Amazon Linux 2:内核 (ALASKERNEL-5.10-2026-129)

high Nessus 插件 ID 337224

简介

远程 Amazon Linux 2 主机缺少安全更新。

描述

远程主机上安装的内核版本低于 5.10.262-262.1063。因此,会受到 ALAS2KERNEL-5.10-2026-129 公告中提及的多个漏洞影响。

在 Linux 内核中,以下漏洞已修复:

net:终止 skb_may_tx_timestamp() (CVE-2026-43216) 中的锁定

在 Linux 内核中,以下漏洞已修复:

netfilter:flowtable:严格检查最大操作数 (CVE-2026-43329)

在 Linux 内核中,以下漏洞已修复:

nvmet-tcp:修复 ICReq 处理和队列拆卸 (CVE-2026-46135) 之间的争用

在 Linux 内核中,以下漏洞已修复:

netfilter:nf_log:在转储前验证已设置 MAC 标头 (CVE-2026-52942)

在 Linux 内核中,以下漏洞已修复:

fuse:替换页面缓存作品集之前的重新锁定请求

fuse_try_move_folio() 在进入时解锁请求,但不会在成功路径上重新锁定它。这意味着 fuse_chan_abort() 可以结束请求并释放fuse_io_args(如 fuse_readpages_end()),而 fuse_try_move_folio() 访问thefuse_io_args之后的后续复制链逻辑会导致释放后使用问题。

通过先调用 lock_request(),先调用 replace_page_cache_folio(),以修复此问题。这可确保请求锁定在成功路径上,从而防止在后续复制逻辑运行时释放fuse_io_args,同时确保 ap->folios[i]->mapping 永远不为空,因为 ap->folios[i] 始终指向 newfolio afterreplace_page_cache_folio()。(CVE-2026-53388)

在 Linux 内核中,以下漏洞已修复:

NFSv4/flexfiles:拒绝零文件句柄版本计数 (CVE-2026-53392)

在 Linux 内核中,以下漏洞已修复:

nfsd:针对延迟的回写错误重置写入验证程序 (CVE-2026-53393)

在 Linux 内核中,以下漏洞已修复:

nfsd:在 setlease 失败 (CVE-2026-53399) 时发布布局策略

在 Linux 内核中,以下漏洞已修复:

i2c:core:修复适配器注册争用

使用 i2c_get_adapter() 可根据适配器的 id 查找适配器,该函数会引用嵌入式结构设备。

确保适配器(包括其结构设备)在将其添加到 IDR 之前已初始化,以避免访问未初始化数据,例如,可能导致空指针取消引用或释放后使用。

请注意,从总线通知程序注册的 i2c-dev chardev 当前使用 i2c_get_adapter(),因此在注册前需要将适配器添加到 IDR。(CVE-2026-53400)

在 Linux 内核中,以下漏洞已修复:

fbdev:fbcon:修复 fbcon_do_set_font() err_out中的越界读取

当 fbcon_do_set_font() 发生故障时(例如,由于沉重的内存压力下的 vc_resize() 内部发生内存分配失败),它会跳至“err_out”标签以回滚控制台状态。然而,当前回滚逻辑忘记还原“hi_font”状态,进而导致严重的状态机损坏。

在函数的较早部分,可调用“set_vc_hi_font()”来更改“vc->vc_hi_font_mask”并改变屏幕缓冲区。如果“vc_resize()”随后失败,“err_out”路径将恢复“vc_font.charcount”,但完全跳过“vc_hi_font_mask”和屏幕缓冲区的回滚。

此不匹配使终端处于非同步状态。由于保持设置“vc_hi_font_mask”,VT 子系统仍将接受来自用户空间的大于 255 的字符索引,并将其写入屏幕缓冲区。随后的渲染调用(如“fbcon_putcs()”)随后将使用这些膨胀的索引来访问恢复的 256 个字符的字体数组,从而导致确定性的越界读取并可能泄露内核内存。

通过在错误路径中添加“hi_font”掩码和屏幕缓冲区缺少的回滚逻辑来修复此问题。
(CVE-2026-53402)

在 Linux 内核中,以下漏洞已修复:

hdlc_ppp:释放 hdlc 状态之前同步每个原型的定时器 (CVE-2026-63803)

在 Linux 内核中,以下漏洞已修复:

KVM:将 ioeventfd datamatch 中的 guest-triggerable BUG_ON() 替换为 get_unaligned()CVE-2026-63806 ()

在 Linux 内核中,以下漏洞已修复:

fbdev:修复 store_modes() 中的释放后使用 (CVE-2026-63826)

在 Linux 内核中,以下漏洞已修复:

net:ip_gre:需要设备 netns 中的CAP_NET_ADMIN用于 changelink (CVE-2026-63829)

在 Linux 内核中,以下漏洞已修复:

net:skmsg:跨 SG 转换保留 sg.copy (CVE-2026-63830)

在 Linux 内核中,以下漏洞已修复:

security/keys:修复查找时缺少的 RCU 读取部分

Nicholas Carlini 报告,keyring 代码在不保持 RCU 读取锁定的情况下调用 find_key_to_update() 中的 assoc_array_find(),而 theassoc_array_gc() 代码实际上设计为从树中删除节点,然后在 RCU 宽限期后将其释放。

常规密钥处理不会看到此问题,因为按住 keyringsemaphore 会隐藏任何生命周期问题,但持久密钥处理使用不同的模型。

无需扩展密钥环锁定,只需执行简单的 RCU 锁定assoc_array的设计目的。(CVE-2026-64015)

在 Linux 内核中,以下漏洞已修复:

netfilter:ipset:修复转储与 ip_set_list resize (CVE-2026-64189) 之间的争用

在 Linux 内核中,以下漏洞已修复:

fuse:从 fuse_ref_folio() (CVE-2026-64266) 返回之前重新锁定请求

在 Linux 内核中,以下漏洞已修复:

输入:synaptics-rmi4 - 将键映射绑定 F30 到 GPIO/LED 计数 (CVE-2026-64276)

在 Linux 内核中,以下漏洞已修复:

exfat:绑定 exfat_find_dir_entry() 中的 uniname advance (CVE-2026-64296)

在 Linux 内核中,以下漏洞已修复:

NFSv4:将MAY_WRITE包含在 O_TRUNC 的开放权限掩码中 (CVE-2026-64298)

在 Linux 内核中,以下漏洞已修复:

tracing:阻止 glob 匹配中的越界读取 (CVE-2026-64299)

在 Linux 内核中,以下漏洞已修复:

crypto:drbg - 修复 CTR_DRBGCVE-2026-64306 () 中失败时返回成功的问题

在 Linux 内核中,以下漏洞已修复:

crypto:pcrypt - 还原非并行回退的回调 (CVE-2026-64312)

在 Linux 内核中,以下漏洞已修复:

crypto:ecc - 修复 vli 乘法 (CVE-2026-64313) 中的进位溢出

在 Linux 内核中,以下漏洞已修复:

isofs:将 Rock Ridge 符号链接组件绑定到 SL 记录 (CVE-2026-64317)

在 Linux 内核中,以下漏洞已修复:

udf:将备用表长度验证为条目计数而非字节计数 (CVE-2026-64322)

在 Linux 内核中,以下漏洞已修复:

udf:根据 VAT inode 大小 (CVE-2026-64323) 验证 VAT 标头长度

在 Linux 内核中,以下漏洞已修复:

udf:根据分区长度 (CVE-2026-64324) 验证可用区块范围

在 Linux 内核中,以下漏洞已修复:

USB:ulpi:修复注册失败时的内存泄漏 (CVE-2026-64332)

在 Linux 内核中,以下漏洞已修复:

USB:serial:digi_acceleport:修复写入缓冲区损坏 (CVE-2026-64333)

在 Linux 内核中,以下漏洞已修复:

USB:serial:digi_acceleport:修复断开连接时的硬锁定 (CVE-2026-64334)

在 Linux 内核中,以下漏洞已修复:

USB:serial:digi_acceleport:修复 throttle (CVE-2026-64335) 后损坏的 rx

在 Linux 内核中,以下漏洞已修复:

USB:legousbtower:修复断开连接争用 (CVE-2026-64340) 时的释放后使用

在 Linux 内核中,以下漏洞已修复:

USB:iowarrior:修复断开连接 (CVE-2026-64342) 时的释放后使用

在 Linux 内核中,以下漏洞已修复:

USB:ldusb:修复断开连接争用 (CVE-2026-64343) 时的释放后使用

在 Linux 内核中,以下漏洞已修复:

USB:idmouse:修复断开连接争用 (CVE-2026-64344) 时的释放后使用

在 Linux 内核中,以下漏洞已修复:

usb:释放失败提交时的 ISO 计划 (CVE-2026-64348)

在 Linux 内核中,以下漏洞已修复:

net:usb:kalmia:限制 kalmia_rx_fixup() (CVE-2026-64351) 中的 RX 帧长度

在 Linux 内核中,以下漏洞已修复:

nilfs2:拒绝具有超出范围段编号 (CVE-2026-64359) CLEAN_SEGMENTS ioctl

在 Linux 内核中,以下漏洞已修复:

hfs/hfsplus:hfs_bnode_read 中的零初始化缓冲区 (CVE-2026-64360)

在 Linux 内核中,以下漏洞已修复:

hfs/hfsplus:修复 check_and_correct_requested_length 中的 u32 溢出 (CVE-2026-64361)

在 Linux 内核中,以下漏洞已修复:

HID:lg-g15:取消移除的待定工作以修复释放后使用 (CVE-2026-64362)

在 Linux 内核中,以下漏洞已修复:

HID:appleir:修复 remove() (CVE-2026-64363) 中的待定key_up_timer上的 UAF

在 Linux 内核中,以下漏洞已修复:

HID:multitouch:修复 mt_io_flags (CVE-2026-64364) 上的越界位访问

在 Linux 内核中,以下漏洞已修复:

posix-cpu-timers:修复 do_cpu_nanosleep() 错误路径 (CVE-2026-64370) 中的 pid 引用计数泄漏

在 Linux 内核中,以下漏洞已修复:

proc:使用 exec_update_lock 保护 ptrace_may_access()(第 1 部分)(CVE-2026-64371)

在 Linux 内核中,以下漏洞已修复:

cpufreq:pcc:修复 _OSC 评估中的释放后使用和双重释放 (CVE-2026-64372)

在 Linux 内核中,以下漏洞已修复:

cpufreq:修复重新启动期间的热插拔暂停争用 (CVE-2026-64373)

在 Linux 内核中,以下漏洞已修复:

sched/rt:将 RT_PUSH_IPI 默认为非PREEMPT_RT关闭 (CVE-2026-64374)

在 Linux 内核中,以下漏洞已修复:

proc:通过 exec_update_lock 保护 ptrace_may_access()(FD 链接) (CVE-2026-64375)

在 Linux 内核中,以下漏洞已修复:

writeback:修复 cgroup_writeback_umount() 与 inode_switch_wbs()CVE-2026-64378 () 之间的争用

在 Linux 内核中,以下漏洞已修复:

smb:客户端:强化 POSIX SID 长度解析 (CVE-2026-64380)

在 Linux 内核中,以下漏洞已修复:

smb:客户端:修复 receive_encrypted_standard() (CVE-2026-64381) 中的下一个缓冲区泄漏

在 Linux 内核中,以下漏洞已修复:

netfilter:ebtables:在 find_table_lock() () 之前CVE-2026-64411终止表名

在 Linux 内核中,以下漏洞已修复:

netfilter:ebtables:模块名称必须以 null 结尾 (CVE-2026-64412)

在 Linux 内核中,以下漏洞已修复:

netfilter:ebtables:零链栈数组 (CVE-2026-64413)

在 Linux 内核中,以下漏洞已修复:

net:ipv4:绑定 TCP 重新排序 sysctl 写入和 MTU 探测大小 (CVE-2026-64422)

在 Linux 内核中,以下漏洞已修复:

ipv4:igmp:在设备销毁时从哈希表中删除多播群组 (CVE-2026-64423)

在 Linux 内核中,以下漏洞已修复:

io_uring/io-wq:重新检查每个链接工作项的IO_WQ_BIT_EXIT (CVE-2026-64425)

在 Linux 内核中,以下漏洞已修复:

audit:修复 audit_queue (CVE-2026-64435) 上 skb_queue_len() 阅读器的数据争用

在 Linux 内核中,以下漏洞已修复:

net:af_key:初始化 IPComp 状态的alg_key_len (CVE-2026-64436)

在 Linux 内核中,以下漏洞已修复:

smb:客户端:将隐式 bcc[0] 豁免限制为没有数据区域 (CVE-2026-64448) 的响应

在 Linux 内核中,以下漏洞已修复:

tipc:修复广播间隙 ACK 区块中的越界读取 (CVE-2026-64450)

在 Linux 内核中,以下漏洞已修复:

USB:chaoskey:修复 chaoskey_release() 中的 slab-after-free() 释放CVE-2026-64455后使用

在 Linux 内核中,以下漏洞已修复:

hwrng:virtio:在 copy_data() (CVE-2026-64456) 处钳制设备报告的 used.len

在 Linux 内核中,以下漏洞已修复:

usb:xhci:修复 xhci_free_streams() ()CVE-2026-64465 中原子上下文中的休眠

在 Linux 内核中,以下漏洞已修复:

vfio/pci:在 register_device() 失败 () 时释放 VGA 仲裁程序客户端 (CVE-2026-64475)

在 Linux 内核中,以下漏洞已修复:

userfaultfd:对 pte_present()CVE-2026-64514 () 进行门must_wait可写性检查

在 Linux 内核中,以下漏洞已修复:

nvmet-tcp:在摘要错误路径 () 中nvmet_req_uninit前检查 INIT_FAILEDCVE-2026-64534

在 Linux 内核中,以下漏洞已修复:

ipv6:修复 fib6_nh_mtu_change() 中的 null-ptr-deref。(CVE-2026-64538)

在 Linux 内核中,以下漏洞已修复:

usbnet:gl620a:修复 genelink_rx_fixup() (CVE-2026-64540) 中的越界读取

在 Linux 内核中,以下漏洞已修复:

crypto:asymmetric_keys - 修复 pefile_digest_pe_contents 中的 OOB 读取 (CVE-2026-64544)

在 Linux 内核中,以下漏洞已修复:

drm/edid:修复 drm_parse_tiled_block() 中的 OOB 读取 (CVE-2026-64546)

在 Linux 内核中,以下漏洞已修复:

net:usb:net1080:在 rx_fixup (CVE-2026-64547) 中进行 pad-byte 访问前验证 packet_len

在 Linux 内核中,以下漏洞已修复:

bpf、sockmap:拒绝 bpf_msg_push_data() (CVE-2026-64548) 中溢出的 copy + len

在 Linux 内核中,以下漏洞已修复:

sctp:在读取过时 (CVE-2026-64551) 之前验证STALE_COOKIE原因长度

在 Linux 内核中,以下漏洞已修复:

net:psample:修复 PSAMPLE_ATTR_DATA (CVE-2026-64553) 中的信息泄漏

在 Linux 内核中,以下漏洞已修复:

posix-cpu-timers:防止非前导线 exec() 争用 (CVE-2026-64560) 导致的 UAF

在 Linux 内核中,以下漏洞已修复:

KVM:x86:*在使 MMU 页面可用之后*检查无效/过时的根

在为影子 MMU 创建 MMU 页面之后,检查过时页面错误,即无效和/或过时的根。如果回收 shadowpage 清除了正在使用的根(即将其标记为无效),则 KVM 将尝试将内存映射到无效的根。就其本身而言,填充无效的根是可以的,但由于子影子页面继承了其父页面的角色,在映射/提取期间创建的任何子页面都将被创建为无效页面,从而违反了 KVM 的不变性,即无效页面永远不会出现在活动的 MMU 页面的列表中。

请注意,自 KVM 于 2008 年首次开始跟踪无效根(提交 2e53d63acba7,KVM:MMU:忽略 zapped rootpagetables)以来,该潜在缺陷就一直存在,但真正的坏处直到 2020 年 (Linux 5.9) 才出现,无效的阴影页面不能出现在活动页面的列表中。

请注意 #2,创建子影子页面时继承 role.invalid 也远非理想;此缺陷将另行解决。(CVE-2026-64561)

在 Linux 内核中,以下漏洞已修复:

btrfs:不修剪不可写入的设备 (CVE-2026-64593)

在 Linux 内核中,以下漏洞已修复:

KVM:VMX:若 vCPU 处于访客模式,则获取 CR8 拦截更新中的 vmcs12 (CVE-2026-64604)

在 Linux 内核中,以下漏洞已修复:

HID:wacom:post-start 探测故障后停止硬件 (CVE-2026-68091)

在 Linux 内核中,以下漏洞已修复:

ipvs:修复更多位置的错误 ipv6 传输偏移 (CVE-2026-68477)

在 Linux 内核中,以下漏洞已修复:

cgroup/cpuset:将 mm mempolicy 重新绑定到 effective_mems,而非 mems_allowed (CVE-2026-72010)

在 Linux 内核中,以下漏洞已修复:

drbd:拒绝负载大小超出范围的数据回复 (CVE-2026-72014)

在 Linux 内核中,以下漏洞已修复:

ipvs:重置 ip_vs_conn_new (CVE-2026-72020) 中的全部 ip_vs_seq struct

在 Linux 内核中,以下漏洞已修复:

ipvs:在 SCTP 状态查找 (CVE-2026-72021) 中使用解析的传输偏移

在 Linux 内核中,以下漏洞已修复:

net/sched:sch_multiq:将直接出列调用替换为 peek 和 qdisc_dequeue_peeked (CVE-2026-72036)

在 Linux 内核中,以下漏洞已修复:

net:liquidio:修复 PF 编号失败 (CVE-2026-72038) 时的 BAR 资源泄漏

在 Linux 内核中,以下漏洞已修复:

bnx2x:修复 bnx2x_alloc_mem_bp() (CVE-2026-72039) 中潜在的内存泄漏

在 Linux 内核中,以下漏洞已修复:

net:ip6_gre:需要设备 netns 中的CAP_NET_ADMIN用于 changelink (CVE-2026-72052)

在 Linux 内核中,以下漏洞已修复:

net:ip_vti:需要设备 netns 中的CAP_NET_ADMIN用于 changelink (CVE-2026-72054)

在 Linux 内核中,以下漏洞已修复:

net:ip6_vti:需要设备 netns 中的CAP_NET_ADMIN用于 changelink (CVE-2026-72055)

在 Linux 内核中,以下漏洞已修复:

net:sit:需要设备 netns 中的CAP_NET_ADMIN用于 changelink (CVE-2026-72061)

在 Linux 内核中,以下漏洞已修复:

cpu:hotplug:保留每个实例的回调错误 (CVE-2026-72067)

在 Linux 内核中,以下漏洞已修复:

posix-cpu-timers:在 update_rlimit_cpu() 中使用 u64 乘法 (CVE-2026-72068)

在 Linux 内核中,以下漏洞已修复:

scsi:target:core:修复 REGISTER AND MOVE (CVE-2026-72083) 中的 iSCSI ISID 释放后使用

在 Linux 内核中,以下漏洞已修复:

scsi:hpsa:修复 IOACCEL2 重置路径 (CVE-2026-72088) 上的 DMA 映射泄漏

在 Linux 内核中,以下漏洞已修复:

dm_early_create:修复dm_resume失败时释放已使用表的问题 (CVE-2026-72102)

在 Linux 内核中,以下漏洞已修复:

dm-log:修复 32 位计算机上的bitset_size溢出 (CVE-2026-72105)

在 Linux 内核中,以下漏洞已修复:

dm era:修复非零起始扇区 (CVE-2026-72107) 的越界内存访问

在 Linux 内核中,以下漏洞已修复:

dm thin metadata:修复提交失败时的元数据快照一致性 (CVE-2026-72108)

在 Linux 内核中,以下漏洞已修复:

can:bcm:添加缺失的 rcu 列表批注和操作 (CVE-2026-72120)

在 Linux 内核中,以下漏洞已修复:

can:bcm:修复无锁 bound/ifindex 争用和静默RX_SETUP失败 (CVE-2026-72122)

在 Linux 内核中,以下漏洞已修复:

nvmet-rdma:处理使用非零偏移 (CVE-2026-72129) 的内联数据

在 Linux 内核中,以下漏洞已修复:

tpm:使 TPM 字符设备不可搜索 (CVE-2026-72135)

在 Linux 内核中,以下漏洞已修复:

xfrm:xfrm_interface:需要设备 netns 中的CAP_NET_ADMIN用于 changelink (CVE-2026-72136)

在 Linux 内核中,以下漏洞已修复:

xen/gntdev:修复 ioctl (CVE-2026-72138) 中的错误处理

在 Linux 内核中,以下漏洞已修复:

lockd:在缓存的 nlm_do_fopen() 失败 () 中插入 nlm_file refcount 泄漏 (CVE-2026-72218)

在 Linux 内核中,以下漏洞已修复:

lockd:当 nlm_do_fopen() 失败时,插nlm_file泄漏 (CVE-2026-72219)

在 Linux 内核中,以下漏洞已修复:

nvdimm/btt:在 discover_arenas() 错误路径 (CVE-2026-72223) 上释放 arena 子分配

在 Linux 内核中,以下漏洞已修复:

nvdimm/btt: 释放 btt_init() 错误路径中的 arenas (CVE-2026-72224)

在 Linux 内核中,以下漏洞已修复:

netfilter:nf_conncount:修复元组 dedup (CVE-2026-72247) 中的区域比较

在 Linux 内核中,以下漏洞已修复:

netfilter:nf_conntrack_reasm:在 IPv6 磁盘碎片整理 (CVE-2026-72250) 后保护mac_header调整

在 Linux 内核中,以下漏洞已修复:

netfilter:nf_nat_sip:重新加载可能的过时数据指针 (CVE-2026-72251)

在 Linux 内核中,以下漏洞已修复:

netfilter:xt_cluster:拒绝哈希匹配 (CVE-2026-72256) 中的模板连接跟踪

在 Linux 内核中,以下漏洞已修复:

KVM:将 kvm_io_bus_get_dev() 锁定责任移动到调用程序 (CVE-2026-72282)

在 Linux 内核中,以下漏洞已修复:

KVM:arm64:vgic:迁移中断之前,先检查中断仍属于我们 (CVE-2026-72289)

在 Linux 内核中,以下漏洞已修复:

net:ife:要求 ETH_HLEN 在 ife_decode() (CVE-2026-72296) 中是可拉取的

在 Linux 内核中,以下漏洞已修复:

mlxsw:修复 mlxsw_sp_vrs_lpm_tree_replace() (CVE-2026-72307) 中的 refcount 泄漏

在 Linux 内核中,以下漏洞已修复:

smb:客户端:修复传递 ioctl 边界检查 (CVE-2026-72310) 中的溢出

在 Linux 内核中,以下漏洞已修复:

regulator:core:regulator_lock_two() 应测试 EDEADLK 而不是 EDEADLOCK (CVE-2026-72314)

在 Linux 内核中,以下漏洞已修复:

dm era:修复 metadata_open() 中的空指针取消引用 (CVE-2026-72316)

在 Linux 内核中,以下漏洞已修复:

ipvs:确保 ICMP 错误中的内部标头位于余量 (CVE-2026-72319) 中

在 Linux 内核中,以下漏洞已修复:

ipv6:mcast:修复 MLD 延迟工作中潜在的 UAF (CVE-2026-72322)

在 Linux 内核中,以下漏洞已修复:

net/sched:cake:拒绝下溢长度 (CVE-2026-72326) 的开销值

在 Linux 内核中,以下漏洞已修复:

qede:修复build_skb失败时 BD 环消耗中的差一 (CVE-2026-72339)

在 Linux 内核中,以下漏洞已修复:

netfilter:ip6tables:标记 hotdrop (CVE-2026-72348) 的畸形 IPv6 扩展标头

在 Linux 内核中,以下漏洞已修复:

netfilter:xt_rateest:修复 xt_rateest_mt() (CVE-2026-72349) 中的 u64 截断

在 Linux 内核中,以下漏洞已修复:

netfilter:xt_u32:拒绝无效的位移计数 (CVE-2026-72350)

在 Linux 内核中,以下漏洞已修复:

gue:验证 REMCSUM 隐私选项长度 (CVE-2026-72351)

在 Linux 内核中,以下漏洞已修复:

hwmon:adm1275:防止读取未初始化的堆栈 (CVE-2026-72396)

在 Linux 内核中,以下漏洞已修复:

seg6:读取固定字段 (CVE-2026-72400) 之前验证 SRH 长度

在 Linux 内核中,以下漏洞已修复:

netfilter:nf_conncount:防止终止及早确认 ct (CVE-2026-72418) 的 connlimit

在 Linux 内核中,以下漏洞已修复:

ipv4:fib:不要忽略 local/main 表中的错误路由。(CVE-2026-72421)

在 Linux 内核中,以下漏洞已修复:

bpf:修复 nospec 检查中的堆栈槽索引 (CVE-2026-72428)

在 Linux 内核中,以下漏洞已修复:

netfilter:nft_meta_bridge:修复NFT_META_BRI_IIFPVID堆栈泄漏 (CVE-2026-72433)

在 Linux 内核中,以下漏洞已修复:

netfilter:ipset:修复 kfree_rcu() 和 rcu_assign_pointer() (CVE-2026-72435) 的顺序

在 Linux 内核中,以下漏洞已修复:

sctp:在 sctp_diag (CVE-2026-72447) 中转储端点时保持套接字锁定

在 Linux 内核中,以下漏洞已修复:

xfrm:在匹配期间验证选择器系列和 prefixlen (CVE-2026-72450)

在 Linux 内核中,以下漏洞已修复:

dmaengine:修复可能的释放后使用 (CVE-2026-72476)

在 Linux 内核中,以下漏洞已修复:

tcp:ipv6:钳制默认公告 MSS 以避免GSO_BY_FRAGS (0xFFFF) (CVE-2026-72502)

在 Linux 内核中,以下漏洞已修复:

tipc:修复 tipc_l2_send_msg() 中的 UAF (CVE-2026-74255)

在 Linux 内核中,以下漏洞已修复:

bpf、sockmap:修复 bpf_msg_pop_data() 边界检查 (CVE-2026-74256) 中的整数溢出

在 Linux 内核中,以下漏洞已修复:

kcm:更改较低套接字回调 (CVE-2026-74262) 时使用 WRITE_ONCE()

在 Linux 内核中,以下漏洞已修复:

net/sched:sch_codel:在还原 qlen (CVE-2026-74267) 之前,在扫视期间不调用 qdisc_tree_reduce_backlog

在 Linux 内核中,以下漏洞已修复:

crypto:cavium/cpt - 修复使用错误循环索引 (CVE-2026-74279) 的 DMA 清理

在 Linux 内核中,以下漏洞已修复:

tipc:防止 CONN_ACK (CVE-2026-74282) 上的snt_unacked下溢

在 Linux 内核中,以下漏洞已修复:

tipc:TIPCv2 netlink mutators 需要 net admin (CVE-2026-74283)

在 Linux 内核中,以下漏洞已修复:

net/sched:sch_hfsc:不使类被动两次 (CVE-2026-74284)

在 Linux 内核中,以下漏洞已修复:

sctp:验证嵌入地址参数长度 (CVE-2026-74287)

在 Linux 内核中,以下漏洞已修复:

net:fib_rules:不在 fib_rules_dump() 中转储垂死的fib_rule。(CVE-2026-74288)

在 Linux 内核中,以下漏洞已修复:

RDMA/mlx5:修复用户 RQ WQE 大小的未定义位移 (CVE-2026-74297)

在 Linux 内核中,以下命令 ...

请注意,描述因长度问题被截断。请参考供应商公告,获取完整描述。

Tenable 已直接从测试产品的安全公告中提取上述描述块。

请注意,Nessus 尚未测试这些问题,而是只依据应用程序自我报告的版本号进行判断。

解决方案

运行“yum update kernel”或“yum update --advisory ALAS2KERNEL-5.10-2026-129”以更新系统。

另见

https://alas.aws.amazon.com//AL2/ALAS2KERNEL-5.10-2026-129.html

https://alas.aws.amazon.com/faqs.html

https://explore.alas.aws.amazon.com/CVE-2026-43216.html

https://explore.alas.aws.amazon.com/CVE-2026-43329.html

https://explore.alas.aws.amazon.com/CVE-2026-46135.html

https://explore.alas.aws.amazon.com/CVE-2026-52942.html

https://explore.alas.aws.amazon.com/CVE-2026-53388.html

https://explore.alas.aws.amazon.com/CVE-2026-53392.html

https://explore.alas.aws.amazon.com/CVE-2026-53393.html

https://explore.alas.aws.amazon.com/CVE-2026-53399.html

https://explore.alas.aws.amazon.com/CVE-2026-53400.html

https://explore.alas.aws.amazon.com/CVE-2026-53402.html

https://explore.alas.aws.amazon.com/CVE-2026-63803.html

https://explore.alas.aws.amazon.com/CVE-2026-63806.html

https://explore.alas.aws.amazon.com/CVE-2026-63826.html

https://explore.alas.aws.amazon.com/CVE-2026-63829.html

https://explore.alas.aws.amazon.com/CVE-2026-63830.html

https://explore.alas.aws.amazon.com/CVE-2026-64015.html

https://explore.alas.aws.amazon.com/CVE-2026-64189.html

https://explore.alas.aws.amazon.com/CVE-2026-64266.html

https://explore.alas.aws.amazon.com/CVE-2026-64276.html

https://explore.alas.aws.amazon.com/CVE-2026-64296.html

https://explore.alas.aws.amazon.com/CVE-2026-64298.html

https://explore.alas.aws.amazon.com/CVE-2026-64299.html

https://explore.alas.aws.amazon.com/CVE-2026-64306.html

https://explore.alas.aws.amazon.com/CVE-2026-64312.html

https://explore.alas.aws.amazon.com/CVE-2026-64313.html

https://explore.alas.aws.amazon.com/CVE-2026-64317.html

https://explore.alas.aws.amazon.com/CVE-2026-64322.html

https://explore.alas.aws.amazon.com/CVE-2026-64323.html

https://explore.alas.aws.amazon.com/CVE-2026-64324.html

https://explore.alas.aws.amazon.com/CVE-2026-64332.html

https://explore.alas.aws.amazon.com/CVE-2026-64333.html

https://explore.alas.aws.amazon.com/CVE-2026-64334.html

https://explore.alas.aws.amazon.com/CVE-2026-64335.html

https://explore.alas.aws.amazon.com/CVE-2026-64340.html

https://explore.alas.aws.amazon.com/CVE-2026-64342.html

https://explore.alas.aws.amazon.com/CVE-2026-64343.html

https://explore.alas.aws.amazon.com/CVE-2026-64344.html

https://explore.alas.aws.amazon.com/CVE-2026-64348.html

https://explore.alas.aws.amazon.com/CVE-2026-64351.html

https://explore.alas.aws.amazon.com/CVE-2026-64359.html

https://explore.alas.aws.amazon.com/CVE-2026-64360.html

https://explore.alas.aws.amazon.com/CVE-2026-64361.html

https://explore.alas.aws.amazon.com/CVE-2026-64362.html

https://explore.alas.aws.amazon.com/CVE-2026-64363.html

https://explore.alas.aws.amazon.com/CVE-2026-64364.html

https://explore.alas.aws.amazon.com/CVE-2026-64370.html

https://explore.alas.aws.amazon.com/CVE-2026-64371.html

https://explore.alas.aws.amazon.com/CVE-2026-64372.html

https://explore.alas.aws.amazon.com/CVE-2026-64373.html

https://explore.alas.aws.amazon.com/CVE-2026-64374.html

https://explore.alas.aws.amazon.com/CVE-2026-64375.html

https://explore.alas.aws.amazon.com/CVE-2026-64378.html

https://explore.alas.aws.amazon.com/CVE-2026-64380.html

https://explore.alas.aws.amazon.com/CVE-2026-64381.html

https://explore.alas.aws.amazon.com/CVE-2026-64411.html

https://explore.alas.aws.amazon.com/CVE-2026-64412.html

https://explore.alas.aws.amazon.com/CVE-2026-64413.html

https://explore.alas.aws.amazon.com/CVE-2026-64422.html

https://explore.alas.aws.amazon.com/CVE-2026-64423.html

https://explore.alas.aws.amazon.com/CVE-2026-64425.html

https://explore.alas.aws.amazon.com/CVE-2026-64435.html

https://explore.alas.aws.amazon.com/CVE-2026-64436.html

https://explore.alas.aws.amazon.com/CVE-2026-64448.html

https://explore.alas.aws.amazon.com/CVE-2026-64450.html

https://explore.alas.aws.amazon.com/CVE-2026-64455.html

https://explore.alas.aws.amazon.com/CVE-2026-64456.html

https://explore.alas.aws.amazon.com/CVE-2026-64465.html

https://explore.alas.aws.amazon.com/CVE-2026-64475.html

https://explore.alas.aws.amazon.com/CVE-2026-64514.html

https://explore.alas.aws.amazon.com/CVE-2026-64534.html

https://explore.alas.aws.amazon.com/CVE-2026-64538.html

https://explore.alas.aws.amazon.com/CVE-2026-64540.html

https://explore.alas.aws.amazon.com/CVE-2026-64544.html

https://explore.alas.aws.amazon.com/CVE-2026-64546.html

https://explore.alas.aws.amazon.com/CVE-2026-64547.html

https://explore.alas.aws.amazon.com/CVE-2026-64548.html

https://explore.alas.aws.amazon.com/CVE-2026-64551.html

https://explore.alas.aws.amazon.com/CVE-2026-64553.html

https://explore.alas.aws.amazon.com/CVE-2026-64560.html

https://explore.alas.aws.amazon.com/CVE-2026-64561.html

https://explore.alas.aws.amazon.com/CVE-2026-64593.html

https://explore.alas.aws.amazon.com/CVE-2026-64604.html

https://explore.alas.aws.amazon.com/CVE-2026-68091.html

https://explore.alas.aws.amazon.com/CVE-2026-68477.html

https://explore.alas.aws.amazon.com/CVE-2026-72010.html

https://explore.alas.aws.amazon.com/CVE-2026-72014.html

https://explore.alas.aws.amazon.com/CVE-2026-72020.html

https://explore.alas.aws.amazon.com/CVE-2026-72021.html

https://explore.alas.aws.amazon.com/CVE-2026-72036.html

https://explore.alas.aws.amazon.com/CVE-2026-72038.html

https://explore.alas.aws.amazon.com/CVE-2026-72039.html

https://explore.alas.aws.amazon.com/CVE-2026-72052.html

https://explore.alas.aws.amazon.com/CVE-2026-72054.html

https://explore.alas.aws.amazon.com/CVE-2026-72055.html

https://explore.alas.aws.amazon.com/CVE-2026-72061.html

https://explore.alas.aws.amazon.com/CVE-2026-72067.html

https://explore.alas.aws.amazon.com/CVE-2026-72068.html

https://explore.alas.aws.amazon.com/CVE-2026-72083.html

https://explore.alas.aws.amazon.com/CVE-2026-72088.html

https://explore.alas.aws.amazon.com/CVE-2026-72102.html

https://explore.alas.aws.amazon.com/CVE-2026-72105.html

https://explore.alas.aws.amazon.com/CVE-2026-72107.html

https://explore.alas.aws.amazon.com/CVE-2026-72108.html

https://explore.alas.aws.amazon.com/CVE-2026-72120.html

https://explore.alas.aws.amazon.com/CVE-2026-72122.html

https://explore.alas.aws.amazon.com/CVE-2026-72129.html

https://explore.alas.aws.amazon.com/CVE-2026-72135.html

https://explore.alas.aws.amazon.com/CVE-2026-72136.html

https://explore.alas.aws.amazon.com/CVE-2026-72138.html

https://explore.alas.aws.amazon.com/CVE-2026-72218.html

https://explore.alas.aws.amazon.com/CVE-2026-72219.html

https://explore.alas.aws.amazon.com/CVE-2026-72223.html

https://explore.alas.aws.amazon.com/CVE-2026-72224.html

https://explore.alas.aws.amazon.com/CVE-2026-72247.html

https://explore.alas.aws.amazon.com/CVE-2026-72250.html

https://explore.alas.aws.amazon.com/CVE-2026-72251.html

https://explore.alas.aws.amazon.com/CVE-2026-72256.html

https://explore.alas.aws.amazon.com/CVE-2026-72282.html

https://explore.alas.aws.amazon.com/CVE-2026-72289.html

https://explore.alas.aws.amazon.com/CVE-2026-72296.html

https://explore.alas.aws.amazon.com/CVE-2026-72307.html

https://explore.alas.aws.amazon.com/CVE-2026-72310.html

https://explore.alas.aws.amazon.com/CVE-2026-72314.html

https://explore.alas.aws.amazon.com/CVE-2026-72316.html

https://explore.alas.aws.amazon.com/CVE-2026-72319.html

https://explore.alas.aws.amazon.com/CVE-2026-72322.html

https://explore.alas.aws.amazon.com/CVE-2026-72326.html

https://explore.alas.aws.amazon.com/CVE-2026-72339.html

https://explore.alas.aws.amazon.com/CVE-2026-72348.html

https://explore.alas.aws.amazon.com/CVE-2026-72349.html

https://explore.alas.aws.amazon.com/CVE-2026-72350.html

https://explore.alas.aws.amazon.com/CVE-2026-72351.html

https://explore.alas.aws.amazon.com/CVE-2026-72396.html

https://explore.alas.aws.amazon.com/CVE-2026-72400.html

https://explore.alas.aws.amazon.com/CVE-2026-72418.html

https://explore.alas.aws.amazon.com/CVE-2026-72421.html

https://explore.alas.aws.amazon.com/CVE-2026-72428.html

https://explore.alas.aws.amazon.com/CVE-2026-72433.html

https://explore.alas.aws.amazon.com/CVE-2026-72435.html

https://explore.alas.aws.amazon.com/CVE-2026-72447.html

https://explore.alas.aws.amazon.com/CVE-2026-72450.html

https://explore.alas.aws.amazon.com/CVE-2026-72476.html

https://explore.alas.aws.amazon.com/CVE-2026-72502.html

https://explore.alas.aws.amazon.com/CVE-2026-74255.html

https://explore.alas.aws.amazon.com/CVE-2026-74256.html

https://explore.alas.aws.amazon.com/CVE-2026-74262.html

https://explore.alas.aws.amazon.com/CVE-2026-74267.html

https://explore.alas.aws.amazon.com/CVE-2026-74279.html

https://explore.alas.aws.amazon.com/CVE-2026-74282.html

https://explore.alas.aws.amazon.com/CVE-2026-74283.html

https://explore.alas.aws.amazon.com/CVE-2026-74284.html

https://explore.alas.aws.amazon.com/CVE-2026-74287.html

https://explore.alas.aws.amazon.com/CVE-2026-74288.html

https://explore.alas.aws.amazon.com/CVE-2026-74297.html

https://explore.alas.aws.amazon.com/CVE-2026-74321.html

https://explore.alas.aws.amazon.com/CVE-2026-74330.html

https://explore.alas.aws.amazon.com/CVE-2026-74331.html

https://explore.alas.aws.amazon.com/CVE-2026-74382.html

https://explore.alas.aws.amazon.com/CVE-2026-74384.html

https://explore.alas.aws.amazon.com/CVE-2026-74394.html

https://explore.alas.aws.amazon.com/CVE-2026-74395.html

https://explore.alas.aws.amazon.com/CVE-2026-74398.html

https://explore.alas.aws.amazon.com/CVE-2026-74416.html

https://explore.alas.aws.amazon.com/CVE-2026-74578.html

https://explore.alas.aws.amazon.com/CVE-2026-80603.html

https://explore.alas.aws.amazon.com/CVE-2026-80604.html

https://explore.alas.aws.amazon.com/CVE-2026-80605.html

https://explore.alas.aws.amazon.com/CVE-2026-80622.html

https://explore.alas.aws.amazon.com/CVE-2026-80630.html

https://explore.alas.aws.amazon.com/CVE-2026-80646.html

https://explore.alas.aws.amazon.com/CVE-2026-80659.html

https://explore.alas.aws.amazon.com/CVE-2026-80664.html

https://explore.alas.aws.amazon.com/CVE-2026-80677.html

https://explore.alas.aws.amazon.com/CVE-2026-80867.html

https://explore.alas.aws.amazon.com/CVE-2026-80875.html

https://explore.alas.aws.amazon.com/CVE-2026-80876.html

插件详情

严重性: High

ID: 337224

文件名: al2_ALASKERNEL-5_10-2026-129.nasl

版本: 1.7

类型: Local

代理: unix

发布时间: 2026/8/18

最近更新时间: 2026/9/10

支持的传感器: Frictionless Assessment AWS, Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Continuous Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

风险信息

VPR

风险因素: High

分数: 8

百分位: 99.69

CVSS v2

风险因素: Medium

基本分数: 6.8

时间分数: 5.3

矢量: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS 分数来源: CVE-2026-64381

CVSS v3

风险因素: High

基本分数: 7.8

时间分数: 7

矢量: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

时间矢量: CVSS:3.0/E:P/RL:O/RC:C

漏洞信息

CPE: cpe:/o:amazon:linux:2, p-cpe:/a:amazon:linux:bpftool-debuginfo, p-cpe:/a:amazon:linux:bpftool, p-cpe:/a:amazon:linux:kernel-debuginfo-common-aarch64, p-cpe:/a:amazon:linux:kernel-debuginfo-common-x86_64, p-cpe:/a:amazon:linux:kernel-debuginfo, p-cpe:/a:amazon:linux:kernel-devel, p-cpe:/a:amazon:linux:kernel-headers, p-cpe:/a:amazon:linux:kernel-livepatch-5.10.262-262.1063, p-cpe:/a:amazon:linux:kernel-tools-debuginfo, p-cpe:/a:amazon:linux:kernel-tools-devel, p-cpe:/a:amazon:linux:kernel-tools, p-cpe:/a:amazon:linux:kernel, p-cpe:/a:amazon:linux:perf-debuginfo, p-cpe:/a:amazon:linux:perf, p-cpe:/a:amazon:linux:python-perf-debuginfo, p-cpe:/a:amazon:linux:python-perf

必需的 KB 项: Host/local_checks_enabled, Host/AmazonLinux/release, Host/AmazonLinux/rpm-list

可利用: true

易利用性: Exploits are available

补丁发布日期: 2026/8/17

漏洞发布日期: 2026/5/6

参考资料信息

CVE: CVE-2026-43216, CVE-2026-43329, CVE-2026-46135, CVE-2026-52942, CVE-2026-53388, CVE-2026-53392, CVE-2026-53393, CVE-2026-53399, CVE-2026-53400, CVE-2026-53402, CVE-2026-63803, CVE-2026-63806, CVE-2026-63826, CVE-2026-63829, CVE-2026-63830, CVE-2026-64015, CVE-2026-64189, CVE-2026-64266, CVE-2026-64276, CVE-2026-64296, CVE-2026-64298, CVE-2026-64299, CVE-2026-64306, CVE-2026-64312, CVE-2026-64313, CVE-2026-64317, CVE-2026-64322, CVE-2026-64323, CVE-2026-64324, CVE-2026-64332, CVE-2026-64333, CVE-2026-64334, CVE-2026-64335, CVE-2026-64340, CVE-2026-64342, CVE-2026-64343, CVE-2026-64344, CVE-2026-64348, CVE-2026-64351, CVE-2026-64359, CVE-2026-64360, CVE-2026-64361, CVE-2026-64362, CVE-2026-64363, CVE-2026-64364, CVE-2026-64370, CVE-2026-64371, CVE-2026-64372, CVE-2026-64373, CVE-2026-64374, CVE-2026-64375, CVE-2026-64378, CVE-2026-64380, CVE-2026-64381, CVE-2026-64411, CVE-2026-64412, CVE-2026-64413, CVE-2026-64422, CVE-2026-64423, CVE-2026-64425, CVE-2026-64435, CVE-2026-64436, CVE-2026-64448, CVE-2026-64450, CVE-2026-64455, CVE-2026-64456, CVE-2026-64465, CVE-2026-64475, CVE-2026-64514, CVE-2026-64534, CVE-2026-64538, CVE-2026-64540, CVE-2026-64544, CVE-2026-64546, CVE-2026-64547, CVE-2026-64548, CVE-2026-64551, CVE-2026-64553, CVE-2026-64560, CVE-2026-64561, CVE-2026-64593, CVE-2026-64604, CVE-2026-68091, CVE-2026-68477, CVE-2026-72010, CVE-2026-72014, CVE-2026-72020, CVE-2026-72021, CVE-2026-72036, CVE-2026-72038, CVE-2026-72039, CVE-2026-72052, CVE-2026-72054, CVE-2026-72055, CVE-2026-72061, CVE-2026-72067, CVE-2026-72068, CVE-2026-72083, CVE-2026-72088, CVE-2026-72102, CVE-2026-72105, CVE-2026-72107, CVE-2026-72108, CVE-2026-72120, CVE-2026-72122, CVE-2026-72129, CVE-2026-72135, CVE-2026-72136, CVE-2026-72138, CVE-2026-72218, CVE-2026-72219, CVE-2026-72223, CVE-2026-72224, CVE-2026-72247, CVE-2026-72250, CVE-2026-72251, CVE-2026-72256, CVE-2026-72282, CVE-2026-72289, CVE-2026-72296, CVE-2026-72307, CVE-2026-72310, CVE-2026-72314, CVE-2026-72316, CVE-2026-72319, CVE-2026-72322, CVE-2026-72326, CVE-2026-72339, CVE-2026-72348, CVE-2026-72349, CVE-2026-72350, CVE-2026-72351, CVE-2026-72396, CVE-2026-72400, CVE-2026-72418, CVE-2026-72421, CVE-2026-72428, CVE-2026-72433, CVE-2026-72435, CVE-2026-72447, CVE-2026-72450, CVE-2026-72476, CVE-2026-72502, CVE-2026-74255, CVE-2026-74256, CVE-2026-74262, CVE-2026-74267, CVE-2026-74279, CVE-2026-74282, CVE-2026-74283, CVE-2026-74284, CVE-2026-74287, CVE-2026-74288, CVE-2026-74297, CVE-2026-74321, CVE-2026-74330, CVE-2026-74331, CVE-2026-74382, CVE-2026-74384, CVE-2026-74394, CVE-2026-74395, CVE-2026-74398, CVE-2026-74416, CVE-2026-74578, CVE-2026-80603, CVE-2026-80604, CVE-2026-80605, CVE-2026-80622, CVE-2026-80630, CVE-2026-80646, CVE-2026-80659, CVE-2026-80664, CVE-2026-80677, CVE-2026-80867, CVE-2026-80875, CVE-2026-80876