Google: sys-kernel/lakitu-kernel-6_1: security update to 17819.0.0

medium Tenable Cloud Security Plugin ID 451428

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: xen: speed up grant-table reclaim When
a grant entry is still in use by the remote domain, Linux must put it on a deferred list. Normally, this
list is very short, because the PV network and block protocols expect the backend to unmap the grant
first. However, Qubes OS's GUI protocol is subject to the constraints of the X Window System, and as such
winds up with the frontend unmapping the window first. As a result, the list can grow very large,
resulting in a massive memory leak and eventual VM freeze. To partially solve this problem, make the
number of entries that the VM will attempt to free at each iteration tunable. The default is still 10, but
it can be overridden via a module parameter. This is Cc: stable because (when combined with appropriate
userspace changes) it fixes a severe performance and stability problem for Qubes OS users.
(CVE-2023-54081)

Solution

Update the sys-kernel/lakitu-kernel-6_1 library and its related packages to version 17819.0.0 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-113.oval.xml.tar.gz

Plugin Details

Severity: Medium

ID: 451428

Version: Revision 1.1

Type: Local

Published: 10/1/2026

Updated: 10/1/2026

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.42

Vendor

Vendor Severity: LOW

CVSS v2

Risk Factor: Medium

Base Score: 4.6

Temporal Score: 3.4

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:C

CVSS Score Source: CVE-2023-54081

CVSS v3

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 9/7/2023

Reference Information

CVE: CVE-2023-54081