Google: sys-kernel/csql-kernel-6_1, sys-kernel/csql-kernel-6_6, sys-kernel/lakitu-kernel-6_1, sys-kernel/lakitu-kernel-6_6, sys-kernel/lakitu-nc-kernel-6_6, sys-kernel/lakitu-vgpu-kernel-6_6, sys-kernel/tpusev-kernel-6_6: security update to 18613.675.11

high Tenable Cloud Security Plugin ID 466259

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: ipv6: account for fraggap on the paged
allocation path In __ip6_append_data(), when the paged-allocation branch is taken (MSG_MORE / NETIF_F_SG /
large fraglen), alloclen and pagedlen are computed as alloclen = fragheaderlen + transhdrlen; pagedlen =
datalen - transhdrlen; datalen already includes fraggap (datalen = length + fraggap). When fraggap is non-
zero, this is not the first skb and transhdrlen is zero. The fraggap bytes carried over from the previous
skb are copied just past the fragment headers in the new skb's linear area. The linear area is therefore
undersized by fraggap bytes while pagedlen is overstated by the same amount, and the copy writes past
skb->end into the trailing skb_shared_info. An unprivileged user can trigger this via a UDPv6 socket using
MSG_MORE together with MSG_SPLICE_PAGES. The bad accounting was introduced by commit 773ba4fe9104 ("ipv6:
avoid partial copy for zc"). Before commit ce650a166335 ("udp6: Fix __ip6_append_data()'s handling of
MSG_SPLICE_PAGES"), the negative copy value caused -EINVAL to be returned. That later commit allowed
MSG_SPLICE_PAGES to proceed in this case, making the corruption triggerable. The non-paged branch sets
alloclen to fraglen, which already accounts for fraggap because datalen does. Bring the paged branch in
line by adding fraggap to alloclen and subtracting it from pagedlen. After this adjustment, copy no longer
collapses to -fraggap on the paged path, so remove the stale comment describing that old arithmetic. Since
a negative copy is no longer expected for a valid MSG_SPLICE_PAGES case, remove the MSG_SPLICE_PAGES
exception from the negative copy check. (CVE-2026-53362)

Solution

Update the sys-kernel/csql-kernel-6_1 library and its related packages to version 18613.675.11 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-117.oval.xml.tar.gz

Plugin Details

Severity: High

ID: 466259

Version: Revision 1.3

Type: Local

Published: 10/2/2026

Updated: 10/3/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: High

Score: 8.9

Percentile: 99.71

Vendor

Vendor Severity: HIGH

CVSS v2

Risk Factor: High

Base Score: 7.1

Temporal Score: 5.9

Vector: CVSS2#AV:N/AC:H/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2026-53362

CVSS v3

Risk Factor: High

Base Score: 7.8

Temporal Score: 7.2

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:F/RL:O/RC:C

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Vulnerability Publication Date: 7/2/2026

CISA Known Exploited Vulnerability Due Dates: 8/30/2026

Reference Information

CVE: CVE-2026-53362