Amazon Linux 2:内核 (ALASKERNEL-5.10-2026-132)

medium Nessus 插件 ID 351061

简介

远程 Amazon Linux 2 主机缺少安全更新。

描述

远程主机上安装的内核版本低于 5.10.268-266.1092。因此,会受到 ALAS2KERNEL-5.10-2026-132 公告中提及的多个漏洞影响。

在 Linux 内核中,以下漏洞已修复:

drm/virtio:对平面更新使用不间断的 resv 锁定 (CVE-2026-64098)

在 Linux 内核中,以下漏洞已修复:

bpf:如果 BPF LSM 未初始化,则拒绝BPF_MAP_TYPE_INODE_STORAGE创建

当设置 CONFIG_BPF_LSM=y 时,BPF inode 存储映射 (BPF_MAP_TYPE_INODE_STORAGE) 被编译到内核中。但是,如果在引导时未显式启用 BPF LSM(例如从 lsm= boot 参数中忽略),则绝不会为 BPF LSM 执行 lsm_prepare()。

因此,BPF inode 安全 blob 偏移 (bpf_lsm_blob_sizes.lbs_inode) 永远不会初始化并且会保持其默认编译大小 8 字节,而不是更新为超过预留结构rcu_head(通常为 16 字节或更多)的有效偏移。

当特权用户创建并更新BPF_MAP_TYPE_INODE_STORAGEmap时,bpf_inode() 评估 inode->i_security + 8。这会在 inode >i_security blob 的开头错误地将 struct rcu_head.func 回调指针别名化。在后续映射元素清除或 inode 析构期间,将 NULL 写入 owner_storage 会清除 queuedRCU 回调指针。当 rcu_do_batch() 稍后执行 queuedcallback 时,它会尝试在地址0x0处提取指令,从而立即触发内核恐慌。

通过引入标有 __ro_after_init 标记的全局bpf_lsm_initialized布尔来修复此问题。当 LSM 框架成功注册 BPF LSM 时,在 bpf_lsm_init() 中将此标记设置为 true。在此标记上inode_storage_map_alloc() 中进行 gate mapallocation,如果 BPF LSM 反过来未初始化则返回 EOPNOTSUPP。

这种故障快速方法可防止用户空间在缺少支持 BPF LSM 基础架构时分配 inodestorage 映射,从而避免僵尸映射状态。(CVE-2026-64192)

在 Linux 内核中,以下漏洞已修复:

i2c:core:修复适配器注销争用 (CVE-2026-64279)

在 Linux 内核中,以下漏洞已修复:

libceph:修复 decode_lockers() (CVE-2026-68082) 中的两个不安全的裸解码

在 Linux 内核中,以下漏洞已修复:

audit:修复 audit_dupe_exe() 中的递归锁定死锁 (CVE-2026-68096)

在 Linux 内核中,以下漏洞已修复:

super:修复冻结区块设备中的紧急解冻死锁 (CVE-2026-68132)

在 Linux 内核中,以下漏洞已修复:

net:gro:修复刷新标记的 skbs 的双重聚合 (CVE-2026-68136)

在 Linux 内核中,以下漏洞已修复:

ftrace:添加全局互斥体以序列化 trace_parser 访问 (CVE-2026-68146)

在 Linux 内核中,以下漏洞已修复:

libceph:将 pg_{temp,upmap,upmap_items} 长度绑定为 CEPH_PG_MAX_SIZE (CVE-2026-68159)

在 Linux 内核中,以下漏洞已修复:

sctp:避免在 netns 拆卸期间auth_enable sysctl UAF (CVE-2026-68162)

在 Linux 内核中,以下漏洞已修复:

drm/virtio:将 EDID 块读取绑定到响应缓冲区 (CVE-2026-68255)

在 Linux 内核中,以下漏洞已修复:

drm/dp/mst:修复边带回复解析器 (CVE-2026-68277) 中 2 字节字段上的 OOB 读取

在 Linux 内核中,以下漏洞已修复:

drm/dp/mst:修复边带区块累积 (CVE-2026-68278) 中的缓冲区溢出

在 Linux 内核中,以下漏洞已修复:

drm/dp/mst:修复远程 DPCD/I2C 边带回复解析器中的 OOB 读取 (CVE-2026-68279)

在 Linux 内核中,以下漏洞已修复:

mmc:vub300:修复探查失败时的释放后使用 (CVE-2026-72073)

在 Linux 内核中,以下漏洞已修复:

scsi:target:将 PR-OUT TransportID 解析绑定到已接收的缓冲区 (CVE-2026-72084)

在 Linux 内核中,以下漏洞已修复:

scsi:lpfc:修复 lpfc_sli4_driver_resource_setup() (CVE-2026-72087) 中的内存泄漏

在 Linux 内核中,以下漏洞已修复:

dm-verity:使错误计数器原子化 (CVE-2026-72096)

在 Linux 内核中,以下漏洞已修复:

dm-integrity:不将 hash_offset 递增两次 (CVE-2026-72099)

在 Linux 内核中,以下漏洞已修复:

jbd2:修复 jbd2_journal_initialize_fast_commit() (CVE-2026-72225) 中的整数下溢

在 Linux 内核中,以下漏洞已修复:

selinux:避免 selinux_sctp_bind_connect() (CVE-2026-72242) 中的sk_socket取消引用

在 Linux 内核中,以下漏洞已修复:

netfilter:nft_set_pipapo:不将错误克隆泄漏到未来的事务 (CVE-2026-72252)

在 Linux 内核中,以下漏洞已修复:

netfilter:nf_conntrack_sip:访问 skb_dst() 前先对其进行验证 (CVE-2026-72253)

在 Linux 内核中,以下漏洞已修复:

netfilter:nf_queue:当 NFQUEUE 保留假 dst (CVE-2026-72255) 时 pin 桥接设备

在 Linux 内核中,以下漏洞已修复:

KVM:arm64:vgic:处理中断相关性变更和 LPI 禁用 (CVE-2026-72288) 之间的争用

在 Linux 内核中,以下漏洞已修复:

tipc:限制入队跟踪点 (CVE-2026-72299) 中的套接字队列转储

在 Linux 内核中,以下漏洞已修复:

mlxsw:修复 mlxsw_sp_port_lag_join() (CVE-2026-72308) 中的 refcount 泄漏

在 Linux 内核中,以下漏洞已修复:

sctp:解包 Cookie 后添加 INIT 验证 (CVE-2026-72398)

在 Linux 内核中,以下漏洞已修复:

sctp:修复 INIT 处理中的err_chunk内存泄漏 (CVE-2026-72413)

在 Linux 内核中,以下漏洞已修复:

netfilter:nft_compat:ebtables 仿真必须拒绝非桥接目标 (CVE-2026-72416)

在 Linux 内核中,以下漏洞已修复:

xprtrdma:重新发布以接收畸形回复的缓冲区 (CVE-2026-72464)

在 Linux 内核中,以下漏洞已修复:

RDMA/rxe:修复 get_srq_wqe 中的 TOCTOU 堆溢出 (CVE-2026-74378)

在 Linux 内核中,以下漏洞已修复:

OPP:修复 OPP 添加和 lookup (CVE-2026-74405) 之间的争用

在 Linux 内核中,以下漏洞已修复:

scsi:scsi_debug:修复 REPORT ZONES alloc_len下溢 OOB 写入 (CVE-2026-74470)

在 Linux 内核中,以下漏洞已修复:

net:pktgen:修复 proc 条目释放后使用 (CVE-2026-74479)

在 Linux 内核中,以下漏洞已修复:

binfmt_misc:还原删除条目 (CVE-2026-74487) 时的写入权限

在 Linux 内核中,以下漏洞已修复:

netfilter:nf_tables:使每个表 nft_object RHLTABLE (CVE-2026-74565)

在 Linux 内核中,以下漏洞已修复:

packet:在非环发送路径中使用一致的hard_header_len (CVE-2026-74582)

在 Linux 内核中,以下漏洞已修复:

sched/psi:关闭 psi_cgroup_free() ()CVE-2026-74594 中的 rtpoll_timer

在 Linux 内核中,以下漏洞已修复:

ring-buffer:将current_context用于安全的每 CPU 缓冲区交换 (CVE-2026-74601)

在 Linux 内核中,以下漏洞已修复:

net/sched:act_gact、act_police:范围检查回退控制操作 (CVE-2026-74620)

在 Linux 内核中,以下漏洞已修复:

mm/huge_memory:修复huge_zero_pfn争用 (CVE-2026-74632)

在 Linux 内核中,以下漏洞已修复:

perf/core:修复同级分离 (CVE-2026-74637) 之后的组组首导符释放后使用

在 Linux 内核中,以下漏洞已修复:

ipv4:修复 RTA_VIA nexthops 的CVE-2026-74657 fib_nlmsg_size()

在 Linux 内核中,以下漏洞已修复:

inet:frags:布防定时器 (CVE-2026-74662) 之前发布队列

在 Linux 内核中,以下漏洞已修复:

net/sched:拒绝过深的 qdisc 层次结构 (CVE-2026-74663)

在 Linux 内核中,以下漏洞已修复:

packet:通过环重新配置 (CVE-2026-74666) 同步压力清除

在 Linux 内核中,以下漏洞已修复:

packet:在 TX_RING 发送路径中使用一致的hard_header_len (CVE-2026-74668)

在 Linux 内核中,以下漏洞已修复:

net:tap:在解析 tap_get_user_xdp() 中的 virtio net 标头之前设置 skb->dev (CVE-2026-74684)

在 Linux 内核中,以下漏洞已修复:

net/sched:cls_api:破坏锁定的分类器 (CVE-2026-74700) 时始终获取 rtnl_lock

在 Linux 内核中,以下漏洞已修复:

netfilter:flowtable:发布 GC 可见元组 last (CVE-2026-74746)

在 Linux 内核中,以下漏洞已修复:

netfilter:ipset:修复 list:set GC 与 swap (CVE-2026-74748) 之间的引用计数争用

在 Linux 内核中,以下漏洞已修复:

ceph:修复将 __ceph_get_caps() 挂起mds_wanted (CVE-2026-80527)

在 Linux 内核中,以下漏洞已修复:

ceph:避免使用 current->journal_info (CVE-2026-80528) 时回收 fs

在 Linux 内核中,以下漏洞已修复:

xfs:修复 xfs_dq_get_next_id (CVE-2026-80534) 中出错时的 ilock 泄漏

在 Linux 内核中,以下漏洞已修复:

xfs:边界检查缓冲区日志项的脏位图 (CVE-2026-80536)

在 Linux 内核中,以下漏洞已修复:

libceph:通过缺少的边界检查 (CVE-2026-80557) 修复 decode_watchers() 中的 OOB 读取

在 Linux 内核中,以下漏洞已修复:

libceph:避免使用 primary_temp (CVE-2026-80558) 中的无效 osd 索引

在 Linux 内核中,以下漏洞已修复:

libceph:修复 decode_locker() (CVE-2026-80561) 中的多种不安全解码

在 Linux 内核中,以下漏洞已修复:

mptcp:选项:如果大小意外,则重置 DSS 字段 (CVE-2026-80586)

在 Linux 内核中,以下漏洞已修复:

inet:frags:重组前从片段中剥离 GSO 状态 (CVE-2026-80590)

在 Linux 内核中,以下漏洞已修复:

serial: amba-pl011: 同步 DMA 拆卸 (CVE-2026-80737)

在 Linux 内核中,以下漏洞已修复:

af_packet:不发送 tpacket_snd() 中的零字节数据。(CVE-2026-80742)

在 Linux 内核中,以下漏洞已修复:

netfilter:nf_tables_offload:禁止中止路径 (CVE-2026-80744) 中 ENOMEM 的WARN_ON_ONCE

在 Linux 内核中,以下漏洞已修复:

selinux:不取消从未开始的策略转换 (CVE-2026-80756)

在 Linux 内核中,以下漏洞已修复:

selinux:拒绝低于其继承公用 (CVE-2026-80757) 的类权限计数

在 Linux 内核中,以下漏洞已修复:

HID:hyperv:验证初始设备信息边界 (CVE-2026-80765)

在 Linux 内核中,以下漏洞已修复:

HID:core:修复 hid_set_field() (CVE-2026-80781) 中 field->usage 的 OOB 读取

在 Linux 内核中,以下漏洞已修复:

ipv6:修复 ip6_finish_output2() 中的释放后使用 (CVE-2026-80792)

在 Linux 内核中,以下漏洞已修复:

ipv4:拒绝 ip_do_fragment() (CVE-2026-80793) 中过小的 MTU

在 Linux 内核中,以下漏洞已修复:

xfs:在字段访问 (CVE-2026-80805) 之前验证 attr 条目指针

在 Linux 内核中,以下漏洞已修复:

ext4:停止重试饱和的 xattr 缓存条目 (CVE-2026-80808)

在 Linux 内核中,以下漏洞已修复:

rndis_host:在 rndis_rx_fixup() 中添加溢出检查 (CVE-2026-80814)

在 Linux 内核中,以下漏洞已修复:

net:packet:修复发送 VLAN 标签的帧 (CVE-2026-80906) 时错误的transport_header

在 Linux 内核中,以下漏洞已修复:

selinux:需要定义每个布尔值 (CVE-2026-80913)

在 Linux 内核中,以下漏洞已修复:

HID:core:修复长项目 (CVE-2026-80918) 中的数字/指针类型混淆

Tenable 已直接从测试产品的安全公告中提取上述描述块。

请注意,Nessus 尚未测试这些问题,而是只依据应用程序自我报告的版本号进行判断。

解决方案

运行“yum update kernel”或“yum update --advisory ALAS2KERNEL-5.10-2026-132”以更新系统。

另见

https://alas.aws.amazon.com//AL2/ALAS2KERNEL-5.10-2026-132.html

https://alas.aws.amazon.com/faqs.html

https://explore.alas.aws.amazon.com/CVE-2026-64098.html

https://explore.alas.aws.amazon.com/CVE-2026-64192.html

https://explore.alas.aws.amazon.com/CVE-2026-64279.html

https://explore.alas.aws.amazon.com/CVE-2026-68082.html

https://explore.alas.aws.amazon.com/CVE-2026-68096.html

https://explore.alas.aws.amazon.com/CVE-2026-68132.html

https://explore.alas.aws.amazon.com/CVE-2026-68136.html

https://explore.alas.aws.amazon.com/CVE-2026-68146.html

https://explore.alas.aws.amazon.com/CVE-2026-68159.html

https://explore.alas.aws.amazon.com/CVE-2026-68162.html

https://explore.alas.aws.amazon.com/CVE-2026-68255.html

https://explore.alas.aws.amazon.com/CVE-2026-68277.html

https://explore.alas.aws.amazon.com/CVE-2026-68278.html

https://explore.alas.aws.amazon.com/CVE-2026-68279.html

https://explore.alas.aws.amazon.com/CVE-2026-72073.html

https://explore.alas.aws.amazon.com/CVE-2026-72084.html

https://explore.alas.aws.amazon.com/CVE-2026-72087.html

https://explore.alas.aws.amazon.com/CVE-2026-72096.html

https://explore.alas.aws.amazon.com/CVE-2026-72099.html

https://explore.alas.aws.amazon.com/CVE-2026-72225.html

https://explore.alas.aws.amazon.com/CVE-2026-72242.html

https://explore.alas.aws.amazon.com/CVE-2026-72252.html

https://explore.alas.aws.amazon.com/CVE-2026-72253.html

https://explore.alas.aws.amazon.com/CVE-2026-72255.html

https://explore.alas.aws.amazon.com/CVE-2026-72288.html

https://explore.alas.aws.amazon.com/CVE-2026-72299.html

https://explore.alas.aws.amazon.com/CVE-2026-72308.html

https://explore.alas.aws.amazon.com/CVE-2026-72398.html

https://explore.alas.aws.amazon.com/CVE-2026-72413.html

https://explore.alas.aws.amazon.com/CVE-2026-72416.html

https://explore.alas.aws.amazon.com/CVE-2026-72464.html

https://explore.alas.aws.amazon.com/CVE-2026-74378.html

https://explore.alas.aws.amazon.com/CVE-2026-74405.html

https://explore.alas.aws.amazon.com/CVE-2026-74470.html

https://explore.alas.aws.amazon.com/CVE-2026-74479.html

https://explore.alas.aws.amazon.com/CVE-2026-74487.html

https://explore.alas.aws.amazon.com/CVE-2026-74565.html

https://explore.alas.aws.amazon.com/CVE-2026-74582.html

https://explore.alas.aws.amazon.com/CVE-2026-74594.html

https://explore.alas.aws.amazon.com/CVE-2026-74601.html

https://explore.alas.aws.amazon.com/CVE-2026-74620.html

https://explore.alas.aws.amazon.com/CVE-2026-74632.html

https://explore.alas.aws.amazon.com/CVE-2026-74637.html

https://explore.alas.aws.amazon.com/CVE-2026-74657.html

https://explore.alas.aws.amazon.com/CVE-2026-74662.html

https://explore.alas.aws.amazon.com/CVE-2026-74663.html

https://explore.alas.aws.amazon.com/CVE-2026-74666.html

https://explore.alas.aws.amazon.com/CVE-2026-74668.html

https://explore.alas.aws.amazon.com/CVE-2026-74684.html

https://explore.alas.aws.amazon.com/CVE-2026-74700.html

https://explore.alas.aws.amazon.com/CVE-2026-74746.html

https://explore.alas.aws.amazon.com/CVE-2026-74748.html

https://explore.alas.aws.amazon.com/CVE-2026-80527.html

https://explore.alas.aws.amazon.com/CVE-2026-80528.html

https://explore.alas.aws.amazon.com/CVE-2026-80534.html

https://explore.alas.aws.amazon.com/CVE-2026-80536.html

https://explore.alas.aws.amazon.com/CVE-2026-80557.html

https://explore.alas.aws.amazon.com/CVE-2026-80558.html

https://explore.alas.aws.amazon.com/CVE-2026-80561.html

https://explore.alas.aws.amazon.com/CVE-2026-80586.html

https://explore.alas.aws.amazon.com/CVE-2026-80590.html

https://explore.alas.aws.amazon.com/CVE-2026-80737.html

https://explore.alas.aws.amazon.com/CVE-2026-80742.html

https://explore.alas.aws.amazon.com/CVE-2026-80744.html

https://explore.alas.aws.amazon.com/CVE-2026-80756.html

https://explore.alas.aws.amazon.com/CVE-2026-80757.html

https://explore.alas.aws.amazon.com/CVE-2026-80765.html

https://explore.alas.aws.amazon.com/CVE-2026-80781.html

https://explore.alas.aws.amazon.com/CVE-2026-80792.html

https://explore.alas.aws.amazon.com/CVE-2026-80793.html

https://explore.alas.aws.amazon.com/CVE-2026-80805.html

https://explore.alas.aws.amazon.com/CVE-2026-80808.html

https://explore.alas.aws.amazon.com/CVE-2026-80814.html

https://explore.alas.aws.amazon.com/CVE-2026-80906.html

https://explore.alas.aws.amazon.com/CVE-2026-80913.html

https://explore.alas.aws.amazon.com/CVE-2026-80918.html

插件详情

严重性: Medium

ID: 351061

文件名: al2_ALASKERNEL-5_10-2026-132.nasl

版本: 1.1

类型: Local

代理: unix

发布时间: 2026/9/29

最近更新时间: 2026/9/29

支持的传感器: Frictionless Assessment AWS, Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Continuous Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

风险信息

VPR

风险因素: High

分数: 7.6

百分位: 98.3

CVSS v2

风险因素: Medium

基本分数: 4.6

时间分数: 3.4

矢量: CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:C

CVSS 分数来源: CVE-2026-64192

CVSS v3

风险因素: Medium

基本分数: 5.5

时间分数: 4.8

矢量: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

时间矢量: CVSS:3.0/E:U/RL:O/RC:C

漏洞信息

CPE: cpe:/o:amazon:linux:2, p-cpe:/a:amazon:linux:bpftool-debuginfo, p-cpe:/a:amazon:linux:bpftool, p-cpe:/a:amazon:linux:kernel-debuginfo-common-aarch64, p-cpe:/a:amazon:linux:kernel-debuginfo-common-x86_64, p-cpe:/a:amazon:linux:kernel-debuginfo, p-cpe:/a:amazon:linux:kernel-devel, p-cpe:/a:amazon:linux:kernel-headers, p-cpe:/a:amazon:linux:kernel-livepatch-5.10.268-266.1092, p-cpe:/a:amazon:linux:kernel-tools-debuginfo, p-cpe:/a:amazon:linux:kernel-tools-devel, p-cpe:/a:amazon:linux:kernel-tools, p-cpe:/a:amazon:linux:kernel, p-cpe:/a:amazon:linux:perf-debuginfo, p-cpe:/a:amazon:linux:perf, p-cpe:/a:amazon:linux:python-perf-debuginfo, p-cpe:/a:amazon:linux:python-perf

必需的 KB 项: Host/local_checks_enabled, Host/AmazonLinux/release, Host/AmazonLinux/rpm-list

易利用性: No known exploits are available

补丁发布日期: 2026/9/28

漏洞发布日期: 2025/4/29

参考资料信息

CVE: CVE-2026-64098, CVE-2026-64192, CVE-2026-64279, CVE-2026-68082, CVE-2026-68096, CVE-2026-68132, CVE-2026-68136, CVE-2026-68146, CVE-2026-68159, CVE-2026-68162, CVE-2026-68255, CVE-2026-68277, CVE-2026-68278, CVE-2026-68279, CVE-2026-72073, CVE-2026-72084, CVE-2026-72087, CVE-2026-72096, CVE-2026-72099, CVE-2026-72225, CVE-2026-72242, CVE-2026-72252, CVE-2026-72253, CVE-2026-72255, CVE-2026-72288, CVE-2026-72299, CVE-2026-72308, CVE-2026-72398, CVE-2026-72413, CVE-2026-72416, CVE-2026-72464, CVE-2026-74378, CVE-2026-74405, CVE-2026-74470, CVE-2026-74479, CVE-2026-74487, CVE-2026-74565, CVE-2026-74582, CVE-2026-74594, CVE-2026-74601, CVE-2026-74620, CVE-2026-74632, CVE-2026-74637, CVE-2026-74657, CVE-2026-74662, CVE-2026-74663, CVE-2026-74666, CVE-2026-74668, CVE-2026-74684, CVE-2026-74700, CVE-2026-74746, CVE-2026-74748, CVE-2026-80527, CVE-2026-80528, CVE-2026-80534, CVE-2026-80536, CVE-2026-80557, CVE-2026-80558, CVE-2026-80561, CVE-2026-80586, CVE-2026-80590, CVE-2026-80737, CVE-2026-80742, CVE-2026-80744, CVE-2026-80756, CVE-2026-80757, CVE-2026-80765, CVE-2026-80781, CVE-2026-80792, CVE-2026-80793, CVE-2026-80805, CVE-2026-80808, CVE-2026-80814, CVE-2026-80906, CVE-2026-80913, CVE-2026-80918