AlmaLinux 9.2 [TuxCare] セキュリティ更新プログラム:bpftool/kernel/kernel-abi-stablelists/kernel-core/etcの複数の脆弱性(ALMALINUX9.2:CLSA-2024:1728936982)

high Nessus プラグイン ID 353076

概要

AlmaLinuxホストに1つ以上のセキュリティ更新プログラムがありません。

説明

AlmaLinux 9.2 ホストには、TuxCare ALMALINUX9.2:CLSA-2024:1728936982アドバイザリに記載されている複数の脆弱性の影響を受けるパッケージがインストールされています。

- Linux カーネルでは、以下の脆弱性が解決されています: tty: Fix out-of-bound vmalloc access in imageblit This issue happens when a userspace program does an ioctl FBIOPUT_VSCREENINFO passing the fb_var_screeninfo struct containing only the fields xres, yres, and bits_per_pixel with values. If this struct is the same as the previous ioctl, the vc_resize() detects it and doesn't call the resize_screen(), leaving the fb_var_screeninfo incomplete. And this leads to the updatescrollmode() calculates a wrong value to fbcon_display->vrows, which makes the real_y() return a wrong value of y, and that value, eventually, causes the imageblit to access an out-of-bound address value. To solve this issue I made the resize_screen() be called even if the screen does not need any resizing, so it will fix and fill the fb_var_screeninfo independently. (CVE-2021-47383)

- Linux カーネルでは、以下の脆弱性が解決されています: seg6: fix the iif in the IPv6 socket control block When an IPv4 packet is received, the ip_rcv_core(...) sets the receiving interface index into the IPv4 socket control block (v5.16-rc4, net/ipv4/ip_input.c line 510): IPCB(skb)->iif = skb->skb_iif; If that IPv4 packet is meant to be encapsulated in an outer IPv6+SRH header, the seg6_do_srh_encap(...) performs the required encapsulation. In this case, the seg6_do_srh_encap function clears the IPv6 socket control block (v5.16-rc4 net/ipv6/seg6_iptunnel.c line 163): memset(IP6CB(skb), 0, sizeof(*IP6CB(skb))); The memset(...) was introduced in commit ef489749aae5 (ipv6: sr: clear IP6CB(skb) on SRH ip4ip6 encapsulation) a long time ago (2019-01-29). Since the IPv6 socket control block and the IPv4 socket control block share the same memory area (skb->cb), the receiving interface index info is lost (IP6CB(skb)->iif is set to zero). As a side effect, that condition triggers a NULL pointer dereference if commit 0857d6f8c759 (ipv6: When forwarding count rx stats on the orig netdev) is applied. To fix that issue, we set the IP6CB(skb)->iif with the index of the receiving interface once again. (CVE-2021-47515)

- Linux カーネルの cxgb4 ドライバーにメモリ解放後使用 (Use After Free) の脆弱性が見つかりました。このバグは、cxgb4 デバイスがワークキューからの flallow_stats_timer の再設定の可能性があることによりデタッチされるときに発生します。この欠陥により、ローカルユーザーがシステムをクラッシュさせ、サービス拒否状態を引き起こす可能性があります。(CVE-2023-4133)

- Linux カーネルの TUN/TAP 機能に欠陥が見つかりました。この問題により、ローカルユーザーはネットワークフィルターをバイパスし、一部のリソースへの認証されていないアクセスを取得する可能性があります。CVE-2023-1076 を修正する元のパッチは、不適切または不完全です。問題は、以下の Upstream がコミットすることです - a096ccca6e50 (tun: tun_chr_open(): がソケット uid を正しく初期化する)、- 66b2c338adce (tap: tap_open():
がソケット uid を正しく初期化)、inode->i_uid を最後のパラメーターとして sock_init_data_uid() に渡すことですが、これは正確ではありません。(CVE-2023-4194)

- Linux カーネルでは、以下の脆弱性が解決されています: bpf, sockmap: Don't let sock_map_{close,destroy,unhash} call itself sock_map proto callbacks should never call themselves by design. Protect against bugs like [1] and break out of the recursive loop to avoid a stack overflow in favor of a resource leak. [1] https://lore.kernel.org/all/[email protected]/(CVE-2023-52735)

Nessus はこれらの問題をテストしておらず、代わりにアプリケーションが自己報告するバージョン番号にのみ依存していることに注意してください。

ソリューション

TuxCareアドバイザリALMALINUX9.2:CLSA-2024:1728936982のガイダンスに基づいて、影響を受けるパッケージを更新してください。

参考資料

https://cve.tuxcare.com/els/releases/CLSA-2024:1728936982

http://www.nessus.org/u?73bc96f8

プラグインの詳細

深刻度: High

ID: 353076

ファイル名: tuxcare_alma_linux_9.2_CLSA-2024-1728936982.nasl

バージョン: 1.1

タイプ: Local

公開日: 2026/9/30

更新日: 2026/9/30

サポートされているセンサー: Continuous Assessment, Nessus Agent, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

リスク情報

VPR

リスクファクター: High

スコア: 7.6

パーセンタイル: 98.67

Vendor

Vendor Severity: Important

CVSS v2

リスクファクター: Medium

基本値: 6.8

現状値: 5

ベクトル: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS スコアのソース: CVE-2024-46859

CVSS v3

リスクファクター: High

基本値: 7.8

現状値: 6.8

ベクトル: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

現状ベクトル: CVSS:3.0/E:U/RL:O/RC:C

脆弱性情報

必要な KB アイテム: Host/OS/extended-third-party, Host/local_checks_enabled, Host/AlmaLinux/release, Host/AlmaLinux/rpm-list, Host/cpu

エクスプロイトの容易さ: No known exploits are available

パッチ公開日: 2024/10/14

脆弱性公開日: 2021/7/21

参照情報

CVE: CVE-2021-47383, CVE-2021-47515, CVE-2023-4133, CVE-2023-4194, CVE-2023-52651, CVE-2023-52735, CVE-2023-52880, CVE-2023-52884, CVE-2024-26629, CVE-2024-26665, CVE-2024-26737, CVE-2024-26853, CVE-2024-26855, CVE-2024-26931, CVE-2024-26946, CVE-2024-27016, CVE-2024-27030, CVE-2024-27046, CVE-2024-27052, CVE-2024-27415, CVE-2024-35789, CVE-2024-35791, CVE-2024-35845, CVE-2024-35852, CVE-2024-35895, CVE-2024-35898, CVE-2024-36025, CVE-2024-36899, CVE-2024-36941, CVE-2024-36979, CVE-2024-38559, CVE-2024-38562, CVE-2024-38579, CVE-2024-38588, CVE-2024-38601, CVE-2024-38619, CVE-2024-38627, CVE-2024-39476, CVE-2024-40905, CVE-2024-40911, CVE-2024-40912, CVE-2024-40914, CVE-2024-40927, CVE-2024-40929, CVE-2024-40941, CVE-2024-40978, CVE-2024-40983, CVE-2024-40995, CVE-2024-41013, CVE-2024-41023, CVE-2024-41039, CVE-2024-41041, CVE-2024-41044, CVE-2024-41071, CVE-2024-41076, CVE-2024-41096, CVE-2024-42082, CVE-2024-42096, CVE-2024-42110, CVE-2024-42131, CVE-2024-42136, CVE-2024-42148, CVE-2024-42152, CVE-2024-42243, CVE-2024-43882, CVE-2024-46700, CVE-2024-46722, CVE-2024-46723, CVE-2024-46724, CVE-2024-46725, CVE-2024-46731, CVE-2024-46738, CVE-2024-46743, CVE-2024-46744, CVE-2024-46746, CVE-2024-46747, CVE-2024-46756, CVE-2024-46757, CVE-2024-46758, CVE-2024-46759, CVE-2024-46800, CVE-2024-46811, CVE-2024-46813, CVE-2024-46818, CVE-2024-46821, CVE-2024-46859

CLSA: 2024:1728936982