Google: sys-kernel/csql-kernel-6_1, sys-kernel/csql-kernel-6_6: security update to 18613.534.95

medium Tenable Cloud Security Plugin ID 466111

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: netfilter: x_tables: restrict
xt_check_match/xt_check_target extensions for NFPROTO_ARP Weiming Shi says: xt_match and xt_target structs
registered with NFPROTO_UNSPEC can be loaded by any protocol family through nft_compat. When such a
match/target sets .hooks to restrict which hooks it may run on, the bitmask uses NF_INET_* constants. This
is only correct for families whose hook layout matches NF_INET_*: IPv4, IPv6, INET, and bridge all share
the same five hooks (PRE_ROUTING ... POST_ROUTING). ARP only has three hooks (IN=0, OUT=1, FORWARD=2) with
different semantics. Because NF_ARP_OUT == 1 == NF_INET_LOCAL_IN, the .hooks validation silently passes
for the wrong reasons, allowing matches to run on ARP chains where the hook assumptions (e.g. state->in
being set on input hooks) do not hold. This leads to NULL pointer dereferences; xt_devgroup is one
concrete example: Oops: general protection fault, probably for non-canonical address 0xdffffc0000000044:
0000 [#1] SMP KASAN NOPTI KASAN: null-ptr-deref in range [0x0000000000000220-0x0000000000000227] RIP:
0010:devgroup_mt+0xff/0x350 Call Trace: <TASK> nft_match_eval (net/netfilter/nft_compat.c:407)
nft_do_chain (net/netfilter/nf_tables_core.c:285) nft_do_chain_arp (net/netfilter/nft_chain_filter.c:61)
nf_hook_slow (net/netfilter/core.c:623) arp_xmit (net/ipv4/arp.c:666) </TASK> Kernel panic - not syncing:
Fatal exception in interrupt Fix it by restricting arptables to NFPROTO_ARP extensions only. Note that
arptables-legacy only supports: - arpt_CLASSIFY - arpt_mangle - arpt_MARK that provide explicit
NFPROTO_ARP match/target declarations. (CVE-2026-31424)

Solution

Update the sys-kernel/csql-kernel-6_1 library and its related packages to version 18613.534.95 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-117.oval.xml.tar.gz

Plugin Details

Severity: Medium

ID: 466111

Version: Revision 1.2

Type: Local

Published: 10/2/2026

Updated: 10/3/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 5

Percentile: 94.36

Vendor

Vendor Severity: LOW

CVSS v2

Risk Factor: Medium

Base Score: 4.6

Temporal Score: 3.4

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:C

CVSS Score Source: CVE-2026-31424

CVSS v3

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 4/13/2026

Reference Information

CVE: CVE-2026-31424