Google: sys-kernel/csql-kernel-6_6: security update to 18867.294.60

high Tenable Cloud Security Plugin ID 452411

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: fs/proc: fix uaf in proc_readdir_de()
Pde is erased from subdir rbtree through rb_erase(), but not set the node to EMPTY, which may result in
uaf access. We should use RB_CLEAR_NODE() set the erased node to EMPTY, then pde_subdir_next() will return
NULL to avoid uaf access. We found an uaf issue while using stress-ng testing, need to run testcase
getdent and tun in the same time. The steps of the issue is as follows: 1) use getdent to traverse dir
/proc/pid/net/dev_snmp6/, and current pde is tun3; 2) in the [time windows] unregister netdevice tun3 and
tun2, and erase them from rbtree. erase tun3 first, and then erase tun2. the pde(tun2) will be released to
slab; 3) continue to getdent process, then pde_subdir_next() will return pde(tun2) which is released, it
will case uaf access. CPU 0 | CPU 1
------------------------------------------------------------------------- traverse dir
/proc/pid/net/dev_snmp6/ | unregister_netdevice(tun->dev) //tun3 tun2 sys_getdents64() | iterate_dir() |
proc_readdir() | proc_readdir_de() | snmp6_unregister_dev() pde_get(de); | proc_remove()
read_unlock(&proc_subdir_lock); | remove_proc_subtree() | write_lock(&proc_subdir_lock); [time window] |
rb_erase(&root->subdir_node, &parent->subdir); | write_unlock(&proc_subdir_lock);
read_lock(&proc_subdir_lock); | next = pde_subdir_next(de); | pde_put(de); | de = next; //UAF | rbtree of
dev_snmp6 | pde(tun3) / \ NULL pde(tun2) (CVE-2025-40271)

Solution

Update the sys-kernel/csql-kernel-6_6 library and its related packages to version 18867.294.60 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-121.oval.xml.tar.gz

Plugin Details

Severity: High

ID: 452411

Version: Revision 1.1

Type: Local

Published: 10/1/2026

Updated: 10/1/2026

Risk Information

VPR

Risk Factor: High

Score: 7.9

Percentile: 99.35

Vendor

Vendor Severity: LOW

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5.3

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2025-40271

CVSS v3

Risk Factor: High

Base Score: 7.8

Temporal Score: 7

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Vulnerability Publication Date: 12/6/2025

Reference Information

CVE: CVE-2025-40271