Linux Distros 未修补的漏洞:CVE-2026-84783

high Nessus 插件 ID 351203

简介

Linux/Unix 主机上安装的一个或多个程序包存在漏洞,但供应商表示不会修补此漏洞。

描述

Linux/Unix 主机中安装的一个或多个程序包受到一个漏洞影响,而供应商没有提供补丁程序。

- 问题摘要:多个线程首次并发使用同一 X.509 证书时,可能导致在另一个线程仍在使用缓存的扩展数据时释放该数据。影响汇总:如果多个连接同时构建到同一个受信任 CA 证书的首个证书链,则未经身份验证的远程对等机可导致请求客户端证书的多线程 TLS 客户端或多线程 TLS 服务器崩溃。这是释放后使用读取,可能会造成进程崩溃,从而导致拒绝服务。CWE:CWE-416:释放后使用 描述:OpenSSL 在第一次需要证书的 X.509v3 扩展的解码值时将其缓存到对象内 X509 。在 OpenSSL 4.0 中,此缓存分两个阶段构建:在保持证书读取锁定的同时计算扩展值,然后在写入锁定下将结果安装到证书中。由于读取锁定不会排除其他读取器,因此多个线程可以同时计算同一证书的缓存。随后获取写锁定的每个线程都会安装自己的结果并释放前面的线程安装的值,即使该较早的线程已将缓存标记为完整并可能已将指针返回给其调用程序也是如此。仍在使用这些指针的调用程序随后会读取释放的内存。线程之间共享的任何证书在第一次解码其扩展时都会暴露。在 TLS 中,存在风险的证书是用于以任何方式进行链验证的受信任 CA 证书,因为每个连接均共享这些证书,并且其扩展在首次构建链时会得到解码和缓存。对等机发送的证书会针对每个连接单独解码,且不共享,因此不会受到影响。在验证服务器证书的 TLS 客户端,或请求并验证客户端证书的 TLS 服务器中,只有在多个连接同时构建到相同受信任 CA 的首条链时,才会发生释放后使用。FIPS 影响:
否 FIPS 模块不受影响,因为 X.509 证书处理超出了 OpenSSL FIPS 模块边界。OpenSSL 4.0 容易受到此问题的影响。OpenSSL 3.6、 3.5、 3.4和 3.0不受 1.1.11.0.2 此问题的影响。OpenSSL 4.0 用户应在发布 OpenSSL 4.0.3 后升级到该版本。此问题由 Tim Becker (Xint.io) 于 2026 年 8 月 27 日报告,aydinmercan 在 2026 年 8 月 31 日的公开报告中独立报告。
该补丁已由 Bob Beck 开发。-- cut(供内部使用的非发布元数据) -- 报告者:
Tim Becker (Xint.io),aydinmercan 修复者:Bob Beck (CVE-2026-84783)

请注意,Nessus 依赖供应商报告的程序包是否存在进行判断。

解决方案

目前尚未有任何已知的解决方案。

另见

https://access.redhat.com/security/cve/cve-2026-84783

https://ubuntu.com/security/CVE-2026-84783

插件详情

严重性: High

ID: 351203

文件名: unpatched_CVE_2026_84783.nasl

版本: 1.2

类型: Local

代理: unix

系列: Misc.

发布时间: 2026/9/29

最近更新时间: 2026/9/30

支持的传感器: Frictionless Assessment AWS, Frictionless Assessment Azure, Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

风险信息

VPR

风险因素: Low

分数: 3

百分位: 23.63

CVSS v2

风险因素: Medium

基本分数: 4.3

时间分数: 3.7

矢量: CVSS2#AV:N/AC:M/Au:N/C:N/I:N/A:P

CVSS 分数来源: CVE-2026-84783

CVSS v3

风险因素: High

基本分数: 7.5

时间分数: 6.9

矢量: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

时间矢量: CVSS:3.0/E:U/RL:U/RC:C

漏洞信息

CPE: cpe:/o:canonical:ubuntu_linux:22.04:-:lts, cpe:/o:centos:centos:7, cpe:/o:centos:centos:8, cpe:/o:redhat:enterprise_linux:10, cpe:/o:redhat:enterprise_linux:7, cpe:/o:redhat:enterprise_linux:8, cpe:/o:redhat:enterprise_linux:9, p-cpe:/a:canonical:ubuntu_linux:nodejs, p-cpe:/a:centos:centos:aavmf, p-cpe:/a:centos:centos:compat-openssl10, p-cpe:/a:centos:centos:compat-openssl11, p-cpe:/a:centos:centos:edk2-aarch64, p-cpe:/a:centos:centos:edk2-ovmf, p-cpe:/a:centos:centos:edk2-tools-doc, p-cpe:/a:centos:centos:edk2-tools, p-cpe:/a:centos:centos:edk2, p-cpe:/a:centos:centos:mingw-openssl, p-cpe:/a:centos:centos:mingw32-openssl, p-cpe:/a:centos:centos:mingw64-openssl, p-cpe:/a:centos:centos:mokutil, p-cpe:/a:centos:centos:openssl-devel, p-cpe:/a:centos:centos:openssl-libs, p-cpe:/a:centos:centos:openssl-perl, p-cpe:/a:centos:centos:openssl-static, p-cpe:/a:centos:centos:openssl, p-cpe:/a:centos:centos:ovmf, p-cpe:/a:centos:centos:shim-aa64, p-cpe:/a:centos:centos:shim-ia32, p-cpe:/a:centos:centos:shim-signed, p-cpe:/a:centos:centos:shim-unsigned-aarch64, p-cpe:/a:centos:centos:shim-unsigned-x64, p-cpe:/a:centos:centos:shim-x64, p-cpe:/a:centos:centos:shim, p-cpe:/a:redhat:enterprise_linux:aavmf, p-cpe:/a:redhat:enterprise_linux:compat-openssl10, p-cpe:/a:redhat:enterprise_linux:compat-openssl11, p-cpe:/a:redhat:enterprise_linux:edk2-aarch64, p-cpe:/a:redhat:enterprise_linux:edk2-ovmf, p-cpe:/a:redhat:enterprise_linux:edk2-tools-doc, p-cpe:/a:redhat:enterprise_linux:edk2-tools, p-cpe:/a:redhat:enterprise_linux:edk2, p-cpe:/a:redhat:enterprise_linux:mingw-openssl, p-cpe:/a:redhat:enterprise_linux:mingw32-openssl, p-cpe:/a:redhat:enterprise_linux:mingw64-openssl, p-cpe:/a:redhat:enterprise_linux:mokutil, p-cpe:/a:redhat:enterprise_linux:openssl-devel, p-cpe:/a:redhat:enterprise_linux:openssl-libs, p-cpe:/a:redhat:enterprise_linux:openssl-perl, p-cpe:/a:redhat:enterprise_linux:openssl-static, p-cpe:/a:redhat:enterprise_linux:openssl, p-cpe:/a:redhat:enterprise_linux:ovmf, p-cpe:/a:redhat:enterprise_linux:shim-aa64, p-cpe:/a:redhat:enterprise_linux:shim-ia32, p-cpe:/a:redhat:enterprise_linux:shim-signed, p-cpe:/a:redhat:enterprise_linux:shim-unsigned-aarch64, p-cpe:/a:redhat:enterprise_linux:shim-unsigned-x64, p-cpe:/a:redhat:enterprise_linux:shim-x64, p-cpe:/a:redhat:enterprise_linux:shim

必需的 KB 项: Host/local_checks_enabled, Host/cpu, global_settings/vendor_unpatched, Host/OS/identifier

易利用性: No known exploits are available

漏洞发布日期: 2026/9/29

参考资料信息

CVE: CVE-2026-84783