Linux Distros 未修补的漏洞:CVE-2026-98307

critical Nessus 插件 ID 363272

简介

Linux/Unix 主机上安装的一个或多个程序包存在漏洞,但供应商表示不会修补此漏洞。

描述

Linux/Unix 主机中安装的一个或多个程序包受到一个漏洞影响,而供应商没有提供补丁程序。

- wifi:ath11k:清理 ath11k_mac_peer_cleanup_all() 中的 arsta mac80211 删除 sta 时,它会调用 .sta_state(),而 () 接着调用 ath11k_mac_station_remove()。在该函数中,我们会同时清理对等机和 arsta 相关的资源。但当固件崩溃时,ath11k 会调用 ieee80211_restart_hw(),进而假设事先清除所有与驱动程序有关的资源。此清理据称由 ath11k_mac_peer_cleanup_all() 完成,但实际上并未释放 arsta->rx_stats/tx_stats。将 arsta 从 ath11k_mac_station_remove() 提取到新 ath11k_mac_station_cleanup() 中,并从该处和 ath11k_mac_peer_cleanup_all() 进行调用。这应该处理 kmemleaks 报告,例如:未引用的对象0xffffff801ae66400(大小 1024):comm hostapd、pid 1306、jiffies 4295011565 hex 转储(前 32 字节):00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................回溯 (CRC d61c08ec):kmemleak_alloc+0x3c/0x50 __kmalloc_cache_noprof+0x2b0/0x3e0 ath11k_mac_op_sta_state+0x1dc/0xb10 drv_sta_state+0xac/0x6f8 sta_info_insert_rcu+0x314/0x5e0 sta_info_insert+0x14/0x38 ieee80211_add_station+0x10c/0x1a0 nl80211_new_station+0x3e8/0x680 genl_family_rcv_msg_doit+0xc0/0x120 genl_rcv_msg+0x1b4/0x258 netlink_rcv_skb+0x4c/0x108 genl_rcv+0x38/0x60 netlink_unicast+0x190/0x278 netlink_sendmsg+0x15c/0x370 ____sys_sendmsg+0x120/0x290
___sys_sendmsg+0x70/0xa0 测试对象: QCN9074 hw1.0 PCI WLAN。HK.2.9.0.1-01977-QCAHKSWPL_SILICONZ-1 (CVE-2026-98307)

请注意,Nessus 依赖供应商报告的程序包是否存在进行判断。

解决方案

目前尚未有任何已知的解决方案。

另见

https://security-tracker.debian.org/tracker/CVE-2026-98307

插件详情

严重性: Critical

ID: 363272

文件名: unpatched_CVE_2026_98307.nasl

版本: 1.1

类型: Local

代理: unix

系列: Misc.

发布时间: 2026/10/6

最近更新时间: 2026/10/6

支持的传感器: Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

风险信息

VPR

风险因素: Low

分数: 3

百分位: 23.66

CVSS v2

风险因素: High

基本分数: 7.5

时间分数: 6.4

矢量: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS 分数来源: CVE-2026-98307

CVSS v3

风险因素: Critical

基本分数: 9.8

时间分数: 9

矢量: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

时间矢量: CVSS:3.0/E:U/RL:U/RC:C

漏洞信息

CPE: cpe:/o:debian:debian_linux:12.0, cpe:/o:debian:debian_linux:13.0, p-cpe:/a:debian:debian_linux:linux

必需的 KB 项: Host/local_checks_enabled, Host/cpu, global_settings/vendor_unpatched, Host/OS/identifier

易利用性: No known exploits are available

漏洞发布日期: 2026/10/6

参考资料信息

CVE: CVE-2026-98307