Amazon Linux 2023:bpftool6.18、kernel6.18、kernel6.18-devel (ALAS2023-2026-3139)

critical Nessus 插件 ID 351016

简介

远程 Amazon Linux 2023 主机缺少安全更新。

描述

因此,该软件受到 ALAS2023-2026-3139 公告中提及的多个漏洞影响。

在 Linux 内核中,以下漏洞已修复:

libceph:修复 decode_lockers() (CVE-2026-68082) 中的两个不安全的裸解码

在 Linux 内核中,以下漏洞已修复:

libceph:将 pg_{temp,upmap,upmap_items} 长度绑定为 CEPH_PG_MAX_SIZE (CVE-2026-68159)

在 Linux 内核中,以下漏洞已修复:

binfmt_misc:挂载失败时不泄漏用户命名空间 (CVE-2026-74483)

在 Linux 内核中,以下漏洞已修复:

KVM:x86:销毁 vCPU 前取消延迟的 I/O APIC EOI 处理 (CVE-2026-74517)

在 Linux 内核中,以下漏洞已修复:

packet:在非环发送路径中使用一致的hard_header_len (CVE-2026-74582)

在 Linux 内核中,以下漏洞已修复:

net/sched:cls_route:修复 filterCVE-2026-74583() 上的 fastmap 释放后使用

在 Linux 内核中,以下漏洞已修复:

sctp:删除对等机 () 时清除new_transportCVE-2026-74586

在 Linux 内核中,以下漏洞已修复:

sctp:修复缓存的 ASCONF 区块 (CVE-2026-74587) 的释放后使用

在 Linux 内核中,以下漏洞已修复:

sctp:使 chunk->transport 与其排队的列表保持一致 (CVE-2026-74588)

在 Linux 内核中,以下漏洞已修复:

bpf、sockmap:修复发送判定 (CVE-2026-74589) 中的sk_redir释放后使用

在 Linux 内核中,以下漏洞已修复:

mm/filemap:__filemap_add_folio() 重试前还原索引 (CVE-2026-74591)

在 Linux 内核中,以下漏洞已修复:

ima:实例化 file_truncate 和 path_truncate 挂钩 (CVE-2026-74592)

在 Linux 内核中,以下漏洞已修复:

sched_ext:在 scx_cgroup_lock()CVE-2026-74593 中首先采用 cgroup_lock()

在 Linux 内核中,以下漏洞已修复:

sched/psi:关闭 psi_cgroup_free() ()CVE-2026-74594 中的 rtpoll_timer

在 Linux 内核中,以下漏洞已修复:

fscrypt:在 fscrypt_ioctl_set_policy() (CVE-2026-74595) 中使用挂载 idmap 进行所有者检查

在 Linux 内核中,以下漏洞已修复:

ip6_tunnel:清除 ip6ip6_err()CVE-2026-74597 () 中的 skb2->cb[]

在 Linux 内核中,以下漏洞已修复:

ipv6:修复路由信息选项长度验证 (CVE-2026-74598)

在 Linux 内核中,以下漏洞已修复:

ring-buffer:将current_context用于安全的每 CPU 缓冲区交换 (CVE-2026-74601)

在 Linux 内核中,以下漏洞已修复:

ring-buffer:在 rb_allocate_cpu_buffer() (CVE-2026-74602) 中初始化阅读器页面顺序

在 Linux 内核中,以下漏洞已修复:

eventfs:修复 eventfs_remove_rec() 中的释放后使用 (CVE-2026-74606)

在 Linux 内核中,以下漏洞已修复:

smb:客户端:修复 cifs_try_adding_channels() 中的释放后使用 (CVE-2026-74608)

在 Linux 内核中,以下漏洞已修复:

tipc:读取 tipc_node_link_down() (CVE-2026-74609) 中节点锁定下的 le->link

在 Linux 内核中,以下漏洞已修复:

tls:不让完整的明文 sk_msg 环未推送 (CVE-2026-74610)

在 Linux 内核中,以下漏洞已修复:

tls:rx:TLS 1.3 乐观重试 () 之前还原 msg_iterCVE-2026-74611

在 Linux 内核中,以下漏洞已修复:

veth:修复 XDP frag 调整 (CVE-2026-74612) 之后的 skb 长度核算

在 Linux 内核中,以下漏洞已修复:

vsock/virtio:避免在拆卸 (CVE-2026-74613) 之后重新填充 RX 队列

在 Linux 内核中,以下漏洞已修复:

vsock/virtio:读取工作线程锁下的 virtqueues (CVE-2026-74614)

在 Linux 内核中,以下漏洞已修复:

vxlan:不布防已停机的设备上老化的定时器 (CVE-2026-74615)

在 Linux 内核中,以下漏洞已修复:

xdp:拒绝 tailroom (CVE-2026-74616) skb_shared_info溢出的克隆

在 Linux 内核中,以下漏洞已修复:

binfmt_misc:从其他用户命名空间完成挂载时不发出警告 (CVE-2026-74618)

在 Linux 内核中,以下漏洞已修复:

ovl:从其他用户命名空间完成挂载时不发出警告 (CVE-2026-74619)

在 Linux 内核中,以下漏洞已修复:

net/sched:act_gact、act_police:范围检查回退控制操作 (CVE-2026-74620)

在 Linux 内核中,以下漏洞已修复:

netfilter:nf_conntrack:延迟无效日志,直至解锁 (CVE-2026-74624) 之后

在 Linux 内核中,以下漏洞已修复:

net:devmem:防止 net-iov / 页面混合 (CVE-2026-74627)

在 Linux 内核中,以下漏洞已修复:

ipv6:阻止 in6_dev_get() 复活 inet6_dev (CVE-2026-74630)

在 Linux 内核中,以下漏洞已修复:

mm/huge_memory:修复huge_zero_pfn争用 (CVE-2026-74632)

在 Linux 内核中,以下漏洞已修复:

tracing:修复模块事件缓存删除中的空指针取消引用 (CVE-2026-74633)

在 Linux 内核中,以下漏洞已修复:

ring-buffer:禁用调整大小时防止 subbuf 顺序变更 (CVE-2026-74634)

在 Linux 内核中,以下漏洞已修复:

fbdev:bitblit:bit_cursor() (CVE-2026-74635) 中的边界检查字形索引

在 Linux 内核中,以下漏洞已修复:

tracing:修复 update_event_fields 和 event_define_fields (CVE-2026-74636) 之间的争用

在 Linux 内核中,以下漏洞已修复:

perf/core:修复同级分离 (CVE-2026-74637) 之后的组组首导符释放后使用

在 Linux 内核中,以下漏洞已修复:

mm/damon/ops-common:放回无效迁移 nid (CVE-2026-74644) 上的作品集

在 Linux 内核中,以下漏洞已修复:

serial:amba-pl011:释放 IRQ (CVE-2026-74652) 后取消 RS485 hrtimers

在 Linux 内核中,以下漏洞已修复:

serial:8250_of:清除 LPC32xx 上卡住的空 FIFO RX 超时 (CVE-2026-74653)

在 Linux 内核中,以下漏洞已修复:

serial:8250_dma:清除关机时过时的 RX 状态 (CVE-2026-74654)

在 Linux 内核中,以下漏洞已修复:

ipv4:修复 fib_nhc_update_mtu() 中的释放后使用 (CVE-2026-74656)

在 Linux 内核中,以下漏洞已修复:

ipv4:修复 RTA_VIA nexthops 的CVE-2026-74657 fib_nlmsg_size()

在 Linux 内核中,以下漏洞已修复:

futex:防止健全 futex 退出争用更多 (CVE-2026-74658)

在 Linux 内核中,以下漏洞已修复:

netfilter:ebt_nflog:固定 NFLOG 后端 (CVE-2026-74660)

在 Linux 内核中,以下漏洞已修复:

inet:frags:布防定时器 (CVE-2026-74662) 之前发布队列

在 Linux 内核中,以下漏洞已修复:

net/sched:拒绝过深的 qdisc 层次结构 (CVE-2026-74663)

在 Linux 内核中,以下漏洞已修复:

net:openvswitch:为不匹配的 ID 重新分配更新回复 (CVE-2026-74664)

在 Linux 内核中,以下漏洞已修复:

net:修复通用 XDP frag 调整 (CVE-2026-74665) 后的 skb 长度核算

在 Linux 内核中,以下漏洞已修复:

packet:通过环重新配置 (CVE-2026-74666) 同步压力清除

在 Linux 内核中,以下漏洞已修复:

net/packet:重置数据包套接字传输路径上的 MAC 标头 (CVE-2026-74667)

在 Linux 内核中,以下漏洞已修复:

packet:在 TX_RING 发送路径中使用一致的hard_header_len (CVE-2026-74668)

在 Linux 内核中,以下漏洞已修复:

ipvs:衍合隧道 ICMP 错误 (CVE-2026-74669) 后清除 IPv4 选项

在 Linux 内核中,以下漏洞已修复:

ipvs:禁用 calc 阶段 (CVE-2026-74670) 后停止估计器

在 Linux 内核中,以下漏洞已修复:

ima:修复 xattr_verify() (CVE-2026-74671) 中的越界读取

在 Linux 内核中,以下漏洞已修复:

mm/vmalloc:获取大型 vmap 上的 init_mm 锁定以避免 ptdump UAF (CVE-2026-74672)

在 Linux 内核中,以下漏洞已修复:

Input:evdev - 修复 evdev_pass_values() (CVE-2026-74673) 中的信息泄漏

在 Linux 内核中,以下漏洞已修复:

vt:通过 tty_port_tty_get (CVE-2026-74675) 稳定 kbd_keycode 中的 tty 引用

在 Linux 内核中,以下漏洞已修复:

vt:添加对 KDSKBMETA ioctl (CVE-2026-74676) 的权限检查

在 Linux 内核中,以下漏洞已修复:

Input:evdev - 获取事件掩码 (CVE-2026-74683) 时审查事件类型索引

在 Linux 内核中,以下漏洞已修复:

net:tap:在解析 tap_get_user_xdp() 中的 virtio net 标头之前设置 skb->dev (CVE-2026-74684)

在 Linux 内核中,以下漏洞已修复:

sctp:清除控制区块传输(如果正在删除CVE-2026-74688)

在 Linux 内核中,以下漏洞已修复:

netfilter:nf_flow_table:在 skb_dst_set_noref() () 之前CVE-2026-74695终止现有 skb dst

在 Linux 内核中,以下漏洞已修复:

tcp:修复跨重用端口迁移的 TFO max_qlen核算 (CVE-2026-74696)

在 Linux 内核中,以下漏洞已修复:

net/mlx5e:修复 SQ 重新激活时的 BQL 重置 (CVE-2026-74698)

在 Linux 内核中,以下漏洞已修复:

net/sched:cls_api:破坏锁定的分类器 (CVE-2026-74700) 时始终获取 rtnl_lock

在 Linux 内核中,以下漏洞已修复:

net/openvswitch:检查 key_extract() (CVE-2026-74701) 中的以太网标头长度

在 Linux 内核中,以下漏洞已修复:

net/sched:sch_cake:终止 ACK 过滤器 (CVE-2026-74704) 中畸形数据包的 WARN_ON(1)

在 Linux 内核中,以下漏洞已修复:

udp:修复隧道分段 (CVE-2026-74705) 中潜在的释放后使用

在 Linux 内核中,以下漏洞已修复:

xsk:处理请求时验证元数据 (CVE-2026-74707)

在 Linux 内核中,以下漏洞已修复:

xsk:验证启动时元数据大小 (CVE-2026-74708)

在 Linux 内核中,以下漏洞已修复:

xsk:未请求时间戳时清除元数据指针 (CVE-2026-74709)

在 Linux 内核中,以下漏洞已修复:

xsk:要求至少 16 字节的 TX 元数据 (CVE-2026-74710)

在 Linux 内核中,以下漏洞已修复:

bpf:tcp:修复 bpf_iter_tcp_established_batch() (CVE-2026-74714) 中的释放后使用

在 Linux 内核中,以下漏洞已修复:

net/mlx5:fw_tracer,创建错误 (CVE-2026-74717) 时返回 NULL

在 Linux 内核中,以下漏洞已修复:

devlink:修复 reload (CVE-2026-74718) 中的 net 命名空间引用泄漏

在 Linux 内核中,以下漏洞已修复:

bpf:保留可换算的指针状态 (CVE-2026-74720)

在 Linux 内核中,以下漏洞已修复:

btrfs:修复 btrfs_do_encoded_write() (CVE-2026-74722) 中的内存泄漏

在 Linux 内核中,以下漏洞已修复:

ipvs:避免 ip_vs_nat_icmp 中的越界写入 (CVE-2026-74724)

在 Linux 内核中,以下漏洞已修复:

bonding:alb:重新检查 bond_alb_monitor (CVE-2026-74726) 中 RTNL 下的primary_is_promisc

在 Linux 内核中,以下漏洞已修复:

xfs:处理 xfs_buf_free (CVE-2026-74728) 中的空b_addr

在 Linux 内核中,以下漏洞已修复:

NFS:在 FREE_STATEID 调用期间固定“struct nfs_server” (CVE-2026-74730)

在 Linux 内核中,以下漏洞已修复:

net/sched:cls_bpf:拒绝绑定到不同设备的 dev-bound 程序 (CVE-2026-74736)

在 Linux 内核中,以下漏洞已修复:

net/sched:cls_u32:跳过 u32_bind_class() (CVE-2026-74739) 中的哈希表

在 Linux 内核中,以下漏洞已修复:

net/sched:act_api:修复 a->goto_chain (CVE-2026-74740) 上的 TOCTOU 空取消引用

在 Linux 内核中,以下漏洞已修复:

veth:修复用于唤醒 veth_poll (CVE-2026-74742) 中的对等机 txq 的队列索引

在 Linux 内核中,以下漏洞已修复:

macvlan:继承 lowerdev () 的 needed_headroom 和CVE-2026-74743 needed_tailroom

在 Linux 内核中,以下漏洞已修复:

ipvlan:继承 phy_dev () 的 needed_headroom 和CVE-2026-74744 needed_tailroom

在 Linux 内核中,以下漏洞已修复:

netfilter:flowtable:发布 GC 可见元组 last (CVE-2026-74746)

在 Linux 内核中,以下漏洞已修复:

netfilter:ipset:修复 list:set GC 与 swap (CVE-2026-74748) 之间的引用计数争用

在 Linux 内核中,以下漏洞已修复:

perf:以组长身份拒绝退出的事件 (CVE-2026-74753)

在 Linux 内核中,以下漏洞已修复:

ceph:修复将 __ceph_get_caps() 挂起mds_wanted (CVE-2026-80527)

在 Linux 内核中,以下漏洞已修复:

ceph:避免使用 current->journal_info (CVE-2026-80528) 时回收 fs

在 Linux 内核中,以下漏洞已修复:

xfs:不吞咽 dquot 恢复验证错误 (CVE-2026-80529)

在 Linux 内核中,以下漏洞已修复:

xfs:修复 INO1_WRITTEN (CVE-2026-80530) 的交换范围引用链接标记清除问题

在 Linux 内核中,以下漏洞已修复:

xfs:修复 xfs_dq_get_next_id (CVE-2026-80534) 中出错时的 ilock 泄漏

在 Linux 内核中,以下漏洞已修复:

xfs:边界检查缓冲区日志项的脏位图 (CVE-2026-80536)

在 Linux 内核中,以下漏洞已修复:

libceph:通过缺少的边界检查 (CVE-2026-80557) 修复 decode_watchers() 中的 OOB 读取

在 Linux 内核中,以下漏洞已修复:

libceph:避免使用 primary_temp (CVE-2026-80558) 中的无效 osd 索引

在 Linux 内核中,以下漏洞已修复:

libceph:修复 decode_locker() (CVE-2026-80561) 中的多种不安全解码

在 Linux 内核中,以下漏洞已修复:

输入:byd - 在释放私有数据之前同步定时器删除 (CVE-2026-80572)

在 Linux 内核中,以下漏洞已修复:

输入:focaltech - 修复 focaltech_process_rel_packet (CVE-2026-80574) 中的数组越界

在 Linux 内核中,以下漏洞已修复:

fbdev:core:修复 fb_io_read() (CVE-2026-80578) 中的指针去同步

在 Linux 内核中,以下漏洞已修复:

mptcp:fastopen:仅使用 SYN 数据 (CVE-2026-80585) 标记 MPTFO 子流

在 Linux 内核中,以下漏洞已修复:

mptcp:选项:如果大小意外,则重置 DSS 字段 (CVE-2026-80586)

在 Linux 内核中,以下漏洞已修复:

mptcp:避免合并某些传入的子选项 (CVE-2026-80587)

在 Linux 内核中,以下漏洞已修复:

mptcp:在收到 RX 路径错误时回收向前分配的内存 (CVE-2026-80588)

在 Linux 内核中,以下漏洞已修复:

block:释放从未添加的磁盘时停止超时定时器 (CVE-2026-80589)

在 Linux 内核中,以下漏洞已修复:

inet:frags:重组前从片段中剥离 GSO 状态 (CVE-2026-80590)

在 Linux 内核中,以下漏洞已修复:

ptp:vmclock:阻止只读映射变为可写入 (CVE-2026-80724)

在 Linux 内核中,以下漏洞已修复:

net:gro:正确验证 BIG TCP 聚合标准 (CVE-2026-80725)

在 Linux 内核中,以下漏洞已修复:

KVM:x86/mmu:创建子影子页 (CVE-2026-80726) 时警告并清除 role.invalid

在 Linux 内核中,以下漏洞已修复:

x86/mce:在 CMCI 发现之前设置轮询定时器 (CVE-2026-80727)

在 Linux 内核中,以下漏洞已修复:

net:删除 dev_validate_header 中的 CAP_SYS_RAWIO 零填充 (CVE-2026-80731)

在 Linux 内核中,以下漏洞已修复:

net:从 sk_mc_loop()CVE-2026-80733 () 中删除 WARN_ON_ONCE()

在 Linux 内核中,以下漏洞已修复:

serial: amba-pl011: 同步 DMA 拆卸 (CVE-2026-80737)

在 Linux 内核中,以下漏洞已修复:

net/mlx5e:TC,获取 devcom lock (CVE-2026-80739) 之前检查流是否为 PEER

在 Linux 内核中,以下漏洞已修复:

af_packet:不发送 tpacket_snd() 中的零字节数据。(CVE-2026-80742)

在 Linux 内核中,以下漏洞已修复:

netfilter:nf_tables_offload:禁止中止路径 (CVE-2026-80744) 中 ENOMEM 的WARN_ON_ONCE

在 Linux 内核中,以下漏洞已修复:

selinux:不取消从未开始的策略转换 (CVE-2026-80756)

在 Linux 内核中,以下漏洞已修复:

selinux:拒绝低于其继承公用 (CVE-2026-80757) 的类权限计数

在 Linux 内核中,以下漏洞已修复:

futex:避免最终放置 (CVE-2026-80758) 时的隐私哈希释放后使用

在 Linux 内核中,以下漏洞已修复:

HID:hyperv:验证初始设备信息边界 (CVE-2026-80765)

在 Linux 内核中,以下漏洞已修复:

futex:修复初始 mm->futex.phash.ref 分配 (CVE-2026-80775) 中的争用

在 Linux 内核中,以下漏洞已修复:

futex:修复隐私哈希大小调整期间 futex_pivot_pending() 中的争用 (CVE-2026-80776)

在 Linux 内核中,以下漏洞已修复:

futex/pi:插入专用 futex exec() 争用 (CVE-2026-80777)

在 Linux 内核中,以下漏洞已修复:

futex/pi:拒绝跨 mm 私有 futex 所有者 (CVE-2026-80778)

在 Linux 内核中,以下漏洞已修复:

HID:core:修复 hid_set_field() (CVE-2026-80781) 中 field->usage 的 OOB 读取

在 Linux 内核中,以下漏洞已修复:

mptcp:pm:修复 alloc-during-teardown 争用造成的内存泄漏 (CVE-2026-80784)

在 Linux 内核中,以下漏洞已修复:

ipv6:修复 ip6_finish_output2() 中的释放后使用 (CVE-2026-80792)

在 Linux 内核中,以下漏洞已修复:

ipv4:拒绝 ip_do_fragment() (CVE-2026-80793) 中过小的 MTU

在 Linux 内核中,以下漏洞已修复:

xfs:在字段访问 (CVE-2026-80805) 之前验证 attr 条目指针

在 Linux 内核中,以下漏洞已修复:

ext4:不对新的加密文件启用 DAX (CVE-2026-80806)

在 Linux 内核中,以下漏洞已修复:

ext4:停止重试饱和的 xattr 缓存条目 (CVE-2026-80808)

在 Linux 内核中,以下漏洞已修复:

io_uring/rsrc:修复 io_vec_fill_bvec() (CVE-2026-80810) 中的作品集大小溢出

在 Linux 内核中,以下漏洞已修复:

io_uring/cmd:修复不回收异步 cmd 时的 iovec 泄漏 (CVE-2026-80811)

在 Linux 内核中,以下漏洞已修复:

iommu/tegra241-cmdqv:修复拆卸 (CVE-2026-80818CMD_SYNC) 时的释放后使用

在 Linux 内核中,以下漏洞已修复:

net/tls:异步解密失败 (CVE-2026-80904) 之后 tls_sw_splice_read() 失败

在 Linux 内核中,以下漏洞已修复:

net:tap:修复发送 VLAN 标记的帧 (CVE-2026-80905) 时错误的transport_header

在 Linux 内核中,以下漏洞已修复:

net:packet:修复发送 VLAN 标签的帧 (CVE-2026-80906) 时错误的transport_header

在 Linux 内核中,以下漏洞已修复:

selinux:拒绝 security_get_classes() (CVE-2026-80912) 中未声明的类值

在 Linux 内核中,以下漏洞已修复:

selinux:需要定义每个布尔值 (CVE-2026-80913)

在 Linux 内核中,以下漏洞已修复:

PCI:host-generic:修复 32 位 CAM 系统中的空指针取消引用 (CVE-2026-80917)

在 Linux 内核中,以下漏洞已修复:

HID:core:修复长项目 (CVE-2026-80918) 中的数字/指针类型混淆

Tenable 已直接从测试产品的安全公告中提取上述描述块。

请注意,Nessus 尚未测试这些问题,而是只依据应用程序自我报告的版本号进行判断。

解决方案

运行“dnf update kernel6.18 --releasever 2023.12.20260928”或“dnf update --advisory ALAS2023-2026-3139 --releasever 2023.12.20260928”以更新系统。

另见

https://alas.aws.amazon.com//AL2023/ALAS2023-2026-3139.html

https://alas.aws.amazon.com/faqs.html

https://explore.alas.aws.amazon.com/CVE-2026-68082.html

https://explore.alas.aws.amazon.com/CVE-2026-68159.html

https://explore.alas.aws.amazon.com/CVE-2026-74483.html

https://explore.alas.aws.amazon.com/CVE-2026-74517.html

https://explore.alas.aws.amazon.com/CVE-2026-74582.html

https://explore.alas.aws.amazon.com/CVE-2026-74583.html

https://explore.alas.aws.amazon.com/CVE-2026-74586.html

https://explore.alas.aws.amazon.com/CVE-2026-74587.html

https://explore.alas.aws.amazon.com/CVE-2026-74588.html

https://explore.alas.aws.amazon.com/CVE-2026-74589.html

https://explore.alas.aws.amazon.com/CVE-2026-74591.html

https://explore.alas.aws.amazon.com/CVE-2026-74592.html

https://explore.alas.aws.amazon.com/CVE-2026-74593.html

https://explore.alas.aws.amazon.com/CVE-2026-74594.html

https://explore.alas.aws.amazon.com/CVE-2026-74595.html

https://explore.alas.aws.amazon.com/CVE-2026-74597.html

https://explore.alas.aws.amazon.com/CVE-2026-74598.html

https://explore.alas.aws.amazon.com/CVE-2026-74601.html

https://explore.alas.aws.amazon.com/CVE-2026-74602.html

https://explore.alas.aws.amazon.com/CVE-2026-74606.html

https://explore.alas.aws.amazon.com/CVE-2026-74608.html

https://explore.alas.aws.amazon.com/CVE-2026-74609.html

https://explore.alas.aws.amazon.com/CVE-2026-74610.html

https://explore.alas.aws.amazon.com/CVE-2026-74611.html

https://explore.alas.aws.amazon.com/CVE-2026-74612.html

https://explore.alas.aws.amazon.com/CVE-2026-74613.html

https://explore.alas.aws.amazon.com/CVE-2026-74614.html

https://explore.alas.aws.amazon.com/CVE-2026-74615.html

https://explore.alas.aws.amazon.com/CVE-2026-74616.html

https://explore.alas.aws.amazon.com/CVE-2026-74618.html

https://explore.alas.aws.amazon.com/CVE-2026-74619.html

https://explore.alas.aws.amazon.com/CVE-2026-74620.html

https://explore.alas.aws.amazon.com/CVE-2026-74624.html

https://explore.alas.aws.amazon.com/CVE-2026-74627.html

https://explore.alas.aws.amazon.com/CVE-2026-74630.html

https://explore.alas.aws.amazon.com/CVE-2026-74632.html

https://explore.alas.aws.amazon.com/CVE-2026-74633.html

https://explore.alas.aws.amazon.com/CVE-2026-74634.html

https://explore.alas.aws.amazon.com/CVE-2026-74635.html

https://explore.alas.aws.amazon.com/CVE-2026-74636.html

https://explore.alas.aws.amazon.com/CVE-2026-74637.html

https://explore.alas.aws.amazon.com/CVE-2026-74644.html

https://explore.alas.aws.amazon.com/CVE-2026-74652.html

https://explore.alas.aws.amazon.com/CVE-2026-74653.html

https://explore.alas.aws.amazon.com/CVE-2026-74654.html

https://explore.alas.aws.amazon.com/CVE-2026-74656.html

https://explore.alas.aws.amazon.com/CVE-2026-74657.html

https://explore.alas.aws.amazon.com/CVE-2026-74658.html

https://explore.alas.aws.amazon.com/CVE-2026-74660.html

https://explore.alas.aws.amazon.com/CVE-2026-74662.html

https://explore.alas.aws.amazon.com/CVE-2026-74663.html

https://explore.alas.aws.amazon.com/CVE-2026-74664.html

https://explore.alas.aws.amazon.com/CVE-2026-74665.html

https://explore.alas.aws.amazon.com/CVE-2026-74666.html

https://explore.alas.aws.amazon.com/CVE-2026-74667.html

https://explore.alas.aws.amazon.com/CVE-2026-74668.html

https://explore.alas.aws.amazon.com/CVE-2026-74669.html

https://explore.alas.aws.amazon.com/CVE-2026-74670.html

https://explore.alas.aws.amazon.com/CVE-2026-74671.html

https://explore.alas.aws.amazon.com/CVE-2026-74672.html

https://explore.alas.aws.amazon.com/CVE-2026-74673.html

https://explore.alas.aws.amazon.com/CVE-2026-74675.html

https://explore.alas.aws.amazon.com/CVE-2026-74676.html

https://explore.alas.aws.amazon.com/CVE-2026-74683.html

https://explore.alas.aws.amazon.com/CVE-2026-74684.html

https://explore.alas.aws.amazon.com/CVE-2026-74688.html

https://explore.alas.aws.amazon.com/CVE-2026-74695.html

https://explore.alas.aws.amazon.com/CVE-2026-74696.html

https://explore.alas.aws.amazon.com/CVE-2026-74698.html

https://explore.alas.aws.amazon.com/CVE-2026-74700.html

https://explore.alas.aws.amazon.com/CVE-2026-74701.html

https://explore.alas.aws.amazon.com/CVE-2026-74704.html

https://explore.alas.aws.amazon.com/CVE-2026-74705.html

https://explore.alas.aws.amazon.com/CVE-2026-74707.html

https://explore.alas.aws.amazon.com/CVE-2026-74708.html

https://explore.alas.aws.amazon.com/CVE-2026-74709.html

https://explore.alas.aws.amazon.com/CVE-2026-74710.html

https://explore.alas.aws.amazon.com/CVE-2026-74714.html

https://explore.alas.aws.amazon.com/CVE-2026-74717.html

https://explore.alas.aws.amazon.com/CVE-2026-74718.html

https://explore.alas.aws.amazon.com/CVE-2026-74720.html

https://explore.alas.aws.amazon.com/CVE-2026-74722.html

https://explore.alas.aws.amazon.com/CVE-2026-74724.html

https://explore.alas.aws.amazon.com/CVE-2026-74726.html

https://explore.alas.aws.amazon.com/CVE-2026-74728.html

https://explore.alas.aws.amazon.com/CVE-2026-74730.html

https://explore.alas.aws.amazon.com/CVE-2026-74736.html

https://explore.alas.aws.amazon.com/CVE-2026-74739.html

https://explore.alas.aws.amazon.com/CVE-2026-74740.html

https://explore.alas.aws.amazon.com/CVE-2026-74742.html

https://explore.alas.aws.amazon.com/CVE-2026-74743.html

https://explore.alas.aws.amazon.com/CVE-2026-74744.html

https://explore.alas.aws.amazon.com/CVE-2026-74746.html

https://explore.alas.aws.amazon.com/CVE-2026-74748.html

https://explore.alas.aws.amazon.com/CVE-2026-74753.html

https://explore.alas.aws.amazon.com/CVE-2026-80527.html

https://explore.alas.aws.amazon.com/CVE-2026-80528.html

https://explore.alas.aws.amazon.com/CVE-2026-80529.html

https://explore.alas.aws.amazon.com/CVE-2026-80530.html

https://explore.alas.aws.amazon.com/CVE-2026-80534.html

https://explore.alas.aws.amazon.com/CVE-2026-80536.html

https://explore.alas.aws.amazon.com/CVE-2026-80557.html

https://explore.alas.aws.amazon.com/CVE-2026-80558.html

https://explore.alas.aws.amazon.com/CVE-2026-80561.html

https://explore.alas.aws.amazon.com/CVE-2026-80572.html

https://explore.alas.aws.amazon.com/CVE-2026-80574.html

https://explore.alas.aws.amazon.com/CVE-2026-80578.html

https://explore.alas.aws.amazon.com/CVE-2026-80585.html

https://explore.alas.aws.amazon.com/CVE-2026-80586.html

https://explore.alas.aws.amazon.com/CVE-2026-80587.html

https://explore.alas.aws.amazon.com/CVE-2026-80588.html

https://explore.alas.aws.amazon.com/CVE-2026-80589.html

https://explore.alas.aws.amazon.com/CVE-2026-80590.html

https://explore.alas.aws.amazon.com/CVE-2026-80724.html

https://explore.alas.aws.amazon.com/CVE-2026-80725.html

https://explore.alas.aws.amazon.com/CVE-2026-80726.html

https://explore.alas.aws.amazon.com/CVE-2026-80727.html

https://explore.alas.aws.amazon.com/CVE-2026-80731.html

https://explore.alas.aws.amazon.com/CVE-2026-80733.html

https://explore.alas.aws.amazon.com/CVE-2026-80737.html

https://explore.alas.aws.amazon.com/CVE-2026-80739.html

https://explore.alas.aws.amazon.com/CVE-2026-80742.html

https://explore.alas.aws.amazon.com/CVE-2026-80744.html

https://explore.alas.aws.amazon.com/CVE-2026-80756.html

https://explore.alas.aws.amazon.com/CVE-2026-80757.html

https://explore.alas.aws.amazon.com/CVE-2026-80758.html

https://explore.alas.aws.amazon.com/CVE-2026-80765.html

https://explore.alas.aws.amazon.com/CVE-2026-80775.html

https://explore.alas.aws.amazon.com/CVE-2026-80776.html

https://explore.alas.aws.amazon.com/CVE-2026-80777.html

https://explore.alas.aws.amazon.com/CVE-2026-80778.html

https://explore.alas.aws.amazon.com/CVE-2026-80781.html

https://explore.alas.aws.amazon.com/CVE-2026-80784.html

https://explore.alas.aws.amazon.com/CVE-2026-80792.html

https://explore.alas.aws.amazon.com/CVE-2026-80793.html

https://explore.alas.aws.amazon.com/CVE-2026-80805.html

https://explore.alas.aws.amazon.com/CVE-2026-80806.html

https://explore.alas.aws.amazon.com/CVE-2026-80808.html

https://explore.alas.aws.amazon.com/CVE-2026-80810.html

https://explore.alas.aws.amazon.com/CVE-2026-80811.html

https://explore.alas.aws.amazon.com/CVE-2026-80818.html

https://explore.alas.aws.amazon.com/CVE-2026-80904.html

https://explore.alas.aws.amazon.com/CVE-2026-80905.html

https://explore.alas.aws.amazon.com/CVE-2026-80906.html

https://explore.alas.aws.amazon.com/CVE-2026-80912.html

https://explore.alas.aws.amazon.com/CVE-2026-80913.html

https://explore.alas.aws.amazon.com/CVE-2026-80917.html

https://explore.alas.aws.amazon.com/CVE-2026-80918.html

插件详情

严重性: Critical

ID: 351016

文件名: al2023_ALAS2023-2026-3139.nasl

版本: 1.1

类型: Local

代理: unix

发布时间: 2026/9/29

最近更新时间: 2026/9/29

支持的传感器: Frictionless Assessment AWS, Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Continuous Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

风险信息

VPR

风险因素: High

分数: 7.6

百分位: 98.35

CVSS v2

风险因素: Critical

基本分数: 10

时间分数: 7.8

矢量: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS 分数来源: CVE-2026-80725

CVSS v3

风险因素: Critical

基本分数: 10

时间分数: 9

矢量: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

时间矢量: CVSS:3.0/E:P/RL:O/RC:C

CVSS 分数来源: CVE-2026-74705

漏洞信息

CPE: cpe:/o:amazon:linux:2023, p-cpe:/a:amazon:linux:bpftool6.18-debuginfo, p-cpe:/a:amazon:linux:bpftool6.18, p-cpe:/a:amazon:linux:kernel-livepatch-6.18.48-107.148, p-cpe:/a:amazon:linux:kernel6.18-debuginfo-common-aarch64, p-cpe:/a:amazon:linux:kernel6.18-debuginfo-common-x86_64, p-cpe:/a:amazon:linux:kernel6.18-debuginfo, p-cpe:/a:amazon:linux:kernel6.18-devel, p-cpe:/a:amazon:linux:kernel6.18-headers, p-cpe:/a:amazon:linux:kernel6.18-modules-extra-common, p-cpe:/a:amazon:linux:kernel6.18-modules-extra, p-cpe:/a:amazon:linux:kernel6.18-tools-debuginfo, p-cpe:/a:amazon:linux:kernel6.18-tools-devel, p-cpe:/a:amazon:linux:kernel6.18-tools, p-cpe:/a:amazon:linux:kernel6.18, p-cpe:/a:amazon:linux:microvm-kernel6.18, p-cpe:/a:amazon:linux:perf6.18-debuginfo, p-cpe:/a:amazon:linux:perf6.18, p-cpe:/a:amazon:linux:python3-perf6.18-debuginfo, p-cpe:/a:amazon:linux:python3-perf6.18

必需的 KB 项: Host/local_checks_enabled, Host/AmazonLinux/release, Host/AmazonLinux/rpm-list

可利用: true

易利用性: Exploits are available

补丁发布日期: 2026/9/29

漏洞发布日期: 2026/8/8

参考资料信息

CVE: CVE-2026-68082, CVE-2026-68159, CVE-2026-74483, CVE-2026-74517, CVE-2026-74582, CVE-2026-74583, CVE-2026-74586, CVE-2026-74587, CVE-2026-74588, CVE-2026-74589, CVE-2026-74591, CVE-2026-74592, CVE-2026-74593, CVE-2026-74594, CVE-2026-74595, CVE-2026-74597, CVE-2026-74598, CVE-2026-74601, CVE-2026-74602, CVE-2026-74606, CVE-2026-74608, CVE-2026-74609, CVE-2026-74610, CVE-2026-74611, CVE-2026-74612, CVE-2026-74613, CVE-2026-74614, CVE-2026-74615, CVE-2026-74616, CVE-2026-74618, CVE-2026-74619, CVE-2026-74620, CVE-2026-74624, CVE-2026-74627, CVE-2026-74630, CVE-2026-74632, CVE-2026-74633, CVE-2026-74634, CVE-2026-74635, CVE-2026-74636, CVE-2026-74637, CVE-2026-74644, CVE-2026-74652, CVE-2026-74653, CVE-2026-74654, CVE-2026-74656, CVE-2026-74657, CVE-2026-74658, CVE-2026-74660, CVE-2026-74662, CVE-2026-74663, CVE-2026-74664, CVE-2026-74665, CVE-2026-74666, CVE-2026-74667, CVE-2026-74668, CVE-2026-74669, CVE-2026-74670, CVE-2026-74671, CVE-2026-74672, CVE-2026-74673, CVE-2026-74675, CVE-2026-74676, CVE-2026-74683, CVE-2026-74684, CVE-2026-74688, CVE-2026-74695, CVE-2026-74696, CVE-2026-74698, CVE-2026-74700, CVE-2026-74701, CVE-2026-74704, CVE-2026-74705, CVE-2026-74707, CVE-2026-74708, CVE-2026-74709, CVE-2026-74710, CVE-2026-74714, CVE-2026-74717, CVE-2026-74718, CVE-2026-74720, CVE-2026-74722, CVE-2026-74724, CVE-2026-74726, CVE-2026-74728, CVE-2026-74730, CVE-2026-74736, CVE-2026-74739, CVE-2026-74740, CVE-2026-74742, CVE-2026-74743, CVE-2026-74744, CVE-2026-74746, CVE-2026-74748, CVE-2026-74753, CVE-2026-80527, CVE-2026-80528, CVE-2026-80529, CVE-2026-80530, CVE-2026-80534, CVE-2026-80536, CVE-2026-80557, CVE-2026-80558, CVE-2026-80561, CVE-2026-80572, CVE-2026-80574, CVE-2026-80578, CVE-2026-80585, CVE-2026-80586, CVE-2026-80587, CVE-2026-80588, CVE-2026-80589, CVE-2026-80590, CVE-2026-80724, CVE-2026-80725, CVE-2026-80726, CVE-2026-80727, CVE-2026-80731, CVE-2026-80733, CVE-2026-80737, CVE-2026-80739, CVE-2026-80742, CVE-2026-80744, CVE-2026-80756, CVE-2026-80757, CVE-2026-80758, CVE-2026-80765, CVE-2026-80775, CVE-2026-80776, CVE-2026-80777, CVE-2026-80778, CVE-2026-80781, CVE-2026-80784, CVE-2026-80792, CVE-2026-80793, CVE-2026-80805, CVE-2026-80806, CVE-2026-80808, CVE-2026-80810, CVE-2026-80811, CVE-2026-80818, CVE-2026-80904, CVE-2026-80905, CVE-2026-80906, CVE-2026-80912, CVE-2026-80913, CVE-2026-80917, CVE-2026-80918