AlmaLinux 9.6 [TuxCare] 安全性更新:kernel / kernel-abi-stablelists / kernel-core / etc 多個弱點 (ALMALINUX9.6:CLSA-2026:1789986443)

high Nessus Plugin ID 352548

概要

AlmaLinux 主機缺少一或多個安全性更新。

說明

AlmaLinux 9.6 主機已安裝的套件會受到 TuxCare ALMALINUX9.6:CLSA-2026:1789986443 公告中提及的多個弱點影響。

- 已解決 Linux 核心中的下列弱點:net: hns3: add vlan list lock to protect vlan list When adding port base VLAN, vf VLAN need to remove from HW and modify the vlan state in vf VLAN list as false. If the periodicity task is freeing the same node, it may cause use after free error. This patch adds a vlan list lock to protect the vlan list. (CVE-2022-49182)

- 已解決 Linux 核心中的下列弱點:tracing: Fix reading strings from synthetic events The follow commands caused a crash: # cd /sys/kernel/tracing # echo 's:open char file[]' > dynamic_events # echo 'hist:keys=common_pid:file=filename:onchange($file).trace(open,$file)' > events/syscalls/sys_enter_openat/trigger' # echo 1 > events/synthetic/open/enable BOOM! The problem is that the synthetic event field char file[] will read the value given to it as a string without any memory checks to make sure the address is valid. The above example will pass in the user space address and the sythetic event code will happily call strlen() on it and then strscpy() where either one will cause an oops when accessing user space addresses. Use the helper functions from trace_kprobe and trace_eprobe that can read strings safely (and actually succeed when the address is from user space and the memory is mapped in). Now the above can show: packagekitd-1721 [000] ...2. 104.597170: open:
file=/usr/lib/rpm/fileattrs/cmake.attr in:imjournal-978 [006] ...2. 104.599642: open:
file=/var/lib/rsyslog/imjournal.state.tmp packagekitd-1721 [000] ...2. 104.626308: open:
file=/usr/lib/rpm/fileattrs/debuginfo.attr (CVE-2022-50255)

- 已解決 Linux 核心中的下列弱點:ipc: fix memleak if msg_init_ns failed in create_ipc_ns Percpu memory allocation may failed during create_ipc_ns however this fail is not handled properly since ipc sysctls and mq sysctls is not released properly. Fix this by release these two resource when failure. Here is the kmemleak stack when percpu failed: unreferenced object 0xffff88819de2a600 (size 512): comm shmem_2nstest, pid 120711, jiffies 4300542254 hex dump (first 32 bytes): 60 aa 9d 84 ff ff ff ff fc 18 48 b2 84 88 ff ff `.........H..... 04 00 00 00 a4 01 00 00 20 e4 56 81 ff ff ff ff ........
.V..... backtrace (crc be7cba35): [<ffffffff81b43f83>] __kmalloc_node_track_caller_noprof+0x333/0x420 [<ffffffff81a52e56>] kmemdup_noprof+0x26/0x50 [<ffffffff821b2f37>] setup_mq_sysctls+0x57/0x1d0 [<ffffffff821b29cc>] copy_ipcs+0x29c/0x3b0 [<ffffffff815d6a10>] create_new_namespaces+0x1d0/0x920 [<ffffffff815d7449>] copy_namespaces+0x2e9/0x3e0 [<ffffffff815458f3>] copy_process+0x29f3/0x7ff0 [<ffffffff8154b080>] kernel_clone+0xc0/0x650 [<ffffffff8154b6b1>] __do_sys_clone+0xa1/0xe0 [<ffffffff843df8ff>] do_syscall_64+0xbf/0x1c0 [<ffffffff846000b0>] entry_SYSCALL_64_after_hwframe+0x4b/0x53 (CVE-2024-53175)

- 已解決 Linux 核心中的下列弱點:net/mlx5: HWS, change error flow on matcher disconnect Currently, when firmware failure occurs during matcher disconnect flow, the error flow of the function reconnects the matcher back and returns an error, which continues running the calling function and eventually frees the matcher that is being disconnected. This leads to a case where we have a freed matcher on the matchers list, which in turn leads to use-after-free and eventual crash. This patch fixes that by not trying to reconnect the matcher back when some FW command fails during disconnect. Note that we're dealing here with FW error. We can't overcome this problem. This might lead to bad steering state (e.g. wrong connection between matchers), and will also lead to resource leakage, as it is the case with any other error handling during resource destruction. However, the goal here is to allow the driver to continue and not crash the machine with use-after-free error. (CVE-2025-21751)

- 已解決 Linux 核心中的下列弱點:wifi: ath12k: Avoid memory leak while enabling statistics Driver uses monitor destination rings for extended statistics mode and standalone monitor mode. In extended statistics mode, TLVs are parsed from the buffer received from the monitor destination ring and assigned to the ppdu_info structure to update per-packet statistics. In standalone monitor mode, along with per-packet statistics, the packet data (payload) is captured, and the driver updates per MSDU to mac80211. When the AP interface is enabled, only extended statistics mode is activated. As part of enabling monitor rings for collecting statistics, the driver subscribes to HAL_RX_MPDU_START TLV in the filter configuration. This TLV is received from the monitor destination ring, and kzalloc for the mon_mpdu object occurs, which is not freed, leading to a memory leak. The kzalloc for the mon_mpdu object is only required while enabling the standalone monitor interface. This causes a memory leak while enabling extended statistics mode in the driver. Fix this memory leak by removing the kzalloc for the mon_mpdu object in the HAL_RX_MPDU_START TLV handling. Additionally, remove the standalone monitor mode handlings in the HAL_MON_BUF_ADDR and HAL_RX_MSDU_END TLVs. These TLV tags will be handled properly when enabling standalone monitor mode in the future. Tested-on: QCN9274 hw2.0 PCI WLAN.WBE.1.3.1-00173-QCAHKSWPL_SILICONZ-1 Tested-on: WCN7850 hw2.0 PCI WLAN.HMT.1.0.c5-00481-QCAHMTSWPL_V1.0_V2.0_SILICONZ-3 (CVE-2025-37743)

請注意,Nessus 並未測試這些問題,而是僅依據應用程式自我報告的版本號碼作出判斷。

解決方案

根據 TuxCare 公告 ALMALINUX9.6:CLSA-2026:1789986443 中的指引更新受影響的套件。

另請參閱

https://cve.tuxcare.com/els/releases/CLSA-2026:1789986443

http://www.nessus.org/u?8e332f8e

Plugin 詳細資訊

嚴重性: High

ID: 352548

檔案名稱: tuxcare_alma_linux_9.6_CLSA-2026-1789986443.nasl

版本: 1.1

類型: Local

已發布: 2026/9/30

已更新: 2026/9/30

支援的感應器: Continuous Assessment, Nessus Agent, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

風險資訊

VPR

風險因素: High

分數: 7.7

百分位數: 99.06

Vendor

Vendor Severity: Important

CVSS v2

風險因素: Medium

基本分數: 6.8

時間性分數: 5.3

媒介: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS 評分資料來源: CVE-2026-45996

CVSS v3

風險因素: High

基本分數: 7.8

時間性分數: 7

媒介: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

時間媒介: CVSS:3.0/E:P/RL:O/RC:C

弱點資訊

必要的 KB 項目: Host/OS/extended-third-party, Host/local_checks_enabled, Host/AlmaLinux/release, Host/AlmaLinux/rpm-list, Host/cpu

可被惡意程式利用: true

可輕鬆利用: Exploits are available

修補程式發佈日期: 2026/9/21

弱點發布日期: 2024/12/27

參考資訊

CVE: CVE-2022-49182, CVE-2022-50255, CVE-2024-53175, CVE-2024-57857, CVE-2025-21751, CVE-2025-22015, CVE-2025-37743, CVE-2025-38364, CVE-2025-38588, CVE-2025-38593, CVE-2025-39946, CVE-2025-39977, CVE-2025-40016, CVE-2025-40105, CVE-2025-40173, CVE-2025-40231, CVE-2025-68192, CVE-2025-68363, CVE-2025-68785, CVE-2025-68816, CVE-2026-23142, CVE-2026-23166, CVE-2026-23262, CVE-2026-23327, CVE-2026-23343, CVE-2026-23386, CVE-2026-23466, CVE-2026-31407, CVE-2026-31440, CVE-2026-31446, CVE-2026-31448, CVE-2026-31449, CVE-2026-31450, CVE-2026-31458, CVE-2026-31491, CVE-2026-31505, CVE-2026-31557, CVE-2026-31589, CVE-2026-31591, CVE-2026-31700, CVE-2026-43025, CVE-2026-43048, CVE-2026-43059, CVE-2026-43091, CVE-2026-43092, CVE-2026-43125, CVE-2026-43134, CVE-2026-43253, CVE-2026-43437, CVE-2026-43468, CVE-2026-45963, CVE-2026-45996, CVE-2026-46197, CVE-2026-52910, CVE-2026-52946, CVE-2026-52961, CVE-2026-53133, CVE-2026-53186, CVE-2026-53250, CVE-2026-53253, CVE-2026-53281, CVE-2026-53324, CVE-2026-53356, CVE-2026-64173, CVE-2026-64210, CVE-2026-64213, CVE-2026-64275, CVE-2026-64570, CVE-2026-68090, CVE-2026-68091, CVE-2026-68093, CVE-2026-68108, CVE-2026-68113, CVE-2026-68115, CVE-2026-68123, CVE-2026-68129, CVE-2026-68142, CVE-2026-68145, CVE-2026-68155, CVE-2026-68156, CVE-2026-68159, CVE-2026-68160, CVE-2026-68162, CVE-2026-68165, CVE-2026-68169, CVE-2026-68188, CVE-2026-68202, CVE-2026-68206, CVE-2026-68234, CVE-2026-68243, CVE-2026-68245, CVE-2026-68246, CVE-2026-68248, CVE-2026-68253, CVE-2026-68257, CVE-2026-68258, CVE-2026-68264, CVE-2026-68269, CVE-2026-68271, CVE-2026-68276, CVE-2026-68277, CVE-2026-68288, CVE-2026-68294, CVE-2026-68296, CVE-2026-68307, CVE-2026-68343, CVE-2026-68348, CVE-2026-68362, CVE-2026-68376, CVE-2026-68377, CVE-2026-68391, CVE-2026-68393, CVE-2026-68394, CVE-2026-68398, CVE-2026-68419, CVE-2026-68432, CVE-2026-68436, CVE-2026-68446, CVE-2026-68448, CVE-2026-72472, CVE-2026-74565

CLSA: 2026:1789986443