SUSE SLES15: cluster-md-kmp-default / dlm-kmp-default / gfs2-kmp-default / etc (SUSE-SU-2026:4284-1)

high Nessus プラグイン ID 349184

Language:

概要

リモートの SUSE ホストに 1 つ以上のセキュリティ更新がありません。

説明

リモートの SUSE Linux SLES15 / SLES_SAP15 ホストには、SUSE-SU-2026:4284-1 のアドバイザリに記載された複数の脆弱性の影響を受けるパッケージがインストールされています。

SUSE Linux Enterprise 15 SP4 カーネルが更新され、さまざまなセキュリティ問題が修正されました:

以下のセキュリティ問題が修正されました。

- CVE-2023-53109:net:tunnels:dev->needed_headroom へのロック無しアクセスに注釈をつけます(bsc#1242405 bsc#1275784)。
- CVE-2024-57841:net:tcp_conn_request() でのメモリ漏洩を修正します(bsc#1235944)。
- CVE-2026-53260:tcp:reqsk_queue_hash_req()にpreempt_{disable,enable}_nested()を追加(bsc#1269731)。
- CVE-2026-23451:bonding:bond_header_parse() の無限ループの可能性を防止します(bsc#1261604)。
- CVE-2026-31502:チーム:非イーサネットポートとのheader_ops型の取り違え(Type Confusion)を修正します(bsc#1263072)。
- CVE-2026-43456:bonding:bond_setup_by_slave() での型の取り違え(Type Confusion)を修正します(bsc#1264734)。
- CVE-2026-43502:net/rds:メッセージがキューに入る前に zerocopy 送信クリーンアップを処理します(bsc#1266008)。
- CVE-2026-45968:cpuidle:アイドル状態が 1 つだけ利用可能な場合はガバナーをスキップします(bsc#1267023)。
- CVE-2026-52910:bpf:RCU 猶予期間(bsc#1268659)後の free-reuseport cBPF prog。
- CVE-2026-52912:netfilter:nf_queue:キューに入れられた間、ブリッジ skb->dev を保留します(bsc#1269000)。
- CVE-2026-52929:sctp:stream:拒否された add-stream 状態を完全にロールバックします(bsc#1269004)。
- CVE-2026-52977:futex:シグナル/タイムアウトウェイクアップ中の requeue-PI におけるロックアップを防止します(bsc#1269242)。
- CVE-2026-53059:dm ログ:region_countオーバーフローによる領域外書き込みを修正します(bsc#1269655)。
- CVE-2026-53163:locking/rtmutex:waiter がキューに入っていない場合、remove_waiter() をスキップします(bsc#1269306)。
- CVE-2026-53264:net/sched:act_api:アクションライフサイクルに対して、遅延解放を伴う RCU を使用します(bsc#1269238)。
- CVE-2026-53381:virtiofs:サブマウントアンマウントの UAF を修正します(bsc#1271830)。
- CVE-2026-63801:tipc:tipc_aead_decrypt_done の slab-use-after-free 読み取りを修正します(bsc#1272230)。
- CVE-2026-63823:keys:ペイロードrequest_key_authインスタンス化パスにピン(bsc#1272182)。
- CVE-2026-63827:apparmor:rawdata 重複排除ループの use-after-free を修正します(bsc#1272179)。
- CVE-2026-63887:scsi:target:iscsi:バインド iscsi_encode_text_output() を rsp_buf(bsc#1272385)に追加します。
- CVE-2026-63888:scsi:target:iscsi:iscsit_handle_text_cmd() での CRC のオーバーリードと二重解放を修正します(bsc#1272390)。
- CVE-2026-63920:ipv6:cmsg にコピーする前に拡張ヘッダーの長さを検証します(bsc#1272877)。
- CVE-2026-63992:トンネル:iptunnel_pmtud_check_icmp() でトランスポートヘッダーを引き受けません(bsc#1272868)。
- CVE-2026-64002:ipv4:unregister_net_sysctl_table() 後に net->ipv4.sysctl_local_reserved_ports を解放します(bsc#1273774)。
- CVE-2026-64007:netfilter:synproxy:skb_ensure_writable後に tcphdr をリフレッシュします(bsc#1273105)。
- CVE-2026-64010:nfc:llcp:nfc_llcp_recv_cc() での use-after-free の競合を修正します(bsc#1273882)。
- CVE-2026-64011:nfc:llcp:llcp_sock_release() の use-after-free を修正します(bsc#1273891)。
- CVE-2026-64015:security/keys:検索で欠落した RCU 読み取りセクションを修正します(bsc#1273762)。
- CVE-2026-64047:net:tls:ラップされた sk_msg リングのエントリカウントsg_chain off-by-one を修正します(bsc#1273060)。
- CVE-2026-64048:net/smc:空の ism_dev スロットに一致する CHID-0 ACCEPT を拒否します(bsc#1273484)。
- CVE-2026-64098:drm/virtio:プレーン更新に対して、割り込み不可な resv ロックを使用します(bsc#1273488)。
- CVE-2026-64109:af_unix:同期されたキューをピークします(bsc#1273748)。
- CVE-2026-64114:ipv4:raw:IHL < 5(bsc#1273742)でIP_HDRINCLパケットを拒否します。
- CVE-2026-64115:vsock/vmci:ハンドシェイク中にピアが接続をリセットする際の UAF を修正します(bsc#1273745)。
- CVE-2026-64268:RDMA/siw:読み取り応答の配置を RREAD の長さ (bsc#1273276) にバインドします。
- CVE-2026-64304:crypto:qat - RSA CRT コンポーネントの長さを検証します(bsc#1273944)。
- CVE-2026-64355:bpf:devmap でフラグメント化されたフレームを拒否します(bsc#1273422)。
- CVE-2026-64423:ipv4:igmp:デバイス破壊時に、ハッシュテーブルからマルチキャストグループを削除します(bsc#1274274)。
- CVE-2026-64450:tipc:ブロードキャストギャップ ACK ブロックの領域外読み取りを修正します(bsc#1273523)。
- CVE-2026-64481:ALSA:had/cs35l41:ファームウェアロードワークティアダウンを修正します(bsc#1274547)。
- CVE-2026-64541:net/smc:ソケットをピンニングすることにより、smc_cdc_rx_handler() で UAF を修正します(bsc#1273303)。
- CVE-2026-64543:tipc:tipc_disc_rcv() におけるディスカバラーの use-after-free を修正します(bsc#1273311)。
- CVE-2026-64556:perf/core:remove_on_exec中にイベントグループをデタッチします(bsc#1273251)。
- CVE-2026-64562:KVM:nVMX:VMCLEAR 直後にシャドウ VMCS を非表示にします(bsc#1273930)。
- CVE-2026-64563:rhashtable:テーブルの再起動で古い iter->p をクリアします(bsc#1273995)。
- CVE-2026-64572:ipv4:fib:挿入エラーパスで kfree_rcu() でfib_aliasを解放します(bsc#1274014)。
- CVE-2026-64581:xfrm:xfrm_user_policy() でのsk_dst_cache二重解放を修正します(bsc#1274041)。
- CVE-2026-64593:btrfs:書き込み不能なデバイスをトリミングしません(bsc#1274497)。
- CVE-2026-68121:pppoe:dev_hard_header() の後にヘッダーポインターをリロードします(bsc#1274888)。
- CVE-2026-68136:net:gro:フラッシュマークの付いた skbs の二重集計を修正します(bsc#1275474)。
- CVE-2026-68138:net/sched:qdisc_rtab_listを同時 get/put に対してシリアル化します(bsc#1274941)。
- CVE-2026-68155:libceph:ゼロモニターをアドバタイズしている monmap を拒否します(bsc#1275304)。
- CVE-2026-68158:libceph:decode_new_up_state_weight() の乗算オーバーフローを修正します(bsc#1275307)。
- CVE-2026-68159:libceph:pg_{temp,upmap,upmap_items} の長さを CEPH_PG_MAX_SIZE にバインドします(bsc#1275470)。
- CVE-2026-68160:ceph:ceph_handle_caps() の snaptrace での事前認証の領域外読み取りを修正します(bsc#1275472)。
- CVE-2026-68202:ALSA:seq:デストラクタで再開されたキュータイマーを閉じます(bsc#1275161)。
- CVE-2026-68397:net/iucv:afiucv_hs_rcv() にあるソケットで参照を取得します(bsc#1274898)。
- CVE-2026-68398:ppp:pppol2tp RX UAF を修正するために、チャネルの解放を RCU 猶予期間に延期します(bsc#1274908)。
- CVE-2026-68417:RDMA/siw:初期化後に QP を公開します(bsc#1274696)。
- CVE-2026-68426:xfrm:非同期暗号が GSO セグメントを盗んだ後の古い skb->prev を修正します(bsc#1274705)。
- CVE-2026-68480:x86/bugs:Safe-RET を割り込みインジェクションに対して堅牢にします(bsc#1274208)。
- CVE-2026-72020:ipvs:ip_vs_conn_new の完全な ip_vs_seq 構造体をリセットします(bsc#1275506)。
- CVE-2026-72069:locking/rt:rt_spin_unlock() の不適切な RCU 保護を修正します(bsc#1275528)。
- CVE-2026-72083:scsi:target:core:REGISTER AND MOVE の iSCSI ISID use-after-free を修正します(bsc#1275535)。
- CVE-2026-72084:scsi:target:core:PR OUT トランスポート ID に対して正しい識別子を生成します(bsc#1275540)。
- CVE-2026-72123:can:bcm:作業キューへの割り当て解除rx_op延期し、thrtimer UAF を修正します(bsc#1277523)。
- CVE-2026-72135:tpm:TPM 文字デバイスをシーク不可能にします(bsc#1277571)。
- CVE-2026-72164:ocfs2:占有されたクラスターへのエクステントの移動を回避します(bsc#1277553)。
- CVE-2026-72251:netfilter:nf_nat_sip:古いデータポインターの可能性をリロードします(bsc#1275827)。
- CVE-2026-72288:KVM:arm64:vgic:割り込みアフィニティの変更と LPI 無効の間の競合を処理します(bsc#1275886)。
- CVE-2026-72289:KVM:arm64:vgic:割り込みを移行する前に、割り込みがまだ私たちのものであることを確認します(bsc#1275905)。
- CVE-2026-72323:ipv4:igmp:igmp_gq_start_timer() での潜在的な UAF を修正します(bsc#1275985)。
- CVE-2026-72339:qede:build_skb障害時の BD リング消費の off-by-one を修正します(bsc#1276006)。
- CVE-2026-72389:ブリッジ:stp:ブリッジを削除する際に発生する可能性のある use-after-free を修正します(bsc#1273869)。
- CVE-2026-74345:RDMA/siw:エンドポイント/ソケット関連付け処理を修正します(bsc#1277285)。
- CVE-2026-74377:RDMA/rxe:WQE を非 SRQ 受信パスのローカルバッファにコピーします(bsc#1278236)。
- CVE-2026-74378:RDMA/rxe:get_srq_wqe の TOCTOU ヒープオーバーフローを修正します(bsc#1278233)。
- CVE-2026-74388:ALSA:seq:oss:組込み SysEx データのあるイベントを処理する際の UAF を修正します(bsc#1278253)。
- CVE-2026-74390:RDMA/irdma:irdma_copy_user_pgaddrs での領域外書き込みを修正します(bsc#1278088)。
- CVE-2026-74394:RDMA/srpt:即時データ長チェックの整数オーバーフローを修正します(bsc#1277408)。
- CVE-2026-74406:vxlan:vxlan_gro_prepare_receive() における潜在的な null-ptr-deref を修正します(bsc#1276395)。
- CVE-2026-74454:drm/vc4:bin BO 全体ではなく、BPOS でオーバーフロースロットサイズを供給します(bsc#1277073)。
- CVE-2026-74488:wifi:mwifiex:A-MSDU TDLS フレームを解析する際に、サブフレーム長を使用します(bsc#1276350)。
- CVE-2026-74496:fou:fou_create() における use-after-free を修正します(bsc#1275867)。
- CVE-2026-74518:mm/hugetlb:allocate_file_region_entries() のリスト破損を修正します(bsc#1275798)。
- CVE-2026-74537:Bluetooth:ISO:iso_conn_readyで sk を適切に保持します(bsc#1275687)。
- CVE-2026-74556:scsi:libiscsi_tcp:SCSI 応答データセグメントを接続バッファにバインドします(bsc#1275696)。
- CVE-2026-74582:packet:非リング送信パスで一貫したhard_header_lenを使用します(bsc#1275784)。
- CVE-2026-74615:vxlan:ダウンしているデバイスでエージングタイマーを非武装させません(bsc#1277901)。
- CVE-2026-74616:xdp:tailroom skb_shared_infoオーバーランするクローンを拒否します(bsc#1277813)。
- CVE-2026-74669:ipvs:トンネル ICMP エラーのリベース後に IPv4 オプションをクリアします(bsc#1277391)。
- CVE-2026-74695:netfilter:nf_flow_table:skb_dst_set_noref() の前に既存の skb dst をドロップします(bsc#1276931)。
- CVE-2026-74743:macvlan:lowerdev から needed_headroom および needed_tailroom を継承します(bsc#1277908)。
- CVE-2026-80580:fbdev:sysfs バッファに sysfs 出力をバインドします(bsc#1278294)。
- CVE-2026-80714:ipvs:同期された conns に one-packet フラグを伝播しません(bsc#1277561)。
- CVE-2026-80716:ALSA:pcm:リンク解除時のリンクされたドレインウェイターをウェイク解除します(bsc#1277837)。
- CVE-2026-80737:シリアル:amba-pl011:DMA 切断を同期します(bsc#1279487)。
- CVE-2026-80909:drm/amdgpu:無効な番号の h265 refs のある UVD メッセージを拒否します(bsc#1279422)。

セキュリティに関係しない以下の問題が修正されました。

- mkspec-dtb:DTS プレフィックスをパッケージリストに移動します。
- mkspec-dtb:provides-obsoletes をパッケージリストに移動します。
- mkspec-dtb:アーキテクチャごとのパッケージリストをハッシュに配置します。
- mkspec-dtb:再インデント。
- net:tap:tap_get_user_xdp() の virtio net ヘッダーを解析する前に skb->dev を設定します(git-fixes bsc#1274550)。
- perf:終了したイベントをグループリーダーとして拒否します(git-fixes)。
- powerpc/pseries:lparcfg - kbuf[] アンダーフローを修正します(bsc#1274753 ltc#221289 bsc#1274754 ltc#221288 bsc#1274752 ltc#221290)。
- RDMA/siw:siw_cep_set_free_and_put を導入します(git-fixes)。
- RDMA/siw:siw_destroy_cep_sock を導入します(git-fixes)。
- RDMA/siw:siw_free_cm_id を導入します(git-fixes)。
- RDMA/siw:siw_create_qp で attrs->cap.max_send_wr のみをチェックします(git-fixes)。
- smb/client:falocate(bsc#1274902)で、重複する割り当て済み範囲を処理します。
- smb:クライアント:CIFS SWN netlink に対して net admin が必要です(bsc#1273966)。

Tenable は、前述の記述ブロックを SUSE セキュリティアドバイザリから直接抽出しています。

Nessus はこれらの問題をテストしておらず、代わりにアプリケーションが自己報告するバージョン番号にのみ依存していることに注意してください。

ソリューション

影響を受けるパッケージを更新してください。

参考資料

https://bugzilla.suse.com/1235944

https://bugzilla.suse.com/1242405

https://bugzilla.suse.com/1261604

https://bugzilla.suse.com/1263072

https://bugzilla.suse.com/1264734

https://bugzilla.suse.com/1266008

https://bugzilla.suse.com/1267023

https://bugzilla.suse.com/1268659

https://bugzilla.suse.com/1269000

https://bugzilla.suse.com/1269004

https://bugzilla.suse.com/1269238

https://bugzilla.suse.com/1269242

https://bugzilla.suse.com/1269306

https://bugzilla.suse.com/1269655

https://bugzilla.suse.com/1269731

https://bugzilla.suse.com/1271825

https://bugzilla.suse.com/1271830

https://bugzilla.suse.com/1272179

https://bugzilla.suse.com/1272182

https://bugzilla.suse.com/1272230

https://bugzilla.suse.com/1272385

https://bugzilla.suse.com/1272390

https://bugzilla.suse.com/1272868

https://bugzilla.suse.com/1272877

https://bugzilla.suse.com/1273060

https://bugzilla.suse.com/1273105

https://bugzilla.suse.com/1273251

https://bugzilla.suse.com/1273276

https://bugzilla.suse.com/1273303

https://bugzilla.suse.com/1273311

https://bugzilla.suse.com/1273422

https://bugzilla.suse.com/1273484

https://bugzilla.suse.com/1273488

https://bugzilla.suse.com/1273523

https://bugzilla.suse.com/1273555

https://bugzilla.suse.com/1273742

https://bugzilla.suse.com/1273745

https://bugzilla.suse.com/1273748

https://bugzilla.suse.com/1273762

https://bugzilla.suse.com/1273774

https://bugzilla.suse.com/1273869

https://bugzilla.suse.com/1273882

https://bugzilla.suse.com/1273891

https://bugzilla.suse.com/1273930

https://bugzilla.suse.com/1273944

https://bugzilla.suse.com/1273966

https://bugzilla.suse.com/1273995

https://bugzilla.suse.com/1274014

https://bugzilla.suse.com/1274041

https://bugzilla.suse.com/1274208

https://bugzilla.suse.com/1274274

https://bugzilla.suse.com/1274497

https://bugzilla.suse.com/1274547

https://bugzilla.suse.com/1274550

https://bugzilla.suse.com/1274696

https://bugzilla.suse.com/1274705

https://bugzilla.suse.com/1274752

https://bugzilla.suse.com/1274753

https://bugzilla.suse.com/1274754

https://bugzilla.suse.com/1274859

https://bugzilla.suse.com/1274888

https://bugzilla.suse.com/1274898

https://bugzilla.suse.com/1274902

https://bugzilla.suse.com/1274908

https://bugzilla.suse.com/1274941

https://bugzilla.suse.com/1275161

https://bugzilla.suse.com/1275304

https://bugzilla.suse.com/1275307

https://bugzilla.suse.com/1275470

https://bugzilla.suse.com/1275472

https://bugzilla.suse.com/1275474

https://bugzilla.suse.com/1275506

https://bugzilla.suse.com/1275528

https://bugzilla.suse.com/1275535

https://bugzilla.suse.com/1275540

https://bugzilla.suse.com/1275687

https://bugzilla.suse.com/1275696

https://bugzilla.suse.com/1275784

https://bugzilla.suse.com/1275798

https://bugzilla.suse.com/1275827

https://bugzilla.suse.com/1275867

https://bugzilla.suse.com/1275886

https://bugzilla.suse.com/1275905

https://bugzilla.suse.com/1275985

https://bugzilla.suse.com/1276006

https://bugzilla.suse.com/1276350

https://bugzilla.suse.com/1276395

https://bugzilla.suse.com/1276665

https://bugzilla.suse.com/1276931

https://bugzilla.suse.com/1277073

https://bugzilla.suse.com/1277285

https://bugzilla.suse.com/1277391

https://bugzilla.suse.com/1277408

https://bugzilla.suse.com/1277523

https://bugzilla.suse.com/1277553

https://bugzilla.suse.com/1277561

https://bugzilla.suse.com/1277571

https://bugzilla.suse.com/1277813

https://bugzilla.suse.com/1277837

https://bugzilla.suse.com/1277901

https://bugzilla.suse.com/1277908

https://bugzilla.suse.com/1278088

https://bugzilla.suse.com/1278233

https://bugzilla.suse.com/1278236

https://bugzilla.suse.com/1278253

https://bugzilla.suse.com/1278294

https://bugzilla.suse.com/1279422

https://bugzilla.suse.com/1279487

https://bugzilla.suse.com/1279813

https://www.suse.com/security/cve/CVE-2023-53109

https://www.suse.com/security/cve/CVE-2024-57841

https://www.suse.com/security/cve/CVE-2026-23451

https://www.suse.com/security/cve/CVE-2026-31502

https://www.suse.com/security/cve/CVE-2026-43456

https://www.suse.com/security/cve/CVE-2026-43502

https://www.suse.com/security/cve/CVE-2026-45968

https://www.suse.com/security/cve/CVE-2026-52910

https://www.suse.com/security/cve/CVE-2026-52912

https://www.suse.com/security/cve/CVE-2026-52929

https://www.suse.com/security/cve/CVE-2026-52977

https://www.suse.com/security/cve/CVE-2026-53059

https://www.suse.com/security/cve/CVE-2026-53163

https://www.suse.com/security/cve/CVE-2026-53260

https://www.suse.com/security/cve/CVE-2026-53264

https://www.suse.com/security/cve/CVE-2026-53381

https://www.suse.com/security/cve/CVE-2026-53388

https://www.suse.com/security/cve/CVE-2026-63801

https://www.suse.com/security/cve/CVE-2026-63823

https://www.suse.com/security/cve/CVE-2026-63827

https://www.suse.com/security/cve/CVE-2026-63887

https://www.suse.com/security/cve/CVE-2026-63888

https://www.suse.com/security/cve/CVE-2026-63920

https://www.suse.com/security/cve/CVE-2026-63992

https://www.suse.com/security/cve/CVE-2026-64002

https://www.suse.com/security/cve/CVE-2026-64007

https://www.suse.com/security/cve/CVE-2026-64010

https://www.suse.com/security/cve/CVE-2026-64011

https://www.suse.com/security/cve/CVE-2026-64015

https://www.suse.com/security/cve/CVE-2026-64047

https://www.suse.com/security/cve/CVE-2026-64048

https://www.suse.com/security/cve/CVE-2026-64098

https://www.suse.com/security/cve/CVE-2026-64109

https://www.suse.com/security/cve/CVE-2026-64114

https://www.suse.com/security/cve/CVE-2026-64115

https://www.suse.com/security/cve/CVE-2026-64137

https://www.suse.com/security/cve/CVE-2026-64266

https://www.suse.com/security/cve/CVE-2026-64268

https://www.suse.com/security/cve/CVE-2026-64304

https://www.suse.com/security/cve/CVE-2026-64355

https://www.suse.com/security/cve/CVE-2026-64423

https://www.suse.com/security/cve/CVE-2026-64450

https://www.suse.com/security/cve/CVE-2026-64481

https://www.suse.com/security/cve/CVE-2026-64541

https://www.suse.com/security/cve/CVE-2026-64543

https://www.suse.com/security/cve/CVE-2026-64556

https://www.suse.com/security/cve/CVE-2026-64562

https://www.suse.com/security/cve/CVE-2026-64563

https://www.suse.com/security/cve/CVE-2026-64572

https://www.suse.com/security/cve/CVE-2026-64581

https://www.suse.com/security/cve/CVE-2026-64593

https://www.suse.com/security/cve/CVE-2026-68121

https://www.suse.com/security/cve/CVE-2026-68136

https://www.suse.com/security/cve/CVE-2026-68138

https://www.suse.com/security/cve/CVE-2026-68155

https://www.suse.com/security/cve/CVE-2026-68158

https://www.suse.com/security/cve/CVE-2026-68159

https://www.suse.com/security/cve/CVE-2026-68160

https://www.suse.com/security/cve/CVE-2026-68202

https://www.suse.com/security/cve/CVE-2026-68397

https://www.suse.com/security/cve/CVE-2026-68398

https://www.suse.com/security/cve/CVE-2026-68417

https://www.suse.com/security/cve/CVE-2026-68426

https://www.suse.com/security/cve/CVE-2026-68480

https://www.suse.com/security/cve/CVE-2026-72020

https://www.suse.com/security/cve/CVE-2026-72069

https://www.suse.com/security/cve/CVE-2026-72083

https://www.suse.com/security/cve/CVE-2026-72084

https://www.suse.com/security/cve/CVE-2026-72123

https://www.suse.com/security/cve/CVE-2026-72135

https://www.suse.com/security/cve/CVE-2026-72164

https://www.suse.com/security/cve/CVE-2026-72251

https://www.suse.com/security/cve/CVE-2026-72288

https://www.suse.com/security/cve/CVE-2026-72289

https://www.suse.com/security/cve/CVE-2026-72323

https://www.suse.com/security/cve/CVE-2026-72339

https://www.suse.com/security/cve/CVE-2026-72389

https://www.suse.com/security/cve/CVE-2026-74345

https://www.suse.com/security/cve/CVE-2026-74377

https://www.suse.com/security/cve/CVE-2026-74378

https://www.suse.com/security/cve/CVE-2026-74388

https://www.suse.com/security/cve/CVE-2026-74390

https://www.suse.com/security/cve/CVE-2026-74394

https://www.suse.com/security/cve/CVE-2026-74406

https://www.suse.com/security/cve/CVE-2026-74454

https://www.suse.com/security/cve/CVE-2026-74488

https://www.suse.com/security/cve/CVE-2026-74496

https://www.suse.com/security/cve/CVE-2026-74518

https://www.suse.com/security/cve/CVE-2026-74537

https://www.suse.com/security/cve/CVE-2026-74556

https://www.suse.com/security/cve/CVE-2026-74582

https://www.suse.com/security/cve/CVE-2026-74615

https://www.suse.com/security/cve/CVE-2026-74616

https://www.suse.com/security/cve/CVE-2026-74669

https://www.suse.com/security/cve/CVE-2026-74695

https://www.suse.com/security/cve/CVE-2026-74743

https://www.suse.com/security/cve/CVE-2026-80580

https://www.suse.com/security/cve/CVE-2026-80714

https://www.suse.com/security/cve/CVE-2026-80716

https://www.suse.com/security/cve/CVE-2026-80737

https://www.suse.com/security/cve/CVE-2026-80909

http://www.nessus.org/u?d2400eb9

プラグインの詳細

深刻度: High

ID: 349184

ファイル名: suse_SU-2026-4284-1.nasl

バージョン: 1.1

タイプ: Local

エージェント: unix

公開日: 2026/9/23

更新日: 2026/9/23

サポートされているセンサー: Agentless Assessment, Continuous Assessment, Frictionless Assessment Agent, Frictionless Assessment AWS, Frictionless Assessment Azure, Nessus Agent, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

リスク情報

VPR

リスクファクター: High

スコア: 7.9

パーセンタイル: 99.35

CVSS v2

リスクファクター: Medium

基本値: 6.8

現状値: 5.3

ベクトル: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS スコアのソース: CVE-2026-53059

CVSS v3

リスクファクター: High

基本値: 7.8

現状値: 7

ベクトル: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

現状ベクトル: CVSS:3.0/E:P/RL:O/RC:C

脆弱性情報

CPE: cpe:/o:novell:suse_linux:15, p-cpe:/a:novell:suse_linux:cluster-md-kmp-default, p-cpe:/a:novell:suse_linux:dlm-kmp-default, p-cpe:/a:novell:suse_linux:gfs2-kmp-default, p-cpe:/a:novell:suse_linux:kernel-64kb, p-cpe:/a:novell:suse_linux:kernel-default-base, p-cpe:/a:novell:suse_linux:kernel-default-livepatch, p-cpe:/a:novell:suse_linux:kernel-default, p-cpe:/a:novell:suse_linux:kernel-livepatch-5_14_21-150400_24_240-default, p-cpe:/a:novell:suse_linux:kernel-obs-build, p-cpe:/a:novell:suse_linux:kernel-source, p-cpe:/a:novell:suse_linux:kernel-zfcpdump, p-cpe:/a:novell:suse_linux:ocfs2-kmp-default, p-cpe:/a:novell:suse_linux:reiserfs-kmp-default

必要な KB アイテム: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list

エクスプロイトが利用可能: true

エクスプロイトの容易さ: Exploits are available

パッチ公開日: 2026/9/22

脆弱性公開日: 2021/7/21

参照情報

CVE: CVE-2023-53109, CVE-2024-57841, CVE-2026-23451, CVE-2026-31502, CVE-2026-43456, CVE-2026-43502, CVE-2026-45968, CVE-2026-52910, CVE-2026-52912, CVE-2026-52929, CVE-2026-52977, CVE-2026-53059, CVE-2026-53163, CVE-2026-53260, CVE-2026-53264, CVE-2026-53381, CVE-2026-53388, CVE-2026-63801, CVE-2026-63823, CVE-2026-63827, CVE-2026-63887, CVE-2026-63888, CVE-2026-63920, CVE-2026-63992, CVE-2026-64002, CVE-2026-64007, CVE-2026-64010, CVE-2026-64011, CVE-2026-64015, CVE-2026-64047, CVE-2026-64048, CVE-2026-64098, CVE-2026-64109, CVE-2026-64114, CVE-2026-64115, CVE-2026-64137, CVE-2026-64266, CVE-2026-64268, CVE-2026-64304, CVE-2026-64355, CVE-2026-64423, CVE-2026-64450, CVE-2026-64481, CVE-2026-64541, CVE-2026-64543, CVE-2026-64556, CVE-2026-64562, CVE-2026-64563, CVE-2026-64572, CVE-2026-64581, CVE-2026-64593, CVE-2026-68121, CVE-2026-68136, CVE-2026-68138, CVE-2026-68155, CVE-2026-68158, CVE-2026-68159, CVE-2026-68160, CVE-2026-68202, CVE-2026-68397, CVE-2026-68398, CVE-2026-68417, CVE-2026-68426, CVE-2026-68480, CVE-2026-72020, CVE-2026-72069, CVE-2026-72083, CVE-2026-72084, CVE-2026-72123, CVE-2026-72135, CVE-2026-72164, CVE-2026-72251, CVE-2026-72288, CVE-2026-72289, CVE-2026-72323, CVE-2026-72339, CVE-2026-72389, CVE-2026-74345, CVE-2026-74377, CVE-2026-74378, CVE-2026-74388, CVE-2026-74390, CVE-2026-74394, CVE-2026-74406, CVE-2026-74454, CVE-2026-74488, CVE-2026-74496, CVE-2026-74518, CVE-2026-74537, CVE-2026-74556, CVE-2026-74582, CVE-2026-74615, CVE-2026-74616, CVE-2026-74669, CVE-2026-74695, CVE-2026-74743, CVE-2026-80580, CVE-2026-80714, CVE-2026-80716, CVE-2026-80737, CVE-2026-80909

SuSE: SUSE-SU-2026:4284-1