AlmaLinux 9.6 [TuxCare] Security Update: kernel / kernel-abi-stablelists / kernel-core / etc Multiple Vulnerabilities (ALMALINUX9.6:CLSA-2026:1782155469)

high Nessus Plugin ID 359640

Synopsis

The AlmaLinux host is missing one or more security updates.

Description

The AlmaLinux 9.6 host has packages installed that are affected by multiple vulnerabilities as referenced in the TuxCare ALMALINUX9.6:CLSA-2026:1782155469 advisory.

- In the Linux kernel, the following vulnerability has been resolved: udf: Fix preallocation discarding at indirect extent boundary When preallocation extent is the first one in the extent block, the code would corrupt extent tree header instead. Fix the problem and use udf_delete_aext() for deleting extent to avoid some code duplication. (CVE-2022-48946)

- In the Linux kernel, the following vulnerability has been resolved: xen/privcmd: fix error exit of privcmd_ioctl_dm_op() The error exit of privcmd_ioctl_dm_op() is calling unlock_pages() potentially with pages being NULL, leading to a NULL dereference. Additionally lock_pages() doesn't check for pin_user_pages_fast() having been completely successful, resulting in potentially not locking all pages into memory. This could result in sporadic failures when using the related memory in user mode. Fix all of that by calling unlock_pages() always with the real number of pinned pages, which will be zero in case pages being NULL, and by checking the number of pages pinned by pin_user_pages_fast() matching the expected number of pages. (CVE-2022-49989)

- In the Linux kernel, the following vulnerability has been resolved: platform/x86: mxm-wmi: fix memleak in mxm_wmi_call_mx[ds|mx]() The ACPI buffer memory (out.pointer) returned by wmi_evaluate_method() is not freed after the call, so it leads to memory leak. The method results in ACPI buffer is not used, so just pass NULL to wmi_evaluate_method() which fixes the memory leak. (CVE-2022-50521)

- In the Linux kernel, the following vulnerability has been resolved: net: USB: Fix wrong-direction WARNING in plusb.c The syzbot fuzzer detected a bug in the plusb network driver: A zero-length control-OUT transfer was treated as a read instead of a write. In modern kernels this error provokes a WARNING: usb 1-1: BOGUS control dir, pipe 80000280 doesn't match bRequestType c0 WARNING: CPU: 0 PID: 4645 at drivers/usb/core/urb.c:411 usb_submit_urb+0x14a7/0x1880 drivers/usb/core/urb.c:411 Modules linked in: CPU:
1 PID: 4645 Comm: dhcpcd Not tainted 6.2.0-rc6-syzkaller-00050-g9f266ccaa2f5 #0 Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/12/2023 RIP: 0010:usb_submit_urb+0x14a7/0x1880 drivers/usb/core/urb.c:411 ... Call Trace: <TASK> usb_start_wait_urb+0x101/0x4b0 drivers/usb/core/message.c:58 usb_internal_control_msg drivers/usb/core/message.c:102 [inline] usb_control_msg+0x320/0x4a0 drivers/usb/core/message.c:153 __usbnet_read_cmd+0xb9/0x390 drivers/net/usb/usbnet.c:2010 usbnet_read_cmd+0x96/0xf0 drivers/net/usb/usbnet.c:2068 pl_vendor_req drivers/net/usb/plusb.c:60 [inline] pl_set_QuickLink_features drivers/net/usb/plusb.c:75 [inline] pl_reset+0x2f/0xf0 drivers/net/usb/plusb.c:85 usbnet_open+0xcc/0x5d0 drivers/net/usb/usbnet.c:889
__dev_open+0x297/0x4d0 net/core/dev.c:1417 __dev_change_flags+0x587/0x750 net/core/dev.c:8530 dev_change_flags+0x97/0x170 net/core/dev.c:8602 devinet_ioctl+0x15a2/0x1d70 net/ipv4/devinet.c:1147 inet_ioctl+0x33f/0x380 net/ipv4/af_inet.c:979 sock_do_ioctl+0xcc/0x230 net/socket.c:1169 sock_ioctl+0x1f8/0x680 net/socket.c:1286 vfs_ioctl fs/ioctl.c:51 [inline] __do_sys_ioctl fs/ioctl.c:870 [inline] __se_sys_ioctl fs/ioctl.c:856 [inline] __x64_sys_ioctl+0x197/0x210 fs/ioctl.c:856 do_syscall_x64 arch/x86/entry/common.c:50 [inline] do_syscall_64+0x39/0xb0 arch/x86/entry/common.c:80 entry_SYSCALL_64_after_hwframe+0x63/0xcd The fix is to call usbnet_write_cmd() instead of usbnet_read_cmd() and remove the USB_DIR_IN flag. (CVE-2023-52742)

- In the Linux kernel, the following vulnerability has been resolved: tracing: Make sure trace_printk() can output as soon as it can be used Currently trace_printk() can be used as soon as early_trace_init() is called from start_kernel(). But if a crash happens, and ftrace_dump_on_oops is set on the kernel command line, all you get will be: [ 0.456075] <idle>-0 0dN.2. 347519us : Unknown type 6 [ 0.456075] <idle>-0 0dN.2. 353141us : Unknown type 6 [ 0.456075] <idle>-0 0dN.2. 358684us : Unknown type 6 This is because the trace_printk() event (type 6) hasn't been registered yet. That gets done via an early_initcall(), which may be early, but not early enough. Instead of registering the trace_printk() event (and other ftrace events, which are not trace events) via an early_initcall(), have them registered at the same time that trace_printk() can be used. This way, if there is a crash before early_initcall(), then the trace_printk()s will actually be useful. (CVE-2023-53007)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected packages based on the guidance in TuxCare advisory ALMALINUX9.6:CLSA-2026:1782155469.

See Also

https://cve.tuxcare.com/els/releases/CLSA-2026:1782155469

http://www.nessus.org/u?7eb50f9f

Plugin Details

Severity: High

ID: 359640

File Name: tuxcare_alma_linux_9.6_CLSA-2026-1782155469.nasl

Version: 1.1

Type: Local

Published: 10/1/2026

Updated: 10/1/2026

Supported Sensors: Nessus Agent, Continuous Assessment, Nessus

Risk Information

VPR

Risk Factor: High

Score: 7.7

Percentile: 98.99

Vendor

Vendor Severity: Important

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5.6

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2026-23013

CVSS v3

Risk Factor: High

Base Score: 7.8

Temporal Score: 7.2

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:F/RL:O/RC:C

Vulnerability Information

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/AlmaLinux/release, Host/AlmaLinux/rpm-list, Host/OS/extended-third-party

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 6/22/2026

Vulnerability Publication Date: 7/21/2021

CISA Known Exploited Vulnerability Due Dates: 9/21/2026

Reference Information

CVE: CVE-2022-48946, CVE-2022-48972, CVE-2022-49779, CVE-2022-49989, CVE-2022-50365, CVE-2022-50521, CVE-2023-52742, CVE-2023-52808, CVE-2023-53007, CVE-2023-53548, CVE-2024-35803, CVE-2024-36286, CVE-2024-41088, CVE-2024-42232, CVE-2024-42290, CVE-2024-43835, CVE-2024-47809, CVE-2024-50012, CVE-2024-50060, CVE-2024-53172, CVE-2024-53219, CVE-2024-56645, CVE-2024-56739, CVE-2024-56770, CVE-2024-57948, CVE-2024-58096, CVE-2024-58097, CVE-2025-21681, CVE-2025-21731, CVE-2025-21817, CVE-2025-21857, CVE-2025-21870, CVE-2025-22090, CVE-2025-37761, CVE-2025-37808, CVE-2025-37914, CVE-2025-38048, CVE-2025-38053, CVE-2025-38064, CVE-2025-38105, CVE-2025-38154, CVE-2025-38161, CVE-2025-38264, CVE-2025-38385, CVE-2025-38460, CVE-2025-38653, CVE-2025-38665, CVE-2025-38681, CVE-2025-38710, CVE-2025-39721, CVE-2025-39925, CVE-2025-39947, CVE-2025-39964, CVE-2025-40167, CVE-2025-40186, CVE-2025-40194, CVE-2025-40259, CVE-2025-40308, CVE-2025-40331, CVE-2025-68366, CVE-2025-68724, CVE-2025-68803, CVE-2025-68813, CVE-2025-68814, CVE-2025-68815, CVE-2025-68820, CVE-2025-71077, CVE-2025-71083, CVE-2025-71084, CVE-2025-71087, CVE-2025-71095, CVE-2025-71096, CVE-2025-71097, CVE-2025-71099, CVE-2025-71122, CVE-2025-71132, CVE-2025-71137, CVE-2025-71142, CVE-2025-71182, CVE-2025-71227, CVE-2025-71235, CVE-2025-71236, CVE-2025-71273, CVE-2026-22979, CVE-2026-22989, CVE-2026-22994, CVE-2026-23002, CVE-2026-23003, CVE-2026-23007, CVE-2026-23013, CVE-2026-23017, CVE-2026-23023, CVE-2026-23038, CVE-2026-23058, CVE-2026-23066, CVE-2026-23070, CVE-2026-23103, CVE-2026-23110, CVE-2026-23113, CVE-2026-23126, CVE-2026-23138, CVE-2026-23154, CVE-2026-23169, CVE-2026-23198, CVE-2026-23210, CVE-2026-23357, CVE-2026-23367, CVE-2026-23379, CVE-2026-23381, CVE-2026-23382, CVE-2026-23389, CVE-2026-23392, CVE-2026-23442, CVE-2026-23444, CVE-2026-23455, CVE-2026-31408, CVE-2026-31488, CVE-2026-31497, CVE-2026-31498, CVE-2026-31510, CVE-2026-31512, CVE-2026-31515, CVE-2026-31521, CVE-2026-31531, CVE-2026-31540, CVE-2026-31546, CVE-2026-31586, CVE-2026-31602, CVE-2026-31613, CVE-2026-31625, CVE-2026-31628, CVE-2026-31634, CVE-2026-31656, CVE-2026-31664, CVE-2026-31671, CVE-2026-31672, CVE-2026-31685, CVE-2026-31694, CVE-2026-43051, CVE-2026-43158, CVE-2026-43332

CLSA: 2026:1782155469