Synopsis
The remote Amazon Linux 2023 host is missing a security update.
Description
It is, therefore, affected by multiple vulnerabilities as referenced in the ALAS2023-2026-2106 advisory.
In the Linux kernel, the following vulnerability has been resolved:
netfilter: nft_counter: serialize reset with spinlock (CVE-2026-45897)
In the Linux kernel, the following vulnerability has been resolved:
netfilter: nf_tables: revert commit_mutex usage in reset path (CVE-2026-45901)
In the Linux kernel, the following vulnerability has been resolved:
bpf: Fix ld_{abs,ind} failure path analysis in subprogs (CVE-2026-53090)
In the Linux kernel, the following vulnerability has been resolved:
net/handshake: Drain pending requests at net namespace exit (CVE-2026-63978)
In the Linux kernel, the following vulnerability has been resolved:
net/handshake: hand off the pinned file reference to accept_doit (CVE-2026-63979)
In the Linux kernel, the following vulnerability has been resolved:
blk-mq: pop cached request if it is usable (CVE-2026-64017)
In the Linux kernel, the following vulnerability has been resolved:
KVM: guest_memfd: Treat memslot binding offset+size as unsigned values (CVE-2026-64283)
In the Linux kernel, the following vulnerability has been resolved:
net/handshake: Take a long-lived file reference at submit (CVE-2026-64523)
In the Linux kernel, the following vulnerability has been resolved:
KVM: nVMX: Hide shadow VMCS right after VMCLEAR (CVE-2026-64562)
In the Linux kernel, the following vulnerability has been resolved:
rhashtable: clear stale iter->p on table restart (CVE-2026-64563)
In the Linux kernel, the following vulnerability has been resolved:
sctp: don't free the ASCONF's own transport in DEL-IP processing (CVE-2026-64564)
In the Linux kernel, the following vulnerability has been resolved:
btrfs: reject free space cache with more entries than pages (CVE-2026-64567)
In the Linux kernel, the following vulnerability has been resolved:
ipv4: fib: free fib_alias with kfree_rcu() on insert error path (CVE-2026-64572)
In the Linux kernel, the following vulnerability has been resolved:
bpf: tcp: fix double sock release on batch realloc (CVE-2026-64575)
In the Linux kernel, the following vulnerability has been resolved:
nexthop: initialize extack in nh_res_bucket_migrate() (CVE-2026-64576)
In the Linux kernel, the following vulnerability has been resolved:
xfrm: policy: preallocate inexact bins before xfrm_hash_rebuild reinsert (CVE-2026-64579)
In the Linux kernel, the following vulnerability has been resolved:
xfrm6: clear dst.dev on error to avoid double netdev_put in xfrm6_fill_dst() (CVE-2026-64580)
In the Linux kernel, the following vulnerability has been resolved:
xfrm: fix sk_dst_cache double-free in xfrm_user_policy() (CVE-2026-64581)
In the Linux kernel, the following vulnerability has been resolved:
KVM: SVM: Bump asid_generation on CPU online to avoid ASID collision after hotplug (CVE-2026-68093)
In the Linux kernel, the following vulnerability has been resolved:
fuse-uring: fix race between registration and connection abortion (CVE-2026-68095)
In the Linux kernel, the following vulnerability has been resolved:
audit: fix recursive locking deadlock in audit_dupe_exe() (CVE-2026-68096)
In the Linux kernel, the following vulnerability has been resolved:
vxlan: mdb: Fix source list corruption on a failed replace (CVE-2026-68116)
In the Linux kernel, the following vulnerability has been resolved:
tipc: clear sock->sk on the failed-insert path in tipc_sk_create() (CVE-2026-68117)
In the Linux kernel, the following vulnerability has been resolved:
tcp: challenge ACK for non-exact RST in SYN-RECEIVED (CVE-2026-68118)
In the Linux kernel, the following vulnerability has been resolved:
pppoe: reload header pointer after dev_hard_header() (CVE-2026-68121)
In the Linux kernel, the following vulnerability has been resolved:
openvswitch: fix GSO userspace truncation underflow (CVE-2026-68123)
In the Linux kernel, the following vulnerability has been resolved:
ila: reload IPv6 header after pskb_may_pull in checksum adjust (CVE-2026-68127)
In the Linux kernel, the following vulnerability has been resolved:
ice: reject out-of-range ptype in ice_parser_profile_init (CVE-2026-68128)
In the Linux kernel, the following vulnerability has been resolved:
rbd: Reset positive result codes to zero in object map update path (CVE-2026-68131)
In the Linux kernel, the following vulnerability has been resolved:
super: fix emergency thaw deadlock on frozen block devices (CVE-2026-68132)
In the Linux kernel, the following vulnerability has been resolved:
ice: fix PTP Call Trace during PTP release (CVE-2026-68133)
In the Linux kernel, the following vulnerability has been resolved:
net: gro: fix double aggregation of flush-marked skbs (CVE-2026-68136)
In the Linux kernel, the following vulnerability has been resolved:
net/sched: serialize qdisc_rtab_list against concurrent get/put (CVE-2026-68138)
In the Linux kernel, the following vulnerability has been resolved:
net/mlx5e: Use sender devcom for MPV master-up (CVE-2026-68139)
In the Linux kernel, the following vulnerability has been resolved:
geneve: require CAP_NET_ADMIN in the device netns for changelink (CVE-2026-68142)
In the Linux kernel, the following vulnerability has been resolved:
iomap: fix out-of-bounds bitmap_set() with zero-length range (CVE-2026-68145)
In the Linux kernel, the following vulnerability has been resolved:
ftrace: Add global mutex to serialize trace_parser access (CVE-2026-68146)
In the Linux kernel, the following vulnerability has been resolved:
fs: preserve ACL_DONT_CACHE state in forget_cached_acl() (CVE-2026-68149)
In the Linux kernel, the following vulnerability has been resolved:
fs/super: fix emergency thaw double-unlock of s_umount (CVE-2026-68150)
In the Linux kernel, the following vulnerability has been resolved:
libceph: remove debugfs files before client teardown (CVE-2026-68153)
In the Linux kernel, the following vulnerability has been resolved:
libceph: reject zero bucket types in crush_decode (CVE-2026-68154)
In the Linux kernel, the following vulnerability has been resolved:
libceph: Reject monmaps advertising zero monitors (CVE-2026-68155)
In the Linux kernel, the following vulnerability has been resolved:
libceph: refresh auth->authorizer_buf{,_len} after authorizer update (CVE-2026-68156)
In the Linux kernel, the following vulnerability has been resolved:
libceph: guard missing CRUSH type name lookup (CVE-2026-68157)
In the Linux kernel, the following vulnerability has been resolved:
libceph: Fix multiplication overflow in decode_new_up_state_weight() (CVE-2026-68158)
In the Linux kernel, the following vulnerability has been resolved:
ceph: fix pre-auth out-of-bounds read on snaptrace in ceph_handle_caps() (CVE-2026-68160)
In the Linux kernel, the following vulnerability has been resolved:
sctp: close UDP tunnel sockets during netns teardown (CVE-2026-68161)
In the Linux kernel, the following vulnerability has been resolved:
sctp: avoid auth_enable sysctl UAF during netns teardown (CVE-2026-68162)
In the Linux kernel, the following vulnerability has been resolved:
mm/damon/core: disallow overlapping input ranges for damon_set_regions() (CVE-2026-68164)
In the Linux kernel, the following vulnerability has been resolved:
mm/damon/core: validate ranges in damon_set_regions() (CVE-2026-68165)
In the Linux kernel, the following vulnerability has been resolved:
userfaultfd: prevent registration of special VMAs (CVE-2026-68166)
In the Linux kernel, the following vulnerability has been resolved:
mptcp: pm: userspace: fix use-after-free in get_local_id (CVE-2026-68169)
In the Linux kernel, the following vulnerability has been resolved:
tracing: Fix union collision of module and refcnt for dynamic events (CVE-2026-68174)
In the Linux kernel, the following vulnerability has been resolved:
misc: nsm: pin the module while the device is open (CVE-2026-68178)
In the Linux kernel, the following vulnerability has been resolved:
misc: nsm: only unlock nsm_dev on post-lock error paths (CVE-2026-68179)
In the Linux kernel, the following vulnerability has been resolved:
cdrom: fix stack out-of-bounds read in CDROMVOLCTRL (CVE-2026-68184)
In the Linux kernel, the following vulnerability has been resolved:
binfmt_misc: set have_execfd only once the interpreter is opened (CVE-2026-68186)
In the Linux kernel, the following vulnerability has been resolved:
drm/ttm: Account for NULL and handle pages in ttm_pool_backup (CVE-2026-68239)
In the Linux kernel, the following vulnerability has been resolved:
drm/i915/mst: limit DP MST ESI service loop (CVE-2026-68241)
In the Linux kernel, the following vulnerability has been resolved:
drm/i915/gem: Fix NULL deref in I915_CONTEXT_PARAM_SSEU (CVE-2026-68243)
In the Linux kernel, the following vulnerability has been resolved:
drm/i915/gem: Do not leak siblings[] on proto context error (CVE-2026-68244)
In the Linux kernel, the following vulnerability has been resolved:
drm/i915/bios: range check LFP Data Block panel_type2 (CVE-2026-68247)
In the Linux kernel, the following vulnerability has been resolved:
drm/i915: Return NULL on error in active_instance (CVE-2026-68248)
In the Linux kernel, the following vulnerability has been resolved:
drm/i915/hdcp: check streams[] bounds before overflow (CVE-2026-68253)
In the Linux kernel, the following vulnerability has been resolved:
drm/i915/vrr: require valid min/max vfreq for VRR (CVE-2026-68254)
In the Linux kernel, the following vulnerability has been resolved:
drm/virtio: bound EDID block reads to the response buffer (CVE-2026-68255)
In the Linux kernel, the following vulnerability has been resolved:
drm/i915/gem: Add missing nospec on parallel submit slot (CVE-2026-68269)
In the Linux kernel, the following vulnerability has been resolved:
drm/sysfb: Avoid possible truncation with calculating visible size (CVE-2026-68270)
In the Linux kernel, the following vulnerability has been resolved:
drm/dp/mst: fix OOB reads on 2-byte fields in sideband reply parsers (CVE-2026-68277)
In the Linux kernel, the following vulnerability has been resolved:
drm/dp/mst: fix buffer overflows in sideband chunk accumulation (CVE-2026-68278)
In the Linux kernel, the following vulnerability has been resolved:
drm/dp/mst: fix OOB reads in remote DPCD/I2C sideband reply parsers (CVE-2026-68279)
In the Linux kernel, the following vulnerability has been resolved:
bpf, sockmap: Fix cork use-after-free in tcp_bpf_sendmsg() (CVE-2026-68284)
In the Linux kernel, the following vulnerability has been resolved:
rds: tcp: unregister sysctl before tearing down listen socket (CVE-2026-68290)
In the Linux kernel, the following vulnerability has been resolved:
ice: prevent tstamp ring allocation for non-PF VSI types (CVE-2026-68292)
In the Linux kernel, the following vulnerability has been resolved:
net/mlx5: Fix MCIA register buffer overflow on 32 dword reads (CVE-2026-68293)
In the Linux kernel, the following vulnerability has been resolved:
net: gre: fix lltx regression for GRE tunnels with SEQ/CSUM (CVE-2026-68296)
In the Linux kernel, the following vulnerability has been resolved:
tipc: fix u16 MTU truncation in media and bearer MTU validation (CVE-2026-68297)
In the Linux kernel, the following vulnerability has been resolved:
vmxnet3: fix BUG_ON in vmxnet3_get_hdr_len() for Geneve packets (CVE-2026-68299)
In the Linux kernel, the following vulnerability has been resolved:
sctp: auth: verify auth requirement when auth_chunk is NULL (CVE-2026-68300)
In the Linux kernel, the following vulnerability has been resolved:
tipc: fix infinite loop in __tipc_nl_compat_dumpit (CVE-2026-68313)
In the Linux kernel, the following vulnerability has been resolved:
sctp: validate stream count in sctp_process_strreset_inreq() (CVE-2026-68315)
In the Linux kernel, the following vulnerability has been resolved:
sctp: fix auth_chunk_list capacity check in sctp_auth_ep_add_chunkid (CVE-2026-68320)
In the Linux kernel, the following vulnerability has been resolved:
rds: Fix inet6_addr_lst NULL dereference when IPv6 is disabled (CVE-2026-68322)
In the Linux kernel, the following vulnerability has been resolved:
iommu/amd: Bound the early ACPI HID map (CVE-2026-68325)
In the Linux kernel, the following vulnerability has been resolved:
iommu/amd: Wait for completion instead of returning early in iommu_completion_wait() (CVE-2026-68329)
In the Linux kernel, the following vulnerability has been resolved:
rds: drop incoming messages that cross network namespace boundaries (CVE-2026-68335)
In the Linux kernel, the following vulnerability has been resolved:
bonding: fix devconf_all NULL dereference when IPv6 is disabled (CVE-2026-68336)
In the Linux kernel, the following vulnerability has been resolved:
net/packet: avoid fanout hook re-registration after unregister (CVE-2026-68338)
In the Linux kernel, the following vulnerability has been resolved:
smb: client: validate DFS referral PathConsumed (CVE-2026-68343)
In the Linux kernel, the following vulnerability has been resolved:
usb: core: sysfs: add lock to bos_descriptors_read() (CVE-2026-68374)
In the Linux kernel, the following vulnerability has been resolved:
sctp: fix auth_hmacs array size in struct sctp_cookie (CVE-2026-68376)
In the Linux kernel, the following vulnerability has been resolved:
dpll: fix NULL pointer dereference in dpll_msg_add_pin_ref_sync() (CVE-2026-68378)
In the Linux kernel, the following vulnerability has been resolved:
bpf, sockmap: Reject unhashed UDP sockets on sockmap update (CVE-2026-68386)
In the Linux kernel, the following vulnerability has been resolved:
can: raw: add locking for raw flags bitfield (CVE-2026-68387)
In the Linux kernel, the following vulnerability has been resolved:
smb/client: handle overlapping allocated ranges in fallocate (CVE-2026-68388)
In the Linux kernel, the following vulnerability has been resolved:
scsi: core: wake eh reliably when using scsi_schedule_eh (CVE-2026-68396)
In the Linux kernel, the following vulnerability has been resolved:
firmware: arm_ffa: Fix Endpoint Memory Access Descriptor offset calculation (CVE-2026-68400)
In the Linux kernel, the following vulnerability has been resolved:
firmware: arm_ffa: Fix out-of-bound writes in ffa_setup_and_transmit() (CVE-2026-68401)
In the Linux kernel, the following vulnerability has been resolved:
mtd: fix double free and WARN_ON in add_mtd_device() error paths (CVE-2026-68416)
In the Linux kernel, the following vulnerability has been resolved:
xfrm: reject optional IPTFS templates in outbound policies (CVE-2026-68420)
In the Linux kernel, the following vulnerability has been resolved:
sched_ext: Don't warn on core-sched forced idle in put_prev_task_scx() (CVE-2026-68421)
In the Linux kernel, the following vulnerability has been resolved:
btrfs: fix root leak if its reloc root is unexpected in merge_reloc_roots() (CVE-2026-68422)
In the Linux kernel, the following vulnerability has been resolved:
IB/mad: Drop unmatched RMPP responses before reassembly (CVE-2026-68425)
In the Linux kernel, the following vulnerability has been resolved:
xfrm: fix stale skb->prev after async crypto steals a GSO segment (CVE-2026-68426)
In the Linux kernel, the following vulnerability has been resolved:
KVM: x86/mmu: Fix use-after-free on vendor module reload (CVE-2026-68428)
In the Linux kernel, the following vulnerability has been resolved:
drm/dp_mst: Handle torn-down topology gracefully in drm_dp_mst_topology_queue_probe() (CVE-2026-68429)
In the Linux kernel, the following vulnerability has been resolved:
vxlan: require CAP_NET_ADMIN in the device netns for changelink (CVE-2026-68432)
In the Linux kernel, the following vulnerability has been resolved:
libceph: bound get_version reply decode to front len (CVE-2026-68433)
In the Linux kernel, the following vulnerability has been resolved:
btrfs: don't propagate EXTENT_FLAG_LOGGING to split extent maps (CVE-2026-68442)
In the Linux kernel, the following vulnerability has been resolved:
firmware: arm_ffa: Fix NULL dereference in ffa_partition_info_get() (CVE-2026-68444)
In the Linux kernel, the following vulnerability has been resolved:
drm/vmwgfx: Validate vmw_surface_metadata::array_size (CVE-2026-68446)
In the Linux kernel, the following vulnerability has been resolved:
ovl: check access to copy_file_range source with src mounter creds (CVE-2026-68448)
In the Linux kernel, the following vulnerability has been resolved:
btrfs: free mapping node on duplicate reloc root insert (CVE-2026-68450)
In the Linux kernel, the following vulnerability has been resolved:
x86/bugs: Make Safe-RET robust against interrupt injection (CVE-2026-68480)
In the Linux kernel, the following vulnerability has been resolved:
ata: libata-core: Reject an invalid concurrent positioning ranges count (CVE-2026-72030)
In the Linux kernel, the following vulnerability has been resolved:
dm: avoid leaking the caller's thread keyring via the table device file (CVE-2026-72103)
In the Linux kernel, the following vulnerability has been resolved:
can: bcm: add missing device refcount for CAN filter removal (CVE-2026-72113)
In the Linux kernel, the following vulnerability has been resolved:
can: bcm: validate frame length in bcm_rx_setup() for RTR replies (CVE-2026-72114)
In the Linux kernel, the following vulnerability has been resolved:
can: bcm: track a single source interface for ANYDEV timeout/throttle ops (CVE-2026-72115)
In the Linux kernel, the following vulnerability has been resolved:
can: bcm: fix stale rx/tx ops after device removal (CVE-2026-72116)
In the Linux kernel, the following vulnerability has been resolved:
can: bcm: fix data race on rx_stamp/rx_ifindex in bcm_rx_handler() (CVE-2026-72117)
In the Linux kernel, the following vulnerability has been resolved:
can: bcm: fix CAN frame rx/tx statistics (CVE-2026-72118)
In the Linux kernel, the following vulnerability has been resolved:
can: bcm: extend bcm_tx_lock usage for data and timer updates (CVE-2026-72119)
In the Linux kernel, the following vulnerability has been resolved:
can: bcm: add locking when updating filter and timer values (CVE-2026-72121)
In the Linux kernel, the following vulnerability has been resolved:
fs/proc/task_mmu: fix make_uffd_wp_huge_pte() prot-update race (CVE-2026-72175)
In the Linux kernel, the following vulnerability has been resolved:
gpu/buddy: bail out of try_harder when alignment cannot be honoured (CVE-2026-72244)
In the Linux kernel, the following vulnerability has been resolved:
netfilter: nf_conntrack_sip: validate skb_dst() before accessing it (CVE-2026-72253)
In the Linux kernel, the following vulnerability has been resolved:
netfilter: nft_fib: reject fib expression on the netdev egress hook (CVE-2026-72254)
In the Linux kernel, the following vulnerability has been resolved:
drm/vmwgfx: avoid destroy_workqueue(NULL) on vkms init failure (CVE-2026-74442)
In the Linux kernel, the following vulnerability has been resolved:
drm/vmwgfx: bound DMA command body size against suffix pointer (CVE-2026-74443)
In the Linux kernel, the following vulnerability has been resolved:
drm/vmwgfx: validate DRAW_PRIMITIVES header size before division (CVE-2026-74444)
In the Linux kernel, the following vulnerability has been resolved:
drm/vmwgfx: reject DX_BIND_QUERY without a DX context (CVE-2026-74445)
In the Linux kernel, the following vulnerability has been resolved:
net: openvswitch: fix skb leak on flow key update failure during ct (CVE-2026-74464)
In the Linux kernel, the following vulnerability has been resolved:
net: openvswitch: fix potential UAF on meter attach failure (CVE-2026-74465)
In the Linux kernel, the following vulnerability has been resolved:
sctp: prevent peer transport count overflow (CVE-2026-74469)
In the Linux kernel, the following vulnerability has been resolved:
tracing: Check return value of __register_event() in trace_module_add_events() (CVE-2026-74471)
In the Linux kernel, the following vulnerability has been resolved:
vxlan: use pskb_network_may_pull() in route_shortcircuit() (CVE-2026-74473)
In the Linux kernel, the following vulnerability has been resolved:
vxlan: use pskb_network_may_pull() for transmit path header pulls (CVE-2026-74474)
In the Linux kernel, the following vulnerability has been resolved:
vxlan: use neigh_ha_snapshot() in route_shortcircuit() (CVE-2026-74475)
In the Linux kernel, the following vulnerability has been resolved:
veth: convert frag_list skbs before running XDP (CVE-2026-74476)
In the Linux kernel, the following vulnerability has been resolved:
uprobes: Fix NULL pointer dereference in hprobe_expire() (CVE-2026-74477)
In the Linux kernel, the following vulnerability has been resolved:
net: bridge: stop fast-leave after deleting a port group (CVE-2026-74480)
In the Linux kernel, the following vulnerability has been resolved:
mm/page_reporting: use system_freezable_wq to fix UAF during suspend (CVE-2026-74481)
In the Linux kernel, the following vulnerability has been resolved:
mm/huge_memory: unlock i_mmap_rwsem before releasing after-split folios (CVE-2026-74482)
In the Linux kernel, the following vulnerability has been resolved:
binfmt_misc: don't let an 'F' entry pin its own instance (CVE-2026-74484)
In the Linux kernel, the following vulnerability has been resolved:
binfmt_misc: reject a flag character as the field delimiter (CVE-2026-74485)
In the Linux kernel, the following vulnerability has been resolved:
binfmt_misc: use exe_file_deny_write_access() for the interpreter clone (CVE-2026-74486)
In the Linux kernel, the following vulnerability has been resolved:
binfmt_misc: restore write access when removing an entry (CVE-2026-74487)
In the Linux kernel, the following vulnerability has been resolved:
tipc: avoid use-after-free in poll trace queue dumps (CVE-2026-74490)
In the Linux kernel, the following vulnerability has been resolved:
of/address: Fix NULL bus dereference in of_pci_range_parser_one() (CVE-2026-74491)
In the Linux kernel, the following vulnerability has been resolved:
netfilter: ipset: do not update comments from kernel-side hash adds (CVE-2026-74492)
In the Linux kernel, the following vulnerability has been resolved:
audit: fix potential use-after-free in audit_del_rule() (CVE-2026-74512)
In the Linux kernel, the following vulnerability has been resolved:
KVM: SVM: Update x2APIC MSR intercepts if AVIC is inhibited while L2 is active (CVE-2026-74516)
In the Linux kernel, the following vulnerability has been resolved:
mm/hugetlb: fix list corruption in allocate_file_region_entries() (CVE-2026-74518)
In the Linux kernel, the following vulnerability has been resolved:
pinctrl: devicetree: don't free uninitialized dev_name on error path (CVE-2026-74519)
In the Linux kernel, the following vulnerability has been resolved:
net: do not send ICMP/NDISC Redirects when peer allocation fails (CVE-2026-74550)
In the Linux kernel, the following vulnerability has been resolved:
scsi: libiscsi_tcp: Bound SCSI Response data segment to the connection buffer (CVE-2026-74556)
In the Linux kernel, the following vulnerability has been resolved:
scsi: libiscsi: Fix stale-data leak into the SCSI sense buffer (CVE-2026-74557)
In the Linux kernel, the following vulnerability has been resolved:
xsk: drain continuation descs after overflow in xsk_build_skb() (CVE-2026-74559)
In the Linux kernel, the following vulnerability has been resolved:
xsk: fix buffer leak in xsk_drop_skb() for AF_XDP multi-buffer Tx (CVE-2026-74560)
In the Linux kernel, the following vulnerability has been resolved:
rds: tcp: hold the RCU lock across ipv6_chk_addr() in rds_tcp_laddr_check() (CVE-2026-74563)
In the Linux kernel, the following vulnerability has been resolved:
netfilter: xt_hashlimit: validate hashtable supports XT_HASHLIMIT_RATE_MATCH (CVE-2026-74564)
In the Linux kernel, the following vulnerability has been resolved:
netfilter: nf_tables: make nft_object rhltable per table (CVE-2026-74565)
In the Linux kernel, the following vulnerability has been resolved:
keys: make keyring key-chunk byte order agree with keyring_diff_objects() (CVE-2026-74566)
In the Linux kernel, the following vulnerability has been resolved:
keys: fix out-of-bounds read in keyring_get_key_chunk() (CVE-2026-74567)
In the Linux kernel, the following vulnerability has been resolved:
netfilter: nf_conntrack_sip: widen NAT rewrite delta to s32 in sip_help_tcp() (CVE-2026-74569)
In the Linux kernel, the following vulnerability has been resolved:
btrfs: zoned: fix deadlock between metadata writeback and transaction commit (CVE-2026-74572)
In the Linux kernel, the following vulnerability has been resolved:
mm/slab: prevent unbounded recursion in free path with new kmalloc type (CVE-2026-74576)
In the Linux kernel, the following vulnerability has been resolved:
net: mpls: initialize rtm_tos in mpls_getroute() (CVE-2026-74577)
In the Linux kernel, the following vulnerability has been resolved:
netfilter: nft_payload: fix mask build for partial field offload (CVE-2026-74579)
In the Linux kernel, the following vulnerability has been resolved:
vhost: reset the vring metadata cache on vring reconfiguration (CVE-2026-74580)
Tenable has extracted the preceding description block directly from the tested product security advisory.
Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
Solution
Run 'dnf update kernel6.18 --releasever 2023.12.20260831' or or 'dnf update --advisory ALAS2023-2026-2106 --releasever 2023.12.20260831' to update your system.
Plugin Details
File Name: al2023_ALAS2023-2026-2106.nasl
Agent: unix
Supported Sensors: Continuous Assessment, Nessus Agent, Nessus
Risk Information
Vector: CVSS2#AV:L/AC:H/Au:S/C:C/I:C/A:C
Vector: CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C
Vulnerability Information
CPE: cpe:/o:amazon:linux:2023, p-cpe:/a:amazon:linux:bpftool6.18-debuginfo, p-cpe:/a:amazon:linux:bpftool6.18, p-cpe:/a:amazon:linux:kernel-livepatch-6.18.44-99.149, p-cpe:/a:amazon:linux:kernel6.18-debuginfo-common-aarch64, p-cpe:/a:amazon:linux:kernel6.18-debuginfo-common-x86_64, p-cpe:/a:amazon:linux:kernel6.18-debuginfo, p-cpe:/a:amazon:linux:kernel6.18-devel, p-cpe:/a:amazon:linux:kernel6.18-headers, p-cpe:/a:amazon:linux:kernel6.18-modules-extra-common, p-cpe:/a:amazon:linux:kernel6.18-modules-extra, p-cpe:/a:amazon:linux:kernel6.18-tools-debuginfo, p-cpe:/a:amazon:linux:kernel6.18-tools-devel, p-cpe:/a:amazon:linux:kernel6.18-tools, p-cpe:/a:amazon:linux:kernel6.18, p-cpe:/a:amazon:linux:microvm-kernel6.18, p-cpe:/a:amazon:linux:perf6.18-debuginfo, p-cpe:/a:amazon:linux:perf6.18, p-cpe:/a:amazon:linux:python3-perf6.18-debuginfo, p-cpe:/a:amazon:linux:python3-perf6.18
Required KB Items: Host/local_checks_enabled, Host/AmazonLinux/release, Host/AmazonLinux/rpm-list
Exploit Ease: Exploits are available
Patch Publication Date: 8/31/2026
Vulnerability Publication Date: 5/27/2026
Reference Information
CVE: CVE-2026-45897, CVE-2026-45901, CVE-2026-53090, CVE-2026-63978, CVE-2026-63979, CVE-2026-64017, CVE-2026-64283, CVE-2026-64523, CVE-2026-64562, CVE-2026-64563, CVE-2026-64564, CVE-2026-64567, CVE-2026-64572, CVE-2026-64575, CVE-2026-64576, CVE-2026-64579, CVE-2026-64580, CVE-2026-64581, CVE-2026-68093, CVE-2026-68095, CVE-2026-68096, CVE-2026-68116, CVE-2026-68117, CVE-2026-68118, CVE-2026-68121, CVE-2026-68123, CVE-2026-68127, CVE-2026-68128, CVE-2026-68131, CVE-2026-68132, CVE-2026-68133, CVE-2026-68136, CVE-2026-68138, CVE-2026-68139, CVE-2026-68142, CVE-2026-68145, CVE-2026-68146, CVE-2026-68149, CVE-2026-68150, CVE-2026-68153, CVE-2026-68154, CVE-2026-68155, CVE-2026-68156, CVE-2026-68157, CVE-2026-68158, CVE-2026-68160, CVE-2026-68161, CVE-2026-68162, CVE-2026-68164, CVE-2026-68165, CVE-2026-68166, CVE-2026-68169, CVE-2026-68174, CVE-2026-68178, CVE-2026-68179, CVE-2026-68184, CVE-2026-68186, CVE-2026-68239, CVE-2026-68241, CVE-2026-68243, CVE-2026-68244, CVE-2026-68247, CVE-2026-68248, CVE-2026-68253, CVE-2026-68254, CVE-2026-68255, CVE-2026-68269, CVE-2026-68270, CVE-2026-68277, CVE-2026-68278, CVE-2026-68279, CVE-2026-68284, CVE-2026-68290, CVE-2026-68292, CVE-2026-68293, CVE-2026-68296, CVE-2026-68297, CVE-2026-68299, CVE-2026-68300, CVE-2026-68313, CVE-2026-68315, CVE-2026-68320, CVE-2026-68322, CVE-2026-68325, CVE-2026-68329, CVE-2026-68335, CVE-2026-68336, CVE-2026-68338, CVE-2026-68343, CVE-2026-68374, CVE-2026-68376, CVE-2026-68378, CVE-2026-68386, CVE-2026-68387, CVE-2026-68388, CVE-2026-68396, CVE-2026-68400, CVE-2026-68401, CVE-2026-68416, CVE-2026-68420, CVE-2026-68421, CVE-2026-68422, CVE-2026-68425, CVE-2026-68426, CVE-2026-68428, CVE-2026-68429, CVE-2026-68432, CVE-2026-68433, CVE-2026-68442, CVE-2026-68444, CVE-2026-68446, CVE-2026-68448, CVE-2026-68450, CVE-2026-68480, CVE-2026-72030, CVE-2026-72103, CVE-2026-72113, CVE-2026-72114, CVE-2026-72115, CVE-2026-72116, CVE-2026-72117, CVE-2026-72118, CVE-2026-72119, CVE-2026-72121, CVE-2026-72175, CVE-2026-72244, CVE-2026-72253, CVE-2026-72254, CVE-2026-74442, CVE-2026-74443, CVE-2026-74444, CVE-2026-74445, CVE-2026-74464, CVE-2026-74465, CVE-2026-74469, CVE-2026-74471, CVE-2026-74473, CVE-2026-74474, CVE-2026-74475, CVE-2026-74476, CVE-2026-74477, CVE-2026-74480, CVE-2026-74481, CVE-2026-74482, CVE-2026-74484, CVE-2026-74485, CVE-2026-74486, CVE-2026-74487, CVE-2026-74490, CVE-2026-74491, CVE-2026-74492, CVE-2026-74512, CVE-2026-74516, CVE-2026-74518, CVE-2026-74519, CVE-2026-74550, CVE-2026-74556, CVE-2026-74557, CVE-2026-74559, CVE-2026-74560, CVE-2026-74563, CVE-2026-74564, CVE-2026-74565, CVE-2026-74566, CVE-2026-74567, CVE-2026-74569, CVE-2026-74572, CVE-2026-74576, CVE-2026-74577, CVE-2026-74579, CVE-2026-74580