AlmaLinux 9.2 [TuxCare] 安全更新:bpftool / kernel / kernel-abi-stablelists / kernel-core / 等多个漏洞 (ALMALINUX9.2:CLSA-2024:1728936982)

high Nessus 插件 ID 353076

简介

AlmaLinux 主机缺少一个或多个安全更新。

描述

AlmaLinux 9.2 主机上安装的程序包受到 TuxCare ALMALINUX9.2:CLSA-2024:1728936982公告中提及的多个漏洞的影响。

- 已修复 Linux 内核中的下列漏洞:tty: Fix out-of-bound vmalloc access in imageblit This issue happens when a userspace program does an ioctl FBIOPUT_VSCREENINFO passing the fb_var_screeninfo struct containing only the fields xres, yres, and bits_per_pixel with values. If this struct is the same as the previous ioctl, the vc_resize() detects it and doesn't call the resize_screen(), leaving the fb_var_screeninfo incomplete. And this leads to the updatescrollmode() calculates a wrong value to fbcon_display->vrows, which makes the real_y() return a wrong value of y, and that value, eventually, causes the imageblit to access an out-of-bound address value. To solve this issue I made the resize_screen() be called even if the screen does not need any resizing, so it will fix and fill the fb_var_screeninfo independently. (CVE-2021-47383)

- 已修复 Linux 内核中的下列漏洞:seg6: fix the iif in the IPv6 socket control block When an IPv4 packet is received, the ip_rcv_core(...) sets the receiving interface index into the IPv4 socket control block (v5.16-rc4, net/ipv4/ip_input.c line 510): IPCB(skb)->iif = skb->skb_iif; If that IPv4 packet is meant to be encapsulated in an outer IPv6+SRH header, the seg6_do_srh_encap(...) performs the required encapsulation. In this case, the seg6_do_srh_encap function clears the IPv6 socket control block (v5.16-rc4 net/ipv6/seg6_iptunnel.c line 163): memset(IP6CB(skb), 0, sizeof(*IP6CB(skb))); The memset(...) was introduced in commit ef489749aae5 (ipv6: sr: clear IP6CB(skb) on SRH ip4ip6 encapsulation) a long time ago (2019-01-29). Since the IPv6 socket control block and the IPv4 socket control block share the same memory area (skb->cb), the receiving interface index info is lost (IP6CB(skb)->iif is set to zero). As a side effect, that condition triggers a NULL pointer dereference if commit 0857d6f8c759 (ipv6: When forwarding count rx stats on the orig netdev) is applied. To fix that issue, we set the IP6CB(skb)->iif with the index of the receiving interface once again. (CVE-2021-47515)

- 在 Linux 内核的 cxgb4 驱动程序中发现释放后使用漏洞。cxgb4 设备分离时会发生此缺陷,可能是因为在工作队列重新准备了 flower_stats_timer。本地用户可利用此缺陷导致系统崩溃,从而造成拒绝服务情况。(CVE-2023-4133)

- Linux 内核的 TUN/TAP 功能中发现缺陷。本地用户可以利用此问题绕过绕过网络过滤器,并获取某些资源未经授权的访问权限。修复 CVE-2023-1076 的原始修补程序并不正确或并不完整。问题在于下列上游提交 - a096ccca6e50(tun:tun_chr_open():正确初始化套接字 uid),- 66b2c338adce(tap:tap_open():
正确初始化套接字 UID),在将 inode->i_uid 作为最后一个参数传递至 sock_init_data_uid() 时发现结果并非准确无误。(CVE-2023-4194)

- 已修复 Linux 内核中的下列漏洞:bpf, sockmap: Don't let sock_map_{close,destroy,unhash} call itself sock_map proto callbacks should never call themselves by design. Protect against bugs like [1] and break out of the recursive loop to avoid a stack overflow in favor of a resource leak. [1] https://lore.kernel.org/all/[email protected]/(CVE-2023-52735)

请注意,Nessus 尚未测试这些问题,而是只依据应用程序自我报告的版本号进行判断。

解决方案

根据 TuxCare 公告 ALMALINUX9.2:CLSA-2024:1728936982 中的指南更新受影响的程序包。

另见

https://cve.tuxcare.com/els/releases/CLSA-2024:1728936982

http://www.nessus.org/u?73bc96f8

插件详情

严重性: High

ID: 353076

文件名: tuxcare_alma_linux_9.2_CLSA-2024-1728936982.nasl

版本: 1.1

类型: Local

发布时间: 2026/9/30

最近更新时间: 2026/9/30

支持的传感器: Continuous Assessment, Nessus Agent, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

风险信息

VPR

风险因素: High

分数: 7.6

百分位: 98.67

Vendor

Vendor Severity: Important

CVSS v2

风险因素: Medium

基本分数: 6.8

时间分数: 5

矢量: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS 分数来源: CVE-2024-46859

CVSS v3

风险因素: High

基本分数: 7.8

时间分数: 6.8

矢量: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

时间矢量: CVSS:3.0/E:U/RL:O/RC:C

漏洞信息

必需的 KB 项: Host/OS/extended-third-party, Host/local_checks_enabled, Host/AlmaLinux/release, Host/AlmaLinux/rpm-list, Host/cpu

易利用性: No known exploits are available

补丁发布日期: 2024/10/14

漏洞发布日期: 2021/7/21

参考资料信息

CVE: CVE-2021-47383, CVE-2021-47515, CVE-2023-4133, CVE-2023-4194, CVE-2023-52651, CVE-2023-52735, CVE-2023-52880, CVE-2023-52884, CVE-2024-26629, CVE-2024-26665, CVE-2024-26737, CVE-2024-26853, CVE-2024-26855, CVE-2024-26931, CVE-2024-26946, CVE-2024-27016, CVE-2024-27030, CVE-2024-27046, CVE-2024-27052, CVE-2024-27415, CVE-2024-35789, CVE-2024-35791, CVE-2024-35845, CVE-2024-35852, CVE-2024-35895, CVE-2024-35898, CVE-2024-36025, CVE-2024-36899, CVE-2024-36941, CVE-2024-36979, CVE-2024-38559, CVE-2024-38562, CVE-2024-38579, CVE-2024-38588, CVE-2024-38601, CVE-2024-38619, CVE-2024-38627, CVE-2024-39476, CVE-2024-40905, CVE-2024-40911, CVE-2024-40912, CVE-2024-40914, CVE-2024-40927, CVE-2024-40929, CVE-2024-40941, CVE-2024-40978, CVE-2024-40983, CVE-2024-40995, CVE-2024-41013, CVE-2024-41023, CVE-2024-41039, CVE-2024-41041, CVE-2024-41044, CVE-2024-41071, CVE-2024-41076, CVE-2024-41096, CVE-2024-42082, CVE-2024-42096, CVE-2024-42110, CVE-2024-42131, CVE-2024-42136, CVE-2024-42148, CVE-2024-42152, CVE-2024-42243, CVE-2024-43882, CVE-2024-46700, CVE-2024-46722, CVE-2024-46723, CVE-2024-46724, CVE-2024-46725, CVE-2024-46731, CVE-2024-46738, CVE-2024-46743, CVE-2024-46744, CVE-2024-46746, CVE-2024-46747, CVE-2024-46756, CVE-2024-46757, CVE-2024-46758, CVE-2024-46759, CVE-2024-46800, CVE-2024-46811, CVE-2024-46813, CVE-2024-46818, CVE-2024-46821, CVE-2024-46859

CLSA: 2024:1728936982