Amazon Linux 2:内核,--advisory ALAS2KERNEL-5。10-2026-129 (ALASKERNEL-5.10-2026-129)

medium Nessus 插件 ID 337224

简介

远程 Amazon Linux 2 主机缺少安全更新。

描述

远程主机上安装的内核版本低于 5.10.262-262.1063。因此,会受到 ALAS2KERNEL-5.10-2026-129 公告中提及的多个漏洞影响。

在 Linux 内核中,以下漏洞已修复:

net:终止 skb_may_tx_timestamp() (CVE-2026-43216) 中的锁定

在 Linux 内核中,以下漏洞已修复:

nvmet-tcp:修复 ICReq 处理和队列拆卸 (CVE-2026-46135) 之间的争用

在 Linux 内核中,以下漏洞已修复:

netfilter:nf_log:在转储前验证已设置 MAC 标头 (CVE-2026-52942)

在 Linux 内核中,以下漏洞已修复:

NFSv4/flexfiles:拒绝零文件句柄版本计数 (CVE-2026-53392)

在 Linux 内核中,以下漏洞已修复:

nfsd:针对延迟的回写错误重置写入验证程序 (CVE-2026-53393)

在 Linux 内核中,以下漏洞已修复:

nfsd:在 setlease 失败 (CVE-2026-53399) 时发布布局策略

在 Linux 内核中,以下漏洞已修复:

i2c:core:修复适配器注册争用

使用 i2c_get_adapter() 可根据适配器的 id 查找适配器,该函数会引用嵌入式结构设备。

确保适配器(包括其结构设备)在将其添加到 IDR 之前已初始化,以避免访问未初始化数据,例如,可能导致空指针取消引用或释放后使用。

请注意,从总线通知程序注册的 i2c-dev chardev 当前使用 i2c_get_adapter(),因此在注册前需要将适配器添加到 IDR。(CVE-2026-53400)

在 Linux 内核中,以下漏洞已修复:

fbdev:fbcon:修复 fbcon_do_set_font() err_out中的越界读取

当 fbcon_do_set_font() 发生故障时(例如,由于沉重的内存压力下的 vc_resize() 内部发生内存分配失败),它会跳至“err_out”标签以回滚控制台状态。然而,当前回滚逻辑忘记还原“hi_font”状态,进而导致严重的状态机损坏。

在函数的较早部分,可调用“set_vc_hi_font()”来更改“vc->vc_hi_font_mask”并改变屏幕缓冲区。如果“vc_resize()”随后失败,“err_out”路径将恢复“vc_font.charcount”,但完全跳过“vc_hi_font_mask”和屏幕缓冲区的回滚。

此不匹配使终端处于非同步状态。由于保持设置“vc_hi_font_mask”,VT 子系统仍将接受来自用户空间的大于 255 的字符索引,并将其写入屏幕缓冲区。随后的渲染调用(如“fbcon_putcs()”)随后将使用这些膨胀的索引来访问恢复的 256 个字符的字体数组,从而导致确定性的越界读取并可能泄露内核内存。

通过在错误路径中添加“hi_font”掩码和屏幕缓冲区缺少的回滚逻辑来修复此问题。
(CVE-2026-53402)

在 Linux 内核中,以下漏洞已修复:

hdlc_ppp:释放 hdlc 状态之前同步每个原型的定时器 (CVE-2026-63803)

在 Linux 内核中,以下漏洞已修复:

KVM:将 ioeventfd datamatch 中的 guest-triggerable BUG_ON() 替换为 get_unaligned()CVE-2026-63806 ()

在 Linux 内核中,以下漏洞已修复:

net:ip_gre:需要设备 netns 中的CAP_NET_ADMIN用于 changelink (CVE-2026-63829)

在 Linux 内核中,以下漏洞已修复:

net:skmsg:跨 SG 转换保留 sg.copy (CVE-2026-63830)

在 Linux 内核中,以下漏洞已修复:

netfilter:ipset:修复转储与 ip_set_list resize (CVE-2026-64189) 之间的争用

在 Linux 内核中,以下漏洞已修复:

fuse:从 fuse_ref_folio() (CVE-2026-64266) 返回之前重新锁定请求

在 Linux 内核中,以下漏洞已修复:

输入:synaptics-rmi4 - 将键映射绑定 F30 到 GPIO/LED 计数 (CVE-2026-64276)

在 Linux 内核中,以下漏洞已修复:

exfat:绑定 exfat_find_dir_entry() 中的 uniname advance (CVE-2026-64296)

在 Linux 内核中,以下漏洞已修复:

NFSv4:将MAY_WRITE包含在 O_TRUNC 的开放权限掩码中 (CVE-2026-64298)

在 Linux 内核中,以下漏洞已修复:

tracing:阻止 glob 匹配中的越界读取 (CVE-2026-64299)

在 Linux 内核中,以下漏洞已修复:

crypto:drbg - 修复 CTR_DRBGCVE-2026-64306 () 中失败时返回成功的问题

在 Linux 内核中,以下漏洞已修复:

crypto:pcrypt - 还原非并行回退的回调 (CVE-2026-64312)

在 Linux 内核中,以下漏洞已修复:

crypto:ecc - 修复 vli 乘法 (CVE-2026-64313) 中的进位溢出

在 Linux 内核中,以下漏洞已修复:

isofs:将 Rock Ridge 符号链接组件绑定到 SL 记录 (CVE-2026-64317)

在 Linux 内核中,以下漏洞已修复:

udf:将备用表长度验证为条目计数而非字节计数 (CVE-2026-64322)

在 Linux 内核中,以下漏洞已修复:

udf:根据 VAT inode 大小 (CVE-2026-64323) 验证 VAT 标头长度

在 Linux 内核中,以下漏洞已修复:

udf:根据分区长度 (CVE-2026-64324) 验证可用区块范围

在 Linux 内核中,以下漏洞已修复:

USB:ulpi:修复注册失败时的内存泄漏 (CVE-2026-64332)

在 Linux 内核中,以下漏洞已修复:

USB:serial:digi_acceleport:修复写入缓冲区损坏 (CVE-2026-64333)

在 Linux 内核中,以下漏洞已修复:

USB:serial:digi_acceleport:修复断开连接时的硬锁定 (CVE-2026-64334)

在 Linux 内核中,以下漏洞已修复:

USB:serial:digi_acceleport:修复 throttle (CVE-2026-64335) 后损坏的 rx

在 Linux 内核中,以下漏洞已修复:

USB:legousbtower:修复断开连接争用 (CVE-2026-64340) 时的释放后使用

在 Linux 内核中,以下漏洞已修复:

USB:iowarrior:修复断开连接 (CVE-2026-64342) 时的释放后使用

在 Linux 内核中,以下漏洞已修复:

USB:ldusb:修复断开连接争用 (CVE-2026-64343) 时的释放后使用

在 Linux 内核中,以下漏洞已修复:

USB:idmouse:修复断开连接争用 (CVE-2026-64344) 时的释放后使用

在 Linux 内核中,以下漏洞已修复:

usb:释放失败提交时的 ISO 计划 (CVE-2026-64348)

在 Linux 内核中,以下漏洞已修复:

net:usb:kalmia:限制 kalmia_rx_fixup() (CVE-2026-64351) 中的 RX 帧长度

在 Linux 内核中,以下漏洞已修复:

nilfs2:拒绝具有超出范围段编号 (CVE-2026-64359) CLEAN_SEGMENTS ioctl

在 Linux 内核中,以下漏洞已修复:

hfs/hfsplus:hfs_bnode_read 中的零初始化缓冲区 (CVE-2026-64360)

在 Linux 内核中,以下漏洞已修复:

hfs/hfsplus:修复 check_and_correct_requested_length 中的 u32 溢出 (CVE-2026-64361)

在 Linux 内核中,以下漏洞已修复:

HID:lg-g15:取消移除的待定工作以修复释放后使用 (CVE-2026-64362)

在 Linux 内核中,以下漏洞已修复:

HID:appleir:修复 remove() (CVE-2026-64363) 中的待定key_up_timer上的 UAF

在 Linux 内核中,以下漏洞已修复:

HID:multitouch:修复 mt_io_flags (CVE-2026-64364) 上的越界位访问

在 Linux 内核中,以下漏洞已修复:

posix-cpu-timers:修复 do_cpu_nanosleep() 错误路径 (CVE-2026-64370) 中的 pid 引用计数泄漏

在 Linux 内核中,以下漏洞已修复:

proc:使用 exec_update_lock 保护 ptrace_may_access()(第 1 部分)(CVE-2026-64371)

在 Linux 内核中,以下漏洞已修复:

cpufreq:pcc:修复 _OSC 评估中的释放后使用和双重释放 (CVE-2026-64372)

在 Linux 内核中,以下漏洞已修复:

cpufreq:修复重新启动期间的热插拔暂停争用 (CVE-2026-64373)

在 Linux 内核中,以下漏洞已修复:

sched/rt:将 RT_PUSH_IPI 默认为非PREEMPT_RT关闭 (CVE-2026-64374)

在 Linux 内核中,以下漏洞已修复:

proc:通过 exec_update_lock 保护 ptrace_may_access()(FD 链接) (CVE-2026-64375)

在 Linux 内核中,以下漏洞已修复:

writeback:修复 cgroup_writeback_umount() 与 inode_switch_wbs()CVE-2026-64378 () 之间的争用

在 Linux 内核中,以下漏洞已修复:

smb:客户端:强化 POSIX SID 长度解析 (CVE-2026-64380)

在 Linux 内核中,以下漏洞已修复:

smb:客户端:修复 receive_encrypted_standard() (CVE-2026-64381) 中的下一个缓冲区泄漏

在 Linux 内核中,以下漏洞已修复:

netfilter:ebtables:在 find_table_lock() () 之前CVE-2026-64411终止表名

在 Linux 内核中,以下漏洞已修复:

netfilter:ebtables:模块名称必须以 null 结尾 (CVE-2026-64412)

在 Linux 内核中,以下漏洞已修复:

netfilter:ebtables:零链栈数组 (CVE-2026-64413)

在 Linux 内核中,以下漏洞已修复:

net:ipv4:绑定 TCP 重新排序 sysctl 写入和 MTU 探测大小 (CVE-2026-64422)

在 Linux 内核中,以下漏洞已修复:

ipv4:igmp:在设备销毁时从哈希表中删除多播群组 (CVE-2026-64423)

在 Linux 内核中,以下漏洞已修复:

io_uring/io-wq:重新检查每个链接工作项的IO_WQ_BIT_EXIT (CVE-2026-64425)

在 Linux 内核中,以下漏洞已修复:

audit:修复 audit_queue (CVE-2026-64435) 上 skb_queue_len() 阅读器的数据争用

在 Linux 内核中,以下漏洞已修复:

net:af_key:初始化 IPComp 状态的alg_key_len (CVE-2026-64436)

在 Linux 内核中,以下漏洞已修复:

smb:客户端:将隐式 bcc[0] 豁免限制为没有数据区域 (CVE-2026-64448) 的响应

在 Linux 内核中,以下漏洞已修复:

tipc:修复广播间隙 ACK 区块中的越界读取 (CVE-2026-64450)

在 Linux 内核中,以下漏洞已修复:

USB:chaoskey:修复 chaoskey_release() 中的 slab-after-free() 释放CVE-2026-64455后使用

在 Linux 内核中,以下漏洞已修复:

hwrng:virtio:在 copy_data() (CVE-2026-64456) 处钳制设备报告的 used.len

在 Linux 内核中,以下漏洞已修复:

usb:xhci:修复 xhci_free_streams() ()CVE-2026-64465 中原子上下文中的休眠

在 Linux 内核中,以下漏洞已修复:

vfio/pci:在 register_device() 失败 () 时释放 VGA 仲裁程序客户端 (CVE-2026-64475)

在 Linux 内核中,以下漏洞已修复:

userfaultfd:对 pte_present()CVE-2026-64514 () 进行门must_wait可写性检查

在 Linux 内核中,以下漏洞已修复:

nvmet-tcp:在摘要错误路径 () 中nvmet_req_uninit前检查 INIT_FAILEDCVE-2026-64534

在 Linux 内核中,以下漏洞已修复:

ipv6:修复 fib6_nh_mtu_change() 中的 null-ptr-deref。(CVE-2026-64538)

在 Linux 内核中,以下漏洞已修复:

usbnet:gl620a:修复 genelink_rx_fixup() (CVE-2026-64540) 中的越界读取

在 Linux 内核中,以下漏洞已修复:

crypto:asymmetric_keys - 修复 pefile_digest_pe_contents 中的 OOB 读取 (CVE-2026-64544)

在 Linux 内核中,以下漏洞已修复:

drm/edid:修复 drm_parse_tiled_block() 中的 OOB 读取 (CVE-2026-64546)

在 Linux 内核中,以下漏洞已修复:

net:usb:net1080:在 rx_fixup (CVE-2026-64547) 中进行 pad-byte 访问前验证 packet_len

在 Linux 内核中,以下漏洞已修复:

bpf、sockmap:拒绝 bpf_msg_push_data() (CVE-2026-64548) 中溢出的 copy + len

在 Linux 内核中,以下漏洞已修复:

sctp:在读取过时 (CVE-2026-64551) 之前验证STALE_COOKIE原因长度

在 Linux 内核中,以下漏洞已修复:

net:psample:修复 PSAMPLE_ATTR_DATA (CVE-2026-64553) 中的信息泄漏

在 Linux 内核中,以下漏洞已修复:

posix-cpu-timers:防止非前导线 exec() 争用 (CVE-2026-64560) 导致的 UAF

在 Linux 内核中,以下漏洞已修复:

btrfs:不修剪不可写入的设备 (CVE-2026-64593)

在 Linux 内核中,以下漏洞已修复:

KVM:VMX:若 vCPU 处于访客模式,则获取 CR8 拦截更新中的 vmcs12 (CVE-2026-64604)

在 Linux 内核中,以下漏洞已修复:

HID:wacom:post-start 探测故障后停止硬件 (CVE-2026-68091)

Tenable 已直接从测试产品的安全公告中提取上述描述块。

请注意,Nessus 尚未测试这些问题,而是只依据应用程序自我报告的版本号进行判断。

解决方案

运行“yum update kernel”或“yum update --advisory ALAS2KERNEL-5.10-2026-129”以更新系统。

另见

https://alas.aws.amazon.com//AL2/ALAS2KERNEL-5.10-2026-129.html

https://alas.aws.amazon.com/faqs.html

https://explore.alas.aws.amazon.com/CVE-2026-43216.html

https://explore.alas.aws.amazon.com/CVE-2026-43329.html

https://explore.alas.aws.amazon.com/CVE-2026-46135.html

https://explore.alas.aws.amazon.com/CVE-2026-52942.html

https://explore.alas.aws.amazon.com/CVE-2026-53388.html

https://explore.alas.aws.amazon.com/CVE-2026-53392.html

https://explore.alas.aws.amazon.com/CVE-2026-53393.html

https://explore.alas.aws.amazon.com/CVE-2026-53399.html

https://explore.alas.aws.amazon.com/CVE-2026-53400.html

https://explore.alas.aws.amazon.com/CVE-2026-53402.html

https://explore.alas.aws.amazon.com/CVE-2026-63803.html

https://explore.alas.aws.amazon.com/CVE-2026-63806.html

https://explore.alas.aws.amazon.com/CVE-2026-63826.html

https://explore.alas.aws.amazon.com/CVE-2026-63829.html

https://explore.alas.aws.amazon.com/CVE-2026-63830.html

https://explore.alas.aws.amazon.com/CVE-2026-64015.html

https://explore.alas.aws.amazon.com/CVE-2026-64189.html

https://explore.alas.aws.amazon.com/CVE-2026-64266.html

https://explore.alas.aws.amazon.com/CVE-2026-64276.html

https://explore.alas.aws.amazon.com/CVE-2026-64296.html

https://explore.alas.aws.amazon.com/CVE-2026-64298.html

https://explore.alas.aws.amazon.com/CVE-2026-64299.html

https://explore.alas.aws.amazon.com/CVE-2026-64306.html

https://explore.alas.aws.amazon.com/CVE-2026-64312.html

https://explore.alas.aws.amazon.com/CVE-2026-64313.html

https://explore.alas.aws.amazon.com/CVE-2026-64317.html

https://explore.alas.aws.amazon.com/CVE-2026-64322.html

https://explore.alas.aws.amazon.com/CVE-2026-64323.html

https://explore.alas.aws.amazon.com/CVE-2026-64324.html

https://explore.alas.aws.amazon.com/CVE-2026-64332.html

https://explore.alas.aws.amazon.com/CVE-2026-64333.html

https://explore.alas.aws.amazon.com/CVE-2026-64334.html

https://explore.alas.aws.amazon.com/CVE-2026-64335.html

https://explore.alas.aws.amazon.com/CVE-2026-64340.html

https://explore.alas.aws.amazon.com/CVE-2026-64342.html

https://explore.alas.aws.amazon.com/CVE-2026-64343.html

https://explore.alas.aws.amazon.com/CVE-2026-64344.html

https://explore.alas.aws.amazon.com/CVE-2026-64348.html

https://explore.alas.aws.amazon.com/CVE-2026-64351.html

https://explore.alas.aws.amazon.com/CVE-2026-64359.html

https://explore.alas.aws.amazon.com/CVE-2026-64360.html

https://explore.alas.aws.amazon.com/CVE-2026-64361.html

https://explore.alas.aws.amazon.com/CVE-2026-64362.html

https://explore.alas.aws.amazon.com/CVE-2026-64363.html

https://explore.alas.aws.amazon.com/CVE-2026-64364.html

https://explore.alas.aws.amazon.com/CVE-2026-64370.html

https://explore.alas.aws.amazon.com/CVE-2026-64371.html

https://explore.alas.aws.amazon.com/CVE-2026-64372.html

https://explore.alas.aws.amazon.com/CVE-2026-64373.html

https://explore.alas.aws.amazon.com/CVE-2026-64374.html

https://explore.alas.aws.amazon.com/CVE-2026-64375.html

https://explore.alas.aws.amazon.com/CVE-2026-64378.html

https://explore.alas.aws.amazon.com/CVE-2026-64380.html

https://explore.alas.aws.amazon.com/CVE-2026-64381.html

https://explore.alas.aws.amazon.com/CVE-2026-64411.html

https://explore.alas.aws.amazon.com/CVE-2026-64412.html

https://explore.alas.aws.amazon.com/CVE-2026-64413.html

https://explore.alas.aws.amazon.com/CVE-2026-64422.html

https://explore.alas.aws.amazon.com/CVE-2026-64423.html

https://explore.alas.aws.amazon.com/CVE-2026-64425.html

https://explore.alas.aws.amazon.com/CVE-2026-64435.html

https://explore.alas.aws.amazon.com/CVE-2026-64436.html

https://explore.alas.aws.amazon.com/CVE-2026-64448.html

https://explore.alas.aws.amazon.com/CVE-2026-64450.html

https://explore.alas.aws.amazon.com/CVE-2026-64455.html

https://explore.alas.aws.amazon.com/CVE-2026-64456.html

https://explore.alas.aws.amazon.com/CVE-2026-64465.html

https://explore.alas.aws.amazon.com/CVE-2026-64475.html

https://explore.alas.aws.amazon.com/CVE-2026-64514.html

https://explore.alas.aws.amazon.com/CVE-2026-64534.html

https://explore.alas.aws.amazon.com/CVE-2026-64538.html

https://explore.alas.aws.amazon.com/CVE-2026-64540.html

https://explore.alas.aws.amazon.com/CVE-2026-64544.html

https://explore.alas.aws.amazon.com/CVE-2026-64546.html

https://explore.alas.aws.amazon.com/CVE-2026-64547.html

https://explore.alas.aws.amazon.com/CVE-2026-64548.html

https://explore.alas.aws.amazon.com/CVE-2026-64551.html

https://explore.alas.aws.amazon.com/CVE-2026-64553.html

https://explore.alas.aws.amazon.com/CVE-2026-64560.html

https://explore.alas.aws.amazon.com/CVE-2026-64561.html

https://explore.alas.aws.amazon.com/CVE-2026-64593.html

https://explore.alas.aws.amazon.com/CVE-2026-64604.html

https://explore.alas.aws.amazon.com/CVE-2026-68091.html

https://explore.alas.aws.amazon.com/CVE-2026-72218.html

https://explore.alas.aws.amazon.com/CVE-2026-74262.html

插件详情

严重性: Medium

ID: 337224

文件名: al2_ALASKERNEL-5_10-2026-129.nasl

版本: 1.2

类型: Local

代理: unix

发布时间: 2026/8/18

最近更新时间: 2026/8/19

支持的传感器: Frictionless Assessment AWS, Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Continuous Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

风险信息

VPR

风险因素: High

分数: 8

百分位: 99.68

CVSS v2

风险因素: Medium

基本分数: 4.6

时间分数: 3.6

矢量: CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:C

CVSS 分数来源: CVE-2026-53393

CVSS v3

风险因素: Medium

基本分数: 5.5

时间分数: 5

矢量: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

时间矢量: CVSS:3.0/E:P/RL:O/RC:C

漏洞信息

CPE: cpe:/o:amazon:linux:2, p-cpe:/a:amazon:linux:bpftool-debuginfo, p-cpe:/a:amazon:linux:bpftool, p-cpe:/a:amazon:linux:kernel-debuginfo-common-aarch64, p-cpe:/a:amazon:linux:kernel-debuginfo-common-x86_64, p-cpe:/a:amazon:linux:kernel-debuginfo, p-cpe:/a:amazon:linux:kernel-devel, p-cpe:/a:amazon:linux:kernel-headers, p-cpe:/a:amazon:linux:kernel-livepatch-5.10.262-262.1063, p-cpe:/a:amazon:linux:kernel-tools-debuginfo, p-cpe:/a:amazon:linux:kernel-tools-devel, p-cpe:/a:amazon:linux:kernel-tools, p-cpe:/a:amazon:linux:kernel, p-cpe:/a:amazon:linux:perf-debuginfo, p-cpe:/a:amazon:linux:perf, p-cpe:/a:amazon:linux:python-perf-debuginfo, p-cpe:/a:amazon:linux:python-perf

必需的 KB 项: Host/local_checks_enabled, Host/AmazonLinux/release, Host/AmazonLinux/rpm-list

可利用: true

易利用性: Exploits are available

补丁发布日期: 2026/8/17

漏洞发布日期: 2026/5/6

参考资料信息

CVE: CVE-2026-43216, CVE-2026-43329, CVE-2026-46135, CVE-2026-52942, CVE-2026-53388, CVE-2026-53392, CVE-2026-53393, CVE-2026-53399, CVE-2026-53400, CVE-2026-53402, CVE-2026-63803, CVE-2026-63806, CVE-2026-63826, CVE-2026-63829, CVE-2026-63830, CVE-2026-64015, CVE-2026-64189, CVE-2026-64266, CVE-2026-64276, CVE-2026-64296, CVE-2026-64298, CVE-2026-64299, CVE-2026-64306, CVE-2026-64312, CVE-2026-64313, CVE-2026-64317, CVE-2026-64322, CVE-2026-64323, CVE-2026-64324, CVE-2026-64332, CVE-2026-64333, CVE-2026-64334, CVE-2026-64335, CVE-2026-64340, CVE-2026-64342, CVE-2026-64343, CVE-2026-64344, CVE-2026-64348, CVE-2026-64351, CVE-2026-64359, CVE-2026-64360, CVE-2026-64361, CVE-2026-64362, CVE-2026-64363, CVE-2026-64364, CVE-2026-64370, CVE-2026-64371, CVE-2026-64372, CVE-2026-64373, CVE-2026-64374, CVE-2026-64375, CVE-2026-64378, CVE-2026-64380, CVE-2026-64381, CVE-2026-64411, CVE-2026-64412, CVE-2026-64413, CVE-2026-64422, CVE-2026-64423, CVE-2026-64425, CVE-2026-64435, CVE-2026-64436, CVE-2026-64448, CVE-2026-64450, CVE-2026-64455, CVE-2026-64456, CVE-2026-64465, CVE-2026-64475, CVE-2026-64514, CVE-2026-64534, CVE-2026-64538, CVE-2026-64540, CVE-2026-64544, CVE-2026-64546, CVE-2026-64547, CVE-2026-64548, CVE-2026-64551, CVE-2026-64553, CVE-2026-64560, CVE-2026-64561, CVE-2026-64593, CVE-2026-64604, CVE-2026-68091, CVE-2026-72218, CVE-2026-74262