RHEL 9:Satellite 6.17.12 Async更新プログラム(重要度最高)(RHSA-2026:74505)

high Nessus プラグイン ID 362682

概要

リモートの Red Hat ホストに 1 つ以上のセキュリティ更新プログラムがありません。

説明

リモートの Redhat Enterprise Linux 9 ホストに、RHSA-2026:74505 アドバイザリに記載されている複数の脆弱性の影響を受けるパッケージがインストールされています。

Red Hat Satellite はシステム管理ソリューションです。これを使用することで組織は、組織のサーバーやその他クライアントシステムにパブリックインターネットアクセスを提供することなく、システムの設定や維持を行うことができるようになります。また、このソリューションは、事前に定義された標準のオペレーティング環境のプロビジョニングや設定管理も行います。

セキュリティ修正:
* foreman:プレビューの閲覧者ロールに対する過剰な権限(CVE-2026-96659)

* foreman:RCE につながるセーフモードバイパス(CVE-2026-96658)

* Dynaconf:サーバーサイドテンプレートインジェクションによる任意のコードの実行(CVE-2026-33154)

* GitPython:TagReference.create() を通じた任意のファイルの読み取り(CVE-2026-78679)

* GitPython:Git ディレクトリのなりすましによるリモートコードの実行(CVE-2026-87817)

* GitPython:Git ディレクトリのなりすましによるリモートコードの実行(CVE-2026-87817)

* Go encoding/asn1:Unmarshal の過剰な再帰によるサービス拒否(CVE-2026-33818)

* Go html/template:異常な入力によるクロスサイトスクリプティング(CVE-2026-56858)

* Golang MIME:悪意を持って細工された MIME ヘッダーによるサービス拒否(CVE-2026-42504)

* Golang crypto/tls:無限の KeyUpdate メッセージによるサービス拒否(CVE-2026-56862)

* Katello Content View History API の組織横断的な認証バイパス(CVE-2026-79654)

* golang net/url:パス解決の二次複雑性によるサービス拒否(CVE-2026-56860)

* lxml:xlink:href の欠落による Cleaner での URL バイパスの脆弱性(CVE-2026-49825)

* sqlparse:非効率的な SQL 解析によるサービス拒否(CVE-2026-59893)

* sqlparse:SQL 解析での 2 次 CPU 消費によるサービス拒否(CVE-2026-54284)

* sqlparse:コメントグループ化での二次 CPU 消費によるサービス拒否(CVE-2026-71491)

* rubygem-foreman_remote_execution:effective_user パラメーターを介したジョブ呼び出しのコマンドインジェクション(CVE-2026-12405)

* foreman:プロビジョニングトークン検証の欠陥による認証されていない情報漏えい(CVE-2026-12423)

* foreman:request_id パラメーターを介した foreman-rake errors:fetch_log でのコマンドインジェクション(CVE-2026-12540)

* foreman:Foreman-rake データベースタスクでのコマンドインジェクション(CVE-2026-12541)

* foreman:foreman-tail でのコマンドインジェクション(CVE-2026-12542)

* foreman:foreman-rake 構成の SSTI および安全でない逆シリアル化(CVE-2026-12544)

* rubygem-hammer_cli:安全でないエディター呼び出しからのコマンドインジェクション(CVE-2026-12545)

* rubygem-katello:ラベルによる Registry Proxy における SQL インジェクション(CVE-2026-56097)

* rubygem-katello:不適切な承認ロジックにより、リソース列挙が可能になります(CVE-2026-56098)

バグ修正:

* ^ 演算子で parent_hostgroup パラメーターを使用する際に発生する問題(SAT-50545)

* PG::InternalError: ERROR: ホスト使用時の無効なメモリ割り当てリクエストサイズが1714242091されます - 利用可能なエラータレポートテンプレート(SAT-50544)

Tenable は、前述の記述ブロックを Red Hat Enterprise Linux セキュリティアドバイザリから直接抽出しています。

Nessus はこれらの問題をテストしておらず、代わりにアプリケーションが自己報告するバージョン番号にのみ依存していることに注意してください。

ソリューション

影響を受けるパッケージを更新してください。

参考資料

https://access.redhat.com/errata/RHSA-2026:74505

https://access.redhat.com/security/updates/classification/#critical

https://bugzilla.redhat.com/show_bug.cgi?id=2449774

https://bugzilla.redhat.com/show_bug.cgi?id=2484204

https://bugzilla.redhat.com/show_bug.cgi?id=2488952

https://bugzilla.redhat.com/show_bug.cgi?id=2488956

https://bugzilla.redhat.com/show_bug.cgi?id=2489969

https://bugzilla.redhat.com/show_bug.cgi?id=2489970

https://bugzilla.redhat.com/show_bug.cgi?id=2489971

https://bugzilla.redhat.com/show_bug.cgi?id=2489992

https://bugzilla.redhat.com/show_bug.cgi?id=2489993

https://bugzilla.redhat.com/show_bug.cgi?id=2490542

https://bugzilla.redhat.com/show_bug.cgi?id=2490543

https://bugzilla.redhat.com/show_bug.cgi?id=2515815

https://bugzilla.redhat.com/show_bug.cgi?id=2515820

https://bugzilla.redhat.com/show_bug.cgi?id=2515838

https://bugzilla.redhat.com/show_bug.cgi?id=2515839

https://bugzilla.redhat.com/show_bug.cgi?id=2517518

https://bugzilla.redhat.com/show_bug.cgi?id=2517523

https://bugzilla.redhat.com/show_bug.cgi?id=2517527

https://bugzilla.redhat.com/show_bug.cgi?id=2520368

https://bugzilla.redhat.com/show_bug.cgi?id=2523205

https://bugzilla.redhat.com/show_bug.cgi?id=2523348

https://bugzilla.redhat.com/show_bug.cgi?id=2530744

https://bugzilla.redhat.com/show_bug.cgi?id=2534185

https://bugzilla.redhat.com/show_bug.cgi?id=2536844

https://issues.redhat.com/browse/SAT-50544

https://issues.redhat.com/browse/SAT-50545

http://www.nessus.org/u?3da86eef

プラグインの詳細

深刻度: High

ID: 362682

ファイル名: redhat-RHSA-2026-74505.nasl

バージョン: 1.1

タイプ: Local

エージェント: unix

公開日: 2026/10/2

更新日: 2026/10/2

サポートされているセンサー: Agentless Assessment, Continuous Assessment, Frictionless Assessment Agent, Frictionless Assessment AWS, Frictionless Assessment Azure, Nessus Agent, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

リスク情報

VPR

リスクファクター: High

スコア: 7

パーセンタイル: 98.05

Vendor

Vendor Severity: Critical

CVSS v2

リスクファクター: High

基本値: 7.6

現状値: 6

ベクトル: CVSS2#AV:N/AC:H/Au:N/C:C/I:C/A:C

CVSS スコアのソース: CVE-2026-33154

CVSS v3

リスクファクター: High

基本値: 8.1

現状値: 7.3

ベクトル: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

現状ベクトル: CVSS:3.0/E:P/RL:O/RC:C

CVSS v4

リスクファクター: High

Base Score: 8.7

Threat Score: 7.4

Threat Vector: CVSS:4.0/E:P

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

CVSS スコアのソース: CVE-2026-87817

脆弱性情報

CPE: cpe:/o:redhat:enterprise_linux:9, p-cpe:/a:redhat:enterprise_linux:foreman-cli, p-cpe:/a:redhat:enterprise_linux:foreman-debug, p-cpe:/a:redhat:enterprise_linux:foreman-dynflow-sidekiq, p-cpe:/a:redhat:enterprise_linux:foreman-ec2, p-cpe:/a:redhat:enterprise_linux:foreman-journald, p-cpe:/a:redhat:enterprise_linux:foreman-libvirt, p-cpe:/a:redhat:enterprise_linux:foreman-openstack, p-cpe:/a:redhat:enterprise_linux:foreman-ovirt, p-cpe:/a:redhat:enterprise_linux:foreman-pcp, p-cpe:/a:redhat:enterprise_linux:foreman-postgresql, p-cpe:/a:redhat:enterprise_linux:foreman-redis, p-cpe:/a:redhat:enterprise_linux:foreman-service, p-cpe:/a:redhat:enterprise_linux:foreman-telemetry, p-cpe:/a:redhat:enterprise_linux:foreman-vmware, p-cpe:/a:redhat:enterprise_linux:foreman, p-cpe:/a:redhat:enterprise_linux:python-dynaconf, p-cpe:/a:redhat:enterprise_linux:python-gitpython, p-cpe:/a:redhat:enterprise_linux:python-lxml, p-cpe:/a:redhat:enterprise_linux:python-sqlparse, p-cpe:/a:redhat:enterprise_linux:python3.11-dynaconf, p-cpe:/a:redhat:enterprise_linux:python3.11-gitpython, p-cpe:/a:redhat:enterprise_linux:python3.11-lxml, p-cpe:/a:redhat:enterprise_linux:python3.11-sqlparse, p-cpe:/a:redhat:enterprise_linux:rubygem-foreman_remote_execution-cockpit, p-cpe:/a:redhat:enterprise_linux:rubygem-foreman_remote_execution, p-cpe:/a:redhat:enterprise_linux:rubygem-hammer_cli, p-cpe:/a:redhat:enterprise_linux:rubygem-katello, p-cpe:/a:redhat:enterprise_linux:rubygem-safemode, p-cpe:/a:redhat:enterprise_linux:satellite-capsule, p-cpe:/a:redhat:enterprise_linux:satellite-cli, p-cpe:/a:redhat:enterprise_linux:satellite-common, p-cpe:/a:redhat:enterprise_linux:satellite-obsolete-packages, p-cpe:/a:redhat:enterprise_linux:satellite, p-cpe:/a:redhat:enterprise_linux:yggdrasil-worker-forwarder

必要な KB アイテム: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list, Host/cpu

エクスプロイトが利用可能: true

エクスプロイトの容易さ: Exploits are available

パッチ公開日: 2026/10/1

脆弱性公開日: 2026/3/18

参照情報

CVE: CVE-2026-12405, CVE-2026-12423, CVE-2026-12540, CVE-2026-12541, CVE-2026-12542, CVE-2026-12544, CVE-2026-12545, CVE-2026-33154, CVE-2026-33818, CVE-2026-42504, CVE-2026-49825, CVE-2026-54284, CVE-2026-56097, CVE-2026-56098, CVE-2026-56858, CVE-2026-56860, CVE-2026-56862, CVE-2026-59893, CVE-2026-71491, CVE-2026-78679, CVE-2026-79654, CVE-2026-87817, CVE-2026-96658, CVE-2026-96659

CWE: 1050, 1333, 166, 203, 22, 267, 306, 502, 639, 770, 776, 78, 79, 89, 917

RHSA: 2026:74505