AlmaLinux 9.6 [TuxCare] 安全性更新:kernel / kernel-abi-stablelists / kernel-core / etc 多個弱點 (ALMALINUX9.6:CLSA-2026:1782155469)

high Nessus Plugin ID 359640

概要

AlmaLinux 主機缺少一或多個安全性更新。

說明

AlmaLinux 9.6 主機已安裝的套件會受到 TuxCare ALMALINUX9.6:CLSA-2026:1782155469 公告中提及的多個弱點影響。

- 已解決 Linux 核心中的下列弱點:udf: Fix preallocation discarding at indirect extent boundary When preallocation extent is the first one in the extent block, the code would corrupt extent tree header instead. Fix the problem and use udf_delete_aext() for deleting extent to avoid some code duplication. (CVE-2022-48946)

- 已解決 Linux 核心中的下列弱點:xen/privcmd: fix error exit of privcmd_ioctl_dm_op() The error exit of privcmd_ioctl_dm_op() is calling unlock_pages() potentially with pages being NULL, leading to a NULL dereference. Additionally lock_pages() doesn't check for pin_user_pages_fast() having been completely successful, resulting in potentially not locking all pages into memory. This could result in sporadic failures when using the related memory in user mode. Fix all of that by calling unlock_pages() always with the real number of pinned pages, which will be zero in case pages being NULL, and by checking the number of pages pinned by pin_user_pages_fast() matching the expected number of pages. (CVE-2022-49989)

- 已解決 Linux 核心中的下列弱點:platform/x86: mxm-wmi: fix memleak in mxm_wmi_call_mx[ds|mx]() The ACPI buffer memory (out.pointer) returned by wmi_evaluate_method() is not freed after the call, so it leads to memory leak. The method results in ACPI buffer is not used, so just pass NULL to wmi_evaluate_method() which fixes the memory leak. (CVE-2022-50521)

- 已解決 Linux 核心中的下列弱點:net: USB: Fix wrong-direction WARNING in plusb.c The syzbot fuzzer detected a bug in the plusb network driver: A zero-length control-OUT transfer was treated as a read instead of a write. In modern kernels this error provokes a WARNING: usb 1-1: BOGUS control dir, pipe 80000280 doesn't match bRequestType c0 WARNING: CPU: 0 PID: 4645 at drivers/usb/core/urb.c:411 usb_submit_urb+0x14a7/0x1880 drivers/usb/core/urb.c:411 Modules linked in: CPU:
1 PID: 4645 Comm: dhcpcd Not tainted 6.2.0-rc6-syzkaller-00050-g9f266ccaa2f5 #0 Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/12/2023 RIP: 0010:usb_submit_urb+0x14a7/0x1880 drivers/usb/core/urb.c:411 ... Call Trace: <TASK> usb_start_wait_urb+0x101/0x4b0 drivers/usb/core/message.c:58 usb_internal_control_msg drivers/usb/core/message.c:102 [inline] usb_control_msg+0x320/0x4a0 drivers/usb/core/message.c:153 __usbnet_read_cmd+0xb9/0x390 drivers/net/usb/usbnet.c:2010 usbnet_read_cmd+0x96/0xf0 drivers/net/usb/usbnet.c:2068 pl_vendor_req drivers/net/usb/plusb.c:60 [inline] pl_set_QuickLink_features drivers/net/usb/plusb.c:75 [inline] pl_reset+0x2f/0xf0 drivers/net/usb/plusb.c:85 usbnet_open+0xcc/0x5d0 drivers/net/usb/usbnet.c:889
__dev_open+0x297/0x4d0 net/core/dev.c:1417 __dev_change_flags+0x587/0x750 net/core/dev.c:8530 dev_change_flags+0x97/0x170 net/core/dev.c:8602 devinet_ioctl+0x15a2/0x1d70 net/ipv4/devinet.c:1147 inet_ioctl+0x33f/0x380 net/ipv4/af_inet.c:979 sock_do_ioctl+0xcc/0x230 net/socket.c:1169 sock_ioctl+0x1f8/0x680 net/socket.c:1286 vfs_ioctl fs/ioctl.c:51 [inline] __do_sys_ioctl fs/ioctl.c:870 [inline] __se_sys_ioctl fs/ioctl.c:856 [inline] __x64_sys_ioctl+0x197/0x210 fs/ioctl.c:856 do_syscall_x64 arch/x86/entry/common.c:50 [inline] do_syscall_64+0x39/0xb0 arch/x86/entry/common.c:80 entry_SYSCALL_64_after_hwframe+0x63/0xcd The fix is to call usbnet_write_cmd() instead of usbnet_read_cmd() and remove the USB_DIR_IN flag. (CVE-2023-52742)

- 已解決 Linux 核心中的下列弱點:tracing: Make sure trace_printk() can output as soon as it can be used Currently trace_printk() can be used as soon as early_trace_init() is called from start_kernel(). But if a crash happens, and ftrace_dump_on_oops is set on the kernel command line, all you get will be: [ 0.456075] <idle>-0 0dN.2. 347519us : Unknown type 6 [ 0.456075] <idle>-0 0dN.2. 353141us : Unknown type 6 [ 0.456075] <idle>-0 0dN.2. 358684us : Unknown type 6 This is because the trace_printk() event (type 6) hasn't been registered yet. That gets done via an early_initcall(), which may be early, but not early enough. Instead of registering the trace_printk() event (and other ftrace events, which are not trace events) via an early_initcall(), have them registered at the same time that trace_printk() can be used. This way, if there is a crash before early_initcall(), then the trace_printk()s will actually be useful. (CVE-2023-53007)

請注意,Nessus 並未測試這些問題,而是僅依據應用程式自我報告的版本號碼作出判斷。

解決方案

根據 TuxCare 公告 ALMALINUX9.6:CLSA-2026:1782155469 中的指引更新受影響的套件。

另請參閱

https://cve.tuxcare.com/els/releases/CLSA-2026:1782155469

http://www.nessus.org/u?7eb50f9f

Plugin 詳細資訊

嚴重性: High

ID: 359640

檔案名稱: tuxcare_alma_linux_9.6_CLSA-2026-1782155469.nasl

版本: 1.1

類型: Local

已發布: 2026/10/1

已更新: 2026/10/1

支援的感應器: Continuous Assessment, Nessus Agent, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

風險資訊

VPR

風險因素: High

分數: 7.7

百分位數: 98.99

Vendor

Vendor Severity: Important

CVSS v2

風險因素: Medium

基本分數: 6.8

時間性分數: 5.6

媒介: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS 評分資料來源: CVE-2026-23013

CVSS v3

風險因素: High

基本分數: 7.8

時間性分數: 7.2

媒介: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

時間媒介: CVSS:3.0/E:F/RL:O/RC:C

弱點資訊

必要的 KB 項目: Host/OS/extended-third-party, Host/local_checks_enabled, Host/AlmaLinux/release, Host/AlmaLinux/rpm-list, Host/cpu

可被惡意程式利用: true

可輕鬆利用: Exploits are available

修補程式發佈日期: 2026/6/22

弱點發布日期: 2021/7/21

CISA 已知遭惡意利用弱點到期日: 2026/9/21

參考資訊

CVE: CVE-2022-48946, CVE-2022-48972, CVE-2022-49779, CVE-2022-49989, CVE-2022-50365, CVE-2022-50521, CVE-2023-52742, CVE-2023-52808, CVE-2023-53007, CVE-2023-53548, CVE-2024-35803, CVE-2024-36286, CVE-2024-41088, CVE-2024-42232, CVE-2024-42290, CVE-2024-43835, CVE-2024-47809, CVE-2024-50012, CVE-2024-50060, CVE-2024-53172, CVE-2024-53219, CVE-2024-56645, CVE-2024-56739, CVE-2024-56770, CVE-2024-57948, CVE-2024-58096, CVE-2024-58097, CVE-2025-21681, CVE-2025-21731, CVE-2025-21817, CVE-2025-21857, CVE-2025-21870, CVE-2025-22090, CVE-2025-37761, CVE-2025-37808, CVE-2025-37914, CVE-2025-38048, CVE-2025-38053, CVE-2025-38064, CVE-2025-38105, CVE-2025-38154, CVE-2025-38161, CVE-2025-38264, CVE-2025-38385, CVE-2025-38460, CVE-2025-38653, CVE-2025-38665, CVE-2025-38681, CVE-2025-38710, CVE-2025-39721, CVE-2025-39925, CVE-2025-39947, CVE-2025-39964, CVE-2025-40167, CVE-2025-40186, CVE-2025-40194, CVE-2025-40259, CVE-2025-40308, CVE-2025-40331, CVE-2025-68366, CVE-2025-68724, CVE-2025-68803, CVE-2025-68813, CVE-2025-68814, CVE-2025-68815, CVE-2025-68820, CVE-2025-71077, CVE-2025-71083, CVE-2025-71084, CVE-2025-71087, CVE-2025-71095, CVE-2025-71096, CVE-2025-71097, CVE-2025-71099, CVE-2025-71122, CVE-2025-71132, CVE-2025-71137, CVE-2025-71142, CVE-2025-71182, CVE-2025-71227, CVE-2025-71235, CVE-2025-71236, CVE-2025-71273, CVE-2026-22979, CVE-2026-22989, CVE-2026-22994, CVE-2026-23002, CVE-2026-23003, CVE-2026-23007, CVE-2026-23013, CVE-2026-23017, CVE-2026-23023, CVE-2026-23038, CVE-2026-23058, CVE-2026-23066, CVE-2026-23070, CVE-2026-23103, CVE-2026-23110, CVE-2026-23113, CVE-2026-23126, CVE-2026-23138, CVE-2026-23154, CVE-2026-23169, CVE-2026-23198, CVE-2026-23210, CVE-2026-23357, CVE-2026-23367, CVE-2026-23379, CVE-2026-23381, CVE-2026-23382, CVE-2026-23389, CVE-2026-23392, CVE-2026-23442, CVE-2026-23444, CVE-2026-23455, CVE-2026-31408, CVE-2026-31488, CVE-2026-31497, CVE-2026-31498, CVE-2026-31510, CVE-2026-31512, CVE-2026-31515, CVE-2026-31521, CVE-2026-31531, CVE-2026-31540, CVE-2026-31546, CVE-2026-31586, CVE-2026-31602, CVE-2026-31613, CVE-2026-31625, CVE-2026-31628, CVE-2026-31634, CVE-2026-31656, CVE-2026-31664, CVE-2026-31671, CVE-2026-31672, CVE-2026-31685, CVE-2026-31694, CVE-2026-43051, CVE-2026-43158, CVE-2026-43332

CLSA: 2026:1782155469