Amazon Linux 2023:bpftool、kernel、kernel-devel (ALAS2023-2026-2107)

critical Nessus 插件 ID 342043

简介

远程 Amazon Linux 2023 主机缺少安全更新。

描述

因此,该软件受到 ALAS2023-2026-2107 公告中提及的多个漏洞影响。

在 Linux 内核中,以下漏洞已修复:

blk-mq:弹出缓存的请求(如果可用CVE-2026-64017)()

在 Linux 内核中,以下漏洞已修复:

sctp:不释放 DEL-IP 处理中 ASCONF 自己的传输 (CVE-2026-64564)

在 Linux 内核中,以下漏洞已修复:

xfrm:修复 xfrm_user_policy() (CVE-2026-64581) 中的sk_dst_cache双重释放

在 Linux 内核中,以下漏洞已修复:

rbd:将对象映射更新路径 (CVE-2026-68131) 中的正面结果代码重置为零

在 Linux 内核中,以下漏洞已修复:

net/sched:针对并发 get/put () 序列化 qdisc_rtab_listCVE-2026-68138

在 Linux 内核中,以下漏洞已修复:

libceph:拒绝公告零监控器的 monmaps (CVE-2026-68155)

在 Linux 内核中,以下漏洞已修复:

ceph:修复 ceph_handle_caps() (CVE-2026-68160) 中 snaptrace 上的预认证越界读取

在 Linux 内核中,以下漏洞已修复:

vmxnet3:修复 Geneve 数据包 (CVE-2026-68299) 的 vmxnet3_get_hdr_len() 中的BUG_ON

在 Linux 内核中,以下漏洞已修复:

rds:丢弃跨网络命名空间边界的传入消息 (CVE-2026-68335)

在 Linux 内核中,以下漏洞已修复:

net/packet:避免 unregister (CVE-2026-68338) 之后的扇出挂钩重新注册

在 Linux 内核中,以下漏洞已修复:

x86/缺陷:使 Safe-RET 加强防御中断注入 (CVE-2026-68480)

在 Linux 内核中,以下漏洞已修复:

net:ip6_tunnel:需要设备 netns 中的CAP_NET_ADMIN用于 changelink (CVE-2026-72051)

在 Linux 内核中,以下漏洞已修复:

scsi:libiscsi_tcp:将 SCSI 响应数据段绑定到连接缓冲区 (CVE-2026-74556)

在 Linux 内核中,以下漏洞已修复:

vhost:重置 vring reconfiguration (CVE-2026-74580) 上的 vring 元数据缓存

Tenable 已直接从测试产品的安全公告中提取上述描述块。

请注意,Nessus 尚未测试这些问题,而是只依据应用程序自我报告的版本号进行判断。

解决方案

运行“dnf update kernel --releasever 2023.12.20260831”或“/或”dnf update --advisory ALAS2023-2026-2107 --releasever 2023.12.20260831“以更新系统。

另见

https://alas.aws.amazon.com//AL2023/ALAS2023-2026-2107.html

https://alas.aws.amazon.com/faqs.html

https://explore.alas.aws.amazon.com/CVE-2026-64017.html

https://explore.alas.aws.amazon.com/CVE-2026-64564.html

https://explore.alas.aws.amazon.com/CVE-2026-64581.html

https://explore.alas.aws.amazon.com/CVE-2026-68131.html

https://explore.alas.aws.amazon.com/CVE-2026-68138.html

https://explore.alas.aws.amazon.com/CVE-2026-68155.html

https://explore.alas.aws.amazon.com/CVE-2026-68160.html

https://explore.alas.aws.amazon.com/CVE-2026-68299.html

https://explore.alas.aws.amazon.com/CVE-2026-68335.html

https://explore.alas.aws.amazon.com/CVE-2026-68338.html

https://explore.alas.aws.amazon.com/CVE-2026-68480.html

https://explore.alas.aws.amazon.com/CVE-2026-72051.html

https://explore.alas.aws.amazon.com/CVE-2026-74556.html

https://explore.alas.aws.amazon.com/CVE-2026-74580.html

插件详情

严重性: Critical

ID: 342043

文件名: al2023_ALAS2023-2026-2107.nasl

版本: 1.1

类型: Local

代理: unix

发布时间: 2026/8/31

最近更新时间: 2026/8/31

支持的传感器: Frictionless Assessment AWS, Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Continuous Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

风险信息

VPR

风险因素: High

分数: 7.9

百分位: 99.36

CVSS v2

风险因素: Critical

基本分数: 10

时间分数: 7.8

矢量: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS 分数来源: CVE-2026-74556

CVSS v3

风险因素: Critical

基本分数: 9.8

时间分数: 8.8

矢量: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

时间矢量: CVSS:3.0/E:P/RL:O/RC:C

漏洞信息

CPE: cpe:/o:amazon:linux:2023, p-cpe:/a:amazon:linux:bpftool-debuginfo, p-cpe:/a:amazon:linux:bpftool, p-cpe:/a:amazon:linux:kernel-debuginfo-common-aarch64, p-cpe:/a:amazon:linux:kernel-debuginfo-common-x86_64, p-cpe:/a:amazon:linux:kernel-debuginfo, p-cpe:/a:amazon:linux:kernel-devel, p-cpe:/a:amazon:linux:kernel-headers, p-cpe:/a:amazon:linux:kernel-livepatch-6.1.182-227.379, p-cpe:/a:amazon:linux:kernel-modules-extra-common, p-cpe:/a:amazon:linux:kernel-modules-extra, p-cpe:/a:amazon:linux:kernel-tools-debuginfo, p-cpe:/a:amazon:linux:kernel-tools-devel, p-cpe:/a:amazon:linux:kernel-tools, p-cpe:/a:amazon:linux:kernel, p-cpe:/a:amazon:linux:perf-debuginfo, p-cpe:/a:amazon:linux:perf, p-cpe:/a:amazon:linux:python3-perf-debuginfo, p-cpe:/a:amazon:linux:python3-perf

必需的 KB 项: Host/local_checks_enabled, Host/AmazonLinux/release, Host/AmazonLinux/rpm-list

可利用: true

易利用性: Exploits are available

补丁发布日期: 2026/8/31

漏洞发布日期: 2026/7/19

参考资料信息

CVE: CVE-2026-64017, CVE-2026-64564, CVE-2026-64581, CVE-2026-68131, CVE-2026-68138, CVE-2026-68155, CVE-2026-68160, CVE-2026-68299, CVE-2026-68335, CVE-2026-68338, CVE-2026-68480, CVE-2026-72051, CVE-2026-74556, CVE-2026-74580