RHEL 9:内核 (RHSA-2026:34094)

high Nessus 插件 ID 324565

简介

远程 Red Hat 主机缺少一个或多个安全更新。

描述

远程 Redhat Enterprise Linux 9 主机上安装的程序包受到 RHSA-2026:34094 公告中提及的多个漏洞影响。

内核程序包中包含 Linux 内核,后者是任何 Linux 操作系统的核心。

安全修复:

* kernel: netfilter:conntrack:将最大哈希表大小限制为 INT_MAX (CVE-2025-21648)

* kernel: cachestat:修复页面缓存统计数据权限检查 (CVE-2025-21691)

* kernel: ALSA: aloop:修复触发 PCM 时的 racy 访问 (CVE-2026-23191)

* kernel: mptcp:修复 __inet_lookup_established 中的 slab-after-free (CVE-2026-31669)

* kernel:netfilter:nf_conntrack_helper:传递帮助程序以预期清除 (CVE-2026-43027)

* kernel:RDMA/umem:修复故障路径中的双重 dma_buf_unpin (CVE-2026-43128)

* kernel: tcp:修复 tcp_v6_syn_recv_sock() 中潜在的争用(CVE-2026-43198)

* kernel: dlm:验证 dlm_search_rsb_tree 中的长度 (CVE-2026-43125)

* kernel:netfilter:flowtable:严格检查最大操作数 (CVE-2026-43329)

* kernel:scsi:qla2xxx:修复了 fcport 双重释放问题 (CVE-2026-43414)

* kernel: ipv6: rpl:再压缩的 SRH 增长时预留mac_len余量 (CVE-2026-43501)

* kernel: ALSA: aloop:修复格式更改停止期间的对等机运行时 UAF (CVE-2026-46090)

* 内核:RDMA/rxe:修复 rxe_srq_from_init 中的双重释放 (CVE-2026-45852)

* 内核:RDMA/mlx4:修复 mlx4_srq_event()CVE-2026-46181 () 中对 RCU 的误用

* kernel: sctp:重新验证 SCTP_SENDALL (CVE-2026-46227) 中 sctp_sendmsg_to_asoc() 之后的列表光标

* 内核:RDMA/mlx5:修复 mlx5_ib_dev_res_srq_init() (CVE-2026-46176) 中的错误路径故障

* kernel:exit:防止抢占 oopsing TASK_DEAD task (CVE-2026-46173)

* kernel:netfilter:nft_inner:修复 IPv6 inner_thoff desync (CVE-2026-46244)

错误修复和增强功能:

* iavf:在 POD 改动期间,可能不会为 vlan 接口添加 vlan 过滤器,spoofchk 会丢弃后续数据包 [rhel-9.6.z] (JIRA:RHEL-172991)

* [rhel-9] 警告:检测到可能的递归锁定 - vmd_enable_domain+0x757/0x910 [rhel-9.6.z] (JIRA:RHEL-174469)

* RHEL9.4 - s390/mm:添加缺少的安全存储访问修复 [rhel-9.6.z] (JIRA:RHEL-183316)

* drm/mgag200:300 毫秒忙碌循环 [rhel-9.6.z] (JIRA:RHEL-150177)

有关上述安全问题的更多详细信息,包括其影响、CVSS 得分、致谢,以及其他相关信息,请参阅列于“参考”部分的 CVE 页面。

Tenable 已直接从 Red Hat Enterprise Linux 安全公告中提取上述描述块。

请注意,Nessus 尚未测试这些问题,而是只依据应用程序自我报告的版本号进行判断。

解决方案

更新受影响的程序包。

另见

https://access.redhat.com/errata/RHSA-2026:34094

https://access.redhat.com/security/updates/classification/#important

https://bugzilla.redhat.com/show_bug.cgi?id=2338814

https://bugzilla.redhat.com/show_bug.cgi?id=2344687

https://bugzilla.redhat.com/show_bug.cgi?id=2439947

https://bugzilla.redhat.com/show_bug.cgi?id=2461503

https://bugzilla.redhat.com/show_bug.cgi?id=2464369

https://bugzilla.redhat.com/show_bug.cgi?id=2467144

https://bugzilla.redhat.com/show_bug.cgi?id=2467228

https://bugzilla.redhat.com/show_bug.cgi?id=2467234

https://bugzilla.redhat.com/show_bug.cgi?id=2468124

https://bugzilla.redhat.com/show_bug.cgi?id=2468155

https://bugzilla.redhat.com/show_bug.cgi?id=2480457

https://bugzilla.redhat.com/show_bug.cgi?id=2481980

https://bugzilla.redhat.com/show_bug.cgi?id=2482166

https://bugzilla.redhat.com/show_bug.cgi?id=2482532

https://bugzilla.redhat.com/show_bug.cgi?id=2482564

https://bugzilla.redhat.com/show_bug.cgi?id=2482594

https://bugzilla.redhat.com/show_bug.cgi?id=2482634

https://bugzilla.redhat.com/show_bug.cgi?id=2484451

http://www.nessus.org/u?1be0c284

插件详情

严重性: High

ID: 324565

文件名: redhat-RHSA-2026-34094.nasl

版本: 1.1

类型: Local

代理: unix

发布时间: 2026/7/1

最近更新时间: 2026/7/1

支持的传感器: Frictionless Assessment AWS, Frictionless Assessment Azure, Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Continuous Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

风险信息

VPR

风险因素: High

分数: 7.6

百分位: 98.47

Vendor

Vendor Severity: Important

CVSS v2

风险因素: Medium

基本分数: 6.8

时间分数: 5

矢量: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS 分数来源: CVE-2026-43128

CVSS v3

风险因素: High

基本分数: 7.8

时间分数: 6.8

矢量: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

时间矢量: CVSS:3.0/E:U/RL:O/RC:C

漏洞信息

CPE: p-cpe:/a:redhat:enterprise_linux:kernel-64k-debug-devel-matched, p-cpe:/a:redhat:enterprise_linux:kernel-debug-modules-core, p-cpe:/a:redhat:enterprise_linux:kernel-rt-core, p-cpe:/a:redhat:enterprise_linux:kernel-rt-modules, p-cpe:/a:redhat:enterprise_linux:kernel-64k-debug-devel, p-cpe:/a:redhat:enterprise_linux:kernel-debug-core, p-cpe:/a:redhat:enterprise_linux:kernel-64k-debug-core, p-cpe:/a:redhat:enterprise_linux:kernel-tools-libs-devel, p-cpe:/a:redhat:enterprise_linux:kernel-zfcpdump-modules-core, p-cpe:/a:redhat:enterprise_linux:kernel-debug-devel, p-cpe:/a:redhat:enterprise_linux:kernel-64k-debug-modules-core, p-cpe:/a:redhat:enterprise_linux:kernel-rt-64k-devel, p-cpe:/a:redhat:enterprise_linux:kernel-core, p-cpe:/a:redhat:enterprise_linux:kernel-64k-modules-extra, p-cpe:/a:redhat:enterprise_linux:kernel-rt, p-cpe:/a:redhat:enterprise_linux:kernel-64k-modules, p-cpe:/a:redhat:enterprise_linux:kernel-rt-64k-modules, p-cpe:/a:redhat:enterprise_linux:kernel-rt-debug-kvm, p-cpe:/a:redhat:enterprise_linux:kernel-debug-uki-virt, p-cpe:/a:redhat:enterprise_linux:kernel-tools-libs, p-cpe:/a:redhat:enterprise_linux:kernel-rt-debug-modules, p-cpe:/a:redhat:enterprise_linux:perf, p-cpe:/a:redhat:enterprise_linux:kernel-rt-debug-devel, p-cpe:/a:redhat:enterprise_linux:kernel-rt-kvm, p-cpe:/a:redhat:enterprise_linux:kernel-tools, p-cpe:/a:redhat:enterprise_linux:kernel-zfcpdump, p-cpe:/a:redhat:enterprise_linux:kernel-64k, p-cpe:/a:redhat:enterprise_linux:kernel-rt-64k-debug, p-cpe:/a:redhat:enterprise_linux:kernel-rt-64k-debug-core, p-cpe:/a:redhat:enterprise_linux:kernel-zfcpdump-devel-matched, p-cpe:/a:redhat:enterprise_linux:kernel-64k-modules-core, p-cpe:/a:redhat:enterprise_linux:kernel-debug-modules-extra, p-cpe:/a:redhat:enterprise_linux:kernel-rt-64k-modules-extra, p-cpe:/a:redhat:enterprise_linux:rv, p-cpe:/a:redhat:enterprise_linux:kernel-64k-debug-modules-extra, p-cpe:/a:redhat:enterprise_linux:kernel-rt-64k-debug-modules-core, p-cpe:/a:redhat:enterprise_linux:kernel-64k-debug, p-cpe:/a:redhat:enterprise_linux:kernel, p-cpe:/a:redhat:enterprise_linux:kernel-devel, p-cpe:/a:redhat:enterprise_linux:kernel-64k-devel, p-cpe:/a:redhat:enterprise_linux:kernel-uki-virt, p-cpe:/a:redhat:enterprise_linux:kernel-rt-64k-debug-modules, p-cpe:/a:redhat:enterprise_linux:kernel-rt-64k, p-cpe:/a:redhat:enterprise_linux:kernel-zfcpdump-core, p-cpe:/a:redhat:enterprise_linux:kernel-modules-extra, p-cpe:/a:redhat:enterprise_linux:kernel-rt-debug-core, p-cpe:/a:redhat:enterprise_linux:kernel-rt-devel, cpe:/o:redhat:rhel_eus:9.6, p-cpe:/a:redhat:enterprise_linux:kernel-64k-debug-modules, p-cpe:/a:redhat:enterprise_linux:kernel-zfcpdump-modules-extra, p-cpe:/a:redhat:enterprise_linux:libperf, p-cpe:/a:redhat:enterprise_linux:kernel-modules, p-cpe:/a:redhat:enterprise_linux:kernel-rt-debug-modules-extra, p-cpe:/a:redhat:enterprise_linux:kernel-zfcpdump-modules, p-cpe:/a:redhat:enterprise_linux:kernel-modules-core, p-cpe:/a:redhat:enterprise_linux:kernel-rt-64k-debug-modules-extra, p-cpe:/a:redhat:enterprise_linux:kernel-rt-64k-debug-devel, p-cpe:/a:redhat:enterprise_linux:kernel-rt-64k-modules-core, p-cpe:/a:redhat:enterprise_linux:kernel-zfcpdump-devel, p-cpe:/a:redhat:enterprise_linux:kernel-uki-virt-addons, p-cpe:/a:redhat:enterprise_linux:kernel-debug-modules, p-cpe:/a:redhat:enterprise_linux:kernel-debug, p-cpe:/a:redhat:enterprise_linux:kernel-rt-modules-core, p-cpe:/a:redhat:enterprise_linux:python3-perf, p-cpe:/a:redhat:enterprise_linux:kernel-debug-devel-matched, p-cpe:/a:redhat:enterprise_linux:kernel-rt-modules-extra, p-cpe:/a:redhat:enterprise_linux:kernel-devel-matched, p-cpe:/a:redhat:enterprise_linux:rtla, p-cpe:/a:redhat:enterprise_linux:kernel-rt-debug-modules-core, p-cpe:/a:redhat:enterprise_linux:kernel-rt-debug, p-cpe:/a:redhat:enterprise_linux:kernel-64k-core, p-cpe:/a:redhat:enterprise_linux:kernel-rt-64k-core, p-cpe:/a:redhat:enterprise_linux:kernel-64k-devel-matched

必需的 KB 项: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list, Host/cpu

易利用性: No known exploits are available

补丁发布日期: 2026/7/1

漏洞发布日期: 2024/4/9

参考资料信息

CVE: CVE-2025-21648, CVE-2025-21691, CVE-2026-23191, CVE-2026-31669, CVE-2026-43027, CVE-2026-43125, CVE-2026-43128, CVE-2026-43198, CVE-2026-43329, CVE-2026-43414, CVE-2026-43501, CVE-2026-45852, CVE-2026-46090, CVE-2026-46173, CVE-2026-46176, CVE-2026-46181, CVE-2026-46227, CVE-2026-46244

CWE: 130, 131, 1341, 364, 366, 367, 459, 763, 770, 789, 821, 823, 825, 863, 911

RHSA: 2026:34094