Unity Linux 20.1050e / 20.1060e / 20.1070e Security Update: kernel (UTSA-2026-107284)

medium Nessus Plugin ID 344920

Synopsis

The Unity Linux host is missing one or more security updates.

Description

The Unity Linux 20 host has a package installed that is affected by a vulnerability as referenced in the UTSA-2026-107284 advisory.

In the Linux kernel, the following vulnerability has been resolved:

firmware: dmi-sysfs: Fix null-ptr-deref in dmi_sysfs_register_handle

KASAN reported a null-ptr-deref error:

KASAN: null-ptr-deref in range [0x0000000000000008-0x000000000000000f] CPU: 0 PID: 1373 Comm: modprobe Hardware name: QEMU Standard PC (i440FX + PIIX, 1996) RIP: 0010:dmi_sysfs_entry_release ...
Call Trace:
<TASK> kobject_put dmi_sysfs_register_handle (drivers/firmware/dmi-sysfs.c:540) dmi_sysfs dmi_decode_table (drivers/firmware/dmi_scan.c:133) dmi_walk (drivers/firmware/dmi_scan.c:1115) dmi_sysfs_init (drivers/firmware/dmi-sysfs.c:149) dmi_sysfs do_one_initcall (init/main.c:1296) ...
Kernel panic - not syncing: Fatal exception Kernel Offset: 0x4000000 from 0xffffffff81000000
---[ end Kernel panic - not syncing: Fatal exception ]---

It is because previous patch added kobject_put() to release the memory which will call dmi_sysfs_entry_release() and list_del().

However, list_add_tail(entry->list) is called after the error block, so the list_head is uninitialized and cannot be deleted.

Move error handling to after list_add_tail to fix this.

Tenable has extracted the preceding description block directly from the Unity Linux security advisory.

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.

Solution

Update the affected kernel package.

See Also

https://nvd.nist.gov/vuln/detail/CVE-2023-53250

https://security-tracker.debian.org/tracker/CVE-2023-53250

http://www.nessus.org/u?23a968cc

http://www.nessus.org/u?354e7eb9

http://www.nessus.org/u?68672be5

http://www.nessus.org/u?8d36d170

http://www.nessus.org/u?a7fae0fd

http://www.nessus.org/u?c73f5b39

Plugin Details

Severity: Medium

ID: 344920

File Name: unity_linux_UTSA-2026-107284.nasl

Version: 1.1

Type: Local

Published: 9/11/2026

Updated: 9/11/2026

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.18

CVSS v2

Risk Factor: Medium

Base Score: 4.6

Temporal Score: 3.4

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:C

CVSS Score Source: CVE-2023-53250

CVSS v3

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/UOS-Server/release, Host/UOS-Server/rpm-list

Exploit Ease: No known exploits are available

Patch Publication Date: 9/11/2026

Vulnerability Publication Date: 3/22/2023

Reference Information

CVE: CVE-2023-53250