Amazon Linux 2023 : bpftool, kernel, kernel-devel (ALAS2023-2024-643)

medium Nessus Plugin ID 200913

Synopsis

The remote Amazon Linux 2023 host is missing a security update.

Description

It is, therefore, affected by multiple vulnerabilities as referenced in the ALAS2023-2024-643 advisory.

2024-12-05: CVE-2024-36882 was added to this advisory.

2024-12-05: CVE-2024-36890 was added to this advisory.

2024-12-05: CVE-2024-36028 was added to this advisory.

2024-12-05: CVE-2024-36917 was added to this advisory.

2024-11-13: CVE-2024-36896 was added to this advisory.

2024-07-03: CVE-2024-26900 was added to this advisory.

2024-07-03: CVE-2024-36883 was added to this advisory.

2024-07-03: CVE-2024-36938 was added to this advisory.

2024-07-03: CVE-2024-36940 was added to this advisory.

2024-07-03: CVE-2024-36902 was added to this advisory.

2024-07-03: CVE-2024-36937 was added to this advisory.

2024-07-03: CVE-2024-36017 was added to this advisory.

2024-07-03: CVE-2024-36939 was added to this advisory.

2024-07-03: CVE-2024-35947 was added to this advisory.

2024-07-03: CVE-2024-36889 was added to this advisory.

2024-07-03: CVE-2024-36944 was added to this advisory.

2024-07-03: CVE-2024-36904 was added to this advisory.

2024-07-03: CVE-2024-36929 was added to this advisory.

In the Linux kernel, the following vulnerability has been resolved:

md: fix kmemleak of rdev->serial (CVE-2024-26900)

In the Linux kernel, the following vulnerability has been resolved:

dyndbg: fix old BUG_ON in >control parser (CVE-2024-35947)

In the Linux kernel, the following vulnerability has been resolved:

rtnetlink: Correct nested IFLA_VF_VLAN_LIST attribute validation (CVE-2024-36017)

In the Linux kernel, the following vulnerability has been resolved:

mm/hugetlb: fix DEBUG_LOCKS_WARN_ON(1) when dissolve_free_hugetlb_folio() (CVE-2024-36028)

In the Linux kernel, the following vulnerability has been resolved:

mm: use memalloc_nofs_save() in page_cache_ra_order() (CVE-2024-36882)

In the Linux kernel, the following vulnerability has been resolved:

net: fix out-of-bounds access in ops_init (CVE-2024-36883)

In the Linux kernel, the following vulnerability has been resolved:

mptcp: ensure snd_nxt is properly initialized on connect (CVE-2024-36889)

In the Linux kernel, the following vulnerability has been resolved:

mm/slab: make __free(kfree) accept error pointers (CVE-2024-36890)

In the Linux kernel, the following vulnerability has been resolved:

USB: core: Fix access violation during port device removal (CVE-2024-36896)

In the Linux kernel, the following vulnerability has been resolved:

ipv6: fib6_rules: avoid possible NULL dereference in fib6_rule_action() (CVE-2024-36902)

In the Linux kernel, the following vulnerability has been resolved:

tcp: Use refcount_inc_not_zero() in tcp_twsk_unique(). (CVE-2024-36904)

In the Linux kernel, the following vulnerability has been resolved:

tcp: defer shutdown(SEND_SHUTDOWN) for TCP_SYN_RECV sockets (CVE-2024-36905)

In the Linux kernel, the following vulnerability has been resolved:

blk-iocost: avoid out of bounds shift (CVE-2024-36916)

In the Linux kernel, the following vulnerability has been resolved:

block: fix overflow in blk_ioctl_discard() (CVE-2024-36917)

In the Linux kernel, the following vulnerability has been resolved:

net: core: reject skb_copy(_expand) for fraglist GSO skbs (CVE-2024-36929)

In the Linux kernel, the following vulnerability has been resolved:

nsh: Restore skb->{protocol,data,mac_header} for outer header in nsh_gso_segment(). (CVE-2024-36933)

In the Linux kernel, the following vulnerability has been resolved:

xdp: use flags field to disambiguate broadcast redirect (CVE-2024-36937)

In the Linux kernel, the following vulnerability has been resolved:

bpf, skmsg: Fix NULL pointer dereference in sk_psock_skb_ingress_enqueue (CVE-2024-36938)

In the Linux kernel, the following vulnerability has been resolved:

nfs: Handle error of rpc_proc_register() in nfs_net_init(). (CVE-2024-36939)

In the Linux kernel, the following vulnerability has been resolved:

pinctrl: core: delete incorrect free in pinctrl_enable() (CVE-2024-36940)

In the Linux kernel, the following vulnerability has been resolved:

Reapply drm/qxl: simplify qxl_fence_wait (CVE-2024-36944)

In the Linux kernel, the following vulnerability has been resolved:

pinctrl: devicetree: fix refcount leak in pinctrl_dt_to_map() (CVE-2024-36959)

Tenable has extracted the preceding description block directly from the tested product security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Run 'dnf update kernel --releasever 2023.5.20240624' to update your system.

See Also

https://alas.aws.amazon.com/AL2023/ALAS-2024-643.html

https://alas.aws.amazon.com/faqs.html

https://alas.aws.amazon.com/cve/html/CVE-2024-26900.html

https://alas.aws.amazon.com/cve/html/CVE-2024-35947.html

https://alas.aws.amazon.com/cve/html/CVE-2024-36017.html

https://alas.aws.amazon.com/cve/html/CVE-2024-36028.html

https://alas.aws.amazon.com/cve/html/CVE-2024-36882.html

https://alas.aws.amazon.com/cve/html/CVE-2024-36883.html

https://alas.aws.amazon.com/cve/html/CVE-2024-36889.html

https://alas.aws.amazon.com/cve/html/CVE-2024-36890.html

https://alas.aws.amazon.com/cve/html/CVE-2024-36896.html

https://alas.aws.amazon.com/cve/html/CVE-2024-36902.html

https://alas.aws.amazon.com/cve/html/CVE-2024-36904.html

https://alas.aws.amazon.com/cve/html/CVE-2024-36905.html

https://alas.aws.amazon.com/cve/html/CVE-2024-36916.html

https://alas.aws.amazon.com/cve/html/CVE-2024-36917.html

https://alas.aws.amazon.com/cve/html/CVE-2024-36929.html

https://alas.aws.amazon.com/cve/html/CVE-2024-36933.html

https://alas.aws.amazon.com/cve/html/CVE-2024-36937.html

https://alas.aws.amazon.com/cve/html/CVE-2024-36938.html

https://alas.aws.amazon.com/cve/html/CVE-2024-36939.html

https://alas.aws.amazon.com/cve/html/CVE-2024-36940.html

https://alas.aws.amazon.com/cve/html/CVE-2024-36944.html

https://alas.aws.amazon.com/cve/html/CVE-2024-36959.html

Plugin Details

Severity: Medium

ID: 200913

File Name: al2023_ALAS2023-2024-643.nasl

Version: 1.5

Type: local

Agent: unix

Published: 6/24/2024

Updated: 12/11/2024

Supported Sensors: Frictionless Assessment AWS, Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Continuous Assessment, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.7

CVSS v2

Risk Factor: Medium

Base Score: 4.6

Temporal Score: 3.4

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:C

CVSS Score Source: CVE-2024-36938

CVSS v3

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: p-cpe:/a:amazon:linux:kernel-modules-extra-common, p-cpe:/a:amazon:linux:perf-debuginfo, p-cpe:/a:amazon:linux:kernel-modules-extra, p-cpe:/a:amazon:linux:kernel-debuginfo-common-aarch64, p-cpe:/a:amazon:linux:kernel-tools, p-cpe:/a:amazon:linux:python3-perf, p-cpe:/a:amazon:linux:kernel-libbpf-static, p-cpe:/a:amazon:linux:kernel-debuginfo, p-cpe:/a:amazon:linux:kernel-libbpf, p-cpe:/a:amazon:linux:bpftool-debuginfo, p-cpe:/a:amazon:linux:kernel-livepatch-6.1.91-99.172, p-cpe:/a:amazon:linux:kernel-libbpf-devel, p-cpe:/a:amazon:linux:kernel-headers, p-cpe:/a:amazon:linux:kernel-tools-devel, cpe:/o:amazon:linux:2023, p-cpe:/a:amazon:linux:perf, p-cpe:/a:amazon:linux:bpftool, p-cpe:/a:amazon:linux:kernel-tools-debuginfo, p-cpe:/a:amazon:linux:kernel-devel, p-cpe:/a:amazon:linux:kernel, p-cpe:/a:amazon:linux:python3-perf-debuginfo, p-cpe:/a:amazon:linux:kernel-debuginfo-common-x86_64

Required KB Items: Host/local_checks_enabled, Host/AmazonLinux/release, Host/AmazonLinux/rpm-list

Exploit Ease: No known exploits are available

Patch Publication Date: 6/19/2024

Vulnerability Publication Date: 5/30/2024

Reference Information

CVE: CVE-2024-26900, CVE-2024-35947, CVE-2024-36017, CVE-2024-36028, CVE-2024-36882, CVE-2024-36883, CVE-2024-36889, CVE-2024-36890, CVE-2024-36896, CVE-2024-36902, CVE-2024-36904, CVE-2024-36905, CVE-2024-36916, CVE-2024-36917, CVE-2024-36929, CVE-2024-36933, CVE-2024-36937, CVE-2024-36938, CVE-2024-36939, CVE-2024-36940, CVE-2024-36944, CVE-2024-36959