Google: sys-kernel/csql-kernel-6_1, sys-kernel/csql-kernel-6_6, sys-kernel/lakitu-kernel-6_1, sys-kernel/lakitu-kernel-6_6, sys-kernel/lakitu-nc-kernel-6_6, sys-kernel/lakitu-vgpu-kernel-6_6, sys-kernel/tpusev-kernel-6_6: security update to 18613.675.2

high Tenable Cloud Security Plugin ID 466283

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: vsock/vmci: fix UAF when peer resets
connection during handshake vmci_transport_recv_connecting_server() returned err = 0 for a peer RST in its
default switch arm: err = pkt->type == VMCI_TRANSPORT_PACKET_TYPE_RST ? 0 : -EINVAL; That made
vmci_transport_recv_listen() skip vsock_remove_pending(), leaving the pending socket on the listener's
pending_links with sk_state = TCP_CLOSE while destroy: still dropped the explicit reference taken before
schedule_delayed_work(). One second later vsock_pending_work() observed is_pending=true and performed full
cleanup: vsock_remove_pending() then the two trailing sock_put(sk) calls -- the first reached refcount 0
and __sk_freed the socket, and the second wrote into the freed object: BUG: KASAN: slab-use-after-free in
refcount_warn_saturate Write of size 4 at addr ffff88800b1cac80 by task kworker Workqueue: events
vsock_pending_work Treat peer RST like any other unexpected packet type (err = -EINVAL). All destroy: arms
now return err < 0, so vmci_transport_recv_listen() removes pending from pending_links synchronously and
vsock_pending_work() takes the is_pending=false / !rejected branch, dropping only its own work reference.
This also closes the multi-packet race Sashiko reported on v2: pending is removed from the list before any
subsequent packet can find it. The pre-existing sk_acceptq_removed() gap on the err < 0 path of
vmci_transport_recv_listen() that Sashiko also noted is not introduced or changed by this patch. Tested on
lts-6.12.79 with KASAN: 52/100 unpatched -> 0/100 patched. (CVE-2026-64115)

Solution

Update the sys-kernel/csql-kernel-6_1 library and its related packages to version 18613.675.2 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-117.oval.xml.tar.gz

Plugin Details

Severity: High

ID: 466283

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/2/2026

Risk Information

VPR

Risk Factor: Medium

Score: 5

Percentile: 93.3

Vendor

Vendor Severity: HIGH

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2026-64115

CVSS v3

Risk Factor: High

Base Score: 8.8

Temporal Score: 7.7

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 6/4/2026

Reference Information

CVE: CVE-2026-64115