Google: sys-kernel/csql-kernel-6_6, sys-kernel/lakitu-kernel-6_6, sys-kernel/lakitu-nc-kernel-6_6, sys-kernel/lakitu-vgpu-kernel-6_6: security update to 18867.381.125

high Tenable Cloud Security Plugin ID 467078

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: xfrm: esp: avoid in-place decrypt on
shared skb frags MSG_SPLICE_PAGES can attach pages from a pipe directly to an skb. TCP marks such skbs
with SKBFL_SHARED_FRAG after skb_splice_from_iter(), so later paths that may modify packet data can first
make a private copy. The IPv4/IPv6 datagram append paths did not set this flag when splicing pages into
UDP skbs. That leaves an ESP-in-UDP packet made from shared pipe pages looking like an ordinary uncloned
nonlinear skb. ESP input then takes the no-COW fast path for uncloned skbs without a frag_list and
decrypts in place over data that is not owned privately by the skb. Mark IPv4/IPv6 datagram splice frags
with SKBFL_SHARED_FRAG, matching TCP. Also make ESP input fall back to skb_cow_data() when the flag is
present, so ESP does not decrypt externally backed frags in place. Private nonlinear skb frags still use
the existing fast path. This intentionally does not change ESP output. In esp_output_head(), the path that
appends the ESP trailer to existing skb tailroom without calling skb_cow_data() is not reachable for
nonlinear skbs: skb_tailroom() returns zero when skb->data_len is nonzero, while ESP tailen is positive.
Thus ESP output will either use the separate destination-frag path or fall back to skb_cow_data().
(CVE-2026-43284)

Solution

Update the sys-kernel/csql-kernel-6_6 library and its related packages to version 18867.381.125 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-121.oval.xml.tar.gz

Plugin Details

Severity: High

ID: 467078

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/2/2026

Risk Information

VPR

Risk Factor: Critical

Score: 9.5

Percentile: 99.87

Vendor

Vendor Severity: HIGH

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5.9

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2026-43284

CVSS v3

Risk Factor: High

Base Score: 7.8

Temporal Score: 7.5

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:H/RL:O/RC:C

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Vulnerability Publication Date: 5/8/2026

Exploitable With

Core Impact

Metasploit (xfrm-ESP Page-Cache Write via CVE-2026-43284)

Reference Information

CVE: CVE-2026-43284