CentOS Linux 8 [TuxCare] 安全更新:bpftool / kernel / kernel-core / kernel-cross-headers / 等多个漏洞 (CENTOS-STREAM8:CLSA-2026:1780132980)

high Nessus 插件 ID 362073

简介

CentOS Linux 主机缺少一个或多个安全更新。

描述

CentOS Linux 8 主机上存在安装的程序包,该程序包受到 TuxCare CENTOS-STREAM8:CLSA-2026:1780132980 公告中提及的多个漏洞的影响。

- Linux 内核 5.12.14 中的 kernel/module.c 未正确处理签名验证,又称为 CID-0c18f29aae7c。如果没有CONFIG_MODULE_SIG,则不会针对 module.sig_enforce=1 命令行参数验证内核模块已签名以通过init_module加载。(CVE-2021-35039)

- 在 5.13.4 之前的 Linux 内核的 drivers/char/virtio_console.c 中,不受信任的设备提供超过缓冲区大小的 buf->len 值时可以触发数据损坏或丢失。注意:供应商表示,所述数据损坏在任何现有使用案例中都不属于漏洞;添加长度验证只是为了在面对主机 OS 异常行为时保持稳定 (CVE-2021-38160)

- Linux 内核的 net/bluetooth/l2cap_core.c 的 l2cap_connect 和 l2cap_le_connect_req 函数中存在释放后使用漏洞,可能允许通过蓝牙(分别)远程执行代码和泄漏内核内存。如果在受害者附近,远程攻击者可通过蓝牙执行泄露内核内存的代码。我们建议升级过去的提交 https://www.google.com/url https://github.com/torvalds/linux/commit/711f8c3fb3db61897080468586b970c87c61d9e4 https://www.google.com/url (CVE-2022-42896)

- 已修复 Linux 内核中的下列漏洞:tracing: Fix potential double free in create_var_ref() In create_var_ref(), init_var_ref() is called to initialize the fields of variable ref_field, which is allocated in the previous function call to create_hist_field(). Function init_var_ref() allocates the corresponding fields such as ref_field->system, but frees these fields when the function encounters an error. The caller later calls destroy_hist_field() to conduct error handling, which frees the fields and the variable itself. This results in double free of the fields which are already freed in the previous function. Fix this by storing NULL to the corresponding fields when they are freed in init_var_ref(). (CVE-2022-49410)

- 已修复 Linux 内核中的下列漏洞:HID: elan: Fix potential double free in elan_input_configured 'input' is a managed resource allocated with devm_input_allocate_device(), so there is no need to call input_free_device() explicitly or there will be a double free. According to the doc of devm_input_allocate_device(): * Managed input devices do not need to be explicitly unregistered or
* freed as it will be done automatically when owner device unbinds from * its driver (or binding fails).
(CVE-2022-49508)

请注意,Nessus 尚未测试这些问题,而是只依据应用程序自我报告的版本号进行判断。

解决方案

根据 TuxCare 公告 CENTOS-STREAM8:CLSA-2026:1780132980 中的指南更新受影响的程序包。

另见

https://cve.tuxcare.com/els/releases/CLSA-2026:1780132980

http://www.nessus.org/u?78268d5f

插件详情

严重性: High

ID: 362073

文件名: tuxcare_centos_8_CLSA-2026-1780132980.nasl

版本: 1.2

类型: Local

代理: unix

发布时间: 2026/10/1

最近更新时间: 2026/10/2

支持的传感器: Continuous Assessment, Nessus Agent, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

风险信息

VPR

风险因素: High

分数: 7.9

百分位: 99.35

Vendor

Vendor Severity: Important

CVSS v2

风险因素: High

基本分数: 7.2

时间分数: 6.3

矢量: CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C

CVSS 分数来源: CVE-2021-38160

CVSS v3

风险因素: High

基本分数: 8.8

时间分数: 8.4

矢量: CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

时间矢量: CVSS:3.0/E:H/RL:O/RC:C

CVSS 分数来源: CVE-2022-42896

漏洞信息

必需的 KB 项: Host/OS/extended-third-party, Host/local_checks_enabled, Host/CentOS/release, Host/CentOS/rpm-list

可利用: true

易利用性: Exploits are available

补丁发布日期: 2026/5/30

漏洞发布日期: 2021/7/7

参考资料信息

CVE: CVE-2021-35039, CVE-2021-38160, CVE-2022-42896, CVE-2022-49410, CVE-2022-49508, CVE-2022-49870, CVE-2022-49907, CVE-2022-49917, CVE-2022-49948, CVE-2022-50200, CVE-2022-50315, CVE-2022-50366, CVE-2022-50432, CVE-2022-50497, CVE-2023-52475, CVE-2023-52531, CVE-2023-52741, CVE-2023-52867, CVE-2023-52868, CVE-2023-52988, CVE-2023-53000, CVE-2023-53019, CVE-2023-53075, CVE-2023-53116, CVE-2023-53285, CVE-2023-53307, CVE-2023-53321, CVE-2023-53338, CVE-2023-53506, CVE-2023-53570, CVE-2023-53622, CVE-2023-53646, CVE-2023-53668, CVE-2024-46812, CVE-2025-68741, CVE-2025-71093, CVE-2025-71116, CVE-2026-23216, CVE-2026-23388, CVE-2026-31602, CVE-2026-31778, CVE-2026-43020, CVE-2026-43040, CVE-2026-43206, CVE-2026-43450, CVE-2026-46243

CLSA: 2026:1780132980