AlmaLinux 9.6 [TuxCare] 安全更新:kernel / kernel-abi-stablelists / kernel-core / 等多个漏洞 (ALMALINUX9.6:CLSA-2026:1778787063)

high Nessus 插件 ID 361904

简介

AlmaLinux 主机缺少一个或多个安全更新。

描述

AlmaLinux 9.6 主机上存在安装的程序包,该程序包受到 TuxCare ALMALINUX9.6:CLSA-2026:1778787063公告中提及的多个漏洞的影响。

- 已修复 Linux 内核中的下列漏洞:can: m_can: pci: add missing m_can_class_free_dev() in probe/remove methods In m_can_pci_remove() and error handling path of m_can_pci_probe(), m_can_class_free_dev() should be called to free resource allocated by m_can_class_allocate_dev(), otherwise there will be memleak. (CVE-2022-49024)

- 已修复 Linux 内核中的下列漏洞:ima: Fix a potential integer overflow in ima_appraise_measurement When the ima-modsig is enabled, the rc passed to evm_verifyxattr() may be negative, which may cause the integer overflow problem. (CVE-2022-49643)

- 已修复 Linux 内核中的下列漏洞:usbnet: fix memory leak in error case usbnet_write_cmd_async() mixed up which buffers need to be freed in which error case. v2: add Fixes tag v3: fix uninitialized buf pointer (CVE-2022-49657)

- 已修复 Linux 内核中的下列漏洞:can: j1939: j1939_send_one(): fix missing CAN header initialization The read access to struct canxl_frame::len inside of a j1939 created skbuff revealed a missing initialization of reserved and later filled elements in struct can_frame. This patch initializes the 8 byte CAN header with zero. (CVE-2022-49845)

- 已修复 Linux 内核中的下列漏洞:misc: tifm: fix possible memory leak in tifm_7xx1_switch_media() If device_register() returns error in tifm_7xx1_switch_media(), name of kobject which is allocated in dev_set_name() called in device_add() is leaked. Never directly free @dev after calling device_register(), even if it returned an error! Always use put_device() to give up the reference initialized. (CVE-2022-50349)

请注意,Nessus 尚未测试这些问题,而是只依据应用程序自我报告的版本号进行判断。

解决方案

根据 TuxCare 公告 ALMALINUX9.6:CLSA-2026:1778787063 中的指南更新受影响的程序包。

另见

https://cve.tuxcare.com/els/releases/CLSA-2026:1778787063

http://www.nessus.org/u?e3932354

插件详情

严重性: High

ID: 361904

文件名: tuxcare_alma_linux_9.6_CLSA-2026-1778787063.nasl

版本: 1.2

类型: Local

发布时间: 2026/10/1

最近更新时间: 2026/10/2

支持的传感器: Continuous Assessment, Nessus Agent, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

风险信息

VPR

风险因素: Critical

分数: 9.5

百分位: 99.87

Vendor

Vendor Severity: Important

CVSS v2

风险因素: Medium

基本分数: 6.8

时间分数: 5.9

矢量: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS 分数来源: CVE-2026-46300

CVSS v3

风险因素: High

基本分数: 7.8

时间分数: 7.5

矢量: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

时间矢量: CVSS:3.0/E:H/RL:O/RC:C

漏洞信息

必需的 KB 项: Host/OS/extended-third-party, Host/local_checks_enabled, Host/AlmaLinux/release, Host/AlmaLinux/rpm-list, Host/cpu

可利用: true

易利用性: Exploits are available

补丁发布日期: 2026/5/14

漏洞发布日期: 2021/7/21

可利用的方式

Core Impact

Metasploit (Fragnesia LPE (CVE-2026-46300))

参考资料信息

CVE: CVE-2022-49024, CVE-2022-49643, CVE-2022-49657, CVE-2022-49845, CVE-2022-50282, CVE-2022-50349, CVE-2022-50387, CVE-2022-50438, CVE-2022-50476, CVE-2022-50498, CVE-2023-53062, CVE-2023-53165, CVE-2023-53629, CVE-2023-53685, CVE-2024-39494, CVE-2024-40954, CVE-2024-47679, CVE-2024-50195, CVE-2024-53052, CVE-2024-53119, CVE-2024-56606, CVE-2024-56662, CVE-2024-57981, CVE-2024-57987, CVE-2024-57993, CVE-2024-58012, CVE-2024-58062, CVE-2024-58068, CVE-2024-58077, CVE-2024-58088, CVE-2025-21636, CVE-2025-21648, CVE-2025-21649, CVE-2025-21664, CVE-2025-21665, CVE-2025-21672, CVE-2025-21683, CVE-2025-21691, CVE-2025-21728, CVE-2025-21729, CVE-2025-21744, CVE-2025-21745, CVE-2025-21750, CVE-2025-21758, CVE-2025-21766, CVE-2025-21776, CVE-2025-21779, CVE-2025-21796, CVE-2025-21830, CVE-2025-21833, CVE-2025-21838, CVE-2025-21844, CVE-2025-21847, CVE-2025-21853, CVE-2025-21861, CVE-2025-21875, CVE-2025-21877, CVE-2025-21881, CVE-2025-21885, CVE-2025-21891, CVE-2025-21909, CVE-2025-21924, CVE-2025-21941, CVE-2025-21948, CVE-2025-21951, CVE-2025-21959, CVE-2025-21971, CVE-2025-21975, CVE-2025-21981, CVE-2025-21996, CVE-2025-22008, CVE-2025-22044, CVE-2025-22057, CVE-2025-22063, CVE-2025-22075, CVE-2025-22086, CVE-2025-22103, CVE-2025-23131, CVE-2025-23136, CVE-2025-23145, CVE-2025-37757, CVE-2025-37765, CVE-2025-37766, CVE-2025-37773, CVE-2025-37792, CVE-2025-37794, CVE-2025-37801, CVE-2025-37824, CVE-2025-37859, CVE-2025-37867, CVE-2025-37877, CVE-2025-37980, CVE-2025-37994, CVE-2025-38045, CVE-2025-38096, CVE-2025-38099, CVE-2025-38193, CVE-2025-38208, CVE-2025-38430, CVE-2025-38436, CVE-2025-38439, CVE-2025-38468, CVE-2025-38474, CVE-2025-38539, CVE-2025-38643, CVE-2025-38705, CVE-2025-39705, CVE-2025-39707, CVE-2025-39745, CVE-2025-39829, CVE-2025-39851, CVE-2025-39889, CVE-2025-39902, CVE-2025-39940, CVE-2025-40164, CVE-2025-40185, CVE-2025-71116, CVE-2025-71225, CVE-2026-23076, CVE-2026-23125, CVE-2026-31493, CVE-2026-31500, CVE-2026-31551, CVE-2026-46300

CLSA: 2026:1778787063