AlmaLinux 9.6 [TuxCare] セキュリティ更新プログラム:kernel/kernel-abi-stablelists/kernel-core/etcの複数の脆弱性(ALMALINUX9.6:CLSA-2026:1778787063)

high Nessus プラグイン ID 361904

概要

AlmaLinuxホストに1つ以上のセキュリティ更新プログラムがありません。

説明

AlmaLinux 9.6 ホストには、TuxCare ALMALINUX9.6:CLSA-2026:1778787063アドバイザリに記載されている複数の脆弱性の影響を受けるパッケージがインストールされています。

- Linux カーネルでは、以下の脆弱性が解決されています: can: m_can: pci: add missing m_can_class_free_dev() in probe/remove methods In m_can_pci_remove() and error handling path of m_can_pci_probe(), m_can_class_free_dev() should be called to free resource allocated by m_can_class_allocate_dev(), otherwise there will be memleak. (CVE-2022-49024)

- Linux カーネルでは、以下の脆弱性が解決されています: ima: Fix a potential integer overflow in ima_appraise_measurement When the ima-modsig is enabled, the rc passed to evm_verifyxattr() may be negative, which may cause the integer overflow problem. (CVE-2022-49643)

- Linux カーネルでは、以下の脆弱性が解決されています: usbnet: fix memory leak in error case usbnet_write_cmd_async() mixed up which buffers need to be freed in which error case. v2: add Fixes tag v3: fix uninitialized buf pointer (CVE-2022-49657)

- Linux カーネルでは、以下の脆弱性が解決されています: can: j1939: j1939_send_one(): fix missing CAN header initialization The read access to struct canxl_frame::len inside of a j1939 created skbuff revealed a missing initialization of reserved and later filled elements in struct can_frame. This patch initializes the 8 byte CAN header with zero. (CVE-2022-49845)

- Linux カーネルでは、以下の脆弱性が解決されています: misc: tifm: fix possible memory leak in tifm_7xx1_switch_media() If device_register() returns error in tifm_7xx1_switch_media(), name of kobject which is allocated in dev_set_name() called in device_add() is leaked. Never directly free @dev after calling device_register(), even if it returned an error! Always use put_device() to give up the reference initialized. (CVE-2022-50349)

Nessus はこれらの問題をテストしておらず、代わりにアプリケーションが自己報告するバージョン番号にのみ依存していることに注意してください。

ソリューション

TuxCareアドバイザリALMALINUX9.6:CLSA-2026:1778787063のガイダンスに基づいて、影響を受けるパッケージを更新してください。

参考資料

https://cve.tuxcare.com/els/releases/CLSA-2026:1778787063

http://www.nessus.org/u?e3932354

プラグインの詳細

深刻度: High

ID: 361904

ファイル名: tuxcare_alma_linux_9.6_CLSA-2026-1778787063.nasl

バージョン: 1.2

タイプ: Local

公開日: 2026/10/1

更新日: 2026/10/2

サポートされているセンサー: Continuous Assessment, Nessus Agent, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

リスク情報

VPR

リスクファクター: Critical

スコア: 9.5

パーセンタイル: 99.87

Vendor

Vendor Severity: Important

CVSS v2

リスクファクター: Medium

基本値: 6.8

現状値: 5.9

ベクトル: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS スコアのソース: CVE-2026-46300

CVSS v3

リスクファクター: High

基本値: 7.8

現状値: 7.5

ベクトル: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

現状ベクトル: CVSS:3.0/E:H/RL:O/RC:C

脆弱性情報

必要な KB アイテム: Host/OS/extended-third-party, Host/local_checks_enabled, Host/AlmaLinux/release, Host/AlmaLinux/rpm-list, Host/cpu

エクスプロイトが利用可能: true

エクスプロイトの容易さ: Exploits are available

パッチ公開日: 2026/5/14

脆弱性公開日: 2021/7/21

エクスプロイト可能

Core Impact

Metasploit (Fragnesia LPE (CVE-2026-46300))

参照情報

CVE: CVE-2022-49024, CVE-2022-49643, CVE-2022-49657, CVE-2022-49845, CVE-2022-50282, CVE-2022-50349, CVE-2022-50387, CVE-2022-50438, CVE-2022-50476, CVE-2022-50498, CVE-2023-53062, CVE-2023-53165, CVE-2023-53629, CVE-2023-53685, CVE-2024-39494, CVE-2024-40954, CVE-2024-47679, CVE-2024-50195, CVE-2024-53052, CVE-2024-53119, CVE-2024-56606, CVE-2024-56662, CVE-2024-57981, CVE-2024-57987, CVE-2024-57993, CVE-2024-58012, CVE-2024-58062, CVE-2024-58068, CVE-2024-58077, CVE-2024-58088, CVE-2025-21636, CVE-2025-21648, CVE-2025-21649, CVE-2025-21664, CVE-2025-21665, CVE-2025-21672, CVE-2025-21683, CVE-2025-21691, CVE-2025-21728, CVE-2025-21729, CVE-2025-21744, CVE-2025-21745, CVE-2025-21750, CVE-2025-21758, CVE-2025-21766, CVE-2025-21776, CVE-2025-21779, CVE-2025-21796, CVE-2025-21830, CVE-2025-21833, CVE-2025-21838, CVE-2025-21844, CVE-2025-21847, CVE-2025-21853, CVE-2025-21861, CVE-2025-21875, CVE-2025-21877, CVE-2025-21881, CVE-2025-21885, CVE-2025-21891, CVE-2025-21909, CVE-2025-21924, CVE-2025-21941, CVE-2025-21948, CVE-2025-21951, CVE-2025-21959, CVE-2025-21971, CVE-2025-21975, CVE-2025-21981, CVE-2025-21996, CVE-2025-22008, CVE-2025-22044, CVE-2025-22057, CVE-2025-22063, CVE-2025-22075, CVE-2025-22086, CVE-2025-22103, CVE-2025-23131, CVE-2025-23136, CVE-2025-23145, CVE-2025-37757, CVE-2025-37765, CVE-2025-37766, CVE-2025-37773, CVE-2025-37792, CVE-2025-37794, CVE-2025-37801, CVE-2025-37824, CVE-2025-37859, CVE-2025-37867, CVE-2025-37877, CVE-2025-37980, CVE-2025-37994, CVE-2025-38045, CVE-2025-38096, CVE-2025-38099, CVE-2025-38193, CVE-2025-38208, CVE-2025-38430, CVE-2025-38436, CVE-2025-38439, CVE-2025-38468, CVE-2025-38474, CVE-2025-38539, CVE-2025-38643, CVE-2025-38705, CVE-2025-39705, CVE-2025-39707, CVE-2025-39745, CVE-2025-39829, CVE-2025-39851, CVE-2025-39889, CVE-2025-39902, CVE-2025-39940, CVE-2025-40164, CVE-2025-40185, CVE-2025-71116, CVE-2025-71225, CVE-2026-23076, CVE-2026-23125, CVE-2026-31493, CVE-2026-31500, CVE-2026-31551, CVE-2026-46300

CLSA: 2026:1778787063