CentOS Linux 7 [TuxCare] 安全更新:bpftool / kernel / kernel-debug / kernel-debug-devel / kernel-devel / 等多个漏洞 (CENTOS7:CLSA-2026:1789037015)

high Nessus 插件 ID 352722

简介

CentOS Linux 主机缺少一个或多个安全更新。

描述

如 TuxCare CENTOS7:CLSA-2026:1789037015 2026 公告所述,CentOS Linux 7 主机上存在安装的程序包,该漏洞会受到多个漏洞的影响。

- 已修复 Linux 内核中的下列漏洞:scsi: iscsi: Fix conn use after free during resets If we haven't done a unbind target call we can race where iscsi_conn_teardown wakes up the EH thread and then frees the conn while those threads are still accessing the conn ehwait. We can only do one TMF per session so this just moves the TMF fields from the conn to the session. We can then rely on the iscsi_session_teardown->iscsi_remove_session->__iscsi_unbind_session call to remove the target and it's devices, and know after that point there is no device or scsi-ml callout trying to access the session. (CVE-2021-47328)

- 已修复 Linux 内核中的下列漏洞:ext4: improve error handling from ext4_dirhash() The ext4_dirhash() will *almost* never fail, especially when the hash tree feature was first introduced. However, with the addition of support of encrypted, casefolded file names, that function can most certainly fail today. So make sure the callers of ext4_dirhash() properly check for failures, and reflect the errors back up to their callers. (CVE-2023-53473)

- 已修复 Linux 内核中的下列漏洞:iommu/vt-d: Clear Present bit before tearing down context entry When tearing down a context entry, the current implementation zeros the entire 128-bit entry using multiple 64-bit writes. This creates a window where the hardware can fetch a torn entry where some fields are already zeroed while the 'Present' bit is still set leading to unpredictable behavior or spurious faults. While x86 provides strong write ordering, the compiler may reorder writes to the two 64-bit halves of the context entry. Even without compiler reordering, the hardware fetch is not guaranteed to be atomic with respect to multiple CPU writes. Align with the Guidance to Software for Invalidations in the VT-d spec (Section 6.5.3.3) by implementing the recommended ownership handshake: 1. Clear only the 'Present' (P) bit of the context entry first to signal the transition of ownership from hardware to software. 2. Use dma_wmb() to ensure the cleared bit is visible to the IOMMU. 3. Perform the required cache and context-cache invalidation to ensure hardware no longer has cached references to the entry. 4. Fully zero out the entry only after the invalidation is complete. Also, add a dma_wmb() to context_set_present() to ensure the entry is fully initialized before the 'Present' bit becomes visible. (CVE-2026-45944)

- 已修复 Linux 内核中的下列漏洞:ipmi: Add limits to event and receive message requests The driver would just fetch events and receive messages until the BMC said it was done.
To avoid issues with BMCs that never say they are done, add a limit of 10 fetches at a time. In addition, an si interface has an attn state it can return from the hardware which is supposed to cause a flag fetch to see if the driver needs to fetch events or message or a few other things. If the attn bit gets stuck, it's a similar problem. So allow messages in between flag fetches so the driver itself doesn't get stuck.
This is a more general fix than the previous fix for the specific bad BMC, but should fix the more general issue of a BMC that won't stop saying it has data. This has been there from the beginning of the driver.
It's not a bug per-se, but it is accounting for bugs in BMCs. (CVE-2026-46177)

- 已修复 Linux 内核中的下列漏洞:PCI: use generic driver_override infrastructure When a driver is probed through __driver_attach(), the bus' match() callback is called without the device lock held, thus accessing the driver_override field without a lock, which can cause a UAF. Fix this by using the driver-core driver_override infrastructure taking care of proper locking internally. Note that calling match() from __driver_attach() without the device lock held is intentional.
[1] (CVE-2026-53120)

请注意,Nessus 尚未测试这些问题,而是只依据应用程序自我报告的版本号进行判断。

解决方案

根据 TuxCare 公告 CENTOS7:CLSA-2026:1789037015 中的指南更新受影响的程序包。

另见

https://cve.tuxcare.com/els/releases/CLSA-2026:1789037015

http://www.nessus.org/u?aef1b8c9

插件详情

严重性: High

ID: 352722

文件名: tuxcare_centos_7_CLSA-2026-1789037015.nasl

版本: 1.1

类型: Local

代理: unix

发布时间: 2026/9/30

最近更新时间: 2026/9/30

支持的传感器: Continuous Assessment, Nessus Agent, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

风险信息

VPR

风险因素: High

分数: 7.6

百分位: 98.35

Vendor

Vendor Severity: Important

CVSS v2

风险因素: Medium

基本分数: 6.8

时间分数: 5

矢量: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS 分数来源: CVE-2026-64348

CVSS v3

风险因素: High

基本分数: 7.8

时间分数: 6.8

矢量: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

时间矢量: CVSS:3.0/E:U/RL:O/RC:C

漏洞信息

必需的 KB 项: Host/OS/extended-third-party, Host/local_checks_enabled, Host/CentOS/release, Host/CentOS/rpm-list

易利用性: No known exploits are available

补丁发布日期: 2026/9/10

漏洞发布日期: 2022/1/28

参考资料信息

CVE: CVE-2021-47328, CVE-2023-53473, CVE-2026-45944, CVE-2026-46177, CVE-2026-53120, CVE-2026-53186, CVE-2026-63829, CVE-2026-64322, CVE-2026-64323, CVE-2026-64341, CVE-2026-64344, CVE-2026-64348, CVE-2026-64411, CVE-2026-64413, CVE-2026-64422, CVE-2026-64448, CVE-2026-68184, CVE-2026-68300, CVE-2026-68349, CVE-2026-68350, CVE-2026-68351, CVE-2026-68430, CVE-2026-68469, CVE-2026-72051, CVE-2026-72053, CVE-2026-72054, CVE-2026-72055, CVE-2026-72061, CVE-2026-72113, CVE-2026-72115, CVE-2026-72116, CVE-2026-72117, CVE-2026-72118, CVE-2026-72122, CVE-2026-72308, CVE-2026-74456, CVE-2026-74464, CVE-2026-74580, CVE-2026-74587, CVE-2026-74597, CVE-2026-74630, CVE-2026-74637, CVE-2026-74641, CVE-2026-74656, CVE-2026-74682, CVE-2026-74688, CVE-2026-74705, CVE-2026-74725, CVE-2026-74752, CVE-2026-80558, CVE-2026-80576

CLSA: 2026:1789037015