Google: sys-kernel/csql-kernel-6_1, sys-kernel/csql-kernel-6_6, sys-kernel/lakitu-kernel-6_1, sys-kernel/lakitu-kernel-6_6, sys-kernel/lakitu-nc-kernel-6_6, sys-kernel/lakitu-vgpu-kernel-6_6, sys-kernel/tpusev-kernel-6_6: security update to 18613.675.37

high Tenable Cloud Security Plugin ID 466371

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: bpf: Support for hardening against JIT
spraying The BPF JIT allocator packs many small programs into larger executable allocations and reuses
space within those allocations as programs are loaded and freed. When fresh code is written into space
that a previous program occupied, an indirect jump into the new program can reuse a branch prediction left
behind by the old one. Flush the indirect branch predictors before reusing JIT memory so that indirect
jumps into a newly written program don't reuse predictions from an old program that occupied the same
space. Introduce bpf_arch_pred_flush_enabled static key and bpf_arch_pred_flush static call for flushing
the branch predictors on JIT memory reuse. Architectures that need a flush, can update it to a predictor
flush function. By default, its a NOP and does not emit any CALL. Allocations larger than a pack are not
covered by this flush. That is safe because cBPF programs (the unprivileged attack surface) are bounded
well below a pack size. Issue a warning if this assumption is ever violated while the flush is active.
(CVE-2026-64508)

Solution

Update the sys-kernel/csql-kernel-6_1 library and its related packages to version 18613.675.37 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-117.oval.xml.tar.gz

Plugin Details

Severity: High

ID: 466371

Version: Revision 1.3

Type: Local

Published: 10/2/2026

Updated: 10/3/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: High

Score: 7.6

Percentile: 98.25

Vendor

Vendor Severity: LOW

CVSS v2

Risk Factor: High

Base Score: 7.2

Temporal Score: 5.3

Vector: CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2026-64508

CVSS v3

Risk Factor: High

Base Score: 8.4

Temporal Score: 7.3

Vector: CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 7/25/2026

Reference Information

CVE: CVE-2026-64508