AlmaLinux 9.6 [TuxCare] Security Update: kernel / kernel-abi-stablelists / kernel-core / etc Multiple Vulnerabilities (ALMALINUX9.6:CLSA-2026:1778787063)

high Nessus Plugin ID 361904

Synopsis

The AlmaLinux host is missing one or more security updates.

Description

The AlmaLinux 9.6 host has packages installed that are affected by multiple vulnerabilities as referenced in the TuxCare ALMALINUX9.6:CLSA-2026:1778787063 advisory.

- In the Linux kernel, the following vulnerability has been resolved: can: m_can: pci: add missing m_can_class_free_dev() in probe/remove methods In m_can_pci_remove() and error handling path of m_can_pci_probe(), m_can_class_free_dev() should be called to free resource allocated by m_can_class_allocate_dev(), otherwise there will be memleak. (CVE-2022-49024)

- In the Linux kernel, the following vulnerability has been resolved: ima: Fix a potential integer overflow in ima_appraise_measurement When the ima-modsig is enabled, the rc passed to evm_verifyxattr() may be negative, which may cause the integer overflow problem. (CVE-2022-49643)

- In the Linux kernel, the following vulnerability has been resolved: usbnet: fix memory leak in error case usbnet_write_cmd_async() mixed up which buffers need to be freed in which error case. v2: add Fixes tag v3: fix uninitialized buf pointer (CVE-2022-49657)

- In the Linux kernel, the following vulnerability has been resolved: can: j1939: j1939_send_one(): fix missing CAN header initialization The read access to struct canxl_frame::len inside of a j1939 created skbuff revealed a missing initialization of reserved and later filled elements in struct can_frame. This patch initializes the 8 byte CAN header with zero. (CVE-2022-49845)

- In the Linux kernel, the following vulnerability has been resolved: misc: tifm: fix possible memory leak in tifm_7xx1_switch_media() If device_register() returns error in tifm_7xx1_switch_media(), name of kobject which is allocated in dev_set_name() called in device_add() is leaked. Never directly free @dev after calling device_register(), even if it returned an error! Always use put_device() to give up the reference initialized. (CVE-2022-50349)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected packages based on the guidance in TuxCare advisory ALMALINUX9.6:CLSA-2026:1778787063.

See Also

https://cve.tuxcare.com/els/releases/CLSA-2026:1778787063

http://www.nessus.org/u?e3932354

Plugin Details

Severity: High

ID: 361904

File Name: tuxcare_alma_linux_9.6_CLSA-2026-1778787063.nasl

Version: 1.2

Type: Local

Published: 10/1/2026

Updated: 10/2/2026

Supported Sensors: Nessus Agent, Continuous Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

Risk Information

VPR

Risk Factor: Critical

Score: 9.5

Percentile: 99.87

Vendor

Vendor Severity: Important

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5.9

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2026-46300

CVSS v3

Risk Factor: High

Base Score: 7.8

Temporal Score: 7.5

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:H/RL:O/RC:C

Vulnerability Information

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/AlmaLinux/release, Host/AlmaLinux/rpm-list, Host/OS/extended-third-party

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 5/14/2026

Vulnerability Publication Date: 7/21/2021

Exploitable With

Core Impact

Metasploit (Fragnesia LPE (CVE-2026-46300))

Reference Information

CVE: CVE-2022-49024, CVE-2022-49643, CVE-2022-49657, CVE-2022-49845, CVE-2022-50282, CVE-2022-50349, CVE-2022-50387, CVE-2022-50438, CVE-2022-50476, CVE-2022-50498, CVE-2023-53062, CVE-2023-53165, CVE-2023-53629, CVE-2023-53685, CVE-2024-39494, CVE-2024-40954, CVE-2024-47679, CVE-2024-50195, CVE-2024-53052, CVE-2024-53119, CVE-2024-56606, CVE-2024-56662, CVE-2024-57981, CVE-2024-57987, CVE-2024-57993, CVE-2024-58012, CVE-2024-58062, CVE-2024-58068, CVE-2024-58077, CVE-2024-58088, CVE-2025-21636, CVE-2025-21648, CVE-2025-21649, CVE-2025-21664, CVE-2025-21665, CVE-2025-21672, CVE-2025-21683, CVE-2025-21691, CVE-2025-21728, CVE-2025-21729, CVE-2025-21744, CVE-2025-21745, CVE-2025-21750, CVE-2025-21758, CVE-2025-21766, CVE-2025-21776, CVE-2025-21779, CVE-2025-21796, CVE-2025-21830, CVE-2025-21833, CVE-2025-21838, CVE-2025-21844, CVE-2025-21847, CVE-2025-21853, CVE-2025-21861, CVE-2025-21875, CVE-2025-21877, CVE-2025-21881, CVE-2025-21885, CVE-2025-21891, CVE-2025-21909, CVE-2025-21924, CVE-2025-21941, CVE-2025-21948, CVE-2025-21951, CVE-2025-21959, CVE-2025-21971, CVE-2025-21975, CVE-2025-21981, CVE-2025-21996, CVE-2025-22008, CVE-2025-22044, CVE-2025-22057, CVE-2025-22063, CVE-2025-22075, CVE-2025-22086, CVE-2025-22103, CVE-2025-23131, CVE-2025-23136, CVE-2025-23145, CVE-2025-37757, CVE-2025-37765, CVE-2025-37766, CVE-2025-37773, CVE-2025-37792, CVE-2025-37794, CVE-2025-37801, CVE-2025-37824, CVE-2025-37859, CVE-2025-37867, CVE-2025-37877, CVE-2025-37980, CVE-2025-37994, CVE-2025-38045, CVE-2025-38096, CVE-2025-38099, CVE-2025-38193, CVE-2025-38208, CVE-2025-38430, CVE-2025-38436, CVE-2025-38439, CVE-2025-38468, CVE-2025-38474, CVE-2025-38539, CVE-2025-38643, CVE-2025-38705, CVE-2025-39705, CVE-2025-39707, CVE-2025-39745, CVE-2025-39829, CVE-2025-39851, CVE-2025-39889, CVE-2025-39902, CVE-2025-39940, CVE-2025-40164, CVE-2025-40185, CVE-2025-71116, CVE-2025-71225, CVE-2026-23076, CVE-2026-23125, CVE-2026-31493, CVE-2026-31500, CVE-2026-31551, CVE-2026-46300

CLSA: 2026:1778787063