Google: sys-kernel/cchost-kernel-6_12, sys-kernel/csql-kernel-6_12, sys-kernel/csql-kernel-6_6, sys-kernel/lakitu-kernel-6_12, sys-kernel/lakitu-kernel-6_6, sys-kernel/lakitu-nc-kernel-6_12, sys-kernel/lakitu-nc-kernel-6_6, sys-kernel/lakitu-vgpu-kernel-6_6: security update to 19216.395.4

high Tenable Cloud Security Plugin ID 469400

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Clear Present bit before
tearing down PASID entry The Intel VT-d Scalable Mode PASID table entry consists of 512 bits (64 bytes).
When tearing down an entry, the current implementation zeros the entire 64-byte structure immediately
using multiple 64-bit writes. Since the IOMMU hardware may fetch these 64 bytes using multiple internal
transactions (e.g., four 128-bit bursts), updating or zeroing the entire entry while it is active (P=1)
risks a "torn" read. If a hardware fetch occurs simultaneously with the CPU zeroing the entry, the
hardware could observe an inconsistent state, leading to unpredictable behavior or spurious faults. Follow
the "Guidance to Software for Invalidations" in the VT-d spec (Section 6.5.3.3) by implementing the
recommended ownership handshake: 1. Clear only the 'Present' (P) bit of the PASID entry. 2. Use a
dma_wmb() to ensure the cleared bit is visible to hardware before proceeding. 3. Execute the required
invalidation sequence (PASID cache, IOTLB, and Device-TLB flush) to ensure the hardware has released all
cached references. 4. Only after the flushes are complete, zero out the remaining fields of the PASID
entry. Also, add a dma_wmb() in pasid_set_present() to ensure that all other fields of the PASID entry are
visible to the hardware before the Present bit is set. (CVE-2026-45894)

Solution

Update the sys-kernel/cchost-kernel-6_12 library and its related packages to version 19216.395.4 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-125.oval.xml.tar.gz

Plugin Details

Severity: High

ID: 469400

Version: Revision 1.6

Type: Local

Published: 10/3/2026

Updated: 10/6/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: High

Score: 7

Percentile: 98.3

Vendor

Vendor Severity: LOW

CVSS v2

Risk Factor: Medium

Base Score: 6

Temporal Score: 4.4

Vector: CVSS2#AV:L/AC:H/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2026-45894

CVSS v3

Risk Factor: High

Base Score: 7.8

Temporal Score: 6.8

Vector: CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 3/27/2026

Reference Information

CVE: CVE-2026-45894