Rocky Linux 8 [CIQ] 安全更新:bpftool / bpftool-debuginfo / kernel / kernel-abi-stablelists / 等 多种漏洞 (crlsa-2022_7683)

high Nessus 插件 ID 357859

简介

Rocky Linux 主机缺少一个或多个安全更新。

描述

Rocky Linux 8 主机上存在安装的程序包,该程序包受到 CIQ crlsa-2022_7683 公告中提及的多个漏洞的影响。

* 路径外攻击者可注入数据或终止受害者的 TCP 会话 (CVE-2020-36516)

* 当 vc_cons[i].d 已经为空时,VT_RESIZEX ioctl 中的争用条件导致空指针取消引用 (CVE-2020-36558)

* 函数 sco_sock_sendmsg()CVE-2021-3640 () 中的释放后使用漏洞

* drivers/media/v4l2-core/v4l2-ioctl.c video_usercopyCVE-2021-30002 函数中大型参数的内存泄漏

* smb2_ioctl_query_info空指针取消引用 (CVE-2022-0168)

* 回写 (CVE-2022-0617) 期间 udf_expand_file_adinicbdue() 中的空指针取消引用

* DMA_FROM_DEVICE (CVE-2022-0854) 导致 swiotlb 信息泄漏

* nft_do_chain 中堆栈上未初始化的寄存器可造成内核指针泄漏给 UM (CVE-2022-1016)

* snd_pcm_hw_free中的争用条件导致释放后使用 (CVE-2022-1048)

* net/sched/cls_api.c 的 tc_new_tfilter() 中的释放后使用 (CVE-2022-1055)

* 当挂载损坏的图像并在该图像上操作时,ext4 中出现释放后使用和内存错误 (CVE-2022-1184)

* x86_emulate_insn 中的空指针取消引用可能导致 DoS (CVE-2022-1852)

* nft_set_desc_concat_parse() (CVE-2022-2078) 中的缓冲区溢出

* nf_tables跨表潜在的释放后使用可导致本地权限升级 (CVE-2022-2586)

* openvswitch:整数下溢导致 reserve_sfa_size() (CVE-2022-2639) 中的越界写入

* 在轮询 PSI 触发器遭到破坏时的释放后使用 (CVE-2022-2938)

* net/packet:packet_recvmsg() (CVE-2022-20368) 中的 slab-out-of-bound 访问

* 可能使用调试程序将零写入所选位置 (CVE-2022-21499)

* Spectre-BHB (CVE-2022-23960)

* 屏障后返回堆栈缓冲区预测 (CVE-2022-26373)

* drivers/hid/hid-elo.c (CVE-2022-27950) 中的内存泄漏

* drivers/net/can/usb/ems_usb.cCVE-2022-28390 () 中 ems_usb_start_xmit 中的双重释放

* SUNRPC 子系统中的释放后使用 (CVE-2022-28893)

* 因未正确更新 net/sched/cls_u32.c 中的引用计数而导致释放后使用 (CVE-2022-29581)

* net/netfilter/nfnetlink_queue.c (CVE-2022-36946) 的 nfqnl_mangle 中的 DoS

* nfs_atomic_open() 返回未初始化的数据而不是 ENOTDIR (CVE-2022-24448)

Tenable 已直接从 CIQ 安全公告中提取上述描述块。

请注意,Nessus 尚未测试这些问题,而是只依据应用程序自我报告的版本号进行判断。

解决方案

根据 CIQ 公告中的指南更新受影响的程序包 crlsa-2022_7683。

另见

https://access.redhat.com/errata/RHSA-2022:7683

https://bugzilla.redhat.com/show_bug.cgi?id=1946279

https://bugzilla.redhat.com/show_bug.cgi?id=1948442

https://bugzilla.redhat.com/show_bug.cgi?id=1977993

https://bugzilla.redhat.com/show_bug.cgi?id=1978539

https://bugzilla.redhat.com/show_bug.cgi?id=1980646

https://bugzilla.redhat.com/show_bug.cgi?id=2004037

https://bugzilla.redhat.com/show_bug.cgi?id=2019942

https://bugzilla.redhat.com/show_bug.cgi?id=2037386

https://bugzilla.redhat.com/show_bug.cgi?id=2042424

https://bugzilla.redhat.com/show_bug.cgi?id=2044837

https://bugzilla.redhat.com/show_bug.cgi?id=2051444

https://bugzilla.redhat.com/show_bug.cgi?id=2053632

https://bugzilla.redhat.com/show_bug.cgi?id=2056383

https://bugzilla.redhat.com/show_bug.cgi?id=2058369

https://bugzilla.redhat.com/show_bug.cgi?id=2058395

https://bugzilla.redhat.com/show_bug.cgi?id=2059928

https://bugzilla.redhat.com/show_bug.cgi?id=2062284

https://bugzilla.redhat.com/show_bug.cgi?id=2062780

https://bugzilla.redhat.com/show_bug.cgi?id=2066614

https://bugzilla.redhat.com/show_bug.cgi?id=2066706

https://bugzilla.redhat.com/show_bug.cgi?id=2066976

https://bugzilla.redhat.com/show_bug.cgi?id=2069408

https://bugzilla.redhat.com/show_bug.cgi?id=2069472

https://bugzilla.redhat.com/show_bug.cgi?id=2070205

https://bugzilla.redhat.com/show_bug.cgi?id=2070220

https://bugzilla.redhat.com/show_bug.cgi?id=2072552

https://bugzilla.redhat.com/show_bug.cgi?id=2073064

https://bugzilla.redhat.com/show_bug.cgi?id=2074208

https://bugzilla.redhat.com/show_bug.cgi?id=2074317

https://bugzilla.redhat.com/show_bug.cgi?id=2080095

https://bugzilla.redhat.com/show_bug.cgi?id=2084183

https://bugzilla.redhat.com/show_bug.cgi?id=2084479

https://bugzilla.redhat.com/show_bug.cgi?id=2088021

https://bugzilla.redhat.com/show_bug.cgi?id=2089815

https://bugzilla.redhat.com/show_bug.cgi?id=2090940

https://bugzilla.redhat.com/show_bug.cgi?id=2091539

https://bugzilla.redhat.com/show_bug.cgi?id=2096178

https://bugzilla.redhat.com/show_bug.cgi?id=2100259

https://bugzilla.redhat.com/show_bug.cgi?id=2107594

https://bugzilla.redhat.com/show_bug.cgi?id=2109327

https://bugzilla.redhat.com/show_bug.cgi?id=2112693

https://bugzilla.redhat.com/show_bug.cgi?id=2114577

https://bugzilla.redhat.com/show_bug.cgi?id=2114878

https://bugzilla.redhat.com/show_bug.cgi?id=2115065

https://bugzilla.redhat.com/show_bug.cgi?id=2115278

https://bugzilla.redhat.com/show_bug.cgi?id=2120175

https://bugzilla.redhat.com/show_bug.cgi?id=2123695

https://errata.build.resf.org/RLSA-2022:7683

http://www.nessus.org/u?490eccea

http://www.nessus.org/u?8494173d

插件详情

严重性: High

ID: 357859

文件名: ciq_rocky_linux_8_crlsa-2022_7683.nasl

版本: 1.2

类型: Local

发布时间: 2026/10/1

最近更新时间: 2026/10/2

支持的传感器: Continuous Assessment, Nessus Agent, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

风险信息

VPR

风险因素: High

分数: 7.9

百分位: 99.35

Vendor

Vendor Severity: Unknown

CVSS v2

风险因素: High

基本分数: 7.2

时间分数: 6.3

矢量: CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C

CVSS 分数来源: CVE-2022-29581

CVSS v3

风险因素: High

基本分数: 7.8

时间分数: 7.5

矢量: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

时间矢量: CVSS:3.0/E:H/RL:O/RC:C

CVSS v4

风险因素: High

Base Score: 8.6

Threat Score: 8.6

Threat Vector: CVSS:4.0/E:A

Vector: CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N

CVSS 分数来源: CVE-2022-1055

漏洞信息

必需的 KB 项: Host/OS/extended-third-party, Host/local_checks_enabled, Host/RockyLinux/release, Host/RockyLinux/rpm-list, Host/cpu

可利用: true

易利用性: Exploits are available

补丁发布日期: 2022/11/8

漏洞发布日期: 2021/3/26

CISA 已知可遭利用的漏洞到期日期: 2024/7/17

参考资料信息

CVE: CVE-2020-36516, CVE-2020-36558, CVE-2021-30002, CVE-2021-3640, CVE-2022-0168, CVE-2022-0617, CVE-2022-0854, CVE-2022-1016, CVE-2022-1048, CVE-2022-1055, CVE-2022-1184, CVE-2022-1852, CVE-2022-20368, CVE-2022-2078, CVE-2022-21499, CVE-2022-23960, CVE-2022-24448, CVE-2022-2586, CVE-2022-26373, CVE-2022-2639, CVE-2022-27950, CVE-2022-28390, CVE-2022-28893, CVE-2022-2938, CVE-2022-29581, CVE-2022-36946