Amazon Linux 2023 : bpftool, kernel, kernel-devel (ALAS2023-2024-517)

high Nessus Plugin ID 190743

Version 1.10

Jul 5, 2024, 2:41 PM

  • CVE (set "CVE" coverage to "CVE-2023-52486,CVE-2023-52489,CVE-2023-52492,CVE-2023-52498,CVE-2023-52583,CVE-2023-52614,CVE-2023-52615,CVE-2023-52619,CVE-2023-52672,CVE-2024-1086,CVE-2024-23849,CVE-2024-26612,CVE-2024-26614,CVE-2024-26625,CVE-2024-26626,CVE-2024-26627,CVE-2024-26634,CVE-2024-26635,CVE-2024-26638,CVE-2024-26640,CVE-2024-26641,CVE-2024-26668")
  • Detection (updated detection logic)
  • Exploit attributes ("Exploitability ease" changed from "Exploits are available" to "No known exploits are available". "Exploited by malware" set to "True". "Exploitability ease" changed from "No known exploits are available" to "Exploits are available")
  • Plugin metadata

Plugin Feed: 202407051441

Version 1.8

Jun 10, 2024, 9:01 AM

  • Exploit attributes ("Exploited by malware" set to "True")
  • Exploit attributes ("Exploitability ease" changed from "No known exploits are available" to "Exploits are available")

Plugin Feed: 202406100901

Version 1.7

Jun 8, 2024, 3:36 AM

  • CVE (set "CVE" coverage to "CVE-2023-52486,CVE-2023-52489,CVE-2023-52492,CVE-2023-52498,CVE-2023-52672,CVE-2024-1086,CVE-2024-23849,CVE-2024-26612,CVE-2024-26614,CVE-2024-26625,CVE-2024-26668")
  • Detection (updated detection logic)
  • Exploit attributes ("Exploitability ease" changed from "Exploits are available" to "No known exploits are available")
  • Exploit attributes ("Exploited by malware" changed from "True" to none)
  • Plugin metadata

Plugin Feed: 202406080336

Version 1.6

May 31, 2024, 1:01 AM

  • CISA reference

Plugin Feed: 202405310101

Version 1.5

May 24, 2024, 10:34 AM

  • Exploit attributes ("Exploitability ease" changed from "No known exploits are available" to "Exploits are available")
  • Exploit attributes ("Exploited by malware" set to "True")

Plugin Feed: 202405241034

Version 1.4

May 24, 2024, 4:00 AM

  • CVE (set "CVE" coverage to "CVE-2024-1086,CVE-2024-23849,CVE-2024-26625,CVE-2024-26668")
  • Detection (updated detection logic)
  • Exploit attributes ("Exploitability ease" changed from "Exploits are available" to "No known exploits are available")
  • Exploit attributes ("Exploited by malware" changed from "True" to none)
  • Plugin metadata

Plugin Feed: 202405240400

Version 1.3

Apr 5, 2024, 1:58 PM

  • CVSS temporal metrics ("CVSSv3 temporal vector" set to "CVSS:3.0/E:H/RL:O/RC:C")
  • Exploit attributes ("Exploited by malware" set to "True")
  • CVSS temporal metrics ("CVSSv2 temporal vector" set to "CVSS2#E:H/RL:OF/RC:C")

Plugin Feed: 202404051358

Version 1.2

Mar 27, 2024, 2:17 PM

  • CVSS temporal metrics ("CVSSv2 temporal vector" set to "CVSS2#E:POC/RL:OF/RC:C". "CVSSv3 temporal vector" set to "CVSS:3.0/E:P/RL:O/RC:C")
  • Exploit attributes ("Exploit available" set to "True". "Exploitability ease" changed from "No known exploits are available" to "Exploits are available")

Plugin Feed: 202403271417

Version 1.1

Mar 5, 2024, 7:01 AM

  • Plugin metadata
  • CVE (set "CVE" coverage to "CVE-2024-1086,CVE-2024-23849")
  • CVSS metrics ("CVSSv2 score" set to 6.8. "CVSSv2 vector" set to "CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C". "CVSSv3 score" set to 7.8. "CVSSv3 vector" set to "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H")
  • CVSSv2 score source (changed from "CVE-2024-23849" to "CVE-2024-1086")
  • CVSSv3 severity (based on None, severity increased from "Medium" to "High")
  • Detection (updated detection logic)

Plugin Feed: 202403050701

Version 1.0

Feb 20, 2024, 8:32 AM

  • New

Plugin Feed: 202402200832

* Changelogs are generally available for changes made after Nov 1, 2022