Google: sys-kernel/csql-kernel-6_1, sys-kernel/csql-kernel-6_6: security update to 18613.439.81

medium Tenable Cloud Security Plugin ID 466093

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: arch_topology: Fix incorrect error
check in topology_parse_cpu_capacity() Fix incorrect use of PTR_ERR_OR_ZERO() in
topology_parse_cpu_capacity() which causes the code to proceed with NULL clock pointers. The current logic
uses !PTR_ERR_OR_ZERO(cpu_clk) which evaluates to true for both valid pointers and NULL, leading to
potential NULL pointer dereference in clk_get_rate(). Per include/linux/err.h documentation,
PTR_ERR_OR_ZERO(ptr) returns: "The error code within @ptr if it is an error pointer; 0 otherwise." This
means PTR_ERR_OR_ZERO() returns 0 for both valid pointers AND NULL pointers. Therefore
!PTR_ERR_OR_ZERO(cpu_clk) evaluates to true (proceed) when cpu_clk is either valid or NULL, causing
clk_get_rate(NULL) to be called when of_clk_get() returns NULL. Replace with !IS_ERR_OR_NULL(cpu_clk)
which only proceeds for valid pointers, preventing potential NULL pointer dereference in clk_get_rate().
(CVE-2025-40346)

Solution

Update the sys-kernel/csql-kernel-6_1 library and its related packages to version 18613.439.81 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-117.oval.xml.tar.gz

Plugin Details

Severity: Medium

ID: 466093

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/2/2026

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.42

Vendor

Vendor Severity: LOW

CVSS v2

Risk Factor: Medium

Base Score: 4.6

Temporal Score: 3.4

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:C

CVSS Score Source: CVE-2025-40346

CVSS v3

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 11/4/2025

Reference Information

CVE: CVE-2025-40346