Amazon Linux 2023:bpftool6.18、kernel6.18、kernel6.18-devel (ALAS2023-2026-1866)

high Nessus 插件 ID 322020

简介

远程 Amazon Linux 2023 主机缺少安全更新。

描述

因此,该软件受到 ALAS2023-2026-1866 公告中提及的多个漏洞影响。

在 Linux 内核中,以下漏洞已修复:

bpf:修复 cgroup_storage_get_next_key() (CVE-2026-45838) 中的列表结尾检测

在 Linux 内核中,以下漏洞已修复:

bpf:拒绝 bpf_core_parse_spec()CVE-2026-45839 () 中的负 CO-RE 访问器索引

在 Linux 内核中,以下漏洞已修复:

openvswitch:上限上调 PID 数组大小和预大小 vport 回复 (CVE-2026-45840)

在 Linux 内核中,以下漏洞已修复:

netfilter:nfnetlink_osf:修复 OSF_WSS_MODULO 中的除以零问题 (CVE-2026-45841)

在 Linux 内核中,以下漏洞已修复:

slip:拒绝没有 rstate 数组 (CVE-2026-45842) 的实例上的 VJ 接收数据包

在 Linux 内核中,以下漏洞已修复:

slip:针对压缩的数据包长度 ()CVE-2026-45843 绑定 decode() 读取

在 Linux 内核中,以下漏洞已修复:

netfilter:arp_tables:修复 IEEE1394 ARP 负载解析 (CVE-2026-45844)

在 Linux 内核中,以下漏洞已修复:

bareudp:修复 bareudp_fill_metadata_dst() 中的空指针取消引用 (CVE-2026-45846)

在 Linux 内核中,以下漏洞已修复:

sched_ext:在 cgroup 设置器 (CVE-2026-46154) 中scx_cgroup_ops_rwsem下的读取scx_root

在 Linux 内核中,以下漏洞已修复:

btrfs:修复可导致信息泄漏 (CVE-2026-46159) 的 TOCTOU slot_count btrfs_ioctl_space_info()

在 Linux 内核中,以下漏洞已修复:

btrfs:修复 create_space_info_sub_group() 错误路径中的双重释放 (CVE-2026-46164)

在 Linux 内核中,以下漏洞已修复:

vsock/virtio:修复非线性缓冲区的 tap skb 中的空负载 (CVE-2026-46207)

在 Linux 内核中,以下漏洞已修复:

drm/gem:修复 drm_gem_fb_init_with_funcs() (CVE-2026-46209) 中不一致的平面尺寸计算

在 Linux 内核中,以下漏洞已修复:

vsock/virtio:修复传输不匹配 (CVE-2026-46214) 时的接受队列计数泄漏

在 Linux 内核中,以下漏洞已修复:

drm:在 change_handleCVE-2026-46215 () 中进行主要交换前将旧句柄设置为 NULL

在 Linux 内核中,以下漏洞已修复:

sctp:重新验证 SCTP_SENDALL (CVE-2026-46227) 中 sctp_sendmsg_to_asoc() 之后的列表光标

在 Linux 内核中,以下漏洞已修复:

vsock:修复缓冲区大小限制顺序 (CVE-2026-46234)

在 Linux 内核中,以下漏洞已修复:

media:rc:xbox_remote:注意 DMA 限制 (CVE-2026-46236)

在 Linux 内核中,以下漏洞已修复:

eventpoll:修复ep_remove结构 eventpoll/结构文件 UAF (CVE-2026-46242)

在 Linux 内核中,以下漏洞已修复:

io-wq:检查前置任务是否在 io_wq_remove_pending() (CVE-2026-46274) 中执行哈希处理

在 Linux 内核中,以下漏洞已修复:

netfilter:nf_tables:将list_del_rcu用于 netlink 挂钩 (CVE-2026-46324)

在 Linux 内核中,以下漏洞已修复:

netfilter:xt_policy:修复严格模式入站策略匹配 (CVE-2026-52920)

在 Linux 内核中,以下漏洞已修复:

vrf:修复从 VRF 中删除端口时潜在的 NPD (CVE-2026-52925)

在 Linux 内核中,以下漏洞已修复:

crypto:jitterentropy - 用互斥体 (CVE-2026-52936) 替换长期持有的旋转锁

在 Linux 内核中,以下漏洞已修复:

iommu/vt-d:修复因超出范围访问而造成的 oops (CVE-2026-52953)

在 Linux 内核中,以下漏洞已修复:

libceph:处理 decode_choose_args() 中的 rbtree 插入错误 (CVE-2026-52954)

在 Linux 内核中,以下漏洞已修复:

libceph:修复 crush_decode() (CVE-2026-52955) 中潜在的越界访问

在 Linux 内核中,以下漏洞已修复:

libceph:修复 decode_choose_args() (CVE-2026-52957) 中潜在的 null-ptr-deref

在 Linux 内核中,以下漏洞已修复:

libceph:修复 osdmap_decode() (CVE-2026-52958) 中潜在的越界访问

在 Linux 内核中,以下漏洞已修复:

virt:sev-guest:不在清理路径 (CVE-2026-52959) 中使用主机控制的页序

在 Linux 内核中,以下漏洞已修复:

ceph:修复 __ceph_build_xattrs_blob() 中因过时 blob 大小造成的 BUG_ON (CVE-2026-52961)

在 Linux 内核中,以下漏洞已修复:

ceph:修复 __ceph_setxattr() (CVE-2026-52962) 中的缓冲区泄漏

在 Linux 内核中,以下漏洞已修复:

smb/client:修复 symlink_data() (CVE-2026-52967) 中可能的无限循环和 OOB 读取

在 Linux 内核中,以下漏洞已修复:

KVM:拒绝 kvm_reset_dirty_gfn() (CVE-2026-52969) 中的封装偏移

在 Linux 内核中,以下漏洞已修复:

netfilter:nft_ct:修复 obj eval (CVE-2026-52970) 中缺少的预期

在 Linux 内核中,以下漏洞已修复:

crypto:af_alg - 将 AEAD AD 长度上限设为 0x80000000 (CVE-2026-52972)

在 Linux 内核中,以下漏洞已修复:

futex:终止对私有默认哈希 alloc (CVE-2026-52973) 的CLONE_THREAD要求

在 Linux 内核中,以下漏洞已修复:

net:tls:修复卸载 RX 设置失败 () 中的 strparser 定位标记 skb 泄漏 (CVE-2026-52974)

在 Linux 内核中,以下漏洞已修复:

bonding:3ad:实现 port->aggregator (CVE-2026-52975) 的适当 RCU 规则

在 Linux 内核中,以下漏洞已修复:

futex:信号/超时唤醒 (CVE-2026-52977) 期间防止 requeue-PI 中的锁定

在 Linux 内核中,以下漏洞已修复:

net:psp:需要 dev-set 和 key-rotate (CVE-2026-52978) 的管理员权限

在 Linux 内核中,以下漏洞已修复:

net:psp:创建 assoc (CVE-2026-52979) 时检查设备注销注册

在 Linux 内核中,以下漏洞已修复:

sched/fair:初始化 fork 实体时清除rel_deadline (CVE-2026-52980)

在 Linux 内核中,以下漏洞已修复:

neigh:让 neigh_xmit 获得 skb 所有权 (CVE-2026-52981)

在 Linux 内核中,以下漏洞已修复:

net/sched:netem:修复队列限制检查以包括重新排序的数据包

netem_enqueue() 中的队列限制检查使用 q->t_len,它仅对内部 tfifo 中的数据包进行计数。
通过重新排序路径 (__qdisc_enqueue_head) 放置在 sch->q 中的数据包不计算在内,从而允许重新排序下的总队列占用率超过 sch->limit。

在限制检查中包含 sch->q.qlen。(CVE-2026-52984)

在 Linux 内核中,以下漏洞已修复:

netdevsim:零初始化虚拟sk_buff中的结构 iphdr (CVE-2026-52985)

在 Linux 内核中,以下漏洞已修复:

netfilter:nf_conntrack_sip:不使用 simple_strtoul (CVE-2026-52986)

在 Linux 内核中,以下漏洞已修复:

fsnotify:修复 fsnotify_recalc_mask() 中的 inode 引用泄漏 (CVE-2026-52990)

在 Linux 内核中,以下漏洞已修复:

sched/psi:修复文件释放和压力写入 (CVE-2026-52991) 之间的争用

在 Linux 内核中,以下漏洞已修复:

tipc:修复 tipc_buf_append() 中的双重释放 (CVE-2026-52993)

在 Linux 内核中,以下漏洞已修复:

vsock/virtio:修复MSG_ZEROCOPY固定页面记账 (CVE-2026-52994)

在 Linux 内核中,以下漏洞已修复:

net/rds:将每项信息缓冲区交给访问者之前将其设置为零 (CVE-2026-52995)

在 Linux 内核中,以下漏洞已修复:

net/sched:sch_dualpi2:同时耗尽 dualpi2_change() (CVE-2026-52997) 中的 C 队列和 L 队列

在 Linux 内核中,以下漏洞已修复:

netfilter:nfnetlink_osf:修复 ttl 检查 (CVE-2026-52998) 中潜在的空取消引用

在 Linux 内核中,以下漏洞已修复:

netfilter:nfnetlink_osf:修复选项匹配 (CVE-2026-52999) 的越界读取

在 Linux 内核中,以下漏洞已修复:

netfilter:nat:使用 kfree_rcu 来释放 ops (CVE-2026-53000)

在 Linux 内核中,以下漏洞已修复:

netfilter:xtables:将多个匹配项限制为 inet 系列 (CVE-2026-53001)

在 Linux 内核中,以下漏洞已修复:

netfilter:conntrack:删除 sprintf 使用情况 (CVE-2026-53002)

在 Linux 内核中,以下漏洞已修复:

pppoe:终止 PFC 帧 (CVE-2026-53003)

在 Linux 内核中,以下漏洞已修复:

sctp:修复对 sctp_getsockopt_peer_auth_chunks (CVE-2026-53004) 中用户空间的越界写入

在 Linux 内核中,以下漏洞已修复:

ipv6:修复 icmpv6_rcv() (CVE-2026-53006) 中可能的 UAF

在 Linux 内核中,以下漏洞已修复:

ice:修复 skb tx_buf的双重释放 (CVE-2026-53009)

在 Linux 内核中,以下漏洞已修复:

net/sched:taprio:在计划切换 ()CVE-2026-53011 上修复 advance_sched() 中的释放后使用

在 Linux 内核中,以下漏洞已修复:

nexthop:修复引用 IPv4 nexthop (CVE-2026-53012) 的 IPv6 路由

在 Linux 内核中,以下漏洞已修复:

macvlan:修复 macvlan_get_size() 不为 IFLA_MACVLAN_BC_CUTOFF (CVE-2026-53013) 预留空间的问题

在 Linux 内核中,以下漏洞已修复:

net/sched:act_mirred:修复tcf_blockcast_redir (CVE-2026-53014) 中 mac_header_xmit 检查的错误设备

在 Linux 内核中,以下漏洞已修复:

erofs:对于 32 位平台,将 LCN 统一为 u64 (CVE-2026-53015)

在 Linux 内核中,以下漏洞已修复:

scsi:target:core:修复 UNMAP 边界检查 (CVE-2026-53021) 中的整数溢出

在 Linux 内核中,以下漏洞已修复:

fs/ntfs3:在 UTF-8 转换后终止缓存的卷标签 (CVE-2026-53023)

在 Linux 内核中,以下漏洞已修复:

NFSD:修复 nfsd4_add_rdaccess_to_wrdeleg 中的 nfs4_file 访问额外计数 (CVE-2026-53026)

在 Linux 内核中,以下漏洞已修复:

bpf:验证 arena_alloc_pages() (CVE-2026-53031) 中的node_id

在 Linux 内核中,以下漏洞已修复:

bpf:修复标量 regs 的 map_kptr_match_type 中的空取消引用 (CVE-2026-53032)

在 Linux 内核中,以下漏洞已修复:

bpf、sockmap:为 af_unix iter (CVE-2026-53033) 进行状态锁定

在 Linux 内核中,以下漏洞已修复:

bpf、sockmap:修复 proto 更新 (CVE-2026-53034) 中的af_unix null-ptr-deref

在 Linux 内核中,以下漏洞已修复:

bpf、sockmap:修复 af_unix iter 死锁 (CVE-2026-53035)

在 Linux 内核中,以下漏洞已修复:

bpf、arm64:修复已签名范围检查 (CVE-2026-53036check_imm) 中的差一

在 Linux 内核中,以下漏洞已修复:

HID:usbhid:修复 hid_post_reset() (CVE-2026-53037) 中的死锁

在 Linux 内核中,以下漏洞已修复:

ima_fs:为不受支持的哈希算法正确创建 securityfs 文件 (CVE-2026-53038)

在 Linux 内核中,以下漏洞已修复:

efi/capsule-loader:修复 phys 数组重新分配 (CVE-2026-53047) 中错误的 sizeof

在 Linux 内核中,以下漏洞已修复:

quota:通过配额停用 (CVE-2026-53050) 修复 dquot_scan_active() 的争用

在 Linux 内核中,以下漏洞已修复:

iommu/amd:修复 clone_alias() 以使用原始设备的 devid (CVE-2026-53053)

在 Linux 内核中,以下漏洞已修复:

dm log:修复了region_count溢出导致的越界写入 (CVE-2026-53059)

在 Linux 内核中,以下漏洞已修复:

dm 缓存元数据:修复元数据中止重试 (CVE-2026-53060) 时的内存泄漏

在 Linux 内核中,以下漏洞已修复:

dm cache:修复传递模式切换中的脏映射检查 (CVE-2026-53061)

在 Linux 内核中,以下漏洞已修复:

dm 缓存策略 smq:修复使缓存块无效化时缺少的锁定 (CVE-2026-53062)

在 Linux 内核中,以下漏洞已修复:

dm cache:修复传递模式中的写入挂起 (CVE-2026-53063)

在 Linux 内核中,以下漏洞已修复:

dm cache:修复传递模式下并发写入的 null-deref (CVE-2026-53064)

在 Linux 内核中,以下漏洞已修复:

PCI:端点:pci-ep-msi:修复错误展开并防止双重 alloc (CVE-2026-53067)

在 Linux 内核中,以下漏洞已修复:

net、bpf:修复下xdp_master_redirect masterCVE-2026-53069() 中的 null-ptr-deref

在 Linux 内核中,以下漏洞已修复:

bpf:拒绝 bpf_prog_test_run_skb 中的短 IPv4/IPv6 输入 (CVE-2026-53074)

在 Linux 内核中,以下漏洞已修复:

ppp:在未附加的 ioctls 的目标 netns 中要求CAP_NET_ADMIN (CVE-2026-53075)

在 Linux 内核中,以下漏洞已修复:

bpf:修复 pcpu_init_value 中的 OOB (CVE-2026-53076)

在 Linux 内核中,以下漏洞已修复:

net/rds:将 RDS/IB 的使用限制在初始网络命名空间 (CVE-2026-53077)

在 Linux 内核中,以下漏洞已修复:

bpf:强制执行 regsafe 基本 ID 一致性以用于 BPF_ADD_CONST 标量 (CVE-2026-53081)

在 Linux 内核中,以下漏洞已修复:

bpf:修复 bpf_fd_array_map_clear() (CVE-2026-53083) 中的 RCU 停止

在 Linux 内核中,以下漏洞已修复:

bpf:返回来自 task_vma 迭代器 (CVE-2026-53084) 的 VMA 快照

在 Linux 内核中,以下漏洞已修复:

bpf:修复开放代码 task_vma 迭代器中的 mm 生命周期 (CVE-2026-53085)

在 Linux 内核中,以下漏洞已修复:

bpf:修复 src_reg == dst_reg (CVE-2026-53092) 时链接的 reg 增量跟踪

在 Linux 内核中,以下漏洞已修复:

bpf:修复了常量伪装 (CVE-2026-53094) 后过时的 offload->prog 指针

在 Linux 内核中,以下漏洞已修复:

bpf:修复通过 freplace (CVE-2026-53095) 滥用的kprobe_write_ctx

在 Linux 内核中,以下漏洞已修复:

bpf:在 dev_map_redirect_multi() SKB 路径 (CVE-2026-53096) 中使用 RCU-safe 迭代

在 Linux 内核中,以下漏洞已修复:

s390/bpf:零扩展 bpf prog 返回值和 kfunc 参数 (CVE-2026-53110)

在 Linux 内核中,以下漏洞已修复:

bpf:test_run:修复 bpf_lwt_xmit_push_encap 中的空指针取消引用问题 (CVE-2026-53111)

在 Linux 内核中,以下漏洞已修复:

perf/amd/ibs:避免从 IBS NMI 处理程序 (CVE-2026-53114) 调用 perf_allow_kernel()

在 Linux 内核中,以下漏洞已修复:

bus:fsl-mc:使用通用 driver_override 基础架构 (CVE-2026-53115)

在 Linux 内核中,以下漏洞已修复:

platform/wmi:使用通用 driver_override 基础架构 (CVE-2026-53119)

在 Linux 内核中,以下漏洞已修复:

PCI:使用通用 driver_override 基础架构 (CVE-2026-53120)

在 Linux 内核中,以下漏洞已修复:

amd-pstate:修复 amd_pstate_epp_cpu_init() (CVE-2026-53121) 中的内存泄漏

在 Linux 内核中,以下漏洞已修复:

btrfs:修复使用 flushoncommit (CVE-2026-53122) 时 reflink 和事务提交之间的死锁

在 Linux 内核中,以下漏洞已修复:

md:暂停前唤醒 raid456 reshape 等待程序 (CVE-2026-53123)

在 Linux 内核中,以下漏洞已修复:

md:修复 array_state=clear sysfs 死锁 (CVE-2026-53125)

在 Linux 内核中,以下漏洞已修复:

blk-cgroup:修复 blkcg_maybe_throttle_current() (CVE-2026-53126) 中的磁盘引用泄漏

在 Linux 内核中,以下漏洞已修复:

drbd:平衡 drbd_adm_dump_devices() (CVE-2026-53128) 中的 RCU 调用

在 Linux 内核中,以下漏洞已修复:

fs/mbcache:破坏缓存前取消收缩工作 (CVE-2026-53129)

在 Linux 内核中,以下漏洞已修复:

iommu/vt-d:避免空指针取消引用或引用计数损坏

提交 60f030f7418d (iommu/vt-d:避免在 WARN_ON_ONCE 后使用空)在不太可能的情况下部分修复了空指针取消引用。

如果在dev_pasids列表中找不到dev_pasid,则它仍然保持 NULL。但是会无条件执行拆卸操作,这会导致空指针取消引用或引用计数损坏。

如果域从未附加到此 IOMMU,则 info 将为空,这会在检查 --info->refcnt 时造成立即取消引用。

即使 info 不是 NULL,在不删除有效 PASID 的情况下递减 refcount 也可能会使计数不平衡。这可能导致引用计数过早降至 0,从而可能对共享该域的其余活动设备造成释放后使用。

如果 dev_pasid 为 NULL,则通过在执行拆卸操作之前提早返回来修复该问题。

问题由 AI 审查发现,并由 Kevin Tian 提出建议。https://sashiko.dev/#/patchset/20260421031347.1408890-1-zhenzhong.duan%40intel.com (CVE-2026-53281)

在 Linux 内核中,以下漏洞已修复:

x86/kexec:即使对非 kjump kexec 也推送 kjump 返回地址 (CVE-2026-53282)

在 Linux 内核中,以下漏洞已修复:

iommu/amd:__rlookup_amd_iommu() (CVE-2026-53283) 中的边界检查 devid

在 Linux 内核中,以下漏洞已修复:

btrfs:成功写入后仅释放脏页 io 树 (CVE-2026-53284)

在 Linux 内核中,以下漏洞已修复:

audit:修复 CAPSET 记录中不正确的可继承功能

__audit_log_capset() 将由于复制粘贴错误而导致的有效功能集记录到可继承字段中。因此,每个 CAPSET auditrecord 都会报告cap_pi(进程可继承),值为 cap_effective 而不是 cap_inheritable。

这会静默地损坏用于合规性和取证分析的审计数据:修改可继承功能以准备权限升级 exec 的攻击者将在审计跟踪中屏蔽该更改。

自 2008 年首次引入 CAPSETaudit 记录以来,此缺陷一直存在。(CVE-2026-53287)

在 Linux 内核中,以下漏洞已修复:

arm64:为早期内核映射预留额外页面 (CVE-2026-53288)

在 Linux 内核中,以下漏洞已修复:

ice:修复 ice_reset_all_vfs() 中的空指针取消引用 (CVE-2026-53289)

在 Linux 内核中,以下漏洞已修复:

mailbox:添加通道数组的健全性检查

如果邮箱控制器未附加通道数组,则正常失败。否则,较后的取消引用将导致可能看不到的 OOPS,因为邮箱控制器可能每年实例化一次。删除解释此处显而易见的评论。(CVE-2026-53295)

在 Linux 内核中,以下漏洞已修复:

scsi:sg:解决打开 /dev/sgX (CVE-2026-53304) 时的软锁定问题

在 Linux 内核中,以下漏洞已修复:

pinctrl:pinconf-generic:完全验证“pinmux”属性 (CVE-2026-53307)

在 Linux 内核中,以下漏洞已修复:

padata:将 CPU 离线回调置于 ONLINE 部分以允许失败

syzbot 报告了以下警告:

CPU1WARNING的 DEAD 回调错误:kernel/cpu.c:1463 at _cpu_down+0x759/0x1020 kernel/cpu.c:1463 CPU#0, :
syz.0.1960/14614

在提交 4ae12d8bd9a8(合并 git://git.kernel.org/pub/scm/linux/kernel/git/kbuild/linux 的标记“kbuild-fixes-7.0-2”)时,tglx 会跟踪到 padata_cpu_dead(),因为它是返回错误的唯一子CPUHP_TEARDOWN_CPU回调。

在将 CPU 离线回调移至可能失败的 ONLINE 部分之前CPUHP_TEARDOWN_CPUso热插拔状态下不允许失败。(CVE-2026-53314)

在 Linux 内核中,以下漏洞已修复:

io_uring/napi:上限busy_poll_to 10 毫秒

目前,未找到事件时 napi 可以轮询的最长时间没有上限,这可导致 kernelcomplaints 对任务卡住,因为该循环内没有条件的重新安排完成。

只需将其总计限制在 10 毫秒,这已经远远高于任何一种可以获得任何好处的合理值,但又足够低,以至于它几乎可以触发抢占投诉。
(CVE-2026-53321)

在 Linux 内核中,以下漏洞已修复:

net:dsa:从 conduit ethtool ops (CVE-2026-53323) 删除冗余的 netdev_lock_ops()

在 Linux 内核中,以下漏洞已修复:

RDMA/core:首选 NLA_NUL_STRING

这些属性作为 c 字符串(传递到 strcmp)进行评估,butNLA_STRING不检查是否存在 \0 终止符。

这需要切换到 nla_strcmp() 并需要调整 printf fmtspecifier 以不使用普通 %s,或者这需要使用NLA_NUL_STRING。

由于代码长期以来一直如此,在我看来,用户空间确实包括终止 nul,甚至到目前为止还没有强制执行,因此使用NLA_NUL_STRING更简单的解决方案。
(CVE-2026-63860)

在 Linux 内核中,以下漏洞已修复:

bpf:从 lsm 可休眠挂钩 (CVE-2026-63865) 中丢弃task_to_inode和inet_conn_established

Tenable 已直接从测试产品的安全公告中提取上述描述块。

请注意,Nessus 尚未测试这些问题,而是只依据应用程序自我报告的版本号进行判断。

解决方案

运行“dnf update kernel6.18 --releasever 2023.12.20260622”或“dnf update --advisory ALAS2023-2026-1866 --releasever 2023.12.20260622”以更新系统。

另见

https://alas.aws.amazon.com//AL2023/ALAS2023-2026-1866.html

https://alas.aws.amazon.com/faqs.html

https://explore.alas.aws.amazon.com/CVE-2026-45838.html

https://explore.alas.aws.amazon.com/CVE-2026-45839.html

https://explore.alas.aws.amazon.com/CVE-2026-45840.html

https://explore.alas.aws.amazon.com/CVE-2026-45841.html

https://explore.alas.aws.amazon.com/CVE-2026-45842.html

https://explore.alas.aws.amazon.com/CVE-2026-45843.html

https://explore.alas.aws.amazon.com/CVE-2026-45844.html

https://explore.alas.aws.amazon.com/CVE-2026-45846.html

https://explore.alas.aws.amazon.com/CVE-2026-46154.html

https://explore.alas.aws.amazon.com/CVE-2026-46159.html

https://explore.alas.aws.amazon.com/CVE-2026-46164.html

https://explore.alas.aws.amazon.com/CVE-2026-46207.html

https://explore.alas.aws.amazon.com/CVE-2026-46209.html

https://explore.alas.aws.amazon.com/CVE-2026-46214.html

https://explore.alas.aws.amazon.com/CVE-2026-46215.html

https://explore.alas.aws.amazon.com/CVE-2026-46227.html

https://explore.alas.aws.amazon.com/CVE-2026-46234.html

https://explore.alas.aws.amazon.com/CVE-2026-46236.html

https://explore.alas.aws.amazon.com/CVE-2026-46242.html

https://explore.alas.aws.amazon.com/CVE-2026-46274.html

https://explore.alas.aws.amazon.com/CVE-2026-46324.html

https://explore.alas.aws.amazon.com/CVE-2026-52920.html

https://explore.alas.aws.amazon.com/CVE-2026-52925.html

https://explore.alas.aws.amazon.com/CVE-2026-52936.html

https://explore.alas.aws.amazon.com/CVE-2026-52953.html

https://explore.alas.aws.amazon.com/CVE-2026-52954.html

https://explore.alas.aws.amazon.com/CVE-2026-52955.html

https://explore.alas.aws.amazon.com/CVE-2026-52957.html

https://explore.alas.aws.amazon.com/CVE-2026-52958.html

https://explore.alas.aws.amazon.com/CVE-2026-52959.html

https://explore.alas.aws.amazon.com/CVE-2026-52961.html

https://explore.alas.aws.amazon.com/CVE-2026-52962.html

https://explore.alas.aws.amazon.com/CVE-2026-52967.html

https://explore.alas.aws.amazon.com/CVE-2026-52969.html

https://explore.alas.aws.amazon.com/CVE-2026-52970.html

https://explore.alas.aws.amazon.com/CVE-2026-52972.html

https://explore.alas.aws.amazon.com/CVE-2026-52973.html

https://explore.alas.aws.amazon.com/CVE-2026-52974.html

https://explore.alas.aws.amazon.com/CVE-2026-52975.html

https://explore.alas.aws.amazon.com/CVE-2026-52977.html

https://explore.alas.aws.amazon.com/CVE-2026-52978.html

https://explore.alas.aws.amazon.com/CVE-2026-52979.html

https://explore.alas.aws.amazon.com/CVE-2026-52980.html

https://explore.alas.aws.amazon.com/CVE-2026-52981.html

https://explore.alas.aws.amazon.com/CVE-2026-52984.html

https://explore.alas.aws.amazon.com/CVE-2026-52985.html

https://explore.alas.aws.amazon.com/CVE-2026-52986.html

https://explore.alas.aws.amazon.com/CVE-2026-52990.html

https://explore.alas.aws.amazon.com/CVE-2026-52991.html

https://explore.alas.aws.amazon.com/CVE-2026-52993.html

https://explore.alas.aws.amazon.com/CVE-2026-52994.html

https://explore.alas.aws.amazon.com/CVE-2026-52995.html

https://explore.alas.aws.amazon.com/CVE-2026-52997.html

https://explore.alas.aws.amazon.com/CVE-2026-52998.html

https://explore.alas.aws.amazon.com/CVE-2026-52999.html

https://explore.alas.aws.amazon.com/CVE-2026-53000.html

https://explore.alas.aws.amazon.com/CVE-2026-53001.html

https://explore.alas.aws.amazon.com/CVE-2026-53002.html

https://explore.alas.aws.amazon.com/CVE-2026-53003.html

https://explore.alas.aws.amazon.com/CVE-2026-53004.html

https://explore.alas.aws.amazon.com/CVE-2026-53006.html

https://explore.alas.aws.amazon.com/CVE-2026-53009.html

https://explore.alas.aws.amazon.com/CVE-2026-53011.html

https://explore.alas.aws.amazon.com/CVE-2026-53012.html

https://explore.alas.aws.amazon.com/CVE-2026-53013.html

https://explore.alas.aws.amazon.com/CVE-2026-53014.html

https://explore.alas.aws.amazon.com/CVE-2026-53015.html

https://explore.alas.aws.amazon.com/CVE-2026-53021.html

https://explore.alas.aws.amazon.com/CVE-2026-53023.html

https://explore.alas.aws.amazon.com/CVE-2026-53026.html

https://explore.alas.aws.amazon.com/CVE-2026-53031.html

https://explore.alas.aws.amazon.com/CVE-2026-53032.html

https://explore.alas.aws.amazon.com/CVE-2026-53033.html

https://explore.alas.aws.amazon.com/CVE-2026-53034.html

https://explore.alas.aws.amazon.com/CVE-2026-53035.html

https://explore.alas.aws.amazon.com/CVE-2026-53036.html

https://explore.alas.aws.amazon.com/CVE-2026-53037.html

https://explore.alas.aws.amazon.com/CVE-2026-53038.html

https://explore.alas.aws.amazon.com/CVE-2026-53047.html

https://explore.alas.aws.amazon.com/CVE-2026-53050.html

https://explore.alas.aws.amazon.com/CVE-2026-53053.html

https://explore.alas.aws.amazon.com/CVE-2026-53059.html

https://explore.alas.aws.amazon.com/CVE-2026-53060.html

https://explore.alas.aws.amazon.com/CVE-2026-53061.html

https://explore.alas.aws.amazon.com/CVE-2026-53062.html

https://explore.alas.aws.amazon.com/CVE-2026-53063.html

https://explore.alas.aws.amazon.com/CVE-2026-53064.html

https://explore.alas.aws.amazon.com/CVE-2026-53067.html

https://explore.alas.aws.amazon.com/CVE-2026-53069.html

https://explore.alas.aws.amazon.com/CVE-2026-53074.html

https://explore.alas.aws.amazon.com/CVE-2026-53075.html

https://explore.alas.aws.amazon.com/CVE-2026-53076.html

https://explore.alas.aws.amazon.com/CVE-2026-53077.html

https://explore.alas.aws.amazon.com/CVE-2026-53081.html

https://explore.alas.aws.amazon.com/CVE-2026-53083.html

https://explore.alas.aws.amazon.com/CVE-2026-53084.html

https://explore.alas.aws.amazon.com/CVE-2026-53085.html

https://explore.alas.aws.amazon.com/CVE-2026-53092.html

https://explore.alas.aws.amazon.com/CVE-2026-53094.html

https://explore.alas.aws.amazon.com/CVE-2026-53095.html

https://explore.alas.aws.amazon.com/CVE-2026-53096.html

https://explore.alas.aws.amazon.com/CVE-2026-53110.html

https://explore.alas.aws.amazon.com/CVE-2026-53111.html

https://explore.alas.aws.amazon.com/CVE-2026-53114.html

https://explore.alas.aws.amazon.com/CVE-2026-53115.html

https://explore.alas.aws.amazon.com/CVE-2026-53119.html

https://explore.alas.aws.amazon.com/CVE-2026-53120.html

https://explore.alas.aws.amazon.com/CVE-2026-53121.html

https://explore.alas.aws.amazon.com/CVE-2026-53122.html

https://explore.alas.aws.amazon.com/CVE-2026-53123.html

https://explore.alas.aws.amazon.com/CVE-2026-53125.html

https://explore.alas.aws.amazon.com/CVE-2026-53126.html

https://explore.alas.aws.amazon.com/CVE-2026-53128.html

https://explore.alas.aws.amazon.com/CVE-2026-53129.html

https://explore.alas.aws.amazon.com/CVE-2026-53281.html

https://explore.alas.aws.amazon.com/CVE-2026-53282.html

https://explore.alas.aws.amazon.com/CVE-2026-53283.html

https://explore.alas.aws.amazon.com/CVE-2026-53284.html

https://explore.alas.aws.amazon.com/CVE-2026-53287.html

https://explore.alas.aws.amazon.com/CVE-2026-53288.html

https://explore.alas.aws.amazon.com/CVE-2026-53289.html

https://explore.alas.aws.amazon.com/CVE-2026-53295.html

https://explore.alas.aws.amazon.com/CVE-2026-53304.html

https://explore.alas.aws.amazon.com/CVE-2026-53307.html

https://explore.alas.aws.amazon.com/CVE-2026-53314.html

https://explore.alas.aws.amazon.com/CVE-2026-53321.html

https://explore.alas.aws.amazon.com/CVE-2026-53323.html

https://explore.alas.aws.amazon.com/CVE-2026-63860.html

https://explore.alas.aws.amazon.com/CVE-2026-63865.html

https://explore.alas.aws.amazon.com/CVE-2026-64379.html

插件详情

严重性: High

ID: 322020

文件名: al2023_ALAS2023-2026-1866.nasl

版本: 1.5

类型: Local

代理: unix

发布时间: 2026/6/22

最近更新时间: 2026/8/6

支持的传感器: Frictionless Assessment AWS, Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Continuous Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

风险信息

VPR

风险因素: High

分数: 7.9

百分位: 99.35

CVSS v2

风险因素: Medium

基本分数: 6.8

时间分数: 5.3

矢量: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS 分数来源: CVE-2026-53129

CVSS v3

风险因素: High

基本分数: 7.8

时间分数: 7

矢量: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

时间矢量: CVSS:3.0/E:P/RL:O/RC:C

漏洞信息

CPE: cpe:/o:amazon:linux:2023, p-cpe:/a:amazon:linux:bpftool6.18-debuginfo, p-cpe:/a:amazon:linux:bpftool6.18, p-cpe:/a:amazon:linux:kernel-livepatch-6.18.33-63.124, p-cpe:/a:amazon:linux:kernel6.18-debuginfo-common-aarch64, p-cpe:/a:amazon:linux:kernel6.18-debuginfo-common-x86_64, p-cpe:/a:amazon:linux:kernel6.18-debuginfo, p-cpe:/a:amazon:linux:kernel6.18-devel, p-cpe:/a:amazon:linux:kernel6.18-headers, p-cpe:/a:amazon:linux:kernel6.18-modules-extra-common, p-cpe:/a:amazon:linux:kernel6.18-modules-extra, p-cpe:/a:amazon:linux:kernel6.18-tools-debuginfo, p-cpe:/a:amazon:linux:kernel6.18-tools-devel, p-cpe:/a:amazon:linux:kernel6.18-tools, p-cpe:/a:amazon:linux:kernel6.18, p-cpe:/a:amazon:linux:perf6.18-debuginfo, p-cpe:/a:amazon:linux:perf6.18, p-cpe:/a:amazon:linux:python3-perf6.18-debuginfo, p-cpe:/a:amazon:linux:python3-perf6.18

必需的 KB 项: Host/local_checks_enabled, Host/AmazonLinux/release, Host/AmazonLinux/rpm-list

可利用: true

易利用性: Exploits are available

补丁发布日期: 2026/6/22

漏洞发布日期: 2026/5/27

参考资料信息

CVE: CVE-2026-45838, CVE-2026-45839, CVE-2026-45840, CVE-2026-45841, CVE-2026-45842, CVE-2026-45843, CVE-2026-45844, CVE-2026-45846, CVE-2026-46154, CVE-2026-46159, CVE-2026-46164, CVE-2026-46207, CVE-2026-46209, CVE-2026-46214, CVE-2026-46215, CVE-2026-46227, CVE-2026-46234, CVE-2026-46236, CVE-2026-46242, CVE-2026-46274, CVE-2026-46324, CVE-2026-52920, CVE-2026-52925, CVE-2026-52936, CVE-2026-52953, CVE-2026-52954, CVE-2026-52955, CVE-2026-52957, CVE-2026-52958, CVE-2026-52959, CVE-2026-52961, CVE-2026-52962, CVE-2026-52967, CVE-2026-52969, CVE-2026-52970, CVE-2026-52972, CVE-2026-52973, CVE-2026-52974, CVE-2026-52975, CVE-2026-52977, CVE-2026-52978, CVE-2026-52979, CVE-2026-52980, CVE-2026-52981, CVE-2026-52984, CVE-2026-52985, CVE-2026-52986, CVE-2026-52990, CVE-2026-52991, CVE-2026-52993, CVE-2026-52994, CVE-2026-52995, CVE-2026-52997, CVE-2026-52998, CVE-2026-52999, CVE-2026-53000, CVE-2026-53001, CVE-2026-53002, CVE-2026-53003, CVE-2026-53004, CVE-2026-53006, CVE-2026-53009, CVE-2026-53011, CVE-2026-53012, CVE-2026-53013, CVE-2026-53014, CVE-2026-53015, CVE-2026-53021, CVE-2026-53023, CVE-2026-53026, CVE-2026-53031, CVE-2026-53032, CVE-2026-53033, CVE-2026-53034, CVE-2026-53035, CVE-2026-53036, CVE-2026-53037, CVE-2026-53038, CVE-2026-53047, CVE-2026-53050, CVE-2026-53053, CVE-2026-53059, CVE-2026-53060, CVE-2026-53061, CVE-2026-53062, CVE-2026-53063, CVE-2026-53064, CVE-2026-53067, CVE-2026-53069, CVE-2026-53074, CVE-2026-53075, CVE-2026-53076, CVE-2026-53077, CVE-2026-53081, CVE-2026-53083, CVE-2026-53084, CVE-2026-53085, CVE-2026-53092, CVE-2026-53094, CVE-2026-53095, CVE-2026-53096, CVE-2026-53110, CVE-2026-53111, CVE-2026-53114, CVE-2026-53115, CVE-2026-53119, CVE-2026-53120, CVE-2026-53121, CVE-2026-53122, CVE-2026-53123, CVE-2026-53125, CVE-2026-53126, CVE-2026-53128, CVE-2026-53129, CVE-2026-53281, CVE-2026-53282, CVE-2026-53283, CVE-2026-53284, CVE-2026-53287, CVE-2026-53288, CVE-2026-53289, CVE-2026-53295, CVE-2026-53304, CVE-2026-53307, CVE-2026-53314, CVE-2026-53321, CVE-2026-53323, CVE-2026-63860, CVE-2026-63865, CVE-2026-64379