Google: sys-kernel/cchost-kernel-6_12, sys-kernel/csql-kernel-6_12, sys-kernel/csql-kernel-6_6, sys-kernel/lakitu-kernel-6_12, sys-kernel/lakitu-kernel-6_6, sys-kernel/lakitu-nc-kernel-6_12, sys-kernel/lakitu-nc-kernel-6_6, sys-kernel/lakitu-vgpu-kernel-6_6: security update to 19216.532.3

high Tenable Cloud Security Plugin ID 454612

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: netfilter: ebtables: fix OOB read in
compat_mtw_from_user Luxiao Xu says: The function compat_mtw_from_user() converts ebtables extensions from
32-bit user structures to kernel native structures. However, it lacks proper validation of the user-
supplied match_size/target_size. When certain extensions are processed, the kernel-side translation logic
may perform memory accesses based on the extension's expected size. If the user provides a size smaller
than what the extension requires, it results in an out-of-bounds read as reported by KASAN. This fix
introduces a check to ensure match_size is at least as large as the extension's required compatsize. This
covers matches, watchers, and targets, while maintaining compatibility with standard targets. AFAIU this
is relevant for matches that need to go though match->compat_from_user() call. Those that use plain memcpy
with the user-provided size are ok because the caller checks that size vs the start of the next rule entry
offset (which itself is checked vs. total size copied from userspace). The ->compat_from_user() callbacks
assume they can read compatsize bytes, so they need this extra check. Based on an earlier patch from
Luxiao Xu. (CVE-2026-52927)

Solution

Update the sys-kernel/cchost-kernel-6_12 library and its related packages to version 19216.532.3 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-125.oval.xml.tar.gz

Plugin Details

Severity: High

ID: 454612

Version: Revision 1.1

Type: Local

Published: 10/1/2026

Updated: 10/1/2026

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 58.15

Vendor

Vendor Severity: HIGH

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2026-52927

CVSS v3

Risk Factor: High

Base Score: 7.8

Temporal Score: 6.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 6/24/2026

Reference Information

CVE: CVE-2026-52927