Amazon Linux 2023 : bpftool6.12, kernel6.12, kernel6.12-devel (ALAS2023-2026-1495)

high Nessus Plugin ID 304297

Synopsis

The remote Amazon Linux 2023 host is missing a security update.

Description

It is, therefore, affected by multiple vulnerabilities as referenced in the ALAS2023-2026-1495 advisory.

In the Linux kernel, the following vulnerability has been resolved:

net/sched: sch_qfq: Fix null-deref in agg_dequeue (CVE-2025-40083)

In the Linux kernel, the following vulnerability has been resolved:

btrfs: fix memory leak of qgroup_list in btrfs_add_qgroup_relation (CVE-2025-40209)

In the Linux kernel, the following vulnerability has been resolved:

ACPI: video: Fix use-after-free in acpi_video_switch_brightness() (CVE-2025-40211)

In the Linux kernel, the following vulnerability has been resolved:

mm: prevent poison consumption when splitting THP (CVE-2025-40230)

In the Linux kernel, the following vulnerability has been resolved:

vsock: fix lock inversion in vsock_assign_transport() (CVE-2025-40231)

In the Linux kernel, the following vulnerability has been resolved:

btrfs: directly free partially initialized fs_info in btrfs_check_leaked_roots() (CVE-2025-40235)

In the Linux kernel, the following vulnerability has been resolved:

fs/notify: call exportfs_encode_fid with s_umount (CVE-2025-40237)

In the Linux kernel, the following vulnerability has been resolved:

net/mlx5: Fix IPsec cleanup over MPV device (CVE-2025-40238)

In the Linux kernel, the following vulnerability has been resolved:

sctp: avoid NULL dereference when chunk data buffer is missing (CVE-2025-40240)

In the Linux kernel, the following vulnerability has been resolved:

virtio-net: fix received length check in big packets (CVE-2025-40292)

In the Linux kernel, the following vulnerability has been resolved:

iommufd: Don't overflow during division for dirty tracking (CVE-2025-40293)

In the Linux kernel, the following vulnerability has been resolved:

net: bridge: fix use-after-free due to MST port state bypass (CVE-2025-40297)

In the Linux kernel, the following vulnerability has been resolved:

media: videobuf2: forbid remove_bufs when legacy fileio is active (CVE-2025-40302)

In the Linux kernel, the following vulnerability has been resolved:

btrfs: ensure no dirty metadata is written back for an fs with errors (CVE-2025-40303)

In the Linux kernel, the following vulnerability has been resolved:

fbdev: Add bounds checking in bit_putcs to fix vmalloc-out-of-bounds (CVE-2025-40304)

In the Linux kernel, the following vulnerability has been resolved:

exfat: validate cluster allocation bits of the allocation bitmap (CVE-2025-40307)

In the Linux kernel, the following vulnerability has been resolved:

ntfs3: pretend $Extend records as regular files (CVE-2025-40313)

In the Linux kernel, the following vulnerability has been resolved:

regmap: slimbus: fix bus_context pointer in regmap init calls (CVE-2025-40317)

In the Linux kernel, the following vulnerability has been resolved:

bpf: Sync pending IRQ work before freeing ring buffer (CVE-2025-40319)

In the Linux kernel, the following vulnerability has been resolved:

smb: client: fix potential cfid UAF in smb2_query_info_compound (CVE-2025-40320)

In the Linux kernel, the following vulnerability has been resolved:

fbdev: bitblit: bound-check glyph index in bit_putcs* (CVE-2025-40322)

In the Linux kernel, the following vulnerability has been resolved:

fbcon: Set fb_display[i]->mode to NULL when the mode is released (CVE-2025-40323)

In the Linux kernel, the following vulnerability has been resolved:

NFSD: Fix crash in nfsd4_read_release() (CVE-2025-40324)

In the Linux kernel, the following vulnerability has been resolved:

smb: client: fix potential UAF in smb2_close_cached_fid() (CVE-2025-40328)

In the Linux kernel, the following vulnerability has been resolved:

drm/sched: Fix deadlock in drm_sched_entity_kill_jobs_cb (CVE-2025-40329)

In the Linux kernel, the following vulnerability has been resolved:

sctp: Prevent TOCTOU out-of-bounds write (CVE-2025-40331)

In the Linux kernel, the following vulnerability has been resolved:

futex: Don't leak robust_list pointer on exec race (CVE-2025-40341)

In the Linux kernel, the following vulnerability has been resolved:

arch_topology: Fix incorrect error check in topology_parse_cpu_capacity() (CVE-2025-40346)

In the Linux kernel, the following vulnerability has been resolved:

slab: Avoid race on slab->obj_exts in alloc_slab_obj_exts (CVE-2025-40348)

In the Linux kernel, the following vulnerability has been resolved:

net/mlx5e: RX, Fix generating skb from non-linear xdp_buff for striding RQ (CVE-2025-40350)

In the Linux kernel, the following vulnerability has been resolved:

arm64: mte: Do not warn if the page is already tagged in copy_highpage() (CVE-2025-40353)

In the Linux kernel, the following vulnerability has been resolved:

net/smc: fix general protection fault in __smc_diag_dump (CVE-2025-40357)

In the Linux kernel, the following vulnerability has been resolved:

perf/x86/intel: Fix KASAN global-out-of-bounds warning (CVE-2025-40359)

In the Linux kernel, the following vulnerability has been resolved:

drm/sysfb: Do not dereference NULL pointer in plane reset (CVE-2025-40360)

In the Linux kernel, the following vulnerability has been resolved:

ceph: fix multifs mds auth caps issue (CVE-2025-40362)

In the Linux kernel, the following vulnerability has been resolved:

net: ipv6: fix field-spanning memcpy warning in AH output (CVE-2025-40363)

In the Linux kernel, the following vulnerability has been resolved:

gpiolib: fix invalid pointer access in debugfs (CVE-2025-68167)

In the Linux kernel, the following vulnerability has been resolved:

x86/fpu: Ensure XFD state on signal delivery (CVE-2025-68171)

In the Linux kernel, the following vulnerability has been resolved:

ftrace: Fix softlockup in ftrace_module_enable (CVE-2025-68173)

In the Linux kernel, the following vulnerability has been resolved:

cpufreq/longhaul: handle NULL policy in longhaul_exit (CVE-2025-68177)

In the Linux kernel, the following vulnerability has been resolved:

blk-cgroup: fix possible deadlock while configuring policy (CVE-2025-68178)

In the Linux kernel, the following vulnerability has been resolved:

ima: don't clear IMA_DIGSIG flag when setting or removing non-IMA xattr (CVE-2025-68183)

In the Linux kernel, the following vulnerability has been resolved:

nfs4_setup_readdir(): insufficient locking for ->d_parent->d_inode dereferencing (CVE-2025-68185)

In the Linux kernel, the following vulnerability has been resolved:

ring-buffer: Do not warn in ring_buffer_map_get_reader() when reader catches up (CVE-2025-68186)

In the Linux kernel, the following vulnerability has been resolved:

tcp: use dst_dev_rcu() in tcp_fastopen_active_disable_ofo_check() (CVE-2025-68188)

In the Linux kernel, the following vulnerability has been resolved:

udp_tunnel: use netdev_warn() instead of netdev_WARN() (CVE-2025-68191)

In the Linux kernel, the following vulnerability has been resolved:

tty: serial: ip22zilog: Use platform device for probing (CVE-2025-68311)

In the Linux kernel, the following vulnerability has been resolved:

x86/CPU/AMD: Add RDSEED fix for Zen5 (CVE-2025-68313)

In the Linux kernel, the following vulnerability has been resolved:

io_uring/zctx: check chained notif contexts (CVE-2025-68317)

In the Linux kernel, the following vulnerability has been resolved:

page_pool: always add GFP_NOWARN for ATOMIC allocations (CVE-2025-68321)

Tenable has extracted the preceding description block directly from the tested product security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Run 'dnf update kernel6.12 --releasever 2023.10.20260325' or or 'dnf update --advisory ALAS2023-2026-1495 --releasever 2023.10.20260325' to update your system.

See Also

https://alas.aws.amazon.com//AL2023/ALAS2023-2026-1495.html

https://alas.aws.amazon.com/faqs.html

https://explore.alas.aws.amazon.com/CVE-2025-40083.html

https://explore.alas.aws.amazon.com/CVE-2025-40209.html

https://explore.alas.aws.amazon.com/CVE-2025-40211.html

https://explore.alas.aws.amazon.com/CVE-2025-40230.html

https://explore.alas.aws.amazon.com/CVE-2025-40231.html

https://explore.alas.aws.amazon.com/CVE-2025-40235.html

https://explore.alas.aws.amazon.com/CVE-2025-40237.html

https://explore.alas.aws.amazon.com/CVE-2025-40238.html

https://explore.alas.aws.amazon.com/CVE-2025-40240.html

https://explore.alas.aws.amazon.com/CVE-2025-40292.html

https://explore.alas.aws.amazon.com/CVE-2025-40293.html

https://explore.alas.aws.amazon.com/CVE-2025-40297.html

https://explore.alas.aws.amazon.com/CVE-2025-40302.html

https://explore.alas.aws.amazon.com/CVE-2025-40303.html

https://explore.alas.aws.amazon.com/CVE-2025-40304.html

https://explore.alas.aws.amazon.com/CVE-2025-40307.html

https://explore.alas.aws.amazon.com/CVE-2025-40313.html

https://explore.alas.aws.amazon.com/CVE-2025-40317.html

https://explore.alas.aws.amazon.com/CVE-2025-40319.html

https://explore.alas.aws.amazon.com/CVE-2025-40320.html

https://explore.alas.aws.amazon.com/CVE-2025-40322.html

https://explore.alas.aws.amazon.com/CVE-2025-40323.html

https://explore.alas.aws.amazon.com/CVE-2025-40324.html

https://explore.alas.aws.amazon.com/CVE-2025-40328.html

https://explore.alas.aws.amazon.com/CVE-2025-40329.html

https://explore.alas.aws.amazon.com/CVE-2025-40331.html

https://explore.alas.aws.amazon.com/CVE-2025-40341.html

https://explore.alas.aws.amazon.com/CVE-2025-40346.html

https://explore.alas.aws.amazon.com/CVE-2025-40348.html

https://explore.alas.aws.amazon.com/CVE-2025-40350.html

https://explore.alas.aws.amazon.com/CVE-2025-40353.html

https://explore.alas.aws.amazon.com/CVE-2025-40357.html

https://explore.alas.aws.amazon.com/CVE-2025-40359.html

https://explore.alas.aws.amazon.com/CVE-2025-40360.html

https://explore.alas.aws.amazon.com/CVE-2025-40362.html

https://explore.alas.aws.amazon.com/CVE-2025-40363.html

https://explore.alas.aws.amazon.com/CVE-2025-68167.html

https://explore.alas.aws.amazon.com/CVE-2025-68171.html

https://explore.alas.aws.amazon.com/CVE-2025-68173.html

https://explore.alas.aws.amazon.com/CVE-2025-68177.html

https://explore.alas.aws.amazon.com/CVE-2025-68178.html

https://explore.alas.aws.amazon.com/CVE-2025-68183.html

https://explore.alas.aws.amazon.com/CVE-2025-68185.html

https://explore.alas.aws.amazon.com/CVE-2025-68186.html

https://explore.alas.aws.amazon.com/CVE-2025-68188.html

https://explore.alas.aws.amazon.com/CVE-2025-68191.html

https://explore.alas.aws.amazon.com/CVE-2025-68311.html

https://explore.alas.aws.amazon.com/CVE-2025-68313.html

https://explore.alas.aws.amazon.com/CVE-2025-68317.html

https://explore.alas.aws.amazon.com/CVE-2025-68321.html

Plugin Details

Severity: High

ID: 304297

File Name: al2023_ALAS2023-2026-1495.nasl

Version: 1.1

Type: local

Agent: unix

Published: 3/30/2026

Updated: 3/30/2026

Supported Sensors: Frictionless Assessment AWS, Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Continuous Assessment, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.7

CVSS v2

Risk Factor: High

Base Score: 9

Temporal Score: 6.7

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:C

CVSS Score Source: CVE-2025-40240

CVSS v3

Risk Factor: High

Base Score: 8.6

Temporal Score: 7.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: p-cpe:/a:amazon:linux:python3-perf6.12, p-cpe:/a:amazon:linux:kernel6.12-libbpf, p-cpe:/a:amazon:linux:kernel6.12, p-cpe:/a:amazon:linux:kernel-livepatch-6.12.58-82.121, p-cpe:/a:amazon:linux:kernel6.12-libbpf-static, p-cpe:/a:amazon:linux:kernel6.12-tools-devel, p-cpe:/a:amazon:linux:kernel6.12-libbpf-debuginfo, p-cpe:/a:amazon:linux:kernel6.12-headers, p-cpe:/a:amazon:linux:kernel6.12-modules-extra, p-cpe:/a:amazon:linux:kernel6.12-debuginfo, p-cpe:/a:amazon:linux:bpftool6.12-debuginfo, p-cpe:/a:amazon:linux:bpftool6.12, p-cpe:/a:amazon:linux:kernel6.12-debuginfo-common-x86_64, p-cpe:/a:amazon:linux:perf6.12, p-cpe:/a:amazon:linux:perf6.12-debuginfo, p-cpe:/a:amazon:linux:kernel6.12-debuginfo-common-aarch64, p-cpe:/a:amazon:linux:kernel6.12-modules-extra-common, cpe:/o:amazon:linux:2023, p-cpe:/a:amazon:linux:kernel6.12-devel, p-cpe:/a:amazon:linux:kernel6.12-tools-debuginfo, p-cpe:/a:amazon:linux:python3-perf6.12-debuginfo, p-cpe:/a:amazon:linux:kernel6.12-libbpf-devel, p-cpe:/a:amazon:linux:kernel6.12-tools

Required KB Items: Host/local_checks_enabled, Host/AmazonLinux/release, Host/AmazonLinux/rpm-list

Exploit Ease: No known exploits are available

Patch Publication Date: 3/27/2026

Vulnerability Publication Date: 10/29/2025

Reference Information

CVE: CVE-2025-40083, CVE-2025-40209, CVE-2025-40211, CVE-2025-40230, CVE-2025-40231, CVE-2025-40235, CVE-2025-40237, CVE-2025-40238, CVE-2025-40240, CVE-2025-40292, CVE-2025-40293, CVE-2025-40297, CVE-2025-40302, CVE-2025-40303, CVE-2025-40304, CVE-2025-40307, CVE-2025-40313, CVE-2025-40317, CVE-2025-40319, CVE-2025-40320, CVE-2025-40322, CVE-2025-40323, CVE-2025-40324, CVE-2025-40328, CVE-2025-40329, CVE-2025-40331, CVE-2025-40341, CVE-2025-40346, CVE-2025-40348, CVE-2025-40350, CVE-2025-40353, CVE-2025-40357, CVE-2025-40359, CVE-2025-40360, CVE-2025-40362, CVE-2025-40363, CVE-2025-68167, CVE-2025-68171, CVE-2025-68173, CVE-2025-68177, CVE-2025-68178, CVE-2025-68183, CVE-2025-68185, CVE-2025-68186, CVE-2025-68188, CVE-2025-68191, CVE-2025-68311, CVE-2025-68313, CVE-2025-68317, CVE-2025-68321