CentOS Linux 8 [TuxCare] セキュリティ更新:bpftool/kernel/kernel-core/kernel-cross-headers/etcの複数の脆弱性(CENTOS-STREAM8:CLSA-2026:1782375682)

high Nessus プラグイン ID 361917

概要

CentOS Linuxホストに1つ以上のセキュリティ更新プログラムがありません。

説明

CentOS Linux 8ホストには、TuxCare CENTOS-STREAM8:CLSA-2026:1782375682アドバイザリに記載されている複数の脆弱性の影響を受けるパッケージがインストールされています。

- Linux カーネルでは、以下の脆弱性が解決されています: bpf: Don't redirect packets with invalid pkt_len Syzbot found an issue [1]: fq_codel_drop() try to drop a flow whitout any skbs, that is, the flow->head is null. The root cause, as the [2] says, is because that bpf_prog_test_run_skb() run a bpf prog which redirects empty skbs. So we should determine whether the length of the packet modified by bpf prog or others like bpf_prog_test is valid before forwarding it directly. (CVE-2022-49975)

- Linux カーネルでは、以下の脆弱性が解決されています: ASoC: SOF: debug: Fix potential buffer overflow by snprintf() snprintf() returns the would-be-filled size when the string overflows the given buffer size, hence using this value may result in the buffer overflow (although it's unrealistic). This patch replaces with a safer version, scnprintf() for papering over such a potential issue.
(CVE-2022-50051)

- Linux カーネルでは、以下の脆弱性が解決されています: x86/alternatives: Disable KASAN in apply_alternatives() Fei has reported that KASAN triggers during apply_alternatives() on a 5-level paging machine: BUG: KASAN: out-of-bounds in rcu_is_watching() Read of size 4 at addr ff110003ee6419a0 by task swapper/0/0 ... __asan_load4() rcu_is_watching() trace_hardirqs_on() text_poke_early() apply_alternatives() ... On machines with 5-level paging, cpu_feature_enabled(X86_FEATURE_LA57) gets patched. It includes KASAN code, where KASAN_SHADOW_START depends on __VIRTUAL_MASK_SHIFT, which is defined with cpu_feature_enabled(). KASAN gets confused when apply_alternatives() patches the KASAN_SHADOW_START users. A test patch that makes KASAN_SHADOW_START static, by replacing
__VIRTUAL_MASK_SHIFT with 56, works around the issue. Fix it for real by disabling KASAN while the kernel is patching alternatives. [ mingo: updated the changelog ] (CVE-2023-52504)

- Linux カーネルでは、以下の脆弱性が解決されています: drm/amd: Fix UBSAN array-index-out-of-bounds for SMU7 For pptable structs that use flexible array sizes, use flexible arrays. (CVE-2023-52818)

- Linux カーネルでは、以下の脆弱性が解決されています: nbd: defer config unlock in nbd_genl_connect There is one use-after-free warning when running NBD_CMD_CONNECT and NBD_CLEAR_SOCK:
nbd_genl_connect nbd_alloc_and_init_config // config_refs=1 nbd_start_device // config_refs=2 set NBD_RT_HAS_CONFIG_REF open nbd // config_refs=3 recv_work done // config_refs=2 NBD_CLEAR_SOCK // config_refs=1 close nbd // config_refs=0 refcount_inc -> uaf ------------[ cut here ]------------ refcount_t: addition on 0; use-after-free. WARNING: CPU: 24 PID: 1014 at lib/refcount.c:25 refcount_warn_saturate+0x12e/0x290 nbd_genl_connect+0x16d0/0x1ab0 genl_family_rcv_msg_doit+0x1f3/0x310 genl_rcv_msg+0x44a/0x790 The issue can be easily reproduced by adding a small delay before refcount_inc(&nbd->config_refs) in nbd_genl_connect(): mutex_unlock(&nbd->config_lock); if (!ret) {set_bit(NBD_RT_HAS_CONFIG_REF, &config->runtime_flags); + printk(before sleep\n); + mdelay(5 * 1000); + printk(after sleep\n); refcount_inc(&nbd->config_refs); nbd_connect_reply(info, nbd->index); } (CVE-2025-68366)

Nessus はこれらの問題をテストしておらず、代わりにアプリケーションが自己報告するバージョン番号にのみ依存していることに注意してください。

ソリューション

TuxCareアドバイザリCENTOS-STREAM8:CLSA-2026:1782375682のガイダンスに基づいて、影響を受けるパッケージを更新してください。

参考資料

https://cve.tuxcare.com/els/releases/CLSA-2026:1782375682

http://www.nessus.org/u?f1ff0a61

プラグインの詳細

深刻度: High

ID: 361917

ファイル名: tuxcare_centos_8_CLSA-2026-1782375682.nasl

バージョン: 1.1

タイプ: Local

エージェント: unix

公開日: 2026/10/1

更新日: 2026/10/1

サポートされているセンサー: Continuous Assessment, Nessus Agent, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

リスク情報

VPR

リスクファクター: Medium

スコア: 6.9

パーセンタイル: 97.08

Vendor

Vendor Severity: Important

CVSS v2

リスクファクター: Medium

基本値: 6.8

現状値: 5

ベクトル: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS スコアのソース: CVE-2026-43027

CVSS v3

リスクファクター: High

基本値: 7.8

現状値: 6.8

ベクトル: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

現状ベクトル: CVSS:3.0/E:U/RL:O/RC:C

脆弱性情報

必要な KB アイテム: Host/OS/extended-third-party, Host/local_checks_enabled, Host/CentOS/release, Host/CentOS/rpm-list

エクスプロイトの容易さ: No known exploits are available

パッチ公開日: 2026/6/25

脆弱性公開日: 2021/7/21

参照情報

CVE: CVE-2022-49975, CVE-2022-50051, CVE-2023-52504, CVE-2023-52818, CVE-2025-38361, CVE-2025-68366, CVE-2025-71082, CVE-2025-71091, CVE-2026-23099, CVE-2026-23191, CVE-2026-23243, CVE-2026-23270, CVE-2026-23455, CVE-2026-31405, CVE-2026-31532, CVE-2026-31581, CVE-2026-31685, CVE-2026-43027, CVE-2026-43110, CVE-2026-43158, CVE-2026-43190, CVE-2026-43370

CLSA: 2026:1782375682