CentOS Linux 7 [TuxCare] 安全更新:bpftool / kernel / kernel-debug / kernel-debug-devel / kernel-devel / 等多个漏洞 (CENTOS7:CLSA-2026:1788170774)

high Nessus 插件 ID 359803

简介

CentOS Linux 主机缺少一个或多个安全更新。

描述

CentOS Linux 7 主机上存在安装的程序包,该程序包受到 TuxCare CENTOS7:CLSA-2026:2026:1788170774 公告中提及的多个漏洞的影响。

- 5.12-rc8 之前的 Linux 内核 SCTP 套接字 (net/sctp/socket.c) 中存在争用情形,可从网络服务上下文或无特权进程造成内核权限升级。如果在没有 sock_net(sk)->sctp.addr_wq_lock 的情况下调用 sctp_destroy_sock,则会从 auto_asconf_splist 列表中删除一个元素,而不会进行任何适当的锁定。如果附加的 BPF_CGROUP_INET_SOCK_CREATE 拒绝创建某些 SCTP 套接字,则具有网络服务权限的攻击者可利用此问题升级到根级权限或直接从非特权用户上下文升级权限。(CVE-2021-23133)

- 已修复 Linux 内核中的下列漏洞:drm: Fix use-after-free read in drm_getunique() There is a time-of-check-to-time-of-use error in drm_getunique() due to retrieving file_priv->master prior to locking the device's master mutex. An example can be seen in the crash report of the use-after-free error found by Syzbot:
https://syzkaller.appspot.com/bug?id=148d2f1dfac64af52ffd27b661981a540724f803 In the report, the master pointer was used after being freed. This is because another process had acquired the device's master mutex in drm_setmaster_ioctl(), then overwrote fpriv->master in drm_new_set_master(). The old value of fpriv->master was subsequently freed before the mutex was unlocked. To fix this, we lock the device's master mutex before retrieving the pointer from from fpriv->master. This patch passes the Syzbot reproducer test. (CVE-2021-47280)

- 已修复 Linux 内核中的下列漏洞:scsi: mpt3sas: Fix kernel panic during drive powercycle test While looping over shost's sdev list it is possible that one of the drives is getting removed and its sas_target object is freed but its sdev object remains intact. Consequently, a kernel panic can occur while the driver is trying to access the sas_address field of sas_target object without also checking the sas_target object for NULL. (CVE-2021-47565)

- 已修复 Linux 内核中的下列漏洞:dm btree remove: fix use after free in rebalance_children() Move dm_tm_unlock() after dm_tm_dec(). (CVE-2021-47600)

- 已修复 Linux 内核中的下列漏洞:media: pvrusb2: fix array-index-out-of-bounds in pvr2_i2c_core_init Syzbot reported that -1 is used as array index. The problem was in missing validation check. hdw->unit_number is initialized with -1 and then if init table walk fails this value remains unchanged. Since code blindly uses this member for array indexing adding sanity check is the easiest fix for that. hdw->workpoll initialization moved upper to prevent warning in __flush_work.
(CVE-2022-49478)

请注意,Nessus 尚未测试这些问题,而是只依据应用程序自我报告的版本号进行判断。

解决方案

根据 TuxCare 公告 CENTOS7:CLSA-2026:1788170774 中的指南更新受影响的程序包。

另见

https://cve.tuxcare.com/els/releases/CLSA-2026:1788170774

http://www.nessus.org/u?cb80664a

插件详情

严重性: High

ID: 359803

文件名: tuxcare_centos_7_CLSA-2026-1788170774.nasl

版本: 1.1

类型: Local

代理: unix

发布时间: 2026/10/1

最近更新时间: 2026/10/1

支持的传感器: Continuous Assessment, Nessus Agent, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

风险信息

VPR

风险因素: High

分数: 7.9

百分位: 99.35

Vendor

Vendor Severity: Important

CVSS v2

风险因素: Medium

基本分数: 6.9

时间分数: 5.4

矢量: CVSS2#AV:L/AC:M/Au:N/C:C/I:C/A:C

CVSS 分数来源: CVE-2021-23133

CVSS v3

风险因素: High

基本分数: 8.2

时间分数: 7.4

矢量: CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

时间矢量: CVSS:3.0/E:P/RL:O/RC:C

CVSS 分数来源: CVE-2026-31788

CVSS v4

风险因素: High

Base Score: 7.3

Threat Score: 6.4

Threat Vector: CVSS:4.0/E:P

Vector: CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

CVSS 分数来源: CVE-2025-54518

漏洞信息

必需的 KB 项: Host/OS/extended-third-party, Host/local_checks_enabled, Host/CentOS/release, Host/CentOS/rpm-list

可利用: true

易利用性: Exploits are available

补丁发布日期: 2026/8/31

漏洞发布日期: 2021/4/13

参考资料信息

CVE: CVE-2021-23133, CVE-2021-47280, CVE-2021-47479, CVE-2021-47565, CVE-2021-47600, CVE-2022-49111, CVE-2022-49478, CVE-2022-49934, CVE-2022-50103, CVE-2022-50185, CVE-2022-50220, CVE-2022-50411, CVE-2022-50432, CVE-2022-50470, CVE-2022-50496, CVE-2022-50551, CVE-2022-50646, CVE-2023-2162, CVE-2023-52818, CVE-2023-52974, CVE-2023-53153, CVE-2023-53265, CVE-2023-53307, CVE-2023-53454, CVE-2023-53524, CVE-2023-53556, CVE-2023-54121, CVE-2023-54243, CVE-2024-0639, CVE-2024-36013, CVE-2025-21753, CVE-2025-21764, CVE-2025-38046, CVE-2025-38103, CVE-2025-38211, CVE-2025-38239, CVE-2025-38563, CVE-2025-39759, CVE-2025-54518, CVE-2025-68798, CVE-2026-22980, CVE-2026-23099, CVE-2026-23318, CVE-2026-31392, CVE-2026-31399, CVE-2026-31500, CVE-2026-31502, CVE-2026-31663, CVE-2026-31788, CVE-2026-43116, CVE-2026-43279, CVE-2026-43281, CVE-2026-43334, CVE-2026-43338, CVE-2026-43339, CVE-2026-43493, CVE-2026-45856, CVE-2026-45861, CVE-2026-45942, CVE-2026-45970, CVE-2026-45984, CVE-2026-46006, CVE-2026-46043, CVE-2026-46052, CVE-2026-46056, CVE-2026-46133, CVE-2026-46149, CVE-2026-46150, CVE-2026-46174, CVE-2026-46189, CVE-2026-46259, CVE-2026-46266, CVE-2026-52918, CVE-2026-52920, CVE-2026-52942, CVE-2026-52956, CVE-2026-52957, CVE-2026-52986, CVE-2026-52998, CVE-2026-53002, CVE-2026-53009, CVE-2026-53062, CVE-2026-53075, CVE-2026-53091, CVE-2026-53112, CVE-2026-53131, CVE-2026-53224, CVE-2026-53228, CVE-2026-53246, CVE-2026-53253, CVE-2026-53254, CVE-2026-53255, CVE-2026-53256, CVE-2026-53264, CVE-2026-53265, CVE-2026-53268, CVE-2026-53270, CVE-2026-53275, CVE-2026-64266, CVE-2026-64298, CVE-2026-64567, CVE-2026-64582, CVE-2026-68093, CVE-2026-68096, CVE-2026-68108, CVE-2026-68121, CVE-2026-68123, CVE-2026-68143, CVE-2026-68153, CVE-2026-68154, CVE-2026-68155, CVE-2026-68156, CVE-2026-68158, CVE-2026-68160, CVE-2026-68176, CVE-2026-68188, CVE-2026-68202, CVE-2026-68226, CVE-2026-68320, CVE-2026-68365, CVE-2026-68376, CVE-2026-68414, CVE-2026-68433, CVE-2026-72396, CVE-2026-72472, CVE-2026-74499, CVE-2026-74583, CVE-2026-74584, CVE-2026-74588, CVE-2026-74624, CVE-2026-74669, CVE-2026-74730

CLSA: 2026:1788170774