Google: sys-kernel/csql-kernel-6_1: security update to 18244.448.6

high Tenable Cloud Security Plugin ID 452447

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: bpf, sockmap: Avoid using sk_socket
after free when sending The sk->sk_socket is not locked or referenced in backlog thread, and during the
call to skb_send_sock(), there is a race condition with the release of sk_socket. All types of
sockets(tcp/udp/unix/vsock) will be affected. Race conditions: ''' CPU0 CPU1 backlog::skb_send_sock
sendmsg_unlocked sock_sendmsg sock_sendmsg_nosec close(fd): ... ops->release() -> sock_map_close()
sk_socket->ops = NULL free(socket) sock->ops->sendmsg ^ panic here ''' The ref of psock become 0 after
sock_map_close() executed. ''' void sock_map_close() { ... if (likely(psock)) { ... // !! here we remove
psock and the ref of psock become 0 sock_map_remove_links(sk, psock) psock = sk_psock_get(sk); if
(unlikely(!psock)) goto no_psock; <=== Control jumps here via goto ...
cancel_delayed_work_sync(&psock->work); <=== not executed sk_psock_put(sk, psock); ... } ''' Based on the
fact that we already wait for the workqueue to finish in sock_map_close() if psock is held, we simply
increase the psock reference count to avoid race conditions. With this patch, if the backlog thread is
running, sock_map_close() will wait for the backlog thread to complete and cancel all pending work. If no
backlog running, any pending work that hasn't started by then will fail when invoked by sk_psock_get(), as
the psock reference count have been zeroed, and sk_psock_drop() will cancel all jobs via
cancel_delayed_work_sync(). In summary, we require synchronization to coordinate the backlog thread and
close() thread. The panic I catched: ''' Workqueue: events sk_psock_backlog RIP:
0010:sock_sendmsg+0x21d/0x440 RAX: 0000000000000000 RBX: ffffc9000521fad8 RCX: 0000000000000001 ... Call
Trace: <TASK> ? die_addr+0x40/0xa0 ? exc_general_protection+0x14c/0x230 ?
asm_exc_general_protection+0x26/0x30 ? sock_sendmsg+0x21d/0x440 ? sock_sendmsg+0x3e0/0x440 ?
__pfx_sock_sendmsg+0x10/0x10 __skb_send_sock+0x543/0xb70 sk_psock_backlog+0x247/0xb80 ... '''
(CVE-2025-38154)

Solution

Update the sys-kernel/csql-kernel-6_1 library and its related packages to version 18244.448.6 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-113.oval.xml.tar.gz

Plugin Details

Severity: High

ID: 452447

Version: Revision 1.1

Type: Local

Published: 10/1/2026

Updated: 10/1/2026

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 57.41

Vendor

Vendor Severity: LOW

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2025-38154

CVSS v3

Risk Factor: High

Base Score: 7.8

Temporal Score: 6.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 7/3/2025

Reference Information

CVE: CVE-2025-38154