Rocky Linux 9 [CIQ] 安全性更新:mysql / mysql-common / mysql-debuginfo / mysql-debugsource / etc 多個弱點 (crlsa-2022_6590)

medium Nessus Plugin ID 358103

概要

Rocky Linux 主機缺少一或多個安全性更新。

說明

Rocky Linux 9 主機已安裝的套件會受到 CIQ crlsa-2022_6590 公告中提及的多個弱點影響。

* mysql: 伺服器: Optimizer 多個不明漏洞 (2022 年 4 月 CPU) (CVE-2022-21412, , , CVE-2022-21435, CVE-2022-21436CVE-2022-21478CVE-2022-21437CVE-2022-21462CVE-2022-21459CVE-2022-21440CVE-2022-21438CVE-2022-21452, CVE-2022-21479CVE-2022-21414

* mysql: 伺服器: DML 不明弱點 (2022 年 4 月 CPU) (CVE-2022-21413)

* mysql: 伺服器: Replication 不明弱點 (2022 年 4 月 CPU) (CVE-2022-21415)

* mysql: InnoDB 多個不明漏洞 (2022 年 4 月 CPU) (CVE-2022-21417, CVE-2022-21418, CVE-2022-21451, CVE-2022-21423)

* mysql: 伺服器: DDL 多個不明漏洞 (2022 年 4 月 CPU) (CVE-2022-21425, CVE-2022-21444)

* mysql: 伺服器: FTS 不明弱點 (2022 年 4 月 CPU) (CVE-2022-21427)

* mysql: 伺服器:群組複製外掛程式不明弱點 (2022 年 4 月 CPU) (CVE-2022-21454)

* mysql: 伺服器: PAM Auth Plugin 不明弱點 (2022 年 7 月 CPU) (CVE-2022-21455)

* mysql: 伺服器: PAM Auth Plugin 不明弱點 (2022 年 4 月 CPU) (CVE-2022-21457)

* mysql: 伺服器: 記錄不明弱點 (2022 年 4 月 CPU) (CVE-2022-21460)

* mysql: 伺服器:Optimizer 多個不明漏洞 (CPU Jul 2022) (CVE-2022-21509, , , CVE-2022-21526, CVE-2022-21553CVE-2022-21531CVE-2022-21528CVE-2022-21556CVE-2022-21527CVE-2022-21529CVE-2022-21530, , , , , , CVE-2022-21569CVE-2022-21525

* mysql: 伺服器: Options 不明弱點 (2022 年 7 月 CPU) (CVE-2022-21515)

* mysql: InnoDB 多個不明漏洞 (2022 年 7 月 CPU) (CVE-2022-21517, CVE-2022-21537, CVE-2022-21539)

* mysql: 伺服器: 預存程序多個不明漏洞 (2022 年 7 月 CPU) (CVE-2022-21522, CVE-2022-21534)

* mysql: 伺服器: Federated 不明弱點 (2022 年 7 月 CPU) (CVE-2022-21547)

* mysql: 伺服器: 安全性: Encryption 不明弱點 (2022 年 7 月 CPU) (CVE-2022-21538)

Tenable 已直接從 CIQ 安全性公告中擷取上述描述區塊。

請注意,Nessus 並未測試這些問題,而是僅依據應用程式自我報告的版本號碼作出判斷。

解決方案

根據 CIQ 公告 crlsa-2022_6590中的指引更新受影響的套件。

另請參閱

https://access.redhat.com/errata/RHSA-2022:6590

https://bugzilla.redhat.com/show_bug.cgi?id=2082636

https://bugzilla.redhat.com/show_bug.cgi?id=2082637

https://bugzilla.redhat.com/show_bug.cgi?id=2082638

https://bugzilla.redhat.com/show_bug.cgi?id=2082639

https://bugzilla.redhat.com/show_bug.cgi?id=2082640

https://bugzilla.redhat.com/show_bug.cgi?id=2082641

https://bugzilla.redhat.com/show_bug.cgi?id=2082642

https://bugzilla.redhat.com/show_bug.cgi?id=2082643

https://bugzilla.redhat.com/show_bug.cgi?id=2082644

https://bugzilla.redhat.com/show_bug.cgi?id=2082645

https://bugzilla.redhat.com/show_bug.cgi?id=2082646

https://bugzilla.redhat.com/show_bug.cgi?id=2082647

https://bugzilla.redhat.com/show_bug.cgi?id=2082648

https://bugzilla.redhat.com/show_bug.cgi?id=2082649

https://bugzilla.redhat.com/show_bug.cgi?id=2082650

https://bugzilla.redhat.com/show_bug.cgi?id=2082651

https://bugzilla.redhat.com/show_bug.cgi?id=2082652

https://bugzilla.redhat.com/show_bug.cgi?id=2082653

https://bugzilla.redhat.com/show_bug.cgi?id=2082654

https://bugzilla.redhat.com/show_bug.cgi?id=2082655

https://bugzilla.redhat.com/show_bug.cgi?id=2082656

https://bugzilla.redhat.com/show_bug.cgi?id=2082657

https://bugzilla.redhat.com/show_bug.cgi?id=2082658

https://bugzilla.redhat.com/show_bug.cgi?id=2082659

https://bugzilla.redhat.com/show_bug.cgi?id=2115282

https://bugzilla.redhat.com/show_bug.cgi?id=2115283

https://bugzilla.redhat.com/show_bug.cgi?id=2115284

https://bugzilla.redhat.com/show_bug.cgi?id=2115285

https://bugzilla.redhat.com/show_bug.cgi?id=2115286

https://bugzilla.redhat.com/show_bug.cgi?id=2115287

https://bugzilla.redhat.com/show_bug.cgi?id=2115288

https://bugzilla.redhat.com/show_bug.cgi?id=2115289

https://bugzilla.redhat.com/show_bug.cgi?id=2115290

https://bugzilla.redhat.com/show_bug.cgi?id=2115291

https://bugzilla.redhat.com/show_bug.cgi?id=2115292

https://bugzilla.redhat.com/show_bug.cgi?id=2115293

https://bugzilla.redhat.com/show_bug.cgi?id=2115294

https://bugzilla.redhat.com/show_bug.cgi?id=2115295

https://bugzilla.redhat.com/show_bug.cgi?id=2115296

https://bugzilla.redhat.com/show_bug.cgi?id=2115297

https://bugzilla.redhat.com/show_bug.cgi?id=2115298

https://bugzilla.redhat.com/show_bug.cgi?id=2115299

https://bugzilla.redhat.com/show_bug.cgi?id=2115300

https://bugzilla.redhat.com/show_bug.cgi?id=2115301

https://bugzilla.redhat.com/show_bug.cgi?id=2122589

https://bugzilla.redhat.com/show_bug.cgi?id=2122592

https://errata.build.resf.org/RLSA-2022:6590

http://www.nessus.org/u?03de57e0

http://www.nessus.org/u?603677e9

Plugin 詳細資訊

嚴重性: Medium

ID: 358103

檔案名稱: ciq_rocky_linux_9_crlsa-2022_6590.nasl

版本: 1.1

類型: Local

已發布: 2026/10/1

已更新: 2026/10/1

支援的感應器: Continuous Assessment, Nessus Agent, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

風險資訊

VPR

風險因素: Medium

分數: 4.3

百分位數: 53.04

Vendor

Vendor Severity: Unknown

CVSS v2

風險因素: Medium

基本分數: 5.5

時間性分數: 4.1

媒介: CVSS2#AV:N/AC:L/Au:S/C:P/I:N/A:P

CVSS 評分資料來源: CVE-2022-21479

CVSS v3

風險因素: Medium

基本分數: 6.5

時間性分數: 5.7

媒介: CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H

時間媒介: CVSS:3.0/E:U/RL:O/RC:C

CVSS 評分資料來源: CVE-2022-21635

弱點資訊

必要的 KB 項目: Host/OS/extended-third-party, Host/local_checks_enabled, Host/RockyLinux/release, Host/RockyLinux/rpm-list, Host/cpu

可輕鬆利用: No known exploits are available

修補程式發佈日期: 2022/9/20

弱點發布日期: 2022/3/22

參考資訊

CVE: CVE-2022-21412, CVE-2022-21413, CVE-2022-21414, CVE-2022-21415, CVE-2022-21417, CVE-2022-21418, CVE-2022-21423, CVE-2022-21425, CVE-2022-21427, CVE-2022-21435, CVE-2022-21436, CVE-2022-21437, CVE-2022-21438, CVE-2022-21440, CVE-2022-21444, CVE-2022-21451, CVE-2022-21452, CVE-2022-21454, CVE-2022-21455, CVE-2022-21457, CVE-2022-21459, CVE-2022-21460, CVE-2022-21462, CVE-2022-21478, CVE-2022-21479, CVE-2022-21509, CVE-2022-21515, CVE-2022-21517, CVE-2022-21522, CVE-2022-21525, CVE-2022-21526, CVE-2022-21527, CVE-2022-21528, CVE-2022-21529, CVE-2022-21530, CVE-2022-21531, CVE-2022-21534, CVE-2022-21537, CVE-2022-21538, CVE-2022-21539, CVE-2022-21547, CVE-2022-21553, CVE-2022-21556, CVE-2022-21569, CVE-2022-21592, CVE-2022-21605, CVE-2022-21607, CVE-2022-21635, CVE-2022-21638, CVE-2022-21641, CVE-2023-21866, CVE-2023-21872