Google: sys-kernel/csql-kernel-6_6: security update to 19165.0.0

medium Tenable Cloud Security Plugin ID 452475

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: virtio-net: fix overflow inside
virtnet_rq_alloc When the frag just got a page, then may lead to regression on VM. Specially if the sysctl
net.core.high_order_alloc_disable value is 1, then the frag always get a page when do refill. Which could
see reliable crashes or scp failure (scp a file 100M in size to VM). The issue is that the virtnet_rq_dma
takes up 16 bytes at the beginning of a new frag. When the frag size is larger than PAGE_SIZE, everything
is fine. However, if the frag is only one page and the total size of the buffer and virtnet_rq_dma is
larger than one page, an overflow may occur. The commit f9dac92ba908 ("virtio_ring: enable premapped mode
whatever use_dma_api") introduced this problem. And we reverted some commits to fix this in last linux
version. Now we try to enable it and fix this bug directly. Here, when the frag size is not enough, we
reduce the buffer len to fix this problem. (CVE-2024-57843)

Solution

Update the sys-kernel/csql-kernel-6_6 library and its related packages to version 19165.0.0 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-125.oval.xml.tar.gz

Plugin Details

Severity: Medium

ID: 452475

Version: Revision 1.1

Type: Local

Published: 10/1/2026

Updated: 10/1/2026

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.17

Vendor

Vendor Severity: MEDIUM

CVSS v2

Risk Factor: Medium

Base Score: 4.6

Temporal Score: 3.4

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:C

CVSS Score Source: CVE-2024-57843

CVSS v3

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 1/11/2025

Reference Information

CVE: CVE-2024-57843