Google: sys-kernel/csql-kernel-6_1, sys-kernel/lakitu-kernel-6_1: security update to 18244.582.55

medium Tenable Cloud Security Plugin ID 451245

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: scsi: target: Fix recursive locking in
__configfs_open_file() In flush_write_buffer, &p->frag_sem is acquired and then the loaded store function
is called, which, here, is target_core_item_dbroot_store(). This function called filp_open(), following
which these functions were called (in reverse order), according to the call trace: down_read
__configfs_open_file do_dentry_open vfs_open do_open path_openat do_filp_open file_open_name filp_open
target_core_item_dbroot_store flush_write_buffer configfs_write_iter target_core_item_dbroot_store() tries
to validate the new file path by trying to open the file path provided to it; however, in this case, the
bug report shows: db_root: not a directory: /sys/kernel/config/target/dbroot indicating that the same
configfs file was tried to be opened, on which it is currently working on. Thus, it is trying to acquire
frag_sem semaphore of the same file of which it already holds the semaphore obtained in
flush_write_buffer(), leading to acquiring the semaphore in a nested manner and a possibility of recursive
locking. Fix this by modifying target_core_item_dbroot_store() to use kern_path() instead of filp_open()
to avoid opening the file using filesystem-specific function __configfs_open_file(), and further modifying
it to make this fix compatible. (CVE-2026-23292)

Solution

Update the sys-kernel/csql-kernel-6_1 library and its related packages to version 18244.582.55 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-113.oval.xml.tar.gz

Plugin Details

Severity: Medium

ID: 451245

Version: Revision 1.1

Type: Local

Published: 10/1/2026

Updated: 10/1/2026

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.66

Vendor

Vendor Severity: LOW

CVSS v2

Risk Factor: Medium

Base Score: 4.6

Temporal Score: 3.4

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:C

CVSS Score Source: CVE-2026-23292

CVSS v3

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 3/25/2026

Reference Information

CVE: CVE-2026-23292