Amazon Linux 2023 : bpftool, kernel, kernel-devel (ALAS2023-2025-1350)

high Nessus Plugin ID 282382

Synopsis

The remote Amazon Linux 2023 host is missing a security update.

Description

It is, therefore, affected by multiple vulnerabilities as referenced in the ALAS2023-2025-1350 advisory.

In the Linux kernel, the following vulnerability has been resolved:

blk-mq: fix NULL dereference on q->elevator in blk_mq_elv_switch_none (CVE-2023-53292)

In the Linux kernel, the following vulnerability has been resolved:

block: fix race between set_blocksize and read paths (CVE-2025-38073)

In the Linux kernel, the following vulnerability has been resolved:

HID: core: Harden s32ton() against conversion to 0 bits (CVE-2025-38556)

In the Linux kernel, the following vulnerability has been resolved:

netfilter: nf_tables: reject duplicate device on updates (CVE-2025-38678)

In the Linux kernel, the following vulnerability has been resolved:

net/sched: sch_qfq: Fix null-deref in agg_dequeue (CVE-2025-40083)

In the Linux kernel, the following vulnerability has been resolved:

ACPI: video: Fix use-after-free in acpi_video_switch_brightness() (CVE-2025-40211)

In the Linux kernel, the following vulnerability has been resolved:

af_unix: Initialise scc_index in unix_add_edge(). (CVE-2025-40214)

In the Linux kernel, the following vulnerability has been resolved:

vsock: Ignore signal/timeout on connect() if already established (CVE-2025-40248)

In the Linux kernel, the following vulnerability has been resolved:

net: openvswitch: remove never-working support for setting nsh fields (CVE-2025-40254)

In the Linux kernel, the following vulnerability has been resolved:

mptcp: fix a race in mptcp_pm_del_add_timer() (CVE-2025-40257)

In the Linux kernel, the following vulnerability has been resolved:

mptcp: fix race condition in mptcp_schedule_work() (CVE-2025-40258)

In the Linux kernel, the following vulnerability has been resolved:

scsi: sg: Do not sleep in atomic context (CVE-2025-40259)

In the Linux kernel, the following vulnerability has been resolved:

be2net: pass wrb_params in case of OS2BMC (CVE-2025-40264)

In the Linux kernel, the following vulnerability has been resolved:

fs/proc: fix uaf in proc_readdir_de() (CVE-2025-40271)

In the Linux kernel, the following vulnerability has been resolved:

mm/secretmem: fix use-after-free race in fault handler (CVE-2025-40272)

In the Linux kernel, the following vulnerability has been resolved:

NFSD: free copynotify stateid in nfs4_free_ol_stateid() (CVE-2025-40273)

In the Linux kernel, the following vulnerability has been resolved:

drm/vmwgfx: Validate command header size against SVGA_CMD_MAX_DATASIZE (CVE-2025-40277)

In the Linux kernel, the following vulnerability has been resolved:

net: sched: act_connmark: initialize struct tc_ife to fix kernel leak (CVE-2025-40279)

In the Linux kernel, the following vulnerability has been resolved:

sctp: prevent possible shift-out-of-bounds in sctp_transport_update_rto (CVE-2025-40281)

In the Linux kernel, the following vulnerability has been resolved:

virtio-net: fix received length check in big packets (CVE-2025-40292)

In the Linux kernel, the following vulnerability has been resolved:

iommufd: Don't overflow during division for dirty tracking (CVE-2025-40293)

In the Linux kernel, the following vulnerability has been resolved:

net: bridge: fix use-after-free due to MST port state bypass (CVE-2025-40297)

In the Linux kernel, the following vulnerability has been resolved:

fbdev: Add bounds checking in bit_putcs to fix vmalloc-out-of-bounds (CVE-2025-40304)

In the Linux kernel, the following vulnerability has been resolved:

ntfs3: pretend $Extend records as regular files (CVE-2025-40313)

In the Linux kernel, the following vulnerability has been resolved:

bpf: Sync pending IRQ work before freeing ring buffer (CVE-2025-40319)

In the Linux kernel, the following vulnerability has been resolved:

fbdev: bitblit: bound-check glyph index in bit_putcs* (CVE-2025-40322)

In the Linux kernel, the following vulnerability has been resolved:

fbcon: Set fb_display[i]->mode to NULL when the mode is released (CVE-2025-40323)

In the Linux kernel, the following vulnerability has been resolved:

NFSD: Fix crash in nfsd4_read_release() (CVE-2025-40324)

In the Linux kernel, the following vulnerability has been resolved:

sctp: Prevent TOCTOU out-of-bounds write (CVE-2025-40331)

In the Linux kernel, the following vulnerability has been resolved:

futex: Don't leak robust_list pointer on exec race (CVE-2025-40341)

In the Linux kernel, the following vulnerability has been resolved:

drm/sysfb: Do not dereference NULL pointer in plane reset (CVE-2025-40360)

In the Linux kernel, the following vulnerability has been resolved:

fs: ext4: change GFP_KERNEL to GFP_NOFS to avoid deadlock (CVE-2025-40361)

In the Linux kernel, the following vulnerability has been resolved:

net: ipv6: fix field-spanning memcpy warning in AH output (CVE-2025-40363)

In the Linux kernel, the following vulnerability has been resolved:

x86/fpu: Ensure XFD state on signal delivery (CVE-2025-68171)

In the Linux kernel, the following vulnerability has been resolved:

ftrace: Fix softlockup in ftrace_module_enable (CVE-2025-68173)

In the Linux kernel, the following vulnerability has been resolved:

nfs4_setup_readdir(): insufficient locking for ->d_parent->d_inode dereferencing (CVE-2025-68185)

In the Linux kernel, the following vulnerability has been resolved:

udp_tunnel: use netdev_warn() instead of netdev_WARN() (CVE-2025-68191)

In the Linux kernel, the following vulnerability has been resolved:

bpf: Add bpf_prog_run_data_pointers() (CVE-2025-68200)

In the Linux kernel, the following vulnerability has been resolved:

timers: Fix NULL function pointer race in timer_shutdown_sync() (CVE-2025-68214)

In the Linux kernel, the following vulnerability has been resolved:

scsi: core: Fix a regression triggered by scsi_host_busy() (CVE-2025-68224)

In the Linux kernel, the following vulnerability has been resolved:

mptcp: Fix proto fallback detection with BPF (CVE-2025-68227)

In the Linux kernel, the following vulnerability has been resolved:

scsi: target: tcm_loop: Fix segfault in tcm_loop_tpg_address_show() (CVE-2025-68229)

In the Linux kernel, the following vulnerability has been resolved:

mm/mempool: fix poisoning order>0 pages with HIGHMEM (CVE-2025-68231)

In the Linux kernel, the following vulnerability has been resolved:

ipv4: route: Prevent rt_bind_exception() from rebinding stale fnhe (CVE-2025-68241)

In the Linux kernel, the following vulnerability has been resolved:

drm/i915: Avoid lock inversion when pinning to GGTT on CHV/BXT+VTD (CVE-2025-68244)

In the Linux kernel, the following vulnerability has been resolved:

libceph: replace BUG_ON with bounds check for map->max_osd (CVE-2025-68283)

In the Linux kernel, the following vulnerability has been resolved:

libceph: prevent potential out-of-bounds writes in handle_auth_session_key() (CVE-2025-68284)

In the Linux kernel, the following vulnerability has been resolved:

libceph: fix potential use-after-free in have_mon_and_osd_map() (CVE-2025-68285)

In the Linux kernel, the following vulnerability has been resolved:

usb: dwc3: Fix race condition between concurrent dwc3_remove_requests() call paths (CVE-2025-68287)

In the Linux kernel, the following vulnerability has been resolved:

usb: storage: Fix memory leak in USB bulk transport (CVE-2025-68288)

In the Linux kernel, the following vulnerability has been resolved:

smb: client: fix memory leak in cifs_construct_tcon() (CVE-2025-68295)

In the Linux kernel, the following vulnerability has been resolved:

page_pool: always add GFP_NOWARN for ATOMIC allocations (CVE-2025-68321)

Tenable has extracted the preceding description block directly from the tested product security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Run 'dnf update kernel --releasever 2023.10.20260105' or or 'dnf update --advisory ALAS2023-2025-1350 --releasever 2023.10.20260105' to update your system.

See Also

https://alas.aws.amazon.com//AL2023/ALAS2023-2025-1350.html

https://alas.aws.amazon.com/faqs.html

https://explore.alas.aws.amazon.com/CVE-2023-53292.html

https://explore.alas.aws.amazon.com/CVE-2025-38073.html

https://explore.alas.aws.amazon.com/CVE-2025-38556.html

https://explore.alas.aws.amazon.com/CVE-2025-38678.html

https://explore.alas.aws.amazon.com/CVE-2025-40083.html

https://explore.alas.aws.amazon.com/CVE-2025-40211.html

https://explore.alas.aws.amazon.com/CVE-2025-40214.html

https://explore.alas.aws.amazon.com/CVE-2025-40248.html

https://explore.alas.aws.amazon.com/CVE-2025-40254.html

https://explore.alas.aws.amazon.com/CVE-2025-40257.html

https://explore.alas.aws.amazon.com/CVE-2025-40258.html

https://explore.alas.aws.amazon.com/CVE-2025-40277.html

https://explore.alas.aws.amazon.com/CVE-2025-40279.html

https://explore.alas.aws.amazon.com/CVE-2025-40281.html

https://explore.alas.aws.amazon.com/CVE-2025-40292.html

https://explore.alas.aws.amazon.com/CVE-2025-40293.html

https://explore.alas.aws.amazon.com/CVE-2025-40297.html

https://explore.alas.aws.amazon.com/CVE-2025-40304.html

https://explore.alas.aws.amazon.com/CVE-2025-40313.html

https://explore.alas.aws.amazon.com/CVE-2025-40319.html

https://explore.alas.aws.amazon.com/CVE-2025-40322.html

https://explore.alas.aws.amazon.com/CVE-2025-40323.html

https://explore.alas.aws.amazon.com/CVE-2025-40324.html

https://explore.alas.aws.amazon.com/CVE-2025-40331.html

https://explore.alas.aws.amazon.com/CVE-2025-40341.html

https://explore.alas.aws.amazon.com/CVE-2025-40360.html

https://explore.alas.aws.amazon.com/CVE-2025-40361.html

https://explore.alas.aws.amazon.com/CVE-2025-40363.html

https://explore.alas.aws.amazon.com/CVE-2025-68171.html

https://explore.alas.aws.amazon.com/CVE-2025-68173.html

https://explore.alas.aws.amazon.com/CVE-2025-68185.html

https://explore.alas.aws.amazon.com/CVE-2025-68191.html

https://explore.alas.aws.amazon.com/CVE-2025-40259.html

https://explore.alas.aws.amazon.com/CVE-2025-40264.html

https://explore.alas.aws.amazon.com/CVE-2025-40271.html

https://explore.alas.aws.amazon.com/CVE-2025-40272.html

https://explore.alas.aws.amazon.com/CVE-2025-40273.html

https://explore.alas.aws.amazon.com/CVE-2025-68200.html

https://explore.alas.aws.amazon.com/CVE-2025-68214.html

https://explore.alas.aws.amazon.com/CVE-2025-68224.html

https://explore.alas.aws.amazon.com/CVE-2025-68227.html

https://explore.alas.aws.amazon.com/CVE-2025-68229.html

https://explore.alas.aws.amazon.com/CVE-2025-68231.html

https://explore.alas.aws.amazon.com/CVE-2025-68241.html

https://explore.alas.aws.amazon.com/CVE-2025-68244.html

https://explore.alas.aws.amazon.com/CVE-2025-68283.html

https://explore.alas.aws.amazon.com/CVE-2025-68284.html

https://explore.alas.aws.amazon.com/CVE-2025-68285.html

https://explore.alas.aws.amazon.com/CVE-2025-68287.html

https://explore.alas.aws.amazon.com/CVE-2025-68288.html

https://explore.alas.aws.amazon.com/CVE-2025-68295.html

https://explore.alas.aws.amazon.com/CVE-2025-68321.html

Plugin Details

Severity: High

ID: 282382

File Name: al2023_ALAS2023-2025-1350.nasl

Version: 1.1

Type: local

Agent: unix

Published: 1/8/2026

Updated: 1/8/2026

Supported Sensors: Frictionless Assessment AWS, Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Continuous Assessment, Nessus

Risk Information

VPR

Risk Factor: High

Score: 7.4

CVSS v2

Risk Factor: Medium

Base Score: 6.2

Temporal Score: 4.9

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:N/A:C

CVSS Score Source: CVE-2025-38556

CVSS v3

Risk Factor: High

Base Score: 7.1

Temporal Score: 6.4

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

CPE: p-cpe:/a:amazon:linux:kernel-modules-extra-common, p-cpe:/a:amazon:linux:perf-debuginfo, p-cpe:/a:amazon:linux:kernel-modules-extra, p-cpe:/a:amazon:linux:kernel-debuginfo-common-aarch64, p-cpe:/a:amazon:linux:kernel-tools, p-cpe:/a:amazon:linux:kernel-livepatch-6.1.159-181.297, p-cpe:/a:amazon:linux:python3-perf, p-cpe:/a:amazon:linux:kernel-libbpf-static, p-cpe:/a:amazon:linux:kernel-libbpf-debuginfo, p-cpe:/a:amazon:linux:kernel-debuginfo, p-cpe:/a:amazon:linux:kernel-libbpf, p-cpe:/a:amazon:linux:bpftool-debuginfo, p-cpe:/a:amazon:linux:kernel-libbpf-devel, p-cpe:/a:amazon:linux:kernel-headers, p-cpe:/a:amazon:linux:kernel-tools-devel, cpe:/o:amazon:linux:2023, p-cpe:/a:amazon:linux:perf, p-cpe:/a:amazon:linux:bpftool, p-cpe:/a:amazon:linux:kernel-tools-debuginfo, p-cpe:/a:amazon:linux:kernel-devel, p-cpe:/a:amazon:linux:kernel, p-cpe:/a:amazon:linux:python3-perf-debuginfo, p-cpe:/a:amazon:linux:kernel-debuginfo-common-x86_64

Required KB Items: Host/local_checks_enabled, Host/AmazonLinux/release, Host/AmazonLinux/rpm-list

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 1/7/2026

Vulnerability Publication Date: 8/19/2025

Reference Information

CVE: CVE-2023-53292, CVE-2025-38556, CVE-2025-38678, CVE-2025-40083, CVE-2025-40211, CVE-2025-40214, CVE-2025-40248, CVE-2025-40254, CVE-2025-40257, CVE-2025-40258, CVE-2025-40259, CVE-2025-40264, CVE-2025-40271, CVE-2025-40272, CVE-2025-40273, CVE-2025-40277, CVE-2025-40279, CVE-2025-40281, CVE-2025-40292, CVE-2025-40293, CVE-2025-40297, CVE-2025-40304, CVE-2025-40313, CVE-2025-40319, CVE-2025-40322, CVE-2025-40323, CVE-2025-40324, CVE-2025-40331, CVE-2025-40341, CVE-2025-40360, CVE-2025-40361, CVE-2025-40363, CVE-2025-68171, CVE-2025-68173, CVE-2025-68185, CVE-2025-68191, CVE-2025-68200, CVE-2025-68214, CVE-2025-68227, CVE-2025-68229, CVE-2025-68231, CVE-2025-68241, CVE-2025-68244, CVE-2025-68283, CVE-2025-68284, CVE-2025-68285, CVE-2025-68287, CVE-2025-68288, CVE-2025-68295, CVE-2025-68321