AlmaLinux 9.2 [TuxCare] 安全性更新:bpftool / kernel / kernel-abi-stablelists / kernel-core / etc 多個弱點 (ALMALINUX9.2:CLSA-2026:1787935638)

high Nessus Plugin ID 361746

概要

AlmaLinux 主機缺少一或多個安全性更新。

說明

AlmaLinux 9.2 主機已安裝的套件會受到 TuxCare ALMALINUX9.2:CLSA-2026:1787935638 公告中提及的多個弱點影響。

- 已解決 Linux 核心中的下列弱點:fs/mount_setattr: always cleanup mount_kattr Make sure that finish_mount_kattr() is called after mount_kattr was succesfully built in both the success and failure case to prevent leaking any references we took when we built it. We returned early if path lookup failed thereby risking to leak an additional reference we took when building mount_kattr when an idmapped mount was requested. (CVE-2021-46923)

- 已解決 Linux 核心中的下列弱點:vdpa: ifcvf: Do proper cleanup if IFCVF init fails ifcvf_mgmt_dev leaks memory if it is not freed before returning. Call is made to correct return statement so memory does not leak. ifcvf_init_hw does not take care of this so it is needed to do it here. (CVE-2022-48706)

- 已解決 Linux 核心中的下列弱點:tracing/histogram: Fix a potential memory leak for kstrdup() kfree() is missing on an error path to free the memory allocated by kstrdup(): p = param = kstrdup(data->params[i], GFP_KERNEL); So it is better to free it via kfree(p). (CVE-2022-48768)

- 已解決 Linux 核心中的下列弱點:efi: fix NULL-deref in init error path In cases where runtime services are not supported or have been disabled, the runtime services workqueue will never have been allocated. Do not try to destroy the workqueue unconditionally in the unlikely event that EFI initialisation fails to avoid dereferencing a NULL pointer. (CVE-2022-48879)

- 已解決 Linux 核心中的下列弱點:RDMA/srp: Do not call scsi_done() from srp_abort() After scmd_eh_abort_handler() has called the SCSI LLD eh_abort_handler callback, it performs one of the following actions: * Call scsi_queue_insert(). * Call scsi_finish_command(). * Call scsi_eh_scmd_add(). Hence, SCSI abort handlers must not call scsi_done(). Otherwise all the above actions would trigger a use-after-free. Hence remove the scsi_done() call from srp_abort(). Keep the srp_free_req() call before returning SUCCESS because we may not see the command again if SUCCESS is returned. (CVE-2023-52515)

請注意,Nessus 並未測試這些問題,而是僅依據應用程式自我報告的版本號碼作出判斷。

解決方案

根據 TuxCare 公告 ALMALINUX9.2:CLSA-2026:1787935638 中的指引更新受影響的套件。

另請參閱

https://cve.tuxcare.com/els/releases/CLSA-2026:1787935638

http://www.nessus.org/u?05e487ee

Plugin 詳細資訊

嚴重性: High

ID: 361746

檔案名稱: tuxcare_alma_linux_9.2_CLSA-2026-1787935638.nasl

版本: 1.1

類型: Local

已發布: 2026/10/1

已更新: 2026/10/1

支援的感應器: Continuous Assessment, Nessus Agent, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

風險資訊

VPR

風險因素: High

分數: 7.9

百分位數: 99.35

Vendor

Vendor Severity: Important

CVSS v2

風險因素: High

基本分數: 7.2

時間性分數: 5.6

媒介: CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C

CVSS 評分資料來源: CVE-2026-53196

CVSS v3

風險因素: High

基本分數: 7.8

時間性分數: 7

媒介: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

時間媒介: CVSS:3.0/E:P/RL:O/RC:C

CVSS 評分資料來源: CVE-2026-64225

CVSS v4

風險因素: High

Base Score: 7.3

Threat Score: 6.4

Threat Vector: CVSS:4.0/E:P

Vector: CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

CVSS 評分資料來源: CVE-2025-54518

弱點資訊

必要的 KB 項目: Host/OS/extended-third-party, Host/local_checks_enabled, Host/AlmaLinux/release, Host/AlmaLinux/rpm-list, Host/cpu

可被惡意程式利用: true

可輕鬆利用: Exploits are available

修補程式發佈日期: 2026/8/28

弱點發布日期: 2021/7/21

參考資訊

CVE: CVE-2021-46923, CVE-2022-48706, CVE-2022-48768, CVE-2022-48879, CVE-2022-49030, CVE-2023-52515, CVE-2023-52910, CVE-2023-52913, CVE-2023-53582, CVE-2024-43854, CVE-2024-49948, CVE-2024-50039, CVE-2024-56720, CVE-2025-21673, CVE-2025-38264, CVE-2025-40048, CVE-2025-54518, CVE-2025-68815, CVE-2026-23007, CVE-2026-23278, CVE-2026-31392, CVE-2026-31393, CVE-2026-31530, CVE-2026-31679, CVE-2026-43060, CVE-2026-43062, CVE-2026-43071, CVE-2026-43187, CVE-2026-43469, CVE-2026-43501, CVE-2026-45838, CVE-2026-45839, CVE-2026-45840, CVE-2026-45841, CVE-2026-45842, CVE-2026-45847, CVE-2026-45850, CVE-2026-45856, CVE-2026-45857, CVE-2026-45886, CVE-2026-45948, CVE-2026-45964, CVE-2026-45983, CVE-2026-45987, CVE-2026-46015, CVE-2026-46018, CVE-2026-46021, CVE-2026-46023, CVE-2026-46040, CVE-2026-46049, CVE-2026-46056, CVE-2026-46082, CVE-2026-46088, CVE-2026-46101, CVE-2026-46108, CVE-2026-46119, CVE-2026-46128, CVE-2026-46132, CVE-2026-46151, CVE-2026-46161, CVE-2026-46167, CVE-2026-46172, CVE-2026-46177, CVE-2026-46184, CVE-2026-46189, CVE-2026-46191, CVE-2026-46197, CVE-2026-46218, CVE-2026-46220, CVE-2026-46234, CVE-2026-46249, CVE-2026-46259, CVE-2026-46294, CVE-2026-52920, CVE-2026-52935, CVE-2026-52947, CVE-2026-52948, CVE-2026-52955, CVE-2026-52957, CVE-2026-52962, CVE-2026-52963, CVE-2026-52969, CVE-2026-52970, CVE-2026-52972, CVE-2026-52985, CVE-2026-52993, CVE-2026-53002, CVE-2026-53012, CVE-2026-53016, CVE-2026-53022, CVE-2026-53037, CVE-2026-53064, CVE-2026-53072, CVE-2026-53075, CVE-2026-53080, CVE-2026-53093, CVE-2026-53135, CVE-2026-53136, CVE-2026-53168, CVE-2026-53176, CVE-2026-53177, CVE-2026-53181, CVE-2026-53195, CVE-2026-53196, CVE-2026-53212, CVE-2026-53218, CVE-2026-53219, CVE-2026-53223, CVE-2026-53227, CVE-2026-53228, CVE-2026-53238, CVE-2026-53239, CVE-2026-53245, CVE-2026-53249, CVE-2026-53254, CVE-2026-53255, CVE-2026-53256, CVE-2026-53263, CVE-2026-53268, CVE-2026-53269, CVE-2026-53287, CVE-2026-53295, CVE-2026-53304, CVE-2026-53337, CVE-2026-53391, CVE-2026-63800, CVE-2026-63945, CVE-2026-64174, CVE-2026-64225, CVE-2026-64237, CVE-2026-64572, CVE-2026-64576, CVE-2026-64579, CVE-2026-68093, CVE-2026-68108, CVE-2026-68121, CVE-2026-68142, CVE-2026-68143, CVE-2026-68153, CVE-2026-68155, CVE-2026-68156, CVE-2026-68160, CVE-2026-68188, CVE-2026-68189, CVE-2026-68313, CVE-2026-68315, CVE-2026-68320, CVE-2026-68324, CVE-2026-68363, CVE-2026-68377, CVE-2026-68388, CVE-2026-68398, CVE-2026-68402, CVE-2026-68414, CVE-2026-68426, CVE-2026-72396, CVE-2026-74499

CLSA: 2026:1787935638