Google: sys-kernel/lakitu-kernel-6_1: security update to 17800.372.99

medium Tenable Cloud Security Plugin ID 452451

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: quota: flush quota_release_work upon
quota writeback One of the paths quota writeback is called from is: freeze_super() sync_filesystem()
ext4_sync_fs() dquot_writeback_dquots() Since we currently don't always flush the quota_release_work queue
in this path, we can end up with the following race: 1. dquot are added to releasing_dquots list during
regular operations. 2. FS Freeze starts, however, this does not flush the quota_release_work queue. 3.
Freeze completes. 4. Kernel eventually tries to flush the workqueue while FS is frozen which hits a
WARN_ON since transaction gets started during frozen state: ext4_journal_check_start+0x28/0x110 [ext4]
(unreliable) __ext4_journal_start_sb+0x64/0x1c0 [ext4] ext4_release_dquot+0x90/0x1d0 [ext4]
quota_release_workfn+0x43c/0x4d0 Which is the following line: WARN_ON(sb->s_writers.frozen ==
SB_FREEZE_COMPLETE); Which ultimately results in generic/390 failing due to dmesg noise. This was detected
on powerpc machine 15 cores. To avoid this, make sure to flush the workqueue during
dquot_writeback_dquots() so we dont have any pending workitems after freeze. (CVE-2024-56780)

Solution

Update the sys-kernel/lakitu-kernel-6_1 library and its related packages to version 17800.372.99 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-109.oval.xml.tar.gz

Plugin Details

Severity: Medium

ID: 452451

Version: Revision 1.1

Type: Local

Published: 10/1/2026

Updated: 10/1/2026

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.18

Vendor

Vendor Severity: MEDIUM

CVSS v2

Risk Factor: Medium

Base Score: 4.6

Temporal Score: 3.4

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:C

CVSS Score Source: CVE-2024-56780

CVSS v3

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 12/12/2023

Reference Information

CVE: CVE-2024-56780