CentOS Linux 8 [TuxCare] 安全更新:bpftool / kernel / kernel-core / kernel-cross-headers / 等多个漏洞 (CENTOS-STREAM8:CLSA-2026:1782375682)

high Nessus 插件 ID 361917

简介

CentOS Linux 主机缺少一个或多个安全更新。

描述

CentOS Linux 8 主机上存在安装的程序包,该程序包受到 TuxCare CENTOS-STREAM8:CLSA-2026:1782375682公告中提及的多个漏洞的影响。

- 已修复 Linux 内核中的下列漏洞:bpf: Don't redirect packets with invalid pkt_len Syzbot found an issue [1]: fq_codel_drop() try to drop a flow whitout any skbs, that is, the flow->head is null. The root cause, as the [2] says, is because that bpf_prog_test_run_skb() run a bpf prog which redirects empty skbs. So we should determine whether the length of the packet modified by bpf prog or others like bpf_prog_test is valid before forwarding it directly. (CVE-2022-49975)

- 已修复 Linux 内核中的下列漏洞:ASoC: SOF: debug: Fix potential buffer overflow by snprintf() snprintf() returns the would-be-filled size when the string overflows the given buffer size, hence using this value may result in the buffer overflow (although it's unrealistic). This patch replaces with a safer version, scnprintf() for papering over such a potential issue.
(CVE-2022-50051)

- 已修复 Linux 内核中的下列漏洞:x86/alternatives: Disable KASAN in apply_alternatives() Fei has reported that KASAN triggers during apply_alternatives() on a 5-level paging machine: BUG: KASAN: out-of-bounds in rcu_is_watching() Read of size 4 at addr ff110003ee6419a0 by task swapper/0/0 ... __asan_load4() rcu_is_watching() trace_hardirqs_on() text_poke_early() apply_alternatives() ... On machines with 5-level paging, cpu_feature_enabled(X86_FEATURE_LA57) gets patched. It includes KASAN code, where KASAN_SHADOW_START depends on __VIRTUAL_MASK_SHIFT, which is defined with cpu_feature_enabled(). KASAN gets confused when apply_alternatives() patches the KASAN_SHADOW_START users. A test patch that makes KASAN_SHADOW_START static, by replacing
__VIRTUAL_MASK_SHIFT with 56, works around the issue. Fix it for real by disabling KASAN while the kernel is patching alternatives. [ mingo: updated the changelog ] (CVE-2023-52504)

- 已修复 Linux 内核中的下列漏洞:drm/amd: Fix UBSAN array-index-out-of-bounds for SMU7 For pptable structs that use flexible array sizes, use flexible arrays. (CVE-2023-52818)

- 已修复 Linux 内核中的下列漏洞:nbd: defer config unlock in nbd_genl_connect There is one use-after-free warning when running NBD_CMD_CONNECT and NBD_CLEAR_SOCK:
nbd_genl_connect nbd_alloc_and_init_config // config_refs=1 nbd_start_device // config_refs=2 set NBD_RT_HAS_CONFIG_REF open nbd // config_refs=3 recv_work done // config_refs=2 NBD_CLEAR_SOCK // config_refs=1 close nbd // config_refs=0 refcount_inc -> uaf ------------[ cut here ]------------ refcount_t: addition on 0; use-after-free. WARNING: CPU: 24 PID: 1014 at lib/refcount.c:25 refcount_warn_saturate+0x12e/0x290 nbd_genl_connect+0x16d0/0x1ab0 genl_family_rcv_msg_doit+0x1f3/0x310 genl_rcv_msg+0x44a/0x790 The issue can be easily reproduced by adding a small delay before refcount_inc(&nbd->config_refs) in nbd_genl_connect(): mutex_unlock(&nbd->config_lock); if (!ret) {set_bit(NBD_RT_HAS_CONFIG_REF, &config->runtime_flags); + printk(before sleep\n); + mdelay(5 * 1000); + printk(after sleep\n); refcount_inc(&nbd->config_refs); nbd_connect_reply(info, nbd->index); } (CVE-2025-68366)

请注意,Nessus 尚未测试这些问题,而是只依据应用程序自我报告的版本号进行判断。

解决方案

根据 TuxCare 公告 CENTOS-STREAM8:CLSA-2026:1782375682 中的指南更新受影响的程序包。

另见

https://cve.tuxcare.com/els/releases/CLSA-2026:1782375682

http://www.nessus.org/u?f1ff0a61

插件详情

严重性: High

ID: 361917

文件名: tuxcare_centos_8_CLSA-2026-1782375682.nasl

版本: 1.1

类型: Local

代理: unix

发布时间: 2026/10/1

最近更新时间: 2026/10/1

支持的传感器: Continuous Assessment, Nessus Agent, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

风险信息

VPR

风险因素: Medium

分数: 6.9

百分位: 97.08

Vendor

Vendor Severity: Important

CVSS v2

风险因素: Medium

基本分数: 6.8

时间分数: 5

矢量: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS 分数来源: CVE-2026-43027

CVSS v3

风险因素: High

基本分数: 7.8

时间分数: 6.8

矢量: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

时间矢量: CVSS:3.0/E:U/RL:O/RC:C

漏洞信息

必需的 KB 项: Host/OS/extended-third-party, Host/local_checks_enabled, Host/CentOS/release, Host/CentOS/rpm-list

易利用性: No known exploits are available

补丁发布日期: 2026/6/25

漏洞发布日期: 2021/7/21

参考资料信息

CVE: CVE-2022-49975, CVE-2022-50051, CVE-2023-52504, CVE-2023-52818, CVE-2025-38361, CVE-2025-68366, CVE-2025-71082, CVE-2025-71091, CVE-2026-23099, CVE-2026-23191, CVE-2026-23243, CVE-2026-23270, CVE-2026-23455, CVE-2026-31405, CVE-2026-31532, CVE-2026-31581, CVE-2026-31685, CVE-2026-43027, CVE-2026-43110, CVE-2026-43158, CVE-2026-43190, CVE-2026-43370

CLSA: 2026:1782375682