Google: sys-kernel/cchost-kernel-6_12, sys-kernel/csql-kernel-6_12, sys-kernel/csql-kernel-6_6, sys-kernel/lakitu-kernel-6_12, sys-kernel/lakitu-kernel-6_6, sys-kernel/lakitu-nc-kernel-6_12, sys-kernel/lakitu-nc-kernel-6_6, sys-kernel/lakitu-vgpu-kernel-6_6: security update to 19216.532.96

medium Tenable Cloud Security Plugin ID 468733

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: ipv6: ndisc: fix NULL deref in
accept_untracked_na() accept_untracked_na() re-fetches the inet6_dev with __in6_dev_get(dev) and
dereferences idev->cnf.accept_untracked_na without a NULL check, even though its only caller
ndisc_recv_na() already fetched and NULL-checked idev for the same device. Both reads of dev->ip6_ptr run
in the same RCU read-side critical section, but a concurrent addrconf_ifdown() can clear dev->ip6_ptr
between them: lowering the MTU below IPV6_MIN_MTU calls addrconf_ifdown() without the synchronize_net()
that orders the unregister path, so the re-fetch returns NULL and oopses: BUG: KASAN: null-ptr-deref in
ndisc_recv_na (net/ipv6/ndisc.c:974) Read of size 4 at addr 0000000000000364 Call Trace: <IRQ>
ndisc_recv_na (net/ipv6/ndisc.c:974) icmpv6_rcv (net/ipv6/icmp.c:1193) ip6_protocol_deliver_rcu
(net/ipv6/ip6_input.c:479) ip6_input_finish (net/ipv6/ip6_input.c:534) ip6_input
(net/ipv6/ip6_input.c:545) ip6_mc_input (net/ipv6/ip6_input.c:635) ipv6_rcv (net/ipv6/ip6_input.c:351)
</IRQ> It is reachable by an unprivileged user via a network namespace. Pass the caller's already
validated idev instead of re-fetching it; the idev stays alive for the whole RCU critical section, so it
is safe even after dev->ip6_ptr has been cleared. (CVE-2026-64542)

Solution

Update the sys-kernel/cchost-kernel-6_12 library and its related packages to version 19216.532.96 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-125.oval.xml.tar.gz

Plugin Details

Severity: Medium

ID: 468733

Version: Revision 1.6

Type: Local

Published: 10/3/2026

Updated: 10/6/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.59

Vendor

Vendor Severity: LOW

CVSS v2

Risk Factor: Low

Base Score: 3.8

Temporal Score: 2.8

Vector: CVSS2#AV:L/AC:H/Au:S/C:N/I:N/A:C

CVSS Score Source: CVE-2026-64542

CVSS v3

Risk Factor: Medium

Base Score: 4.7

Temporal Score: 4.1

Vector: CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 7/27/2026

Reference Information

CVE: CVE-2026-64542