Google: sys-kernel/csql-kernel-6_1, sys-kernel/csql-kernel-6_6: security update to 18613.263.4

medium Tenable Cloud Security Plugin ID 465812

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: x86/mm: Fix flush_tlb_range() when
used for zapping normal PMDs On the following path, flush_tlb_range() can be used for zapping normal PMD
entries (PMD entries that point to page tables) together with the PTE entries in the pointed-to page
table: collapse_pte_mapped_thp pmdp_collapse_flush flush_tlb_range The arm64 version of flush_tlb_range()
has a comment describing that it can be used for page table removal, and does not use any last-level
invalidation optimizations. Fix the X86 version by making it behave the same way. Currently, X86 only uses
this information for the following two purposes, which I think means the issue doesn't have much impact: -
In native_flush_tlb_multi() for checking if lazy TLB CPUs need to be IPI'd to avoid issues with
speculative page table walks. - In Hyper-V TLB paravirtualization, again for lazy TLB stuff. The patch
"x86/mm: only invalidate final translations with INVLPGB" which is currently under review (see
<https://lore.kernel.org/all/[email protected]/>) would probably be making the
impact of this a lot worse. (CVE-2025-22045)

Solution

Update the sys-kernel/csql-kernel-6_1 library and its related packages to version 18613.263.4 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-117.oval.xml.tar.gz

Plugin Details

Severity: Medium

ID: 465812

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/2/2026

Risk Information

VPR

Risk Factor: Medium

Score: 5.8

Percentile: 96.99

Vendor

Vendor Severity: MEDIUM

CVSS v2

Risk Factor: Medium

Base Score: 4.6

Temporal Score: 3.4

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:C

CVSS Score Source: CVE-2025-22045

CVSS v3

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 4/16/2025

Reference Information

CVE: CVE-2025-22045