AlmaLinux 9.2 [TuxCare] セキュリティ更新:bpftool/kernel/kernel-abi-stablelists/kernel-core/etc 複数の脆弱性(ALMALINUX9.2:CLSA-2026:1787935638)

high Nessus プラグイン ID 361746

概要

AlmaLinuxホストに1つ以上のセキュリティ更新プログラムがありません。

説明

AlmaLinux 9.2 ホストには、TuxCare ALMALINUX9.2:CLSA-2026:1787935638アドバイザリに記載されている複数の脆弱性の影響を受けるパッケージがインストールされています。

- Linux カーネルでは、以下の脆弱性が解決されています: fs/mount_setattr: always cleanup mount_kattr Make sure that finish_mount_kattr() is called after mount_kattr was succesfully built in both the success and failure case to prevent leaking any references we took when we built it. We returned early if path lookup failed thereby risking to leak an additional reference we took when building mount_kattr when an idmapped mount was requested. (CVE-2021-46923)

- Linux カーネルでは、以下の脆弱性が解決されています: vdpa: ifcvf: Do proper cleanup if IFCVF init fails ifcvf_mgmt_dev leaks memory if it is not freed before returning. Call is made to correct return statement so memory does not leak. ifcvf_init_hw does not take care of this so it is needed to do it here. (CVE-2022-48706)

- Linux カーネルでは、以下の脆弱性が解決されています: tracing/histogram: Fix a potential memory leak for kstrdup() kfree() is missing on an error path to free the memory allocated by kstrdup(): p = param = kstrdup(data->params[i], GFP_KERNEL); So it is better to free it via kfree(p). (CVE-2022-48768)

- Linux カーネルでは、以下の脆弱性が解決されています: efi: fix NULL-deref in init error path In cases where runtime services are not supported or have been disabled, the runtime services workqueue will never have been allocated. Do not try to destroy the workqueue unconditionally in the unlikely event that EFI initialisation fails to avoid dereferencing a NULL pointer. (CVE-2022-48879)

- Linux カーネルでは、以下の脆弱性が解決されています: RDMA/srp: Do not call scsi_done() from srp_abort() After scmd_eh_abort_handler() has called the SCSI LLD eh_abort_handler callback, it performs one of the following actions: * Call scsi_queue_insert(). * Call scsi_finish_command(). * Call scsi_eh_scmd_add(). Hence, SCSI abort handlers must not call scsi_done(). Otherwise all the above actions would trigger a use-after-free. Hence remove the scsi_done() call from srp_abort(). Keep the srp_free_req() call before returning SUCCESS because we may not see the command again if SUCCESS is returned. (CVE-2023-52515)

Nessus はこれらの問題をテストしておらず、代わりにアプリケーションが自己報告するバージョン番号にのみ依存していることに注意してください。

ソリューション

TuxCareアドバイザリALMALINUX9.2:CLSA-2026:1787935638のガイダンスに基づいて、影響を受けるパッケージを更新してください。

参考資料

https://cve.tuxcare.com/els/releases/CLSA-2026:1787935638

http://www.nessus.org/u?05e487ee

プラグインの詳細

深刻度: High

ID: 361746

ファイル名: tuxcare_alma_linux_9.2_CLSA-2026-1787935638.nasl

バージョン: 1.1

タイプ: Local

公開日: 2026/10/1

更新日: 2026/10/1

サポートされているセンサー: Continuous Assessment, Nessus Agent, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

リスク情報

VPR

リスクファクター: High

スコア: 7.9

パーセンタイル: 99.35

Vendor

Vendor Severity: Important

CVSS v2

リスクファクター: High

基本値: 7.2

現状値: 5.6

ベクトル: CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C

CVSS スコアのソース: CVE-2026-53196

CVSS v3

リスクファクター: High

基本値: 7.8

現状値: 7

ベクトル: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

現状ベクトル: CVSS:3.0/E:P/RL:O/RC:C

CVSS スコアのソース: CVE-2026-64225

CVSS v4

リスクファクター: High

Base Score: 7.3

Threat Score: 6.4

Threat Vector: CVSS:4.0/E:P

Vector: CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

CVSS スコアのソース: CVE-2025-54518

脆弱性情報

必要な KB アイテム: Host/OS/extended-third-party, Host/local_checks_enabled, Host/AlmaLinux/release, Host/AlmaLinux/rpm-list, Host/cpu

エクスプロイトが利用可能: true

エクスプロイトの容易さ: Exploits are available

パッチ公開日: 2026/8/28

脆弱性公開日: 2021/7/21

参照情報

CVE: CVE-2021-46923, CVE-2022-48706, CVE-2022-48768, CVE-2022-48879, CVE-2022-49030, CVE-2023-52515, CVE-2023-52910, CVE-2023-52913, CVE-2023-53582, CVE-2024-43854, CVE-2024-49948, CVE-2024-50039, CVE-2024-56720, CVE-2025-21673, CVE-2025-38264, CVE-2025-40048, CVE-2025-54518, CVE-2025-68815, CVE-2026-23007, CVE-2026-23278, CVE-2026-31392, CVE-2026-31393, CVE-2026-31530, CVE-2026-31679, CVE-2026-43060, CVE-2026-43062, CVE-2026-43071, CVE-2026-43187, CVE-2026-43469, CVE-2026-43501, CVE-2026-45838, CVE-2026-45839, CVE-2026-45840, CVE-2026-45841, CVE-2026-45842, CVE-2026-45847, CVE-2026-45850, CVE-2026-45856, CVE-2026-45857, CVE-2026-45886, CVE-2026-45948, CVE-2026-45964, CVE-2026-45983, CVE-2026-45987, CVE-2026-46015, CVE-2026-46018, CVE-2026-46021, CVE-2026-46023, CVE-2026-46040, CVE-2026-46049, CVE-2026-46056, CVE-2026-46082, CVE-2026-46088, CVE-2026-46101, CVE-2026-46108, CVE-2026-46119, CVE-2026-46128, CVE-2026-46132, CVE-2026-46151, CVE-2026-46161, CVE-2026-46167, CVE-2026-46172, CVE-2026-46177, CVE-2026-46184, CVE-2026-46189, CVE-2026-46191, CVE-2026-46197, CVE-2026-46218, CVE-2026-46220, CVE-2026-46234, CVE-2026-46249, CVE-2026-46259, CVE-2026-46294, CVE-2026-52920, CVE-2026-52935, CVE-2026-52947, CVE-2026-52948, CVE-2026-52955, CVE-2026-52957, CVE-2026-52962, CVE-2026-52963, CVE-2026-52969, CVE-2026-52970, CVE-2026-52972, CVE-2026-52985, CVE-2026-52993, CVE-2026-53002, CVE-2026-53012, CVE-2026-53016, CVE-2026-53022, CVE-2026-53037, CVE-2026-53064, CVE-2026-53072, CVE-2026-53075, CVE-2026-53080, CVE-2026-53093, CVE-2026-53135, CVE-2026-53136, CVE-2026-53168, CVE-2026-53176, CVE-2026-53177, CVE-2026-53181, CVE-2026-53195, CVE-2026-53196, CVE-2026-53212, CVE-2026-53218, CVE-2026-53219, CVE-2026-53223, CVE-2026-53227, CVE-2026-53228, CVE-2026-53238, CVE-2026-53239, CVE-2026-53245, CVE-2026-53249, CVE-2026-53254, CVE-2026-53255, CVE-2026-53256, CVE-2026-53263, CVE-2026-53268, CVE-2026-53269, CVE-2026-53287, CVE-2026-53295, CVE-2026-53304, CVE-2026-53337, CVE-2026-53391, CVE-2026-63800, CVE-2026-63945, CVE-2026-64174, CVE-2026-64225, CVE-2026-64237, CVE-2026-64572, CVE-2026-64576, CVE-2026-64579, CVE-2026-68093, CVE-2026-68108, CVE-2026-68121, CVE-2026-68142, CVE-2026-68143, CVE-2026-68153, CVE-2026-68155, CVE-2026-68156, CVE-2026-68160, CVE-2026-68188, CVE-2026-68189, CVE-2026-68313, CVE-2026-68315, CVE-2026-68320, CVE-2026-68324, CVE-2026-68363, CVE-2026-68377, CVE-2026-68388, CVE-2026-68398, CVE-2026-68402, CVE-2026-68414, CVE-2026-68426, CVE-2026-72396, CVE-2026-74499

CLSA: 2026:1787935638