AlmaLinux 9.2 [TuxCare] 安全更新:bpftool / kernel / kernel-abi-stablelists / kernel-core / 等多个漏洞 (ALMALINUX9.2:CLSA-2025:1742806909)

high Nessus 插件 ID 361511

简介

AlmaLinux 主机缺少一个或多个安全更新。

描述

AlmaLinux 9.2 主机上存在安装的程序包,该程序包受到 TuxCare ALMALINUX9.2:CLSA-2025:1742806909公告中提及的多个漏洞的影响。

- 已修复 Linux 内核中的下列漏洞:asix: fix uninit-value in asix_mdio_read() asix_read_cmd() may read less than sizeof(smsr) bytes and in this case smsr will be uninitialized. Fail log: BUG: KMSAN: uninit-value in asix_check_host_enable drivers/net/usb/asix_common.c:82 [inline] BUG: KMSAN: uninit-value in asix_check_host_enable drivers/net/usb/asix_common.c:82 [inline] drivers/net/usb/asix_common.c:497 BUG: KMSAN: uninit-value in asix_mdio_read+0x3c1/0xb00 drivers/net/usb/asix_common.c:497 drivers/net/usb/asix_common.c:497 asix_check_host_enable drivers/net/usb/asix_common.c:82 [inline] asix_check_host_enable drivers/net/usb/asix_common.c:82 [inline] drivers/net/usb/asix_common.c:497 asix_mdio_read+0x3c1/0xb00 drivers/net/usb/asix_common.c:497 drivers/net/usb/asix_common.c:497 (CVE-2021-47101)

- 已修复 Linux 内核中的下列漏洞:vt_ioctl: fix array_index_nospec in vt_setactivate array_index_nospec ensures that an out-of-bounds value is set to zero on the transient path. Decreasing the value by one afterwards causes a transient integer underflow. vsa.console should be decreased first and then sanitized with array_index_nospec. Kasper Acknowledgements: Jakob Koschel, Brian Johannesmeyer, Kaveh Razavi, Herbert Bos, Cristiano Giuffrida from the VUSec group at VU Amsterdam.
(CVE-2022-48804)

- 已修复 Linux 内核中的下列漏洞:hwmon: (coretemp) fix pci device refcount leak in nv1a_ram_new() As comment of pci_get_domain_bus_and_slot() says, it returns a pci device with refcount increment, when finish using it, the caller must decrement the reference count by calling pci_dev_put(). So call it after using to avoid refcount leak. (CVE-2022-49011)

- 已修复 Linux 内核中的下列漏洞:bus: mhi: host: Add alignment check for event ring read pointer Though we do check the event ring read pointer by is_valid_ring_ptr to make sure it is in the buffer range, but there is another risk the pointer may be not aligned. Since we are expecting event ring elements are 128 bits(struct mhi_ring_element) aligned, an unaligned read pointer could lead to multiple issues like DoS or ring buffer memory corruption. So add a alignment check for event ring read pointer. (CVE-2023-52494)

- 已修复 Linux 内核中的下列漏洞:ring-buffer: Do not attempt to read past commit When iterating over the ring buffer while the ring buffer is active, the writer can corrupt the reader. There's barriers to help detect this and handle it, but that code missed the case where the last event was at the very end of the page and has only 4 bytes left. The checks to detect the corruption by the writer to reads needs to see the length of the event. If the length in the first 4 bytes is zero then the length is stored in the second 4 bytes. But if the writer is in the process of updating that code, there's a small window where the length in the first 4 bytes could be zero even though the length is only 4 bytes. That will cause rb_event_length() to read the next 4 bytes which could happen to be off the allocated page. To protect against this, fail immediately if the next event pointer is less than 8 bytes from the end of the commit (last byte of data), as all events must be a minimum of 8 bytes anyway.
(CVE-2023-52501)

请注意,Nessus 尚未测试这些问题,而是只依据应用程序自我报告的版本号进行判断。

解决方案

根据 TuxCare 公告 ALMALINUX9.2:CLSA-2025:1742806909 中的指南更新受影响的程序包。

另见

https://cve.tuxcare.com/els/releases/CLSA-2025:1742806909

http://www.nessus.org/u?cb525ea3

插件详情

严重性: High

ID: 361511

文件名: tuxcare_alma_linux_9.2_CLSA-2025-1742806909.nasl

版本: 1.1

类型: Local

发布时间: 2026/10/1

最近更新时间: 2026/10/1

支持的传感器: Continuous Assessment, Nessus Agent, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

风险信息

VPR

风险因素: High

分数: 8.9

百分位: 99.7

Vendor

Vendor Severity: Important

CVSS v2

风险因素: Medium

基本分数: 6.8

时间分数: 5.6

矢量: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS 分数来源: CVE-2025-21692

CVSS v3

风险因素: High

基本分数: 7.8

时间分数: 7.2

矢量: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

时间矢量: CVSS:3.0/E:F/RL:O/RC:C

漏洞信息

必需的 KB 项: Host/OS/extended-third-party, Host/local_checks_enabled, Host/AlmaLinux/release, Host/AlmaLinux/rpm-list, Host/cpu

可利用: true

易利用性: Exploits are available

补丁发布日期: 2025/3/24

漏洞发布日期: 2021/7/21

CISA 已知可遭利用的漏洞到期日期: 2025/2/26, 2025/3/25

参考资料信息

CVE: CVE-2021-47101, CVE-2022-48804, CVE-2022-49011, CVE-2023-52494, CVE-2023-52501, CVE-2023-52612, CVE-2023-52637, CVE-2023-52679, CVE-2023-52741, CVE-2023-52812, CVE-2023-52837, CVE-2023-52840, CVE-2023-52854, CVE-2023-52859, CVE-2024-26704, CVE-2024-26734, CVE-2024-26782, CVE-2024-26885, CVE-2024-26958, CVE-2024-26961, CVE-2024-26989, CVE-2024-27045, CVE-2024-27395, CVE-2024-35847, CVE-2024-35855, CVE-2024-35862, CVE-2024-35863, CVE-2024-35864, CVE-2024-35866, CVE-2024-35867, CVE-2024-35905, CVE-2024-35979, CVE-2024-36940, CVE-2024-39502, CVE-2024-43830, CVE-2024-44970, CVE-2024-46853, CVE-2024-50074, CVE-2024-50127, CVE-2024-50131, CVE-2024-50143, CVE-2024-50150, CVE-2024-50151, CVE-2024-50154, CVE-2024-50267, CVE-2024-50278, CVE-2024-50279, CVE-2024-50301, CVE-2024-50302, CVE-2024-53059, CVE-2024-53104, CVE-2024-53239, CVE-2024-56538, CVE-2024-56551, CVE-2024-56606, CVE-2024-56615, CVE-2024-56658, CVE-2024-57798, CVE-2025-21692, CVE-2025-21795

CLSA: 2025:1742806909