Google: sys-kernel/cchost-kernel-6_12, sys-kernel/csql-kernel-6_12, sys-kernel/csql-kernel-6_6, sys-kernel/lakitu-kernel-6_12, sys-kernel/lakitu-kernel-6_6, sys-kernel/lakitu-nc-kernel-6_12, sys-kernel/lakitu-nc-kernel-6_6, sys-kernel/lakitu-vgpu-kernel-6_6: security update to 19216.655.6

medium Tenable Cloud Security Plugin ID 468989

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: binfmt_misc: don't let an 'F' entry
pin its own instance An entry registered with 'F' opens its interpreter at registration time and holds
that file until the entry is freed. Any entry nobody removes by hand only gets closed once the binfmt_misc
superblock is shut down. If the interpreter lives on a mount that keeps that superblock alive the two pin
each other: binfmt_misc sb -> inode -> entry -> interp_file -> vfsmount -> binfmt_misc sb TL;DR the file
is never closed. Once the mount namespace is gone there is nothing left to unregister through either.
There are two ways to trigger this bug: - Point the interpreter at the instance itself. Its files are
regular files owned by the mounter and both bm_get_inode() and simple_fill_super() leave i_op at
empty_iops. So notify_change() falls back to simple_setattr() and chmod +x works. We never set SB_I_NOEXEC
and so open_exec() accepts it. - Use the instance as an overlayfs lower layer. The overlay superblock
holds a clone_private_mount() of every layer until it is destroyed and that clone is in no namespace. So
umount_tree() never reaches it. That's a DoS. And it isn't only the superblock that leaks. It pins the
user namespace it was mounted in, so every iteration permanently eats one of the caller's user namespace
charges. So let's just do the sane thing. SB_I_NOEXEC makes open_exec() fail on the instance's own files
and s_stack_depth makes overlayfs reject the layer before it ever takes a clone. That also covers the
ecryptfs and fuse passthrough variants. What 'F' promises is unchanged. The stable tag is narrower than
the Fixes tags on purpose. Before sandboxed mounts this needed global root against the single instance
everyone shares, and the change doesn't apply to those trees anyway. Note that SB_I_NODEV is implicitly
raised for userns mounts but raise it explicitly here as well. (CVE-2026-74484)

Solution

Update the sys-kernel/cchost-kernel-6_12 library and its related packages to version 19216.655.6 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-125.oval.xml.tar.gz

Plugin Details

Severity: Medium

ID: 468989

Version: Revision 1.4

Type: Local

Published: 10/3/2026

Updated: 10/5/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.66

Vendor

Vendor Severity: LOW

CVSS v2

Risk Factor: High

Base Score: 7.2

Temporal Score: 5.3

Vector: CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2026-74484

CVSS v3

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 8/11/2026

Reference Information

CVE: CVE-2026-74484