CentOS Linux 7 [TuxCare] セキュリティ更新プログラム:bpftool/kernel/kernel-debug/kernel-debug-devel/kernel-devel/etcの複数の脆弱性(CENTOS7:CLSA-2026:1788170774)

high Nessus プラグイン ID 359803

概要

CentOS Linuxホストに1つ以上のセキュリティ更新プログラムがありません。

説明

CentOS Linux 7ホストには、TuxCare CENTOS7:CLSA-2026:1788170774アドバイザリに記載されている複数の脆弱性の影響を受けるパッケージがインストールされています。

-5.12-rc8より前のLinuxカーネルSCTPソケット (net/sctp/socket.c) の競合状態により、ネットワークサービスのコンテキストまたは権限のないプロセスからのカーネル権限昇格につながる可能性があります。sock_net(sk)->sctp.addr_wq_lockなしでsctp_destroy_sockが呼び出された場合、適切なロックがない状態で、要素がauto_asconf_splistリストから削除されます。これが悪用され、ネットワークサービス権限を持つ攻撃者が root への権限昇格が行われる、あるいは一部の SCTP ソケットの作成を拒否する BPF_CGROUP_INET_SOCK_CREATE が添付されている場合、権限のないユーザーのコンテキストから権限昇格が行われる可能性があります。(CVE-2021-23133)

- Linux カーネルでは、以下の脆弱性が解決されています: drm: Fix use-after-free read in drm_getunique() There is a time-of-check-to-time-of-use error in drm_getunique() due to retrieving file_priv->master prior to locking the device's master mutex. An example can be seen in the crash report of the use-after-free error found by Syzbot:
https://syzkaller.appspot.com/bug?id=148d2f1dfac64af52ffd27b661981a540724f803 In the report, the master pointer was used after being freed. This is because another process had acquired the device's master mutex in drm_setmaster_ioctl(), then overwrote fpriv->master in drm_new_set_master(). The old value of fpriv->master was subsequently freed before the mutex was unlocked. To fix this, we lock the device's master mutex before retrieving the pointer from from fpriv->master. This patch passes the Syzbot reproducer test. (CVE-2021-47280)

- Linux カーネルでは、以下の脆弱性が解決されています: scsi: mpt3sas: Fix kernel panic during drive powercycle test While looping over shost's sdev list it is possible that one of the drives is getting removed and its sas_target object is freed but its sdev object remains intact. Consequently, a kernel panic can occur while the driver is trying to access the sas_address field of sas_target object without also checking the sas_target object for NULL. (CVE-2021-47565)

- Linux カーネルでは、以下の脆弱性が解決されています: dm btree remove: fix use after free in rebalance_children() Move dm_tm_unlock() after dm_tm_dec(). (CVE-2021-47600)

- Linux カーネルでは、以下の脆弱性が解決されています: media: pvrusb2: fix array-index-out-of-bounds in pvr2_i2c_core_init Syzbot reported that -1 is used as array index. The problem was in missing validation check. hdw->unit_number is initialized with -1 and then if init table walk fails this value remains unchanged. Since code blindly uses this member for array indexing adding sanity check is the easiest fix for that. hdw->workpoll initialization moved upper to prevent warning in __flush_work.
(CVE-2022-49478)

Nessus はこれらの問題をテストしておらず、代わりにアプリケーションが自己報告するバージョン番号にのみ依存していることに注意してください。

ソリューション

TuxCareアドバイザリCENTOS7:CLSA-2026:1788170774のガイダンスに基づいて、影響を受けるパッケージを更新してください。

参考資料

https://cve.tuxcare.com/els/releases/CLSA-2026:1788170774

http://www.nessus.org/u?cb80664a

プラグインの詳細

深刻度: High

ID: 359803

ファイル名: tuxcare_centos_7_CLSA-2026-1788170774.nasl

バージョン: 1.1

タイプ: Local

エージェント: unix

公開日: 2026/10/1

更新日: 2026/10/1

サポートされているセンサー: Continuous Assessment, Nessus Agent, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

リスク情報

VPR

リスクファクター: High

スコア: 7.9

パーセンタイル: 99.35

Vendor

Vendor Severity: Important

CVSS v2

リスクファクター: Medium

基本値: 6.9

現状値: 5.4

ベクトル: CVSS2#AV:L/AC:M/Au:N/C:C/I:C/A:C

CVSS スコアのソース: CVE-2021-23133

CVSS v3

リスクファクター: High

基本値: 8.2

現状値: 7.4

ベクトル: CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

現状ベクトル: CVSS:3.0/E:P/RL:O/RC:C

CVSS スコアのソース: CVE-2026-31788

CVSS v4

リスクファクター: High

Base Score: 7.3

Threat Score: 6.4

Threat Vector: CVSS:4.0/E:P

Vector: CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

CVSS スコアのソース: CVE-2025-54518

脆弱性情報

必要な KB アイテム: Host/OS/extended-third-party, Host/local_checks_enabled, Host/CentOS/release, Host/CentOS/rpm-list

エクスプロイトが利用可能: true

エクスプロイトの容易さ: Exploits are available

パッチ公開日: 2026/8/31

脆弱性公開日: 2021/4/13

参照情報

CVE: CVE-2021-23133, CVE-2021-47280, CVE-2021-47479, CVE-2021-47565, CVE-2021-47600, CVE-2022-49111, CVE-2022-49478, CVE-2022-49934, CVE-2022-50103, CVE-2022-50185, CVE-2022-50220, CVE-2022-50411, CVE-2022-50432, CVE-2022-50470, CVE-2022-50496, CVE-2022-50551, CVE-2022-50646, CVE-2023-2162, CVE-2023-52818, CVE-2023-52974, CVE-2023-53153, CVE-2023-53265, CVE-2023-53307, CVE-2023-53454, CVE-2023-53524, CVE-2023-53556, CVE-2023-54121, CVE-2023-54243, CVE-2024-0639, CVE-2024-36013, CVE-2025-21753, CVE-2025-21764, CVE-2025-38046, CVE-2025-38103, CVE-2025-38211, CVE-2025-38239, CVE-2025-38563, CVE-2025-39759, CVE-2025-54518, CVE-2025-68798, CVE-2026-22980, CVE-2026-23099, CVE-2026-23318, CVE-2026-31392, CVE-2026-31399, CVE-2026-31500, CVE-2026-31502, CVE-2026-31663, CVE-2026-31788, CVE-2026-43116, CVE-2026-43279, CVE-2026-43281, CVE-2026-43334, CVE-2026-43338, CVE-2026-43339, CVE-2026-43493, CVE-2026-45856, CVE-2026-45861, CVE-2026-45942, CVE-2026-45970, CVE-2026-45984, CVE-2026-46006, CVE-2026-46043, CVE-2026-46052, CVE-2026-46056, CVE-2026-46133, CVE-2026-46149, CVE-2026-46150, CVE-2026-46174, CVE-2026-46189, CVE-2026-46259, CVE-2026-46266, CVE-2026-52918, CVE-2026-52920, CVE-2026-52942, CVE-2026-52956, CVE-2026-52957, CVE-2026-52986, CVE-2026-52998, CVE-2026-53002, CVE-2026-53009, CVE-2026-53062, CVE-2026-53075, CVE-2026-53091, CVE-2026-53112, CVE-2026-53131, CVE-2026-53224, CVE-2026-53228, CVE-2026-53246, CVE-2026-53253, CVE-2026-53254, CVE-2026-53255, CVE-2026-53256, CVE-2026-53264, CVE-2026-53265, CVE-2026-53268, CVE-2026-53270, CVE-2026-53275, CVE-2026-64266, CVE-2026-64298, CVE-2026-64567, CVE-2026-64582, CVE-2026-68093, CVE-2026-68096, CVE-2026-68108, CVE-2026-68121, CVE-2026-68123, CVE-2026-68143, CVE-2026-68153, CVE-2026-68154, CVE-2026-68155, CVE-2026-68156, CVE-2026-68158, CVE-2026-68160, CVE-2026-68176, CVE-2026-68188, CVE-2026-68202, CVE-2026-68226, CVE-2026-68320, CVE-2026-68365, CVE-2026-68376, CVE-2026-68414, CVE-2026-68433, CVE-2026-72396, CVE-2026-72472, CVE-2026-74499, CVE-2026-74583, CVE-2026-74584, CVE-2026-74588, CVE-2026-74624, CVE-2026-74669, CVE-2026-74730

CLSA: 2026:1788170774