AlmaLinux 9.6 [TuxCare] Security Update: kernel / kernel-abi-stablelists / kernel-core / etc Multiple Vulnerabilities (ALMALINUX9.6:CLSA-2026:1781344094)

high Nessus Plugin ID 360739

Synopsis

The AlmaLinux host is missing one or more security updates.

Description

The AlmaLinux 9.6 host has packages installed that are affected by multiple vulnerabilities as referenced in the TuxCare ALMALINUX9.6:CLSA-2026:1781344094 advisory.

- In the Linux kernel, the following vulnerability has been resolved: i2c: designware: use casting of u64 in clock multiplication to avoid overflow In functions i2c_dw_scl_lcnt() and i2c_dw_scl_hcnt() may have overflow by depending on the values of the given parameters including the ic_clk. For example in our use case where ic_clk is larger than one million, multiplication of ic_clk * 4700 will result in 32 bit overflow. Add cast of u64 to the calculation to avoid multiplication overflow, and use the corresponding define for divide. (CVE-2022-49749)

- In the Linux kernel, the following vulnerability has been resolved: kernel/irq/irqdomain.c: fix memory leak with using debugfs_lookup() When calling debugfs_lookup() the result must have dput() called on it, otherwise the memory will leak over time. To make things simpler, just call debugfs_lookup_and_remove() instead which handles all of the logic at once. (CVE-2023-52936)

- In the Linux kernel, the following vulnerability has been resolved: tracing: Fix null pointer dereference in tracing_err_log_open() Fix an issue in function 'tracing_err_log_open'. The function doesn't call 'seq_open' if the file is opened only with write permissions, which results in 'file->private_data' being left as null. If we then use 'lseek' on that opened file, 'seq_lseek' dereferences 'file->private_data' in 'mutex_lock(&m->lock)', resulting in a kernel panic. Writing to this node requires root privileges, therefore this bug has very little security impact. Tracefs node: /sys/kernel/tracing/error_log Example Kernel panic: Unable to handle kernel NULL pointer dereference at virtual address 0000000000000038 Call trace: mutex_lock+0x30/0x110 seq_lseek+0x34/0xb8 __arm64_sys_lseek+0x6c/0xb8 invoke_syscall+0x58/0x13c el0_svc_common+0xc4/0x10c do_el0_svc+0x24/0x98 el0_svc+0x24/0x88 el0t_64_sync_handler+0x84/0xe4 el0t_64_sync+0x1b4/0x1b8 Code: d503201f aa0803e0 aa1f03e1 aa0103e9 (c8e97d02) ---[ end trace 561d1b49c12cf8a5 ]--- Kernel panic - not syncing: Oops: Fatal exception (CVE-2023-53167)

- In the Linux kernel, the following vulnerability has been resolved: irqchip: Fix refcount leak in platform_irqchip_probe of_irq_find_parent() returns a node pointer with refcount incremented, We should use of_node_put() on it when not needed anymore. Add missing of_node_put() to avoid refcount leak.
(CVE-2023-53610)

- In the Linux kernel, the following vulnerability has been resolved: uio_hv_generic: Fix kernel NULL pointer dereference in hv_uio_rescind For primary VM Bus channels, primary_channel pointer is always NULL.
This pointer is valid only for the secondary channels. Also, rescind callback is meant for primary channels only. Fix NULL pointer dereference by retrieving the device_obj from the parent for the primary channel. (CVE-2024-46739)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected packages based on the guidance in TuxCare advisory ALMALINUX9.6:CLSA-2026:1781344094.

See Also

https://cve.tuxcare.com/els/releases/CLSA-2026:1781344094

http://www.nessus.org/u?0d0e8293

Plugin Details

Severity: High

ID: 360739

File Name: tuxcare_alma_linux_9.6_CLSA-2026-1781344094.nasl

Version: 1.1

Type: Local

Published: 10/1/2026

Updated: 10/1/2026

Supported Sensors: Nessus Agent, Continuous Assessment, Nessus

Risk Information

VPR

Risk Factor: High

Score: 7.6

Percentile: 98.58

Vendor

Vendor Severity: Important

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5.3

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2026-43328

CVSS v3

Risk Factor: High

Base Score: 7.8

Temporal Score: 7

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/AlmaLinux/release, Host/AlmaLinux/rpm-list, Host/OS/extended-third-party

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 6/13/2026

Vulnerability Publication Date: 7/21/2021

Reference Information

CVE: CVE-2022-49749, CVE-2023-52616, CVE-2023-52936, CVE-2023-53167, CVE-2023-53610, CVE-2024-26839, CVE-2024-46739, CVE-2024-49955, CVE-2024-50010, CVE-2024-50294, CVE-2024-53090, CVE-2024-53128, CVE-2024-56629, CVE-2024-56681, CVE-2024-56715, CVE-2024-57974, CVE-2024-58051, CVE-2024-58052, CVE-2025-21709, CVE-2025-21746, CVE-2025-21763, CVE-2025-21806, CVE-2025-21839, CVE-2025-22089, CVE-2025-37800, CVE-2025-38067, CVE-2025-38080, CVE-2025-38162, CVE-2025-38248, CVE-2025-38279, CVE-2025-38305, CVE-2025-38391, CVE-2025-38424, CVE-2025-38458, CVE-2025-38470, CVE-2025-38524, CVE-2025-38591, CVE-2025-38678, CVE-2025-39916, CVE-2025-40134, CVE-2025-68211, CVE-2025-71088, CVE-2025-71100, CVE-2025-71117, CVE-2025-71120, CVE-2025-71127, CVE-2025-71157, CVE-2025-71160, CVE-2026-22996, CVE-2026-23021, CVE-2026-23069, CVE-2026-23086, CVE-2026-23190, CVE-2026-23247, CVE-2026-23255, CVE-2026-23286, CVE-2026-23290, CVE-2026-23293, CVE-2026-23300, CVE-2026-23302, CVE-2026-23303, CVE-2026-23304, CVE-2026-23307, CVE-2026-23335, CVE-2026-23370, CVE-2026-23399, CVE-2026-23468, CVE-2026-23472, CVE-2026-31480, CVE-2026-31496, CVE-2026-31503, CVE-2026-31523, CVE-2026-31579, CVE-2026-31590, CVE-2026-31651, CVE-2026-31661, CVE-2026-31663, CVE-2026-31669, CVE-2026-31677, CVE-2026-31709, CVE-2026-31777, CVE-2026-43066, CVE-2026-43074, CVE-2026-43079, CVE-2026-43080, CVE-2026-43085, CVE-2026-43089, CVE-2026-43107, CVE-2026-43110, CVE-2026-43190, CVE-2026-43234, CVE-2026-43303, CVE-2026-43328

CLSA: 2026:1781344094