Google: sys-kernel/csql-kernel-6_1, sys-kernel/csql-kernel-6_6, sys-kernel/lakitu-kernel-6_1, sys-kernel/lakitu-kernel-6_6, sys-kernel/lakitu-nc-kernel-6_6, sys-kernel/lakitu-vgpu-kernel-6_6, sys-kernel/tpusev-kernel-6_6: security update to 18613.613.40

high Tenable Cloud Security Plugin ID 465906

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: xfrm: defensively unhash xfrm_state
lists in __xfrm_state_delete KASAN reproduces a slab-use-after-free in __xfrm_state_delete()'s
hlist_del_rcu calls under syzkaller load on linux-6.12.y stable (reproduced on 6.12.47, also reachable via
the same code path on torvalds/master and on the ipsec tree). Nine unique signatures cluster in the
xfrm_state lifecycle, the load-bearing one being: BUG: KASAN: slab-use-after-free in __hlist_del
include/linux/list.h:990 [inline] BUG: KASAN: slab-use-after-free in hlist_del_rcu
include/linux/rculist.h:516 [inline] BUG: KASAN: slab-use-after-free in __xfrm_state_delete
net/xfrm/xfrm_state.c Write of size 8 at addr ffff8881198bcb70 by task kworker/u8:9/435 Workqueue: netns
cleanup_net Call Trace: __hlist_del / hlist_del_rcu __xfrm_state_delete xfrm_state_delete xfrm_state_flush
xfrm_state_fini ops_exit_list cleanup_net The other observed signatures hit the same slab object from
__xfrm_state_lookup, xfrm_alloc_spi, __xfrm_state_insert and an OOB write variant of __xfrm_state_delete,
all on the byseq/byspi hash chains. __xfrm_state_delete() guards its byseq and byspi unhashes with value-
based predicates: if (x->km.seq) hlist_del_rcu(&x->byseq); if (x->id.spi) hlist_del_rcu(&x->byspi); while
everywhere else in the file (e.g. state_cache, state_cache_input) the safer hlist_unhashed() check is
used. xfrm_alloc_spi() sets x->id.spi = newspi inside xfrm_state_lock and then immediately inserts into
byspi, but a path that observes x->id.spi != 0 outside of xfrm_state_lock can still skip-or-hit the byspi
unhash inconsistently with whether x is actually on the list. The same holds for x->km.seq versus byseq,
and the bydst/bysrc unhashes have no predicate at all, so a second __xfrm_state_delete() on the same
object writes through LIST_POISON pprev. The defensive change here: - Use hlist_del_init_rcu() instead of
hlist_del_rcu() on bydst, bysrc, byseq and byspi so a second deletion is a no-op rather than a write
through LIST_POISON pprev. The byseq/byspi nodes are already initialised in xfrm_state_alloc(). - Test
hlist_unhashed() rather than the value predicate for byseq/byspi, so the unhash decision tracks list state
rather than mutable scalar fields. Empirical verification: applied this patch on top of v6.12.47, rebuilt,
and re-ran the same syzkaller harness for 1h16m on a previously-crashy configuration that produced ~100
hits each of slab-use-after-free Read in xfrm_alloc_spi / Read in __xfrm_state_lookup / Write in
__xfrm_state_delete. After the patch, 7.1M execs across 32 VMs at ~1550 exec/sec produced zero xfrm_state
UAF/OOB hits. /proc/slabinfo confirms the xfrm_state slab is actively allocated and freed during the run
(~143 KiB resident), so the fuzzer is still exercising those code paths -- they just no longer crash.
Reproduction: - Linux 6.12.47 x86_64 + KASAN_GENERIC + KASAN_INLINE + KCOV - syzkaller @
746545b8b1e4c3a128db8652b340d3df90ce61db - 32 QEMU/KVM VMs x 2 vCPU on AWS c5.metal bare metal - 9 unique
signatures collected in ~9h, all within xfrm_state lifecycle (CVE-2026-46116)

Solution

Update the sys-kernel/csql-kernel-6_1 library and its related packages to version 18613.613.40 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-117.oval.xml.tar.gz

Plugin Details

Severity: High

ID: 465906

Version: Revision 1.3

Type: Local

Published: 10/2/2026

Updated: 10/3/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 6.9

Percentile: 96.92

Vendor

Vendor Severity: LOW

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2026-46116

CVSS v3

Risk Factor: High

Base Score: 7

Temporal Score: 6.1

Vector: CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 5/26/2026

Reference Information

CVE: CVE-2026-46116