Google: sys-kernel/cchost-kernel-6_12, sys-kernel/csql-kernel-6_6: security update to 19216.220.9

medium Tenable Cloud Security Plugin ID 468097

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: bpf, test_run: Subtract size of
xdp_frame from allowed metadata size The xdp_frame structure takes up part of the XDP frame headroom,
limiting the size of the metadata. However, in bpf_test_run, we don't take this into account, which makes
it possible for userspace to supply a metadata size that is too large (taking up the entire headroom). If
userspace supplies such a large metadata size in live packet mode, the xdp_update_frame_from_buff() call
in xdp_test_run_init_page() call will fail, after which packet transmission proceeds with an uninitialised
frame structure, leading to the usual Bad Stuff. The commit in the Fixes tag fixed a related bug where the
second check in xdp_update_frame_from_buff() could fail, but did not add any additional constraints on the
metadata size. Complete the fix by adding an additional check on the metadata size. Reorder the checks
slightly to make the logic clearer and add a comment. (CVE-2026-23140)

Solution

Update the sys-kernel/cchost-kernel-6_12 library and its related packages to version 19216.220.9 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-125.oval.xml.tar.gz

Plugin Details

Severity: Medium

ID: 468097

Version: Revision 1.1

Type: Local

Published: 10/3/2026

Updated: 10/3/2026

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.66

Vendor

Vendor Severity: LOW

CVSS v2

Risk Factor: Medium

Base Score: 4.6

Temporal Score: 3.4

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:C

CVSS Score Source: CVE-2026-23140

CVSS v3

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 2/14/2026

Reference Information

CVE: CVE-2026-23140