Google: sys-kernel/cchost-kernel-6_12, sys-kernel/csql-kernel-6_12, sys-kernel/lakitu-kernel-6_12, sys-kernel/lakitu-nc-kernel-6_12: security update to 19506.448.8

medium Tenable Cloud Security Plugin ID 469286

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: keys: make keyring key-chunk byte
order agree with keyring_diff_objects() keyring_get_key_chunk() loads description bytes into the index
chunk low address first, while keyring_diff_objects() numbers the first differing bit from the low end and
folds the absolute byte index into the level without removing the inline-prefix offset the level already
carries. The two disagree on byte order and bit position, so the array can be told two keys first differ
at a bit that does not differ in the chunk the walker uses, letting crafted descriptions collide into one
node. Load the chunk in the order keyring_diff_objects() assumes and drop the inline-prefix length when
folding the byte index into the level. This only changes the in-memory ordering used to place keys within
a keyring; add, search and read of non-colliding keys are unaffected. (CVE-2026-74566)

Solution

Update the sys-kernel/cchost-kernel-6_12 library and its related packages to version 19506.448.8 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-129.oval.xml.tar.gz

Plugin Details

Severity: Medium

ID: 469286

Version: Revision 1.6

Type: Local

Published: 10/3/2026

Updated: 10/6/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 2.1

Percentile: 8.04

Vendor

Vendor Severity: LOW

CVSS v2

Risk Factor: Low

Base Score: 3.2

Temporal Score: 2.4

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:P/A:P

CVSS Score Source: CVE-2026-74566

CVSS v3

Risk Factor: Medium

Base Score: 4.4

Temporal Score: 3.9

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 8/11/2026

Reference Information

CVE: CVE-2026-74566