Amazon Linux 2023 : bpftool6.18、kernel6.18、kernel6.18-devel (ALAS2023-2026-2071)

medium Nessus プラグイン ID 341880

概要

リモートの Amazon Linux 2023 ホストに、セキュリティ更新プログラムがありません。

説明

したがって、ALAS2023-2026-2071 のアドバイザリに記載されている複数の脆弱性の影響を受けます。

Linux カーネルで、以下の脆弱性が解決されています。

af_unix:SOCKMAP のすべての SCM 属性をドロップします。(CVE-2026-53005)

Linux カーネルで、以下の脆弱性が解決されています。

bpf:BPF LSM が初期化されていない場合、BPF_MAP_TYPE_INODE_STORAGE作成を拒否します

CONFIG_BPF_LSM=y が設定されている場合、BPF inode ストレージマップ(BPF_MAP_TYPE_INODE_STORAGE)がカーネルにコンパイルされます。ただし、BPF LSM が起動時に明示的に有効化されていない場合(例:lsm= boot パラメーターから省略)、BPF LSM に対して lsm_prepare() は実行されません。

その結果、BPF inodeセキュリティブロブオフセット(bpf_lsm_blob_sizes.lbs_inode)は初期化されず、予約された構造体rcu_head(通常は16バイト以上)を超えて有効なオフセットに更新されることなく、デフォルトのコンパイル後サイズ8バイトのままになります。

特権ユーザーがBPF_MAP_TYPE_INODE_STORAGEmapを作成して更新すると、bpf_inode() は inode->i_security + 8 を評価します。これは、inode >i_security blob の先頭で struct rcu_head.func コールバックポインターを誤ってエイリアスします。後続のマップ要素のクリーンアップまたは inode の破壊中に、owner_storageに NULL を書き込むと、queuedRCU コールバックポインターがクリアされます。rcu_do_batch()が後にキューコールバックを実行するとき、アドレス0x0で命令フェッチを試み、即時のカーネルパニックをトリガーします。

__ro_after_init でマークされたグローバルbpf_lsm_initializedブール値を導入することにより、これを修正します。LSM フレームワークが BPF LSM を正常に登録する際に、bpf_lsm_init() 内でこのフラグを true に設定します。このフラグの inode_storage_map_alloc() におけるゲートマッピング割り当て、BPF LSM が逆に初期化されていない場合は EOPNOTSUPP を返します。

このフェイルファストのアプローチにより、サポート BPF LSM インフラストラクチャがないときにユーザー空間が inodestorage マップを割り当てることを防ぎ、ゾンビマップ状態を回避します。(CVE-2026-64192)

Linux カーネルで、以下の脆弱性が解決されています。

ACPI:ドライバー:プローブ中に ACPI_COMPANION() を NULL に対してチェックします(CVE-2026-64227)

Linux カーネルで、以下の脆弱性が解決されています。

KVM:arm64:pKVM hyp vCPU をフラッシュする際のused_lrsがバインドされます(CVE-2026-64287)

Linux カーネルで、以下の脆弱性が解決されています。

bpf:スリータブル BPF プログラムからの LPM マップアクセスを許可します(CVE-2026-64352)

Linux カーネルで、以下の脆弱性が解決されています。

bpf:動的な内部配列検索を null 許容に保ちます(CVE-2026-64353)

Linux カーネルで、以下の脆弱性が解決されています。

proc:exec_update_lockで ptrace_may_access() を保護します(パート 1)(CVE-2026-64371)

Linux カーネルで、以下の脆弱性が解決されています。

proc:exec_update_lock で ptrace_may_access() を保護します(FD リンク)(CVE-2026-64375)

Linux カーネルで、以下の脆弱性が解決されています。

vfio/mlx5:racy ビットフィールドを修正し、構造体レイアウトを縮小します(CVE-2026-64472)

Linux カーネルで、以下の脆弱性が解決されています。

net/sched:cls_api:tcf_qevent_handle のTC_ACT_CONSUMED処理(CVE-2026-64530)

Linux カーネルで、以下の脆弱性が解決されています。

fs/ntfs3:UpdateRecordData{Root,Allocation} の NTFS_DE view.data_off がバインドされます(CVE-2026-64532)

Linux カーネルで、以下の脆弱性が解決されています。

fs/ntfs3:log_replay 変換でlcns_followを検証します(CVE-2026-64533)

Linux カーネルで、以下の脆弱性が解決されています。

ipv6:fib6_nh_mtu_change() の null-ptr-deref を修正します。(CVE-2026-64538)

Linux カーネルで、以下の脆弱性が解決されています。

ipv6:ndisc:accept_untracked_na() の NULL デリファレンスを修正します(CVE-2026-64542)

Linux カーネルで、以下の脆弱性が解決されています。

tipc:tipc_disc_rcv() におけるディスカバラーの use-after-free を修正します(CVE-2026-64543)

Linux カーネルで、以下の脆弱性が解決されています。

crypto:asymmetric_keys - pefile_digest_pe_contents における OOB 読み取りを修正します(CVE-2026-64544)

Linux カーネルで、以下の脆弱性が解決されています。

net、bpf:マスターが xdp_master_redirect() の NULL をチェックします(CVE-2026-64545)

Linux カーネルで、以下の脆弱性が解決されています。

drm/edid:drm_parse_tiled_block() での OOB 読み取りを修正します(CVE-2026-64546)

Linux カーネルで、以下の脆弱性が解決されています。

bpf、sockmap:bpf_msg_push_data() でオーバーフローするコピー + len を拒否します(CVE-2026-64548)

Linux カーネルで、以下の脆弱性が解決されています。

sctp:古くなったSTALE_COOKIE読み取る前に長さを検証します(CVE-2026-64551)

Linux カーネルで、以下の脆弱性が解決されています。

virtio-net:receive_big() の len チェックを修正します(CVE-2026-64552)

Linux カーネルで、以下の脆弱性が解決されています。

net:psample:PSAMPLE_ATTR_DATA での情報漏洩を修正します(CVE-2026-64553)

Linux カーネルで、以下の脆弱性が解決されています。

KVM:arm64:nv:kvm_hyp_handle_mops() での復元SPSR_EL2を修正します(CVE-2026-64555)

Linux カーネルで、以下の脆弱性が解決されています。

posix-cpu-timers:リーダー以外の exec() 競合による UAF を回避します(CVE-2026-64560)

Linux カーネルで、以下の脆弱性が解決されています。

KVM:x86:MMU ページを利用可能にした *後* の無効な/廃止されたルートをチェックします

shadow MMU で MMU ページを利用可能にした後、古いページフォールト(無効および/または廃止された root など)がないかチェックします。シャドウページの再要求によって使用中のルートが破壊される場合、つまり無効としてマークされる場合、KVM はメモリを無効なルートにマッピングしようとします。無効なルートに入力することはそれ自体では問題ありませんが、子シャドウページは親のロールを継承するため、map/fetch 中に作成された子は無効なページとして作成され、無効なページがアクティブな MMU ページのリストに決して載らないという KVM の不変性に違反します。

注意:KVMが2008年に初めて無効なルートの追跡を開始して以来(コミット2e53d63acba7、KVM: MMU:zapped rootpagetablesを無視)、本当の悪さは2020年(Linux 5.9)にのみ現れました。無効なシャドーページはアクティブページのリストに入れることができないという不変性がありました。

#2、子シャドーページの作成時に role.invalid を継承することも理想的とは程遠いことに、この欠陥は別途対処されることに、注意してください。(CVE-2026-64561)

Linux カーネルで、以下の脆弱性が解決されています。

KVM:nVMX:ネスト化された VM-Enter が無効なゲスト状態により失敗した場合に、vmcs12 ページを配置します(CVE-2026-68081)

Linux カーネルで、以下の脆弱性が解決されています。

binder:リリースがゼロになる前に secctx サイズをキャッシュします(CVE-2026-68458)

Linux カーネルで、以下の脆弱性が解決されています。

ipvs:ヘッドの再割り当て後に IP ヘッダーをリロードします(CVE-2026-68476)

Linux カーネルで、以下の脆弱性が解決されています。

ipvs:間違っている ipv6 トランスポートオフセットのあるより多くの場所を修正します(CVE-2026-68477)

Linux カーネルで、以下の脆弱性が解決されています。

net/mlx5:最終的な dealloc でのmlx5_st_idx_data解放(CVE-2026-72006)

Linux カーネルで、以下の脆弱性が解決されています。

cgroup/cpuset:mm mempolicy を mems_allowed ではなく effective_mems に再バインドします(CVE-2026-72010)

Linux カーネルで、以下の脆弱性が解決されています。

tracing/osnoise:登録解除時に synchronize_rcu() を呼び出します(CVE-2026-72012)

Linux カーネルで、以下の脆弱性が解決されています。

drbd:範囲外のペイロードサイズのデータ応答を拒否します(CVE-2026-72014)

Linux カーネルで、以下の脆弱性が解決されています。

cpu/hotplug:cpuhp_smt_enable() の NULL kobject 警告を修正します(CVE-2026-72016)

Linux カーネルで、以下の脆弱性が解決されています。

ipvs:ip_vs_conn_new の完全な ip_vs_seq 構造体をリセットします(CVE-2026-72020)

Linux カーネルで、以下の脆弱性が解決されています。

ipvs:SCTP 状態検索で解析済みのトランスポートオフセットを使用します(CVE-2026-72021)

Linux カーネルで、以下の脆弱性が解決されています。

mm/compaction:compaction_free() で free_pages_prepare() を適切に処理します(CVE-2026-72027)

Linux カーネルで、以下の脆弱性が解決されています。

net/mlx5:HWS、サイズ変更ターゲットのセットアップ失敗時の matcher 漏洩を修正します(CVE-2026-72032)

Linux カーネルで、以下の脆弱性が解決されています。

fhandle:capable_wrt_mount() で取り外したマウントを拒否します(CVE-2026-72034)

Linux カーネルで、以下の脆弱性が解決されています。

net/sched:sch_taprio:直接 dequeue 呼び出しをピークおよび qdisc_dequeue_peeked で置換(CVE-2026-72035)

Linux カーネルで、以下の脆弱性が解決されています。

net/sched:sch_multiq:直接 dequeue 呼び出しをピークおよび qdisc_dequeue_peeked で置換(CVE-2026-72036)

Linux カーネルで、以下の脆弱性が解決されています。

ipmi:i_ipmi_request() での refcount 漏洩を修正します(CVE-2026-72040)

Linux カーネルで、以下の脆弱性が解決されています。

espintcp:sk_msg_free_partialを使用して、部分送信を修正します(CVE-2026-72041)

Linux カーネルで、以下の脆弱性が解決されています。

ipmi:イベント配信におけるユーザー refcount アンダーフローを修正します(CVE-2026-72042)

Linux カーネルで、以下の脆弱性が解決されています。

net:ip6_tunnel:changelink 用のデバイス netns に CAP_NET_ADMIN が必要です(CVE-2026-72051)

Linux カーネルで、以下の脆弱性が解決されています。

net:ip6_gre:changelink 用のデバイス netns に CAP_NET_ADMIN が必要です(CVE-2026-72052)

Linux カーネルで、以下の脆弱性が解決されています。

net:ipip:changelink 用のデバイス netns で CAP_NET_ADMIN が必要です(CVE-2026-72053)

Linux カーネルで、以下の脆弱性が解決されています。

net:ip_vti:changelink 用のデバイス netns に CAP_NET_ADMIN が必要です(CVE-2026-72054)

Linux カーネルで、以下の脆弱性が解決されています。

net:ip6_vti:changelink 用のデバイス netns で CAP_NET_ADMIN が必要です(CVE-2026-72055)

Linux カーネルで、以下の脆弱性が解決されています。

net/sched:act_ct:デフラグ全体でtc_skb_cbを維持します(CVE-2026-72057)

Linux カーネルで、以下の脆弱性が解決されています。

net:sit:changelink 用のデバイス netns で CAP_NET_ADMIN が必要です(CVE-2026-72061)

Linux カーネルで、以下の脆弱性が解決されています。

gpio:tegra:GPIO ディレクションに対して pinctrl を呼び出しません(CVE-2026-72063)

Linux カーネルで、以下の脆弱性が解決されています。

cpu:hotplug:バインドされたホットプラグ状態 sysfs 出力(CVE-2026-72066)

Linux カーネルで、以下の脆弱性が解決されています。

cpu:hotplug:インスタンスごとのコールバックエラーを保存します(CVE-2026-72067)

Linux カーネルで、以下の脆弱性が解決されています。

posix-cpu-timers:update_rlimit_cpu() で u64 乗算を使用します(CVE-2026-72068)

Linux カーネルで、以下の脆弱性が解決されています。

tracing/user_events:user_event_mm_dup() における use-after-free を修正します(CVE-2026-72071)

Linux カーネルで、以下の脆弱性が解決されています。

net/mlx5e:macsec:RX SC 削除の metadata_dst の use-after-free を修正します(CVE-2026-72072)

Linux カーネルで、以下の脆弱性が解決されています。

scsi:target:core:REGISTER AND MOVE の iSCSI ISID use-after-free を修正します(CVE-2026-72083)

Linux カーネルで、以下の脆弱性が解決されています。

scsi:target:受信したバッファへの PR-OUT TransportID 解析をバインドします(CVE-2026-72084)

Linux カーネルで、以下の脆弱性が解決されています。

dma-fence:dma_fence_dedup_array() を 0 カウント入力に対して堅牢にします(CVE-2026-72095)

Linux カーネルで、以下の脆弱性が解決されています。

dm-verity:エラーカウンターをアトミックにします(CVE-2026-72096)

Linux カーネルで、以下の脆弱性が解決されています。

dm-verity:潜在的な NULL ポインターデリファレンスを修正します(CVE-2026-72097)

Linux カーネルで、以下の脆弱性が解決されています。

dm-integrity:hash_offset を 2 回増分しません(CVE-2026-72099)

Linux カーネルで、以下の脆弱性が解決されています。

dm-integrity:bio が制限外の場合のバグを修正します(CVE-2026-72100)

Linux カーネルで、以下の脆弱性が解決されています。

dm-integrity:初期化されていないカーネルメモリの漏洩を修正します(CVE-2026-72101)

Linux カーネルで、以下の脆弱性が解決されています。

dm_early_create:dm_resume 失敗時の使用済みテーブル解放を修正します(CVE-2026-72102)

Linux カーネルで、以下の脆弱性が解決されています。

dm-log:32 ビットマシンのbitset_sizeオーバーフローを修正します(CVE-2026-72105)

Linux カーネルで、以下の脆弱性が解決されています。

dm-ioctl:list_version_get_info の潜在的なオーバーフローを修正します(CVE-2026-72106)

Linux カーネルで、以下の脆弱性が解決されています。

dm thin metadata:コミット失敗時のメタデータスナップショットの一貫性を修正します(CVE-2026-72108)

Linux カーネルで、以下の脆弱性が解決されています。

bpf、fork:それにアクセスする救済の前に ->bpf_storage をワイプします(CVE-2026-72110)

Linux カーネルで、以下の脆弱性が解決されています。

bpf:check_mem_access() の retval 範囲を狭める前にレジスタ境界をリセットします(CVE-2026-72111)

Linux カーネルで、以下の脆弱性が解決されています。

CAN:BCM:欠落している RCU リストの注釈と操作を追加します(CVE-2026-72120)

Linux カーネルで、以下の脆弱性が解決されています。

can:bcm:作業キューへの割り当て解除rx_op延期し、thrtimer UAF を修正します(CVE-2026-72123)

Linux カーネルで、以下の脆弱性が解決されています。

netdev-genl:呼び出し側の pid 名前空間の NAPI スレッド PID を報告します(CVE-2026-72127)

Linux カーネルで、以下の脆弱性が解決されています。

NFS:フォリオサイズではなくリクエストサイズで不安定な書き込みを課金します(CVE-2026-72132)

Linux カーネルで、以下の脆弱性が解決されています。

xfrm:xfrm_interface:changelink 用のデバイス netns で CAP_NET_ADMIN が必要です(CVE-2026-72136)

Linux カーネルで、以下の脆弱性が解決されています。

xfrm:nat_keepalive:送信エラーの二重解放を回避します(CVE-2026-72137)

Linux カーネルで、以下の脆弱性が解決されています。

xen/gntdev:ioctl でのエラー処理を修正します(CVE-2026-72138)

Linux カーネルで、以下の脆弱性が解決されています。

tcp:tcp_connect md5sig_info RCU 猶予期間を超えて kfree を延期します(CVE-2026-72139)

Linux カーネルで、以下の脆弱性が解決されています。

sunrpc:初期化されていない xprt_create_args 構造を修正します(CVE-2026-72150)

Linux カーネルで、以下の脆弱性が解決されています。

tpm:tpm2-sessions:tpm_buf_append_salt での非同期 KPP 完了を待ちます(CVE-2026-72151)

Linux カーネルで、以下の脆弱性が解決されています。

tpm:tpm_tis_spi:wait_for_tmp_stat() で wait_woken() を使用します(CVE-2026-72152)

Linux カーネルで、以下の脆弱性が解決されています。

mtd:spi-nor:swp:ユーザーエクスペリエンスのロックを改善します(CVE-2026-72155)

Linux カーネルで、以下の脆弱性が解決されています。

mm/mm_init:ZONE_DEVICE 用の初期化されていない構造体ページを修正します(CVE-2026-72172)

Linux カーネルで、以下の脆弱性が解決されています。

fs/proc/task_mmu:pagemap_scan_pte_hole() における hugetlb セルフデッドロックを修正します(CVE-2026-72174)

Linux カーネルで、以下の脆弱性が解決されています。

mm/damon/sysfs-schemes:scheme_add_dirs() 内部エラーに対する統計を配置します(CVE-2026-72176)

Linux カーネルで、以下の脆弱性が解決されています。

mm/damon/sysfs-schemes:dir が access_pattern_add_dirs() で注文を渡すのを修正します(CVE-2026-72177)

Linux カーネルで、以下の脆弱性が解決されています。

mm/damon/core:正常にコミットされていないターゲット pid を常に配置します(CVE-2026-72178)

Linux カーネルで、以下の脆弱性が解決されています。

landlock:SIGIO パスでのLANDLOCK_SCOPE_SIGNALバイパスを修正します(CVE-2026-72183)

Linux カーネルで、以下の脆弱性が解決されています。

ntfs3:indx_insert_into_buffer のスプリットポイントオフセットを検証します(CVE-2026-72191)

Linux カーネルで、以下の脆弱性が解決されています。

ntfs3:hdr_insert_head前の indx_insert_into_root におけるバインドto_move(CVE-2026-72192)

Linux カーネルで、以下の脆弱性が解決されています。

ntfs3:rt->used でフリーチェーンウォーカー RESTART_TABLEキャップします(CVE-2026-72193)

Linux カーネルで、以下の脆弱性が解決されています。

fs/ntfs3:indx_find_buffer に深さ制限を追加して、スタックオーバーフローを防ぎます(CVE-2026-72194)

Linux カーネルで、以下の脆弱性が解決されています。

fs/ntfs3:data_offに対する UpdateResidentValue の attr_off をバインドします(CVE-2026-72195)

Linux カーネルで、以下の脆弱性が解決されています。

fs/ntfs3:分析パスにおける DP->page_lcns[] インデックスcopy_lcnsバインド(CVE-2026-72196)

Linux カーネルで、以下の脆弱性が解決されています。

fs/ntfs3:バインドされた DeleteIndexEntryAllocation memmove の長さ(CVE-2026-72197)

Linux カーネルで、以下の脆弱性が解決されています。

mm/memory_hotplug:エラーパスでの不適切な altmap の受け渡しを修正します(CVE-2026-72212)

Linux カーネルで、以下の脆弱性が解決されています。

mm/hugetlb:hugetlb cgroup rsvd の充電/充電解除の不一致を修正します(CVE-2026-72213)

Linux カーネルで、以下の脆弱性が解決されています。

SUNRPC:書き込み前の xdr_buf_to_bvec() ストアの境界チェック(CVE-2026-72217)

Linux カーネルで、以下の脆弱性が解決されています。

lockd:キャッシュされた nlm_do_fopen() の失敗時に refcount 漏洩nlm_fileプラグを補います(CVE-2026-72218)

Linux カーネルで、以下の脆弱性が解決されています。

lockd:nlm_do_fopen() が失敗する際にnlm_file漏洩を塞ぎます(CVE-2026-72219)

Linux カーネルで、以下の脆弱性が解決されています。

sunrpc:rq_procinfo ライフサイクルを強化して、二重解放(CVE-2026-72220)を防止します

Linux カーネルで、以下の脆弱性が解決されています。

sunrpc:キャンセルで競合に負けた場合、インフライトの TLS ハンドシェイクコールバックを待ちます(CVE-2026-72221)

Linux カーネルで、以下の脆弱性が解決されています。

sunrpc:非同期 TLS ハンドシェイクコールバック全体にsvc_xprtを固定します(CVE-2026-72222)

Linux カーネルで、以下の脆弱性が解決されています。

nvdimm/btt:discover_arenas() エラーパスでの解放アリーナサブ割り当て(CVE-2026-72223)

Linux カーネルで、以下の脆弱性が解決されています。

nvdimm/btt:btt_init() エラーパス上の無料のアリーナ(CVE-2026-72224)

Linux カーネルで、以下の脆弱性が解決されています。

jbd2:jbd2_journal_initialize_fast_commit() での整数アンダーフローを修正します(CVE-2026-72225)

Linux カーネルで、以下の脆弱性が解決されています。

batman-adv:mcast:num_dests ヘッダーの OOB 読み取りを回避します(CVE-2026-72227)

Linux カーネルで、以下の脆弱性が解決されています。

selinux:selinux_sctp_bind_connect() での sk_socket 逆参照を回避します(CVE-2026-72242)

Linux カーネルで、以下の脆弱性が解決されています。

selinux:TCP Fast Open(CVE-2026-72243)で接続関連の権限をチェックします

Linux カーネルで、以下の脆弱性が解決されています。

netfilter:nf_conncount:tuple dedup でのゾーン比較を修正します(CVE-2026-72247)

Linux カーネルで、以下の脆弱性が解決されています。

netfilter:nf_conntrack_reasm:IPv6 デフラグ後のガードmac_header調整(CVE-2026-72250)

Linux カーネルで、以下の脆弱性が解決されています。

netfilter:nf_nat_sip:古いデータポインターの可能性があるリロード(CVE-2026-72251)

Linux カーネルで、以下の脆弱性が解決されています。

netfilter:nft_set_pipapo:不良クローンを将来のトランザクションに漏洩しません(CVE-2026-72252)

Linux カーネルで、以下の脆弱性が解決されています。

netfilter:nf_queue:NFQUEUE が偽造の dst を保持している間にブリッジデバイスを固定します(CVE-2026-72255)

Linux カーネルで、以下の脆弱性が解決されています。

netfilter:xt_cluster:ハッシュマッチでテンプレート conntrack を拒否します(CVE-2026-72256)

Linux カーネルで、以下の脆弱性が解決されています。

fbdev:vesafb:vesafb_probe() でのメモリ漏洩を修正します(CVE-2026-72266)

Linux カーネルで、以下の脆弱性が解決されています。

fbdev:efifb:efifb_probe() でのメモリ漏洩を修正します(CVE-2026-72273)

Linux カーネルで、以下の脆弱性が解決されています。

fbdev:hecubafb:hecubafb_probe() でのメモリ漏洩の可能性を修正します(CVE-2026-72274)

Linux カーネルで、以下の脆弱性が解決されています。

fbdev:broadsheetfb:broadsheetfb_probe() でのメモリ漏洩の可能性を修正します(CVE-2026-72275)

Linux カーネルで、以下の脆弱性が解決されています。

fbdev:metronomefb:metronomefb_probe() でのメモリ漏洩の可能性を修正します(CVE-2026-72276)

Linux カーネルで、以下の脆弱性が解決されています。

KVM:arm64:nv:ゲスト VNCR が正常なメモリでない場合、SEA を注入します(CVE-2026-72277)

Linux カーネルで、以下の脆弱性が解決されています。

KVM:arm64:nv:中止を注入する前に VNCR を再変換します(CVE-2026-72278)

Linux カーネルで、以下の脆弱性が解決されています。

KVM:arm64:nv:L1 VNCR をマッピングする際に読み取り専用 PFN を尊重します(CVE-2026-72279)

Linux カーネルで、以下の脆弱性が解決されています。

KVM:arm64:nv:ZCR_EL2 への書き込みのための偽造 WARN をドロップします(CVE-2026-72280)

Linux カーネルで、以下の脆弱性が解決されています。

KVM:kvm_io_bus_get_dev() ロック責任を呼び出し元に移動します(CVE-2026-72282)

Linux カーネルで、以下の脆弱性が解決されています。

KVM:x86:バイパス用の IRTE の更新が失敗する場合、irqfd->producer を無効化(CVE-2026-72283)

Linux カーネルで、以下の脆弱性が解決されています。

KVM:x86:vCPU がその後 PV EOI を無効にしている場合は、保留中の PV EOI を無視します(CVE-2026-72284)

Linux カーネルで、以下の脆弱性が解決されています。

KVM:SEV:SNP VM のホスト内移行/ミラーリングを許可しません(CVE-2026-72286)

Linux カーネルで、以下の脆弱性が解決されています。

KVM:arm64:vgic:割り込みアフィニティの変更と LPI 無効の間の競合を処理します(CVE-2026-72288)

Linux カーネルで、以下の脆弱性が解決されています。

KVM:arm64:vgic:割り込みを移行する前に、割り込みがまだ私たちのものであることを確認します(CVE-2026-72289)

Linux カーネルで、以下の脆弱性が解決されています。

KVM:s390:pci:AIF 有効エラーの GISC refcount 漏洩を修正します(CVE-2026-72290)

Linux カーネルで、以下の脆弱性が解決されています。

net:ife:ETH_HLEN を ife_decode() でプル可能にする必要があります(CVE-2026-72296)

Linux カーネルで、以下の脆弱性が解決されています。

tipc:enqueue tracepoints のソケットキューダンプを制限します(CVE-2026-72299)

Linux カーネルで、以下の脆弱性が解決されています。

smb:client:パススルー ioctl 境界チェックのオーバーフローを修正します(CVE-2026-72310)

Linux カーネルで、以下の脆弱性が解決されています。

SUNRPC:TLS connect_worker全体に上部rpc_clntを固定します(CVE-2026-72317)

Linux カーネルで、以下の脆弱性が解決されています。

cifs:DFS 参照文字列のオフセットを検証します(CVE-2026-72318)

Linux カーネルで、以下の脆弱性が解決されています。

ipvs:ICMP エラーの内部ヘッダーがヘッドルーム内にあることを確認します(CVE-2026-72319)

Linux カーネルで、以下の脆弱性が解決されています。

netfilter:nft_lookup:反転検索での catchall 要素の処理を修正します(CVE-2026-72320)

Linux カーネルで、以下の脆弱性が解決されています。

ipv4:igmp:igmp_mod_timer() および igmp_stop_timer() のメモリリークの可能性を修正します(CVE-2026-72321)

Linux カーネルで、以下の脆弱性が解決されています。

ipv6:mcast:MLD 遅延作業の UAF の可能性を修正(CVE-2026-72322)

Linux カーネルで、以下の脆弱性が解決されています。

ipv4:igmp:igmp_gq_start_timer() の UAF の可能性を修正します(CVE-2026-72323)

Linux カーネルで、以下の脆弱性が解決されています。

perf/x86/amd/core:SVM リロードパスから BRS を有効にすることを回避します(CVE-2026-72325)

Linux カーネルで、以下の脆弱性が解決されています。

net/sched:cake:長さがアンダーフローするオーバーヘッド値を拒否します(CVE-2026-72326)

Linux カーネルで、以下の脆弱性が解決されています。

net/tls:tls_sw_read_sock() の空のデータレコードを消費します(CVE-2026-72330)

Linux カーネルで、以下の脆弱性が解決されています。

net/sched:act_pedit:tc オフロードの TOCTOU ヒープ OOB 書き込みを修正します(CVE-2026-72338)

Linux カーネルで、以下の脆弱性が解決されています。

net/mlx5e:priv->channel_stats[] のパブリケーション競合を修正します(CVE-2026-72341)

Linux カーネルで、以下の脆弱性が解決されています。

net/mlx5e:HV VHCA 統計エージェント登録競合を修正(CVE-2026-72342)

Linux カーネルで、以下の脆弱性が解決されています。

net/mlx5e:HV VHCA 統計のゼロサイズバッファ割り当てを修正します(CVE-2026-72343)

Linux カーネルで、以下の脆弱性が解決されています。

netfilter:xt_connmark:無効なシフトパラメーターを拒否します(CVE-2026-72347)

Linux カーネルで、以下の脆弱性が解決されています。

netfilter:ip6tables:ホットドロップ用に無効な形式の IPv6 拡張ヘッダーをマークします(CVE-2026-72348)

Linux カーネルで、以下の脆弱性が解決されています。

netfilter:xt_rateest:xt_rateest_mt() の u64 切り捨てを修正します(CVE-2026-72349)

Linux カーネルで、以下の脆弱性が解決されています。

netfilter:xt_u32:無効なシフトカウントを拒否します(CVE-2026-72350)

Linux カーネルで、以下の脆弱性が解決されています。

gue:REMCSUM プライベートオプションの長さを検証します(CVE-2026-72351)

Linux カーネルで、以下の脆弱性が解決されています。

HID:bpf:hid_bpf_get_data() 範囲チェックを修正します(CVE-2026-72352)

Linux カーネルで、以下の脆弱性が解決されています。

cifs:cifs_issue_read() の失敗時にクレジットリリースがないのを修正します(CVE-2026-72356)

Linux カーネルで、以下の脆弱性が解決されています。

uprobes/x86:__in_uprobe_trampolineで適切なmm_structを使用します(CVE-2026-72357)

Linux カーネルで、以下の脆弱性が解決されています。

netfs:writeback 反復中の ENOMEM 後のフォリオ状態を修正します(CVE-2026-72363)

Linux カーネルで、以下の脆弱性が解決されています。

netfs:書き戻しエラー処理を修正します(CVE-2026-72364)

Linux カーネルで、以下の脆弱性が解決されています。

netfs:コレクションオフロードを使用するためのライトスルーを修正します(CVE-2026-72365)

Linux カーネルで、以下の脆弱性が解決されています。

netfs:非同期キャッシュオブジェクト作成を処理するために netfs_create_write_req() を修正します(CVE-2026-72366)

Linux カーネルで、以下の脆弱性が解決されています。

iomap:EOF トリムio_size同時切り捨てアンダーフローから保護します(CVE-2026-72367)

Linux カーネルで、以下の脆弱性が解決されています。

afs:再初期化を修正 o ...

注意: この説明は、長さの関係上省略されています。詳細については、ベンダーのアドバイザリを参照してください。

Tenable は、前述の記述ブロックをテスト済み製品のセキュリティアドバイザリから直接抽出しています。

Nessus はこれらの問題をテストしておらず、代わりにアプリケーションが自己報告するバージョン番号にのみ依存していることに注意してください。

ソリューション

「dnf update kernel6.18 --releasever 2023.12.20260831」または「dnf update --advisory ALAS2023-2026-2071 --releasever 2023.12.20260831」を実行してシステムを更新してください。

参考資料

https://alas.aws.amazon.com//AL2023/ALAS2023-2026-2071.html

https://alas.aws.amazon.com/faqs.html

https://explore.alas.aws.amazon.com/CVE-2026-53005.html

https://explore.alas.aws.amazon.com/CVE-2026-64192.html

https://explore.alas.aws.amazon.com/CVE-2026-64227.html

https://explore.alas.aws.amazon.com/CVE-2026-64287.html

https://explore.alas.aws.amazon.com/CVE-2026-64352.html

https://explore.alas.aws.amazon.com/CVE-2026-64353.html

https://explore.alas.aws.amazon.com/CVE-2026-64371.html

https://explore.alas.aws.amazon.com/CVE-2026-64375.html

https://explore.alas.aws.amazon.com/CVE-2026-64472.html

https://explore.alas.aws.amazon.com/CVE-2026-64530.html

https://explore.alas.aws.amazon.com/CVE-2026-64532.html

https://explore.alas.aws.amazon.com/CVE-2026-64533.html

https://explore.alas.aws.amazon.com/CVE-2026-64538.html

https://explore.alas.aws.amazon.com/CVE-2026-64542.html

https://explore.alas.aws.amazon.com/CVE-2026-64543.html

https://explore.alas.aws.amazon.com/CVE-2026-64544.html

https://explore.alas.aws.amazon.com/CVE-2026-64545.html

https://explore.alas.aws.amazon.com/CVE-2026-64546.html

https://explore.alas.aws.amazon.com/CVE-2026-64548.html

https://explore.alas.aws.amazon.com/CVE-2026-64551.html

https://explore.alas.aws.amazon.com/CVE-2026-64552.html

https://explore.alas.aws.amazon.com/CVE-2026-64553.html

https://explore.alas.aws.amazon.com/CVE-2026-64555.html

https://explore.alas.aws.amazon.com/CVE-2026-64560.html

https://explore.alas.aws.amazon.com/CVE-2026-64561.html

https://explore.alas.aws.amazon.com/CVE-2026-68081.html

https://explore.alas.aws.amazon.com/CVE-2026-68458.html

https://explore.alas.aws.amazon.com/CVE-2026-68476.html

https://explore.alas.aws.amazon.com/CVE-2026-68477.html

https://explore.alas.aws.amazon.com/CVE-2026-72006.html

https://explore.alas.aws.amazon.com/CVE-2026-72010.html

https://explore.alas.aws.amazon.com/CVE-2026-72012.html

https://explore.alas.aws.amazon.com/CVE-2026-72014.html

https://explore.alas.aws.amazon.com/CVE-2026-72016.html

https://explore.alas.aws.amazon.com/CVE-2026-72020.html

https://explore.alas.aws.amazon.com/CVE-2026-72021.html

https://explore.alas.aws.amazon.com/CVE-2026-72027.html

https://explore.alas.aws.amazon.com/CVE-2026-72032.html

https://explore.alas.aws.amazon.com/CVE-2026-72034.html

https://explore.alas.aws.amazon.com/CVE-2026-72035.html

https://explore.alas.aws.amazon.com/CVE-2026-72036.html

https://explore.alas.aws.amazon.com/CVE-2026-72040.html

https://explore.alas.aws.amazon.com/CVE-2026-72041.html

https://explore.alas.aws.amazon.com/CVE-2026-72042.html

https://explore.alas.aws.amazon.com/CVE-2026-72051.html

https://explore.alas.aws.amazon.com/CVE-2026-72052.html

https://explore.alas.aws.amazon.com/CVE-2026-72053.html

https://explore.alas.aws.amazon.com/CVE-2026-72054.html

https://explore.alas.aws.amazon.com/CVE-2026-72055.html

https://explore.alas.aws.amazon.com/CVE-2026-72057.html

https://explore.alas.aws.amazon.com/CVE-2026-72061.html

https://explore.alas.aws.amazon.com/CVE-2026-72063.html

https://explore.alas.aws.amazon.com/CVE-2026-72066.html

https://explore.alas.aws.amazon.com/CVE-2026-72067.html

https://explore.alas.aws.amazon.com/CVE-2026-72068.html

https://explore.alas.aws.amazon.com/CVE-2026-72071.html

https://explore.alas.aws.amazon.com/CVE-2026-72072.html

https://explore.alas.aws.amazon.com/CVE-2026-72083.html

https://explore.alas.aws.amazon.com/CVE-2026-72084.html

https://explore.alas.aws.amazon.com/CVE-2026-72095.html

https://explore.alas.aws.amazon.com/CVE-2026-72096.html

https://explore.alas.aws.amazon.com/CVE-2026-72097.html

https://explore.alas.aws.amazon.com/CVE-2026-72099.html

https://explore.alas.aws.amazon.com/CVE-2026-72100.html

https://explore.alas.aws.amazon.com/CVE-2026-72101.html

https://explore.alas.aws.amazon.com/CVE-2026-72102.html

https://explore.alas.aws.amazon.com/CVE-2026-72105.html

https://explore.alas.aws.amazon.com/CVE-2026-72106.html

https://explore.alas.aws.amazon.com/CVE-2026-72108.html

https://explore.alas.aws.amazon.com/CVE-2026-72110.html

https://explore.alas.aws.amazon.com/CVE-2026-72111.html

https://explore.alas.aws.amazon.com/CVE-2026-72120.html

https://explore.alas.aws.amazon.com/CVE-2026-72122.html

https://explore.alas.aws.amazon.com/CVE-2026-72123.html

https://explore.alas.aws.amazon.com/CVE-2026-72127.html

https://explore.alas.aws.amazon.com/CVE-2026-72132.html

https://explore.alas.aws.amazon.com/CVE-2026-72135.html

https://explore.alas.aws.amazon.com/CVE-2026-72136.html

https://explore.alas.aws.amazon.com/CVE-2026-72137.html

https://explore.alas.aws.amazon.com/CVE-2026-72138.html

https://explore.alas.aws.amazon.com/CVE-2026-72139.html

https://explore.alas.aws.amazon.com/CVE-2026-72150.html

https://explore.alas.aws.amazon.com/CVE-2026-72151.html

https://explore.alas.aws.amazon.com/CVE-2026-72152.html

https://explore.alas.aws.amazon.com/CVE-2026-72155.html

https://explore.alas.aws.amazon.com/CVE-2026-72172.html

https://explore.alas.aws.amazon.com/CVE-2026-72174.html

https://explore.alas.aws.amazon.com/CVE-2026-72176.html

https://explore.alas.aws.amazon.com/CVE-2026-72177.html

https://explore.alas.aws.amazon.com/CVE-2026-72178.html

https://explore.alas.aws.amazon.com/CVE-2026-72183.html

https://explore.alas.aws.amazon.com/CVE-2026-72191.html

https://explore.alas.aws.amazon.com/CVE-2026-72192.html

https://explore.alas.aws.amazon.com/CVE-2026-72193.html

https://explore.alas.aws.amazon.com/CVE-2026-72194.html

https://explore.alas.aws.amazon.com/CVE-2026-72195.html

https://explore.alas.aws.amazon.com/CVE-2026-72196.html

https://explore.alas.aws.amazon.com/CVE-2026-72197.html

https://explore.alas.aws.amazon.com/CVE-2026-72212.html

https://explore.alas.aws.amazon.com/CVE-2026-72213.html

https://explore.alas.aws.amazon.com/CVE-2026-72217.html

https://explore.alas.aws.amazon.com/CVE-2026-72218.html

https://explore.alas.aws.amazon.com/CVE-2026-72219.html

https://explore.alas.aws.amazon.com/CVE-2026-72220.html

https://explore.alas.aws.amazon.com/CVE-2026-72221.html

https://explore.alas.aws.amazon.com/CVE-2026-72222.html

https://explore.alas.aws.amazon.com/CVE-2026-72223.html

https://explore.alas.aws.amazon.com/CVE-2026-72224.html

https://explore.alas.aws.amazon.com/CVE-2026-72225.html

https://explore.alas.aws.amazon.com/CVE-2026-72227.html

https://explore.alas.aws.amazon.com/CVE-2026-72242.html

https://explore.alas.aws.amazon.com/CVE-2026-72243.html

https://explore.alas.aws.amazon.com/CVE-2026-72247.html

https://explore.alas.aws.amazon.com/CVE-2026-72250.html

https://explore.alas.aws.amazon.com/CVE-2026-72251.html

https://explore.alas.aws.amazon.com/CVE-2026-72252.html

https://explore.alas.aws.amazon.com/CVE-2026-72255.html

https://explore.alas.aws.amazon.com/CVE-2026-72256.html

https://explore.alas.aws.amazon.com/CVE-2026-72266.html

https://explore.alas.aws.amazon.com/CVE-2026-72273.html

https://explore.alas.aws.amazon.com/CVE-2026-72274.html

https://explore.alas.aws.amazon.com/CVE-2026-72275.html

https://explore.alas.aws.amazon.com/CVE-2026-72276.html

https://explore.alas.aws.amazon.com/CVE-2026-72277.html

https://explore.alas.aws.amazon.com/CVE-2026-72278.html

https://explore.alas.aws.amazon.com/CVE-2026-72279.html

https://explore.alas.aws.amazon.com/CVE-2026-72280.html

https://explore.alas.aws.amazon.com/CVE-2026-72282.html

https://explore.alas.aws.amazon.com/CVE-2026-72283.html

https://explore.alas.aws.amazon.com/CVE-2026-72284.html

https://explore.alas.aws.amazon.com/CVE-2026-72286.html

https://explore.alas.aws.amazon.com/CVE-2026-72288.html

https://explore.alas.aws.amazon.com/CVE-2026-72289.html

https://explore.alas.aws.amazon.com/CVE-2026-72290.html

https://explore.alas.aws.amazon.com/CVE-2026-72296.html

https://explore.alas.aws.amazon.com/CVE-2026-72299.html

https://explore.alas.aws.amazon.com/CVE-2026-72310.html

https://explore.alas.aws.amazon.com/CVE-2026-72317.html

https://explore.alas.aws.amazon.com/CVE-2026-72318.html

https://explore.alas.aws.amazon.com/CVE-2026-72319.html

https://explore.alas.aws.amazon.com/CVE-2026-72320.html

https://explore.alas.aws.amazon.com/CVE-2026-72321.html

https://explore.alas.aws.amazon.com/CVE-2026-72322.html

https://explore.alas.aws.amazon.com/CVE-2026-72323.html

https://explore.alas.aws.amazon.com/CVE-2026-72325.html

https://explore.alas.aws.amazon.com/CVE-2026-72326.html

https://explore.alas.aws.amazon.com/CVE-2026-72330.html

https://explore.alas.aws.amazon.com/CVE-2026-72338.html

https://explore.alas.aws.amazon.com/CVE-2026-72341.html

https://explore.alas.aws.amazon.com/CVE-2026-72342.html

https://explore.alas.aws.amazon.com/CVE-2026-72343.html

https://explore.alas.aws.amazon.com/CVE-2026-72347.html

https://explore.alas.aws.amazon.com/CVE-2026-72348.html

https://explore.alas.aws.amazon.com/CVE-2026-72349.html

https://explore.alas.aws.amazon.com/CVE-2026-72350.html

https://explore.alas.aws.amazon.com/CVE-2026-72351.html

https://explore.alas.aws.amazon.com/CVE-2026-72352.html

https://explore.alas.aws.amazon.com/CVE-2026-72356.html

https://explore.alas.aws.amazon.com/CVE-2026-72357.html

https://explore.alas.aws.amazon.com/CVE-2026-72363.html

https://explore.alas.aws.amazon.com/CVE-2026-72364.html

https://explore.alas.aws.amazon.com/CVE-2026-72365.html

https://explore.alas.aws.amazon.com/CVE-2026-72366.html

https://explore.alas.aws.amazon.com/CVE-2026-72367.html

https://explore.alas.aws.amazon.com/CVE-2026-72375.html

https://explore.alas.aws.amazon.com/CVE-2026-72379.html

https://explore.alas.aws.amazon.com/CVE-2026-72383.html

https://explore.alas.aws.amazon.com/CVE-2026-72385.html

https://explore.alas.aws.amazon.com/CVE-2026-72389.html

https://explore.alas.aws.amazon.com/CVE-2026-72390.html

https://explore.alas.aws.amazon.com/CVE-2026-72392.html

https://explore.alas.aws.amazon.com/CVE-2026-72398.html

https://explore.alas.aws.amazon.com/CVE-2026-72400.html

https://explore.alas.aws.amazon.com/CVE-2026-72405.html

https://explore.alas.aws.amazon.com/CVE-2026-72416.html

https://explore.alas.aws.amazon.com/CVE-2026-72418.html

https://explore.alas.aws.amazon.com/CVE-2026-72419.html

https://explore.alas.aws.amazon.com/CVE-2026-72420.html

https://explore.alas.aws.amazon.com/CVE-2026-72421.html

https://explore.alas.aws.amazon.com/CVE-2026-72425.html

https://explore.alas.aws.amazon.com/CVE-2026-72427.html

https://explore.alas.aws.amazon.com/CVE-2026-72428.html

https://explore.alas.aws.amazon.com/CVE-2026-72433.html

https://explore.alas.aws.amazon.com/CVE-2026-72434.html

https://explore.alas.aws.amazon.com/CVE-2026-72435.html

https://explore.alas.aws.amazon.com/CVE-2026-72436.html

https://explore.alas.aws.amazon.com/CVE-2026-72437.html

https://explore.alas.aws.amazon.com/CVE-2026-72444.html

https://explore.alas.aws.amazon.com/CVE-2026-72447.html

https://explore.alas.aws.amazon.com/CVE-2026-72450.html

https://explore.alas.aws.amazon.com/CVE-2026-72451.html

https://explore.alas.aws.amazon.com/CVE-2026-72452.html

https://explore.alas.aws.amazon.com/CVE-2026-72466.html

https://explore.alas.aws.amazon.com/CVE-2026-72470.html

https://explore.alas.aws.amazon.com/CVE-2026-72472.html

https://explore.alas.aws.amazon.com/CVE-2026-72476.html

https://explore.alas.aws.amazon.com/CVE-2026-72478.html

https://explore.alas.aws.amazon.com/CVE-2026-72487.html

https://explore.alas.aws.amazon.com/CVE-2026-72502.html

https://explore.alas.aws.amazon.com/CVE-2026-74255.html

https://explore.alas.aws.amazon.com/CVE-2026-74256.html

https://explore.alas.aws.amazon.com/CVE-2026-74257.html

https://explore.alas.aws.amazon.com/CVE-2026-74259.html

https://explore.alas.aws.amazon.com/CVE-2026-74262.html

https://explore.alas.aws.amazon.com/CVE-2026-74264.html

https://explore.alas.aws.amazon.com/CVE-2026-74266.html

https://explore.alas.aws.amazon.com/CVE-2026-74267.html

https://explore.alas.aws.amazon.com/CVE-2026-74268.html

https://explore.alas.aws.amazon.com/CVE-2026-74270.html

https://explore.alas.aws.amazon.com/CVE-2026-74271.html

https://explore.alas.aws.amazon.com/CVE-2026-74281.html

https://explore.alas.aws.amazon.com/CVE-2026-74282.html

https://explore.alas.aws.amazon.com/CVE-2026-74283.html

https://explore.alas.aws.amazon.com/CVE-2026-74284.html

https://explore.alas.aws.amazon.com/CVE-2026-74286.html

https://explore.alas.aws.amazon.com/CVE-2026-74287.html

https://explore.alas.aws.amazon.com/CVE-2026-74288.html

https://explore.alas.aws.amazon.com/CVE-2026-74290.html

https://explore.alas.aws.amazon.com/CVE-2026-74296.html

https://explore.alas.aws.amazon.com/CVE-2026-74297.html

https://explore.alas.aws.amazon.com/CVE-2026-74305.html

https://explore.alas.aws.amazon.com/CVE-2026-74308.html

https://explore.alas.aws.amazon.com/CVE-2026-74310.html

https://explore.alas.aws.amazon.com/CVE-2026-74316.html

https://explore.alas.aws.amazon.com/CVE-2026-74318.html

https://explore.alas.aws.amazon.com/CVE-2026-74321.html

https://explore.alas.aws.amazon.com/CVE-2026-74327.html

https://explore.alas.aws.amazon.com/CVE-2026-74329.html

https://explore.alas.aws.amazon.com/CVE-2026-74330.html

https://explore.alas.aws.amazon.com/CVE-2026-74331.html

https://explore.alas.aws.amazon.com/CVE-2026-74335.html

https://explore.alas.aws.amazon.com/CVE-2026-74337.html

https://explore.alas.aws.amazon.com/CVE-2026-74344.html

https://explore.alas.aws.amazon.com/CVE-2026-74346.html

https://explore.alas.aws.amazon.com/CVE-2026-74352.html

https://explore.alas.aws.amazon.com/CVE-2026-74355.html

https://explore.alas.aws.amazon.com/CVE-2026-74356.html

https://explore.alas.aws.amazon.com/CVE-2026-74358.html

https://explore.alas.aws.amazon.com/CVE-2026-74359.html

https://explore.alas.aws.amazon.com/CVE-2026-74360.html

https://explore.alas.aws.amazon.com/CVE-2026-74361.html

https://explore.alas.aws.amazon.com/CVE-2026-74363.html

https://explore.alas.aws.amazon.com/CVE-2026-74364.html

https://explore.alas.aws.amazon.com/CVE-2026-74365.html

https://explore.alas.aws.amazon.com/CVE-2026-74371.html

https://explore.alas.aws.amazon.com/CVE-2026-74372.html

https://explore.alas.aws.amazon.com/CVE-2026-74376.html

https://explore.alas.aws.amazon.com/CVE-2026-74379.html

https://explore.alas.aws.amazon.com/CVE-2026-74380.html

https://explore.alas.aws.amazon.com/CVE-2026-74382.html

https://explore.alas.aws.amazon.com/CVE-2026-74383.html

https://explore.alas.aws.amazon.com/CVE-2026-74384.html

https://explore.alas.aws.amazon.com/CVE-2026-74393.html

https://explore.alas.aws.amazon.com/CVE-2026-74395.html

https://explore.alas.aws.amazon.com/CVE-2026-74396.html

https://explore.alas.aws.amazon.com/CVE-2026-74397.html

https://explore.alas.aws.amazon.com/CVE-2026-74398.html

https://explore.alas.aws.amazon.com/CVE-2026-74399.html

https://explore.alas.aws.amazon.com/CVE-2026-74400.html

https://explore.alas.aws.amazon.com/CVE-2026-74405.html

https://explore.alas.aws.amazon.com/CVE-2026-74406.html

https://explore.alas.aws.amazon.com/CVE-2026-74417.html

https://explore.alas.aws.amazon.com/CVE-2026-74424.html

https://explore.alas.aws.amazon.com/CVE-2026-74439.html

https://explore.alas.aws.amazon.com/CVE-2026-74578.html

プラグインの詳細

深刻度: Medium

ID: 341880

ファイル名: al2023_ALAS2023-2026-2071.nasl

バージョン: 1.2

タイプ: Local

エージェント: unix

公開日: 2026/8/31

更新日: 2026/9/1

サポートされているセンサー: Frictionless Assessment AWS, Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Continuous Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

リスク情報

VPR

リスクファクター: High

スコア: 8

パーセンタイル: 99.68

CVSS v2

リスクファクター: Medium

基本値: 4.6

現状値: 3.6

ベクトル: CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:C

CVSS スコアのソース: CVE-2026-64227

CVSS v3

リスクファクター: Medium

基本値: 5.5

現状値: 5

ベクトル: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

現状ベクトル: CVSS:3.0/E:P/RL:O/RC:C

脆弱性情報

CPE: cpe:/o:amazon:linux:2023, p-cpe:/a:amazon:linux:bpftool6.18-debuginfo, p-cpe:/a:amazon:linux:bpftool6.18, p-cpe:/a:amazon:linux:kernel-livepatch-6.18.41-94.142, p-cpe:/a:amazon:linux:kernel6.18-debuginfo-common-aarch64, p-cpe:/a:amazon:linux:kernel6.18-debuginfo-common-x86_64, p-cpe:/a:amazon:linux:kernel6.18-debuginfo, p-cpe:/a:amazon:linux:kernel6.18-devel, p-cpe:/a:amazon:linux:kernel6.18-headers, p-cpe:/a:amazon:linux:kernel6.18-modules-extra-common, p-cpe:/a:amazon:linux:kernel6.18-modules-extra, p-cpe:/a:amazon:linux:kernel6.18-tools-debuginfo, p-cpe:/a:amazon:linux:kernel6.18-tools-devel, p-cpe:/a:amazon:linux:kernel6.18-tools, p-cpe:/a:amazon:linux:kernel6.18, p-cpe:/a:amazon:linux:microvm-kernel6.18, p-cpe:/a:amazon:linux:perf6.18-debuginfo, p-cpe:/a:amazon:linux:perf6.18, p-cpe:/a:amazon:linux:python3-perf6.18-debuginfo, p-cpe:/a:amazon:linux:python3-perf6.18

必要な KB アイテム: Host/local_checks_enabled, Host/AmazonLinux/release, Host/AmazonLinux/rpm-list

エクスプロイトが利用可能: true

エクスプロイトの容易さ: Exploits are available

パッチ公開日: 2026/8/31

脆弱性公開日: 2026/6/24

参照情報

CVE: CVE-2026-53005, CVE-2026-64192, CVE-2026-64227, CVE-2026-64287, CVE-2026-64352, CVE-2026-64353, CVE-2026-64371, CVE-2026-64375, CVE-2026-64472, CVE-2026-64530, CVE-2026-64532, CVE-2026-64533, CVE-2026-64538, CVE-2026-64542, CVE-2026-64543, CVE-2026-64544, CVE-2026-64545, CVE-2026-64546, CVE-2026-64548, CVE-2026-64551, CVE-2026-64552, CVE-2026-64553, CVE-2026-64555, CVE-2026-64560, CVE-2026-64561, CVE-2026-68081, CVE-2026-68458, CVE-2026-68476, CVE-2026-68477, CVE-2026-72006, CVE-2026-72010, CVE-2026-72012, CVE-2026-72014, CVE-2026-72016, CVE-2026-72020, CVE-2026-72021, CVE-2026-72027, CVE-2026-72032, CVE-2026-72034, CVE-2026-72035, CVE-2026-72036, CVE-2026-72040, CVE-2026-72041, CVE-2026-72042, CVE-2026-72051, CVE-2026-72052, CVE-2026-72053, CVE-2026-72054, CVE-2026-72055, CVE-2026-72057, CVE-2026-72061, CVE-2026-72063, CVE-2026-72066, CVE-2026-72067, CVE-2026-72068, CVE-2026-72071, CVE-2026-72072, CVE-2026-72083, CVE-2026-72084, CVE-2026-72095, CVE-2026-72096, CVE-2026-72097, CVE-2026-72099, CVE-2026-72100, CVE-2026-72101, CVE-2026-72102, CVE-2026-72105, CVE-2026-72106, CVE-2026-72108, CVE-2026-72110, CVE-2026-72111, CVE-2026-72120, CVE-2026-72122, CVE-2026-72123, CVE-2026-72127, CVE-2026-72132, CVE-2026-72135, CVE-2026-72136, CVE-2026-72137, CVE-2026-72138, CVE-2026-72139, CVE-2026-72150, CVE-2026-72151, CVE-2026-72152, CVE-2026-72155, CVE-2026-72172, CVE-2026-72174, CVE-2026-72176, CVE-2026-72177, CVE-2026-72178, CVE-2026-72183, CVE-2026-72191, CVE-2026-72192, CVE-2026-72193, CVE-2026-72194, CVE-2026-72195, CVE-2026-72196, CVE-2026-72197, CVE-2026-72212, CVE-2026-72213, CVE-2026-72217, CVE-2026-72218, CVE-2026-72219, CVE-2026-72220, CVE-2026-72221, CVE-2026-72222, CVE-2026-72223, CVE-2026-72224, CVE-2026-72225, CVE-2026-72227, CVE-2026-72242, CVE-2026-72243, CVE-2026-72247, CVE-2026-72250, CVE-2026-72251, CVE-2026-72252, CVE-2026-72255, CVE-2026-72256, CVE-2026-72266, CVE-2026-72273, CVE-2026-72274, CVE-2026-72275, CVE-2026-72276, CVE-2026-72277, CVE-2026-72278, CVE-2026-72279, CVE-2026-72280, CVE-2026-72282, CVE-2026-72283, CVE-2026-72284, CVE-2026-72286, CVE-2026-72288, CVE-2026-72289, CVE-2026-72290, CVE-2026-72296, CVE-2026-72299, CVE-2026-72310, CVE-2026-72317, CVE-2026-72318, CVE-2026-72319, CVE-2026-72320, CVE-2026-72321, CVE-2026-72322, CVE-2026-72323, CVE-2026-72325, CVE-2026-72326, CVE-2026-72330, CVE-2026-72338, CVE-2026-72341, CVE-2026-72342, CVE-2026-72343, CVE-2026-72347, CVE-2026-72348, CVE-2026-72349, CVE-2026-72350, CVE-2026-72351, CVE-2026-72352, CVE-2026-72356, CVE-2026-72357, CVE-2026-72363, CVE-2026-72364, CVE-2026-72365, CVE-2026-72366, CVE-2026-72367, CVE-2026-72375, CVE-2026-72379, CVE-2026-72383, CVE-2026-72385, CVE-2026-72389, CVE-2026-72390, CVE-2026-72392, CVE-2026-72398, CVE-2026-72400, CVE-2026-72405, CVE-2026-72416, CVE-2026-72418, CVE-2026-72419, CVE-2026-72420, CVE-2026-72421, CVE-2026-72425, CVE-2026-72427, CVE-2026-72428, CVE-2026-72433, CVE-2026-72434, CVE-2026-72435, CVE-2026-72436, CVE-2026-72437, CVE-2026-72444, CVE-2026-72447, CVE-2026-72450, CVE-2026-72451, CVE-2026-72452, CVE-2026-72466, CVE-2026-72470, CVE-2026-72472, CVE-2026-72476, CVE-2026-72478, CVE-2026-72487, CVE-2026-72502, CVE-2026-74255, CVE-2026-74256, CVE-2026-74257, CVE-2026-74259, CVE-2026-74262, CVE-2026-74264, CVE-2026-74266, CVE-2026-74267, CVE-2026-74268, CVE-2026-74270, CVE-2026-74271, CVE-2026-74281, CVE-2026-74282, CVE-2026-74283, CVE-2026-74284, CVE-2026-74286, CVE-2026-74287, CVE-2026-74288, CVE-2026-74290, CVE-2026-74296, CVE-2026-74297, CVE-2026-74305, CVE-2026-74308, CVE-2026-74310, CVE-2026-74316, CVE-2026-74318, CVE-2026-74321, CVE-2026-74327, CVE-2026-74329, CVE-2026-74330, CVE-2026-74331, CVE-2026-74335, CVE-2026-74337, CVE-2026-74344, CVE-2026-74346, CVE-2026-74352, CVE-2026-74355, CVE-2026-74356, CVE-2026-74358, CVE-2026-74359, CVE-2026-74360, CVE-2026-74361, CVE-2026-74363, CVE-2026-74364, CVE-2026-74365, CVE-2026-74371, CVE-2026-74372, CVE-2026-74376, CVE-2026-74379, CVE-2026-74380, CVE-2026-74382, CVE-2026-74383, CVE-2026-74384, CVE-2026-74393, CVE-2026-74395, CVE-2026-74396, CVE-2026-74397, CVE-2026-74398, CVE-2026-74399, CVE-2026-74400, CVE-2026-74405, CVE-2026-74406, CVE-2026-74417, CVE-2026-74424, CVE-2026-74439, CVE-2026-74578