CentOS Linux 8.5 [TuxCare] 安全性更新:bpftool / kernel / kernel-core / kernel-cross-headers / etc 多個弱點 (CENTOS8.5:CLSA-2026:1768775579)

high Nessus Plugin ID 353189

概要

CentOS Linux 主機缺少一個或多個安全性更新。

說明

CentOS Linux 8.5 主機已安裝的套件會受到 TuxCare CENTOS8.5:CLSA-2026:1768775579 公告中提及的多個弱點影響。

- 在 5.6.2 及之前版本的 Linux 核心 3.16的 drivers/net/can/slcan.c 的 slc_bump 中發現一個問題。如果組態缺少 CONFIG_INIT_STACK_ALL (亦稱 CID-b9258a2cece4),攻擊者可利用此弱點讀取未初始化的 can_frame 資料,而其中可能含有來自核心堆疊記憶體的敏感資訊。
(CVE-2020-11494)

- 在具有裝置檔案「/dev/dri/renderD128 (or Dxxx)」的 Linux 核心中,在 drivers/gpu/vmxgfx/vmxgfx_kms.c 的 vmwgfx 驅動程式中發現超出邊界 (OOB) 記憶體存取弱點。此缺陷允許具有系統使用者帳戶的本機攻擊者取得權限,進而造成系統拒絕服務 (DoS)。(CVE-2022-36280)

- 已解決 Linux 核心中的下列弱點:ath9k_htc: fix potential out of bounds access with invalid rxstatus->rs_keyix The rxstatus->rs_keyix eventually gets passed to test_bit() so we need to ensure that it is within the bitmap. drivers/net/wireless/ath/ath9k/common.c:46 ath9k_cmn_rx_accept() error: passing untrusted data 'rx_stats->rs_keyix' to 'test_bit()' (CVE-2022-49503)

- 已解決 Linux 核心中的下列弱點:ata: libata-transport: fix double ata_host_put() in ata_tport_add() In the error path in ata_tport_add(), when calling put_device(), ata_tport_release() is called, it will put the refcount of 'ap->host'. And then ata_host_put() is called again, the refcount is decreased to 0, ata_host_release() is called, all ports are freed and set to null.
When unbinding the device after failure, ata_host_stop() is called to release the resources, it leads a null-ptr-deref(), because all the ports all freed and null. Unable to handle kernel NULL pointer dereference at virtual address 0000000000000008 CPU: 7 PID: 18671 Comm: modprobe Kdump: loaded Tainted: G E 6.1.0-rc3+ #8 pstate: 80400009 (Nzcv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--) pc :
ata_host_stop+0x3c/0x84 [libata] lr : release_nodes+0x64/0xd0 Call trace: ata_host_stop+0x3c/0x84 [libata] release_nodes+0x64/0xd0 devres_release_all+0xbc/0x1b0 device_unbind_cleanup+0x20/0x70 really_probe+0x158/0x320 __driver_probe_device+0x84/0x120 driver_probe_device+0x44/0x120
__driver_attach+0xb4/0x220 bus_for_each_dev+0x78/0xdc driver_attach+0x2c/0x40 bus_add_driver+0x184/0x240 driver_register+0x80/0x13c __pci_register_driver+0x4c/0x60 ahci_pci_driver_init+0x30/0x1000 [ahci] Fix this by removing redundant ata_host_put() in the error path. (CVE-2022-49826)

- 已解決 Linux 核心中的下列弱點:capabilities: fix undefined behavior in bit shift for CAP_TO_MASK Shifting signed 32-bit value by 31 bits is undefined, so changing significant bit to unsigned. The UBSAN warning calltrace like below: UBSAN: shift-out-of-bounds in security/commoncap.c:1252:2 left shift of 1 by 31 places cannot be represented in type 'int' Call Trace:
<TASK> dump_stack_lvl+0x7d/0xa5 dump_stack+0x15/0x1b ubsan_epilogue+0xe/0x4e
__ubsan_handle_shift_out_of_bounds+0x1e7/0x20c cap_task_prctl+0x561/0x6f0 security_task_prctl+0x5a/0xb0
__x64_sys_prctl+0x61/0x8f0 do_syscall_64+0x58/0x80 entry_SYSCALL_64_after_hwframe+0x63/0xcd </TASK> (CVE-2022-49870)

請注意,Nessus 並未測試這些問題,而是僅依據應用程式自我報告的版本號碼作出判斷。

解決方案

根據 TuxCare 公告 CENTOS8.5:CLSA-2026:1768775579 中的指引更新受影響的套件。

另請參閱

https://cve.tuxcare.com/els/releases/CLSA-2026:1768775579

http://www.nessus.org/u?7dba2d2e

Plugin 詳細資訊

嚴重性: High

ID: 353189

檔案名稱: tuxcare_centos_8.5_CLSA-2026-1768775579.nasl

版本: 1.2

類型: Local

代理程式: unix

已發布: 2026/9/30

已更新: 2026/10/1

支援的感應器: Continuous Assessment, Nessus Agent, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

風險資訊

VPR

風險因素: High

分數: 7.6

百分位數: 98.59

Vendor

Vendor Severity: Important

CVSS v2

風險因素: Low

基本分數: 2.1

時間性分數: 1.6

媒介: CVSS2#AV:L/AC:L/Au:N/C:P/I:N/A:N

CVSS 評分資料來源: CVE-2020-11494

CVSS v3

風險因素: High

基本分數: 7.8

時間性分數: 6.8

媒介: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

時間媒介: CVSS:3.0/E:U/RL:O/RC:C

CVSS 評分資料來源: CVE-2025-38618

弱點資訊

必要的 KB 項目: Host/OS/extended-third-party, Host/local_checks_enabled, Host/CentOS/release, Host/CentOS/rpm-list

可輕鬆利用: No known exploits are available

修補程式發佈日期: 2026/1/18

弱點發布日期: 2020/4/2

參考資訊

CVE: CVE-2020-11494, CVE-2022-36280, CVE-2022-49503, CVE-2022-49826, CVE-2022-49870, CVE-2022-49917, CVE-2022-49948, CVE-2022-50084, CVE-2022-50200, CVE-2022-50258, CVE-2022-50315, CVE-2022-50320, CVE-2022-50366, CVE-2022-50411, CVE-2022-50419, CVE-2022-50423, CVE-2022-50440, CVE-2022-50638, CVE-2022-50710, CVE-2022-50881, CVE-2023-53116, CVE-2023-53215, CVE-2023-53265, CVE-2023-53285, CVE-2023-53286, CVE-2023-53307, CVE-2023-53321, CVE-2023-53338, CVE-2023-53357, CVE-2023-53372, CVE-2023-53395, CVE-2023-53427, CVE-2023-53446, CVE-2023-53679, CVE-2023-53761, CVE-2023-53765, CVE-2023-53786, CVE-2023-53803, CVE-2023-53821, CVE-2023-53832, CVE-2023-54286, CVE-2024-27075, CVE-2024-46815, CVE-2025-38249, CVE-2025-38445, CVE-2025-38459, CVE-2025-38618, CVE-2025-40240

CLSA: 2026:1768775579