Google: sys-kernel/csql-kernel-6_6: security update to 18867.294.100

high Tenable Cloud Security Plugin ID 454069

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: ethtool: Avoid overflowing userspace
buffer on stats query The ethtool -S command operates across three ioctl calls: ETHTOOL_GSSET_INFO for the
size, ETHTOOL_GSTRINGS for the names, and ETHTOOL_GSTATS for the values. If the number of stats changes
between these calls (e.g., due to device reconfiguration), userspace's buffer allocation will be
incorrect, potentially leading to buffer overflow. Drivers are generally expected to maintain stable stat
counts, but some drivers (e.g., mlx5, bnx2x, bna, ksz884x) use dynamic counters, making this scenario
possible. Some drivers try to handle this internally: - bnad_get_ethtool_stats() returns early in case
stats.n_stats is not equal to the driver's stats count. - micrel/ksz884x also makes sure not to write
anything beyond stats.n_stats and overflow the buffer. However, both use stats.n_stats which is already
assigned with the value returned from get_sset_count(), hence won't solve the issue described here. Change
ethtool_get_strings(), ethtool_get_stats(), ethtool_get_phy_stats() to not return anything in case of a
mismatch between userspace's size and get_sset_size(), to prevent buffer overflow. The returned n_stats
value will be equal to zero, to reflect that nothing has been returned. This could result in one of two
cases when using upstream ethtool, depending on when the size change is detected: 1. When detected in
ethtool_get_strings(): # ethtool -S eth2 no stats available 2. When detected in get stats, all stats will
be reported as zero. Both cases are presumably transient, and a subsequent ethtool call should succeed.
Other than the overflow avoidance, these two cases are very evident (no output/cleared stats), which is
arguably better than presenting incorrect/shifted stats. I also considered returning an error instead of a
"silent" response, but that seems more destructive towards userspace apps. Notes: - This patch does not
claim to fix the inherent race, it only makes sure that we do not overflow the userspace buffer, and makes
for a more predictable behavior. - RTNL lock is held during each ioctl, the race window exists between the
separate ioctl calls when the lock is released. - Userspace ethtool always fills stats.n_stats, but it is
likely that these stats ioctls are implemented in other userspace applications which might not fill it.
The added code checks that it's not zero, to prevent any regressions. (CVE-2025-68795)

Solution

Update the sys-kernel/csql-kernel-6_6 library and its related packages to version 18867.294.100 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-121.oval.xml.tar.gz

Plugin Details

Severity: High

ID: 454069

Version: Revision 1.1

Type: Local

Published: 10/1/2026

Updated: 10/1/2026

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 58.12

Vendor

Vendor Severity: LOW

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2025-68795

CVSS v3

Risk Factor: High

Base Score: 7.8

Temporal Score: 6.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 1/13/2026

Reference Information

CVE: CVE-2025-68795