Amazon Linux 2023:bpftool6.12、kernel6.12、kernel6.12-devel (ALAS2023-2026-1968)

high Nessus 插件 ID 328493

简介

远程 Amazon Linux 2023 主机缺少安全更新。

描述

因此,该软件受到 ALAS2023-2026-1968 公告中提及的多个漏洞影响。

在 Linux 内核中,以下漏洞已修复:

mm/page_alloc:清除 free_pages_prepare() 中的 page->private (CVE-2026-43303)

在 Linux 内核中,以下漏洞已修复:

ipvs:跳过 csum 检查的 ipv6 扩展标头 (CVE-2026-45850)

在 Linux 内核中,以下漏洞已修复:

selinux:修复 overlayfs mmap() 和 mprotect() 访问检查 (CVE-2026-46054)

在 Linux 内核中,以下漏洞已修复:

eventpoll:修复ep_remove结构 eventpoll/结构文件 UAF (CVE-2026-46242)

在 Linux 内核中,以下漏洞已修复:

tap:释放 tap_get_user_xdp() 中的错误路径上的页面 (CVE-2026-46320)

在 Linux 内核中,以下漏洞已修复:

tun:tun_xdp_one() (CVE-2026-46321) 中的短框架拒绝的释放页

在 Linux 内核中,以下漏洞已修复:

tun:tun_xdp_one() (CVE-2026-46322) 中build_skb失败的释放页面

在 Linux 内核中,以下漏洞已修复:

net/sched:修复导致页面缓存损坏的 pedit 部分 COW (CVE-2026-46331)

在 Linux 内核中,以下漏洞已修复:

RDMA:在rereg_mr期间确保 REREG_ACCESS 兼容 (CVE-2026-52908)

在 Linux 内核中,以下漏洞已修复:

bpf:在 RCU 宽限期后释放 reuseport cBPF prog。(CVE-2026-52910)

在 Linux 内核中,以下漏洞已修复:

ipc:将next_id分配限制为有效 ID 范围 (CVE-2026-52923)

在 Linux 内核中,以下漏洞已修复:

sctp:清除过时的 COOKIE-ECHO 处理中的出队列 (CVE-2026-52924)

在 Linux 内核中,以下漏洞已修复:

netfilter:ebtables:修复 compat_mtw_from_user 中的 OOB 读取 (CVE-2026-52927)

在 Linux 内核中,以下漏洞已修复:

sctp:stream:完全回滚回拒绝的 add-stream 状态 (CVE-2026-52929)

在 Linux 内核中,以下漏洞已修复:

ipc/shm:通过shm_nattch更新序列化孤立清除 (CVE-2026-52930)

在 Linux 内核中,以下漏洞已修复:

netfilter:nf_log:在转储前验证已设置 MAC 标头 (CVE-2026-52942)

在 Linux 内核中,以下漏洞已修复:

net:skbuff:修复 pskb_carve 帮助程序 (CVE-2026-52943) 中缺少的 zerocopy 引用

在 Linux 内核中,以下漏洞已修复:

fs/fcntl:修复 fasync 信号 (CVE-2026-52946) 中的 SOFTIRQ-unsafe 锁定顺序

在 Linux 内核中,以下漏洞已修复:

netfilter:使用 eth_hdr() (CVE-2026-53131) 之前需要以太网 MAC 标头

在 Linux 内核中,以下漏洞已修复:

vsock/virtio:修复潜在的不受限制的 skb 队列 (CVE-2026-53132)

在 Linux 内核中,以下漏洞已修复:

RDMA/umem:修复区块大小的截断 >= 4G (CVE-2026-53133)

在 Linux 内核中,以下漏洞已修复:

netfilter:nft_fib:修复通过 OIFNAME 寄存器 (CVE-2026-53134) 产生的过时堆栈泄漏

在 Linux 内核中,以下漏洞已修复:

mm/hugetlb:当 hugetlb 作品集复制路径 (CVE-2026-53154) 中出错时恢复保留

在 Linux 内核中,以下漏洞已修复:

nvmem:core:修复错误路径中的释放后使用缺陷 (CVE-2026-53156)

在 Linux 内核中,以下漏洞已修复:

fuse:拒绝 fuse_notify() 目录上的 pagecache ops (CVE-2026-53168)

在 Linux 内核中,以下漏洞已修复:

timers/migration:修复 tmigr_handle_remote_up() (CVE-2026-53180) 中的活锁

在 Linux 内核中,以下漏洞已修复:

mptcp:允许子流 rcv wnd 缩小 (CVE-2026-53183)

在 Linux 内核中,以下漏洞已修复:

udp:运行 sockmap 判定 (CVE-2026-53184) 之前清除 skb->dev

在 Linux 内核中,以下漏洞已修复:

mm/huge_memory:在 folio_put() () 之前CVE-2026-53189更新文件 PMD 计数器

在 Linux 内核中,以下漏洞已修复:

drm/virtio:修复 virtio_gpu_dma_fence_wait() (CVE-2026-53190) 中发生错误时dma_fence refcount 泄漏

在 Linux 内核中,以下漏洞已修复:

io_uring/net:跨捆绑 recv 重试 (CVE-2026-53191) 继承IORING_CQE_F_BUF_MORE

在 Linux 内核中,以下漏洞已修复:

hv_netvsc:在 netvsc_copy_to_send_buf 中使用 kmap_local_page (CVE-2026-53199)

在 Linux 内核中,以下漏洞已修复:

mm/memory-failure:修复 get_huge_page_for_hwpoison (CVE-2026-53207) 中的 hugetlb_lock AA 死锁

在 Linux 内核中,以下漏洞已修复:

netfilter:nft_tunnel:修复对象破坏时的释放后使用 (CVE-2026-53212)

在 Linux 内核中,以下漏洞已修复:

ipv6:修复 cleanup_prefix_route() 中的潜在 NPD

addrconf_get_prefix_route() 可返回具有空fib6_table指针的 fib6_null_entry sentinelentry。因此,在设置路由的到期时间之前,请检查我们是否没有使用此条目,否则将触发 NPD [1]。

请注意,addrconf_get_prefix_route() 的其他调用程序不易受到此缺陷的影响:

1. addrconf_prefix_rcv():请求包含“RTF_ADDRCONF |RTF_PREFIX_RT“标记,这些标记未在fib6_null_entry上设置。

2. modify_prefix_route():通过提交 a747e02430df 修复(ipv6:避免 modify_prefix_route() 中可能的空取消引用)。

3. __ipv6_ifa_notify():调用 ip6_del_rt(),专门检查forfib6_null_entry并返回错误。

[1]哎呀:一般保护错误,可能针对非规范地址 0xdffffc0000000006:0000 [#1] SMP KASANKASAN:范围内的 null-ptr-deref [0x0000000000000030-0x0000000000000037][...]调用 Trace:<TASK>__kasan_check_byte (mm/kasan/common.c:573)lock_acquire.part.0 (kernel/locking/lockdep.c:5842 (discriminator 1))_raw_spin_lock_bh (kernel/locking/spinlock.c:182 (discriminator 1))cleanup_prefix_route (net/ipv6/addrconf.c:1280)ipv6_del_addr (net/ipv6/addrconf.c:1342)inet6_addr_del.isra.0 (net/ipv6/addrconf.c:3119)inet6_rtm_deladdr (net/ipv6/addrconf.c:4812)rtnetlink_rcv_msg (net/core/rtnetlink.c:6997)netlink_rcv_skb (net/netlink/af_netlink.c:2555)netlink_unicast (net/netlink/af_netlink.c:1344)netlink_sendmsg (net/netlink/af_netlink.c:1899)__sock_sendmsg (net/socket.c:802 (discriminator 4))____sys_sendmsg (net/socket.c:2698)___sys_sendmsg (net/socket.c:2752)__sys_sendmsg (net/socket.c:2784)do_syscall_64 (arch/x86/entry/syscall_64.c:63 arch/x86/entry/syscall_64.c:94)entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121) (CVE-2026-53214)

在 Linux 内核中,以下漏洞已修复:

netfilter:nft_exthdr:修复 F_PRESENT 标记 (CVE-2026-53218) 的寄存器跟踪

在 Linux 内核中,以下漏洞已修复:

netfilter:x_tables:避免泄漏 percpu 计数器指针 (CVE-2026-53219)

在 Linux 内核中,以下漏洞已修复:

netfilter:重新验证桥接端口 (CVE-2026-53220)

在 Linux 内核中,以下漏洞已修复:

ip6_vti:修复 vti6_tnl_lookup() (CVE-2026-53221) 中不正确的隧道匹配

在 Linux 内核中,以下漏洞已修复:

net:保护时间戳 cmsgs 以实现真正的错误队列 skbs (CVE-2026-53223)

在 Linux 内核中,以下漏洞已修复:

sctp:修复 __sctp_rcv_asconf_lookup() 中的 uninit-value (CVE-2026-53225)

在 Linux 内核中,以下漏洞已修复:

net:openvswitch:修复可能的 ERR_PTR kfree_skb (CVE-2026-53227)

在 Linux 内核中,以下漏洞已修复:

ipv6:sit:GSO 卸载后重新加载内部 IPv6 标头 (CVE-2026-53228)

在 Linux 内核中,以下漏洞已修复:

net/mlx5e:xsk:修复 XDP_TX xmit 失败 (CVE-2026-53229) 时的 DMA 和xdp_frame泄漏

在 Linux 内核中,以下漏洞已修复:

net/mlx5:修复 mlx5_query_nic_vport_mac_list 中的 slab-out-of-bound (CVE-2026-53230)

在 Linux 内核中,以下漏洞已修复:

net:phy:如果 phy 探测失败,则清除 sfp 上游 (CVE-2026-53232)

在 Linux 内核中,以下漏洞已修复:

netdev:修复 netdev_nl_bind_rx_doit() 中的双重释放 (CVE-2026-53233)

在 Linux 内核中,以下漏洞已修复:

net:将 pskb_may_pull() 添加到 skb_gro_receive_list() (CVE-2026-53235)

在 Linux 内核中,以下漏洞已修复:

tcp:将SO_ATTACH_FILTER限制为 priv 用户 (CVE-2026-53236)

在 Linux 内核中,以下漏洞已修复:

netlabel:验证未标记的地址和掩码属性长度 (CVE-2026-53238)

在 Linux 内核中,以下漏洞已修复:

xfrm:policy:修复 xfrm_policy_bysel_ctx() (CVE-2026-53239) 中不准确的 bin 上的释放后使用

在 Linux 内核中,以下漏洞已修复:

net/802/mrp:修复 mrp_pdu_parse_vecattr (CVE-2026-53245) 中的矢量属性解析

在 Linux 内核中,以下漏洞已修复:

ipv4:限制IPOPT_SSRR和IPOPT_LSRR选项 (CVE-2026-53249)

在 Linux 内核中,以下漏洞已修复:

devlink:释放 devlink free (CVE-2026-53261) 上的嵌套关系

在 Linux 内核中,以下漏洞已修复:

net/sched:act_api:将 RCU 与操作生命周期 (CVE-2026-53264) 的延迟释放一起使用

在 Linux 内核中,以下漏洞已修复:

netfilter:bridge:使 ebt_snat ARP 重写可写 (CVE-2026-53266)

在 Linux 内核中,以下漏洞已修复:

netfilter:nft_ct:退出 get eval (CVE-2026-53267) 中的模板 ct

在 Linux 内核中,以下漏洞已修复:

netfilter:conntrack_irc:修复可能的越界读取 (CVE-2026-53268)

在 Linux 内核中,以下漏洞已修复:

netfilter:synproxy:添加互斥体以保护挂钩引用计数 (CVE-2026-53269)

在 Linux 内核中,以下漏洞已修复:

ipvs:编辑时提前清除 svc 计划程序 ptr (CVE-2026-53270)

在 Linux 内核中,以下漏洞已修复:

erofs:修复 sbi->sync_decompress 中的释放后使用 (CVE-2026-53272)

在 Linux 内核中,以下漏洞已修复:

ipv6:mcast:修复处理 MLD 查询时的释放后使用 (CVE-2026-53275)

在 Linux 内核中,以下漏洞已修复:

sched_ext:不就 scx_cgroup_move_task() 中的空cgrp_moving_from发出警告 (CVE-2026-53328)

在 Linux 内核中,以下漏洞已修复:

net:bonding:修复 bond_do_ioctl() 中的空指针取消引用

在 bond_do_ioctl() 中,slave_dev 是通过 __dev_get_by_name() 获取的,如果请求的接口名称不存在,该 () 可返回 NULL。但是,随后的 slave_dbg() 调用会在 NULL 检查之前进行:

slave_dev = __dev_get_by_name(net, ifr->ifr_slave);slave_dbg(bond_dev, slave_dev, slave_dev=%p:\n, slave_dev); //hereif (!slave_dev)return -ENODEV;

slave_dbg() 宏扩展为 netdev_dbg(bond_dev, (slave %s): fmt,(slave_dev)->name, ...),这会在执行空检查之前无条件取消引用 slave_dev->name。这会导致当用户调用具有不存在的从属接口名称的绑定 ioctl(如 SIOCBONDENSLAVE、SIOCBONDRELEASE 等)时,发生空指针取消引用内核 oops。

可通过绑定 ioctl 接口withCAP_NET_ADMIN功能从用户空间访问此问题,使其成为潜在的本地拒绝服务矢量。

通过在 NULL 检查之后移动 slave_dbg() 调用修复。(CVE-2026-53337)

在 Linux 内核中,以下漏洞已修复:

KVM:当 VM 消亡时,如果内存在无 vCPU 的情况下被污染,则不发出警告 (CVE-2026-53345)

在 Linux 内核中,以下漏洞已修复:

drm/virtio:修复禁用 KMS 时删除驱动程序的问题 (CVE-2026-53347)

在 Linux 内核中,以下漏洞已修复:

netfilter:nf_conntrack:破坏注销时过时的 expectfn 预期

NAT 帮助程序,如 nf_nat_h323存储指向模块文本 inexp->expectfn 的原始指针(例如
ip_nat_q931_expect)。nf_ct_helper_expectfn_unregister()仅取消回调描述符的链接并且从不遍历期望表,因此删除模块时待定的期望会随着悬摆的 exp->expectfn 留存到释放的模块文本中。

当预期的连接到达时,init_conntrack() 会调用 exp->expectfn(),现在是进入卸载模块的过时指针。通过加载 H.323 帮助程序、创建 Q.931expectation、卸载 nf_nat_h323,然后连接到预期端口来重现 KASAN 版本:

Oops: int3: 0000 [#1] SMP KASAN NOPTIRIP: 0010:0xffffffffa06102d1init_conntrack.isra.0 (net/netfilter/nf_conntrack_core.c:1862)nf_conntrack_in (net/netfilter/nf_conntrack_core.c:2049)ipv4_conntrack_local (net/netfilter/nf_conntrack_proto.c:223)nf_hook_slow (net/netfilter/core.c:619)__ip_local_out (net/ipv4/ip_output.c:120)__tcp_transmit_skb (net/ipv4/tcp_output.c:1715)tcp_connect (net/ipv4/tcp_output.c:4374)tcp_v4_connect (net/ipv4/tcp_ipv4.c:345)__sys_连接 (net/socket.c:2167) 链接的模块:nf_conntrack_h323 [上次卸载:nf_nat_h323]

要达到悬摆状态,需要在初始用户空间中CAP_SYS_MODULE以删除仍具有实时预期的 NAT 帮助程序,因此这是一个健全性补丁;无论如何,保留指向自由文本的期望是错误的。

添加 nf_ct_helper_expectfn_destroy(),它遍历期望表并删除其
->expectfn 匹配被拆散的描述符。在现有 RCU 宽限期过后,从每个 NAT 帮助程序的退出路径调用它,这样就不会有任何期望超过它所指向的代码,并且不会引入 extrasynchronize_rcu()。通过该补丁,同一复制器运行至完成而不发生 Oops。(CVE-2026-53349)

在 Linux 内核中,以下漏洞已修复:

signal:清除 zap_other_threads() 中调用程序的JOBCTL_PENDING_MASK

当多线程进程接收到停止信号(例如 SIGSTOP)时,do_signal_stop() 会在 allthreads 上设置 JOBCTL_STOP_PENDING 和 JOBCTL_STOP_CONSUME,并将 signal->group_stop_count 设置为线程数。如果其中一个线程同时调用 execve()、de_thread() invokeszap_other_threads() 终止所有其他线程。zap_other_threads() 通过将 signal->group_stop_count 重置为 0 中止待定的群组停止,并为所有其他线程清除JOBCTL_PENDING_MASK。但是,无法清除调用线程的作业控制标记。

execve() 完成后,调用线程返回用户模式并检查待定信号。看到过时的 JOBCTL_STOP_PENDING 标记,它会调用 do_signal_stop(),从而调用 task_participate_group_stop()。由于 JOBCTL_STOP_CONSUME 仍处于设置状态,它会尝试递减已经为零的信号>group_stop_count,从而触发警告:

sig->group_stop_count == 0WARNING: CPU: 1 PID: 6475 at kernel/signal.c:373task_participate_group_stop+0x215/0x2d0Call Trace:<TASK>do_signal_stop+0x3be/0x5c0 kernel/signal.c:2619get_signal+0xa8c/0x1330 kernel/signal.c:2884arch_do_signal_or_restart+0xbc/0x840 arch/x86/kernel/signal.c:337exit_to_user_mode_loop+0x8c/0x4d0 kernel/entry/common.c:98do_syscall_64+0x33e/0xf80 arch/x86/entry/syscall_64.c:100entry_SYSCALL_64_after_hwframe+0x77/0x7f</TASK>

通过清除 zap_other_threads() 中调用线程的JOBCTL_PENDING_MASK修复此争用条件,确保其在销毁线程组之后不保留任何过时的作业控制状态。这与其他去除线程组并中止群组停止的函数保持一致,如 zap_process() 和 complete_signal(),这些函数会为包括当前线程在内的所有线程正确清除这些标记。
(CVE-2026-53352)

在 Linux 内核中,以下漏洞已修复:

arm64:勘误表:缓解各种 Arm CPU 上的 TLBI 勘误表

Arm 开发的多个 CPU 受到勘误表的影响,由此,broadcastTLBI;DSB 序列可能会在全局观察由受影响的 TLB 条目转换的写入之前完成。

这些勘误表仅影响已由已失效的 TLB 条目转换的内存访问的完成,这些勘误表不会影响 TLB 条目的实际失效。TLB 条目删除正确。

此问题已分配 CVE ID CVE-2025-10263。

为了缓解此问题,Arm 建议软件通过额外的 TLBI;DSB 遵循任何受影响的 TLBI;DSB 序列,这将确保全局观察到受到第一个 TLBI 影响的所有内存写入效果。附加 TLBI 可以使用广播到受影响 CPU 的任何操作,附加 DSB 可以使用任何足以完成附加 TLBI 的选项。

ARM64_WORKAROUND_REPEAT_TLBI的变通方案足以缓解问题。对受影响的 CPU 启用此变通方案,并相应更新芯片勘误表文档。

请注意,由于 Arm 开发 IP 和跟踪 errata 的方式,一些 CPU 共享一个通用的 erratum 编号。(CVE-2026-53354)

在 Linux 内核中,以下漏洞已修复:

drm/i915/gem:修复具有偏移 (CVE-2026-53356) 的 phys BO pread/pwrite

Tenable 已直接从测试产品的安全公告中提取上述描述块。

请注意,Nessus 尚未测试这些问题,而是只依据应用程序自我报告的版本号进行判断。

解决方案

运行“dnf update kernel6.12 --releasever 2023.12.20260720”或“dnf update --advisory ALAS2023-2026-1968 --releasever 2023.12.20260720”以更新系统。

另见

https://alas.aws.amazon.com//AL2023/ALAS2023-2026-1968.html

https://alas.aws.amazon.com/faqs.html

https://explore.alas.aws.amazon.com/CVE-2026-43303.html

https://explore.alas.aws.amazon.com/CVE-2026-45850.html

https://explore.alas.aws.amazon.com/CVE-2026-46054.html

https://explore.alas.aws.amazon.com/CVE-2026-46242.html

https://explore.alas.aws.amazon.com/CVE-2026-46320.html

https://explore.alas.aws.amazon.com/CVE-2026-46321.html

https://explore.alas.aws.amazon.com/CVE-2026-46322.html

https://explore.alas.aws.amazon.com/CVE-2026-46331.html

https://explore.alas.aws.amazon.com/CVE-2026-52908.html

https://explore.alas.aws.amazon.com/CVE-2026-52910.html

https://explore.alas.aws.amazon.com/CVE-2026-52923.html

https://explore.alas.aws.amazon.com/CVE-2026-52924.html

https://explore.alas.aws.amazon.com/CVE-2026-52927.html

https://explore.alas.aws.amazon.com/CVE-2026-52929.html

https://explore.alas.aws.amazon.com/CVE-2026-52930.html

https://explore.alas.aws.amazon.com/CVE-2026-52942.html

https://explore.alas.aws.amazon.com/CVE-2026-52943.html

https://explore.alas.aws.amazon.com/CVE-2026-52946.html

https://explore.alas.aws.amazon.com/CVE-2026-53131.html

https://explore.alas.aws.amazon.com/CVE-2026-53132.html

https://explore.alas.aws.amazon.com/CVE-2026-53133.html

https://explore.alas.aws.amazon.com/CVE-2026-53134.html

https://explore.alas.aws.amazon.com/CVE-2026-53154.html

https://explore.alas.aws.amazon.com/CVE-2026-53156.html

https://explore.alas.aws.amazon.com/CVE-2026-53168.html

https://explore.alas.aws.amazon.com/CVE-2026-53180.html

https://explore.alas.aws.amazon.com/CVE-2026-53183.html

https://explore.alas.aws.amazon.com/CVE-2026-53184.html

https://explore.alas.aws.amazon.com/CVE-2026-53189.html

https://explore.alas.aws.amazon.com/CVE-2026-53190.html

https://explore.alas.aws.amazon.com/CVE-2026-53191.html

https://explore.alas.aws.amazon.com/CVE-2026-53199.html

https://explore.alas.aws.amazon.com/CVE-2026-53207.html

https://explore.alas.aws.amazon.com/CVE-2026-53212.html

https://explore.alas.aws.amazon.com/CVE-2026-53214.html

https://explore.alas.aws.amazon.com/CVE-2026-53218.html

https://explore.alas.aws.amazon.com/CVE-2026-53219.html

https://explore.alas.aws.amazon.com/CVE-2026-53220.html

https://explore.alas.aws.amazon.com/CVE-2026-53221.html

https://explore.alas.aws.amazon.com/CVE-2026-53223.html

https://explore.alas.aws.amazon.com/CVE-2026-53225.html

https://explore.alas.aws.amazon.com/CVE-2026-53227.html

https://explore.alas.aws.amazon.com/CVE-2026-53228.html

https://explore.alas.aws.amazon.com/CVE-2026-53229.html

https://explore.alas.aws.amazon.com/CVE-2026-53230.html

https://explore.alas.aws.amazon.com/CVE-2026-53232.html

https://explore.alas.aws.amazon.com/CVE-2026-53233.html

https://explore.alas.aws.amazon.com/CVE-2026-53235.html

https://explore.alas.aws.amazon.com/CVE-2026-53236.html

https://explore.alas.aws.amazon.com/CVE-2026-53238.html

https://explore.alas.aws.amazon.com/CVE-2026-53239.html

https://explore.alas.aws.amazon.com/CVE-2026-53245.html

https://explore.alas.aws.amazon.com/CVE-2026-53249.html

https://explore.alas.aws.amazon.com/CVE-2026-53261.html

https://explore.alas.aws.amazon.com/CVE-2026-53264.html

https://explore.alas.aws.amazon.com/CVE-2026-53266.html

https://explore.alas.aws.amazon.com/CVE-2026-53267.html

https://explore.alas.aws.amazon.com/CVE-2026-53268.html

https://explore.alas.aws.amazon.com/CVE-2026-53269.html

https://explore.alas.aws.amazon.com/CVE-2026-53270.html

https://explore.alas.aws.amazon.com/CVE-2026-53272.html

https://explore.alas.aws.amazon.com/CVE-2026-53275.html

https://explore.alas.aws.amazon.com/CVE-2026-53328.html

https://explore.alas.aws.amazon.com/CVE-2026-53337.html

https://explore.alas.aws.amazon.com/CVE-2026-53345.html

https://explore.alas.aws.amazon.com/CVE-2026-53347.html

https://explore.alas.aws.amazon.com/CVE-2026-53349.html

https://explore.alas.aws.amazon.com/CVE-2026-53352.html

https://explore.alas.aws.amazon.com/CVE-2026-53354.html

https://explore.alas.aws.amazon.com/CVE-2026-53356.html

插件详情

严重性: High

ID: 328493

文件名: al2023_ALAS2023-2026-1968.nasl

版本: 1.1

类型: Local

代理: unix

发布时间: 2026/7/20

最近更新时间: 2026/7/20

支持的传感器: Frictionless Assessment AWS, Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Continuous Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

风险信息

VPR

风险因素: High

分数: 8.9

百分位: 99.7

CVSS v2

风险因素: Medium

基本分数: 6.8

时间分数: 5.3

矢量: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS 分数来源: CVE-2026-53272

CVSS v3

风险因素: High

基本分数: 7.8

时间分数: 7

矢量: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

时间矢量: CVSS:3.0/E:P/RL:O/RC:C

漏洞信息

CPE: cpe:/o:amazon:linux:2023, p-cpe:/a:amazon:linux:bpftool6.12-debuginfo, p-cpe:/a:amazon:linux:bpftool6.12, p-cpe:/a:amazon:linux:kernel-livepatch-6.12.94-123.174, p-cpe:/a:amazon:linux:kernel6.12-debuginfo-common-aarch64, p-cpe:/a:amazon:linux:kernel6.12-debuginfo-common-x86_64, p-cpe:/a:amazon:linux:kernel6.12-debuginfo, p-cpe:/a:amazon:linux:kernel6.12-devel, p-cpe:/a:amazon:linux:kernel6.12-headers, p-cpe:/a:amazon:linux:kernel6.12-modules-extra-common, p-cpe:/a:amazon:linux:kernel6.12-modules-extra, p-cpe:/a:amazon:linux:kernel6.12-tools-debuginfo, p-cpe:/a:amazon:linux:kernel6.12-tools-devel, p-cpe:/a:amazon:linux:kernel6.12-tools, p-cpe:/a:amazon:linux:kernel6.12, p-cpe:/a:amazon:linux:perf6.12-debuginfo, p-cpe:/a:amazon:linux:perf6.12, p-cpe:/a:amazon:linux:python3-perf6.12-debuginfo, p-cpe:/a:amazon:linux:python3-perf6.12

必需的 KB 项: Host/local_checks_enabled, Host/AmazonLinux/release, Host/AmazonLinux/rpm-list

可利用: true

易利用性: Exploits are available

补丁发布日期: 2026/7/20

漏洞发布日期: 2026/5/8

参考资料信息

CVE: CVE-2026-43303, CVE-2026-45850, CVE-2026-46054, CVE-2026-46242, CVE-2026-46320, CVE-2026-46321, CVE-2026-46322, CVE-2026-46331, CVE-2026-52908, CVE-2026-52910, CVE-2026-52923, CVE-2026-52924, CVE-2026-52927, CVE-2026-52929, CVE-2026-52930, CVE-2026-52942, CVE-2026-52943, CVE-2026-52946, CVE-2026-53131, CVE-2026-53132, CVE-2026-53133, CVE-2026-53134, CVE-2026-53154, CVE-2026-53156, CVE-2026-53168, CVE-2026-53180, CVE-2026-53183, CVE-2026-53184, CVE-2026-53189, CVE-2026-53190, CVE-2026-53191, CVE-2026-53199, CVE-2026-53207, CVE-2026-53212, CVE-2026-53214, CVE-2026-53218, CVE-2026-53219, CVE-2026-53220, CVE-2026-53221, CVE-2026-53223, CVE-2026-53225, CVE-2026-53227, CVE-2026-53228, CVE-2026-53229, CVE-2026-53230, CVE-2026-53232, CVE-2026-53233, CVE-2026-53235, CVE-2026-53236, CVE-2026-53238, CVE-2026-53239, CVE-2026-53245, CVE-2026-53249, CVE-2026-53261, CVE-2026-53264, CVE-2026-53266, CVE-2026-53267, CVE-2026-53268, CVE-2026-53269, CVE-2026-53270, CVE-2026-53272, CVE-2026-53275, CVE-2026-53328, CVE-2026-53337, CVE-2026-53345, CVE-2026-53347, CVE-2026-53349, CVE-2026-53352, CVE-2026-53354, CVE-2026-53356