Linux Distros のパッチ未適用の脆弱性: CVE-2026-74289

critical Nessus プラグイン ID 335521

概要

Linux/Unix ホストには、ベンダーにより修正されていないことを示す脆弱性を持つ複数のパッケージがインストールされています。

説明

Linux/Unix ホストには、ベンダーが提供するパッチが利用できない脆弱性の影響を受ける複数のパッケージがインストールされています。

- ipv4:fib:fib_leaf_notify() で瀕死fib_infoをダンプしません。syzbot が nsim_fib4_prepare_event() の use-after-free を報告しました。[0] 問題は、次の関数がRCUでfib_infoをダンプする間、fib_info_hold()/refcount_inc()を呼び出すため、安全ではありません。* mlxsw_sp_router_fib4_event() * rocker_router_fib_event() * nsim_fib4_prepare_event() refcount_inc_not_zero() を使用する必要がありますが、そこでは手遅れになります。fib_leaf_notify() のfib_infoの寿命を保証しましょう。fib6_table_dump()はfib6_table.tb6_lockを保持するため、IPv6に対応する変更は必要ありません。[0]:refcount_t:0 の加算;use-after-free。警告: lib/refcount.c:25 at refcount_warn_saturate+0x9f/0x110 lib/refcount.c:25、 CPU#0: kworker/u8:15/3420 リンクされているモジュール: CPU: 0 UID: 0 PID: 3420 通信: kworker/u8:15 汚染されていない syzkaller #0 PREEMPT_{RT,(full)} ハードウェア名: Google Google Compute Engine/Google Compute Engine、BIOS Google 2026 年 4 月 18 日 Workqueue: netns cleanup_net RIP: 0010:refcount_warn_saturate+0x9f/0x110 lib/refcount.c:25 コード: EB 66 85 DB 74 3E 83 FB 01 75 4C E8 1B F1 22 FD 48 8D 3D 84 CB F1 0A 67 48 0f B9 3A EB 4A E8 08 F1 22 FD 48 8D 3D 81 CB F1 0A <67> 48 0F B9 3A EB 37 E8 F5 F0 22 FD 48 8D 3D 7E CB F1 0A 67 48 0f RSP: 0018:ffffc9000f2c7270 EFLAGS: 00010293 RAX: ffffffff84a18858 RBX: 0000000000000002 RCX:
ffff888032ff9ec0 RDX: 0000000000000000000 RSI: 000000000000000000 RDI: ffffffff8f9353e0 RBP: 0000000000000000000 R08: ffff888032ff9ec0 R09: 0000000000000005 R10: 0000000000000100 R11: 0000000000000004 R12:
ffff8880570cc000 R13: dffffc00000000000 R14: ffff88802b40563c R15: ffff8880570cc000 FS:
000000000000000000(0000) GS:ffff888126173000(0000) knlGS:000000000000000000 CS:0010 DS:0000 ES:0000 CR0:
0000000080050033 CR2: 00007fb1f4d5d000 CR3: 000000006072a000 CR4: 00000000003526f0 コールトレース: <TASK>
__refcount_add include/linux/refcount.h:-1 [インライン] __refcount_inc include/linux/refcount.h:366 [インライン] refcount_inc include/linux/refcount.h:383 [インライン] fib_info_hold include/net/ip_fib.h:629 [インライン] nsim_fib4_prepare_event drivers/net/netdevsim/fib.c:930 [インライン] nsim_fib_event_schedule_work drivers/net/netdevsim/fib.c:1000 [インライン] nsim_fib_event_nb+0x1055/0x1240 drivers/net/netdevsim/fib.c:1043 call_fib_notifier+0x45/0x80 net/core/fib_notifier.c:25 call_fib_entry_notifier net/ipv4/fib_trie.c:90 [インライン] fib_leaf_notify net/ipv4/fib_trie.c:2176 [インライン] fib_table_notify net/ipv4/fib_trie.c:2194 [インライン] fib_notify+0x36b/0x5e0 net/ipv4/fib_trie.c:2217 fib_net_dump net/core/fib_notifier.c:70 [インライン] register_fib_notifier+0x184/0x360 net/core/fib_notifier.c:108 nsim_fib_create+0x85d/0x9f0 drivers/net/netdevsim/fib.c:1596 nsim_dev_reload_create drivers/net/netdevsim/dev.c:1604 [インライン] nsim_dev_reload_up+0x374/0x7c0 drivers/net/netdevsim/dev.c:1058 devlink_reload+0x501/0x8d0 net/devlink/dev.c:475 devlink_pernet_pre_exit+0x1ff/0x420 net/devlink/core.c:558 ops_pre_exit_list net/core/net_namespace.c:161 [インライン] ops_undo_list+0x187/0x940 net/core/net_namespace.c:234 cleanup_net+0x56e/0x800 net/core/net_namespace.c:702 process_one_work kernel/workqueue.c:3314 [インライン] process_scheduled_works+0xb5d/0x1860 kernel/workqueue.c:3397 worker_thread+0xa53/0xfc0 kernel/workqueue.c:3478 kthread+0x388/0x470 kernel/kthread.c:436 ret_from_fork+0x514/0xb70 arch/x86/kernel/process.c:158 ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245 </TASK> (CVE-2026-74289)

Nessus は、ベンダーによって報告されたパッケージの存在に依存していることに注意してください。

ソリューション

現時点で既知の解決策はありません。

参考資料

https://security-tracker.debian.org/tracker/CVE-2026-74289

プラグインの詳細

深刻度: Critical

ID: 335521

ファイル名: unpatched_CVE_2026_74289.nasl

バージョン: 1.1

タイプ: Local

エージェント: unix

ファミリー: Misc.

公開日: 2026/8/15

更新日: 2026/8/15

サポートされているセンサー: Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

リスク情報

VPR

リスクファクター: Medium

スコア: 6.3

パーセンタイル: 96.61

CVSS v2

リスクファクター: High

基本値: 7.5

現状値: 6.4

ベクトル: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS スコアのソース: CVE-2026-74289

CVSS v3

リスクファクター: Critical

基本値: 9.8

現状値: 9

ベクトル: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

現状ベクトル: CVSS:3.0/E:U/RL:U/RC:C

脆弱性情報

CPE: cpe:/o:debian:debian_linux:11.0, cpe:/o:debian:debian_linux:12.0, cpe:/o:debian:debian_linux:13.0, p-cpe:/a:debian:debian_linux:linux

必要な KB アイテム: Host/local_checks_enabled, Host/cpu, global_settings/vendor_unpatched, Host/OS/identifier

エクスプロイトの容易さ: No known exploits are available

脆弱性公開日: 2026/8/15

参照情報

CVE: CVE-2026-74289