Unity Linux 20.1050e / 20.1060e / 20.1070e Security Update: kernel (UTSA-2026-107287)

medium Nessus Plugin ID 344942

Synopsis

The Unity Linux host is missing one or more security updates.

Description

The Unity Linux 20 host has a package installed that is affected by a vulnerability as referenced in the UTSA-2026-107287 advisory.

In the Linux kernel, the following vulnerability has been resolved:

net_sched: Prevent creation of classes with TC_H_ROOT

The function qdisc_tree_reduce_backlog() uses TC_H_ROOT as a termination condition when traversing up the qdisc tree to update parent backlog counters. However, if a class is created with classid TC_H_ROOT, the traversal terminates prematurely at this class instead of reaching the actual root qdisc, causing parent statistics to be incorrectly maintained.
In case of DRR, this could lead to a crash as reported by Mingi Cho.

Prevent the creation of any Qdisc class with classid TC_H_ROOT (0xFFFFFFFF) across all qdisc types, as suggested by Jamal.

Tenable has extracted the preceding description block directly from the Unity Linux security advisory.

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.

Solution

Update the affected kernel package.

See Also

https://nvd.nist.gov/vuln/detail/CVE-2025-21971

https://security-tracker.debian.org/tracker/CVE-2025-21971

http://www.nessus.org/u?00d86f2c

http://www.nessus.org/u?1c84904d

http://www.nessus.org/u?1e9c30b2

http://www.nessus.org/u?2c93c4f4

http://www.nessus.org/u?3427c62b

http://www.nessus.org/u?534a64e0

http://www.nessus.org/u?68563202

http://www.nessus.org/u?ae3a7f34

http://www.nessus.org/u?b492c893

http://www.nessus.org/u?fd559ac6

Plugin Details

Severity: Medium

ID: 344942

File Name: unity_linux_UTSA-2026-107287.nasl

Version: 1.1

Type: Local

Published: 9/11/2026

Updated: 9/11/2026

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.19

CVSS v2

Risk Factor: Medium

Base Score: 4.6

Temporal Score: 3.4

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:C

CVSS Score Source: CVE-2025-21971

CVSS v3

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/UOS-Server/release, Host/UOS-Server/rpm-list

Exploit Ease: No known exploits are available

Patch Publication Date: 9/11/2026

Vulnerability Publication Date: 4/1/2025

Reference Information

CVE: CVE-2025-21971