RockyLinux 10:カーネル(RLSA-2026:71602)

high Nessus プラグイン ID 350784

概要

リモート RockyLinux ホストに 1 つ以上のセキュリティ更新がありません。

説明

リモートのRockyLinux 10ホストには、RLSA-2026:71602アドバイザリに記載された複数の脆弱性の影響を受けるパッケージがインストールされています。

* カーネル:fbcon:モードがリリースされたときにfb_display[i]->modeをNULLに設定(CVE-2025-40323)

* kernel: libceph: have_mon_and_osd_map() における潜在的なメモリ解放後使用 (Use After Free) の問題を修正 (CVE-2025-68285)

* kernel: libceph: 破損した OSD マップに対応できるよう、decode_pool() の耐障害性を向上 (CVE-2025-71116)

* kernel: libceph: handle_auth_done() での領域外読み取りの可能性を防止 (CVE-2026-22984)

* kernel: libceph: osdmap_apply_incremental() の過剰な BUG_ON を置換 (CVE-2026-22990)

* kernel: Linux kernel: スパース読み取り状態がリセットされないことによる libceph OSD クライアントのサービス拒否 (CVE-2026-23136)

* カーネル:drm/amdgpu/vcn3:dec msg の解析時に OOB 読み取りを防止(CVE-2026-46230)

* カーネル:drm/amdgpu/vcn4:IB の解析時に OOB 読み取りを防止します(CVE-2026-46204)

* カーネル:drm/amdgpu/vcn4:dec msg の解析時に OOB 読み取りを防止(CVE-2026-46199)

* カーネル:drm/amdgpu/userq:古い wptr マッピングへのアクセスを修正します(CVE-2026-46311)

* カーネル:af_unix:SOCKMAP のすべての SCM 属性をドロップします(CVE-2026-53005)

* カーネル:accel/ivpu:MS get_info_ioctl でバッファオーバーフローチェックを追加します(CVE-2026-53203)

* カーネル:drm/xe/eustall:クローズでストリームが無効になる前に呼び出されるdrm_dev_putを修正します(CVE-2026-53290)

* カーネル:drm/virtio:プレーン更新に対して割り込み不可な resv ロックを使用します(CVE-2026-64098)

* カーネル:Linux カーネル:古いポインターによる PPPoE メモリ破損(CVE-2026-68121)

* カーネル:drm/amdgpu/vce:画像サイズの整数オーバーフローを修正します(CVE-2026-68108)

* カーネル:drm/amdkfd:CWSR 合計サイズ計算の 32 ビットオーバーフローを修正(CVE-2026-68257)

* カーネル:drm/xe/rtp:OA ホワイトリストにRING_FORCE_TO_NONPRIV_DENYを追加(CVE-2026-68267)

* カーネル:drm/xe:インポートされた BO の dma-buf 参照を保持します(CVE-2026-68266)

* カーネル:drm/amdgpu:コンテキスト pstate オーバーライド処理を修正します(CVE-2026-68273)

* カーネル:Linux カーネル IPVS:古いメモリ参照によるサービス拒否(CVE-2026-80714)

* カーネル:nvme-tcp:読み取りコマンド用の R2T におけるホストメモリ漏洩を修正します(CVE-2026-89481)

バグ修正と拡張機能:

* 事前にマップされたメモリに対するコヒーレントな割り当てのための DMA API をバイパスします [rhel-10.2.z](JIRA:Rocky Linux-252331)

Tenable は、前述の記述ブロックを RockyLinux セキュリティアドバイザリから直接抽出しています。

Nessus はこれらの問題をテストしておらず、代わりにアプリケーションが自己報告するバージョン番号にのみ依存していることに注意してください。

ソリューション

影響を受けるパッケージを更新してください。

参考資料

https://bugzilla.redhat.com/show_bug.cgi?id=2419883

https://bugzilla.redhat.com/show_bug.cgi?id=2422801

https://bugzilla.redhat.com/show_bug.cgi?id=2429602

https://bugzilla.redhat.com/show_bug.cgi?id=2432389

https://bugzilla.redhat.com/show_bug.cgi?id=2432400

https://bugzilla.redhat.com/show_bug.cgi?id=2439852

https://bugzilla.redhat.com/show_bug.cgi?id=2482533

https://bugzilla.redhat.com/show_bug.cgi?id=2482543

https://bugzilla.redhat.com/show_bug.cgi?id=2482649

https://bugzilla.redhat.com/show_bug.cgi?id=2486470

https://bugzilla.redhat.com/show_bug.cgi?id=2492381

https://bugzilla.redhat.com/show_bug.cgi?id=2492798

https://bugzilla.redhat.com/show_bug.cgi?id=2493739

https://bugzilla.redhat.com/show_bug.cgi?id=2502536

https://bugzilla.redhat.com/show_bug.cgi?id=2513233

https://bugzilla.redhat.com/show_bug.cgi?id=2513361

https://bugzilla.redhat.com/show_bug.cgi?id=2513372

https://bugzilla.redhat.com/show_bug.cgi?id=2513414

https://bugzilla.redhat.com/show_bug.cgi?id=2513429

https://bugzilla.redhat.com/show_bug.cgi?id=2513434

https://bugzilla.redhat.com/show_bug.cgi?id=2525436

https://bugzilla.redhat.com/show_bug.cgi?id=2532184

https://errata.rockylinux.org/RLSA-2026:71602

プラグインの詳細

深刻度: High

ID: 350784

ファイル名: rocky_linux_RLSA-2026-71602.nasl

バージョン: 1.1

タイプ: Local

公開日: 2026/9/26

更新日: 2026/9/26

サポートされているセンサー: Nessus Agent, Continuous Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

リスク情報

VPR

リスクファクター: High

スコア: 7.9

パーセンタイル: 99.35

CVSS v2

リスクファクター: Medium

基本値: 6.2

現状値: 4.9

ベクトル: CVSS2#AV:L/AC:L/Au:S/C:C/I:N/A:C

CVSS スコアのソース: CVE-2026-22984

CVSS v3

リスクファクター: High

基本値: 7.1

現状値: 6.4

ベクトル: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

現状ベクトル: CVSS:3.0/E:P/RL:O/RC:C

脆弱性情報

CPE: cpe:/o:rocky:linux:10, p-cpe:/a:rocky:linux:kernel-64k-core, p-cpe:/a:rocky:linux:kernel-64k-debug-core, p-cpe:/a:rocky:linux:kernel-64k-debug-debuginfo, p-cpe:/a:rocky:linux:kernel-64k-debug-devel-matched, p-cpe:/a:rocky:linux:kernel-64k-debug-devel, p-cpe:/a:rocky:linux:kernel-64k-debug-modules-core, p-cpe:/a:rocky:linux:kernel-64k-debug-modules-extra, p-cpe:/a:rocky:linux:kernel-64k-debug-modules, p-cpe:/a:rocky:linux:kernel-64k-debug, p-cpe:/a:rocky:linux:kernel-64k-debuginfo, p-cpe:/a:rocky:linux:kernel-64k-devel-matched, p-cpe:/a:rocky:linux:kernel-64k-devel, p-cpe:/a:rocky:linux:kernel-64k-modules-core, p-cpe:/a:rocky:linux:kernel-64k-modules-extra, p-cpe:/a:rocky:linux:kernel-64k-modules, p-cpe:/a:rocky:linux:kernel-64k, p-cpe:/a:rocky:linux:kernel-abi-stablelists, p-cpe:/a:rocky:linux:kernel-core, p-cpe:/a:rocky:linux:kernel-debug-core, p-cpe:/a:rocky:linux:kernel-debug-debuginfo, p-cpe:/a:rocky:linux:kernel-debug-devel-matched, p-cpe:/a:rocky:linux:kernel-debug-devel, p-cpe:/a:rocky:linux:kernel-debug-modules-core, p-cpe:/a:rocky:linux:kernel-debug-modules-extra, p-cpe:/a:rocky:linux:kernel-debug-modules, p-cpe:/a:rocky:linux:kernel-debug-uki-virt, p-cpe:/a:rocky:linux:kernel-debug, p-cpe:/a:rocky:linux:kernel-debuginfo-common-aarch64, p-cpe:/a:rocky:linux:kernel-debuginfo-common-ppc64le, p-cpe:/a:rocky:linux:kernel-debuginfo-common-s390x, p-cpe:/a:rocky:linux:kernel-debuginfo-common-x86_64, p-cpe:/a:rocky:linux:kernel-debuginfo, p-cpe:/a:rocky:linux:kernel-devel-matched, p-cpe:/a:rocky:linux:kernel-devel, p-cpe:/a:rocky:linux:kernel-modules-core, p-cpe:/a:rocky:linux:kernel-modules-extra-matched, p-cpe:/a:rocky:linux:kernel-modules-extra, p-cpe:/a:rocky:linux:kernel-modules, p-cpe:/a:rocky:linux:kernel-rt-64k-core, p-cpe:/a:rocky:linux:kernel-rt-64k-debug-core, p-cpe:/a:rocky:linux:kernel-rt-64k-debug-debuginfo, p-cpe:/a:rocky:linux:kernel-rt-64k-debug-devel, p-cpe:/a:rocky:linux:kernel-rt-64k-debug-modules-core, p-cpe:/a:rocky:linux:kernel-rt-64k-debug-modules-extra, p-cpe:/a:rocky:linux:kernel-rt-64k-debug-modules, p-cpe:/a:rocky:linux:kernel-rt-64k-debug, p-cpe:/a:rocky:linux:kernel-rt-64k-debuginfo, p-cpe:/a:rocky:linux:kernel-rt-64k-devel, p-cpe:/a:rocky:linux:kernel-rt-64k-modules-core, p-cpe:/a:rocky:linux:kernel-rt-64k-modules-extra, p-cpe:/a:rocky:linux:kernel-rt-64k-modules, p-cpe:/a:rocky:linux:kernel-rt-64k, p-cpe:/a:rocky:linux:kernel-rt-core, p-cpe:/a:rocky:linux:kernel-rt-debug-core, p-cpe:/a:rocky:linux:kernel-rt-debug-debuginfo, p-cpe:/a:rocky:linux:kernel-rt-debug-devel, p-cpe:/a:rocky:linux:kernel-rt-debug-modules-core, p-cpe:/a:rocky:linux:kernel-rt-debug-modules-extra, p-cpe:/a:rocky:linux:kernel-rt-debug-modules, p-cpe:/a:rocky:linux:kernel-rt-debug, p-cpe:/a:rocky:linux:kernel-rt-debuginfo, p-cpe:/a:rocky:linux:kernel-rt-devel, p-cpe:/a:rocky:linux:kernel-rt-modules-core, p-cpe:/a:rocky:linux:kernel-rt-modules-extra, p-cpe:/a:rocky:linux:kernel-rt-modules, p-cpe:/a:rocky:linux:kernel-rt, p-cpe:/a:rocky:linux:kernel-tools-debuginfo, p-cpe:/a:rocky:linux:kernel-tools-libs-devel, p-cpe:/a:rocky:linux:kernel-tools-libs, p-cpe:/a:rocky:linux:kernel-tools, p-cpe:/a:rocky:linux:kernel-uki-virt-addons, p-cpe:/a:rocky:linux:kernel-uki-virt, p-cpe:/a:rocky:linux:kernel-zfcpdump-core, p-cpe:/a:rocky:linux:kernel-zfcpdump-debuginfo, p-cpe:/a:rocky:linux:kernel-zfcpdump-devel-matched, p-cpe:/a:rocky:linux:kernel-zfcpdump-devel, p-cpe:/a:rocky:linux:kernel-zfcpdump-modules-core, p-cpe:/a:rocky:linux:kernel-zfcpdump-modules-extra, p-cpe:/a:rocky:linux:kernel-zfcpdump-modules, p-cpe:/a:rocky:linux:kernel-zfcpdump, p-cpe:/a:rocky:linux:kernel, p-cpe:/a:rocky:linux:libperf-debuginfo, p-cpe:/a:rocky:linux:libperf, p-cpe:/a:rocky:linux:perf-debuginfo, p-cpe:/a:rocky:linux:perf, p-cpe:/a:rocky:linux:python3-perf-debuginfo, p-cpe:/a:rocky:linux:python3-perf, p-cpe:/a:rocky:linux:rtla, p-cpe:/a:rocky:linux:rv

必要な KB アイテム: Host/local_checks_enabled, Host/cpu, Host/RockyLinux/release, Host/RockyLinux/rpm-list

エクスプロイトが利用可能: true

エクスプロイトの容易さ: Exploits are available

パッチ公開日: 2026/9/26

脆弱性公開日: 2025/12/8

参照情報

CVE: CVE-2025-40323, CVE-2025-68285, CVE-2025-71116, CVE-2026-22984, CVE-2026-22990, CVE-2026-23136, CVE-2026-46199, CVE-2026-46204, CVE-2026-46230, CVE-2026-46311, CVE-2026-53005, CVE-2026-53203, CVE-2026-53290, CVE-2026-64098, CVE-2026-68108, CVE-2026-68121, CVE-2026-68257, CVE-2026-68266, CVE-2026-68267, CVE-2026-68273, CVE-2026-80714, CVE-2026-89481