Google: sys-kernel/csql-kernel-6_6, sys-kernel/lakitu-kernel-6_6, sys-kernel/lakitu-nc-kernel-6_6, sys-kernel/lakitu-vgpu-kernel-6_6: security update to 18867.381.132

medium Tenable Cloud Security Plugin ID 467696

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: EFI/CPER: don't go past the ARM
processor CPER record buffer There's a logic inside GHES/CPER to detect if the section_length is too
small, but it doesn't detect if it is too big. Currently, if the firmware receives an ARM processor CPER
record stating that a section length is big, kernel will blindly trust section_length, producing a very
long dump. For instance, a 67 bytes record with ERR_INFO_NUM set 46198 and section length set to 854918320
would dump a lot of data going a way past the firmware memory-mapped area. Fix it by adding a logic to
prevent it to go past the buffer if ERR_INFO_NUM is too big, making it report instead: [Hardware Error]:
Hardware error from APEI Generic Hardware Error Source: 1 [Hardware Error]: event severity: recoverable
[Hardware Error]: Error 0, type: recoverable [Hardware Error]: section_type: ARM processor error [Hardware
Error]: MIDR: 0xff304b2f8476870a [Hardware Error]: section length: 854918320, CPER size: 67 [Hardware
Error]: section length is too big [Hardware Error]: firmware-generated error record is incorrect [Hardware
Error]: ERR_INFO_NUM is 46198 [ rjw: Subject and changelog tweaks ] (CVE-2026-43266)

Solution

Update the sys-kernel/csql-kernel-6_6 library and its related packages to version 18867.381.132 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-121.oval.xml.tar.gz

Plugin Details

Severity: Medium

ID: 467696

Version: Revision 1.3

Type: Local

Published: 10/3/2026

Updated: 10/3/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 5

Percentile: 93.7

Vendor

Vendor Severity: LOW

CVSS v2

Risk Factor: Medium

Base Score: 4.6

Temporal Score: 3.4

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:C

CVSS Score Source: CVE-2026-43266

CVSS v3

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 3/12/2026

Reference Information

CVE: CVE-2026-43266