CentOS Linux 8.4 [TuxCare] Security Update: bpftool / kernel / kernel-core / kernel-cross-headers / etc Multiple Vulnerabilities (CENTOS8.4:CLSA-2025:1763731262)

high Nessus Plugin ID 361530

Synopsis

The CentOS Linux host is missing one or more security updates.

Description

The CentOS Linux 8.4 host has packages installed that are affected by multiple vulnerabilities as referenced in the TuxCare CENTOS8.4:CLSA-2025:1763731262 advisory.

- An issue was discovered on Samsung Galaxy S3 i9305 4.4.4 devices. The WEP, WPA, WPA2, and WPA3 implementations accept plaintext A-MSDU frames as long as the first 8 bytes correspond to a valid RFC1042 (i.e., LLC/SNAP) header for EAPOL. An adversary can abuse this to inject arbitrary network packets independent of the network configuration. (CVE-2020-26144)

- An issue was discovered in the Linux kernel before 5.11.8. kernel/bpf/verifier.c performs undesirable out- of-bounds speculation on pointer arithmetic, leading to side-channel attacks that defeat Spectre mitigations and obtain sensitive information from kernel memory, aka CID-f232326f6966. This affects pointer types that do not define a ptr_limit. (CVE-2020-27170)

- An issue was discovered in the Linux kernel before 5.11.8. kernel/bpf/verifier.c has an off-by-one error (with a resultant integer underflow) affecting out-of-bounds speculation on pointer arithmetic, leading to side-channel attacks that defeat Spectre mitigations and obtain sensitive information from kernel memory, aka CID-10d2bb2e6b1d. (CVE-2020-27171)

- In the Linux kernel, the following vulnerability has been resolved: scsi: mpt3sas: Fix use-after-free warning Fix the following use-after-free warning which is observed during controller reset: refcount_t:
underflow; use-after-free. WARNING: CPU: 23 PID: 5399 at lib/refcount.c:28 refcount_warn_saturate+0xa6/0xf0 (CVE-2022-48695)

- In the Linux kernel, the following vulnerability has been resolved: ASoC: ops: Reject out of bounds values in snd_soc_put_volsw() We don't currently validate that the values being set are within the range we advertised to userspace as being valid, do so and reject any values that are out of range.
(CVE-2022-48738)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected packages based on the guidance in TuxCare advisory CENTOS8.4:CLSA-2025:1763731262.

See Also

https://cve.tuxcare.com/els/releases/CLSA-2025:1763731262

http://www.nessus.org/u?2e819eae

Plugin Details

Severity: High

ID: 361530

File Name: tuxcare_centos_8.4_CLSA-2025-1763731262.nasl

Version: 1.1

Type: Local

Agent: unix

Published: 10/1/2026

Updated: 10/1/2026

Supported Sensors: Nessus Agent, Continuous Assessment, Nessus

Risk Information

VPR

Risk Factor: High

Score: 7

Percentile: 98.57

Vendor

Vendor Severity: Important

CVSS v2

Risk Factor: Low

Base Score: 3.6

Temporal Score: 2.8

Vector: CVSS2#AV:L/AC:L/Au:N/C:P/I:N/A:P

CVSS Score Source: CVE-2020-27171

CVSS v3

Risk Factor: High

Base Score: 7.8

Temporal Score: 7

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

CVSS Score Source: CVE-2025-39864

Vulnerability Information

Required KB Items: Host/local_checks_enabled, Host/CentOS/release, Host/CentOS/rpm-list, Host/OS/extended-third-party

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 11/21/2025

Vulnerability Publication Date: 3/20/2021

Reference Information

CVE: CVE-2020-26144, CVE-2020-27170, CVE-2020-27171, CVE-2022-48695, CVE-2022-48738, CVE-2022-48759, CVE-2022-49044, CVE-2022-49073, CVE-2022-49145, CVE-2022-49292, CVE-2022-49407, CVE-2022-49519, CVE-2022-49592, CVE-2022-49935, CVE-2022-49985, CVE-2022-50087, CVE-2022-50228, CVE-2022-50367, CVE-2022-50408, CVE-2023-52804, CVE-2023-52836, CVE-2023-52847, CVE-2023-52867, CVE-2023-52868, CVE-2023-53019, CVE-2023-53034, CVE-2023-53125, CVE-2023-53178, CVE-2023-53185, CVE-2023-53226, CVE-2023-53229, CVE-2023-53297, CVE-2023-53322, CVE-2023-53365, CVE-2023-53373, CVE-2023-53386, CVE-2023-53581, CVE-2023-53675, CVE-2023-53705, CVE-2024-36015, CVE-2024-38621, CVE-2024-38635, CVE-2024-38659, CVE-2024-42119, CVE-2024-52332, CVE-2024-53214, CVE-2024-56570, CVE-2024-57904, CVE-2024-57929, CVE-2024-58014, CVE-2024-58072, CVE-2025-21704, CVE-2025-21772, CVE-2025-22121, CVE-2025-37789, CVE-2025-37796, CVE-2025-38001, CVE-2025-38461, CVE-2025-38498, CVE-2025-38527, CVE-2025-38718, CVE-2025-39730, CVE-2025-39757, CVE-2025-39817, CVE-2025-39841, CVE-2025-39864

CLSA: 2025:1763731262