Amazon Linux 2023:bpftool6.18、kernel6.18、kernel6.18-devel (ALAS2023-2026-1925)

high Nessus 插件 ID 327383

简介

远程 Amazon Linux 2023 主机缺少安全更新。

描述

因此,该软件受到 ALAS2023-2026-1925 公告中提及的多个漏洞影响。

在 Linux 内核中,以下漏洞已修复:

ipvs:跳过 csum 检查的 ipv6 扩展标头 (CVE-2026-45850)

在 Linux 内核中,以下漏洞已修复:

selinux:修复 overlayfs mmap() 和 mprotect() 访问检查 (CVE-2026-46054)

在 Linux 内核中,以下漏洞已修复:

tap:释放 tap_get_user_xdp() 中的错误路径上的页面 (CVE-2026-46320)

在 Linux 内核中,以下漏洞已修复:

net/sched:修复导致页面缓存损坏的 pedit 部分 COW (CVE-2026-46331)

在 Linux 内核中,以下漏洞已修复:

RDMA:在rereg_mr期间确保 REREG_ACCESS 兼容 (CVE-2026-52908)

在 Linux 内核中,以下漏洞已修复:

ip6_vti:在回退设备上设置netns_immutable。(CVE-2026-52909)

在 Linux 内核中,以下漏洞已修复:

bpf:在 RCU 宽限期后释放 reuseport cBPF prog。(CVE-2026-52910)

在 Linux 内核中,以下漏洞已修复:

sctp:清除过时的 COOKIE-ECHO 处理中的出队列 (CVE-2026-52924)

在 Linux 内核中,以下漏洞已修复:

sctp:stream:完全回滚回拒绝的 add-stream 状态 (CVE-2026-52929)

在 Linux 内核中,以下漏洞已修复:

ipc/shm:通过shm_nattch更新序列化孤立清除 (CVE-2026-52930)

在 Linux 内核中,以下漏洞已修复:

tun:将 tun_put_user() ()CVE-2026-52940 中的整个 vnet 标头清零

在 Linux 内核中,以下漏洞已修复:

netfilter:nf_log:在转储前验证已设置 MAC 标头 (CVE-2026-52942)

在 Linux 内核中,以下漏洞已修复:

fs/fcntl:修复 fasync 信号 (CVE-2026-52946) 中的 SOFTIRQ-unsafe 锁定顺序

在 Linux 内核中,以下漏洞已修复:

netfilter:使用 eth_hdr() (CVE-2026-53131) 之前需要以太网 MAC 标头

在 Linux 内核中,以下漏洞已修复:

vsock/virtio:修复潜在的不受限制的 skb 队列 (CVE-2026-53132)

在 Linux 内核中,以下漏洞已修复:

RDMA/umem:修复区块大小的截断 >= 4G (CVE-2026-53133)

在 Linux 内核中,以下漏洞已修复:

netfilter:nft_fib:修复通过 OIFNAME 寄存器 (CVE-2026-53134) 产生的过时堆栈泄漏

在 Linux 内核中,以下漏洞已修复:

drm/gem: 尝试修复 change_handle ioctl,尝试 4 (CVE-2026-53145)

在 Linux 内核中,以下漏洞已修复:

mm/list_lru:清除 reparent (CVE-2026-53153) 上的 xarray 条目之前耗尽

在 Linux 内核中,以下漏洞已修复:

mm/hugetlb:当 hugetlb 作品集复制路径 (CVE-2026-53154) 中出错时恢复保留

在 Linux 内核中,以下漏洞已修复:

nvmem:core:修复错误路径中的释放后使用缺陷 (CVE-2026-53156)

在 Linux 内核中,以下漏洞已修复:

memcg:在 refill_stock 中使用轮循机制受害者选择 (CVE-2026-53162)

在 Linux 内核中,以下漏洞已修复:

locking/rtmutex:等候程序未排队时跳过 remove_waiter() (CVE-2026-53163)

在 Linux 内核中,以下漏洞已修复:

iommu/dma:不尝试在 swiotlb (CVE-2026-53164) 中iommu_map 0 长度区域

在 Linux 内核中,以下漏洞已修复:

fuse:将FUSE_NOTIFY_RETRIEVE限制为最新的 folios (CVE-2026-53167)

在 Linux 内核中,以下漏洞已修复:

fuse:拒绝 fuse_notify() 目录上的 pagecache ops (CVE-2026-53168)

在 Linux 内核中,以下漏洞已修复:

inet:frags:修复 fqdir_pre_exit() flush (CVE-2026-53175) 造成的释放后使用

在 Linux 内核中,以下漏洞已修复:

timers/migration:修复 tmigr_handle_remote_up() (CVE-2026-53180) 中的活锁

在 Linux 内核中,以下漏洞已修复:

mptcp:允许子流 rcv wnd 缩小 (CVE-2026-53183)

在 Linux 内核中,以下漏洞已修复:

udp:运行 sockmap 判定 (CVE-2026-53184) 之前清除 skb->dev

在 Linux 内核中,以下漏洞已修复:

RDMA/core:针对 DMAH 分配中的nr_cpu_ids验证cpu_id (CVE-2026-53187)

在 Linux 内核中,以下漏洞已修复:

RDMA/core:验证 ib_get_ucaps()CVE-2026-53188 () 的传入 fops

在 Linux 内核中,以下漏洞已修复:

mm/huge_memory:在 folio_put() () 之前CVE-2026-53189更新文件 PMD 计数器

在 Linux 内核中,以下漏洞已修复:

drm/virtio:修复 virtio_gpu_dma_fence_wait() (CVE-2026-53190) 中发生错误时dma_fence refcount 泄漏

在 Linux 内核中,以下漏洞已修复:

io_uring/net:跨捆绑 recv 重试 (CVE-2026-53191) 继承IORING_CQE_F_BUF_MORE

在 Linux 内核中,以下漏洞已修复:

mm/memory-failure:修复 get_huge_page_for_hwpoison (CVE-2026-53207) 中的 hugetlb_lock AA 死锁

在 Linux 内核中,以下漏洞已修复:

netfilter:nft_tunnel:修复对象破坏时的释放后使用 (CVE-2026-53212)

在 Linux 内核中,以下漏洞已修复:

ipv6:修复 cleanup_prefix_route() 中的潜在 NPD

addrconf_get_prefix_route() 可返回具有空fib6_table指针的 fib6_null_entry sentinelentry。因此,在设置路由的到期时间之前,请检查我们是否没有使用此条目,否则将触发 NPD [1]。

请注意,addrconf_get_prefix_route() 的其他调用程序不易受到此缺陷的影响:

1. addrconf_prefix_rcv():请求包含“RTF_ADDRCONF |RTF_PREFIX_RT“标记,这些标记未在fib6_null_entry上设置。

2. modify_prefix_route():通过提交 a747e02430df 修复(ipv6:避免 modify_prefix_route() 中可能的空取消引用)。

3. __ipv6_ifa_notify():调用 ip6_del_rt(),专门检查forfib6_null_entry并返回错误。

[1]哎呀:一般保护错误,可能针对非规范地址 0xdffffc0000000006:0000 [#1] SMP KASANKASAN:范围内的 null-ptr-deref [0x0000000000000030-0x0000000000000037][...]调用 Trace:<TASK>__kasan_check_byte (mm/kasan/common.c:573)lock_acquire.part.0 (kernel/locking/lockdep.c:5842 (discriminator 1))_raw_spin_lock_bh (kernel/locking/spinlock.c:182 (discriminator 1))cleanup_prefix_route (net/ipv6/addrconf.c:1280)ipv6_del_addr (net/ipv6/addrconf.c:1342)inet6_addr_del.isra.0 (net/ipv6/addrconf.c:3119)inet6_rtm_deladdr (net/ipv6/addrconf.c:4812)rtnetlink_rcv_msg (net/core/rtnetlink.c:6997)netlink_rcv_skb (net/netlink/af_netlink.c:2555)netlink_unicast (net/netlink/af_netlink.c:1344)netlink_sendmsg (net/netlink/af_netlink.c:1899)__sock_sendmsg (net/socket.c:802 (discriminator 4))____sys_sendmsg (net/socket.c:2698)___sys_sendmsg (net/socket.c:2752)__sys_sendmsg (net/socket.c:2784)do_syscall_64 (arch/x86/entry/syscall_64.c:63 arch/x86/entry/syscall_64.c:94)entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121) (CVE-2026-53214)

在 Linux 内核中,以下漏洞已修复:

netfilter:nft_exthdr:修复 F_PRESENT 标记 (CVE-2026-53218) 的寄存器跟踪

在 Linux 内核中,以下漏洞已修复:

netfilter:重新验证桥接端口 (CVE-2026-53220)

在 Linux 内核中,以下漏洞已修复:

ip6_vti:修复 vti6_tnl_lookup() (CVE-2026-53221) 中不正确的隧道匹配

在 Linux 内核中,以下漏洞已修复:

net:保护时间戳 cmsgs 以实现真正的错误队列 skbs (CVE-2026-53223)

在 Linux 内核中,以下漏洞已修复:

sctp:验证 cookie (CVE-2026-53224) 中嵌入的 INIT 区块和地址列表长度

在 Linux 内核中,以下漏洞已修复:

sctp:修复 __sctp_rcv_asconf_lookup() 中的 uninit-value (CVE-2026-53225)

在 Linux 内核中,以下漏洞已修复:

net:openvswitch:修复可能的 ERR_PTR kfree_skb (CVE-2026-53227)

在 Linux 内核中,以下漏洞已修复:

ipv6:sit:GSO 卸载后重新加载内部 IPv6 标头 (CVE-2026-53228)

在 Linux 内核中,以下漏洞已修复:

net/mlx5e:xsk:修复 XDP_TX xmit 失败 (CVE-2026-53229) 时的 DMA 和xdp_frame泄漏

在 Linux 内核中,以下漏洞已修复:

net/mlx5:修复 mlx5_query_nic_vport_mac_list 中的 slab-out-of-bound (CVE-2026-53230)

在 Linux 内核中,以下漏洞已修复:

net:phy:如果 phy 探测失败,则清除 sfp 上游 (CVE-2026-53232)

在 Linux 内核中,以下漏洞已修复:

netdev:修复 netdev_nl_bind_rx_doit() 中的双重释放 (CVE-2026-53233)

在 Linux 内核中,以下漏洞已修复:

net:将 pskb_may_pull() 添加到 skb_gro_receive_list() (CVE-2026-53235)

在 Linux 内核中,以下漏洞已修复:

tcp:将SO_ATTACH_FILTER限制为 priv 用户 (CVE-2026-53236)

在 Linux 内核中,以下漏洞已修复:

netlabel:验证未标记的地址和掩码属性长度 (CVE-2026-53238)

在 Linux 内核中,以下漏洞已修复:

xfrm:policy:修复 xfrm_policy_bysel_ctx() (CVE-2026-53239) 中不准确的 bin 上的释放后使用

在 Linux 内核中,以下漏洞已修复:

net/802/mrp:修复 mrp_pdu_parse_vecattr (CVE-2026-53245) 中的矢量属性解析

在 Linux 内核中,以下漏洞已修复:

sctp:验证 COOKIE_ECHO 处理中缓存的对等机 INIT 区块长度 (CVE-2026-53246)

在 Linux 内核中,以下漏洞已修复:

ipv4:限制IPOPT_SSRR和IPOPT_LSRR选项 (CVE-2026-53249)

在 Linux 内核中,以下漏洞已修复:

xsk:缓存 csum_start/csum_offset 以修复 xsk_skb_metadata() (CVE-2026-53250) 中的 TOCTOU

在 Linux 内核中,以下漏洞已修复:

ipv6:任播:将 ACA 插入 idev->lock (CVE-2026-53259) 下的全局哈希

在 Linux 内核中,以下漏洞已修复:

devlink:释放 devlink free (CVE-2026-53261) 上的嵌套关系

在 Linux 内核中,以下漏洞已修复:

net/sched:act_api:将 RCU 与操作生命周期 (CVE-2026-53264) 的延迟释放一起使用

在 Linux 内核中,以下漏洞已修复:

dm 缓存策略 smq:检查无效锁定 (CVE-2026-53265) 下的分配

在 Linux 内核中,以下漏洞已修复:

netfilter:bridge:使 ebt_snat ARP 重写可写 (CVE-2026-53266)

在 Linux 内核中,以下漏洞已修复:

netfilter:nft_ct:退出 get eval (CVE-2026-53267) 中的模板 ct

在 Linux 内核中,以下漏洞已修复:

netfilter:conntrack_irc:修复可能的越界读取 (CVE-2026-53268)

在 Linux 内核中,以下漏洞已修复:

netfilter:synproxy:添加互斥体以保护挂钩引用计数 (CVE-2026-53269)

在 Linux 内核中,以下漏洞已修复:

ipvs:编辑时提前清除 svc 计划程序 ptr (CVE-2026-53270)

在 Linux 内核中,以下漏洞已修复:

erofs:修复 sbi->sync_decompress 中的释放后使用 (CVE-2026-53272)

在 Linux 内核中,以下漏洞已修复:

ipv6:mcast:修复处理 MLD 查询时的释放后使用 (CVE-2026-53275)

在 Linux 内核中,以下漏洞已修复:

sched_ext:不就 scx_cgroup_move_task() 中的空cgrp_moving_from发出警告 (CVE-2026-53328)

在 Linux 内核中,以下漏洞已修复:

mm/mincore:在 !CONFIG_SWAP guard (CVE-2026-53333) 之前处理 non-swap 条目

在 Linux 内核中,以下漏洞已修复:

mm/damon/reclaim:处理 ctx 分配失败 (CVE-2026-53334)

在 Linux 内核中,以下漏洞已修复:

mm/damon/lru_sort:处理 ctx 分配失败 (CVE-2026-53335)

在 Linux 内核中,以下漏洞已修复:

net:bonding:修复 bond_do_ioctl() 中的空指针取消引用

在 bond_do_ioctl() 中,slave_dev 是通过 __dev_get_by_name() 获取的,如果请求的接口名称不存在,该 () 可返回 NULL。但是,随后的 slave_dbg() 调用会在 NULL 检查之前进行:

slave_dev = __dev_get_by_name(net, ifr->ifr_slave);slave_dbg(bond_dev, slave_dev, slave_dev=%p:\n, slave_dev); //hereif (!slave_dev)return -ENODEV;

slave_dbg() 宏扩展为 netdev_dbg(bond_dev, (slave %s): fmt,(slave_dev)->name, ...),这会在执行空检查之前无条件取消引用 slave_dev->name。这会导致当用户调用具有不存在的从属接口名称的绑定 ioctl(如 SIOCBONDENSLAVE、SIOCBONDRELEASE 等)时,发生空指针取消引用内核 oops。

可通过绑定 ioctl 接口withCAP_NET_ADMIN功能从用户空间访问此问题,使其成为潜在的本地拒绝服务矢量。

通过在 NULL 检查之后移动 slave_dbg() 调用修复。(CVE-2026-53337)

在 Linux 内核中,以下漏洞已修复:

fhandle:修复 may_decode_fh() (CVE-2026-53341) 中未锁定的 ->mnt_ns 读取造成的 UAF

在 Linux 内核中,以下漏洞已修复:

arm64:mm:当释放热删除的页表时调用页表 dtor (CVE-2026-53342)

在 Linux 内核中,以下漏洞已修复:

KVM:当 VM 消亡时,如果内存在无 vCPU 的情况下被污染,则不发出警告 (CVE-2026-53345)

在 Linux 内核中,以下漏洞已修复:

drm/virtio:修复禁用 KMS 时删除驱动程序的问题 (CVE-2026-53347)

在 Linux 内核中,以下漏洞已修复:

netfilter:nf_conntrack:破坏注销时过时的 expectfn 预期

NAT 帮助程序,如 nf_nat_h323存储指向模块文本 inexp->expectfn 的原始指针(例如
ip_nat_q931_expect)。nf_ct_helper_expectfn_unregister()仅取消回调描述符的链接并且从不遍历期望表,因此删除模块时待定的期望会随着悬摆的 exp->expectfn 留存到释放的模块文本中。

当预期的连接到达时,init_conntrack() 会调用 exp->expectfn(),现在是进入卸载模块的过时指针。通过加载 H.323 帮助程序、创建 Q.931expectation、卸载 nf_nat_h323,然后连接到预期端口来重现 KASAN 版本:

Oops: int3: 0000 [#1] SMP KASAN NOPTIRIP: 0010:0xffffffffa06102d1init_conntrack.isra.0 (net/netfilter/nf_conntrack_core.c:1862)nf_conntrack_in (net/netfilter/nf_conntrack_core.c:2049)ipv4_conntrack_local (net/netfilter/nf_conntrack_proto.c:223)nf_hook_slow (net/netfilter/core.c:619)__ip_local_out (net/ipv4/ip_output.c:120)__tcp_transmit_skb (net/ipv4/tcp_output.c:1715)tcp_connect (net/ipv4/tcp_output.c:4374)tcp_v4_connect (net/ipv4/tcp_ipv4.c:345)__sys_连接 (net/socket.c:2167) 链接的模块:nf_conntrack_h323 [上次卸载:nf_nat_h323]

要达到悬摆状态,需要在初始用户空间中CAP_SYS_MODULE以删除仍具有实时预期的 NAT 帮助程序,因此这是一个健全性补丁;无论如何,保留指向自由文本的期望是错误的。

添加 nf_ct_helper_expectfn_destroy(),它遍历期望表并删除其
->expectfn 匹配被拆散的描述符。在现有 RCU 宽限期过后,从每个 NAT 帮助程序的退出路径调用它,这样就不会有任何期望超过它所指向的代码,并且不会引入 extrasynchronize_rcu()。通过该补丁,同一复制器运行至完成而不发生 Oops。(CVE-2026-53349)

在 Linux 内核中,以下漏洞已修复:

signal:清除 zap_other_threads() 中调用程序的JOBCTL_PENDING_MASK

当多线程进程接收到停止信号(例如 SIGSTOP)时,do_signal_stop() 会在 allthreads 上设置 JOBCTL_STOP_PENDING 和 JOBCTL_STOP_CONSUME,并将 signal->group_stop_count 设置为线程数。如果其中一个线程同时调用 execve()、de_thread() invokeszap_other_threads() 终止所有其他线程。zap_other_threads() 通过将 signal->group_stop_count 重置为 0 中止待定的群组停止,并为所有其他线程清除JOBCTL_PENDING_MASK。但是,无法清除调用线程的作业控制标记。

execve() 完成后,调用线程返回用户模式并检查待定信号。看到过时的 JOBCTL_STOP_PENDING 标记,它会调用 do_signal_stop(),从而调用 task_participate_group_stop()。由于 JOBCTL_STOP_CONSUME 仍处于设置状态,它会尝试递减已经为零的信号>group_stop_count,从而触发警告:

sig->group_stop_count == 0WARNING: CPU: 1 PID: 6475 at kernel/signal.c:373task_participate_group_stop+0x215/0x2d0Call Trace:<TASK>do_signal_stop+0x3be/0x5c0 kernel/signal.c:2619get_signal+0xa8c/0x1330 kernel/signal.c:2884arch_do_signal_or_restart+0xbc/0x840 arch/x86/kernel/signal.c:337exit_to_user_mode_loop+0x8c/0x4d0 kernel/entry/common.c:98do_syscall_64+0x33e/0xf80 arch/x86/entry/syscall_64.c:100entry_SYSCALL_64_after_hwframe+0x77/0x7f</TASK>

通过清除 zap_other_threads() 中调用线程的JOBCTL_PENDING_MASK修复此争用条件,确保其在销毁线程组之后不保留任何过时的作业控制状态。这与其他去除线程组并中止群组停止的函数保持一致,如 zap_process() 和 complete_signal(),这些函数会为包括当前线程在内的所有线程正确清除这些标记。
(CVE-2026-53352)

在 Linux 内核中,以下漏洞已修复:

arm64:勘误表:缓解各种 Arm CPU 上的 TLBI 勘误表

Arm 开发的多个 CPU 受到勘误表的影响,由此,broadcastTLBI;DSB 序列可能会在全局观察由受影响的 TLB 条目转换的写入之前完成。

这些勘误表仅影响已由已失效的 TLB 条目转换的内存访问的完成,这些勘误表不会影响 TLB 条目的实际失效。TLB 条目删除正确。

此问题已分配 CVE ID CVE-2025-10263。

为了缓解此问题,Arm 建议软件通过额外的 TLBI;DSB 遵循任何受影响的 TLBI;DSB 序列,这将确保全局观察到受到第一个 TLBI 影响的所有内存写入效果。附加 TLBI 可以使用广播到受影响 CPU 的任何操作,附加 DSB 可以使用任何足以完成附加 TLBI 的选项。

ARM64_WORKAROUND_REPEAT_TLBI的变通方案足以缓解问题。对受影响的 CPU 启用此变通方案,并相应更新芯片勘误表文档。

请注意,由于 Arm 开发 IP 和跟踪 errata 的方式,一些 CPU 共享一个通用的 erratum 编号。(CVE-2026-53354)

在 Linux 内核中,以下漏洞已修复:

drm/i915/gem:修复具有偏移 (CVE-2026-53356) 的 phys BO pread/pwrite

在 Linux 内核中,以下漏洞已修复:

mptcp:计算 rcv_wnd 时关闭 TOCTOU 争用 (CVE-2026-63867)

在 Linux 内核中,以下漏洞已修复:

net:garp:修复 garp_pdu_parse_attr 中无符号的整数下溢

接收端 GARP 属性解析器计算具有反向多数的 dlen:

dlen = sizeof(*ga) - ga->len;

ga->len 是在线属性长度,包含 GARP 属性标头。对于具有数据的普通属性,ga->len 大于sizeof(*ga),因此无符号算术中的减法下溢。

结果值稍后传递给 garp_attr_lookup(),其长度参数为 u8。截断后,解析的数据长度通常不再与为本地注册的属性存储的长度匹配,因此会忽略接收到的加入/退出事件。这会中断通用属性(如 GVRP VLAN 注册属性)的 GARP 接收路径。

计算数据长度为属性长度减去标头长度。(CVE-2026-63868)

Tenable 已直接从测试产品的安全公告中提取上述描述块。

请注意,Nessus 尚未测试这些问题,而是只依据应用程序自我报告的版本号进行判断。

解决方案

运行“dnf update kernel6.18 --releasever 2023.12.20260706”或“dnf update --advisory ALAS2023-2026-1925 --releasever 2023.12.20260706”以更新系统。

另见

https://alas.aws.amazon.com//AL2023/ALAS2023-2026-1925.html

https://alas.aws.amazon.com/faqs.html

https://explore.alas.aws.amazon.com/CVE-2026-45850.html

https://explore.alas.aws.amazon.com/CVE-2026-46054.html

https://explore.alas.aws.amazon.com/CVE-2026-46320.html

https://explore.alas.aws.amazon.com/CVE-2026-46331.html

https://explore.alas.aws.amazon.com/CVE-2026-52908.html

https://explore.alas.aws.amazon.com/CVE-2026-52909.html

https://explore.alas.aws.amazon.com/CVE-2026-52910.html

https://explore.alas.aws.amazon.com/CVE-2026-52924.html

https://explore.alas.aws.amazon.com/CVE-2026-52929.html

https://explore.alas.aws.amazon.com/CVE-2026-52930.html

https://explore.alas.aws.amazon.com/CVE-2026-52940.html

https://explore.alas.aws.amazon.com/CVE-2026-52942.html

https://explore.alas.aws.amazon.com/CVE-2026-52946.html

https://explore.alas.aws.amazon.com/CVE-2026-53131.html

https://explore.alas.aws.amazon.com/CVE-2026-53132.html

https://explore.alas.aws.amazon.com/CVE-2026-53133.html

https://explore.alas.aws.amazon.com/CVE-2026-53134.html

https://explore.alas.aws.amazon.com/CVE-2026-53145.html

https://explore.alas.aws.amazon.com/CVE-2026-53153.html

https://explore.alas.aws.amazon.com/CVE-2026-53154.html

https://explore.alas.aws.amazon.com/CVE-2026-53156.html

https://explore.alas.aws.amazon.com/CVE-2026-53162.html

https://explore.alas.aws.amazon.com/CVE-2026-53163.html

https://explore.alas.aws.amazon.com/CVE-2026-53164.html

https://explore.alas.aws.amazon.com/CVE-2026-53167.html

https://explore.alas.aws.amazon.com/CVE-2026-53168.html

https://explore.alas.aws.amazon.com/CVE-2026-53175.html

https://explore.alas.aws.amazon.com/CVE-2026-53180.html

https://explore.alas.aws.amazon.com/CVE-2026-53183.html

https://explore.alas.aws.amazon.com/CVE-2026-53184.html

https://explore.alas.aws.amazon.com/CVE-2026-53187.html

https://explore.alas.aws.amazon.com/CVE-2026-53188.html

https://explore.alas.aws.amazon.com/CVE-2026-53189.html

https://explore.alas.aws.amazon.com/CVE-2026-53190.html

https://explore.alas.aws.amazon.com/CVE-2026-53191.html

https://explore.alas.aws.amazon.com/CVE-2026-53207.html

https://explore.alas.aws.amazon.com/CVE-2026-53212.html

https://explore.alas.aws.amazon.com/CVE-2026-53214.html

https://explore.alas.aws.amazon.com/CVE-2026-53218.html

https://explore.alas.aws.amazon.com/CVE-2026-53220.html

https://explore.alas.aws.amazon.com/CVE-2026-53221.html

https://explore.alas.aws.amazon.com/CVE-2026-53223.html

https://explore.alas.aws.amazon.com/CVE-2026-53224.html

https://explore.alas.aws.amazon.com/CVE-2026-53225.html

https://explore.alas.aws.amazon.com/CVE-2026-53227.html

https://explore.alas.aws.amazon.com/CVE-2026-53228.html

https://explore.alas.aws.amazon.com/CVE-2026-53229.html

https://explore.alas.aws.amazon.com/CVE-2026-53230.html

https://explore.alas.aws.amazon.com/CVE-2026-53232.html

https://explore.alas.aws.amazon.com/CVE-2026-53233.html

https://explore.alas.aws.amazon.com/CVE-2026-53235.html

https://explore.alas.aws.amazon.com/CVE-2026-53236.html

https://explore.alas.aws.amazon.com/CVE-2026-53238.html

https://explore.alas.aws.amazon.com/CVE-2026-53239.html

https://explore.alas.aws.amazon.com/CVE-2026-53245.html

https://explore.alas.aws.amazon.com/CVE-2026-53246.html

https://explore.alas.aws.amazon.com/CVE-2026-53249.html

https://explore.alas.aws.amazon.com/CVE-2026-53250.html

https://explore.alas.aws.amazon.com/CVE-2026-53259.html

https://explore.alas.aws.amazon.com/CVE-2026-53261.html

https://explore.alas.aws.amazon.com/CVE-2026-53264.html

https://explore.alas.aws.amazon.com/CVE-2026-53265.html

https://explore.alas.aws.amazon.com/CVE-2026-53266.html

https://explore.alas.aws.amazon.com/CVE-2026-53267.html

https://explore.alas.aws.amazon.com/CVE-2026-53268.html

https://explore.alas.aws.amazon.com/CVE-2026-53269.html

https://explore.alas.aws.amazon.com/CVE-2026-53270.html

https://explore.alas.aws.amazon.com/CVE-2026-53272.html

https://explore.alas.aws.amazon.com/CVE-2026-53275.html

https://explore.alas.aws.amazon.com/CVE-2026-53328.html

https://explore.alas.aws.amazon.com/CVE-2026-53333.html

https://explore.alas.aws.amazon.com/CVE-2026-53334.html

https://explore.alas.aws.amazon.com/CVE-2026-53335.html

https://explore.alas.aws.amazon.com/CVE-2026-53337.html

https://explore.alas.aws.amazon.com/CVE-2026-53341.html

https://explore.alas.aws.amazon.com/CVE-2026-53342.html

https://explore.alas.aws.amazon.com/CVE-2026-53345.html

https://explore.alas.aws.amazon.com/CVE-2026-53347.html

https://explore.alas.aws.amazon.com/CVE-2026-53349.html

https://explore.alas.aws.amazon.com/CVE-2026-53352.html

https://explore.alas.aws.amazon.com/CVE-2026-53354.html

https://explore.alas.aws.amazon.com/CVE-2026-53356.html

https://explore.alas.aws.amazon.com/CVE-2026-63867.html

https://explore.alas.aws.amazon.com/CVE-2026-63868.html

插件详情

严重性: High

ID: 327383

文件名: al2023_ALAS2023-2026-1925.nasl

版本: 1.3

类型: Local

代理: unix

发布时间: 2026/7/16

最近更新时间: 2026/7/31

支持的传感器: Frictionless Assessment AWS, Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Continuous Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

风险信息

VPR

风险因素: High

分数: 7.9

百分位: 99.36

CVSS v2

风险因素: Medium

基本分数: 6.8

时间分数: 5.3

矢量: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS 分数来源: CVE-2026-53272

CVSS v3

风险因素: High

基本分数: 7.8

时间分数: 7

矢量: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

时间矢量: CVSS:3.0/E:P/RL:O/RC:C

漏洞信息

CPE: cpe:/o:amazon:linux:2023, p-cpe:/a:amazon:linux:bpftool6.18-debuginfo, p-cpe:/a:amazon:linux:bpftool6.18, p-cpe:/a:amazon:linux:kernel-livepatch-6.18.36-69.134, p-cpe:/a:amazon:linux:kernel6.18-debuginfo-common-aarch64, p-cpe:/a:amazon:linux:kernel6.18-debuginfo-common-x86_64, p-cpe:/a:amazon:linux:kernel6.18-debuginfo, p-cpe:/a:amazon:linux:kernel6.18-devel, p-cpe:/a:amazon:linux:kernel6.18-headers, p-cpe:/a:amazon:linux:kernel6.18-modules-extra-common, p-cpe:/a:amazon:linux:kernel6.18-modules-extra, p-cpe:/a:amazon:linux:kernel6.18-tools-debuginfo, p-cpe:/a:amazon:linux:kernel6.18-tools-devel, p-cpe:/a:amazon:linux:kernel6.18-tools, p-cpe:/a:amazon:linux:kernel6.18, p-cpe:/a:amazon:linux:microvm-kernel6.18, p-cpe:/a:amazon:linux:perf6.18-debuginfo, p-cpe:/a:amazon:linux:perf6.18, p-cpe:/a:amazon:linux:python3-perf6.18-debuginfo, p-cpe:/a:amazon:linux:python3-perf6.18

必需的 KB 项: Host/local_checks_enabled, Host/AmazonLinux/release, Host/AmazonLinux/rpm-list

可利用: true

易利用性: Exploits are available

补丁发布日期: 2026/7/7

漏洞发布日期: 2026/5/27

参考资料信息

CVE: CVE-2026-45850, CVE-2026-46054, CVE-2026-46320, CVE-2026-46331, CVE-2026-52908, CVE-2026-52909, CVE-2026-52910, CVE-2026-52924, CVE-2026-52929, CVE-2026-52930, CVE-2026-52940, CVE-2026-52942, CVE-2026-52946, CVE-2026-53131, CVE-2026-53132, CVE-2026-53133, CVE-2026-53134, CVE-2026-53145, CVE-2026-53153, CVE-2026-53154, CVE-2026-53156, CVE-2026-53162, CVE-2026-53163, CVE-2026-53164, CVE-2026-53167, CVE-2026-53168, CVE-2026-53175, CVE-2026-53180, CVE-2026-53183, CVE-2026-53184, CVE-2026-53187, CVE-2026-53188, CVE-2026-53189, CVE-2026-53190, CVE-2026-53191, CVE-2026-53207, CVE-2026-53212, CVE-2026-53214, CVE-2026-53218, CVE-2026-53220, CVE-2026-53221, CVE-2026-53223, CVE-2026-53224, CVE-2026-53225, CVE-2026-53227, CVE-2026-53228, CVE-2026-53229, CVE-2026-53230, CVE-2026-53232, CVE-2026-53233, CVE-2026-53235, CVE-2026-53236, CVE-2026-53238, CVE-2026-53239, CVE-2026-53245, CVE-2026-53246, CVE-2026-53249, CVE-2026-53250, CVE-2026-53259, CVE-2026-53261, CVE-2026-53264, CVE-2026-53265, CVE-2026-53266, CVE-2026-53267, CVE-2026-53268, CVE-2026-53269, CVE-2026-53270, CVE-2026-53272, CVE-2026-53275, CVE-2026-53328, CVE-2026-53333, CVE-2026-53334, CVE-2026-53335, CVE-2026-53337, CVE-2026-53341, CVE-2026-53342, CVE-2026-53345, CVE-2026-53347, CVE-2026-53349, CVE-2026-53352, CVE-2026-53354, CVE-2026-53356, CVE-2026-63867, CVE-2026-63868