Google: sys-kernel/csql-kernel-6_1, sys-kernel/csql-kernel-6_6, sys-kernel/lakitu-kernel-6_1, sys-kernel/lakitu-kernel-6_6, sys-kernel/lakitu-nc-kernel-6_6, sys-kernel/lakitu-vgpu-kernel-6_6, sys-kernel/tpusev-kernel-6_6: security update to 18613.731.2

high Tenable Cloud Security Plugin ID 466210

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: packet: synchronize pressure clearing
with ring reconfiguration packet_set_ring() updates the RX ring state under sk_receive_queue.lock, but
used to publish the tpacket receive mode through po->prot_hook.func after releasing that lock.
packet_poll() and packet_recvmsg() can then run the pressure clearing path after the ring has been cleared
while still seeing tpacket_rcv, causing __packet_rcv_has_room() to dereference stale or NULL ring storage.
Move the existing receive hook assignment into the same sk_receive_queue.lock section as the ring state
update. Keep the assignment otherwise unchanged, including on TX ring reconfiguration, to avoid adding
behavior changes that are not required for the fix. Serialize packet_recvmsg() pressure clearing with the
same queue lock only after PACKET_SOCK_PRESSURE has been observed. If the flag is clear and the socket has
moved away from tpacket_rcv, packet_set_ring() has already detached the socket and waited for
synchronize_net(), so no new packet input can set the flag again. packet_poll() already holds
sk_receive_queue.lock, so it uses the new unlocked helper directly. (CVE-2026-74666)

Solution

Update the sys-kernel/csql-kernel-6_1 library and its related packages to version 18613.731.2 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-117.oval.xml.tar.gz

Plugin Details

Severity: High

ID: 466210

Version: Revision 1.3

Type: Local

Published: 10/2/2026

Updated: 10/3/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 6.9

Percentile: 96.62

Vendor

Vendor Severity: LOW

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2026-74666

CVSS v3

Risk Factor: High

Base Score: 7.8

Temporal Score: 6.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 8/22/2026

Reference Information

CVE: CVE-2026-74666