Google: sys-kernel/csql-kernel-6_1, sys-kernel/lakitu-kernel-6_1: security update to 18244.582.100

high Tenable Cloud Security Plugin ID 451326

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: net: fix fanout UAF in
packet_release() via NETDEV_UP race `packet_release()` has a race window where `NETDEV_UP` can re-register
a socket into a fanout group's `arr[]` array. The re-registration is not cleaned up by `fanout_release()`,
leaving a dangling pointer in the fanout array. `packet_release()` does NOT zero `po->num` in its
`bind_lock` section. After releasing `bind_lock`, `po->num` is still non-zero and `po->ifindex` still
matches the bound device. A concurrent `packet_notifier(NETDEV_UP)` that already found the socket in
`sklist` can re-register the hook. For fanout sockets, this re-registration calls `__fanout_link(sk, po)`
which adds the socket back into `f->arr[]` and increments `f->num_members`, but does NOT increment
`f->sk_ref`. The fix sets `po->num` to zero in `packet_release` while `bind_lock` is held to prevent
NETDEV_UP from linking, preventing the race window. This bug was found following an additional audit with
Claude Code based on CVE-2025-38617. (CVE-2026-31504)

Solution

Update the sys-kernel/csql-kernel-6_1 library and its related packages to version 18244.582.100 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-113.oval.xml.tar.gz

Plugin Details

Severity: High

ID: 451326

Version: Revision 1.1

Type: Local

Published: 10/1/2026

Updated: 10/1/2026

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 57.92

Vendor

Vendor Severity: LOW

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2026-31504

CVSS v3

Risk Factor: High

Base Score: 7.8

Temporal Score: 6.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 4/22/2026

Reference Information

CVE: CVE-2026-31504