Google: sys-kernel/csql-kernel-6_12, sys-kernel/csql-kernel-6_6: security update to 19216.104.89

high Tenable Cloud Security Plugin ID 469001

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: ima: don't clear IMA_DIGSIG flag when
setting or removing non-IMA xattr Currently when both IMA and EVM are in fix mode, the IMA signature will
be reset to IMA hash if a program first stores IMA signature in security.ima and then writes/removes some
other security xattr for the file. For example, on Fedora, after booting the kernel with "ima_appraise=fix
evm=fix ima_policy=appraise_tcb" and installing rpm-plugin-ima, installing/reinstalling a package will not
make good reference IMA signature generated. Instead IMA hash is generated, # getfattr -m - -d -e hex
/usr/bin/bash # file: usr/bin/bash security.ima=0x0404... This happens because when setting
security.selinux, the IMA_DIGSIG flag that had been set early was cleared. As a result, IMA hash is
generated when the file is closed. Similarly, IMA signature can be cleared on file close after removing
security xattr like security.evm or setting/removing ACL. Prevent replacing the IMA file signature with a
file hash, by preventing the IMA_DIGSIG flag from being reset. Here's a minimal C reproducer which sets
security.selinux as the last step which can also replaced by removing security.evm or setting ACL,
#include <stdio.h> #include <sys/xattr.h> #include <fcntl.h> #include <unistd.h> #include <string.h>
#include <stdlib.h> int main() { const char* file_path = "/usr/sbin/test_binary"; const char* hex_string =
"030204d33204490066306402304"; int length = strlen(hex_string); char* ima_attr_value; int fd; fd =
open(file_path, O_WRONLY|O_CREAT|O_EXCL, 0644); if (fd == -1) { perror("Error opening file"); return 1; }
ima_attr_value = (char*)malloc(length / 2 ); for (int i = 0, j = 0; i < length; i += 2, j++) {
sscanf(hex_string + i, "%2hhx", &ima_attr_value[j]); } if (fsetxattr(fd, "security.ima", ima_attr_value,
length/2, 0) == -1) { perror("Error setting extended attribute"); close(fd); return 1; } const char*
selinux_value= "system_u:object_r:bin_t:s0"; if (fsetxattr(fd, "security.selinux", selinux_value,
strlen(selinux_value), 0) == -1) { perror("Error setting extended attribute"); close(fd); return 1; }
close(fd); return 0; } (CVE-2025-68183)

Solution

Update the sys-kernel/csql-kernel-6_12 library and its related packages to version 19216.104.89 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-125.oval.xml.tar.gz

Plugin Details

Severity: High

ID: 469001

Version: Revision 1.4

Type: Local

Published: 10/3/2026

Updated: 10/6/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 58.13

Vendor

Vendor Severity: LOW

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2025-68183

CVSS v3

Risk Factor: High

Base Score: 7.8

Temporal Score: 6.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 12/16/2025

Reference Information

CVE: CVE-2025-68183