CentOS Linux 8 [TuxCare] Security Update: bpftool / kernel / kernel-core / kernel-cross-headers / etc Multiple Vulnerabilities (CENTOS-STREAM8:CLSA-2026:1780132980)

high Nessus Plugin ID 362073

Synopsis

The CentOS Linux host is missing one or more security updates.

Description

The CentOS Linux 8 host has packages installed that are affected by multiple vulnerabilities as referenced in the TuxCare CENTOS-STREAM8:CLSA-2026:1780132980 advisory.

- kernel/module.c in the Linux kernel before 5.12.14 mishandles Signature Verification, aka CID-0c18f29aae7c. Without CONFIG_MODULE_SIG, verification that a kernel module is signed, for loading via init_module, does not occur for a module.sig_enforce=1 command-line argument. (CVE-2021-35039)

- In drivers/char/virtio_console.c in the Linux kernel before 5.13.4, data corruption or loss can be triggered by an untrusted device that supplies a buf->len value exceeding the buffer size. NOTE: the vendor indicates that the cited data corruption is not a vulnerability in any existing use case; the length validation was added solely for robustness in the face of anomalous host OS behavior (CVE-2021-38160)

- There are use-after-free vulnerabilities in the Linux kernel's net/bluetooth/l2cap_core.c's l2cap_connect and l2cap_le_connect_req functions which may allow code execution and leaking kernel memory (respectively) remotely via Bluetooth. A remote attacker could execute code leaking kernel memory via Bluetooth if within proximity of the victim. We recommend upgrading past commit https://www.google.com/url https://github.com/torvalds/linux/commit/711f8c3fb3db61897080468586b970c87c61d9e4 https://www.google.com/url (CVE-2022-42896)

- In the Linux kernel, the following vulnerability has been resolved: tracing: Fix potential double free in create_var_ref() In create_var_ref(), init_var_ref() is called to initialize the fields of variable ref_field, which is allocated in the previous function call to create_hist_field(). Function init_var_ref() allocates the corresponding fields such as ref_field->system, but frees these fields when the function encounters an error. The caller later calls destroy_hist_field() to conduct error handling, which frees the fields and the variable itself. This results in double free of the fields which are already freed in the previous function. Fix this by storing NULL to the corresponding fields when they are freed in init_var_ref(). (CVE-2022-49410)

- In the Linux kernel, the following vulnerability has been resolved: HID: elan: Fix potential double free in elan_input_configured 'input' is a managed resource allocated with devm_input_allocate_device(), so there is no need to call input_free_device() explicitly or there will be a double free. According to the doc of devm_input_allocate_device(): * Managed input devices do not need to be explicitly unregistered or
* freed as it will be done automatically when owner device unbinds from * its driver (or binding fails).
(CVE-2022-49508)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected packages based on the guidance in TuxCare advisory CENTOS-STREAM8:CLSA-2026:1780132980.

See Also

https://cve.tuxcare.com/els/releases/CLSA-2026:1780132980

http://www.nessus.org/u?78268d5f

Plugin Details

Severity: High

ID: 362073

File Name: tuxcare_centos_8_CLSA-2026-1780132980.nasl

Version: 1.1

Type: Local

Agent: unix

Published: 10/1/2026

Updated: 10/1/2026

Supported Sensors: Nessus Agent, Continuous Assessment, Nessus

Risk Information

VPR

Risk Factor: High

Score: 7.9

Percentile: 99.35

Vendor

Vendor Severity: Important

CVSS v2

Risk Factor: High

Base Score: 7.2

Temporal Score: 6.3

Vector: CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2021-38160

CVSS v3

Risk Factor: High

Base Score: 8.8

Temporal Score: 8.4

Vector: CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:H/RL:O/RC:C

CVSS Score Source: CVE-2022-42896

Vulnerability Information

Required KB Items: Host/local_checks_enabled, Host/CentOS/release, Host/CentOS/rpm-list, Host/OS/extended-third-party

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 5/30/2026

Vulnerability Publication Date: 7/7/2021

Reference Information

CVE: CVE-2021-35039, CVE-2021-38160, CVE-2022-42896, CVE-2022-49410, CVE-2022-49508, CVE-2022-49870, CVE-2022-49907, CVE-2022-49917, CVE-2022-49948, CVE-2022-50200, CVE-2022-50315, CVE-2022-50366, CVE-2022-50432, CVE-2022-50497, CVE-2023-52475, CVE-2023-52531, CVE-2023-52741, CVE-2023-52867, CVE-2023-52868, CVE-2023-52988, CVE-2023-53000, CVE-2023-53019, CVE-2023-53075, CVE-2023-53116, CVE-2023-53285, CVE-2023-53307, CVE-2023-53321, CVE-2023-53338, CVE-2023-53506, CVE-2023-53570, CVE-2023-53622, CVE-2023-53646, CVE-2023-53668, CVE-2024-46812, CVE-2025-68741, CVE-2025-71093, CVE-2025-71116, CVE-2026-23216, CVE-2026-23388, CVE-2026-31602, CVE-2026-31778, CVE-2026-43020, CVE-2026-43040, CVE-2026-43206, CVE-2026-43450, CVE-2026-46243

CLSA: 2026:1780132980