Google: sys-kernel/csql-kernel-6_1, sys-kernel/csql-kernel-6_6: security update to 18613.534.2

medium Tenable Cloud Security Plugin ID 466174

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: bpf: Do not let BPF test infra emit
invalid GSO types to stack Yinhao et al. reported that their fuzzer tool was able to trigger a
skb_warn_bad_offload() from netif_skb_features() -> gso_features_check(). When a BPF program - triggered
via BPF test infra - pushes the packet to the loopback device via bpf_clone_redirect() then mentioned
offload warning can be seen. GSO-related features are then rightfully disabled. We get into this situation
due to convert___skb_to_skb() setting gso_segs and gso_size but not gso_type. Technically, it makes sense
that this warning triggers since the GSO properties are malformed due to the gso_type. Potentially, the
gso_type could be marked non-trustworthy through setting it at least to SKB_GSO_DODGY without any other
specific assumptions, but that also feels wrong given we should not go further into the GSO engine in the
first place. The checks were added in 121d57af308d ("gso: validate gso_type in GSO handlers") because
there were malicious (syzbot) senders that combine a protocol with a non-matching gso_type. If we would
want to drop such packets, gso_features_check() currently only returns feature flags via
netif_skb_features(), so one location for potentially dropping such skbs could be
validate_xmit_unreadable_skb(), but then otoh it would be an additional check in the fast-path for a very
corner case. Given bpf_clone_redirect() is the only place where BPF test infra could emit such packets,
lets reject them right there. (CVE-2025-68725)

Solution

Update the sys-kernel/csql-kernel-6_1 library and its related packages to version 18613.534.2 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-117.oval.xml.tar.gz

Plugin Details

Severity: Medium

ID: 466174

Version: Revision 1.3

Type: Local

Published: 10/2/2026

Updated: 10/3/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 5.7

Percentile: 96.73

Vendor

Vendor Severity: LOW

CVSS v2

Risk Factor: Medium

Base Score: 4.6

Temporal Score: 3.4

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:C

CVSS Score Source: CVE-2025-68725

CVSS v3

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 12/24/2025

Reference Information

CVE: CVE-2025-68725