AlmaLinux 9.2 [TuxCare] 安全性更新:bpftool / kernel / kernel-abi-stablelists / kernel-core / etc 多個弱點 (ALMALINUX9.2:CLSA-2025:1742806909)

high Nessus Plugin ID 361511

概要

AlmaLinux 主機缺少一或多個安全性更新。

說明

AlmaLinux 9.2 主機已安裝的套件會受到 TuxCare ALMALINUX9.2:CLSA-2025:1742806909 公告中提及的多個弱點影響。

- 已解決 Linux 核心中的下列弱點:asix: fix uninit-value in asix_mdio_read() asix_read_cmd() may read less than sizeof(smsr) bytes and in this case smsr will be uninitialized. Fail log: BUG: KMSAN: uninit-value in asix_check_host_enable drivers/net/usb/asix_common.c:82 [inline] BUG: KMSAN: uninit-value in asix_check_host_enable drivers/net/usb/asix_common.c:82 [inline] drivers/net/usb/asix_common.c:497 BUG: KMSAN: uninit-value in asix_mdio_read+0x3c1/0xb00 drivers/net/usb/asix_common.c:497 drivers/net/usb/asix_common.c:497 asix_check_host_enable drivers/net/usb/asix_common.c:82 [inline] asix_check_host_enable drivers/net/usb/asix_common.c:82 [inline] drivers/net/usb/asix_common.c:497 asix_mdio_read+0x3c1/0xb00 drivers/net/usb/asix_common.c:497 drivers/net/usb/asix_common.c:497 (CVE-2021-47101)

- 已解決 Linux 核心中的下列弱點:vt_ioctl: fix array_index_nospec in vt_setactivate array_index_nospec ensures that an out-of-bounds value is set to zero on the transient path. Decreasing the value by one afterwards causes a transient integer underflow. vsa.console should be decreased first and then sanitized with array_index_nospec. Kasper Acknowledgements: Jakob Koschel, Brian Johannesmeyer, Kaveh Razavi, Herbert Bos, Cristiano Giuffrida from the VUSec group at VU Amsterdam.
(CVE-2022-48804)

- 已解決 Linux 核心中的下列弱點:hwmon: (coretemp) fix pci device refcount leak in nv1a_ram_new() As comment of pci_get_domain_bus_and_slot() says, it returns a pci device with refcount increment, when finish using it, the caller must decrement the reference count by calling pci_dev_put(). So call it after using to avoid refcount leak. (CVE-2022-49011)

- 已解決 Linux 核心中的下列弱點:bus: mhi: host: Add alignment check for event ring read pointer Though we do check the event ring read pointer by is_valid_ring_ptr to make sure it is in the buffer range, but there is another risk the pointer may be not aligned. Since we are expecting event ring elements are 128 bits(struct mhi_ring_element) aligned, an unaligned read pointer could lead to multiple issues like DoS or ring buffer memory corruption. So add a alignment check for event ring read pointer. (CVE-2023-52494)

- 已解決 Linux 核心中的下列弱點:ring-buffer: Do not attempt to read past commit When iterating over the ring buffer while the ring buffer is active, the writer can corrupt the reader. There's barriers to help detect this and handle it, but that code missed the case where the last event was at the very end of the page and has only 4 bytes left. The checks to detect the corruption by the writer to reads needs to see the length of the event. If the length in the first 4 bytes is zero then the length is stored in the second 4 bytes. But if the writer is in the process of updating that code, there's a small window where the length in the first 4 bytes could be zero even though the length is only 4 bytes. That will cause rb_event_length() to read the next 4 bytes which could happen to be off the allocated page. To protect against this, fail immediately if the next event pointer is less than 8 bytes from the end of the commit (last byte of data), as all events must be a minimum of 8 bytes anyway.
(CVE-2023-52501)

請注意,Nessus 並未測試這些問題,而是僅依據應用程式自我報告的版本號碼作出判斷。

解決方案

根據 TuxCare 公告 ALMALINUX9.2:CLSA-2025:1742806909 中的指引更新受影響的套件。

另請參閱

https://cve.tuxcare.com/els/releases/CLSA-2025:1742806909

http://www.nessus.org/u?cb525ea3

Plugin 詳細資訊

嚴重性: High

ID: 361511

檔案名稱: tuxcare_alma_linux_9.2_CLSA-2025-1742806909.nasl

版本: 1.1

類型: Local

已發布: 2026/10/1

已更新: 2026/10/1

支援的感應器: Continuous Assessment, Nessus Agent, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

風險資訊

VPR

風險因素: High

分數: 8.9

百分位數: 99.7

Vendor

Vendor Severity: Important

CVSS v2

風險因素: Medium

基本分數: 6.8

時間性分數: 5.6

媒介: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS 評分資料來源: CVE-2025-21692

CVSS v3

風險因素: High

基本分數: 7.8

時間性分數: 7.2

媒介: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

時間媒介: CVSS:3.0/E:F/RL:O/RC:C

弱點資訊

必要的 KB 項目: Host/OS/extended-third-party, Host/local_checks_enabled, Host/AlmaLinux/release, Host/AlmaLinux/rpm-list, Host/cpu

可被惡意程式利用: true

可輕鬆利用: Exploits are available

修補程式發佈日期: 2025/3/24

弱點發布日期: 2021/7/21

CISA 已知遭惡意利用弱點到期日: 2025/2/26, 2025/3/25

參考資訊

CVE: CVE-2021-47101, CVE-2022-48804, CVE-2022-49011, CVE-2023-52494, CVE-2023-52501, CVE-2023-52612, CVE-2023-52637, CVE-2023-52679, CVE-2023-52741, CVE-2023-52812, CVE-2023-52837, CVE-2023-52840, CVE-2023-52854, CVE-2023-52859, CVE-2024-26704, CVE-2024-26734, CVE-2024-26782, CVE-2024-26885, CVE-2024-26958, CVE-2024-26961, CVE-2024-26989, CVE-2024-27045, CVE-2024-27395, CVE-2024-35847, CVE-2024-35855, CVE-2024-35862, CVE-2024-35863, CVE-2024-35864, CVE-2024-35866, CVE-2024-35867, CVE-2024-35905, CVE-2024-35979, CVE-2024-36940, CVE-2024-39502, CVE-2024-43830, CVE-2024-44970, CVE-2024-46853, CVE-2024-50074, CVE-2024-50127, CVE-2024-50131, CVE-2024-50143, CVE-2024-50150, CVE-2024-50151, CVE-2024-50154, CVE-2024-50267, CVE-2024-50278, CVE-2024-50279, CVE-2024-50301, CVE-2024-50302, CVE-2024-53059, CVE-2024-53104, CVE-2024-53239, CVE-2024-56538, CVE-2024-56551, CVE-2024-56606, CVE-2024-56615, CVE-2024-56658, CVE-2024-57798, CVE-2025-21692, CVE-2025-21795

CLSA: 2025:1742806909