AlmaLinux 9.2 [TuxCare] Security Update: bpftool / kernel / kernel-abi-stablelists / kernel-core / etc Multiple Vulnerabilities (ALMALINUX9.2:CLSA-2026:1781347338)

high Nessus Plugin ID 360826

Synopsis

The AlmaLinux host is missing one or more security updates.

Description

The AlmaLinux 9.2 host has packages installed that are affected by multiple vulnerabilities as referenced in the TuxCare ALMALINUX9.2:CLSA-2026:1781347338 advisory.

- In the Linux kernel, the following vulnerability has been resolved: net: mdio: unexport __init-annotated mdio_bus_init() EXPORT_SYMBOL and __init is a bad combination because the .init.text section is freed up after the initialization. Hence, modules cannot use symbols annotated __init. The access to a freed symbol may end up with kernel panic. modpost used to detect it, but it has been broken for a decade. Recently, I fixed modpost so it started to warn it again, then this showed up in linux-next builds. There are two ways to fix it: - Remove __init - Remove EXPORT_SYMBOL I chose the latter for this case because the only in- tree call-site, drivers/net/phy/phy_device.c is never compiled as modular. (CONFIG_PHYLIB is boolean) (CVE-2022-49350)

- In the Linux kernel, the following vulnerability has been resolved: selinux: fix memleak in security_read_state_kernel() In this function, it directly returns the result of __security_read_policy without freeing the allocated memory in *data, cause memory leak issue, so free the memory if
__security_read_policy failed. [PM: subject line tweak] (CVE-2022-50201)

- In the Linux kernel, the following vulnerability has been resolved: usb: typec: tcpci: fix of node refcount leak in tcpci_register_port() I got the following report while doing device(mt6370-tcpc) load test with CONFIG_OF_UNITTEST and CONFIG_OF_DYNAMIC enabled: OF: ERROR: memory leak, expected refcount 1 instead of 2, of_node_get()/of_node_put() unbalanced - destroy cset entry: attach overlay node /i2c/pmic@34/tcpc/connector The 'fwnode' set in tcpci_parse_config() which is called in tcpci_register_port(), its node refcount is increased in device_get_named_child_node(). It needs be put while exiting, so call fwnode_handle_put() in the error path of tcpci_register_port() and in tcpci_unregister_port() to avoid leak. (CVE-2022-50246)

- In the Linux kernel, the following vulnerability has been resolved: drivers: serial: jsm: fix some leaks in probe This error path needs to unwind instead of just returning directly. (CVE-2022-50312)

- In the Linux kernel, the following vulnerability has been resolved: thermal: intel_powerclamp: Use get_cpu() instead of smp_processor_id() to avoid crash When CPU 0 is offline and intel_powerclamp is used to inject idle, it generates kernel BUG: BUG: using smp_processor_id() in preemptible [00000000] code:
bash/15687 caller is debug_smp_processor_id+0x17/0x20 CPU: 4 PID: 15687 Comm: bash Not tainted 5.19.0-rc7+ #57 Call Trace: <TASK> dump_stack_lvl+0x49/0x63 dump_stack+0x10/0x16 check_preemption_disabled+0xdd/0xe0 debug_smp_processor_id+0x17/0x20 powerclamp_set_cur_state+0x7f/0xf9 [intel_powerclamp] ... ... Here CPU 0 is the control CPU by default and changed to the current CPU, if CPU 0 offlined. This check has to be performed under cpus_read_lock(), hence the above warning. Use get_cpu() instead of smp_processor_id() to avoid this BUG. [ rjw: Subject edits ] (CVE-2022-50494)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected packages based on the guidance in TuxCare advisory ALMALINUX9.2:CLSA-2026:1781347338.

See Also

https://cve.tuxcare.com/els/releases/CLSA-2026:1781347338

http://www.nessus.org/u?b692b298

Plugin Details

Severity: High

ID: 360826

File Name: tuxcare_alma_linux_9.2_CLSA-2026-1781347338.nasl

Version: 1.1

Type: Local

Published: 10/1/2026

Updated: 10/1/2026

Supported Sensors: Nessus Agent, Continuous Assessment, Nessus

Risk Information

VPR

Risk Factor: High

Score: 7.9

Percentile: 99.36

Vendor

Vendor Severity: Important

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5.3

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2026-43128

CVSS v3

Risk Factor: High

Base Score: 7.8

Temporal Score: 7

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/AlmaLinux/release, Host/AlmaLinux/rpm-list, Host/OS/extended-third-party

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 6/13/2026

Vulnerability Publication Date: 7/21/2021

Reference Information

CVE: CVE-2022-49350, CVE-2022-50201, CVE-2022-50246, CVE-2022-50312, CVE-2022-50494, CVE-2022-50510, CVE-2022-50578, CVE-2022-50883, CVE-2023-52703, CVE-2023-52795, CVE-2023-52798, CVE-2023-52814, CVE-2023-52851, CVE-2023-52942, CVE-2023-52974, CVE-2023-52996, CVE-2023-53051, CVE-2023-53058, CVE-2023-53073, CVE-2023-53078, CVE-2023-53095, CVE-2023-53102, CVE-2023-53120, CVE-2023-53275, CVE-2023-53334, CVE-2023-53335, CVE-2023-53408, CVE-2023-53546, CVE-2023-53549, CVE-2023-53598, CVE-2023-53605, CVE-2023-53612, CVE-2023-54106, CVE-2023-54322, CVE-2024-26742, CVE-2024-26843, CVE-2024-27012, CVE-2024-27013, CVE-2024-27436, CVE-2024-36920, CVE-2024-41098, CVE-2024-43879, CVE-2024-46783, CVE-2024-46830, CVE-2024-47696, CVE-2024-50003, CVE-2024-56679, CVE-2024-56726, CVE-2024-57897, CVE-2025-21758, CVE-2025-21759, CVE-2025-21763, CVE-2025-21764, CVE-2025-21765, CVE-2025-21766, CVE-2025-21975, CVE-2025-22008, CVE-2025-37852, CVE-2025-37949, CVE-2025-38512, CVE-2026-23111, CVE-2026-23286, CVE-2026-23304, CVE-2026-23307, CVE-2026-31408, CVE-2026-31590, CVE-2026-43026, CVE-2026-43035, CVE-2026-43036, CVE-2026-43043, CVE-2026-43068, CVE-2026-43079, CVE-2026-43080, CVE-2026-43085, CVE-2026-43107, CVE-2026-43123, CVE-2026-43124, CVE-2026-43128, CVE-2026-43132, CVE-2026-43167, CVE-2026-43216, CVE-2026-43251, CVE-2026-43303, CVE-2026-43315, CVE-2026-43381, CVE-2026-43411, CVE-2026-43425, CVE-2026-43453

CLSA: 2026:1781347338