Google: sys-kernel/cchost-kernel-6_12, sys-kernel/csql-kernel-6_12, sys-kernel/lakitu-kernel-6_12, sys-kernel/lakitu-nc-kernel-6_12: security update to 19506.224.80

high Tenable Cloud Security Plugin ID 469288

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: ipc: limit next_id allocation to the
valid ID range The checkpoint/restore sysctl path can request the next SysV IPC id through ids->next_id.
ipc_idr_alloc() currently forwards that request to idr_alloc() with an open-ended upper bound. If the
valid tail of the SysV IPC id space is full, the allocation can spill beyond ipc_mni. The returned SysV
IPC id still uses the normal index encoding, so later lookup and removal can target the wrong slot. This
leaves the real IDR entry behind and breaks the IDR state for the object. The bug is in ipc_idr_alloc() in
the checkpoint/restore path. 1. ids->next_id is passed to: idr_alloc(&ids->ipcs_idr, new,
ipcid_to_idx(next_id), 0, ...) 2. The zero upper bound makes the allocation effectively open-ended. Once
the valid SysV IPC tail is occupied, idr_alloc() can spill past ipc_mni and allocate an entry beyond the
valid IPC id range. 3. The new object id is still encoded with the narrower SysV IPC index width: new->id
= (new->seq << ipcmni_seq_shift()) + idx 4. Later removal goes through ipc_rmid(), which uses:
ipcid_to_idx(ipcp->id) That truncates the real IDR index. An object actually stored at a high index can
then be removed as if it lived at a low in-range index. 5. For shared memory, shm_destroy() frees the
current object anyway, but the real high IDR slot is left behind as a dangling pointer. 6. A subsequent
walk of /proc/sysvipc/shm reaches the stale IDR entry and dereferences freed memory. Prevent this by
bounding the requested allocation to ipc_mni so the checkpoint/restore path fails once the valid range is
exhausted. (CVE-2026-52923)

Solution

Update the sys-kernel/cchost-kernel-6_12 library and its related packages to version 19506.224.80 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-129.oval.xml.tar.gz

Plugin Details

Severity: High

ID: 469288

Version: Revision 1.2

Type: Local

Published: 10/3/2026

Updated: 10/3/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: High

Score: 7.6

Percentile: 98.34

Vendor

Vendor Severity: HIGH

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2026-52923

CVSS v3

Risk Factor: High

Base Score: 7.8

Temporal Score: 6.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 6/22/2026

Reference Information

CVE: CVE-2026-52923