Google: sys-kernel/cchost-kernel-6_12, sys-kernel/csql-kernel-6_12, sys-kernel/csql-kernel-6_6, sys-kernel/lakitu-kernel-6_12, sys-kernel/lakitu-kernel-6_6, sys-kernel/lakitu-nc-kernel-6_12, sys-kernel/lakitu-nc-kernel-6_6, sys-kernel/lakitu-vgpu-kernel-6_6: security update to 19216.532.108

high Tenable Cloud Security Plugin ID 468975

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: binfmt_misc: set have_execfd only once
the interpreter is opened load_misc_binary() raises bprm->have_execfd as soon as it sees the 'O' (or 'C')
flag. This happens well before it opens the interpreter. If that open fails the flag stays set on the
bprm. binfmt_misc is at the head of the format list so an interpreter open failure that returns -ENOEXEC
lets the search fall through to a later format. This means it runs the matched binary directly having
never staged an interpreter. So bprm->executable is NULL while have_execfd falsely claims a descriptor is
present. Consequently, begin_new_exec() dereferences the missing executable: would_dump(bprm,
bprm->executable); and NULL derefs. Had it not, the hand-off later in the same function would have failed
anyway. FD_ADD(0, bprm->executable) rejects a NULL file with -ENOMEM. Both sites are past the point of no
return so the exec cannot be unwound either way. This can be reached by unprivileged users as binfmt_misc
can be mounted in user namespaces. So a user can register an 'O' entry whose interpreter lives on a FUSE
mount, have the FUSE server fail the open with -ENOEXEC and execute a native ELF file that matches the
entry. have_execfd only means anything alongside the executable it describes which is not set until the
interpreter has been opened and staged. So lets raise it there, next to execfd_creds, which is already set
at that point. An open failure now leaves it clear, so the fallback format derives credentials from the
binary and emits no AT_EXECFD, as it would for any native exec. The argv rewrite load_misc_binary()
performs before the open is still not undone. This means the binary sees the interpreter path in argv[0]
and its own path in argv[1] but that predates this change and only became observable once the exec stopped
faulting. (CVE-2026-68186)

Solution

Update the sys-kernel/cchost-kernel-6_12 library and its related packages to version 19216.532.108 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-125.oval.xml.tar.gz

Plugin Details

Severity: High

ID: 468975

Version: Revision 1.5

Type: Local

Published: 10/3/2026

Updated: 10/6/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 6.9

Percentile: 96.5

Vendor

Vendor Severity: LOW

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2026-68186

CVSS v3

Risk Factor: High

Base Score: 7.8

Temporal Score: 6.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 8/10/2026

Reference Information

CVE: CVE-2026-68186