AlmaLinux 9.6 [TuxCare] セキュリティ更新:kernel / kernel-abi-stablelists / kernel-core / etcの複数の脆弱性(ALMALINUX9.6:CLSA-2026:1787305050)

high Nessus プラグイン ID 352220

概要

AlmaLinuxホストに1つ以上のセキュリティ更新プログラムがありません。

説明

AlmaLinux 9.6 ホストには、TuxCare ALMALINUX9.6:CLSA-2026:1787305050アドバイザリに記載されている複数の脆弱性の影響を受けるパッケージがインストールされています。

- Linux カーネルでは、以下の脆弱性が解決されています: l2tp: prevent possible tunnel refcount underflow When a session is created, it sets a backpointer to its tunnel. When the session refcount drops to 0, l2tp_session_free drops the tunnel refcount if session->tunnel is non-NULL. However, session->tunnel is set in l2tp_session_create, before the tunnel refcount is incremented by l2tp_session_register, which leaves a small window where session->tunnel is non-NULL when the tunnel refcount hasn't been bumped.
Moving the assignment to l2tp_session_register is trivial but l2tp_session_create calls l2tp_session_set_header_len which uses session->tunnel to get the tunnel's encap. Add an encap arg to l2tp_session_set_header_len to avoid using session->tunnel. If l2tpv3 sessions have colliding IDs, it is possible for l2tp_v3_session_get to race with l2tp_session_register and fetch a session which doesn't yet have session->tunnel set. Add a check for this case. (CVE-2024-49940)

- Linux カーネルでは、以下の脆弱性が解決されています: mm/thp: fix deferred split unqueue naming and locking Recent changes are putting more pressure on THP deferred split queues: under load revealing long-standing races, causing list_del corruptions, Bad page states and worse (I keep BUGs in both of those, so usually don't get to see how badly they end up without). The relevant recent changes being 6.8's mTHP, 6.10's mTHP swapout, and 6.12's mTHP swapin, improved swap allocation, and underused THP splitting. Before fixing locking: rename misleading folio_undo_large_rmappable(), which does not undo large_rmappable, to folio_unqueue_deferred_split(), which is what it does. But that and its out-of-line
__callee are mm internals of very limited usability: add comment and WARN_ON_ONCEs to check usage; and return a bool to say if a deferred split was unqueued, which can then be used in WARN_ON_ONCEs around safety checks (sparing callers the arcane conditionals in __folio_unqueue_deferred_split()). Just omit the folio_unqueue_deferred_split() from free_unref_folios(), all of whose callers now call it beforehand (and if any forget then bad_page() will tell) - except for its caller put_pages_list(), which itself no longer has any callers (and will be deleted separately). Swapout: mem_cgroup_swapout() has been resetting folio->memcg_data 0 without checking and unqueueing a THP folio from deferred split list; which is unfortunate, since the split_queue_lock depends on the memcg (when memcg is enabled); so swapout has been unqueueing such THPs later, when freeing the folio, using the pgdat's lock instead: potentially corrupting the memcg's list. __remove_mapping() has frozen refcount to 0 here, so no problem with calling folio_unqueue_deferred_split() before resetting memcg_data. That goes back to 5.4 commit 87eaceb3faa5 (mm: thp: make deferred split shrinker memcg aware): which included a check on swapcache before adding to deferred queue, but no check on deferred queue before adding THP to swapcache. That worked fine with the usual sequence of events in reclaim (though there were a couple of rare ways in which a THP on deferred queue could have been swapped out), but 6.12 commit dafff3f4c850 (mm: split underused THPs) avoids splitting underused THPs in reclaim, which makes swapcache THPs on deferred queue commonplace. Keep the check on swapcache before adding to deferred queue? Yes: it is no longer essential, but preserves the existing behaviour, and is likely to be a worthwhile optimization (vmstat showed much more traffic on the queue under swapping load if the check was removed); update its comment. Memcg-v1 move (deprecated):
mem_cgroup_move_account() has been changing folio->memcg_data without checking and unqueueing a THP folio from the deferred list, sometimes corrupting from memcg's list, like swapout. Refcount is non-zero here, so folio_unqueue_deferred_split() can only be used in a WARN_ON_ONCE to validate the fix, which must be done earlier: mem_cgroup_move_charge_pte_range() first try to split the THP (splitting of course unqueues), or skip it if that fails. Not ideal, but moving charge has been requested, and khugepaged should repair the THP later: nobody wants new custom unqueueing code just for this deprecated case. The 87eaceb3faa5 commit did have the code to move from one deferred list to another (but was not conscious of its unsafety while refcount non-0); but that was removed by 5.6 commit fac0516b5534 (mm: thp: don't need care deferred split queue in memcg charge move path), which argued that the existence of a PMD mapping guarantees that the THP cannot be on a deferred list. As above, false in rare cases, and now commonly false. Backport to 6.11 should be straightforward. Earlier backports must take care that other
_deferred_list fixes and dependencies are included. There is not a strong case for backports, but they can fix cornercases. (CVE-2024-53079)

- Linux カーネルでは、以下の脆弱性が解決されています: io_uring/kbuf: reallocate buf lists on upgrade IORING_REGISTER_PBUF_RING can reuse an old struct io_buffer_list if it was created for legacy selected buffer and has been emptied. It violates the requirement that most of the field should stay stable after publish. Always reallocate it instead. (CVE-2025-21836)

- Linux カーネルでは、以下の脆弱性が解決されています: RDMA/bnxt_re: Add sanity checks on rdev validity There is a possibility that ulp_irq_stop and ulp_irq_start callbacks will be called when the device is in detached state. This can cause a crash due to NULL pointer dereference as the rdev is already freed. (CVE-2025-21901)

- Linux カーネルでは、以下の脆弱性が解決されています: cpufreq/amd-pstate: Add missing NULL ptr check in amd_pstate_update Check if policy is NULL before dereferencing it in amd_pstate_update.
(CVE-2025-23137)

Nessus はこれらの問題をテストしておらず、代わりにアプリケーションが自己報告するバージョン番号にのみ依存していることに注意してください。

ソリューション

TuxCareアドバイザリALMALINUX9.6:CLSA-2026:1787305050のガイダンスに基づいて、影響を受けるパッケージを更新してください。

参考資料

https://cve.tuxcare.com/els/releases/CLSA-2026:1787305050

http://www.nessus.org/u?58ac8a8b

プラグインの詳細

深刻度: High

ID: 352220

ファイル名: tuxcare_alma_linux_9.6_CLSA-2026-1787305050.nasl

バージョン: 1.1

タイプ: Local

公開日: 2026/9/30

更新日: 2026/9/30

サポートされているセンサー: Nessus Agent, Continuous Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

リスク情報

VPR

リスクファクター: High

スコア: 7.9

パーセンタイル: 99.36

Vendor

Vendor Severity: Important

CVSS v2

リスクファクター: Medium

基本値: 6.8

現状値: 5.3

ベクトル: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS スコアのソース: CVE-2026-64225

CVSS v3

リスクファクター: High

基本値: 7.8

現状値: 7

ベクトル: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

現状ベクトル: CVSS:3.0/E:P/RL:O/RC:C

脆弱性情報

必要な KB アイテム: Host/local_checks_enabled, Host/cpu, Host/AlmaLinux/release, Host/AlmaLinux/rpm-list, Host/OS/extended-third-party

エクスプロイトが利用可能: true

エクスプロイトの容易さ: Exploits are available

パッチ公開日: 2026/8/21

脆弱性公開日: 2024/10/21

参照情報

CVE: CVE-2024-49940, CVE-2024-53079, CVE-2025-21836, CVE-2025-21901, CVE-2025-23137, CVE-2025-23154, CVE-2025-37744, CVE-2025-39830, CVE-2025-39834, CVE-2025-39956, CVE-2025-39959, CVE-2025-39969, CVE-2025-39978, CVE-2025-40187, CVE-2025-40200, CVE-2025-40204, CVE-2025-68218, CVE-2025-68245, CVE-2025-68265, CVE-2025-68291, CVE-2025-68312, CVE-2025-68740, CVE-2025-68764, CVE-2025-71295, CVE-2026-23054, CVE-2026-23230, CVE-2026-23274, CVE-2026-23282, CVE-2026-23297, CVE-2026-23313, CVE-2026-31389, CVE-2026-31392, CVE-2026-31473, CVE-2026-31530, CVE-2026-31693, CVE-2026-31698, CVE-2026-31786, CVE-2026-43010, CVE-2026-43325, CVE-2026-43350, CVE-2026-43383, CVE-2026-43408, CVE-2026-43487, CVE-2026-45880, CVE-2026-45925, CVE-2026-46005, CVE-2026-46115, CVE-2026-46137, CVE-2026-46327, CVE-2026-52909, CVE-2026-52981, CVE-2026-53205, CVE-2026-53206, CVE-2026-53221, CVE-2026-53251, CVE-2026-53291, CVE-2026-53321, CVE-2026-64097, CVE-2026-64166, CVE-2026-64225, CVE-2026-64237, CVE-2026-64266, CVE-2026-64279, CVE-2026-64298, CVE-2026-64564, CVE-2026-68110, CVE-2026-68121, CVE-2026-68138, CVE-2026-68143, CVE-2026-68153, CVE-2026-68158, CVE-2026-68250, CVE-2026-68251, CVE-2026-68286, CVE-2026-68300, CVE-2026-68309, CVE-2026-68320, CVE-2026-68324, CVE-2026-68336, CVE-2026-68365, CVE-2026-68397, CVE-2026-68402, CVE-2026-68426, CVE-2026-68430, CVE-2026-68433, CVE-2026-68439, CVE-2026-68444

CLSA: 2026:1787305050