Linux Distros 未修補弱點:CVE-2026-98228

critical Nessus Plugin ID 363239

概要

Linux/Unix 主機上安裝的一個或多個套件存有弱點,廠商表示將不會修補。

說明

Linux/Unix 主機上安裝了一個或多個受到弱點影響的套件,且廠商未提供可用的修補程式。

- mips:從 CONFIG_EYEQ 中選取 CONFIG_WEAK_REORDERING_BEYOND_LLSC 在 CPU 核心上 I6500 ,lld 和 scd 不提供排序保證 (與所有其他指令相同)。為了尊重 arch_cmpxchg() 完全有序的假設,我們必須使用已經存在的 WEAK_REORDERING_BEYOND_LLSC 基礎設施在 lld/scd 迴圈的上方和下方注入同步指令。否則,可能會發生不好的事情: [ 34.054496] CPU 3 無法處理虛擬位址 00000000000000000 的核心分頁請求,epc == a80000080838e01c, ra == a80000080838dfc4 [ 34.054559] 哎呀[#1]: [ 34.069561] CPU:3 UID:0 PID:170 通訊:pipe_race 未受污染 7.2.0-rc6-01553-gb73c35220968-dirty #103 VOLUNTARY [ 34.079932] 硬體名稱:Mobile EyeQ5 MP5 評估板 [ 34.085592] $ 0 : 000000000000000000000 0000000000000001 000000000000000000000000000000000000000000000000 [ 34.093616] $ 4 : a800000808ee2618 000000000b7a879d 0000000000001000 000000000000000000 [ 34.101638] $ 8 :
00000000000e3f2c9 000000000000000000 a8000000808a2a9f8 0000000000000000000 [ 34.109660] $12 : a80000008139ffcd8 ffffffff84080018 a8000008037fae0 7878787878787878 [ 34.117682] $16 : a8000000807e82940 0000000000001000 0000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 [ 34.125704] $20 : a800000802920e00 a8000008139ffdf8 a800000802649400 0000000000e3f2c9 [ 34.133726] $24 : 0000000000000006 00000001200406e0 [ 34.141783] $28 : a8000008139fc000 a8000008139ffd10 000000000e3f2c8 a80000080838dfc4 [ 34.149837] epc : a80000080838e01c anon_pipe_read+0xd4/0x428 [ 34.155697] ra : a80000080838dfc4 anon_pipe_read+0x7c/0x428 [ 34.161549] 狀態: 140000e3 KX SX UX 核心 EXL IE [ 34.166551] 原因 : 40800408 (ExcCode 02) [ 34.170574] BadVA :
00000000000000000 [ 34.174161] prId : 0001b028 (MIPS I6500) [ 34.178183] 處理程序 pipe_race (pid: 170, threadinfo=000000005ca35720, task=00000000e1013890, tls=000000014ebbb780) [ 34.188568] 堆疊 :
a800000802649400 00000000000000000000000000000000000000000000000000000000000000000000000000000000000fba 34.196623a8000000800000 0000000000000001 a8000008130c3e80 [ 34.204676] a8000008080d1280 a8000008139ffd58 a8000008139ffd58 1dbd2 b22ea1dd500 [ 34.212729] a800000802649400 a800000808ee0008ee000 ffffffffea 0000000000000001 [ 34.220783] 0000000000001000 0000000000000000000000000000000000 000000001200ae518 ffffff [34.228836] 0000000fffbe0e530 a800000080837edf4 0000000fffbe0e530 00000000000000000000000 [ 34.236890] 00000000000000000 00000000000000000000000000000000000000000014ebb55a0 0000000000001000 [ 34.244943] 0000000000000001 a8000000802649400 0000000000000000000000000000 [ 34.252996] 0000000000000000000 0000400400000000 0000000000000000 1dbd2b22ea1dd500 [ 34.261049] 00000000140000e3 a8000000802649400 a8000000808ee0000 [ 34.269103] ...[ 34.271568] 呼叫追蹤: [ 34.274026] [<a80000080838e01c>] anon_pipe_read+0xd4/0x428 [ 34.279533] [<a80000080837edf4>] vfs_read+0x25c/0x318 [ 34.284607] [<a80000080837faac>] ksys_read+0x104/0x138 [ 34.289763] [<a80000080802b9cc>] syscall_common+0x44/0x68 [34.295187] [ 34.296689] 代碼:f84000cf 02209825 de020010 <dc420000> d8400004 02002825 0040f809 02802025 f84000c3 [ 34.306504] [ 34.308099] ---[ 結束追蹤 000000000000000000000 ]--- 我最初的再現器是 xdp-tools 測試套件。獨立的重現器將是一個 lld/scd 迴圈,當 CPU 重新排序讀取時,會觸發錯誤。我們可以透過強調使用互斥的匿名管道來從使用者空間實現這一點。使用的程式: // spdx-License-Identifier: GPL-2.0 // pipe_race.c - MIPS LL/SC 重新排序與 fs/pipe.c 的再現器 // // 匿名管道上的兩個使用者空間進程: // 父 = 寫入器:緊密的 write() 迴圈 // 子 = reader:緊密的 read() 迴圈 #define _GNU_SOURCE #include #include #include #include #include #include #include <stdlib.h><string.h><stdio.h> #include < sys/types.h> #include ---truncated--- ()CVE-2026-98228<signal.h><sched.h><errno.h><assert.h>

請注意,Nessus 的判定取決於廠商所報告的套件是否存在。

解決方案

目前尚未有已知的解決方案。

另請參閱

https://security-tracker.debian.org/tracker/CVE-2026-98228

Plugin 詳細資訊

嚴重性: Critical

ID: 363239

檔案名稱: unpatched_CVE_2026_98228.nasl

版本: 1.1

類型: Local

代理程式: unix

系列: Misc.

已發布: 2026/10/6

已更新: 2026/10/6

支援的感應器: Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

風險資訊

VPR

風險因素: Medium

分數: 4.9

百分位數: 58.41

CVSS v2

風險因素: High

基本分數: 7.5

時間性分數: 6.4

媒介: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS 評分資料來源: CVE-2026-98228

CVSS v3

風險因素: Critical

基本分數: 9.8

時間性分數: 9

媒介: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

時間媒介: CVSS:3.0/E:U/RL:U/RC:C

弱點資訊

CPE: cpe:/o:debian:debian_linux:13.0, p-cpe:/a:debian:debian_linux:linux

必要的 KB 項目: Host/local_checks_enabled, Host/cpu, global_settings/vendor_unpatched, Host/OS/identifier

可輕鬆利用: No known exploits are available

弱點發布日期: 2026/10/6

參考資訊

CVE: CVE-2026-98228