Google: sys-kernel/csql-kernel-6_1: security update to 18244.382.65

high Tenable Cloud Security Plugin ID 450835

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: net/sched: Always pass notifications
when child class becomes empty Certain classful qdiscs may invoke their classes' dequeue handler on an
enqueue operation. This may unexpectedly empty the child qdisc and thus make an in-flight class passive
via qlen_notify(). Most qdiscs do not expect such behaviour at this point in time and may re-activate the
class eventually anyways which will lead to a use-after-free. The referenced fix commit attempted to fix
this behavior for the HFSC case by moving the backlog accounting around, though this turned out to be
incomplete since the parent's parent may run into the issue too. The following reproducer demonstrates
this use-after-free: tc qdisc add dev lo root handle 1: drr tc filter add dev lo parent 1: basic classid
1:1 tc class add dev lo parent 1: classid 1:1 drr tc qdisc add dev lo parent 1:1 handle 2: hfsc def 1 tc
class add dev lo parent 2: classid 2:1 hfsc rt m1 8 d 1 m2 0 tc qdisc add dev lo parent 2:1 handle 3:
netem tc qdisc add dev lo parent 3:1 handle 4: blackhole echo 1 | socat -u STDIN
UDP4-DATAGRAM:127.0.0.1:8888 tc class delete dev lo classid 1:1 echo 1 | socat -u STDIN
UDP4-DATAGRAM:127.0.0.1:8888 Since backlog accounting issues leading to a use-after-frees on stale class
pointers is a recurring pattern at this point, this patch takes a different approach. Instead of trying to
fix the accounting, the patch ensures that qdisc_tree_reduce_backlog always calls qlen_notify when the
child qdisc is empty. This solves the problem because deletion of qdiscs always involves a call to
qdisc_reset() and / or qdisc_purge_queue() which ultimately resets its qlen to 0 thus causing the
following qdisc_tree_reduce_backlog() to report to the parent. Note that this may call qlen_notify on
passive classes multiple times. This is not a problem after the recent patch series that made all the
classful qdiscs qlen_notify() handlers idempotent. (CVE-2025-38350)

Solution

Update the sys-kernel/csql-kernel-6_1 library and its related packages to version 18244.382.65 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-113.oval.xml.tar.gz

Plugin Details

Severity: High

ID: 450835

Version: Revision 1.2

Type: Local

Published: 10/1/2026

Updated: 10/1/2026

Risk Information

VPR

Risk Factor: High

Score: 7.6

Percentile: 98.25

Vendor

Vendor Severity: LOW

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2025-38350

CVSS v3

Risk Factor: High

Base Score: 7.8

Temporal Score: 6.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 2/12/2025

Reference Information

CVE: CVE-2025-38350