CentOS Linux 8 [TuxCare] 安全性更新:bpftool / kernel / kernel-core / kernel-cross-headers / etc多個漏洞 (CENTOS-STREAM8:CLSA-2026:1780132980)

high Nessus Plugin ID 362073

概要

CentOS Linux 主機缺少一個或多個安全性更新。

說明

CentOS Linux 8 主機已安裝的套件會受到 TuxCare CENTOS-STREAM8:CLSA-2026:1780132980 公告中提及的多個弱點影響。

- kernel 5.12.14 /module.c 在錯誤處理簽章驗證之前,也就是 CID-0c18f29aae7c。如果沒有CONFIG_MODULE_SIG,則不會針對 module.sig_enforce=1 命令列引數驗證核心模組是否已簽署以透過init_module載入。(CVE-2021-35039)

- 在 Linux 核心 5.13.4 之前版本的 drivers/char/virtio_console.c 中,未受信任的裝置提供超出緩衝區大小的 buf->len 值時可觸發資料損毀或丟失。注意:廠商指出,上述資料損毀在現有的所有使用案例中都不是弱點;新增長度驗證只是為了在主機 OS 行為異常時保持穩健 (CVE-2021-38160)

- 在 Linux 核心中,net/bluetooth/l2cap_core.c 的 l2cap_connect 和 l2cap_le_connect_req 函式中存在釋放後使用弱點,攻擊者可利用此弱點,透過藍牙從遠端執行程式碼和洩漏核心記憶體 (分別)。如果在受害者附近,遠端攻擊者可透過藍牙執行會引致核心記憶體洩漏的程式碼。建議升級過去的 commit https://www.google.com/url https://github.com/torvalds/linux/commit/711f8c3fb3db61897080468586b970c87c61d9e4 https://www.google.com/url (CVE-2022-42896)

- 已解決 Linux 核心中的下列弱點:tracing: Fix potential double free in create_var_ref() In create_var_ref(), init_var_ref() is called to initialize the fields of variable ref_field, which is allocated in the previous function call to create_hist_field(). Function init_var_ref() allocates the corresponding fields such as ref_field->system, but frees these fields when the function encounters an error. The caller later calls destroy_hist_field() to conduct error handling, which frees the fields and the variable itself. This results in double free of the fields which are already freed in the previous function. Fix this by storing NULL to the corresponding fields when they are freed in init_var_ref(). (CVE-2022-49410)

- 已解決 Linux 核心中的下列弱點:HID: elan: Fix potential double free in elan_input_configured 'input' is a managed resource allocated with devm_input_allocate_device(), so there is no need to call input_free_device() explicitly or there will be a double free. According to the doc of devm_input_allocate_device(): * Managed input devices do not need to be explicitly unregistered or
* freed as it will be done automatically when owner device unbinds from * its driver (or binding fails).
(CVE-2022-49508)

請注意,Nessus 並未測試這些問題,而是僅依據應用程式自我報告的版本號碼作出判斷。

解決方案

根據 TuxCare 公告 CENTOS-STREAM8:CLSA-2026:1780132980 中的指引更新受影響的套件。

另請參閱

https://cve.tuxcare.com/els/releases/CLSA-2026:1780132980

http://www.nessus.org/u?78268d5f

Plugin 詳細資訊

嚴重性: High

ID: 362073

檔案名稱: tuxcare_centos_8_CLSA-2026-1780132980.nasl

版本: 1.2

類型: Local

代理程式: unix

已發布: 2026/10/1

已更新: 2026/10/2

支援的感應器: Continuous Assessment, Nessus Agent, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

風險資訊

VPR

風險因素: High

分數: 7.9

百分位數: 99.35

Vendor

Vendor Severity: Important

CVSS v2

風險因素: High

基本分數: 7.2

時間性分數: 6.3

媒介: CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C

CVSS 評分資料來源: CVE-2021-38160

CVSS v3

風險因素: High

基本分數: 8.8

時間性分數: 8.4

媒介: CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

時間媒介: CVSS:3.0/E:H/RL:O/RC:C

CVSS 評分資料來源: CVE-2022-42896

弱點資訊

必要的 KB 項目: Host/OS/extended-third-party, Host/local_checks_enabled, Host/CentOS/release, Host/CentOS/rpm-list

可被惡意程式利用: true

可輕鬆利用: Exploits are available

修補程式發佈日期: 2026/5/30

弱點發布日期: 2021/7/7

參考資訊

CVE: CVE-2021-35039, CVE-2021-38160, CVE-2022-42896, CVE-2022-49410, CVE-2022-49508, CVE-2022-49870, CVE-2022-49907, CVE-2022-49917, CVE-2022-49948, CVE-2022-50200, CVE-2022-50315, CVE-2022-50366, CVE-2022-50432, CVE-2022-50497, CVE-2023-52475, CVE-2023-52531, CVE-2023-52741, CVE-2023-52867, CVE-2023-52868, CVE-2023-52988, CVE-2023-53000, CVE-2023-53019, CVE-2023-53075, CVE-2023-53116, CVE-2023-53285, CVE-2023-53307, CVE-2023-53321, CVE-2023-53338, CVE-2023-53506, CVE-2023-53570, CVE-2023-53622, CVE-2023-53646, CVE-2023-53668, CVE-2024-46812, CVE-2025-68741, CVE-2025-71093, CVE-2025-71116, CVE-2026-23216, CVE-2026-23388, CVE-2026-31602, CVE-2026-31778, CVE-2026-43020, CVE-2026-43040, CVE-2026-43206, CVE-2026-43450, CVE-2026-46243

CLSA: 2026:1780132980