kernel-5.14.0-570.28.1.el9_6
エラータID: AXSA:2025-10762:55
リリース日:
2025/08/21 Thursday - 09:07
題名:
kernel-5.14.0-570.28.1.el9_6
影響のあるチャネル:
MIRACLE LINUX 9 for x86_64
Severity:
High
Description:
以下項目について対処しました。
[Security Fix]
- kernel の uvc ドライバには、メモリ領域の解放後利用の問題が
あるため、ローカルの攻撃者により、情報の漏洩、データ破壊、
およびサービス拒否攻撃を可能とする脆弱性が存在します。
(CVE-2024-58002)
- kernel の sunrpc の実装 には、リモートの攻撃者により、巧妙に
細工されたパケットを介して、データ破壊、およびサービス拒否攻撃を
可能とする脆弱性が存在します。(CVE-2025-38089)
解決策:
パッケージをアップデートしてください。
CVE:
CVE-2024-58002
In the Linux kernel, the following vulnerability has been resolved: media: uvcvideo: Remove dangling pointers When an async control is written, we copy a pointer to the file handle that started the operation. That pointer will be used when the device is done. Which could be anytime in the future. If the user closes that file descriptor, its structure will be freed, and there will be one dangling pointer per pending async control, that the driver will try to use. Clean all the dangling pointers during release(). To avoid adding a performance penalty in the most common case (no async operation), a counter has been introduced with some logic to make sure that it is properly handled.
In the Linux kernel, the following vulnerability has been resolved: media: uvcvideo: Remove dangling pointers When an async control is written, we copy a pointer to the file handle that started the operation. That pointer will be used when the device is done. Which could be anytime in the future. If the user closes that file descriptor, its structure will be freed, and there will be one dangling pointer per pending async control, that the driver will try to use. Clean all the dangling pointers during release(). To avoid adding a performance penalty in the most common case (no async operation), a counter has been introduced with some logic to make sure that it is properly handled.
CVE-2025-38089
In the Linux kernel, the following vulnerability has been resolved: sunrpc: handle SVC_GARBAGE during svc auth processing as auth error tianshuo han reported a remotely-triggerable crash if the client sends a kernel RPC server a specially crafted packet. If decoding the RPC reply fails in such a way that SVC_GARBAGE is returned without setting the rq_accept_statp pointer, then that pointer can be dereferenced and a value stored there. If it's the first time the thread has processed an RPC, then that pointer will be set to NULL and the kernel will crash. In other cases, it could create a memory scribble. The server sunrpc code treats a SVC_GARBAGE return from svc_authenticate or pg_authenticate as if it should send a GARBAGE_ARGS reply. RFC 5531 says that if authentication fails that the RPC should be rejected instead with a status of AUTH_ERR. Handle a SVC_GARBAGE return as an AUTH_ERROR, with a reason of AUTH_BADCRED instead of returning GARBAGE_ARGS in that case. This sidesteps the whole problem of touching the rpc_accept_statp pointer in this situation and avoids the crash.
In the Linux kernel, the following vulnerability has been resolved: sunrpc: handle SVC_GARBAGE during svc auth processing as auth error tianshuo han reported a remotely-triggerable crash if the client sends a kernel RPC server a specially crafted packet. If decoding the RPC reply fails in such a way that SVC_GARBAGE is returned without setting the rq_accept_statp pointer, then that pointer can be dereferenced and a value stored there. If it's the first time the thread has processed an RPC, then that pointer will be set to NULL and the kernel will crash. In other cases, it could create a memory scribble. The server sunrpc code treats a SVC_GARBAGE return from svc_authenticate or pg_authenticate as if it should send a GARBAGE_ARGS reply. RFC 5531 says that if authentication fails that the RPC should be rejected instead with a status of AUTH_ERR. Handle a SVC_GARBAGE return as an AUTH_ERROR, with a reason of AUTH_BADCRED instead of returning GARBAGE_ARGS in that case. This sidesteps the whole problem of touching the rpc_accept_statp pointer in this situation and avoids the crash.
追加情報:
N/A
ダウンロード:
SRPMS
- kernel-5.14.0-570.28.1.el9_6.src.rpm
MD5: 1c9b9fad4c18130d3fa6f786e13186e8
SHA-256: 41411505ded032110d539d5987599a11083a72e64a2703e4bd180728ff5a4d18
Size: 142.50 MB
Asianux Server 9 for x86_64
- kernel-5.14.0-570.28.1.el9_6.x86_64.rpm
MD5: b4d4fdd717b4baeb70861a334618c993
SHA-256: f156d3513123e6dd99888e58f3efe93b9b75933ea03d10050a980aa59eee04d1
Size: 1.78 MB - kernel-abi-stablelists-5.14.0-570.28.1.el9_6.noarch.rpm
MD5: ce4bd1c5c792e2f41d58bc03951d5d7e
SHA-256: 6590687ab538b2053cb4960f4b848b36af0966a9b05d606f45719e0c106a93a6
Size: 1.80 MB - kernel-core-5.14.0-570.28.1.el9_6.x86_64.rpm
MD5: 8a11f4ac6cea1f8d2daa0023c93848a5
SHA-256: f81427aeaed4c5c6d56a86dd42ba43bf26a25852ebfa485753ed051d15a8ba0c
Size: 17.85 MB - kernel-cross-headers-5.14.0-570.28.1.el9_6.x86_64.rpm
MD5: 5c39c0ecb68ca2e428da27a91c0d626a
SHA-256: 2c24086ef18bf997c1b8de0088a05bd2ac7b99d8e76cd8879c24f35c7581efe1
Size: 8.65 MB - kernel-debug-5.14.0-570.28.1.el9_6.x86_64.rpm
MD5: fd73aebd26038949acb7784f3ce3338b
SHA-256: e40cc9ce405bdb2764759a8fe23dc11f79a3b1d9c277f4fddca757032687f159
Size: 1.78 MB - kernel-debug-core-5.14.0-570.28.1.el9_6.x86_64.rpm
MD5: a05ded233b480b3a3dbbd8eba242429d
SHA-256: fd5b6ad5daa3ea392080a6fde8331346b3185452d393ab3c4976b7d33c3a73ed
Size: 31.28 MB - kernel-debug-devel-5.14.0-570.28.1.el9_6.x86_64.rpm
MD5: 35d58ebab906a716fcec1ed8d6214611
SHA-256: bf1fc6bf665eaba95fc0853128f32f9b65b69b3ca691f1415faceba4f1a6e2fa
Size: 21.77 MB - kernel-debug-devel-matched-5.14.0-570.28.1.el9_6.x86_64.rpm
MD5: 632ef3cb6df89f8bbf4ec67a3bb6e730
SHA-256: 97fdb29015bb85f6067fbcc984daaeafa0f8570e52f63cf21e1c8a479a031d46
Size: 1.78 MB - kernel-debug-modules-5.14.0-570.28.1.el9_6.x86_64.rpm
MD5: fe72a9f3604a207be66cdfac6f87a444
SHA-256: 277924669d5ba47f3744af2628213f3891cdd22bfe56e44ad8100a9de7a7d0de
Size: 67.38 MB - kernel-debug-modules-core-5.14.0-570.28.1.el9_6.x86_64.rpm
MD5: b1ec2ce336037f8ea2512b13282ca5fe
SHA-256: 0d76be63524410976a72fac5b1feb4e1d4b1bed10bfd7bf0abf9ccd93f603876
Size: 48.90 MB - kernel-debug-modules-extra-5.14.0-570.28.1.el9_6.x86_64.rpm
MD5: a412b09178e23483d26d84b178b81269
SHA-256: 2f32ac85643ad863d84a32311087f241a81a89e7225076465abf7a666174318a
Size: 2.55 MB - kernel-debug-uki-virt-5.14.0-570.28.1.el9_6.x86_64.rpm
MD5: 9539d007e9a39c5ac985d6631128e50d
SHA-256: 0da3affbe12eb138b896f1329c144cb100d87284cb9c2ce735cc71ae5e543b22
Size: 84.36 MB - kernel-devel-5.14.0-570.28.1.el9_6.x86_64.rpm
MD5: 238ada35867a42eec86b3b909412d243
SHA-256: d547c3f09154c43110ac0bbe33320e25cf89c406fbfa26e20b569b7b1a0f978f
Size: 21.60 MB - kernel-devel-matched-5.14.0-570.28.1.el9_6.x86_64.rpm
MD5: 8e22718263cdd878eaf47694ed5ff49d
SHA-256: 58de67af10a01300595a352f5658659bddf02f80736df09012eda8f7aa590b9d
Size: 1.78 MB - kernel-doc-5.14.0-570.28.1.el9_6.noarch.rpm
MD5: bc0842f0049e6643be6832664bac5ca1
SHA-256: dec7e59d66a18d04e11b16c5d3b8bd2c38360ac0ad3ce83ffaa314d6bf768c1c
Size: 37.91 MB - kernel-headers-5.14.0-570.28.1.el9_6.x86_64.rpm
MD5: b61d5e020bf9e083beb2c4d1f3db22fd
SHA-256: d2c97fafd3552f414a30456618b8ae2d1124567bf2129fb6d74375e42bd25ed1
Size: 3.52 MB - kernel-modules-5.14.0-570.28.1.el9_6.x86_64.rpm
MD5: 6b19c42eaa1499ac3e522daaf2e72a1b
SHA-256: 19c60a86ba7a471500df71f26f771a9f97d3311b134e95892b0b17a3447fe7ac
Size: 38.96 MB - kernel-modules-core-5.14.0-570.28.1.el9_6.x86_64.rpm
MD5: 736f20b087473800aa16132c019a991a
SHA-256: 9ebb518a9024242cad5af7b3a1d4d69ee8ef1023c63451c05541ccf3e867c515
Size: 30.87 MB - kernel-modules-extra-5.14.0-570.28.1.el9_6.x86_64.rpm
MD5: 8724dd788249a3501d4bc84c0f3173f6
SHA-256: f1f14f702692cce2ea6b1b1211850ffe670438f28892a880d1e645f680796734
Size: 2.20 MB - kernel-rt-5.14.0-570.28.1.el9_6.x86_64.rpm
MD5: c899993bc287c35f1be090bb9e8dfa31
SHA-256: dfead6bdafe0c026eb48b4a0c8ccfbb2e7ee4e53e366312c4c35954779e74f95
Size: 1.78 MB - kernel-rt-core-5.14.0-570.28.1.el9_6.x86_64.rpm
MD5: 1b08c0bd3c8b95201f6c119d9b139f4e
SHA-256: f7c0ca915d7334fe1c64ff771aeacaf20de92be09738427c582d4be511c765ea
Size: 17.75 MB - kernel-rt-debug-5.14.0-570.28.1.el9_6.x86_64.rpm
MD5: 8954eea6be9998fb7bf6173dd5817014
SHA-256: 5a01f5e407df5e76aa1e4b4474cde0291d29a6a60ca700727fdcf1231b203508
Size: 1.78 MB - kernel-rt-debug-core-5.14.0-570.28.1.el9_6.x86_64.rpm
MD5: 9ae5301280027941a2ca96469e2c98a2
SHA-256: 2ef0998cee7ad167b71e224c76ed8fc792c06bf2fe048a86ee3a438d28dedcde
Size: 19.15 MB - kernel-rt-debug-devel-5.14.0-570.28.1.el9_6.x86_64.rpm
MD5: af7dd24a2c1a84f1a8c601830b1d1c9d
SHA-256: 3cabaa3fa1c6bc2723e2ebde1cc37cab5b661b8bf300cafa3bc0c9bcc1529c35
Size: 21.73 MB - kernel-rt-debug-modules-5.14.0-570.28.1.el9_6.x86_64.rpm
MD5: bba9e2f7ae3733b15f4a05a21a3112c5
SHA-256: dbd8f2ca63c8e5a07d3e7dfbf1bb4dd4faa4adfe1a733f074146dd9e3d2e5ed5
Size: 40.36 MB - kernel-rt-debug-modules-core-5.14.0-570.28.1.el9_6.x86_64.rpm
MD5: 3f155c64313cd91a5ca4808d4458a87e
SHA-256: 3700f12969a08dc58b9a4e19b15db824c2d5d1c219d9d5ce7132ef07d6ea65c7
Size: 31.29 MB - kernel-rt-debug-modules-extra-5.14.0-570.28.1.el9_6.x86_64.rpm
MD5: a6f328764ef9f9a0661334c6b4d07000
SHA-256: 74193e731525d88082d7e10eddecbea04580212f30b8b65575ab9cbb9e141537
Size: 2.23 MB - kernel-rt-devel-5.14.0-570.28.1.el9_6.x86_64.rpm
MD5: 989cd7d834ed26aedf2734c8312da489
SHA-256: 0b78226304b2da868cb429c860c7d9094c4e018722a5cd31526bfceec79dbec0
Size: 21.58 MB - kernel-rt-modules-5.14.0-570.28.1.el9_6.x86_64.rpm
MD5: 8d1b1e7725a6a6a8f4a0e09a9aa26867
SHA-256: 4f19080be7976647dbdb2c23f5934aa002e3dfa3982cd6b788577737f10f92e2
Size: 38.98 MB - kernel-rt-modules-core-5.14.0-570.28.1.el9_6.x86_64.rpm
MD5: e34813af3af51ac0f9c54f44577de6b3
SHA-256: abff0e3ae9e3e41c8f91601788fd86056b74e851052e9cdebac629aae52a3171
Size: 30.25 MB - kernel-rt-modules-extra-5.14.0-570.28.1.el9_6.x86_64.rpm
MD5: d892c76aef049f0119f00a0f319ad050
SHA-256: 1fe34488f0544ccf1e9c3ea3259585da370d8df8106f15e060b0311cd68e26bc
Size: 2.21 MB - kernel-tools-5.14.0-570.28.1.el9_6.x86_64.rpm
MD5: 038c53288780e7f5ee4d6fb75377628a
SHA-256: 513d3cfed3490dede6dde1d6055d0ee4efa344e7b0666e6120726a3f45df7c1e
Size: 2.06 MB - kernel-tools-libs-5.14.0-570.28.1.el9_6.x86_64.rpm
MD5: 3cf60db7d90b22cf132deec39279ae5e
SHA-256: a777f50f99e16ef6cf98199533aa24da9094dccab96ce97f09f4c37591289619
Size: 1.79 MB - kernel-tools-libs-devel-5.14.0-570.28.1.el9_6.x86_64.rpm
MD5: b2c5dd60f2d15e2c52711e70db5774e7
SHA-256: 18233f7706f38865a61c2a295d96f70692950ee7b8c767a28ccef1d2ebc75c4b
Size: 1.78 MB - kernel-uki-virt-5.14.0-570.28.1.el9_6.x86_64.rpm
MD5: 01235dda2c95e4aef67a14a05701ee89
SHA-256: 86abdc845a663b85def12a9f92fbb0ac04f2040e6e5d93bf7d976f40fd40f025
Size: 63.00 MB - kernel-uki-virt-addons-5.14.0-570.28.1.el9_6.x86_64.rpm
MD5: 69c53b52f9da2bc60d6bbc45a8613845
SHA-256: db2b5f465ec9a1e3cce4025d60324f5ff2ddb6345b878c521d20ce7a3468c44e
Size: 1.80 MB - libperf-5.14.0-570.28.1.el9_6.x86_64.rpm
MD5: 86542a64abe141a596fa1aaa2e3c359d
SHA-256: beb21a1659f1e8f3d03f2d75adc2564f8c64f4b7a8c7327160e44fcee1cb137b
Size: 1.80 MB - perf-5.14.0-570.28.1.el9_6.x86_64.rpm
MD5: bcaf4b78619d5ef7083bca07a28584b4
SHA-256: 4030035349122ab5bf51130b31e060f16a432cf3e59181e86f51b598eea6ab72
Size: 4.01 MB - python3-perf-5.14.0-570.28.1.el9_6.x86_64.rpm
MD5: 6550ad4c359dc011052ec5244a053233
SHA-256: 9a7dbdfc6053f4ef882fbf6e2aa8464d08ccd18b8c8a93bcf768ca34300a4c70
Size: 3.19 MB - rtla-5.14.0-570.28.1.el9_6.x86_64.rpm
MD5: 3de7fd2ccc92b734654e279752b50163
SHA-256: a9c0ab76d103e422974fd93088eb83c00501d64be312f947736b2e1ce68ef512
Size: 1.84 MB - rv-5.14.0-570.28.1.el9_6.x86_64.rpm
MD5: d36ce3cf5faa8e3968ba7d3f877b61eb
SHA-256: 3014e56af0d80e4438bd200e4002d193b654a03635d4c95aa163ef0838bd7131
Size: 1.79 MB