AlmaLinux 9.2 [TuxCare] 安全更新:bpftool / kernel / kernel-abi-stablelists / kernel-core / 等多个漏洞 (ALMALINUX9.2:CLSA-2026:1778266904)

high Nessus 插件 ID 361258

简介

AlmaLinux 主机缺少一个或多个安全更新。

描述

AlmaLinux 9.2 主机上存在安装的程序包,该程序包受到 TuxCare ALMALINUX9.2:CLSA-2026:1778266904公告中提及的多个漏洞的影响。

- 已修复 Linux 内核中的下列漏洞:samples/landlock: Fix path_list memory leak Clang static analysis reports this error sandboxer.c:134:8: warning: Potential leak of memory pointed to by 'path_list' ret = 0; ^ path_list is allocated in parse_path() but never freed. (CVE-2021-47654)

- 已修复 Linux 内核中的下列漏洞:tty: synclink_gt: Fix null-pointer-dereference in slgt_clean() When the driver fails at alloc_hdlcdev(), and then we remove the driver module, we will get the following splat: [ 25.065966] general protection fault, probably for non-canonical address 0xdffffc0000000182: 0000 [#1] PREEMPT SMP KASAN PTI [ 25.066914] KASAN: null-ptr-deref in range [0x0000000000000c10-0x0000000000000c17] [ 25.069262] RIP: 0010:detach_hdlc_protocol+0x2a/0x3e0 [25.077709] Call Trace: [ 25.077924] <TASK> [ 25.078108] unregister_hdlc_device+0x16/0x30 [ 25.078481] slgt_cleanup+0x157/0x9f0 [synclink_gt] Fix this by checking whether the 'info->netdev' is a null pointer first. (CVE-2022-49307)

- 已修复 Linux 内核中的下列漏洞:ima: Fix potential memory leak in ima_init_crypto() On failure to allocate the SHA1 tfm, IMA fails to initialize and exits without freeing the ima_algo_array. Add the missing kfree() for ima_algo_array to avoid the potential memory leak.
(CVE-2022-49627)

- 已修复 Linux 内核中的下列漏洞:tracing/histograms: Fix memory leak problem This reverts commit 46bbe5c671e06f070428b9be142cc4ee5cedebac. As commit 46bbe5c671e0 (tracing:
fix double free) said, the double free problem reported by clang static analyzer is: > In parse_var_defs() if there is a problem allocating > var_defs.expr, the earlier var_defs.name is freed. > This free is duplicated by free_var_defs() which frees > the rest of the list. However, if there is a problem allocating N-th var_defs.expr: + in parse_var_defs(), the freed 'earlier var_defs.name' is actually the N-th var_defs.name; + then in free_var_defs(), the names from 0th to (N-1)-th are freed; IF ALLOCATING PROBLEM HAPPENED HERE!!! -+ \ | 0th 1th (N-1)-th N-th V +-------------+-------------+-----+-------------+----------- var_defs: | name | expr | name | expr | ... | name | expr | name | /// +-------------+-------------+-----+-------------+----------- These two frees don't act on same name, so there was no double free problem before. Conversely, after that commit, we get a memory leak problem because the above N-th var_defs.name is not freed. If enable CONFIG_DEBUG_KMEMLEAK and inject a fault at where the N-th var_defs.expr allocated, then execute on shell like: $ echo 'hist:key=call_site:val=$v1,$v2:v1=bytes_req,v2=bytes_alloc' > \ /sys/kernel/debug/tracing/events/kmem/kmalloc/trigger Then kmemleak reports: unreferenced object 0xffff8fb100ef3518 (size 8): comm bash, pid 196, jiffies 4295681690 (age 28.538s) hex dump (first 8 bytes): 76 31 00 00 b1 8f ff ff v1...... backtrace: [<0000000038fe4895>] kstrdup+0x2d/0x60 [<00000000c99c049a>] event_hist_trigger_parse+0x206f/0x20e0 [<00000000ae70d2cc>] trigger_process_regex+0xc0/0x110 [<0000000066737a4c>] event_trigger_write+0x75/0xd0 [<000000007341e40c>] vfs_write+0xbb/0x2a0 [<0000000087fde4c2>] ksys_write+0x59/0xd0 [<00000000581e9cdf>] do_syscall_64+0x3a/0x80 [<00000000cf3b065c>] entry_SYSCALL_64_after_hwframe+0x46/0xb0 (CVE-2022-49648)

- 已修复 Linux 内核中的下列漏洞:linux/dim: Fix divide by 0 in RDMA DIM Fix a divide 0 error in rdma_dim_stats_compare() when prev->cpe_ratio == 0. CallTrace: Hardware name: H3C R4900 G3/RS33M2C9S, BIOS 2.00.37P21 03/12/2020 task: ffff880194b78000 task.stack: ffffc90006714000 RIP:
0010:backport_rdma_dim+0x10e/0x240 [mlx_compat] RSP: 0018:ffff880c10e83ec0 EFLAGS: 00010202 RAX:
0000000000002710 RBX: ffff88096cd7f780 RCX: 0000000000000064 RDX: 0000000000000000 RSI: 0000000000000002 RDI: 0000000000000001 RBP: 0000000000000001 R08: 0000000000000000 R09: 0000000000000000 R10:
0000000000000000 R11: 0000000000000000 R12: 000000001d7c6c09 R13: ffff88096cd7f780 R14: ffff880b174fe800 R15: 0000000000000000 FS: 0000000000000000(0000) GS:ffff880c10e80000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 00000000a0965b00 CR3: 000000000200a003 CR4: 00000000007606e0 DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 DR3: 0000000000000000 DR6:
00000000fffe0ff0 DR7: 0000000000000400 PKRU: 55555554 Call Trace: <IRQ> ib_poll_handler+0x43/0x80 [ib_core] irq_poll_softirq+0xae/0x110 __do_softirq+0xd1/0x28c irq_exit+0xde/0xf0 do_IRQ+0x54/0xe0 common_interrupt+0x8f/0x8f </IRQ> ? cpuidle_enter_state+0xd9/0x2a0 ? cpuidle_enter_state+0xc7/0x2a0 ? do_idle+0x170/0x1d0 ? cpu_startup_entry+0x6f/0x80 ? start_secondary+0x1b9/0x210 ? secondary_startup_64+0xa5/0xb0 Code: 0f 87 e1 00 00 00 8b 4c 24 14 44 8b 43 14 89 c8 4d 63 c8 44 29 c0 99 31 d0 29 d0 31 d2 48 98 48 8d 04 80 48 8d 04 80 48 c1 e0 02 <49> f7 f1 48 83 f8 0a 0f 86 c1 00 00 00 44 39 c1 7f 10 48 89 df RIP: backport_rdma_dim+0x10e/0x240 [mlx_compat] RSP: ffff880c10e83ec0 (CVE-2022-49670)

请注意,Nessus 尚未测试这些问题,而是只依据应用程序自我报告的版本号进行判断。

解决方案

根据 TuxCare 公告 ALMALINUX9.2:CLSA-2026:2026:1778266904 中的指南更新受影响的程序包。

另见

https://cve.tuxcare.com/els/releases/CLSA-2026:1778266904

http://www.nessus.org/u?2c3b3881

插件详情

严重性: High

ID: 361258

文件名: tuxcare_alma_linux_9.2_CLSA-2026-1778266904.nasl

版本: 1.2

类型: Local

发布时间: 2026/10/1

最近更新时间: 2026/10/2

支持的传感器: Continuous Assessment, Nessus Agent, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

风险信息

VPR

风险因素: Critical

分数: 9.5

百分位: 99.87

Vendor

Vendor Severity: Important

CVSS v2

风险因素: Medium

基本分数: 6.8

时间分数: 5.9

矢量: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS 分数来源: CVE-2026-31581

CVSS v3

风险因素: High

基本分数: 7.8

时间分数: 7.5

矢量: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

时间矢量: CVSS:3.0/E:H/RL:O/RC:C

漏洞信息

必需的 KB 项: Host/OS/extended-third-party, Host/local_checks_enabled, Host/AlmaLinux/release, Host/AlmaLinux/rpm-list, Host/cpu

可利用: true

易利用性: Exploits are available

补丁发布日期: 2026/5/8

漏洞发布日期: 2021/7/21

可利用的方式

Core Impact

Metasploit (xfrm-ESP Page-Cache Write via CVE-2026-43284)

参考资料信息

CVE: CVE-2021-47430, CVE-2021-47654, CVE-2022-48972, CVE-2022-49002, CVE-2022-49021, CVE-2022-49148, CVE-2022-49187, CVE-2022-49307, CVE-2022-49481, CVE-2022-49627, CVE-2022-49648, CVE-2022-49670, CVE-2022-49672, CVE-2022-49748, CVE-2022-49785, CVE-2022-49801, CVE-2022-49802, CVE-2022-49803, CVE-2022-49832, CVE-2022-49863, CVE-2022-49869, CVE-2022-49871, CVE-2022-50108, CVE-2022-50222, CVE-2022-50280, CVE-2022-50282, CVE-2022-50304, CVE-2022-50319, CVE-2022-50321, CVE-2022-50346, CVE-2022-50349, CVE-2022-50365, CVE-2022-50380, CVE-2022-50387, CVE-2022-50409, CVE-2022-50505, CVE-2022-50625, CVE-2022-50640, CVE-2022-50645, CVE-2022-50724, CVE-2022-50825, CVE-2022-50856, CVE-2022-50879, CVE-2023-52486, CVE-2023-52560, CVE-2023-52580, CVE-2023-52619, CVE-2023-52743, CVE-2023-52912, CVE-2023-52936, CVE-2023-52976, CVE-2023-52979, CVE-2023-53101, CVE-2023-53143, CVE-2023-53237, CVE-2023-53290, CVE-2023-53518, CVE-2023-53768, CVE-2023-53844, CVE-2023-53992, CVE-2023-54003, CVE-2023-54010, CVE-2023-54083, CVE-2023-54260, CVE-2023-54268, CVE-2023-54312, CVE-2024-26660, CVE-2024-26717, CVE-2024-26774, CVE-2024-26835, CVE-2024-26900, CVE-2024-27015, CVE-2024-35925, CVE-2024-35933, CVE-2024-36286, CVE-2024-36930, CVE-2024-36954, CVE-2024-38596, CVE-2024-39468, CVE-2024-39509, CVE-2024-40919, CVE-2024-40960, CVE-2024-40961, CVE-2024-41060, CVE-2024-41095, CVE-2024-42090, CVE-2024-42098, CVE-2024-42106, CVE-2024-42288, CVE-2024-43828, CVE-2024-43856, CVE-2024-43861, CVE-2024-44948, CVE-2024-45018, CVE-2024-46719, CVE-2024-46791, CVE-2024-46794, CVE-2024-46805, CVE-2024-46819, CVE-2024-47668, CVE-2024-47671, CVE-2024-47673, CVE-2024-47710, CVE-2024-49858, CVE-2024-49866, CVE-2024-49890, CVE-2024-49896, CVE-2024-49911, CVE-2024-49962, CVE-2024-49977, CVE-2024-50001, CVE-2024-50019, CVE-2024-50044, CVE-2024-50049, CVE-2024-50075, CVE-2024-50078, CVE-2024-50082, CVE-2024-50153, CVE-2024-50179, CVE-2024-50201, CVE-2024-50272, CVE-2024-50299, CVE-2024-50304, CVE-2024-53066, CVE-2024-53120, CVE-2024-53161, CVE-2024-53217, CVE-2024-56533, CVE-2024-56589, CVE-2024-56593, CVE-2024-56629, CVE-2024-56636, CVE-2024-56645, CVE-2024-56688, CVE-2024-56716, CVE-2024-56747, CVE-2024-56748, CVE-2024-56763, CVE-2024-57986, CVE-2024-58017, CVE-2024-58090, CVE-2025-21689, CVE-2025-21699, CVE-2025-21745, CVE-2025-21848, CVE-2025-21924, CVE-2025-21948, CVE-2025-21996, CVE-2025-21997, CVE-2025-22044, CVE-2025-22045, CVE-2025-22086, CVE-2025-22103, CVE-2025-23136, CVE-2025-37757, CVE-2025-37788, CVE-2025-37792, CVE-2025-37794, CVE-2025-37857, CVE-2025-38408, CVE-2025-38544, CVE-2025-38664, CVE-2025-38668, CVE-2025-40040, CVE-2025-68340, CVE-2025-71125, CVE-2025-71182, CVE-2025-71235, CVE-2026-23021, CVE-2026-23190, CVE-2026-23335, CVE-2026-23439, CVE-2026-31503, CVE-2026-31510, CVE-2026-31515, CVE-2026-31521, CVE-2026-31523, CVE-2026-31540, CVE-2026-31581, CVE-2026-31592, CVE-2026-31624, CVE-2026-31625, CVE-2026-31634, CVE-2026-31651, CVE-2026-31661, CVE-2026-31664, CVE-2026-31671, CVE-2026-31672, CVE-2026-43284

CLSA: 2026:1778266904