AlmaLinux 9.2 [TuxCare] 安全性更新:bpftool / kernel / kernel-abi-stablelists / kernel-core / etc 多個弱點 (ALMALINUX9.2:CLSA-2026:1778266904)

high Nessus Plugin ID 361258

概要

AlmaLinux 主機缺少一或多個安全性更新。

說明

AlmaLinux 9.2 主機已安裝的套件會受到 TuxCare ALMALINUX9.2:CLSA-2026:1778266904 公告中提及的多個弱點影響。

- 已解決 Linux 核心中的下列弱點:samples/landlock: Fix path_list memory leak Clang static analysis reports this error sandboxer.c:134:8: warning: Potential leak of memory pointed to by 'path_list' ret = 0; ^ path_list is allocated in parse_path() but never freed. (CVE-2021-47654)

- 已解決 Linux 核心中的下列弱點:tty: synclink_gt: Fix null-pointer-dereference in slgt_clean() When the driver fails at alloc_hdlcdev(), and then we remove the driver module, we will get the following splat: [ 25.065966] general protection fault, probably for non-canonical address 0xdffffc0000000182: 0000 [#1] PREEMPT SMP KASAN PTI [ 25.066914] KASAN: null-ptr-deref in range [0x0000000000000c10-0x0000000000000c17] [ 25.069262] RIP: 0010:detach_hdlc_protocol+0x2a/0x3e0 [25.077709] Call Trace: [ 25.077924] <TASK> [ 25.078108] unregister_hdlc_device+0x16/0x30 [ 25.078481] slgt_cleanup+0x157/0x9f0 [synclink_gt] Fix this by checking whether the 'info->netdev' is a null pointer first. (CVE-2022-49307)

- 已解決 Linux 核心中的下列弱點:ima: Fix potential memory leak in ima_init_crypto() On failure to allocate the SHA1 tfm, IMA fails to initialize and exits without freeing the ima_algo_array. Add the missing kfree() for ima_algo_array to avoid the potential memory leak.
(CVE-2022-49627)

- 已解決 Linux 核心中的下列弱點:tracing/histograms: Fix memory leak problem This reverts commit 46bbe5c671e06f070428b9be142cc4ee5cedebac. As commit 46bbe5c671e0 (tracing:
fix double free) said, the double free problem reported by clang static analyzer is: > In parse_var_defs() if there is a problem allocating > var_defs.expr, the earlier var_defs.name is freed. > This free is duplicated by free_var_defs() which frees > the rest of the list. However, if there is a problem allocating N-th var_defs.expr: + in parse_var_defs(), the freed 'earlier var_defs.name' is actually the N-th var_defs.name; + then in free_var_defs(), the names from 0th to (N-1)-th are freed; IF ALLOCATING PROBLEM HAPPENED HERE!!! -+ \ | 0th 1th (N-1)-th N-th V +-------------+-------------+-----+-------------+----------- var_defs: | name | expr | name | expr | ... | name | expr | name | /// +-------------+-------------+-----+-------------+----------- These two frees don't act on same name, so there was no double free problem before. Conversely, after that commit, we get a memory leak problem because the above N-th var_defs.name is not freed. If enable CONFIG_DEBUG_KMEMLEAK and inject a fault at where the N-th var_defs.expr allocated, then execute on shell like: $ echo 'hist:key=call_site:val=$v1,$v2:v1=bytes_req,v2=bytes_alloc' > \ /sys/kernel/debug/tracing/events/kmem/kmalloc/trigger Then kmemleak reports: unreferenced object 0xffff8fb100ef3518 (size 8): comm bash, pid 196, jiffies 4295681690 (age 28.538s) hex dump (first 8 bytes): 76 31 00 00 b1 8f ff ff v1...... backtrace: [<0000000038fe4895>] kstrdup+0x2d/0x60 [<00000000c99c049a>] event_hist_trigger_parse+0x206f/0x20e0 [<00000000ae70d2cc>] trigger_process_regex+0xc0/0x110 [<0000000066737a4c>] event_trigger_write+0x75/0xd0 [<000000007341e40c>] vfs_write+0xbb/0x2a0 [<0000000087fde4c2>] ksys_write+0x59/0xd0 [<00000000581e9cdf>] do_syscall_64+0x3a/0x80 [<00000000cf3b065c>] entry_SYSCALL_64_after_hwframe+0x46/0xb0 (CVE-2022-49648)

- 已解決 Linux 核心中的下列弱點:linux/dim: Fix divide by 0 in RDMA DIM Fix a divide 0 error in rdma_dim_stats_compare() when prev->cpe_ratio == 0. CallTrace: Hardware name: H3C R4900 G3/RS33M2C9S, BIOS 2.00.37P21 03/12/2020 task: ffff880194b78000 task.stack: ffffc90006714000 RIP:
0010:backport_rdma_dim+0x10e/0x240 [mlx_compat] RSP: 0018:ffff880c10e83ec0 EFLAGS: 00010202 RAX:
0000000000002710 RBX: ffff88096cd7f780 RCX: 0000000000000064 RDX: 0000000000000000 RSI: 0000000000000002 RDI: 0000000000000001 RBP: 0000000000000001 R08: 0000000000000000 R09: 0000000000000000 R10:
0000000000000000 R11: 0000000000000000 R12: 000000001d7c6c09 R13: ffff88096cd7f780 R14: ffff880b174fe800 R15: 0000000000000000 FS: 0000000000000000(0000) GS:ffff880c10e80000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 00000000a0965b00 CR3: 000000000200a003 CR4: 00000000007606e0 DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 DR3: 0000000000000000 DR6:
00000000fffe0ff0 DR7: 0000000000000400 PKRU: 55555554 Call Trace: <IRQ> ib_poll_handler+0x43/0x80 [ib_core] irq_poll_softirq+0xae/0x110 __do_softirq+0xd1/0x28c irq_exit+0xde/0xf0 do_IRQ+0x54/0xe0 common_interrupt+0x8f/0x8f </IRQ> ? cpuidle_enter_state+0xd9/0x2a0 ? cpuidle_enter_state+0xc7/0x2a0 ? do_idle+0x170/0x1d0 ? cpu_startup_entry+0x6f/0x80 ? start_secondary+0x1b9/0x210 ? secondary_startup_64+0xa5/0xb0 Code: 0f 87 e1 00 00 00 8b 4c 24 14 44 8b 43 14 89 c8 4d 63 c8 44 29 c0 99 31 d0 29 d0 31 d2 48 98 48 8d 04 80 48 8d 04 80 48 c1 e0 02 <49> f7 f1 48 83 f8 0a 0f 86 c1 00 00 00 44 39 c1 7f 10 48 89 df RIP: backport_rdma_dim+0x10e/0x240 [mlx_compat] RSP: ffff880c10e83ec0 (CVE-2022-49670)

請注意,Nessus 並未測試這些問題,而是僅依據應用程式自我報告的版本號碼作出判斷。

解決方案

根據 TuxCare 公告 ALMALINUX9.2:CLSA-2026:1778266904 中的指引更新受影響的套件。

另請參閱

https://cve.tuxcare.com/els/releases/CLSA-2026:1778266904

http://www.nessus.org/u?2c3b3881

Plugin 詳細資訊

嚴重性: High

ID: 361258

檔案名稱: tuxcare_alma_linux_9.2_CLSA-2026-1778266904.nasl

版本: 1.2

類型: Local

已發布: 2026/10/1

已更新: 2026/10/2

支援的感應器: Continuous Assessment, Nessus Agent, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

風險資訊

VPR

風險因素: Critical

分數: 9.5

百分位數: 99.87

Vendor

Vendor Severity: Important

CVSS v2

風險因素: Medium

基本分數: 6.8

時間性分數: 5.9

媒介: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS 評分資料來源: CVE-2026-31581

CVSS v3

風險因素: High

基本分數: 7.8

時間性分數: 7.5

媒介: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

時間媒介: CVSS:3.0/E:H/RL:O/RC:C

弱點資訊

必要的 KB 項目: Host/OS/extended-third-party, Host/local_checks_enabled, Host/AlmaLinux/release, Host/AlmaLinux/rpm-list, Host/cpu

可被惡意程式利用: true

可輕鬆利用: Exploits are available

修補程式發佈日期: 2026/5/8

弱點發布日期: 2021/7/21

可惡意利用

Core Impact

Metasploit (xfrm-ESP Page-Cache Write via CVE-2026-43284)

參考資訊

CVE: CVE-2021-47430, CVE-2021-47654, CVE-2022-48972, CVE-2022-49002, CVE-2022-49021, CVE-2022-49148, CVE-2022-49187, CVE-2022-49307, CVE-2022-49481, CVE-2022-49627, CVE-2022-49648, CVE-2022-49670, CVE-2022-49672, CVE-2022-49748, CVE-2022-49785, CVE-2022-49801, CVE-2022-49802, CVE-2022-49803, CVE-2022-49832, CVE-2022-49863, CVE-2022-49869, CVE-2022-49871, CVE-2022-50108, CVE-2022-50222, CVE-2022-50280, CVE-2022-50282, CVE-2022-50304, CVE-2022-50319, CVE-2022-50321, CVE-2022-50346, CVE-2022-50349, CVE-2022-50365, CVE-2022-50380, CVE-2022-50387, CVE-2022-50409, CVE-2022-50505, CVE-2022-50625, CVE-2022-50640, CVE-2022-50645, CVE-2022-50724, CVE-2022-50825, CVE-2022-50856, CVE-2022-50879, CVE-2023-52486, CVE-2023-52560, CVE-2023-52580, CVE-2023-52619, CVE-2023-52743, CVE-2023-52912, CVE-2023-52936, CVE-2023-52976, CVE-2023-52979, CVE-2023-53101, CVE-2023-53143, CVE-2023-53237, CVE-2023-53290, CVE-2023-53518, CVE-2023-53768, CVE-2023-53844, CVE-2023-53992, CVE-2023-54003, CVE-2023-54010, CVE-2023-54083, CVE-2023-54260, CVE-2023-54268, CVE-2023-54312, CVE-2024-26660, CVE-2024-26717, CVE-2024-26774, CVE-2024-26835, CVE-2024-26900, CVE-2024-27015, CVE-2024-35925, CVE-2024-35933, CVE-2024-36286, CVE-2024-36930, CVE-2024-36954, CVE-2024-38596, CVE-2024-39468, CVE-2024-39509, CVE-2024-40919, CVE-2024-40960, CVE-2024-40961, CVE-2024-41060, CVE-2024-41095, CVE-2024-42090, CVE-2024-42098, CVE-2024-42106, CVE-2024-42288, CVE-2024-43828, CVE-2024-43856, CVE-2024-43861, CVE-2024-44948, CVE-2024-45018, CVE-2024-46719, CVE-2024-46791, CVE-2024-46794, CVE-2024-46805, CVE-2024-46819, CVE-2024-47668, CVE-2024-47671, CVE-2024-47673, CVE-2024-47710, CVE-2024-49858, CVE-2024-49866, CVE-2024-49890, CVE-2024-49896, CVE-2024-49911, CVE-2024-49962, CVE-2024-49977, CVE-2024-50001, CVE-2024-50019, CVE-2024-50044, CVE-2024-50049, CVE-2024-50075, CVE-2024-50078, CVE-2024-50082, CVE-2024-50153, CVE-2024-50179, CVE-2024-50201, CVE-2024-50272, CVE-2024-50299, CVE-2024-50304, CVE-2024-53066, CVE-2024-53120, CVE-2024-53161, CVE-2024-53217, CVE-2024-56533, CVE-2024-56589, CVE-2024-56593, CVE-2024-56629, CVE-2024-56636, CVE-2024-56645, CVE-2024-56688, CVE-2024-56716, CVE-2024-56747, CVE-2024-56748, CVE-2024-56763, CVE-2024-57986, CVE-2024-58017, CVE-2024-58090, CVE-2025-21689, CVE-2025-21699, CVE-2025-21745, CVE-2025-21848, CVE-2025-21924, CVE-2025-21948, CVE-2025-21996, CVE-2025-21997, CVE-2025-22044, CVE-2025-22045, CVE-2025-22086, CVE-2025-22103, CVE-2025-23136, CVE-2025-37757, CVE-2025-37788, CVE-2025-37792, CVE-2025-37794, CVE-2025-37857, CVE-2025-38408, CVE-2025-38544, CVE-2025-38664, CVE-2025-38668, CVE-2025-40040, CVE-2025-68340, CVE-2025-71125, CVE-2025-71182, CVE-2025-71235, CVE-2026-23021, CVE-2026-23190, CVE-2026-23335, CVE-2026-23439, CVE-2026-31503, CVE-2026-31510, CVE-2026-31515, CVE-2026-31521, CVE-2026-31523, CVE-2026-31540, CVE-2026-31581, CVE-2026-31592, CVE-2026-31624, CVE-2026-31625, CVE-2026-31634, CVE-2026-31651, CVE-2026-31661, CVE-2026-31664, CVE-2026-31671, CVE-2026-31672, CVE-2026-43284

CLSA: 2026:1778266904