Language:
Severity: High
ID: 261826
File Name: alma_linux_ALSA-2025-15471.nasl
Version: 1.1
Type: local
Family: Alma Linux Local Security Checks
Published: 9/9/2025
Updated: 9/9/2025
Supported Sensors: Continuous Assessment, Nessus Agent, Nessus
Risk Factor: Critical
Score: 9.2
Risk Factor: Medium
Base Score: 6.8
Temporal Score: 5.6
Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C
CVSS Score Source: CVE-2025-38352
Risk Factor: High
Base Score: 7.4
Temporal Score: 6.9
Vector: CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Temporal Vector: CVSS:3.0/E:F/RL:O/RC:C
CPE: p-cpe:/a:alma:linux:kernel-tools, p-cpe:/a:alma:linux:kernel-cross-headers, p-cpe:/a:alma:linux:kernel-debug-modules-extra, p-cpe:/a:alma:linux:kernel-tools-libs-devel, p-cpe:/a:alma:linux:kernel, cpe:/o:alma:linux:8::appstream, p-cpe:/a:alma:linux:kernel-debug, p-cpe:/a:alma:linux:kernel-headers, p-cpe:/a:alma:linux:kernel-core, p-cpe:/a:alma:linux:kernel-zfcpdump-core, p-cpe:/a:alma:linux:kernel-zfcpdump, p-cpe:/a:alma:linux:kernel-zfcpdump-modules-extra, p-cpe:/a:alma:linux:perf, p-cpe:/a:alma:linux:kernel-debug-core, p-cpe:/a:alma:linux:kernel-modules, p-cpe:/a:alma:linux:kernel-zfcpdump-modules, cpe:/o:alma:linux:8::nfv, cpe:/o:alma:linux:8::powertools, cpe:/o:alma:linux:8, p-cpe:/a:alma:linux:kernel-debug-modules, cpe:/o:alma:linux:8::supplementary, p-cpe:/a:alma:linux:bpftool, p-cpe:/a:alma:linux:kernel-devel, p-cpe:/a:alma:linux:python3-perf, p-cpe:/a:alma:linux:kernel-debug-devel, p-cpe:/a:alma:linux:kernel-zfcpdump-devel, cpe:/o:alma:linux:8::sap_hana, cpe:/o:alma:linux:8::realtime, p-cpe:/a:alma:linux:kernel-modules-extra, cpe:/o:alma:linux:8::highavailability, p-cpe:/a:alma:linux:kernel-tools-libs, cpe:/o:alma:linux:8::resilientstorage, cpe:/o:alma:linux:8::baseos, cpe:/o:alma:linux:8::sap, p-cpe:/a:alma:linux:kernel-abi-stablelists
Required KB Items: Host/local_checks_enabled, Host/AlmaLinux/release, Host/AlmaLinux/rpm-list, Host/cpu
Exploit Available: true
Exploit Ease: Exploits are available
Patch Publication Date: 9/8/2025
Vulnerability Publication Date: 10/11/2022
CISA Known Exploited Vulnerability Due Dates: 9/25/2025
CVE: CVE-2022-49985, CVE-2025-38352
RHSA: 2025:15471