Rocky Linux 8 [CIQ] 安全性更新:bpftool / bpftool-debuginfo / kernel / kernel-abi-stablelists / etc 多個弱點 (crlsa-2022_1988)

critical Nessus Plugin ID 357390

概要

Rocky Linux 主機缺少一或多個安全性更新。

說明

Rocky Linux 8 主機已安裝的套件會受到 CIQ crlsa-2022_1988 公告中提及的多個弱點影響。

* 核心:fget:在取得 fd 的 ref 後,檢查 fd 是否仍然存在 (CVE-2021-4083)

* 核心:避免由於 USB 描述元格式錯誤而導致的循環實體鏈結 (CVE-2020-0404)

* 核心:對 IBM Power9 上未完全驗證資料的推測 (CVE-2020-4788)

* 核心:在 drivers/tty/vt/keyboard.c (CVE-2020-13974) 中,k_ascii() 中的整數溢位

* 核心:由於釋放後使用 (CVE-2021-0941),filter.c 的 bpf_skb_change_head() 中發生越界讀取

* 核心:joydev:傳遞給 joydev_handle_JSIOCSBTNMAP()CVE-2021-3612 () 的零大小

* 核心:讀取 /proc/sysvipc/shm 不會隨著較大的共用記憶體區段計數而擴展 (CVE-2021-3669)

* 核心:net/qrtr/qrtr.c (CVE-2021-3743) 中的 qrtr_endpoint_post 越界讀取

* 核心:crypto:ccp - 修正 ccp_run_aes_gcm_cmd()CVE-2021-3744 () 中的資源洩漏

* 核心:藍牙模組 (CVE-2021-3752) 中可能的釋放後使用

* 核心:Linux 核心中不明的 ipc 物件會導致突破 memcg 限制和 DoS 攻擊 (CVE-2021-3759)

* 核心:ccp_run_aes_gcm_cmd() 函式中的 DoS (CVE-2021-3764)

* 核心:sctp:無效區塊可用來遠端移除現有關聯 (CVE-2021-3772)

* 核心:NATD 和 netfilter 中缺少連接埠健全性檢查導致 OpenVPN 用戶端遭到惡意利用 (CVE-2021-3773)

* 核心:駐留在 hugetlbfs (CVE-2021-4002) 上的資料可能洩露或破壞

* 核心:(CVE-2021-4037) 的CVE-2018-13405安全性迴歸

* 核心:decode_nfs_fh函式 (CVE-2021-4157) 中的緩衝區覆寫

* 核心:cgroup:使用開放時間憑證和命名空間進行移轉永久檢查 (CVE-2021-4197)

* 核心:sk_peer_pid 和 sk_peer_cred 存取中的爭用情形 (CVE-2021-4203)

* 核心:基於 ICMP 片段所需的封包回覆 (CVE-2021-20322) 的新 DNS 快取中毒攻擊

* 核心:arm:SIGPAGE 資訊洩漏弱點 (CVE-2021-21781)

* hw: cpu:(CVE-2021-26401) 的 CVE-2017-5715 LFENCE/JMP 緩解更新

* 核心:由於不正確的 BPF JIT 分支位移計算導致本機權限提升 (CVE-2021-29154)

* 核心:在 drivers/net/usb/hso.c 的 hso_free_net_device() 中釋放後使用 (CVE-2021-37159)

* 核心:在 kernel/bpf/stackmap.c 中,prealloc_elems_and_freelist() 中的 eBPF 乘法整數溢位導致越界寫入 (CVE-2021-41864)

* 核心:firedtv 驅動程式中的堆積緩衝區溢位 (CVE-2021-42739)

* 核心:ppc: kvm:允許惡意 KVM 客體當機主機 (CVE-2021-43056)

* 核心:在 drivers/isdn/capi/kcapi.c () 中detach_capi_ctr的陣列索引出界 (CVE-2021-43389)

* 核心:drivers/net/wireless/marvell/mwifiex/usb.c 中的 mwifiex_usb_recv() 允許攻擊者透過特製的 USB 裝置 (CVE-2021-43976) 造成 DoS

* 核心:TEE 子系統中的釋放後使用 (CVE-2021-44733)

* 核心:IPv6 實作中的資訊洩露 (CVE-2021-45485)

* 核心:IPv4 實作中的資訊洩露 (CVE-2021-45486)

* hw: cpu: intel: 分支歷史插入 (BHI) (CVE-2022-0001)

* hw: cpu: intel: 模式內 BTI (CVE-2022-0002)

* 核心:bond_ipsec_add_sa (CVE-2022-0286) 中的本地拒絕服務

* 核心:net/sctp/sm_make_chunk.c (CVE-2022-0322) 中sctp_addto_chunk中的 DoS

* 核心:FUSE 允許 UAF 讀取 write() 緩衝區,進而允許竊取 (部分) /etc/shadow 雜湊 (CVE-2022-1011)

* 核心:nouveau 核心模組 (CVE-2020-27820) 中的釋放後使用

Tenable 已直接從 CIQ 安全性公告中擷取上述描述區塊。

請注意,Nessus 並未測試這些問題,而是僅依據應用程式自我報告的版本號碼作出判斷。

解決方案

根據 CIQ 公告 crlsa-2022_1988中的指引更新受影響的套件。

另請參閱

https://access.redhat.com/errata/RHSA-2022:1988

https://bugzilla.redhat.com/show_bug.cgi?id=1888433

https://bugzilla.redhat.com/show_bug.cgi?id=1901726

https://bugzilla.redhat.com/show_bug.cgi?id=1919791

https://bugzilla.redhat.com/show_bug.cgi?id=1946684

https://bugzilla.redhat.com/show_bug.cgi?id=1951739

https://bugzilla.redhat.com/show_bug.cgi?id=1957375

https://bugzilla.redhat.com/show_bug.cgi?id=1974079

https://bugzilla.redhat.com/show_bug.cgi?id=1981950

https://bugzilla.redhat.com/show_bug.cgi?id=1983894

https://bugzilla.redhat.com/show_bug.cgi?id=1985353

https://bugzilla.redhat.com/show_bug.cgi?id=1986473

https://bugzilla.redhat.com/show_bug.cgi?id=1994390

https://bugzilla.redhat.com/show_bug.cgi?id=1997338

https://bugzilla.redhat.com/show_bug.cgi?id=1997467

https://bugzilla.redhat.com/show_bug.cgi?id=1997961

https://bugzilla.redhat.com/show_bug.cgi?id=1999544

https://bugzilla.redhat.com/show_bug.cgi?id=1999675

https://bugzilla.redhat.com/show_bug.cgi?id=2000627

https://bugzilla.redhat.com/show_bug.cgi?id=2000694

https://bugzilla.redhat.com/show_bug.cgi?id=2004949

https://bugzilla.redhat.com/show_bug.cgi?id=2009312

https://bugzilla.redhat.com/show_bug.cgi?id=2009521

https://bugzilla.redhat.com/show_bug.cgi?id=2010463

https://bugzilla.redhat.com/show_bug.cgi?id=2011104

https://bugzilla.redhat.com/show_bug.cgi?id=2013180

https://bugzilla.redhat.com/show_bug.cgi?id=2014230

https://bugzilla.redhat.com/show_bug.cgi?id=2015525

https://bugzilla.redhat.com/show_bug.cgi?id=2015755

https://bugzilla.redhat.com/show_bug.cgi?id=2016169

https://bugzilla.redhat.com/show_bug.cgi?id=2017073

https://bugzilla.redhat.com/show_bug.cgi?id=2017796

https://bugzilla.redhat.com/show_bug.cgi?id=2018205

https://bugzilla.redhat.com/show_bug.cgi?id=2022814

https://bugzilla.redhat.com/show_bug.cgi?id=2025003

https://bugzilla.redhat.com/show_bug.cgi?id=2025726

https://bugzilla.redhat.com/show_bug.cgi?id=2027239

https://bugzilla.redhat.com/show_bug.cgi?id=2029923

https://bugzilla.redhat.com/show_bug.cgi?id=2030476

https://bugzilla.redhat.com/show_bug.cgi?id=2030747

https://bugzilla.redhat.com/show_bug.cgi?id=2031200

https://bugzilla.redhat.com/show_bug.cgi?id=2034342

https://bugzilla.redhat.com/show_bug.cgi?id=2035652

https://bugzilla.redhat.com/show_bug.cgi?id=2036934

https://bugzilla.redhat.com/show_bug.cgi?id=2037019

https://bugzilla.redhat.com/show_bug.cgi?id=2039911

https://bugzilla.redhat.com/show_bug.cgi?id=2039914

https://bugzilla.redhat.com/show_bug.cgi?id=2042798

https://bugzilla.redhat.com/show_bug.cgi?id=2042822

https://bugzilla.redhat.com/show_bug.cgi?id=2043453

https://bugzilla.redhat.com/show_bug.cgi?id=2046021

https://bugzilla.redhat.com/show_bug.cgi?id=2048251

https://bugzilla.redhat.com/show_bug.cgi?id=2061700

https://bugzilla.redhat.com/show_bug.cgi?id=2061712

https://bugzilla.redhat.com/show_bug.cgi?id=2061721

https://bugzilla.redhat.com/show_bug.cgi?id=2064855

https://errata.build.resf.org/RLSA-2022:1988

http://www.nessus.org/u?5d413859

http://www.nessus.org/u?d8ab8dc8

Plugin 詳細資訊

嚴重性: Critical

ID: 357390

檔案名稱: ciq_rocky_linux_8_crlsa-2022_1988.nasl

版本: 1.1

類型: Local

已發布: 2026/10/1

已更新: 2026/10/1

支援的感應器: Continuous Assessment, Nessus Agent, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

風險資訊

VPR

風險因素: High

分數: 7.6

百分位數: 98.25

Vendor

Vendor Severity: Unknown

CVSS v2

風險因素: High

基本分數: 7.9

時間性分數: 6.2

媒介: CVSS2#AV:A/AC:M/Au:N/C:C/I:C/A:C

CVSS 評分資料來源: CVE-2021-3752

CVSS v3

風險因素: Critical

基本分數: 9.8

時間性分數: 8.8

媒介: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

時間媒介: CVSS:3.0/E:P/RL:O/RC:C

CVSS 評分資料來源: CVE-2021-3773

弱點資訊

必要的 KB 項目: Host/OS/extended-third-party, Host/local_checks_enabled, Host/RockyLinux/release, Host/RockyLinux/rpm-list, Host/cpu

可被惡意程式利用: true

可輕鬆利用: Exploits are available

修補程式發佈日期: 2022/5/10

弱點發布日期: 2020/6/9

參考資訊

CVE: CVE-2020-0404, CVE-2020-13974, CVE-2020-27820, CVE-2020-4788, CVE-2021-0941, CVE-2021-20322, CVE-2021-21781, CVE-2021-26401, CVE-2021-29154, CVE-2021-3612, CVE-2021-3669, CVE-2021-37159, CVE-2021-3743, CVE-2021-3744, CVE-2021-3752, CVE-2021-3759, CVE-2021-3764, CVE-2021-3772, CVE-2021-3773, CVE-2021-4002, CVE-2021-4037, CVE-2021-4083, CVE-2021-4093, CVE-2021-4157, CVE-2021-41864, CVE-2021-4197, CVE-2021-4203, CVE-2021-42739, CVE-2021-43056, CVE-2021-43389, CVE-2021-43976, CVE-2021-44733, CVE-2021-45485, CVE-2021-45486, CVE-2022-0001, CVE-2022-0002, CVE-2022-0286, CVE-2022-0322, CVE-2022-1011