Amazon Linux 2023:bpftool6.18、kernel6.18、kernel6.18-devel (ALAS2023-2026-3139)

critical Nessus Plugin ID 351016

概要

遠端 Amazon Linux 2023 主機缺少一個安全性更新。

說明

因此,會受到 ALAS2023-2026-3139 公告中所提及的多個弱點影響。

在 Linux 核心中,下列弱點已解決:

libceph:修正 decode_lockers()CVE-2026-68082 () 中兩個不安全的裸解碼

在 Linux 核心中,下列弱點已解決:

libceph:將 pg_{temp,upmap,upmap_items} 長度綁定為 CEPH_PG_MAX_SIZE (CVE-2026-68159)

在 Linux 核心中,下列弱點已解決:

binfmt_misc:掛載失敗時,不要洩漏使用者命名空間 (CVE-2026-74483)

在 Linux 核心中,下列弱點已解決:

KVM:x86:在銷毀 vCPU 之前,取消延遲的 I/O APIC EOI 處理 (CVE-2026-74517)

在 Linux 核心中,下列弱點已解決:

封包:在非環形傳送路徑中使用一致的hard_header_len (CVE-2026-74582)

在 Linux 核心中,下列弱點已解決:

net/sched: cls_route:修正 filterCVE-2026-74583() 上的 fastmap 釋放後使用

在 Linux 核心中,下列弱點已解決:

sctp:移除對等體時清除new_transport (CVE-2026-74586)

在 Linux 核心中,下列弱點已解決:

sctp:修正快取的 ASCONF 區塊的釋放後使用 (CVE-2026-74587)

在 Linux 核心中,下列弱點已解決:

sctp:保持區塊>傳輸與其排入佇列的清單保持一致 (CVE-2026-74588)

在 Linux 核心中,下列弱點已解決:

bpf, sockmap:修正傳送判定 (CVE-2026-74589) 中的sk_redir釋放後使用

在 Linux 核心中,下列弱點已解決:

mm/filemap:__filemap_add_folio() 重試前還原索引 (CVE-2026-74591)

在 Linux 核心中,下列弱點已解決:

ima:實例化file_truncate和path_truncate勾點 (CVE-2026-74592)

在 Linux 核心中,下列弱點已解決:

sched_ext:首先在 scx_cgroup_lock() 中取 cgroup_lock()CVE-2026-74593

在 Linux 核心中,下列弱點已解決:

sched/psi:關閉 psi_cgroup_free() 中的 rtpoll_timer (CVE-2026-74594)

在 Linux 核心中,下列弱點已解決:

fscrypt:在 fscrypt_ioctl_set_policy() (CVE-2026-74595) 中使用掛載 idmap 進行所有者簽入

在 Linux 核心中,下列弱點已解決:

ip6_tunnel:清除 ip6ip6_err() 中的 skb2->cb[] (CVE-2026-74597)

在 Linux 核心中,下列弱點已解決:

ipv6:修正路由資訊選項長度驗證 (CVE-2026-74598)

在 Linux 核心中,下列弱點已解決:

ring-buffer:使用 current_context 進行安全的 per-CPU 緩衝區交換 (CVE-2026-74601)

在 Linux 核心中,下列弱點已解決:

ring-buffer:在 rb_allocate_cpu_buffer() 中初始化閱讀器頁面順序 (CVE-2026-74602)

在 Linux 核心中,下列弱點已解決:

eventfs:修正 eventfs_remove_rec() 中的釋放後使用 (CVE-2026-74606)

在 Linux 核心中,下列弱點已解決:

smb: client:修正 cifs_try_adding_channels() 中的釋放後使用 (CVE-2026-74608)

在 Linux 核心中,下列弱點已解決:

tipc:讀取 tipc_node_link_down() 中節點鎖定下的 le->link (CVE-2026-74609)

在 Linux 核心中,下列弱點已解決:

TLS:不要讓完整的純文字sk_msg環未推送 (CVE-2026-74610)

在 Linux 核心中,下列弱點已解決:

tls: rx:在TLS 1.3 樂觀重試之前還原msg_iter (CVE-2026-74611)

在 Linux 核心中,下列弱點已解決:

veth:修正 XDP 片段調整後的 skb 長度統計 (CVE-2026-74612)

在 Linux 核心中,下列弱點已解決:

vsock/virtio:避免在拆卸後重新填充 RX 佇列 (CVE-2026-74613)

在 Linux 核心中,下列弱點已解決:

vsock/virtio:讀取背景工作鎖定下的 virtqueues (CVE-2026-74614)

在 Linux 核心中,下列弱點已解決:

vxlan:不要在已關閉的裝置上布防老化計時器 (CVE-2026-74615)

在 Linux 核心中,下列弱點已解決:

xdp:拒絕超出 skb_shared_info tailroom 的複製 (CVE-2026-74616)

在 Linux 核心中,下列弱點已解決:

binfmt_misc:從另一個使用者命名空間完成掛載時,不要發出警告 (CVE-2026-74618)

在 Linux 核心中,下列弱點已解決:

ovl:從另一個使用者命名空間完成掛載時,不要發出警告 (CVE-2026-74619)

在 Linux 核心中,下列弱點已解決:

net/sched:act_gact,act_police:範圍檢查後援控制動作 (CVE-2026-74620)

在 Linux 核心中,下列弱點已解決:

netfilter: nf_conntrack:將無效記錄推遲到解鎖 () 之後 (CVE-2026-74624)

在 Linux 核心中,下列弱點已解決:

net: devmem:防止 net-iov / 頁面混合 (CVE-2026-74627)

在 Linux 核心中,下列弱點已解決:

ipv6:防止 in6_dev_get() 復活 inet6_dev (CVE-2026-74630)

在 Linux 核心中,下列弱點已解決:

mm/huge_memory:修正huge_zero_pfn爭用 (CVE-2026-74632)

在 Linux 核心中,下列弱點已解決:

跟蹤:修正模組事件快取移除中的 NULL 指標解除參照 (CVE-2026-74633)

在 Linux 核心中,下列弱點已解決:

ring-buffer:停用調整大小時,防止 subbuf 順序變更 (CVE-2026-74634)

在 Linux 核心中,下列弱點已解決:

fbdev: bitblit:bit_cursor() 中的界限檢查字形索引 (CVE-2026-74635)

在 Linux 核心中,下列弱點已解決:

跟蹤:修正 update_event_fields 和 event_define_fields (CVE-2026-74636) 之間的爭用

在 Linux 核心中,下列弱點已解決:

perf/core: 修正同級分離後的群組領導者釋放後使用 (CVE-2026-74637)

在 Linux 核心中,下列弱點已解決:

mm/damon/ops-common:在無效的移轉 nid () 上放回對開本 (CVE-2026-74644)

在 Linux 核心中,下列弱點已解決:

serial: amba-pl011: 釋放 IRQ 後取消 RS485 hrtimers (CVE-2026-74652)

在 Linux 核心中,下列弱點已解決:

serial: 8250_of:LPC32xx 上清除卡住的空 FIFO RX 逾時 (CVE-2026-74653)

在 Linux 核心中,下列弱點已解決:

serial: 8250_dma: 關機時清除過時的 RX 狀態 (CVE-2026-74654)

在 Linux 核心中,下列弱點已解決:

ipv4:修正 fib_nhc_update_mtu() 中的釋放後使用 (CVE-2026-74656)

在 Linux 核心中,下列弱點已解決:

ipv4:修正 RTA_VIA nexthop 的 fib_nlmsg_size() (CVE-2026-74657)

在 Linux 核心中,下列弱點已解決:

futex:再防止強大的 futex 退出爭用 (CVE-2026-74658)

在 Linux 核心中,下列弱點已解決:

netfilter: ebt_nflog:釘選 NFLOG 後端 (CVE-2026-74660)

在 Linux 核心中,下列弱點已解決:

inet: frags:在布防計時器之前發布佇列 (CVE-2026-74662)

在 Linux 核心中,下列弱點已解決:

net/sched:拒絕過深的 qdisc 階層 (CVE-2026-74663)

在 Linux 核心中,下列弱點已解決:

net: openvswitch:重新分配不相符 ID 的更新回覆 (CVE-2026-74664)

在 Linux 核心中,下列弱點已解決:

net:修正通用 XDP 片段調整後的 skb 長度統計 (CVE-2026-74665)

在 Linux 核心中,下列弱點已解決:

packet:將壓力清除與環形重新配置同步 (CVE-2026-74666)

在 Linux 核心中,下列弱點已解決:

net/packet:重設封包通訊端傳輸路徑上的 MAC 標頭 (CVE-2026-74667)

在 Linux 核心中,下列弱點已解決:

封包:在TX_RING傳送路徑中使用一致的hard_header_len (CVE-2026-74668)

在 Linux 核心中,下列弱點已解決:

ipvs:在重定基底通道後清除 IPv4 選項 ICMP 錯誤 (CVE-2026-74669)

在 Linux 核心中,下列弱點已解決:

ipvs:停用 calc 階段 (CVE-2026-74670) 後停止估算器

在 Linux 核心中,下列弱點已解決:

ima:修正 xattr_verify() 中的越界讀取 (CVE-2026-74671)

在 Linux 核心中,下列弱點已解決:

mm/vmalloc:取得大型 vmap 的 init_mm 鎖定以避免 ptdump UAF (CVE-2026-74672)

在 Linux 核心中,下列弱點已解決:

輸入:evdev - 修正 evdev_pass_values()CVE-2026-74673 () 中的資訊洩露

在 Linux 核心中,下列弱點已解決:

vt:用 tty_port_tty_get 穩定 kbd_keycode 中的 tty 參照 (CVE-2026-74675)

在 Linux 核心中,下列弱點已解決:

vt:新增 KDSKBMETA ioctl 的權限檢查 (CVE-2026-74676)

在 Linux 核心中,下列弱點已解決:

輸入:evdev - 擷取事件遮罩時清理事件類型索引 (CVE-2026-74683)

在 Linux 核心中,下列弱點已解決:

net: tap:在剖析 tap_get_user_xdp() 中的 virtio net 標頭之前設定 skb->dev (CVE-2026-74684)

在 Linux 核心中,下列弱點已解決:

sctp:如果要移除控制區塊傳輸,則清除它 (CVE-2026-74688)

在 Linux 核心中,下列弱點已解決:

netfilter: nf_flow_table:在 skb_dst_set_noref()CVE-2026-74695 () 之前刪除現有的 skb dst

在 Linux 核心中,下列弱點已解決:

tcp:修正跨 reuseport 移轉的 TFO max_qlen帳戶處理 (CVE-2026-74696)

在 Linux 核心中,下列弱點已解決:

net/mlx5e:修正 SQ 重新啟用時的 BQL 重設 (CVE-2026-74698)

在 Linux 核心中,下列弱點已解決:

net/sched: cls_api:破壞鎖定的分類器時,一律獲取 rtnl_lock (CVE-2026-74700)

在 Linux 核心中,下列弱點已解決:

net/openvswitch:檢查 key_extract() 中的乙太網路標頭長度 (CVE-2026-74701)

在 Linux 核心中,下列弱點已解決:

net/sched: sch_cake:丟棄 ACK 過濾器 (CVE-2026-74704) 中格式錯誤的封包的 WARN_ON(1)

在 Linux 核心中,下列弱點已解決:

udp:修正通道分段中潛在的釋放後使用 (CVE-2026-74705)

在 Linux 核心中,下列弱點已解決:

xsk:處理請求時驗證中繼資料 (CVE-2026-74707)

在 Linux 核心中,下列弱點已解決:

xsk:驗證啟動時中繼資料大小 (CVE-2026-74708)

在 Linux 核心中,下列弱點已解決:

xsk:未要求時間戳記時清除中繼資料指標 (CVE-2026-74709)

在 Linux 核心中,下列弱點已解決:

xsk:需要至少 16 位元組的 TX 中繼資料 (CVE-2026-74710)

在 Linux 核心中,下列弱點已解決:

bpf: tcp:修正 bpf_iter_tcp_established_batch() 中的釋放後使用 (CVE-2026-74714)

在 Linux 核心中,下列弱點已解決:

net/mlx5: fw_tracer,在建立錯誤時傳回 NULL (CVE-2026-74717)

在 Linux 核心中,下列弱點已解決:

devlink:修正重新載入 (CVE-2026-74718) 中的網路命名空間參照洩漏

在 Linux 核心中,下列弱點已解決:

bpf:保留交換算術的指標狀態 (CVE-2026-74720)

在 Linux 核心中,下列弱點已解決:

btrfs:修正 btrfs_do_encoded_write()CVE-2026-74722 () 中的記憶體洩漏

在 Linux 核心中,下列弱點已解決:

ipvs:避免 ip_vs_nat_icmp (CVE-2026-74724) 中的越界寫入

在 Linux 核心中,下列弱點已解決:

bonding: alb:重新檢查 bond_alb_monitor 中 RTNL 下的primary_is_promisc (CVE-2026-74726)

在 Linux 核心中,下列弱點已解決:

xfs:處理 xfs_buf_free (CVE-2026-74728) 中的 NULL b_addr

在 Linux 核心中,下列弱點已解決:

NFS:在FREE_STATEID呼叫CVE-2026-74730期間釘選「結構nfs_server」()

在 Linux 核心中,下列弱點已解決:

net/sched: cls_bpf:拒絕繫結到不同裝置的開發程式 (CVE-2026-74736)

在 Linux 核心中,下列弱點已解決:

net/sched: cls_u32:跳過 u32_bind_class() 中的雜湊表 (CVE-2026-74739)

在 Linux 核心中,下列弱點已解決:

net/sched: act_api:修正 a->goto_chain 上的 TOCTOU NULL 解除參照 (CVE-2026-74740)

在 Linux 核心中,下列弱點已解決:

veth:修正用於喚醒 veth_poll 中對等 txq 的佇列索引 (CVE-2026-74742)

在 Linux 核心中,下列弱點已解決:

macvlan:繼承 lowerdev (CVE-2026-74743) 的needed_headroom和needed_tailroom

在 Linux 核心中,下列弱點已解決:

ipvlan:繼承 phy_dev (CVE-2026-74744) 的 needed_headroom 和 needed_tailroom

在 Linux 核心中,下列弱點已解決:

netfilter: flowtable:最後發布 GC 可見元組 (CVE-2026-74746)

在 Linux 核心中,下列弱點已解決:

netfilter: ipset:修正 list:set GC 和 swap (CVE-2026-74748) 之間的參照計數爭用

在 Linux 核心中,下列弱點已解決:

perf:以群組領導者身分拒絕已結束的事件 (CVE-2026-74753)

在 Linux 核心中,下列弱點已解決:

ceph:修正懸置的 __ceph_get_caps() 與過時mds_wanted (CVE-2026-80527)

在 Linux 核心中,下列弱點已解決:

ceph:使用 current->journal_info (CVE-2026-80528) 時避免 fs 回收

在 Linux 核心中,下列弱點已解決:

xfs:不要吞下 dquot 復原驗證錯誤 (CVE-2026-80529)

在 Linux 核心中,下列弱點已解決:

xfs:修正 INO1_WRITTEN 的 exchange-range reflink 旗標清除問題 (CVE-2026-80530)

在 Linux 核心中,下列弱點已解決:

xfs:修正 xfs_dq_get_next_id (CVE-2026-80534) 中錯誤時的 ilock 洩漏

在 Linux 核心中,下列弱點已解決:

xfs:邊界檢查緩衝區記錄項目的已變更點陣圖 (CVE-2026-80536)

在 Linux 核心中,下列弱點已解決:

libceph:透過缺少邊界檢查 (CVE-2026-80557) 修正 decode_watchers() 中的 OOB 讀取

在 Linux 核心中,下列弱點已解決:

libceph:避免使用 primary_temp (CVE-2026-80558) 中無效的 osd 索引

在 Linux 核心中,下列弱點已解決:

libceph:修正 decode_locker() 中的多個不安全解碼 (CVE-2026-80561)

在 Linux 核心中,下列弱點已解決:

輸入:比亞迪 - 在釋放私人資料之前同步計時器刪除 (CVE-2026-80572)

在 Linux 核心中,下列弱點已解決:

輸入:focaltech - 修正focaltech_process_rel_packet中的陣列越界 (CVE-2026-80574)

在 Linux 核心中,下列弱點已解決:

fbdev: core:修正 fb_io_read() 中的指標不同步 (CVE-2026-80578)

在 Linux 核心中,下列弱點已解決:

mptcp:fastopen:僅使用 SYN 資料 () 標示 MPTFO 子資料 (CVE-2026-80585)

在 Linux 核心中,下列弱點已解決:

mptcp: options:在大小意外的情況下重設 DSS 欄位 (CVE-2026-80586)

在 Linux 核心中,下列弱點已解決:

mptcp:避免組合某些傳入的子選項 (CVE-2026-80587)

在 Linux 核心中,下列弱點已解決:

mptcp:在 RX 路徑錯誤上回收轉發配置的記憶體 (CVE-2026-80588)

在 Linux 核心中,下列弱點已解決:

block:釋放從未新增的磁碟時停止逾時計時器 (CVE-2026-80589)

在 Linux 核心中,下列弱點已解決:

inet: frags:在重組之前從片段中剝離 GSO 狀態 (CVE-2026-80590)

在 Linux 核心中,下列弱點已解決:

ptp: vmclock:防止唯讀對應變成可寫入 (CVE-2026-80724)

在 Linux 核心中,下列弱點已解決:

net: gro:正確驗證 BIG TCP 彙總準則 (CVE-2026-80725)

在 Linux 核心中,下列弱點已解決:

KVM:x86/mmu:建立子影子頁面時,警告並清除 role.invalid (CVE-2026-80726)

在 Linux 核心中,下列弱點已解決:

x86/mce:在 CMCI 發現之前設定輪詢計時器 (CVE-2026-80727)

在 Linux 核心中,下列弱點已解決:

net:移除 dev_validate_header (CVE-2026-80731) 中的CAP_SYS_RAWIO零填充

在 Linux 核心中,下列弱點已解決:

net:從 sk_mc_loop() 中移除 WARN_ON_ONCE()CVE-2026-80733 ()

在 Linux 核心中,下列弱點已解決:

serial: amba-pl011: synchronize DMA teardown (CVE-2026-80737)

在 Linux 核心中,下列弱點已解決:

net/mlx5e: TC,在取得 devcom 鎖定之前檢查流量是否為 PEER (CVE-2026-80739)

在 Linux 核心中,下列弱點已解決:

af_packet:不要在 tpacket_snd() 中傳送零位元組資料。(CVE-2026-80742)

在 Linux 核心中,下列弱點已解決:

netfilter: nf_tables_offload:禁止中止路徑中 ENOMEM 的WARN_ON_ONCE (CVE-2026-80744)

在 Linux 核心中,下列弱點已解決:

selinux:不要取消從未開始的原則轉換 (CVE-2026-80756)

在 Linux 核心中,下列弱點已解決:

selinux:拒絕低於其繼承的 common (CVE-2026-80757) 的類別權限計數

在 Linux 核心中,下列弱點已解決:

futex:避免在最終放置 (CVE-2026-80758) 時釋放後使用私有雜湊

在 Linux 核心中,下列弱點已解決:

HID: hyperv:驗證初始裝置資訊邊界 (CVE-2026-80765)

在 Linux 核心中,下列弱點已解決:

futex:修正初始 mm->futex.phash.ref 分配 (CVE-2026-80775) 上的爭用

在 Linux 核心中,下列弱點已解決:

futex:在私有雜湊調整大小期間修正 futex_pivot_pending() 中的爭用 (CVE-2026-80776)

在 Linux 核心中,下列弱點已解決:

futex/pi: 插入私有 futex exec() 爭用 (CVE-2026-80777)

在 Linux 核心中,下列弱點已解決:

futex/pi: 拒絕 cross-mm 私有 futex 擁有者 (CVE-2026-80778)

在 Linux 核心中,下列弱點已解決:

HID: core:修正 hid_set_field() 中 field->usage 的 OOB 讀取 (CVE-2026-80781)

在 Linux 核心中,下列弱點已解決:

mptcp: pm:修正來自 alloc-during-teardown 爭用 (CVE-2026-80784) 的記憶體洩漏

在 Linux 核心中,下列弱點已解決:

ipv6:修正 ip6_finish_output2() 中的釋放後使用 (CVE-2026-80792)

在 Linux 核心中,下列弱點已解決:

ipv4:拒絕 ip_do_fragment() 中大小過小的 MTU (CVE-2026-80793)

在 Linux 核心中,下列弱點已解決:

xfs:在欄位存取之前驗證 ATTR 進入指標 (CVE-2026-80805)

在 Linux 核心中,下列弱點已解決:

ext4:不要在新的加密檔案上啟用 DAX (CVE-2026-80806)

在 Linux 核心中,下列弱點已解決:

ext4:停止重試飽和的 xattr 快取項目 (CVE-2026-80808)

在 Linux 核心中,下列弱點已解決:

io_uring/rsrc:修正 io_vec_fill_bvec() 中的作品集大小溢位 (CVE-2026-80810)

在 Linux 核心中,下列弱點已解決:

io_uring/cmd:修正未回收非同步 cmd 時的 iovec 洩漏 (CVE-2026-80811)

在 Linux 核心中,下列弱點已解決:

iommu/tegra241-cmdqv:修正拆卸時CMD_SYNC釋放後使用 (CVE-2026-80818)

在 Linux 核心中,下列弱點已解決:

net/tls:非同步解密失敗後 tls_sw_splice_read() 失敗 (CVE-2026-80904)

在 Linux 核心中,下列弱點已解決:

net: tap:修正傳送 VLAN 標籤框架時的錯誤transport_header (CVE-2026-80905)

在 Linux 核心中,下列弱點已解決:

net: packet:修正傳送 VLAN 標記框架時的錯誤transport_header (CVE-2026-80906)

在 Linux 核心中,下列弱點已解決:

selinux:拒絕 security_get_classes() 中未認領的類別值 (CVE-2026-80912)

在 Linux 核心中,下列弱點已解決:

selinux:要求定義每個布林值 (CVE-2026-80913)

在 Linux 核心中,下列弱點已解決:

PCI: host-generic:修正 32 位元 CAM 系統上的 NULL 指標解除參照 (CVE-2026-80917)

在 Linux 核心中,下列弱點已解決:

HID: core:修正長項目上的數字/指標類型混淆 (CVE-2026-80918)

Tenable 已直接從所測試產品的安全公告擷取前置描述區塊。

請注意,Nessus 並未測試這些問題,而是僅依據應用程式自我報告的版本號碼作出判斷。

解決方案

執行「dnf update kernel6.18 --releasever 2023.12.20260928」或「dnf update --advisory ALAS2023-2026-3139 --releasever 2023.12.20260928」以更新系統。

另請參閱

https://alas.aws.amazon.com//AL2023/ALAS2023-2026-3139.html

https://alas.aws.amazon.com/faqs.html

https://explore.alas.aws.amazon.com/CVE-2026-68082.html

https://explore.alas.aws.amazon.com/CVE-2026-68159.html

https://explore.alas.aws.amazon.com/CVE-2026-74483.html

https://explore.alas.aws.amazon.com/CVE-2026-74517.html

https://explore.alas.aws.amazon.com/CVE-2026-74582.html

https://explore.alas.aws.amazon.com/CVE-2026-74583.html

https://explore.alas.aws.amazon.com/CVE-2026-74586.html

https://explore.alas.aws.amazon.com/CVE-2026-74587.html

https://explore.alas.aws.amazon.com/CVE-2026-74588.html

https://explore.alas.aws.amazon.com/CVE-2026-74589.html

https://explore.alas.aws.amazon.com/CVE-2026-74591.html

https://explore.alas.aws.amazon.com/CVE-2026-74592.html

https://explore.alas.aws.amazon.com/CVE-2026-74593.html

https://explore.alas.aws.amazon.com/CVE-2026-74594.html

https://explore.alas.aws.amazon.com/CVE-2026-74595.html

https://explore.alas.aws.amazon.com/CVE-2026-74597.html

https://explore.alas.aws.amazon.com/CVE-2026-74598.html

https://explore.alas.aws.amazon.com/CVE-2026-74601.html

https://explore.alas.aws.amazon.com/CVE-2026-74602.html

https://explore.alas.aws.amazon.com/CVE-2026-74606.html

https://explore.alas.aws.amazon.com/CVE-2026-74608.html

https://explore.alas.aws.amazon.com/CVE-2026-74609.html

https://explore.alas.aws.amazon.com/CVE-2026-74610.html

https://explore.alas.aws.amazon.com/CVE-2026-74611.html

https://explore.alas.aws.amazon.com/CVE-2026-74612.html

https://explore.alas.aws.amazon.com/CVE-2026-74613.html

https://explore.alas.aws.amazon.com/CVE-2026-74614.html

https://explore.alas.aws.amazon.com/CVE-2026-74615.html

https://explore.alas.aws.amazon.com/CVE-2026-74616.html

https://explore.alas.aws.amazon.com/CVE-2026-74618.html

https://explore.alas.aws.amazon.com/CVE-2026-74619.html

https://explore.alas.aws.amazon.com/CVE-2026-74620.html

https://explore.alas.aws.amazon.com/CVE-2026-74624.html

https://explore.alas.aws.amazon.com/CVE-2026-74627.html

https://explore.alas.aws.amazon.com/CVE-2026-74630.html

https://explore.alas.aws.amazon.com/CVE-2026-74632.html

https://explore.alas.aws.amazon.com/CVE-2026-74633.html

https://explore.alas.aws.amazon.com/CVE-2026-74634.html

https://explore.alas.aws.amazon.com/CVE-2026-74635.html

https://explore.alas.aws.amazon.com/CVE-2026-74636.html

https://explore.alas.aws.amazon.com/CVE-2026-74637.html

https://explore.alas.aws.amazon.com/CVE-2026-74644.html

https://explore.alas.aws.amazon.com/CVE-2026-74652.html

https://explore.alas.aws.amazon.com/CVE-2026-74653.html

https://explore.alas.aws.amazon.com/CVE-2026-74654.html

https://explore.alas.aws.amazon.com/CVE-2026-74656.html

https://explore.alas.aws.amazon.com/CVE-2026-74657.html

https://explore.alas.aws.amazon.com/CVE-2026-74658.html

https://explore.alas.aws.amazon.com/CVE-2026-74660.html

https://explore.alas.aws.amazon.com/CVE-2026-74662.html

https://explore.alas.aws.amazon.com/CVE-2026-74663.html

https://explore.alas.aws.amazon.com/CVE-2026-74664.html

https://explore.alas.aws.amazon.com/CVE-2026-74665.html

https://explore.alas.aws.amazon.com/CVE-2026-74666.html

https://explore.alas.aws.amazon.com/CVE-2026-74667.html

https://explore.alas.aws.amazon.com/CVE-2026-74668.html

https://explore.alas.aws.amazon.com/CVE-2026-74669.html

https://explore.alas.aws.amazon.com/CVE-2026-74670.html

https://explore.alas.aws.amazon.com/CVE-2026-74671.html

https://explore.alas.aws.amazon.com/CVE-2026-74672.html

https://explore.alas.aws.amazon.com/CVE-2026-74673.html

https://explore.alas.aws.amazon.com/CVE-2026-74675.html

https://explore.alas.aws.amazon.com/CVE-2026-74676.html

https://explore.alas.aws.amazon.com/CVE-2026-74683.html

https://explore.alas.aws.amazon.com/CVE-2026-74684.html

https://explore.alas.aws.amazon.com/CVE-2026-74688.html

https://explore.alas.aws.amazon.com/CVE-2026-74695.html

https://explore.alas.aws.amazon.com/CVE-2026-74696.html

https://explore.alas.aws.amazon.com/CVE-2026-74698.html

https://explore.alas.aws.amazon.com/CVE-2026-74700.html

https://explore.alas.aws.amazon.com/CVE-2026-74701.html

https://explore.alas.aws.amazon.com/CVE-2026-74704.html

https://explore.alas.aws.amazon.com/CVE-2026-74705.html

https://explore.alas.aws.amazon.com/CVE-2026-74707.html

https://explore.alas.aws.amazon.com/CVE-2026-74708.html

https://explore.alas.aws.amazon.com/CVE-2026-74709.html

https://explore.alas.aws.amazon.com/CVE-2026-74710.html

https://explore.alas.aws.amazon.com/CVE-2026-74714.html

https://explore.alas.aws.amazon.com/CVE-2026-74717.html

https://explore.alas.aws.amazon.com/CVE-2026-74718.html

https://explore.alas.aws.amazon.com/CVE-2026-74720.html

https://explore.alas.aws.amazon.com/CVE-2026-74722.html

https://explore.alas.aws.amazon.com/CVE-2026-74724.html

https://explore.alas.aws.amazon.com/CVE-2026-74726.html

https://explore.alas.aws.amazon.com/CVE-2026-74728.html

https://explore.alas.aws.amazon.com/CVE-2026-74730.html

https://explore.alas.aws.amazon.com/CVE-2026-74736.html

https://explore.alas.aws.amazon.com/CVE-2026-74739.html

https://explore.alas.aws.amazon.com/CVE-2026-74740.html

https://explore.alas.aws.amazon.com/CVE-2026-74742.html

https://explore.alas.aws.amazon.com/CVE-2026-74743.html

https://explore.alas.aws.amazon.com/CVE-2026-74744.html

https://explore.alas.aws.amazon.com/CVE-2026-74746.html

https://explore.alas.aws.amazon.com/CVE-2026-74748.html

https://explore.alas.aws.amazon.com/CVE-2026-74753.html

https://explore.alas.aws.amazon.com/CVE-2026-80527.html

https://explore.alas.aws.amazon.com/CVE-2026-80528.html

https://explore.alas.aws.amazon.com/CVE-2026-80529.html

https://explore.alas.aws.amazon.com/CVE-2026-80530.html

https://explore.alas.aws.amazon.com/CVE-2026-80534.html

https://explore.alas.aws.amazon.com/CVE-2026-80536.html

https://explore.alas.aws.amazon.com/CVE-2026-80557.html

https://explore.alas.aws.amazon.com/CVE-2026-80558.html

https://explore.alas.aws.amazon.com/CVE-2026-80561.html

https://explore.alas.aws.amazon.com/CVE-2026-80572.html

https://explore.alas.aws.amazon.com/CVE-2026-80574.html

https://explore.alas.aws.amazon.com/CVE-2026-80578.html

https://explore.alas.aws.amazon.com/CVE-2026-80585.html

https://explore.alas.aws.amazon.com/CVE-2026-80586.html

https://explore.alas.aws.amazon.com/CVE-2026-80587.html

https://explore.alas.aws.amazon.com/CVE-2026-80588.html

https://explore.alas.aws.amazon.com/CVE-2026-80589.html

https://explore.alas.aws.amazon.com/CVE-2026-80590.html

https://explore.alas.aws.amazon.com/CVE-2026-80724.html

https://explore.alas.aws.amazon.com/CVE-2026-80725.html

https://explore.alas.aws.amazon.com/CVE-2026-80726.html

https://explore.alas.aws.amazon.com/CVE-2026-80727.html

https://explore.alas.aws.amazon.com/CVE-2026-80731.html

https://explore.alas.aws.amazon.com/CVE-2026-80733.html

https://explore.alas.aws.amazon.com/CVE-2026-80737.html

https://explore.alas.aws.amazon.com/CVE-2026-80739.html

https://explore.alas.aws.amazon.com/CVE-2026-80742.html

https://explore.alas.aws.amazon.com/CVE-2026-80744.html

https://explore.alas.aws.amazon.com/CVE-2026-80756.html

https://explore.alas.aws.amazon.com/CVE-2026-80757.html

https://explore.alas.aws.amazon.com/CVE-2026-80758.html

https://explore.alas.aws.amazon.com/CVE-2026-80765.html

https://explore.alas.aws.amazon.com/CVE-2026-80775.html

https://explore.alas.aws.amazon.com/CVE-2026-80776.html

https://explore.alas.aws.amazon.com/CVE-2026-80777.html

https://explore.alas.aws.amazon.com/CVE-2026-80778.html

https://explore.alas.aws.amazon.com/CVE-2026-80781.html

https://explore.alas.aws.amazon.com/CVE-2026-80784.html

https://explore.alas.aws.amazon.com/CVE-2026-80792.html

https://explore.alas.aws.amazon.com/CVE-2026-80793.html

https://explore.alas.aws.amazon.com/CVE-2026-80805.html

https://explore.alas.aws.amazon.com/CVE-2026-80806.html

https://explore.alas.aws.amazon.com/CVE-2026-80808.html

https://explore.alas.aws.amazon.com/CVE-2026-80810.html

https://explore.alas.aws.amazon.com/CVE-2026-80811.html

https://explore.alas.aws.amazon.com/CVE-2026-80818.html

https://explore.alas.aws.amazon.com/CVE-2026-80904.html

https://explore.alas.aws.amazon.com/CVE-2026-80905.html

https://explore.alas.aws.amazon.com/CVE-2026-80906.html

https://explore.alas.aws.amazon.com/CVE-2026-80912.html

https://explore.alas.aws.amazon.com/CVE-2026-80913.html

https://explore.alas.aws.amazon.com/CVE-2026-80917.html

https://explore.alas.aws.amazon.com/CVE-2026-80918.html

Plugin 詳細資訊

嚴重性: Critical

ID: 351016

檔案名稱: al2023_ALAS2023-2026-3139.nasl

版本: 1.1

類型: Local

代理程式: unix

已發布: 2026/9/29

已更新: 2026/9/29

支援的感應器: Frictionless Assessment AWS, Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Continuous Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

風險資訊

VPR

風險因素: High

分數: 7.6

百分位數: 98.35

CVSS v2

風險因素: Critical

基本分數: 10

時間性分數: 7.8

媒介: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS 評分資料來源: CVE-2026-80725

CVSS v3

風險因素: Critical

基本分數: 10

時間性分數: 9

媒介: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

時間媒介: CVSS:3.0/E:P/RL:O/RC:C

CVSS 評分資料來源: CVE-2026-74705

弱點資訊

CPE: cpe:/o:amazon:linux:2023, p-cpe:/a:amazon:linux:bpftool6.18-debuginfo, p-cpe:/a:amazon:linux:bpftool6.18, p-cpe:/a:amazon:linux:kernel-livepatch-6.18.48-107.148, p-cpe:/a:amazon:linux:kernel6.18-debuginfo-common-aarch64, p-cpe:/a:amazon:linux:kernel6.18-debuginfo-common-x86_64, p-cpe:/a:amazon:linux:kernel6.18-debuginfo, p-cpe:/a:amazon:linux:kernel6.18-devel, p-cpe:/a:amazon:linux:kernel6.18-headers, p-cpe:/a:amazon:linux:kernel6.18-modules-extra-common, p-cpe:/a:amazon:linux:kernel6.18-modules-extra, p-cpe:/a:amazon:linux:kernel6.18-tools-debuginfo, p-cpe:/a:amazon:linux:kernel6.18-tools-devel, p-cpe:/a:amazon:linux:kernel6.18-tools, p-cpe:/a:amazon:linux:kernel6.18, p-cpe:/a:amazon:linux:microvm-kernel6.18, p-cpe:/a:amazon:linux:perf6.18-debuginfo, p-cpe:/a:amazon:linux:perf6.18, p-cpe:/a:amazon:linux:python3-perf6.18-debuginfo, p-cpe:/a:amazon:linux:python3-perf6.18

必要的 KB 項目: Host/local_checks_enabled, Host/AmazonLinux/release, Host/AmazonLinux/rpm-list

可被惡意程式利用: true

可輕鬆利用: Exploits are available

修補程式發佈日期: 2026/9/29

弱點發布日期: 2026/8/8

參考資訊

CVE: CVE-2026-68082, CVE-2026-68159, CVE-2026-74483, CVE-2026-74517, CVE-2026-74582, CVE-2026-74583, CVE-2026-74586, CVE-2026-74587, CVE-2026-74588, CVE-2026-74589, CVE-2026-74591, CVE-2026-74592, CVE-2026-74593, CVE-2026-74594, CVE-2026-74595, CVE-2026-74597, CVE-2026-74598, CVE-2026-74601, CVE-2026-74602, CVE-2026-74606, CVE-2026-74608, CVE-2026-74609, CVE-2026-74610, CVE-2026-74611, CVE-2026-74612, CVE-2026-74613, CVE-2026-74614, CVE-2026-74615, CVE-2026-74616, CVE-2026-74618, CVE-2026-74619, CVE-2026-74620, CVE-2026-74624, CVE-2026-74627, CVE-2026-74630, CVE-2026-74632, CVE-2026-74633, CVE-2026-74634, CVE-2026-74635, CVE-2026-74636, CVE-2026-74637, CVE-2026-74644, CVE-2026-74652, CVE-2026-74653, CVE-2026-74654, CVE-2026-74656, CVE-2026-74657, CVE-2026-74658, CVE-2026-74660, CVE-2026-74662, CVE-2026-74663, CVE-2026-74664, CVE-2026-74665, CVE-2026-74666, CVE-2026-74667, CVE-2026-74668, CVE-2026-74669, CVE-2026-74670, CVE-2026-74671, CVE-2026-74672, CVE-2026-74673, CVE-2026-74675, CVE-2026-74676, CVE-2026-74683, CVE-2026-74684, CVE-2026-74688, CVE-2026-74695, CVE-2026-74696, CVE-2026-74698, CVE-2026-74700, CVE-2026-74701, CVE-2026-74704, CVE-2026-74705, CVE-2026-74707, CVE-2026-74708, CVE-2026-74709, CVE-2026-74710, CVE-2026-74714, CVE-2026-74717, CVE-2026-74718, CVE-2026-74720, CVE-2026-74722, CVE-2026-74724, CVE-2026-74726, CVE-2026-74728, CVE-2026-74730, CVE-2026-74736, CVE-2026-74739, CVE-2026-74740, CVE-2026-74742, CVE-2026-74743, CVE-2026-74744, CVE-2026-74746, CVE-2026-74748, CVE-2026-74753, CVE-2026-80527, CVE-2026-80528, CVE-2026-80529, CVE-2026-80530, CVE-2026-80534, CVE-2026-80536, CVE-2026-80557, CVE-2026-80558, CVE-2026-80561, CVE-2026-80572, CVE-2026-80574, CVE-2026-80578, CVE-2026-80585, CVE-2026-80586, CVE-2026-80587, CVE-2026-80588, CVE-2026-80589, CVE-2026-80590, CVE-2026-80724, CVE-2026-80725, CVE-2026-80726, CVE-2026-80727, CVE-2026-80731, CVE-2026-80733, CVE-2026-80737, CVE-2026-80739, CVE-2026-80742, CVE-2026-80744, CVE-2026-80756, CVE-2026-80757, CVE-2026-80758, CVE-2026-80765, CVE-2026-80775, CVE-2026-80776, CVE-2026-80777, CVE-2026-80778, CVE-2026-80781, CVE-2026-80784, CVE-2026-80792, CVE-2026-80793, CVE-2026-80805, CVE-2026-80806, CVE-2026-80808, CVE-2026-80810, CVE-2026-80811, CVE-2026-80818, CVE-2026-80904, CVE-2026-80905, CVE-2026-80906, CVE-2026-80912, CVE-2026-80913, CVE-2026-80917, CVE-2026-80918