Amazon Linux 2:kernel (ALASKERNEL-5.10-2026-132)

medium Nessus Plugin ID 351061

概要

遠端 Amazon Linux 2 主機缺少安全性更新。

說明

遠端主機上安裝的核心版本早於 5.10.268-266.1092。因此,會受到 ALAS2KERNEL-5.10-2026-132 公告中所提及的多個弱點影響。

在 Linux 核心中,下列弱點已解決:

drm/virtio:對平面更新使用不中斷的 resv 鎖定 (CVE-2026-64098)

在 Linux 核心中,下列弱點已解決:

bpf:如果 BPF LSM 未初始化,則拒絕BPF_MAP_TYPE_INODE_STORAGE建立

當設定 CONFIG_BPF_LSM=y 時,BPF inode 儲存體映射 (BPF_MAP_TYPE_INODE_STORAGE) 會編譯到核心中。但是,如果在啟動時未明確啟用 BPF LSM(例如,從 lsm= 啟動參數中省略),則永遠不會針對 BPF LSM 執行 lsm_prepare()。

因此,BPF inode 安全性 blob 位移 (bpf_lsm_blob_sizes.lbs_inode) 永遠不會初始化,並保持其預設編譯大小 8 位元組,而不是更新為超過保留結構rcu_head的有效位移 (通常為 16 位元組或更多)。

當特權使用者建立並更新BPF_MAP_TYPE_INODE_STORAGEmap時,bpf_inode() 會評估 inode->i_security + 8。這會錯誤地將 inode >i_security blob 開頭的結構 rcu_head.func 回呼指標別名。在後續的對應元素清除或 inode 損毀期間,將 NULL 寫入 owner_storage 會清除 queuedRCU 回呼指標。當 rcu_do_batch() 稍後執行佇列回呼時,它會嘗試在位址0x0處擷取指令,從而觸發立即核心錯誤。

透過引入標有 __ro_after_init 的全域 bpf_lsm_initialized 布林標記來解決此問題。當 LSM 架構成功註冊 BPF LSM 時,在 bpf_lsm_init() 內將此標誌設定為 true。在此標誌的 inode_storage_map_alloc() 中進行閘對應分配,如果 BPF LSM 反過來未初始化,則返回 EOPNOTSUPP。

這種故障快速方法可防止使用者空間在支援的 BPF LSM 基礎架構缺失時配置 inode 儲存映射,從而避免殭屍映射狀態。(CVE-2026-64192)

在 Linux 核心中,下列弱點已解決:

i2c: core:修正轉接器取消註冊爭用 (CVE-2026-64279)

在 Linux 核心中,下列弱點已解決:

libceph:修正 decode_lockers()CVE-2026-68082 () 中兩個不安全的裸解碼

在 Linux 核心中,下列弱點已解決:

audit:修正 audit_dupe_exe() 中的遞迴鎖定鎖死 (CVE-2026-68096)

在 Linux 核心中,下列弱點已解決:

super:修正凍結區塊裝置上的緊急解凍鎖死 (CVE-2026-68132)

在 Linux 核心中,下列弱點已解決:

net: gro:修正齊清標記的 skb 的雙重彙總 (CVE-2026-68136)

在 Linux 核心中,下列弱點已解決:

ftrace:新增全域互斥以序列化 trace_parser 存取 (CVE-2026-68146)

在 Linux 核心中,下列弱點已解決:

libceph:將 pg_{temp,upmap,upmap_items} 長度綁定為 CEPH_PG_MAX_SIZE (CVE-2026-68159)

在 Linux 核心中,下列弱點已解決:

sctp:避免在 netns 拆卸期間auth_enable sysctl UAF (CVE-2026-68162)

在 Linux 核心中,下列弱點已解決:

drm/virtio:繫結的 EDID 區塊讀取到回應緩衝區 (CVE-2026-68255)

在 Linux 核心中,下列弱點已解決:

drm/dp/mst:修正邊帶回覆剖析器 (CVE-2026-68277) 中 2 位元組欄位的 OOB 讀取

在 Linux 核心中,下列弱點已解決:

drm/dp/mst:修正邊帶區塊累積中的緩衝區溢位 (CVE-2026-68278)

在 Linux 核心中,下列弱點已解決:

drm/dp/mst:修正遠端 DPCD/I2C 邊帶回覆剖析器中的 OOB 讀取 (CVE-2026-68279)

在 Linux 核心中,下列弱點已解決:

mmc:vub300:修正探查失敗時的釋放後使用 (CVE-2026-72073)

在 Linux 核心中,下列弱點已解決:

scsi: target:繫結的 PR-OUT TransportID 剖析至接收的緩衝區 (CVE-2026-72084)

在 Linux 核心中,下列弱點已解決:

scsi:lpfc:修正 lpfc_sli4_driver_resource_setup()CVE-2026-72087 () 中的記憶體洩漏

在 Linux 核心中,下列弱點已解決:

dm-verity:使錯誤計數器不可部分完成 (CVE-2026-72096)

在 Linux 核心中,下列弱點已解決:

dm-integrity:不要將 hash_offset 遞增兩次 (CVE-2026-72099)

在 Linux 核心中,下列弱點已解決:

jbd2:修正 jbd2_journal_initialize_fast_commit() 中的整數反向溢位 (CVE-2026-72225)

在 Linux 核心中,下列弱點已解決:

selinux:避免 selinux_sctp_bind_connect() 中的sk_socket取消參照 (CVE-2026-72242)

在 Linux 核心中,下列弱點已解決:

netfilter: nft_set_pipapo:不要將錯誤的複製洩漏到未來的事務中 (CVE-2026-72252)

在 Linux 核心中,下列弱點已解決:

netfilter: nf_conntrack_sip:在存取 skb_dst() 之前先驗證它 (CVE-2026-72253)

在 Linux 核心中,下列弱點已解決:

netfilter: nf_queue:當 NFQUEUE 持有假 dst () 時,pin 橋接裝置 (CVE-2026-72255)

在 Linux 核心中,下列弱點已解決:

KVM:arm64:vgic:處理中斷關聯性變更與停用 LPI 之間的爭用 (CVE-2026-72288)

在 Linux 核心中,下列弱點已解決:

TIPC:限制佇列追蹤點中的通訊端佇列傾出 (CVE-2026-72299)

在 Linux 核心中,下列弱點已解決:

mlxsw:修正 mlxsw_sp_port_lag_join()CVE-2026-72308 () 中的參照計數洩漏

在 Linux 核心中,下列弱點已解決:

sctp:在 cookie 解壓縮後新增 INIT 驗證 (CVE-2026-72398)

在 Linux 核心中,下列弱點已解決:

sctp:修正 INIT 處理中的 err_chunk 記憶體洩漏 (CVE-2026-72413)

在 Linux 核心中,下列弱點已解決:

netfilter: nft_compat:ebtables 模擬必須拒絕非橋接目標 (CVE-2026-72416)

在 Linux 核心中,下列弱點已解決:

xprtrdma:重新張貼格式錯誤回覆的接收緩衝區 (CVE-2026-72464)

在 Linux 核心中,下列弱點已解決:

RDMA/rxe:修正 get_srq_wqe 中的 TOCTOU 堆積溢位 (CVE-2026-74378)

在 Linux 核心中,下列弱點已解決:

OPP:修正 OPP 新增和查詢 () 之間的爭用 (CVE-2026-74405)

在 Linux 核心中,下列弱點已解決:

scsi: scsi_debug:修正 REPORT ZONES alloc_len下溢 OOB 寫入 (CVE-2026-74470)

在 Linux 核心中,下列弱點已解決:

net: pktgen:修正 proc 項目釋放後使用 (CVE-2026-74479)

在 Linux 核心中,下列弱點已解決:

binfmt_misc:移除項目時還原寫入存取權 (CVE-2026-74487)

在 Linux 核心中,下列弱點已解決:

netfilter: nf_tables:使每個表nft_object rhltable (CVE-2026-74565)

在 Linux 核心中,下列弱點已解決:

封包:在非環形傳送路徑中使用一致的hard_header_len (CVE-2026-74582)

在 Linux 核心中,下列弱點已解決:

sched/psi:關閉 psi_cgroup_free() 中的 rtpoll_timer (CVE-2026-74594)

在 Linux 核心中,下列弱點已解決:

ring-buffer:使用 current_context 進行安全的 per-CPU 緩衝區交換 (CVE-2026-74601)

在 Linux 核心中,下列弱點已解決:

net/sched:act_gact,act_police:範圍檢查後援控制動作 (CVE-2026-74620)

在 Linux 核心中,下列弱點已解決:

mm/huge_memory:修正huge_zero_pfn爭用 (CVE-2026-74632)

在 Linux 核心中,下列弱點已解決:

perf/core: 修正同級分離後的群組領導者釋放後使用 (CVE-2026-74637)

在 Linux 核心中,下列弱點已解決:

ipv4:修正 RTA_VIA nexthop 的 fib_nlmsg_size() (CVE-2026-74657)

在 Linux 核心中,下列弱點已解決:

inet: frags:在布防計時器之前發布佇列 (CVE-2026-74662)

在 Linux 核心中,下列弱點已解決:

net/sched:拒絕過深的 qdisc 階層 (CVE-2026-74663)

在 Linux 核心中,下列弱點已解決:

packet:將壓力清除與環形重新配置同步 (CVE-2026-74666)

在 Linux 核心中,下列弱點已解決:

封包:在TX_RING傳送路徑中使用一致的hard_header_len (CVE-2026-74668)

在 Linux 核心中,下列弱點已解決:

net: tap:在剖析 tap_get_user_xdp() 中的 virtio net 標頭之前設定 skb->dev (CVE-2026-74684)

在 Linux 核心中,下列弱點已解決:

net/sched: cls_api:破壞鎖定的分類器時,一律獲取 rtnl_lock (CVE-2026-74700)

在 Linux 核心中,下列弱點已解決:

netfilter: flowtable:最後發布 GC 可見元組 (CVE-2026-74746)

在 Linux 核心中,下列弱點已解決:

netfilter: ipset:修正 list:set GC 和 swap (CVE-2026-74748) 之間的參照計數爭用

在 Linux 核心中,下列弱點已解決:

ceph:修正懸置的 __ceph_get_caps() 與過時mds_wanted (CVE-2026-80527)

在 Linux 核心中,下列弱點已解決:

ceph:使用 current->journal_info (CVE-2026-80528) 時避免 fs 回收

在 Linux 核心中,下列弱點已解決:

xfs:修正 xfs_dq_get_next_id (CVE-2026-80534) 中錯誤時的 ilock 洩漏

在 Linux 核心中,下列弱點已解決:

xfs:邊界檢查緩衝區記錄項目的已變更點陣圖 (CVE-2026-80536)

在 Linux 核心中,下列弱點已解決:

libceph:透過缺少邊界檢查 (CVE-2026-80557) 修正 decode_watchers() 中的 OOB 讀取

在 Linux 核心中,下列弱點已解決:

libceph:避免使用 primary_temp (CVE-2026-80558) 中無效的 osd 索引

在 Linux 核心中,下列弱點已解決:

libceph:修正 decode_locker() 中的多個不安全解碼 (CVE-2026-80561)

在 Linux 核心中,下列弱點已解決:

mptcp: options:在大小意外的情況下重設 DSS 欄位 (CVE-2026-80586)

在 Linux 核心中,下列弱點已解決:

inet: frags:在重組之前從片段中剝離 GSO 狀態 (CVE-2026-80590)

在 Linux 核心中,下列弱點已解決:

serial: amba-pl011: synchronize DMA teardown (CVE-2026-80737)

在 Linux 核心中,下列弱點已解決:

af_packet:不要在 tpacket_snd() 中傳送零位元組資料。(CVE-2026-80742)

在 Linux 核心中,下列弱點已解決:

netfilter: nf_tables_offload:禁止中止路徑中 ENOMEM 的WARN_ON_ONCE (CVE-2026-80744)

在 Linux 核心中,下列弱點已解決:

selinux:不要取消從未開始的原則轉換 (CVE-2026-80756)

在 Linux 核心中,下列弱點已解決:

selinux:拒絕低於其繼承的 common (CVE-2026-80757) 的類別權限計數

在 Linux 核心中,下列弱點已解決:

HID: hyperv:驗證初始裝置資訊邊界 (CVE-2026-80765)

在 Linux 核心中,下列弱點已解決:

HID: core:修正 hid_set_field() 中 field->usage 的 OOB 讀取 (CVE-2026-80781)

在 Linux 核心中,下列弱點已解決:

ipv6:修正 ip6_finish_output2() 中的釋放後使用 (CVE-2026-80792)

在 Linux 核心中,下列弱點已解決:

ipv4:拒絕 ip_do_fragment() 中大小過小的 MTU (CVE-2026-80793)

在 Linux 核心中,下列弱點已解決:

xfs:在欄位存取之前驗證 ATTR 進入指標 (CVE-2026-80805)

在 Linux 核心中,下列弱點已解決:

ext4:停止重試飽和的 xattr 快取項目 (CVE-2026-80808)

在 Linux 核心中,下列弱點已解決:

rndis_host:在 rndis_rx_fixup() 中新增溢位檢查 (CVE-2026-80814)

在 Linux 核心中,下列弱點已解決:

net: packet:修正傳送 VLAN 標記框架時的錯誤transport_header (CVE-2026-80906)

在 Linux 核心中,下列弱點已解決:

selinux:要求定義每個布林值 (CVE-2026-80913)

在 Linux 核心中,下列弱點已解決:

HID: core:修正長項目上的數字/指標類型混淆 (CVE-2026-80918)

Tenable 已直接從所測試產品的安全公告擷取前置描述區塊。

請注意,Nessus 並未測試這些問題,而是僅依據應用程式自我報告的版本號碼作出判斷。

解決方案

執行「yum update 核心」或「yum update --advisory ALAS2KERNEL-5.10-2026-132」以更新系統。

另請參閱

https://alas.aws.amazon.com//AL2/ALAS2KERNEL-5.10-2026-132.html

https://alas.aws.amazon.com/faqs.html

https://explore.alas.aws.amazon.com/CVE-2026-64098.html

https://explore.alas.aws.amazon.com/CVE-2026-64192.html

https://explore.alas.aws.amazon.com/CVE-2026-64279.html

https://explore.alas.aws.amazon.com/CVE-2026-68082.html

https://explore.alas.aws.amazon.com/CVE-2026-68096.html

https://explore.alas.aws.amazon.com/CVE-2026-68132.html

https://explore.alas.aws.amazon.com/CVE-2026-68136.html

https://explore.alas.aws.amazon.com/CVE-2026-68146.html

https://explore.alas.aws.amazon.com/CVE-2026-68159.html

https://explore.alas.aws.amazon.com/CVE-2026-68162.html

https://explore.alas.aws.amazon.com/CVE-2026-68255.html

https://explore.alas.aws.amazon.com/CVE-2026-68277.html

https://explore.alas.aws.amazon.com/CVE-2026-68278.html

https://explore.alas.aws.amazon.com/CVE-2026-68279.html

https://explore.alas.aws.amazon.com/CVE-2026-72073.html

https://explore.alas.aws.amazon.com/CVE-2026-72084.html

https://explore.alas.aws.amazon.com/CVE-2026-72087.html

https://explore.alas.aws.amazon.com/CVE-2026-72096.html

https://explore.alas.aws.amazon.com/CVE-2026-72099.html

https://explore.alas.aws.amazon.com/CVE-2026-72225.html

https://explore.alas.aws.amazon.com/CVE-2026-72242.html

https://explore.alas.aws.amazon.com/CVE-2026-72252.html

https://explore.alas.aws.amazon.com/CVE-2026-72253.html

https://explore.alas.aws.amazon.com/CVE-2026-72255.html

https://explore.alas.aws.amazon.com/CVE-2026-72288.html

https://explore.alas.aws.amazon.com/CVE-2026-72299.html

https://explore.alas.aws.amazon.com/CVE-2026-72308.html

https://explore.alas.aws.amazon.com/CVE-2026-72398.html

https://explore.alas.aws.amazon.com/CVE-2026-72413.html

https://explore.alas.aws.amazon.com/CVE-2026-72416.html

https://explore.alas.aws.amazon.com/CVE-2026-72464.html

https://explore.alas.aws.amazon.com/CVE-2026-74378.html

https://explore.alas.aws.amazon.com/CVE-2026-74405.html

https://explore.alas.aws.amazon.com/CVE-2026-74470.html

https://explore.alas.aws.amazon.com/CVE-2026-74479.html

https://explore.alas.aws.amazon.com/CVE-2026-74487.html

https://explore.alas.aws.amazon.com/CVE-2026-74565.html

https://explore.alas.aws.amazon.com/CVE-2026-74582.html

https://explore.alas.aws.amazon.com/CVE-2026-74594.html

https://explore.alas.aws.amazon.com/CVE-2026-74601.html

https://explore.alas.aws.amazon.com/CVE-2026-74620.html

https://explore.alas.aws.amazon.com/CVE-2026-74632.html

https://explore.alas.aws.amazon.com/CVE-2026-74637.html

https://explore.alas.aws.amazon.com/CVE-2026-74657.html

https://explore.alas.aws.amazon.com/CVE-2026-74662.html

https://explore.alas.aws.amazon.com/CVE-2026-74663.html

https://explore.alas.aws.amazon.com/CVE-2026-74666.html

https://explore.alas.aws.amazon.com/CVE-2026-74668.html

https://explore.alas.aws.amazon.com/CVE-2026-74684.html

https://explore.alas.aws.amazon.com/CVE-2026-74700.html

https://explore.alas.aws.amazon.com/CVE-2026-74746.html

https://explore.alas.aws.amazon.com/CVE-2026-74748.html

https://explore.alas.aws.amazon.com/CVE-2026-80527.html

https://explore.alas.aws.amazon.com/CVE-2026-80528.html

https://explore.alas.aws.amazon.com/CVE-2026-80534.html

https://explore.alas.aws.amazon.com/CVE-2026-80536.html

https://explore.alas.aws.amazon.com/CVE-2026-80557.html

https://explore.alas.aws.amazon.com/CVE-2026-80558.html

https://explore.alas.aws.amazon.com/CVE-2026-80561.html

https://explore.alas.aws.amazon.com/CVE-2026-80586.html

https://explore.alas.aws.amazon.com/CVE-2026-80590.html

https://explore.alas.aws.amazon.com/CVE-2026-80737.html

https://explore.alas.aws.amazon.com/CVE-2026-80742.html

https://explore.alas.aws.amazon.com/CVE-2026-80744.html

https://explore.alas.aws.amazon.com/CVE-2026-80756.html

https://explore.alas.aws.amazon.com/CVE-2026-80757.html

https://explore.alas.aws.amazon.com/CVE-2026-80765.html

https://explore.alas.aws.amazon.com/CVE-2026-80781.html

https://explore.alas.aws.amazon.com/CVE-2026-80792.html

https://explore.alas.aws.amazon.com/CVE-2026-80793.html

https://explore.alas.aws.amazon.com/CVE-2026-80805.html

https://explore.alas.aws.amazon.com/CVE-2026-80808.html

https://explore.alas.aws.amazon.com/CVE-2026-80814.html

https://explore.alas.aws.amazon.com/CVE-2026-80906.html

https://explore.alas.aws.amazon.com/CVE-2026-80913.html

https://explore.alas.aws.amazon.com/CVE-2026-80918.html

Plugin 詳細資訊

嚴重性: Medium

ID: 351061

檔案名稱: al2_ALASKERNEL-5_10-2026-132.nasl

版本: 1.1

類型: Local

代理程式: unix

已發布: 2026/9/29

已更新: 2026/9/29

支援的感應器: Frictionless Assessment AWS, Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Continuous Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

風險資訊

VPR

風險因素: High

分數: 7.6

百分位數: 98.3

CVSS v2

風險因素: Medium

基本分數: 4.6

時間性分數: 3.4

媒介: CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:C

CVSS 評分資料來源: CVE-2026-64192

CVSS v3

風險因素: Medium

基本分數: 5.5

時間性分數: 4.8

媒介: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

時間媒介: CVSS:3.0/E:U/RL:O/RC:C

弱點資訊

CPE: cpe:/o:amazon:linux:2, p-cpe:/a:amazon:linux:bpftool-debuginfo, p-cpe:/a:amazon:linux:bpftool, p-cpe:/a:amazon:linux:kernel-debuginfo-common-aarch64, p-cpe:/a:amazon:linux:kernel-debuginfo-common-x86_64, p-cpe:/a:amazon:linux:kernel-debuginfo, p-cpe:/a:amazon:linux:kernel-devel, p-cpe:/a:amazon:linux:kernel-headers, p-cpe:/a:amazon:linux:kernel-livepatch-5.10.268-266.1092, p-cpe:/a:amazon:linux:kernel-tools-debuginfo, p-cpe:/a:amazon:linux:kernel-tools-devel, p-cpe:/a:amazon:linux:kernel-tools, p-cpe:/a:amazon:linux:kernel, p-cpe:/a:amazon:linux:perf-debuginfo, p-cpe:/a:amazon:linux:perf, p-cpe:/a:amazon:linux:python-perf-debuginfo, p-cpe:/a:amazon:linux:python-perf

必要的 KB 項目: Host/local_checks_enabled, Host/AmazonLinux/release, Host/AmazonLinux/rpm-list

可輕鬆利用: No known exploits are available

修補程式發佈日期: 2026/9/28

弱點發布日期: 2025/4/29

參考資訊

CVE: CVE-2026-64098, CVE-2026-64192, CVE-2026-64279, CVE-2026-68082, CVE-2026-68096, CVE-2026-68132, CVE-2026-68136, CVE-2026-68146, CVE-2026-68159, CVE-2026-68162, CVE-2026-68255, CVE-2026-68277, CVE-2026-68278, CVE-2026-68279, CVE-2026-72073, CVE-2026-72084, CVE-2026-72087, CVE-2026-72096, CVE-2026-72099, CVE-2026-72225, CVE-2026-72242, CVE-2026-72252, CVE-2026-72253, CVE-2026-72255, CVE-2026-72288, CVE-2026-72299, CVE-2026-72308, CVE-2026-72398, CVE-2026-72413, CVE-2026-72416, CVE-2026-72464, CVE-2026-74378, CVE-2026-74405, CVE-2026-74470, CVE-2026-74479, CVE-2026-74487, CVE-2026-74565, CVE-2026-74582, CVE-2026-74594, CVE-2026-74601, CVE-2026-74620, CVE-2026-74632, CVE-2026-74637, CVE-2026-74657, CVE-2026-74662, CVE-2026-74663, CVE-2026-74666, CVE-2026-74668, CVE-2026-74684, CVE-2026-74700, CVE-2026-74746, CVE-2026-74748, CVE-2026-80527, CVE-2026-80528, CVE-2026-80534, CVE-2026-80536, CVE-2026-80557, CVE-2026-80558, CVE-2026-80561, CVE-2026-80586, CVE-2026-80590, CVE-2026-80737, CVE-2026-80742, CVE-2026-80744, CVE-2026-80756, CVE-2026-80757, CVE-2026-80765, CVE-2026-80781, CVE-2026-80792, CVE-2026-80793, CVE-2026-80805, CVE-2026-80808, CVE-2026-80814, CVE-2026-80906, CVE-2026-80913, CVE-2026-80918