Rocky Linux 10 [CIQ] セキュリティ更新:kernel / kernel-64k / kernel-64k-core / kernel-64k-debug / etc 複数の脆弱性(crlsa-2025_20095)

medium Nessus プラグイン ID 358707

概要

Rocky Linuxホストに1つ以上のセキュリティ更新プログラムがありません。

説明

Rocky Linux 10ホストには、CIQ crlsa-2025_20095 アドバイザリに記載された複数の脆弱性の影響を受けるパッケージがインストールされています。

* kernel: xen: 投機的攻撃に対して安全でない Xen ハイパーコールページ (Xen セキュリティアドバイザリ 466) (CVE-2024-53241)

* カーネル:exfat:ディレクトリエントリの領域外アクセスを修正(CVE-2024-53147)

* kernel: zram: comp_algorithm_show() の NULL ポインターを修正 (CVE-2024-53222)

* kernel: rcu_work のある svc_expkey/svc_export を解放します (CVE-2024-53216)

* kernel: acpi: nfit: acpi_nfit_ctl での vmalloc-out-of-bounds 読み取り (CVE-2024-56662)

* kernel: bpf: bpf_prog/attachment RCU フレーバーの不一致により UAF を修正 (CVE-2024-56675)

* kernel: crypto: pcrypt - padata_do_parallel() が -EBUSY を返すときに暗号レイヤーを直接呼び出す (CVE-2024-56690)

* kernel: igb: igb_init_module() の潜在的な無効なメモリアクセスを修正 (CVE-2024-52332)

* カーネル:af_packet:vlan_get_protocol_dgram() vs MSG_PEEK(CVE-2024-57901)を修正

* カーネル:af_packet:vlan_get_tci() vs MSG_PEEK(CVE-2024-57902)を修正

* kernel: io_uring/sqpoll: tctx エラーの sqd->thread をゼロにします (CVE-2025-21633)

* カーネル:ipvlan:ipvlan_get_iflink() の use-after-free を修正します。(CVE-2025-21652)

* kernel: sched: sch_cake: ホストのバルクフロー公平性カウントに領域チェックを追加 (CVE-2025-21647)

* カーネル:io_uring/eventfd:io_eventfd_signal() が別の RCU 期間を延期することを保証します(CVE-2025-21655)

* カーネル:netfs:キャッシュが一時的に無効になっているときのコピーの(非)キャンセルを修正します(CVE-2024-57941)

* カーネル:netfs:write-begin でキャッシュするために ceph のコピーを修正します(CVE-2024-57942)

* kernel: zram: zram テーブルの潜在的な UAF を修正 (CVE-2025-21671)

* カーネル:pktgen:get_imix_entries での領域外アクセスを回避します(CVE-2025-21680)

* kernel: mm: zswap: CPU のホットアンプラグ中に解放中のリソースを適切に同期 (CVE-2025-21693)

* kernel: cachestat: ページキャッシュ統計権限チェックを修正 (CVE-2025-21691)

* kernel: mm: mremap() の uffd-wp PTE/PMD 状態をクリアします (CVE-2025-21696)

* kernel: pfifo_tail_enqueue: sch->limit == 0 の場合、新しいパケットをドロップします (CVE-2025-21702)

* カーネル:RDMA/mlx5:エラーを伴う CQE につながる ODP MR の競合を修正します(CVE-2025-21732)

* kernel: NFSD: nfsd4_shutdown_callback のハングアップを修正 (CVE-2025-21795)

* kernel: NFS: nfs_sysfs_link_rpc_client() の潜在的なバッファオーバーフローを修正 (CVE-2024-54456)

* kernel: Bluetooth: btrtl: btrtl_setup_realtek() で NULL をチェック (CVE-2024-57987)

* kernel: wifi: brcmsmac: wlc_phy_iqcal_gainparams_nphy() にゲイン範囲チェックを追加 (CVE-2024-58014)

* kernel: Bluetooth: btbcm: btbcm_get_board_name() の NULL デリファレンスを修正 (CVE-2024-57988)

* kernel: drm/xe/tracing: 潜在的な TP_printk UAF を修正 (CVE-2024-49570)

* カーネル:メディア:intel/ipu6:エラー時の CPU レイテンシ QoS リクエストを削除します(CVE-2024-58004)

* カーネル:usbnet:ipheth:URB の静的 NDP16 位置を使用(CVE-2025-21742)

* カーネル:usbnet:ipheth:DPE の長さチェックの潜在的なオーバーフローを修正します(CVE-2025-21743)

* kernel: wifi: mt76: mt7925: mt7925_change_vif_links の NULL デリファレンスチェックを修正 (CVE-2024-57989)

* kernel: wifi: ath12k: 領域外アクセスエラーの修正 (CVE-2024-58015)

* kernel: wifi: ath12k: ath12k_mac_assign_vif_to_vdev() における解放後の読み込みポインターを修正 (CVE-2024-57995)

* kernel: nfsd: acl_access/acl_default の解放後に、それらをクリア (CVE-2025-21796)

* kernel: workqueue: プールから rescuer をデタッチした後に pwq を配置 (CVE-2025-21786)

* kernel: tpm: eventlog/acpi.c において kvalloc() に変更 (CVE-2024-58005)

* カーネル:Bluetooth:MGMT:mgmt_remove_adv_monitor_sync における slab-use-after-free 読み取りを修正します(CVE-2024-58013)

* カーネル:ring-buffer:永続メタデータ subbuf 配列を検証します(CVE-2025-21777)

* kernel: ata: libata-sff: 割り当てられたバッファ外に書き込めないことを確認する (CVE-2025-21738)

* kernel: HID: core: 解像度乗数が論理コレクション内にあるという前提を修正 (CVE-2024-57986)

* kernel: padata: reorder_work に対する UAF を回避 (CVE-2025-21726)

* kernel: vrf: l3mdev_l3_out() で RCU 保護を使用 (CVE-2025-21791)

* カーネル:HID:multitouch:mt_input_configured で NULL チェックを追加します(CVE-2024-58020)

* カーネル:i3c:dw:競合状態による dw_i3c_master ドライバーの use-after-free を修正します(CVE-2024-57984)

* カーネル:openvswitch:ovs_vport_cmd_fill_info() で RCU 保護を使用します(CVE-2025-21761)

* カーネル:sched_ext:不適切な自動グループ移行検出を修正します(CVE-2025-21771)

* kernel: usb: xhci: 特定のコマンド中断時に発生する NULL ポインターデリファレンスを修正 (CVE-2024-57981)

* カーネル:memcg:OOM プロセスのソフトロックアップを修正します(CVE-2024-57977)

* kernel: vxlan: vxlan_vnigroup_init() の戻り値をチェック (CVE-2025-21790)

* カーネル:usbnet:ipheth:DPE OoB 読み取りを修正します(CVE-2025-21741)

* kernel: arm64: cacheinfo: cacheinfo 配列への領域外書き込みを回避 (CVE-2025-21785)

* kernel: ipv6: ip6_default_advmss() で RCU 保護を使用 (CVE-2025-21765)

* カーネル:PCI:dwc:ep:pci_epc_set_bar() の BAR サイズ/フラグの変更を防止します(CVE-2024-58006)

* kernel: ASoC: SOF: Intel: hda-dai: DAI ウィジェットが params 中に有効であることを確認 (CVE-2024-58012)

*カーネル:wifi:brcmfmac:of_property_read_string_index()の戻り値をチェック(CVE-2025-21750)

* kernel: wifi: rtlwifi: 未使用の check_buddy_priv を削除 (CVE-2024-58072)

* kernel: rtc: pcf85063: PCF85063 NVMEM 読み取りでの潜在的な OOB 書き込みを修正 (CVE-2024-58069)

* カーネル:wifi:mac80211:無効化全てのリンクを禁止(CVE-2024-58061)

* kernel: idpf: workqueue を unbound に変換 (CVE-2024-58057)

* kernel: wifi: mac80211: アップロードされていない STA をフラッシュしない (CVE-2025-21828)

* kernel: netfilter: 設定されているキー長と field_len の合計が一致しない場合は、拒否するように修正 (CVE-2025-21826)

* kernel: ASoC: soc-pcm: .prepare コールバックで soc_pcm_ret() を使用しない (CVE-2024-58077)

* kernel: crypto: tegra - tegra init が失敗した場合に req を転送しない (CVE-2024-58075)

* kernel: io_uring/uring_cmd: 準備時に SQE を無条件にコピー (CVE-2025-21837)

* kernel: 一部の AMD プロセッサでの一時的な実行の脆弱性による情報漏洩 (CVE-2024-36350)

* kernel: 一部の AMD プロセッサでの一時的な実行の脆弱性 (CVE-2024-36357)

* kernel:net/sched:cls_api:NULL デリファレンスを引き起こすエラー処理を修正(CVE-2025-21857)

* kernel: bpf: 64k ページカーネルでの arena_map_free でのソフトロックアップを修正 (CVE-2025-21851)

* kernel: ibmvnic: VIOS への送信後 skb を参照しない (CVE-2025-21855)

* kernel: smb: client: receive_encrypted_standard() の next_buffer にチェックを追加 (CVE-2025-21844)

* kernel: bpf: mmap 操作中の freeze_mutex の保持を回避 (CVE-2025-21853)

* kernel: ASoC: SOF: stream-ipc: sof_ipc_msg_data() で cstream がヌルでないかチェック (CVE-2025-21847)

* kernel: tcp: 現在のドロップ dst と同時に secpath をドロップ (CVE-2025-21864)

* kernel: bpf: cgroup ストレージを解放する際のデッドロックを修正 (CVE-2024-58088)

* kernel: acct: 最後の書き込みをワークキューから実行 (CVE-2025-21846)

* kernel: mm/migrate_device: migrate_device_finalize() の LRU に解放される folio を追加しない (CVE-2025-21861)

* kernel: io_uring: io_uring: opcode の投機を阻止 (CVE-2025-21863)

* カーネル:fbdev:hyperv_fb:フレームバッファの緩やかな削除を許可します(CVE-2025-21976)

* kernel: netfilter: nft_tunnel: geneve_opt の型を混同した追加を修正 (CVE-2025-22056)

* kernel: net: ppp: ppp_sync_txmung の skb データのバインドチェックを追加します (CVE-2025-37749)

* microcode_ctl: CVEorg コレクターから (CVE-2024-28956)

* kernel: usb: typec: ucsi: displayport: NULL ポインターアクセスを修正 (CVE-2025-37994)

* kernel: wifi: ath12k: ath12k_core_init() の uaf を修正 (CVE-2025-38116)

* カーネル:platform/x86:dell-wmi-sysman:sysfs コールバックでの WMI データブロック取得を修正します(CVE-2025-38412)

* カーネル:dmaengine:idxd:使用する前に、idxd wq ドライバーによって割り当てられた作業キューの可用性をチェックします(CVE-2025-38369)

* カーネル:net/sched:htb_lookup_leafが空のrbtreeに遭遇した場合はNULLを返します(CVE-2025-38468)

Tenableは、前述の記述ブロックをCIQセキュリティアドバイザリから直接抽出しています。

Nessus はこれらの問題をテストしておらず、代わりにアプリケーションが自己報告するバージョン番号にのみ依存していることに注意してください。

ソリューション

CIQアドバイザリ crlsa-2025_20095のガイダンスに基づいて、影響を受けるパッケージを更新してください。

参考資料

https://access.redhat.com/errata/RHSA-2025:20095

https://bugzilla.redhat.com/show_bug.cgi?id=2331326

https://bugzilla.redhat.com/show_bug.cgi?id=2333985

https://bugzilla.redhat.com/show_bug.cgi?id=2334373

https://bugzilla.redhat.com/show_bug.cgi?id=2334415

https://bugzilla.redhat.com/show_bug.cgi?id=2334547

https://bugzilla.redhat.com/show_bug.cgi?id=2334548

https://bugzilla.redhat.com/show_bug.cgi?id=2334676

https://bugzilla.redhat.com/show_bug.cgi?id=2337121

https://bugzilla.redhat.com/show_bug.cgi?id=2338185

https://bugzilla.redhat.com/show_bug.cgi?id=2338211

https://bugzilla.redhat.com/show_bug.cgi?id=2338813

https://bugzilla.redhat.com/show_bug.cgi?id=2338821

https://bugzilla.redhat.com/show_bug.cgi?id=2338828

https://bugzilla.redhat.com/show_bug.cgi?id=2338998

https://bugzilla.redhat.com/show_bug.cgi?id=2339130

https://bugzilla.redhat.com/show_bug.cgi?id=2339141

https://bugzilla.redhat.com/show_bug.cgi?id=2343172

https://bugzilla.redhat.com/show_bug.cgi?id=2343186

https://bugzilla.redhat.com/show_bug.cgi?id=2344684

https://bugzilla.redhat.com/show_bug.cgi?id=2344687

https://bugzilla.redhat.com/show_bug.cgi?id=2345240

https://bugzilla.redhat.com/show_bug.cgi?id=2346272

https://bugzilla.redhat.com/show_bug.cgi?id=2348522

https://bugzilla.redhat.com/show_bug.cgi?id=2348523

https://bugzilla.redhat.com/show_bug.cgi?id=2348541

https://bugzilla.redhat.com/show_bug.cgi?id=2348543

https://bugzilla.redhat.com/show_bug.cgi?id=2348547

https://bugzilla.redhat.com/show_bug.cgi?id=2348550

https://bugzilla.redhat.com/show_bug.cgi?id=2348556

https://bugzilla.redhat.com/show_bug.cgi?id=2348561

https://bugzilla.redhat.com/show_bug.cgi?id=2348567

https://bugzilla.redhat.com/show_bug.cgi?id=2348572

https://bugzilla.redhat.com/show_bug.cgi?id=2348574

https://bugzilla.redhat.com/show_bug.cgi?id=2348577

https://bugzilla.redhat.com/show_bug.cgi?id=2348581

https://bugzilla.redhat.com/show_bug.cgi?id=2348584

https://bugzilla.redhat.com/show_bug.cgi?id=2348587

https://bugzilla.redhat.com/show_bug.cgi?id=2348590

https://bugzilla.redhat.com/show_bug.cgi?id=2348592

https://bugzilla.redhat.com/show_bug.cgi?id=2348593

https://bugzilla.redhat.com/show_bug.cgi?id=2348595

https://bugzilla.redhat.com/show_bug.cgi?id=2348597

https://bugzilla.redhat.com/show_bug.cgi?id=2348600

https://bugzilla.redhat.com/show_bug.cgi?id=2348601

https://bugzilla.redhat.com/show_bug.cgi?id=2348602

https://bugzilla.redhat.com/show_bug.cgi?id=2348603

https://bugzilla.redhat.com/show_bug.cgi?id=2348612

https://bugzilla.redhat.com/show_bug.cgi?id=2348617

https://bugzilla.redhat.com/show_bug.cgi?id=2348620

https://bugzilla.redhat.com/show_bug.cgi?id=2348621

https://bugzilla.redhat.com/show_bug.cgi?id=2348625

https://bugzilla.redhat.com/show_bug.cgi?id=2348629

https://bugzilla.redhat.com/show_bug.cgi?id=2348630

https://bugzilla.redhat.com/show_bug.cgi?id=2348645

https://bugzilla.redhat.com/show_bug.cgi?id=2348647

https://bugzilla.redhat.com/show_bug.cgi?id=2348650

https://bugzilla.redhat.com/show_bug.cgi?id=2348656

https://bugzilla.redhat.com/show_bug.cgi?id=2350363

https://bugzilla.redhat.com/show_bug.cgi?id=2350364

https://bugzilla.redhat.com/show_bug.cgi?id=2350373

https://bugzilla.redhat.com/show_bug.cgi?id=2350375

https://bugzilla.redhat.com/show_bug.cgi?id=2350386

https://bugzilla.redhat.com/show_bug.cgi?id=2350392

https://bugzilla.redhat.com/show_bug.cgi?id=2350396

https://bugzilla.redhat.com/show_bug.cgi?id=2350397

https://bugzilla.redhat.com/show_bug.cgi?id=2350589

https://bugzilla.redhat.com/show_bug.cgi?id=2350725

https://bugzilla.redhat.com/show_bug.cgi?id=2350726

https://bugzilla.redhat.com/show_bug.cgi?id=2351605

https://bugzilla.redhat.com/show_bug.cgi?id=2351606

https://bugzilla.redhat.com/show_bug.cgi?id=2351608

https://bugzilla.redhat.com/show_bug.cgi?id=2351612

https://bugzilla.redhat.com/show_bug.cgi?id=2351613

https://bugzilla.redhat.com/show_bug.cgi?id=2351616

https://bugzilla.redhat.com/show_bug.cgi?id=2351618

https://bugzilla.redhat.com/show_bug.cgi?id=2351620

https://bugzilla.redhat.com/show_bug.cgi?id=2351624

https://bugzilla.redhat.com/show_bug.cgi?id=2351625

https://bugzilla.redhat.com/show_bug.cgi?id=2351629

https://bugzilla.redhat.com/show_bug.cgi?id=2356641

https://bugzilla.redhat.com/show_bug.cgi?id=2356647

https://bugzilla.redhat.com/show_bug.cgi?id=2356664

https://bugzilla.redhat.com/show_bug.cgi?id=2360215

https://bugzilla.redhat.com/show_bug.cgi?id=2363332

https://bugzilla.redhat.com/show_bug.cgi?id=2366125

https://bugzilla.redhat.com/show_bug.cgi?id=2369184

https://bugzilla.redhat.com/show_bug.cgi?id=2376076

https://bugzilla.redhat.com/show_bug.cgi?id=2383398

https://bugzilla.redhat.com/show_bug.cgi?id=2383432

https://bugzilla.redhat.com/show_bug.cgi?id=2383913

https://errata.build.resf.org/RLSA-2025:20095

http://www.nessus.org/u?282e3380

http://www.nessus.org/u?cfa7e99c

プラグインの詳細

深刻度: Medium

ID: 358707

ファイル名: ciq_rocky_linux_10_crlsa-2025_20095.nasl

バージョン: 1.2

タイプ: Local

公開日: 2026/10/1

更新日: 2026/10/2

サポートされているセンサー: Continuous Assessment, Nessus Agent, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

リスク情報

VPR

リスクファクター: High

スコア: 7

パーセンタイル: 98.48

Vendor

Vendor Severity: Unknown

CVSS v2

リスクファクター: Medium

基本値: 6.8

現状値: 5

ベクトル: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS スコアのソース: CVE-2025-38369

CVSS v3

リスクファクター: High

基本値: 7.8

現状値: 6.8

ベクトル: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

現状ベクトル: CVSS:3.0/E:U/RL:O/RC:C

CVSS v4

リスクファクター: Medium

Base Score: 5.7

Threat Score: 1.9

Threat Vector: CVSS:4.0/E:U

Vector: CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

CVSS スコアのソース: CVE-2024-28956

脆弱性情報

必要な KB アイテム: Host/OS/extended-third-party, Host/local_checks_enabled, Host/RockyLinux/release, Host/RockyLinux/rpm-list, Host/cpu

エクスプロイトの容易さ: No known exploits are available

パッチ公開日: 2025/11/27

脆弱性公開日: 2023/12/12

参照情報

CVE: CVE-2024-28956, CVE-2024-36350, CVE-2024-36357, CVE-2024-49570, CVE-2024-52332, CVE-2024-53147, CVE-2024-53216, CVE-2024-53222, CVE-2024-53241, CVE-2024-54456, CVE-2024-56662, CVE-2024-56675, CVE-2024-56690, CVE-2024-57901, CVE-2024-57902, CVE-2024-57941, CVE-2024-57942, CVE-2024-57977, CVE-2024-57981, CVE-2024-57984, CVE-2024-57986, CVE-2024-57987, CVE-2024-57988, CVE-2024-57989, CVE-2024-57995, CVE-2024-58004, CVE-2024-58005, CVE-2024-58006, CVE-2024-58012, CVE-2024-58013, CVE-2024-58014, CVE-2024-58015, CVE-2024-58020, CVE-2024-58057, CVE-2024-58061, CVE-2024-58069, CVE-2024-58072, CVE-2024-58075, CVE-2024-58077, CVE-2024-58088, CVE-2025-21633, CVE-2025-21647, CVE-2025-21652, CVE-2025-21655, CVE-2025-21671, CVE-2025-21680, CVE-2025-21691, CVE-2025-21693, CVE-2025-21696, CVE-2025-21702, CVE-2025-21726, CVE-2025-21732, CVE-2025-21738, CVE-2025-21741, CVE-2025-21742, CVE-2025-21743, CVE-2025-21750, CVE-2025-21761, CVE-2025-21765, CVE-2025-21771, CVE-2025-21777, CVE-2025-21785, CVE-2025-21786, CVE-2025-21790, CVE-2025-21791, CVE-2025-21795, CVE-2025-21796, CVE-2025-21826, CVE-2025-21828, CVE-2025-21837, CVE-2025-21844, CVE-2025-21846, CVE-2025-21847, CVE-2025-21851, CVE-2025-21853, CVE-2025-21855, CVE-2025-21857, CVE-2025-21861, CVE-2025-21863, CVE-2025-21864, CVE-2025-21902, CVE-2025-21931, CVE-2025-21976, CVE-2025-22056, CVE-2025-37749, CVE-2025-37994, CVE-2025-38116, CVE-2025-38369, CVE-2025-38412, CVE-2025-38468