Google: sys-kernel/csql-kernel-6_6, sys-kernel/lakitu-kernel-6_6, sys-kernel/lakitu-nc-kernel-6_6, sys-kernel/lakitu-vgpu-kernel-6_6, sys-kernel/tpusev-kernel-6_6: security update to 18613.675.37

high Tenable Cloud Security Plugin ID 467326

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: udf: validate free block extents
against the partition length udf_free_blocks() checks the logical block number and count against the
partition length, but drops the extent offset from that final bound. A crafted extent can pass the guard
while logicalBlockNum + offset + count points past the partition, which later indexes past the space
bitmap array. A single ftruncate(2) on a file backed by such an extent reliably panics the kernel. This is
a local availability issue. On desktop systems where UDisks/polkit allows the active user to mount
removable UDF media without CAP_SYS_ADMIN, an unprivileged local user can supply the crafted filesystem
and trigger the panic by truncating a writable file on it. Systems that require root or CAP_SYS_ADMIN to
mount the image have a higher prerequisite. No confidentiality or integrity impact is claimed: the
reproduced primitive is an out-of-bounds read of a bitmap pointer slot followed by a kernel panic. Use the
already computed logicalBlockNum + offset + count value for the partition length check. Also make
load_block_bitmap() reject an out-of-range block group before indexing s_block_bitmap[], so corrupted
callers cannot walk past the flexible array. (CVE-2026-64324)

Solution

Update the sys-kernel/csql-kernel-6_6 library and its related packages to version 18613.675.37 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-117.oval.xml.tar.gz

Plugin Details

Severity: High

ID: 467326

Version: Revision 1.3

Type: Local

Published: 10/2/2026

Updated: 10/3/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 6.9

Percentile: 96.76

Vendor

Vendor Severity: HIGH

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2026-64324

CVSS v3

Risk Factor: High

Base Score: 7.8

Temporal Score: 6.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 7/23/2026

Reference Information

CVE: CVE-2026-64324