下列弱點已解決:

geneve:需要在裝置 netns 中CAP_NET_ADMIN以進行 changelink (CVE-2026-68142)

在 Linux 核心中,下列弱點已解決:

iomap:修正具有零長度範圍CVE-2026-68145的越界 bitmap_set() ()

在 Linux 核心中,下列弱點已解決:

ftrace:新增全域互斥以序列化 trace_parser 存取 (CVE-2026-68146)

在 Linux 核心中,下列弱點已解決:

fs:在 forget_cached_acl() 中保留ACL_DONT_CACHE狀態 (CVE-2026-68149)

在 Linux 核心中,下列弱點已解決:

libceph:在用戶端拆卸之前移除 debugfs 檔案 (CVE-2026-68153)

在 Linux 核心中,下列弱點已解決:

libceph:拒絕 crush_decode (CVE-2026-68154) 中的零儲存貯體類型

在 Linux 核心中,下列弱點已解決:

libceph:拒絕 monmaps 通告零監視器 (CVE-2026-68155)

在 Linux 核心中,下列弱點已解決:

libceph:授權者更新後重新整理 auth->authorizer_buf{,_len} (CVE-2026-68156)

在 Linux 核心中,下列弱點已解決:

libceph:保護缺少 CRUSH 類型名稱查詢 (CVE-2026-68157)

在 Linux 核心中,下列弱點已解決:

libceph:修正 decode_new_up_state_weight() 中的乘法溢位 (CVE-2026-68158)

在 Linux 核心中,下列弱點已解決:

Ceph:修正 ceph_handle_caps() 中 Snaptrace 上的預先驗證越界讀取 (CVE-2026-68160)

在 Linux 核心中,下列弱點已解決:

sctp:在 netns 拆卸期間關閉 UDP 通道通訊端 (CVE-2026-68161)

在 Linux 核心中,下列弱點已解決:

sctp:避免在 netns 拆卸期間auth_enable sysctl UAF (CVE-2026-68162)

在 Linux 核心中,下列弱點已解決:

mm/damon/core:不允許 damon_set_regions() 的重疊輸入範圍 (CVE-2026-68164)

在 Linux 核心中,下列弱點已解決:

mm/damon/core:驗證 damon_set_regions() 中的範圍 (CVE-2026-68165)

在 Linux 核心中,下列弱點已解決:

mptcp: pm: userspace:修正 get_local_id 中的釋放後使用 (CVE-2026-68169)

在 Linux 核心中,下列弱點已解決:

misc: nsm:裝置開啟時固定模組 (CVE-2026-68178)

在 Linux 核心中,下列弱點已解決:

misc: nsm:僅在鎖定後錯誤路徑上解鎖nsm_dev (CVE-2026-68179)

在 Linux 核心中,下列弱點已解決:

cdrom:修正 CDROMVOLCTRL 中的堆疊越界讀取 (CVE-2026-68184)

在 Linux 核心中,下列弱點已解決:

binfmt_misc:僅在解譯器開啟後設定have_execfd (CVE-2026-68186)

在 Linux 核心中,下列弱點已解決:

drm/i915/gem: 修正 I915_CONTEXT_PARAM_SSEU 中的 NULL 解除參照 (CVE-2026-68243)

在 Linux 核心中,下列弱點已解決:

drm/i915/gem:不要在原始上下文錯誤 (CVE-2026-68244) 上洩露 siblings[]

在 Linux 核心中,下列弱點已解決:

drm/i915/bios:範圍檢查 LFP 資料區塊 panel_type2 (CVE-2026-68247)

在 Linux 核心中,下列弱點已解決:

drm/i915:active_instance (CVE-2026-68248) 中出錯時傳回 NULL

在 Linux 核心中,下列弱點已解決:

drm/i915/hdcp:在溢位前檢查 streams[] 邊界 (CVE-2026-68253)

在 Linux 核心中,下列弱點已解決:

drm/i915/vrr:需要 VRR 的有效最小/最大 vfreq (CVE-2026-68254)

在 Linux 核心中,下列弱點已解決:

drm/virtio:繫結的 EDID 區塊讀取到回應緩衝區 (CVE-2026-68255)

在 Linux 核心中,下列弱點已解決:

drm/i915/gem: 在平行提交槽位 (CVE-2026-68269) 上新增缺少的 nospec

在 Linux 核心中,下列弱點已解決:

drm/dp/mst:修正邊帶回覆剖析器 (CVE-2026-68277) 中 2 位元組欄位的 OOB 讀取

在 Linux 核心中,下列弱點已解決:

drm/dp/mst:修正邊帶區塊累積中的緩衝區溢位 (CVE-2026-68278)

在 Linux 核心中,下列弱點已解決:

drm/dp/mst:修正遠端 DPCD/I2C 邊帶回覆剖析器中的 OOB 讀取 (CVE-2026-68279)

在 Linux 核心中,下列弱點已解決:

bpf, sockmap:修正 tcp_bpf_sendmsg() 中的軟木塞釋放後使用 (CVE-2026-68284)

在 Linux 核心中,下列弱點已解決:

rds: tcp:拆除偵聽通訊端 (CVE-2026-68290) 之前取消註冊 sysctl

在 Linux 核心中,下列弱點已解決:

net/mlx5:修正 32 個 dword 讀取時的 MCIA 暫存器緩衝區溢位 (CVE-2026-68293)

在 Linux 核心中,下列弱點已解決:

net: gre:使用 SEQ/CSUM 修正 GRE 通道的 lltx 迴歸 (CVE-2026-68296)

在 Linux 核心中,下列弱點已解決:

tipc:修正媒體和承載 MTU 驗證中的 u16 MTU 截斷 (CVE-2026-68297)

在 Linux 核心中,下列弱點已解決:

vmxnet3:修正 vmxnet3_get_hdr_len() 中對 Geneve 封包的BUG_ON (CVE-2026-68299)

在 Linux 核心中,下列弱點已解決:

sctp: auth:當 auth_chunk 為 NULL 時,驗證驗證要求 (CVE-2026-68300)

在 Linux 核心中,下列弱點已解決:

tipc:修正 __tipc_nl_compat_dumpit (CVE-2026-68313) 中的無限迴圈

在 Linux 核心中,下列弱點已解決:

sctp:驗證 sctp_process_strreset_inreq() 中的資料流計數 (CVE-2026-68315)

在 Linux 核心中,下列弱點已解決:

sctp:修正 sctp_auth_ep_add_chunkid (CVE-2026-68320) 中的auth_chunk_list容量檢查

在 Linux 核心中,下列弱點已解決:

rds:修正停用 IPv6 時inet6_addr_lst NULL 解除參照 (CVE-2026-68322)

在 Linux 核心中,下列弱點已解決:

iommu/amd:繫結早期 ACPI HID 對應 (CVE-2026-68325)

在 Linux 核心中,下列弱點已解決:

iommu/amd:等待完成,而不是在 iommu_completion_wait() 中提前返回 (CVE-2026-68329)

在 Linux 核心中,下列弱點已解決:

rds:丟棄跨網路命名空間邊界的傳入訊息 (CVE-2026-68335)

在 Linux 核心中,下列弱點已解決:

bonding:修正停用 IPv6 時devconf_all NULL 解除參照 (CVE-2026-68336)

在 Linux 核心中,下列弱點已解決:

net/packet:避免取消註冊 (CVE-2026-68338) 後的 fanout hook 重新註冊

在 Linux 核心中,下列弱點已解決:

smb: client:驗證 DFS 轉介 PathConsumed (CVE-2026-68343)

在 Linux 核心中,下列弱點已解決:

USB: core: sysfs:將鎖新增至 bos_descriptors_read() (CVE-2026-68374)

在 Linux 核心中,下列弱點已解決:

sctp:修正 struct sctp_cookieCVE-2026-68376 () 中的 auth_hmacs 陣列大小

在 Linux 核心中,下列弱點已解決:

bpf, sockmap:拒絕 sockmap 更新 (CVE-2026-68386) 上未雜湊的 UDP 通訊端

在 Linux 核心中,下列弱點已解決:

smb/client:處理 fallocate (CVE-2026-68388) 中重疊的分配範圍

在 Linux 核心中,下列弱點已解決:

scsi: core:使用 scsi_schedule_eh (CVE-2026-68396) 時可靠地喚醒 eh

在 Linux 核心中,下列弱點已解決:

mtd:修正 add_mtd_device() 錯誤路徑中的雙重釋放和WARN_ON (CVE-2026-68416)

在 Linux 核心中,下列弱點已解決:

btrfs:如果 merge_reloc_roots()CVE-2026-68422 () 中的重新定位根目錄意外,則修正根洩漏

在 Linux 核心中,下列弱點已解決:

IB/mad:在重組之前刪除不相符的 RMPP 回應 (CVE-2026-68425)

在 Linux 核心中,下列弱點已解決:

KVM:x86/mmu:修正廠商模組重新載入時的釋放後使用 (CVE-2026-68428)

在 Linux 核心中,下列弱點已解決:

drm/dp_mst:在 drm_dp_mst_topology_queue_probe() (CVE-2026-68429) 中正常地處理已拆除的拓撲

在 Linux 核心中,下列弱點已解決:

vxlan:需要在裝置 netns 中CAP_NET_ADMIN以進行 changelink (CVE-2026-68432)

在 Linux 核心中,下列弱點已解決:

libceph:綁定get_version回覆解碼到前面的 len (CVE-2026-68433)

在 Linux 核心中,下列弱點已解決:

btrfs:不要將EXTENT_FLAG_LOGGING傳播至分割範圍對應 (CVE-2026-68442)

在 Linux 核心中,下列弱點已解決:

韌體:arm_ffa:修正 ffa_partition_info_get() 中的空取消參照 (CVE-2026-68444)

在 Linux 核心中,下列弱點已解決:

drm/vmwgfx: 驗證 vmw_surface_metadata::array_size (CVE-2026-68446)

在 Linux 核心中,下列弱點已解決:

btrfs:重複重新定位根插入 (CVE-2026-68450) 上的釋放映射節點

在 Linux 核心中,下列弱點已解決:

x86/錯誤:使 Safe-RET 加強中斷插入 (CVE-2026-68480)

在 Linux 核心中,下列弱點已解決:

ata: libata-core: 拒絕無效的並行定位範圍 count (CVE-2026-72030)

在 Linux 核心中,下列弱點已解決:

net/mlx5: HWS,修正調整大小目標設定失敗時的匹配器洩漏 (CVE-2026-72032)

在 Linux 核心中,下列弱點已解決:

ipmi:修正 i_ipmi_request()CVE-2026-72040 () 中的參照計數洩漏

在 Linux 核心中,下列弱點已解決:

net: ip6_tunnel:需要在裝置 netns 中CAP_NET_ADMIN以進行 changelink (CVE-2026-72051)

在 Linux 核心中,下列弱點已解決:

dm-integrity:修正洩漏的未初始化核心記憶體 (CVE-2026-72101)

在 Linux 核心中,下列弱點已解決:

dm:避免透過表格裝置檔案 (CVE-2026-72103) 洩漏呼叫者的執行緒金鑰環

在 Linux 核心中,下列弱點已解決:

bpf:在縮小 check_mem_access() 中的 retval 範圍之前重設暫存器邊界 (CVE-2026-72111)

在 Linux 核心中,下列弱點已解決:

can: bcm:新增缺少的裝置參照計數以移除 CAN 篩選器 (CVE-2026-72113)

在 Linux 核心中,下列弱點已解決:

can: bcm:驗證 RTR 回覆的 bcm_rx_setup() 中的框架長度 (CVE-2026-72114)

在 Linux 核心中,下列弱點已解決:

can: bcm:追蹤單一來源介面的 ANYDEV 逾時/節流操作 (CVE-2026-72115)

在 Linux 核心中,下列弱點已解決:

can: bcm:移除裝置後修正過時的 rx/tx 操作 (CVE-2026-72116)

在 Linux 核心中,下列弱點已解決:

can: bcm:修正 bcm_rx_handler() 中 rx_stamp/rx_ifindex 上的資料爭用 (CVE-2026-72117)

在 Linux 核心中,下列弱點已解決:

can: bcm:修正 CAN 框架 rx/tx 統計資料 (CVE-2026-72118)

在 Linux 核心中,下列弱點已解決:

can: bcm:擴充資料和計時器更新的 bcm_tx_lock 使用 (CVE-2026-72119)

在 Linux 核心中,下列弱點已解決:

can: bcm:更新篩選器和計時器值時新增鎖定 (CVE-2026-72121)

在 Linux 核心中,下列弱點已解決:

xfrm: nat_keepalive:避免傳送錯誤時的雙重釋放 (CVE-2026-72137)

在 Linux 核心中,下列弱點已解決:

fs/proc/task_mmu:修正 make_uffd_wp_huge_pte() prot-update 爭用 (CVE-2026-72175)

在 Linux 核心中,下列弱點已解決:

landlock:修正 SIGIO 路徑上的 LANDLOCK_SCOPE_SIGNAL 繞過 (CVE-2026-72183)

在 Linux 核心中,下列弱點已解決:

mm/hugetlb:修正 hugetlb cgroup RSVD 充值/未充值不相符 (CVE-2026-72213)

在 Linux 核心中,下列弱點已解決:

GPU/buddy:當無法遵守對齊時,退出try_harder (CVE-2026-72244)

在 Linux 核心中,下列弱點已解決:

netfilter: nf_conntrack_sip:在存取 skb_dst() 之前先驗證它 (CVE-2026-72253)

在 Linux 核心中,下列弱點已解決:

netfilter: nft_fib:拒絕 netdev 出口勾點 (CVE-2026-72254) 上的 fib 運算式

在 Linux 核心中,下列弱點已解決:

TIPC:限制佇列追蹤點中的通訊端佇列傾出 (CVE-2026-72299)

在 Linux 核心中,下列弱點已解決:

bpf:釋放 bpf_rb_root (CVE-2026-74344) 時清除 rb 節點連結

在 Linux 核心中,下列弱點已解決:

drm/vmwgfx:避免 vkms init 失敗 (CVE-2026-74442) 時的 destroy_workqueue (NULL)

在 Linux 核心中,下列弱點已解決:

drm/vmwgfx:根據尾碼指標 (CVE-2026-74443) 繫結 DMA 命令內文大小

在 Linux 核心中,下列弱點已解決:

drm/vmwgfx:在分割 (CVE-2026-74444) 之前驗證DRAW_PRIMITIVES標頭大小

在 Linux 核心中,下列弱點已解決:

drm/vmwgfx:拒絕沒有 DX 內容的DX_BIND_QUERY (CVE-2026-74445)

在 Linux 核心中,下列弱點已解決:

net: openvswitch:修正 CT 期間流程金鑰更新失敗時的 skb 洩漏 (CVE-2026-74464)

在 Linux 核心中,下列弱點已解決:

net: openvswitch:修正儀表連接失敗時的潛在 UAF (CVE-2026-74465)

在 Linux 核心中,下列弱點已解決:

sctp:防止對等傳輸計數溢位 (CVE-2026-74469)

在 Linux 核心中,下列弱點已解決:

tracing:檢查 trace_module_add_events() 中 __register_event() 的傳回值 (CVE-2026-74471)

在 Linux 核心中,下列弱點已解決:

vxlan:在 route_shortcircuit() 中使用 pskb_network_may_pull()CVE-2026-74473

在 Linux 核心中,下列弱點已解決:

vxlan:在 route_shortcircuit() 中使用 neigh_ha_snapshot()CVE-2026-74475 ()

在 Linux 核心中,下列弱點已解決:

veth:在執行 XDP 之前轉換frag_list skb (CVE-2026-74476)

在 Linux 核心中,下列弱點已解決:

net: bridge:刪除連接埠群組後停止快速離開 (CVE-2026-74480)

在 Linux 核心中,下列弱點已解決:

mm/page_reporting:在暫停期間使用 system_freezable_wq 修正 UAF (CVE-2026-74481)

在 Linux 核心中,下列弱點已解決:

mm/huge_memory:在釋放分割後對開本之前解除鎖定i_mmap_rwsem (CVE-2026-74482)

在 Linux 核心中,下列弱點已解決:

binfmt_misc:不要讓 'F' 項目釘選自己的實例 (CVE-2026-74484)

在 Linux 核心中,下列弱點已解決:

binfmt_misc:拒絕旗標字元作為欄位分隔符號 (CVE-2026-74485)

在 Linux 核心中,下列弱點已解決:

提示:避免輪詢追蹤佇列轉儲中的釋放後使用 (CVE-2026-74490)

在 Linux 核心中,下列弱點已解決:

netfilter: ipset:不要更新來自核心端雜湊新增 (CVE-2026-74492) 的註解

在 Linux 核心中,下列弱點已解決:

audit:修正 audit_del_rule() 中潛在的釋放後使用 (CVE-2026-74512)

在 Linux 核心中,下列弱點已解決:

KVM: SVM:如果 Avia 在 L2 處於活動狀態時被禁止,則更新 x2APIC MSR 攔截 (CVE-2026-74516)

在 Linux 核心中,下列弱點已解決:

mm/hugetlb:修正 allocate_file_region_entries()CVE-2026-74518 () 中的清單損毀

在 Linux 核心中,下列弱點已解決:

pinctrl: devicetree:不要釋放錯誤路徑上的未初始化dev_name (CVE-2026-74519)

在 Linux 核心中,下列弱點已解決:

net:當對等配置失敗時,不要傳送 ICMP/NDISC 重新導向 (CVE-2026-74550)

在 Linux 核心中,下列弱點已解決:

scsi: libiscsi_tcp:將 SCSI 回應資料區段繫結至連線緩衝區 (CVE-2026-74556)

在 Linux 核心中,下列弱點已解決:

scsi: libiscsi:修正 SCSI 感應緩衝區中的過時資料洩漏 (CVE-2026-74557)

在 Linux 核心中,下列弱點已解決:

rds: tcp:在 rds_tcp_laddr_check() 中跨 ipv6_chk_addr() 保持 RCU 鎖定 (CVE-2026-74563)

在 Linux 核心中,下列弱點已解決:

netfilter: xt_hashlimit:驗證雜湊表是否支援 XT_HASHLIMIT_RATE_MATCH (CVE-2026-74564)

在 Linux 核心中,下列弱點已解決:

netfilter: nf_tables:使每個表nft_object rhltable (CVE-2026-74565)

在 Linux 核心中,下列弱點已解決:

keys:使金鑰環金鑰區塊位元組順序與 keyring_diff_objects() (CVE-2026-74566) 一致

在 Linux 核心中,下列弱點已解決:

KEYS:修正 keyring_get_key_chunk()CVE-2026-74567 () 中的越界讀取

在 Linux 核心中,下列弱點已解決:

netfilter: nf_conntrack_sip:在 sip_help_tcp()CVE-2026-74569 () 中將 NAT 重寫差異擴大到 s32

在 Linux 核心中,下列弱點已解決:

btrfs: zoned:修正中繼資料回寫和交易提交之間的鎖死 (CVE-2026-74572)

在 Linux 核心中,下列弱點已解決:

mm/slab:使用新的 kmalloc 類型 () 防止自由路徑中的無限遞迴 (CVE-2026-74576)

在 Linux 核心中,下列弱點已解決:

net: mpls:在 mpls_getroute() 中初始化 rtm_tos (CVE-2026-74577)

在 Linux 核心中,下列弱點已解決:

netfilter: nft_payload:修正部分欄位卸載的遮罩構建 (CVE-2026-74579)

在 Linux 核心中,下列弱點已解決:

vhost:在 VRING 重新設定時重設 VRING 中繼資料快取 (CVE-2026-74580)

Tenable 已直接從所測試產品的安全公告擷取前置描述區塊。

請注意,Nessus 並未測試這些問題,而是僅依據應用程式自我報告的版本號碼作出判斷。

解決方案

執行「dnf update kernel6.12 --releasever 2023.12.20260831」或「dnf update --advisory ALAS2023-2026-2110 --releasever 2023.12.20260831」來更新您的系統。

另請參閱

https://alas.aws.amazon.com//AL2023/ALAS2023-2026-2110.html

https://alas.aws.amazon.com/faqs.html

https://explore.alas.aws.amazon.com/CVE-2026-45897.html

https://explore.alas.aws.amazon.com/CVE-2026-45901.html

https://explore.alas.aws.amazon.com/CVE-2026-53090.html

https://explore.alas.aws.amazon.com/CVE-2026-64017.html

https://explore.alas.aws.amazon.com/CVE-2026-64205.html

https://explore.alas.aws.amazon.com/CVE-2026-64290.html

https://explore.alas.aws.amazon.com/CVE-2026-64562.html

https://explore.alas.aws.amazon.com/CVE-2026-64563.html

https://explore.alas.aws.amazon.com/CVE-2026-64564.html

https://explore.alas.aws.amazon.com/CVE-2026-64567.html

https://explore.alas.aws.amazon.com/CVE-2026-64572.html

https://explore.alas.aws.amazon.com/CVE-2026-64576.html

https://explore.alas.aws.amazon.com/CVE-2026-64579.html

https://explore.alas.aws.amazon.com/CVE-2026-64580.html

https://explore.alas.aws.amazon.com/CVE-2026-64581.html

https://explore.alas.aws.amazon.com/CVE-2026-68093.html

https://explore.alas.aws.amazon.com/CVE-2026-68096.html

https://explore.alas.aws.amazon.com/CVE-2026-68116.html

https://explore.alas.aws.amazon.com/CVE-2026-68117.html

https://explore.alas.aws.amazon.com/CVE-2026-68121.html

https://explore.alas.aws.amazon.com/CVE-2026-68123.html

https://explore.alas.aws.amazon.com/CVE-2026-68127.html

https://explore.alas.aws.amazon.com/CVE-2026-68128.html

https://explore.alas.aws.amazon.com/CVE-2026-68131.html

https://explore.alas.aws.amazon.com/CVE-2026-68133.html

https://explore.alas.aws.amazon.com/CVE-2026-68136.html

https://explore.alas.aws.amazon.com/CVE-2026-68138.html

https://explore.alas.aws.amazon.com/CVE-2026-68139.html

https://explore.alas.aws.amazon.com/CVE-2026-68142.html

https://explore.alas.aws.amazon.com/CVE-2026-68145.html

https://explore.alas.aws.amazon.com/CVE-2026-68146.html

https://explore.alas.aws.amazon.com/CVE-2026-68149.html

https://explore.alas.aws.amazon.com/CVE-2026-68153.html

https://explore.alas.aws.amazon.com/CVE-2026-68154.html

https://explore.alas.aws.amazon.com/CVE-2026-68155.html

https://explore.alas.aws.amazon.com/CVE-2026-68156.html

https://explore.alas.aws.amazon.com/CVE-2026-68157.html

https://explore.alas.aws.amazon.com/CVE-2026-68158.html

https://explore.alas.aws.amazon.com/CVE-2026-68160.html

https://explore.alas.aws.amazon.com/CVE-2026-68161.html

https://explore.alas.aws.amazon.com/CVE-2026-68162.html

https://explore.alas.aws.amazon.com/CVE-2026-68164.html

https://explore.alas.aws.amazon.com/CVE-2026-68165.html

https://explore.alas.aws.amazon.com/CVE-2026-68169.html

https://explore.alas.aws.amazon.com/CVE-2026-68178.html

https://explore.alas.aws.amazon.com/CVE-2026-68179.html

https://explore.alas.aws.amazon.com/CVE-2026-68184.html

https://explore.alas.aws.amazon.com/CVE-2026-68186.html

https://explore.alas.aws.amazon.com/CVE-2026-68243.html

https://explore.alas.aws.amazon.com/CVE-2026-68244.html

https://explore.alas.aws.amazon.com/CVE-2026-68247.html

https://explore.alas.aws.amazon.com/CVE-2026-68248.html

https://explore.alas.aws.amazon.com/CVE-2026-68253.html

https://explore.alas.aws.amazon.com/CVE-2026-68254.html

https://explore.alas.aws.amazon.com/CVE-2026-68255.html

https://explore.alas.aws.amazon.com/CVE-2026-68269.html

https://explore.alas.aws.amazon.com/CVE-2026-68277.html

https://explore.alas.aws.amazon.com/CVE-2026-68278.html

https://explore.alas.aws.amazon.com/CVE-2026-68279.html

https://explore.alas.aws.amazon.com/CVE-2026-68284.html

https://explore.alas.aws.amazon.com/CVE-2026-68290.html

https://explore.alas.aws.amazon.com/CVE-2026-68293.html

https://explore.alas.aws.amazon.com/CVE-2026-68296.html

https://explore.alas.aws.amazon.com/CVE-2026-68297.html

https://explore.alas.aws.amazon.com/CVE-2026-68299.html

https://explore.alas.aws.amazon.com/CVE-2026-68300.html

https://explore.alas.aws.amazon.com/CVE-2026-68313.html

https://explore.alas.aws.amazon.com/CVE-2026-68315.html

https://explore.alas.aws.amazon.com/CVE-2026-68320.html

https://explore.alas.aws.amazon.com/CVE-2026-68322.html

https://explore.alas.aws.amazon.com/CVE-2026-68325.html

https://explore.alas.aws.amazon.com/CVE-2026-68329.html

https://explore.alas.aws.amazon.com/CVE-2026-68335.html

https://explore.alas.aws.amazon.com/CVE-2026-68336.html

https://explore.alas.aws.amazon.com/CVE-2026-68338.html

https://explore.alas.aws.amazon.com/CVE-2026-68343.html

https://explore.alas.aws.amazon.com/CVE-2026-68374.html

https://explore.alas.aws.amazon.com/CVE-2026-68376.html

https://explore.alas.aws.amazon.com/CVE-2026-68386.html

https://explore.alas.aws.amazon.com/CVE-2026-68388.html

https://explore.alas.aws.amazon.com/CVE-2026-68396.html

https://explore.alas.aws.amazon.com/CVE-2026-68416.html

https://explore.alas.aws.amazon.com/CVE-2026-68422.html

https://explore.alas.aws.amazon.com/CVE-2026-68425.html

https://explore.alas.aws.amazon.com/CVE-2026-68428.html

https://explore.alas.aws.amazon.com/CVE-2026-68429.html

https://explore.alas.aws.amazon.com/CVE-2026-68432.html

https://explore.alas.aws.amazon.com/CVE-2026-68433.html

https://explore.alas.aws.amazon.com/CVE-2026-68442.html

https://explore.alas.aws.amazon.com/CVE-2026-68444.html

https://explore.alas.aws.amazon.com/CVE-2026-68446.html

https://explore.alas.aws.amazon.com/CVE-2026-68450.html

https://explore.alas.aws.amazon.com/CVE-2026-68480.html

https://explore.alas.aws.amazon.com/CVE-2026-72030.html

https://explore.alas.aws.amazon.com/CVE-2026-72032.html

https://explore.alas.aws.amazon.com/CVE-2026-72040.html

https://explore.alas.aws.amazon.com/CVE-2026-72051.html

https://explore.alas.aws.amazon.com/CVE-2026-72101.html

https://explore.alas.aws.amazon.com/CVE-2026-72103.html

https://explore.alas.aws.amazon.com/CVE-2026-72111.html

https://explore.alas.aws.amazon.com/CVE-2026-72113.html

https://explore.alas.aws.amazon.com/CVE-2026-72114.html

https://explore.alas.aws.amazon.com/CVE-2026-72115.html

https://explore.alas.aws.amazon.com/CVE-2026-72116.html

https://explore.alas.aws.amazon.com/CVE-2026-72117.html

https://explore.alas.aws.amazon.com/CVE-2026-72118.html

https://explore.alas.aws.amazon.com/CVE-2026-72119.html

https://explore.alas.aws.amazon.com/CVE-2026-72121.html

https://explore.alas.aws.amazon.com/CVE-2026-72137.html

https://explore.alas.aws.amazon.com/CVE-2026-72175.html

https://explore.alas.aws.amazon.com/CVE-2026-72183.html

https://explore.alas.aws.amazon.com/CVE-2026-72213.html

https://explore.alas.aws.amazon.com/CVE-2026-72244.html

https://explore.alas.aws.amazon.com/CVE-2026-72253.html

https://explore.alas.aws.amazon.com/CVE-2026-72254.html

https://explore.alas.aws.amazon.com/CVE-2026-72299.html

https://explore.alas.aws.amazon.com/CVE-2026-74344.html

https://explore.alas.aws.amazon.com/CVE-2026-74442.html

https://explore.alas.aws.amazon.com/CVE-2026-74443.html

https://explore.alas.aws.amazon.com/CVE-2026-74444.html

https://explore.alas.aws.amazon.com/CVE-2026-74445.html

https://explore.alas.aws.amazon.com/CVE-2026-74464.html

https://explore.alas.aws.amazon.com/CVE-2026-74465.html

https://explore.alas.aws.amazon.com/CVE-2026-74469.html

https://explore.alas.aws.amazon.com/CVE-2026-74471.html

https://explore.alas.aws.amazon.com/CVE-2026-74473.html

https://explore.alas.aws.amazon.com/CVE-2026-74475.html

https://explore.alas.aws.amazon.com/CVE-2026-74476.html

https://explore.alas.aws.amazon.com/CVE-2026-74480.html

https://explore.alas.aws.amazon.com/CVE-2026-74481.html

https://explore.alas.aws.amazon.com/CVE-2026-74482.html

https://explore.alas.aws.amazon.com/CVE-2026-74484.html

https://explore.alas.aws.amazon.com/CVE-2026-74485.html

https://explore.alas.aws.amazon.com/CVE-2026-74490.html

https://explore.alas.aws.amazon.com/CVE-2026-74492.html

https://explore.alas.aws.amazon.com/CVE-2026-74512.html

https://explore.alas.aws.amazon.com/CVE-2026-74516.html

https://explore.alas.aws.amazon.com/CVE-2026-74518.html

https://explore.alas.aws.amazon.com/CVE-2026-74519.html

https://explore.alas.aws.amazon.com/CVE-2026-74550.html

https://explore.alas.aws.amazon.com/CVE-2026-74556.html

https://explore.alas.aws.amazon.com/CVE-2026-74557.html

https://explore.alas.aws.amazon.com/CVE-2026-74563.html

https://explore.alas.aws.amazon.com/CVE-2026-74564.html

https://explore.alas.aws.amazon.com/CVE-2026-74565.html

https://explore.alas.aws.amazon.com/CVE-2026-74566.html

https://explore.alas.aws.amazon.com/CVE-2026-74567.html

https://explore.alas.aws.amazon.com/CVE-2026-74569.html

https://explore.alas.aws.amazon.com/CVE-2026-74572.html

https://explore.alas.aws.amazon.com/CVE-2026-74576.html

https://explore.alas.aws.amazon.com/CVE-2026-74577.html

https://explore.alas.aws.amazon.com/CVE-2026-74579.html

https://explore.alas.aws.amazon.com/CVE-2026-74580.html

Plugin 詳細資訊

嚴重性: Medium

ID: 341899

檔案名稱: al2023_ALAS2023-2026-2110.nasl

版本: 1.1

類型: Local

代理程式: unix

已發布: 2026/8/31

已更新: 2026/8/31

支援的感應器: Agentless Assessment, Continuous Assessment, Frictionless Assessment Agent, Frictionless Assessment AWS, Nessus Agent, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

風險資訊

VPR

風險因素: High

分數: 7.9

百分位數: 99.36

CVSS v2

風險因素: Medium

基本分數: 4.6

時間性分數: 3.6

媒介: CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:C

CVSS 評分資料來源: CVE-2026-64290

CVSS v3

風險因素: Medium

基本分數: 5.5

時間性分數: 5

媒介: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

時間媒介: CVSS:3.0/E:P/RL:O/RC:C

弱點資訊

CPE: cpe:/o:amazon:linux:2023, p-cpe:/a:amazon:linux:bpftool6.12-debuginfo, p-cpe:/a:amazon:linux:bpftool6.12, p-cpe:/a:amazon:linux:kernel-livepatch-6.12.103-127.188, p-cpe:/a:amazon:linux:kernel6.12-debuginfo-common-aarch64, p-cpe:/a:amazon:linux:kernel6.12-debuginfo-common-x86_64, p-cpe:/a:amazon:linux:kernel6.12-debuginfo, p-cpe:/a:amazon:linux:kernel6.12-devel, p-cpe:/a:amazon:linux:kernel6.12-headers, p-cpe:/a:amazon:linux:kernel6.12-modules-extra-common, p-cpe:/a:amazon:linux:kernel6.12-modules-extra, p-cpe:/a:amazon:linux:kernel6.12-tools-debuginfo, p-cpe:/a:amazon:linux:kernel6.12-tools-devel, p-cpe:/a:amazon:linux:kernel6.12-tools, p-cpe:/a:amazon:linux:kernel6.12, p-cpe:/a:amazon:linux:perf6.12-debuginfo, p-cpe:/a:amazon:linux:perf6.12, p-cpe:/a:amazon:linux:python3-perf6.12-debuginfo, p-cpe:/a:amazon:linux:python3-perf6.12

必要的 KB 項目: Host/local_checks_enabled, Host/AmazonLinux/release, Host/AmazonLinux/rpm-list

可被惡意程式利用: true

可輕鬆利用: Exploits are available

修補程式發佈日期: 2026/8/31

弱點發布日期: 2026/5/27

參考資訊

CVE: CVE-2026-45897, CVE-2026-45901, CVE-2026-53090, CVE-2026-64017, CVE-2026-64205, CVE-2026-64290, CVE-2026-64562, CVE-2026-64563, CVE-2026-64564, CVE-2026-64567, CVE-2026-64572, CVE-2026-64576, CVE-2026-64579, CVE-2026-64580, CVE-2026-64581, CVE-2026-68093, CVE-2026-68096, CVE-2026-68116, CVE-2026-68117, CVE-2026-68121, CVE-2026-68123, CVE-2026-68127, CVE-2026-68128, CVE-2026-68131, CVE-2026-68133, CVE-2026-68136, CVE-2026-68138, CVE-2026-68139, CVE-2026-68142, CVE-2026-68145, CVE-2026-68146, CVE-2026-68149, CVE-2026-68153, CVE-2026-68154, CVE-2026-68155, CVE-2026-68156, CVE-2026-68157, CVE-2026-68158, CVE-2026-68160, CVE-2026-68161, CVE-2026-68162, CVE-2026-68164, CVE-2026-68165, CVE-2026-68169, CVE-2026-68178, CVE-2026-68179, CVE-2026-68184, CVE-2026-68186, CVE-2026-68243, CVE-2026-68244, CVE-2026-68247, CVE-2026-68248, CVE-2026-68253, CVE-2026-68254, CVE-2026-68255, CVE-2026-68269, CVE-2026-68277, CVE-2026-68278, CVE-2026-68279, CVE-2026-68284, CVE-2026-68290, CVE-2026-68293, CVE-2026-68296, CVE-2026-68297, CVE-2026-68299, CVE-2026-68300, CVE-2026-68313, CVE-2026-68315, CVE-2026-68320, CVE-2026-68322, CVE-2026-68325, CVE-2026-68329, CVE-2026-68335, CVE-2026-68336, CVE-2026-68338, CVE-2026-68343, CVE-2026-68374, CVE-2026-68376, CVE-2026-68386, CVE-2026-68388, CVE-2026-68396, CVE-2026-68416, CVE-2026-68422, CVE-2026-68425, CVE-2026-68428, CVE-2026-68429, CVE-2026-68432, CVE-2026-68433, CVE-2026-68442, CVE-2026-68444, CVE-2026-68446, CVE-2026-68450, CVE-2026-68480, CVE-2026-72030, CVE-2026-72032, CVE-2026-72040, CVE-2026-72051, CVE-2026-72101, CVE-2026-72103, CVE-2026-72111, CVE-2026-72113, CVE-2026-72114, CVE-2026-72115, CVE-2026-72116, CVE-2026-72117, CVE-2026-72118, CVE-2026-72119, CVE-2026-72121, CVE-2026-72137, CVE-2026-72175, CVE-2026-72183, CVE-2026-72213, CVE-2026-72244, CVE-2026-72253, CVE-2026-72254, CVE-2026-72299, CVE-2026-74344, CVE-2026-74442, CVE-2026-74443, CVE-2026-74444, CVE-2026-74445, CVE-2026-74464, CVE-2026-74465, CVE-2026-74469, CVE-2026-74471, CVE-2026-74473, CVE-2026-74475, CVE-2026-74476, CVE-2026-74480, CVE-2026-74481, CVE-2026-74482, CVE-2026-74484, CVE-2026-74485, CVE-2026-74490, CVE-2026-74492, CVE-2026-74512, CVE-2026-74516, CVE-2026-74518, CVE-2026-74519, CVE-2026-74550, CVE-2026-74556, CVE-2026-74557, CVE-2026-74563, CVE-2026-74564, CVE-2026-74565, CVE-2026-74566, CVE-2026-74567, CVE-2026-74569, CVE-2026-74572, CVE-2026-74576, CVE-2026-74577, CVE-2026-74579, CVE-2026-74580