Amazon Linux 2:kernel (ALASKERNEL-5.15-2026-116)

high Nessus Plugin ID 351051

概要

遠端 Amazon Linux 2 主機缺少安全性更新。

說明

遠端主機上安裝的核心版本早於 5.15.220-153.252。因此,會受到 ALAS2KERNEL-5.15-2026-116 公告中所提及的多個弱點影響。

在 Linux 核心中,下列弱點已解決:

futex:在訊號/逾時喚醒期間,防止在 requeue-PI 中鎖定 (CVE-2026-52977)

在 Linux 核心中,下列弱點已解決:

bpf:修正卸載的地圖/程序資訊填充 (CVE-2026-53089) 中的釋放後使用

在 Linux 核心中,下列弱點已解決:

bpf:修正子程序 (CVE-2026-53090) 中的 ld_{abs,ind} 故障路徑分析

在 Linux 核心中,下列弱點已解決:

bpf:如果 BPF LSM 未初始化,則拒絕BPF_MAP_TYPE_INODE_STORAGE建立

當設定 CONFIG_BPF_LSM=y 時,BPF inode 儲存體映射 (BPF_MAP_TYPE_INODE_STORAGE) 會編譯到核心中。但是,如果在啟動時未明確啟用 BPF LSM(例如,從 lsm= 啟動參數中省略),則永遠不會針對 BPF LSM 執行 lsm_prepare()。

因此,BPF inode 安全性 blob 位移 (bpf_lsm_blob_sizes.lbs_inode) 永遠不會初始化,並保持其預設編譯大小 8 位元組,而不是更新為超過保留結構rcu_head的有效位移 (通常為 16 位元組或更多)。

當特權使用者建立並更新BPF_MAP_TYPE_INODE_STORAGEmap時,bpf_inode() 會評估 inode->i_security + 8。這會錯誤地將 inode >i_security blob 開頭的結構 rcu_head.func 回呼指標別名。在後續的對應元素清除或 inode 損毀期間,將 NULL 寫入 owner_storage 會清除 queuedRCU 回呼指標。當 rcu_do_batch() 稍後執行佇列回呼時,它會嘗試在位址0x0處擷取指令,從而觸發立即核心錯誤。

透過引入標有 __ro_after_init 的全域 bpf_lsm_initialized 布林標記來解決此問題。當 LSM 架構成功註冊 BPF LSM 時,在 bpf_lsm_init() 內將此標誌設定為 true。在此標誌的 inode_storage_map_alloc() 中進行閘對應分配,如果 BPF LSM 反過來未初始化,則返回 EOPNOTSUPP。

這種故障快速方法可防止使用者空間在支援的 BPF LSM 基礎架構缺失時配置 inode 儲存映射,從而避免殭屍映射狀態。(CVE-2026-64192)

在 Linux 核心中,下列弱點已解決:

mm:使用正確的掛載 idmap (CVE-2026-64294) 進行檔案擁有權檢查

在 Linux 核心中,下列弱點已解決:

KVM: nVMX:在 VMCLEAR 之後立即隱藏影子 VMCS (CVE-2026-64562)

在 Linux 核心中,下列弱點已解決:

rhashtable:在表格重新啟動時清除過時的 iter->p (CVE-2026-64563)

在 Linux 核心中,下列弱點已解決:

sctp:不要在 DEL-IP 處理中釋放 ASCONF 自己的傳輸 (CVE-2026-64564)

在 Linux 核心中,下列弱點已解決:

btrfs:拒絕項目多於頁面的可用空間快取 (CVE-2026-64567)

在 Linux 核心中,下列弱點已解決:

ipv4: fib:在插入錯誤路徑上釋放帶有 kfree_rcu() 的fib_alias (CVE-2026-64572)

在 Linux 核心中,下列弱點已解決:

nexthop:在 nh_res_bucket_migrate() 中初始化 extack (CVE-2026-64576)

在 Linux 核心中,下列弱點已解決:

xfrm: policy:在xfrm_hash_rebuild重新插入之前預先配置不精確的 bin (CVE-2026-64579)

在 Linux 核心中,下列弱點已解決:

xfrm:修正 xfrm_user_policy() 中的雙重釋放sk_dst_cache (CVE-2026-64581)

在 Linux 核心中,下列弱點已解決:

libceph:修正 decode_lockers()CVE-2026-68082 () 中兩個不安全的裸解碼

在 Linux 核心中,下列弱點已解決:

audit:修正 audit_dupe_exe() 中的遞迴鎖定鎖死 (CVE-2026-68096)

在 Linux 核心中,下列弱點已解決:

openvswitch:修正 GSO 使用者空間截斷反向溢位 (CVE-2026-68123)

在 Linux 核心中,下列弱點已解決:

ila:在總和檢查碼 adjust (CVE-2026-68127) 中pskb_may_pull後重新載入 IPv6 標頭

在 Linux 核心中,下列弱點已解決:

rbd:將物件對應更新路徑中的正結果代碼重設為零 (CVE-2026-68131)

在 Linux 核心中,下列弱點已解決:

super:修正凍結區塊裝置上的緊急解凍鎖死 (CVE-2026-68132)

在 Linux 核心中,下列弱點已解決:

net/sched:針對並行 get/put (CVE-2026-68138) 序列化 qdisc_rtab_list

在 Linux 核心中,下列弱點已解決:

geneve:需要在裝置 netns 中CAP_NET_ADMIN以進行 changelink (CVE-2026-68142)

在 Linux 核心中,下列弱點已解決:

ftrace:新增全域互斥以序列化 trace_parser 存取 (CVE-2026-68146)

在 Linux 核心中,下列弱點已解決:

libceph:在用戶端拆卸之前移除 debugfs 檔案 (CVE-2026-68153)

在 Linux 核心中,下列弱點已解決:

libceph:拒絕 crush_decode (CVE-2026-68154) 中的零儲存貯體類型

在 Linux 核心中,下列弱點已解決:

libceph:拒絕 monmaps 通告零監視器 (CVE-2026-68155)

在 Linux 核心中,下列弱點已解決:

libceph:授權者更新後重新整理 auth->authorizer_buf{,_len} (CVE-2026-68156)

在 Linux 核心中,下列弱點已解決:

libceph:保護缺少 CRUSH 類型名稱查詢 (CVE-2026-68157)

在 Linux 核心中,下列弱點已解決:

libceph:修正 decode_new_up_state_weight() 中的乘法溢位 (CVE-2026-68158)

在 Linux 核心中,下列弱點已解決:

libceph:將 pg_{temp,upmap,upmap_items} 長度綁定為 CEPH_PG_MAX_SIZE (CVE-2026-68159)

在 Linux 核心中,下列弱點已解決:

Ceph:修正 ceph_handle_caps() 中 Snaptrace 上的預先驗證越界讀取 (CVE-2026-68160)

在 Linux 核心中,下列弱點已解決:

sctp:避免在 netns 拆卸期間auth_enable sysctl UAF (CVE-2026-68162)

在 Linux 核心中,下列弱點已解決:

cdrom:修正 CDROMVOLCTRL 中的堆疊越界讀取 (CVE-2026-68184)

在 Linux 核心中,下列弱點已解決:

binfmt_misc:僅在解譯器開啟後設定have_execfd (CVE-2026-68186)

在 Linux 核心中,下列弱點已解決:

drm/i915/gem: 修正 I915_CONTEXT_PARAM_SSEU 中的 NULL 解除參照 (CVE-2026-68243)

在 Linux 核心中,下列弱點已解決:

drm/i915/gem:不要在原始上下文錯誤 (CVE-2026-68244) 上洩露 siblings[]

在 Linux 核心中,下列弱點已解決:

drm/i915:active_instance (CVE-2026-68248) 中出錯時傳回 NULL

在 Linux 核心中,下列弱點已解決:

drm/i915/hdcp:在溢位前檢查 streams[] 邊界 (CVE-2026-68253)

在 Linux 核心中,下列弱點已解決:

drm/i915/vrr:需要 VRR 的有效最小/最大 vfreq (CVE-2026-68254)

在 Linux 核心中,下列弱點已解決:

drm/dp/mst:修正邊帶回覆剖析器 (CVE-2026-68277) 中 2 位元組欄位的 OOB 讀取

在 Linux 核心中,下列弱點已解決:

drm/dp/mst:修正邊帶區塊累積中的緩衝區溢位 (CVE-2026-68278)

在 Linux 核心中,下列弱點已解決:

drm/dp/mst:修正遠端 DPCD/I2C 邊帶回覆剖析器中的 OOB 讀取 (CVE-2026-68279)

在 Linux 核心中,下列弱點已解決:

bpf, sockmap:修正 tcp_bpf_sendmsg() 中的軟木塞釋放後使用 (CVE-2026-68284)

在 Linux 核心中,下列弱點已解決:

vmxnet3:修正 vmxnet3_get_hdr_len() 中對 Geneve 封包的BUG_ON (CVE-2026-68299)

在 Linux 核心中,下列弱點已解決:

sctp: auth:當 auth_chunk 為 NULL 時,驗證驗證要求 (CVE-2026-68300)

在 Linux 核心中,下列弱點已解決:

sctp:驗證 sctp_process_strreset_inreq() 中的資料流計數 (CVE-2026-68315)

在 Linux 核心中,下列弱點已解決:

sctp:修正 sctp_auth_ep_add_chunkid (CVE-2026-68320) 中的auth_chunk_list容量檢查

在 Linux 核心中,下列弱點已解決:

rds:修正停用 IPv6 時inet6_addr_lst NULL 解除參照 (CVE-2026-68322)

在 Linux 核心中,下列弱點已解決:

iommu/amd:繫結早期 ACPI HID 對應 (CVE-2026-68325)

在 Linux 核心中,下列弱點已解決:

rds:丟棄跨網路命名空間邊界的傳入訊息 (CVE-2026-68335)

在 Linux 核心中,下列弱點已解決:

net/packet:避免取消註冊 (CVE-2026-68338) 後的 fanout hook 重新註冊

在 Linux 核心中,下列弱點已解決:

sctp:修正 struct sctp_cookieCVE-2026-68376 () 中的 auth_hmacs 陣列大小

在 Linux 核心中,下列弱點已解決:

smb/client:處理 fallocate (CVE-2026-68388) 中重疊的分配範圍

在 Linux 核心中,下列弱點已解決:

btrfs:如果 merge_reloc_roots()CVE-2026-68422 () 中的重新定位根目錄意外,則修正根洩漏

在 Linux 核心中,下列弱點已解決:

IB/mad:在重組之前刪除不相符的 RMPP 回應 (CVE-2026-68425)

在 Linux 核心中,下列弱點已解決:

KVM:x86/mmu:修正廠商模組重新載入時的釋放後使用 (CVE-2026-68428)

在 Linux 核心中,下列弱點已解決:

vxlan:需要在裝置 netns 中CAP_NET_ADMIN以進行 changelink (CVE-2026-68432)

在 Linux 核心中,下列弱點已解決:

libceph:綁定get_version回覆解碼到前面的 len (CVE-2026-68433)

在 Linux 核心中,下列弱點已解決:

btrfs:重複重新定位根插入 (CVE-2026-68450) 上的釋放映射節點

在 Linux 核心中,下列弱點已解決:

ipvs:重新配置磁頭後重新載入 IP 標頭 (CVE-2026-68476)

在 Linux 核心中,下列弱點已解決:

net: ip6_tunnel:需要在裝置 netns 中CAP_NET_ADMIN以進行 changelink (CVE-2026-72051)

在 Linux 核心中,下列弱點已解決:

net: ipip:需要在裝置 netns 中CAP_NET_ADMIN以進行 changelink (CVE-2026-72053)

在 Linux 核心中,下列弱點已解決:

dm-integrity:不要將 hash_offset 遞增兩次 (CVE-2026-72099)

在 Linux 核心中,下列弱點已解決:

bpf,fork:在存取它的救助之前擦除 ->bpf_storage (CVE-2026-72110)

在 Linux 核心中,下列弱點已解決:

can: bcm:新增缺少的裝置參照計數以移除 CAN 篩選器 (CVE-2026-72113)

在 Linux 核心中,下列弱點已解決:

can: bcm:驗證 RTR 回覆的 bcm_rx_setup() 中的框架長度 (CVE-2026-72114)

在 Linux 核心中,下列弱點已解決:

can: bcm:追蹤單一來源介面的 ANYDEV 逾時/節流操作 (CVE-2026-72115)

在 Linux 核心中,下列弱點已解決:

can: bcm:移除裝置後修正過時的 rx/tx 操作 (CVE-2026-72116)

在 Linux 核心中,下列弱點已解決:

can: bcm:修正 bcm_rx_handler() 中 rx_stamp/rx_ifindex 上的資料爭用 (CVE-2026-72117)

在 Linux 核心中,下列弱點已解決:

can: bcm:修正 CAN 框架 rx/tx 統計資料 (CVE-2026-72118)

在 Linux 核心中,下列弱點已解決:

can: bcm:擴充資料和計時器更新的 bcm_tx_lock 使用 (CVE-2026-72119)

在 Linux 核心中,下列弱點已解決:

can: bcm:更新篩選器和計時器值時新增鎖定 (CVE-2026-72121)

在 Linux 核心中,下列弱點已解決:

can: bcm:將rx_op解除分配延遲到工作佇列以修正 thrtimer UAF (CVE-2026-72123)

在 Linux 核心中,下列弱點已解決:

ntfs3:驗證 indx_insert_into_buffer (CVE-2026-72191) 中的分割點偏移

在 Linux 核心中,下列弱點已解決:

selinux:避免 selinux_sctp_bind_connect() 中的sk_socket取消參照 (CVE-2026-72242)

在 Linux 核心中,下列弱點已解決:

netfilter: nft_set_pipapo:不要將錯誤的複製洩漏到未來的事務中 (CVE-2026-72252)

在 Linux 核心中,下列弱點已解決:

netfilter: nf_conntrack_sip:在存取 skb_dst() 之前先驗證它 (CVE-2026-72253)

在 Linux 核心中,下列弱點已解決:

netfilter: nf_queue:當 NFQUEUE 持有假 dst () 時,pin 橋接裝置 (CVE-2026-72255)

在 Linux 核心中,下列弱點已解決:

ipv4: igmp:修正 igmp_gq_start_timer() 中潛在的 UAF (CVE-2026-72323)

在 Linux 核心中,下列弱點已解決:

net: openvswitch:修正 CT 期間流程金鑰更新失敗時的 skb 洩漏 (CVE-2026-74464)

在 Linux 核心中,下列弱點已解決:

net: openvswitch:修正儀表連接失敗時的潛在 UAF (CVE-2026-74465)

在 Linux 核心中,下列弱點已解決:

sctp:防止對等傳輸計數溢位 (CVE-2026-74469)

在 Linux 核心中,下列弱點已解決:

tracing:檢查 trace_module_add_events() 中 __register_event() 的傳回值 (CVE-2026-74471)

在 Linux 核心中,下列弱點已解決:

vxlan:在 route_shortcircuit() 中使用 pskb_network_may_pull()CVE-2026-74473

在 Linux 核心中,下列弱點已解決:

vxlan:在 route_shortcircuit() 中使用 neigh_ha_snapshot()CVE-2026-74475 ()

在 Linux 核心中,下列弱點已解決:

net: bridge:刪除連接埠群組後停止快速離開 (CVE-2026-74480)

在 Linux 核心中,下列弱點已解決:

mm/page_reporting:在暫停期間使用 system_freezable_wq 修正 UAF (CVE-2026-74481)

在 Linux 核心中,下列弱點已解決:

mm/huge_memory:在釋放分割後對開本之前解除鎖定i_mmap_rwsem (CVE-2026-74482)

在 Linux 核心中,下列弱點已解決:

binfmt_misc:拒絕旗標字元作為欄位分隔符號 (CVE-2026-74485)

在 Linux 核心中,下列弱點已解決:

binfmt_misc:移除項目時還原寫入存取權 (CVE-2026-74487)

在 Linux 核心中,下列弱點已解決:

netfilter: ipset:不要更新來自核心端雜湊新增 (CVE-2026-74492) 的註解

在 Linux 核心中,下列弱點已解決:

audit:修正 audit_del_rule() 中潛在的釋放後使用 (CVE-2026-74512)

在 Linux 核心中,下列弱點已解決:

mm/hugetlb:修正 allocate_file_region_entries()CVE-2026-74518 () 中的清單損毀

在 Linux 核心中,下列弱點已解決:

pinctrl: devicetree:不要釋放錯誤路徑上的未初始化dev_name (CVE-2026-74519)

在 Linux 核心中,下列弱點已解決:

scsi: libiscsi_tcp:將 SCSI 回應資料區段繫結至連線緩衝區 (CVE-2026-74556)

在 Linux 核心中,下列弱點已解決:

scsi: libiscsi:修正 SCSI 感應緩衝區中的過時資料洩漏 (CVE-2026-74557)

在 Linux 核心中,下列弱點已解決:

rds: tcp:在 rds_tcp_laddr_check() 中跨 ipv6_chk_addr() 保持 RCU 鎖定 (CVE-2026-74563)

在 Linux 核心中,下列弱點已解決:

netfilter: xt_hashlimit:驗證雜湊表是否支援 XT_HASHLIMIT_RATE_MATCH (CVE-2026-74564)

在 Linux 核心中,下列弱點已解決:

keys:使金鑰環金鑰區塊位元組順序與 keyring_diff_objects() (CVE-2026-74566) 一致

在 Linux 核心中,下列弱點已解決:

KEYS:修正 keyring_get_key_chunk()CVE-2026-74567 () 中的越界讀取

在 Linux 核心中,下列弱點已解決:

netfilter: nf_conntrack_sip:在 sip_help_tcp()CVE-2026-74569 () 中將 NAT 重寫差異擴大到 s32

在 Linux 核心中,下列弱點已解決:

net: mpls:在 mpls_getroute() 中初始化 rtm_tos (CVE-2026-74577)

在 Linux 核心中,下列弱點已解決:

netfilter: nft_payload:修正部分欄位卸載的遮罩構建 (CVE-2026-74579)

在 Linux 核心中,下列弱點已解決:

net: ipv6:清除隱藏的 fib6 規則結果 (CVE-2026-74581)

在 Linux 核心中,下列弱點已解決:

封包:在非環形傳送路徑中使用一致的hard_header_len (CVE-2026-74582)

在 Linux 核心中,下列弱點已解決:

net/sched: cls_route:修正 filterCVE-2026-74583() 上的 fastmap 釋放後使用

在 Linux 核心中,下列弱點已解決:

sctp:移除對等體時清除new_transport (CVE-2026-74586)

在 Linux 核心中,下列弱點已解決:

sctp:修正快取的 ASCONF 區塊的釋放後使用 (CVE-2026-74587)

在 Linux 核心中,下列弱點已解決:

sctp:保持區塊>傳輸與其排入佇列的清單保持一致 (CVE-2026-74588)

在 Linux 核心中,下列弱點已解決:

bpf, sockmap:修正傳送判定 (CVE-2026-74589) 中的sk_redir釋放後使用

在 Linux 核心中,下列弱點已解決:

sched/psi:關閉 psi_cgroup_free() 中的 rtpoll_timer (CVE-2026-74594)

在 Linux 核心中,下列弱點已解決:

ip6_tunnel:清除 ip6ip6_err() 中的 skb2->cb[] (CVE-2026-74597)

在 Linux 核心中,下列弱點已解決:

ipv6:修正路由資訊選項長度驗證 (CVE-2026-74598)

在 Linux 核心中,下列弱點已解決:

ring-buffer:使用 current_context 進行安全的 per-CPU 緩衝區交換 (CVE-2026-74601)

在 Linux 核心中,下列弱點已解決:

vsock/virtio:避免在拆卸後重新填充 RX 佇列 (CVE-2026-74613)

在 Linux 核心中,下列弱點已解決:

vsock/virtio:讀取背景工作鎖定下的 virtqueues (CVE-2026-74614)

在 Linux 核心中,下列弱點已解決:

vxlan:不要在已關閉的裝置上布防老化計時器 (CVE-2026-74615)

在 Linux 核心中,下列弱點已解決:

xdp:拒絕超出 skb_shared_info tailroom 的複製 (CVE-2026-74616)

在 Linux 核心中,下列弱點已解決:

net/sched:act_gact,act_police:範圍檢查後援控制動作 (CVE-2026-74620)

在 Linux 核心中,下列弱點已解決:

ipv6:防止 in6_dev_get() 復活 inet6_dev (CVE-2026-74630)

在 Linux 核心中,下列弱點已解決:

mm/huge_memory:修正huge_zero_pfn爭用 (CVE-2026-74632)

在 Linux 核心中,下列弱點已解決:

fbdev: bitblit:bit_cursor() 中的界限檢查字形索引 (CVE-2026-74635)

在 Linux 核心中,下列弱點已解決:

跟蹤:修正 update_event_fields 和 event_define_fields (CVE-2026-74636) 之間的爭用

在 Linux 核心中,下列弱點已解決:

perf/core: 修正同級分離後的群組領導者釋放後使用 (CVE-2026-74637)

在 Linux 核心中,下列弱點已解決:

serial: 8250_dma: 關機時清除過時的 RX 狀態 (CVE-2026-74654)

在 Linux 核心中,下列弱點已解決:

ipv4:修正 fib_nhc_update_mtu() 中的釋放後使用 (CVE-2026-74656)

在 Linux 核心中,下列弱點已解決:

ipv4:修正 RTA_VIA nexthop 的 fib_nlmsg_size() (CVE-2026-74657)

在 Linux 核心中,下列弱點已解決:

futex:再防止強大的 futex 退出爭用 (CVE-2026-74658)

在 Linux 核心中,下列弱點已解決:

netfilter: ebt_nflog:釘選 NFLOG 後端 (CVE-2026-74660)

在 Linux 核心中,下列弱點已解決:

inet: frags:在布防計時器之前發布佇列 (CVE-2026-74662)

在 Linux 核心中,下列弱點已解決:

net/sched:拒絕過深的 qdisc 階層 (CVE-2026-74663)

在 Linux 核心中,下列弱點已解決:

net: openvswitch:重新分配不相符 ID 的更新回覆 (CVE-2026-74664)

在 Linux 核心中,下列弱點已解決:

packet:將壓力清除與環形重新配置同步 (CVE-2026-74666)

在 Linux 核心中,下列弱點已解決:

net/packet:重設封包通訊端傳輸路徑上的 MAC 標頭 (CVE-2026-74667)

在 Linux 核心中,下列弱點已解決:

封包:在TX_RING傳送路徑中使用一致的hard_header_len (CVE-2026-74668)

在 Linux 核心中,下列弱點已解決:

ipvs:在重定基底通道後清除 IPv4 選項 ICMP 錯誤 (CVE-2026-74669)

在 Linux 核心中,下列弱點已解決:

輸入:evdev - 修正 evdev_pass_values()CVE-2026-74673 () 中的資訊洩露

在 Linux 核心中,下列弱點已解決:

vt:用 tty_port_tty_get 穩定 kbd_keycode 中的 tty 參照 (CVE-2026-74675)

在 Linux 核心中,下列弱點已解決:

vt:新增 KDSKBMETA ioctl 的權限檢查 (CVE-2026-74676)

在 Linux 核心中,下列弱點已解決:

輸入:evdev - 擷取事件遮罩時清理事件類型索引 (CVE-2026-74683)

在 Linux 核心中,下列弱點已解決:

sctp:如果要移除控制區塊傳輸,則清除它 (CVE-2026-74688)

在 Linux 核心中,下列弱點已解決:

tcp:修正跨 reuseport 移轉的 TFO max_qlen帳戶處理 (CVE-2026-74696)

在 Linux 核心中,下列弱點已解決:

net/openvswitch:檢查 key_extract() 中的乙太網路標頭長度 (CVE-2026-74701)

在 Linux 核心中,下列弱點已解決:

net/sched: sch_cake:丟棄 ACK 過濾器 (CVE-2026-74704) 中格式錯誤的封包的 WARN_ON(1)

在 Linux 核心中,下列弱點已解決:

udp:修正通道分段中潛在的釋放後使用 (CVE-2026-74705)

在 Linux 核心中,下列弱點已解決:

net/mlx5: fw_tracer,在建立錯誤時傳回 NULL (CVE-2026-74717)

在 Linux 核心中,下列弱點已解決:

bpf:保留交換算術的指標狀態 (CVE-2026-74720)

在 Linux 核心中,下列弱點已解決:

bonding: alb:重新檢查 bond_alb_monitor 中 RTNL 下的primary_is_promisc (CVE-2026-74726)

在 Linux 核心中,下列弱點已解決:

NFS:在FREE_STATEID呼叫CVE-2026-74730期間釘選「結構nfs_server」()

在 Linux 核心中,下列弱點已解決:

netfilter: flowtable:最後發布 GC 可見元組 (CVE-2026-74746)

在 Linux 核心中,下列弱點已解決:

netfilter: ipset:修正 list:set GC 和 swap (CVE-2026-74748) 之間的參照計數爭用

在 Linux 核心中,下列弱點已解決:

ceph:修正懸置的 __ceph_get_caps() 與過時mds_wanted (CVE-2026-80527)

在 Linux 核心中,下列弱點已解決:

ceph:使用 current->journal_info (CVE-2026-80528) 時避免 fs 回收

在 Linux 核心中,下列弱點已解決:

xfs:修正 xfs_dq_get_next_id (CVE-2026-80534) 中錯誤時的 ilock 洩漏

在 Linux 核心中,下列弱點已解決:

xfs:邊界檢查緩衝區記錄項目的已變更點陣圖 (CVE-2026-80536)

在 Linux 核心中,下列弱點已解決:

libceph:透過缺少邊界檢查 (CVE-2026-80557) 修正 decode_watchers() 中的 OOB 讀取

在 Linux 核心中,下列弱點已解決:

libceph:避免使用 primary_temp (CVE-2026-80558) 中無效的 osd 索引

在 Linux 核心中,下列弱點已解決:

libceph:修正 decode_locker() 中的多個不安全解碼 (CVE-2026-80561)

在 Linux 核心中,下列弱點已解決:

mptcp: options:在大小意外的情況下重設 DSS 欄位 (CVE-2026-80586)

在 Linux 核心中,下列弱點已解決:

mptcp:避免組合某些傳入的子選項 (CVE-2026-80587)

在 Linux 核心中,下列弱點已解決:

inet: frags:在重組之前從片段中剝離 GSO 狀態 (CVE-2026-80590)

在 Linux 核心中,下列弱點已解決:

vxlan:在 route_shortcircuit() 之後重新擷取 ETH 標頭 (CVE-2026-80681)

在 Linux 核心中,下列弱點已解決:

ipvs:不要將單封包旗標傳播到同步的 conns (CVE-2026-80714)

在 Linux 核心中,下列弱點已解決:

sctp:驗證適應指示參數長度 (CVE-2026-80717)

在 Linux 核心中,下列弱點已解決:

net:移除 dev_validate_header (CVE-2026-80731) 中的CAP_SYS_RAWIO零填充

在 Linux 核心中,下列弱點已解決:

net:從 sk_mc_loop() 中移除 WARN_ON_ONCE()CVE-2026-80733 ()

在 Linux 核心中,下列弱點已解決:

serial: amba-pl011: synchronize DMA teardown (CVE-2026-80737)

在 Linux 核心中,下列弱點已解決:

af_packet:不要在 tpacket_snd() 中傳送零位元組資料。(CVE-2026-80742)

在 Linux 核心中,下列弱點已解決:

netfilter: nf_tables_offload:禁止中止路徑中 ENOMEM 的WARN_ON_ONCE (CVE-2026-80744)

在 Linux 核心中,下列弱點已解決:

selinux:不要取消從未開始的原則轉換 (CVE-2026-80756)

在 Linux 核心中,下列弱點已解決:

selinux:拒絕低於其繼承的 common (CVE-2026-80757) 的類別權限計數

在 Linux 核心中,下列弱點已解決:

HID: hyperv:驗證初始裝置資訊範圍 (C ...

請注意,由於長度原因,描述已被截斷。如需完整說明,請參閱供應商公告。

Tenable 已直接從所測試產品的安全公告擷取前置描述區塊。

請注意,Nessus 並未測試這些問題,而是僅依據應用程式自我報告的版本號碼作出判斷。

解決方案

執行「yum update 核心」或「yum update --advisory ALAS2KERNEL-5.15-2026-116」以更新系統。

另請參閱

https://alas.aws.amazon.com//AL2/ALAS2KERNEL-5.15-2026-116.html

https://alas.aws.amazon.com/faqs.html

https://explore.alas.aws.amazon.com/CVE-2026-52977.html

https://explore.alas.aws.amazon.com/CVE-2026-53089.html

https://explore.alas.aws.amazon.com/CVE-2026-53090.html

https://explore.alas.aws.amazon.com/CVE-2026-64192.html

https://explore.alas.aws.amazon.com/CVE-2026-64294.html

https://explore.alas.aws.amazon.com/CVE-2026-64562.html

https://explore.alas.aws.amazon.com/CVE-2026-64563.html

https://explore.alas.aws.amazon.com/CVE-2026-64564.html

https://explore.alas.aws.amazon.com/CVE-2026-64567.html

https://explore.alas.aws.amazon.com/CVE-2026-64572.html

https://explore.alas.aws.amazon.com/CVE-2026-64576.html

https://explore.alas.aws.amazon.com/CVE-2026-64579.html

https://explore.alas.aws.amazon.com/CVE-2026-64581.html

https://explore.alas.aws.amazon.com/CVE-2026-68082.html

https://explore.alas.aws.amazon.com/CVE-2026-68096.html

https://explore.alas.aws.amazon.com/CVE-2026-68123.html

https://explore.alas.aws.amazon.com/CVE-2026-68127.html

https://explore.alas.aws.amazon.com/CVE-2026-68131.html

https://explore.alas.aws.amazon.com/CVE-2026-68132.html

https://explore.alas.aws.amazon.com/CVE-2026-68138.html

https://explore.alas.aws.amazon.com/CVE-2026-68142.html

https://explore.alas.aws.amazon.com/CVE-2026-68146.html

https://explore.alas.aws.amazon.com/CVE-2026-68153.html

https://explore.alas.aws.amazon.com/CVE-2026-68154.html

https://explore.alas.aws.amazon.com/CVE-2026-68155.html

https://explore.alas.aws.amazon.com/CVE-2026-68156.html

https://explore.alas.aws.amazon.com/CVE-2026-68157.html

https://explore.alas.aws.amazon.com/CVE-2026-68158.html

https://explore.alas.aws.amazon.com/CVE-2026-68159.html

https://explore.alas.aws.amazon.com/CVE-2026-68160.html

https://explore.alas.aws.amazon.com/CVE-2026-68162.html

https://explore.alas.aws.amazon.com/CVE-2026-68184.html

https://explore.alas.aws.amazon.com/CVE-2026-68186.html

https://explore.alas.aws.amazon.com/CVE-2026-68243.html

https://explore.alas.aws.amazon.com/CVE-2026-68244.html

https://explore.alas.aws.amazon.com/CVE-2026-68248.html

https://explore.alas.aws.amazon.com/CVE-2026-68253.html

https://explore.alas.aws.amazon.com/CVE-2026-68254.html

https://explore.alas.aws.amazon.com/CVE-2026-68277.html

https://explore.alas.aws.amazon.com/CVE-2026-68278.html

https://explore.alas.aws.amazon.com/CVE-2026-68279.html

https://explore.alas.aws.amazon.com/CVE-2026-68284.html

https://explore.alas.aws.amazon.com/CVE-2026-68299.html

https://explore.alas.aws.amazon.com/CVE-2026-68300.html

https://explore.alas.aws.amazon.com/CVE-2026-68315.html

https://explore.alas.aws.amazon.com/CVE-2026-68320.html

https://explore.alas.aws.amazon.com/CVE-2026-68322.html

https://explore.alas.aws.amazon.com/CVE-2026-68325.html

https://explore.alas.aws.amazon.com/CVE-2026-68335.html

https://explore.alas.aws.amazon.com/CVE-2026-68338.html

https://explore.alas.aws.amazon.com/CVE-2026-68376.html

https://explore.alas.aws.amazon.com/CVE-2026-68388.html

https://explore.alas.aws.amazon.com/CVE-2026-68422.html

https://explore.alas.aws.amazon.com/CVE-2026-68425.html

https://explore.alas.aws.amazon.com/CVE-2026-68428.html

https://explore.alas.aws.amazon.com/CVE-2026-68432.html

https://explore.alas.aws.amazon.com/CVE-2026-68433.html

https://explore.alas.aws.amazon.com/CVE-2026-68450.html

https://explore.alas.aws.amazon.com/CVE-2026-68476.html

https://explore.alas.aws.amazon.com/CVE-2026-72051.html

https://explore.alas.aws.amazon.com/CVE-2026-72053.html

https://explore.alas.aws.amazon.com/CVE-2026-72099.html

https://explore.alas.aws.amazon.com/CVE-2026-72110.html

https://explore.alas.aws.amazon.com/CVE-2026-72113.html

https://explore.alas.aws.amazon.com/CVE-2026-72114.html

https://explore.alas.aws.amazon.com/CVE-2026-72115.html

https://explore.alas.aws.amazon.com/CVE-2026-72116.html

https://explore.alas.aws.amazon.com/CVE-2026-72117.html

https://explore.alas.aws.amazon.com/CVE-2026-72118.html

https://explore.alas.aws.amazon.com/CVE-2026-72119.html

https://explore.alas.aws.amazon.com/CVE-2026-72121.html

https://explore.alas.aws.amazon.com/CVE-2026-72123.html

https://explore.alas.aws.amazon.com/CVE-2026-72191.html

https://explore.alas.aws.amazon.com/CVE-2026-72242.html

https://explore.alas.aws.amazon.com/CVE-2026-72252.html

https://explore.alas.aws.amazon.com/CVE-2026-72253.html

https://explore.alas.aws.amazon.com/CVE-2026-72255.html

https://explore.alas.aws.amazon.com/CVE-2026-72323.html

https://explore.alas.aws.amazon.com/CVE-2026-74464.html

https://explore.alas.aws.amazon.com/CVE-2026-74465.html

https://explore.alas.aws.amazon.com/CVE-2026-74469.html

https://explore.alas.aws.amazon.com/CVE-2026-74471.html

https://explore.alas.aws.amazon.com/CVE-2026-74473.html

https://explore.alas.aws.amazon.com/CVE-2026-74475.html

https://explore.alas.aws.amazon.com/CVE-2026-74480.html

https://explore.alas.aws.amazon.com/CVE-2026-74481.html

https://explore.alas.aws.amazon.com/CVE-2026-74482.html

https://explore.alas.aws.amazon.com/CVE-2026-74485.html

https://explore.alas.aws.amazon.com/CVE-2026-74487.html

https://explore.alas.aws.amazon.com/CVE-2026-74492.html

https://explore.alas.aws.amazon.com/CVE-2026-74512.html

https://explore.alas.aws.amazon.com/CVE-2026-74518.html

https://explore.alas.aws.amazon.com/CVE-2026-74519.html

https://explore.alas.aws.amazon.com/CVE-2026-74556.html

https://explore.alas.aws.amazon.com/CVE-2026-74557.html

https://explore.alas.aws.amazon.com/CVE-2026-74563.html

https://explore.alas.aws.amazon.com/CVE-2026-74564.html

https://explore.alas.aws.amazon.com/CVE-2026-74566.html

https://explore.alas.aws.amazon.com/CVE-2026-74567.html

https://explore.alas.aws.amazon.com/CVE-2026-74569.html

https://explore.alas.aws.amazon.com/CVE-2026-74577.html

https://explore.alas.aws.amazon.com/CVE-2026-74579.html

https://explore.alas.aws.amazon.com/CVE-2026-74581.html

https://explore.alas.aws.amazon.com/CVE-2026-74582.html

https://explore.alas.aws.amazon.com/CVE-2026-74583.html

https://explore.alas.aws.amazon.com/CVE-2026-74586.html

https://explore.alas.aws.amazon.com/CVE-2026-74587.html

https://explore.alas.aws.amazon.com/CVE-2026-74588.html

https://explore.alas.aws.amazon.com/CVE-2026-74589.html

https://explore.alas.aws.amazon.com/CVE-2026-74594.html

https://explore.alas.aws.amazon.com/CVE-2026-74597.html

https://explore.alas.aws.amazon.com/CVE-2026-74598.html

https://explore.alas.aws.amazon.com/CVE-2026-74601.html

https://explore.alas.aws.amazon.com/CVE-2026-74613.html

https://explore.alas.aws.amazon.com/CVE-2026-74614.html

https://explore.alas.aws.amazon.com/CVE-2026-74615.html

https://explore.alas.aws.amazon.com/CVE-2026-74616.html

https://explore.alas.aws.amazon.com/CVE-2026-74620.html

https://explore.alas.aws.amazon.com/CVE-2026-74630.html

https://explore.alas.aws.amazon.com/CVE-2026-74632.html

https://explore.alas.aws.amazon.com/CVE-2026-74635.html

https://explore.alas.aws.amazon.com/CVE-2026-74636.html

https://explore.alas.aws.amazon.com/CVE-2026-74637.html

https://explore.alas.aws.amazon.com/CVE-2026-74654.html

https://explore.alas.aws.amazon.com/CVE-2026-74656.html

https://explore.alas.aws.amazon.com/CVE-2026-74657.html

https://explore.alas.aws.amazon.com/CVE-2026-74658.html

https://explore.alas.aws.amazon.com/CVE-2026-74660.html

https://explore.alas.aws.amazon.com/CVE-2026-74662.html

https://explore.alas.aws.amazon.com/CVE-2026-74663.html

https://explore.alas.aws.amazon.com/CVE-2026-74664.html

https://explore.alas.aws.amazon.com/CVE-2026-74666.html

https://explore.alas.aws.amazon.com/CVE-2026-74667.html

https://explore.alas.aws.amazon.com/CVE-2026-74668.html

https://explore.alas.aws.amazon.com/CVE-2026-74669.html

https://explore.alas.aws.amazon.com/CVE-2026-74673.html

https://explore.alas.aws.amazon.com/CVE-2026-74675.html

https://explore.alas.aws.amazon.com/CVE-2026-74676.html

https://explore.alas.aws.amazon.com/CVE-2026-74683.html

https://explore.alas.aws.amazon.com/CVE-2026-74688.html

https://explore.alas.aws.amazon.com/CVE-2026-74696.html

https://explore.alas.aws.amazon.com/CVE-2026-74701.html

https://explore.alas.aws.amazon.com/CVE-2026-74704.html

https://explore.alas.aws.amazon.com/CVE-2026-74705.html

https://explore.alas.aws.amazon.com/CVE-2026-74717.html

https://explore.alas.aws.amazon.com/CVE-2026-74720.html

https://explore.alas.aws.amazon.com/CVE-2026-74726.html

https://explore.alas.aws.amazon.com/CVE-2026-74730.html

https://explore.alas.aws.amazon.com/CVE-2026-74746.html

https://explore.alas.aws.amazon.com/CVE-2026-74748.html

https://explore.alas.aws.amazon.com/CVE-2026-80527.html

https://explore.alas.aws.amazon.com/CVE-2026-80528.html

https://explore.alas.aws.amazon.com/CVE-2026-80534.html

https://explore.alas.aws.amazon.com/CVE-2026-80536.html

https://explore.alas.aws.amazon.com/CVE-2026-80557.html

https://explore.alas.aws.amazon.com/CVE-2026-80558.html

https://explore.alas.aws.amazon.com/CVE-2026-80561.html

https://explore.alas.aws.amazon.com/CVE-2026-80586.html

https://explore.alas.aws.amazon.com/CVE-2026-80587.html

https://explore.alas.aws.amazon.com/CVE-2026-80590.html

https://explore.alas.aws.amazon.com/CVE-2026-80681.html

https://explore.alas.aws.amazon.com/CVE-2026-80714.html

https://explore.alas.aws.amazon.com/CVE-2026-80717.html

https://explore.alas.aws.amazon.com/CVE-2026-80731.html

https://explore.alas.aws.amazon.com/CVE-2026-80733.html

https://explore.alas.aws.amazon.com/CVE-2026-80737.html

https://explore.alas.aws.amazon.com/CVE-2026-80742.html

https://explore.alas.aws.amazon.com/CVE-2026-80744.html

https://explore.alas.aws.amazon.com/CVE-2026-80756.html

https://explore.alas.aws.amazon.com/CVE-2026-80757.html

https://explore.alas.aws.amazon.com/CVE-2026-80765.html

https://explore.alas.aws.amazon.com/CVE-2026-80781.html

https://explore.alas.aws.amazon.com/CVE-2026-80792.html

https://explore.alas.aws.amazon.com/CVE-2026-80793.html

https://explore.alas.aws.amazon.com/CVE-2026-80805.html

https://explore.alas.aws.amazon.com/CVE-2026-80806.html

https://explore.alas.aws.amazon.com/CVE-2026-80808.html

https://explore.alas.aws.amazon.com/CVE-2026-80824.html

https://explore.alas.aws.amazon.com/CVE-2026-80830.html

https://explore.alas.aws.amazon.com/CVE-2026-80840.html

https://explore.alas.aws.amazon.com/CVE-2026-80842.html

https://explore.alas.aws.amazon.com/CVE-2026-80843.html

https://explore.alas.aws.amazon.com/CVE-2026-80844.html

https://explore.alas.aws.amazon.com/CVE-2026-80855.html

https://explore.alas.aws.amazon.com/CVE-2026-80856.html

https://explore.alas.aws.amazon.com/CVE-2026-80890.html

https://explore.alas.aws.amazon.com/CVE-2026-80906.html

https://explore.alas.aws.amazon.com/CVE-2026-80913.html

https://explore.alas.aws.amazon.com/CVE-2026-80917.html

https://explore.alas.aws.amazon.com/CVE-2026-80918.html

Plugin 詳細資訊

嚴重性: High

ID: 351051

檔案名稱: al2_ALASKERNEL-5_15-2026-116.nasl

版本: 1.1

類型: Local

代理程式: unix

已發布: 2026/9/29

已更新: 2026/9/29

支援的感應器: Frictionless Assessment AWS, Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Continuous Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

風險資訊

VPR

風險因素: High

分數: 7.9

百分位數: 99.36

CVSS v2

風險因素: Medium

基本分數: 6.8

時間性分數: 5.3

媒介: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS 評分資料來源: CVE-2026-53089

CVSS v3

風險因素: High

基本分數: 7.8

時間性分數: 7

媒介: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

時間媒介: CVSS:3.0/E:P/RL:O/RC:C

弱點資訊

CPE: cpe:/o:amazon:linux:2, p-cpe:/a:amazon:linux:bpftool-debuginfo, p-cpe:/a:amazon:linux:bpftool, p-cpe:/a:amazon:linux:kernel-debuginfo-common-aarch64, p-cpe:/a:amazon:linux:kernel-debuginfo-common-x86_64, p-cpe:/a:amazon:linux:kernel-debuginfo, p-cpe:/a:amazon:linux:kernel-devel, p-cpe:/a:amazon:linux:kernel-headers, p-cpe:/a:amazon:linux:kernel-livepatch-5.15.220-153.252, p-cpe:/a:amazon:linux:kernel-tools-debuginfo, p-cpe:/a:amazon:linux:kernel-tools-devel, p-cpe:/a:amazon:linux:kernel-tools, p-cpe:/a:amazon:linux:kernel, p-cpe:/a:amazon:linux:perf-debuginfo, p-cpe:/a:amazon:linux:perf, p-cpe:/a:amazon:linux:python-perf-debuginfo, p-cpe:/a:amazon:linux:python-perf

必要的 KB 項目: Host/local_checks_enabled, Host/AmazonLinux/release, Host/AmazonLinux/rpm-list

可被惡意程式利用: true

可輕鬆利用: Exploits are available

修補程式發佈日期: 2026/9/28

弱點發布日期: 2025/4/29

參考資訊

CVE: CVE-2026-52977, CVE-2026-53089, CVE-2026-53090, CVE-2026-64192, CVE-2026-64294, CVE-2026-64562, CVE-2026-64563, CVE-2026-64564, CVE-2026-64567, CVE-2026-64572, CVE-2026-64576, CVE-2026-64579, CVE-2026-64581, CVE-2026-68082, CVE-2026-68096, CVE-2026-68123, CVE-2026-68127, CVE-2026-68131, CVE-2026-68132, CVE-2026-68138, CVE-2026-68142, CVE-2026-68146, CVE-2026-68153, CVE-2026-68154, CVE-2026-68155, CVE-2026-68156, CVE-2026-68157, CVE-2026-68158, CVE-2026-68159, CVE-2026-68160, CVE-2026-68162, CVE-2026-68184, CVE-2026-68186, CVE-2026-68243, CVE-2026-68244, CVE-2026-68248, CVE-2026-68253, CVE-2026-68254, CVE-2026-68277, CVE-2026-68278, CVE-2026-68279, CVE-2026-68284, CVE-2026-68299, CVE-2026-68300, CVE-2026-68315, CVE-2026-68320, CVE-2026-68322, CVE-2026-68325, CVE-2026-68335, CVE-2026-68338, CVE-2026-68376, CVE-2026-68388, CVE-2026-68422, CVE-2026-68425, CVE-2026-68428, CVE-2026-68432, CVE-2026-68433, CVE-2026-68450, CVE-2026-68476, CVE-2026-72051, CVE-2026-72053, CVE-2026-72099, CVE-2026-72110, CVE-2026-72113, CVE-2026-72114, CVE-2026-72115, CVE-2026-72116, CVE-2026-72117, CVE-2026-72118, CVE-2026-72119, CVE-2026-72121, CVE-2026-72123, CVE-2026-72191, CVE-2026-72242, CVE-2026-72252, CVE-2026-72253, CVE-2026-72255, CVE-2026-72323, CVE-2026-74464, CVE-2026-74465, CVE-2026-74469, CVE-2026-74471, CVE-2026-74473, CVE-2026-74475, CVE-2026-74480, CVE-2026-74481, CVE-2026-74482, CVE-2026-74485, CVE-2026-74487, CVE-2026-74492, CVE-2026-74512, CVE-2026-74518, CVE-2026-74519, CVE-2026-74556, CVE-2026-74557, CVE-2026-74563, CVE-2026-74564, CVE-2026-74566, CVE-2026-74567, CVE-2026-74569, CVE-2026-74577, CVE-2026-74579, CVE-2026-74581, CVE-2026-74582, CVE-2026-74583, CVE-2026-74586, CVE-2026-74587, CVE-2026-74588, CVE-2026-74589, CVE-2026-74594, CVE-2026-74597, CVE-2026-74598, CVE-2026-74601, CVE-2026-74613, CVE-2026-74614, CVE-2026-74615, CVE-2026-74616, CVE-2026-74620, CVE-2026-74630, CVE-2026-74632, CVE-2026-74635, CVE-2026-74636, CVE-2026-74637, CVE-2026-74654, CVE-2026-74656, CVE-2026-74657, CVE-2026-74658, CVE-2026-74660, CVE-2026-74662, CVE-2026-74663, CVE-2026-74664, CVE-2026-74666, CVE-2026-74667, CVE-2026-74668, CVE-2026-74669, CVE-2026-74673, CVE-2026-74675, CVE-2026-74676, CVE-2026-74683, CVE-2026-74688, CVE-2026-74696, CVE-2026-74701, CVE-2026-74704, CVE-2026-74705, CVE-2026-74717, CVE-2026-74720, CVE-2026-74726, CVE-2026-74730, CVE-2026-74746, CVE-2026-74748, CVE-2026-80527, CVE-2026-80528, CVE-2026-80534, CVE-2026-80536, CVE-2026-80557, CVE-2026-80558, CVE-2026-80561, CVE-2026-80586, CVE-2026-80587, CVE-2026-80590, CVE-2026-80681, CVE-2026-80714, CVE-2026-80717, CVE-2026-80731, CVE-2026-80733, CVE-2026-80737, CVE-2026-80742, CVE-2026-80744, CVE-2026-80756, CVE-2026-80757, CVE-2026-80765, CVE-2026-80781, CVE-2026-80792, CVE-2026-80793, CVE-2026-80805, CVE-2026-80806, CVE-2026-80808, CVE-2026-80824, CVE-2026-80830, CVE-2026-80840, CVE-2026-80842, CVE-2026-80843, CVE-2026-80844, CVE-2026-80855, CVE-2026-80856, CVE-2026-80890, CVE-2026-80906, CVE-2026-80913, CVE-2026-80917, CVE-2026-80918