EulerOS 2.0 SP13 : kernel (EulerOS-SA-2026-3021)

high Nessus Plugin ID 332872

Synopsis

The remote EulerOS host is missing multiple security updates.

Description

According to the versions of the kernel packages installed, the EulerOS installation on the remote host is affected by the following vulnerabilities :

USB: core: Limit the length of unkillable synchronous timeouts(CVE-2026-43428)

usb: typec: ucsi: validate connector number in ucsi_notify_common()(CVE-2026-31729)

ext4: reject mount if bigalloc with s_first_data_block != 0(CVE-2026-31447)

xfrm6: fix uninitialized saddr in xfrm6_get_saddr()(CVE-2026-43139)

rtmutex: Use waiter::task instead of current in remove_waiter()(CVE-2026-43499)

ext4: don#39;t set EXT4_GET_BLOCKS_CONVERT when splitting before submitting I/O(CVE-2026-45985)

KVM: SVM: Inject #UD for INVLPGA if EFER.SVME=0(CVE-2026-46082)

ipmi: Check event message buffer response for bad data(CVE-2026-46128)

ceph: add a bunch of missing ceph_path_info initializers(CVE-2026-43408)

libceph: Prevent potential null-ptr-deref in ceph_handle_auth_reply()(CVE-2026-46024)

netfilter: nf_conntrack_helper: pass helper to expect cleanup(CVE-2026-43027)

md/raid10: fix divide-by-zero in setup_geo() with zero far_copies(CVE-2026-46161)

xfrm: always flush state and policy upon NETDEV_UNREGISTER event(CVE-2026-43167)

HID: logitech-hidpp: Prevent use-after-free on force feedback initialisation failure(CVE-2026-43049)

nfsd: never defer requests during idmap lookup(CVE-2026-45983)

iommu/amd: move wait_on_sem() out of spinlock(CVE-2026-43253)

fat: avoid parent link count underflow in rmdir(CVE-2026-45915)

openvswitch: cap upcall PID array size and pre-size vport replies(CVE-2026-45840)

netfilter: nf_conntrack_sip: fix Content-Length u32 truncation in sip_help_tcp()(CVE-2026-23457)

PM: runtime: Fix a race condition related to device removal(CVE-2026-23452)

net/sched: sch_hfsc: fix divide-by-zero in rtsc_min()(CVE-2026-31423)

mm: blk-cgroup: fix use-after-free in cgwb_release_workfn()(CVE-2026-31586)

drm/ioc32: stop speculation on the drm_compat_ioctl path(CVE-2026-31781)

tpm: tpm_i2c_infineon: Fix locality leak on get_burstcount() failure(CVE-2026-45941)

xfs: remove xfs_attr_leaf_hasname(CVE-2026-43153)

fs/smb/client: fix out-of-bounds read in cifs_sanitize_prepath(CVE-2026-43112)

crypto: ccp: Don#39;t attempt to copy ID to userspace if PSP command failed(CVE-2026-31697)

fanotify: fix false positive on permission events(CVE-2026-46150)

ipv6: icmp: clear skb2-gt;cb[] in ip6_err_gen_icmpv6_unreach()(CVE-2026-43038)

APEI/GHES: ensure that won#39;t go past CPER allocated record(CVE-2026-43277)

netfilter: nf_conntrack_h323: fix OOB read in decode_choice()(CVE-2026-43233)

serial: core: fix infinite loop in handle_tx() for PORT_UNKNOWN(CVE-2026-23472)

xfrm: Wait for RCU readers during policy netns exit(CVE-2026-43091)

net: skbuff: propagate shared-frag marker through frag-transfer helpers(CVE-2026-43503)

net/tcp-md5: Fix MAC comparison to be constant-time(CVE-2026-43383)

ext4: avoid infinite loops caused by residual data(CVE-2026-31448)

bpf: fix end-of-list detection in cgroup_storage_get_next_key()(CVE-2026-45838)

ipvs: skip ipv6 extension headers for csum checks(CVE-2026-45850)

netfilter: ctnetlink: zero expect NAT fields when CTA_EXPECT_NAT absent(CVE-2026-43026)

mailbox: Prevent out-of-bounds access in fw_mbox_index_xlate()(CVE-2026-43281)

crypto: ccp: Don#39;t attempt to copy CSR to userspace if PSP command failed(CVE-2026-31699)

erofs: fix the out-of-bounds nameoff handling for trailing dirents(CVE-2026-46078)

spi: fix resource leaks on device setup failure(CVE-2026-46083)

RDMA/hns: Fix WQ_MEM_RECLAIM warning(CVE-2026-46265)

smb: client: reject userspace cifs.spnego descriptions(CVE-2026-46243)

RDMA/mlx4: Fix resource leak on error in mlx4_ib_create_srq()(CVE-2026-46178)

crypto: ccp: Don#39;t attempt to copy PDH cert to userspace if PSP command failed(CVE-2026-31698)

net/sched: sch_red: Replace direct dequeue call with peek and qdisc_dequeue_peeked(CVE-2026-43496)

ext4: fix dirtyclusters double decrement on fs shutdown(CVE-2026-45920)

ipv4: nexthop: allocate skb dynamically in rtm_get_nexthop()(CVE-2026-31531)

net: use skb_header_pointer() for TCPv4 GSO frag_off check(CVE-2026-43036)

KVM: SVM: Set/clear CR8 write interception when AVIC is (de)activated(CVE-2026-43483)

SUNRPC: auth_gss: fix memory leaks in XDR decoding error paths(CVE-2026-45870)

netfilter: nft_set_rbtree: check for partial overlaps in anonymous sets(CVE-2026-45873)

sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL(CVE-2026-46227)

ext4: drop extent cache after doing PARTIAL_VALID1 zeroout(CVE-2026-45892)

HID: multitouch: Check to ensure report responses match the request(CVE-2026-43047)

KVM: nSVM: Sync interrupt shadow to cached vmcb12 after VMRUN of L2(CVE-2026-45987)

scsi: storvsc: Fix scheduling while atomic on PREEMPT_RT(CVE-2026-43475)

x86/CPU: Fix FPDSS on Zen1(CVE-2026-31628)

net: usb: cdc_ncm: add ndpoffset to NDP16 nframes bounds check(CVE-2026-23448)

netfilter: nfnetlink_log: initialize nfgenmsg in NLMSG_DONE terminator(CVE-2026-43085)

scsi: csiostor: Fix dereference of null pointer rn(CVE-2026-45857)

netfilter: nf_tables: reject immediate NF_QUEUE verdict(CVE-2026-43024)

nvmet: move async event work off nvmet-wq(CVE-2026-31557)

dm: fix a buffer overflow in ioctl processing(CVE-2026-46294)

ipv6: xfrm6: release dst on error in xfrm6_rcv_encap()(CVE-2026-46172)

ext4: fix missing brelse() in ext4_xattr_inode_dec_ref_all()(CVE-2026-46046)

crypto: authencesn - reject short ahash digests during instance creation(CVE-2026-46033)

libceph: Fix potential out-of-bounds access in ceph_handle_auth_reply()(CVE-2026-43407)

xfs: fix undersized l_iclog_roundoff values(CVE-2026-43365)

ixgbevf: add missing negotiate_features op to Hyper-V ops table(CVE-2026-43094)

netfilter: nft_set_pipapo: fix stack out-of-bounds read in pipapo_drop()(CVE-2026-43453)

dlm: validate length in dlm_search_rsb_tree(CVE-2026-43125)

netfilter: ctnetlink: ensure safe access to master conntrack(CVE-2026-43116)

RDMA/hns: Fix unlocked call to hns_roce_qp_remove()(CVE-2026-46112)

esp: fix skb leak with espintcp and async crypto(CVE-2026-31518)

af_unix: read UNIX_DIAG_VFS data under unix_state_lock(CVE-2026-31673)

net/mlx5e: Fix DMA FIFO desync on error CQE SQ recovery(CVE-2026-43466)

drm/amd/display: Fix dc_link NULL handling in HPD init(CVE-2026-46245)

fbcon: Avoid OOB font access if console rotation fails(CVE-2026-46191)

smb: client: fix OOB read in smb2_ioctl_query_info QUERY_INFO path(CVE-2026-31708)

x86/CPU/AMD: Prevent improper isolation of shared resources in Zen2#39;s op cache(CVE-2026-46174)

HID: magicmouse: Do not crash on missing msc-gt;input(CVE-2026-43140)

dmaengine: idxd: fix possible wrong descriptor completion in llist_abort_desc()(CVE-2026-31436)

ipv6: rpl: reserve mac_len headroom when recompressed SRH grows(CVE-2026-43501)

ptrace: slightly saner #39;get_dumpable()#39; logic(CVE-2026-46333)

drm/nouveau: fix u32 overflow in pushbuf reloc bounds check(CVE-2026-46006)

md/bitmap: fix GPF in write_page caused by resize race(CVE-2026-43163)

KVM: SVM: Add missing save/restore handling of LBR MSRs(CVE-2026-46014)

ext4: fix memory leak in ext4_ext_shift_extents()(CVE-2026-45948)

udf: fix partition descriptor append bookkeeping(CVE-2026-45991)

xfs: fix freemap adjustments when adding xattrs to leaf blocks(CVE-2026-43158)

drm/gem: Fix inconsistent plane dimension calculation in drm_gem_fb_init_with_funcs()(CVE-2026-46209)

usb: usblp: fix heap leak in IEEE 1284 device ID via short response(CVE-2026-46151)

net: rtnetlink: zero ifla_vf_broadcast to avoid stack infoleak in rtnl_fill_vfinfo(CVE-2026-46132)

xfs: delete attr leaf freemap entries when empty(CVE-2026-43187)

ext4: fix iloc.bh leak in ext4_fc_replay_inode() error paths(CVE-2026-43066)

cpufreq: governor: fix double free in cpufreq_dbs_governor_init() error path(CVE-2026-43328)

netfilter: nft_ct: fix use-after-free in timeout object destroy(CVE-2026-31665)

netfilter: ctnetlink: ignore explicit helper on new expectations(CVE-2026-43025)

netfilter: nfnetlink_queue: fix entry leak in bridge verdict error path(CVE-2026-43451)

ext4: drop extent cache when splitting extent fails(CVE-2026-45899)

HID: alps: fix NULL pointer dereference in alps_raw_event()(CVE-2026-31625)

net: usb: pegasus: enable basic endpoint checking(CVE-2026-43156)

udp: Fix wildcard bind conflict check when using hash2(CVE-2026-31503)

net/sched: sch_netem: fix out-of-bounds access in packet corruption(CVE-2026-31675)

fuse: reject oversized dirents in page cache(CVE-2026-31694)

netfilter: ip6t_eui64: reject invalid MAC header for all packets(CVE-2026-31685)

l2tp: Drop large packets with UDP encap(CVE-2026-43080)

HID: core: Mitigate potential OOB by removing bogus memset()(CVE-2026-43048)

iommu/vt-d: Clear Present bit before tearing down context entry(CVE-2026-45944)

net: ipv6: flowlabel: defer exclusive option free until RCU teardown(CVE-2026-31680)

usb: class: cdc-wdm: fix reordering issue in read code path(CVE-2026-43427)

usb: image: mdc800: kill download URB on timeout(CVE-2026-43425)

mmc: vub300: fix NULL-deref on disconnect(CVE-2026-31651)

lib/crypto: mpi: Fix integer underflow in mpi_read_raw_from_sgl()(CVE-2026-43492)

ceph: fix i_nlink underrun during async unlink(CVE-2026-43420)

mmc: core: Avoid bitfield RMW for claim/retune flags(CVE-2026-43484)

net: strparser: fix skb_head leak in strp_abort_strp()(CVE-2026-46102)

unshare: fix unshare_fs() handling(CVE-2026-43472)

openvswitch: defer tunnel netdev_put to RCU release(CVE-2026-31678)

x86/apic: Disable x2apic on resume if the kernel expects so(CVE-2026-43363)

vsock/virtio: fix accept queue count leak on transport mismatch(CVE-2026-46214)

scsi: target: configfs: Bound snprintf() return in tg_pt_gp_members_show()(CVE-2026-46149)

ceph: only d_add() negative dentries when they are unhashed(CVE-2026-46052)

netfilter: nf_conntrack_h323: check for zero length in DecodeQ931()(CVE-2026-23455)

nouveau/dpcd: return EBUSY for aux xfer if the device is asleep(CVE-2026-43381)

netfilter: x_tables: guard option walkers against 1-byte tail reads(CVE-2026-43452)

netfilter: xt_tcpmss: check remaining length before reading optlen(CVE-2026-43190)

crypto: pcrypt - Fix handling of MAY_BACKLOG requests(CVE-2026-43493)

netfilter: arp_tables: fix IEEE1394 ARP payload parsing(CVE-2026-45844)

ext4: move ext4_percpu_param_init() before ext4_mb_init()(CVE-2026-43288)

netfilter: ctnetlink: fix use-after-free in ctnetlink_dump_exp_ct()(CVE-2026-23458)

dm: remove fake timeout to avoid leak request(CVE-2026-43314)

vsock: fix buffer size clamping order(CVE-2026-46234)

net: sched: cls_api: fix tc_chain_fill_node to initialize tcm_info to zero to prevent an info- leak(CVE-2026-43035)

net: consume xmit errors of GSO frames(CVE-2026-43194)

tipc: fix divide-by-zero in tipc_sk_filter_connect()(CVE-2026-43411)

APEI/GHES: ARM processor Error: don#39;t go past allocated memory(CVE-2026-43201)

dmaengine: idxd: Fix not releasing workqueue on .release()(CVE-2026-43064)

ext4: don#39;t zero the entire extent if EXT4_EXT_DATA_PARTIAL_VALID1(CVE-2026-45858)

netfilter: xt_multiport: validate range encoding in checkentry(CVE-2026-31681)

RDMA/vmw_pvrdma: Fix double free on pvrdma_alloc_ucontext() error path(CVE-2026-46189)

lib/crypto: chacha: Zeroize permuted_state before it leaves scope(CVE-2026-43336)

bridge: br_nd_send: validate ND option lengths(CVE-2026-31752)

nfsd: fix heap overflow in NFSv4.0 LOCK replay cache(CVE-2026-31402)

iommu/vt-d: Clear Present bit before tearing down PASID entry(CVE-2026-45894)

isofs: validate block number from NFS file handle in isofs_export_iget(CVE-2026-46124)

ext4: publish jinode after initialization(CVE-2026-31450)

net/sched: teql: Fix double-free in teql_master_xmit(CVE-2026-23449)

RDMA/rxe: Reject unknown opcodes before ICRC processing(CVE-2026-46133)

net: af_key: zero aligned sockaddr tail in PF_KEY exports(CVE-2026-43088)

netfilter: nfnetlink_cthelper: fix OOB read in nfnl_cthelper_dump_table()(CVE-2026-43450)

tracepoint: balance regfunc() on func_add() failure in tracepoint_add_func()(CVE-2026-46196)

nvme-pci: Fix race bug in nvme_poll_irqdisable()(CVE-2026-43448)

crypto: af-alg - fix NULL pointer dereference in scatterwalk(CVE-2026-43043)

RDMA/uverbs: Validate wqe_size before using it in ib_uverbs_post_send(CVE-2026-45856)

bpf: reject direct access to nullable PTR_TO_BUF pointers(CVE-2026-43333)

netfilter: conntrack: add missing netlink policy validations(CVE-2026-31407)

netfilter: reject zero shift in nft_bitwise(CVE-2026-46101)

fbdev: defio: Disconnect deferred I/O from the lifetime of struct fb_info(CVE-2026-46065)

vxlan: validate ND option lengths in vxlan_na_create(CVE-2026-31738)

inotify: fix watch count leak when fsnotify_add_inode_mark_locked() fails(CVE-2026-46040)

RDMA/mlx5: Fix UMR hang in LAG error state unload(CVE-2026-45973)

usb: ulpi: fix double free in ulpi_register_interface() error path(CVE-2026-31759)

slip: reject VJ receive packets on instances with no rstate array(CVE-2026-45842)

e1000/e1000e: Fix leak in DMA error cleanup(CVE-2026-43445)

futex: Clear stale exiting pointer in futex_lock_pi() retry path(CVE-2026-31555)

RDMA/rxe: Validate pad and ICRC before payload_size() in rxe_rcv(CVE-2026-46043)

slip: bound decode() reads against the compressed packet length(CVE-2026-45843)

net: ipv6: ndisc: fix ndisc_ra_useropt to initialize nduseropt_padX fields to zero to prevent an info- leak(CVE-2026-43040)

bpf: reject negative CO-RE accessor indices in bpf_core_parse_spec()(CVE-2026-45839)

netfilter: nfnetlink_osf: fix divide-by-zero in OSF_WSS_MODULO(CVE-2026-45841)

netfilter: nf_conntrack_h323: fix OOB read in decode_int() CONS case(CVE-2026-23456)

xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete(CVE-2026-46116)

driver core: platform: use generic driver_override infrastructure(CVE-2026-31527)

xfs: stop reclaim before pushing AIL during unmount(CVE-2026-31455)

ceph: supply snapshot context in ceph_zero_partial_object()(CVE-2026-43273)

ext4: convert inline data to extents when truncate exceeds inline size(CVE-2026-31452)

dm-thin: fix metadata refcount underflow(CVE-2026-46107)

netfilter: x_tables: restrict xt_check_match/xt_check_target extensions for NFPROTO_ARP(CVE-2026-31424)

usb: xhci: Fix memory leak in xhci_disable_slot()(CVE-2026-43432)

bonding: alb: fix UAF in rlb_arp_recv during bond up/down(CVE-2026-45970)

EFI/CPER: don#39;t go past the ARM processor CPER record buffer(CVE-2026-43266)

RDMA/rxe: Fix double free in rxe_srq_from_init(CVE-2026-45852)

SUNRPC: fix gss_auth kref leak in gss_alloc_msg error path(CVE-2026-45964)

nvmet-tcp: fix race between ICReq handling and queue teardown(CVE-2026-46135)

HID: core: clamp report_size in s32ton() to avoid undefined shift(CVE-2026-31624)

xfrm_user: fix info leak in build_report()(CVE-2026-31671)

EFI/CPER: don#39;t dump the entire memory region(CVE-2026-43171)

netfilter: nft_set_pipapo_avx2: don#39;t return non-matching entry on expiry(CVE-2026-43114)

pstore: ram_core: fix incorrect success return when vmap() fails(CVE-2026-43124)

USB: usbtmc: Use usb_bulk_msg_killable() with user-specified timeouts(CVE-2026-43429)

cgroup: fix race between task migration and iteration(CVE-2026-43439)

thermal: core: Fix thermal zone governor cleanup issues(CVE-2026-46021)

cpuidle: Skip governor when only one idle state is available(CVE-2026-45968)

netfilter: ctnetlink: use netlink policy range checks(CVE-2026-31495)

kprobes: avoid crash when rmmod/insmod after ftrace killed(CVE-2026-43409)

ipvs: do not keep dest_dst if dev is going down(CVE-2026-45917)

xfs: avoid dereferencing log items after push callbacks(CVE-2026-31453)

netfilter: x_tables: ensure names are nul-terminated(CVE-2026-43028)

xfrm: fix ip_rt_bug race in icmp_route_lookup reverse path(CVE-2026-45905)

HID: logitech-hidpp: Check maxfield in hidpp_get_report_length()(CVE-2026-43136)

net/sched: cls_fw: fix NULL pointer dereference on shared blocks(CVE-2026-31421)

openvswitch: validate MPLS set/set_masked payload length(CVE-2026-31679)

tcp: fix potential race in tcp_v6_syn_recv_sock()(CVE-2026-43198)

xfrm: hold dev ref until after transport_finish NF_HOOK(CVE-2026-31663)

bpf: Fix regsafe() for pointers to packet(CVE-2026-43030)

media: pvrusb2: fix URB leak in pvr2_send_request_ex(CVE-2026-43223)

tipc: fix bc_ackers underflow on duplicate GRP_ACK_MSG(CVE-2026-31662)

net/sched: cls_flow: fix NULL pointer dereference on shared blocks(CVE-2026-31422)

KVM: x86: Use scratch field in MMIO fragment to hold small write values(CVE-2026-31588)

pstore/ram: fix buffer overflow in persistent_ram_save_old()(CVE-2026-46253)

md/raid5: fix soft lockup in retry_aligned_read()(CVE-2026-46051)

net: bridge: use a stable FDB dst snapshot in RCU readers(CVE-2026-46086)

fbcon: check return value of con2fb_acquire_newinfo()(CVE-2026-43123)

xfrm: ah: account for ESN high bits in async callbacks(CVE-2026-46193)

net: rfkill: prevent unlimited numbers of rfkill events from being created(CVE-2026-31670)

comedi: dt2815: add hardware detection to prevent crash(CVE-2026-31751)

RDMA/mlx4: Fix mis-use of RCU in mlx4_srq_event()(CVE-2026-46181)

net: sched: act_csum: validate nested VLAN headers(CVE-2026-31684)

xfs: save ailp before dropping the AIL lock in push callbacks(CVE-2026-31454)

xsk: tighten UMEM headroom validation to account for tailroom and min frame(CVE-2026-43093)

8021q: delete cleared egress QoS mappings(CVE-2026-46153)

apparmor: fix NULL sock in aa_sock_file_perm(CVE-2026-45848)

net: hns3: fix double free issue for tx spare buffer(CVE-2026-45891)

ext4: avoid allocate block from corrupted group in ext4_mb_find_by_goal()(CVE-2026-43068)

ipv6: prevent possible UaF in addrconf_permanent_addr()(CVE-2026-43339)

mfd: core: Add locking around #39;mfd_of_node_list#39;(CVE-2026-43143)

net: Drop the lock in skb_may_tx_timestamp()(CVE-2026-43216)

dm mirror: fix integer overflow in create_dirty_log()(CVE-2026-46023)

ip6_tunnel: clear skb2-gt;cb[] in ip4ip6_err()(CVE-2026-43037)

net: usb: kaweth: remove TX queue manipulation in kaweth_set_rx_mode(CVE-2026-43180)

ipmi:si: Return state to normal if message allocation fails(CVE-2026-46108)

xfrm: account XFRMA_IF_ID in aevent size calculation(CVE-2026-43107)

ext4: validate p_idx bounds in ext4_ext_correct_indexes(CVE-2026-31449)

usb: usblp: fix uninitialized heap leak via LPGETSTATUS ioctl(CVE-2026-46167)

xfrm: prevent policy_hthresh.work from racing with netns teardown(CVE-2026-31516)

usb: usbtmc: Flush anchored URBs in usbtmc_release(CVE-2026-31758)

perf/x86/intel/uncore: Fix die ID init and look up bugs(CVE-2026-43344)

xfrm_user: fix info leak in build_mapping()(CVE-2026-43089)

smb: client: require a full NFS mode SID before reading mode bits(CVE-2026-43350)

net: usb: catc: enable basic endpoint checking(CVE-2026-45923)

media: saa7164: add ioremap return checks and cleanups(CVE-2026-46235)

ipmi:ssif: Clean up kthread on errors(CVE-2026-46044)

nvme-pci: Fix slab-out-of-bounds in nvme_dbbuf_set(CVE-2026-43449)

scsi: sd: fix missing put_disk() when device_add(amp;disk_dev) fails(CVE-2026-45997)

powerpc, perf: Check that current-gt;mm is alive before getting user callchain(CVE-2026-43416)

netfilter: nft_ct: drop pending enqueued packets on removal(CVE-2026-43060)

md/raid5: validate payload size before accessing journal metadata(CVE-2026-46070)

serial: 8250: Fix TX deadlock when using DMA(CVE-2026-43061)

md raid: fix hang when stopping arrays with metadata through dm-raid(CVE-2026-43309)

x86-64: rename misleadingly named #39;__copy_user_nocache()#39; function(CVE-2026-43073)

perf/x86/intel/uncore: Skip discovery table for offline dies(CVE-2026-43079)

nvme-pci: ensure we#39;re polling a polled queue(CVE-2026-31523)

xfrm: clear trailing padding in build_polexpire()(CVE-2026-31664)

net/packet: fix TOCTOU race on mmap#39;d vnet_hdr in tpacket_snd()(CVE-2026-31700)

ipmi: Add limits to event and receive message requests(CVE-2026-46177)

ipv6: avoid overflows in ip6_datagram_send_ctl()(CVE-2026-31415)

module: Fix kernel panic when a symbol st_shndx is out of bounds(CVE-2026-31521)

dmaengine: idxd: Fix memory leak when a wq is reset(CVE-2026-31441)

bridge: br_nd_send: linearize skb before parsing ND options(CVE-2026-31682)

crypto: af_alg - limit RX SG extraction by receive buffer budget(CVE-2026-31677)

net: bonding: fix use-after-free in bond_xmit_broadcast()(CVE-2026-31419)

NFSD: Hold net reference for the lifetime of /proc/fs/nfs/exports fd(CVE-2026-31403)

netfilter: ipset: drop logically empty buckets in mtype_del(CVE-2026-31418)

smb: client: fix krb5 mount with username option(CVE-2026-31392)

af_key: validate families in pfkey_send_migrate()(CVE-2026-31515)

netfilter: nfnetlink_log: account for netlink header size(CVE-2026-31416)

sunrpc: fix cache_request leak in cache_release(CVE-2026-31400)

netfilter: nf_conntrack_expect: skip expectations in other netns via proc(CVE-2026-31496)

net: usb: cdc_ncm: add ndpoffset to NDP32 nframes bounds check(CVE-2026-23447)

net: openvswitch: Avoid releasing netdev before teardown completes(CVE-2026-31508)

virtio_net: Fix UAF on dst_ops when IFF_XMIT_DST_RELEASE is cleared and napi_tx is false(CVE-2026-31469)

net: bonding: fix NULL deref in bond_debug_rlb_hash_show(CVE-2026-31546)

nvdimm/bus: Fix potential use after free in asynchronous initialization(CVE-2026-31399)

media: mc, v4l2: serialize REINIT and REQBUFS with req_queue_mutex(CVE-2026-31473)

ACPI: EC: clean up handlers on probe failure in acpi_ec_setup()(CVE-2026-31426)

netfilter: ip6t_rt: reject oversized addrnr in rt_mt6_check()(CVE-2026-31674)

netfilter: nf_conntrack_sip: fix use of uninitialized rtp_addr in process_sdp(CVE-2026-31427)

netfilter: nfnetlink_log: fix uninitialized padding leak in NFULA_PAYLOAD(CVE-2026-31428)

media: dvb-net: fix OOB access in ULE extension header tables(CVE-2026-31405)

spi: use generic driver_override infrastructure(CVE-2026-31487)

netfilter: nf_conntrack_expect: use expect-gt;helper(CVE-2026-31414)

Tenable has extracted the preceding description block directly from the EulerOS kernel security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected kernel packages.

See Also

http://www.nessus.org/u?e6818737

Plugin Details

Severity: High

ID: 332872

File Name: EulerOS_SA-2026-3021.nasl

Version: 1.1

Type: Local

Published: 8/6/2026

Updated: 8/6/2026

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Critical

Score: 9.4

Percentile: 99.82

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5.9

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2026-46294

CVSS v3

Risk Factor: High

Base Score: 7.8

Temporal Score: 7.5

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:H/RL:O/RC:C

Vulnerability Information

CPE: cpe:/o:huawei:euleros:2.0, p-cpe:/a:huawei:euleros:bpftool, p-cpe:/a:huawei:euleros:kernel-abi-stablelists, p-cpe:/a:huawei:euleros:kernel-tools-libs-devel, p-cpe:/a:huawei:euleros:kernel-tools-libs, p-cpe:/a:huawei:euleros:kernel-tools, p-cpe:/a:huawei:euleros:kernel, p-cpe:/a:huawei:euleros:perf-lite, p-cpe:/a:huawei:euleros:perf, p-cpe:/a:huawei:euleros:python3-perf

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/EulerOS/release, Host/EulerOS/rpm-list, Host/EulerOS/sp

Excluded KB Items: Host/EulerOS/uvp_version

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 8/6/2026

Vulnerability Publication Date: 3/12/2026

Reference Information

CVE: CVE-2026-23447, CVE-2026-23448, CVE-2026-23449, CVE-2026-23452, CVE-2026-23455, CVE-2026-23456, CVE-2026-23457, CVE-2026-23458, CVE-2026-23472, CVE-2026-31392, CVE-2026-31399, CVE-2026-31400, CVE-2026-31402, CVE-2026-31403, CVE-2026-31405, CVE-2026-31407, CVE-2026-31414, CVE-2026-31415, CVE-2026-31416, CVE-2026-31418, CVE-2026-31419, CVE-2026-31421, CVE-2026-31422, CVE-2026-31423, CVE-2026-31424, CVE-2026-31426, CVE-2026-31427, CVE-2026-31428, CVE-2026-31436, CVE-2026-31441, CVE-2026-31447, CVE-2026-31448, CVE-2026-31449, CVE-2026-31450, CVE-2026-31452, CVE-2026-31453, CVE-2026-31454, CVE-2026-31455, CVE-2026-31469, CVE-2026-31473, CVE-2026-31487, CVE-2026-31495, CVE-2026-31496, CVE-2026-31503, CVE-2026-31508, CVE-2026-31515, CVE-2026-31516, CVE-2026-31518, CVE-2026-31521, CVE-2026-31523, CVE-2026-31527, CVE-2026-31531, CVE-2026-31546, CVE-2026-31555, CVE-2026-31557, CVE-2026-31586, CVE-2026-31588, CVE-2026-31624, CVE-2026-31625, CVE-2026-31628, CVE-2026-31651, CVE-2026-31662, CVE-2026-31663, CVE-2026-31664, CVE-2026-31665, CVE-2026-31670, CVE-2026-31671, CVE-2026-31673, CVE-2026-31674, CVE-2026-31675, CVE-2026-31677, CVE-2026-31678, CVE-2026-31679, CVE-2026-31680, CVE-2026-31681, CVE-2026-31682, CVE-2026-31684, CVE-2026-31685, CVE-2026-31694, CVE-2026-31697, CVE-2026-31698, CVE-2026-31699, CVE-2026-31700, CVE-2026-31708, CVE-2026-31729, CVE-2026-31738, CVE-2026-31751, CVE-2026-31752, CVE-2026-31758, CVE-2026-31759, CVE-2026-31781, CVE-2026-43024, CVE-2026-43025, CVE-2026-43026, CVE-2026-43027, CVE-2026-43028, CVE-2026-43030, CVE-2026-43035, CVE-2026-43036, CVE-2026-43037, CVE-2026-43038, CVE-2026-43040, CVE-2026-43043, CVE-2026-43047, CVE-2026-43048, CVE-2026-43049, CVE-2026-43060, CVE-2026-43061, CVE-2026-43064, CVE-2026-43066, CVE-2026-43068, CVE-2026-43073, CVE-2026-43079, CVE-2026-43080, CVE-2026-43085, CVE-2026-43088, CVE-2026-43089, CVE-2026-43091, CVE-2026-43093, CVE-2026-43094, CVE-2026-43107, CVE-2026-43112, CVE-2026-43114, CVE-2026-43116, CVE-2026-43123, CVE-2026-43124, CVE-2026-43125, CVE-2026-43136, CVE-2026-43139, CVE-2026-43140, CVE-2026-43143, CVE-2026-43153, CVE-2026-43156, CVE-2026-43158, CVE-2026-43163, CVE-2026-43167, CVE-2026-43171, CVE-2026-43180, CVE-2026-43187, CVE-2026-43190, CVE-2026-43194, CVE-2026-43198, CVE-2026-43201, CVE-2026-43216, CVE-2026-43223, CVE-2026-43233, CVE-2026-43253, CVE-2026-43266, CVE-2026-43273, CVE-2026-43277, CVE-2026-43281, CVE-2026-43288, CVE-2026-43309, CVE-2026-43314, CVE-2026-43328, CVE-2026-43333, CVE-2026-43336, CVE-2026-43339, CVE-2026-43344, CVE-2026-43350, CVE-2026-43363, CVE-2026-43365, CVE-2026-43381, CVE-2026-43383, CVE-2026-43407, CVE-2026-43408, CVE-2026-43409, CVE-2026-43411, CVE-2026-43416, CVE-2026-43420, CVE-2026-43425, CVE-2026-43427, CVE-2026-43428, CVE-2026-43429, CVE-2026-43432, CVE-2026-43439, CVE-2026-43445, CVE-2026-43448, CVE-2026-43449, CVE-2026-43450, CVE-2026-43451, CVE-2026-43452, CVE-2026-43453, CVE-2026-43466, CVE-2026-43472, CVE-2026-43475, CVE-2026-43483, CVE-2026-43484, CVE-2026-43492, CVE-2026-43493, CVE-2026-43496, CVE-2026-43499, CVE-2026-43501, CVE-2026-43503, CVE-2026-45838, CVE-2026-45839, CVE-2026-45840, CVE-2026-45841, CVE-2026-45842, CVE-2026-45843, CVE-2026-45844, CVE-2026-45848, CVE-2026-45850, CVE-2026-45852, CVE-2026-45856, CVE-2026-45857, CVE-2026-45858, CVE-2026-45870, CVE-2026-45873, CVE-2026-45891, CVE-2026-45892, CVE-2026-45894, CVE-2026-45899, CVE-2026-45905, CVE-2026-45915, CVE-2026-45917, CVE-2026-45920, CVE-2026-45923, CVE-2026-45941, CVE-2026-45944, CVE-2026-45948, CVE-2026-45964, CVE-2026-45968, CVE-2026-45970, CVE-2026-45973, CVE-2026-45983, CVE-2026-45985, CVE-2026-45987, CVE-2026-45991, CVE-2026-45997, CVE-2026-46006, CVE-2026-46014, CVE-2026-46021, CVE-2026-46023, CVE-2026-46024, CVE-2026-46033, CVE-2026-46040, CVE-2026-46043, CVE-2026-46044, CVE-2026-46046, CVE-2026-46051, CVE-2026-46052, CVE-2026-46065, CVE-2026-46070, CVE-2026-46078, CVE-2026-46082, CVE-2026-46083, CVE-2026-46086, CVE-2026-46101, CVE-2026-46102, CVE-2026-46107, CVE-2026-46108, CVE-2026-46112, CVE-2026-46116, CVE-2026-46124, CVE-2026-46128, CVE-2026-46132, CVE-2026-46133, CVE-2026-46135, CVE-2026-46149, CVE-2026-46150, CVE-2026-46151, CVE-2026-46153, CVE-2026-46161, CVE-2026-46167, CVE-2026-46172, CVE-2026-46174, CVE-2026-46177, CVE-2026-46178, CVE-2026-46181, CVE-2026-46189, CVE-2026-46191, CVE-2026-46193, CVE-2026-46196, CVE-2026-46209, CVE-2026-46214, CVE-2026-46227, CVE-2026-46234, CVE-2026-46235, CVE-2026-46243, CVE-2026-46245, CVE-2026-46253, CVE-2026-46265, CVE-2026-46294, CVE-2026-46333