Rocky Linux 10 [CIQ] 安全性更新:kernel / kernel-64k / kernel-64k-core / kernel-64k-debug / etc 多個弱點 (crlsa-2025_20095)

medium Nessus Plugin ID 358707

概要

Rocky Linux 主機缺少一或多個安全性更新。

說明

Rocky Linux 10 主機已安裝的套件會受到 CIQ crlsa-2025_20095 公告中所述多個弱點的影響。

* 核心: xen: Xen hypercall 頁面未對推測性攻擊提供保護 (Xen 安全公告 466) (CVE-2024-53241)

* 核心:exfat:修正目錄項目的越界存取 (CVE-2024-53147)

* 核心:zram:修復 comp_algorithm_show() 中的 NULL 指標 (CVE-2024-53222)

* 核心:nfsd:使用 rcu_work 發布 svc_expkey/svc_export (CVE-2024-53216)

* 核心:acpi:nfit:acpi_nfit_ctl 中的 vmalloc-out-of-bounds 讀取 (CVE-2024-56662)

* 核心:bpf:透過錯誤匹配 bpf_prog/attachment RCU flavors 修正 UAF (CVE-2024-56675)

* 核心:crypto:pcrypt - 當 padata_do_parallel() 傳回 -EBUSY 時直接呼叫 crypto 層(CVE-2024-56690)

* 核心:igb:修正 igb_init_module() 中潛在的無效記憶體存取 (CVE-2024-52332)

* 核心:af_packet:修正 vlan_get_protocol_dgram() 與 MSG_PEEK (CVE-2024-57901)

* 核心:af_packet:修正 vlan_get_tci() 與 MSG_PEEK (CVE-2024-57902)

* 核心:io_uring/sqpoll:將 sqd->thread 設定為零以處理 tctx 錯誤 (CVE-2025-21633)

* 核心:ipvlan:修正 ipvlan_get_iflink() 中的釋放後使用。(CVE-2025-21652)

* 核心:sched:sch_cake:將邊界檢查新增至主機大量流量公平計數(CVE-2025-21647)

* 核心:io_uring/eventfd:確保 io_eventfd_signal() 延遲另一個 RCU 週期 (CVE-2025-21655)

* 核心:netfs:修正暫時停用快取時(非)取消複製的問題 (CVE-2024-57941)

* 核心:netfs:修正 ceph 複製以在 write-begin (CVE-2024-57942) 時快取

* 核心:zram:修復 zram 表格潛在的 UAF 問題 (CVE-2025-21671)

* 核心:pktgen:避免get_imix_entries (CVE-2025-21680) 中的越界存取

* 核心:mm:zswap:CPU hotunplug 期間正確同步釋放資源 (CVE-2025-21693)

* 核心:cachestat:修正頁面快取統計資料權限檢查 (CVE-2025-21691)

* 核心:mm:清除 mremap() 上的 uffd-wp PTE/PMD 狀態 (CVE-2025-21696)

* 核心:pfifo_tail_enqueue::當 sch->limit == 0 時放置新封包 (CVE-2025-21702)

* 核心:RDMA/mlx5:修正導致 CQE 並出現錯誤 (CVE-2025-21732) 的 ODP MR 爭用

* 核心:NFSD:修正 nfsd4_shutdown_callback 中的懸置 (CVE-2025-21795)

* 核心:NFS:修正 nfs_sysfs_link_rpc_client() 中的潛在緩衝區溢位 (CVE-2024-54456)

* 核心:Bluetooth:btrtl:檢查 btrtl_setup_realtek() 中的 NULL (CVE-2024-57987)

* 核心:wifi: brcmsmac: 將增益範圍檢查新增至 wlc_phy_iqcal_gainparams_nphy() (CVE-2024-58014)

* 核心:Bluetooth:btbcm:修正 btbcm_get_board_name() 中的 NULL 解除參照 (CVE-2024-57988)

* 核心:drm/xe/tracing:修正潛在的 TP_printk UAF (CVE-2024-49570)

* 核心:media:intel/ipu6:錯誤時移除 CPU 延遲 QoS 要求 (CVE-2024-58004)

* 核心:usbnet: ipheth:在 URB 中使用靜態 NDP16 位置 (CVE-2025-21742)

* 核心:usbnet: ipheth:修正 DPE 長度檢查中可能的溢位 (CVE-2025-21743)

* 核心:wifi:mt76:mt7925:修正 mt7925_change_vif_links 中的 NULL 解除參照檢查 (CVE-2024-57989)

* 核心:wifi: ath12k:對於超出邊界存取錯誤的修正 (CVE-2024-58015)

* 核心:wifi:ath12k:修正 ath12k_mac_assign_vif_to_vdev() 中的釋放後讀取指標 (CVE-2024-57995)

* 核心:nfsd:釋放 acl_access/acl_default 後予以清除 (CVE-2025-21796)

* 核心:workqueue:將集區與 rescuer 分開後放置 pwq (CVE-2025-21786)

* 核心:tpm:變更為 eventlog/acpi.c 中的 kvalloc() (CVE-2024-58005)

* 核心:藍牙:管理:修正 mgmt_remove_adv_monitor_syncCVE-2024-58013 () 中的 slab-use-after-free Read

* 核心:ring-buffer:驗證持續性中繼資料 subbuf 陣列 (CVE-2025-21777)

* 核心:ata:libata-sff:確保我們無法在配置的緩衝區之外寫入 (CVE-2025-21738)

* 核心:HID: core: 修復解析乘數必須位於邏輯集合中的假設 (CVE-2024-57986)

* 核心:padata:避免 reorder_work 的 UAF (CVE-2025-21726)

* 核心:vrf:在 l3mdev_l3_out() 中使用 RCU 保護 (CVE-2025-21791)

* 核心:HID:多點觸控:在mt_input_configured中新增 NULL 檢查 (CVE-2024-58020)

* 核心:i3c:dw:修正 dw_i3c_master 驅動程式中由於爭用情形造成的釋放後使用 (CVE-2024-57984)

* 核心:openvswitch:在 ovs_vport_cmd_fill_info() 中使用 RCU 保護 (CVE-2025-21761)

* 核心:sched_ext:修正不正確的自動群組移轉偵測 (CVE-2025-21771)

* 核心:usb: xhci: 修復中止特定命令期間的 NULL 指標解除參照 (CVE-2024-57981)

* 核心:memcg:修正 OOM 處理程序中的軟鎖定 (CVE-2024-57977)

* 核心:vxlan:檢查 vxlan_vnigroup_init() 傳回值 (CVE-2025-21790)

* 核心:usbnet: ipheth:修正 DPE OoB 讀取 (CVE-2025-21741)

*核心:arm64:cacheinfo:避免超出邊界寫入 cacheinfo 陣列 (CVE-2025-21785)

* 核心:ipv6:在 ip6_default_advmss() 中使用 RCU 保護 (CVE-2025-21765)

* 核心:PCI:dwc:ep:防止變更 pci_epc_set_bar() 中的 BAR 大小/旗標 (CVE-2024-58006)

* 核心:ASoC:SOF:Intel:hda-dai:確保 DAI Widget 在參數執行期間有效 (CVE-2024-58012)

* 核心:wifi:brcmfmac:檢查 of_property_read_string_index() (CVE-2025-21750) 的傳回值

* 核心:wifi:rtlwifi:移除未使用的 check_buddy_priv (CVE-2024-58072)

* 核心:rtc:pcf85063:修復 PCF85063 NVMEM 讀取中潛在的 OOB 寫入問題 (CVE-2024-58069)

* 核心:wifi:mac80211:禁止停用所有連結 (CVE-2024-58061)

* 核心:idpf:將工作佇列轉換為未繫結 (CVE-2024-58057)

* 核心:wifi:mac80211:不清除未上傳的 STA (CVE-2025-21828)

* 核心:netfilter:nf_tables:拒絕包含設定金鑰長度的 field_len 不相符的總和 (CVE-2025-21826)

* 核心:ASoC:soc-pcm:不要在 .prepare 回呼時使用 soc_pcm_ret() (CVE-2024-58077)

* 核心:crypto:不在 tegra init 失敗時傳輸 req (CVE-2024-58075)

* 核心:io_uring/uring_cmd:在準備階段無條件複製 SQE (CVE-2025-21837)

* 核心:透過某些 AMD 處理器中的瞬態執行弱點造成資訊洩漏 (CVE-2024-36350)

* 核心:某些 AMD 處理器中的瞬態執行弱點 (CVE-2024-36357)

* 核心:net/sched:cls_api:修正導致 NULL 取消參照的錯誤處理 (CVE-2025-21857)

* 核心:bpf:修正 64k 頁面核心上 arena_map_free 中的 softlockup (CVE-2025-21851)

* 核心:ibmvnic:傳送至 VIOS 後不參照 skb (CVE-2025-21855)

* 核心:smb:client:在 receive_encrypted_standard() 中新增 next_buffer 檢查 (CVE-2025-21844)

* 核心:bpf:避免在 mmap 作業期間持有 freeze_mutex (CVE-2025-21853)

* 核心:ASoC:SOF:stream-ipc:檢查 sof_ipc_msg_data() 中的 cstream 無效性 (CVE-2025-21847)

* 核心:tcp:在我們目前放置 dst 的同時放置 secpath (CVE-2025-21864)

* 核心:bpf:修正釋放 cgroup 儲存空間時的鎖死問題 (CVE-2024-58088)

* 核心:acct:從工作佇列執行上次寫入 (CVE-2025-21846)

* 核心:mm/migrate_device:不要在 migrate_device_finalize() 中新增釋放至 LRU 的 folio (CVE-2025-21861)

* 核心:io_uring:防止 opcode 推測 (CVE-2025-21863)

* 核心:fbdev: hyperv_fb:允許正常移除 framebuffer (CVE-2025-21976)

* 核心:netfilter:nft_tunnel:修正 geneve_opt 類型混淆新增 (CVE-2025-22056)

* 核心:net:ppp:在 ppp_sync_txmung 中新增對 skb 資料的邊界檢查 (CVE-2025-37749)

* microcode_ctl:來自 CVEorg 收集器 (CVE-2024-28956)

* 核心:usb:typec:ucsi:displayport:修正 NULL 指標存取 (CVE-2025-37994)

* 核心:wifi: ath12k:修正 ath12k_core_init() 中的 uaf (CVE-2025-38116)

* 核心:platform/x86:dell-wmi-sysman:修正 sysfs 回呼中的 WMI 資料區塊擷取 (CVE-2025-38412)

* 核心:dmaengine:idxd:使用 (CVE-2025-38369) 之前,請檢查 idxd wq 驅動程式配置的工作佇列可用性

* 核心:net/sched:當htb_lookup_leaf遇到空的 rbtree (CVE-2025-38468) 時傳回 NULL

Tenable 已直接從 CIQ 安全性公告中擷取上述描述區塊。

請注意,Nessus 並未測試這些問題,而是僅依據應用程式自我報告的版本號碼作出判斷。

解決方案

根據 CIQ 公告 crlsa-2025_20095中的指引更新受影響的套件。

另請參閱

https://access.redhat.com/errata/RHSA-2025:20095

https://bugzilla.redhat.com/show_bug.cgi?id=2331326

https://bugzilla.redhat.com/show_bug.cgi?id=2333985

https://bugzilla.redhat.com/show_bug.cgi?id=2334373

https://bugzilla.redhat.com/show_bug.cgi?id=2334415

https://bugzilla.redhat.com/show_bug.cgi?id=2334547

https://bugzilla.redhat.com/show_bug.cgi?id=2334548

https://bugzilla.redhat.com/show_bug.cgi?id=2334676

https://bugzilla.redhat.com/show_bug.cgi?id=2337121

https://bugzilla.redhat.com/show_bug.cgi?id=2338185

https://bugzilla.redhat.com/show_bug.cgi?id=2338211

https://bugzilla.redhat.com/show_bug.cgi?id=2338813

https://bugzilla.redhat.com/show_bug.cgi?id=2338821

https://bugzilla.redhat.com/show_bug.cgi?id=2338828

https://bugzilla.redhat.com/show_bug.cgi?id=2338998

https://bugzilla.redhat.com/show_bug.cgi?id=2339130

https://bugzilla.redhat.com/show_bug.cgi?id=2339141

https://bugzilla.redhat.com/show_bug.cgi?id=2343172

https://bugzilla.redhat.com/show_bug.cgi?id=2343186

https://bugzilla.redhat.com/show_bug.cgi?id=2344684

https://bugzilla.redhat.com/show_bug.cgi?id=2344687

https://bugzilla.redhat.com/show_bug.cgi?id=2345240

https://bugzilla.redhat.com/show_bug.cgi?id=2346272

https://bugzilla.redhat.com/show_bug.cgi?id=2348522

https://bugzilla.redhat.com/show_bug.cgi?id=2348523

https://bugzilla.redhat.com/show_bug.cgi?id=2348541

https://bugzilla.redhat.com/show_bug.cgi?id=2348543

https://bugzilla.redhat.com/show_bug.cgi?id=2348547

https://bugzilla.redhat.com/show_bug.cgi?id=2348550

https://bugzilla.redhat.com/show_bug.cgi?id=2348556

https://bugzilla.redhat.com/show_bug.cgi?id=2348561

https://bugzilla.redhat.com/show_bug.cgi?id=2348567

https://bugzilla.redhat.com/show_bug.cgi?id=2348572

https://bugzilla.redhat.com/show_bug.cgi?id=2348574

https://bugzilla.redhat.com/show_bug.cgi?id=2348577

https://bugzilla.redhat.com/show_bug.cgi?id=2348581

https://bugzilla.redhat.com/show_bug.cgi?id=2348584

https://bugzilla.redhat.com/show_bug.cgi?id=2348587

https://bugzilla.redhat.com/show_bug.cgi?id=2348590

https://bugzilla.redhat.com/show_bug.cgi?id=2348592

https://bugzilla.redhat.com/show_bug.cgi?id=2348593

https://bugzilla.redhat.com/show_bug.cgi?id=2348595

https://bugzilla.redhat.com/show_bug.cgi?id=2348597

https://bugzilla.redhat.com/show_bug.cgi?id=2348600

https://bugzilla.redhat.com/show_bug.cgi?id=2348601

https://bugzilla.redhat.com/show_bug.cgi?id=2348602

https://bugzilla.redhat.com/show_bug.cgi?id=2348603

https://bugzilla.redhat.com/show_bug.cgi?id=2348612

https://bugzilla.redhat.com/show_bug.cgi?id=2348617

https://bugzilla.redhat.com/show_bug.cgi?id=2348620

https://bugzilla.redhat.com/show_bug.cgi?id=2348621

https://bugzilla.redhat.com/show_bug.cgi?id=2348625

https://bugzilla.redhat.com/show_bug.cgi?id=2348629

https://bugzilla.redhat.com/show_bug.cgi?id=2348630

https://bugzilla.redhat.com/show_bug.cgi?id=2348645

https://bugzilla.redhat.com/show_bug.cgi?id=2348647

https://bugzilla.redhat.com/show_bug.cgi?id=2348650

https://bugzilla.redhat.com/show_bug.cgi?id=2348656

https://bugzilla.redhat.com/show_bug.cgi?id=2350363

https://bugzilla.redhat.com/show_bug.cgi?id=2350364

https://bugzilla.redhat.com/show_bug.cgi?id=2350373

https://bugzilla.redhat.com/show_bug.cgi?id=2350375

https://bugzilla.redhat.com/show_bug.cgi?id=2350386

https://bugzilla.redhat.com/show_bug.cgi?id=2350392

https://bugzilla.redhat.com/show_bug.cgi?id=2350396

https://bugzilla.redhat.com/show_bug.cgi?id=2350397

https://bugzilla.redhat.com/show_bug.cgi?id=2350589

https://bugzilla.redhat.com/show_bug.cgi?id=2350725

https://bugzilla.redhat.com/show_bug.cgi?id=2350726

https://bugzilla.redhat.com/show_bug.cgi?id=2351605

https://bugzilla.redhat.com/show_bug.cgi?id=2351606

https://bugzilla.redhat.com/show_bug.cgi?id=2351608

https://bugzilla.redhat.com/show_bug.cgi?id=2351612

https://bugzilla.redhat.com/show_bug.cgi?id=2351613

https://bugzilla.redhat.com/show_bug.cgi?id=2351616

https://bugzilla.redhat.com/show_bug.cgi?id=2351618

https://bugzilla.redhat.com/show_bug.cgi?id=2351620

https://bugzilla.redhat.com/show_bug.cgi?id=2351624

https://bugzilla.redhat.com/show_bug.cgi?id=2351625

https://bugzilla.redhat.com/show_bug.cgi?id=2351629

https://bugzilla.redhat.com/show_bug.cgi?id=2356641

https://bugzilla.redhat.com/show_bug.cgi?id=2356647

https://bugzilla.redhat.com/show_bug.cgi?id=2356664

https://bugzilla.redhat.com/show_bug.cgi?id=2360215

https://bugzilla.redhat.com/show_bug.cgi?id=2363332

https://bugzilla.redhat.com/show_bug.cgi?id=2366125

https://bugzilla.redhat.com/show_bug.cgi?id=2369184

https://bugzilla.redhat.com/show_bug.cgi?id=2376076

https://bugzilla.redhat.com/show_bug.cgi?id=2383398

https://bugzilla.redhat.com/show_bug.cgi?id=2383432

https://bugzilla.redhat.com/show_bug.cgi?id=2383913

https://errata.build.resf.org/RLSA-2025:20095

http://www.nessus.org/u?282e3380

http://www.nessus.org/u?cfa7e99c

Plugin 詳細資訊

嚴重性: Medium

ID: 358707

檔案名稱: ciq_rocky_linux_10_crlsa-2025_20095.nasl

版本: 1.2

類型: Local

已發布: 2026/10/1

已更新: 2026/10/2

支援的感應器: Continuous Assessment, Nessus Agent, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

風險資訊

VPR

風險因素: High

分數: 7

百分位數: 98.48

Vendor

Vendor Severity: Unknown

CVSS v2

風險因素: Medium

基本分數: 6.8

時間性分數: 5

媒介: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS 評分資料來源: CVE-2025-38369

CVSS v3

風險因素: High

基本分數: 7.8

時間性分數: 6.8

媒介: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

時間媒介: CVSS:3.0/E:U/RL:O/RC:C

CVSS v4

風險因素: Medium

Base Score: 5.7

Threat Score: 1.9

Threat Vector: CVSS:4.0/E:U

Vector: CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

CVSS 評分資料來源: CVE-2024-28956

弱點資訊

必要的 KB 項目: Host/OS/extended-third-party, Host/local_checks_enabled, Host/RockyLinux/release, Host/RockyLinux/rpm-list, Host/cpu

可輕鬆利用: No known exploits are available

修補程式發佈日期: 2025/11/27

弱點發布日期: 2023/12/12

參考資訊

CVE: CVE-2024-28956, CVE-2024-36350, CVE-2024-36357, CVE-2024-49570, CVE-2024-52332, CVE-2024-53147, CVE-2024-53216, CVE-2024-53222, CVE-2024-53241, CVE-2024-54456, CVE-2024-56662, CVE-2024-56675, CVE-2024-56690, CVE-2024-57901, CVE-2024-57902, CVE-2024-57941, CVE-2024-57942, CVE-2024-57977, CVE-2024-57981, CVE-2024-57984, CVE-2024-57986, CVE-2024-57987, CVE-2024-57988, CVE-2024-57989, CVE-2024-57995, CVE-2024-58004, CVE-2024-58005, CVE-2024-58006, CVE-2024-58012, CVE-2024-58013, CVE-2024-58014, CVE-2024-58015, CVE-2024-58020, CVE-2024-58057, CVE-2024-58061, CVE-2024-58069, CVE-2024-58072, CVE-2024-58075, CVE-2024-58077, CVE-2024-58088, CVE-2025-21633, CVE-2025-21647, CVE-2025-21652, CVE-2025-21655, CVE-2025-21671, CVE-2025-21680, CVE-2025-21691, CVE-2025-21693, CVE-2025-21696, CVE-2025-21702, CVE-2025-21726, CVE-2025-21732, CVE-2025-21738, CVE-2025-21741, CVE-2025-21742, CVE-2025-21743, CVE-2025-21750, CVE-2025-21761, CVE-2025-21765, CVE-2025-21771, CVE-2025-21777, CVE-2025-21785, CVE-2025-21786, CVE-2025-21790, CVE-2025-21791, CVE-2025-21795, CVE-2025-21796, CVE-2025-21826, CVE-2025-21828, CVE-2025-21837, CVE-2025-21844, CVE-2025-21846, CVE-2025-21847, CVE-2025-21851, CVE-2025-21853, CVE-2025-21855, CVE-2025-21857, CVE-2025-21861, CVE-2025-21863, CVE-2025-21864, CVE-2025-21902, CVE-2025-21931, CVE-2025-21976, CVE-2025-22056, CVE-2025-37749, CVE-2025-37994, CVE-2025-38116, CVE-2025-38369, CVE-2025-38412, CVE-2025-38468