Google: sys-kernel/csql-kernel-6_1, sys-kernel/csql-kernel-6_6: security update to 18613.439.72

high Tenable Cloud Security Plugin ID 466242

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: bridge: mcast: Fix use-after-free
during router port configuration The bridge maintains a global list of ports behind which a multicast
router resides. The list is consulted during forwarding to ensure multicast packets are forwarded to these
ports even if the ports are not member in the matching MDB entry. When per-VLAN multicast snooping is
enabled, the per-port multicast context is disabled on each port and the port is removed from the global
router port list: # ip link add name br1 up type bridge vlan_filtering 1 mcast_snooping 1 # ip link add
name dummy1 up master br1 type dummy # ip link set dev dummy1 type bridge_slave mcast_router 2 $ bridge -d
mdb show | grep router router ports on br1: dummy1 # ip link set dev br1 type bridge mcast_vlan_snooping 1
$ bridge -d mdb show | grep router However, the port can be re-added to the global list even when per-VLAN
multicast snooping is enabled: # ip link set dev dummy1 type bridge_slave mcast_router 0 # ip link set dev
dummy1 type bridge_slave mcast_router 2 $ bridge -d mdb show | grep router router ports on br1: dummy1
Since commit 4b30ae9adb04 ("net: bridge: mcast: re-implement br_multicast_{enable, disable}_port
functions"), when per-VLAN multicast snooping is enabled, multicast disablement on a port will disable the
per-{port, VLAN} multicast contexts and not the per-port one. As a result, a port will remain in the
global router port list even after it is deleted. This will lead to a use-after-free [1] when the list is
traversed (when adding a new port to the list, for example): # ip link del dev dummy1 # ip link add name
dummy2 up master br1 type dummy # ip link set dev dummy2 type bridge_slave mcast_router 2 Similarly, stale
entries can also be found in the per-VLAN router port list. When per-VLAN multicast snooping is disabled,
the per-{port, VLAN} contexts are disabled on each port and the port is removed from the per-VLAN router
port list: # ip link add name br1 up type bridge vlan_filtering 1 mcast_snooping 1 mcast_vlan_snooping 1 #
ip link add name dummy1 up master br1 type dummy # bridge vlan add vid 2 dev dummy1 # bridge vlan global
set vid 2 dev br1 mcast_snooping 1 # bridge vlan set vid 2 dev dummy1 mcast_router 2 $ bridge vlan global
show dev br1 vid 2 | grep router router ports: dummy1 # ip link set dev br1 type bridge
mcast_vlan_snooping 0 $ bridge vlan global show dev br1 vid 2 | grep router However, the port can be re-
added to the per-VLAN list even when per-VLAN multicast snooping is disabled: # bridge vlan set vid 2 dev
dummy1 mcast_router 0 # bridge vlan set vid 2 dev dummy1 mcast_router 2 $ bridge vlan global show dev br1
vid 2 | grep router router ports: dummy1 When the VLAN is deleted from the port, the per-{port, VLAN}
multicast context will not be disabled since multicast snooping is not enabled on the VLAN. As a result,
the port will remain in the per-VLAN router port list even after it is no longer member in the VLAN. This
will lead to a use-after-free [2] when the list is traversed (when adding a new port to the list, for
example): # ip link add name dummy2 up master br1 type dummy # bridge vlan add vid 2 dev dummy2 # bridge
vlan del vid 2 dev dummy1 # bridge vlan set vid 2 dev dummy2 mcast_router 2 Fix these issues by removing
the port from the relevant (global or per-VLAN) router port list in br_multicast_port_ctx_deinit(). The
function is invoked during port deletion with the per-port multicast context and during VLAN deletion with
the per-{port, VLAN} multicast context. Note that deleting the multicast router timer is not enough as it
only takes care of the temporary multicast router states (1 or 3) and not the permanent one (2). [1] BUG:
KASAN: slab-out-of-bounds in br_multicast_add_router.part.0+0x3f1/0x560 Write of size 8 at addr
ffff888004a67328 by task ip/384 [...] Call Trace: <TASK> dump_stack ---truncated--- (CVE-2025-38248)

Solution

Update the sys-kernel/csql-kernel-6_1 library and its related packages to version 18613.439.72 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-117.oval.xml.tar.gz

Plugin Details

Severity: High

ID: 466242

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/2/2026

Risk Information

VPR

Risk Factor: Medium

Score: 6.9

Percentile: 96.5

Vendor

Vendor Severity: HIGH

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2025-38248

CVSS v3

Risk Factor: High

Base Score: 7.8

Temporal Score: 6.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 7/9/2025

Reference Information

CVE: CVE-2025-38248