Google: sys-kernel/csql-kernel-6_1, sys-kernel/lakitu-kernel-5_15: security update to 17800.436.106

high Tenable Cloud Security Plugin ID 454457

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: sched/fair: Fix potential memory
corruption in child_cfs_rq_on_list child_cfs_rq_on_list attempts to convert a 'prev' pointer to a cfs_rq.
This 'prev' pointer can originate from struct rq's leaf_cfs_rq_list, making the conversion invalid and
potentially leading to memory corruption. Depending on the relative positions of leaf_cfs_rq_list and the
task group (tg) pointer within the struct, this can cause a memory fault or access garbage data. The issue
arises in list_add_leaf_cfs_rq, where both cfs_rq->leaf_cfs_rq_list and rq->leaf_cfs_rq_list are added to
the same leaf list. Also, rq->tmp_alone_branch can be set to rq->leaf_cfs_rq_list. This adds a check `if
(prev == &rq->leaf_cfs_rq_list)` after the main conditional in child_cfs_rq_on_list. This ensures that the
container_of operation will convert a correct cfs_rq struct. This check is sufficient because only cfs_rqs
on the same CPU are added to the list, so verifying the 'prev' pointer against the current rq's list head
is enough. Fixes a potential memory corruption issue that due to current struct layout might not be
manifesting as a crash but could lead to unpredictable behavior when the layout changes. (CVE-2025-21919)

Solution

Update the sys-kernel/csql-kernel-6_1 library and its related packages to version 17800.436.106 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-109.oval.xml.tar.gz

Plugin Details

Severity: High

ID: 454457

Version: Revision 1.1

Type: Local

Published: 10/1/2026

Updated: 10/1/2026

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 57.12

Vendor

Vendor Severity: HIGH

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2025-21919

CVSS v3

Risk Factor: High

Base Score: 7.8

Temporal Score: 6.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 4/1/2025

Reference Information

CVE: CVE-2025-21919