Amazon Linux 2023:bpftool6.18、kernel6.18、kernel6.18-devel (ALAS2023-2026-1881)

high Nessus 插件 ID 322087

简介

远程 Amazon Linux 2023 主机缺少安全更新。

描述

因此,该软件受到 ALAS2023-2026-1881 公告中提及的多个漏洞影响。

在 Linux 内核中,以下漏洞已修复:

fs/ntfs3:处理截断文件 (CVE-2025-71289) 时的 attr_set_size() 错误

在 Linux 内核中,以下漏洞已修复:

smb:客户端:在 cifsacl 中重写 DACL 之前对其进行全面验证 (CVE-2026-31709)

在 Linux 内核中,以下漏洞已修复:

netfilter:nft_inner:修复 IPv6 inner_thoff desync (CVE-2026-46244)

在 Linux 内核中,以下漏洞已修复:

io_uring/waitid:将 waitid 信息复制到 userspace (CVE-2026-46315) 之前清除 waitid 信息

在 Linux 内核中,以下漏洞已修复:

KVM:arm64:vgic-its:仅删除已删除条目 (CVE-2026-46316) 的转换缓存引用

在 Linux 内核中,以下漏洞已修复:

KVM:arm64:重新分配 nested_mmus mmu_lock (CVE-2026-46317) 后面的数组

在 Linux 内核中,以下漏洞已修复:

tun:tun_xdp_one() (CVE-2026-46321) 中的短框架拒绝的释放页

在 Linux 内核中,以下漏洞已修复:

tun:tun_xdp_one() (CVE-2026-46322) 中build_skb失败的释放页面

在 Linux 内核中,以下漏洞已修复:

netfilter:nf_queue:排队时保持桥接 skb->dev (CVE-2026-52912)

在 Linux 内核中,以下漏洞已修复:

netfilter:ip6t_hbh:拒绝超大选项列表 (CVE-2026-52915)

在 Linux 内核中,以下漏洞已修复:

netfilter:ipset:停止哈希:* 结束时的范围迭代 (CVE-2026-52921)

在 Linux 内核中,以下漏洞已修复:

ipc:将next_id分配限制为有效 ID 范围 (CVE-2026-52923)

在 Linux 内核中,以下漏洞已修复:

xfrm:ipcomp:acomp 错误 (CVE-2026-52932) 时释放目标页面

在 Linux 内核中,以下漏洞已修复:

tap:修复 tap_ioctl() SIOCGIFHWADDR (CVE-2026-52937) 中的堆栈信息泄漏

在 Linux 内核中,以下漏洞已修复:

net:skbuff:修复 pskb_carve 帮助程序 (CVE-2026-52943) 中缺少的 zerocopy 引用

在 Linux 内核中,以下漏洞已修复:

KVM:arm64:在错误注入和 AT 仿真 (CVE-2026-53277) 中进行页表查询的 SRCU 锁定

在 Linux 内核中,以下漏洞已修复:

fuse:修复 fuse_dentry_revalidate() (CVE-2026-53311) 中的 uninit-value

在 Linux 内核中,以下漏洞已修复:

KVM:SEV:如果使用 GHCB v2+,则需要 in-GHCB 擦除区域 (CVE-2026-53360)

在 Linux 内核中,以下漏洞已修复:

vsock/virtio:修复多 skb 发送的 zerocopy 完成 (CVE-2026-53365)

在 Linux 内核中,以下漏洞已修复:

arm64:tlb:取消共享 PMD 表时刷新 walk 缓存 (CVE-2026-63875)

在 Linux 内核中,以下漏洞已修复:

serial:zs: 转换为使用平台设备 (CVE-2026-63876)

在 Linux 内核中,以下漏洞已修复:

serial:dz: 转换为使用平台设备 (CVE-2026-63877)

在 Linux 内核中,以下漏洞已修复:

drm/i915:修复 TTM 对象清除中潜在的 UAF (CVE-2026-63884)

在 Linux 内核中,以下漏洞已修复:

drm/gem:修复 change_handle 和 handle_delete 之间的争用 (CVE-2026-63885)

在 Linux 内核中,以下漏洞已修复:

scsi:target:iscsi:在 base64 解码 (CVE-2026-63886) 之前验证CHAP_R长度

在 Linux 内核中,以下漏洞已修复:

scsi:target:iscsi:绑定 iscsi_encode_text_output() 附加至 rsp_buf (CVE-2026-63887)

在 Linux 内核中,以下漏洞已修复:

scsi:target:iscsi:修复 iscsit_handle_text_cmd() (CVE-2026-63888) 中的 CRC 越界读取和双重释放

在 Linux 内核中,以下漏洞已修复:

scsi:scsi_transport_fc:将 FPIN pname 遍历器计数器加宽至 u32 (CVE-2026-63889)

在 Linux 内核中,以下漏洞已修复:

usb:gadget:composite:修复 WebUSB GET_URL处理中的整数下溢 (CVE-2026-63896)

在 Linux 内核中,以下漏洞已修复:

xfrm:esp:还原合并的单 frag 长度门

ESP 就地快速路径在 esp_output_head() 分配目标页面碎片之前将尾部附加到 esp_output_tail() 中。head-side gate 当前分别检查 skb->data_len 和 tailen,但尾部代码从组合后的拖车 skb->data_len 分配单个目标碎片。

当组合对齐长度超过 apage 时,拒绝 page-frag 快速路径。否则,skb_page_frag_refill() 可能会在目标 sg 仍跨越合并的 skb->data_len 时回退到单个页面。

为 IPv4 和 IPv6 还原此组合长度页面门控。(CVE-2026-63912)

在 Linux 内核中,以下漏洞已修复:

netfilter:conntrack:tcp:不在没有方向检查 (CVE-2026-63913) 的情况下强制关闭无效的 seq RST

在 Linux 内核中,以下漏洞已修复:

xfrm:将 MIGRATE 通知路由到调用方的 netns (CVE-2026-63914)

在 Linux 内核中,以下漏洞已修复:

ip6:vti:在 vti6_changelink() 中使用 ip6_tnl.net。(CVE-2026-63917)

在 Linux 内核中,以下漏洞已修复:

xfrm:input:在延迟传输重新注入期间保持 netns (CVE-2026-63919)

在 Linux 内核中,以下漏洞已修复:

ipv6:复制到 cmsg (CVE-2026-63920) 之前验证扩展标头长度

在 Linux 内核中,以下漏洞已修复:

ip6:vti:在 vti6_siocdevprivate() 中使用 ip6_tnl.net。

在本系列的 1/2 修补程序后,vti6_update() 通过 t->net 断开和重新链接隧道。
vti6_siocdevprivate() 仍usesdev_net(dev) 进行冲突查找。对于throughIFLA_NET_NS_FD移动的隧道,dev_net(dev) 是新的 netns,而非 t->net。

然后,迁移的隧道中的 SIOCCHGTUNNEL 运行:

net = dev_net(dev) /* 迁移的 netns */t = vti6_locate(net, &p1, false) /* t->net 中未达到目标 */...t = netdev_priv(dev)vti6_update(t, &p1, false) /* 改变 t->net 的哈希
*/

迁移的 netns 中的调用程序会选择与创建 netns 中的隧道匹配的参数。dev_net(dev) 中的查找发现 nothing.vti6_update() 在创建 netns 哈希存储桶头部为这些参数添加了迁移的隧道。稍后在创建 netns 中的查找会解析到已迁移的设备。xfrm receive通过调用方控制的设备发送匹配的数据包。

可从非特权用户命名空间访问 (unshare --user--map-root-user --net)。容器主机上的跨租户范围。

将非回退设备上的 SIOCCHGTUNNEL 路径切换为 uset->net 进行查找。查找现在与操作 netnsvti6_update() 相匹配。

还在查找前添加 ns_capable(self->net->user_ns, CAP_NET_ADMIN)。案例顶部的检查是 againstdev_net(dev)->user_ns,迁移后就是攻击者的 snetns。那里的调用程序可以选择 self->net 中不存在的参数,查找返回 NULL,t 变为 self,然后 vti6_update() 将设备插入创建 netns 哈希。新的 checkrequires 也会在创建 netns user_ns中CAP_NET_ADMIN。

SIOCADDTUNNEL 和 SIOCCHGTUNNEL 安装在回退设备 keepdev_net(dev) 上,等于init_net。
(CVE-2026-63921)

在 Linux 内核中,以下漏洞已修复:

ipv6:exthdrs:处理 HAO 选项 (CVE-2026-63922) 后刷新 nh

在 Linux 内核中,以下漏洞已修复:

ipv6:exthdrs:ipv6_hop_jumbo() 之后刷新 nh 指针

ipv6_hop_jumbo() 会调用 pskb_trim_rcsum(),其可更改 skb 指针。让我们重新计算 nh 指针以确保任何更改都不会把事情搞砸。(CVE-2026-63924)

在 Linux 内核中,以下漏洞已修复:

macsec:修复 XPN lower-PN wrap (CVE-2026-63925) 时的重放保护

在 Linux 内核中,以下漏洞已修复:

bpf:sockmap:修复 bpf_msg_push_data 中的末尾碎片偏移

当 bpf_msg_push_data() 在 scatterlistentry 中间插入数据时,它会将原始条目拆分为左片段和右片段。

正确的片段偏移量为页面本地,但代码通过“start”来推进它,此是消息全局插入点。对于插入到非第一个 SG 条目中,这会过度推进偏移量并使 splitlayout 不一致。

将右侧片段偏移前推进片段本地增量“start - offset”,该增量与从原始条目前面删除的长度匹配。(CVE-2026-63926)

在 Linux 内核中,以下漏洞已修复:

KVM:SEV:从 PSC 缓冲区 (CVE-2026-63937) 读取条目/索引时使用 READ_ONCE()

在 Linux 内核中,以下漏洞已修复:

KVM:SEV:根据缓冲区的实际大小检查 PSC 请求索引 (CVE-2026-63938)

在 Linux 内核中,以下漏洞已修复:

KVM:SEV:计算 GHCB 内擦除区域 (CVE-2026-63939) 的正确最大长度

在 Linux 内核中,以下漏洞已修复:

KVM:SEV:忽略长度为“0”的端口 I/O 请求

明确忽略长度为“0”(或计数为“0”)的端口 I/O 请求,以便设置软件暂存区域(和其他代码)时不必担心长度下溢,并允许在尝试将暂存区域配置为 len==0 时发出警告。(CVE-2026-63940)

在 Linux 内核中,以下漏洞已修复:

mm/rmap:在 try_to_unmap_one (CVE-2026-63950) 中循环开始时将 nr_pages 初始化为 1

在 Linux 内核中,以下漏洞已修复:

memfd:暗示 SEAL_WRITE (CVE-2026-63952) 时拒绝可写入映射

在 Linux 内核中,以下漏洞已修复:

usb:typec:tcpm:在 svdm_consume_modes() (CVE-2026-63962) 中按迭代绑定altmode_desc[]

在 Linux 内核中,以下漏洞已修复:

ipv6:修复 fib6_select_path() (CVE-2026-63968) 中可能的无限循环

在 Linux 内核中,以下漏洞已修复:

ipv6:修复 rt6_fill_node() (CVE-2026-63969) 中可能的无限循环

在 Linux 内核中,以下漏洞已修复:

vsock/virtio:填充 zerocopy skb (CVE-2026-63970) 之前绑定 uarg

在 Linux 内核中,以下漏洞已修复:

sctp:修复sctp_wait_for_connect和剥离之间的争用

sctp_wait_for_connect() 在等待关联达到 ESTABLISHED 状态时舍弃并重新获取套接字锁。在此窗口期间,另一个线程可解除与新套接字 viagetsockopt(SCTP_SOCKOPT_PEELOFF) 的关联,从而更改 asoc->base.sk。重新获取旧套接字锁后,sctp_wait_for_connect() 返回成功而不注意迁移 -- 调用程序随后访问 sctp_datamsg_from_user() 中错误锁定下的关联。

添加 sctp_wait_for_sndbuf() 已进行的相同 sk != asoc->base.sk 检查,如果关联在我们休眠时迁移,则会返回错误。(CVE-2026-63971)

在 Linux 内核中,以下漏洞已修复:

net/handshake:将spin_lock_bh用于hn_lock (CVE-2026-63980)

在 Linux 内核中,以下漏洞已修复:

ipv6:rpl:修复 ipv6_rpl_srh_decompress() () 中的CVE-2026-63984 hdrlen 溢出

在 Linux 内核中,以下漏洞已修复:

ethtool:eeprom:向 EEPROM Netlink 回退添加更多安全 (CVE-2026-63985)

在 Linux 内核中,以下漏洞已修复:

ethtool:tsinfo:准备失败时不将ERR_PTR传递给 genlmsg_cancel (CVE-2026-63986)

在 Linux 内核中,以下漏洞已修复:

ethtool:coalesce:NET_DIM_PARAMS_NUM_PROFILES 处的 CAP 配置文件更新 (CVE-2026-63987)

在 Linux 内核中,以下漏洞已修复:

bridge:修复 sysfs 路径 (CVE-2026-63988) 中原子上下文中的休眠

在 Linux 内核中,以下漏洞已修复:

bridge:修复 netlink 路径 (CVE-2026-63989) 中原子上下文中的休眠

在 Linux 内核中,以下漏洞已修复:

bonding:拒绝从属 CAN 设备 (CVE-2026-63990)

在 Linux 内核中,以下漏洞已修复:

隧道:不假设 iptunnel_pmtud_check_icmp() 中的传输标头 (CVE-2026-63992)

在 Linux 内核中,以下漏洞已修复:

vxlan:在 skb_tunnel_check_pmtu() (CVE-2026-63993) 之后不重用缓存的 ip_hdr() 值

在 Linux 内核中,以下漏洞已修复:

隧道:在 iptunnel_pmtud_build_icmp[v6]()CVE-2026-63994 () 中的 skb_cow() 之后加载网络标头

在 Linux 内核中,以下漏洞已修复:

ethtool:cmis:验证来自模块 (CVE-2026-63995) 的start_cmd_payload_size

在 Linux 内核中,以下漏洞已修复:

ethtool:cmis:需要确切的 CDB 回复长度 (CVE-2026-63996)

在 Linux 内核中,以下漏洞已修复:

ethtool:module:避免泄漏有关模块闪存错误 (CVE-2026-63997) 的 netdev ref

在 Linux 内核中,以下漏洞已修复:

ethtool:module:在模块闪存错误 (CVE-2026-63998) 时调用 ethnl_ops_complete()

在 Linux 内核中,以下漏洞已修复:

ethtool:rss:修复get_rxfh失败时的 indir_table 和 hkey 泄漏 (CVE-2026-63999)

在 Linux 内核中,以下漏洞已修复:

ipv4:在 unregister_net_sysctl_table() () 之后CVE-2026-64002释放 net->ipv4.sysctl_local_reserved_ports

在 Linux 内核中,以下漏洞已修复:

scsi:core:从 scsi_run_host_queues (CVE-2026-64003) 为所有非SDEV_DEL设备运行队列

在 Linux 内核中,以下漏洞已修复:

net/smc:不重新初始化 smc 哈希表 (CVE-2026-64005)

在 Linux 内核中,以下漏洞已修复:

netfilter:nf_tables:修复同一寄存器操作中的 dst 损坏

对于 lshift 和 rshift,移位操作在 32 位字的循环中执行。循环计算移位值并将其写入 dst,然后立即从 src 中读取以计算下一次迭代的进位。由于 src 和 dst 可能指向相同的内存位置,因此无法使用新修改的 dst 值而非原始 src 值正确计算进位。

添加一个临时本地变量以在写入 dst 之前缓存原始值并将其用于进位计算可解决该问题。此外,所有操作(包括字节顺序)的控制平面都会拒绝部分重叠。这是使用下列字节码进行测试的:

表 test_table ip 标记 0 使用 1 句柄 1ip test_table test_chain 使用 3 类型过滤器挂钩输入 prio 0 策略接受数据包 0 字节 0 标记 1ip test_table test_chain 2[ immediate reg 1 0x44332211 0x88776655][ bitwise reg 1 = ( reg 1 << 0x08000000 ) ][ cmp eq reg 1 0x66443322 0x00887766 ][ counter pkts 0 bytes 0]ip test_table test_chain 4 3[ immediate reg 1 0x44332211 0x88776655 ][ bitwise reg 1 = ( reg1 << 0x08000000 ) ][ cmp eq reg 1 0x55443322 0x00887766 ][ counter pkts 21794 字节 1917798 ] (CVE-2026-64006)

在 Linux 内核中,以下漏洞已修复:

netfilter:synproxy:skb_ensure_writable后刷新 tcphdr

synproxy_tstamp_adjust() 会就地重写 TCP 时间戳选项,然后通过调用方提供的 tcphdr 指针上的 inet_proto_csum_replace4() 修补 TCP 校验和。ipv4_synproxy_hook() andipv6_synproxy_hook() 都会在调用之前通过 skb_header_pointer() 获取该指针,因此它可以直接将 skb->head 别名或指向调用方的堆栈上的_tcph缓冲区。

在获取指针和使用指针之间,函数callsskb_ensure_writable(skb, optend),该函数在克隆的或非线性 skb 上调用 pskb_expand_head() 并释放旧的 skb->head。在该之后,缓存的 th 将过时:

调用程序 (ipv[46]_synproxy_hook)th = skb_header_pointer(skb, ..., &_tcph)synproxy_tstamp_adjust(skb, protoff, th, ...)skb_ensure_writable(skb, optend)pskb_expand_head() /* kfree(旧 skb->head)
*/...inet_proto_csum_replace4(&th->check, ...)/* 写入释放的头,或写入调用程序的堆栈 copy,保留在线校验和过时 */

选项字节通过 skb->data 写入,没有问题;只有校验和更新会经过 th,因此会到达错误的位置。结果是写入已释放的 slab 内存或数据包留下与其负载不匹配的校验和。

通过立即从 skb->data + protoff 重新派生 th 进行修复 afterskb_ensure_writable() 成功,因此后续校验和更新以线性可写标头为目标。(CVE-2026-64007)

在 Linux 内核中,以下漏洞已修复:

xfrm:检查 xfrm_state_mtu (CVE-2026-64009) 中的下溢

在 Linux 内核中,以下漏洞已修复:

net/sched:sch_sfb:将直接出列调用替换为 peek 和 qdisc_dequeue_peeked (CVE-2026-64012)

在 Linux 内核中,以下漏洞已修复:

security/keys:修复查找时缺少的 RCU 读取部分

Nicholas Carlini 报告,keyring 代码在不保持 RCU 读取锁定的情况下调用 find_key_to_update() 中的 assoc_array_find(),而 theassoc_array_gc() 代码实际上设计为从树中删除节点,然后在 RCU 宽限期后将其释放。

常规密钥处理不会看到此问题,因为按住 keyringsemaphore 会隐藏任何生命周期问题,但持久密钥处理使用不同的模型。

无需扩展密钥环锁定,只需执行简单的 RCU 锁定assoc_array的设计目的。(CVE-2026-64015)

在 Linux 内核中,以下漏洞已修复:

tcp:修复启用 ISN 预测时过时的每 CPU tcp_tw_isn泄漏

假设写入该值的同一数据包的 tcp_conn_request() 始终耗用该值,则受到指责的提交会将 TIME_WAIT 派生的 ISN 从 skb 控制块移动到每个 CPU 的变量。tcp_v{4,6}_rcv() 中的 producer(__this_cpu_write(tcp_tw_isn, isn) 与 consumer(tcp_conn_request()) 之间的多个终止路径违反了该假设:

- min_ttl/min_hopcount检查- xfrm 策略检查- tcp_inbound_hash() MD5/AO 不匹配- tcp_filter() eBPF/SO_ATTACH_FILTER 在 tcp_rcv_state_process() 中丢弃 tcp_v{4,6}_do_rcv() 中的 TCP_LISTEN-psp_sk_rx_policy_check() 中的 th->syn &&; th->fin 丢弃- tcp_v{4,6}_do_rcv() 中的 tcp_checksum_complete() - tcp_v{4,6}_cookie_check() 返回 NULL

数据包在其中任一路径中丢弃时,tcp_tw_isn会保持设定状态。

然后,在同一 CPU 上处理的下一个 SYN 消耗非零值 intcp_conn_request(),从而接收可能可预测的 ISN。

此修补程序tcp_tw_isn后移至 skb->cb[],去除了 per-cpu 变量。

请注意,tcp_v{4,6}_fill_cb() 未对其进行设置。

对整体代码大小/复杂性的影响非常轻微:

$ scripts/bloat-o-meter -t vmlinux.old vmlinux.newadd/remove: 0/0 增长/缩小:2/1 向上/向下:8/-15 (-7) 函数 旧的 新 deltatcp_v6_rcv 3038 3042 +4tcp_v4_rcv 3035 3039 +4tcp_conn_request 2938 2923 -15合计: 之前=24436060, 之后=24436053, chg -0.00% (CVE-2026-64024)

在 Linux 内核中,以下漏洞已修复:

bpf、skmsg:修复 testdict sk_data_ready ktls rx 争用

当存在 TLS RX 上下文时,sk_psock_strp_data_ready() 已经检查 tls_sw_has_ctx_rx() 并推迟到 psock->saved_data_ready,从而避免与 TLS strparser 的 receivequeue 所有权发生冲突(提交 e91de6afa81c,bpf:修复运行sk_skb程序类型与 ktls)。

sk_psock_verdict_data_ready() 没有等效保护。在配置 TLS RX 之前将套接字插入 sockmap (BPF_SK_SKB_VERDICT) 时,tls_sw_strparser_arm() 将保存 sk_psock_verdict_data_readyas rx_ctx->saved_data_ready。数据到达时:

tls_data_ready -> tls_strp_data_ready -> tls_rx_msg_ready-> saved_data_ready() = sk_psock_verdict_data_ready()-> tcp_read_skb() 在不调用 tcp_eat_skb() 的情况下通过 __skb_unlink() 耗尽sk_receive_queue,因此未推进copied_seq。

然后,tls_strp_msg_load() 在现在为空的队列中查找 tcp_inq() >= full_len(过时)、callstcp_recv_skb(),命中 WARN_ON_ONCE(!first),然后返回指向 psock 拥有(可能已释放)skb 的 rx_ctx->strp.anchor.frag_list。tls_decrypt_sg() 进而thatfrag_list:释放后使用。

应用与 sk_psock_strp_data_ready() 相同的补丁:如果存在 TLS RX 上下文,则对 wakerecv() 等待程序调用 psock->saved_data_ready (sock_def_readable) 并立即返回,不影响接收队列。TLS 保留队列的唯一所有权并通过 tls_sw_recvmsg() 正常解密记录。(CVE-2026-64025)

在 Linux 内核中,以下漏洞已修复:

net:shaper:重做有效标记(再次)(CVE-2026-64027)

在 Linux 内核中,以下漏洞已修复:

erofs:修复未对齐盘区的受管缓存争用 (CVE-2026-64031)

在 Linux 内核中,以下漏洞已修复:

bridge:mcast:修复删除桥接端口时可能的释放后使用 (CVE-2026-64032)

在 Linux 内核中,以下漏洞已修复:

igc:设置 SMD 帧的 tx 缓冲区类型 (CVE-2026-64035)

在 Linux 内核中,以下漏洞已修复:

cgroup/rstat:访问 css_rstat_cpu() 之前验证 CPU

css_rstat_updated() 公开为 BPF kfunc 并接受调用程序提供的 cpu 参数。该函数将 cpu 用于每个 cpu 的 rstatlookups,而不检查它是否引用有效的可能 CPU。

具有 CAP_BPF 和 CAP_PERFMON 的 BPF iter/cgroup 程序可传递无效的 cpu 值。在未修复的 UBSCAN_BOUNDS 测试内核上,cpu ==0x7fffffff 触发:

UBSAN: array-index-out-of-bounds 在 kernel/cgroup/rstat.c:31:9index 中,2147483647超出“long unsigned int [64]”类型的范围。 调用跟踪:css_rstat_updatedbpf_iter_run_progcgroup_iter_seq_showbpf_seq_read

向面向 BPF 的 css_rstat_updated() kfunc 添加 cpu 验证并将通用实现移动到
__css_rstat_updated() 用于 in-kernelcallers。(CVE-2026-64036)

在 Linux 内核中,以下漏洞已修复:

ovpn:遵守错误路径 CMD_NEW_PEER 中的对等机引用计数 (CVE-2026-64044)

在 Linux 内核中,以下漏洞已修复:

ovpn:tcp - 使用 ovpn_tcp_close() (CVE-2026-64045) 中缓存的对等机指针

在 Linux 内核中,以下漏洞已修复:

net:tls:防止明文 SG (CVE-2026-64046) 中的链后链

在 Linux 内核中,以下漏洞已修复:

net:tls:修复封装的 sk_msg 环的 sg_chain 条目计数中的差一

当sk_msg scatterlist 环封装 (sg.end < sg.start) 时,tls_push_record() 将环的尾部链接到 headusing sg_chain() 上。sg 数组中的一个额外条目是为此保留的:

结构sk_msg_sg {[...]/* 额外的两个元素:* 1) 用于在列表分区* 时链接前面和部分(例如结束<开始)。加密 API 需要* chaining;* 2) 以在 message.*/struct scatterlist data[MAX_MSG_FRAGS + 2];

当前代码使用 MAX_SKB_FRAGS + 1 作为环大小:

sg_chain(&msg_pl->sg.data[msg_pl->sg.start],MAX_SKB_FRAGS - msg_pl->sg.start + 1,msg_pl->sg.data);

这会将链接指针放置在

sg_chain(data[start], (MAX_SKB_FRAGS - msg_start + 1) .. =&data[start] + (MAX_SKB_FRAGS - msg_start + 1) - 1 =data[start[start + (MAX_SKB_FRAGS - start + 1) - 1] =data[MAX_SKB_FRAGS]

而不是真正的最后一个条目。这很可能是由于在接近提交 031097d9e079 的补丁着陆时存在提交争用(bpf:sk_msg,psock down 时的 zap 入口队列)

转换为 ARRAY_SIZE 并终止 data[start] / - start(依据 Sabrina 建议)。(CVE-2026-64047)

在 Linux 内核中,以下漏洞已修复:

block:bio-integrity:修复 bio_integrity_map_user() 中的 null-ptr-deref (CVE-2026-64052)

在 Linux 内核中,以下漏洞已修复:

block:不覆盖 bio_integrity_copy_user() (CVE-2026-64053) 中的 bip_vcnt

在 Linux 内核中,以下漏洞已修复:

net:shaper:拒绝 GROUP request (CVE-2026-64054) 中的重复叶

在 Linux 内核中,以下漏洞已修复:

netfs:修复 netfs_read_folio() 以等待回写 (CVE-2026-64058)

在 Linux 内核中,以下漏洞已修复:

netfs:修复 netfs_perform_write() (CVE-2026-64059) 中的 folio->private 处理

在 Linux 内核中,以下漏洞已修复:

netfs:修复 netfs_write_begin() 错误处理中的请求泄漏

修复 netfs_write_begin(),以便在收到 netfs_wait_for_read() 错误时不泄漏请求中的 ref。(CVE-2026-64060)

在 Linux 内核中,以下漏洞已修复:

netfs:修复 netfs_read_gaps() (CVE-2026-64061) 中过早放置接收器作品集

在 Linux 内核中,以下漏洞已修复:

netfs:修复了连续写入模式下可能发生的死锁 (CVE-2026-64062)

在 Linux 内核中,以下漏洞已修复:

netfs:修复正在被覆盖的流写入 (CVE-2026-64063)

在 Linux 内核中,以下漏洞已修复:

netfs:修复 netfs_invalidate_folio() 以在所有更改消失时清除脏位 (CVE-2026-64064)

在 Linux 内核中,以下漏洞已修复:

netfs:修复 netfs_write_begin() 调用 (CVE-2026-64065) 中的 VM_BUG_ON_FOLIO() 问题

在 Linux 内核中,以下漏洞已修复:

netfs:修复 netfs_read_to_pagecache() 以在 subreq 失败时暂停 (CVE-2026-64066)

在 Linux 内核中,以下漏洞已修复:

netfs:修复 DIO 和单一读取子请求 (CVE-2026-64069) 的取消

在 Linux 内核中,以下漏洞已修复:

nvme-pci:修复 nvme_free_host_mem() (CVE-2026-64071) 中的释放后使用

在 Linux 内核中,以下漏洞已修复:

nvme:修复映射失败时的 bio 泄漏 (CVE-2026-64072)

在 Linux 内核中,以下漏洞已修复:

irq_work:修复 PREEMPT_RT 上 irq_work_single() 中的释放后使用 ...

请注意,描述因长度问题被截断。请参考供应商公告,获取完整描述。

Tenable 已直接从测试产品的安全公告中提取上述描述块。

请注意,Nessus 尚未测试这些问题,而是只依据应用程序自我报告的版本号进行判断。

解决方案

运行“dnf update kernel6.18 --releasever 2023.12.20260622”或“dnf update --advisory ALAS2023-2026-1881 --releasever 2023.12.20260622”以更新系统。

另见

https://alas.aws.amazon.com//AL2023/ALAS2023-2026-1881.html

https://alas.aws.amazon.com/faqs.html

https://explore.alas.aws.amazon.com/CVE-2025-71289.html

https://explore.alas.aws.amazon.com/CVE-2026-31709.html

https://explore.alas.aws.amazon.com/CVE-2026-46244.html

https://explore.alas.aws.amazon.com/CVE-2026-46315.html

https://explore.alas.aws.amazon.com/CVE-2026-46316.html

https://explore.alas.aws.amazon.com/CVE-2026-46317.html

https://explore.alas.aws.amazon.com/CVE-2026-46321.html

https://explore.alas.aws.amazon.com/CVE-2026-46322.html

https://explore.alas.aws.amazon.com/CVE-2026-52912.html

https://explore.alas.aws.amazon.com/CVE-2026-52915.html

https://explore.alas.aws.amazon.com/CVE-2026-52921.html

https://explore.alas.aws.amazon.com/CVE-2026-52923.html

https://explore.alas.aws.amazon.com/CVE-2026-52932.html

https://explore.alas.aws.amazon.com/CVE-2026-52937.html

https://explore.alas.aws.amazon.com/CVE-2026-52943.html

https://explore.alas.aws.amazon.com/CVE-2026-53277.html

https://explore.alas.aws.amazon.com/CVE-2026-53311.html

https://explore.alas.aws.amazon.com/CVE-2026-53360.html

https://explore.alas.aws.amazon.com/CVE-2026-53365.html

https://explore.alas.aws.amazon.com/CVE-2026-63875.html

https://explore.alas.aws.amazon.com/CVE-2026-63876.html

https://explore.alas.aws.amazon.com/CVE-2026-63877.html

https://explore.alas.aws.amazon.com/CVE-2026-63884.html

https://explore.alas.aws.amazon.com/CVE-2026-63885.html

https://explore.alas.aws.amazon.com/CVE-2026-63886.html

https://explore.alas.aws.amazon.com/CVE-2026-63887.html

https://explore.alas.aws.amazon.com/CVE-2026-63888.html

https://explore.alas.aws.amazon.com/CVE-2026-63889.html

https://explore.alas.aws.amazon.com/CVE-2026-63896.html

https://explore.alas.aws.amazon.com/CVE-2026-63912.html

https://explore.alas.aws.amazon.com/CVE-2026-63913.html

https://explore.alas.aws.amazon.com/CVE-2026-63914.html

https://explore.alas.aws.amazon.com/CVE-2026-63917.html

https://explore.alas.aws.amazon.com/CVE-2026-63919.html

https://explore.alas.aws.amazon.com/CVE-2026-63920.html

https://explore.alas.aws.amazon.com/CVE-2026-63921.html

https://explore.alas.aws.amazon.com/CVE-2026-63922.html

https://explore.alas.aws.amazon.com/CVE-2026-63924.html

https://explore.alas.aws.amazon.com/CVE-2026-63925.html

https://explore.alas.aws.amazon.com/CVE-2026-63926.html

https://explore.alas.aws.amazon.com/CVE-2026-63937.html

https://explore.alas.aws.amazon.com/CVE-2026-63938.html

https://explore.alas.aws.amazon.com/CVE-2026-63939.html

https://explore.alas.aws.amazon.com/CVE-2026-63940.html

https://explore.alas.aws.amazon.com/CVE-2026-63950.html

https://explore.alas.aws.amazon.com/CVE-2026-63952.html

https://explore.alas.aws.amazon.com/CVE-2026-63962.html

https://explore.alas.aws.amazon.com/CVE-2026-63968.html

https://explore.alas.aws.amazon.com/CVE-2026-63969.html

https://explore.alas.aws.amazon.com/CVE-2026-63970.html

https://explore.alas.aws.amazon.com/CVE-2026-63971.html

https://explore.alas.aws.amazon.com/CVE-2026-63980.html

https://explore.alas.aws.amazon.com/CVE-2026-63984.html

https://explore.alas.aws.amazon.com/CVE-2026-63985.html

https://explore.alas.aws.amazon.com/CVE-2026-63986.html

https://explore.alas.aws.amazon.com/CVE-2026-63987.html

https://explore.alas.aws.amazon.com/CVE-2026-63988.html

https://explore.alas.aws.amazon.com/CVE-2026-63989.html

https://explore.alas.aws.amazon.com/CVE-2026-63990.html

https://explore.alas.aws.amazon.com/CVE-2026-63992.html

https://explore.alas.aws.amazon.com/CVE-2026-63993.html

https://explore.alas.aws.amazon.com/CVE-2026-63994.html

https://explore.alas.aws.amazon.com/CVE-2026-63995.html

https://explore.alas.aws.amazon.com/CVE-2026-63996.html

https://explore.alas.aws.amazon.com/CVE-2026-63997.html

https://explore.alas.aws.amazon.com/CVE-2026-63998.html

https://explore.alas.aws.amazon.com/CVE-2026-63999.html

https://explore.alas.aws.amazon.com/CVE-2026-64002.html

https://explore.alas.aws.amazon.com/CVE-2026-64003.html

https://explore.alas.aws.amazon.com/CVE-2026-64005.html

https://explore.alas.aws.amazon.com/CVE-2026-64006.html

https://explore.alas.aws.amazon.com/CVE-2026-64007.html

https://explore.alas.aws.amazon.com/CVE-2026-64009.html

https://explore.alas.aws.amazon.com/CVE-2026-64012.html

https://explore.alas.aws.amazon.com/CVE-2026-64015.html

https://explore.alas.aws.amazon.com/CVE-2026-64024.html

https://explore.alas.aws.amazon.com/CVE-2026-64025.html

https://explore.alas.aws.amazon.com/CVE-2026-64027.html

https://explore.alas.aws.amazon.com/CVE-2026-64031.html

https://explore.alas.aws.amazon.com/CVE-2026-64032.html

https://explore.alas.aws.amazon.com/CVE-2026-64035.html

https://explore.alas.aws.amazon.com/CVE-2026-64036.html

https://explore.alas.aws.amazon.com/CVE-2026-64044.html

https://explore.alas.aws.amazon.com/CVE-2026-64045.html

https://explore.alas.aws.amazon.com/CVE-2026-64046.html

https://explore.alas.aws.amazon.com/CVE-2026-64047.html

https://explore.alas.aws.amazon.com/CVE-2026-64052.html

https://explore.alas.aws.amazon.com/CVE-2026-64053.html

https://explore.alas.aws.amazon.com/CVE-2026-64054.html

https://explore.alas.aws.amazon.com/CVE-2026-64058.html

https://explore.alas.aws.amazon.com/CVE-2026-64059.html

https://explore.alas.aws.amazon.com/CVE-2026-64060.html

https://explore.alas.aws.amazon.com/CVE-2026-64061.html

https://explore.alas.aws.amazon.com/CVE-2026-64062.html

https://explore.alas.aws.amazon.com/CVE-2026-64063.html

https://explore.alas.aws.amazon.com/CVE-2026-64064.html

https://explore.alas.aws.amazon.com/CVE-2026-64065.html

https://explore.alas.aws.amazon.com/CVE-2026-64066.html

https://explore.alas.aws.amazon.com/CVE-2026-64069.html

https://explore.alas.aws.amazon.com/CVE-2026-64071.html

https://explore.alas.aws.amazon.com/CVE-2026-64072.html

https://explore.alas.aws.amazon.com/CVE-2026-64073.html

https://explore.alas.aws.amazon.com/CVE-2026-64074.html

https://explore.alas.aws.amazon.com/CVE-2026-64075.html

https://explore.alas.aws.amazon.com/CVE-2026-64076.html

https://explore.alas.aws.amazon.com/CVE-2026-64077.html

https://explore.alas.aws.amazon.com/CVE-2026-64078.html

https://explore.alas.aws.amazon.com/CVE-2026-64080.html

https://explore.alas.aws.amazon.com/CVE-2026-64081.html

https://explore.alas.aws.amazon.com/CVE-2026-64098.html

https://explore.alas.aws.amazon.com/CVE-2026-64104.html

https://explore.alas.aws.amazon.com/CVE-2026-64105.html

https://explore.alas.aws.amazon.com/CVE-2026-64106.html

https://explore.alas.aws.amazon.com/CVE-2026-64108.html

https://explore.alas.aws.amazon.com/CVE-2026-64109.html

https://explore.alas.aws.amazon.com/CVE-2026-64110.html

https://explore.alas.aws.amazon.com/CVE-2026-64111.html

https://explore.alas.aws.amazon.com/CVE-2026-64112.html

https://explore.alas.aws.amazon.com/CVE-2026-64113.html

https://explore.alas.aws.amazon.com/CVE-2026-64114.html

https://explore.alas.aws.amazon.com/CVE-2026-64115.html

https://explore.alas.aws.amazon.com/CVE-2026-64116.html

https://explore.alas.aws.amazon.com/CVE-2026-64120.html

https://explore.alas.aws.amazon.com/CVE-2026-64121.html

https://explore.alas.aws.amazon.com/CVE-2026-64122.html

https://explore.alas.aws.amazon.com/CVE-2026-64124.html

https://explore.alas.aws.amazon.com/CVE-2026-64130.html

https://explore.alas.aws.amazon.com/CVE-2026-64131.html

https://explore.alas.aws.amazon.com/CVE-2026-64132.html

https://explore.alas.aws.amazon.com/CVE-2026-64136.html

https://explore.alas.aws.amazon.com/CVE-2026-64149.html

https://explore.alas.aws.amazon.com/CVE-2026-64150.html

https://explore.alas.aws.amazon.com/CVE-2026-64153.html

https://explore.alas.aws.amazon.com/CVE-2026-64156.html

https://explore.alas.aws.amazon.com/CVE-2026-64157.html

https://explore.alas.aws.amazon.com/CVE-2026-64158.html

https://explore.alas.aws.amazon.com/CVE-2026-64163.html

https://explore.alas.aws.amazon.com/CVE-2026-64164.html

https://explore.alas.aws.amazon.com/CVE-2026-64166.html

https://explore.alas.aws.amazon.com/CVE-2026-64172.html

https://explore.alas.aws.amazon.com/CVE-2026-64180.html

https://explore.alas.aws.amazon.com/CVE-2026-64181.html

https://explore.alas.aws.amazon.com/CVE-2026-64182.html

https://explore.alas.aws.amazon.com/CVE-2026-64183.html

https://explore.alas.aws.amazon.com/CVE-2026-64184.html

https://explore.alas.aws.amazon.com/CVE-2026-64185.html

https://explore.alas.aws.amazon.com/CVE-2026-64186.html

https://explore.alas.aws.amazon.com/CVE-2026-64190.html

https://explore.alas.aws.amazon.com/CVE-2026-64216.html

https://explore.alas.aws.amazon.com/CVE-2026-64217.html

https://explore.alas.aws.amazon.com/CVE-2026-64220.html

https://explore.alas.aws.amazon.com/CVE-2026-64226.html

https://explore.alas.aws.amazon.com/CVE-2026-64228.html

https://explore.alas.aws.amazon.com/CVE-2026-64229.html

https://explore.alas.aws.amazon.com/CVE-2026-64232.html

https://explore.alas.aws.amazon.com/CVE-2026-64235.html

https://explore.alas.aws.amazon.com/CVE-2026-64239.html

https://explore.alas.aws.amazon.com/CVE-2026-64302.html

https://explore.alas.aws.amazon.com/CVE-2026-64518.html

https://explore.alas.aws.amazon.com/CVE-2026-64519.html

https://explore.alas.aws.amazon.com/CVE-2026-64520.html

https://explore.alas.aws.amazon.com/CVE-2026-64522.html

https://explore.alas.aws.amazon.com/CVE-2026-64525.html

https://explore.alas.aws.amazon.com/CVE-2026-64526.html

插件详情

严重性: High

ID: 322087

文件名: al2023_ALAS2023-2026-1881.nasl

版本: 1.10

类型: Local

代理: unix

发布时间: 2026/6/22

最近更新时间: 2026/8/13

支持的传感器: Frictionless Assessment AWS, Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Continuous Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

风险信息

VPR

风险因素: High

分数: 7.9

百分位: 99.36

CVSS v2

风险因素: Medium

基本分数: 6.8

时间分数: 5.3

矢量: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS 分数来源: CVE-2026-64239

CVSS v3

风险因素: High

基本分数: 7.8

时间分数: 7

矢量: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

时间矢量: CVSS:3.0/E:P/RL:O/RC:C

漏洞信息

CPE: cpe:/o:amazon:linux:2023, p-cpe:/a:amazon:linux:bpftool6.18-debuginfo, p-cpe:/a:amazon:linux:bpftool6.18, p-cpe:/a:amazon:linux:kernel-livepatch-6.18.35-68.127, p-cpe:/a:amazon:linux:kernel6.18-debuginfo-common-aarch64, p-cpe:/a:amazon:linux:kernel6.18-debuginfo-common-x86_64, p-cpe:/a:amazon:linux:kernel6.18-debuginfo, p-cpe:/a:amazon:linux:kernel6.18-devel, p-cpe:/a:amazon:linux:kernel6.18-headers, p-cpe:/a:amazon:linux:kernel6.18-modules-extra-common, p-cpe:/a:amazon:linux:kernel6.18-modules-extra, p-cpe:/a:amazon:linux:kernel6.18-tools-debuginfo, p-cpe:/a:amazon:linux:kernel6.18-tools-devel, p-cpe:/a:amazon:linux:kernel6.18-tools, p-cpe:/a:amazon:linux:kernel6.18, p-cpe:/a:amazon:linux:microvm-kernel6.18, p-cpe:/a:amazon:linux:perf6.18-debuginfo, p-cpe:/a:amazon:linux:perf6.18, p-cpe:/a:amazon:linux:python3-perf6.18-debuginfo, p-cpe:/a:amazon:linux:python3-perf6.18

必需的 KB 项: Host/local_checks_enabled, Host/AmazonLinux/release, Host/AmazonLinux/rpm-list

可利用: true

易利用性: Exploits are available

补丁发布日期: 2026/6/22

漏洞发布日期: 2026/5/1

参考资料信息

CVE: CVE-2025-71289, CVE-2026-31709, CVE-2026-46244, CVE-2026-46315, CVE-2026-46316, CVE-2026-46317, CVE-2026-46321, CVE-2026-46322, CVE-2026-52912, CVE-2026-52915, CVE-2026-52921, CVE-2026-52923, CVE-2026-52932, CVE-2026-52937, CVE-2026-52943, CVE-2026-53277, CVE-2026-53311, CVE-2026-53360, CVE-2026-53365, CVE-2026-63875, CVE-2026-63876, CVE-2026-63877, CVE-2026-63884, CVE-2026-63885, CVE-2026-63886, CVE-2026-63887, CVE-2026-63888, CVE-2026-63889, CVE-2026-63896, CVE-2026-63912, CVE-2026-63913, CVE-2026-63914, CVE-2026-63917, CVE-2026-63919, CVE-2026-63920, CVE-2026-63921, CVE-2026-63922, CVE-2026-63924, CVE-2026-63925, CVE-2026-63926, CVE-2026-63937, CVE-2026-63938, CVE-2026-63939, CVE-2026-63940, CVE-2026-63950, CVE-2026-63952, CVE-2026-63962, CVE-2026-63968, CVE-2026-63969, CVE-2026-63970, CVE-2026-63971, CVE-2026-63980, CVE-2026-63984, CVE-2026-63985, CVE-2026-63986, CVE-2026-63987, CVE-2026-63988, CVE-2026-63989, CVE-2026-63990, CVE-2026-63992, CVE-2026-63993, CVE-2026-63994, CVE-2026-63995, CVE-2026-63996, CVE-2026-63997, CVE-2026-63998, CVE-2026-63999, CVE-2026-64002, CVE-2026-64003, CVE-2026-64005, CVE-2026-64006, CVE-2026-64007, CVE-2026-64009, CVE-2026-64012, CVE-2026-64015, CVE-2026-64024, CVE-2026-64025, CVE-2026-64027, CVE-2026-64031, CVE-2026-64032, CVE-2026-64035, CVE-2026-64036, CVE-2026-64044, CVE-2026-64045, CVE-2026-64046, CVE-2026-64047, CVE-2026-64052, CVE-2026-64053, CVE-2026-64054, CVE-2026-64058, CVE-2026-64059, CVE-2026-64060, CVE-2026-64061, CVE-2026-64062, CVE-2026-64063, CVE-2026-64064, CVE-2026-64065, CVE-2026-64066, CVE-2026-64069, CVE-2026-64071, CVE-2026-64072, CVE-2026-64073, CVE-2026-64074, CVE-2026-64075, CVE-2026-64076, CVE-2026-64077, CVE-2026-64078, CVE-2026-64080, CVE-2026-64081, CVE-2026-64098, CVE-2026-64104, CVE-2026-64105, CVE-2026-64106, CVE-2026-64108, CVE-2026-64109, CVE-2026-64110, CVE-2026-64111, CVE-2026-64112, CVE-2026-64113, CVE-2026-64114, CVE-2026-64115, CVE-2026-64116, CVE-2026-64120, CVE-2026-64121, CVE-2026-64122, CVE-2026-64124, CVE-2026-64130, CVE-2026-64131, CVE-2026-64132, CVE-2026-64136, CVE-2026-64149, CVE-2026-64150, CVE-2026-64153, CVE-2026-64156, CVE-2026-64157, CVE-2026-64158, CVE-2026-64163, CVE-2026-64164, CVE-2026-64166, CVE-2026-64172, CVE-2026-64180, CVE-2026-64181, CVE-2026-64182, CVE-2026-64183, CVE-2026-64184, CVE-2026-64185, CVE-2026-64186, CVE-2026-64190, CVE-2026-64216, CVE-2026-64217, CVE-2026-64220, CVE-2026-64226, CVE-2026-64228, CVE-2026-64229, CVE-2026-64232, CVE-2026-64235, CVE-2026-64239, CVE-2026-64302, CVE-2026-64518, CVE-2026-64519, CVE-2026-64520, CVE-2026-64522, CVE-2026-64525, CVE-2026-64526