EulerOS 2.0 SP15 : kernel (EulerOS-SA-2026-2889)

high Nessus Plugin ID 332913

Synopsis

The remote EulerOS host is missing multiple security updates.

Description

According to the versions of the kernel packages installed, the EulerOS installation on the remote host is affected by the following vulnerabilities :

mm: blk-cgroup: fix use-after-free in cgwb_release_workfn()(CVE-2026-31586)

e1000/e1000e: Fix leak in DMA error cleanup(CVE-2026-43445)

futex: Clear stale exiting pointer in futex_lock_pi() retry path(CVE-2026-31555)

kexec: derive purgatory entry from symbol(CVE-2026-43289)

nvme-pci: Fix race bug in nvme_poll_irqdisable()(CVE-2026-43448)

ext4: avoid infinite loops caused by residual data(CVE-2026-31448)

mm/userfaultfd: fix hugetlb fault mutex hash calculation(CVE-2026-31575)

netfilter: ip6t_rt: reject oversized addrnr in rt_mt6_check()(CVE-2026-31674)

net: skbuff: propagate shared-frag marker through frag-transfer helpers(CVE-2026-43503)

crypto: af-alg - fix NULL pointer dereference in scatterwalk(CVE-2026-43043)

net: bonding: fix NULL deref in bond_debug_rlb_hash_show(CVE-2026-31546)

drm/ioc32: stop speculation on the drm_compat_ioctl path(CVE-2026-31781)

ext4: always drain queued discard work in ext4_mb_release()(CVE-2026-43065)

netfilter: ctnetlink: fix use-after-free in ctnetlink_dump_exp_ct()(CVE-2026-23458)

x86/platform/uv: Handle deconfigured sockets(CVE-2026-31542)

USB: core: Limit the length of unkillable synchronous timeouts(CVE-2026-43428)

cifs: some missing initializations on replay(CVE-2026-31693)

serial: core: fix infinite loop in handle_tx() for PORT_UNKNOWN(CVE-2026-23472)

EDAC/mc: Fix error path ordering in edac_mc_alloc()(CVE-2026-31689)

module: Fix kernel panic when a symbol st_shndx is out of bounds(CVE-2026-31521)

can: gw: fix OOB heap access in cgw_csum_crc8_rel()(CVE-2026-31570)

ext4: publish jinode after initialization(CVE-2026-31450)

netfilter: xt_multiport: validate range encoding in checkentry(CVE-2026-31681)

usb: xhci: Prevent interrupt storm on host controller error (HCE)(CVE-2026-43488)

netfilter: nf_conntrack_sip: fix Content-Length u32 truncation in sip_help_tcp()(CVE-2026-23457)

ext4: replace BUG_ON with proper error handling in ext4_read_inline_folio(CVE-2026-31451)

crypto: caam - fix DMA corruption on long hmac keys(CVE-2026-43044)

scsi: qla2xxx: Completely fix fcport double free(CVE-2026-43414)

ext4: reject mount if bigalloc with s_first_data_block != 0(CVE-2026-31447)

net: ipv6: flowlabel: defer exclusive option free until RCU teardown(CVE-2026-31680)

spi: use generic driver_override infrastructure(CVE-2026-31487)

HID: logitech-hidpp: Prevent use-after-free on force feedback initialisation failure(CVE-2026-43049)

dmaengine: idxd: Fix not releasing workqueue on .release()(CVE-2026-43064)

usb: gadget: f_ecm: Fix net_device lifecycle with device_move(CVE-2026-31725)

crypto: atmel-sha204a - Fix OOM -gt;tfm_count leak(CVE-2026-31391)

netfilter: nf_conntrack_h323: check for zero length in DecodeQ931()(CVE-2026-23455)

scsi: hisi_sas: Fix NULL pointer exception during user_scan()(CVE-2026-43413)

x86/apic: Disable x2apic on resume if the kernel expects so(CVE-2026-43363)

netfilter: nf_conntrack_expect: use expect-gt;helper(CVE-2026-31414)

nvme-pci: Fix slab-out-of-bounds in nvme_dbbuf_set(CVE-2026-43449)

HID: core: Mitigate potential OOB by removing bogus memset()(CVE-2026-43048)

mfd: core: Add locking around #39;mfd_of_node_list#39;(CVE-2026-43143)

scsi: target: tcm_loop: Drain commands in target_reset handler(CVE-2026-43054)

ACPI: processor: Fix NULL-pointer dereference in acpi_processor_errata_piix4()(CVE-2026-43313)

netfilter: nft_ct: fix use-after-free in timeout object destroy(CVE-2026-31665)

lib/crypto: mpi: Fix integer underflow in mpi_read_raw_from_sgl()(CVE-2026-43492)

xfrm: clear trailing padding in build_polexpire()(CVE-2026-31664)

perf/x86/intel/uncore: Skip discovery table for offline dies(CVE-2026-43079)

usb: dwc3: gadget: Move vbus draw to workqueue context(CVE-2026-43170)

net: fix fanout UAF in packet_release() via NETDEV_UP race(CVE-2026-31504)

usb: gadget: u_ether: Fix race between gether_disconnect and eth_stop(CVE-2026-31728)

netfilter: ip6t_eui64: reject invalid MAC header for all packets(CVE-2026-31685)

perf/x86/intel/uncore: Fix die ID init and look up bugs(CVE-2026-43344)

udp: Fix wildcard bind conflict check when using hash2(CVE-2026-31503)

net/sched: sch_netem: fix out-of-bounds access in packet corruption(CVE-2026-31675)

ext4: validate p_idx bounds in ext4_ext_correct_indexes(CVE-2026-31449)

xfrm: prevent policy_hthresh.work from racing with netns teardown(CVE-2026-31516)

f2fs: fix use-after-free of sbi in f2fs_compress_write_end_io()(CVE-2026-31702)

KVM: x86: Ignore -EBUSY when checking nested events from vcpu_block()(CVE-2026-43265)

ext4: avoid allocate block from corrupted group in ext4_mb_find_by_goal()(CVE-2026-43068)

cifs: Fix locking usage for tcon fields(CVE-2026-43215)

dmaengine: idxd: fix possible wrong descriptor completion in llist_abort_desc()(CVE-2026-31436)

fbcon: check return value of con2fb_acquire_newinfo()(CVE-2026-43123)

xfs: close crash window in attr dabtree inactivation(CVE-2026-43053)

HID: alps: fix NULL pointer dereference in alps_raw_event()(CVE-2026-31625)

netfilter: nf_conntrack_expect: skip expectations in other netns via proc(CVE-2026-31496)

xfs: save ailp before dropping the AIL lock in push callbacks(CVE-2026-31454)

KVM: SEV: Protect *all* of sev_mem_enc_register_region() with kvm-gt;lock(CVE-2026-31592)

KVM: SEV: Drop WARN on large size for KVM_MEMORY_ENCRYPT_REG_REGION(CVE-2026-31590)

net: ethernet: xscale: Check for PTP support properly(CVE-2026-43173)

HID: magicmouse: Do not crash on missing msc-gt;input(CVE-2026-43140)

smb: client: fix OOB reads parsing symlink error response(CVE-2026-31613)

net/sched: cls_flow: fix NULL pointer dereference on shared blocks(CVE-2026-31422)

xfrm: hold dev ref until after transport_finish NF_HOOK(CVE-2026-31663)

bpf: Fix regsafe() for pointers to packet(CVE-2026-43030)

xfs: avoid dereferencing log items after push callbacks(CVE-2026-31453)

smb: client: prevent races in -gt;query_interfaces()(CVE-2026-43239)

kprobes: avoid crash when rmmod/insmod after ftrace killed(CVE-2026-43409)

xfs: fix undersized l_iclog_roundoff values(CVE-2026-43365)

ixgbevf: add missing negotiate_features op to Hyper-V ops table(CVE-2026-43094)

arm64: contpte: fix set_access_flags() no-op check for SMMU/ATS faults(CVE-2026-43486)

arm64: Add support for TSV110 Spectre-BHB mitigation(CVE-2026-43261)

KVM: x86: Add SRCU protection for reading PDPTRs in __get_sregs2()(CVE-2026-43214)

can: raw: fix ro-gt;uniq use-after-free in raw_rcv()(CVE-2026-31532)

ptrace: slightly saner #39;get_dumpable()#39; logic(CVE-2026-46333)

openvswitch: validate MPLS set/set_masked payload length(CVE-2026-31679)

smb: client: fix OOB read in smb2_ioctl_query_info QUERY_INFO path(CVE-2026-31708)

af_unix: read UNIX_DIAG_VFS data under unix_state_lock(CVE-2026-31673)

esp: fix skb leak with espintcp and async crypto(CVE-2026-31518)

smb: client: fix off-by-8 bounds check in check_wsl_eas()(CVE-2026-31614)

af_key: validate families in pfkey_send_migrate()(CVE-2026-31515)

USB: usbtmc: Use usb_bulk_msg_killable() with user-specified timeouts(CVE-2026-43429)

bpf: Fix incorrect pruning due to atomic fetch precision tracking(CVE-2026-43009)

xfs: stop reclaim before pushing AIL during unmount(CVE-2026-31455)

netfilter: x_tables: restrict xt_check_match/xt_check_target extensions for NFPROTO_ARP(CVE-2026-31424)

ext4: convert inline data to extents when truncate exceeds inline size(CVE-2026-31452)

HID: multitouch: Check to ensure report responses match the request(CVE-2026-43047)

HID: core: clamp report_size in s32ton() to avoid undefined shift(CVE-2026-31624)

EFI/CPER: don#39;t dump the entire memory region(CVE-2026-43171)

pstore: ram_core: fix incorrect success return when vmap() fails(CVE-2026-43124)

xfrm_user: fix info leak in build_report()(CVE-2026-31671)

KVM: SVM: Set/clear CR8 write interception when AVIC is (de)activated(CVE-2026-43483)

dcache: Limit the minimal number of bucket to two(CVE-2026-43071)

netfilter: nf_conntrack_h323: fix OOB read in decode_int() CONS case(CVE-2026-23456)

dm: clear cloned request bio pointer when last clone bio completes(CVE-2026-43278)

net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption(CVE-2026-31533)

netfilter: ipset: drop logically empty buckets in mtype_del(CVE-2026-31418)

bridge: br_nd_send: linearize skb before parsing ND options(CVE-2026-31682)

x86/CPU: Fix FPDSS on Zen1(CVE-2026-31628)

ext4: fix use-after-free in update_super_work when racing with umount(CVE-2026-31446)

nvmet: move async event work off nvmet-wq(CVE-2026-31557)

bpf: Reject sleepable kprobe_multi programs at attach time(CVE-2026-43010)

ipv4: nexthop: allocate skb dynamically in rtm_get_nexthop()(CVE-2026-31531)

hwmon: (pmbus/core) Protect regulator operations with mutex(CVE-2026-31486)

iavf: fix out-of-bounds writes in iavf_get_ethtool_stats()(CVE-2026-31505)

bpf: reject direct access to nullable PTR_TO_BUF pointers(CVE-2026-43333)

netfilter: ctnetlink: use netlink policy range checks(CVE-2026-31495)

nfsd: fix heap overflow in NFSv4.0 LOCK replay cache(CVE-2026-31402)

virtio_net: Fix UAF on dst_ops when IFF_XMIT_DST_RELEASE is cleared and napi_tx is false(CVE-2026-31469)

nvme-pci: ensure we#39;re polling a polled queue(CVE-2026-31523)

nvdimm/bus: Fix potential use after free in asynchronous initialization(CVE-2026-31399)

net: bonding: fix use-after-free in bond_xmit_broadcast()(CVE-2026-31419)

mm/damon/sysfs: check contexts-gt;nr before accessing contexts_arr[0](CVE-2026-31458)

ipv6: avoid overflows in ip6_datagram_send_ctl()(CVE-2026-31415)

openvswitch: defer tunnel netdev_put to RCU release(CVE-2026-31678)

mmc: vub300: fix NULL-deref on disconnect(CVE-2026-31651)

net: openvswitch: Avoid releasing netdev before teardown completes(CVE-2026-31508)

netfilter: nfnetlink_log: fix uninitialized padding leak in NFULA_PAYLOAD(CVE-2026-31428)

perf: Make sure to use pmu_ctx-gt;pmu for groups(CVE-2026-31528)

netfilter: nf_conntrack_sip: fix use of uninitialized rtp_addr in process_sdp(CVE-2026-31427)

netfilter: nfnetlink_log: account for netlink header size(CVE-2026-31416)

X.509: Fix out-of-bounds access when parsing extensions(CVE-2026-31430)

HID: apple: avoid memory leak in apple_report_fixup()(CVE-2026-31520)

driver core: platform: use generic driver_override infrastructure(CVE-2026-31527)

crypto: af_alg - limit RX SG extraction by receive buffer budget(CVE-2026-31677)

HID: magicmouse: avoid memory leak in magicmouse_report_fixup()(CVE-2026-31522)

bpf, arm64: Force 8-byte alignment for JIT buffer to prevent atomic tearing(CVE-2026-23383)

Tenable has extracted the preceding description block directly from the EulerOS kernel security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected kernel packages.

See Also

http://www.nessus.org/u?d8568a7c

Plugin Details

Severity: High

ID: 332913

File Name: EulerOS_SA-2026-2889.nasl

Version: 1.1

Type: Local

Published: 8/6/2026

Updated: 8/6/2026

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Critical

Score: 9.2

Percentile: 99.76

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5.6

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2026-43049

CVSS v3

Risk Factor: High

Base Score: 7.8

Temporal Score: 7.2

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:F/RL:O/RC:C

Vulnerability Information

CPE: cpe:/o:huawei:euleros:2.0, p-cpe:/a:huawei:euleros:bpftool, p-cpe:/a:huawei:euleros:kernel-abi-stablelists, p-cpe:/a:huawei:euleros:kernel-tools-libs-devel, p-cpe:/a:huawei:euleros:kernel-tools-libs, p-cpe:/a:huawei:euleros:kernel-tools, p-cpe:/a:huawei:euleros:kernel, p-cpe:/a:huawei:euleros:perf, p-cpe:/a:huawei:euleros:python3-perf

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/EulerOS/release, Host/EulerOS/rpm-list, Host/EulerOS/sp

Excluded KB Items: Host/EulerOS/uvp_version

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 8/6/2026

Vulnerability Publication Date: 3/25/2026

Reference Information

CVE: CVE-2026-23383, CVE-2026-23455, CVE-2026-23456, CVE-2026-23457, CVE-2026-23458, CVE-2026-23472, CVE-2026-31391, CVE-2026-31399, CVE-2026-31402, CVE-2026-31414, CVE-2026-31415, CVE-2026-31416, CVE-2026-31418, CVE-2026-31419, CVE-2026-31422, CVE-2026-31424, CVE-2026-31427, CVE-2026-31428, CVE-2026-31430, CVE-2026-31436, CVE-2026-31446, CVE-2026-31447, CVE-2026-31448, CVE-2026-31449, CVE-2026-31450, CVE-2026-31451, CVE-2026-31452, CVE-2026-31453, CVE-2026-31454, CVE-2026-31455, CVE-2026-31458, CVE-2026-31469, CVE-2026-31486, CVE-2026-31487, CVE-2026-31495, CVE-2026-31496, CVE-2026-31503, CVE-2026-31504, CVE-2026-31505, CVE-2026-31508, CVE-2026-31515, CVE-2026-31516, CVE-2026-31518, CVE-2026-31520, CVE-2026-31521, CVE-2026-31522, CVE-2026-31523, CVE-2026-31527, CVE-2026-31528, CVE-2026-31531, CVE-2026-31532, CVE-2026-31533, CVE-2026-31542, CVE-2026-31546, CVE-2026-31555, CVE-2026-31557, CVE-2026-31570, CVE-2026-31575, CVE-2026-31586, CVE-2026-31590, CVE-2026-31592, CVE-2026-31613, CVE-2026-31614, CVE-2026-31624, CVE-2026-31625, CVE-2026-31628, CVE-2026-31651, CVE-2026-31663, CVE-2026-31664, CVE-2026-31665, CVE-2026-31671, CVE-2026-31673, CVE-2026-31674, CVE-2026-31675, CVE-2026-31677, CVE-2026-31678, CVE-2026-31679, CVE-2026-31680, CVE-2026-31681, CVE-2026-31682, CVE-2026-31685, CVE-2026-31689, CVE-2026-31693, CVE-2026-31702, CVE-2026-31708, CVE-2026-31725, CVE-2026-31728, CVE-2026-31781, CVE-2026-43009, CVE-2026-43010, CVE-2026-43030, CVE-2026-43043, CVE-2026-43044, CVE-2026-43047, CVE-2026-43048, CVE-2026-43049, CVE-2026-43053, CVE-2026-43054, CVE-2026-43064, CVE-2026-43065, CVE-2026-43068, CVE-2026-43071, CVE-2026-43079, CVE-2026-43094, CVE-2026-43123, CVE-2026-43124, CVE-2026-43140, CVE-2026-43143, CVE-2026-43170, CVE-2026-43171, CVE-2026-43173, CVE-2026-43214, CVE-2026-43215, CVE-2026-43239, CVE-2026-43261, CVE-2026-43265, CVE-2026-43278, CVE-2026-43289, CVE-2026-43313, CVE-2026-43333, CVE-2026-43344, CVE-2026-43363, CVE-2026-43365, CVE-2026-43409, CVE-2026-43413, CVE-2026-43414, CVE-2026-43428, CVE-2026-43429, CVE-2026-43445, CVE-2026-43448, CVE-2026-43449, CVE-2026-43483, CVE-2026-43486, CVE-2026-43488, CVE-2026-43492, CVE-2026-43503, CVE-2026-46333