Nutanix AHV : Multiple Vulnerabilities (NXSA-AHV-11.2)

critical Nessus Plugin ID 335152

Synopsis

The Nutanix AHV host is affected by multiple vulnerabilities .

Description

The version of AHV installed on the remote host is prior to 11.2. It is, therefore, affected by multiple vulnerabilities as referenced in the NXSA-AHV-11.2 advisory.

- A vulnerability has been found in GNU Binutils 2.45. The affected element is the function elf_swap_shdr in the library bfd/elfcode.h of the component Linker. The manipulation leads to heap-based buffer overflow.
The attack must be carried out locally. The exploit has been disclosed to the public and may be used. The identifier of the patch is 9ca499644a21ceb3f946d1c179c38a83be084490. To fix this issue, it is recommended to deploy a patch. The code maintainer replied with [f]ixed for 2.46. (CVE-2025-11083)

- Capstone is a disassembly framework. In versions 6.0.0-Alpha5 and prior, an unchecked vsnprintf return in SStream_concat lets a malicious cs_opt_mem.vsnprintf drive SStream's index negative or past the end, leading to a stack buffer underflow/overflow when the next write occurs. Commit 2c7797182a1618be12017d7d41e0b6581d5d529e fixes the issue. (CVE-2025-68114)

- In MIT Kerberos 5 (aka krb5) before 1.22.3, there is an integer underflow and resultant out-of-bounds read if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, possibly causing the process to terminate in parse_message. (CVE-2026-40356)

- In Sudo through 1.9.17p2 before 3e474c2, a failure of a setuid, setgid, or setgroups call, during a privilege drop before running the mailer, is not a fatal error and can lead to privilege escalation.
(CVE-2026-35535)

- In GnuPG before 2.4.9, armor_filter in g10/armor.c has two increments of an index variable where one is intended, leading to an out-of-bounds write for crafted input. (For ExtendedLTS, 2.2.51 and later are fixed versions.) (CVE-2025-68973)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the Nutanix AHV software to the recommended version. Before upgrading: if this cluster is registered with Prism Central, ensure that Prism Central has been upgraded first to a compatible version. Refer to the Software Product Interoperability page on the Nutanix portal.

See Also

http://www.nessus.org/u?2e0b689e

Plugin Details

Severity: Critical

ID: 335152

File Name: nutanix_NXSA-AHV-11_2.nasl

Version: 1.1

Type: Local

Family: Misc.

Published: 8/13/2026

Updated: 8/13/2026

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Critical

Score: 9.5

Percentile: 99.86

CVSS v2

Risk Factor: Medium

Base Score: 4.3

Temporal Score: 3.7

Vector: CVSS2#AV:L/AC:L/Au:S/C:P/I:P/A:P

CVSS Score Source: CVE-2025-11083

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 9.4

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:H/RL:O/RC:C

CVSS Score Source: CVE-2025-68114

CVSS v4

Risk Factor: Critical

Base Score: 9.1

Threat Score: 9.1

Threat Vector: CVSS:4.0/E:A

Vector: CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

CVSS Score Source: CVE-2026-6100

Vulnerability Information

CPE: cpe:/o:nutanix:ahv

Required KB Items: Host/Nutanix/Data/Node/Version, Host/Nutanix/Data/Node/Type

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 7/27/2026

Vulnerability Publication Date: 9/26/2023

CISA Known Exploited Vulnerability Due Dates: 5/15/2026

Reference Information

CVE: CVE-2023-40403, CVE-2024-12086, CVE-2025-10158, CVE-2025-11083, CVE-2025-12084, CVE-2025-13601, CVE-2025-14087, CVE-2025-14512, CVE-2025-14831, CVE-2025-15366, CVE-2025-15367, CVE-2025-15467, CVE-2025-40778, CVE-2025-40780, CVE-2025-45582, CVE-2025-59375, CVE-2025-5987, CVE-2025-61662, CVE-2025-6176, CVE-2025-61984, CVE-2025-61985, CVE-2025-64720, CVE-2025-65018, CVE-2025-66293, CVE-2025-67873, CVE-2025-68114, CVE-2025-68973, CVE-2025-69419, CVE-2025-9086, CVE-2025-9230, CVE-2025-9714, CVE-2026-0994, CVE-2026-1299, CVE-2026-1519, CVE-2026-22695, CVE-2026-22801, CVE-2026-25646, CVE-2026-25749, CVE-2026-27135, CVE-2026-28417, CVE-2026-28421, CVE-2026-31431, CVE-2026-33412, CVE-2026-33416, CVE-2026-33636, CVE-2026-3497, CVE-2026-35385, CVE-2026-35386, CVE-2026-35387, CVE-2026-35388, CVE-2026-35414, CVE-2026-35535, CVE-2026-37555, CVE-2026-39979, CVE-2026-40164, CVE-2026-40356, CVE-2026-41035, CVE-2026-4111, CVE-2026-4424, CVE-2026-4519, CVE-2026-4786, CVE-2026-4878, CVE-2026-5121, CVE-2026-6100