SUSE SLED15:cluster-md-kmp-default / dlm-kmp-default / gfs2-kmp-default / etc(SUSE-SU-2026:2722-1)

high Nessus プラグイン ID 324872

Language:

概要

リモートの SUSE ホストに 1 つ以上のセキュリティ更新がありません。

説明

リモートの SUSE Linux SLED15 / SLED_SAP15 / SLES15 / SLES_SAP15 ホストには、SUSE-SU-2026:2722-1 のアドバイザリに記載された複数の脆弱性の影響を受けるパッケージがインストールされています。

SUSE Linux Enterprise 15 SP7 カーネルが更新され、さまざまなセキュリティバグの修正が行われています。


次のセキュリティバグを修正しました。

- CVE-2025-10263:arm64:エラータ:さまざまな Arm CPU で TLBI エラータを緩和します(bsc#1266290)。
- CVE-2025-68822:Input:alps - dev3_register_work によって引き起こされる use-after-free のバグを修正します(bsc#1256668)。
- CVE-2026-23392:netfilter:nf_tables:エラー時の rcu 猶予期間の後にフローテーブルをリリースします(bsc#1260531)。
- CVE-2026-31414:netfilter:nf_conntrack_expect:expect->helper を使用します(bsc#1262085)。
- CVE-2026-31429:net:skb:KFENCE が割り当てた skb ヘッドのクロスキャッシュ解放を修正します(bsc#1262392)。
- CVE-2026-31452:ext4:切り捨てがインラインサイズ(bsc#1262620)を超える場合、インラインデータをエクステントに変換します。
- CVE-2026-31469:virtio_net:IFF_XMIT_DST_RELEASEがクリアされ、napi_txが偽の場合に、dst_opsの UAF を修正します
- CVE-2026-31492:RDMA/irdma:使用する前にfree_qp完了を初期化します(bsc#1262748)。
- CVE-2026-31495:netfilter:ctnetlink:netlink ポリシー範囲チェックを使用します(bsc#1262798)。
- CVE-2026-31499:Bluetooth:L2CAP:l2cap_conn_del() のデッドロックを修正します(bsc#1262674)。
- CVE-2026-31500:Bluetooth:btintel:btintel_hw_error() を hci_req_sync_lock でシリアル化します(bsc#1262993)。
- CVE-2026-31555:futex:futex_lock_pi() 再試行パスの古い終了ポインターをクリアします(bsc#1263178)。
- CVE-2026-31560:spi:spi-dw-dma:待機完了トランザクション時のエラーログの印刷を修正します(bsc#1263057)。
- CVE-2026-31592:KVM:SEV:kvm->lock (bsc#1263123) で sev_mem_enc_register_region() の *すべて* を保護します。
- CVE-2026-31593:KVM:SEV:すでに起動/暗号化された vCPU の VMSA を同期しようとする試みを拒否します(bsc#1263124)。
- CVE-2026-31664:string.h:末尾のメンバー/パディングをワイプするために memset_after() を導入します(bsc#1263578)。
- CVE-2026-31665:kABI:netfilter:nft_ct:タイムアウトオブジェクト破壊時の use-after-free を修正します(bsc#1263137)。
- CVE-2026-31674:netfilter:ip6t_rt:rt_mt6_check() でサイズが大きすぎる addrnr を拒否します(bsc#1263568)。
- CVE-2026-31680:net:ipv6:flowlabel:RCU 分解(bsc#1263563)まで排他的オプションの解放を延期します。
- CVE-2026-31693:cifs:リプレイでいくつかの欠落した初期化(bsc#1267744)。
- CVE-2026-31752:ブリッジ:br_nd_send:ND オプションの長さを検証します(bsc#1264045)。
- CVE-2026-31759:usb:ulpi:ulpi_register_interface() エラーパスの二重解放を修正します(bsc#1264076)。
- CVE-2026-43023:Bluetooth:SCO:sco_sock_connect() での競合状態を修正します(bsc#1264137)。
- CVE-2026-43024:netfilter:nf_tables:即時NF_QUEUE判定を拒否します(bsc#1263930)。
- CVE-2026-43028:netfilter:x_tables:名前が NULL で終わるようにします(bsc#1263934)。
- CVE-2026-43035:net:sched:cls_api:情報漏洩を防ぐために、tcm_infoをゼロに初期化するためにtc_chain_fill_nodeを修正します(bsc#1263996)。
- CVE-2026-43036:net:TCPv4 GSO frag_offチェックに skb_header_pointer() を使用します(bsc#1263993)。
- CVE-2026-43049:HID:logitech-hidpp:フォースフィードバック初期化失敗時の use-after-free を防止します(bsc#1264080)。
- CVE-2026-43077:crypto:algif_aead - 復号化のための最小 RX サイズチェックを修正します(bsc#1264470)。
- CVE-2026-43083:net:ioam6:OOB および欠如しているロックを修正します(bsc#1264266)。
- CVE-2026-43101:ipv6:ioam:__ioam6_fill_trace_data() での NULL 逆参照の可能性を修正します(bsc#1264239)。
- CVE-2026-43112:fs/smb/client:cifs_sanitize_prepath における領域外読み取りを修正します(bsc#1264437)。
- CVE-2026-43119:Bluetooth:hci_sync:hdev->req_status 周辺のデータ競合に注釈をつけます(bsc#1264561)。
- CVE-2026-43158:xfs:リーフブロックに xattrs を追加する際の freemap 調整を修正します(bsc#1264595)。
- CVE-2026-43171:EFI/CPER:メモリ領域全体をダンプしません(bsc#1264549)。
- CVE-2026-43187:xfs:空の場合は属性リーフフリーマップエントリを削除します(bsc#1264603)。
- CVE-2026-43198:tcp:tcp_v6_syn_recv_sock() での競合の可能性を修正します(bsc#1264610)。
- CVE-2026-43239:smb:client:->query_interfaces() での競合を防止します(bsc#1264444)。
- CVE-2026-43339:ipv6:addrconf_permanent_addr() での潜在的な UaF を防止します(bsc#1264763)。
- CVE-2026-43345:net:ipa:IPA v5.0+ に対してプログラムされていないイベントリングインデックスを修正します(bsc#1265103)。
- CVE-2026-43405:libceph:ceph_monmap_decode() の負でない値に対して u32 を使用します(bsc#1264741)。
- CVE-2026-43469:xprtrdma:早期終了パスのre_receivingを減少(bsc#1265143)。
- CVE-2026-43491:net:qrtr:ns:ノードあたりのサーバー登録の最大数(bsc#1265628)を制限します。
- CVE-2026-45840:openvswitch:cap upcall PID 配列サイズと事前サイズ vport 応答(bsc#1266397)。
- CVE-2026-45841:netfilter:nfnetlink_osf:OSF_WSS_MODULO でのゼロ除算を修正します(bsc#1266390)。
- CVE-2026-45862:iommu/vt-d:PASID テーブルを使用する前に、そのキャッシュをフラッシュします(bsc#1266705)。
- CVE-2026-45870:SUNRPC:auth_gss:XDR デコーディングエラーパスのメモリリークを修正します(bsc#1266704)。
- CVE-2026-45894:iommu/vt-d:PASID エントリをティアダウンする前に、現在のビットをクリアします(bsc#1266895)。
- CVE-2026-45940:net:stmmac:ヘッダー分割が有効な場合の oops を修正します(bsc#1266916)。
- CVE-2026-45961:gfs2:gfs2_fill_super エラーパスでのメモリリークを修正します(bsc#1266933)。
- CVE-2026-45964:SUNRPC:エラーパスgss_auth kref 漏洩を修正gss_alloc_msg(bsc#1266698)。
- CVE-2026-45965:apparmor:export_binary が未設定の場合の rawdata の無効な逆参照を修正します(bsc#1267208)。
- CVE-2026-45974:btrfs:参照キーが見つからない場合の btrfs_quota_enable() での無効なリーフアクセスを修正します(bsc#1266922)。
- CVE-2026-46005:xfs:xfs_alloc_buftarg() でのリソース漏洩を修正します(bsc#1267431)。
- CVE-2026-46037:ipv4:icmp:icmp_pointers を使用する前に返信タイプを検証します(bsc#1267361)。
- CVE-2026-46101:netfilter:nft_bitwise のゼロシフトを拒否します(bsc#1266878)。
- CVE-2026-46119:libceph:認証メッセージ処理における slab-out-of-bounds アクセスを修正します(bsc#1267628)。
- CVE-2026-46123:Bluetooth:virtio_bt:skb_put前に rx の長さをクランプします(bsc#1267621)。
- CVE-2026-46150:fanotify:権限イベントの誤検出を修正します(bsc#1267387)。
- CVE-2026-46160:btrfs:ディレクトリを削除する際に欠落した last_unlink_trans 更新を修正します(bsc#1267624)。
- CVE-2026-46162:ice:ice_sf_eth_activate() エラーパスの二重解放を修正します(bsc#1266840)。
- CVE-2026-46172:ipv6:xfrm6:xfrm6_rcv_encap() のエラー時に DST をリリースします(bsc#1266903)。
- CVE-2026-46244:netfilter:nft_inner:IPv6 inner_thoff非同期を修正します(bsc#1267654)。
- CVE-2026-46259:procfs:do_task_stat() で real_parent を読み取るときに RCU 保護がないのを修正します(bsc#1267685)。
- CVE-2026-46273:ibmveth:MSS が小さいパケットに対して GSO を無効にします(bsc#1267651)。


Tenable は、前述の記述ブロックを SUSE セキュリティアドバイザリから直接抽出しています。

Nessus はこれらの問題をテストしておらず、代わりにアプリケーションが自己報告するバージョン番号にのみ依存していることに注意してください。

ソリューション

影響を受けるパッケージを更新してください。

参考資料

https://bugzilla.suse.com/1256668

https://bugzilla.suse.com/1260531

https://bugzilla.suse.com/1262085

https://bugzilla.suse.com/1262392

https://bugzilla.suse.com/1262617

https://bugzilla.suse.com/1262620

https://bugzilla.suse.com/1262674

https://bugzilla.suse.com/1262748

https://bugzilla.suse.com/1262798

https://bugzilla.suse.com/1262993

https://bugzilla.suse.com/1263057

https://bugzilla.suse.com/1263123

https://bugzilla.suse.com/1263124

https://bugzilla.suse.com/1263137

https://bugzilla.suse.com/1263178

https://bugzilla.suse.com/1263563

https://bugzilla.suse.com/1263568

https://bugzilla.suse.com/1263578

https://bugzilla.suse.com/1263930

https://bugzilla.suse.com/1263934

https://bugzilla.suse.com/1263993

https://bugzilla.suse.com/1263996

https://bugzilla.suse.com/1264045

https://bugzilla.suse.com/1264076

https://bugzilla.suse.com/1264080

https://bugzilla.suse.com/1264137

https://bugzilla.suse.com/1264239

https://bugzilla.suse.com/1264266

https://bugzilla.suse.com/1264437

https://bugzilla.suse.com/1264444

https://bugzilla.suse.com/1264470

https://bugzilla.suse.com/1264549

https://bugzilla.suse.com/1264561

https://bugzilla.suse.com/1264595

https://bugzilla.suse.com/1264603

https://bugzilla.suse.com/1264610

https://bugzilla.suse.com/1264741

https://bugzilla.suse.com/1264763

https://bugzilla.suse.com/1265103

https://bugzilla.suse.com/1265143

https://bugzilla.suse.com/1265628

https://bugzilla.suse.com/1266290

https://bugzilla.suse.com/1266390

https://bugzilla.suse.com/1266397

https://bugzilla.suse.com/1266698

https://bugzilla.suse.com/1266704

https://bugzilla.suse.com/1266705

https://bugzilla.suse.com/1266840

https://bugzilla.suse.com/1266878

https://bugzilla.suse.com/1266895

https://bugzilla.suse.com/1266903

https://bugzilla.suse.com/1266916

https://bugzilla.suse.com/1266922

https://bugzilla.suse.com/1266933

https://bugzilla.suse.com/1267208

https://bugzilla.suse.com/1267251

https://bugzilla.suse.com/1267361

https://bugzilla.suse.com/1267387

https://bugzilla.suse.com/1267431

https://bugzilla.suse.com/1267621

https://bugzilla.suse.com/1267624

https://bugzilla.suse.com/1267628

https://bugzilla.suse.com/1267651

https://bugzilla.suse.com/1267654

https://bugzilla.suse.com/1267685

https://bugzilla.suse.com/1267744

https://lists.suse.com/pipermail/sle-updates/2026-July/047848.html

https://www.suse.com/security/cve/CVE-2025-10263

https://www.suse.com/security/cve/CVE-2025-68822

https://www.suse.com/security/cve/CVE-2026-23392

https://www.suse.com/security/cve/CVE-2026-31414

https://www.suse.com/security/cve/CVE-2026-31429

https://www.suse.com/security/cve/CVE-2026-31452

https://www.suse.com/security/cve/CVE-2026-31453

https://www.suse.com/security/cve/CVE-2026-31469

https://www.suse.com/security/cve/CVE-2026-31492

https://www.suse.com/security/cve/CVE-2026-31495

https://www.suse.com/security/cve/CVE-2026-31499

https://www.suse.com/security/cve/CVE-2026-31500

https://www.suse.com/security/cve/CVE-2026-31555

https://www.suse.com/security/cve/CVE-2026-31560

https://www.suse.com/security/cve/CVE-2026-31592

https://www.suse.com/security/cve/CVE-2026-31593

https://www.suse.com/security/cve/CVE-2026-31664

https://www.suse.com/security/cve/CVE-2026-31665

https://www.suse.com/security/cve/CVE-2026-31674

https://www.suse.com/security/cve/CVE-2026-31680

https://www.suse.com/security/cve/CVE-2026-31693

https://www.suse.com/security/cve/CVE-2026-31752

https://www.suse.com/security/cve/CVE-2026-31759

https://www.suse.com/security/cve/CVE-2026-43023

https://www.suse.com/security/cve/CVE-2026-43024

https://www.suse.com/security/cve/CVE-2026-43028

https://www.suse.com/security/cve/CVE-2026-43035

https://www.suse.com/security/cve/CVE-2026-43036

https://www.suse.com/security/cve/CVE-2026-43049

https://www.suse.com/security/cve/CVE-2026-43077

https://www.suse.com/security/cve/CVE-2026-43083

https://www.suse.com/security/cve/CVE-2026-43101

https://www.suse.com/security/cve/CVE-2026-43112

https://www.suse.com/security/cve/CVE-2026-43119

https://www.suse.com/security/cve/CVE-2026-43158

https://www.suse.com/security/cve/CVE-2026-43171

https://www.suse.com/security/cve/CVE-2026-43187

https://www.suse.com/security/cve/CVE-2026-43198

https://www.suse.com/security/cve/CVE-2026-43239

https://www.suse.com/security/cve/CVE-2026-43339

https://www.suse.com/security/cve/CVE-2026-43345

https://www.suse.com/security/cve/CVE-2026-43405

https://www.suse.com/security/cve/CVE-2026-43469

https://www.suse.com/security/cve/CVE-2026-43491

https://www.suse.com/security/cve/CVE-2026-45840

https://www.suse.com/security/cve/CVE-2026-45841

https://www.suse.com/security/cve/CVE-2026-45862

https://www.suse.com/security/cve/CVE-2026-45870

https://www.suse.com/security/cve/CVE-2026-45894

https://www.suse.com/security/cve/CVE-2026-45940

https://www.suse.com/security/cve/CVE-2026-45961

https://www.suse.com/security/cve/CVE-2026-45964

https://www.suse.com/security/cve/CVE-2026-45965

https://www.suse.com/security/cve/CVE-2026-45974

https://www.suse.com/security/cve/CVE-2026-46005

https://www.suse.com/security/cve/CVE-2026-46037

https://www.suse.com/security/cve/CVE-2026-46101

https://www.suse.com/security/cve/CVE-2026-46119

https://www.suse.com/security/cve/CVE-2026-46123

https://www.suse.com/security/cve/CVE-2026-46150

https://www.suse.com/security/cve/CVE-2026-46160

https://www.suse.com/security/cve/CVE-2026-46162

https://www.suse.com/security/cve/CVE-2026-46172

https://www.suse.com/security/cve/CVE-2026-46244

https://www.suse.com/security/cve/CVE-2026-46259

https://www.suse.com/security/cve/CVE-2026-46273

プラグインの詳細

深刻度: High

ID: 324872

ファイル名: suse_SU-2026-2722-1.nasl

バージョン: 1.1

タイプ: Local

エージェント: unix

公開日: 2026/7/2

更新日: 2026/7/2

サポートされているセンサー: Agentless Assessment, Continuous Assessment, Frictionless Assessment Agent, Frictionless Assessment AWS, Frictionless Assessment Azure, Nessus Agent, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

リスク情報

VPR

リスクファクター: High

スコア: 7.5

パーセンタイル: 98.46

CVSS v2

リスクファクター: Medium

基本値: 6.8

現状値: 5.3

ベクトル: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS スコアのソース: CVE-2026-46162

CVSS v3

リスクファクター: High

基本値: 7.8

現状値: 7

ベクトル: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

現状ベクトル: CVSS:3.0/E:P/RL:O/RC:C

脆弱性情報

CPE: p-cpe:/a:novell:suse_linux:kernel-livepatch-6_4_0-150700_53_63-default, p-cpe:/a:novell:suse_linux:kernel-default-base, p-cpe:/a:novell:suse_linux:reiserfs-kmp-default, p-cpe:/a:novell:suse_linux:kernel-default-livepatch, p-cpe:/a:novell:suse_linux:kernel-zfcpdump, p-cpe:/a:novell:suse_linux:cluster-md-kmp-default, p-cpe:/a:novell:suse_linux:gfs2-kmp-default, p-cpe:/a:novell:suse_linux:kernel-default, p-cpe:/a:novell:suse_linux:kernel-obs-build, p-cpe:/a:novell:suse_linux:kernel-default-extra, p-cpe:/a:novell:suse_linux:ocfs2-kmp-default, p-cpe:/a:novell:suse_linux:kernel-azure, p-cpe:/a:novell:suse_linux:dlm-kmp-default, p-cpe:/a:novell:suse_linux:kernel-source, p-cpe:/a:novell:suse_linux:kernel-64kb, cpe:/o:novell:suse_linux:15

必要な KB アイテム: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list

エクスプロイトが利用可能: true

エクスプロイトの容易さ: Exploits are available

パッチ公開日: 2026/7/1

脆弱性公開日: 2026/1/13

参照情報

CVE: CVE-2025-10263, CVE-2025-68822, CVE-2026-23392, CVE-2026-31414, CVE-2026-31429, CVE-2026-31452, CVE-2026-31453, CVE-2026-31469, CVE-2026-31492, CVE-2026-31495, CVE-2026-31499, CVE-2026-31500, CVE-2026-31555, CVE-2026-31560, CVE-2026-31592, CVE-2026-31593, CVE-2026-31664, CVE-2026-31665, CVE-2026-31674, CVE-2026-31680, CVE-2026-31693, CVE-2026-31752, CVE-2026-31759, CVE-2026-43023, CVE-2026-43024, CVE-2026-43028, CVE-2026-43035, CVE-2026-43036, CVE-2026-43049, CVE-2026-43077, CVE-2026-43083, CVE-2026-43101, CVE-2026-43112, CVE-2026-43119, CVE-2026-43158, CVE-2026-43171, CVE-2026-43187, CVE-2026-43198, CVE-2026-43239, CVE-2026-43339, CVE-2026-43345, CVE-2026-43405, CVE-2026-43469, CVE-2026-43491, CVE-2026-45840, CVE-2026-45841, CVE-2026-45862, CVE-2026-45870, CVE-2026-45894, CVE-2026-45940, CVE-2026-45961, CVE-2026-45964, CVE-2026-45965, CVE-2026-45974, CVE-2026-46005, CVE-2026-46037, CVE-2026-46101, CVE-2026-46119, CVE-2026-46123, CVE-2026-46150, CVE-2026-46160, CVE-2026-46162, CVE-2026-46172, CVE-2026-46244, CVE-2026-46259, CVE-2026-46273

SuSE: SUSE-SU-2026:2722-1