Google: sys-kernel/cchost-kernel-6_12, sys-kernel/csql-kernel-6_12, sys-kernel/csql-kernel-6_6, sys-kernel/lakitu-kernel-6_12, sys-kernel/lakitu-kernel-6_6, sys-kernel/lakitu-nc-kernel-6_12, sys-kernel/lakitu-nc-kernel-6_6, sys-kernel/lakitu-vgpu-kernel-6_6: security update to 19216.700.7

critical Tenable Cloud Security Plugin ID 469240

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: net: skbuff: don't skb_tx_error() the
source skb in skb_zerocopy() skb_zerocopy() copies frags from @from into @to. On an skb_orphan_frags()
failure it calls skb_tx_error(@from), a destructive operation on the source skb the copy helper does not
own. That completes @from's zerocopy uarg and clears SKBFL_ALL_ZEROCOPY, including the SKBFL_SHARED_FRAG
page-ownership marker. Both callers already report the failure on their own drop path. nfnetlink_queue
does it at nla_put_failure, and Open vSwitch does it in the flow-miss drop arm of ovs_dp_process_packet(),
so nothing is lost by dropping it here. On Open vSwitch's OVS_ACTION_ATTR_USERSPACE path the skb is not
freed on this error: do_execute_actions() ignores output_userspace()'s return value and, unless the upcall
was the last action, keeps forwarding the same skb through the flow's remaining actions. The uarg is
completed while that skb is still in flight, telling the producer its buffers are free, and
SKBFL_SHARED_FRAG is cleared on an skb the rest of the stack still handles. That flag is what makes
esp_input() call skb_cow_data() instead of decrypting in place, so a later local ESP delivery can decrypt
over frags the skb does not own privately. Leave error reporting to the callers. (CVE-2026-90049)

Solution

Update the sys-kernel/cchost-kernel-6_12 library and its related packages to version 19216.700.7 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-125.oval.xml.tar.gz

Plugin Details

Severity: Critical

ID: 469240

Version: Revision 1.3

Type: Local

Published: 10/3/2026

Updated: 10/3/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 5

Percentile: 93.3

Vendor

Vendor Severity: HIGH

CVSS v2

Risk Factor: High

Base Score: 7.2

Temporal Score: 5.3

Vector: CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2026-90049

CVSS v3

Risk Factor: Critical

Base Score: 9.3

Temporal Score: 8.1

Vector: CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 9/16/2026

Reference Information

CVE: CVE-2026-90049