CentOS Linux 7 [TuxCare] 安全性更新:bpftool / kernel / kernel-debug / kernel-debug-devel / kernel-devel / etc 多個弱點 (CENTOS7:CLSA-2024:1724693366)

high Nessus Plugin ID 352493

概要

CentOS Linux 主機缺少一個或多個安全性更新。

說明

CentOS Linux 7 主機安裝的套件會受到 TuxCare CENTOS7:CLSA-2024:1724693366 公告中提及的多個弱點影響。

- 已解決 Linux 核心中的下列弱點:tty: Fix out-of-bound vmalloc access in imageblit This issue happens when a userspace program does an ioctl FBIOPUT_VSCREENINFO passing the fb_var_screeninfo struct containing only the fields xres, yres, and bits_per_pixel with values. If this struct is the same as the previous ioctl, the vc_resize() detects it and doesn't call the resize_screen(), leaving the fb_var_screeninfo incomplete. And this leads to the updatescrollmode() calculates a wrong value to fbcon_display->vrows, which makes the real_y() return a wrong value of y, and that value, eventually, causes the imageblit to access an out-of-bound address value. To solve this issue I made the resize_screen() be called even if the screen does not need any resizing, so it will fix and fill the fb_var_screeninfo independently. (CVE-2021-47383)

- 之前 6.3 Linux 核心中的 IPv6 實作有一個 net/ipv6/route.c max_size臨界值,可以輕鬆使用,例如,當 IPv6 封包透過原始通訊端在迴圈中傳送時,會導致拒絕服務(網路無法連線錯誤)。(CVE-2023-52340)

- 已解決 Linux 核心中的下列弱點:drivers/amd/pm: fix a use-after-free in kv_parse_power_table When ps allocated by kzalloc equals to NULL, kv_parse_power_table frees adev->pm.dpm.ps that allocated before. However, after the control flow goes through the following call chains: kv_parse_power_table |-> kv_dpm_init |-> kv_dpm_sw_init |-> kv_dpm_fini The adev->pm.dpm.ps is used in the for loop of kv_dpm_fini after its first free in kv_parse_power_table and causes a use-after-free bug. (CVE-2023-52469)

- 在 Linux 核心的 ext4 中,在 fs/ext4/super.c 的 __ext4_remount 中發現一個釋放後使用缺陷。此缺陷允許本機使用者在釋放舊的配額檔案名稱以觸發潛在的失敗時,造成資訊洩漏問題,進而導致釋放後使用。(CVE-2024-0775)

- 在 Linux、x86、ARM (md、raid、raid5 模組) 主機上,Linux 核心中的整數溢位或循環弱點允許強制整數溢位。(CVE-2024-23307)

請注意,Nessus 並未測試這些問題,而是僅依據應用程式自我報告的版本號碼作出判斷。

解決方案

根據 TuxCare 公告 CENTOS7:CLSA-2024:1724693366 中的指引更新受影響的套件。

另請參閱

https://cve.tuxcare.com/els/releases/CLSA-2024:1724693366

http://www.nessus.org/u?d30a729c

Plugin 詳細資訊

嚴重性: High

ID: 352493

檔案名稱: tuxcare_centos_7_CLSA-2024-1724693366.nasl

版本: 1.1

類型: Local

代理程式: unix

已發布: 2026/9/30

已更新: 2026/9/30

支援的感應器: Nessus Agent, Continuous Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

風險資訊

VPR

風險因素: Medium

分數: 6.9

百分位數: 96.5

Vendor

Vendor Severity: Important

CVSS v2

風險因素: Medium

基本分數: 6.8

時間性分數: 5

媒介: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS 評分資料來源: CVE-2024-39494

CVSS v3

風險因素: High

基本分數: 7.8

時間性分數: 6.8

媒介: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

時間媒介: CVSS:3.0/E:U/RL:O/RC:C

弱點資訊

必要的 KB 項目: Host/local_checks_enabled, Host/CentOS/release, Host/CentOS/rpm-list, Host/OS/extended-third-party

可輕鬆利用: No known exploits are available

修補程式發佈日期: 2024/8/26

弱點發布日期: 2021/7/21

參考資訊

CVE: CVE-2021-47383, CVE-2023-52340, CVE-2023-52469, CVE-2024-0775, CVE-2024-23307, CVE-2024-26668, CVE-2024-26855, CVE-2024-26882, CVE-2024-26923, CVE-2024-26934, CVE-2024-27020, CVE-2024-36960, CVE-2024-38570, CVE-2024-39494, CVE-2024-42228

CLSA: 2024:1724693366