Google: sys-kernel/cchost-kernel-6_12, sys-kernel/csql-kernel-6_12, sys-kernel/lakitu-kernel-6_12, sys-kernel/lakitu-nc-kernel-6_12: security update to 19506.448.8

medium Tenable Cloud Security Plugin ID 469395

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: xprtrdma: Initialize re_id before
removal registration rpcrdma_create_id() registers ep->re_rn with the rpcrdma ib_client before returning
the new rdma_cm_id to rpcrdma_ep_create(). However rpcrdma_ep_create() currently stores that pointer in
ep->re_id only after rpcrdma_create_id() returns. A local administrator can race an NFS/RDMA mount against
RDMA device removal. If rpcrdma_remove_one() observes the just-registered notification before
rpcrdma_ep_create() assigns ep->re_id, rpcrdma_ep_removal_done() calls
trace_xprtrdma_device_removal(NULL). The tracepoint dereferences id->device->name and copies
id->route.addr.dst_addr, so the callback can crash the kernel with a NULL pointer dereference. Store the
rdma_cm_id in ep->re_id immediately before publishing ep->re_rn. The existing error path still destroys
the id directly if registration fails; ep is then freed by the caller without using ep->re_id. Remove the
later duplicate assignment in rpcrdma_ep_create(). (CVE-2026-72468)

Solution

Update the sys-kernel/cchost-kernel-6_12 library and its related packages to version 19506.448.8 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-129.oval.xml.tar.gz

Plugin Details

Severity: Medium

ID: 469395

Version: Revision 1.6

Type: Local

Published: 10/3/2026

Updated: 10/6/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.59

Vendor

Vendor Severity: LOW

CVSS v2

Risk Factor: Medium

Base Score: 4.6

Temporal Score: 3.4

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:C

CVSS Score Source: CVE-2026-72468

CVSS v3

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 8/11/2026

Reference Information

CVE: CVE-2026-72468