Amazon Linux 2 : rust、--advisory ALAS2-2026-3865 (ALAS-2026-3865)

low Nessus 插件 ID 337227

简介

远程 Amazon Linux 2 主机缺少安全更新。

描述

远程主机上安装的 rust 版本低于 1.97.0-2。因此,该软件受到 ALAS2-2026-3865 公告中提及的多个漏洞影响。

RustCrypto CMOV 提供有条件的移动 CPU 内部函数,保证在主要平台上以恒定时间执行,并且不会被编译器重写为分支。从 0.1.10.5.4till 开始,cmov/src/backends/aarch64.rs 中 Cmov 和 CmovEq 的 aarch64 实现假设高位在加载小于寄存器的值时为零扩展,因此设置高位(例如 Cmov 选择器中的 [8..])或 u16 和 i16 CmovEq 实现中的 self 或其他的 [16..] 可导致 left.cmovz(&right, condition) 产生错误的输出。此问题已在 0.5.4 版本中修复。(CVE-2026-50185)

OpenSSL 后端中的 libgit2 反向 IP SubjectAltName 比较 ( vuln_1_1_1 ) (CVE-2026-53583)

libgit2 子模块路径遍历 (CVE-2026-53584)

通过增量对象 Result-Size 标头 (CVE-2026-53585) 进行的不受限制的内存分配

libgit2 的内置 HTTP 传输默认遵循初始智能 HTTP 请求的异地重定向。
如果重定向的服务器随后返回 401 Unauthorized,libgit2 会使用原始远程 URL(而非重定向 URL)向应用程序凭据回调要求凭据。返回的凭据随后会作为授权标头附加到对重定向主机的下一个请求中。(CVE-2026-53586)

libgit2 和更低版本 1.9.4 容易受到 src/libgit2/transports/smart_pkt.c 内 set_data() 中堆越界读取的影响。

易受攻击的代码针对智能协议 pkt-line 的未经验证的功能缓冲区使用固定大小的 strncmp (smart_pkt.c:239)。当连续接收缓冲区中 pkt-line 之后的字节碰巧继续使用 ct-format= 时,比较将发生虚假匹配,进format_str超过 pkt-line 边界。然后,以下 memchr(format_str, ' ', len - (format_str - line)) (smart_pkt.c:246) 将其size_t大小参数下溢至 ~SIZE_MAX,并遍历堆以寻找空格字节。控制(或中间人)通过 HTTP/HTTPS/SSH/git:// 连接的 Git 服务器的未经身份验证的远程攻击者可在发生任何功能协商之前,在 refs 公告的第一个 ref-pkt 上触发此操作。OOB walk 在 memchr 进入未映射的页面时导致进程崩溃 (SIGSEGV),并且在 memchr 在崩溃前发现零散空间字节的堆布局上,还可额外驱动 git_error_set(...'%.*s'、format_len、format_str) 格式化程序将大型堆内存窗口复制到错误字符串中。(CVE-2026-53587)

Tenable 已直接从测试产品的安全公告中提取上述描述块。

请注意,Nessus 尚未测试这些问题,而是只依据应用程序自我报告的版本号进行判断。

解决方案

运行“yum update rust”或“yum update --advisory ALAS2-2026-3865”以更新系统。

另见

https://alas.aws.amazon.com//AL2/ALAS2-2026-3865.html

https://alas.aws.amazon.com/faqs.html

https://explore.alas.aws.amazon.com/CVE-2026-50185.html

https://explore.alas.aws.amazon.com/CVE-2026-53583.html

https://explore.alas.aws.amazon.com/CVE-2026-53584.html

https://explore.alas.aws.amazon.com/CVE-2026-53585.html

https://explore.alas.aws.amazon.com/CVE-2026-53586.html

https://explore.alas.aws.amazon.com/CVE-2026-53587.html

插件详情

严重性: Low

ID: 337227

文件名: al2_ALAS-2026-3865.nasl

版本: 1.2

类型: Local

代理: unix

发布时间: 2026/8/18

最近更新时间: 2026/8/20

支持的传感器: Frictionless Assessment AWS, Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Continuous Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

风险信息

VPR

风险因素: Medium

分数: 4.3

百分位: 53.53

CVSS v2

风险因素: Medium

基本分数: 5.8

时间分数: 4.5

矢量: CVSS2#AV:N/AC:M/Au:N/C:P/I:N/A:P

CVSS 分数来源: CVE-2026-53587

CVSS v3

风险因素: Critical

基本分数: 9.1

时间分数: 8.2

矢量: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

时间矢量: CVSS:3.0/E:P/RL:O/RC:C

CVSS v4

风险因素: Low

Base Score: 2

Threat Score: 1.1

Threat Vector: CVSS:4.0/E:P

Vector: CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N

CVSS 分数来源: CVE-2026-50185

漏洞信息

CPE: cpe:/o:amazon:linux:2, p-cpe:/a:amazon:linux:cargo, p-cpe:/a:amazon:linux:clippy, p-cpe:/a:amazon:linux:rust-analyzer, p-cpe:/a:amazon:linux:rust-debugger-common, p-cpe:/a:amazon:linux:rust-doc, p-cpe:/a:amazon:linux:rust-gdb, p-cpe:/a:amazon:linux:rust-src, p-cpe:/a:amazon:linux:rust-std-static, p-cpe:/a:amazon:linux:rust-toolset-srpm-macros, p-cpe:/a:amazon:linux:rust-toolset, p-cpe:/a:amazon:linux:rust, p-cpe:/a:amazon:linux:rustfmt

必需的 KB 项: Host/local_checks_enabled, Host/AmazonLinux/release, Host/AmazonLinux/rpm-list

可利用: true

易利用性: Exploits are available

补丁发布日期: 2026/8/17

漏洞发布日期: 2026/7/2

参考资料信息

CVE: CVE-2026-50185, CVE-2026-53583, CVE-2026-53584, CVE-2026-53585, CVE-2026-53586, CVE-2026-53587