CentOS Linux 8 [TuxCare] 安全性更新:bpftool / kernel / kernel-core / kernel-cross-headers / etc多個漏洞 (CENTOS-STREAM8:CLSA-2026:1782375682)

high Nessus Plugin ID 361917

概要

CentOS Linux 主機缺少一個或多個安全性更新。

說明

CentOS Linux 8 主機已安裝的套件會受到 TuxCare CENTOS-STREAM8:CLSA-2026:1782375682 公告中提及的多個弱點影響。

- 已解決 Linux 核心中的下列弱點:bpf: Don't redirect packets with invalid pkt_len Syzbot found an issue [1]: fq_codel_drop() try to drop a flow whitout any skbs, that is, the flow->head is null. The root cause, as the [2] says, is because that bpf_prog_test_run_skb() run a bpf prog which redirects empty skbs. So we should determine whether the length of the packet modified by bpf prog or others like bpf_prog_test is valid before forwarding it directly. (CVE-2022-49975)

- 已解決 Linux 核心中的下列弱點:ASoC: SOF: debug: Fix potential buffer overflow by snprintf() snprintf() returns the would-be-filled size when the string overflows the given buffer size, hence using this value may result in the buffer overflow (although it's unrealistic). This patch replaces with a safer version, scnprintf() for papering over such a potential issue.
(CVE-2022-50051)

- 已解決 Linux 核心中的下列弱點:x86/alternatives: Disable KASAN in apply_alternatives() Fei has reported that KASAN triggers during apply_alternatives() on a 5-level paging machine: BUG: KASAN: out-of-bounds in rcu_is_watching() Read of size 4 at addr ff110003ee6419a0 by task swapper/0/0 ... __asan_load4() rcu_is_watching() trace_hardirqs_on() text_poke_early() apply_alternatives() ... On machines with 5-level paging, cpu_feature_enabled(X86_FEATURE_LA57) gets patched. It includes KASAN code, where KASAN_SHADOW_START depends on __VIRTUAL_MASK_SHIFT, which is defined with cpu_feature_enabled(). KASAN gets confused when apply_alternatives() patches the KASAN_SHADOW_START users. A test patch that makes KASAN_SHADOW_START static, by replacing
__VIRTUAL_MASK_SHIFT with 56, works around the issue. Fix it for real by disabling KASAN while the kernel is patching alternatives. [ mingo: updated the changelog ] (CVE-2023-52504)

- 已解決 Linux 核心中的下列弱點:drm/amd: Fix UBSAN array-index-out-of-bounds for SMU7 For pptable structs that use flexible array sizes, use flexible arrays. (CVE-2023-52818)

- 已解決 Linux 核心中的下列弱點:nbd: defer config unlock in nbd_genl_connect There is one use-after-free warning when running NBD_CMD_CONNECT and NBD_CLEAR_SOCK:
nbd_genl_connect nbd_alloc_and_init_config // config_refs=1 nbd_start_device // config_refs=2 set NBD_RT_HAS_CONFIG_REF open nbd // config_refs=3 recv_work done // config_refs=2 NBD_CLEAR_SOCK // config_refs=1 close nbd // config_refs=0 refcount_inc -> uaf ------------[ cut here ]------------ refcount_t: addition on 0; use-after-free. WARNING: CPU: 24 PID: 1014 at lib/refcount.c:25 refcount_warn_saturate+0x12e/0x290 nbd_genl_connect+0x16d0/0x1ab0 genl_family_rcv_msg_doit+0x1f3/0x310 genl_rcv_msg+0x44a/0x790 The issue can be easily reproduced by adding a small delay before refcount_inc(&nbd->config_refs) in nbd_genl_connect(): mutex_unlock(&nbd->config_lock); if (!ret) {set_bit(NBD_RT_HAS_CONFIG_REF, &config->runtime_flags); + printk(before sleep\n); + mdelay(5 * 1000); + printk(after sleep\n); refcount_inc(&nbd->config_refs); nbd_connect_reply(info, nbd->index); } (CVE-2025-68366)

請注意,Nessus 並未測試這些問題,而是僅依據應用程式自我報告的版本號碼作出判斷。

解決方案

根據 TuxCare 公告 CENTOS-STREAM8:CLSA-2026:1782375682 中的指引更新受影響的套件。

另請參閱

https://cve.tuxcare.com/els/releases/CLSA-2026:1782375682

http://www.nessus.org/u?f1ff0a61

Plugin 詳細資訊

嚴重性: High

ID: 361917

檔案名稱: tuxcare_centos_8_CLSA-2026-1782375682.nasl

版本: 1.1

類型: Local

代理程式: unix

已發布: 2026/10/1

已更新: 2026/10/1

支援的感應器: Continuous Assessment, Nessus Agent, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

風險資訊

VPR

風險因素: Medium

分數: 6.9

百分位數: 97.08

Vendor

Vendor Severity: Important

CVSS v2

風險因素: Medium

基本分數: 6.8

時間性分數: 5

媒介: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS 評分資料來源: CVE-2026-43027

CVSS v3

風險因素: High

基本分數: 7.8

時間性分數: 6.8

媒介: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

時間媒介: CVSS:3.0/E:U/RL:O/RC:C

弱點資訊

必要的 KB 項目: Host/OS/extended-third-party, Host/local_checks_enabled, Host/CentOS/release, Host/CentOS/rpm-list

可輕鬆利用: No known exploits are available

修補程式發佈日期: 2026/6/25

弱點發布日期: 2021/7/21

參考資訊

CVE: CVE-2022-49975, CVE-2022-50051, CVE-2023-52504, CVE-2023-52818, CVE-2025-38361, CVE-2025-68366, CVE-2025-71082, CVE-2025-71091, CVE-2026-23099, CVE-2026-23191, CVE-2026-23243, CVE-2026-23270, CVE-2026-23455, CVE-2026-31405, CVE-2026-31532, CVE-2026-31581, CVE-2026-31685, CVE-2026-43027, CVE-2026-43110, CVE-2026-43158, CVE-2026-43190, CVE-2026-43370

CLSA: 2026:1782375682