CentOS Linux 8.5 [TuxCare] セキュリティ更新プログラム:bpftool/kernel/kernel-core/kernel-cross-headers/etcの複数の脆弱性(CENTOS8.5:CLSA-2026:1768775579)

high Nessus プラグイン ID 353189

概要

CentOS Linuxホストに1つ以上のセキュリティ更新プログラムがありません。

説明

CentOS Linux 8.5 ホストには、TuxCare CENTOS8.5:CLSA-2026:1768775579アドバイザリに記載されている複数の脆弱性の影響を受けるパッケージがインストールされています。

-Linuxカーネル3.16~5.6.2までのdrivers/net/can/slcan.cのslc_bumpに問題が発見されました。そのため、構成からCONFIG_INIT_STACK_ALLが欠落していた場合に、攻撃者は初期化されていないcan_frameデータを読み取ることができます。データにはカーネルスタックメモリからの機密情報が含まれる可能性があります。(別名CID-b9258a2cece4)
(CVE-2020-11494)

- デバイスファイル「/dev/dri/renderD128 (または Dxxx)」を含む Linux カーネル内の GPU コンポーネントの drivers/gpu/vmxgfx/vmxgfx_kms.c の vmwgfx ドライバーに、領域外 (OOB) メモリアクセスの脆弱性が見つかりました。この欠陥により、システム上のユーザーアカウントを持つローカルの攻撃者が権限を取得し、サービス拒否 (DoS) を引き起こす可能性があります。(CVE-2022-36280)

- Linux カーネルでは、以下の脆弱性が解決されています: ath9k_htc: fix potential out of bounds access with invalid rxstatus->rs_keyix The rxstatus->rs_keyix eventually gets passed to test_bit() so we need to ensure that it is within the bitmap. drivers/net/wireless/ath/ath9k/common.c:46 ath9k_cmn_rx_accept() error: passing untrusted data 'rx_stats->rs_keyix' to 'test_bit()' (CVE-2022-49503)

- Linux カーネルでは、以下の脆弱性が解決されています: ata: libata-transport: fix double ata_host_put() in ata_tport_add() In the error path in ata_tport_add(), when calling put_device(), ata_tport_release() is called, it will put the refcount of 'ap->host'. And then ata_host_put() is called again, the refcount is decreased to 0, ata_host_release() is called, all ports are freed and set to null.
When unbinding the device after failure, ata_host_stop() is called to release the resources, it leads a null-ptr-deref(), because all the ports all freed and null. Unable to handle kernel NULL pointer dereference at virtual address 0000000000000008 CPU: 7 PID: 18671 Comm: modprobe Kdump: loaded Tainted: G E 6.1.0-rc3+ #8 pstate: 80400009 (Nzcv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--) pc :
ata_host_stop+0x3c/0x84 [libata] lr : release_nodes+0x64/0xd0 Call trace: ata_host_stop+0x3c/0x84 [libata] release_nodes+0x64/0xd0 devres_release_all+0xbc/0x1b0 device_unbind_cleanup+0x20/0x70 really_probe+0x158/0x320 __driver_probe_device+0x84/0x120 driver_probe_device+0x44/0x120
__driver_attach+0xb4/0x220 bus_for_each_dev+0x78/0xdc driver_attach+0x2c/0x40 bus_add_driver+0x184/0x240 driver_register+0x80/0x13c __pci_register_driver+0x4c/0x60 ahci_pci_driver_init+0x30/0x1000 [ahci] Fix this by removing redundant ata_host_put() in the error path. (CVE-2022-49826)

- Linux カーネルでは、以下の脆弱性が解決されています: capabilities: fix undefined behavior in bit shift for CAP_TO_MASK Shifting signed 32-bit value by 31 bits is undefined, so changing significant bit to unsigned. The UBSAN warning calltrace like below: UBSAN: shift-out-of-bounds in security/commoncap.c:1252:2 left shift of 1 by 31 places cannot be represented in type 'int' Call Trace:
<TASK> dump_stack_lvl+0x7d/0xa5 dump_stack+0x15/0x1b ubsan_epilogue+0xe/0x4e
__ubsan_handle_shift_out_of_bounds+0x1e7/0x20c cap_task_prctl+0x561/0x6f0 security_task_prctl+0x5a/0xb0
__x64_sys_prctl+0x61/0x8f0 do_syscall_64+0x58/0x80 entry_SYSCALL_64_after_hwframe+0x63/0xcd </TASK> (CVE-2022-49870)

Nessus はこれらの問題をテストしておらず、代わりにアプリケーションが自己報告するバージョン番号にのみ依存していることに注意してください。

ソリューション

TuxCareアドバイザリCENTOS8.5:CLSA-2026:1768775579のガイダンスに基づいて、影響を受けるパッケージを更新してください。

参考資料

https://cve.tuxcare.com/els/releases/CLSA-2026:1768775579

http://www.nessus.org/u?7dba2d2e

プラグインの詳細

深刻度: High

ID: 353189

ファイル名: tuxcare_centos_8.5_CLSA-2026-1768775579.nasl

バージョン: 1.2

タイプ: Local

エージェント: unix

公開日: 2026/9/30

更新日: 2026/10/1

サポートされているセンサー: Continuous Assessment, Nessus Agent, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

リスク情報

VPR

リスクファクター: High

スコア: 7.6

パーセンタイル: 98.59

Vendor

Vendor Severity: Important

CVSS v2

リスクファクター: Low

基本値: 2.1

現状値: 1.6

ベクトル: CVSS2#AV:L/AC:L/Au:N/C:P/I:N/A:N

CVSS スコアのソース: CVE-2020-11494

CVSS v3

リスクファクター: High

基本値: 7.8

現状値: 6.8

ベクトル: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

現状ベクトル: CVSS:3.0/E:U/RL:O/RC:C

CVSS スコアのソース: CVE-2025-38618

脆弱性情報

必要な KB アイテム: Host/OS/extended-third-party, Host/local_checks_enabled, Host/CentOS/release, Host/CentOS/rpm-list

エクスプロイトの容易さ: No known exploits are available

パッチ公開日: 2026/1/18

脆弱性公開日: 2020/4/2

参照情報

CVE: CVE-2020-11494, CVE-2022-36280, CVE-2022-49503, CVE-2022-49826, CVE-2022-49870, CVE-2022-49917, CVE-2022-49948, CVE-2022-50084, CVE-2022-50200, CVE-2022-50258, CVE-2022-50315, CVE-2022-50320, CVE-2022-50366, CVE-2022-50411, CVE-2022-50419, CVE-2022-50423, CVE-2022-50440, CVE-2022-50638, CVE-2022-50710, CVE-2022-50881, CVE-2023-53116, CVE-2023-53215, CVE-2023-53265, CVE-2023-53285, CVE-2023-53286, CVE-2023-53307, CVE-2023-53321, CVE-2023-53338, CVE-2023-53357, CVE-2023-53372, CVE-2023-53395, CVE-2023-53427, CVE-2023-53446, CVE-2023-53679, CVE-2023-53761, CVE-2023-53765, CVE-2023-53786, CVE-2023-53803, CVE-2023-53821, CVE-2023-53832, CVE-2023-54286, CVE-2024-27075, CVE-2024-46815, CVE-2025-38249, CVE-2025-38445, CVE-2025-38459, CVE-2025-38618, CVE-2025-40240

CLSA: 2026:1768775579