Google: sys-kernel/csql-kernel-6_1, sys-kernel/csql-kernel-6_6, sys-kernel/lakitu-kernel-6_1, sys-kernel/lakitu-kernel-6_6, sys-kernel/lakitu-nc-kernel-6_6, sys-kernel/lakitu-vgpu-kernel-6_6, sys-kernel/tpusev-kernel-6_6: security update to 18613.675.2

critical Tenable Cloud Security Plugin ID 466404

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: netfilter: synproxy: refresh tcphdr
after skb_ensure_writable synproxy_tstamp_adjust() rewrites the TCP timestamp option in place and then
patches the TCP checksum via inet_proto_csum_replace4() on the caller-supplied tcphdr pointer. Both
ipv4_synproxy_hook() and ipv6_synproxy_hook() obtain that pointer with skb_header_pointer() before calling
in, so it may either alias skb->head directly or point at the caller's on-stack _tcph buffer. Between
obtaining the pointer and using it, the function calls skb_ensure_writable(skb, optend), which on a cloned
or non-linear skb invokes pskb_expand_head() and frees the old skb->head. After that point the cached th
is stale: caller (ipv[46]_synproxy_hook) th = skb_header_pointer(skb, ..., &_tcph)
synproxy_tstamp_adjust(skb, protoff, th, ...) skb_ensure_writable(skb, optend) pskb_expand_head() /*
kfree(old skb->head) */ ... inet_proto_csum_replace4(&th->check, ...) /* writes into freed head, or into
the caller's stack copy leaving the on-wire checksum stale */ The option bytes are written through
skb->data and are fine; only the checksum update goes through th and so lands in the wrong place. The
result is either a write into freed slab memory or a packet leaving with a checksum that does not match
its payload. Fix by re-deriving th from skb->data + protoff immediately after skb_ensure_writable()
succeeds, so the subsequent checksum update targets the linear, writable header. (CVE-2026-64007)

Solution

Update the sys-kernel/csql-kernel-6_1 library and its related packages to version 18613.675.2 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-117.oval.xml.tar.gz

Plugin Details

Severity: Critical

ID: 466404

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/2/2026

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 58.27

Vendor

Vendor Severity: LOW

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2026-64007

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 8.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 6/22/2026

Reference Information

CVE: CVE-2026-64007