AlmaLinux 9.6 [TuxCare] 安全性更新:kernel / kernel-abi-stablelists / kernel-core / etc 多個弱點 (ALMALINUX9.6:CLSA-2026:1778787063)

high Nessus Plugin ID 361904

概要

AlmaLinux 主機缺少一或多個安全性更新。

說明

AlmaLinux 9.6 主機已安裝的套件會受到 TuxCare ALMALINUX9.6:CLSA-2026:1778787063 公告中提及的多個弱點影響。

- 已解決 Linux 核心中的下列弱點:can: m_can: pci: add missing m_can_class_free_dev() in probe/remove methods In m_can_pci_remove() and error handling path of m_can_pci_probe(), m_can_class_free_dev() should be called to free resource allocated by m_can_class_allocate_dev(), otherwise there will be memleak. (CVE-2022-49024)

- 已解決 Linux 核心中的下列弱點:ima: Fix a potential integer overflow in ima_appraise_measurement When the ima-modsig is enabled, the rc passed to evm_verifyxattr() may be negative, which may cause the integer overflow problem. (CVE-2022-49643)

- 已解決 Linux 核心中的下列弱點:usbnet: fix memory leak in error case usbnet_write_cmd_async() mixed up which buffers need to be freed in which error case. v2: add Fixes tag v3: fix uninitialized buf pointer (CVE-2022-49657)

- 已解決 Linux 核心中的下列弱點:can: j1939: j1939_send_one(): fix missing CAN header initialization The read access to struct canxl_frame::len inside of a j1939 created skbuff revealed a missing initialization of reserved and later filled elements in struct can_frame. This patch initializes the 8 byte CAN header with zero. (CVE-2022-49845)

- 已解決 Linux 核心中的下列弱點:misc: tifm: fix possible memory leak in tifm_7xx1_switch_media() If device_register() returns error in tifm_7xx1_switch_media(), name of kobject which is allocated in dev_set_name() called in device_add() is leaked. Never directly free @dev after calling device_register(), even if it returned an error! Always use put_device() to give up the reference initialized. (CVE-2022-50349)

請注意,Nessus 並未測試這些問題,而是僅依據應用程式自我報告的版本號碼作出判斷。

解決方案

根據 TuxCare 公告 ALMALINUX9.6:CLSA-2026:1778787063 中的指引更新受影響的套件。

另請參閱

https://cve.tuxcare.com/els/releases/CLSA-2026:1778787063

http://www.nessus.org/u?e3932354

Plugin 詳細資訊

嚴重性: High

ID: 361904

檔案名稱: tuxcare_alma_linux_9.6_CLSA-2026-1778787063.nasl

版本: 1.2

類型: Local

已發布: 2026/10/1

已更新: 2026/10/2

支援的感應器: Continuous Assessment, Nessus Agent, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

風險資訊

VPR

風險因素: Critical

分數: 9.5

百分位數: 99.87

Vendor

Vendor Severity: Important

CVSS v2

風險因素: Medium

基本分數: 6.8

時間性分數: 5.9

媒介: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS 評分資料來源: CVE-2026-46300

CVSS v3

風險因素: High

基本分數: 7.8

時間性分數: 7.5

媒介: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

時間媒介: CVSS:3.0/E:H/RL:O/RC:C

弱點資訊

必要的 KB 項目: Host/OS/extended-third-party, Host/local_checks_enabled, Host/AlmaLinux/release, Host/AlmaLinux/rpm-list, Host/cpu

可被惡意程式利用: true

可輕鬆利用: Exploits are available

修補程式發佈日期: 2026/5/14

弱點發布日期: 2021/7/21

可惡意利用

Core Impact

Metasploit (Fragnesia LPE (CVE-2026-46300))

參考資訊

CVE: CVE-2022-49024, CVE-2022-49643, CVE-2022-49657, CVE-2022-49845, CVE-2022-50282, CVE-2022-50349, CVE-2022-50387, CVE-2022-50438, CVE-2022-50476, CVE-2022-50498, CVE-2023-53062, CVE-2023-53165, CVE-2023-53629, CVE-2023-53685, CVE-2024-39494, CVE-2024-40954, CVE-2024-47679, CVE-2024-50195, CVE-2024-53052, CVE-2024-53119, CVE-2024-56606, CVE-2024-56662, CVE-2024-57981, CVE-2024-57987, CVE-2024-57993, CVE-2024-58012, CVE-2024-58062, CVE-2024-58068, CVE-2024-58077, CVE-2024-58088, CVE-2025-21636, CVE-2025-21648, CVE-2025-21649, CVE-2025-21664, CVE-2025-21665, CVE-2025-21672, CVE-2025-21683, CVE-2025-21691, CVE-2025-21728, CVE-2025-21729, CVE-2025-21744, CVE-2025-21745, CVE-2025-21750, CVE-2025-21758, CVE-2025-21766, CVE-2025-21776, CVE-2025-21779, CVE-2025-21796, CVE-2025-21830, CVE-2025-21833, CVE-2025-21838, CVE-2025-21844, CVE-2025-21847, CVE-2025-21853, CVE-2025-21861, CVE-2025-21875, CVE-2025-21877, CVE-2025-21881, CVE-2025-21885, CVE-2025-21891, CVE-2025-21909, CVE-2025-21924, CVE-2025-21941, CVE-2025-21948, CVE-2025-21951, CVE-2025-21959, CVE-2025-21971, CVE-2025-21975, CVE-2025-21981, CVE-2025-21996, CVE-2025-22008, CVE-2025-22044, CVE-2025-22057, CVE-2025-22063, CVE-2025-22075, CVE-2025-22086, CVE-2025-22103, CVE-2025-23131, CVE-2025-23136, CVE-2025-23145, CVE-2025-37757, CVE-2025-37765, CVE-2025-37766, CVE-2025-37773, CVE-2025-37792, CVE-2025-37794, CVE-2025-37801, CVE-2025-37824, CVE-2025-37859, CVE-2025-37867, CVE-2025-37877, CVE-2025-37980, CVE-2025-37994, CVE-2025-38045, CVE-2025-38096, CVE-2025-38099, CVE-2025-38193, CVE-2025-38208, CVE-2025-38430, CVE-2025-38436, CVE-2025-38439, CVE-2025-38468, CVE-2025-38474, CVE-2025-38539, CVE-2025-38643, CVE-2025-38705, CVE-2025-39705, CVE-2025-39707, CVE-2025-39745, CVE-2025-39829, CVE-2025-39851, CVE-2025-39889, CVE-2025-39902, CVE-2025-39940, CVE-2025-40164, CVE-2025-40185, CVE-2025-71116, CVE-2025-71225, CVE-2026-23076, CVE-2026-23125, CVE-2026-31493, CVE-2026-31500, CVE-2026-31551, CVE-2026-46300

CLSA: 2026:1778787063