Google: sys-kernel/csql-kernel-6_6, sys-kernel/tpusev-kernel-6_6: security update to 18613.439.65

medium Tenable Cloud Security Plugin ID 466135

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: xfrm: also call
xfrm_state_delete_tunnel at destroy time for states that were never added In commit b441cf3f8c4b ("xfrm:
delete x->tunnel as we delete x"), I missed the case where state creation fails between full
initialization (->init_state has been called) and being inserted on the lists. In this situation,
->init_state has been called, so for IPcomp tunnels, the fallback tunnel has been created and added onto
the lists, but the user state never gets added, because we fail before that. The user state doesn't go
through __xfrm_state_delete, so we don't call xfrm_state_delete_tunnel for those states, and we end up
leaking the FB tunnel. There are several codepaths affected by this: the add/update paths, in both net/key
and xfrm, and the migrate code (xfrm_migrate, xfrm_state_migrate). A "proper" rollback of the init_state
work would probably be doable in the add/update code, but for migrate it gets more complicated as multiple
states may be involved. At some point, the new (not-inserted) state will be destroyed, so call
xfrm_state_delete_tunnel during xfrm_state_gc_destroy. Most states will have their fallback tunnel cleaned
up during __xfrm_state_delete, which solves the issue that b441cf3f8c4b (and other patches before it)
aimed at. All states (including FB tunnels) will be removed from the lists once xfrm_state_fini has called
flush_work(&xfrm_state_gc_work). (CVE-2025-40256)

Solution

Update the sys-kernel/csql-kernel-6_6 library and its related packages to version 18613.439.65 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-117.oval.xml.tar.gz

Plugin Details

Severity: Medium

ID: 466135

Version: Revision 1.2

Type: Local

Published: 10/2/2026

Updated: 10/3/2026

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.42

Vendor

Vendor Severity: LOW

CVSS v2

Risk Factor: Medium

Base Score: 4.6

Temporal Score: 3.4

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:C

CVSS Score Source: CVE-2025-40256

CVSS v3

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 12/4/2025

Reference Information

CVE: CVE-2025-40256