Google: sys-kernel/lakitu-kernel-6_1: security update to 17935.0.0

medium Tenable Cloud Security Plugin ID 450594

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: bpf: Fix issue in verifying
allow_ptr_leaks After we converted the capabilities of our networking-bpf program from cap_sys_admin to
cap_net_admin+cap_bpf, our networking-bpf program failed to start. Because it failed the bpf verifier, and
the error log is "R3 pointer comparison prohibited". A simple reproducer as follows, SEC("cls-ingress")
int ingress(struct __sk_buff *skb) { struct iphdr *iph = (void *)(long)skb->data + sizeof(struct ethhdr);
if ((long)(iph + 1) > (long)skb->data_end) return TC_ACT_STOLEN; return TC_ACT_OK; } Per discussion with
Yonghong and Alexei [1], comparison of two packet pointers is not a pointer leak. This patch fixes it. Our
local kernel is 6.1.y and we expect this fix to be backported to 6.1.y, so stable is CCed. [1].
https://lore.kernel.org/bpf/CAADnVQ+Nmspr7Si+pxWn8zkE7hX-7s93ugwC+94aXSy4uQ9vBg@mail.gmail.com/
(CVE-2023-54181)

Solution

Update the sys-kernel/lakitu-kernel-6_1 library and its related packages to version 17935.0.0 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-113.oval.xml.tar.gz

Plugin Details

Severity: Medium

ID: 450594

Version: Revision 1.1

Type: Local

Published: 10/1/2026

Updated: 10/1/2026

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.42

Vendor

Vendor Severity: LOW

CVSS v2

Risk Factor: Medium

Base Score: 4.6

Temporal Score: 3.4

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:C

CVSS Score Source: CVE-2023-54181

CVSS v3

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 10/3/2023

Reference Information

CVE: CVE-2023-54181