Google: sys-kernel/csql-kernel-6_6, sys-kernel/lakitu-kernel-6_6, sys-kernel/lakitu-nc-kernel-6_6, sys-kernel/lakitu-vgpu-kernel-6_6: security update to 18867.381.201

high Tenable Cloud Security Plugin ID 467346

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: dm cache policy smq: fix missing locks
in invalidating cache blocks In passthrough mode, the policy invalidate_mapping operation is called
simultaneously from multiple workers, thus it should be protected by a lock. Otherwise, we might end up
with data races on the allocated blocks counter, or even use-after-free issues with internal data
structures when doing concurrent writes. Note that the existing FIXME in smq_invalidate_mapping() doesn't
affect passthrough mode since migration tasks don't exist there, but would need attention if supporting
fast device shrinking via suspend/resume without target reloading. Reproduce steps: 1. Create a cache
device consisting of 1024 cache entries dmsetup create cmeta --table "0 8192 linear /dev/sdc 0" dmsetup
create cdata --table "0 131072 linear /dev/sdc 8192" dmsetup create corig --table "0 262144 linear
/dev/sdc 262144" dd if=/dev/zero of=/dev/mapper/cmeta bs=4k count=1 oflag=direct dmsetup create cache
--table "0 262144 cache /dev/mapper/cmeta \ /dev/mapper/cdata /dev/mapper/corig 128 2 metadata2
writethrough smq 0" 2. Populate the cache, and record the number of cached blocks fio --name=populate
--filename=/dev/mapper/cache --rw=randwrite --bs=4k \ --size=64m --direct=1 nr_cached=$(dmsetup status
cache | awk '{split($7, a, "/"); print a[1]}') 3. Reload the cache into passthrough mode dmsetup suspend
cache dmsetup reload cache --table "0 262144 cache /dev/mapper/cmeta \ /dev/mapper/cdata /dev/mapper/corig
128 2 metadata2 passthrough smq 0" dmsetup resume cache 4. Write to the passthrough cache. By setting
multiple jobs with I/O size equal to the cache block size, cache blocks are invalidated concurrently from
different workers. fio --filename=/dev/mapper/cache --name=test --rw=randwrite --bs=64k \ --direct=1
--numjobs=2 --randrepeat=0 --size=64m 5. Check if demoted matches cached block count. These numbers should
match but may differ due to the data race. nr_demoted=$(dmsetup status cache | awk '{print $12}') echo
"$nr_cached, $nr_demoted" (CVE-2026-53062)

Solution

Update the sys-kernel/csql-kernel-6_6 library and its related packages to version 18867.381.201 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-121.oval.xml.tar.gz

Plugin Details

Severity: High

ID: 467346

Version: Revision 1.2

Type: Local

Published: 10/2/2026

Updated: 10/3/2026

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 58.16

Vendor

Vendor Severity: HIGH

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2026-53062

CVSS v3

Risk Factor: High

Base Score: 7.8

Temporal Score: 6.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 6/3/2026

Reference Information

CVE: CVE-2026-53062