Google: sys-kernel/csql-kernel-6_1, sys-kernel/csql-kernel-6_6, sys-kernel/lakitu-kernel-6_1, sys-kernel/lakitu-kernel-6_6, sys-kernel/lakitu-nc-kernel-6_6, sys-kernel/lakitu-vgpu-kernel-6_6, sys-kernel/tpusev-kernel-6_6: security update to 18613.675.2

critical Tenable Cloud Security Plugin ID 466073

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: ixgbevf: fix use-after-free in VEPA
multicast source pruning ixgbevf_clean_rx_irq() prunes frames whose source MAC matches the VF's own
address (VEPA multicast workaround) by freeing the skb and continuing to the next descriptor:
dev_kfree_skb_irq(skb); continue; The skb pointer is declared outside the while loop and persists across
iterations. Because the continue skips the "skb = NULL" reset at the bottom of the loop, the next
iteration enters the "else if (skb)" path and calls ixgbevf_add_rx_frag() on the freed skb, dereferencing
skb_shinfo(skb)->nr_frags - a use-after-free in NAPI softirq context. The sibling driver iavf already
handles this correctly by nulling the pointer before continuing. Apply the same pattern here. I do not
have ixgbevf hardware; the bug was found by static analysis (scan_drop_continue_loops.py + semgrep
drop_continue_in_loop, multi-tool corroboration with the highest score in the scan). The UAF was confirmed
under KASAN by loading a test module that reproduces the exact code pattern (alloc skb, kfree_skb, then
read skb_shinfo(skb)->nr_frags): BUG: KASAN: slab-use-after-free in ixgbevf_uaf_test_init+0x100/0x1000
Read of size 8 at addr 000000006163ae78 by task insmod/30 freed 208-byte region [000000006163adc0,
000000006163ae90) QEMU emulates igb (82576) but not ixgbe (82599), and the igbvf VF driver does not
include the VEPA source pruning path, so a full end-to-end reproduction with emulated hardware was not
possible. (CVE-2026-64113)

Solution

Update the sys-kernel/csql-kernel-6_1 library and its related packages to version 18613.675.2 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-117.oval.xml.tar.gz

Plugin Details

Severity: Critical

ID: 466073

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/2/2026

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 58.27

Vendor

Vendor Severity: HIGH

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2026-64113

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 8.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 6/4/2026

Reference Information

CVE: CVE-2026-64113