Google: sys-kernel/lakitu-kernel-5_15, sys-kernel/lakitu-kernel-6_1: security update to 17800.372.84

medium Tenable Cloud Security Plugin ID 452105

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: ext4: don't set SB_RDONLY after
filesystem errors When the filesystem is mounted with errors=remount-ro, we were setting SB_RDONLY flag to
stop all filesystem modifications. We knew this misses proper locking (sb->s_umount) and does not go
through proper filesystem remount procedure but it has been the way this worked since early ext2 days and
it was good enough for catastrophic situation damage mitigation. Recently, syzbot has found a way (see
link) to trigger warnings in filesystem freezing because the code got confused by SB_RDONLY changing under
its hands. Since these days we set EXT4_FLAGS_SHUTDOWN on the superblock which is enough to stop all
filesystem modifications, modifying SB_RDONLY shouldn't be needed. So stop doing that. (CVE-2024-50191)

Solution

Update the sys-kernel/lakitu-kernel-5_15 library and its related packages to version 17800.372.84 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-109.oval.xml.tar.gz

Plugin Details

Severity: Medium

ID: 452105

Version: Revision 1.1

Type: Local

Published: 10/1/2026

Updated: 10/1/2026

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.18

Vendor

Vendor Severity: MEDIUM

CVSS v2

Risk Factor: Medium

Base Score: 4.6

Temporal Score: 3.4

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:C

CVSS Score Source: CVE-2024-50191

CVSS v3

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 10/31/2024

Reference Information

CVE: CVE-2024-50191