RockyLinux 10:核心 (RLSA-2026:77690)

medium Nessus Plugin ID 364445

概要

遠端 RockyLinux 主機缺少一個或多個安全性更新。

說明

遠端 RockyLinux 10 主機已安裝的套件會受到 RLSA-2026:77690 公告中提及的多個弱點影響。

* 核心:ipvlan:根據每個連接埠建立 addrs_lock (CVE-2026-23103)

* 核心:KVM:SEV:如果 GHCB v2+ 正在使用中,則需要 GHCB 內暫存區域 (CVE-2026-53360)

* 核心:vsock/virtio:修正多重 skb 傳送的零複製完成 (CVE-2026-53365)

* 核心:NFSD:修正 SECINFO_NO_NAME 解碼錯誤清除 (CVE-2026-53398)

* 核心:vsock/virtio:在填入 Zerocopy skb (CVE-2026-63970) 之前綁定 uarg

* 核心:igc:設定 SMD 框架的 tx 緩衝區類型 (CVE-2026-64035)

* 核心:vsock/vmci:修正對等體在交握期間重設連線時的 UAF (CVE-2026-64115)

* 核心:SUNRPC:將上rpc_clnt釘在TLS connect_worker (CVE-2026-72317)

* 核心:udp:修正通道分段中潛在的釋放後使用 (CVE-2026-74705)

* 核心:ipvlan:繼承 phy_dev (CVE-2026-74744) 的needed_headroom和needed_tailroom

* 核心:nfsd:延遲複合操作的 vfree 以修正 UAF rpc_status (CVE-2026-89690)

* 核心:nfsd:在發佈之前初始化 copy-notify stateid (CVE-2026-89669)

* 核心:svcrdma:拒絕溢位上拉緩衝區的內嵌回覆 (CVE-2026-89530)

* 核心:nfsd:修正非同步 COPY (CVE-2026-89676) 的過時s2s_cp_stateids IDR 項目

* 核心:nfsd:在刪除參照之前撤銷 copy-notify stateid (CVE-2026-89663)

* 核心:nfsd:修正非同步複製取消和關機中的 UAF (CVE-2026-89675)

錯誤修正和增強功能:

* mlxbf_bootctl:驅動程式更新至 Linux v6.16 [Nvidia 10.2.z FEAT] (JIRA:Rocky Linux-212709)

* [GNR-D] 缺少介面tspll_cfg [rhel-10.2] (JIRA:Rocky Linux-273805)

Tenable 已直接從 RockyLinux 安全公告擷取前置描述區塊。

請注意,Nessus 並未測試這些問題,而是僅依據應用程式自我報告的版本號碼作出判斷。

解決方案

更新受影響的套件。

另請參閱

https://bugzilla.redhat.com/show_bug.cgi?id=2436771

https://bugzilla.redhat.com/show_bug.cgi?id=2497032

https://bugzilla.redhat.com/show_bug.cgi?id=2499742

https://bugzilla.redhat.com/show_bug.cgi?id=2502222

https://bugzilla.redhat.com/show_bug.cgi?id=2502411

https://bugzilla.redhat.com/show_bug.cgi?id=2502476

https://bugzilla.redhat.com/show_bug.cgi?id=2502593

https://bugzilla.redhat.com/show_bug.cgi?id=2516705

https://bugzilla.redhat.com/show_bug.cgi?id=2521498

https://bugzilla.redhat.com/show_bug.cgi?id=2524431

https://bugzilla.redhat.com/show_bug.cgi?id=2532103

https://bugzilla.redhat.com/show_bug.cgi?id=2532111

https://bugzilla.redhat.com/show_bug.cgi?id=2532218

https://bugzilla.redhat.com/show_bug.cgi?id=2532219

https://bugzilla.redhat.com/show_bug.cgi?id=2532231

https://bugzilla.redhat.com/show_bug.cgi?id=2532272

https://errata.rockylinux.org/RLSA-2026:77690

Plugin 詳細資訊

嚴重性: Medium

ID: 364445

檔案名稱: rocky_linux_RLSA-2026-77690.nasl

版本: 1.1

類型: Local

已發布: 2026/10/9

已更新: 2026/10/9

支援的感應器: Nessus Agent, Continuous Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

風險資訊

VPR

風險因素: High

分數: 7.8

百分位數: 99.34

CVSS v2

風險因素: Medium

基本分數: 4.6

時間性分數: 3.8

媒介: CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:C

CVSS 評分資料來源: CVE-2026-53365

CVSS v3

風險因素: Medium

基本分數: 5.5

時間性分數: 5.1

媒介: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

時間媒介: CVSS:3.0/E:F/RL:O/RC:C

弱點資訊

CPE: cpe:/o:rocky:linux:10, p-cpe:/a:rocky:linux:kernel-64k-core, p-cpe:/a:rocky:linux:kernel-64k-debug-core, p-cpe:/a:rocky:linux:kernel-64k-debug-debuginfo, p-cpe:/a:rocky:linux:kernel-64k-debug-devel-matched, p-cpe:/a:rocky:linux:kernel-64k-debug-devel, p-cpe:/a:rocky:linux:kernel-64k-debug-modules-core, p-cpe:/a:rocky:linux:kernel-64k-debug-modules-extra, p-cpe:/a:rocky:linux:kernel-64k-debug-modules, p-cpe:/a:rocky:linux:kernel-64k-debug, p-cpe:/a:rocky:linux:kernel-64k-debuginfo, p-cpe:/a:rocky:linux:kernel-64k-devel-matched, p-cpe:/a:rocky:linux:kernel-64k-devel, p-cpe:/a:rocky:linux:kernel-64k-modules-core, p-cpe:/a:rocky:linux:kernel-64k-modules-extra, p-cpe:/a:rocky:linux:kernel-64k-modules, p-cpe:/a:rocky:linux:kernel-64k, p-cpe:/a:rocky:linux:kernel-abi-stablelists, p-cpe:/a:rocky:linux:kernel-core, p-cpe:/a:rocky:linux:kernel-debug-core, p-cpe:/a:rocky:linux:kernel-debug-debuginfo, p-cpe:/a:rocky:linux:kernel-debug-devel-matched, p-cpe:/a:rocky:linux:kernel-debug-devel, p-cpe:/a:rocky:linux:kernel-debug-modules-core, p-cpe:/a:rocky:linux:kernel-debug-modules-extra, p-cpe:/a:rocky:linux:kernel-debug-modules, p-cpe:/a:rocky:linux:kernel-debug-uki-virt, p-cpe:/a:rocky:linux:kernel-debug, p-cpe:/a:rocky:linux:kernel-debuginfo-common-aarch64, p-cpe:/a:rocky:linux:kernel-debuginfo-common-ppc64le, p-cpe:/a:rocky:linux:kernel-debuginfo-common-s390x, p-cpe:/a:rocky:linux:kernel-debuginfo-common-x86_64, p-cpe:/a:rocky:linux:kernel-debuginfo, p-cpe:/a:rocky:linux:kernel-devel-matched, p-cpe:/a:rocky:linux:kernel-devel, p-cpe:/a:rocky:linux:kernel-modules-core, p-cpe:/a:rocky:linux:kernel-modules-extra-matched, p-cpe:/a:rocky:linux:kernel-modules-extra, p-cpe:/a:rocky:linux:kernel-modules, p-cpe:/a:rocky:linux:kernel-rt-64k-core, p-cpe:/a:rocky:linux:kernel-rt-64k-debug-core, p-cpe:/a:rocky:linux:kernel-rt-64k-debug-debuginfo, p-cpe:/a:rocky:linux:kernel-rt-64k-debug-devel, p-cpe:/a:rocky:linux:kernel-rt-64k-debug-modules-core, p-cpe:/a:rocky:linux:kernel-rt-64k-debug-modules-extra, p-cpe:/a:rocky:linux:kernel-rt-64k-debug-modules, p-cpe:/a:rocky:linux:kernel-rt-64k-debug, p-cpe:/a:rocky:linux:kernel-rt-64k-debuginfo, p-cpe:/a:rocky:linux:kernel-rt-64k-devel, p-cpe:/a:rocky:linux:kernel-rt-64k-modules-core, p-cpe:/a:rocky:linux:kernel-rt-64k-modules-extra, p-cpe:/a:rocky:linux:kernel-rt-64k-modules, p-cpe:/a:rocky:linux:kernel-rt-64k, p-cpe:/a:rocky:linux:kernel-rt-core, p-cpe:/a:rocky:linux:kernel-rt-debug-core, p-cpe:/a:rocky:linux:kernel-rt-debug-debuginfo, p-cpe:/a:rocky:linux:kernel-rt-debug-devel, p-cpe:/a:rocky:linux:kernel-rt-debug-modules-core, p-cpe:/a:rocky:linux:kernel-rt-debug-modules-extra, p-cpe:/a:rocky:linux:kernel-rt-debug-modules, p-cpe:/a:rocky:linux:kernel-rt-debug, p-cpe:/a:rocky:linux:kernel-rt-debuginfo, p-cpe:/a:rocky:linux:kernel-rt-devel, p-cpe:/a:rocky:linux:kernel-rt-modules-core, p-cpe:/a:rocky:linux:kernel-rt-modules-extra, p-cpe:/a:rocky:linux:kernel-rt-modules, p-cpe:/a:rocky:linux:kernel-rt, p-cpe:/a:rocky:linux:kernel-tools-debuginfo, p-cpe:/a:rocky:linux:kernel-tools-libs-devel, p-cpe:/a:rocky:linux:kernel-tools-libs, p-cpe:/a:rocky:linux:kernel-tools, p-cpe:/a:rocky:linux:kernel-uki-virt-addons, p-cpe:/a:rocky:linux:kernel-uki-virt, p-cpe:/a:rocky:linux:kernel-zfcpdump-core, p-cpe:/a:rocky:linux:kernel-zfcpdump-debuginfo, p-cpe:/a:rocky:linux:kernel-zfcpdump-devel-matched, p-cpe:/a:rocky:linux:kernel-zfcpdump-devel, p-cpe:/a:rocky:linux:kernel-zfcpdump-modules-core, p-cpe:/a:rocky:linux:kernel-zfcpdump-modules-extra, p-cpe:/a:rocky:linux:kernel-zfcpdump-modules, p-cpe:/a:rocky:linux:kernel-zfcpdump, p-cpe:/a:rocky:linux:kernel, p-cpe:/a:rocky:linux:libperf-debuginfo, p-cpe:/a:rocky:linux:libperf, p-cpe:/a:rocky:linux:perf-debuginfo, p-cpe:/a:rocky:linux:perf, p-cpe:/a:rocky:linux:python3-perf-debuginfo, p-cpe:/a:rocky:linux:python3-perf, p-cpe:/a:rocky:linux:rtla, p-cpe:/a:rocky:linux:rv

必要的 KB 項目: Host/local_checks_enabled, Host/cpu, Host/RockyLinux/release, Host/RockyLinux/rpm-list

可被惡意程式利用: true

可輕鬆利用: Exploits are available

修補程式發佈日期: 2026/10/9

弱點發布日期: 2026/2/4

參考資訊

CVE: CVE-2026-23103, CVE-2026-53360, CVE-2026-53365, CVE-2026-53398, CVE-2026-63970, CVE-2026-64035, CVE-2026-64115, CVE-2026-72317, CVE-2026-74705, CVE-2026-74744, CVE-2026-89530, CVE-2026-89663, CVE-2026-89669, CVE-2026-89675, CVE-2026-89676, CVE-2026-89690