EulerOS 2.0 SP12 : kernel (EulerOS-SA-2026-3270)

high Nessus Plugin ID 343617

Synopsis

The remote EulerOS host is missing multiple security updates.

Description

According to the versions of the kernel packages installed, the EulerOS installation on the remote host is affected by the following vulnerabilities :

- Improper isolation of shared resources within the CPU operation cache on Zen 2-based products could allow an attacker to corrupt instructions executed at a different privilege level, potentially resulting in privilege escalation. (CVE-2025-54518)

- In the Linux kernel, the following vulnerability has been resolved: tcp: secure_seq: add back ports to TS offset This reverts 28ee1b746f49 ('secure_seq: downgrade to per-host timestamp offsets') tcp_tw_recycle went away in 2017. Zhouyan Deng reported off-path TCP source port leakage via SYN cookie side-channel that can be fixed in multiple ways. One of them is to bring back TCP ports in TS offset randomization. As a bonus, we perform a single siphash() computation to provide both an ISN and a TS offset. (CVE-2026-23247)

- In the Linux kernel, the following vulnerability has been resolved: net: annotate data-races around sk->sk_{data_ready,write_space} skmsg (and probably other layers) are changing these pointers while other cpus might read them concurrently. Add corresponding READ_ONCE()/WRITE_ONCE() annotations for UDP, TCP and AF_UNIX. (CVE-2026-23302)

- In the Linux kernel, the following vulnerability has been resolved: netfilter: x_tables: restrict xt_check_match/xt_check_target extensions for NFPROTO_ARP Weiming Shi says: xt_match and xt_target structs registered with NFPROTO_UNSPEC can be loaded by any protocol family through nft_compat. When such a match/target sets .hooks to restrict which hooks it may run on, the bitmask uses NF_INET_* constants. This is only correct for families whose hook layout matches NF_INET_*: IPv4, IPv6, INET, and bridge all share the same five hooks (PRE_ROUTING ... POST_ROUTING). ARP only has three hooks (IN=0, OUT=1, FORWARD=2) with different semantics. Because NF_ARP_OUT == 1 == NF_INET_LOCAL_IN, the .hooks validation silently passes for the wrong reasons, allowing matches to run on ARP chains where the hook assumptions (e.g. state->in being set on input hooks) do not hold. This leads to NULL pointer dereferences; xt_devgroup is one concrete example: Oops: general protection fault, probably for non-canonical address 0xdffffc0000000044:
0000 [#1] SMP KASAN NOPTI KASAN: null-ptr-deref in range [0x0000000000000220-0x0000000000000227] RIP:
0010:devgroup_mt+0xff/0x350 Call Trace: <TASK> nft_match_eval (net/netfilter/nft_compat.c:407) nft_do_chain (net/netfilter/nf_tables_core.c:285) nft_do_chain_arp (net/netfilter/nft_chain_filter.c:61) nf_hook_slow (net/netfilter/core.c:623) arp_xmit (net/ipv4/arp.c:666) </TASK> Kernel panic - not syncing:
Fatal exception in interrupt Fix it by restricting arptables to NFPROTO_ARP extensions only. Note that arptables-legacy only supports: - arpt_CLASSIFY - arpt_mangle - arpt_MARK that provide explicit NFPROTO_ARP match/target declarations. (CVE-2026-31424)

- In the Linux kernel, the following vulnerability has been resolved: spi: use generic driver_override infrastructure When a driver is probed through __driver_attach(), the bus' match() callback is called without the device lock held, thus accessing the driver_override field without a lock, which can cause a UAF. Fix this by using the driver-core driver_override infrastructure taking care of proper locking internally. Note that calling match() from __driver_attach() without the device lock held is intentional.
[1] Also note that we do not enable the driver_override feature of struct bus_type, as SPI - in contrast to most other buses - passes '' to sysfs_emit() when the driver_override pointer is NULL. Thus, printing '\n' instead of '(null)\n'. (CVE-2026-31487)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected kernel packages.

See Also

http://www.nessus.org/u?4927f31c

Plugin Details

Severity: High

ID: 343617

File Name: EulerOS_SA-2026-3270.nasl

Version: 1.1

Type: Local

Published: 9/8/2026

Updated: 9/8/2026

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Critical

Score: 9.5

Percentile: 99.87

CVSS v2

Risk Factor: High

Base Score: 7.2

Temporal Score: 6.3

Vector: CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2026-53196

CVSS v3

Risk Factor: High

Base Score: 7.8

Temporal Score: 7.5

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:H/RL:O/RC:C

CVSS Score Source: CVE-2026-53195

CVSS v4

Risk Factor: High

Base Score: 7.3

Threat Score: 7.3

Threat Vector: CVSS:4.0/E:A

Vector: CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

CVSS Score Source: CVE-2025-54518

Vulnerability Information

CPE: cpe:/o:huawei:euleros:2.0, p-cpe:/a:huawei:euleros:bpftool, p-cpe:/a:huawei:euleros:kernel-abi-stablelists, p-cpe:/a:huawei:euleros:kernel-tools-libs-devel, p-cpe:/a:huawei:euleros:kernel-tools-libs, p-cpe:/a:huawei:euleros:kernel-tools, p-cpe:/a:huawei:euleros:kernel, p-cpe:/a:huawei:euleros:perf, p-cpe:/a:huawei:euleros:python3-perf

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/EulerOS/release, Host/EulerOS/rpm-list, Host/EulerOS/sp

Excluded KB Items: Host/EulerOS/uvp_version

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 9/8/2026

Vulnerability Publication Date: 3/18/2026

Reference Information

CVE: CVE-2025-54518, CVE-2026-23247, CVE-2026-23302, CVE-2026-31424, CVE-2026-31487, CVE-2026-31518, CVE-2026-31592, CVE-2026-31663, CVE-2026-31671, CVE-2026-31681, CVE-2026-31684, CVE-2026-31694, CVE-2026-31697, CVE-2026-31698, CVE-2026-31699, CVE-2026-31700, CVE-2026-31738, CVE-2026-31752, CVE-2026-43024, CVE-2026-43025, CVE-2026-43026, CVE-2026-43035, CVE-2026-43036, CVE-2026-43049, CVE-2026-43066, CVE-2026-43073, CVE-2026-43080, CVE-2026-43085, CVE-2026-43088, CVE-2026-43089, CVE-2026-43091, CVE-2026-43093, CVE-2026-43107, CVE-2026-43112, CVE-2026-43114, CVE-2026-43116, CVE-2026-43123, CVE-2026-43125, CVE-2026-43136, CVE-2026-43139, CVE-2026-43140, CVE-2026-43143, CVE-2026-43153, CVE-2026-43163, CVE-2026-43167, CVE-2026-43190, CVE-2026-43198, CVE-2026-43201, CVE-2026-43216, CVE-2026-43223, CVE-2026-43253, CVE-2026-43266, CVE-2026-43277, CVE-2026-43287, CVE-2026-43288, CVE-2026-43309, CVE-2026-43314, CVE-2026-43328, CVE-2026-43333, CVE-2026-43336, CVE-2026-43339, CVE-2026-43350, CVE-2026-43381, CVE-2026-43411, CVE-2026-43420, CVE-2026-43425, CVE-2026-43427, CVE-2026-43428, CVE-2026-43432, CVE-2026-43439, CVE-2026-43448, CVE-2026-43449, CVE-2026-43451, CVE-2026-43456, CVE-2026-43466, CVE-2026-43472, CVE-2026-43475, CVE-2026-43483, CVE-2026-43484, CVE-2026-43492, CVE-2026-43496, CVE-2026-43499, CVE-2026-43501, CVE-2026-45838, CVE-2026-45839, CVE-2026-45840, CVE-2026-45841, CVE-2026-45842, CVE-2026-45843, CVE-2026-45848, CVE-2026-45850, CVE-2026-45852, CVE-2026-45856, CVE-2026-45857, CVE-2026-45858, CVE-2026-45862, CVE-2026-45870, CVE-2026-45891, CVE-2026-45892, CVE-2026-45894, CVE-2026-45899, CVE-2026-45905, CVE-2026-45915, CVE-2026-45917, CVE-2026-45919, CVE-2026-45920, CVE-2026-45923, CVE-2026-45941, CVE-2026-45944, CVE-2026-45948, CVE-2026-45964, CVE-2026-45968, CVE-2026-45970, CVE-2026-45973, CVE-2026-45983, CVE-2026-45985, CVE-2026-45987, CVE-2026-45991, CVE-2026-46006, CVE-2026-46014, CVE-2026-46021, CVE-2026-46023, CVE-2026-46024, CVE-2026-46033, CVE-2026-46040, CVE-2026-46043, CVE-2026-46044, CVE-2026-46046, CVE-2026-46051, CVE-2026-46052, CVE-2026-46065, CVE-2026-46070, CVE-2026-46082, CVE-2026-46083, CVE-2026-46086, CVE-2026-46101, CVE-2026-46102, CVE-2026-46107, CVE-2026-46108, CVE-2026-46116, CVE-2026-46124, CVE-2026-46128, CVE-2026-46132, CVE-2026-46133, CVE-2026-46135, CVE-2026-46149, CVE-2026-46150, CVE-2026-46151, CVE-2026-46153, CVE-2026-46161, CVE-2026-46167, CVE-2026-46172, CVE-2026-46174, CVE-2026-46177, CVE-2026-46178, CVE-2026-46181, CVE-2026-46189, CVE-2026-46191, CVE-2026-46193, CVE-2026-46196, CVE-2026-46209, CVE-2026-46214, CVE-2026-46227, CVE-2026-46234, CVE-2026-46235, CVE-2026-46245, CVE-2026-46252, CVE-2026-46253, CVE-2026-46254, CVE-2026-46259, CVE-2026-46265, CVE-2026-46266, CVE-2026-46274, CVE-2026-46292, CVE-2026-46294, CVE-2026-46302, CVE-2026-46303, CVE-2026-46304, CVE-2026-46312, CVE-2026-46320, CVE-2026-46321, CVE-2026-46322, CVE-2026-46324, CVE-2026-46328, CVE-2026-46331, CVE-2026-52909, CVE-2026-52910, CVE-2026-52912, CVE-2026-52915, CVE-2026-52917, CVE-2026-52920, CVE-2026-52921, CVE-2026-52923, CVE-2026-52924, CVE-2026-52925, CVE-2026-52927, CVE-2026-52929, CVE-2026-52930, CVE-2026-52933, CVE-2026-52936, CVE-2026-52937, CVE-2026-52942, CVE-2026-52943, CVE-2026-52946, CVE-2026-52948, CVE-2026-52954, CVE-2026-52955, CVE-2026-52957, CVE-2026-52958, CVE-2026-52962, CVE-2026-52972, CVE-2026-52975, CVE-2026-52981, CVE-2026-52982, CVE-2026-52986, CVE-2026-52988, CVE-2026-52989, CVE-2026-52991, CVE-2026-52993, CVE-2026-52998, CVE-2026-52999, CVE-2026-53001, CVE-2026-53002, CVE-2026-53003, CVE-2026-53004, CVE-2026-53006, CVE-2026-53009, CVE-2026-53016, CVE-2026-53021, CVE-2026-53036, CVE-2026-53037, CVE-2026-53050, CVE-2026-53053, CVE-2026-53059, CVE-2026-53061, CVE-2026-53062, CVE-2026-53063, CVE-2026-53064, CVE-2026-53075, CVE-2026-53076, CVE-2026-53078, CVE-2026-53089, CVE-2026-53090, CVE-2026-53111, CVE-2026-53129, CVE-2026-53131, CVE-2026-53133, CVE-2026-53134, CVE-2026-53138, CVE-2026-53146, CVE-2026-53148, CVE-2026-53149, CVE-2026-53150, CVE-2026-53163, CVE-2026-53167, CVE-2026-53168, CVE-2026-53175, CVE-2026-53176, CVE-2026-53177, CVE-2026-53186, CVE-2026-53189, CVE-2026-53194, CVE-2026-53195, CVE-2026-53196, CVE-2026-53199, CVE-2026-53218, CVE-2026-53219, CVE-2026-53220, CVE-2026-53221, CVE-2026-53223, CVE-2026-53224, CVE-2026-53225, CVE-2026-53227, CVE-2026-53228, CVE-2026-53229, CVE-2026-53230, CVE-2026-53232, CVE-2026-53236, CVE-2026-53238, CVE-2026-53239, CVE-2026-53245, CVE-2026-53246, CVE-2026-53264, CVE-2026-53265, CVE-2026-53266, CVE-2026-53267, CVE-2026-53268, CVE-2026-53269, CVE-2026-53270, CVE-2026-53275, CVE-2026-53287, CVE-2026-53289, CVE-2026-53295, CVE-2026-53304, CVE-2026-53314, CVE-2026-53330, CVE-2026-53349, CVE-2026-53352, CVE-2026-53369, CVE-2026-53397, CVE-2026-63860, CVE-2026-63887, CVE-2026-63888, CVE-2026-63928, CVE-2026-63956, CVE-2026-64106, CVE-2026-64113, CVE-2026-64118