Google: sys-kernel/csql-kernel-6_12, sys-kernel/csql-kernel-6_6: security update to 19216.104.95

critical Tenable Cloud Security Plugin ID 469014

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: RX, Fix generating skb from
non-linear xdp_buff for striding RQ XDP programs can change the layout of an xdp_buff through
bpf_xdp_adjust_tail() and bpf_xdp_adjust_head(). Therefore, the driver cannot assume the size of the
linear data area nor fragments. Fix the bug in mlx5 by generating skb according to xdp_buff after XDP
programs run. Currently, when handling multi-buf XDP, the mlx5 driver assumes the layout of an xdp_buff to
be unchanged. That is, the linear data area continues to be empty and fragments remain the same. This may
cause the driver to generate erroneous skb or triggering a kernel warning. When an XDP program added
linear data through bpf_xdp_adjust_head(), the linear data will be ignored as mlx5e_build_linear_skb()
builds an skb without linear data and then pull data from fragments to fill the linear data area. When an
XDP program has shrunk the non-linear data through bpf_xdp_adjust_tail(), the delta passed to
__pskb_pull_tail() may exceed the actual nonlinear data size and trigger the BUG_ON in it. To fix the
issue, first record the original number of fragments. If the number of fragments changes after the XDP
program runs, rewind the end fragment pointer by the difference and recalculate the truesize. Then, build
the skb with the linear data area matching the xdp_buff. Finally, only pull data in if there is non-linear
data and fill the linear part up to 256 bytes. (CVE-2025-40350)

Solution

Update the sys-kernel/csql-kernel-6_12 library and its related packages to version 19216.104.95 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-125.oval.xml.tar.gz

Plugin Details

Severity: Critical

ID: 469014

Version: Revision 1.4

Type: Local

Published: 10/3/2026

Updated: 10/6/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 58.12

Vendor

Vendor Severity: LOW

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2025-40350

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 8.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 12/16/2025

Reference Information

CVE: CVE-2025-40350