Amazon Linux 2023:bpftool6.18、kernel6.18、kernel6.18-devel (ALAS2023-2026-2106)

high Nessus 插件 ID 341888

语言:

简介

远程 Amazon Linux 2023 主机缺少安全更新。

描述

因此,该软件受到 ALAS2023-2026-2106 公告中提及的多个漏洞影响。

在 Linux 内核中,以下漏洞已修复:

netfilter:nft_counter:使用旋转锁 (CVE-2026-45897) 序列化重置

在 Linux 内核中,以下漏洞已修复:

netfilter:nf_tables:恢复重置路径 (CVE-2026-45901) 中的commit_mutex使用情况

在 Linux 内核中,以下漏洞已修复:

bpf:修复 subprogs (CVE-2026-53090) 中的 ld_{abs,ind} 故障路径分析

在 Linux 内核中,以下漏洞已修复:

net/handshake:耗尽 net 命名空间 exit (CVE-2026-63978) 处的待定请求

在 Linux 内核中,以下漏洞已修复:

net/handshake:将固定文件引用移交给 accept_doit (CVE-2026-63979)

在 Linux 内核中,以下漏洞已修复:

blk-mq:弹出缓存的请求(如果可用CVE-2026-64017)()

在 Linux 内核中,以下漏洞已修复:

KVM:guest_memfd:将内存插槽绑定偏移+大小视为无符号值 (CVE-2026-64283)

在 Linux 内核中,以下漏洞已修复:

net/handshake:在 submit (CVE-2026-64523) 时获取长期限文件引用

在 Linux 内核中,以下漏洞已修复:

KVM:nVMX:在 VMCLEAR (CVE-2026-64562) 之后隐藏阴影 VMCS

在 Linux 内核中,以下漏洞已修复:

rhashtable:清除表重新启动 (CVE-2026-64563) 上过时的 iter->p

在 Linux 内核中,以下漏洞已修复:

sctp:不释放 DEL-IP 处理中 ASCONF 自己的传输 (CVE-2026-64564)

在 Linux 内核中,以下漏洞已修复:

btrfs:拒绝条目多于页面 (CVE-2026-64567) 的可用空间缓存

在 Linux 内核中,以下漏洞已修复:

ipv4:fib:通过插入错误路径 (CVE-2026-64572) 上的 kfree_rcu() 释放fib_alias

在 Linux 内核中,以下漏洞已修复:

bpf:tcp:修复批次 realloc (CVE-2026-64575) 上的双重 sock 释放

在 Linux 内核中,以下漏洞已修复:

nexthop:初始化 nh_res_bucket_migrate() 中的 extack (CVE-2026-64576)

在 Linux 内核中,以下漏洞已修复:

xfrm:policy:重新插入 xfrm_hash_rebuild 前预先分配不准确的 bin (CVE-2026-64579)

在 Linux 内核中,以下漏洞已修复:

xfrm6:清除错误 dst.dev 以避免 xfrm6_fill_dst() (CVE-2026-64580) 中的双重netdev_put

在 Linux 内核中,以下漏洞已修复:

xfrm:修复 xfrm_user_policy() (CVE-2026-64581) 中的sk_dst_cache双重释放

在 Linux 内核中,以下漏洞已修复:

KVM:SVM:在 CPU 在线时升级 asid_generation,以避免热插拔 (CVE-2026-68093) 后发生 ASID 冲突

在 Linux 内核中,以下漏洞已修复:

fuse-uring:修复注册和连接中止之间的争用 (CVE-2026-68095)

在 Linux 内核中,以下漏洞已修复:

audit:修复 audit_dupe_exe() 中的递归锁定死锁 (CVE-2026-68096)

在 Linux 内核中,以下漏洞已修复:

vxlan:mdb:修复失败的替换 (CVE-2026-68116) 的源列表损坏

在 Linux 内核中,以下漏洞已修复:

tipc:清除 tipc_sk_create()CVE-2026-68117 () 中 failed-insert 路径上的 sock->sk

在 Linux 内核中,以下漏洞已修复:

tcp:质询 SYN-RECEIVED (CVE-2026-68118) 中非精确 RST 的 ACK

在 Linux 内核中,以下漏洞已修复:

pppoe:在 dev_hard_header() () 之后CVE-2026-68121重新加载标头指针

在 Linux 内核中,以下漏洞已修复:

openvswitch:修复 GSO 用户空间截断下溢 (CVE-2026-68123)

在 Linux 内核中,以下漏洞已修复:

ila:在校验和调整 (CVE-2026-68127) 中pskb_may_pull后重新加载 IPv6 标头

在 Linux 内核中,以下漏洞已修复:

ice:拒绝 ice_parser_profile_init 中的超出范围 ptype (CVE-2026-68128)

在 Linux 内核中,以下漏洞已修复:

rbd:将对象映射更新路径 (CVE-2026-68131) 中的正面结果代码重置为零

在 Linux 内核中,以下漏洞已修复:

super:修复冻结区块设备中的紧急解冻死锁 (CVE-2026-68132)

在 Linux 内核中,以下漏洞已修复:

ice:修复 PTP 版本期间的 PTP 调用跟踪 (CVE-2026-68133)

在 Linux 内核中,以下漏洞已修复:

net:gro:修复刷新标记的 skbs 的双重聚合 (CVE-2026-68136)

在 Linux 内核中,以下漏洞已修复:

net/sched:针对并发 get/put () 序列化 qdisc_rtab_listCVE-2026-68138

在 Linux 内核中,以下漏洞已修复:

net/mlx5e:将发送方 devcom 用于 MPV master-up (CVE-2026-68139)

在 Linux 内核中,以下漏洞已修复:

geneve:需要设备 netns 中的CAP_NET_ADMIN用于 changelink (CVE-2026-68142)

在 Linux 内核中,以下漏洞已修复:

iomap:修复具有零长度范围 (CVE-2026-68145) 的越界 bitmap_set()

在 Linux 内核中,以下漏洞已修复:

ftrace:添加全局互斥体以序列化 trace_parser 访问 (CVE-2026-68146)

在 Linux 内核中,以下漏洞已修复:

fs:在 forget_cached_acl() (CVE-2026-68149) 中保留 ACL_DONT_CACHE 状态

在 Linux 内核中,以下漏洞已修复:

fs/super:修复 s_umount 的紧急解冻双重解锁 (CVE-2026-68150)

在 Linux 内核中,以下漏洞已修复:

libceph:客户端拆卸前删除 debugfs 文件 (CVE-2026-68153)

在 Linux 内核中,以下漏洞已修复:

libceph:拒绝 crush_decode (CVE-2026-68154) 中的零存储桶类型

在 Linux 内核中,以下漏洞已修复:

libceph:拒绝公告零监控器的 monmaps (CVE-2026-68155)

在 Linux 内核中,以下漏洞已修复:

libceph:授权者更新CVE-2026-68156后刷新 auth->authorizer_buf{,_len}

在 Linux 内核中,以下漏洞已修复:

libceph:保护缺少的 CRUSH 类型名称查找 (CVE-2026-68157)

在 Linux 内核中,以下漏洞已修复:

libceph:修复 decode_new_up_state_weight() (CVE-2026-68158) 中的乘法溢出

在 Linux 内核中,以下漏洞已修复:

ceph:修复 ceph_handle_caps() (CVE-2026-68160) 中 snaptrace 上的预认证越界读取

在 Linux 内核中,以下漏洞已修复:

sctp:netns 拆卸期间关闭 UDP 隧道套接字 (CVE-2026-68161)

在 Linux 内核中,以下漏洞已修复:

sctp:避免在 netns 拆卸期间auth_enable sysctl UAF (CVE-2026-68162)

在 Linux 内核中,以下漏洞已修复:

mm/damon/core:不允许 damon_set_regions()CVE-2026-68164 () 的重叠输入范围

在 Linux 内核中,以下漏洞已修复:

mm/damon/core:验证 damon_set_regions() (CVE-2026-68165) 中的范围

在 Linux 内核中,以下漏洞已修复:

userfaultfd:阻止注册特殊 VMA (CVE-2026-68166)

在 Linux 内核中,以下漏洞已修复:

mptcp:pm:userspace:修复 get_local_id 中的释放后使用 (CVE-2026-68169)

在 Linux 内核中,以下漏洞已修复:

tracing:修复动态事件的模块与 refcnt 的 union 冲突 (CVE-2026-68174)

在 Linux 内核中,以下漏洞已修复:

misc:nsm:设备开启时固定模块 (CVE-2026-68178)

在 Linux 内核中,以下漏洞已修复:

misc:nsm:仅解锁锁定后错误路径上的nsm_dev (CVE-2026-68179)

在 Linux 内核中,以下漏洞已修复:

cdrom:修复 CDROMVOLCTRL (CVE-2026-68184) 中的堆栈越界读取

在 Linux 内核中,以下漏洞已修复:

binfmt_misc:仅在打开解释器时设置 have_execfd (CVE-2026-68186)

在 Linux 内核中,以下漏洞已修复:

drm/ttm:考虑 NULL 并处理 ttm_pool_backup 中的页面 (CVE-2026-68239)

在 Linux 内核中,以下漏洞已修复:

drm/i915/mst:限制 DP MST ESI 服务循环 (CVE-2026-68241)

在 Linux 内核中,以下漏洞已修复:

drm/i915/gem:修复 I915_CONTEXT_PARAM_SSEU 中的空取消引用 (CVE-2026-68243)

在 Linux 内核中,以下漏洞已修复:

drm/i915/gem:不泄漏原始上下文错误 (CVE-2026-68244) 的 siblings[]

在 Linux 内核中,以下漏洞已修复:

drm/i915/bios:范围检查 LFP 数据块 panel_type2 (CVE-2026-68247)

在 Linux 内核中,以下漏洞已修复:

drm/i915:active_instance () 中出错时返回 NULLCVE-2026-68248

在 Linux 内核中,以下漏洞已修复:

drm/i915/hdcp:在溢出前检查 streams[] 边界 (CVE-2026-68253)

在 Linux 内核中,以下漏洞已修复:

drm/i915/vrr:需要适用于 VRR 的有效最小/最大 vfreq (CVE-2026-68254)

在 Linux 内核中,以下漏洞已修复:

drm/virtio:将 EDID 块读取绑定到响应缓冲区 (CVE-2026-68255)

在 Linux 内核中,以下漏洞已修复:

drm/i915/gem:添加并行提交槽 (CVE-2026-68269) 上缺失的 nospec

在 Linux 内核中,以下漏洞已修复:

drm/sysfb:避免通过计算可见大小 (CVE-2026-68270) 可能的截断

在 Linux 内核中,以下漏洞已修复:

drm/dp/mst:修复边带回复解析器 (CVE-2026-68277) 中 2 字节字段上的 OOB 读取

在 Linux 内核中,以下漏洞已修复:

drm/dp/mst:修复边带区块累积 (CVE-2026-68278) 中的缓冲区溢出

在 Linux 内核中,以下漏洞已修复:

drm/dp/mst:修复远程 DPCD/I2C 边带回复解析器中的 OOB 读取 (CVE-2026-68279)

在 Linux 内核中,以下漏洞已修复:

bpf、sockmap:修复 tcp_bpf_sendmsg() 中的软木塞释放后使用 (CVE-2026-68284)

在 Linux 内核中,以下漏洞已修复:

rds:tcp:拆除监听套接字 (CVE-2026-68290) 之前取消注册 sysctl

在 Linux 内核中,以下漏洞已修复:

ice:防止为非 PF VSI 类型分配 tstamp 环 (CVE-2026-68292)

在 Linux 内核中,以下漏洞已修复:

net/mlx5:修复 32 dword 读取 (CVE-2026-68293) 中的 MCIA 寄存器缓冲区溢出

在 Linux 内核中,以下漏洞已修复:

net:gre:修复具有 SEQ/CSUM (CVE-2026-68296) 的 GRE 隧道的 lltx 回归

在 Linux 内核中,以下漏洞已修复:

tipc:修复媒体和承载 MTU 验证中的 u16 MTU 截断 (CVE-2026-68297)

在 Linux 内核中,以下漏洞已修复:

vmxnet3:修复 Geneve 数据包 (CVE-2026-68299) 的 vmxnet3_get_hdr_len() 中的BUG_ON

在 Linux 内核中,以下漏洞已修复:

sctp: auth:验证 auth_chunk 为 NULL 时的认证要求 (CVE-2026-68300)

在 Linux 内核中,以下漏洞已修复:

tipc:修复 __tipc_nl_compat_dumpit (CVE-2026-68313) 中的无限循环

在 Linux 内核中,以下漏洞已修复:

sctp:验证 sctp_process_strreset_inreq() 中的流计数 (CVE-2026-68315)

在 Linux 内核中,以下漏洞已修复:

sctp:修复 sctp_auth_ep_add_chunkid (CVE-2026-68320) 中的auth_chunk_list容量检查

在 Linux 内核中,以下漏洞已修复:

rds:修复禁用 IPv6 时inet6_addr_lst空取消引用 (CVE-2026-68322)

在 Linux 内核中,以下漏洞已修复:

iommu/amd:绑定早期 ACPI HID 映射 (CVE-2026-68325)

在 Linux 内核中,以下漏洞已修复:

iommu/amd:在 iommu_completion_wait() (CVE-2026-68329) 中等待完成而非提早返回

在 Linux 内核中,以下漏洞已修复:

rds:丢弃跨网络命名空间边界的传入消息 (CVE-2026-68335)

在 Linux 内核中,以下漏洞已修复:

bonding:修复禁用 IPv6 时devconf_all空取消引用 (CVE-2026-68336)

在 Linux 内核中,以下漏洞已修复:

net/packet:避免 unregister (CVE-2026-68338) 之后的扇出挂钩重新注册

在 Linux 内核中,以下漏洞已修复:

smb:客户端:验证 DFS 参照 PathConsumed (CVE-2026-68343)

在 Linux 内核中,以下漏洞已修复:

usb:core:sysfs:向 bos_descriptors_read() 添加锁 (CVE-2026-68374)

在 Linux 内核中,以下漏洞已修复:

sctp:修复 struct sctp_cookie 中的 auth_hmacs 数组大小 (CVE-2026-68376)

在 Linux 内核中,以下漏洞已修复:

dpll:修复 dpll_msg_add_pin_ref_sync() 中的空指针取消引用 (CVE-2026-68378)

在 Linux 内核中,以下漏洞已修复:

bpf、sockmap:拒绝 sockmap 更新 (CVE-2026-68386) 中未散列的 UDP 套接字

在 Linux 内核中,以下漏洞已修复:

can:raw:添加原始标记 bitfield (CVE-2026-68387) 的锁定

在 Linux 内核中,以下漏洞已修复:

smb/client:处理 fallocate (CVE-2026-68388) 中重叠的已分配范围

在 Linux 内核中,以下漏洞已修复:

scsi:core:使用 scsi_schedule_eh (CVE-2026-68396) 时可靠地唤醒 eh

在 Linux 内核中,以下漏洞已修复:

firmware:arm_ffa:修复端点内存访问描述符偏移计算 (CVE-2026-68400)

在 Linux 内核中,以下漏洞已修复:

firmware:arm_ffa:修复 ffa_setup_and_transmit() 中的越界写入 (CVE-2026-68401)

在 Linux 内核中,以下漏洞已修复:

mtd:修复 add_mtd_device() 错误路径 (CVE-2026-68416) 中的双重释放和WARN_ON

在 Linux 内核中,以下漏洞已修复:

xfrm:拒绝出站策略中的可选 IPTFS 模板 (CVE-2026-68420)

在 Linux 内核中,以下漏洞已修复:

sched_ext:不就 put_prev_task_scx()CVE-2026-68421 中的 core-sched 强制空闲发出警告

在 Linux 内核中,以下漏洞已修复:

btrfs:修复在 merge_reloc_roots()CVE-2026-68422 () 中非预期的 reloc 根时的根泄漏

在 Linux 内核中,以下漏洞已修复:

IB/mad:重组前终止不匹配的 RMPP 响应 (CVE-2026-68425)

在 Linux 内核中,以下漏洞已修复:

xfrm:异步加密窃取 GSO 段 (CVE-2026-68426) 后修复过时的 skb->prev

在 Linux 内核中,以下漏洞已修复:

KVM:x86/mmu:修复供应商模块重新加载时的释放后使用 (CVE-2026-68428)

在 Linux 内核中,以下漏洞已修复:

drm/dp_mst:在 drm_dp_mst_topology_queue_probe() (CVE-2026-68429) 中妥善处理拆散的拓扑

在 Linux 内核中,以下漏洞已修复:

vxlan:需要设备 netns 中的CAP_NET_ADMIN用于 changelink (CVE-2026-68432)

在 Linux 内核中,以下漏洞已修复:

libceph:绑定get_version回复解码到前 len (CVE-2026-68433)

在 Linux 内核中,以下漏洞已修复:

btrfs:不将EXTENT_FLAG_LOGGING传播至拆分盘区映射 (CVE-2026-68442)

在 Linux 内核中,以下漏洞已修复:

firmware:arm_ffa:修复 ffa_partition_info_get() 中的空取消引用 (CVE-2026-68444)

在 Linux 内核中,以下漏洞已修复:

drm/vmwgfx: 验证 vmw_surface_metadata::array_size (CVE-2026-68446)

在 Linux 内核中,以下漏洞已修复:

ovl:通过 src 挂载程序 creds (CVE-2026-68448) 检查对copy_file_range源的访问

在 Linux 内核中,以下漏洞已修复:

btrfs:在重复的 reloc 根插入 (CVE-2026-68450) 中释放映射节点

在 Linux 内核中,以下漏洞已修复:

x86/缺陷:使 Safe-RET 加强防御中断注入 (CVE-2026-68480)

在 Linux 内核中,以下漏洞已修复:

ata:libata-core:拒绝无效的并发定位范围 count (CVE-2026-72030)

在 Linux 内核中,以下漏洞已修复:

dm:避免通过表设备文件 (CVE-2026-72103) 泄漏调用程序的线程 keyring

在 Linux 内核中,以下漏洞已修复:

can:bcm:添加缺失的设备引用计数以进行 CAN 过滤器删除 (CVE-2026-72113)

在 Linux 内核中,以下漏洞已修复:

can:bcm:验证 RTR 回复的 bcm_rx_setup() 中的帧长度 (CVE-2026-72114)

在 Linux 内核中,以下漏洞已修复:

can:bcm:跟踪 ANYDEV 超时/节流操作的单一源接口 (CVE-2026-72115)

在 Linux 内核中,以下漏洞已修复:

can:bcm:修复设备删除后过时的 rx/tx ops (CVE-2026-72116)

在 Linux 内核中,以下漏洞已修复:

can:bcm:修复 bcm_rx_handler()CVE-2026-72117 () 中 rx_stamp/rx_ifindex 上的数据争用

在 Linux 内核中,以下漏洞已修复:

can:bcm:修复 CAN 帧 rx/tx 统计数据 (CVE-2026-72118)

在 Linux 内核中,以下漏洞已修复:

can:bcm:扩展数据和定时器更新的 bcm_tx_lock 使用 (CVE-2026-72119)

在 Linux 内核中,以下漏洞已修复:

can:bcm:更新过滤器和定时器值时添加锁定 (CVE-2026-72121)

在 Linux 内核中,以下漏洞已修复:

fs/proc/task_mmu:修复 make_uffd_wp_huge_pte() prot-update 争用 (CVE-2026-72175)

在 Linux 内核中,以下漏洞已修复:

gpu/buddy:无法遵守对齐时退出try_harder (CVE-2026-72244)

在 Linux 内核中,以下漏洞已修复:

netfilter:nf_conntrack_sip:访问 skb_dst() 前先对其进行验证 (CVE-2026-72253)

在 Linux 内核中,以下漏洞已修复:

netfilter:nft_fib:拒绝 netdev 出口挂钩上的 fib 表达式 (CVE-2026-72254)

在 Linux 内核中,以下漏洞已修复:

drm/vmwgfx:避免 vkms init 失败 (CVE-2026-74442) 时 destroy_workqueue(NULL)

在 Linux 内核中,以下漏洞已修复:

drm/vmwgfx:根据后缀指针 (CVE-2026-74443) 限制 DMA 命令正文大小

在 Linux 内核中,以下漏洞已修复:

drm/vmwgfx:在 division () 之前验证 DRAW_PRIMITIVES 标CVE-2026-74444头大小

在 Linux 内核中,以下漏洞已修复:

drm/vmwgfx:拒绝没有 DX 上下文 (CVE-2026-74445) 的DX_BIND_QUERY

在 Linux 内核中,以下漏洞已修复:

net:openvswitch:修复 ct (CVE-2026-74464) 期间流密钥更新失败时的 skb 泄漏

在 Linux 内核中,以下漏洞已修复:

net:openvswitch:修复仪表连接失败 (CVE-2026-74465) 中潜在的 UAF

在 Linux 内核中,以下漏洞已修复:

sctp:防止对等机传输计数溢出 (CVE-2026-74469)

在 Linux 内核中,以下漏洞已修复:

tracing:检查 trace_module_add_events()CVE-2026-74471 中 __register_event() 的返回值

在 Linux 内核中,以下漏洞已修复:

vxlan:在 route_shortcircuit()CVE-2026-74473 中使用 pskb_network_may_pull()

在 Linux 内核中,以下漏洞已修复:

vxlan:将 pskb_network_may_pull() 用于传输路径标头 pulls (CVE-2026-74474)

在 Linux 内核中,以下漏洞已修复:

vxlan:在 route_shortcircuit()CVE-2026-74475 中使用 neigh_ha_snapshot()

在 Linux 内核中,以下漏洞已修复:

veth:运行 XDP 之前转换frag_list skbs (CVE-2026-74476)

在 Linux 内核中,以下漏洞已修复:

uprobes:修复 hprobe_expire() 中的空指针取消引用 (CVE-2026-74477)

在 Linux 内核中,以下漏洞已修复:

net:bridge:删除端口组后停止快速离开 (CVE-2026-74480)

在 Linux 内核中,以下漏洞已修复:

mm/page_reporting:使用 system_freezable_wq 修复暂停期间的 UAF (CVE-2026-74481)

在 Linux 内核中,以下漏洞已修复:

mm/huge_memory:释放拆分后作品集 () 之前解锁 i_mmap_rwsemCVE-2026-74482

在 Linux 内核中,以下漏洞已修复:

binfmt_misc:不让“F”条目固定其自己的实例 (CVE-2026-74484)

在 Linux 内核中,以下漏洞已修复:

binfmt_misc:拒绝将标记字符作为字段分隔符 (CVE-2026-74485)

在 Linux 内核中,以下漏洞已修复:

binfmt_misc:将 exe_file_deny_write_access() 用于解释器 clone (CVE-2026-74486)

在 Linux 内核中,以下漏洞已修复:

binfmt_misc:还原删除条目 (CVE-2026-74487) 时的写入权限

在 Linux 内核中,以下漏洞已修复:

tipc:避免轮询跟踪队列转储 (CVE-2026-74490) 中的释放后使用

在 Linux 内核中,以下漏洞已修复:

of/address:修复 of_pci_range_parser_one() 中的空总线取消引用 (CVE-2026-74491)

在 Linux 内核中,以下漏洞已修复:

netfilter:ipset:不更新来自内核端哈希添加 (CVE-2026-74492) 的注释

在 Linux 内核中,以下漏洞已修复:

audit:修复 audit_del_rule() (CVE-2026-74512) 中潜在的释放后使用

在 Linux 内核中,以下漏洞已修复:

KVM:SVM:如果 Aic 在 L2 启用时受到禁止,则更新 x2APIC MSR 拦截 (CVE-2026-74516)

在 Linux 内核中,以下漏洞已修复:

mm/hugetlb:修复 allocate_file_region_entries() (CVE-2026-74518) 中的列表损坏

在 Linux 内核中,以下漏洞已修复:

pinctrl:devicetree:不释放错误路径 (CVE-2026-74519) 上的未初始化dev_name

在 Linux 内核中,以下漏洞已修复:

net:对等机分配失败时不发送 ICMP/NDISC 重定向 (CVE-2026-74550)

在 Linux 内核中,以下漏洞已修复:

scsi:libiscsi_tcp:将 SCSI 响应数据段绑定到连接缓冲区 (CVE-2026-74556)

在 Linux 内核中,以下漏洞已修复:

scsi:libiscsi:修复过时数据泄漏到 SCSI 感知缓冲区 (CVE-2026-74557)

在 Linux 内核中,以下漏洞已修复:

xsk:在 xsk_build_skb() () 中溢出后耗尽延续 descsCVE-2026-74559

在 Linux 内核中,以下漏洞已修复:

xsk:修复 AF_XDP 多缓冲区 Tx (CVE-2026-74560) 的 xsk_drop_skb() 中的缓冲区泄漏

在 Linux 内核中,以下漏洞已修复:

rds:tcp:在 rds_tcp_laddr_check()CVE-2026-74563 () 中的 ipv6_chk_addr() 上保持 RCU 锁定

在 Linux 内核中,以下漏洞已修复:

netfilter:xt_hashlimit:验证哈希表支持 XT_HASHLIMIT_RATE_MATCH (CVE-2026-74564)

在 Linux 内核中,以下漏洞已修复:

netfilter:nf_tables:使每个表 nft_object RHLTABLE (CVE-2026-74565)

在 Linux 内核中,以下漏洞已修复:

keys:使 keyring 密钥区块字节顺序与 keyring_diff_objects() (CVE-2026-74566) 一致

在 Linux 内核中,以下漏洞已修复:

keys:修复 keyring_get_key_chunk() (CVE-2026-74567) 中的越界读取

在 Linux 内核中,以下漏洞已修复:

netfilter:nf_conntrack_sip:在 sip_help_tcp() (CVE-2026-74569) 中将 NAT 重写增量加宽到 s32

在 Linux 内核中,以下漏洞已修复:

btrfs:zoned:修复元数据回写与事务提交 (CVE-2026-74572) 之间的死锁

在 Linux 内核中,以下漏洞已修复:

mm/slab:使用新的 kmalloc 类型 (CVE-2026-74576) 防止自由路径中未限制边界的递归

在 Linux 内核中,以下漏洞已修复:

net:mpls:初始化 mpls_getroute()CVE-2026-74577 () 中的 rtm_tos

在 Linux 内核中,以下漏洞已修复:

netfilter:nft_payload:修复部分字段卸载的掩码构建 (CVE-2026-74579)

在 Linux 内核中,以下漏洞已修复:

vhost:重置 vring reconfiguration (CVE-2026-74580) 上的 vring 元数据缓存

Tenable 已直接从测试产品的安全公告中提取上述描述块。

请注意,Nessus 尚未测试这些问题,而是只依据应用程序自我报告的版本号进行判断。

解决方案

运行“dnf update kernel6.18 --releasever 2023.12.20260831”或“dnf update --advisory ALAS2023-2026-2106 --releasever 2023.12.20260831”以更新系统。

另见

https://alas.aws.amazon.com//AL2023/ALAS2023-2026-2106.html

https://alas.aws.amazon.com/faqs.html

https://explore.alas.aws.amazon.com/CVE-2026-45897.html

https://explore.alas.aws.amazon.com/CVE-2026-45901.html

https://explore.alas.aws.amazon.com/CVE-2026-53090.html

https://explore.alas.aws.amazon.com/CVE-2026-63978.html

https://explore.alas.aws.amazon.com/CVE-2026-63979.html

https://explore.alas.aws.amazon.com/CVE-2026-64017.html

https://explore.alas.aws.amazon.com/CVE-2026-64283.html

https://explore.alas.aws.amazon.com/CVE-2026-64523.html

https://explore.alas.aws.amazon.com/CVE-2026-64562.html

https://explore.alas.aws.amazon.com/CVE-2026-64563.html

https://explore.alas.aws.amazon.com/CVE-2026-64564.html

https://explore.alas.aws.amazon.com/CVE-2026-64567.html

https://explore.alas.aws.amazon.com/CVE-2026-64572.html

https://explore.alas.aws.amazon.com/CVE-2026-64575.html

https://explore.alas.aws.amazon.com/CVE-2026-64576.html

https://explore.alas.aws.amazon.com/CVE-2026-64579.html

https://explore.alas.aws.amazon.com/CVE-2026-64580.html

https://explore.alas.aws.amazon.com/CVE-2026-64581.html

https://explore.alas.aws.amazon.com/CVE-2026-68093.html

https://explore.alas.aws.amazon.com/CVE-2026-68095.html

https://explore.alas.aws.amazon.com/CVE-2026-68096.html

https://explore.alas.aws.amazon.com/CVE-2026-68116.html

https://explore.alas.aws.amazon.com/CVE-2026-68117.html

https://explore.alas.aws.amazon.com/CVE-2026-68118.html

https://explore.alas.aws.amazon.com/CVE-2026-68121.html

https://explore.alas.aws.amazon.com/CVE-2026-68123.html

https://explore.alas.aws.amazon.com/CVE-2026-68127.html

https://explore.alas.aws.amazon.com/CVE-2026-68128.html

https://explore.alas.aws.amazon.com/CVE-2026-68131.html

https://explore.alas.aws.amazon.com/CVE-2026-68132.html

https://explore.alas.aws.amazon.com/CVE-2026-68133.html

https://explore.alas.aws.amazon.com/CVE-2026-68136.html

https://explore.alas.aws.amazon.com/CVE-2026-68138.html

https://explore.alas.aws.amazon.com/CVE-2026-68139.html

https://explore.alas.aws.amazon.com/CVE-2026-68142.html

https://explore.alas.aws.amazon.com/CVE-2026-68145.html

https://explore.alas.aws.amazon.com/CVE-2026-68146.html

https://explore.alas.aws.amazon.com/CVE-2026-68149.html

https://explore.alas.aws.amazon.com/CVE-2026-68150.html

https://explore.alas.aws.amazon.com/CVE-2026-68153.html

https://explore.alas.aws.amazon.com/CVE-2026-68154.html

https://explore.alas.aws.amazon.com/CVE-2026-68155.html

https://explore.alas.aws.amazon.com/CVE-2026-68156.html

https://explore.alas.aws.amazon.com/CVE-2026-68157.html

https://explore.alas.aws.amazon.com/CVE-2026-68158.html

https://explore.alas.aws.amazon.com/CVE-2026-68160.html

https://explore.alas.aws.amazon.com/CVE-2026-68161.html

https://explore.alas.aws.amazon.com/CVE-2026-68162.html

https://explore.alas.aws.amazon.com/CVE-2026-68164.html

https://explore.alas.aws.amazon.com/CVE-2026-68165.html

https://explore.alas.aws.amazon.com/CVE-2026-68166.html

https://explore.alas.aws.amazon.com/CVE-2026-68169.html

https://explore.alas.aws.amazon.com/CVE-2026-68174.html

https://explore.alas.aws.amazon.com/CVE-2026-68178.html

https://explore.alas.aws.amazon.com/CVE-2026-68179.html

https://explore.alas.aws.amazon.com/CVE-2026-68184.html

https://explore.alas.aws.amazon.com/CVE-2026-68186.html

https://explore.alas.aws.amazon.com/CVE-2026-68239.html

https://explore.alas.aws.amazon.com/CVE-2026-68241.html

https://explore.alas.aws.amazon.com/CVE-2026-68243.html

https://explore.alas.aws.amazon.com/CVE-2026-68244.html

https://explore.alas.aws.amazon.com/CVE-2026-68247.html

https://explore.alas.aws.amazon.com/CVE-2026-68248.html

https://explore.alas.aws.amazon.com/CVE-2026-68253.html

https://explore.alas.aws.amazon.com/CVE-2026-68254.html

https://explore.alas.aws.amazon.com/CVE-2026-68255.html

https://explore.alas.aws.amazon.com/CVE-2026-68269.html

https://explore.alas.aws.amazon.com/CVE-2026-68270.html

https://explore.alas.aws.amazon.com/CVE-2026-68277.html

https://explore.alas.aws.amazon.com/CVE-2026-68278.html

https://explore.alas.aws.amazon.com/CVE-2026-68279.html

https://explore.alas.aws.amazon.com/CVE-2026-68284.html

https://explore.alas.aws.amazon.com/CVE-2026-68290.html

https://explore.alas.aws.amazon.com/CVE-2026-68292.html

https://explore.alas.aws.amazon.com/CVE-2026-68293.html

https://explore.alas.aws.amazon.com/CVE-2026-68296.html

https://explore.alas.aws.amazon.com/CVE-2026-68297.html

https://explore.alas.aws.amazon.com/CVE-2026-68299.html

https://explore.alas.aws.amazon.com/CVE-2026-68300.html

https://explore.alas.aws.amazon.com/CVE-2026-68313.html

https://explore.alas.aws.amazon.com/CVE-2026-68315.html

https://explore.alas.aws.amazon.com/CVE-2026-68320.html

https://explore.alas.aws.amazon.com/CVE-2026-68322.html

https://explore.alas.aws.amazon.com/CVE-2026-68325.html

https://explore.alas.aws.amazon.com/CVE-2026-68329.html

https://explore.alas.aws.amazon.com/CVE-2026-68335.html

https://explore.alas.aws.amazon.com/CVE-2026-68336.html

https://explore.alas.aws.amazon.com/CVE-2026-68338.html

https://explore.alas.aws.amazon.com/CVE-2026-68343.html

https://explore.alas.aws.amazon.com/CVE-2026-68374.html

https://explore.alas.aws.amazon.com/CVE-2026-68376.html

https://explore.alas.aws.amazon.com/CVE-2026-68378.html

https://explore.alas.aws.amazon.com/CVE-2026-68386.html

https://explore.alas.aws.amazon.com/CVE-2026-68387.html

https://explore.alas.aws.amazon.com/CVE-2026-68388.html

https://explore.alas.aws.amazon.com/CVE-2026-68396.html

https://explore.alas.aws.amazon.com/CVE-2026-68400.html

https://explore.alas.aws.amazon.com/CVE-2026-68401.html

https://explore.alas.aws.amazon.com/CVE-2026-68416.html

https://explore.alas.aws.amazon.com/CVE-2026-68420.html

https://explore.alas.aws.amazon.com/CVE-2026-68421.html

https://explore.alas.aws.amazon.com/CVE-2026-68422.html

https://explore.alas.aws.amazon.com/CVE-2026-68425.html

https://explore.alas.aws.amazon.com/CVE-2026-68426.html

https://explore.alas.aws.amazon.com/CVE-2026-68428.html

https://explore.alas.aws.amazon.com/CVE-2026-68429.html

https://explore.alas.aws.amazon.com/CVE-2026-68432.html

https://explore.alas.aws.amazon.com/CVE-2026-68433.html

https://explore.alas.aws.amazon.com/CVE-2026-68442.html

https://explore.alas.aws.amazon.com/CVE-2026-68444.html

https://explore.alas.aws.amazon.com/CVE-2026-68446.html

https://explore.alas.aws.amazon.com/CVE-2026-68448.html

https://explore.alas.aws.amazon.com/CVE-2026-68450.html

https://explore.alas.aws.amazon.com/CVE-2026-68480.html

https://explore.alas.aws.amazon.com/CVE-2026-72030.html

https://explore.alas.aws.amazon.com/CVE-2026-72103.html

https://explore.alas.aws.amazon.com/CVE-2026-72113.html

https://explore.alas.aws.amazon.com/CVE-2026-72114.html

https://explore.alas.aws.amazon.com/CVE-2026-72115.html

https://explore.alas.aws.amazon.com/CVE-2026-72116.html

https://explore.alas.aws.amazon.com/CVE-2026-72117.html

https://explore.alas.aws.amazon.com/CVE-2026-72118.html

https://explore.alas.aws.amazon.com/CVE-2026-72119.html

https://explore.alas.aws.amazon.com/CVE-2026-72121.html

https://explore.alas.aws.amazon.com/CVE-2026-72175.html

https://explore.alas.aws.amazon.com/CVE-2026-72244.html

https://explore.alas.aws.amazon.com/CVE-2026-72253.html

https://explore.alas.aws.amazon.com/CVE-2026-72254.html

https://explore.alas.aws.amazon.com/CVE-2026-74442.html

https://explore.alas.aws.amazon.com/CVE-2026-74443.html

https://explore.alas.aws.amazon.com/CVE-2026-74444.html

https://explore.alas.aws.amazon.com/CVE-2026-74445.html

https://explore.alas.aws.amazon.com/CVE-2026-74464.html

https://explore.alas.aws.amazon.com/CVE-2026-74465.html

https://explore.alas.aws.amazon.com/CVE-2026-74469.html

https://explore.alas.aws.amazon.com/CVE-2026-74471.html

https://explore.alas.aws.amazon.com/CVE-2026-74473.html

https://explore.alas.aws.amazon.com/CVE-2026-74474.html

https://explore.alas.aws.amazon.com/CVE-2026-74475.html

https://explore.alas.aws.amazon.com/CVE-2026-74476.html

https://explore.alas.aws.amazon.com/CVE-2026-74477.html

https://explore.alas.aws.amazon.com/CVE-2026-74480.html

https://explore.alas.aws.amazon.com/CVE-2026-74481.html

https://explore.alas.aws.amazon.com/CVE-2026-74482.html

https://explore.alas.aws.amazon.com/CVE-2026-74484.html

https://explore.alas.aws.amazon.com/CVE-2026-74485.html

https://explore.alas.aws.amazon.com/CVE-2026-74486.html

https://explore.alas.aws.amazon.com/CVE-2026-74487.html

https://explore.alas.aws.amazon.com/CVE-2026-74490.html

https://explore.alas.aws.amazon.com/CVE-2026-74491.html

https://explore.alas.aws.amazon.com/CVE-2026-74492.html

https://explore.alas.aws.amazon.com/CVE-2026-74512.html

https://explore.alas.aws.amazon.com/CVE-2026-74516.html

https://explore.alas.aws.amazon.com/CVE-2026-74518.html

https://explore.alas.aws.amazon.com/CVE-2026-74519.html

https://explore.alas.aws.amazon.com/CVE-2026-74543.html

https://explore.alas.aws.amazon.com/CVE-2026-74550.html

https://explore.alas.aws.amazon.com/CVE-2026-74556.html

https://explore.alas.aws.amazon.com/CVE-2026-74557.html

https://explore.alas.aws.amazon.com/CVE-2026-74559.html

https://explore.alas.aws.amazon.com/CVE-2026-74560.html

https://explore.alas.aws.amazon.com/CVE-2026-74563.html

https://explore.alas.aws.amazon.com/CVE-2026-74564.html

https://explore.alas.aws.amazon.com/CVE-2026-74565.html

https://explore.alas.aws.amazon.com/CVE-2026-74566.html

https://explore.alas.aws.amazon.com/CVE-2026-74567.html

https://explore.alas.aws.amazon.com/CVE-2026-74569.html

https://explore.alas.aws.amazon.com/CVE-2026-74572.html

https://explore.alas.aws.amazon.com/CVE-2026-74576.html

https://explore.alas.aws.amazon.com/CVE-2026-74577.html

https://explore.alas.aws.amazon.com/CVE-2026-74579.html

https://explore.alas.aws.amazon.com/CVE-2026-74580.html

https://explore.alas.aws.amazon.com/CVE-2026-74581.html

插件详情

严重性: High

ID: 341888

文件名: al2023_ALAS2023-2026-2106.nasl

版本: 1.2

类型: Local

代理: unix

发布时间: 2026/8/31

最近更新时间: 2026/9/1

支持的传感器: Agentless Assessment, Continuous Assessment, Frictionless Assessment Agent, Frictionless Assessment AWS, Nessus Agent, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

风险信息

VPR

风险因素: High

分数: 7.9

百分位: 99.36

CVSS v2

风险因素: Medium

基本分数: 6

时间分数: 4.7

矢量: CVSS2#AV:L/AC:H/Au:S/C:C/I:C/A:C

CVSS 分数来源: CVE-2026-64283

CVSS v3

风险因素: High

基本分数: 7

时间分数: 6.3

矢量: CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

时间矢量: CVSS:3.0/E:P/RL:O/RC:C

漏洞信息

CPE: cpe:/o:amazon:linux:2023, p-cpe:/a:amazon:linux:bpftool6.18-debuginfo, p-cpe:/a:amazon:linux:bpftool6.18, p-cpe:/a:amazon:linux:kernel-livepatch-6.18.44-99.149, p-cpe:/a:amazon:linux:kernel6.18-debuginfo-common-aarch64, p-cpe:/a:amazon:linux:kernel6.18-debuginfo-common-x86_64, p-cpe:/a:amazon:linux:kernel6.18-debuginfo, p-cpe:/a:amazon:linux:kernel6.18-devel, p-cpe:/a:amazon:linux:kernel6.18-headers, p-cpe:/a:amazon:linux:kernel6.18-modules-extra-common, p-cpe:/a:amazon:linux:kernel6.18-modules-extra, p-cpe:/a:amazon:linux:kernel6.18-tools-debuginfo, p-cpe:/a:amazon:linux:kernel6.18-tools-devel, p-cpe:/a:amazon:linux:kernel6.18-tools, p-cpe:/a:amazon:linux:kernel6.18, p-cpe:/a:amazon:linux:microvm-kernel6.18, p-cpe:/a:amazon:linux:perf6.18-debuginfo, p-cpe:/a:amazon:linux:perf6.18, p-cpe:/a:amazon:linux:python3-perf6.18-debuginfo, p-cpe:/a:amazon:linux:python3-perf6.18

必需的 KB 项: Host/local_checks_enabled, Host/AmazonLinux/release, Host/AmazonLinux/rpm-list

可利用: true

易利用性: Exploits are available

补丁发布日期: 2026/8/31

漏洞发布日期: 2026/5/27

参考资料信息

CVE: CVE-2026-45897, CVE-2026-45901, CVE-2026-53090, CVE-2026-63978, CVE-2026-63979, CVE-2026-64017, CVE-2026-64283, CVE-2026-64523, CVE-2026-64562, CVE-2026-64563, CVE-2026-64564, CVE-2026-64567, CVE-2026-64572, CVE-2026-64575, CVE-2026-64576, CVE-2026-64579, CVE-2026-64580, CVE-2026-64581, CVE-2026-68093, CVE-2026-68095, CVE-2026-68096, CVE-2026-68116, CVE-2026-68117, CVE-2026-68118, CVE-2026-68121, CVE-2026-68123, CVE-2026-68127, CVE-2026-68128, CVE-2026-68131, CVE-2026-68132, CVE-2026-68133, CVE-2026-68136, CVE-2026-68138, CVE-2026-68139, CVE-2026-68142, CVE-2026-68145, CVE-2026-68146, CVE-2026-68149, CVE-2026-68150, CVE-2026-68153, CVE-2026-68154, CVE-2026-68155, CVE-2026-68156, CVE-2026-68157, CVE-2026-68158, CVE-2026-68160, CVE-2026-68161, CVE-2026-68162, CVE-2026-68164, CVE-2026-68165, CVE-2026-68166, CVE-2026-68169, CVE-2026-68174, CVE-2026-68178, CVE-2026-68179, CVE-2026-68184, CVE-2026-68186, CVE-2026-68239, CVE-2026-68241, CVE-2026-68243, CVE-2026-68244, CVE-2026-68247, CVE-2026-68248, CVE-2026-68253, CVE-2026-68254, CVE-2026-68255, CVE-2026-68269, CVE-2026-68270, CVE-2026-68277, CVE-2026-68278, CVE-2026-68279, CVE-2026-68284, CVE-2026-68290, CVE-2026-68292, CVE-2026-68293, CVE-2026-68296, CVE-2026-68297, CVE-2026-68299, CVE-2026-68300, CVE-2026-68313, CVE-2026-68315, CVE-2026-68320, CVE-2026-68322, CVE-2026-68325, CVE-2026-68329, CVE-2026-68335, CVE-2026-68336, CVE-2026-68338, CVE-2026-68343, CVE-2026-68374, CVE-2026-68376, CVE-2026-68378, CVE-2026-68386, CVE-2026-68387, CVE-2026-68388, CVE-2026-68396, CVE-2026-68400, CVE-2026-68401, CVE-2026-68416, CVE-2026-68420, CVE-2026-68421, CVE-2026-68422, CVE-2026-68425, CVE-2026-68426, CVE-2026-68428, CVE-2026-68429, CVE-2026-68432, CVE-2026-68433, CVE-2026-68442, CVE-2026-68444, CVE-2026-68446, CVE-2026-68448, CVE-2026-68450, CVE-2026-68480, CVE-2026-72030, CVE-2026-72103, CVE-2026-72113, CVE-2026-72114, CVE-2026-72115, CVE-2026-72116, CVE-2026-72117, CVE-2026-72118, CVE-2026-72119, CVE-2026-72121, CVE-2026-72175, CVE-2026-72244, CVE-2026-72253, CVE-2026-72254, CVE-2026-74442, CVE-2026-74443, CVE-2026-74444, CVE-2026-74445, CVE-2026-74464, CVE-2026-74465, CVE-2026-74469, CVE-2026-74471, CVE-2026-74473, CVE-2026-74474, CVE-2026-74475, CVE-2026-74476, CVE-2026-74477, CVE-2026-74480, CVE-2026-74481, CVE-2026-74482, CVE-2026-74484, CVE-2026-74485, CVE-2026-74486, CVE-2026-74487, CVE-2026-74490, CVE-2026-74491, CVE-2026-74492, CVE-2026-74512, CVE-2026-74516, CVE-2026-74518, CVE-2026-74519, CVE-2026-74543, CVE-2026-74550, CVE-2026-74556, CVE-2026-74557, CVE-2026-74559, CVE-2026-74560, CVE-2026-74563, CVE-2026-74564, CVE-2026-74565, CVE-2026-74566, CVE-2026-74567, CVE-2026-74569, CVE-2026-74572, CVE-2026-74576, CVE-2026-74577, CVE-2026-74579, CVE-2026-74580, CVE-2026-74581