Google: sys-kernel/lakitu-kernel-6_1: security update to 18244.151.9

medium Tenable Cloud Security Plugin ID 451654

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: ACPICA: Revert "ACPICA: avoid Info:
mapping multiple BARs. Your kernel is fine." Undo the modifications made in commit d410ee5109a1 ("ACPICA:
avoid "Info: mapping multiple BARs. Your kernel is fine.""). The initial purpose of this commit was to
stop memory mappings for operation regions from overlapping page boundaries, as it can trigger warnings if
different page attributes are present. However, it was found that when this situation arises, mapping
continues until the boundary's end, but there is still an attempt to read/write the entire length of the
map, leading to a NULL pointer deference. For example, if a four-byte mapping request is made but only one
byte is mapped because it hits the current page boundary's end, a four-byte read/write attempt is still
made, resulting in a NULL pointer deference. Instead, map the entire length, as the ACPI specification
does not mandate that it must be within the same page boundary. It is permissible for it to be mapped
across different regions. (CVE-2024-40984)

Solution

Update the sys-kernel/lakitu-kernel-6_1 library and its related packages to version 18244.151.9 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-113.oval.xml.tar.gz

Plugin Details

Severity: Medium

ID: 451654

Version: Revision 1.1

Type: Local

Published: 10/1/2026

Updated: 10/1/2026

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.18

Vendor

Vendor Severity: MEDIUM

CVSS v2

Risk Factor: Medium

Base Score: 4.6

Temporal Score: 3.4

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:C

CVSS Score Source: CVE-2024-40984

CVSS v3

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 4/9/2024

Reference Information

CVE: CVE-2024-40984