RHEL 9:Satellite 6.18.10 Async更新プログラム(重要度最高)(RHSA-2026:74504)

high Nessus プラグイン ID 362465

概要

リモートの Red Hat ホストに 1 つ以上のセキュリティ更新プログラムがありません。

説明

リモートの Redhat Enterprise Linux 9 ホストに、RHSA-2026:74504 アドバイザリに記載されている複数の脆弱性の影響を受けるパッケージがインストールされています。

Red Hat Satellite はシステム管理ソリューションです。これを使用することで組織は、組織のサーバーやその他クライアントシステムにパブリックインターネットアクセスを提供することなく、システムの設定や維持を行うことができるようになります。また、このソリューションは、事前に定義された標準のオペレーティング環境のプロビジョニングや構成管理も行います。

セキュリティ修正プログラム:

* foreman:プレビューの閲覧者ロールに対する過剰な権限(CVE-2026-96659)

* python3.12-gitpython:GitPython:Git ディレクトリのなりすましによるリモートコードの実行(CVE-2026-87817)

* python3.12-gitpython:GitPython:TagReference.create() を通じた任意のファイルの読み取り(CVE-2026-78679)

* python3.12-dynaconf:Dynaconf:サーバーサイドテンプレートインジェクションによる任意のコードの実行(CVE-2026-33154)

* yggdrasil-worker-forwarder:Golang MIME:悪意を持って細工された MIME ヘッダーによるサービス拒否(CVE-2026-42504)

* satellite/iop-advisor-backend-rhel9:sqlparse:SQL 解析における二次の CPU 消費によるサービス拒否(CVE-2026-54284)

* python3.12-sqlparse:sqlparse:SQL 解析における二次 CPU 消費によるサービス拒否(CVE-2026-54284)

* satellite/iop-advisor-backend-rhel9:sqlparse:非効率的な SQL 解析によるサービス拒否(CVE-2026-59893)

* python3.12-sqlparse:sqlparse:非効率的な SQL 解析によるサービス拒否(CVE-2026-59893)

* python3.12-sqlparse:sqlparse:コメントグループ化での 2 次 CPU 消費によるサービス拒否(CVE-2026-71491)

* rubygem-katello:Katello Content View History API の組織を越えた認証バイパス(CVE-2026-79654)

* yggdrasil-worker-forwarder:Golang crypto/tls:無限の KeyUpdate メッセージによるサービス拒否(CVE-2026-56862)

* yggdrasil-worker-forwarder:golang net/url:パス解決の二次複雑度によるサービス拒否(CVE-2026-56860)

* yggdrasil-worker-forwarder:Go encoding/asn1:Unmarshal の過剰な再帰によるサービス拒否(CVE-2026-33818)

* yggdrasil-worker-forwarder:html/template へ移動:異常な入力によるクロスサイトスクリプティング(CVE-2026-56858)

* rubygem-katello:不適切な承認ロジックにより、リソース列挙が可能になります(CVE-2026-56098)

* rubygem-katello:ラベルによる Registry Proxy における SQL インジェクション(CVE-2026-56097)

* rubygem-hammer_cli:安全でないエディター呼び出しからのコマンドインジェクション(CVE-2026-12545)

* foreman:foreman-rake 構成の SSTI および安全でない逆シリアル化(CVE-2026-12544)

* foreman:foreman-tail でのコマンドインジェクション(CVE-2026-12542)

* foreman:Foreman-rake データベースタスクでのコマンドインジェクション(CVE-2026-12541)

* foreman:request_id パラメーターを介した foreman-rake errors:fetch_log でのコマンドインジェクション(CVE-2026-12540)

* foreman:プロビジョニングトークン検証の欠陥による認証されていない情報漏えい(CVE-2026-12423)

* rubygem-foreman_remote_execution:effective_user パラメーターを介したジョブ呼び出しのコマンドインジェクション(CVE-2026-12405)

* foreman:RCE につながるセーフモードバイパス(CVE-2026-96658)

バグ修正:

* ^ 演算子で parent_hostgroup パラメーターを使用する際に発生する問題(SAT-50953)

* PG::InternalError:エラー:ホスト使用時の無効なメモリ割り当てリクエストサイズ1714242091 - 利用可能なエラータレポートテンプレート(SAT-50952)

Tenable は、前述の記述ブロックを Red Hat Enterprise Linux セキュリティアドバイザリから直接抽出しています。

Nessus はこれらの問題をテストしておらず、代わりにアプリケーションが自己報告するバージョン番号にのみ依存していることに注意してください。

ソリューション

影響を受けるパッケージを更新してください。

参考資料

https://access.redhat.com/errata/RHSA-2026:74504

https://access.redhat.com/security/updates/classification/#critical

https://bugzilla.redhat.com/show_bug.cgi?id=2449774

https://bugzilla.redhat.com/show_bug.cgi?id=2484204

https://bugzilla.redhat.com/show_bug.cgi?id=2488952

https://bugzilla.redhat.com/show_bug.cgi?id=2488956

https://bugzilla.redhat.com/show_bug.cgi?id=2489969

https://bugzilla.redhat.com/show_bug.cgi?id=2489970

https://bugzilla.redhat.com/show_bug.cgi?id=2489971

https://bugzilla.redhat.com/show_bug.cgi?id=2489992

https://bugzilla.redhat.com/show_bug.cgi?id=2489993

https://bugzilla.redhat.com/show_bug.cgi?id=2490542

https://bugzilla.redhat.com/show_bug.cgi?id=2490543

https://bugzilla.redhat.com/show_bug.cgi?id=2515815

https://bugzilla.redhat.com/show_bug.cgi?id=2515820

https://bugzilla.redhat.com/show_bug.cgi?id=2515838

https://bugzilla.redhat.com/show_bug.cgi?id=2515839

https://bugzilla.redhat.com/show_bug.cgi?id=2517518

https://bugzilla.redhat.com/show_bug.cgi?id=2517523

https://bugzilla.redhat.com/show_bug.cgi?id=2517527

https://bugzilla.redhat.com/show_bug.cgi?id=2523205

https://bugzilla.redhat.com/show_bug.cgi?id=2523348

https://bugzilla.redhat.com/show_bug.cgi?id=2530744

https://bugzilla.redhat.com/show_bug.cgi?id=2534185

https://bugzilla.redhat.com/show_bug.cgi?id=2536844

https://issues.redhat.com/browse/SAT-50952

https://issues.redhat.com/browse/SAT-50953

http://www.nessus.org/u?d0930597

プラグインの詳細

深刻度: High

ID: 362465

ファイル名: redhat-RHSA-2026-74504.nasl

バージョン: 1.1

タイプ: Local

エージェント: unix

公開日: 2026/10/1

更新日: 2026/10/1

サポートされているセンサー: Agentless Assessment, Continuous Assessment, Frictionless Assessment Agent, Frictionless Assessment AWS, Frictionless Assessment Azure, Nessus Agent, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

リスク情報

VPR

リスクファクター: High

スコア: 7

パーセンタイル: 98.05

Vendor

Vendor Severity: Critical

CVSS v2

リスクファクター: High

基本値: 8

現状値: 6.3

ベクトル: CVSS2#AV:N/AC:L/Au:S/C:C/I:P/A:P

CVSS スコアのソース: CVE-2026-96659

CVSS v3

リスクファクター: High

基本値: 8.1

現状値: 7.3

ベクトル: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

現状ベクトル: CVSS:3.0/E:P/RL:O/RC:C

CVSS スコアのソース: CVE-2026-33154

CVSS v4

リスクファクター: High

Base Score: 8.7

Threat Score: 7.4

Threat Vector: CVSS:4.0/E:P

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

CVSS スコアのソース: CVE-2026-87817

脆弱性情報

CPE: cpe:/o:redhat:enterprise_linux:9, p-cpe:/a:redhat:enterprise_linux:foreman-cli, p-cpe:/a:redhat:enterprise_linux:foreman-debug, p-cpe:/a:redhat:enterprise_linux:foreman-dynflow-sidekiq, p-cpe:/a:redhat:enterprise_linux:foreman-ec2, p-cpe:/a:redhat:enterprise_linux:foreman-journald, p-cpe:/a:redhat:enterprise_linux:foreman-libvirt, p-cpe:/a:redhat:enterprise_linux:foreman-openstack, p-cpe:/a:redhat:enterprise_linux:foreman-pcp, p-cpe:/a:redhat:enterprise_linux:foreman-postgresql, p-cpe:/a:redhat:enterprise_linux:foreman-redis, p-cpe:/a:redhat:enterprise_linux:foreman-service, p-cpe:/a:redhat:enterprise_linux:foreman-telemetry, p-cpe:/a:redhat:enterprise_linux:foreman-vmware, p-cpe:/a:redhat:enterprise_linux:foreman, p-cpe:/a:redhat:enterprise_linux:python3.12-dynaconf, p-cpe:/a:redhat:enterprise_linux:python3.12-gitpython, p-cpe:/a:redhat:enterprise_linux:python3.12-sqlparse, p-cpe:/a:redhat:enterprise_linux:rubygem-foreman_remote_execution-cockpit, p-cpe:/a:redhat:enterprise_linux:rubygem-foreman_remote_execution, p-cpe:/a:redhat:enterprise_linux:rubygem-hammer_cli, p-cpe:/a:redhat:enterprise_linux:rubygem-katello, p-cpe:/a:redhat:enterprise_linux:rubygem-safemode, p-cpe:/a:redhat:enterprise_linux:yggdrasil-worker-forwarder

必要な KB アイテム: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list, Host/cpu

エクスプロイトが利用可能: true

エクスプロイトの容易さ: Exploits are available

パッチ公開日: 2026/10/1

脆弱性公開日: 2026/3/18

参照情報

CVE: CVE-2026-12405, CVE-2026-12423, CVE-2026-12540, CVE-2026-12541, CVE-2026-12542, CVE-2026-12544, CVE-2026-12545, CVE-2026-33154, CVE-2026-33818, CVE-2026-42504, CVE-2026-54284, CVE-2026-56097, CVE-2026-56098, CVE-2026-56858, CVE-2026-56860, CVE-2026-56862, CVE-2026-59893, CVE-2026-71491, CVE-2026-78679, CVE-2026-79654, CVE-2026-87817, CVE-2026-96658, CVE-2026-96659

CWE: 1050, 1333, 203, 22, 267, 306, 502, 639, 770, 776, 78, 79, 89, 917

RHSA: 2026:74504