Google: sys-kernel/cchost-kernel-6_12, sys-kernel/csql-kernel-6_12, sys-kernel/lakitu-kernel-6_12, sys-kernel/lakitu-nc-kernel-6_12: security update to 19216.655.6

high Tenable Cloud Security Plugin ID 468809

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: fs/proc/task_mmu: fix
make_uffd_wp_huge_pte() prot-update race Patch series "userfaultfd/pagemap: pre-existing fixes". These are
pre-existing bug fixes that were carried at the front of the userfaultfd RWP working-set-tracking series
up to v5 [1]. Per review feedback that fixes should not sit in the middle of a feature series, they are
split out and sent on their own; the RWP series is reposted rebased on top of this. All six were flagged
by the Sashiko AI review of the RWP series and carry independent of RWP, apply to mm-new directly, and
carry Cc: stable@. 1: fs/proc/task_mmu: a missing huge_ptep_modify_prot_start() in make_uffd_wp_huge_pte()
can lose hardware Dirty/Accessed updates when PAGEMAP_SCAN write-protects a hugetlb PTE. 2:
fs/proc/task_mmu: pagemap_scan_hugetlb_entry() compares the range against HPAGE_SIZE rather than the
hstate page size, so it never write-protects gigantic hugetlb pages. 3: fs/proc/task_mmu: PAGEMAP_SCAN
with PM_SCAN_WP_MATCHING over an unpopulated hugetlb range self-deadlocks -- pagemap_scan_pte_hole() calls
uffd_wp_range() while walk_hugetlb_range() holds the hugetlb vma lock for read, and
hugetlb_change_protection() then takes it for write. Install the marker inline instead. 4: mm/huge_memory:
change_non_present_huge_pmd() drops pmd_swp_uffd_wp on a device-private PMD permission downgrade, silently
losing the uffd-wp marker. 5: userfaultfd: must_wait() applies pte_write() to a locklessly read PTE
without checking pte_present(), so swap/migration entries decode random offset bits and a thread can stay
parked on a stale fault. 6: userfaultfd: __VMA_UFFD_FLAGS feeds VMA_UFFD_MINOR_BIT (41) to mk_vma_flags()
unconditionally, an out-of-bounds write into the single-word vma_flags_t on 32-bit. Build the mask from
config-gated per-mode masks so an unavailable bit is never materialised. This patch (of 6):
make_uffd_wp_huge_pte() arms the UFFD_WP bit on a present HugeTLB PTE by calling
huge_ptep_modify_prot_commit() with a ptent snapshot that was fetched without the corresponding
huge_ptep_modify_prot_start(). The start helper is what atomically clears the entry so the kernel-owned
snapshot stays consistent until the commit; without it, the hardware may set Dirty or Accessed in the live
PTE between the original read and the commit, and huge_ptep_modify_prot_commit() (whose generic
implementation just calls set_huge_pte_at()) then writes the stale snapshot back over the live hardware
bits, losing the update. The non-hugetlb sibling make_uffd_wp_pte() does this correctly via
ptep_modify_prot_start() / ptep_modify_prot_commit(). Mirror that pattern for the present-PTE branch. The
migration case stays as-is -- migration entries are non-present, so there's no hardware update to race
against. (CVE-2026-72175)

Solution

Update the sys-kernel/cchost-kernel-6_12 library and its related packages to version 19216.655.6 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-125.oval.xml.tar.gz

Plugin Details

Severity: High

ID: 468809

Version: Revision 1.5

Type: Local

Published: 10/3/2026

Updated: 10/6/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 6.3

Percentile: 96.6

Vendor

Vendor Severity: LOW

CVSS v2

Risk Factor: Medium

Base Score: 6.2

Temporal Score: 4.6

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:N

CVSS Score Source: CVE-2026-72175

CVSS v3

Risk Factor: High

Base Score: 7.1

Temporal Score: 6.2

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 8/11/2026

Reference Information

CVE: CVE-2026-72175