CentOS Linux 7 [TuxCare] 安全性更新:bpftool / kernel / kernel-debug / kernel-debug-devel / kernel-devel / etc 多個弱點 (CENTOS7:CLSA-2025:1759431860)

high Nessus Plugin ID 352574

概要

CentOS Linux 主機缺少一個或多個安全性更新。

說明

CentOS Linux 7 主機安裝的套件會受到 TuxCare CENTOS7:CLSA-2025:1759431860 公告中提及的多個弱點影響。

- 已解決 Linux 核心中的下列弱點:watchdog: Fix possible use-after-free by calling del_timer_sync() This driver's remove path calls del_timer(). However, that function does not wait until the timer handler finishes. This means that the timer handler may still be running after the driver's remove function has finished, which would result in a use-after-free. Fix by calling del_timer_sync(), which makes sure the timer handler has finished, and unable to re-schedule itself.
(CVE-2021-47321)

- 已解決 Linux 核心中的下列弱點:virtio-net: Add validation for used length This adds validation for used length (might come from an untrusted device) to avoid data corruption or loss. (CVE-2021-47352)

- 已解決 Linux 核心中的下列弱點:nvmem: Fix shift-out-of-bound (UBSAN) with byte size cells If a cell has 'nbits' equal to a multiple of BITS_PER_BYTE the logic *p &= GENMASK((cell->nbits%BITS_PER_BYTE) - 1, 0); will become undefined behavior because nbits modulo BITS_PER_BYTE is 0, and we subtract one from that making a large number that is then shifted more than the number of bits that fit into an unsigned long. UBSAN reports this problem: UBSAN: shift-out-of-bounds in drivers/nvmem/core.c:1386:8 shift exponent 64 is too large for 64-bit type 'unsigned long' CPU: 6 PID: 7 Comm: kworker/u16:0 Not tainted 5.15.0-rc3+ #9 Hardware name: Google Lazor (rev3+) with KB Backlight (DT) Workqueue: events_unbound deferred_probe_work_func Call trace: dump_backtrace+0x0/0x170 show_stack+0x24/0x30 dump_stack_lvl+0x64/0x7c dump_stack+0x18/0x38 ubsan_epilogue+0x10/0x54
__ubsan_handle_shift_out_of_bounds+0x180/0x194 __nvmem_cell_read+0x1ec/0x21c nvmem_cell_read+0x58/0x94 nvmem_cell_read_variable_common+0x4c/0xb0 nvmem_cell_read_variable_le_u32+0x40/0x100 a6xx_gpu_init+0x170/0x2f4 adreno_bind+0x174/0x284 component_bind_all+0xf0/0x264 msm_drm_bind+0x1d8/0x7a0 try_to_bring_up_master+0x164/0x1ac __component_add+0xbc/0x13c component_add+0x20/0x2c dp_display_probe+0x340/0x384 platform_probe+0xc0/0x100 really_probe+0x110/0x304
__driver_probe_device+0xb8/0x120 driver_probe_device+0x4c/0xfc __device_attach_driver+0xb0/0x128 bus_for_each_drv+0x90/0xdc __device_attach+0xc8/0x174 device_initial_probe+0x20/0x2c bus_probe_device+0x40/0xa4 deferred_probe_work_func+0x7c/0xb8 process_one_work+0x128/0x21c process_scheduled_works+0x40/0x54 worker_thread+0x1ec/0x2a8 kthread+0x138/0x158 ret_from_fork+0x10/0x20 Fix it by making sure there are any bits to mask out. (CVE-2021-47497)

- Linux PV 裝置前端容易受到後端攻擊 [其 CNA 資訊記錄與多個 CVE 有關;文字說明了哪些方面/弱點對應哪個 CVE。] 數個 Linux PV 裝置前端正在以易受爭用情形影響的方式,使用授權表介面移除後端的存取權,進而可能導致資料洩漏、惡意後端損毀資料以及惡意後端觸發拒絕服務:blkfront、netfront、scsifront 和 gntalloc 驅動程式正在測試授權參照是否仍在使用中。如果情況並非如此,則它們會假設後續每次都能移除授予的存取權;但如果後端已在執行這兩項作業之間對應授權頁面,則此假設不成立。因此,無論前端 I/O 完成後如何使用頁面,後端都可以繼續存取客體的記憶體頁面。
xenbus 驅動程式有一個類似的問題,因為它不會檢查是否成功移除向共用環形緩衝區授予的存取權。blkfront:CVE-2022-23036 netfront:CVE-2022-23037 scsifront:CVE-2022-23038 gntalloc:CVE-2022-23039 xenbus:CVE-2022-23040 blkfront、netfront、scsifront、usbfront、dmabuf、xenbus、9p、kbdfront 和 pvcalls 使用功能延遲釋放授權參照 (直到不再使用這個參照),但相關資料頁面的釋放與刪除授予的存取權並不同步。因此,即使在記憶體頁面被釋放並重新用於其他目的之後,後端仍可繼續存取該頁面。CVE-2022-23041 如果 netfront 無法撤銷 rx 路徑中的存取權,則 BUG_ON() 宣告將失敗。這將導致客體出現拒絕服務 (DoS) 情況,而後端可能會觸發。 CVE-2022-23042 (CVE-2022-23037, CVE-2022-23038, CVE-2022-23039)

- 在 6.0.9 版之前的 Linux 核心中發現一個問題。drivers/media/dvb-core/dvbdev.c 有一個與 dvb_register_device 動態配置 fops 相關的釋放後使用問題。(CVE-2022-45884)

請注意,Nessus 並未測試這些問題,而是僅依據應用程式自我報告的版本號碼作出判斷。

解決方案

根據 TuxCare 公告 CENTOS7:CLSA-2025:1759431860 中的指引更新受影響的套件。

另請參閱

https://cve.tuxcare.com/els/releases/CLSA-2025:1759431860

http://www.nessus.org/u?333c00c0

Plugin 詳細資訊

嚴重性: High

ID: 352574

檔案名稱: tuxcare_centos_7_CLSA-2025-1759431860.nasl

版本: 1.2

類型: Local

代理程式: unix

已發布: 2026/9/30

已更新: 2026/10/1

支援的感應器: Continuous Assessment, Nessus Agent, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

風險資訊

VPR

風險因素: Critical

分數: 9.4

百分位數: 99.82

Vendor

Vendor Severity: Important

CVSS v2

風險因素: Medium

基本分數: 4.4

時間性分數: 3.8

媒介: CVSS2#AV:L/AC:M/Au:N/C:P/I:P/A:P

CVSS 評分資料來源: CVE-2022-23039

CVSS v3

風險因素: High

基本分數: 7.8

時間性分數: 7.5

媒介: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

時間媒介: CVSS:3.0/E:H/RL:O/RC:C

CVSS 評分資料來源: CVE-2025-38350

弱點資訊

必要的 KB 項目: Host/OS/extended-third-party, Host/local_checks_enabled, Host/CentOS/release, Host/CentOS/rpm-list

可被惡意程式利用: true

可輕鬆利用: Exploits are available

修補程式發佈日期: 2025/10/2

弱點發布日期: 2021/7/21

CISA 已知遭惡意利用弱點到期日: 2025/7/8

可惡意利用

Core Impact

Metasploit (Local Privilege Escalation via CVE-2023-0386)

參考資訊

CVE: CVE-2021-47103, CVE-2021-47310, CVE-2021-47321, CVE-2021-47352, CVE-2021-47497, CVE-2022-23037, CVE-2022-23038, CVE-2022-23039, CVE-2022-45884, CVE-2022-45885, CVE-2022-48695, CVE-2022-48757, CVE-2022-48760, CVE-2022-49292, CVE-2023-0386, CVE-2023-52530, CVE-2023-52578, CVE-2023-52594, CVE-2023-52764, CVE-2023-52835, CVE-2023-52864, CVE-2024-26961, CVE-2024-26974, CVE-2024-35965, CVE-2024-35966, CVE-2024-36921, CVE-2024-38621, CVE-2024-39499, CVE-2024-40901, CVE-2024-40929, CVE-2024-40978, CVE-2024-41069, CVE-2024-52332, CVE-2024-53214, CVE-2024-56616, CVE-2025-21704, CVE-2025-37798, CVE-2025-37932, CVE-2025-38350

CLSA: 2025:1759431860