Google: sys-kernel/cchost-kernel-6_12, sys-kernel/csql-kernel-6_12, sys-kernel/csql-kernel-6_6, sys-kernel/lakitu-kernel-6_12, sys-kernel/lakitu-kernel-6_6, sys-kernel/lakitu-nc-kernel-6_12, sys-kernel/lakitu-nc-kernel-6_6, sys-kernel/lakitu-vgpu-kernel-6_6: security update to 19216.395.138

medium Tenable Cloud Security Plugin ID 454593

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: vrf: Fix a potential NPD when removing
a port from a VRF RCU readers that identified a net device as a VRF port using netif_is_l3_slave() assume
that a subsequent call to netdev_master_upper_dev_get_rcu() will return a VRF device. They then continue
to dereference its l3mdev operations. This assumption is not always correct and can result in a NPD [1].
There is no RCU synchronization when removing a port from a VRF, so it is possible for an RCU reader to
see a new master device (e.g., a bridge) that does not have l3mdev operations. Fix by adding RCU
synchronization after clearing the IFF_L3MDEV_SLAVE flag. Skip this synchronization when a net device is
removed from a VRF as part of its deletion and when the VRF device itself is deleted. In the latter case
an RCU grace period will pass by the time RTNL is released. [1] BUG: kernel NULL pointer dereference,
address: 0000000000000000 [...] RIP: 0010:l3mdev_fib_table_rcu (net/l3mdev/l3mdev.c:181) [...] Call Trace:
<TASK> l3mdev_fib_table_by_index (net/l3mdev/l3mdev.c:201 net/l3mdev/l3mdev.c:189) __inet_bind
(net/ipv4/af_inet.c:499 (discriminator 3)) inet_bind_sk (net/ipv4/af_inet.c:469) __sys_bind
(./include/linux/file.h:62 (discriminator 1) ./include/linux/file.h:83 (discriminator 1) net/socket.c:1951
(discriminator 1)) __x64_sys_bind (net/socket.c:1969 (discriminator 1) net/socket.c:1967 (discriminator 1)
net/socket.c:1967 (discriminator 1)) do_syscall_64 (arch/x86/entry/syscall_64.c:63 (discriminator 1)
arch/x86/entry/syscall_64.c:94 (discriminator 1)) entry_SYSCALL_64_after_hwframe
(arch/x86/entry/entry_64.S:130) (CVE-2026-52925)

Solution

Update the sys-kernel/cchost-kernel-6_12 library and its related packages to version 19216.395.138 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-125.oval.xml.tar.gz

Plugin Details

Severity: Medium

ID: 454593

Version: Revision 1.1

Type: Local

Published: 10/1/2026

Updated: 10/1/2026

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.58

Vendor

Vendor Severity: MEDIUM

CVSS v2

Risk Factor: Medium

Base Score: 4.6

Temporal Score: 3.4

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:C

CVSS Score Source: CVE-2026-52925

CVSS v3

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 6/3/2026

Reference Information

CVE: CVE-2026-52925