Amazon Linux 2:内核、 --advisory ALAS2KERNEL-5。10-2026-124 (ALASKERNEL-5。10-2026-124)

high Nessus 插件 ID 325574

简介

远程 Amazon Linux 2 主机缺少安全更新。

描述

远程主机上安装的内核版本低于 5.10.259-258.1043。因此,会受到 ALAS2KERNEL-5.10-2026-124 公告中提及的多个漏洞影响。

在 Linux 内核中,以下漏洞已修复:

net/sched:teql:修复 teql_master_xmit 中的双重释放 (CVE-2026-23449)

在 Linux 内核中,以下漏洞已修复:

ext4:验证 ext4_ext_correct_indexes 中的p_idx边界 (CVE-2026-31449)

在 Linux 内核中,以下漏洞已修复:

net/tls:修复 tls_do_encryption (CVE-2026-31533) 的 -EBUSY 错误路径中的释放后使用

在 Linux 内核中,以下漏洞已修复:

smb:客户端:修复 smb2_ioctl_query_info QUERY_INFO 路径中的 OOB 读取 (CVE-2026-31708)

在 Linux 内核中,以下漏洞已修复:

smb:客户端:读取模式位 (CVE-2026-43350) 之前需要完整的 NFS 模式 SID

在 Linux 内核中,以下漏洞已修复:

lib/crypto:mpi:修复 mpi_read_raw_from_sgl() (CVE-2026-43492) 中的整数下溢

在 Linux 内核中,以下漏洞已修复:

ipvs:跳过 csum 检查的 ipv6 扩展标头 (CVE-2026-45850)

在 Linux 内核中,以下漏洞已修复:

udf:修复分区描述符附加簿记 (CVE-2026-45991)

在 Linux 内核中,以下漏洞已修复:

thermal:core:修复 thermal 区域调控器清理问题 (CVE-2026-46021)

在 Linux 内核中,以下漏洞已修复:

ceph:仅在未哈希时d_add() 负 dentry (CVE-2026-46052)

在 Linux 内核中,以下漏洞已修复:

net:bridge:在 RCU 阅读器中使用稳定的 FDB dst 快照 (CVE-2026-46086)

在 Linux 内核中,以下漏洞已修复:

dm-thin:修复元数据引用计数下溢 (CVE-2026-46107)

在 Linux 内核中,以下漏洞已修复:

mptcp:pm:ADD_ADDR rtx:修复潜在的数据争用 (CVE-2026-46137)

在 Linux 内核中,以下漏洞已修复:

btrfs:修复可导致信息泄漏 (CVE-2026-46159) 的 TOCTOU slot_count btrfs_ioctl_space_info()

在 Linux 内核中,以下漏洞已修复:

btrfs:修复删除目录 (CVE-2026-46160) 时缺失的last_unlink_trans更新

在 Linux 内核中,以下漏洞已修复:

hfsplus:通过验证目录记录大小 (CVE-2026-46169) 修复 uninit-value

在 Linux 内核中,以下漏洞已修复:

fbcon:避免控制台旋转失败时的 OOB 字体访问 (CVE-2026-46191)

在 Linux 内核中,以下漏洞已修复:

tracepoint:平衡 tracepoint_add_func()CVE-2026-46196 中 func_add() 失败时的 regfunc()

在 Linux 内核中,以下漏洞已修复:

pmdomain:core:修复 genpd (CVE-2026-46292) 中虚拟设备的分离过程

在 Linux 内核中,以下漏洞已修复:

hfsplus:修复 hfsplus_fill_super() (CVE-2026-46299) 上释放的保持锁定

在 Linux 内核中,以下漏洞已修复:

tap:释放 tap_get_user_xdp() 中的错误路径上的页面 (CVE-2026-46320)

在 Linux 内核中,以下漏洞已修复:

tun:tun_xdp_one() (CVE-2026-46321) 中的短框架拒绝的释放页

在 Linux 内核中,以下漏洞已修复:

tun:tun_xdp_one() (CVE-2026-46322) 中build_skb失败的释放页面

在 Linux 内核中,以下漏洞已修复:

bpf:在 RCU 宽限期后释放 reuseport cBPF prog。(CVE-2026-52910)

在 Linux 内核中,以下漏洞已修复:

netfilter:nf_queue:排队时保持桥接 skb->dev (CVE-2026-52912)

在 Linux 内核中,以下漏洞已修复:

ipc:将next_id分配限制为有效 ID 范围 (CVE-2026-52923)

在 Linux 内核中,以下漏洞已修复:

sctp:清除过时的 COOKIE-ECHO 处理中的出队列 (CVE-2026-52924)

在 Linux 内核中,以下漏洞已修复:

netfilter:ebtables:修复 compat_mtw_from_user 中的 OOB 读取 (CVE-2026-52927)

在 Linux 内核中,以下漏洞已修复:

sctp:stream:完全回滚回拒绝的 add-stream 状态 (CVE-2026-52929)

在 Linux 内核中,以下漏洞已修复:

ipc/shm:通过shm_nattch更新序列化孤立清除 (CVE-2026-52930)

在 Linux 内核中,以下漏洞已修复:

net:skbuff:修复 pskb_carve 帮助程序 (CVE-2026-52943) 中缺少的 zerocopy 引用

在 Linux 内核中,以下漏洞已修复:

fs/fcntl:修复 fasync 信号 (CVE-2026-52946) 中的 SOFTIRQ-unsafe 锁定顺序

在 Linux 内核中,以下漏洞已修复:

i2c:dev:防止 I2C_TIMEOUT ioctl (CVE-2026-52948) 中的整数溢出

在 Linux 内核中,以下漏洞已修复:

net/sched:cls_fw:修复 change() (CVE-2026-53080) 之前旧过滤器的空取消引用

在 Linux 内核中,以下漏洞已修复:

RDMA/umem:修复区块大小的截断 >= 4G (CVE-2026-53133)

在 Linux 内核中,以下漏洞已修复:

netfilter:nft_fib:修复通过 OIFNAME 寄存器 (CVE-2026-53134) 产生的过时堆栈泄漏

在 Linux 内核中,以下漏洞已修复:

fuse:拒绝 fuse_notify() 目录上的 pagecache ops (CVE-2026-53168)

在 Linux 内核中,以下漏洞已修复:

IB/isert:拒绝短于 ISER_HEADERS_LEN (CVE-2026-53176) 的登录 PDU

在 Linux 内核中,以下漏洞已修复:

RDMA/srp:通过接收到的长度 (CVE-2026-53186) 绑定 SRP_RSP 感知副本

在 Linux 内核中,以下漏洞已修复:

mm/huge_memory:在 folio_put() () 之前CVE-2026-53189更新文件 PMD 计数器

在 Linux 内核中,以下漏洞已修复:

USB:serial:kl5kusb105:修复大量输出缓冲区溢出 (CVE-2026-53194)

在 Linux 内核中,以下漏洞已修复:

USB:serial:io_ti:修复 build_i2c_fw_hdr() (CVE-2026-53195) 中的堆溢出

在 Linux 内核中,以下漏洞已修复:

USB:serial:io_ti:修复 get_manuf_info() (CVE-2026-53196) 中的堆溢出

在 Linux 内核中,以下漏洞已修复:

hv_netvsc:在 netvsc_copy_to_send_buf 中使用 kmap_local_page (CVE-2026-53199)

在 Linux 内核中,以下漏洞已修复:

netfilter:nft_tunnel:修复对象破坏时的释放后使用 (CVE-2026-53212)

在 Linux 内核中,以下漏洞已修复:

netfilter:nft_exthdr:修复 F_PRESENT 标记 (CVE-2026-53218) 的寄存器跟踪

在 Linux 内核中,以下漏洞已修复:

netfilter:x_tables:避免泄漏 percpu 计数器指针 (CVE-2026-53219)

在 Linux 内核中,以下漏洞已修复:

ip6_vti:修复 vti6_tnl_lookup() (CVE-2026-53221) 中不正确的隧道匹配

在 Linux 内核中,以下漏洞已修复:

net:保护时间戳 cmsgs 以实现真正的错误队列 skbs (CVE-2026-53223)

在 Linux 内核中,以下漏洞已修复:

sctp:修复 __sctp_rcv_asconf_lookup() 中的 uninit-value (CVE-2026-53225)

在 Linux 内核中,以下漏洞已修复:

net:openvswitch:修复可能的 ERR_PTR kfree_skb (CVE-2026-53227)

在 Linux 内核中,以下漏洞已修复:

ipv6:sit:GSO 卸载后重新加载内部 IPv6 标头 (CVE-2026-53228)

在 Linux 内核中,以下漏洞已修复:

netlabel:验证未标记的地址和掩码属性长度 (CVE-2026-53238)

在 Linux 内核中,以下漏洞已修复:

xfrm:policy:修复 xfrm_policy_bysel_ctx() (CVE-2026-53239) 中不准确的 bin 上的释放后使用

在 Linux 内核中,以下漏洞已修复:

net/802/mrp:修复 mrp_pdu_parse_vecattr (CVE-2026-53245) 中的矢量属性解析

在 Linux 内核中,以下漏洞已修复:

ipv4:限制IPOPT_SSRR和IPOPT_LSRR选项 (CVE-2026-53249)

在 Linux 内核中,以下漏洞已修复:

net/sched:act_api:将 RCU 与操作生命周期 (CVE-2026-53264) 的延迟释放一起使用

在 Linux 内核中,以下漏洞已修复:

netfilter:bridge:使 ebt_snat ARP 重写可写 (CVE-2026-53266)

在 Linux 内核中,以下漏洞已修复:

netfilter:conntrack_irc:修复可能的越界读取 (CVE-2026-53268)

在 Linux 内核中,以下漏洞已修复:

netfilter:synproxy:添加互斥体以保护挂钩引用计数 (CVE-2026-53269)

在 Linux 内核中,以下漏洞已修复:

ipvs:编辑时提前清除 svc 计划程序 ptr (CVE-2026-53270)

在 Linux 内核中,以下漏洞已修复:

net:bonding:修复 bond_do_ioctl() 中的空指针取消引用

在 bond_do_ioctl() 中,slave_dev 是通过 __dev_get_by_name() 获取的,如果请求的接口名称不存在,该 () 可返回 NULL。但是,随后的 slave_dbg() 调用会在 NULL 检查之前进行:

slave_dev = __dev_get_by_name(net, ifr->ifr_slave);slave_dbg(bond_dev, slave_dev, slave_dev=%p:\n, slave_dev); //hereif (!slave_dev)return -ENODEV;

slave_dbg() 宏扩展为 netdev_dbg(bond_dev, (slave %s): fmt,(slave_dev)->name, ...),这会在执行空检查之前无条件取消引用 slave_dev->name。这会导致当用户调用具有不存在的从属接口名称的绑定 ioctl(如 SIOCBONDENSLAVE、SIOCBONDRELEASE 等)时,发生空指针取消引用内核 oops。

可通过绑定 ioctl 接口withCAP_NET_ADMIN功能从用户空间访问此问题,使其成为潜在的本地拒绝服务矢量。

通过在 NULL 检查之后移动 slave_dbg() 调用修复。(CVE-2026-53337)

在 Linux 内核中,以下漏洞已修复:

signal:清除 zap_other_threads() 中调用程序的JOBCTL_PENDING_MASK

当多线程进程接收到停止信号(例如 SIGSTOP)时,do_signal_stop() 会在 allthreads 上设置 JOBCTL_STOP_PENDING 和 JOBCTL_STOP_CONSUME,并将 signal->group_stop_count 设置为线程数。如果其中一个线程同时调用 execve()、de_thread() invokeszap_other_threads() 终止所有其他线程。zap_other_threads() 通过将 signal->group_stop_count 重置为 0 中止待定的群组停止,并为所有其他线程清除JOBCTL_PENDING_MASK。但是,无法清除调用线程的作业控制标记。

execve() 完成后,调用线程返回用户模式并检查待定信号。看到过时的 JOBCTL_STOP_PENDING 标记,它会调用 do_signal_stop(),从而调用 task_participate_group_stop()。由于 JOBCTL_STOP_CONSUME 仍处于设置状态,它会尝试递减已经为零的信号>group_stop_count,从而触发警告:

sig->group_stop_count == 0WARNING: CPU: 1 PID: 6475 at kernel/signal.c:373task_participate_group_stop+0x215/0x2d0Call Trace:<TASK>do_signal_stop+0x3be/0x5c0 kernel/signal.c:2619get_signal+0xa8c/0x1330 kernel/signal.c:2884arch_do_signal_or_restart+0xbc/0x840 arch/x86/kernel/signal.c:337exit_to_user_mode_loop+0x8c/0x4d0 kernel/entry/common.c:98do_syscall_64+0x33e/0xf80 arch/x86/entry/syscall_64.c:100entry_SYSCALL_64_after_hwframe+0x77/0x7f</TASK>

通过清除 zap_other_threads() 中调用线程的JOBCTL_PENDING_MASK修复此争用条件,确保其在销毁线程组之后不保留任何过时的作业控制状态。这与其他去除线程组并中止群组停止的函数保持一致,如 zap_process() 和 complete_signal(),这些函数会为包括当前线程在内的所有线程正确清除这些标记。
(CVE-2026-53352)

在 Linux 内核中,以下漏洞已修复:

arm64:勘误表:缓解各种 Arm CPU 上的 TLBI 勘误表

Arm 开发的多个 CPU 受到勘误表的影响,由此,broadcastTLBI;DSB 序列可能会在全局观察由受影响的 TLB 条目转换的写入之前完成。

这些勘误表仅影响已由已失效的 TLB 条目转换的内存访问的完成,这些勘误表不会影响 TLB 条目的实际失效。TLB 条目删除正确。

此问题已分配 CVE ID CVE-2025-10263。

为了缓解此问题,Arm 建议软件通过额外的 TLBI;DSB 遵循任何受影响的 TLBI;DSB 序列,这将确保全局观察到受到第一个 TLBI 影响的所有内存写入效果。附加 TLBI 可以使用广播到受影响 CPU 的任何操作,附加 DSB 可以使用任何足以完成附加 TLBI 的选项。

ARM64_WORKAROUND_REPEAT_TLBI的变通方案足以缓解问题。对受影响的 CPU 启用此变通方案,并相应更新芯片勘误表文档。

请注意,由于 Arm 开发 IP 和跟踪 errata 的方式,一些 CPU 共享一个通用的 erratum 编号。(CVE-2026-53354)

在 Linux 内核中,以下漏洞已修复:

drm/i915/gem:修复具有偏移 (CVE-2026-53356) 的 phys BO pread/pwrite

在 Linux 内核中,以下漏洞已修复:

net:garp:修复 garp_pdu_parse_attr 中无符号的整数下溢

接收端 GARP 属性解析器计算具有反向多数的 dlen:

dlen = sizeof(*ga) - ga->len;

ga->len 是在线属性长度,包含 GARP 属性标头。对于具有数据的普通属性,ga->len 大于sizeof(*ga),因此无符号算术中的减法下溢。

结果值稍后传递给 garp_attr_lookup(),其长度参数为 u8。截断后,解析的数据长度通常不再与为本地注册的属性存储的长度匹配,因此会忽略接收到的加入/退出事件。这会中断通用属性(如 GVRP VLAN 注册属性)的 GARP 接收路径。

计算数据长度为属性长度减去标头长度。(CVE-2026-63868)

在 Linux 内核中,以下漏洞已修复:

scsi:target:iscsi:绑定 iscsi_encode_text_output() 附加至 rsp_buf (CVE-2026-63887)

在 Linux 内核中,以下漏洞已修复:

scsi:target:iscsi:修复 iscsit_handle_text_cmd() (CVE-2026-63888) 中的 CRC 越界读取和双重释放

在 Linux 内核中,以下漏洞已修复:

scsi:fcoe:拒绝 CVL 遍历器中具有零fip_dlen的 FIP 描述符

drivers/scsi/fcoe/fcoe_ctlr.c::fcoe_ctlr_recv_clr_vlink() 通过攻击者提供的fip_dlen推进描述符光标,而不需要默认分支中的 DLEN >= sizeof(struct fip_desc)。命名描述符案例(FIP_DT_MAC、FIP_DT_NAME、FIP_DT_VN_ID)会检查其各类型的最小长度,但FIP_DT_NON_CRITICAL描述符(fip_dtype >= 128,标准要求接收者静默忽略)完全跳过了该检查。

通过发出一个单一描述符fip_dtype ==FIP_DT_NON_CRITICAL 且 fip_dlen == 0 的 FIP CVL 帧,FCoE 控制 VLAN 上未经身份验证的 L2 对等机可无限期地hangfcoe_ctlr_recv_work fcoe、qedf 或 bnx2fc 启动程序:光标高级零字节秒迭代和循环条件 rlen >= sizeof(*desc) 永远保持 true, 阻断该控制器上每个后续 FIP 帧。

加强外部 dlen 防护,以同时拒绝 sizeof(structfip_desc) < dlen,以便在切换之前拒绝长度甚至不能覆盖描述符标头的畸形描述符。这是相同的命名案例已经适用的下限,并且是关闭循环的最小范围。(CVE-2026-63890)

在 Linux 内核中,以下漏洞已修复:

USB:serial:mct_u232:修复缺少的中断输入传输健全性检查

添加缺少的对中断输入传输大小的健全性检查,以避免解析过时或未初始化的 slab 数据(并将其泄露到用户空间)。(CVE-2026-63897)

在 Linux 内核中,以下漏洞已修复:

USB:serial:mct_u232:通过小端点 (CVE-2026-63898) 修复内存损坏

在 Linux 内核中,以下漏洞已修复:

USB:serial:keyspan:修复缺少的 indat 传输健全性检查

为 usa49wg indat 传输大小添加缺少的健全性检查,以避免解析过时或未初始化的 slab 数据。(CVE-2026-63900)

在 Linux 内核中,以下漏洞已修复:

USB:serial:digi_acceleport:修复小端点的内存损坏

添加缺少的大量输出缓冲区大小健全性检查,以避免在恶意设备报告的缓冲区小于预期时发生越界内存访问或 slab 损坏。(CVE-2026-63901)

在 Linux 内核中,以下漏洞已修复:

USB:serial:cypress_m8:验证中断数据包标头

cypress_read_int_callback() 根据选定的 Cypress 数据包格式解析中断输入缓冲区。
格式 1 具有两个字节的状态/计数标头,格式 2 具有一个字节的状态/计数标头。
usb-serial 核心根据端点描述符的 wMaxPacketSize 调整中断输入缓冲区的大小,当未设置URB_SHORT_NOT_OK时,成功的中断传输可以完成短。

在读取之前,检查已完成的数据包是否包含所选的标头。畸形短报告会被忽略并通过现有重试路径重新提交中断 URB,从而防止越界标头字节读取。

KASAN 报告如下:大小为 1 的 cypress_read_int_callback+0x240/0x7f0Read 中的 KASAN slab-out-of-bound调用跟踪:cypress_read_int_callback() (drivers/usb/serial/cypress_m8.c:1009)__usb_hcd_giveback_urb()dummy_timer()

[ johan:在标头长度健全性检查中使用常量 ](CVE-2026-63902)

在 Linux 内核中,以下漏洞已修复:

USB:serial:belkin_sa:验证中断状态长度

Belkin 中断回调将中断数据视为四字节状态报告,并读取偏移 2 和 3 处的 LSR/MSR 字段。中断输入缓冲区长度来源于端点 wMaxPacketSize,短中断传输可通过smalleractual_length成功完成。

在解析 statusfields 之前检查已完成的中断数据包长度,以便忽略短中断端点和短而成功的数据包,而不是造成越界或过时的状态字节读取。

KASAN 报告如下:

缺陷:KASAN:大小为 1 的 belkin_sa_read_int_callback()Read 中的 slab-out-boundCall trace:belkin_sa_read_int_callback() (drivers/usb/serial/belkin_sa.c:202)__usb_hcd_giveback_urb() (drivers/usb/core/hcd.c:1630)dummy_timer() (?:?)(CVE-2026-63903)

在 Linux 内核中,以下漏洞已修复:

usb:usbtmc:检查 URB actual_length是否有中断 IN 通知

USBTMC 设备可对 notificationmessages 使用可选中断端点。这些通常包含指示有效负载格式的两字节标头,但驱动程序在访问数据缓冲区之前不会检查这些标头是否表示。如果URBactual_length不足以适合这些标头,驱动程序将造成越界读取,或消耗之前通知中过时的剩余数据。

通过检查actual_data是否包含足够的标头字节进行修复,否则将 URB 重新提交到中断端点。(CVE-2026-63904)

在 Linux 内核中,以下漏洞已修复:

xfrm:esp:还原合并的单 frag 长度门

ESP 就地快速路径在 esp_output_head() 分配目标页面碎片之前将尾部附加到 esp_output_tail() 中。head-side gate 当前分别检查 skb->data_len 和 tailen,但尾部代码从组合后的拖车 skb->data_len 分配单个目标碎片。

当组合对齐长度超过 apage 时,拒绝 page-frag 快速路径。否则,skb_page_frag_refill() 可能会在目标 sg 仍跨越合并的 skb->data_len 时回退到单个页面。

为 IPv4 和 IPv6 还原此组合长度页面门控。(CVE-2026-63912)

在 Linux 内核中,以下漏洞已修复:

netfilter:conntrack:tcp:不在没有方向检查 (CVE-2026-63913) 的情况下强制关闭无效的 seq RST

在 Linux 内核中,以下漏洞已修复:

xfrm:将 MIGRATE 通知路由到调用方的 netns (CVE-2026-63914)

在 Linux 内核中,以下漏洞已修复:

HID:wacom:修复 wacom_hid_set_device_mode() 中的越界写入

wacom_hid_set_device_mode() 当前假设HID_DG_INPUTMODEusage始终位于特征报告的第一个字段 (field[0]) 中。但是,设备可以在其他字段中指定HID_DG_INPUTMODE。

如果HID_DG_INPUTMODE在第一个字段以外的字段中,并且第一个字段具有小于HID_DG_INPUTMODE usage_index的report_count,这会导致越界写入 r->field[0]->value。

通过在功能映射期间将 HID_DG_INPUTMODE 的字段索引存储在“structhid_data”中来修复此问题。在 wacom_hid_set_device_mode() 中,使用此存储的字段索引访问正确的字段,并添加边界检查以确保字段索引和值索引在写入前都在无效范围内。(CVE-2026-63916)

在 Linux 内核中,以下漏洞已修复:

ip6:vti:在 vti6_changelink() 中使用 ip6_tnl.net。(CVE-2026-63917)

在 Linux 内核中,以下漏洞已修复:

xfrm:input:在延迟传输重新注入期间保持 netns (CVE-2026-63919)

在 Linux 内核中,以下漏洞已修复:

ipv6:复制到 cmsg (CVE-2026-63920) 之前验证扩展标头长度

在 Linux 内核中,以下漏洞已修复:

ip6:vti:在 vti6_siocdevprivate() 中使用 ip6_tnl.net。

在本系列的 1/2 修补程序后,vti6_update() 通过 t->net 断开和重新链接隧道。
vti6_siocdevprivate() 仍usesdev_net(dev) 进行冲突查找。对于throughIFLA_NET_NS_FD移动的隧道,dev_net(dev) 是新的 netns,而非 t->net。

然后,迁移的隧道中的 SIOCCHGTUNNEL 运行:

net = dev_net(dev) /* 迁移的 netns */t = vti6_locate(net, &p1, false) /* t->net 中未达到目标 */...t = netdev_priv(dev)vti6_update(t, &p1, false) /* 改变 t->net 的哈希
*/

迁移的 netns 中的调用程序会选择与创建 netns 中的隧道匹配的参数。dev_net(dev) 中的查找发现 nothing.vti6_update() 在创建 netns 哈希存储桶头部为这些参数添加了迁移的隧道。稍后在创建 netns 中的查找会解析到已迁移的设备。xfrm receive通过调用方控制的设备发送匹配的数据包。

可从非特权用户命名空间访问 (unshare --user--map-root-user --net)。容器主机上的跨租户范围。

将非回退设备上的 SIOCCHGTUNNEL 路径切换为 uset->net 进行查找。查找现在与操作 netnsvti6_update() 相匹配。

还在查找前添加 ns_capable(self->net->user_ns, CAP_NET_ADMIN)。案例顶部的检查是 againstdev_net(dev)->user_ns,迁移后就是攻击者的 snetns。那里的调用程序可以选择 self->net 中不存在的参数,查找返回 NULL,t 变为 self,然后 vti6_update() 将设备插入创建 netns 哈希。新的 checkrequires 也会在创建 netns user_ns中CAP_NET_ADMIN。

SIOCADDTUNNEL 和 SIOCCHGTUNNEL 安装在回退设备 keepdev_net(dev) 上,等于init_net。
(CVE-2026-63921)

在 Linux 内核中,以下漏洞已修复:

ipv6:exthdrs:处理 HAO 选项 (CVE-2026-63922) 后刷新 nh

在 Linux 内核中,以下漏洞已修复:

ipv6:exthdrs:ipv6_hop_jumbo() 之后刷新 nh 指针

ipv6_hop_jumbo() 会调用 pskb_trim_rcsum(),其可更改 skb 指针。让我们重新计算 nh 指针以确保任何更改都不会把事情搞砸。(CVE-2026-63924)

在 Linux 内核中,以下漏洞已修复:

macsec:修复 XPN lower-PN wrap (CVE-2026-63925) 时的重放保护

在 Linux 内核中,以下漏洞已修复:

bpf:sockmap:修复 bpf_msg_push_data 中的末尾碎片偏移

当 bpf_msg_push_data() 在 scatterlistentry 中间插入数据时,它会将原始条目拆分为左片段和右片段。

正确的片段偏移量为页面本地,但代码通过“start”来推进它,此是消息全局插入点。对于插入到非第一个 SG 条目中,这会过度推进偏移量并使 splitlayout 不一致。

将右侧片段偏移前推进片段本地增量“start - offset”,该增量与从原始条目前面删除的长度匹配。(CVE-2026-63926)

在 Linux 内核中,以下漏洞已修复:

USB:serial:omninet:通过小端点修复内存损坏

确保批量输出缓冲区至少与硬编码传输大小一样大,以避免用户控制的 slab 损坏,恶意设备报告的端点最大数据包大小应小于预期。(CVE-2026-63928)

在 Linux 内核中,以下漏洞已修复:

USB:serial:cypress_m8:通过小端点修复内存损坏

确保中断输出端点数据包大小上限至少为八字节,以避免在恶意设备报告较小大小时发生用户控制的 slab 损坏或空指针取消引用。
(CVE-2026-63956)

在 Linux 内核中,以下漏洞已修复:

USB:serial:safe_serial:通过小端点 (CVE-2026-63957) 修复内存损坏

在 Linux 内核中,以下漏洞已修复:

sctp:修复sctp_wait_for_connect和剥离之间的争用

sctp_wait_for_connect() 在等待关联达到 ESTABLISHED 状态时舍弃并重新获取套接字锁。在此窗口期间,另一个线程可解除与新套接字 viagetsockopt(SCTP_SOCKOPT_PEELOFF) 的关联,从而更改 asoc->base.sk。重新获取旧套接字锁后,sctp_wait_for_connect() 返回成功而不注意迁移 -- 调用程序随后访问 sctp_datamsg_from_user() 中错误锁定下的关联。

添加 sctp_wait_for_sndbuf() 已进行的相同 sk != asoc->base.sk 检查,如果关联在我们休眠时迁移,则会返回错误。(CVE-2026-63971)

在 Linux 内核中,以下漏洞已修复:

ipv6:rpl:修复 ipv6_rpl_srh_d 中的 hdrlen 溢出...

请注意,描述因长度问题被截断。请参考供应商公告,获取完整描述。

Tenable 已直接从测试产品的安全公告中提取上述描述块。

请注意,Nessus 尚未测试这些问题,而是只依据应用程序自我报告的版本号进行判断。

解决方案

运行 'yum update kernel' 或 'yum update --advisory ALAS2KERNEL-5.10-2026-124' 以更新系统。

另见

https://alas.aws.amazon.com//AL2/ALAS2KERNEL-5.10-2026-124.html

https://alas.aws.amazon.com/faqs.html

https://explore.alas.aws.amazon.com/CVE-2026-23449.html

https://explore.alas.aws.amazon.com/CVE-2026-31449.html

https://explore.alas.aws.amazon.com/CVE-2026-31533.html

https://explore.alas.aws.amazon.com/CVE-2026-31708.html

https://explore.alas.aws.amazon.com/CVE-2026-43350.html

https://explore.alas.aws.amazon.com/CVE-2026-43492.html

https://explore.alas.aws.amazon.com/CVE-2026-45850.html

https://explore.alas.aws.amazon.com/CVE-2026-45991.html

https://explore.alas.aws.amazon.com/CVE-2026-46021.html

https://explore.alas.aws.amazon.com/CVE-2026-46052.html

https://explore.alas.aws.amazon.com/CVE-2026-46086.html

https://explore.alas.aws.amazon.com/CVE-2026-46107.html

https://explore.alas.aws.amazon.com/CVE-2026-46137.html

https://explore.alas.aws.amazon.com/CVE-2026-46159.html

https://explore.alas.aws.amazon.com/CVE-2026-46160.html

https://explore.alas.aws.amazon.com/CVE-2026-46169.html

https://explore.alas.aws.amazon.com/CVE-2026-46191.html

https://explore.alas.aws.amazon.com/CVE-2026-46196.html

https://explore.alas.aws.amazon.com/CVE-2026-46292.html

https://explore.alas.aws.amazon.com/CVE-2026-46299.html

https://explore.alas.aws.amazon.com/CVE-2026-46320.html

https://explore.alas.aws.amazon.com/CVE-2026-46321.html

https://explore.alas.aws.amazon.com/CVE-2026-46322.html

https://explore.alas.aws.amazon.com/CVE-2026-52910.html

https://explore.alas.aws.amazon.com/CVE-2026-52912.html

https://explore.alas.aws.amazon.com/CVE-2026-52923.html

https://explore.alas.aws.amazon.com/CVE-2026-52924.html

https://explore.alas.aws.amazon.com/CVE-2026-52927.html

https://explore.alas.aws.amazon.com/CVE-2026-52929.html

https://explore.alas.aws.amazon.com/CVE-2026-52930.html

https://explore.alas.aws.amazon.com/CVE-2026-52943.html

https://explore.alas.aws.amazon.com/CVE-2026-52946.html

https://explore.alas.aws.amazon.com/CVE-2026-52948.html

https://explore.alas.aws.amazon.com/CVE-2026-53080.html

https://explore.alas.aws.amazon.com/CVE-2026-53133.html

https://explore.alas.aws.amazon.com/CVE-2026-53134.html

https://explore.alas.aws.amazon.com/CVE-2026-53168.html

https://explore.alas.aws.amazon.com/CVE-2026-53176.html

https://explore.alas.aws.amazon.com/CVE-2026-53186.html

https://explore.alas.aws.amazon.com/CVE-2026-53189.html

https://explore.alas.aws.amazon.com/CVE-2026-53194.html

https://explore.alas.aws.amazon.com/CVE-2026-53195.html

https://explore.alas.aws.amazon.com/CVE-2026-53196.html

https://explore.alas.aws.amazon.com/CVE-2026-53199.html

https://explore.alas.aws.amazon.com/CVE-2026-53212.html

https://explore.alas.aws.amazon.com/CVE-2026-53218.html

https://explore.alas.aws.amazon.com/CVE-2026-53219.html

https://explore.alas.aws.amazon.com/CVE-2026-53221.html

https://explore.alas.aws.amazon.com/CVE-2026-53223.html

https://explore.alas.aws.amazon.com/CVE-2026-53225.html

https://explore.alas.aws.amazon.com/CVE-2026-53227.html

https://explore.alas.aws.amazon.com/CVE-2026-53228.html

https://explore.alas.aws.amazon.com/CVE-2026-53238.html

https://explore.alas.aws.amazon.com/CVE-2026-53239.html

https://explore.alas.aws.amazon.com/CVE-2026-53245.html

https://explore.alas.aws.amazon.com/CVE-2026-53249.html

https://explore.alas.aws.amazon.com/CVE-2026-53264.html

https://explore.alas.aws.amazon.com/CVE-2026-53266.html

https://explore.alas.aws.amazon.com/CVE-2026-53268.html

https://explore.alas.aws.amazon.com/CVE-2026-53269.html

https://explore.alas.aws.amazon.com/CVE-2026-53270.html

https://explore.alas.aws.amazon.com/CVE-2026-53337.html

https://explore.alas.aws.amazon.com/CVE-2026-53352.html

https://explore.alas.aws.amazon.com/CVE-2026-53354.html

https://explore.alas.aws.amazon.com/CVE-2026-53356.html

https://explore.alas.aws.amazon.com/CVE-2026-63868.html

https://explore.alas.aws.amazon.com/CVE-2026-63887.html

https://explore.alas.aws.amazon.com/CVE-2026-63888.html

https://explore.alas.aws.amazon.com/CVE-2026-63890.html

https://explore.alas.aws.amazon.com/CVE-2026-63897.html

https://explore.alas.aws.amazon.com/CVE-2026-63898.html

https://explore.alas.aws.amazon.com/CVE-2026-63900.html

https://explore.alas.aws.amazon.com/CVE-2026-63901.html

https://explore.alas.aws.amazon.com/CVE-2026-63902.html

https://explore.alas.aws.amazon.com/CVE-2026-63903.html

https://explore.alas.aws.amazon.com/CVE-2026-63904.html

https://explore.alas.aws.amazon.com/CVE-2026-63912.html

https://explore.alas.aws.amazon.com/CVE-2026-63913.html

https://explore.alas.aws.amazon.com/CVE-2026-63914.html

https://explore.alas.aws.amazon.com/CVE-2026-63916.html

https://explore.alas.aws.amazon.com/CVE-2026-63917.html

https://explore.alas.aws.amazon.com/CVE-2026-63919.html

https://explore.alas.aws.amazon.com/CVE-2026-63920.html

https://explore.alas.aws.amazon.com/CVE-2026-63921.html

https://explore.alas.aws.amazon.com/CVE-2026-63922.html

https://explore.alas.aws.amazon.com/CVE-2026-63924.html

https://explore.alas.aws.amazon.com/CVE-2026-63925.html

https://explore.alas.aws.amazon.com/CVE-2026-63926.html

https://explore.alas.aws.amazon.com/CVE-2026-63928.html

https://explore.alas.aws.amazon.com/CVE-2026-63956.html

https://explore.alas.aws.amazon.com/CVE-2026-63957.html

https://explore.alas.aws.amazon.com/CVE-2026-63971.html

https://explore.alas.aws.amazon.com/CVE-2026-63984.html

https://explore.alas.aws.amazon.com/CVE-2026-63992.html

https://explore.alas.aws.amazon.com/CVE-2026-63993.html

https://explore.alas.aws.amazon.com/CVE-2026-63994.html

https://explore.alas.aws.amazon.com/CVE-2026-64002.html

https://explore.alas.aws.amazon.com/CVE-2026-64005.html

https://explore.alas.aws.amazon.com/CVE-2026-64007.html

https://explore.alas.aws.amazon.com/CVE-2026-64009.html

https://explore.alas.aws.amazon.com/CVE-2026-64012.html

https://explore.alas.aws.amazon.com/CVE-2026-64118.html

https://explore.alas.aws.amazon.com/CVE-2026-64170.html

插件详情

严重性: High

ID: 325574

文件名: al2_ALASKERNEL-5_10-2026-124.nasl

版本: 1.6

类型: Local

代理: unix

发布时间: 2026/7/8

最近更新时间: 2026/8/13

支持的传感器: Frictionless Assessment AWS, Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Continuous Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

风险信息

VPR

风险因素: High

分数: 7.9

百分位: 99.36

CVSS v2

风险因素: High

基本分数: 7.2

时间分数: 5.6

矢量: CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C

CVSS 分数来源: CVE-2026-53196

CVSS v3

风险因素: High

基本分数: 7.8

时间分数: 7

矢量: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

时间矢量: CVSS:3.0/E:P/RL:O/RC:C

CVSS 分数来源: CVE-2026-53195

漏洞信息

CPE: cpe:/o:amazon:linux:2, p-cpe:/a:amazon:linux:bpftool-debuginfo, p-cpe:/a:amazon:linux:bpftool, p-cpe:/a:amazon:linux:kernel-debuginfo-common-aarch64, p-cpe:/a:amazon:linux:kernel-debuginfo-common-x86_64, p-cpe:/a:amazon:linux:kernel-debuginfo, p-cpe:/a:amazon:linux:kernel-devel, p-cpe:/a:amazon:linux:kernel-headers, p-cpe:/a:amazon:linux:kernel-livepatch-5.10.259-258.1043, p-cpe:/a:amazon:linux:kernel-tools-debuginfo, p-cpe:/a:amazon:linux:kernel-tools-devel, p-cpe:/a:amazon:linux:kernel-tools, p-cpe:/a:amazon:linux:kernel, p-cpe:/a:amazon:linux:perf-debuginfo, p-cpe:/a:amazon:linux:perf, p-cpe:/a:amazon:linux:python-perf-debuginfo, p-cpe:/a:amazon:linux:python-perf

必需的 KB 项: Host/local_checks_enabled, Host/AmazonLinux/release, Host/AmazonLinux/rpm-list

可利用: true

易利用性: Exploits are available

补丁发布日期: 2026/7/8

漏洞发布日期: 2026/4/3

参考资料信息

CVE: CVE-2026-23449, CVE-2026-31449, CVE-2026-31533, CVE-2026-31708, CVE-2026-43350, CVE-2026-43492, CVE-2026-45850, CVE-2026-45991, CVE-2026-46021, CVE-2026-46052, CVE-2026-46086, CVE-2026-46107, CVE-2026-46137, CVE-2026-46159, CVE-2026-46160, CVE-2026-46169, CVE-2026-46191, CVE-2026-46196, CVE-2026-46292, CVE-2026-46299, CVE-2026-46320, CVE-2026-46321, CVE-2026-46322, CVE-2026-52910, CVE-2026-52912, CVE-2026-52923, CVE-2026-52924, CVE-2026-52927, CVE-2026-52929, CVE-2026-52930, CVE-2026-52943, CVE-2026-52946, CVE-2026-52948, CVE-2026-53080, CVE-2026-53133, CVE-2026-53134, CVE-2026-53168, CVE-2026-53176, CVE-2026-53186, CVE-2026-53189, CVE-2026-53194, CVE-2026-53195, CVE-2026-53196, CVE-2026-53199, CVE-2026-53212, CVE-2026-53218, CVE-2026-53219, CVE-2026-53221, CVE-2026-53223, CVE-2026-53225, CVE-2026-53227, CVE-2026-53228, CVE-2026-53238, CVE-2026-53239, CVE-2026-53245, CVE-2026-53249, CVE-2026-53264, CVE-2026-53266, CVE-2026-53268, CVE-2026-53269, CVE-2026-53270, CVE-2026-53337, CVE-2026-53352, CVE-2026-53354, CVE-2026-53356, CVE-2026-63868, CVE-2026-63887, CVE-2026-63888, CVE-2026-63890, CVE-2026-63897, CVE-2026-63898, CVE-2026-63900, CVE-2026-63901, CVE-2026-63902, CVE-2026-63903, CVE-2026-63904, CVE-2026-63912, CVE-2026-63913, CVE-2026-63914, CVE-2026-63916, CVE-2026-63917, CVE-2026-63919, CVE-2026-63920, CVE-2026-63921, CVE-2026-63922, CVE-2026-63924, CVE-2026-63925, CVE-2026-63926, CVE-2026-63928, CVE-2026-63956, CVE-2026-63957, CVE-2026-63971, CVE-2026-63984, CVE-2026-63992, CVE-2026-63993, CVE-2026-63994, CVE-2026-64002, CVE-2026-64005, CVE-2026-64007, CVE-2026-64009, CVE-2026-64012, CVE-2026-64118, CVE-2026-64170