CentOS Linux 7 [TuxCare] 安全性更新:bpftool / kernel / kernel-debug / kernel-debug-devel / kernel-devel / etc 多個弱點 (CENTOS7:CLSA-2026:1789037015)

high Nessus Plugin ID 352722

概要

CentOS Linux 主機缺少一個或多個安全性更新。

說明

CentOS Linux 7 主機已安裝的套件會受到 TuxCare CENTOS7:CLSA-2026:2026:1789037015 公告中提及的多個弱點影響。

- 已解決 Linux 核心中的下列弱點:scsi: iscsi: Fix conn use after free during resets If we haven't done a unbind target call we can race where iscsi_conn_teardown wakes up the EH thread and then frees the conn while those threads are still accessing the conn ehwait. We can only do one TMF per session so this just moves the TMF fields from the conn to the session. We can then rely on the iscsi_session_teardown->iscsi_remove_session->__iscsi_unbind_session call to remove the target and it's devices, and know after that point there is no device or scsi-ml callout trying to access the session. (CVE-2021-47328)

- 已解決 Linux 核心中的下列弱點:ext4: improve error handling from ext4_dirhash() The ext4_dirhash() will *almost* never fail, especially when the hash tree feature was first introduced. However, with the addition of support of encrypted, casefolded file names, that function can most certainly fail today. So make sure the callers of ext4_dirhash() properly check for failures, and reflect the errors back up to their callers. (CVE-2023-53473)

- 已解決 Linux 核心中的下列弱點:iommu/vt-d: Clear Present bit before tearing down context entry When tearing down a context entry, the current implementation zeros the entire 128-bit entry using multiple 64-bit writes. This creates a window where the hardware can fetch a torn entry where some fields are already zeroed while the 'Present' bit is still set leading to unpredictable behavior or spurious faults. While x86 provides strong write ordering, the compiler may reorder writes to the two 64-bit halves of the context entry. Even without compiler reordering, the hardware fetch is not guaranteed to be atomic with respect to multiple CPU writes. Align with the Guidance to Software for Invalidations in the VT-d spec (Section 6.5.3.3) by implementing the recommended ownership handshake: 1. Clear only the 'Present' (P) bit of the context entry first to signal the transition of ownership from hardware to software. 2. Use dma_wmb() to ensure the cleared bit is visible to the IOMMU. 3. Perform the required cache and context-cache invalidation to ensure hardware no longer has cached references to the entry. 4. Fully zero out the entry only after the invalidation is complete. Also, add a dma_wmb() to context_set_present() to ensure the entry is fully initialized before the 'Present' bit becomes visible. (CVE-2026-45944)

- 已解決 Linux 核心中的下列弱點:ipmi: Add limits to event and receive message requests The driver would just fetch events and receive messages until the BMC said it was done.
To avoid issues with BMCs that never say they are done, add a limit of 10 fetches at a time. In addition, an si interface has an attn state it can return from the hardware which is supposed to cause a flag fetch to see if the driver needs to fetch events or message or a few other things. If the attn bit gets stuck, it's a similar problem. So allow messages in between flag fetches so the driver itself doesn't get stuck.
This is a more general fix than the previous fix for the specific bad BMC, but should fix the more general issue of a BMC that won't stop saying it has data. This has been there from the beginning of the driver.
It's not a bug per-se, but it is accounting for bugs in BMCs. (CVE-2026-46177)

- 已解決 Linux 核心中的下列弱點:PCI: use generic driver_override infrastructure When a driver is probed through __driver_attach(), the bus' match() callback is called without the device lock held, thus accessing the driver_override field without a lock, which can cause a UAF. Fix this by using the driver-core driver_override infrastructure taking care of proper locking internally. Note that calling match() from __driver_attach() without the device lock held is intentional.
[1] (CVE-2026-53120)

請注意,Nessus 並未測試這些問題,而是僅依據應用程式自我報告的版本號碼作出判斷。

解決方案

根據 TuxCare 公告 CENTOS7:CLSA-2026:1789037015 中的指引更新受影響的套件。

另請參閱

https://cve.tuxcare.com/els/releases/CLSA-2026:1789037015

http://www.nessus.org/u?aef1b8c9

Plugin 詳細資訊

嚴重性: High

ID: 352722

檔案名稱: tuxcare_centos_7_CLSA-2026-1789037015.nasl

版本: 1.1

類型: Local

代理程式: unix

已發布: 2026/9/30

已更新: 2026/9/30

支援的感應器: Continuous Assessment, Nessus Agent, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

風險資訊

VPR

風險因素: High

分數: 7.6

百分位數: 98.35

Vendor

Vendor Severity: Important

CVSS v2

風險因素: Medium

基本分數: 6.8

時間性分數: 5

媒介: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS 評分資料來源: CVE-2026-64348

CVSS v3

風險因素: High

基本分數: 7.8

時間性分數: 6.8

媒介: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

時間媒介: CVSS:3.0/E:U/RL:O/RC:C

弱點資訊

必要的 KB 項目: Host/OS/extended-third-party, Host/local_checks_enabled, Host/CentOS/release, Host/CentOS/rpm-list

可輕鬆利用: No known exploits are available

修補程式發佈日期: 2026/9/10

弱點發布日期: 2022/1/28

參考資訊

CVE: CVE-2021-47328, CVE-2023-53473, CVE-2026-45944, CVE-2026-46177, CVE-2026-53120, CVE-2026-53186, CVE-2026-63829, CVE-2026-64322, CVE-2026-64323, CVE-2026-64341, CVE-2026-64344, CVE-2026-64348, CVE-2026-64411, CVE-2026-64413, CVE-2026-64422, CVE-2026-64448, CVE-2026-68184, CVE-2026-68300, CVE-2026-68349, CVE-2026-68350, CVE-2026-68351, CVE-2026-68430, CVE-2026-68469, CVE-2026-72051, CVE-2026-72053, CVE-2026-72054, CVE-2026-72055, CVE-2026-72061, CVE-2026-72113, CVE-2026-72115, CVE-2026-72116, CVE-2026-72117, CVE-2026-72118, CVE-2026-72122, CVE-2026-72308, CVE-2026-74456, CVE-2026-74464, CVE-2026-74580, CVE-2026-74587, CVE-2026-74597, CVE-2026-74630, CVE-2026-74637, CVE-2026-74641, CVE-2026-74656, CVE-2026-74682, CVE-2026-74688, CVE-2026-74705, CVE-2026-74725, CVE-2026-74752, CVE-2026-80558, CVE-2026-80576

CLSA: 2026:1789037015