2023 Amazon Linux:bpftool6.12、kernel6.12、kernel6.12-devel(ALAS2023-2026-2057)

high Nessus プラグイン ID 337239

概要

リモートの Amazon Linux 2023 ホストに、セキュリティ更新プログラムがありません。

説明

したがって、ALAS2023-2026-2057 のアドバイザリに記載されている複数の脆弱性の影響を受けます。

Linux カーネルで、以下の脆弱性が解決されています。

iommu/vt-d:コンテキストエントリをティアダウンする前に、現在ビットをクリアします(CVE-2026-45944)

Linux カーネルで、以下の脆弱性が解決されています。

mm/vmalloc:シュリンカでvmap_purge_lockを取り入れます(CVE-2026-46093)

Linux カーネルで、以下の脆弱性が解決されています。

af_unix:SOCKMAP のすべての SCM 属性をドロップします。(CVE-2026-53005)

Linux カーネルで、以下の脆弱性が解決されています。

fs/ntfs3:attr_data_get_block_locked() の vcn0 に対する実行ロードの欠落を修正します(CVE-2026-53027)

Linux カーネルで、以下の脆弱性が解決されています。

vsock/virtio:multi-skb 送信の zerocopy 完了を修正します(CVE-2026-53365)

Linux カーネルで、以下の脆弱性が解決されています。

NFSv4/flexfiles:ゼロのファイルハンドルバージョンカウントを拒否します(CVE-2026-53392)

Linux カーネルで、以下の脆弱性が解決されています。

fbdev:fbcon:fbcon_do_set_font() のerr_outにおける領域外読み取りを修正します

fbcon_do_set_font() が失敗する場合(例:高メモリ圧迫状態での vc_resize() 内部のメモリ割り当て失敗が原因)、「err_out」ラベルにジャンプしてコンソールの状態をロールバックします。ただし、現在のロールバックロジックは「hi_font」状態を復元するのを忘れるため、深刻な状態のマシン破損につながります。

この関数の初期段階で、「vc->vc_hi_font_mask」を変更し、画面バッファを変更するために「set_vc_hi_font()」が呼び出される可能性があります。その後「vc_resize()」が失敗すると、「err_out」パスは「vc_font.charcount」を復元しますが、「vc_hi_font_mask」とスクリーンバッファのロールバックを完全にスキップします。

この不一致により、端末が非同期状態になります。「vc_hi_font_mask」が設定されたままであるため、VT サブシステムはユーザー空間から 255 を超える文字インデックスを受け入れ、これらをスクリーンバッファに書き込みます。その後のレンダリング呼び出し(「fbcon_putcs()」)はこれらの拡大したインデックスを使用して、戻された 256 文字のフォント配列にアクセスし、決定論的な領域外読み取りとカーネルメモリの漏洩を引き起こす可能性があります。

エラーパスの「hi_font」マスクおよびスクリーンバッファに欠如しているロールバックロジックを追加することで、これを修正します。
(CVE-2026-53402)

Linux カーネルで、以下の脆弱性が解決されています。

vsock/virtio:zerocopy skb を満たす前に uarg をバインドします(CVE-2026-63970)

Linux カーネルで、以下の脆弱性が解決されています。

tcp:ISN 予測を有効にする古い CPU ごとのtcp_tw_isn漏洩を修正します

Blamed commit が、TIME_WAIT派生の ISN を skb 制御ブロックから CPU ごとの変数に移動しました。これは、その値を書き込んだ同じパケットに対して tcp_conn_request() が常にその値を消費することを想定しています。この前提は、プロデューサー(__this_cpu_write(tcp_tw_isn, isn) in tcp_v{4,6}_rcv))とコンシューマー(tcp_conn_request())の間の複数のドロップパスによって違反されます。

- min_ttl / min_hopcount check- xfrm ポリシーチェック- tcp_inbound_hash() MD5/AO の不一致- tcp_filter() eBPF/SO_ATTACH_FILTER ドロップ- th->syn &; &; th->fin を tcp_rcv_state_process() TCP_LISTEN-psp_sk_rx_policy_check() in tcp_v{4,6}_do_rcv() - tcp_checksum_complete() in tcp_v{4,6}_do_rcv()- tcp_v{4,6}_cookie_check() NULL を返す

パケットがこれらのパスのいずれかでドロップされると、tcp_tw_isnは設定されたままになります。

次に同じCPUで処理された次のSYNがゼロでない値intcp_conn_request()を消費し、潜在的に予測可能なISNを受け取ります。

このパッチは skb->cb[] にtcp_tw_isn戻り、per-cpuvariable を排除します。

注意:tcp_v{4,6}_fill_cb() では設定されません。

全体的なコードのサイズ/複雑さへの影響はごくわずかです:

$ scripts/bloat-o-meter -t vmlinux.old vmlinux.newadd/remove: 0/0 grow/shrink: 2/1 up/down: 8/-15 (-7)function old new deltatcp_v6_rcv 3038 3042 +4tcp_v4_rcv 3035 3039 +4tcp_conn_request 2938 2923 -15Total: Before=24436060, After=24436053, chg -0.00% (CVE-2026-64024)

Linux カーネルで、以下の脆弱性が解決されています。

netfilter:ebtables:2 段階削除スキームに移動します(CVE-2026-64077)

Linux カーネルで、以下の脆弱性が解決されています。

xfs:領域のないコミットされたログ項目でリカバリが失敗する

トランザクションの最初の操作がベア・トランザクション・ヘッダー(len == sizeof(struct xfs_trans_header))の場合、xlog_recover_add_to_trans()はアイテムを追加しますが、リージョンは追加せず、ri_cnt == 0 andri_buf == NULLのr_itemqに残します。

ヘッダーはopレコード間で分割できるため、後のopsは引き続きregionsを追加できます。トランザクションが None でコミットする場合にのみ、項目は無効になります。ランタイムコミットパスはそのようなトランザクションを決して発行しないため、これは細工されたログでのみ発生します。これは、回復パーサーのAI支援コード監査から得られたものです。

xlog_recover_reorder_trans() はアイテム上で ITEM_TYPE() を呼び出します。
*)item->ri_buf[0].iov_baseおよびNULLri_bufの障害。同じくreadri_buf[0]のコミットハンドラーの前に、そこで拒否します。

KASAN:範囲の null-ptr-deref [0x0000000000000000-0x0000000000000007]RIP:0010:xlog_recover_reorder_trans(fs/xfs/xfs_log_recover.c:1836)xlog_recover_commit_trans(fs/xfs/xfs_log_recover.c:2043)xlog_recover_process_data(fs/xfs/xfs_log_recover.c:2501)xlog_do_recovery_pass(fs/xfs/xfs_log_recover.c:3244)xlog_recover(fs/xfs/xfs_log_recover.c:3493)xfs_log_mount(fs/xfs/xfs_log.c:618)xfs_mountfs(fs/xfs/xfs_mount.c:1034)xfs_fs_fill_super(fs/xfs/xfs_super.c:1938)vfs_get_tree(fs/super.c:1695)path_mount(fs/namespace.c:4161)__x64_sys_mount(fs/namespace.c:4367)(CVE-2026-64187)

Linux カーネルで、以下の脆弱性が解決されています。

netfilter:ipset:ダンプとip_set_listのサイズ変更間の競合を修正します(CVE-2026-64189)

Linux カーネルで、以下の脆弱性が解決されています。

bpf:BPF LSM が初期化されていない場合、BPF_MAP_TYPE_INODE_STORAGE作成を拒否します

CONFIG_BPF_LSM=y が設定されている場合、BPF inode ストレージマップ(BPF_MAP_TYPE_INODE_STORAGE)がカーネルにコンパイルされます。ただし、BPF LSM が起動時に明示的に有効化されていない場合(例:lsm= boot パラメーターから省略)、BPF LSM に対して lsm_prepare() は実行されません。

その結果、BPF inodeセキュリティブロブオフセット(bpf_lsm_blob_sizes.lbs_inode)は初期化されず、予約された構造体rcu_head(通常は16バイト以上)を超えて有効なオフセットに更新されることなく、デフォルトのコンパイル後サイズ8バイトのままになります。

特権ユーザーがBPF_MAP_TYPE_INODE_STORAGEmapを作成して更新すると、bpf_inode() は inode->i_security + 8 を評価します。これは、inode >i_security blob の先頭で struct rcu_head.func コールバックポインターを誤ってエイリアスします。後続のマップ要素のクリーンアップまたは inode の破壊中に、owner_storageに NULL を書き込むと、queuedRCU コールバックポインターがクリアされます。rcu_do_batch()が後にキューコールバックを実行するとき、アドレス0x0で命令フェッチを試み、即時のカーネルパニックをトリガーします。

__ro_after_init でマークされたグローバルbpf_lsm_initializedブール値を導入することにより、これを修正します。LSM フレームワークが BPF LSM を正常に登録する際に、bpf_lsm_init() 内でこのフラグを true に設定します。このフラグの inode_storage_map_alloc() におけるゲートマッピング割り当て、BPF LSM が逆に初期化されていない場合は EOPNOTSUPP を返します。

このフェイルファストのアプローチにより、サポート BPF LSM インフラストラクチャがないときにユーザー空間が inodestorage マップを割り当てることを防ぎ、ゾンビマップ状態を回避します。(CVE-2026-64192)

Linux カーネルで、以下の脆弱性が解決されています。

ACPI:ドライバー:プローブ中に ACPI_COMPANION() を NULL に対してチェックします(CVE-2026-64227)

Linux カーネルで、以下の脆弱性が解決されています。

fuse:fuse_resend および fuse_remove_pending_req のintr_entryを消去します(CVE-2026-64265)

Linux カーネルで、以下の脆弱性が解決されています。

fuse:fuse_ref_folio() から戻る前にリクエストを再ロックします(CVE-2026-64266)

Linux カーネルで、以下の脆弱性が解決されています。

i2c:core:アダプターの登録解除競合を修正(CVE-2026-64279)

Linux カーネルで、以下の脆弱性が解決されています。

KVM:x86:fastpath ユーザー空間が終了する前にベンダーの終了ハンドラーが確実に実行されるようにします(CVE-2026-64284)

Linux カーネルで、以下の脆弱性が解決されています。

KVM:arm64:pKVM hyp vCPU をフラッシュする際に__hyp_running_vcpuをクリアします(CVE-2026-64286)

Linux カーネルで、以下の脆弱性が解決されています。

KVM:arm64:pKVM hyp vCPU をフラッシュする際のused_lrsがバインドされます(CVE-2026-64287)

Linux カーネルで、以下の脆弱性が解決されています。

mm:適切なマウント idmap でファイル所有権チェックを行います(CVE-2026-64294)

Linux カーネルで、以下の脆弱性が解決されています。

exfat:exfat_find_dir_entry() で uniname の進行をバインドします(CVE-2026-64296)

Linux カーネルで、以下の脆弱性が解決されています。

NFSv4:O_TRUNC 用のオープンパーミッションマスクにMAY_WRITEを含めます(CVE-2026-64298)

Linux カーネルで、以下の脆弱性が解決されています。

tracing:glob マッチングでの領域外読み取りを防ぎます(CVE-2026-64299)

Linux カーネルで、以下の脆弱性が解決されています。

crypto:drbg - CTR_DRBG の失敗時に成功を返すのを修正します(CVE-2026-64306)

Linux カーネルで、以下の脆弱性が解決されています。

crypto:pcrypt - 非パラレルフォールバックのコールバックを復元します(CVE-2026-64312)

Linux カーネルで、以下の脆弱性が解決されています。

crypto:ecc - vli 乗算でのキャリーオーバーフローを修正します(CVE-2026-64313)

Linux カーネルで、以下の脆弱性が解決されています。

isofs:Rock Ridge シンボリックリンクコンポーネントを SL レコードにバインドします(CVE-2026-64317)

Linux カーネルで、以下の脆弱性が解決されています。

udf:バイトカウントではなくエントリカウントとして、スペアリングテーブルの長さを検証します(CVE-2026-64322)

Linux カーネルで、以下の脆弱性が解決されています。

udf:VAT inode サイズに対して VAT ヘッダーの長さを検証します(CVE-2026-64323)

Linux カーネルで、以下の脆弱性が解決されています。

udf:パーティションの長さに対するフリーブロックエクステントを検証します(CVE-2026-64324)

Linux カーネルで、以下の脆弱性が解決されています。

block:bdev_mark_dead() の予期しない削除で sync_blockdev() をスキップします(CVE-2026-64326)

Linux カーネルで、以下の脆弱性が解決されています。

bpf:スリータブル BPF プログラムからの LPM マップアクセスを許可します(CVE-2026-64352)

Linux カーネルで、以下の脆弱性が解決されています。

bpf:拡張前の BTF 繰り返しフィールドカウントを検証します(CVE-2026-64354)

Linux カーネルで、以下の脆弱性が解決されています。

bpf:devmap のフラグメント化されたフレームを拒否します(CVE-2026-64355)

Linux カーネルで、以下の脆弱性が解決されています。

xfs:exchmaps の予約制限チェックを修正します(CVE-2026-64357)

Linux カーネルで、以下の脆弱性が解決されています。

HID:multitouch:mt_io_flags での領域外ビットアクセスを修正します(CVE-2026-64364)

Linux カーネルで、以下の脆弱性が解決されています。

mm/slab:赤いゾーニングのみが有効の場合、ゼロイングを orig_size に制限しません(CVE-2026-64368)

Linux カーネルで、以下の脆弱性が解決されています。

posix-cpu-timers:do_cpu_nanosleep() エラーパスの pid refcount 漏洩を修正します(CVE-2026-64370)

Linux カーネルで、以下の脆弱性が解決されています。

proc:exec_update_lockで ptrace_may_access() を保護します(パート 1)(CVE-2026-64371)

Linux カーネルで、以下の脆弱性が解決されています。

cpufreq:pcc:_OSC 評価における use-after-free および二重解放を修正します(CVE-2026-64372)

Linux カーネルで、以下の脆弱性が解決されています。

cpufreq:再起動中のホットプラグと一時停止の競合を修正します(CVE-2026-64373)

Linux カーネルで、以下の脆弱性が解決されています。

sched/rt:RT_PUSH_IPI が非PREEMPT_RTに対してデフォルトでオフにします(CVE-2026-64374)

Linux カーネルで、以下の脆弱性が解決されています。

proc:exec_update_lock で ptrace_may_access() を保護します(FD リンク)(CVE-2026-64375)

Linux カーネルで、以下の脆弱性が解決されています。

smb:クライアント:POSIX SID の長さの解析を強化します(CVE-2026-64380)

Linux カーネルで、以下の脆弱性が解決されています。

smb:client:receive_encrypted_standard() の次のバッファ漏洩を修正します(CVE-2026-64381)

Linux カーネルで、以下の脆弱性が解決されています。

smb:クライアント:SMB2_open() リプレイでの二重解放を修正します(CVE-2026-64382)

Linux カーネルで、以下の脆弱性が解決されています。

smb:クライアント:SMB2_flush() 再生での二重解放を修正します(CVE-2026-64383)

Linux カーネルで、以下の脆弱性が解決されています。

smb:client:変更通知再生の二重解放を修正します(CVE-2026-64384)

Linux カーネルで、以下の脆弱性が解決されています。

smb:client:SMB2_ioctl() リプレイでの二重解放を修正します(CVE-2026-64385)

Linux カーネルで、以下の脆弱性が解決されています。

smb:クライアント:query_info() リプレイ二重解放を修正(CVE-2026-64386)

Linux カーネルで、以下の脆弱性が解決されています。

smb:client:クエリディレクトリリプレイの二重解放を修正(CVE-2026-64387)

Linux カーネルで、以下の脆弱性が解決されています。

netfilter:ebtables:find_table_lock() の前にテーブル名を終了します(CVE-2026-64411)

Linux カーネルで、以下の脆弱性が解決されています。

netfilter:ebtables:モジュール名は NULL 終端にする必要があります(CVE-2026-64412)

Linux カーネルで、以下の脆弱性が解決されています。

netfilter:ebtables:ゼロチェーンスタック配列(CVE-2026-64413)

Linux カーネルで、以下の脆弱性が解決されています。

netfilter:読み取れないフラグを処理します(CVE-2026-64414)

Linux カーネルで、以下の脆弱性が解決されています。

mm/swap:swap_reclaim_full_clustersに cond_resched() を追加して、softlockup(CVE-2026-64415)を防止します

Linux カーネルで、以下の脆弱性が解決されています。

mm:swap_cgroup:スワップレスホストの lookup_swap_cgroup_id の NULL デリファレンスを修正します(CVE-2026-64416)

Linux カーネルで、以下の脆弱性が解決されています。

mm:シュリンカー:拡張とのshrinker_infoティアダウン競合を修正します(CVE-2026-64418)

Linux カーネルで、以下の脆弱性が解決されています。

net:ipv4:バインドされた TCP の並べ替え sysctl 書き込みおよび MTU プローブサイズ(CVE-2026-64422)

Linux カーネルで、以下の脆弱性が解決されています。

ipv4:igmp:デバイス破壊時に、ハッシュテーブルからマルチキャストグループを削除します(CVE-2026-64423)

Linux カーネルで、以下の脆弱性が解決されています。

io_uring/io-wq:リンクされた各作業項目のIO_WQ_BIT_EXITを再チェックします(CVE-2026-64425)

Linux カーネルで、以下の脆弱性が解決されています。

fs/ntfs3:log_replay copy_lcns のダーティページテーブルの容量を検証します(CVE-2026-64432)

Linux カーネルで、以下の脆弱性が解決されています。

audit:audit_queue 上の skb_queue_len() リーダーのデータ競合を修正します(CVE-2026-64435)

Linux カーネルで、以下の脆弱性が解決されています。

net:af_key:IPComp 状態のalg_key_lenを初期化します(CVE-2026-64436)

Linux カーネルで、以下の脆弱性が解決されています。

SMB:クライアント:データエリアのない応答に対する暗黙の BCC[0] の除外を制限します(CVE-2026-64448)

Linux カーネルで、以下の脆弱性が解決されています。

tipc:ブロードキャストギャップ ACK ブロックの領域外読み取りを修正します(CVE-2026-64450)

Linux カーネルで、以下の脆弱性が解決されています。

hwrng:virtio:device-reported used.len を copy_data() でクランプします(CVE-2026-64456)

Linux カーネルで、以下の脆弱性が解決されています。

virtio_pci:誤ったインデックスによる vq 情報ポインター検索を修正します(CVE-2026-64457)

Linux カーネルで、以下の脆弱性が解決されています。

mm/damon/ops-common:damon_hot_score() における極端な間隔を処理します(CVE-2026-64458)

Linux カーネルで、以下の脆弱性が解決されています。

usb:xhci:xhci_free_streams() 内のアトミックコンテキストのスリープを修正します(CVE-2026-64465)

Linux カーネルで、以下の脆弱性が解決されています。

vfio/mlx5:racy ビットフィールドを修正し、構造体レイアウトを縮小します(CVE-2026-64472)

Linux カーネルで、以下の脆弱性が解決されています。

vfio:ブロックされた arc の vfio_mig_get_next_state() における無限ループを防止します(CVE-2026-64474)

Linux カーネルで、以下の脆弱性が解決されています。

vfio/pci:register_device() が失敗した場合、VGA アービタークライアントを解放します(CVE-2026-64475)

Linux カーネルで、以下の脆弱性が解決されています。

vfio/pci:デバイスごとのラッチdisable_idle_d3(CVE-2026-64476)

Linux カーネルで、以下の脆弱性が解決されています。

x86/bugs:BPF JIT 割り当てで IBPB フラッシュを有効にします(CVE-2026-64507)

Linux カーネルで、以下の脆弱性が解決されています。

bpf:JIT スプレーに対する強化のサポート(CVE-2026-64508)

Linux カーネルで、以下の脆弱性が解決されています。

ACPI:CPPC:フィールドの誤用によって引き起こされる UBSAN 警告を抑制します(CVE-2026-64512)

Linux カーネルで、以下の脆弱性が解決されています。

userfaultfd:pte_present() でのゲートmust_wait書き込み可能性チェック(CVE-2026-64514)

Linux カーネルで、以下の脆弱性が解決されています。

net/sched:cls_api:tcf_qevent_handle のTC_ACT_CONSUMED処理(CVE-2026-64530)

Linux カーネルで、以下の脆弱性が解決されています。

fs/ntfs3:UpdateRecordData{Root,Allocation} の NTFS_DE view.data_off がバインドされます(CVE-2026-64532)

Linux カーネルで、以下の脆弱性が解決されています。

fs/ntfs3:log_replay 変換でlcns_followを検証します(CVE-2026-64533)

Linux カーネルで、以下の脆弱性が解決されています。

ipv6:fib6_nh_mtu_change() の null-ptr-deref を修正します。(CVE-2026-64538)

Linux カーネルで、以下の脆弱性が解決されています。

ipv6:ndisc:accept_untracked_na() の NULL デリファレンスを修正します(CVE-2026-64542)

Linux カーネルで、以下の脆弱性が解決されています。

tipc:tipc_disc_rcv() におけるディスカバラーの use-after-free を修正します(CVE-2026-64543)

Linux カーネルで、以下の脆弱性が解決されています。

crypto:asymmetric_keys - pefile_digest_pe_contents における OOB 読み取りを修正します(CVE-2026-64544)

Linux カーネルで、以下の脆弱性が解決されています。

net、bpf:マスターが xdp_master_redirect() の NULL をチェックします(CVE-2026-64545)

Linux カーネルで、以下の脆弱性が解決されています。

drm/edid:drm_parse_tiled_block() での OOB 読み取りを修正します(CVE-2026-64546)

Linux カーネルで、以下の脆弱性が解決されています。

bpf、sockmap:bpf_msg_push_data() でオーバーフローするコピー + len を拒否します(CVE-2026-64548)

Linux カーネルで、以下の脆弱性が解決されています。

sctp:古くなったSTALE_COOKIE読み取る前に長さを検証します(CVE-2026-64551)

Linux カーネルで、以下の脆弱性が解決されています。

virtio-net:receive_big() の len チェックを修正します(CVE-2026-64552)

Linux カーネルで、以下の脆弱性が解決されています。

net:psample:PSAMPLE_ATTR_DATA での情報漏洩を修正します(CVE-2026-64553)

Linux カーネルで、以下の脆弱性が解決されています。

KVM:arm64:nv:kvm_hyp_handle_mops() での復元SPSR_EL2を修正します(CVE-2026-64555)

Linux カーネルで、以下の脆弱性が解決されています。

perf/core:remove_on_exec中にイベントグループをデタッチ

perf_event_remove_on_exec() は、callingperf_event_exit_event() によってイベントを削除します。これにより、最上位のイベントの場合、DETACH_EXITのみのコンテキストからイベントが削除されます。

これにより、削除されたイベントがグループリーダーで、グループにremove_on_execのない兄弟が含まれている場合、グループの状態に一貫性がないままになる可能性があります。グループがアクティブだった場合、生き残った兄弟はアクティブなままで、移動されたリーダーの兄弟リストに接続できますが、PMU コンテキスト・アクティブ・リストの有効なグループ・リーダーによって表されなくなります。

削除されたリーダーを後で閉じると、DETACH_GROUPが使用され、この古いグループ状態からまだアクティブな兄弟を昇格させることができます。次の schedule-in は、既にリンクされているactive_listエントリを再度追加することができ、PMUcontext アクティブリストを破損します。

DEBUG_LISTが有効な場合、これはlist_add二重追加inmerge_sched_in()として捕捉されます。

remove_on_execがイベントを削除するときにグループ関係をデタッチすることにより、これを修正します。これにより、既存のタスク終了および取り消しの動作が維持されると同時に、削除されたイベントがコンテキストを離れる前に生き残っている兄弟のグループ化が解除されるようになります。(CVE-2026-64556)

Linux カーネルで、以下の脆弱性が解決されています。

posix-cpu-timers:リーダー以外の exec() 競合による UAF を回避します(CVE-2026-64560)

Linux カーネルで、以下の脆弱性が解決されています。

KVM:x86:MMU ページを利用可能にした *後* の無効な/廃止されたルートをチェックします

shadow MMU で MMU ページを利用可能にした後、古いページフォールト(無効および/または廃止された root など)がないかチェックします。シャドウページの再要求によって使用中のルートが破壊される場合、つまり無効としてマークされる場合、KVM はメモリを無効なルートにマッピングしようとします。無効なルートに入力することはそれ自体では問題ありませんが、子シャドウページは親のロールを継承するため、map/fetch 中に作成された子は無効なページとして作成され、無効なページがアクティブな MMU ページのリストに決して載らないという KVM の不変性に違反します。

注意:KVMが2008年に初めて無効なルートの追跡を開始して以来(コミット2e53d63acba7、KVM: MMU:zapped rootpagetablesを無視)、本当の悪さは2020年(Linux 5.9)にのみ現れました。無効なシャドーページはアクティブページのリストに入れることができないという不変性がありました。

#2、子シャドーページの作成時に role.invalid を継承することも理想的とは程遠いことに、この欠陥は別途対処されることに、注意してください。(CVE-2026-64561)

Linux カーネルで、以下の脆弱性が解決されています。

i2c:core:アダプター登録エラーの NULL-deref を修正します(CVE-2026-64589)

Linux カーネルで、以下の脆弱性が解決されています。

btrfs:書き込み不可のデバイスをトリミングしません(CVE-2026-64593)

Linux カーネルで、以下の脆弱性が解決されています。

smb:クライアント:SMB2_close() 再生での二重解放を修正します(CVE-2026-64597)

Linux カーネルで、以下の脆弱性が解決されています。

smb/client:smb2_aead_req_alloc() のエラーコードを修正します(CVE-2026-64598)

Linux カーネルで、以下の脆弱性が解決されています。

KVM:VMX:vCPU がゲストモードの場合、CR8 傍受更新で vmcs12 を入手します(CVE-2026-64604)

Linux カーネルで、以下の脆弱性が解決されています。

mm/khugepaged:折りたたむときにすべてのダーティファイルの Folio が書き込みます(CVE-2026-68086)

Linux カーネルで、以下の脆弱性が解決されています。

debugobjects:同時 OOM 無効化に対するプラグ競合(CVE-2026-68090)

Linux カーネルで、以下の脆弱性が解決されています。

time/jiffies:使用前に jiffies クロックソースを登録します(CVE-2026-68092)

Linux カーネルで、以下の脆弱性が解決されています。

KVM:s390:pci:AISB なしの AIF 有効化の処理を修正します(CVE-2026-68454)

Linux カーネルで、以下の脆弱性が解決されています。

デバイスプロパティ:fwnode_init() の残りの fwnode_handle フィールドを初期化します(CVE-2026-68461)

Linux カーネルで、以下の脆弱性が解決されています。

ipvs:ヘッドの再割り当て後に IP ヘッダーをリロードします(CVE-2026-68476)

Linux カーネルで、以下の脆弱性が解決されています。

ipvs:間違っている ipv6 トランスポートオフセットのあるより多くの場所を修正します(CVE-2026-68477)

Linux カーネルで、以下の脆弱性が解決されています。

cgroup/cpuset:mm mempolicy を mems_allowed ではなく effective_mems に再バインドします(CVE-2026-72010)

Linux カーネルで、以下の脆弱性が解決されています。

tracing/osnoise:登録解除時に synchronize_rcu() を呼び出します(CVE-2026-72012)

Linux カーネルで、以下の脆弱性が解決されています。

drbd:範囲外のペイロードサイズのデータ応答を拒否します(CVE-2026-72014)

Linux カーネルで、以下の脆弱性が解決されています。

ipvs:ip_vs_conn_new の完全な ip_vs_seq 構造体をリセットします(CVE-2026-72020)

Linux カーネルで、以下の脆弱性が解決されています。

ipvs:SCTP 状態検索で解析済みのトランスポートオフセットを使用します(CVE-2026-72021)

Linux カーネルで、以下の脆弱性が解決されています。

mm/compaction:compaction_free() で free_pages_prepare() を適切に処理します(CVE-2026-72027)

Linux カーネルで、以下の脆弱性が解決されています。

fhandle:capable_wrt_mount() で取り外したマウントを拒否します(CVE-2026-72034)

Linux カーネルで、以下の脆弱性が解決されています。

net/sched:sch_taprio:直接 dequeue 呼び出しをピークおよび qdisc_dequeue_peeked で置換(CVE-2026-72035)

Linux カーネルで、以下の脆弱性が解決されています。

net/sched:sch_multiq:直接 dequeue 呼び出しをピークおよび qdisc_dequeue_peeked で置換(CVE-2026-72036)

Linux カーネルで、以下の脆弱性が解決されています。

espintcp:sk_msg_free_partialを使用して、部分送信を修正します(CVE-2026-72041)

Linux カーネルで、以下の脆弱性が解決されています。

net:ip6_gre:changelink 用のデバイス netns に CAP_NET_ADMIN が必要です(CVE-2026-72052)

Linux カーネルで、以下の脆弱性が解決されています。

net:ipip:changelink 用のデバイス netns で CAP_NET_ADMIN が必要です(CVE-2026-72053)

Linux カーネルで、以下の脆弱性が解決されています。

net:ip_vti:changelink 用のデバイス netns に CAP_NET_ADMIN が必要です(CVE-2026-72054)

Linux カーネルで、以下の脆弱性が解決されています。

net:ip6_vti:changelink 用のデバイス netns で CAP_NET_ADMIN が必要です(CVE-2026-72055)

Linux カーネルで、以下の脆弱性が解決されています。

net/sched:act_ct:デフラグ全体でtc_skb_cbを維持します(CVE-2026-72057)

Linux カーネルで、以下の脆弱性が解決されています。

net:sit:changelink 用のデバイス netns で CAP_NET_ADMIN が必要です(CVE-2026-72061)

Linux カーネルで、以下の脆弱性が解決されています。

gpio:tegra:GPIO ディレクションに対して pinctrl を呼び出しません(CVE-2026-72063)

Linux カーネルで、以下の脆弱性が解決されています。

cpu:hotplug:バインドされたホットプラグ状態 sysfs 出力(CVE-2026-72066)

Linux カーネルで、以下の脆弱性が解決されています。

cpu:hotplug:インスタンスごとのコールバックエラーを保存します(CVE-2026-72067)

Linux カーネルで、以下の脆弱性が解決されています。

posix-cpu-timers:update_rlimit_cpu() で u64 乗算を使用します(CVE-2026-72068)

Linux カーネルで、以下の脆弱性が解決されています。

tracing/user_events:user_event_mm_dup() における use-after-free を修正します(CVE-2026-72071)

Linux カーネルで、以下の脆弱性が解決されています。

net/mlx5e:macsec:RX SC 削除の metadata_dst の use-after-free を修正します(CVE-2026-72072)

Linux カーネルで、以下の脆弱性が解決されています。

...

注意: この説明は、長さの関係上省略されています。詳細については、ベンダーのアドバイザリを参照してください。

Tenable は、前述の記述ブロックをテスト済み製品のセキュリティアドバイザリから直接抽出しています。

Nessus はこれらの問題をテストしておらず、代わりにアプリケーションが自己報告するバージョン番号にのみ依存していることに注意してください。

ソリューション

「dnf update kernel6.12 --releasever 2023.12.20260817」または「dnf update --advisory ALAS2023-2026-2057 --releasever 2023.12.20260817」を実行してシステムを更新してください。

参考資料

https://alas.aws.amazon.com//AL2023/ALAS2023-2026-2057.html

https://alas.aws.amazon.com/faqs.html

https://explore.alas.aws.amazon.com/CVE-2026-45944.html

https://explore.alas.aws.amazon.com/CVE-2026-46093.html

https://explore.alas.aws.amazon.com/CVE-2026-53005.html

https://explore.alas.aws.amazon.com/CVE-2026-53027.html

https://explore.alas.aws.amazon.com/CVE-2026-53365.html

https://explore.alas.aws.amazon.com/CVE-2026-53392.html

https://explore.alas.aws.amazon.com/CVE-2026-53402.html

https://explore.alas.aws.amazon.com/CVE-2026-63970.html

https://explore.alas.aws.amazon.com/CVE-2026-64024.html

https://explore.alas.aws.amazon.com/CVE-2026-64077.html

https://explore.alas.aws.amazon.com/CVE-2026-64187.html

https://explore.alas.aws.amazon.com/CVE-2026-64189.html

https://explore.alas.aws.amazon.com/CVE-2026-64192.html

https://explore.alas.aws.amazon.com/CVE-2026-64227.html

https://explore.alas.aws.amazon.com/CVE-2026-64265.html

https://explore.alas.aws.amazon.com/CVE-2026-64266.html

https://explore.alas.aws.amazon.com/CVE-2026-64279.html

https://explore.alas.aws.amazon.com/CVE-2026-64284.html

https://explore.alas.aws.amazon.com/CVE-2026-64286.html

https://explore.alas.aws.amazon.com/CVE-2026-64287.html

https://explore.alas.aws.amazon.com/CVE-2026-64294.html

https://explore.alas.aws.amazon.com/CVE-2026-64296.html

https://explore.alas.aws.amazon.com/CVE-2026-64298.html

https://explore.alas.aws.amazon.com/CVE-2026-64299.html

https://explore.alas.aws.amazon.com/CVE-2026-64306.html

https://explore.alas.aws.amazon.com/CVE-2026-64312.html

https://explore.alas.aws.amazon.com/CVE-2026-64313.html

https://explore.alas.aws.amazon.com/CVE-2026-64317.html

https://explore.alas.aws.amazon.com/CVE-2026-64322.html

https://explore.alas.aws.amazon.com/CVE-2026-64323.html

https://explore.alas.aws.amazon.com/CVE-2026-64324.html

https://explore.alas.aws.amazon.com/CVE-2026-64326.html

https://explore.alas.aws.amazon.com/CVE-2026-64352.html

https://explore.alas.aws.amazon.com/CVE-2026-64354.html

https://explore.alas.aws.amazon.com/CVE-2026-64355.html

https://explore.alas.aws.amazon.com/CVE-2026-64357.html

https://explore.alas.aws.amazon.com/CVE-2026-64364.html

https://explore.alas.aws.amazon.com/CVE-2026-64368.html

https://explore.alas.aws.amazon.com/CVE-2026-64370.html

https://explore.alas.aws.amazon.com/CVE-2026-64371.html

https://explore.alas.aws.amazon.com/CVE-2026-64372.html

https://explore.alas.aws.amazon.com/CVE-2026-64373.html

https://explore.alas.aws.amazon.com/CVE-2026-64374.html

https://explore.alas.aws.amazon.com/CVE-2026-64375.html

https://explore.alas.aws.amazon.com/CVE-2026-64380.html

https://explore.alas.aws.amazon.com/CVE-2026-64381.html

https://explore.alas.aws.amazon.com/CVE-2026-64382.html

https://explore.alas.aws.amazon.com/CVE-2026-64383.html

https://explore.alas.aws.amazon.com/CVE-2026-64384.html

https://explore.alas.aws.amazon.com/CVE-2026-64385.html

https://explore.alas.aws.amazon.com/CVE-2026-64386.html

https://explore.alas.aws.amazon.com/CVE-2026-64387.html

https://explore.alas.aws.amazon.com/CVE-2026-64411.html

https://explore.alas.aws.amazon.com/CVE-2026-64412.html

https://explore.alas.aws.amazon.com/CVE-2026-64413.html

https://explore.alas.aws.amazon.com/CVE-2026-64414.html

https://explore.alas.aws.amazon.com/CVE-2026-64415.html

https://explore.alas.aws.amazon.com/CVE-2026-64416.html

https://explore.alas.aws.amazon.com/CVE-2026-64418.html

https://explore.alas.aws.amazon.com/CVE-2026-64422.html

https://explore.alas.aws.amazon.com/CVE-2026-64423.html

https://explore.alas.aws.amazon.com/CVE-2026-64425.html

https://explore.alas.aws.amazon.com/CVE-2026-64432.html

https://explore.alas.aws.amazon.com/CVE-2026-64435.html

https://explore.alas.aws.amazon.com/CVE-2026-64436.html

https://explore.alas.aws.amazon.com/CVE-2026-64448.html

https://explore.alas.aws.amazon.com/CVE-2026-64450.html

https://explore.alas.aws.amazon.com/CVE-2026-64456.html

https://explore.alas.aws.amazon.com/CVE-2026-64457.html

https://explore.alas.aws.amazon.com/CVE-2026-64458.html

https://explore.alas.aws.amazon.com/CVE-2026-64465.html

https://explore.alas.aws.amazon.com/CVE-2026-64472.html

https://explore.alas.aws.amazon.com/CVE-2026-64474.html

https://explore.alas.aws.amazon.com/CVE-2026-64475.html

https://explore.alas.aws.amazon.com/CVE-2026-64476.html

https://explore.alas.aws.amazon.com/CVE-2026-64507.html

https://explore.alas.aws.amazon.com/CVE-2026-64508.html

https://explore.alas.aws.amazon.com/CVE-2026-64512.html

https://explore.alas.aws.amazon.com/CVE-2026-64514.html

https://explore.alas.aws.amazon.com/CVE-2026-64530.html

https://explore.alas.aws.amazon.com/CVE-2026-64532.html

https://explore.alas.aws.amazon.com/CVE-2026-64533.html

https://explore.alas.aws.amazon.com/CVE-2026-64538.html

https://explore.alas.aws.amazon.com/CVE-2026-64542.html

https://explore.alas.aws.amazon.com/CVE-2026-64543.html

https://explore.alas.aws.amazon.com/CVE-2026-64544.html

https://explore.alas.aws.amazon.com/CVE-2026-64545.html

https://explore.alas.aws.amazon.com/CVE-2026-64546.html

https://explore.alas.aws.amazon.com/CVE-2026-64548.html

https://explore.alas.aws.amazon.com/CVE-2026-64551.html

https://explore.alas.aws.amazon.com/CVE-2026-64552.html

https://explore.alas.aws.amazon.com/CVE-2026-64553.html

https://explore.alas.aws.amazon.com/CVE-2026-64555.html

https://explore.alas.aws.amazon.com/CVE-2026-64556.html

https://explore.alas.aws.amazon.com/CVE-2026-64560.html

https://explore.alas.aws.amazon.com/CVE-2026-64561.html

https://explore.alas.aws.amazon.com/CVE-2026-64589.html

https://explore.alas.aws.amazon.com/CVE-2026-64593.html

https://explore.alas.aws.amazon.com/CVE-2026-64597.html

https://explore.alas.aws.amazon.com/CVE-2026-64598.html

https://explore.alas.aws.amazon.com/CVE-2026-64604.html

https://explore.alas.aws.amazon.com/CVE-2026-68086.html

https://explore.alas.aws.amazon.com/CVE-2026-68090.html

https://explore.alas.aws.amazon.com/CVE-2026-68092.html

https://explore.alas.aws.amazon.com/CVE-2026-68454.html

https://explore.alas.aws.amazon.com/CVE-2026-68461.html

https://explore.alas.aws.amazon.com/CVE-2026-68476.html

https://explore.alas.aws.amazon.com/CVE-2026-68477.html

https://explore.alas.aws.amazon.com/CVE-2026-72010.html

https://explore.alas.aws.amazon.com/CVE-2026-72012.html

https://explore.alas.aws.amazon.com/CVE-2026-72014.html

https://explore.alas.aws.amazon.com/CVE-2026-72020.html

https://explore.alas.aws.amazon.com/CVE-2026-72021.html

https://explore.alas.aws.amazon.com/CVE-2026-72027.html

https://explore.alas.aws.amazon.com/CVE-2026-72034.html

https://explore.alas.aws.amazon.com/CVE-2026-72035.html

https://explore.alas.aws.amazon.com/CVE-2026-72036.html

https://explore.alas.aws.amazon.com/CVE-2026-72041.html

https://explore.alas.aws.amazon.com/CVE-2026-72052.html

https://explore.alas.aws.amazon.com/CVE-2026-72053.html

https://explore.alas.aws.amazon.com/CVE-2026-72054.html

https://explore.alas.aws.amazon.com/CVE-2026-72055.html

https://explore.alas.aws.amazon.com/CVE-2026-72057.html

https://explore.alas.aws.amazon.com/CVE-2026-72061.html

https://explore.alas.aws.amazon.com/CVE-2026-72063.html

https://explore.alas.aws.amazon.com/CVE-2026-72066.html

https://explore.alas.aws.amazon.com/CVE-2026-72067.html

https://explore.alas.aws.amazon.com/CVE-2026-72068.html

https://explore.alas.aws.amazon.com/CVE-2026-72071.html

https://explore.alas.aws.amazon.com/CVE-2026-72072.html

https://explore.alas.aws.amazon.com/CVE-2026-72083.html

https://explore.alas.aws.amazon.com/CVE-2026-72084.html

https://explore.alas.aws.amazon.com/CVE-2026-72096.html

https://explore.alas.aws.amazon.com/CVE-2026-72097.html

https://explore.alas.aws.amazon.com/CVE-2026-72099.html

https://explore.alas.aws.amazon.com/CVE-2026-72100.html

https://explore.alas.aws.amazon.com/CVE-2026-72102.html

https://explore.alas.aws.amazon.com/CVE-2026-72105.html

https://explore.alas.aws.amazon.com/CVE-2026-72106.html

https://explore.alas.aws.amazon.com/CVE-2026-72108.html

https://explore.alas.aws.amazon.com/CVE-2026-72110.html

https://explore.alas.aws.amazon.com/CVE-2026-72120.html

https://explore.alas.aws.amazon.com/CVE-2026-72122.html

https://explore.alas.aws.amazon.com/CVE-2026-72123.html

https://explore.alas.aws.amazon.com/CVE-2026-72127.html

https://explore.alas.aws.amazon.com/CVE-2026-72132.html

https://explore.alas.aws.amazon.com/CVE-2026-72135.html

https://explore.alas.aws.amazon.com/CVE-2026-72136.html

https://explore.alas.aws.amazon.com/CVE-2026-72138.html

https://explore.alas.aws.amazon.com/CVE-2026-72151.html

https://explore.alas.aws.amazon.com/CVE-2026-72152.html

https://explore.alas.aws.amazon.com/CVE-2026-72155.html

https://explore.alas.aws.amazon.com/CVE-2026-72172.html

https://explore.alas.aws.amazon.com/CVE-2026-72174.html

https://explore.alas.aws.amazon.com/CVE-2026-72176.html

https://explore.alas.aws.amazon.com/CVE-2026-72177.html

https://explore.alas.aws.amazon.com/CVE-2026-72178.html

https://explore.alas.aws.amazon.com/CVE-2026-72191.html

https://explore.alas.aws.amazon.com/CVE-2026-72192.html

https://explore.alas.aws.amazon.com/CVE-2026-72193.html

https://explore.alas.aws.amazon.com/CVE-2026-72194.html

https://explore.alas.aws.amazon.com/CVE-2026-72195.html

https://explore.alas.aws.amazon.com/CVE-2026-72196.html

https://explore.alas.aws.amazon.com/CVE-2026-72197.html

https://explore.alas.aws.amazon.com/CVE-2026-72212.html

https://explore.alas.aws.amazon.com/CVE-2026-72217.html

https://explore.alas.aws.amazon.com/CVE-2026-72218.html

https://explore.alas.aws.amazon.com/CVE-2026-72219.html

https://explore.alas.aws.amazon.com/CVE-2026-72221.html

https://explore.alas.aws.amazon.com/CVE-2026-72222.html

https://explore.alas.aws.amazon.com/CVE-2026-72223.html

https://explore.alas.aws.amazon.com/CVE-2026-72224.html

https://explore.alas.aws.amazon.com/CVE-2026-72225.html

https://explore.alas.aws.amazon.com/CVE-2026-72227.html

https://explore.alas.aws.amazon.com/CVE-2026-72242.html

https://explore.alas.aws.amazon.com/CVE-2026-72243.html

https://explore.alas.aws.amazon.com/CVE-2026-72247.html

https://explore.alas.aws.amazon.com/CVE-2026-72250.html

https://explore.alas.aws.amazon.com/CVE-2026-72251.html

https://explore.alas.aws.amazon.com/CVE-2026-72252.html

https://explore.alas.aws.amazon.com/CVE-2026-72255.html

https://explore.alas.aws.amazon.com/CVE-2026-72256.html

https://explore.alas.aws.amazon.com/CVE-2026-72266.html

https://explore.alas.aws.amazon.com/CVE-2026-72273.html

https://explore.alas.aws.amazon.com/CVE-2026-72274.html

https://explore.alas.aws.amazon.com/CVE-2026-72275.html

https://explore.alas.aws.amazon.com/CVE-2026-72276.html

https://explore.alas.aws.amazon.com/CVE-2026-72280.html

https://explore.alas.aws.amazon.com/CVE-2026-72282.html

https://explore.alas.aws.amazon.com/CVE-2026-72284.html

https://explore.alas.aws.amazon.com/CVE-2026-72286.html

https://explore.alas.aws.amazon.com/CVE-2026-72289.html

https://explore.alas.aws.amazon.com/CVE-2026-72290.html

https://explore.alas.aws.amazon.com/CVE-2026-72296.html

https://explore.alas.aws.amazon.com/CVE-2026-72310.html

https://explore.alas.aws.amazon.com/CVE-2026-72317.html

https://explore.alas.aws.amazon.com/CVE-2026-72318.html

https://explore.alas.aws.amazon.com/CVE-2026-72319.html

https://explore.alas.aws.amazon.com/CVE-2026-72320.html

https://explore.alas.aws.amazon.com/CVE-2026-72322.html

https://explore.alas.aws.amazon.com/CVE-2026-72323.html

https://explore.alas.aws.amazon.com/CVE-2026-72325.html

https://explore.alas.aws.amazon.com/CVE-2026-72326.html

https://explore.alas.aws.amazon.com/CVE-2026-72330.html

https://explore.alas.aws.amazon.com/CVE-2026-72338.html

https://explore.alas.aws.amazon.com/CVE-2026-72342.html

https://explore.alas.aws.amazon.com/CVE-2026-72343.html

https://explore.alas.aws.amazon.com/CVE-2026-72347.html

https://explore.alas.aws.amazon.com/CVE-2026-72348.html

https://explore.alas.aws.amazon.com/CVE-2026-72349.html

https://explore.alas.aws.amazon.com/CVE-2026-72350.html

https://explore.alas.aws.amazon.com/CVE-2026-72351.html

https://explore.alas.aws.amazon.com/CVE-2026-72352.html

https://explore.alas.aws.amazon.com/CVE-2026-72356.html

https://explore.alas.aws.amazon.com/CVE-2026-72364.html

https://explore.alas.aws.amazon.com/CVE-2026-72379.html

https://explore.alas.aws.amazon.com/CVE-2026-72389.html

https://explore.alas.aws.amazon.com/CVE-2026-72390.html

https://explore.alas.aws.amazon.com/CVE-2026-72392.html

https://explore.alas.aws.amazon.com/CVE-2026-72400.html

https://explore.alas.aws.amazon.com/CVE-2026-72405.html

https://explore.alas.aws.amazon.com/CVE-2026-72416.html

https://explore.alas.aws.amazon.com/CVE-2026-72418.html

https://explore.alas.aws.amazon.com/CVE-2026-72419.html

https://explore.alas.aws.amazon.com/CVE-2026-72420.html

https://explore.alas.aws.amazon.com/CVE-2026-72421.html

https://explore.alas.aws.amazon.com/CVE-2026-72425.html

https://explore.alas.aws.amazon.com/CVE-2026-72427.html

https://explore.alas.aws.amazon.com/CVE-2026-72428.html

https://explore.alas.aws.amazon.com/CVE-2026-72433.html

https://explore.alas.aws.amazon.com/CVE-2026-72434.html

https://explore.alas.aws.amazon.com/CVE-2026-72435.html

https://explore.alas.aws.amazon.com/CVE-2026-72436.html

https://explore.alas.aws.amazon.com/CVE-2026-72437.html

https://explore.alas.aws.amazon.com/CVE-2026-72444.html

https://explore.alas.aws.amazon.com/CVE-2026-72447.html

https://explore.alas.aws.amazon.com/CVE-2026-72450.html

https://explore.alas.aws.amazon.com/CVE-2026-72451.html

https://explore.alas.aws.amazon.com/CVE-2026-72452.html

https://explore.alas.aws.amazon.com/CVE-2026-72466.html

https://explore.alas.aws.amazon.com/CVE-2026-72470.html

https://explore.alas.aws.amazon.com/CVE-2026-72472.html

https://explore.alas.aws.amazon.com/CVE-2026-72476.html

https://explore.alas.aws.amazon.com/CVE-2026-72478.html

https://explore.alas.aws.amazon.com/CVE-2026-72487.html

https://explore.alas.aws.amazon.com/CVE-2026-72502.html

https://explore.alas.aws.amazon.com/CVE-2026-74255.html

https://explore.alas.aws.amazon.com/CVE-2026-74256.html

https://explore.alas.aws.amazon.com/CVE-2026-74259.html

https://explore.alas.aws.amazon.com/CVE-2026-74262.html

https://explore.alas.aws.amazon.com/CVE-2026-74267.html

https://explore.alas.aws.amazon.com/CVE-2026-74270.html

https://explore.alas.aws.amazon.com/CVE-2026-74271.html

https://explore.alas.aws.amazon.com/CVE-2026-74281.html

https://explore.alas.aws.amazon.com/CVE-2026-74282.html

https://explore.alas.aws.amazon.com/CVE-2026-74283.html

https://explore.alas.aws.amazon.com/CVE-2026-74284.html

https://explore.alas.aws.amazon.com/CVE-2026-74286.html

https://explore.alas.aws.amazon.com/CVE-2026-74287.html

https://explore.alas.aws.amazon.com/CVE-2026-74288.html

https://explore.alas.aws.amazon.com/CVE-2026-74290.html

https://explore.alas.aws.amazon.com/CVE-2026-74296.html

https://explore.alas.aws.amazon.com/CVE-2026-74297.html

https://explore.alas.aws.amazon.com/CVE-2026-74305.html

https://explore.alas.aws.amazon.com/CVE-2026-74307.html

https://explore.alas.aws.amazon.com/CVE-2026-74308.html

https://explore.alas.aws.amazon.com/CVE-2026-74310.html

https://explore.alas.aws.amazon.com/CVE-2026-74316.html

https://explore.alas.aws.amazon.com/CVE-2026-74318.html

https://explore.alas.aws.amazon.com/CVE-2026-74321.html

https://explore.alas.aws.amazon.com/CVE-2026-74327.html

https://explore.alas.aws.amazon.com/CVE-2026-74329.html

https://explore.alas.aws.amazon.com/CVE-2026-74330.html

https://explore.alas.aws.amazon.com/CVE-2026-74331.html

https://explore.alas.aws.amazon.com/CVE-2026-74346.html

https://explore.alas.aws.amazon.com/CVE-2026-74356.html

https://explore.alas.aws.amazon.com/CVE-2026-74359.html

https://explore.alas.aws.amazon.com/CVE-2026-74363.html

https://explore.alas.aws.amazon.com/CVE-2026-74365.html

https://explore.alas.aws.amazon.com/CVE-2026-74376.html

https://explore.alas.aws.amazon.com/CVE-2026-74379.html

https://explore.alas.aws.amazon.com/CVE-2026-74380.html

https://explore.alas.aws.amazon.com/CVE-2026-74382.html

https://explore.alas.aws.amazon.com/CVE-2026-74384.html

https://explore.alas.aws.amazon.com/CVE-2026-74393.html

https://explore.alas.aws.amazon.com/CVE-2026-74395.html

https://explore.alas.aws.amazon.com/CVE-2026-74397.html

https://explore.alas.aws.amazon.com/CVE-2026-74398.html

https://explore.alas.aws.amazon.com/CVE-2026-74399.html

https://explore.alas.aws.amazon.com/CVE-2026-74406.html

https://explore.alas.aws.amazon.com/CVE-2026-74417.html

https://explore.alas.aws.amazon.com/CVE-2026-74424.html

https://explore.alas.aws.amazon.com/CVE-2026-74439.html

https://explore.alas.aws.amazon.com/CVE-2026-74578.html

https://explore.alas.aws.amazon.com/CVE-2026-80598.html

https://explore.alas.aws.amazon.com/CVE-2026-80602.html

https://explore.alas.aws.amazon.com/CVE-2026-80603.html

https://explore.alas.aws.amazon.com/CVE-2026-80604.html

https://explore.alas.aws.amazon.com/CVE-2026-80611.html

https://explore.alas.aws.amazon.com/CVE-2026-80613.html

https://explore.alas.aws.amazon.com/CVE-2026-80620.html

https://explore.alas.aws.amazon.com/CVE-2026-80630.html

https://explore.alas.aws.amazon.com/CVE-2026-80636.html

https://explore.alas.aws.amazon.com/CVE-2026-80637.html

https://explore.alas.aws.amazon.com/CVE-2026-80646.html

https://explore.alas.aws.amazon.com/CVE-2026-80664.html

https://explore.alas.aws.amazon.com/CVE-2026-80667.html

https://explore.alas.aws.amazon.com/CVE-2026-80669.html

https://explore.alas.aws.amazon.com/CVE-2026-80676.html

https://explore.alas.aws.amazon.com/CVE-2026-80677.html

https://explore.alas.aws.amazon.com/CVE-2026-80865.html

https://explore.alas.aws.amazon.com/CVE-2026-80867.html

https://explore.alas.aws.amazon.com/CVE-2026-80875.html

https://explore.alas.aws.amazon.com/CVE-2026-80876.html

https://explore.alas.aws.amazon.com/CVE-2026-80880.html

プラグインの詳細

深刻度: High

ID: 337239

ファイル名: al2023_ALAS2023-2026-2057.nasl

バージョン: 1.9

タイプ: Local

エージェント: unix

公開日: 2026/8/18

更新日: 2026/9/23

サポートされているセンサー: Agentless Assessment, Continuous Assessment, Frictionless Assessment Agent, Frictionless Assessment AWS, Nessus Agent, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

リスク情報

VPR

リスクファクター: High

スコア: 8

パーセンタイル: 99.68

CVSS v2

リスクファクター: Medium

基本値: 6.8

現状値: 5.6

ベクトル: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS スコアのソース: CVE-2026-64381

CVSS v3

リスクファクター: High

基本値: 7.8

現状値: 7.2

ベクトル: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

現状ベクトル: CVSS:3.0/E:F/RL:O/RC:C

脆弱性情報

CPE: cpe:/o:amazon:linux:2023, p-cpe:/a:amazon:linux:bpftool6.12-debuginfo, p-cpe:/a:amazon:linux:bpftool6.12, p-cpe:/a:amazon:linux:kernel-livepatch-6.12.100-125.179, p-cpe:/a:amazon:linux:kernel6.12-debuginfo-common-aarch64, p-cpe:/a:amazon:linux:kernel6.12-debuginfo-common-x86_64, p-cpe:/a:amazon:linux:kernel6.12-debuginfo, p-cpe:/a:amazon:linux:kernel6.12-devel, p-cpe:/a:amazon:linux:kernel6.12-headers, p-cpe:/a:amazon:linux:kernel6.12-modules-extra-common, p-cpe:/a:amazon:linux:kernel6.12-modules-extra, p-cpe:/a:amazon:linux:kernel6.12-tools-debuginfo, p-cpe:/a:amazon:linux:kernel6.12-tools-devel, p-cpe:/a:amazon:linux:kernel6.12-tools, p-cpe:/a:amazon:linux:kernel6.12, p-cpe:/a:amazon:linux:perf6.12-debuginfo, p-cpe:/a:amazon:linux:perf6.12, p-cpe:/a:amazon:linux:python3-perf6.12-debuginfo, p-cpe:/a:amazon:linux:python3-perf6.12

必要な KB アイテム: Host/local_checks_enabled, Host/AmazonLinux/release, Host/AmazonLinux/rpm-list

エクスプロイトが利用可能: true

エクスプロイトの容易さ: Exploits are available

パッチ公開日: 2026/8/17

脆弱性公開日: 2026/5/27

エクスプロイト可能

Core Impact

参照情報

CVE: CVE-2026-45944, CVE-2026-46093, CVE-2026-53005, CVE-2026-53027, CVE-2026-53365, CVE-2026-53392, CVE-2026-53402, CVE-2026-63970, CVE-2026-64024, CVE-2026-64077, CVE-2026-64187, CVE-2026-64189, CVE-2026-64192, CVE-2026-64227, CVE-2026-64265, CVE-2026-64266, CVE-2026-64279, CVE-2026-64284, CVE-2026-64286, CVE-2026-64287, CVE-2026-64294, CVE-2026-64296, CVE-2026-64298, CVE-2026-64299, CVE-2026-64306, CVE-2026-64312, CVE-2026-64313, CVE-2026-64317, CVE-2026-64322, CVE-2026-64323, CVE-2026-64324, CVE-2026-64326, CVE-2026-64352, CVE-2026-64354, CVE-2026-64355, CVE-2026-64357, CVE-2026-64364, CVE-2026-64368, CVE-2026-64370, CVE-2026-64371, CVE-2026-64372, CVE-2026-64373, CVE-2026-64374, CVE-2026-64375, CVE-2026-64380, CVE-2026-64381, CVE-2026-64382, CVE-2026-64383, CVE-2026-64384, CVE-2026-64385, CVE-2026-64386, CVE-2026-64387, CVE-2026-64411, CVE-2026-64412, CVE-2026-64413, CVE-2026-64414, CVE-2026-64415, CVE-2026-64416, CVE-2026-64418, CVE-2026-64422, CVE-2026-64423, CVE-2026-64425, CVE-2026-64432, CVE-2026-64435, CVE-2026-64436, CVE-2026-64448, CVE-2026-64450, CVE-2026-64456, CVE-2026-64457, CVE-2026-64458, CVE-2026-64465, CVE-2026-64472, CVE-2026-64474, CVE-2026-64475, CVE-2026-64476, CVE-2026-64507, CVE-2026-64508, CVE-2026-64512, CVE-2026-64514, CVE-2026-64530, CVE-2026-64532, CVE-2026-64533, CVE-2026-64538, CVE-2026-64542, CVE-2026-64543, CVE-2026-64544, CVE-2026-64545, CVE-2026-64546, CVE-2026-64548, CVE-2026-64551, CVE-2026-64552, CVE-2026-64553, CVE-2026-64555, CVE-2026-64556, CVE-2026-64560, CVE-2026-64561, CVE-2026-64589, CVE-2026-64593, CVE-2026-64597, CVE-2026-64598, CVE-2026-64604, CVE-2026-68086, CVE-2026-68090, CVE-2026-68092, CVE-2026-68454, CVE-2026-68461, CVE-2026-68476, CVE-2026-68477, CVE-2026-72010, CVE-2026-72012, CVE-2026-72014, CVE-2026-72020, CVE-2026-72021, CVE-2026-72027, CVE-2026-72034, CVE-2026-72035, CVE-2026-72036, CVE-2026-72041, CVE-2026-72052, CVE-2026-72053, CVE-2026-72054, CVE-2026-72055, CVE-2026-72057, CVE-2026-72061, CVE-2026-72063, CVE-2026-72066, CVE-2026-72067, CVE-2026-72068, CVE-2026-72071, CVE-2026-72072, CVE-2026-72083, CVE-2026-72084, CVE-2026-72096, CVE-2026-72097, CVE-2026-72099, CVE-2026-72100, CVE-2026-72102, CVE-2026-72105, CVE-2026-72106, CVE-2026-72108, CVE-2026-72110, CVE-2026-72120, CVE-2026-72122, CVE-2026-72123, CVE-2026-72127, CVE-2026-72132, CVE-2026-72135, CVE-2026-72136, CVE-2026-72138, CVE-2026-72151, CVE-2026-72152, CVE-2026-72155, CVE-2026-72172, CVE-2026-72174, CVE-2026-72176, CVE-2026-72177, CVE-2026-72178, CVE-2026-72191, CVE-2026-72192, CVE-2026-72193, CVE-2026-72194, CVE-2026-72195, CVE-2026-72196, CVE-2026-72197, CVE-2026-72212, CVE-2026-72217, CVE-2026-72218, CVE-2026-72219, CVE-2026-72221, CVE-2026-72222, CVE-2026-72223, CVE-2026-72224, CVE-2026-72225, CVE-2026-72227, CVE-2026-72242, CVE-2026-72243, CVE-2026-72247, CVE-2026-72250, CVE-2026-72251, CVE-2026-72252, CVE-2026-72255, CVE-2026-72256, CVE-2026-72266, CVE-2026-72273, CVE-2026-72274, CVE-2026-72275, CVE-2026-72276, CVE-2026-72280, CVE-2026-72282, CVE-2026-72284, CVE-2026-72286, CVE-2026-72289, CVE-2026-72290, CVE-2026-72296, CVE-2026-72310, CVE-2026-72317, CVE-2026-72318, CVE-2026-72319, CVE-2026-72320, CVE-2026-72322, CVE-2026-72323, CVE-2026-72325, CVE-2026-72326, CVE-2026-72330, CVE-2026-72338, CVE-2026-72342, CVE-2026-72343, CVE-2026-72347, CVE-2026-72348, CVE-2026-72349, CVE-2026-72350, CVE-2026-72351, CVE-2026-72352, CVE-2026-72356, CVE-2026-72364, CVE-2026-72379, CVE-2026-72389, CVE-2026-72390, CVE-2026-72392, CVE-2026-72400, CVE-2026-72405, CVE-2026-72416, CVE-2026-72418, CVE-2026-72419, CVE-2026-72420, CVE-2026-72421, CVE-2026-72425, CVE-2026-72427, CVE-2026-72428, CVE-2026-72433, CVE-2026-72434, CVE-2026-72435, CVE-2026-72436, CVE-2026-72437, CVE-2026-72444, CVE-2026-72447, CVE-2026-72450, CVE-2026-72451, CVE-2026-72452, CVE-2026-72466, CVE-2026-72470, CVE-2026-72472, CVE-2026-72476, CVE-2026-72478, CVE-2026-72487, CVE-2026-72502, CVE-2026-74255, CVE-2026-74256, CVE-2026-74259, CVE-2026-74262, CVE-2026-74267, CVE-2026-74270, CVE-2026-74271, CVE-2026-74281, CVE-2026-74282, CVE-2026-74283, CVE-2026-74284, CVE-2026-74286, CVE-2026-74287, CVE-2026-74288, CVE-2026-74290, CVE-2026-74296, CVE-2026-74297, CVE-2026-74305, CVE-2026-74307, CVE-2026-74308, CVE-2026-74310, CVE-2026-74316, CVE-2026-74318, CVE-2026-74321, CVE-2026-74327, CVE-2026-74329, CVE-2026-74330, CVE-2026-74331, CVE-2026-74346, CVE-2026-74356, CVE-2026-74359, CVE-2026-74363, CVE-2026-74365, CVE-2026-74376, CVE-2026-74379, CVE-2026-74380, CVE-2026-74382, CVE-2026-74384, CVE-2026-74393, CVE-2026-74395, CVE-2026-74397, CVE-2026-74398, CVE-2026-74399, CVE-2026-74406, CVE-2026-74417, CVE-2026-74424, CVE-2026-74439, CVE-2026-74578, CVE-2026-80598, CVE-2026-80602, CVE-2026-80603, CVE-2026-80604, CVE-2026-80611, CVE-2026-80613, CVE-2026-80620, CVE-2026-80630, CVE-2026-80636, CVE-2026-80637, CVE-2026-80646, CVE-2026-80664, CVE-2026-80667, CVE-2026-80669, CVE-2026-80676, CVE-2026-80677, CVE-2026-80865, CVE-2026-80867, CVE-2026-80875, CVE-2026-80876, CVE-2026-80880