CentOS Linux 7 [TuxCare] 安全性更新:bpftool / kernel / kernel-debug / kernel-debug-devel / kernel-devel / etc 多個弱點 (CENTOS7:CLSA-2026:1783884048)

medium Nessus Plugin ID 352704

概要

CentOS Linux 主機缺少一個或多個安全性更新。

說明

CentOS Linux 7 主機安裝的套件會受到 TuxCare CENTOS7:CLSA-2026:1783884048 公告中提及的多個弱點影響。

- 已解決 Linux 核心中的下列弱點:net: usb: pegasus: validate USB endpoints The pegasus driver should validate that the device it is probing has the proper number and types of USB endpoints it is expecting before it binds to it. If a malicious device were to not have the same urbs the driver will crash later on when it blindly accesses these endpoints. (CVE-2026-23290)

- 已解決 Linux 核心中的下列弱點:rtmutex: Use waiter::task instead of current in remove_waiter() remove_waiter() is used by the slowlock paths, but it is also used for proxy-lock rollback in rt_mutex_start_proxy_lock() when invoked from futex_requeue(). In the latter case waiter::task is not current, but remove_waiter() operates on current for the dequeue operation. That results in several problems: 1) the rbtree dequeue happens without waiter::task::pi_lock being held 2) the waiter task's pi_blocked_on state is not cleared, which leaves a dangling pointer primed for UAF around.
3) rt_mutex_adjust_prio_chain() operates on the wrong top priority waiter task Use waiter::task instead of current in all related operations in remove_waiter() to cure those problems. [ tglx: Fixup rt_mutex_adjust_prio_chain(), add a comment and amend the changelog ] (CVE-2026-43499)

請注意,Nessus 並未測試這些問題,而是僅依據應用程式自我報告的版本號碼作出判斷。

解決方案

根據 TuxCare 公告 CENTOS7:CLSA-2026:1783884048 中的指引更新受影響的套件。

另請參閱

https://cve.tuxcare.com/els/releases/CLSA-2026:1783884048

http://www.nessus.org/u?4578a9d1

Plugin 詳細資訊

嚴重性: Medium

ID: 352704

檔案名稱: tuxcare_centos_7_CLSA-2026-1783884048.nasl

版本: 1.2

類型: Local

代理程式: unix

已發布: 2026/9/30

已更新: 2026/10/1

支援的感應器: Continuous Assessment, Nessus Agent, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

風險資訊

VPR

風險因素: Critical

分數: 9.5

百分位數: 99.87

Vendor

Vendor Severity: Important

CVSS v2

風險因素: Medium

基本分數: 4.6

時間性分數: 4

媒介: CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:C

CVSS 評分資料來源: CVE-2026-23290

CVSS v3

風險因素: Medium

基本分數: 5.5

時間性分數: 5.3

媒介: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

時間媒介: CVSS:3.0/E:H/RL:O/RC:C

弱點資訊

必要的 KB 項目: Host/OS/extended-third-party, Host/local_checks_enabled, Host/CentOS/release, Host/CentOS/rpm-list

可被惡意程式利用: true

可輕鬆利用: Exploits are available

修補程式發佈日期: 2026/7/12

弱點發布日期: 2026/3/25

參考資訊

CVE: CVE-2026-23290, CVE-2026-43499

CLSA: 2026:1783884048