AlmaLinux 9.2 [TuxCare] 安全更新:bpftool / kernel / kernel-abi-stablelists / kernel-core / 等多种漏洞 (ALMALINUX9.2:CLSA-2026:1787935638)

high Nessus 插件 ID 361746

简介

AlmaLinux 主机缺少一个或多个安全更新。

描述

AlmaLinux 9.2 主机上存在安装的程序包,该程序包受到 TuxCare ALMALINUX9.2:CLSA-2026:1787935638公告中提及的多个漏洞的影响。

- 已修复 Linux 内核中的下列漏洞:fs/mount_setattr: always cleanup mount_kattr Make sure that finish_mount_kattr() is called after mount_kattr was succesfully built in both the success and failure case to prevent leaking any references we took when we built it. We returned early if path lookup failed thereby risking to leak an additional reference we took when building mount_kattr when an idmapped mount was requested. (CVE-2021-46923)

- 已修复 Linux 内核中的下列漏洞:vdpa: ifcvf: Do proper cleanup if IFCVF init fails ifcvf_mgmt_dev leaks memory if it is not freed before returning. Call is made to correct return statement so memory does not leak. ifcvf_init_hw does not take care of this so it is needed to do it here. (CVE-2022-48706)

- 已修复 Linux 内核中的下列漏洞:tracing/histogram: Fix a potential memory leak for kstrdup() kfree() is missing on an error path to free the memory allocated by kstrdup(): p = param = kstrdup(data->params[i], GFP_KERNEL); So it is better to free it via kfree(p). (CVE-2022-48768)

- 已修复 Linux 内核中的下列漏洞:efi: fix NULL-deref in init error path In cases where runtime services are not supported or have been disabled, the runtime services workqueue will never have been allocated. Do not try to destroy the workqueue unconditionally in the unlikely event that EFI initialisation fails to avoid dereferencing a NULL pointer. (CVE-2022-48879)

- 已修复 Linux 内核中的下列漏洞:RDMA/srp: Do not call scsi_done() from srp_abort() After scmd_eh_abort_handler() has called the SCSI LLD eh_abort_handler callback, it performs one of the following actions: * Call scsi_queue_insert(). * Call scsi_finish_command(). * Call scsi_eh_scmd_add(). Hence, SCSI abort handlers must not call scsi_done(). Otherwise all the above actions would trigger a use-after-free. Hence remove the scsi_done() call from srp_abort(). Keep the srp_free_req() call before returning SUCCESS because we may not see the command again if SUCCESS is returned. (CVE-2023-52515)

请注意,Nessus 尚未测试这些问题,而是只依据应用程序自我报告的版本号进行判断。

解决方案

根据 TuxCare 公告 ALMALINUX9.2:CLSA-2026:1787935638 中的指南更新受影响的程序包。

另见

https://cve.tuxcare.com/els/releases/CLSA-2026:1787935638

http://www.nessus.org/u?05e487ee

插件详情

严重性: High

ID: 361746

文件名: tuxcare_alma_linux_9.2_CLSA-2026-1787935638.nasl

版本: 1.1

类型: Local

发布时间: 2026/10/1

最近更新时间: 2026/10/1

支持的传感器: Continuous Assessment, Nessus Agent, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

风险信息

VPR

风险因素: High

分数: 7.9

百分位: 99.35

Vendor

Vendor Severity: Important

CVSS v2

风险因素: High

基本分数: 7.2

时间分数: 5.6

矢量: CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C

CVSS 分数来源: CVE-2026-53196

CVSS v3

风险因素: High

基本分数: 7.8

时间分数: 7

矢量: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

时间矢量: CVSS:3.0/E:P/RL:O/RC:C

CVSS 分数来源: CVE-2026-64225

CVSS v4

风险因素: High

Base Score: 7.3

Threat Score: 6.4

Threat Vector: CVSS:4.0/E:P

Vector: CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

CVSS 分数来源: CVE-2025-54518

漏洞信息

必需的 KB 项: Host/OS/extended-third-party, Host/local_checks_enabled, Host/AlmaLinux/release, Host/AlmaLinux/rpm-list, Host/cpu

可利用: true

易利用性: Exploits are available

补丁发布日期: 2026/8/28

漏洞发布日期: 2021/7/21

参考资料信息

CVE: CVE-2021-46923, CVE-2022-48706, CVE-2022-48768, CVE-2022-48879, CVE-2022-49030, CVE-2023-52515, CVE-2023-52910, CVE-2023-52913, CVE-2023-53582, CVE-2024-43854, CVE-2024-49948, CVE-2024-50039, CVE-2024-56720, CVE-2025-21673, CVE-2025-38264, CVE-2025-40048, CVE-2025-54518, CVE-2025-68815, CVE-2026-23007, CVE-2026-23278, CVE-2026-31392, CVE-2026-31393, CVE-2026-31530, CVE-2026-31679, CVE-2026-43060, CVE-2026-43062, CVE-2026-43071, CVE-2026-43187, CVE-2026-43469, CVE-2026-43501, CVE-2026-45838, CVE-2026-45839, CVE-2026-45840, CVE-2026-45841, CVE-2026-45842, CVE-2026-45847, CVE-2026-45850, CVE-2026-45856, CVE-2026-45857, CVE-2026-45886, CVE-2026-45948, CVE-2026-45964, CVE-2026-45983, CVE-2026-45987, CVE-2026-46015, CVE-2026-46018, CVE-2026-46021, CVE-2026-46023, CVE-2026-46040, CVE-2026-46049, CVE-2026-46056, CVE-2026-46082, CVE-2026-46088, CVE-2026-46101, CVE-2026-46108, CVE-2026-46119, CVE-2026-46128, CVE-2026-46132, CVE-2026-46151, CVE-2026-46161, CVE-2026-46167, CVE-2026-46172, CVE-2026-46177, CVE-2026-46184, CVE-2026-46189, CVE-2026-46191, CVE-2026-46197, CVE-2026-46218, CVE-2026-46220, CVE-2026-46234, CVE-2026-46249, CVE-2026-46259, CVE-2026-46294, CVE-2026-52920, CVE-2026-52935, CVE-2026-52947, CVE-2026-52948, CVE-2026-52955, CVE-2026-52957, CVE-2026-52962, CVE-2026-52963, CVE-2026-52969, CVE-2026-52970, CVE-2026-52972, CVE-2026-52985, CVE-2026-52993, CVE-2026-53002, CVE-2026-53012, CVE-2026-53016, CVE-2026-53022, CVE-2026-53037, CVE-2026-53064, CVE-2026-53072, CVE-2026-53075, CVE-2026-53080, CVE-2026-53093, CVE-2026-53135, CVE-2026-53136, CVE-2026-53168, CVE-2026-53176, CVE-2026-53177, CVE-2026-53181, CVE-2026-53195, CVE-2026-53196, CVE-2026-53212, CVE-2026-53218, CVE-2026-53219, CVE-2026-53223, CVE-2026-53227, CVE-2026-53228, CVE-2026-53238, CVE-2026-53239, CVE-2026-53245, CVE-2026-53249, CVE-2026-53254, CVE-2026-53255, CVE-2026-53256, CVE-2026-53263, CVE-2026-53268, CVE-2026-53269, CVE-2026-53287, CVE-2026-53295, CVE-2026-53304, CVE-2026-53337, CVE-2026-53391, CVE-2026-63800, CVE-2026-63945, CVE-2026-64174, CVE-2026-64225, CVE-2026-64237, CVE-2026-64572, CVE-2026-64576, CVE-2026-64579, CVE-2026-68093, CVE-2026-68108, CVE-2026-68121, CVE-2026-68142, CVE-2026-68143, CVE-2026-68153, CVE-2026-68155, CVE-2026-68156, CVE-2026-68160, CVE-2026-68188, CVE-2026-68189, CVE-2026-68313, CVE-2026-68315, CVE-2026-68320, CVE-2026-68324, CVE-2026-68363, CVE-2026-68377, CVE-2026-68388, CVE-2026-68398, CVE-2026-68402, CVE-2026-68414, CVE-2026-68426, CVE-2026-72396, CVE-2026-74499

CLSA: 2026:1787935638