CentOS Linux 7 [TuxCare] Security Update: bpftool / kernel / kernel-debug / kernel-debug-devel / kernel-devel / etc Multiple Vulnerabilities (CENTOS7:CLSA-2026:1789037015)

high Nessus Plugin ID 352722

Synopsis

The CentOS Linux host is missing one or more security updates.

Description

The CentOS Linux 7 host has packages installed that are affected by multiple vulnerabilities as referenced in the TuxCare CENTOS7:CLSA-2026:1789037015 advisory.

- In the Linux kernel, the following vulnerability has been resolved: scsi: iscsi: Fix conn use after free during resets If we haven't done a unbind target call we can race where iscsi_conn_teardown wakes up the EH thread and then frees the conn while those threads are still accessing the conn ehwait. We can only do one TMF per session so this just moves the TMF fields from the conn to the session. We can then rely on the iscsi_session_teardown->iscsi_remove_session->__iscsi_unbind_session call to remove the target and it's devices, and know after that point there is no device or scsi-ml callout trying to access the session. (CVE-2021-47328)

- In the Linux kernel, the following vulnerability has been resolved: ext4: improve error handling from ext4_dirhash() The ext4_dirhash() will *almost* never fail, especially when the hash tree feature was first introduced. However, with the addition of support of encrypted, casefolded file names, that function can most certainly fail today. So make sure the callers of ext4_dirhash() properly check for failures, and reflect the errors back up to their callers. (CVE-2023-53473)

- In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Clear Present bit before tearing down context entry When tearing down a context entry, the current implementation zeros the entire 128-bit entry using multiple 64-bit writes. This creates a window where the hardware can fetch a torn entry where some fields are already zeroed while the 'Present' bit is still set leading to unpredictable behavior or spurious faults. While x86 provides strong write ordering, the compiler may reorder writes to the two 64-bit halves of the context entry. Even without compiler reordering, the hardware fetch is not guaranteed to be atomic with respect to multiple CPU writes. Align with the Guidance to Software for Invalidations in the VT-d spec (Section 6.5.3.3) by implementing the recommended ownership handshake: 1. Clear only the 'Present' (P) bit of the context entry first to signal the transition of ownership from hardware to software. 2. Use dma_wmb() to ensure the cleared bit is visible to the IOMMU. 3. Perform the required cache and context-cache invalidation to ensure hardware no longer has cached references to the entry. 4. Fully zero out the entry only after the invalidation is complete. Also, add a dma_wmb() to context_set_present() to ensure the entry is fully initialized before the 'Present' bit becomes visible. (CVE-2026-45944)

- In the Linux kernel, the following vulnerability has been resolved: ipmi: Add limits to event and receive message requests The driver would just fetch events and receive messages until the BMC said it was done.
To avoid issues with BMCs that never say they are done, add a limit of 10 fetches at a time. In addition, an si interface has an attn state it can return from the hardware which is supposed to cause a flag fetch to see if the driver needs to fetch events or message or a few other things. If the attn bit gets stuck, it's a similar problem. So allow messages in between flag fetches so the driver itself doesn't get stuck.
This is a more general fix than the previous fix for the specific bad BMC, but should fix the more general issue of a BMC that won't stop saying it has data. This has been there from the beginning of the driver.
It's not a bug per-se, but it is accounting for bugs in BMCs. (CVE-2026-46177)

- In the Linux kernel, the following vulnerability has been resolved: PCI: use generic driver_override infrastructure When a driver is probed through __driver_attach(), the bus' match() callback is called without the device lock held, thus accessing the driver_override field without a lock, which can cause a UAF. Fix this by using the driver-core driver_override infrastructure taking care of proper locking internally. Note that calling match() from __driver_attach() without the device lock held is intentional.
[1] (CVE-2026-53120)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected packages based on the guidance in TuxCare advisory CENTOS7:CLSA-2026:1789037015.

See Also

https://cve.tuxcare.com/els/releases/CLSA-2026:1789037015

http://www.nessus.org/u?aef1b8c9

Plugin Details

Severity: High

ID: 352722

File Name: tuxcare_centos_7_CLSA-2026-1789037015.nasl

Version: 1.1

Type: Local

Agent: unix

Published: 9/30/2026

Updated: 9/30/2026

Supported Sensors: Nessus Agent, Continuous Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

Risk Information

VPR

Risk Factor: High

Score: 7.6

Percentile: 98.35

Vendor

Vendor Severity: Important

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2026-64348

CVSS v3

Risk Factor: High

Base Score: 7.8

Temporal Score: 6.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Required KB Items: Host/local_checks_enabled, Host/CentOS/release, Host/CentOS/rpm-list, Host/OS/extended-third-party

Exploit Ease: No known exploits are available

Patch Publication Date: 9/10/2026

Vulnerability Publication Date: 1/28/2022

Reference Information

CVE: CVE-2021-47328, CVE-2023-53473, CVE-2026-45944, CVE-2026-46177, CVE-2026-53120, CVE-2026-53186, CVE-2026-63829, CVE-2026-64322, CVE-2026-64323, CVE-2026-64341, CVE-2026-64344, CVE-2026-64348, CVE-2026-64411, CVE-2026-64413, CVE-2026-64422, CVE-2026-64448, CVE-2026-68184, CVE-2026-68300, CVE-2026-68349, CVE-2026-68350, CVE-2026-68351, CVE-2026-68430, CVE-2026-68469, CVE-2026-72051, CVE-2026-72053, CVE-2026-72054, CVE-2026-72055, CVE-2026-72061, CVE-2026-72113, CVE-2026-72115, CVE-2026-72116, CVE-2026-72117, CVE-2026-72118, CVE-2026-72122, CVE-2026-72308, CVE-2026-74456, CVE-2026-74464, CVE-2026-74580, CVE-2026-74587, CVE-2026-74597, CVE-2026-74630, CVE-2026-74637, CVE-2026-74641, CVE-2026-74656, CVE-2026-74682, CVE-2026-74688, CVE-2026-74705, CVE-2026-74725, CVE-2026-74752, CVE-2026-80558, CVE-2026-80576

CLSA: 2026:1789037015