Rocky Linux 8 [CIQ] 安全更新:kernel-rt / kernel-rt-core / kernel-rt-debug / kernel-rt-debug-core / etc 多种漏洞 (crlsa-2022_1975)

critical Nessus 插件 ID 358465

简介

Rocky Linux 主机缺少一个或多个安全更新。

描述

Rocky Linux 8 主机上存在安装的程序包,该程序包受到 CIQ crlsa-2022_1975 公告中提及的多个漏洞的影响。

* kernel:fget:获取 fd 的 ref 后检查其是否仍存在 (CVE-2021-4083)

* kernel:避免畸形 USB 描述符 (CVE-2020-0404) 导致的循环实体链

* 内核:在 drivers/tty/vt/keyboard.c (CVE-2020-13974) 中,k_ascii() 中的整数溢出

* 内核:由于释放后使用 (CVE-2021-0941),filter.c 的 bpf_skb_change_head() 中存在越界读取

* kernel:joydev:零大小传递给 joydev_handle_JSIOCSBTNMAP() (CVE-2021-3612)

* 内核:读取 /proc/sysvipc/shm 不会随着共享内存段计数 (CVE-2021-3669) 的增加而增加

* 内核:net/qrtr/qrtr.c (CVE-2021-3743) 的 qrtr_endpoint_post 中的越界读取

* kernel: crypto: ccp - 修复 ccp_run_aes_gcm_cmd() (CVE-2021-3744) 中的资源泄漏

* 内核:蓝牙模块 (CVE-2021-3752) 中可能的释放后使用

* 内核:Linux 内核中不明的 ipc 对象导致突破 memcg 限制和 DoS 攻击 (CVE-2021-3759)

* 内核:ccp_run_aes_gcm_cmd() 函数 (CVE-2021-3764) 中的 DoS

* kernel: sctp:无效的区块可用于远程删除现有关联 (CVE-2021-3772)

* 内核:natd 和 netfilter 中缺少端口健全性检查导致对 OpenVPN 客户端的利用 (CVE-2021-3773)

* kernel:驻留在 hugetlbfs (CVE-2021-4002) 上的数据可能泄漏或破坏

* kernel:(CVE-2021-4037) 的安全CVE-2018-13405回归

* kernel:decode_nfs_fh函数 (CVE-2021-4157) 中的缓冲区覆盖

* kernel:cgroup:使用开放时间凭据和命名空间进行迁移权限检查 (CVE-2021-4197)

* 内核:sk_peer_pid和sk_peer_cred访问中的争用条件 (CVE-2021-4203)

* 内核:基于 ICMP 片段所需的数据包回复 (CVE-2021-20322) 发动新的 DNS 缓存中毒攻击

* hw: cpu:() 的 CVE-2017-5715 LFENCECVE-2021-26401/JMP 缓解更新

* 内核:由于错误的 BPF JIT 分支置换计算而导致本地权限升级 (CVE-2021-29154)

* 内核:在 drivers/net/usb/hso.cCVE-2021-37159 () 的 hso_free_net_device() 中释放后使用

* kernel:kernel/bpf/stackmap.c 的 prealloc_elems_and_freelist() 中的 eBPF 乘法整数溢出导致越界写入 (CVE-2021-41864)

* 内核:firedtv 驱动程序中的堆缓冲区溢出 (CVE-2021-42739)

* 内核:在 drivers/isdn/capi/kcapi.c (CVE-2021-43389) 的detach_capi_ctr中存在数组索引越界

* 内核:drivers/net/wireless/marvell/mwifiex/usb.c 中的 mwifiex_usb_recv() 允许攻击者通过构建的 USB 设备 (CVE-2021-43976) 造成 DoS

* 内核:TEE 子系统中的释放后使用 (CVE-2021-44733)

* 内核:IPv6 实现中的信息泄漏 (CVE-2021-45485)

* 内核:IPv4 实现中的信息泄漏 (CVE-2021-45486)

* hw: cpu: intel: 分支历史记录注入 (BHI) (CVE-2022-0001)

* hw:cpu:intel:模式内 BTI (CVE-2022-0002)

* kernel:bond_ipsec_add_sa 中的本地拒绝服务 (CVE-2022-0286)

* 内核:net/sctp/sm_make_chunk.cCVE-2022-0322 () 的 sctp_addto_chunk 中的 DoS

* kernel:FUSE 允许 UAF 读取 write() 缓冲区,从而允许窃取(部分)/etc/shadow 哈希 (CVE-2022-1011)

* 内核:nouveau 内核模块 (CVE-2020-27820) 中的释放后使用

Tenable 已直接从 CIQ 安全公告中提取上述描述块。

请注意,Nessus 尚未测试这些问题,而是只依据应用程序自我报告的版本号进行判断。

解决方案

根据 CIQ 公告中的指南更新受影响的程序包 crlsa-2022_1975。

另见

https://access.redhat.com/errata/RHSA-2022:1975

https://bugzilla.redhat.com/show_bug.cgi?id=1901726

https://bugzilla.redhat.com/show_bug.cgi?id=1903578

https://bugzilla.redhat.com/show_bug.cgi?id=1905749

https://bugzilla.redhat.com/show_bug.cgi?id=1919791

https://bugzilla.redhat.com/show_bug.cgi?id=1946684

https://bugzilla.redhat.com/show_bug.cgi?id=1951739

https://bugzilla.redhat.com/show_bug.cgi?id=1974079

https://bugzilla.redhat.com/show_bug.cgi?id=1985353

https://bugzilla.redhat.com/show_bug.cgi?id=1986473

https://bugzilla.redhat.com/show_bug.cgi?id=1997467

https://bugzilla.redhat.com/show_bug.cgi?id=1997961

https://bugzilla.redhat.com/show_bug.cgi?id=1999544

https://bugzilla.redhat.com/show_bug.cgi?id=1999675

https://bugzilla.redhat.com/show_bug.cgi?id=2000627

https://bugzilla.redhat.com/show_bug.cgi?id=2000694

https://bugzilla.redhat.com/show_bug.cgi?id=2004949

https://bugzilla.redhat.com/show_bug.cgi?id=2010463

https://bugzilla.redhat.com/show_bug.cgi?id=2013180

https://bugzilla.redhat.com/show_bug.cgi?id=2014230

https://bugzilla.redhat.com/show_bug.cgi?id=2016169

https://bugzilla.redhat.com/show_bug.cgi?id=2018205

https://bugzilla.redhat.com/show_bug.cgi?id=2025003

https://bugzilla.redhat.com/show_bug.cgi?id=2025726

https://bugzilla.redhat.com/show_bug.cgi?id=2027239

https://bugzilla.redhat.com/show_bug.cgi?id=2029923

https://bugzilla.redhat.com/show_bug.cgi?id=2030747

https://bugzilla.redhat.com/show_bug.cgi?id=2034342

https://bugzilla.redhat.com/show_bug.cgi?id=2035652

https://bugzilla.redhat.com/show_bug.cgi?id=2036934

https://bugzilla.redhat.com/show_bug.cgi?id=2037019

https://bugzilla.redhat.com/show_bug.cgi?id=2039911

https://bugzilla.redhat.com/show_bug.cgi?id=2039914

https://bugzilla.redhat.com/show_bug.cgi?id=2042822

https://bugzilla.redhat.com/show_bug.cgi?id=2061700

https://bugzilla.redhat.com/show_bug.cgi?id=2061712

https://bugzilla.redhat.com/show_bug.cgi?id=2061721

https://bugzilla.redhat.com/show_bug.cgi?id=2064855

https://errata.build.resf.org/RLSA-2022:1975

http://www.nessus.org/u?a317d35d

http://www.nessus.org/u?ce1172cb

插件详情

严重性: Critical

ID: 358465

文件名: ciq_rocky_linux_8_crlsa-2022_1975.nasl

版本: 1.1

类型: Local

发布时间: 2026/10/1

最近更新时间: 2026/10/1

支持的传感器: Continuous Assessment, Nessus Agent, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

风险信息

VPR

风险因素: High

分数: 7.6

百分位: 98.25

Vendor

Vendor Severity: Unknown

CVSS v2

风险因素: High

基本分数: 7.9

时间分数: 6.2

矢量: CVSS2#AV:A/AC:M/Au:N/C:C/I:C/A:C

CVSS 分数来源: CVE-2021-3752

CVSS v3

风险因素: Critical

基本分数: 9.8

时间分数: 8.8

矢量: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

时间矢量: CVSS:3.0/E:P/RL:O/RC:C

CVSS 分数来源: CVE-2021-3773

漏洞信息

必需的 KB 项: Host/OS/extended-third-party, Host/local_checks_enabled, Host/RockyLinux/release, Host/RockyLinux/rpm-list, Host/cpu

可利用: true

易利用性: Exploits are available

补丁发布日期: 2022/5/10

漏洞发布日期: 2020/6/9

参考资料信息

CVE: CVE-2020-0404, CVE-2020-13974, CVE-2020-27820, CVE-2021-0941, CVE-2021-20322, CVE-2021-26401, CVE-2021-29154, CVE-2021-3612, CVE-2021-3669, CVE-2021-37159, CVE-2021-3743, CVE-2021-3744, CVE-2021-3752, CVE-2021-3759, CVE-2021-3764, CVE-2021-3772, CVE-2021-3773, CVE-2021-4002, CVE-2021-4037, CVE-2021-4083, CVE-2021-4157, CVE-2021-41864, CVE-2021-4197, CVE-2021-4203, CVE-2021-42739, CVE-2021-43389, CVE-2021-43976, CVE-2021-44733, CVE-2021-45485, CVE-2021-45486, CVE-2022-0001, CVE-2022-0002, CVE-2022-0286, CVE-2022-0322, CVE-2022-1011