AlmaLinux 9.2 [TuxCare] セキュリティ更新プログラム:bpftool/kernel/kernel-abi-stablelists/kernel-core/etcの複数の脆弱性(ALMALINUX9.2:CLSA-2026:1773139548)

high Nessus プラグイン ID 362121

概要

AlmaLinuxホストに1つ以上のセキュリティ更新プログラムがありません。

説明

AlmaLinux 9.2 ホストには、TuxCare ALMALINUX9.2:CLSA-2026:1773139548アドバイザリに記載されている複数の脆弱性の影響を受けるパッケージがインストールされています。

- Linux カーネルでは、以下の脆弱性が解決されています: virtio_net: fix xdp_rxq_info bug after suspend/resume The following sequence currently causes a driver bug warning when using virtio_net: # ip link set eth0 up # echo mem > /sys/power/state (or e.g. # rtcwake -s 10 -m mem) <resume> # ip link set eth0 down Missing register, driver bug WARNING: CPU: 0 PID: 375 at net/core/xdp.c:138 xdp_rxq_info_unreg+0x58/0x60 Call trace: xdp_rxq_info_unreg+0x58/0x60 virtnet_close+0x58/0xac
__dev_close_many+0xac/0x140 __dev_change_flags+0xd8/0x210 dev_change_flags+0x24/0x64 do_setlink+0x230/0xdd0 ... This happens because virtnet_freeze() frees the receive_queue completely (including struct xdp_rxq_info) but does not call xdp_rxq_info_unreg(). Similarly, virtnet_restore() sets up the receive_queue again but does not call xdp_rxq_info_reg(). Actually, parts of virtnet_freeze_down() and virtnet_restore_up() are almost identical to virtnet_close() and virtnet_open(): only the calls to xdp_rxq_info_(un)reg() are missing. This means that we can fix this easily and avoid such problems in the future by just calling virtnet_close()/open() from the freeze/restore handlers. Aside from adding the missing xdp_rxq_info calls the only difference is that the refill work is only cancelled if netif_running(). However, this should not make any functional difference since the refill work should only be active if the network interface is actually up. (CVE-2022-49687)

- Linux カーネルでは、以下の脆弱性が解決されています: scsi: libsas: Fix use-after-free bug in smp_execute_task_sg() When executing SMP task failed, the smp_execute_task_sg() calls del_timer() to delete slow_task->timer. However, if the timer handler sas_task_internal_timedout() is running, the del_timer() in smp_execute_task_sg() will not stop it and a UAF will happen. The process is shown below:
(thread 1) | (thread 2) smp_execute_task_sg() | sas_task_internal_timedout() ... | del_timer() | ... | ...
sas_free_task(task) | kfree(task->slow_task) //FREE| | task->slow_task->... //USE Fix by calling del_timer_sync() in smp_execute_task_sg(), which makes sure the timer handler have finished before the task->slow_task is deallocated. (CVE-2022-50422)

- Linux カーネルでは、以下の脆弱性が解決されています: xhci: Remove device endpoints from bandwidth list when freeing the device Endpoints are normally deleted from the bandwidth list when they are dropped, before the virt device is freed. If xHC host is dying or being removed then the endpoints aren't dropped cleanly due to functions returning early to avoid interacting with a non-accessible host controller. So check and delete endpoints that are still on the bandwidth list when freeing the virt device. Solves a list_del corruption kernel crash when unbinding xhci-pci, caused by xhci_mem_cleanup() when it later tried to delete already freed endpoints from the bandwidth list. This only affects hosts that use software bandwidth checking, which currenty is only the xHC in intel Panther Point PCH (Ivy Bridge) (CVE-2022-50470)

- Linux カーネルでは、以下の脆弱性が解決されています: mmc: via-sdmmc: fix return value check of mmc_add_host() mmc_add_host() may return error, if we ignore its return value, it will lead two issues:
1. The memory that allocated in mmc_alloc_host() is leaked. 2. In the remove() path, mmc_remove_host() will be called to delete device, but it's not added yet, it will lead a kernel crash because of null-ptr-deref in device_del(). Fix this by checking the return value and goto error path which will call mmc_free_host(). (CVE-2022-50846)

- Linux カーネルでは、以下の脆弱性が解決されています: media: uvcvideo: Fix memory leak in uvc_gpio_parse Previously the unit buffer was allocated before checking the IRQ for privacy GPIO. In case of error, the unit buffer was leaked. Allocate the unit buffer after the IRQ to avoid it. Addresses-Coverity-ID: 1474639 (Resource leak) (CVE-2022-50882)

Nessus はこれらの問題をテストしておらず、代わりにアプリケーションが自己報告するバージョン番号にのみ依存していることに注意してください。

ソリューション

TuxCareアドバイザリALMALINUX9.2:CLSA-2026:1773139548のガイダンスに基づいて、影響を受けるパッケージを更新してください。

参考資料

https://cve.tuxcare.com/els/releases/CLSA-2026:1773139548

http://www.nessus.org/u?52e0f903

プラグインの詳細

深刻度: High

ID: 362121

ファイル名: tuxcare_alma_linux_9.2_CLSA-2026-1773139548.nasl

バージョン: 1.1

タイプ: Local

公開日: 2026/10/1

更新日: 2026/10/1

サポートされているセンサー: Continuous Assessment, Nessus Agent, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

リスク情報

VPR

リスクファクター: High

スコア: 7.6

パーセンタイル: 98.57

Vendor

Vendor Severity: Important

CVSS v2

リスクファクター: Medium

基本値: 6.8

現状値: 5.3

ベクトル: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS スコアのソース: CVE-2025-39945

CVSS v3

リスクファクター: High

基本値: 7.8

現状値: 7

ベクトル: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

現状ベクトル: CVSS:3.0/E:P/RL:O/RC:C

脆弱性情報

必要な KB アイテム: Host/OS/extended-third-party, Host/local_checks_enabled, Host/AlmaLinux/release, Host/AlmaLinux/rpm-list, Host/cpu

エクスプロイトが利用可能: true

エクスプロイトの容易さ: Exploits are available

パッチ公開日: 2026/3/10

脆弱性公開日: 2021/7/21

参照情報

CVE: CVE-2022-49687, CVE-2022-50422, CVE-2022-50470, CVE-2022-50846, CVE-2022-50882, CVE-2023-3773, CVE-2023-53085, CVE-2023-53105, CVE-2023-53347, CVE-2023-53392, CVE-2023-53454, CVE-2023-53471, CVE-2023-53500, CVE-2023-53506, CVE-2023-53515, CVE-2023-53524, CVE-2023-53535, CVE-2023-53540, CVE-2023-53556, CVE-2023-53560, CVE-2023-53571, CVE-2023-53574, CVE-2023-53587, CVE-2023-53588, CVE-2023-53589, CVE-2023-53600, CVE-2023-53601, CVE-2023-53604, CVE-2023-53619, CVE-2023-53622, CVE-2023-53629, CVE-2023-53652, CVE-2023-54114, CVE-2023-54148, CVE-2023-54173, CVE-2023-54184, CVE-2023-54186, CVE-2023-54195, CVE-2023-54202, CVE-2023-54234, CVE-2023-54242, CVE-2023-54244, CVE-2023-54246, CVE-2023-54283, CVE-2023-54289, CVE-2023-54294, CVE-2023-54296, CVE-2023-54299, CVE-2023-54303, CVE-2023-54306, CVE-2023-54321, CVE-2024-43892, CVE-2024-58020, CVE-2025-38022, CVE-2025-38201, CVE-2025-38494, CVE-2025-38495, CVE-2025-38535, CVE-2025-38565, CVE-2025-38691, CVE-2025-38728, CVE-2025-38732, CVE-2025-39683, CVE-2025-39693, CVE-2025-39760, CVE-2025-39824, CVE-2025-39835, CVE-2025-39866, CVE-2025-39913, CVE-2025-39945, CVE-2025-39949, CVE-2025-40251, CVE-2025-40304, CVE-2025-40322, CVE-2025-68349, CVE-2025-68811, CVE-2025-71085, CVE-2026-22998

CLSA: 2026:1773139548