AlmaLinux 9.6 [TuxCare] 安全更新:kernel / kernel-abi-stablelists / kernel-core / 等多个漏洞 (ALMALINUX9.6:CLSA-2026:1782155469)

high Nessus 插件 ID 359640

简介

AlmaLinux 主机缺少一个或多个安全更新。

描述

AlmaLinux 9.6 主机上存在安装的程序包,该程序包受到 TuxCare ALMALINUX9.6:CLSA-2026:2026:1782155469公告中提及的多个漏洞的影响。

- 已修复 Linux 内核中的下列漏洞:udf: Fix preallocation discarding at indirect extent boundary When preallocation extent is the first one in the extent block, the code would corrupt extent tree header instead. Fix the problem and use udf_delete_aext() for deleting extent to avoid some code duplication. (CVE-2022-48946)

- 已修复 Linux 内核中的下列漏洞:xen/privcmd: fix error exit of privcmd_ioctl_dm_op() The error exit of privcmd_ioctl_dm_op() is calling unlock_pages() potentially with pages being NULL, leading to a NULL dereference. Additionally lock_pages() doesn't check for pin_user_pages_fast() having been completely successful, resulting in potentially not locking all pages into memory. This could result in sporadic failures when using the related memory in user mode. Fix all of that by calling unlock_pages() always with the real number of pinned pages, which will be zero in case pages being NULL, and by checking the number of pages pinned by pin_user_pages_fast() matching the expected number of pages. (CVE-2022-49989)

- 已修复 Linux 内核中的下列漏洞:platform/x86: mxm-wmi: fix memleak in mxm_wmi_call_mx[ds|mx]() The ACPI buffer memory (out.pointer) returned by wmi_evaluate_method() is not freed after the call, so it leads to memory leak. The method results in ACPI buffer is not used, so just pass NULL to wmi_evaluate_method() which fixes the memory leak. (CVE-2022-50521)

- 已修复 Linux 内核中的下列漏洞:net: USB: Fix wrong-direction WARNING in plusb.c The syzbot fuzzer detected a bug in the plusb network driver: A zero-length control-OUT transfer was treated as a read instead of a write. In modern kernels this error provokes a WARNING: usb 1-1: BOGUS control dir, pipe 80000280 doesn't match bRequestType c0 WARNING: CPU: 0 PID: 4645 at drivers/usb/core/urb.c:411 usb_submit_urb+0x14a7/0x1880 drivers/usb/core/urb.c:411 Modules linked in: CPU:
1 PID: 4645 Comm: dhcpcd Not tainted 6.2.0-rc6-syzkaller-00050-g9f266ccaa2f5 #0 Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/12/2023 RIP: 0010:usb_submit_urb+0x14a7/0x1880 drivers/usb/core/urb.c:411 ... Call Trace: <TASK> usb_start_wait_urb+0x101/0x4b0 drivers/usb/core/message.c:58 usb_internal_control_msg drivers/usb/core/message.c:102 [inline] usb_control_msg+0x320/0x4a0 drivers/usb/core/message.c:153 __usbnet_read_cmd+0xb9/0x390 drivers/net/usb/usbnet.c:2010 usbnet_read_cmd+0x96/0xf0 drivers/net/usb/usbnet.c:2068 pl_vendor_req drivers/net/usb/plusb.c:60 [inline] pl_set_QuickLink_features drivers/net/usb/plusb.c:75 [inline] pl_reset+0x2f/0xf0 drivers/net/usb/plusb.c:85 usbnet_open+0xcc/0x5d0 drivers/net/usb/usbnet.c:889
__dev_open+0x297/0x4d0 net/core/dev.c:1417 __dev_change_flags+0x587/0x750 net/core/dev.c:8530 dev_change_flags+0x97/0x170 net/core/dev.c:8602 devinet_ioctl+0x15a2/0x1d70 net/ipv4/devinet.c:1147 inet_ioctl+0x33f/0x380 net/ipv4/af_inet.c:979 sock_do_ioctl+0xcc/0x230 net/socket.c:1169 sock_ioctl+0x1f8/0x680 net/socket.c:1286 vfs_ioctl fs/ioctl.c:51 [inline] __do_sys_ioctl fs/ioctl.c:870 [inline] __se_sys_ioctl fs/ioctl.c:856 [inline] __x64_sys_ioctl+0x197/0x210 fs/ioctl.c:856 do_syscall_x64 arch/x86/entry/common.c:50 [inline] do_syscall_64+0x39/0xb0 arch/x86/entry/common.c:80 entry_SYSCALL_64_after_hwframe+0x63/0xcd The fix is to call usbnet_write_cmd() instead of usbnet_read_cmd() and remove the USB_DIR_IN flag. (CVE-2023-52742)

- 已修复 Linux 内核中的下列漏洞:tracing: Make sure trace_printk() can output as soon as it can be used Currently trace_printk() can be used as soon as early_trace_init() is called from start_kernel(). But if a crash happens, and ftrace_dump_on_oops is set on the kernel command line, all you get will be: [ 0.456075] <idle>-0 0dN.2. 347519us : Unknown type 6 [ 0.456075] <idle>-0 0dN.2. 353141us : Unknown type 6 [ 0.456075] <idle>-0 0dN.2. 358684us : Unknown type 6 This is because the trace_printk() event (type 6) hasn't been registered yet. That gets done via an early_initcall(), which may be early, but not early enough. Instead of registering the trace_printk() event (and other ftrace events, which are not trace events) via an early_initcall(), have them registered at the same time that trace_printk() can be used. This way, if there is a crash before early_initcall(), then the trace_printk()s will actually be useful. (CVE-2023-53007)

请注意,Nessus 尚未测试这些问题,而是只依据应用程序自我报告的版本号进行判断。

解决方案

根据 TuxCare 公告 ALMALINUX9.6:CLSA-2026:1782155469 中的指南更新受影响的程序包。

另见

https://cve.tuxcare.com/els/releases/CLSA-2026:1782155469

http://www.nessus.org/u?7eb50f9f

插件详情

严重性: High

ID: 359640

文件名: tuxcare_alma_linux_9.6_CLSA-2026-1782155469.nasl

版本: 1.1

类型: Local

发布时间: 2026/10/1

最近更新时间: 2026/10/1

支持的传感器: Continuous Assessment, Nessus Agent, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

风险信息

VPR

风险因素: High

分数: 7.7

百分位: 98.99

Vendor

Vendor Severity: Important

CVSS v2

风险因素: Medium

基本分数: 6.8

时间分数: 5.6

矢量: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS 分数来源: CVE-2026-23013

CVSS v3

风险因素: High

基本分数: 7.8

时间分数: 7.2

矢量: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

时间矢量: CVSS:3.0/E:F/RL:O/RC:C

漏洞信息

必需的 KB 项: Host/OS/extended-third-party, Host/local_checks_enabled, Host/AlmaLinux/release, Host/AlmaLinux/rpm-list, Host/cpu

可利用: true

易利用性: Exploits are available

补丁发布日期: 2026/6/22

漏洞发布日期: 2021/7/21

CISA 已知可遭利用的漏洞到期日期: 2026/9/21

参考资料信息

CVE: CVE-2022-48946, CVE-2022-48972, CVE-2022-49779, CVE-2022-49989, CVE-2022-50365, CVE-2022-50521, CVE-2023-52742, CVE-2023-52808, CVE-2023-53007, CVE-2023-53548, CVE-2024-35803, CVE-2024-36286, CVE-2024-41088, CVE-2024-42232, CVE-2024-42290, CVE-2024-43835, CVE-2024-47809, CVE-2024-50012, CVE-2024-50060, CVE-2024-53172, CVE-2024-53219, CVE-2024-56645, CVE-2024-56739, CVE-2024-56770, CVE-2024-57948, CVE-2024-58096, CVE-2024-58097, CVE-2025-21681, CVE-2025-21731, CVE-2025-21817, CVE-2025-21857, CVE-2025-21870, CVE-2025-22090, CVE-2025-37761, CVE-2025-37808, CVE-2025-37914, CVE-2025-38048, CVE-2025-38053, CVE-2025-38064, CVE-2025-38105, CVE-2025-38154, CVE-2025-38161, CVE-2025-38264, CVE-2025-38385, CVE-2025-38460, CVE-2025-38653, CVE-2025-38665, CVE-2025-38681, CVE-2025-38710, CVE-2025-39721, CVE-2025-39925, CVE-2025-39947, CVE-2025-39964, CVE-2025-40167, CVE-2025-40186, CVE-2025-40194, CVE-2025-40259, CVE-2025-40308, CVE-2025-40331, CVE-2025-68366, CVE-2025-68724, CVE-2025-68803, CVE-2025-68813, CVE-2025-68814, CVE-2025-68815, CVE-2025-68820, CVE-2025-71077, CVE-2025-71083, CVE-2025-71084, CVE-2025-71087, CVE-2025-71095, CVE-2025-71096, CVE-2025-71097, CVE-2025-71099, CVE-2025-71122, CVE-2025-71132, CVE-2025-71137, CVE-2025-71142, CVE-2025-71182, CVE-2025-71227, CVE-2025-71235, CVE-2025-71236, CVE-2025-71273, CVE-2026-22979, CVE-2026-22989, CVE-2026-22994, CVE-2026-23002, CVE-2026-23003, CVE-2026-23007, CVE-2026-23013, CVE-2026-23017, CVE-2026-23023, CVE-2026-23038, CVE-2026-23058, CVE-2026-23066, CVE-2026-23070, CVE-2026-23103, CVE-2026-23110, CVE-2026-23113, CVE-2026-23126, CVE-2026-23138, CVE-2026-23154, CVE-2026-23169, CVE-2026-23198, CVE-2026-23210, CVE-2026-23357, CVE-2026-23367, CVE-2026-23379, CVE-2026-23381, CVE-2026-23382, CVE-2026-23389, CVE-2026-23392, CVE-2026-23442, CVE-2026-23444, CVE-2026-23455, CVE-2026-31408, CVE-2026-31488, CVE-2026-31497, CVE-2026-31498, CVE-2026-31510, CVE-2026-31512, CVE-2026-31515, CVE-2026-31521, CVE-2026-31531, CVE-2026-31540, CVE-2026-31546, CVE-2026-31586, CVE-2026-31602, CVE-2026-31613, CVE-2026-31625, CVE-2026-31628, CVE-2026-31634, CVE-2026-31656, CVE-2026-31664, CVE-2026-31671, CVE-2026-31672, CVE-2026-31685, CVE-2026-31694, CVE-2026-43051, CVE-2026-43158, CVE-2026-43332

CLSA: 2026:1782155469