Google: sys-kernel/csql-kernel-6_1, sys-kernel/lakitu-kernel-6_1: security update to 18244.448.6

medium Tenable Cloud Security Plugin ID 451419

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: x86/iopl: Cure TIF_IO_BITMAP
inconsistencies io_bitmap_exit() is invoked from exit_thread() when a task exists or when a fork fails. In
the latter case the exit_thread() cleans up resources which were allocated during fork(). io_bitmap_exit()
invokes task_update_io_bitmap(), which in turn ends up in tss_update_io_bitmap(). tss_update_io_bitmap()
operates on the current task. If current has TIF_IO_BITMAP set, but no bitmap installed,
tss_update_io_bitmap() crashes with a NULL pointer dereference. There are two issues, which lead to that
problem: 1) io_bitmap_exit() should not invoke task_update_io_bitmap() when the task, which is cleaned up,
is not the current task. That's a clear indicator for a cleanup after a failed fork(). 2) A task should
not have TIF_IO_BITMAP set and neither a bitmap installed nor IOPL emulation level 3 activated. This
happens when a kernel thread is created in the context of a user space thread, which has TIF_IO_BITMAP set
as the thread flags are copied and the IO bitmap pointer is cleared. Other than in the failed fork() case
this has no impact because kernel threads including IO workers never return to user space and therefore
never invoke tss_update_io_bitmap(). Cure this by adding the missing cleanups and checks: 1) Prevent
io_bitmap_exit() to invoke task_update_io_bitmap() if the to be cleaned up task is not the current task.
2) Clear TIF_IO_BITMAP in copy_thread() unconditionally. For user space forks it is set later, when the IO
bitmap is inherited in io_bitmap_share(). For paranoia sake, add a warning into tss_update_io_bitmap() to
catch the case, when that code is invoked with inconsistent state. (CVE-2025-38100)

Solution

Update the sys-kernel/csql-kernel-6_1 library and its related packages to version 18244.448.6 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-113.oval.xml.tar.gz

Plugin Details

Severity: Medium

ID: 451419

Version: Revision 1.2

Type: Local

Published: 10/1/2026

Updated: 10/1/2026

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.18

Vendor

Vendor Severity: LOW

CVSS v2

Risk Factor: Medium

Base Score: 4.6

Temporal Score: 3.4

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:C

CVSS Score Source: CVE-2025-38100

CVSS v3

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 7/3/2025

Reference Information

CVE: CVE-2025-38100