AlmaLinux 9.2 [TuxCare] Security Update: bpftool / kernel / kernel-abi-stablelists / kernel-core / etc Multiple Vulnerabilities (ALMALINUX9.2:CLSA-2024:1728936982)

high Nessus Plugin ID 353076

Synopsis

The AlmaLinux host is missing one or more security updates.

Description

The AlmaLinux 9.2 host has packages installed that are affected by multiple vulnerabilities as referenced in the TuxCare ALMALINUX9.2:CLSA-2024:1728936982 advisory.

- In the Linux kernel, the following vulnerability has been resolved: tty: Fix out-of-bound vmalloc access in imageblit This issue happens when a userspace program does an ioctl FBIOPUT_VSCREENINFO passing the fb_var_screeninfo struct containing only the fields xres, yres, and bits_per_pixel with values. If this struct is the same as the previous ioctl, the vc_resize() detects it and doesn't call the resize_screen(), leaving the fb_var_screeninfo incomplete. And this leads to the updatescrollmode() calculates a wrong value to fbcon_display->vrows, which makes the real_y() return a wrong value of y, and that value, eventually, causes the imageblit to access an out-of-bound address value. To solve this issue I made the resize_screen() be called even if the screen does not need any resizing, so it will fix and fill the fb_var_screeninfo independently. (CVE-2021-47383)

- In the Linux kernel, the following vulnerability has been resolved: seg6: fix the iif in the IPv6 socket control block When an IPv4 packet is received, the ip_rcv_core(...) sets the receiving interface index into the IPv4 socket control block (v5.16-rc4, net/ipv4/ip_input.c line 510): IPCB(skb)->iif = skb->skb_iif; If that IPv4 packet is meant to be encapsulated in an outer IPv6+SRH header, the seg6_do_srh_encap(...) performs the required encapsulation. In this case, the seg6_do_srh_encap function clears the IPv6 socket control block (v5.16-rc4 net/ipv6/seg6_iptunnel.c line 163): memset(IP6CB(skb), 0, sizeof(*IP6CB(skb))); The memset(...) was introduced in commit ef489749aae5 (ipv6: sr: clear IP6CB(skb) on SRH ip4ip6 encapsulation) a long time ago (2019-01-29). Since the IPv6 socket control block and the IPv4 socket control block share the same memory area (skb->cb), the receiving interface index info is lost (IP6CB(skb)->iif is set to zero). As a side effect, that condition triggers a NULL pointer dereference if commit 0857d6f8c759 (ipv6: When forwarding count rx stats on the orig netdev) is applied. To fix that issue, we set the IP6CB(skb)->iif with the index of the receiving interface once again. (CVE-2021-47515)

- A use-after-free vulnerability was found in the cxgb4 driver in the Linux kernel. The bug occurs when the cxgb4 device is detaching due to a possible rearming of the flower_stats_timer from the work queue. This flaw allows a local user to crash the system, causing a denial of service condition. (CVE-2023-4133)

- A flaw was found in the Linux kernel's TUN/TAP functionality. This issue could allow a local user to bypass network filters and gain unauthorized access to some resources. The original patches fixing CVE-2023-1076 are incorrect or incomplete. The problem is that the following upstream commits - a096ccca6e50 (tun: tun_chr_open(): correctly initialize socket uid), - 66b2c338adce (tap: tap_open():
correctly initialize socket uid), pass inode->i_uid to sock_init_data_uid() as the last parameter and that turns out to not be accurate. (CVE-2023-4194)

- In the Linux kernel, the following vulnerability has been resolved: bpf, sockmap: Don't let sock_map_{close,destroy,unhash} call itself sock_map proto callbacks should never call themselves by design. Protect against bugs like [1] and break out of the recursive loop to avoid a stack overflow in favor of a resource leak. [1] https://lore.kernel.org/all/[email protected]/ (CVE-2023-52735)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected packages based on the guidance in TuxCare advisory ALMALINUX9.2:CLSA-2024:1728936982.

See Also

https://cve.tuxcare.com/els/releases/CLSA-2024:1728936982

http://www.nessus.org/u?73bc96f8

Plugin Details

Severity: High

ID: 353076

File Name: tuxcare_alma_linux_9.2_CLSA-2024-1728936982.nasl

Version: 1.1

Type: Local

Published: 9/30/2026

Updated: 9/30/2026

Supported Sensors: Nessus Agent, Continuous Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

Risk Information

VPR

Risk Factor: High

Score: 7.6

Percentile: 98.67

Vendor

Vendor Severity: Important

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2024-46859

CVSS v3

Risk Factor: High

Base Score: 7.8

Temporal Score: 6.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/AlmaLinux/release, Host/AlmaLinux/rpm-list, Host/OS/extended-third-party

Exploit Ease: No known exploits are available

Patch Publication Date: 10/14/2024

Vulnerability Publication Date: 7/21/2021

Reference Information

CVE: CVE-2021-47383, CVE-2021-47515, CVE-2023-4133, CVE-2023-4194, CVE-2023-52651, CVE-2023-52735, CVE-2023-52880, CVE-2023-52884, CVE-2024-26629, CVE-2024-26665, CVE-2024-26737, CVE-2024-26853, CVE-2024-26855, CVE-2024-26931, CVE-2024-26946, CVE-2024-27016, CVE-2024-27030, CVE-2024-27046, CVE-2024-27052, CVE-2024-27415, CVE-2024-35789, CVE-2024-35791, CVE-2024-35845, CVE-2024-35852, CVE-2024-35895, CVE-2024-35898, CVE-2024-36025, CVE-2024-36899, CVE-2024-36941, CVE-2024-36979, CVE-2024-38559, CVE-2024-38562, CVE-2024-38579, CVE-2024-38588, CVE-2024-38601, CVE-2024-38619, CVE-2024-38627, CVE-2024-39476, CVE-2024-40905, CVE-2024-40911, CVE-2024-40912, CVE-2024-40914, CVE-2024-40927, CVE-2024-40929, CVE-2024-40941, CVE-2024-40978, CVE-2024-40983, CVE-2024-40995, CVE-2024-41013, CVE-2024-41023, CVE-2024-41039, CVE-2024-41041, CVE-2024-41044, CVE-2024-41071, CVE-2024-41076, CVE-2024-41096, CVE-2024-42082, CVE-2024-42096, CVE-2024-42110, CVE-2024-42131, CVE-2024-42136, CVE-2024-42148, CVE-2024-42152, CVE-2024-42243, CVE-2024-43882, CVE-2024-46700, CVE-2024-46722, CVE-2024-46723, CVE-2024-46724, CVE-2024-46725, CVE-2024-46731, CVE-2024-46738, CVE-2024-46743, CVE-2024-46744, CVE-2024-46746, CVE-2024-46747, CVE-2024-46756, CVE-2024-46757, CVE-2024-46758, CVE-2024-46759, CVE-2024-46800, CVE-2024-46811, CVE-2024-46813, CVE-2024-46818, CVE-2024-46821, CVE-2024-46859

CLSA: 2024:1728936982