Google: sys-kernel/csql-kernel-6_1, sys-kernel/csql-kernel-6_6: security update to 18555.0.0

medium Tenable Cloud Security Plugin ID 465618

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: ext4: fix uninitialized
ratelimit_state->lock access in __ext4_fill_super() In the following concurrency we will access the
uninitialized rs->lock: ext4_fill_super ext4_register_sysfs // sysfs registered msg_ratelimit_interval_ms
// Other processes modify rs->interval to // non-zero via msg_ratelimit_interval_ms ext4_orphan_cleanup
ext4_msg(sb, KERN_INFO, "Errors on filesystem, " __ext4_msg
___ratelimit(&(EXT4_SB(sb)->s_msg_ratelimit_state) if (!rs->interval) // do nothing if interval is 0
return 1; raw_spin_trylock_irqsave(&rs->lock, flags) raw_spin_trylock(lock) _raw_spin_trylock
__raw_spin_trylock spin_acquire(&lock->dep_map, 0, 1, _RET_IP_) lock_acquire __lock_acquire
register_lock_class assign_lock_key dump_stack(); ratelimit_state_init(&sbi->s_msg_ratelimit_state, 5 *
HZ, 10); raw_spin_lock_init(&rs->lock); // init rs->lock here and get the following dump_stack:
========================================================= INFO: trying to register non-static key. The
code is fine but needs lockdep annotation, or maybe you didn't initialize this object before use? turning
off the locking correctness validator. CPU: 12 PID: 753 Comm: mount Tainted: G E 6.7.0-rc6-next-20231222
#504 [...] Call Trace: dump_stack_lvl+0xc5/0x170 dump_stack+0x18/0x30 register_lock_class+0x740/0x7c0
__lock_acquire+0x69/0x13a0 lock_acquire+0x120/0x450 _raw_spin_trylock+0x98/0xd0 ___ratelimit+0xf6/0x220
__ext4_msg+0x7f/0x160 [ext4] ext4_orphan_cleanup+0x665/0x740 [ext4] __ext4_fill_super+0x21ea/0x2b10 [ext4]
ext4_fill_super+0x14d/0x360 [ext4] [...] =========================================================
Normally interval is 0 until s_msg_ratelimit_state is initialized, so ___ratelimit() does nothing. But
registering sysfs precedes initializing rs->lock, so it is possible to change rs->interval to a non-zero
value via the msg_ratelimit_interval_ms interface of sysfs while rs->lock is uninitialized, and then a
call to ext4_msg triggers the problem by accessing an uninitialized rs->lock. Therefore register sysfs
after all initializations are complete to avoid such problems. (CVE-2024-40998)

Solution

Update the sys-kernel/csql-kernel-6_1 library and its related packages to version 18555.0.0 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-117.oval.xml.tar.gz

Plugin Details

Severity: Medium

ID: 465618

Version: Revision 1.2

Type: Local

Published: 10/2/2026

Updated: 10/3/2026

Risk Information

VPR

Risk Factor: Medium

Score: 5.7

Percentile: 97

Vendor

Vendor Severity: MEDIUM

CVSS v2

Risk Factor: Medium

Base Score: 4.6

Temporal Score: 3.4

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:C

CVSS Score Source: CVE-2024-40998

CVSS v3

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 7/12/2024

Reference Information

CVE: CVE-2024-40998