Amazon Linux 2 : kernel (ALASKERNEL-5.10-2026-132)

medium Nessus Plugin ID 351061

Synopsis

The remote Amazon Linux 2 host is missing a security update.

Description

The version of kernel installed on the remote host is prior to 5.10.268-266.1092. It is, therefore, affected by multiple vulnerabilities as referenced in the ALAS2KERNEL-5.10-2026-132 advisory.

In the Linux kernel, the following vulnerability has been resolved:

drm/virtio: use uninterruptible resv lock for plane updates (CVE-2026-64098)

In the Linux kernel, the following vulnerability has been resolved:

bpf: Reject BPF_MAP_TYPE_INODE_STORAGE creation if BPF LSM is uninitialized

When CONFIG_BPF_LSM=y is set, BPF inode storage maps(BPF_MAP_TYPE_INODE_STORAGE) are compiled into the kernel. However,if the BPF LSM is not explicitly enabled at boot time (e.g. omittedfrom the lsm= boot parameter), lsm_prepare() is never executed forthe BPF LSM.

Consequently, the BPF inode security blob offset(bpf_lsm_blob_sizes.lbs_inode) is never initialized and remains atits default compiled size of 8 bytes instead of being updated to avalid offset past the reserved struct rcu_head (typically 16 bytesor more).

When a privileged user creates and updates a BPF_MAP_TYPE_INODE_STORAGEmap, bpf_inode() evaluates inode->i_security + 8. This erroneouslyaliases the struct rcu_head.func callback pointer at the beginningof the inode->i_security blob. During subsequent map element cleanupor inode destruction, writing NULL to owner_storage clears the queuedRCU callback pointer. When rcu_do_batch() later executes the queuedcallback, it attempts an instruction fetch at address 0x0, triggeringan immediate kernel panic.

Fix this by introducing a global bpf_lsm_initialized boolean flagmarked with __ro_after_init. Set this flag to true inside bpf_lsm_init()when the LSM framework successfully registers the BPF LSM. Gate mapallocation in inode_storage_map_alloc() on this flag, returning-EOPNOTSUPP if the BPF LSM is in turn uninitialized.

This fail-fast approach prevents userspace from allocating inodestorage maps when the supporting BPF LSM infrastructure is absent,avoiding zombie map states. (CVE-2026-64192)

In the Linux kernel, the following vulnerability has been resolved:

i2c: core: fix adapter deregistration race (CVE-2026-64279)

In the Linux kernel, the following vulnerability has been resolved:

libceph: fix two unsafe bare decodes in decode_lockers() (CVE-2026-68082)

In the Linux kernel, the following vulnerability has been resolved:

audit: fix recursive locking deadlock in audit_dupe_exe() (CVE-2026-68096)

In the Linux kernel, the following vulnerability has been resolved:

super: fix emergency thaw deadlock on frozen block devices (CVE-2026-68132)

In the Linux kernel, the following vulnerability has been resolved:

net: gro: fix double aggregation of flush-marked skbs (CVE-2026-68136)

In the Linux kernel, the following vulnerability has been resolved:

ftrace: Add global mutex to serialize trace_parser access (CVE-2026-68146)

In the Linux kernel, the following vulnerability has been resolved:

libceph: bound pg_{temp,upmap,upmap_items} length to CEPH_PG_MAX_SIZE (CVE-2026-68159)

In the Linux kernel, the following vulnerability has been resolved:

sctp: avoid auth_enable sysctl UAF during netns teardown (CVE-2026-68162)

In the Linux kernel, the following vulnerability has been resolved:

drm/virtio: bound EDID block reads to the response buffer (CVE-2026-68255)

In the Linux kernel, the following vulnerability has been resolved:

drm/dp/mst: fix OOB reads on 2-byte fields in sideband reply parsers (CVE-2026-68277)

In the Linux kernel, the following vulnerability has been resolved:

drm/dp/mst: fix buffer overflows in sideband chunk accumulation (CVE-2026-68278)

In the Linux kernel, the following vulnerability has been resolved:

drm/dp/mst: fix OOB reads in remote DPCD/I2C sideband reply parsers (CVE-2026-68279)

In the Linux kernel, the following vulnerability has been resolved:

mmc: vub300: fix use-after-free on probe failure (CVE-2026-72073)

In the Linux kernel, the following vulnerability has been resolved:

scsi: target: Bound PR-OUT TransportID parsing to the received buffer (CVE-2026-72084)

In the Linux kernel, the following vulnerability has been resolved:

scsi: lpfc: Fix memory leak in lpfc_sli4_driver_resource_setup() (CVE-2026-72087)

In the Linux kernel, the following vulnerability has been resolved:

dm-verity: make error counter atomic (CVE-2026-72096)

In the Linux kernel, the following vulnerability has been resolved:

dm-integrity: don't increment hash_offset twice (CVE-2026-72099)

In the Linux kernel, the following vulnerability has been resolved:

jbd2: fix integer underflow in jbd2_journal_initialize_fast_commit() (CVE-2026-72225)

In the Linux kernel, the following vulnerability has been resolved:

selinux: avoid sk_socket dereference in selinux_sctp_bind_connect() (CVE-2026-72242)

In the Linux kernel, the following vulnerability has been resolved:

netfilter: nft_set_pipapo: don't leak bad clone into future transaction (CVE-2026-72252)

In the Linux kernel, the following vulnerability has been resolved:

netfilter: nf_conntrack_sip: validate skb_dst() before accessing it (CVE-2026-72253)

In the Linux kernel, the following vulnerability has been resolved:

netfilter: nf_queue: pin bridge device while NFQUEUE holds fake dst (CVE-2026-72255)

In the Linux kernel, the following vulnerability has been resolved:

KVM: arm64: vgic: Handle race between interrupt affinity change and LPI disabling (CVE-2026-72288)

In the Linux kernel, the following vulnerability has been resolved:

tipc: restrict socket queue dumps in enqueue tracepoints (CVE-2026-72299)

In the Linux kernel, the following vulnerability has been resolved:

mlxsw: fix refcount leak in mlxsw_sp_port_lag_join() (CVE-2026-72308)

In the Linux kernel, the following vulnerability has been resolved:

sctp: add INIT verification after cookie unpacking (CVE-2026-72398)

In the Linux kernel, the following vulnerability has been resolved:

sctp: fix err_chunk memory leaks in INIT handling (CVE-2026-72413)

In the Linux kernel, the following vulnerability has been resolved:

netfilter: nft_compat: ebtables emulation must reject non-bridge targets (CVE-2026-72416)

In the Linux kernel, the following vulnerability has been resolved:

xprtrdma: Repost Receive buffers for malformed replies (CVE-2026-72464)

In the Linux kernel, the following vulnerability has been resolved:

RDMA/rxe: Fix TOCTOU heap overflow in get_srq_wqe (CVE-2026-74378)

In the Linux kernel, the following vulnerability has been resolved:

OPP: Fix race between OPP addition and lookup (CVE-2026-74405)

In the Linux kernel, the following vulnerability has been resolved:

scsi: scsi_debug: Fix REPORT ZONES alloc_len underflow OOB write (CVE-2026-74470)

In the Linux kernel, the following vulnerability has been resolved:

net: pktgen: fix proc entry use-after-free (CVE-2026-74479)

In the Linux kernel, the following vulnerability has been resolved:

binfmt_misc: restore write access when removing an entry (CVE-2026-74487)

In the Linux kernel, the following vulnerability has been resolved:

netfilter: nf_tables: make nft_object rhltable per table (CVE-2026-74565)

In the Linux kernel, the following vulnerability has been resolved:

packet: use consistent hard_header_len in non-ring send paths (CVE-2026-74582)

In the Linux kernel, the following vulnerability has been resolved:

sched/psi: Shut down rtpoll_timer in psi_cgroup_free() (CVE-2026-74594)

In the Linux kernel, the following vulnerability has been resolved:

ring-buffer: Use current_context for safe per-CPU buffer swap (CVE-2026-74601)

In the Linux kernel, the following vulnerability has been resolved:

net/sched: act_gact, act_police: range check the fallback control action (CVE-2026-74620)

In the Linux kernel, the following vulnerability has been resolved:

mm/huge_memory: fix huge_zero_pfn race (CVE-2026-74632)

In the Linux kernel, the following vulnerability has been resolved:

perf/core: Fix group leader use-after-free after sibling detach (CVE-2026-74637)

In the Linux kernel, the following vulnerability has been resolved:

ipv4: Fix fib_nlmsg_size() for RTA_VIA nexthops (CVE-2026-74657)

In the Linux kernel, the following vulnerability has been resolved:

inet: frags: publish queues before arming timer (CVE-2026-74662)

In the Linux kernel, the following vulnerability has been resolved:

net/sched: reject overly deep qdisc hierarchies (CVE-2026-74663)

In the Linux kernel, the following vulnerability has been resolved:

packet: synchronize pressure clearing with ring reconfiguration (CVE-2026-74666)

In the Linux kernel, the following vulnerability has been resolved:

packet: use consistent hard_header_len in TX_RING send path (CVE-2026-74668)

In the Linux kernel, the following vulnerability has been resolved:

net: tap: set skb->dev before parsing virtio net header in tap_get_user_xdp() (CVE-2026-74684)

In the Linux kernel, the following vulnerability has been resolved:

net/sched: cls_api: Always acquire rtnl_lock when destroying locked classifiers (CVE-2026-74700)

In the Linux kernel, the following vulnerability has been resolved:

netfilter: flowtable: publish GC-visible tuple last (CVE-2026-74746)

In the Linux kernel, the following vulnerability has been resolved:

netfilter: ipset: fix refcount race between list:set GC and swap (CVE-2026-74748)

In the Linux kernel, the following vulnerability has been resolved:

ceph: fix hanging __ceph_get_caps() with stale mds_wanted (CVE-2026-80527)

In the Linux kernel, the following vulnerability has been resolved:

ceph: avoid fs reclaim while using current->journal_info (CVE-2026-80528)

In the Linux kernel, the following vulnerability has been resolved:

xfs: fix ilock leak on error in xfs_dq_get_next_id (CVE-2026-80534)

In the Linux kernel, the following vulnerability has been resolved:

xfs: bounds-check buffer log item's dirty bitmap (CVE-2026-80536)

In the Linux kernel, the following vulnerability has been resolved:

libceph: fix OOB read in decode_watchers() via missing bounds check (CVE-2026-80557)

In the Linux kernel, the following vulnerability has been resolved:

libceph: Avoid using invalid osd indices from primary_temp (CVE-2026-80558)

In the Linux kernel, the following vulnerability has been resolved:

libceph: fix multiple unsafe decodes in decode_locker() (CVE-2026-80561)

In the Linux kernel, the following vulnerability has been resolved:

mptcp: options: reset DSS fields in case of unexpected size (CVE-2026-80586)

In the Linux kernel, the following vulnerability has been resolved:

inet: frags: strip GSO state from fragments before reassembly (CVE-2026-80590)

In the Linux kernel, the following vulnerability has been resolved:

serial: amba-pl011: synchronize DMA teardown (CVE-2026-80737)

In the Linux kernel, the following vulnerability has been resolved:

af_packet: Don't send zero-byte data in tpacket_snd(). (CVE-2026-80742)

In the Linux kernel, the following vulnerability has been resolved:

netfilter: nf_tables_offload: suppress WARN_ON_ONCE for ENOMEM in abort path (CVE-2026-80744)

In the Linux kernel, the following vulnerability has been resolved:

selinux: do not cancel a policy conversion that never started (CVE-2026-80756)

In the Linux kernel, the following vulnerability has been resolved:

selinux: reject a class permission count below its inherited common (CVE-2026-80757)

In the Linux kernel, the following vulnerability has been resolved:

HID: hyperv: validate initial device info bounds (CVE-2026-80765)

In the Linux kernel, the following vulnerability has been resolved:

HID: core: fix OOB read of field->usage in hid_set_field() (CVE-2026-80781)

In the Linux kernel, the following vulnerability has been resolved:

ipv6: fix use-after-free in ip6_finish_output2() (CVE-2026-80792)

In the Linux kernel, the following vulnerability has been resolved:

ipv4: reject undersized MTUs in ip_do_fragment() (CVE-2026-80793)

In the Linux kernel, the following vulnerability has been resolved:

xfs: validate attr entry pointer before field access (CVE-2026-80805)

In the Linux kernel, the following vulnerability has been resolved:

ext4: stop retrying saturated xattr cache entries (CVE-2026-80808)

In the Linux kernel, the following vulnerability has been resolved:

rndis_host: add overflow check in rndis_rx_fixup() (CVE-2026-80814)

In the Linux kernel, the following vulnerability has been resolved:

net: packet: fix wrong transport_header when sending VLAN-tagged frame (CVE-2026-80906)

In the Linux kernel, the following vulnerability has been resolved:

selinux: require every boolean value to be defined (CVE-2026-80913)

In the Linux kernel, the following vulnerability has been resolved:

HID: core: fix number/pointer type confusion on long items (CVE-2026-80918)

Tenable has extracted the preceding description block directly from the tested product security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Run 'yum update kernel' or or 'yum update --advisory ALAS2KERNEL-5.10-2026-132' to update your system.

See Also

https://alas.aws.amazon.com//AL2/ALAS2KERNEL-5.10-2026-132.html

https://alas.aws.amazon.com/faqs.html

https://explore.alas.aws.amazon.com/CVE-2026-64098.html

https://explore.alas.aws.amazon.com/CVE-2026-64192.html

https://explore.alas.aws.amazon.com/CVE-2026-64279.html

https://explore.alas.aws.amazon.com/CVE-2026-68082.html

https://explore.alas.aws.amazon.com/CVE-2026-68096.html

https://explore.alas.aws.amazon.com/CVE-2026-68132.html

https://explore.alas.aws.amazon.com/CVE-2026-68136.html

https://explore.alas.aws.amazon.com/CVE-2026-68146.html

https://explore.alas.aws.amazon.com/CVE-2026-68159.html

https://explore.alas.aws.amazon.com/CVE-2026-68162.html

https://explore.alas.aws.amazon.com/CVE-2026-68255.html

https://explore.alas.aws.amazon.com/CVE-2026-68277.html

https://explore.alas.aws.amazon.com/CVE-2026-68278.html

https://explore.alas.aws.amazon.com/CVE-2026-68279.html

https://explore.alas.aws.amazon.com/CVE-2026-72073.html

https://explore.alas.aws.amazon.com/CVE-2026-72084.html

https://explore.alas.aws.amazon.com/CVE-2026-72087.html

https://explore.alas.aws.amazon.com/CVE-2026-72096.html

https://explore.alas.aws.amazon.com/CVE-2026-72099.html

https://explore.alas.aws.amazon.com/CVE-2026-72225.html

https://explore.alas.aws.amazon.com/CVE-2026-72242.html

https://explore.alas.aws.amazon.com/CVE-2026-72252.html

https://explore.alas.aws.amazon.com/CVE-2026-72253.html

https://explore.alas.aws.amazon.com/CVE-2026-72255.html

https://explore.alas.aws.amazon.com/CVE-2026-72288.html

https://explore.alas.aws.amazon.com/CVE-2026-72299.html

https://explore.alas.aws.amazon.com/CVE-2026-72308.html

https://explore.alas.aws.amazon.com/CVE-2026-72398.html

https://explore.alas.aws.amazon.com/CVE-2026-72413.html

https://explore.alas.aws.amazon.com/CVE-2026-72416.html

https://explore.alas.aws.amazon.com/CVE-2026-72464.html

https://explore.alas.aws.amazon.com/CVE-2026-74378.html

https://explore.alas.aws.amazon.com/CVE-2026-74405.html

https://explore.alas.aws.amazon.com/CVE-2026-74470.html

https://explore.alas.aws.amazon.com/CVE-2026-74479.html

https://explore.alas.aws.amazon.com/CVE-2026-74487.html

https://explore.alas.aws.amazon.com/CVE-2026-74565.html

https://explore.alas.aws.amazon.com/CVE-2026-74582.html

https://explore.alas.aws.amazon.com/CVE-2026-74594.html

https://explore.alas.aws.amazon.com/CVE-2026-74601.html

https://explore.alas.aws.amazon.com/CVE-2026-74620.html

https://explore.alas.aws.amazon.com/CVE-2026-74632.html

https://explore.alas.aws.amazon.com/CVE-2026-74637.html

https://explore.alas.aws.amazon.com/CVE-2026-74657.html

https://explore.alas.aws.amazon.com/CVE-2026-74662.html

https://explore.alas.aws.amazon.com/CVE-2026-74663.html

https://explore.alas.aws.amazon.com/CVE-2026-74666.html

https://explore.alas.aws.amazon.com/CVE-2026-74668.html

https://explore.alas.aws.amazon.com/CVE-2026-74684.html

https://explore.alas.aws.amazon.com/CVE-2026-74700.html

https://explore.alas.aws.amazon.com/CVE-2026-74746.html

https://explore.alas.aws.amazon.com/CVE-2026-74748.html

https://explore.alas.aws.amazon.com/CVE-2026-80527.html

https://explore.alas.aws.amazon.com/CVE-2026-80528.html

https://explore.alas.aws.amazon.com/CVE-2026-80534.html

https://explore.alas.aws.amazon.com/CVE-2026-80536.html

https://explore.alas.aws.amazon.com/CVE-2026-80557.html

https://explore.alas.aws.amazon.com/CVE-2026-80558.html

https://explore.alas.aws.amazon.com/CVE-2026-80561.html

https://explore.alas.aws.amazon.com/CVE-2026-80586.html

https://explore.alas.aws.amazon.com/CVE-2026-80590.html

https://explore.alas.aws.amazon.com/CVE-2026-80737.html

https://explore.alas.aws.amazon.com/CVE-2026-80742.html

https://explore.alas.aws.amazon.com/CVE-2026-80744.html

https://explore.alas.aws.amazon.com/CVE-2026-80756.html

https://explore.alas.aws.amazon.com/CVE-2026-80757.html

https://explore.alas.aws.amazon.com/CVE-2026-80765.html

https://explore.alas.aws.amazon.com/CVE-2026-80781.html

https://explore.alas.aws.amazon.com/CVE-2026-80792.html

https://explore.alas.aws.amazon.com/CVE-2026-80793.html

https://explore.alas.aws.amazon.com/CVE-2026-80805.html

https://explore.alas.aws.amazon.com/CVE-2026-80808.html

https://explore.alas.aws.amazon.com/CVE-2026-80814.html

https://explore.alas.aws.amazon.com/CVE-2026-80906.html

https://explore.alas.aws.amazon.com/CVE-2026-80913.html

https://explore.alas.aws.amazon.com/CVE-2026-80918.html

Plugin Details

Severity: Medium

ID: 351061

File Name: al2_ALASKERNEL-5_10-2026-132.nasl

Version: 1.1

Type: Local

Agent: unix

Published: 9/29/2026

Updated: 9/29/2026

Supported Sensors: Nessus Agent, Continuous Assessment, Nessus

Risk Information

VPR

Risk Factor: High

Score: 7.6

Percentile: 98.3

CVSS v2

Risk Factor: Medium

Base Score: 4.6

Temporal Score: 3.4

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:C

CVSS Score Source: CVE-2026-64192

CVSS v3

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/o:amazon:linux:2, p-cpe:/a:amazon:linux:bpftool-debuginfo, p-cpe:/a:amazon:linux:bpftool, p-cpe:/a:amazon:linux:kernel-debuginfo-common-aarch64, p-cpe:/a:amazon:linux:kernel-debuginfo-common-x86_64, p-cpe:/a:amazon:linux:kernel-debuginfo, p-cpe:/a:amazon:linux:kernel-devel, p-cpe:/a:amazon:linux:kernel-headers, p-cpe:/a:amazon:linux:kernel-livepatch-5.10.268-266.1092, p-cpe:/a:amazon:linux:kernel-tools-debuginfo, p-cpe:/a:amazon:linux:kernel-tools-devel, p-cpe:/a:amazon:linux:kernel-tools, p-cpe:/a:amazon:linux:kernel, p-cpe:/a:amazon:linux:perf-debuginfo, p-cpe:/a:amazon:linux:perf, p-cpe:/a:amazon:linux:python-perf-debuginfo, p-cpe:/a:amazon:linux:python-perf

Required KB Items: Host/local_checks_enabled, Host/AmazonLinux/release, Host/AmazonLinux/rpm-list

Exploit Ease: No known exploits are available

Patch Publication Date: 9/28/2026

Vulnerability Publication Date: 4/29/2025

Reference Information

CVE: CVE-2026-64098, CVE-2026-64192, CVE-2026-64279, CVE-2026-68082, CVE-2026-68096, CVE-2026-68132, CVE-2026-68136, CVE-2026-68146, CVE-2026-68159, CVE-2026-68162, CVE-2026-68255, CVE-2026-68277, CVE-2026-68278, CVE-2026-68279, CVE-2026-72073, CVE-2026-72084, CVE-2026-72087, CVE-2026-72096, CVE-2026-72099, CVE-2026-72225, CVE-2026-72242, CVE-2026-72252, CVE-2026-72253, CVE-2026-72255, CVE-2026-72288, CVE-2026-72299, CVE-2026-72308, CVE-2026-72398, CVE-2026-72413, CVE-2026-72416, CVE-2026-72464, CVE-2026-74378, CVE-2026-74405, CVE-2026-74470, CVE-2026-74479, CVE-2026-74487, CVE-2026-74565, CVE-2026-74582, CVE-2026-74594, CVE-2026-74601, CVE-2026-74620, CVE-2026-74632, CVE-2026-74637, CVE-2026-74657, CVE-2026-74662, CVE-2026-74663, CVE-2026-74666, CVE-2026-74668, CVE-2026-74684, CVE-2026-74700, CVE-2026-74746, CVE-2026-74748, CVE-2026-80527, CVE-2026-80528, CVE-2026-80534, CVE-2026-80536, CVE-2026-80557, CVE-2026-80558, CVE-2026-80561, CVE-2026-80586, CVE-2026-80590, CVE-2026-80737, CVE-2026-80742, CVE-2026-80744, CVE-2026-80756, CVE-2026-80757, CVE-2026-80765, CVE-2026-80781, CVE-2026-80792, CVE-2026-80793, CVE-2026-80805, CVE-2026-80808, CVE-2026-80814, CVE-2026-80906, CVE-2026-80913, CVE-2026-80918