Google: sys-kernel/csql-kernel-6_1, sys-kernel/csql-kernel-6_6, sys-kernel/lakitu-kernel-6_1, sys-kernel/lakitu-kernel-6_6, sys-kernel/lakitu-nc-kernel-6_6, sys-kernel/lakitu-vgpu-kernel-6_6, sys-kernel/tpusev-kernel-6_6: security update to 18613.613.25

high Tenable Cloud Security Plugin ID 467051

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: ipv6: rpl: reserve mac_len headroom
when recompressed SRH grows ipv6_rpl_srh_rcv() decompresses an RFC 6554 Source Routing Header, swaps the
next segment into ipv6_hdr->daddr, recompresses, then pulls the old header and pushes the new one plus the
IPv6 header back. The recompressed header can be larger than the received one when the swap reduces the
common-prefix length the segments share with daddr (CmprI=0, CmprE>0, seg[0][0] != daddr[0] gives the
maximum +8 bytes). pskb_expand_head() was gated on segments_left == 0, so on earlier segments the push
consumed unchecked headroom. Once skb_push() leaves fewer than skb->mac_len bytes in front of data,
skb_mac_header_rebuild()'s call to: skb_set_mac_header(skb, -skb->mac_len); will store (data - head) -
mac_len into the u16 mac_header field, which wraps to ~65530, and the following memmove() writes mac_len
bytes ~64KiB past skb->head. A single AF_INET6/SOCK_RAW/IPV6_HDRINCL packet over lo with a two segment
type-3 SRH (CmprI=0, CmprE=15) reaches headroom 8 after one pass; KASAN reports a 14-byte OOB write in
ipv6_rthdr_rcv. Fix this by expanding the head whenever the remaining room is less than the push size plus
mac_len, and request that much extra so the rebuilt MAC header fits afterwards. (CVE-2026-43501)

Solution

Update the sys-kernel/csql-kernel-6_1 library and its related packages to version 18613.613.25 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-117.oval.xml.tar.gz

Plugin Details

Severity: High

ID: 467051

Version: Revision 1.3

Type: Local

Published: 10/2/2026

Updated: 10/3/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: High

Score: 7.6

Percentile: 98.3

Vendor

Vendor Severity: CRITICAL

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2026-43501

CVSS v3

Risk Factor: High

Base Score: 7.5

Temporal Score: 6.5

Vector: CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 5/21/2026

Reference Information

CVE: CVE-2026-43501