Google: sys-kernel/csql-kernel-6_6, sys-kernel/lakitu-kernel-6_6, sys-kernel/lakitu-nc-kernel-6_6, sys-kernel/lakitu-vgpu-kernel-6_6: security update to 18867.528.3

high Tenable Cloud Security Plugin ID 467172

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: bridge: mcast: Fix a possible use-
after-free when removing a bridge port When per-VLAN multicast snooping is enabled, the bridge iterates
over all the bridge ports, disables the per-port multicast context on each port and enables the per-{port,
VLAN} multicast contexts instead. The reverse happens when per-VLAN multicast snooping is disabled. When
global multicast snooping is enabled, the bridge iterates over all the bridge ports and enables the per-
port multicast context on each port. The reverse happens when multicast snooping is disabled. The above
scheme can result in a situation where both types of contexts (per-port and per-{port, VLAN}) are enabled
on a single bridge port: # ip link add name br1 up type bridge mcast_snooping 1 mcast_querier 1
vlan_filtering 1 # ip link add name dummy1 up master br1 type dummy # ip link set dev br1 type bridge
mcast_vlan_snooping 1 # ip link set dev br1 type bridge mcast_snooping 0 # ip link set dev br1 type bridge
mcast_snooping 1 This is not intended and it is a problem since the commit cited below. Prior to this
commit, when removing a bridge port, br_multicast_disable_port() would disable the per-port multicast
context and the per-{port, VLAN} multicast contexts would get disabled when flushing VLANs. After this
commit, br_multicast_disable_port() only disables the per-port multicast context if per-VLAN multicast
snooping is disabled. If both types of contexts were enabled on the port when it was removed, the per-port
multicast context would remain enabled when freeing the bridge port, leading to a use-after-free [1]. Fix
by preventing the bridge from enabling / disabling the per-port multicast contexts when toggling global
multicast snooping if per-VLAN multicast snooping is enabled. [1] ODEBUG: free active (active state 0)
object: ffff88810f8bda78 object type: timer_list hint: br_ip6_multicast_port_query_expired
(net/bridge/br_multicast.c:1927) WARNING: lib/debugobjects.c:629 at debug_print_object+0x1b1/0x3e0, CPU#5:
swapper/5/0 [...] Call Trace: <IRQ> __debug_check_no_obj_freed (lib/debugobjects.c:1116) kfree
(mm/slub.c:2620 mm/slub.c:6250 mm/slub.c:6565) kobject_cleanup (lib/kobject.c:689) rcu_do_batch
(kernel/rcu/tree.c:2617) rcu_core (kernel/rcu/tree.c:2869) handle_softirqs (kernel/softirq.c:622)
__irq_exit_rcu (kernel/softirq.c:656 kernel/softirq.c:496 kernel/softirq.c:735) irq_exit_rcu
(kernel/softirq.c:752) sysvec_apic_timer_interrupt (arch/x86/kernel/apic/apic.c:1061 (discriminator 47)
arch/x86/kernel/apic/apic.c:1061 (discriminator 47)) </IRQ> (CVE-2026-64032)

Solution

Update the sys-kernel/csql-kernel-6_6 library and its related packages to version 18867.528.3 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-121.oval.xml.tar.gz

Plugin Details

Severity: High

ID: 467172

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/2/2026

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 58.14

Vendor

Vendor Severity: LOW

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2026-64032

CVSS v3

Risk Factor: High

Base Score: 7.8

Temporal Score: 6.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 6/4/2026

Reference Information

CVE: CVE-2026-64032