Amazon Linux 2:内核、 --advisory ALAS2KERNEL-5。10-2026-123 (ALASKERNEL-5。10-2026-123)

high Nessus 插件 ID 321988

简介

远程 Amazon Linux 2 主机缺少安全更新。

描述

远程主机上安装的内核版本低于 5.10.258-257.1041。因此,会受到 ALAS2KERNEL-5.10-2026-123 公告中提及的多个漏洞影响。

在 Linux 内核中,以下漏洞已修复:

IB/mad:在原子上下文中不调用可能休眠的函数 (CVE-2022-50472)

在 Linux 内核中,以下漏洞已修复:

scsi:qla2xxx:修复 I/O 中止超时时的崩溃 (CVE-2022-50493)

在 Linux 内核中,以下漏洞已修复:

blk-mq:重新初始化队列时使用静止的 elevator 开关 (CVE-2022-50552)

在 Linux 内核中,以下漏洞已修复:

mm:修复 zswap 回写争用条件 (CVE-2023-53178)

在 Linux 内核中,以下漏洞已修复:

blk-cgroup:在 blkcg_reset_stats() (CVE-2023-53421) 中清除后重新初始化 blkg_iostat_set

在 Linux 内核中,以下漏洞已修复:

page_pool:修复 page_pool_recycle_in_ring 中的释放后使用 (CVE-2025-38129)

在 Linux 内核中,以下漏洞已修复:

gfs2:验证 exhash 目录的i_depth (CVE-2025-38710)

在 Linux 内核中,以下漏洞已修复:

mm/damon/sysfs:修复 state_show() (CVE-2025-39877) 中的释放后使用

在 Linux 内核中,以下漏洞已修复:

net/sched:cls_u32:使用 skb_header_pointer_careful() (CVE-2026-23204)

在 Linux 内核中,以下漏洞已修复:

netfilter:nf_tables:插入 (CVE-2026-23272) 前无条件升级 set->nelems

在 Linux 内核中,以下漏洞已修复:

net:sched:避免无锁 qdiscs (CVE-2026-23340) 的 qdisc_reset_all_tx_gt() 与出列争用

在 Linux 内核中,以下漏洞已修复:

ipv6:为 SRv6 路径中的 idev 添加 NULL 检查 (CVE-2026-23442)

在 Linux 内核中,以下漏洞已修复:

netfilter:conntrack:添加缺少的 netlink 策略验证 (CVE-2026-31407)

在 Linux 内核中,以下漏洞已修复:

net:bonding:修复 bond_xmit_broadcast() 中的释放后使用 (CVE-2026-31419)

在 Linux 内核中,以下漏洞已修复:

can:raw:修复 raw_rcv()CVE-2026-31532 () 中的 ro->uniq 释放后使用

在 Linux 内核中,以下漏洞已修复:

nilfs2:修复 nilfs_mdt_save_to_shadow_map 中的空i_assoc_inode取消引用 (CVE-2026-31577)

在 Linux 内核中,以下漏洞已修复:

bcache:修复 cached_dev.sb_bio 释放后使用和崩溃 (CVE-2026-31580)

在 Linux 内核中,以下漏洞已修复:

mm:blk-cgroup:修复 cgwb_release_workfn() (CVE-2026-31586) 中的释放后使用

在 Linux 内核中,以下漏洞已修复:

KVM:x86:使用 MMIO 片段中的暂存字段保存小写入值 (CVE-2026-31588)

在 Linux 内核中,以下漏洞已修复:

KVM:SEV:终止对大尺寸的 KVM_MEMORY_ENCRYPT_REG_REGION WARN (CVE-2026-31590)

在 Linux 内核中,以下漏洞已修复:

usbip:验证 usbip_pack_ret_submit() (CVE-2026-31607) 中的number_of_packets

在 Linux 内核中,以下漏洞已修复:

HID:core:在 s32ton() 中钳制 report_size 以避免未定义的位移 (CVE-2026-31624)

在 Linux 内核中,以下漏洞已修复:

rxrpc:修复 rxrpc_server_keyring() 中的引用计数泄漏 (CVE-2026-31634)

在 Linux 内核中,以下漏洞已修复:

drm/i915/gt:修复 intel_engine_park_heartbeat (CVE-2026-31656) 中的 refcount 下溢

在 Linux 内核中,以下漏洞已修复:

xfrm:将 dev ref 保留到 transport_finish NF_HOOK (CVE-2026-31663) 之后

在 Linux 内核中,以下漏洞已修复:

xfrm:清除 build_polexpire() (CVE-2026-31664) 中的尾部填充

在 Linux 内核中,以下漏洞已修复:

af_unix:读取 unix_state_lock (CVE-2026-31673) 下的UNIX_DIAG_VFS数据

在 Linux 内核中,以下漏洞已修复:

rxrpc:仅在服务质询 (CVE-2026-31676) 期间处理 RESPONSE

在 Linux 内核中,以下漏洞已修复:

netfilter:xt_multiport:验证 checkentry (CVE-2026-31681) 中的范围编码

在 Linux 内核中,以下漏洞已修复:

net:sched: act_csum:验证嵌套的 VLAN 标头 (CVE-2026-31684)

在 Linux 内核中,以下漏洞已修复:

netfilter:ip6t_eui64:拒绝所有数据包的无效 MAC 标头 (CVE-2026-31685)

在 Linux 内核中,以下漏洞已修复:

rtnetlink:添加对等机 netnsCVE-2026-31692 缺少的 netlink_ns_capable() 检查

在 Linux 内核中,以下漏洞已修复:

net/packet:修复 tpacket_snd()CVE-2026-31700 () 中的 mmap'd vnet_hdr中的 TOCTOU 争用

在 Linux 内核中,以下漏洞已修复:

netfilter:nfnetlink_log:初始化 NLMSG_DONE 结束符 (CVE-2026-43085) 中的 nfgenmsg

在 Linux 内核中,以下漏洞已修复:

xfrm_user:修复 build_mapping() (CVE-2026-43089) 中的信息泄漏

在 Linux 内核中,以下漏洞已修复:

xsk:加强 UMEM 余量验证,以考虑尾余量和最小帧 (CVE-2026-43093)

在 Linux 内核中,以下漏洞已修复:

HID:roccat:修复 roccat_report_event 中的释放后使用 (CVE-2026-43111)

在 Linux 内核中,以下漏洞已修复:

netfilter:nft_set_pipapo_avx2:到期时不返回不匹配的条目 (CVE-2026-43114)

在 Linux 内核中,以下漏洞已修复:

netfilter:ctnetlink:确保安全访问主控 conntrack (CVE-2026-43116)

在 Linux 内核中,以下漏洞已修复:

btrfs:tracepoints:从事件 btrfs_sync_file()CVE-2026-43117 () 中的 dentry 获取正确的超级块

在 Linux 内核中,以下漏洞已修复:

邮箱:防止 fw_mbox_index_xlate() 中的越界访问 (CVE-2026-43281)

在 Linux 内核中,以下漏洞已修复:

crypto:pcrypt - 修复 MAY_BACKLOG 请求的处理 (CVE-2026-43493)

在 Linux 内核中,以下漏洞已修复:

net/sched:sch_red:将直接出列调用替换为 peek 和 qdisc_dequeue_peeked (CVE-2026-43496)

在 Linux 内核中,以下漏洞已修复:

net/rds:在消息排队之前处理 zerocopy 发送清除 (CVE-2026-43502)

在 Linux 内核中,以下漏洞已修复:

bpf:修复 cgroup_storage_get_next_key() (CVE-2026-45838) 中的列表结尾检测

在 Linux 内核中,以下漏洞已修复:

openvswitch:上限上调 PID 数组大小和预大小 vport 回复 (CVE-2026-45840)

在 Linux 内核中,以下漏洞已修复:

netfilter:nfnetlink_osf:修复 OSF_WSS_MODULO 中的除以零问题 (CVE-2026-45841)

在 Linux 内核中,以下漏洞已修复:

slip:拒绝没有 rstate 数组 (CVE-2026-45842) 的实例上的 VJ 接收数据包

在 Linux 内核中,以下漏洞已修复:

slip:针对压缩的数据包长度 ()CVE-2026-45843 绑定 decode() 读取

在 Linux 内核中,以下漏洞已修复:

netfilter:arp_tables:修复 IEEE1394 ARP 负载解析 (CVE-2026-45844)

在 Linux 内核中,以下漏洞已修复:

KVM:nSVM:在 L2 的 VMRUN 之后将中断阴影同步到缓存的 vmcb12 (CVE-2026-45987)

在 Linux 内核中,以下漏洞已修复:

ext2:拒绝 ext2_iget() ()CVE-2026-46002 中具有零i_nlink和有效模式的 inode

在 Linux 内核中,以下漏洞已修复:

dm mirror:修复 create_dirty_log() 中的整数溢出 (CVE-2026-46023)

在 Linux 内核中,以下漏洞已修复:

crypto:authencesn - 拒绝实例创建期间的短 ahash 摘要 (CVE-2026-46033)

在 Linux 内核中,以下漏洞已修复:

inotify:修复当 fsnotify_add_inode_mark_locked() 失败时的监视计数泄漏 (CVE-2026-46040)

在 Linux 内核中,以下漏洞已修复:

RDMA/rxe:在 rxe_rcv () 中的 payload_size() 之前验证 pad 和CVE-2026-46043 ICRC

在 Linux 内核中,以下漏洞已修复:

ext4:修复 ext4_xattr_inode_dec_ref_all() (CVE-2026-46046) 中缺少的 brelse()

在 Linux 内核中,以下漏洞已修复:

md/raid5:修复 retry_aligned_read() 中的软锁定 (CVE-2026-46051)

在 Linux 内核中,以下漏洞已修复:

net:rds:修复复制错误 (CVE-2026-46053) 时的 MR 清理

在 Linux 内核中,以下漏洞已修复:

md/raid5:访问日志元数据 (CVE-2026-46070) 之前验证负载大小

在 Linux 内核中,以下漏洞已修复:

netfilter:拒绝 nft_bitwise 中的零位移 (CVE-2026-46101)

在 Linux 内核中,以下漏洞已修复:

net:strparser:修复 strp_abort_strp() (CVE-2026-46102) 中的skb_head泄漏

在 Linux 内核中,以下漏洞已修复:

ipmi:si:消息分配失败时恢复状态 (CVE-2026-46108)

在 Linux 内核中,以下漏洞已修复:

usb:ulpi:修复 ulpi_register() 错误路径中的内存泄漏 (CVE-2026-46109)

在 Linux 内核中,以下漏洞已修复:

KVM:x86:修复了由于非预期 GFN (CVE-2026-46113) 导致的阴影分页释放后使用问题

在 Linux 内核中,以下漏洞已修复:

ip6_gre:在 ip6erspan_changelink() 中使用缓存的 t->net。(CVE-2026-46120)

在 Linux 内核中,以下漏洞已修复:

isofs:验证 isofs_export_iget (CVE-2026-46124) 中 NFS 文件句柄中的区块号

在 Linux 内核中,以下漏洞已修复:

ipmi:检查事件消息缓冲区响应是否有错误数据 (CVE-2026-46128)

在 Linux 内核中,以下漏洞已修复:

net:rtnetlink:零ifla_vf_broadcast以避免 rtnl_fill_vfinfo (CVE-2026-46132) 中堆栈信息泄漏

在 Linux 内核中,以下漏洞已修复:

RDMA/rxe:在 ICRC 处理 (CVE-2026-46133) 之前拒绝未知操作码

在 Linux 内核中,以下漏洞已修复:

scsi:target:configfs:限制 snprintf() 在 tg_pt_gp_members_show()CVE-2026-46149 () 中的返回

在 Linux 内核中,以下漏洞已修复:

fanotify:修复权限事件的误报 (CVE-2026-46150)

在 Linux 内核中,以下漏洞已修复:

usb:usblp:通过短响应 (CVE-2026-46151) 修复 IEEE 1284 设备 ID 中的堆泄漏

在 Linux 内核中,以下漏洞已修复:

md/raid10:修复含零far_copies (CVE-2026-46161) 的 setup_geo() 中的除以零问题

在 Linux 内核中,以下漏洞已修复:

usb:usblp:修复通过 LPGETSTATUS ioctl (CVE-2026-46167) 导致的未初始化堆泄漏

在 Linux 内核中,以下漏洞已修复:

ipv6:xfrm6:xfrm6_rcv_encap() (CVE-2026-46172) 中发生错误时释放 dst

在 Linux 内核中,以下漏洞已修复:

ipmi:添加对事件的限制和接收消息请求 (CVE-2026-46177)

在 Linux 内核中,以下漏洞已修复:

RDMA/mlx4:修复 mlx4_ib_create_srq()CVE-2026-46178 () 中出错时的资源泄漏

在 Linux 内核中,以下漏洞已修复:

drm/gem:修复 drm_gem_fb_init_with_funcs() (CVE-2026-46209) 中不一致的平面尺寸计算

在 Linux 内核中,以下漏洞已修复:

vsock/virtio:修复传输不匹配 (CVE-2026-46214) 时的接受队列计数泄漏

在 Linux 内核中,以下漏洞已修复:

sctp:重新验证 SCTP_SENDALL (CVE-2026-46227) 中 sctp_sendmsg_to_asoc() 之后的列表光标

在 Linux 内核中,以下漏洞已修复:

vsock:修复缓冲区大小限制顺序 (CVE-2026-46234)

在 Linux 内核中,以下漏洞已修复:

io-wq:检查前置任务是否在 io_wq_remove_pending() (CVE-2026-46274) 中执行哈希处理

在 Linux 内核中,以下漏洞已修复:

dm:修复 ioctl 处理中的缓冲区溢出 (CVE-2026-46294)

在 Linux 内核中,以下漏洞已修复:

nvmet:避免 nvmet_ctrl_free (CVE-2026-46304) 中的递归 nvmet-wq 刷新

在 Linux 内核中,以下漏洞已修复:

netfilter:ip6t_hbh:拒绝超大选项列表 (CVE-2026-52915)

在 Linux 内核中,以下漏洞已修复:

netfilter:xt_policy:修复严格模式入站策略匹配 (CVE-2026-52920)

在 Linux 内核中,以下漏洞已修复:

netfilter:ipset:停止哈希:* 结束时的范围迭代 (CVE-2026-52921)

在 Linux 内核中,以下漏洞已修复:

vrf:修复从 VRF 中删除端口时潜在的 NPD (CVE-2026-52925)

在 Linux 内核中,以下漏洞已修复:

libceph:处理 decode_choose_args() 中的 rbtree 插入错误 (CVE-2026-52954)

在 Linux 内核中,以下漏洞已修复:

libceph:修复 crush_decode() (CVE-2026-52955) 中潜在的越界访问

在 Linux 内核中,以下漏洞已修复:

libceph:修复 decode_choose_args() (CVE-2026-52957) 中潜在的 null-ptr-deref

在 Linux 内核中,以下漏洞已修复:

libceph:修复 osdmap_decode() (CVE-2026-52958) 中潜在的越界访问

在 Linux 内核中,以下漏洞已修复:

ceph:修复 __ceph_setxattr() (CVE-2026-52962) 中的缓冲区泄漏

在 Linux 内核中,以下漏洞已修复:

netfilter:nft_ct:修复 obj eval (CVE-2026-52970) 中缺少的预期

在 Linux 内核中,以下漏洞已修复:

crypto:af_alg - 将 AEAD AD 长度上限设为 0x80000000 (CVE-2026-52972)

在 Linux 内核中,以下漏洞已修复:

net:usb:rtl8150:修复 rtl8150_start_xmit() (CVE-2026-52982) 中的释放后使用

在 Linux 内核中,以下漏洞已修复:

net/sched:netem:修复队列限制检查以包括重新排序的数据包

netem_enqueue() 中的队列限制检查使用 q->t_len,它仅对内部 tfifo 中的数据包进行计数。
通过重新排序路径 (__qdisc_enqueue_head) 放置在 sch->q 中的数据包不计算在内,从而允许重新排序下的总队列占用率超过 sch->limit。

在限制检查中包含 sch->q.qlen。(CVE-2026-52984)

在 Linux 内核中,以下漏洞已修复:

netdevsim:零初始化虚拟sk_buff中的结构 iphdr (CVE-2026-52985)

在 Linux 内核中,以下漏洞已修复:

netfilter:nf_conntrack_sip:不使用 simple_strtoul (CVE-2026-52986)

在 Linux 内核中,以下漏洞已修复:

tipc:修复 tipc_buf_append() 中的双重释放 (CVE-2026-52993)

在 Linux 内核中,以下漏洞已修复:

net/rds:将每项信息缓冲区交给访问者之前将其设置为零 (CVE-2026-52995)

在 Linux 内核中,以下漏洞已修复:

netfilter:nfnetlink_osf:修复 ttl 检查 (CVE-2026-52998) 中潜在的空取消引用

在 Linux 内核中,以下漏洞已修复:

netfilter:nfnetlink_osf:修复选项匹配 (CVE-2026-52999) 的越界读取

在 Linux 内核中,以下漏洞已修复:

netfilter:xtables:将多个匹配项限制为 inet 系列 (CVE-2026-53001)

在 Linux 内核中,以下漏洞已修复:

netfilter:conntrack:删除 sprintf 使用情况 (CVE-2026-53002)

在 Linux 内核中,以下漏洞已修复:

pppoe:终止 PFC 帧 (CVE-2026-53003)

在 Linux 内核中,以下漏洞已修复:

sctp:修复对 sctp_getsockopt_peer_auth_chunks (CVE-2026-53004) 中用户空间的越界写入

在 Linux 内核中,以下漏洞已修复:

ipv6:修复 icmpv6_rcv() (CVE-2026-53006) 中可能的 UAF

在 Linux 内核中,以下漏洞已修复:

net/sched:taprio:在计划切换 ()CVE-2026-53011 上修复 advance_sched() 中的释放后使用

在 Linux 内核中,以下漏洞已修复:

nexthop:修复引用 IPv4 nexthop (CVE-2026-53012) 的 IPv6 路由

在 Linux 内核中,以下漏洞已修复:

crypto:ccp - 使用 skcipher ivsize (CVE-2026-53016) 复制 IV

在 Linux 内核中,以下漏洞已修复:

scsi:target:core:修复 UNMAP 边界检查 (CVE-2026-53021) 中的整数溢出

在 Linux 内核中,以下漏洞已修复:

HID:usbhid:修复 hid_post_reset() (CVE-2026-53037) 中的死锁

在 Linux 内核中,以下漏洞已修复:

efi/capsule-loader:修复 phys 数组重新分配 (CVE-2026-53047) 中错误的 sizeof

在 Linux 内核中,以下漏洞已修复:

quota:通过配额停用 (CVE-2026-53050) 修复 dquot_scan_active() 的争用

在 Linux 内核中,以下漏洞已修复:

dm log:修复了region_count溢出导致的越界写入 (CVE-2026-53059)

在 Linux 内核中,以下漏洞已修复:

dm 缓存元数据:修复元数据中止重试 (CVE-2026-53060) 时的内存泄漏

在 Linux 内核中,以下漏洞已修复:

dm cache:修复传递模式切换中的脏映射检查 (CVE-2026-53061)

在 Linux 内核中,以下漏洞已修复:

dm 缓存策略 smq:修复使缓存块无效化时缺少的锁定 (CVE-2026-53062)

在 Linux 内核中,以下漏洞已修复:

dm cache:修复传递模式下并发写入的 null-deref (CVE-2026-53064)

在 Linux 内核中,以下漏洞已修复:

bpf:拒绝 bpf_prog_test_run_skb 中的短 IPv4/IPv6 输入 (CVE-2026-53074)

在 Linux 内核中,以下漏洞已修复:

ppp:在未附加的 ioctls 的目标 netns 中要求CAP_NET_ADMIN (CVE-2026-53075)

在 Linux 内核中,以下漏洞已修复:

net/rds:将 RDS/IB 的使用限制在初始网络命名空间 (CVE-2026-53077)

在 Linux 内核中,以下漏洞已修复:

drbd:平衡 drbd_adm_dump_devices() (CVE-2026-53128) 中的 RCU 调用

在 Linux 内核中,以下漏洞已修复:

audit:修复 CAPSET 记录中不正确的可继承功能

__audit_log_capset() 将由于复制粘贴错误而导致的有效功能集记录到可继承字段中。因此,每个 CAPSET auditrecord 都会报告cap_pi(进程可继承),值为 cap_effective 而不是 cap_inheritable。

这会静默地损坏用于合规性和取证分析的审计数据:修改可继承功能以准备权限升级 exec 的攻击者将在审计跟踪中屏蔽该更改。

自 2008 年首次引入 CAPSETaudit 记录以来,此缺陷一直存在。(CVE-2026-53287)

在 Linux 内核中,以下漏洞已修复:

mailbox:添加通道数组的健全性检查

如果邮箱控制器未附加通道数组,则正常失败。否则,较后的取消引用将导致可能看不到的 OOPS,因为邮箱控制器可能每年实例化一次。删除解释此处显而易见的评论。(CVE-2026-53295)

在 Linux 内核中,以下漏洞已修复:

scsi:sg:解决打开 /dev/sgX (CVE-2026-53304) 时的软锁定问题

在 Linux 内核中,以下漏洞已修复:

nilfs2:拒绝 nilfs_ioctl_mark_blocks_dirty() 中的零bd_oblocknr

nilfs_ioctl_mark_blocks_dirty() 使用 bd_oblocknr 通过将其与当前块号bd_blocknr进行比较来检测死块。如果它们不同,则该块被视为死并被跳过。

但是,bd_oblocknr不应为 0,因为块 0 通常存储主超级块,并且从来都不是有效的 GC 目标块。当查找返回 -ENOENT 并将 bd_blocknr 设置为 0 时,bd_oblocknr 设置为 0 的损坏 ioctlrequest 造成比较匹配不正确,从而绕过死块检查并对不存在的块调用 nilfs_bmap_mark()。这会导致 nilfs_btree_do_lookup() 返回
-ENOENT,触发 WARN_ON(ret == -ENOENT)。

通过拒绝在每次迭代开始时将 bd_oblocknr 设置为 0 的 ioctl 请求来修复此问题。

[Ryusuke:为准确起见,稍微修改了提交消息和注释](CVE-2026-53320)

在 Linux 内核中,以下漏洞已修复:

udf:拒绝 CRC 长度超大的描述符

udf_read_tagged() 在 descCRCLength +sizeof(struct tag) 超过区块大小时跳过 CRC 验证。构建的 UDF 图像 canset 将 descCRCLength 描述为超大值以完全绕过 CRC 验证;然后仅根据可轻易重聚的 8 位标签校验和来接受描述符。

拒绝此类描述符,而非静默接受它们。合法的单区块描述符的 CRC 长度不应超过区块。(CVE-2026-53369)

在 Linux 内核中,以下漏洞已修复:

RDMA/core:首选 NLA_NUL_STRING

这些属性作为 c 字符串(传递到 strcmp)进行评估,butNLA_STRING不检查是否存在 \0 终止符。

这需要切换到 nla_strcmp() 并需要调整 printf fmtspecifier 以不使用普通 %s,或者这需要使用NLA_NUL_STRING。

由于代码长期以来一直如此,在我看来,用户空间确实包括终止 nul,甚至到目前为止还没有强制执行,因此使用NLA_NUL_STRING更简单的解决方案。
(CVE-2026-63860)

在 Linux 内核中,以下漏洞已修复:

arm64:tlb:取消共享 PMD 表时刷新 walk 缓存 (CVE-2026-63875)

在 Linux 内核中,以下漏洞已修复:

net:tls:防止明文 SG (CVE-2026-64046) 中的链后链

在 Linux 内核中,以下漏洞已修复:

net:tls:修复封装的 sk_msg 环的 sg_chain 条目计数中的差一

当sk_msg scatterlist 环封装 (sg.end < sg.start) 时,tls_push_record() 将环的尾部链接到 headusing sg_chain() 上。sg 数组中的一个额外条目是为此保留的:

结构sk_msg_sg {[...]/* 额外的两个元素:* 1) 用于在列表分区* 时链接前面和部分(例如结束<开始)。加密 API 需要* chaining;* 2) 以在 message.*/struct scatterlist data[MAX_MSG_FRAGS + 2];

当前代码使用 MAX_SKB_FRAGS + 1 作为环大小:

sg_chain(&msg_pl->sg.data[msg_pl->sg.start],MAX_SKB_FRAGS - msg_pl->sg.start + 1,msg_pl->sg.data);

这会将链接指针放置在

sg_chain(data[start], (MAX_SKB_FRAGS - msg_start + 1) .. =&data[start] + (MAX_SKB_FRAGS - msg_start + 1) - 1 =data[start[start + (MAX_SKB_FRAGS - start + 1) - 1] =data[MAX_SKB_FRAGS]

而不是真正的最后一个条目。这很可能是由于在接近提交 031097d9e079 的补丁着陆时存在提交争用(bpf:sk_msg,psock down 时的 zap 入口队列)

转换为 ARRAY_SIZE 并终止 data[start] / - start(依据 Sabrina 建议)。(CVE-2026-64047)

在 Linux 内核中,以下漏洞已修复:

ixgbevf:修复 VEPA 多播源修剪中的释放后使用

ixgbevf_clean_rx_irq() 通过释放 skb 并继续进行下一个描述符删除其源 MAC 匹配 VF 的自有地址的帧(VEPA 多播变通方案):

dev_kfree_skb_irq(skb);继续;

skb 指针在 while 循环之外声明并保留 acrossiterations。由于继续跳过循环底部的 skb = NULL 重置,因此下一个迭代会进入 else if (skb) 路径并在释放的 skb 上调用 ixgbevf_add_rx_frag(),dereferencingskb_shinfo(skb)->nr_frags - NAPI softirq 上下文中的释放后使用。

同级驱动程序 iavf 已通过在继续之前将指针为空来正确处理此操作。在这里应用相同的模式。

我没有 ixgbevf 硬件;该缺陷是通过静态分析发现的(scan_drop_continue_loops.py + semgrep drop_continue_in_loop,扫描中得分最高的多工具佐证)。通过加载再现确切代码模式(alloc skb,kfree_skb,然后读取 skb_shinfo(skb)->nr_frags)的测试模块,在 KASAN 下确认了 UAF:

缺陷:KASAN:任务 insmod/30freed 208 字节区域在地址 0000000006163ae78 的 ixgbevf_uaf_test_init++0x100/0x1000Read 中释放后使用 [000000006163adc0, 000000006163ae90)

QEMU 仿真 igb (82576) 但不仿真 ixgbe (82599),并且 igbvf VFdriver 不包括 VEPA 源修剪路径,因此无法使用仿真硬件进行端到端再现。(CVE-2026-64113)

在 Linux 内核中,以下漏洞已修复:

ipv4:raw:拒绝具有 IHL < 5 的 IP_HDRINCL 数据包

raw_send_hdrinc() 验证调用程序提供的 IPv4 标头是否适合消息长度:

iphlen = iph->ihl * 4;错误 = -EINVAL;if (iphlen > length)转至error_free;

if (iphlen >= sizeof(*iph)) {/* 修复 saddr, tot_len, id, csum, transport_header */}

但是,它并不拒绝国际<法第 5 条。对于此类数据包,会跳过 theif (iphlen >= sizeof(*iph)) 分支,从而不影响特制的 iphdr,但仍会to__ip_local_out() 及后续传递数据包。
readiph->ihl 假设值合理的下游使用者:net/ipv4/ah4.c:ah_output() inparticular 从 top_iph->ihl * 4 减去 sizeof(struct iphdr) 并将(signed-int-negative,然后转换为 size_t)结果传递到 memcpy(),从而产生长度接近toSIZE_MAX的 OOB 访问和主机内核错误。

根据定义,带有 ihl < 5 的 IPv4 标头格式错误(RFC 791:Internet 标头长度是 Internet 标头在 32 位字中的长度... 请注意,正确标头的最小值为 5。)内核不应愿意将此类数据包注入其自己的输出路径。

拒绝 iphlen < sizeof(*iph) 与 existingiphlen >长度检查。这符合重新进入 IP 堆栈的本地构造数据包必须传递 ...

请注意,描述因长度问题被截断。请参考供应商公告,获取完整描述。

Tenable 已直接从测试产品的安全公告中提取上述描述块。

请注意,Nessus 尚未测试这些问题,而是只依据应用程序自我报告的版本号进行判断。

解决方案

运行 'yum update kernel' 或 'yum update --advisory ALAS2KERNEL-5.10-2026-123' 以更新系统。

另见

https://alas.aws.amazon.com//AL2/ALAS2KERNEL-5.10-2026-123.html

https://alas.aws.amazon.com/faqs.html

https://explore.alas.aws.amazon.com/CVE-2022-50472.html

https://explore.alas.aws.amazon.com/CVE-2022-50493.html

https://explore.alas.aws.amazon.com/CVE-2022-50552.html

https://explore.alas.aws.amazon.com/CVE-2023-53178.html

https://explore.alas.aws.amazon.com/CVE-2023-53421.html

https://explore.alas.aws.amazon.com/CVE-2025-38129.html

https://explore.alas.aws.amazon.com/CVE-2025-38710.html

https://explore.alas.aws.amazon.com/CVE-2025-39877.html

https://explore.alas.aws.amazon.com/CVE-2026-23204.html

https://explore.alas.aws.amazon.com/CVE-2026-23272.html

https://explore.alas.aws.amazon.com/CVE-2026-23340.html

https://explore.alas.aws.amazon.com/CVE-2026-23442.html

https://explore.alas.aws.amazon.com/CVE-2026-31407.html

https://explore.alas.aws.amazon.com/CVE-2026-31419.html

https://explore.alas.aws.amazon.com/CVE-2026-31532.html

https://explore.alas.aws.amazon.com/CVE-2026-31577.html

https://explore.alas.aws.amazon.com/CVE-2026-31580.html

https://explore.alas.aws.amazon.com/CVE-2026-31586.html

https://explore.alas.aws.amazon.com/CVE-2026-31588.html

https://explore.alas.aws.amazon.com/CVE-2026-31590.html

https://explore.alas.aws.amazon.com/CVE-2026-31607.html

https://explore.alas.aws.amazon.com/CVE-2026-31624.html

https://explore.alas.aws.amazon.com/CVE-2026-31634.html

https://explore.alas.aws.amazon.com/CVE-2026-31656.html

https://explore.alas.aws.amazon.com/CVE-2026-31663.html

https://explore.alas.aws.amazon.com/CVE-2026-31664.html

https://explore.alas.aws.amazon.com/CVE-2026-31673.html

https://explore.alas.aws.amazon.com/CVE-2026-31676.html

https://explore.alas.aws.amazon.com/CVE-2026-31681.html

https://explore.alas.aws.amazon.com/CVE-2026-31684.html

https://explore.alas.aws.amazon.com/CVE-2026-31685.html

https://explore.alas.aws.amazon.com/CVE-2026-31692.html

https://explore.alas.aws.amazon.com/CVE-2026-31700.html

https://explore.alas.aws.amazon.com/CVE-2026-43085.html

https://explore.alas.aws.amazon.com/CVE-2026-43089.html

https://explore.alas.aws.amazon.com/CVE-2026-43093.html

https://explore.alas.aws.amazon.com/CVE-2026-43111.html

https://explore.alas.aws.amazon.com/CVE-2026-43114.html

https://explore.alas.aws.amazon.com/CVE-2026-43116.html

https://explore.alas.aws.amazon.com/CVE-2026-43117.html

https://explore.alas.aws.amazon.com/CVE-2026-43281.html

https://explore.alas.aws.amazon.com/CVE-2026-43493.html

https://explore.alas.aws.amazon.com/CVE-2026-43496.html

https://explore.alas.aws.amazon.com/CVE-2026-43502.html

https://explore.alas.aws.amazon.com/CVE-2026-45838.html

https://explore.alas.aws.amazon.com/CVE-2026-45840.html

https://explore.alas.aws.amazon.com/CVE-2026-45841.html

https://explore.alas.aws.amazon.com/CVE-2026-45842.html

https://explore.alas.aws.amazon.com/CVE-2026-45843.html

https://explore.alas.aws.amazon.com/CVE-2026-45844.html

https://explore.alas.aws.amazon.com/CVE-2026-45987.html

https://explore.alas.aws.amazon.com/CVE-2026-46002.html

https://explore.alas.aws.amazon.com/CVE-2026-46023.html

https://explore.alas.aws.amazon.com/CVE-2026-46033.html

https://explore.alas.aws.amazon.com/CVE-2026-46040.html

https://explore.alas.aws.amazon.com/CVE-2026-46043.html

https://explore.alas.aws.amazon.com/CVE-2026-46046.html

https://explore.alas.aws.amazon.com/CVE-2026-46051.html

https://explore.alas.aws.amazon.com/CVE-2026-46053.html

https://explore.alas.aws.amazon.com/CVE-2026-46070.html

https://explore.alas.aws.amazon.com/CVE-2026-46101.html

https://explore.alas.aws.amazon.com/CVE-2026-46102.html

https://explore.alas.aws.amazon.com/CVE-2026-46108.html

https://explore.alas.aws.amazon.com/CVE-2026-46109.html

https://explore.alas.aws.amazon.com/CVE-2026-46113.html

https://explore.alas.aws.amazon.com/CVE-2026-46120.html

https://explore.alas.aws.amazon.com/CVE-2026-46124.html

https://explore.alas.aws.amazon.com/CVE-2026-46128.html

https://explore.alas.aws.amazon.com/CVE-2026-46132.html

https://explore.alas.aws.amazon.com/CVE-2026-46133.html

https://explore.alas.aws.amazon.com/CVE-2026-46149.html

https://explore.alas.aws.amazon.com/CVE-2026-46150.html

https://explore.alas.aws.amazon.com/CVE-2026-46151.html

https://explore.alas.aws.amazon.com/CVE-2026-46161.html

https://explore.alas.aws.amazon.com/CVE-2026-46167.html

https://explore.alas.aws.amazon.com/CVE-2026-46172.html

https://explore.alas.aws.amazon.com/CVE-2026-46177.html

https://explore.alas.aws.amazon.com/CVE-2026-46178.html

https://explore.alas.aws.amazon.com/CVE-2026-46209.html

https://explore.alas.aws.amazon.com/CVE-2026-46214.html

https://explore.alas.aws.amazon.com/CVE-2026-46227.html

https://explore.alas.aws.amazon.com/CVE-2026-46234.html

https://explore.alas.aws.amazon.com/CVE-2026-46274.html

https://explore.alas.aws.amazon.com/CVE-2026-46294.html

https://explore.alas.aws.amazon.com/CVE-2026-46304.html

https://explore.alas.aws.amazon.com/CVE-2026-52915.html

https://explore.alas.aws.amazon.com/CVE-2026-52920.html

https://explore.alas.aws.amazon.com/CVE-2026-52921.html

https://explore.alas.aws.amazon.com/CVE-2026-52925.html

https://explore.alas.aws.amazon.com/CVE-2026-52954.html

https://explore.alas.aws.amazon.com/CVE-2026-52955.html

https://explore.alas.aws.amazon.com/CVE-2026-52957.html

https://explore.alas.aws.amazon.com/CVE-2026-52958.html

https://explore.alas.aws.amazon.com/CVE-2026-52962.html

https://explore.alas.aws.amazon.com/CVE-2026-52970.html

https://explore.alas.aws.amazon.com/CVE-2026-52972.html

https://explore.alas.aws.amazon.com/CVE-2026-52982.html

https://explore.alas.aws.amazon.com/CVE-2026-52984.html

https://explore.alas.aws.amazon.com/CVE-2026-52985.html

https://explore.alas.aws.amazon.com/CVE-2026-52986.html

https://explore.alas.aws.amazon.com/CVE-2026-52993.html

https://explore.alas.aws.amazon.com/CVE-2026-52995.html

https://explore.alas.aws.amazon.com/CVE-2026-52998.html

https://explore.alas.aws.amazon.com/CVE-2026-52999.html

https://explore.alas.aws.amazon.com/CVE-2026-53001.html

https://explore.alas.aws.amazon.com/CVE-2026-53002.html

https://explore.alas.aws.amazon.com/CVE-2026-53003.html

https://explore.alas.aws.amazon.com/CVE-2026-53004.html

https://explore.alas.aws.amazon.com/CVE-2026-53006.html

https://explore.alas.aws.amazon.com/CVE-2026-53011.html

https://explore.alas.aws.amazon.com/CVE-2026-53012.html

https://explore.alas.aws.amazon.com/CVE-2026-53016.html

https://explore.alas.aws.amazon.com/CVE-2026-53021.html

https://explore.alas.aws.amazon.com/CVE-2026-53037.html

https://explore.alas.aws.amazon.com/CVE-2026-53047.html

https://explore.alas.aws.amazon.com/CVE-2026-53050.html

https://explore.alas.aws.amazon.com/CVE-2026-53059.html

https://explore.alas.aws.amazon.com/CVE-2026-53060.html

https://explore.alas.aws.amazon.com/CVE-2026-53061.html

https://explore.alas.aws.amazon.com/CVE-2026-53062.html

https://explore.alas.aws.amazon.com/CVE-2026-53064.html

https://explore.alas.aws.amazon.com/CVE-2026-53074.html

https://explore.alas.aws.amazon.com/CVE-2026-53075.html

https://explore.alas.aws.amazon.com/CVE-2026-53077.html

https://explore.alas.aws.amazon.com/CVE-2026-53128.html

https://explore.alas.aws.amazon.com/CVE-2026-53287.html

https://explore.alas.aws.amazon.com/CVE-2026-53295.html

https://explore.alas.aws.amazon.com/CVE-2026-53304.html

https://explore.alas.aws.amazon.com/CVE-2026-53320.html

https://explore.alas.aws.amazon.com/CVE-2026-53369.html

https://explore.alas.aws.amazon.com/CVE-2026-63860.html

https://explore.alas.aws.amazon.com/CVE-2026-63875.html

https://explore.alas.aws.amazon.com/CVE-2026-64046.html

https://explore.alas.aws.amazon.com/CVE-2026-64047.html

https://explore.alas.aws.amazon.com/CVE-2026-64113.html

https://explore.alas.aws.amazon.com/CVE-2026-64114.html

https://explore.alas.aws.amazon.com/CVE-2026-64115.html

https://explore.alas.aws.amazon.com/CVE-2026-64185.html

插件详情

严重性: High

ID: 321988

文件名: al2_ALASKERNEL-5_10-2026-123.nasl

版本: 1.7

类型: Local

代理: unix

发布时间: 2026/6/22

最近更新时间: 2026/7/31

支持的传感器: Frictionless Assessment AWS, Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Continuous Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

风险信息

VPR

风险因素: High

分数: 7.8

百分位: 99.33

CVSS v2

风险因素: Medium

基本分数: 6.8

时间分数: 5.3

矢量: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS 分数来源: CVE-2026-53059

CVSS v3

风险因素: High

基本分数: 7.8

时间分数: 7

矢量: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

时间矢量: CVSS:3.0/E:P/RL:O/RC:C

漏洞信息

CPE: cpe:/o:amazon:linux:2, p-cpe:/a:amazon:linux:bpftool-debuginfo, p-cpe:/a:amazon:linux:bpftool, p-cpe:/a:amazon:linux:kernel-debuginfo-common-aarch64, p-cpe:/a:amazon:linux:kernel-debuginfo-common-x86_64, p-cpe:/a:amazon:linux:kernel-debuginfo, p-cpe:/a:amazon:linux:kernel-devel, p-cpe:/a:amazon:linux:kernel-headers, p-cpe:/a:amazon:linux:kernel-livepatch-5.10.258-257.1041, p-cpe:/a:amazon:linux:kernel-tools-debuginfo, p-cpe:/a:amazon:linux:kernel-tools-devel, p-cpe:/a:amazon:linux:kernel-tools, p-cpe:/a:amazon:linux:kernel, p-cpe:/a:amazon:linux:perf-debuginfo, p-cpe:/a:amazon:linux:perf, p-cpe:/a:amazon:linux:python-perf-debuginfo, p-cpe:/a:amazon:linux:python-perf

必需的 KB 项: Host/local_checks_enabled, Host/AmazonLinux/release, Host/AmazonLinux/rpm-list

可利用: true

易利用性: Exploits are available

补丁发布日期: 2026/6/22

漏洞发布日期: 2023/6/27

参考资料信息

CVE: CVE-2022-50472, CVE-2022-50493, CVE-2022-50552, CVE-2023-53178, CVE-2023-53421, CVE-2025-38129, CVE-2025-38710, CVE-2025-39877, CVE-2026-23204, CVE-2026-23272, CVE-2026-23340, CVE-2026-23442, CVE-2026-31407, CVE-2026-31419, CVE-2026-31532, CVE-2026-31577, CVE-2026-31580, CVE-2026-31586, CVE-2026-31588, CVE-2026-31590, CVE-2026-31607, CVE-2026-31624, CVE-2026-31634, CVE-2026-31656, CVE-2026-31663, CVE-2026-31664, CVE-2026-31673, CVE-2026-31676, CVE-2026-31681, CVE-2026-31684, CVE-2026-31685, CVE-2026-31692, CVE-2026-31700, CVE-2026-43085, CVE-2026-43089, CVE-2026-43093, CVE-2026-43111, CVE-2026-43114, CVE-2026-43116, CVE-2026-43117, CVE-2026-43281, CVE-2026-43493, CVE-2026-43496, CVE-2026-43502, CVE-2026-45838, CVE-2026-45840, CVE-2026-45841, CVE-2026-45842, CVE-2026-45843, CVE-2026-45844, CVE-2026-45987, CVE-2026-46002, CVE-2026-46023, CVE-2026-46033, CVE-2026-46040, CVE-2026-46043, CVE-2026-46046, CVE-2026-46051, CVE-2026-46053, CVE-2026-46070, CVE-2026-46101, CVE-2026-46102, CVE-2026-46108, CVE-2026-46109, CVE-2026-46113, CVE-2026-46120, CVE-2026-46124, CVE-2026-46128, CVE-2026-46132, CVE-2026-46133, CVE-2026-46149, CVE-2026-46150, CVE-2026-46151, CVE-2026-46161, CVE-2026-46167, CVE-2026-46172, CVE-2026-46177, CVE-2026-46178, CVE-2026-46209, CVE-2026-46214, CVE-2026-46227, CVE-2026-46234, CVE-2026-46274, CVE-2026-46294, CVE-2026-46304, CVE-2026-52915, CVE-2026-52920, CVE-2026-52921, CVE-2026-52925, CVE-2026-52954, CVE-2026-52955, CVE-2026-52957, CVE-2026-52958, CVE-2026-52962, CVE-2026-52970, CVE-2026-52972, CVE-2026-52982, CVE-2026-52984, CVE-2026-52985, CVE-2026-52986, CVE-2026-52993, CVE-2026-52995, CVE-2026-52998, CVE-2026-52999, CVE-2026-53001, CVE-2026-53002, CVE-2026-53003, CVE-2026-53004, CVE-2026-53006, CVE-2026-53011, CVE-2026-53012, CVE-2026-53016, CVE-2026-53021, CVE-2026-53037, CVE-2026-53047, CVE-2026-53050, CVE-2026-53059, CVE-2026-53060, CVE-2026-53061, CVE-2026-53062, CVE-2026-53064, CVE-2026-53074, CVE-2026-53075, CVE-2026-53077, CVE-2026-53128, CVE-2026-53287, CVE-2026-53295, CVE-2026-53304, CVE-2026-53320, CVE-2026-53369, CVE-2026-63860, CVE-2026-63875, CVE-2026-64046, CVE-2026-64047, CVE-2026-64113, CVE-2026-64114, CVE-2026-64115, CVE-2026-64185