Amazon Linux 2 : runfinch-finch (ALASDOCKER-2026-142)

high Nessus Plugin ID 351054

Synopsis

The remote Amazon Linux 2 host is missing a security update.

Description

The version of runfinch-finch installed on the remote host is prior to 1.19.0-1. It is, therefore, affected by multiple vulnerabilities as referenced in the ALAS2DOCKER-2026-142 advisory.

A custom client can produce such an upload request to the BuildKit daemon that files can escape from the BuildKit-controlled state directory. The client needs to have valid permissions to access the BuildKit control API to issue builds, e.g., bypass authentication, etc. (CVE-2026-15789)

A crafted message in the BuildKit low-level build API can be used to remove the contents of the /tmp directory. The action that can normally be used to delete files inside the build container rootfs can escape into the real host temp directory. (CVE-2026-15791)

A malicious BuildKit client or frontend could craft a request that could lead to BuildKit daemon crashing with a panic. (CVE-2026-15792)

BuildKit custom frontends or clients using the raw low-level API can set git.checkoutbundle=true when checking out Git sources. If the Git source is malicious, this could lead to a crafted command invocation on the host. (CVE-2026-15793)

The tar extraction routines in moby/go-archive (Unpack, UnpackLayer, Untar/UntarUncompressed, and the ApplyLayer helpers) do not confine filesystem operations to the destination directory. A crafted archive can create or overwrite files outside the intended destination. (CVE-2026-17106)

Memory exhaustion DoS causing OOM kill of containerd process

NOTE: https://github.com/containerd/containerd/security/advisories/GHSA-jpcc-p29g-p8mq (CVE-2026-47262)

Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking. (CVE-2026-56855)

BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to 0.31.1, a custom frontend could place an invalid SecurityMode value in a crafted build request, and executor/oci/spec_linux.go treated the unsupported value as a non-sandbox mode without requiring the security.insecure entitlement. This disabled Seccomp and AppArmor protections for the build container even though Linux capabilities remained restricted. This issue is fixed in version 0.31.1. (CVE-2026-61711)

BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to 0.31.1, BuildKit read attacker-controlled /etc/passwd and /etc/group files without an upper bound while resolving a username to a user identifier or group identifier in executor/oci/user.go and solver/llbsolver/ops/user_linux.go. A malicious base image or build could provide oversized files that exhausted memory during user resolution and caused out-of-memory termination of the buildkitd process. This issue is fixed in version 0.31.1. (CVE-2026-61712)

BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to 0.31.2, a custom client can produce such an upload request to the BuildKit daemon that files can escape from the BuildKit-controlled state directory. The client needs to have valid permissions to access BuildKit control API to issue builds, eg., bypass authentication, etc. This issue is fixed in version 0.31.2. (CVE-2026-75593)

Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection.
(CVE-2026-78662)

Tenable has extracted the preceding description block directly from the tested product security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Run 'yum update runfinch-finch' or or 'yum update --advisory ALAS2DOCKER-2026-142' to update your system.

See Also

https://alas.aws.amazon.com//AL2/ALAS2DOCKER-2026-142.html

https://alas.aws.amazon.com/faqs.html

https://explore.alas.aws.amazon.com/CVE-2026-15789.html

https://explore.alas.aws.amazon.com/CVE-2026-15791.html

https://explore.alas.aws.amazon.com/CVE-2026-15792.html

https://explore.alas.aws.amazon.com/CVE-2026-15793.html

https://explore.alas.aws.amazon.com/CVE-2026-17106.html

https://explore.alas.aws.amazon.com/CVE-2026-47262.html

https://explore.alas.aws.amazon.com/CVE-2026-56855.html

https://explore.alas.aws.amazon.com/CVE-2026-61711.html

https://explore.alas.aws.amazon.com/CVE-2026-61712.html

https://explore.alas.aws.amazon.com/CVE-2026-75593.html

https://explore.alas.aws.amazon.com/CVE-2026-78662.html

Plugin Details

Severity: High

ID: 351054

File Name: al2_ALASDOCKER-2026-142.nasl

Version: 1.1

Type: Local

Agent: unix

Published: 9/29/2026

Updated: 9/29/2026

Supported Sensors: Nessus Agent, Continuous Assessment, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.9

Percentile: 96.54

CVSS v2

Risk Factor: High

Base Score: 7.8

Temporal Score: 6.1

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:C/A:N

CVSS Score Source: CVE-2026-15793

CVSS v3

Risk Factor: High

Base Score: 7.5

Temporal Score: 6.7

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

CVSS v4

Risk Factor: High

Base Score: 7.3

Threat Score: 6.4

Threat Vector: CVSS:4.0/E:P

Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Vulnerability Information

CPE: cpe:/o:amazon:linux:2, p-cpe:/a:amazon:linux:runfinch-finch

Required KB Items: Host/local_checks_enabled, Host/AmazonLinux/release, Host/AmazonLinux/rpm-list

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 9/28/2026

Vulnerability Publication Date: 6/18/2026

Reference Information

CVE: CVE-2026-15789, CVE-2026-15791, CVE-2026-15792, CVE-2026-15793, CVE-2026-17106, CVE-2026-47262, CVE-2026-56855, CVE-2026-61711, CVE-2026-61712, CVE-2026-75593, CVE-2026-78662